Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 2 vulnerabilities and has 5 bug fixes can now be installed.. openSUSE security update: security update for go1.26-openssl ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21321-1 Rating: important References: * bsc#1245878 * bsc#1255111 * bsc#1264395 * bsc#1271014 * bsc#1271015 Cross-References: * CVE-2026-39822 * CVE-2026-42505 CVSS scores: * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 5 bug fixes can now be installed. Description: This update for go1.26-openssl fixes the following issues - Update to version go1.26.5 (bsc#1255111). - CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). - CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1225=1 Package List: - openSUSE Leap 16.0: go1.26-openssl-1.26.5-160000.1.1 go1.26-openssl-doc-1.26.5-160000.1.1 go1.26-openssl-race-1.26.5-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42505.html . This important update for openSUSE fixes two vulnerabilities in go1.26-openssl, addressing critical security flaws related to symlink issues.. openSUSE Go OpenSSL Security Update CVE-2026-39822 CVE-2026-42505. . Severity: Important. LinuxSecurity.com Team
An update that solves five vulnerabilities can now be installed.. # Security update for curl Announcement ID: SUSE-SU-2026:22156-1 Release Date: 2026-06-17T08:47:34Z Rating: moderate References: * bsc#1262631 * bsc#1262632 * bsc#1262635 * bsc#1262636 * bsc#1262638 Cross-References: * CVE-2026-4873 * CVE-2026-5545 * CVE-2026-6253 * CVE-2026-6276 * CVE-2026-6429 CVSS scores: * CVE-2026-4873 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-4873 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-4873 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-5545 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-5545 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-5545 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-5545 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-6253 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-6253 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-6253 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6276 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-6276 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6276 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6276 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6429 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-6429 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-6429 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves five vulnerabilities can now be installed. ##Description: This update for curl fixes the following issues: * CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). * CVE-2026-5545: wrong reuse of HTTP Negotiate connection (bsc#1262632). * CVE-2026-6253: proxy credentials leak over redirect-to proxy (bsc#1262635). * CVE-2026-6276: stale custom cookie host causes cookie leak (bsc#1262636). * CVE-2026-6429: netrc credential leak with reused proxy connection (bsc#1262638). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-938=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-938=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libcurl-mini4-8.14.1-160000.6.1 * curl-debugsource-8.14.1-160000.6.1 * libcurl-mini4-debuginfo-8.14.1-160000.6.1 * libcurl4-8.14.1-160000.6.1 * curl-mini-debugsource-8.14.1-160000.6.1 * libcurl4-debuginfo-8.14.1-160000.6.1 * libcurl-devel-8.14.1-160000.6.1 * curl-debuginfo-8.14.1-160000.6.1 * curl-8.14.1-160000.6.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * curl-zsh-completion-8.14.1-160000.6.1 * libcurl-devel-doc-8.14.1-160000.6.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libcurl-mini4-8.14.1-160000.6.1 * curl-debugsource-8.14.1-160000.6.1 * libcurl-mini4-debuginfo-8.14.1-160000.6.1 * libcurl4-8.14.1-160000.6.1 * curl-mini-debugsource-8.14.1-160000.6.1 * libcurl4-debuginfo-8.14.1-160000.6.1 * libcurl-devel-8.14.1-160000.6.1 * curl-debuginfo-8.14.1-160000.6.1 * curl-8.14.1-160000.6.1 * SUSE Linux Enterprise Server 16.0 (noarch) * curl-zsh-completion-8.14.1-160000.6.1 * libcurl-devel-doc-8.14.1-160000.6.1 ## References: *https://www.suse.com/security/cve/CVE-2026-4873.html * https://www.suse.com/security/cve/CVE-2026-5545.html * https://www.suse.com/security/cve/CVE-2026-6253.html * https://www.suse.com/security/cve/CVE-2026-6276.html * https://www.suse.com/security/cve/CVE-2026-6429.html * https://bugzilla.suse.com/show_bug.cgi?id=1262631 * https://bugzilla.suse.com/show_bug.cgi?id=1262632 * https://bugzilla.suse.com/show_bug.cgi?id=1262635 * https://bugzilla.suse.com/show_bug.cgi?id=1262636 * https://bugzilla.suse.com/show_bug.cgi?id=1262638 . Five vulnerabilities addressed in moderates security update for curl on SUSE. Install using recommended methods now.. SUSE Security Update, Curl Security Fix, Moderate Curl Vulnerability, SUSE Curl Patch. . Severity: moderate. LinuxSecurity.com Team
