It was discovered that incorrect memory management in the ffmpeg plugin for GStreamer could result in heap memory corruption. For the stable distribution (trixie), this problem has been fixed in version 1.26.2-1+deb13u1. We recommend that you upgrade your gst-libav1.0 packages.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6353-1
An update that solves one vulnerability can now be installed.. # Security update for ldns Announcement ID: SUSE-SU-2026:2461-1 Release Date: 2026-06-19T07:38:26Z Rating: important References: * bsc#1267670 Cross-References: * CVE-2026-10846 CVSS scores: * CVE-2026-10846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-10846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-10846 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10846 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for ldns fixes the following issue * CVE-2026-10846: When ldns is used by applications for (stub) resolving, it does not sufficiently verify that received responses belong to a sent query (bsc#1267670). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypperin -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2461=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2461=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2461=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2461=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2461=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2461=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2461=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2461=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 *perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10846.html *https://bugzilla.suse.com/show_bug.cgi?id=1267670 . SUSE releases an important security update for ldns addressing critical issues and ensuring system safety. Updated now.. SUSE advisory ldns update security risk review CVE-2026-10846. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for ldns Announcement ID: SUSE-SU-2026:2462-1 Release Date: 2026-06-19T07:39:02Z Rating: important References: * bsc#1267670 Cross-References: * CVE-2026-10846 CVSS scores: * CVE-2026-10846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-10846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-10846 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10846 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for ldns fixes the following issue * CVE-2026-10846: When ldns is used by applications for (stub) resolving, it does not sufficiently verify that received responses belong to a sent query (bsc#1267670). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2462=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2462=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2462=1 * SUSE Package Hub15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2462=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2462=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2462=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * perl-DNS-LDNS-debuginfo-1.8.3-150600.3.3.1 * perl-DNS-LDNS-1.8.3-150600.3.3.1 * libldns3-1.8.3-150600.3.3.1 * python3-ldns-1.8.3-150600.3.3.1 * ldns-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * python3-ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-devel-1.8.3-150600.3.3.1 * libldns3-debuginfo-1.8.3-150600.3.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libldns3-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-devel-1.8.3-150600.3.3.1 * libldns3-debuginfo-1.8.3-150600.3.3.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-DNS-LDNS-debuginfo-1.8.3-150600.3.3.1 * perl-DNS-LDNS-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * ldns-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * perl-DNS-LDNS-debuginfo-1.8.3-150600.3.3.1 * perl-DNS-LDNS-1.8.3-150600.3.3.1 * libldns3-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-devel-1.8.3-150600.3.3.1 * libldns3-debuginfo-1.8.3-150600.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * perl-DNS-LDNS-debuginfo-1.8.3-150600.3.3.1 * perl-DNS-LDNS-1.8.3-150600.3.3.1 * libldns3-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-devel-1.8.3-150600.3.3.1 * libldns3-debuginfo-1.8.3-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10846.html * https://bugzilla.suse.com/show_bug.cgi?id=1267670 . # Security update for ldns Announcement ID: SUSE-SU-2026:2462-1 Release Date: 2026-06-19T07:39:02Z R. update, solves, vulnerability, installed, security, announcemen. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for ldns Announcement ID: SUSE-SU-2026:2462-1 Release Date: 2026-06-19T07:39:02Z Rating: important References: * bsc#1267670 Cross-References: * CVE-2026-10846 CVSS scores: * CVE-2026-10846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-10846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-10846 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10846 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for ldns fixes the following issue * CVE-2026-10846: When ldns is used by applications for (stub) resolving, it does not sufficiently verify that received responses belong to a sent query (bsc#1267670). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2462=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2462=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2462=1 * SUSE Package Hub15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2462=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2462=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2462=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * perl-DNS-LDNS-debuginfo-1.8.3-150600.3.3.1 * perl-DNS-LDNS-1.8.3-150600.3.3.1 * libldns3-1.8.3-150600.3.3.1 * python3-ldns-1.8.3-150600.3.3.1 * ldns-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * python3-ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-devel-1.8.3-150600.3.3.1 * libldns3-debuginfo-1.8.3-150600.3.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libldns3-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-devel-1.8.3-150600.3.3.1 * libldns3-debuginfo-1.8.3-150600.3.3.