Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
A security update for python-soupsieve addresses two vulnerabilities related to memory exhaustion and denial of service, impacting several SUSE Linux products.. # Security update for python-soupsieve Announcement ID: SUSE-SU-2026:3240-1 Release Date: 2026-07-24T13:05:20Z Rating: important References: * bsc#1256316 * bsc#1271187 * bsc#1271188 Cross-References: * CVE-2026-49476 * CVE-2026-49477 CVSS scores: * CVE-2026-49476 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49476 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49477 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49477 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for python-soupsieve fixes the following issues * CVE-2026-49476: Memory Exhaustion via Large Comma-Separated Selector Lists (bsc#1271187). * CVE-2026-49477: Regular Expression Denial of Service (ReDoS) via Selector Parser (bsc#1271188). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3240=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3240=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3240=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3240=1 ## Package List: * openSUSE Leap 15.6 (noarch) * python311-soupsieve-2.5-150600.3.3.1 * Python 3 Module 15-SP7 (noarch) * python311-soupsieve-2.5-150600.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python311-soupsieve-2.5-150600.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python311-soupsieve-2.5-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49476.html * https://www.suse.com/security/cve/CVE-2026-49477.html * https://bugzilla.suse.com/show_bug.cgi?id=1256316 * https://bugzilla.suse.com/show_bug.cgi?id=1271187 * https://bugzilla.suse.com/show_bug.cgi?id=1271188 . Security update for python-soupsieve addresses vulnerabilities including memory exhaustion and ReDoS in SUSE distributions.. Python Security,SUSE Updates,Security Fixes,Open Source Software. . Severity: Important. LinuxSecurity.com Team
A security update for gzip addressing CVE-2026-41991, involving insecure temporary file handling, is available for several SUSE Linux Enterprise products. Recommended installation methods are provided.. # Security update for gzip Announcement ID: SUSE-SU-2026:3241-1 Release Date: 2026-07-24T13:06:57Z Rating: important References: * bsc#1269622 Cross-References: * CVE-2026-41991 CVSS scores: * CVE-2026-41991 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41991 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41991 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41991 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gzip fixes the following issue: * CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3241=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3241=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) *gzip-debugsource-1.10-4.17.1 * gzip-debuginfo-1.10-4.17.1 * gzip-1.10-4.17.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * gzip-1.10-4.17.1 * gzip-debugsource-1.10-4.17.1 * gzip-debuginfo-1.10-4.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41991.html * https://bugzilla.suse.com/show_bug.cgi?id=1269622 . A security update for gzip addresses an important flaw in temporary file handling in SUSE Linux.. gzip security update, SUSE vulnerability, Linux patch, gzip insecure file handling, Linux update. . Severity: Important. LinuxSecurity.com Team