An update that solves six vulnerabilities can now be installed.. # Security update for curl Announcement ID: SUSE-SU-2026:1717-1 Release Date: 2026-05-06T12:14:02Z Rating: important References: * bsc#1259362 * bsc#1262631 * bsc#1262632 * bsc#1262635 * bsc#1262636 * bsc#1262638 Cross-References: * CVE-2026-1965 * CVE-2026-4873 * CVE-2026-5545 * CVE-2026-6253 * CVE-2026-6276 * CVE-2026-6429 CVSS scores: * CVE-2026-1965 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2026-1965 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-1965 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4873 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-4873 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-5545 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-5545 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-6253 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-6253 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-6276 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-6276 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6429 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-6429 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves six vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues: Security issues fixed: * CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). * CVE-2026-5545: wrong reuse of HTTP Negotiate connection (bsc#1262632). * CVE-2026-6253: proxy credentials leak over redirect-to proxy (bsc#1262635). * CVE-2026-6276: stale custom cookie host causes cookie leak (bsc#1262636). * CVE-2026-6429: netrc credential leak with reused proxy connection (bsc#1262638). Other updates and bugfixes: * sws: prevent "connection monitor" to say disconnect twice (bsc#1259362). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-1717=1 * SUSE Linux Enterprise Server 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-1717=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-1717=1 SUSE-SLE-Product- SLES_SAP-15-SP5-2026-1717=1 * SUSE Linux Enterprise Desktop 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-1717=1 *SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-1717=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-1717=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-1717=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-1717=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-1717=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1717=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1717=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1717=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1717=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1717=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1717=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1717=1 SUSE-SLE- INSTALLER-15-SP4-2026-1717=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1717=1 * SUSE Linux Enterprise High Performance Computing 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-1717=1 * SUSE Linux Enterprise Server 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-1717=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-1717=1 * SUSE Linux Enterprise Desktop 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-1717=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-1717=1 * SUSEManager Proxy 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-1717=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 15 SP5 (aarch64 x86_64) * libcurl4-8.14.1-150400.5.83.1 * SUSE Linux Enterprise Server 15 SP5 (aarch64 ppc64le s390x x86_64) * libcurl4-8.14.1-150400.5.83.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libcurl-devel-8.14.1-150400.5.83.1 * libcurl4-8.14.1-150400.5.83.1 * curl-debugsource-8.14.1-150400.5.83.1 * curl-debuginfo-8.14.1-150400.5.83.1 * libcurl4-debuginfo-8.14.1-150400.5.83.1 * curl-8.14.1-150400.5.83.