Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
SUSE has released a security update for python-tornado addressing three vulnerabilities that affect multiple SUSE Linux Enterprise products, prompting users to apply the update immediately.. # Security update for python-tornado Announcement ID: SUSE-SU-2026:3291-1 Release Date: 2026-07-27T15:15:54Z Rating: important References: * bsc#1268395 * bsc#1268396 * bsc#1268397 Cross-References: * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 CVSS scores: * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49853 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49854 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Desktop 12 * SUSE Linux Enterprise Desktop 12 SP1 * SUSE Linux Enterprise Desktop 12 SP2 * SUSE Linux Enterprise Desktop 12 SP3 * SUSE Linux Enterprise Desktop 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux EnterpriseServer for the Raspberry Pi 12-SP2 * SUSE Manager Client Tools for SLE 12 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-tornado fixes the following issues * CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395). * CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396). * CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (bsc#1268397). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Client Tools for SLE 12 zypper in -t patch SUSE-SLE-Manager-Tools-12-2026-3291=1 ## Package List: * SUSE Manager Client Tools for SLE 12 (aarch64 ppc64le s390x x86_64) * python-tornado-debugsource-4.2.1-17.21.1 * python-tornado-debuginfo-4.2.1-17.21.1 * python-tornado-4.2.1-17.21.1 * python3-tornado-4.2.1-17.21.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 . Three vulnerabilities in python-tornado have been addressed with this important SUSE security update. Install recommended.. python-tornado security,SUSE Linux Enterprise,security update,access control issues. . Severity: Important. LinuxSecurity.com Team
A security update for SUSE Linux Kernel RT addresses six vulnerabilities including race conditions and memory issues, enhancing system stability and security for affected products.. # Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3286-1 Release Date: 2026-07-27T14:33:45Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.40 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2-> cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3276=1 SUSE-SLE- Module-Live-Patching-15-SP7-2026-3277=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-3278=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-3286=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP7_Update_9-debugsource-9-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_13-debugsource-5-150700.2.1 * kernel-livepatch-6_4_0-150700_53_28-default-10-150700.2.1 * kernel-livepatch-6_4_0-150700_53_28-default-debuginfo-10-150700.2.1 *kernel-livepatch-6_4_0-150700_53_31-default-9-150700.2.1 * kernel-livepatch-6_4_0-150700_53_31-default-debuginfo-9-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_8-debugsource-10-150700.2.1 * kernel-livepatch-6_4_0-150700_53_45-default-5-150700.2.1 * kernel-livepatch-6_4_0-150700_53_45-default-debuginfo-5-150700.2.1 * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_40-rt-debuginfo-6-150700.2.1 * kernel-livepatch-6_4_0-150700_7_40-rt-6-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_12-debugsource-6-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 . SUSE's important security update addresses six kernel RT issues. Install recommended patches to protect your system.. SUSE security update,kernel vulnerabilities,system patches. . Severity: Important. LinuxSecurity.com Team
SUSE has released a security update addressing five vulnerabilities in the Linux kernel for multiple products, emphasizing the importance of installing the patch using recommended methods.. # Security update for the Linux Kernel (Live Patch 29 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:3289-1 Release Date: 2026-07-27T15:36:28Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE LinuxEnterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.116 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2-> cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3289=1 SUSE-SLE- Module-Live-Patching-15-SP5-2026-3295=1 SUSE-SLE-Module-Live- Patching-15-SP5-2026-3293=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3287=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3292=1 SUSE-SLE-Module-Live- Patching-15-SP5-2026-3296=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3294=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3280=1 SUSE-SLE-Module-Live- Patching-15-SP5-2026-3279=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3288=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3290=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3289=1 SUSE-2026-3295=1 SUSE-2026-3293=1 SUSE-2026-3287=1 SUSE-2026-3292=1 SUSE-2026-3296=1 SUSE-2026-3294=1 SUSE-2026-3280=1 SUSE-2026-3279=1 SUSE-2026-3288=1 SUSE-2026-3290=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) *kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_33-debugsource-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_28-debugsource-21-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_34-debugsource-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_29-debugsource-19-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_163-default-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_37-debugsource-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-22-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_30-debugsource-16-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_31-debugsource-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_127-default-debuginfo-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_36-debugsource-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_127-default-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_27-debugsource-22-150500.2.1 * kernel-livepatch-5_14_21-150500_55_141-default-debuginfo-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-19-150500.2.1 * kernel-livepatch-5_14_21-150500_55_141-default-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_113-default-21-150500.2.1 * kernel-livepatch-5_14_21-150500_55_144-default-debuginfo-7-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_32-debugsource-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_144-default-7-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_39-debugsource-5-150500.2.1 *kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-22-150500.2.1 * kernel-livepatch-5_14_21-150500_55_116-default-19-150500.2.1 * kernel-livepatch-5_14_21-150500_55_113-default-debuginfo-21-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-11-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_33-debugsource-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_28-debugsource-21-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_34-debugsource-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_163-default-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_37-debugsource-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-22-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_30-debugsource-16-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_31-debugsource-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_127-default-debuginfo-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_36-debugsource-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_127-default-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_27-debugsource-22-150500.2.1 * kernel-livepatch-5_14_21-150500_55_141-default-debuginfo-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-19-150500.2.1 * kernel-livepatch-5_14_21-150500_55_141-default-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_113-default-21-150500.2.1 *kernel-livepatch-5_14_21-150500_55_144-default-debuginfo-7-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_32-debugsource-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_144-default-7-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_39-debugsource-5-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-22-150500.2.1 * kernel-livepatch-5_14_21-150500_55_116-default-19-150500.2.1 * kernel-livepatch-5_14_21-150500_55_113-default-debuginfo-21-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-11-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x) * kernel-livepatch-SLE15-SP5_Update_29-debugsource-19-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 . This security advisory highlights important updates for the openSUSE kernel, addressing five vulnerabilities. Follow installation instructions.. openSUSE security kernel update patches vulnerabilities. . Severity: Important. LinuxSecurity.com Team
SUSE released a critical security update for Linux Kernel Live Patch 29 addressing five vulnerabilities affecting various SUSE Linux Enterprise products, recommending installation via zypper or YaST.. # Security update for the Linux Kernel (Live Patch 29 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:3289-1 Release Date: 2026-07-27T15:36:28Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 *SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.116 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2-> cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3289=1 SUSE-SLE- Module-Live-Patching-15-SP5-2026-3295=1 SUSE-SLE-Module-Live- Patching-15-SP5-2026-3293=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3287=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3292=1 SUSE-SLE-Module-Live- Patching-15-SP5-2026-3296=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3294=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3280=1 SUSE-SLE-Module-Live- Patching-15-SP5-2026-3279=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3288=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3290=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3289=1 SUSE-2026-3295=1 SUSE-2026-3293=1 SUSE-2026-3287=1 SUSE-2026-3292=1 SUSE-2026-3296=1 SUSE-2026-3294=1 SUSE-2026-3280=1 SUSE-2026-3279=1 SUSE-2026-3288=1 SUSE-2026-3290=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) *kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_33-debugsource-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_28-debugsource-21-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_34-debugsource-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_29-debugsource-19-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_163-default-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_37-debugsource-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-22-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_30-debugsource-16-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_31-debugsource-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_127-default-debuginfo-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_36-debugsource-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_127-default-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_27-debugsource-22-150500.2.1 * kernel-livepatch-5_14_21-150500_55_141-default-debuginfo-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-19-150500.2.1 * kernel-livepatch-5_14_21-150500_55_141-default-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_113-default-21-150500.2.1 * kernel-livepatch-5_14_21-150500_55_144-default-debuginfo-7-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_32-debugsource-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_144-default-7-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_39-debugsource-5-150500.2.1 *kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-22-150500.2.1 * kernel-livepatch-5_14_21-150500_55_116-default-19-150500.2.1 * kernel-livepatch-5_14_21-150500_55_113-default-debuginfo-21-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-11-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_33-debugsource-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_28-debugsource-21-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_34-debugsource-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_163-default-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_37-debugsource-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-22-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_30-debugsource-16-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_31-debugsource-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_127-default-debuginfo-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_36-debugsource-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_127-default-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_27-debugsource-22-150500.2.1 * kernel-livepatch-5_14_21-150500_55_141-default-debuginfo-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-14-150500.2.1 * kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-19-150500.2.1 * kernel-livepatch-5_14_21-150500_55_141-default-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_113-default-21-150500.2.1 *kernel-livepatch-5_14_21-150500_55_144-default-debuginfo-7-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_32-debugsource-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_144-default-7-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_39-debugsource-5-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-22-150500.2.1 * kernel-livepatch-5_14_21-150500_55_116-default-19-150500.2.1 * kernel-livepatch-5_14_21-150500_55_113-default-debuginfo-21-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-11-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x) * kernel-livepatch-SLE15-SP5_Update_29-debugsource-19-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 . This important security update for SUSE's kernel addresses five vulnerabilities to enhance system safety.. SUSE Kernel Patch, System Security Patch, Live Patching, Vulnerability Resolution. . Severity: Important. LinuxSecurity.com Team
A security update for SUSE Linux Micro 6.0 addresses 13 vulnerabilities in afterburn, enhancing security with fixes for issues related to openssl, regex, and others.. # Security update for afterburn Announcement ID: SUSE-SU-2026:22917-1 Release Date: 2026-07-23T11:05:19Z Rating: important References: * bsc#1196972 * bsc#1242665 * bsc#1243850 * bsc#1244199 * bsc#1270175 * bsc#1270483 * bsc#1270555 * bsc#1270651 * bsc#1270787 * bsc#1270817 * bsc#1270886 * bsc#1270949 * bsc#1271348 Cross-References: * CVE-2022-24713 * CVE-2024-12224 * CVE-2025-3416 * CVE-2025-5791 * CVE-2026-25541 * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2022-24713 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2022-24713 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-12224 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-12224 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-12224 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-3416 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-3416 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-3416 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-5791 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-5791 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2025-5791 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25541 ( NVD ): 5.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45784 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.0 An update that solves 13 vulnerabilities can now be installed. ## Description: Thisupdate for afterburn fixes the following issues Update to version 5.10.0.git73.b97f772. Security issues fixed: * CVE-2022-24713: regex: high complexity when parsing regexes with large repetitions on empty sub-expressions can lead to DoS (bsc#1196972). * CVE-2024-12224: idna: privilege escalation due acceptance Punycode labels that do not produce any non-ASCII when decoded (bsc#1243850). * CVE-2025-3416: openssl: use-after-free in `Md::fetch` and `Cipher::fetch` (bsc#1242665). * CVE-2025-5791: users: `root` appended to group listings unless the correct listing has exactly 1024 groups (bsc#1244199). * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270175). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270555). * CVE-2026-41678: openssl: incorrect bounds assertion in `aes::unwrap_key()` can lead to OOB write (bsc#1270651). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270787). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to network peers (bsc#1270817). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270483). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding (bsc#1270886). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers (bsc#1270949). * CVE-2026-25541: bytes: integer overflow in `BytesMut:reserve` can lead to undefined behavior and crashes (bsc#1271348). Other updates and bugfixes: * Version 5.10.0.git73.b97f772: * build(deps): bump anyhow from 1.0.99 to 1.0.103 https://github.com/coreos/afterburn/pull/1284 * build(deps): bump libflate from 2.1.0 to 2.2.2 https://github.com/coreos/afterburn/pull/1283 * build(deps): bump openssl from 0.10.79 to 0.10.80 https://github.com/coreos/afterburn/pull/1277 * Version 5.10.0.git70.9cc2a7b: * build(deps): bump openssl from 0.10.78 to 0.10.79 * providers/hetzner: Add the HETZNER_PUBLIC_IPV6 attribute * providers/hetzner: Add support for network configuration * build(deps): bump rustls-webpki from 0.103.10 to 0.103.13 * build(deps): bump openssl from 0.10.73 to 0.10.78 * docs: Add AGENTS.md and CLAUDE.md for AI coding assistants * build(deps): bump rand from 0.9.2 to 0.9.4 * opencode: add skills for provider scaffolding and release automation * ibmcloud-classic: Add missing network_id to fixture * kubevirt: Support static gateway and DNS with DHCP * build(deps): bump rustls-webpki from 0.103.6 to 0.103.10 * fix(proxmoxve): Define DNS entries for every interface * Makefile: download `90-afterburn-authorized-keys-file.conf` for rpm building * Sync repo templates ⚙ * build(deps): bump bytes from 1.10.1 to 1.11.1 * util/dhcp: Fix clippy lints * build(deps): bump actions/checkout from 4 to 6 * build(deps): bump actions/upload-artifact from 4 to 5 * kubevirt: modprobe for virtio_blk; remove dracut preload * kubevirt: Add NoCloud network configuration support * kubevirt: Support config drive network data * kubevirt: Refactor the provider to follow the proxmoxve structure * dracut: Add virtio_blk module preload to afterburn-network-kargs service * docs: Add release notes * cargo: Afterburn release 5.10.0 * Version 5.10.0: * docs/release-notes: update for release 5.10.0 * cargo: update dependencies * microsoft/azure: Add XML attribute alias for serde-xml-rs Fedora compat * docs/release-notes: Add entry for Azure SharedConfig XML parsing fix * microsoft/azure: Fix SharedConfig parsing of XML attributes * microsoft/azure: Mock goalstate.SharedConfig output in tests * providers/azure: switch SSH key retrieval from certs endpoint to IMDS * build(deps): bump thebuild group with 8 updates * build(deps): bump slab from 0.4.10 to 0.4.11 * build(deps): bump actions/checkout from 4 to 5 * upcloud: implement UpCloud provider * build(deps): bump the build group with 4 updates ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-807=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 x86_64) * afterburn-debuginfo-5.10.0.git73.b97f772-1.1 * afterburn-5.10.0.git73.b97f772-1.1 * afterburn-debugsource-5.10.0.git73.b97f772-1.1 * SUSE Linux Micro 6.0 (noarch) * afterburn-dracut-5.10.0.git73.b97f772-1.1 ## References: * https://www.suse.com/security/cve/CVE-2022-24713.html * https://www.suse.com/security/cve/CVE-2024-12224.html * https://www.suse.com/security/cve/CVE-2025-3416.html * https://www.suse.com/security/cve/CVE-2025-5791.html * https://www.suse.com/security/cve/CVE-2026-25541.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1196972 * https://bugzilla.suse.com/show_bug.cgi?id=1242665 * https://bugzilla.suse.com/show_bug.cgi?id=1243850 * https://bugzilla.suse.com/show_bug.cgi?id=1244199 * https://bugzilla.suse.com/show_bug.cgi?id=1270175 * https://bugzilla.suse.com/show_bug.cgi?id=1270483 * https://bugzilla.suse.com/show_bug.cgi?id=1270555 * https://bugzilla.suse.com/show_bug.cgi?id=1270651 * https://bugzilla.suse.com/show_bug.cgi?id=1270787 * https://bugzilla.suse.com/show_bug.cgi?id=1270817 * https://bugzilla.suse.com/show_bug.cgi?id=1270886 * https://bugzilla.suse.com/show_bug.cgi?id=1270949 * https://bugzilla.suse.com/show_bug.cgi?id=1271348 . SUSE issued an important security update for Afterburn addressing 13 vulnerabilities and enhancing system security.. SUSE Linux Afterburn Update Security Patch Vulnerability. . Severity: Important. LinuxSecurity.com Team
A recent security update for gzip addresses vulnerability CVE-2026-41991, impacting SUSE Linux Micro 6.0, particularly regarding insecure temporary file handling when the mktemp utility is unavailable.. # Security update for gzip Announcement ID: SUSE-SU-2026:22918-1 Release Date: 2026-07-23T11:09:05Z Rating: important References: * bsc#1269622 Cross-References: * CVE-2026-41991 CVSS scores: * CVE-2026-41991 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41991 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41991 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41991 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for gzip fixes the following issue * CVE-2026-41991: insecure temporary file handling in the `gzexe` utility when the `mktemp` utility is not available in a user's `PATH` (bsc#1269622). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-808=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * gzip-debuginfo-1.13-2.1 * gzip-debugsource-1.13-2.1 * gzip-1.13-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41991.html * https://bugzilla.suse.com/show_bug.cgi?id=1269622 . SUSE updates gzip to fix an important security issue related to insecure temporary file handling.. SUSE security update, gzip issues, temporary file handling. . Severity: Important. LinuxSecurity.com Team
SUSE released a security update for libgcrypt addressing CVE-2026-41989, a heap-based buffer overflow vulnerability in SUSE Linux Micro 6.0, potentially leading to denial of service.. # Security update for libgcrypt Announcement ID: SUSE-SU-2026:22919-1 Release Date: 2026-07-24T08:12:11Z Rating: moderate References: * bsc#1262684 Cross-References: * CVE-2026-41989 CVSS scores: * CVE-2026-41989 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41989 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-41989 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for libgcrypt fixes the following issue * CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-811=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libgcrypt-debugsource-1.10.3-4.1 * libgcrypt20-debuginfo-1.10.3-4.1 * libgcrypt20-1.10.3-4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41989.html * https://bugzilla.suse.com/show_bug.cgi?id=1262684 . Install the latest security update for libgcrypt on SUSE to address a buffer overflow issue affecting system stability.. security update, SUSE libgcrypt, buffer overflow. . Severity: Medium. LinuxSecurity.com Team
A security update for libsoup resolves two vulnerabilities in SUSE Linux Micro 6.0, including an incomplete fix for an out-of-bounds read issue in WebSocket connections.. # Security update for libsoup Announcement ID: SUSE-SU-2026:22920-1 Release Date: 2026-07-24T08:15:09Z Rating: moderate References: * bsc#1271401 Cross-References: * CVE-2026-0716 * CVE-2026-12478 CVSS scores: * CVE-2026-0716 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-0716 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-0716 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12478 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12478 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12478 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for libsoup fixes the following issues: * Incomplete fix for CVE-2026-12478: out-of-bounds read in the `process_frame()` function of `SoupWebSocketConnection` (bsc#1271401). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-812=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libsoup-3_0-0-debuginfo-3.4.2-17.1 * libsoup-debugsource-3.4.2-17.1 * libsoup-3_0-0-3.4.2-17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-0716.html * https://www.suse.com/security/cve/CVE-2026-12478.html * https://bugzilla.suse.com/show_bug.cgi?id=1271401 . SUSE releases a security update for libsoup addressing two vulnerabilities that impact system integrity and confidentiality.. libsoupupdate,SUSE vulnerabilities,security advisory,moderate threat. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.