A security update has been released for gpg2 to address the vulnerability CVE-2026-57062, affecting several SUSE products, with recommended installation methods provided.. # Security update for gpg2 Announcement ID: SUSE-SU-2026:3243-1 Release Date: 2026-07-24T13:09:39Z Rating: low References: * bsc#1269279 Cross-References: * CVE-2026-57062 CVSS scores: * CVE-2026-57062 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-57062 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-57062 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for gpg2 fixes the following issue: * CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM (bsc#1269279). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3243=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3243=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * gpg2-debugsource-2.4.4-150600.3.18.1 * gpg2-tpm-debuginfo-2.4.4-150600.3.18.1 * gpg2-2.4.4-150600.3.18.1 * dirmngr-debuginfo-2.4.4-150600.3.18.1 * dirmngr-2.4.4-150600.3.18.1 * gpg2-debuginfo-2.4.4-150600.3.18.1 * gpg2-tpm-2.4.4-150600.3.18.1 * openSUSE Leap 15.6 (noarch) * gpg2-lang-2.4.4-150600.3.18.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * gpg2-debugsource-2.4.4-150600.3.18.1 *gpg2-2.4.4-150600.3.18.1 * dirmngr-debuginfo-2.4.4-150600.3.18.1 * dirmngr-2.4.4-150600.3.18.1 * gpg2-debuginfo-2.4.4-150600.3.18.1 * Basesystem Module 15-SP7 (noarch) * gpg2-lang-2.4.4-150600.3.18.1 ## References: * https://www.suse.com/security/cve/CVE-2026-57062.html * https://bugzilla.suse.com/show_bug.cgi?id=1269279 . # Security update for gpg2 Announcement ID: SUSE-SU-2026:3243-1 Release Date: 2026-07-24T13:09:39Z R. security, update, released, address, vulnerability, cve-2026-57062, affecting. . Severity: Low. LinuxSecurity.com Team
A security update for gpg2 addresses a vulnerability in CMS parsing, applicable to various SUSE and openSUSE products, with instructions for installing the patch.. # Security update for gpg2 Announcement ID: SUSE-SU-2026:3243-1 Release Date: 2026-07-24T13:09:39Z Rating: low References: * bsc#1269279 Cross-References: * CVE-2026-57062 CVSS scores: * CVE-2026-57062 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-57062 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-57062 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for gpg2 fixes the following issue: * CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM (bsc#1269279). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3243=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3243=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * gpg2-debugsource-2.4.4-150600.3.18.1 * gpg2-tpm-debuginfo-2.4.4-150600.3.18.1 * gpg2-2.4.4-150600.3.18.1 * dirmngr-debuginfo-2.4.4-150600.3.18.1 * dirmngr-2.4.4-150600.3.18.1 * gpg2-debuginfo-2.4.4-150600.3.18.1 * gpg2-tpm-2.4.4-150600.3.18.1 * openSUSE Leap 15.6 (noarch) * gpg2-lang-2.4.4-150600.3.18.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * gpg2-debugsource-2.4.4-150600.3.18.1 *gpg2-2.4.4-150600.3.18.1 * dirmngr-debuginfo-2.4.4-150600.3.18.1 * dirmngr-2.4.4-150600.3.18.1 * gpg2-debuginfo-2.4.4-150600.3.18.1 * Basesystem Module 15-SP7 (noarch) * gpg2-lang-2.4.4-150600.3.18.1 ## References: * https://www.suse.com/security/cve/CVE-2026-57062.html * https://bugzilla.suse.com/show_bug.cgi?id=1269279 . SUSE's security update for gpg2 addresses a low severity issue in CMS parsing. Install the patch to secure your systems.. SUSE gpg2 update low severity security patch. . Severity: Low. LinuxSecurity.com Team