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.83.1 * libcurl4-32bit-8.14.1-150400.5.83.1 * SUSE Linux Enterprise Desktop 15 SP5 (x86_64) * libcurl4-8.14.1-150400.5.83.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libcurl4-8.14.1-150400.5.83.1 * curl-debugsource-8.14.1-150400.5.83.1 * curl-debuginfo-8.14.1-150400.5.83.1 * libcurl4-debuginfo-8.14.1-150400.5.83.1 * curl-8.14.1-150400.5.83.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libcurl4-8.14.1-150400.5.83.1 * curl-debugsource-8.14.1-150400.5.83.1 * curl-debuginfo-8.14.1-150400.5.83.1 * libcurl4-debuginfo-8.14.1-150400.5.83.1 * curl-8.14.1-150400.5.83.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libcurl4-8.14.1-150400.5.83.1 * curl-debugsource-8.14.1-150400.5.83.1 * curl-debuginfo-8.14.1-150400.5.83.1 * libcurl4-debuginfo-8.14.1-150400.5.83.1 * curl-8.14.1-150400.5.83.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libcurl4-8.14.1-150400.5.83.1 * curl-debugsource-8.14.1-150400.5.83.1 * curl-debuginfo-8.14.1-150400.5.83.1 * libcurl4-debuginfo-8.14.1-150400.5.83.1 * curl-8.14.1-150400.5.83.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) *libcurl4-8.14.1-150400.5.83.1 * curl-debugsource-8.14.1-150400.5.83.1 * curl-debuginfo-8.14.1-150400.5.83.1 * libcurl4-debuginfo-8.14.1-150400.5.83.1 * curl-8.14.1-150400.5.83.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libcurl-devel-8.14.1-150400.5.83.1 * libcurl4-8.14.1-150400.5.83.1 * curl-debugsource-8.14.1-150400.5.83.1 * curl-debuginfo-8.14.1-150400.5.83.1 * libcurl4-debuginfo-8.14.1-150400.5.83.1 * curl-8.14.1-150400.5.83.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.83.1 * libcurl4-32bit-8.14.1-150400.5.83.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libcurl-devel-8.14.1-150400.5.83.1 * libcurl4-8.14.1-150400.5.83.1 * curl-debugsource-8.14.1-150400.5.83.1 * curl-debuginfo-8.14.1-150400.5.83.1 * libcurl4-debuginfo-8.14.1-150400.5.83.1 * curl-8.14.1-150400.5.83.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.83.1 * libcurl4-32bit-8.14.1-150400.5.83.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libcurl-devel-8.14.1-150400.5.83.1 * libcurl4-8.14.1-150400.5.83.1 * curl-debugsource-8.14.1-150400.5.83.1 * curl-debuginfo-8.14.1-150400.5.83.1 * libcurl4-debuginfo-8.14.1-150400.5.83.1 * curl-8.14.1-150400.5.83.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.83.1 * libcurl4-32bit-8.14.1-150400.5.83.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libcurl-devel-8.14.1-150400.5.83.1 * libcurl4-8.14.1-150400.5.83.1 * curl-debugsource-8.14.1-150400.5.83.1 * curl-debuginfo-8.14.1-150400.5.83.1 * libcurl4-debuginfo-8.14.1-150400.5.83.1 * curl-8.14.1-150400.5.83.1 * SUSE Linux Enterprise HighPerformance Computing LTSS 15 SP5 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.83.1 * libcurl4-32bit-8.14.1-150400.5.83.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libcurl-devel-8.14.1-150400.5.83.1 * libcurl4-8.14.1-150400.5.83.1 * curl-debugsource-8.14.1-150400.5.83.1 * curl-debuginfo-8.14.1-150400.5.83.1 * libcurl4-debuginfo-8.14.1-150400.5.83.1 * curl-8.14.1-150400.5.83.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.83.1 * libcurl4-32bit-8.14.1-150400.5.83.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libcurl-devel-8.14.1-150400.5.83.1 * libcurl4-8.14.1-150400.5.83.1 * curl-debugsource-8.14.1-150400.5.83.1 * curl-debuginfo-8.14.1-150400.5.83.1 * libcurl4-debuginfo-8.14.1-150400.5.83.1 * curl-8.14.1-150400.5.83.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.83.1 * libcurl4-32bit-8.14.1-150400.5.83.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libcurl-devel-8.14.1-150400.5.83.1 * libcurl4-8.14.1-150400.5.83.1 * curl-debugsource-8.14.1-150400.5.83.1 * curl-debuginfo-8.14.1-150400.5.83.1 * libcurl4-debuginfo-8.14.1-150400.5.83.1 * curl-8.14.1-150400.5.83.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.83.1 * libcurl4-32bit-8.14.1-150400.5.83.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libcurl-devel-8.14.1-150400.5.83.1 * curl-mini-debugsource-8.14.1-150400.5.83.1 * libcurl4-8.14.1-150400.5.83.1 * curl-debugsource-8.14.1-150400.5.83.1 * curl-debuginfo-8.14.1-150400.5.83.1 * libcurl-mini4-debuginfo-8.14.1-150400.5.83.1 * libcurl-mini4-8.14.1-150400.5.83.1 * libcurl4-debuginfo-8.14.1-150400.5.83.1 * curl-8.14.1-150400.5.83.1 * openSUSE Leap 15.4 (noarch) *curl-zsh-completion-8.14.1-150400.5.83.1 * curl-fish-completion-8.14.1-150400.5.83.1 * libcurl-devel-doc-8.14.1-150400.5.83.1 * openSUSE Leap 15.4 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.83.1 * libcurl4-32bit-8.14.1-150400.5.83.1 * libcurl-devel-32bit-8.14.1-150400.5.83.