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-DNS-LDNS-debuginfo-1.8.3-150600.3.3.1 * perl-DNS-LDNS-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * ldns-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * perl-DNS-LDNS-debuginfo-1.8.3-150600.3.3.1 * perl-DNS-LDNS-1.8.3-150600.3.3.1 * libldns3-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-devel-1.8.3-150600.3.3.1 * libldns3-debuginfo-1.8.3-150600.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * perl-DNS-LDNS-debuginfo-1.8.3-150600.3.3.1 * perl-DNS-LDNS-1.8.3-150600.3.3.1 * libldns3-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-devel-1.8.3-150600.3.3.1 * libldns3-debuginfo-1.8.3-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10846.html * https://bugzilla.suse.com/show_bug.cgi?id=1267670 . Critical security update for ldns on SUSE fixes response verification issues with significant risks. Update recommended.. SUSE Linux Update, ldns Security Patch, Important Security Advisory. . Severity: Important. LinuxSecurity.com Team
An update that solves 3 vulnerabilities can now be installed.. # tinyproxy-1.11.3-3.1 on GA media Announcement ID: openSUSE-SU-2026:11060-1 Rating: moderate Cross-References: * CVE-2026-54387 * CVE-2026-54388 * CVE-2026-55202 Affected Products: * openSUSE Tumbleweed An update that solves 3 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the tinyproxy-1.11.3-3.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * tinyproxy 1.11.3-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54387.html * https://www.suse.com/security/cve/CVE-2026-54388.html * https://www.suse.com/security/cve/CVE-2026-55202.html . This update for openSUSE Tumbleweed resolves three moderate vulnerabilities in tinyproxy, enhancing security.. openSUSE advisory,tinyproxy update,vulnerability fix,tinyproxy security,moderate vulnerabilities. . Severity: moderate. LinuxSecurity.com Team
An update that solves 14 vulnerabilities can now be installed.. # alloy-1.17.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:11053-1 Rating: moderate Cross-References: * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-33532 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39834 * CVE-2026-44740 * CVE-2026-45678 * CVE-2026-45682 * CVE-2026-45685 * CVE-2026-45686 * CVE-2026-46598 CVSS scores: * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-33532 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33532 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44740 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44740 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N *CVE-2026-45678 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45678 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45682 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45682 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45685 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45685 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45686 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45686 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 14 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the alloy-1.17.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * alloy 1.17.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-33532.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-44740.html * https://www.suse.com/security/cve/CVE-2026-45678.html * https://www.suse.com/security/cve/CVE-2026-45682.html * https://www.suse.com/security/cve/CVE-2026-45685.html * https://www.suse.com/security/cve/CVE-2026-45686.html * https://www.suse.com/security/cve/CVE-2026-46598.html . Update for alloy in openSUSE resolvesmultiple issues, enhancing security and stability. Install without delay for best protection.. openSUSE security advisory, alloy update, moderate threat level. . Severity: moderate. LinuxSecurity.com Team
An update that solves 2 vulnerabilities can now be installed.. # lemon-3.53.2-2.1 on GA media Announcement ID: openSUSE-SU-2026:11059-1 Rating: moderate Cross-References: * CVE-2026-11822 * CVE-2026-11824 CVSS scores: * CVE-2026-11822 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11824 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the lemon-3.53.2-2.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * lemon 3.53.2-2.1 * libsqlite3-0 3.53.2-2.1 * libsqlite3-0-32bit 3.53.2-2.1 * libsqlite3-0-x86-64-v3 3.53.2-2.1 * sqlite3 3.53.2-2.1 * sqlite3-devel 3.53.2-2.1 * sqlite3-doc 3.53.2-2.1 * sqlite3-tcl 3.53.2-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11822.html * https://www.suse.com/security/cve/CVE-2026-11824.html . An update has been released for openSUSE Tumbleweed addressing critical issues found in the lemon package.. opensuse update security lemon vulnerabilities. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # containerized-data-importer-1.65-api-1.65.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:11054-1 Rating: moderate Cross-References: * CVE-2024-3727 CVSS scores: * CVE-2024-3727 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the containerized-data-importer-1.65-api-1.65.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * containerized-data-importer-1.65-api 1.65.0-1.1 * containerized-data-importer-1.65-cloner 1.65.0-1.1 * containerized-data-importer-1.65-controller 1.65.0-1.1 * containerized-data-importer-1.65-importer 1.65.0-1.1 * containerized-data-importer-1.65-manifests 1.65.0-1.1 * containerized-data-importer-1.65-operator 1.65.0-1.1 * containerized-data-importer-1.65-uploadproxy 1.65.0-1.1 * containerized-data-importer-1.65-uploadserver 1.65.0-1.1 * obs-service-cdi-1.65_containers_meta 1.65.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-3727.html . An update for containerized-data-importer on openSUSE addresses a security threat; installation is recommended.. openSUSE security update, containerized-data-importer vulnerability, CVE-2024-3727 fix. . Severity: moderate. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.