A SUSE security update for systemd addresses CVE-2026-40226 and includes five additional security fixes, impacting various SUSE products and requiring a system reboot after installation.. # Security update for systemd Announcement ID: SUSE-SU-2026:3244-1 Release Date: 2026-07-24T13:11:41Z Rating: moderate References: * bsc#1261400 * bsc#1261982 * bsc#1261983 * bsc#1262305 * bsc#1267644 * bsc#1267647 Cross-References: * CVE-2026-40226 CVSS scores: * CVE-2026-40226 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-40226 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40226 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability and has five security fixes can now be installed. ## Description: This update for systemd fixes the following issues: Security issues fixed: * CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: * Fix soft reboot not restarting user services with default.target (bsc#1262305). * Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). * Import commit 429043ca9a (bsc#1261982 bsc#1261983). * Import commit 58e5d2e21e (bsc#1261982). * Import commit 4bd91117cc (bsc#1261983). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patchSUSE-SLE-Module-Basesystem-15-SP7-2026-3244=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3244=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3244=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libudev-mini1-debuginfo-254.27-150600.4.71.1 * systemd-sysvcompat-debuginfo-254.27-150600.4.71.2 * systemd-mini-254.27-150600.4.71.1 * systemd-network-254.27-150600.4.71.2 * systemd-testsuite-254.27-150600.4.71.2 * systemd-254.27-150600.4.71.2 * systemd-resolved-debuginfo-254.27-150600.4.71.2 * libsystemd0-debuginfo-254.27-150600.4.71.2 * systemd-doc-254.27-150600.4.71.2 * udev-254.27-150600.4.71.2 * systemd-journal-remote-debuginfo-254.27-150600.4.71.2 * systemd-networkd-254.27-150600.4.71.2 * udev-mini-debuginfo-254.27-150600.4.71.1 * libudev1-debuginfo-254.27-150600.4.71.2 * systemd-debugsource-254.27-150600.4.71.2 * systemd-homed-debuginfo-254.27-150600.4.71.2 * systemd-networkd-debuginfo-254.27-150600.4.71.2 * systemd-mini-debuginfo-254.27-150600.4.71.1 * systemd-mini-container-debuginfo-254.27-150600.4.71.1 * libsystemd0-254.27-150600.4.71.2 * udev-mini-254.27-150600.4.71.1 * libudev1-254.27-150600.4.71.2 * systemd-experimental-debuginfo-254.27-150600.4.71.2 * systemd-mini-devel-254.27-150600.4.71.1 * libudev-mini1-254.27-150600.4.71.1 * systemd-debuginfo-254.27-150600.4.71.2 * libsystemd0-mini-debuginfo-254.27-150600.4.71.1 * systemd-coredump-debuginfo-254.27-150600.4.71.2 * systemd-testsuite-debuginfo-254.27-150600.4.71.2 * systemd-container-254.27-150600.4.71.2 * systemd-experimental-254.27-150600.4.71.2 * systemd-portable-debuginfo-254.27-150600.4.71.2 * libsystemd0-mini-254.27-150600.4.71.1 * systemd-portable-254.27-150600.4.71.2 * systemd-mini-debugsource-254.27-150600.4.71.1 * systemd-journal-remote-254.27-150600.4.71.2 *systemd-coredump-254.27-150600.4.71.2 * systemd-mini-container-254.27-150600.4.71.1 * systemd-resolved-254.27-150600.4.71.2 * systemd-container-debuginfo-254.27-150600.4.71.2 * systemd-homed-254.27-150600.4.71.2 * udev-debuginfo-254.27-150600.4.71.2 * systemd-devel-254.27-150600.4.71.2 * systemd-sysvcompat-254.27-150600.4.71.2 * openSUSE Leap 15.6 (x86_64) * libudev1-32bit-254.27-150600.4.71.2 * libsystemd0-32bit-debuginfo-254.27-150600.4.71.2 * libudev1-32bit-debuginfo-254.27-150600.4.71.2 * libsystemd0-32bit-254.27-150600.4.71.2 * systemd-32bit-254.27-150600.4.71.2 * systemd-devel-32bit-254.27-150600.4.71.2 * systemd-32bit-debuginfo-254.27-150600.4.71.2 * openSUSE Leap 15.6 (aarch64_ilp32) * libudev1-64bit-254.27-150600.4.71.2 * systemd-64bit-debuginfo-254.27-150600.4.71.2 * libsystemd0-64bit-debuginfo-254.27-150600.4.71.2 * systemd-devel-64bit-254.27-150600.4.71.2 * libsystemd0-64bit-254.27-150600.4.71.2 * libudev1-64bit-debuginfo-254.27-150600.4.71.2 * systemd-64bit-254.27-150600.4.71.2 * openSUSE Leap 15.6 (aarch64 i586 x86_64) * systemd-boot-254.27-150600.4.71.2 * systemd-boot-debuginfo-254.27-150600.4.71.2 * openSUSE Leap 15.6 (noarch) * systemd-lang-254.27-150600.4.71.2 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * systemd-sysvcompat-debuginfo-254.27-150600.4.71.2 * systemd-doc-254.27-150600.4.71.2 * libsystemd0-debuginfo-254.27-150600.4.71.2 * systemd-resolved-debuginfo-254.27-150600.4.71.2 * systemd-254.27-150600.4.71.2 * udev-254.27-150600.4.71.2 * systemd-journal-remote-debuginfo-254.27-150600.4.71.2 * libudev1-debuginfo-254.27-150600.4.71.2 * systemd-debugsource-254.27-150600.4.71.2 * libsystemd0-254.27-150600.4.71.2 * libudev1-254.27-150600.4.71.2 * systemd-debuginfo-254.27-150600.4.71.2 * systemd-coredump-debuginfo-254.27-150600.4.71.2 * systemd-container-254.27-150600.4.71.2 *systemd-journal-remote-254.27-150600.4.71.2 * systemd-coredump-254.27-150600.4.71.2 * systemd-resolved-254.27-150600.4.71.2 * systemd-container-debuginfo-254.27-150600.4.71.2 * udev-debuginfo-254.27-150600.4.71.2 * systemd-devel-254.27-150600.4.71.2 * systemd-sysvcompat-254.27-150600.4.71.2 * Basesystem Module 15-SP7 (noarch) * systemd-lang-254.27-150600.4.71.2 * Basesystem Module 15-SP7 (x86_64) * libudev1-32bit-254.27-150600.4.71.2 * libsystemd0-32bit-debuginfo-254.27-150600.4.71.2 * libudev1-32bit-debuginfo-254.27-150600.4.71.2 * libsystemd0-32bit-254.27-150600.4.71.2 * systemd-32bit-254.27-150600.4.71.2 * systemd-32bit-debuginfo-254.27-150600.4.71.2 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * systemd-debugsource-254.27-150600.4.71.2 * systemd-debuginfo-254.27-150600.4.71.2 * systemd-network-254.27-150600.4.71.2 * systemd-networkd-debuginfo-254.27-150600.4.71.2 * systemd-networkd-254.27-150600.4.71.2 ## References: * https://www.suse.com/security/cve/CVE-2026-40226.html * https://bugzilla.suse.com/show_bug.cgi?id=1261400 * https://bugzilla.suse.com/show_bug.cgi?id=1261982 * https://bugzilla.suse.com/show_bug.cgi?id=1261983 * https://bugzilla.suse.com/show_bug.cgi?id=1262305 * https://bugzilla.suse.com/show_bug.cgi?id=1267644 * https://bugzilla.suse.com/show_bug.cgi?id=1267647 . # Security update for systemd Announcement ID: SUSE-SU-2026:3244-1 Release Date: 2026-07-24T13:11:41. security, update, systemd, addresses, cve-2026-40226, additional. . Severity: moderate. LinuxSecurity.com Team
A security update for systemd addresses CVE-2026-40226 and several bug fixes across various SUSE products, requiring a system reboot after installation.. # Security update for systemd Announcement ID: SUSE-SU-2026:3244-1 Release Date: 2026-07-24T13:11:41Z Rating: moderate References: * bsc#1261400 * bsc#1261982 * bsc#1261983 * bsc#1262305 * bsc#1267644 * bsc#1267647 Cross-References: * CVE-2026-40226 CVSS scores: * CVE-2026-40226 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-40226 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40226 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability and has five security fixes can now be installed. ## Description: This update for systemd fixes the following issues: Security issues fixed: * CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: * Fix soft reboot not restarting user services with default.target (bsc#1262305). * Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). * Import commit 429043ca9a (bsc#1261982 bsc#1261983). * Import commit 58e5d2e21e (bsc#1261982). * Import commit 4bd91117cc (bsc#1261983). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3244=1 * openSUSE Leap15.6 zypper in -t patch SUSE-2026-3244=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3244=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libudev-mini1-debuginfo-254.27-150600.4.71.1 * systemd-sysvcompat-debuginfo-254.27-150600.4.71.2 * systemd-mini-254.27-150600.4.71.1 * systemd-network-254.27-150600.4.71.2 * systemd-testsuite-254.27-150600.4.71.2 * systemd-254.27-150600.4.71.2 * systemd-resolved-debuginfo-254.27-150600.4.71.2 * libsystemd0-debuginfo-254.27-150600.4.71.2 * systemd-doc-254.27-150600.4.71.2 * udev-254.27-150600.4.71.2 * systemd-journal-remote-debuginfo-254.27-150600.4.71.2 * systemd-networkd-254.27-150600.4.71.2 * udev-mini-debuginfo-254.27-150600.4.71.1 * libudev1-debuginfo-254.27-150600.4.71.2 * systemd-debugsource-254.27-150600.4.71.2 * systemd-homed-debuginfo-254.27-150600.4.71.2 * systemd-networkd-debuginfo-254.27-150600.4.71.2 * systemd-mini-debuginfo-254.27-150600.4.71.1 * systemd-mini-container-debuginfo-254.27-150600.4.71.1 * libsystemd0-254.27-150600.4.71.2 * udev-mini-254.27-150600.4.71.1 * libudev1-254.27-150600.4.71.2 * systemd-experimental-debuginfo-254.27-150600.4.71.2 * systemd-mini-devel-254.27-150600.4.71.1 * libudev-mini1-254.27-150600.4.71.1 * systemd-debuginfo-254.27-150600.4.71.2 * libsystemd0-mini-debuginfo-254.27-150600.4.71.1 * systemd-coredump-debuginfo-254.27-150600.4.71.2 * systemd-testsuite-debuginfo-254.27-150600.4.71.2 * systemd-container-254.27-150600.4.71.2 * systemd-experimental-254.27-150600.4.71.2 * systemd-portable-debuginfo-254.27-150600.4.71.2 * libsystemd0-mini-254.27-150600.4.71.1 * systemd-portable-254.27-150600.4.71.2 * systemd-mini-debugsource-254.27-150600.4.71.1 * systemd-journal-remote-254.27-150600.4.71.2 * systemd-coredump-254.27-150600.4.71.2 * systemd-mini-container-254.27-150600.4.71.1 *systemd-resolved-254.27-150600.4.71.2 * systemd-container-debuginfo-254.27-150600.4.71.2 * systemd-homed-254.27-150600.4.71.2 * udev-debuginfo-254.27-150600.4.71.2 * systemd-devel-254.27-150600.4.71.2 * systemd-sysvcompat-254.27-150600.4.71.2 * openSUSE Leap 15.6 (x86_64) * libudev1-32bit-254.27-150600.4.71.2 * libsystemd0-32bit-debuginfo-254.27-150600.4.71.2 * libudev1-32bit-debuginfo-254.27-150600.4.71.2 * libsystemd0-32bit-254.27-150600.4.71.2 * systemd-32bit-254.27-150600.4.71.2 * systemd-devel-32bit-254.27-150600.4.71.2 * systemd-32bit-debuginfo-254.27-150600.4.71.2 * openSUSE Leap 15.6 (aarch64_ilp32) * libudev1-64bit-254.27-150600.4.71.2 * systemd-64bit-debuginfo-254.27-150600.4.71.2 * libsystemd0-64bit-debuginfo-254.27-150600.4.71.2 * systemd-devel-64bit-254.27-150600.4.71.2 * libsystemd0-64bit-254.27-150600.4.71.2 * libudev1-64bit-debuginfo-254.27-150600.4.71.2 * systemd-64bit-254.27-150600.4.71.2 * openSUSE Leap 15.6 (aarch64 i586 x86_64) * systemd-boot-254.27-150600.4.71.2 * systemd-boot-debuginfo-254.27-150600.4.71.2 * openSUSE Leap 15.6 (noarch) * systemd-lang-254.27-150600.4.71.2 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * systemd-sysvcompat-debuginfo-254.27-150600.4.71.2 * systemd-doc-254.27-150600.4.71.2 * libsystemd0-debuginfo-254.27-150600.4.71.2 * systemd-resolved-debuginfo-254.27-150600.4.71.2 * systemd-254.27-150600.4.71.2 * udev-254.27-150600.4.71.2 * systemd-journal-remote-debuginfo-254.27-150600.4.71.2 * libudev1-debuginfo-254.27-150600.4.71.2 * systemd-debugsource-254.27-150600.4.71.2 * libsystemd0-254.27-150600.4.71.2 * libudev1-254.27-150600.4.71.2 * systemd-debuginfo-254.27-150600.4.71.2 * systemd-coredump-debuginfo-254.27-150600.4.71.2 * systemd-container-254.27-150600.4.71.2 * systemd-journal-remote-254.27-150600.4.71.2 * systemd-coredump-254.27-150600.4.71.2 * systemd-resolved-254.27-150600.4.71.2 *systemd-container-debuginfo-254.27-150600.4.71.2 * udev-debuginfo-254.27-150600.4.71.2 * systemd-devel-254.27-150600.4.71.2 * systemd-sysvcompat-254.27-150600.4.71.2 * Basesystem Module 15-SP7 (noarch) * systemd-lang-254.27-150600.4.71.2 * Basesystem Module 15-SP7 (x86_64) * libudev1-32bit-254.27-150600.4.71.2 * libsystemd0-32bit-debuginfo-254.27-150600.4.71.2 * libudev1-32bit-debuginfo-254.27-150600.4.71.2 * libsystemd0-32bit-254.27-150600.4.71.2 * systemd-32bit-254.27-150600.4.71.2 * systemd-32bit-debuginfo-254.27-150600.4.71.2 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * systemd-debugsource-254.27-150600.4.71.2 * systemd-debuginfo-254.27-150600.4.71.2 * systemd-network-254.27-150600.4.71.2 * systemd-networkd-debuginfo-254.27-150600.4.71.2 * systemd-networkd-254.27-150600.4.71.2 ## References: * https://www.suse.com/security/cve/CVE-2026-40226.html * https://bugzilla.suse.com/show_bug.cgi?id=1261400 * https://bugzilla.suse.com/show_bug.cgi?id=1261982 * https://bugzilla.suse.com/show_bug.cgi?id=1261983 * https://bugzilla.suse.com/show_bug.cgi?id=1262305 * https://bugzilla.suse.com/show_bug.cgi?id=1267644 * https://bugzilla.suse.com/show_bug.cgi?id=1267647 . An essential update for SUSE addressing a moderate risk vulnerability in systemd, ensuring system integrity and security.. systemd patch update,suse security update,linux security advisory. . Severity: moderate. LinuxSecurity.com Team
SUSE released a security update for Python 3 fixing three vulnerabilities, which include hash flooding, SSRF risks, and an archive extraction filter bypass, applicable to various SUSE Linux Enterprise products.. # Security update for python3 Announcement ID: SUSE-SU-2026:3245-1 Release Date: 2026-07-24T13:43:52Z Rating: important References: * bsc#1264962 * bsc#1265268 * bsc#1268977 Cross-References: * CVE-2026-11940 * CVE-2026-7210 * CVE-2026-8328 CVSS scores: * CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( NVD ): 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7210 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8328 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for python3 fixes the following issues: * CVE-2026-7210: insufficient entropy used for Expat hash-flooding protection allows a crafted XML document to trigger hash flooding (bsc#1264962). * CVE-2026-8328: server-supplied PASV host address is trusted by `ftpcp()` and allows for SSRF (bsc#1265268). * CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3245=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3245=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python3-base-debuginfo-3.4.10-25.188.1 * python3-tk-debuginfo-3.4.10-25.188.1 * python3-3.4.10-25.188.1 * python3-base-debugsource-3.4.10-25.188.1 * python3-curses-debuginfo-3.4.10-25.188.1 * python3-tk-3.4.10-25.188.1 * python3-devel-3.4.10-25.188.1 * libpython3_4m1_0-3.4.10-25.188.1 * python3-base-3.4.10-25.188.1 * libpython3_4m1_0-debuginfo-3.4.10-25.188.1 * python3-debugsource-3.4.10-25.188.1 * python3-curses-3.4.10-25.188.1 * python3-debuginfo-3.4.10-25.188.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * python3-base-debuginfo-32bit-3.4.10-25.188.1 * libpython3_4m1_0-32bit-3.4.10-25.188.1 * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.188.