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libcurl4-64bit-8.14.1-150400.5.83.1 * libcurl-devel-64bit-8.14.1-150400.5.83.1 * libcurl4-64bit-debuginfo-8.14.1-150400.5.83.1 * SUSE Linux Enterprise High Performance Computing 15 SP4 (aarch64 x86_64) * libcurl4-8.14.1-150400.5.83.1 * SUSE Linux Enterprise Server 15 SP4 (aarch64 ppc64le s390x x86_64) * libcurl4-8.14.1-150400.5.83.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * libcurl4-8.14.1-150400.5.83.1 * SUSE Linux Enterprise Desktop 15 SP4 (x86_64) * libcurl4-8.14.1-150400.5.83.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * libcurl4-8.14.1-150400.5.83.1 * SUSE Manager Proxy 4.3 (x86_64) * libcurl4-8.14.1-150400.5.83.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1965.html * https://www.suse.com/security/cve/CVE-2026-4873.html * https://www.suse.com/security/cve/CVE-2026-5545.html * https://www.suse.com/security/cve/CVE-2026-6253.html * https://www.suse.com/security/cve/CVE-2026-6276.html * https://www.suse.com/security/cve/CVE-2026-6429.html * https://bugzilla.suse.com/show_bug.cgi?id=1259362 * https://bugzilla.suse.com/show_bug.cgi?id=1262631 * https://bugzilla.suse.com/show_bug.cgi?id=1262632 * https://bugzilla.suse.com/show_bug.cgi?id=1262635 * https://bugzilla.suse.com/show_bug.cgi?id=1262636 * https://bugzilla.suse.com/show_bug.cgi?id=1262638 . Update available for curl on SUSE to address critical credential leaks and TLS issues with six vulnerabilities fixed.. curl update, SUSE vulnerabilities, important security updates, curl security fix. . Severity: Important. LinuxSecurity.com Team
An update that solves 11 vulnerabilities can now be installed.. # Security update for tomcat11 Announcement ID: SUSE-SU-2026:21366-1 Release Date: 2026-04-21T11:33:15Z Rating: important References: * bsc#1258371 * bsc#1261850 * bsc#1261851 * bsc#1261852 * bsc#1261853 * bsc#1261854 * bsc#1261855 * bsc#1261856 * bsc#1261857 Cross-References: * CVE-2025-66614 * CVE-2026-24880 * CVE-2026-25854 * CVE-2026-29129 * CVE-2026-29145 * CVE-2026-29146 * CVE-2026-32990 * CVE-2026-34483 * CVE-2026-34486 * CVE-2026-34487 * CVE-2026-34500 CVSS scores: * CVE-2025-66614 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-66614 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-66614 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L * CVE-2025-66614 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-24880 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-24880 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-24880 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-25854 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-25854 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-25854 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-29129 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-29129 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-29129 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-29145 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-29145 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-29145 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-29146 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-29146 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-29146 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-32990 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34483 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34483 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34483 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34486 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34486 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34486 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34487 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34487 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34487 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34500 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34500 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34500 