openSUSE Tumbleweed — signing-party — multiple vulnerabilities (2 CVEs) — patch and remediation guide
🔴 Critical ⏱ 15–90 min Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read • Source: SUSE advisory openSUSE-SU-2019:1388-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-11627 CVE-2018-15599 Upstream summary: gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID. Table […]