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (ppc64le s390x x86_64) * python3-devel-debuginfo-3.4.10-25.188.1 * SUSE Linux Enterprise Server 12 SP5 LTSSExtended Security (x86_64) * python3-base-debuginfo-3.4.10-25.188.1 * libpython3_4m1_0-32bit-3.4.10-25.188.1 * python3-tk-debuginfo-3.4.10-25.188.1 * python3-tk-3.4.10-25.188.1 * python3-3.4.10-25.188.1 * python3-curses-debuginfo-3.4.10-25.188.1 * python3-base-debugsource-3.4.10-25.188.1 * python3-devel-3.4.10-25.188.1 * python3-base-debuginfo-32bit-3.4.10-25.188.1 * libpython3_4m1_0-3.4.10-25.188.1 * python3-devel-debuginfo-3.4.10-25.188.1 * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.188.1 * libpython3_4m1_0-debuginfo-3.4.10-25.188.1 * python3-base-3.4.10-25.188.1 * python3-debuginfo-3.4.10-25.188.1 * python3-debugsource-3.4.10-25.188.1 * python3-curses-3.4.10-25.188.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11940.html * https://www.suse.com/security/cve/CVE-2026-7210.html * https://www.suse.com/security/cve/CVE-2026-8328.html * https://bugzilla.suse.com/show_bug.cgi?id=1264962 * https://bugzilla.suse.com/show_bug.cgi?id=1265268 * https://bugzilla.suse.com/show_bug.cgi?id=1268977 . Install a vital SUSE update for python3 addressing multiple security issues including buffer overflow risks and SSRF.. SUSE Linux Python Security Update, Python Security Fix, SUSE Python Update. . Severity: Important. LinuxSecurity.com Team
A security update for vim has been released, addressing three vulnerabilities that may allow arbitrary code execution and out-of-bounds writes, with installation recommended for affected SUSE Linux Micro products.. # Security update for vim Announcement ID: SUSE-SU-2026:22789-1 Release Date: 2026-07-17T12:25:54Z Rating: important References: * bsc#1271193 * bsc#1271194 * bsc#1271195 Cross-References: * CVE-2026-59856 * CVE-2026-59857 * CVE-2026-59858 CVSS scores: * CVE-2026-59856 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59856 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59856 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59856 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59857 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59857 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59857 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59858 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59858 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59858 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59858 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves three vulnerabilitiescan now be installed. ## Description: This update for vim fixes the following issues * Updated to version 9.2.0780 * CVE-2026-59856: Arbitrary Code Execution via PHP Omni-Completion (bsc#1271194). * CVE-2026-59857: Out-of-bounds Write in SAL Soundfolding (bsc#1271195). * CVE-2026-59858: Arbitrary Code Execution via C Omni-Completion (bsc#1271193). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-796=1 ## Package List: * SUSE Linux Micro Extras 6.0 (aarch64 s390x x86_64) * vim-9.2.0780-1.1 * vim-debugsource-9.2.0780-1.1 * vim-debuginfo-9.2.0780-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59856.html * https://www.suse.com/security/cve/CVE-2026-59857.html * https://www.suse.com/security/cve/CVE-2026-59858.html * https://bugzilla.suse.com/show_bug.cgi?id=1271193 * https://bugzilla.suse.com/show_bug.cgi?id=1271194 * https://bugzilla.suse.com/show_bug.cgi?id=1271195 . A security update for SUSE addressing three vulnerabilities in vim, enhancing system protection and functionality.. SUSE security update,vim security patch,arbitrary code execution,out-of-bounds write,SUSE vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.