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for tomcat11 fixes the following issues: * Update to Tomcat 11.0.21 * CVE-2026-24880: Request smuggling via invalid chunk extension (bsc#1261850). * CVE-2026-25854: Occasionally open redirect (bsc#1261851). * CVE-2026-29129: TLS cipher order is not preserved (bsc#1261852). * CVE-2026-29145: OCSP checks sometimes soft-fail even when soft-fail is disabled (bsc#1261853). * CVE-2026-29146,CVE-2026-34486: Fix for allowed bypass of EncryptInterceptor (bsc#1261854). *CVE-2026-34483: Incomplete escaping of JSON access logs (bsc#1261855). * CVE-2026-34487: Cloud membership for clustering component exposed the Kubernetes bearer token (bsc#1261856). * CVE-2026-34500: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled (bsc#1261857). * CVE-2026-32990: The fix for CVE-2025-66614 was incomplete. (bsc#1258371) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-605=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-605=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * tomcat11-webapps-11.0.21-160000.1.1 * tomcat11-docs-webapp-11.0.21-160000.1.1 * tomcat11-embed-11.0.21-160000.1.1 * tomcat11-jsp-4_0-api-11.0.21-160000.1.1 * tomcat11-servlet-6_1-api-11.0.21-160000.1.1 * tomcat11-lib-11.0.21-160000.1.1 * tomcat11-doc-11.0.21-160000.1.1 * tomcat11-jsvc-11.0.21-160000.1.1 * tomcat11-admin-webapps-11.0.21-160000.1.1 * tomcat11-el-6_0-api-11.0.21-160000.1.1 * tomcat11-11.0.21-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * tomcat11-webapps-11.0.21-160000.1.1 * tomcat11-docs-webapp-11.0.21-160000.1.1 * tomcat11-embed-11.0.21-160000.1.1 * tomcat11-jsp-4_0-api-11.0.21-160000.1.1 * tomcat11-servlet-6_1-api-11.0.21-160000.1.1 * tomcat11-lib-11.0.21-160000.1.1 * tomcat11-doc-11.0.21-160000.1.1 * tomcat11-jsvc-11.0.21-160000.1.1 * tomcat11-admin-webapps-11.0.21-160000.1.1 * tomcat11-el-6_0-api-11.0.21-160000.1.1 * tomcat11-11.0.21-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-66614.html * https://www.suse.com/security/cve/CVE-2026-24880.html * https://www.suse.com/security/cve/CVE-2026-25854.html *https://www.suse.com/security/cve/CVE-2026-29129.html * https://www.suse.com/security/cve/CVE-2026-29145.html * https://www.suse.com/security/cve/CVE-2026-29146.html * https://www.suse.com/security/cve/CVE-2026-32990.html * https://www.suse.com/security/cve/CVE-2026-34483.html * https://www.suse.com/security/cve/CVE-2026-34486.html * https://www.suse.com/security/cve/CVE-2026-34487.html * https://www.suse.com/security/cve/CVE-2026-34500.html * https://bugzilla.suse.com/show_bug.cgi?id=1258371 * https://bugzilla.suse.com/show_bug.cgi?id=1261850 * https://bugzilla.suse.com/show_bug.cgi?id=1261851 * https://bugzilla.suse.com/show_bug.cgi?id=1261852 * https://bugzilla.suse.com/show_bug.cgi?id=1261853 * https://bugzilla.suse.com/show_bug.cgi?id=1261854 * https://bugzilla.suse.com/show_bug.cgi?id=1261855 * https://bugzilla.suse.com/show_bug.cgi?id=1261856 * https://bugzilla.suse.com/show_bug.cgi?id=1261857 . SUSE security update for tomcat11 resolves important issues including request smuggling and TLS cipher order.. SUSE tomcat11 update important vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves 11 vulnerabilities can now be installed.. # Security update for tomcat11 Announcement ID: SUSE-SU-2026:1558-1 Release Date: 2026-04-22T16:24:40Z Rating: important References: * bsc#1258371 * bsc#1261850 * bsc#1261851 * bsc#1261852 * bsc#1261853 * bsc#1261854 * bsc#1261855 * bsc#1261856 * bsc#1261857 Cross-References: * CVE-2025-66614 * CVE-2026-24880 * CVE-2026-25854 * CVE-2026-29129 * CVE-2026-29145 * CVE-2026-29146 * CVE-2026-32990 * CVE-2026-34483 * CVE-2026-34486 * CVE-2026-34487 * CVE-2026-34500 CVSS scores: * CVE-2025-66614 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-66614 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-66614 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L * CVE-2025-66614 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-24880 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-24880 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-24880 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-25854 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-25854 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-25854 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-29129 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-29129 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-29129 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-29145 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-29145 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-29145 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-29146 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-29146 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-29146 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-32990 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34483 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34483 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34483 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34486 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34486 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34486 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34487 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34487 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34487 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34500 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34500 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34500 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for tomcat11 fixes the following issues: Security fixes: * CVE-2026-24880: Request smuggling via invalid chunk extension (bsc#1261850). * CVE-2026-25854: Occasionally open redirect (bsc#1261851). * CVE-2026-29129: TLS cipher order is not preserved (bsc#1261852). *CVE-2026-29145: OCSP checks sometimes soft-fail even when soft-fail is disabled (bsc#1261853). * CVE-2026-29146,CVE-2026-34486: Fix for allowed bypass of EncryptInterceptor (bsc#1261854). * CVE-2026-34483: Incomplete escaping of JSON access logs (bsc#1261855). * CVE-2026-34487: Cloud membership for clustering component exposed the Kubernetes bearer token (bsc#1261856). * CVE-2026-34500: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled (bsc#1261857). * CVE-2026-32990: The fix for CVE-2025-66614 was incomplete, so this CVE completes it (bsc#1258371). Other fixes: * Update to Tomcat 11.0.21 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1558=1 * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-1558=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1558=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1558=1 ## Package List: * openSUSE Leap 15.6 (noarch) * tomcat11-jsp-4_0-api-11.0.21-150600.13.18.1 * tomcat11-webapps-11.0.21-150600.13.18.1 * tomcat11-embed-11.0.21-150600.13.18.1 * tomcat11-jsvc-11.0.21-150600.13.18.1 * tomcat11-lib-11.0.21-150600.13.18.1 * tomcat11-doc-11.0.21-150600.13.18.1 * tomcat11-11.0.21-150600.13.18.1 * tomcat11-docs-webapp-11.0.21-150600.13.18.1 * tomcat11-admin-webapps-11.0.21-150600.13.18.1 * tomcat11-el-6_0-api-11.0.21-150600.13.18.1 * tomcat11-servlet-6_1-api-11.0.21-150600.13.18.1 * Web and Scripting Module 15-SP7 (noarch) * tomcat11-jsp-4_0-api-11.0.21-150600.13.18.1 * tomcat11-webapps-11.0.21-150600.13.18.1 * tomcat11-lib-11.0.21-150600.13.18.1 *tomcat11-11.0.21-150600.13.18.1 * tomcat11-admin-webapps-11.0.21-150600.13.18.1 * tomcat11-el-6_0-api-11.0.21-150600.13.18.1 * tomcat11-servlet-6_1-api-11.0.21-150600.13.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * tomcat11-jsp-4_0-api-11.0.21-150600.13.18.1 * tomcat11-webapps-11.0.21-150600.13.18.1 * tomcat11-lib-11.0.21-150600.13.18.1 * tomcat11-11.0.21-150600.13.18.1 * tomcat11-admin-webapps-11.0.21-150600.13.18.1 * tomcat11-el-6_0-api-11.0.21-150600.13.18.1 * tomcat11-servlet-6_1-api-11.0.21-150600.13.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * tomcat11-jsp-4_0-api-11.0.21-150600.13.18.1 * tomcat11-webapps-11.0.21-150600.13.18.1 * tomcat11-lib-11.0.21-150600.13.18.1 * tomcat11-11.0.21-150600.13.18.1 * tomcat11-admin-webapps-11.0.21-150600.13.18.1 * tomcat11-el-6_0-api-11.0.21-150600.13.18.1 * tomcat11-servlet-6_1-api-11.0.21-150600.13.18.1 ## References: * https://www.suse.com/security/cve/CVE-2025-66614.html * https://www.suse.com/security/cve/CVE-2026-24880.html * https://www.suse.com/security/cve/CVE-2026-25854.html * https://www.suse.com/security/cve/CVE-2026-29129.html * https://www.suse.com/security/cve/CVE-2026-29145.html * https://www.suse.com/security/cve/CVE-2026-29146.html * https://www.suse.com/security/cve/CVE-2026-32990.html * https://www.suse.com/security/cve/CVE-2026-34483.html * https://www.suse.com/security/cve/CVE-2026-34486.html * https://www.suse.com/security/cve/CVE-2026-34487.html * https://www.suse.com/security/cve/CVE-2026-34500.html * https://bugzilla.suse.com/show_bug.cgi?id=1258371 * https://bugzilla.suse.com/show_bug.cgi?id=1261850 * https://bugzilla.suse.com/show_bug.cgi?id=1261851 * https://bugzilla.suse.com/show_bug.cgi?id=1261852 * https://bugzilla.suse.com/show_bug.cgi?id=1261853 * https://bugzilla.suse.com/show_bug.cgi?id=1261854 * https://bugzilla.suse.com/show_bug.cgi?id=1261855 *https://bugzilla.suse.com/show_bug.cgi?id=1261856 * https://bugzilla.suse.com/show_bug.cgi?id=1261857 . SUSE has released an important advisory addressing 11 vulnerabilities in tomcat11, ensuring better security.. SUSE Linux, security update, tomcat11 vulnerabilities, important update, web application security. . Severity: Important. LinuxSecurity.com Team
Update uv and python-uv-build to 0.11.2. Version 0.11 includes changes to the networking stack used by uv. While its developers think that breakage will be rare, it is possible that these changes will result in the rejection of certificates previously trusted by uv so, they have marked the change as breaking out of an abundance of caution. The changes are largely driven by the. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b8b59dcf44 2026-03-28 00:15:26.019955+00:00 -------------------------------------------------------------------------------- Name : rust-reqsign-azure-storage Product : Fedora 44 Version : 3.0.0 Release : 1.fc44 URL : https://crates.io/crates/reqsign-azure-storage Summary : Azure Storage signing implementation for reqsign Description : Azure Storage signing implementation for reqsign. -------------------------------------------------------------------------------- Update Information: Update uv and python-uv-build to 0.11.2. Version 0.11 includes changes to the networking stack used by uv. While its developers think that breakage will be rare, it is possible that these changes will result in the rejection of certificates previously trusted by uv so, they have marked the change as breaking out of an abundance of caution. The changes are largely driven by the upgrade of reqwest, which powers uv's HTTP clients, to v0.13, which included some breaking changes to TLS certificate verification. This update also includes updates for several of uv\u2019s Rust library dependencies. Update rust-openssl-probe to 0.2.1, including breaking changes introduced in 0.2.0, and introduce a new rust-openssl-probe0.1 compat package. Update rust-rustls-native-certs to 0.8.3, now using openssl-probe 0.2. Update rust-native-tls to 0.2.18. Version 0.2.16 added TLS 1.3 as an option, added stack_from_pem, and upgraded openssl-probe to 0.2. Version 0.2.17 added support for ALPN on the server side. Version 0.2.18fixed min/max protocol selection fallback for very old OpenSSL versions. Add an initial package for rust-webpki-root-certs. -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 24 2026 Benjamin A. Beasley - 3.0.0-1 - Update to version 3.0.0; Fixes RHBZ#2432771 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2425802 - rust-openssl-probe-0.2.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2425802 [ 2 ] Bug #2425819 - rust-rustls-native-certs-0.8.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2425819 [ 3 ] Bug #2432768 - rust-reqsign-aliyun-oss-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432768 [ 4 ] Bug #2432769 - rust-reqsign-core-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432769 [ 5 ] Bug #2432770 - rust-reqsign-0.20.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432770 [ 6 ] Bug #2432771 - rust-reqsign-azure-storage-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432771 [ 7 ] Bug #2432772 - rust-reqsign-http-send-reqwest-4.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432772 [ 8 ] Bug #2432773 - rust-reqsign-google-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432773 [ 9 ] Bug #2432774 - rust-reqsign-file-read-tokio-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432774 [ 10 ] Bug #2432775 - rust-reqsign-command-execute-tokio-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432775 [ 11 ] Bug #2432776 - rust-reqsign-aws-v4-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432776 [ 12 ] Bug #2432777 - rust-reqsign-huaweicloud-obs-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432777 [ 13 ] Bug #2432779 - rust-reqsign-tencent-cos-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432779 [ 14 ] Bug #2436289 - rust-ambient-id-0.0.11 is available https://bugzilla.redhat.com/show_bug.cgi?id=2436289 [ 15 ] Bug #2437941 - rust-astral-reqwest-middleware-0.5.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2437941 [ 16 ] Bug #2437942 - rust-astral-reqwest-retry-0.9.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2437942 [ 17 ] Bug #2437976 - rust-astral_async_http_range_reader-0.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2437976 [ 18 ] Bug #2439752 - rust-native-tls-0.2.18 is available https://bugzilla.redhat.com/show_bug.cgi?id=2439752 [ 19 ] Bug #2450541 - python-uv-build-0.11.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2450541 [ 20 ] Bug #2450582 - uv-0.11.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2450582 [ 21 ] Bug #2451103 - Review Request: rust-webpki-root-certs - Mozilla trusted certificate authorities in self-signed X.509 format https://bugzilla.redhat.com/show_bug.cgi?id=2451103 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b8b59dcf44' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update for rust-reqsign-azure-storage in Fedora 44 addressing breaking changes to TLS certificates and networking stack.. rust-reqsign-azure-storage,tls update,networking change,security advisory. . Severity: Important. LinuxSecurity.com Team
* bsc#1248672 * bsc#1249537 Cross-References: * CVE-2025-38500 . # Security update for kernel-livepatch-MICRO-6-0-RT_Update_8 Announcement ID: SUSE-SU-2025:21090-1 Release Date: 2025-11-28T08:19:29Z Rating: important References: * bsc#1248672 * bsc#1249537 Cross-References: * CVE-2025-38500 * CVE-2025-38616 CVSS scores: * CVE-2025-38500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38616 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2025-38616 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_8 fixes the following issues: * CVE-2025-38500: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (bsc#1248672) * CVE-2025-38616: tls: handle data disappearing from under the TLS ULP (bsc#1249537) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-213=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_8-debugsource-9-1.2 * kernel-livepatch-6_4_0-31-rt-debuginfo-9-1.2 * kernel-livepatch-6_4_0-31-rt-9-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-38500.html * https://www.suse.com/security/cve/CVE-2025-38616.html * https://bugzilla.suse.com/show_bug.cgi?id=1248672 * https://bugzilla.suse.com/show_bug.cgi?id=1249537 . Kernel Livepatch 6.0 security update fixes TLS and xfrm vulnerabilities. Immediate patching is recommendedfor system integrity.. kernel update, SUSE Linux, livepatch security, TLS vulnerability, system patching. . Severity: Important. LinuxSecurity.com Team
* bsc#1248672 * bsc#1249537 Cross-References: * CVE-2025-38500 . # Security update for kernel-livepatch-MICRO-6-0-RT_Update_10 Announcement ID: SUSE-SU-2025:21099-1 Release Date: 2025-11-28T08:21:02Z Rating: important References: * bsc#1248672 * bsc#1249537 Cross-References: * CVE-2025-38500 * CVE-2025-38616 CVSS scores: * CVE-2025-38500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38616 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2025-38616 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_10 fixes the following issues: * CVE-2025-38500: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (bsc#1248672) * CVE-2025-38616: tls: handle data disappearing from under the TLS ULP (bsc#1249537) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-215=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-34-rt-8-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_10-debugsource-8-1.1 * kernel-livepatch-6_4_0-34-rt-debuginfo-8-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-38500.html * https://www.suse.com/security/cve/CVE-2025-38616.html * https://bugzilla.suse.com/show_bug.cgi?id=1248672 * https://bugzilla.suse.com/show_bug.cgi?id=1249537 . This security advisory addresses critical updates for SUSE Linux Micro 6.0 kernel-livepatch, coveringimportant vulnerabilities.. Linux Micro Security Fix, Kernel Module Update, SUSE Security Patch. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.