February 2026 - Page 103 of 176

SLES 16 — fish — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — fish — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 February 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2019:2177-1 Related CVEs: CVE-2014-2905 CVE-2014-2906 CVE-2014-2914 CVE-2014-3219 CVE-2022-20001 CVE-2014-3856 CVE-2023-49284 Upstream summary: fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via […]

Read more
openSUSE Leap 15.6 — python311-tornado6 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.6

openSUSE Leap 15.6 — python311-tornado6 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.6 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:13641 (see also SUSE bugzilla) Related CVEs: CVE-2026-31958 CVE-2024-52804 Upstream summary: Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit […]

Read more
SLES 16 — python313-PyJWT — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — python313-PyJWT — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 February 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:12176 (see also SUSE bugzilla) Related CVEs: CVE-2026-32597 CVE-2022-29217 CVE-2024-53861 Upstream summary: PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header […]

Read more
SLES 16 — udev — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — udev — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 12 February 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2018-21029 CVE-2026-4105 CVE-2017-18078 CVE-2018-15688 CVE-2018-16864 CVE-2018-16865 CVE-2018-6954 CVE-2019-6454  +12 more Upstream summary: systemd 239 through 245 accepts any certificate signed by a trusted certificate authority […]

Read more
SLES 16 — tree-sitter-devel — vulnerability — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — tree-sitter-devel — vulnerability — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 12 February 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2022-45299 Upstream summary: An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Table […]

Read more
Amazon Linux 2 — libarchive — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — libarchive — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2026-3257 Related CVEs: CVE-2026-5121 CVE-2025-5914 CVE-2019-18408 CVE-2025-5917 CVE-2021-31566 CVE-2017-14503 CVE-2018-1000877 CVE-2018-1000878  +3 more Upstream summary: A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in […]

Read more
SLES 16 — ruby3.4 — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — ruby3.4 — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 12 February 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2025:14621-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-41816 CVE-2022-28738 CVE-2020-10663 CVE-2021-31799 CVE-2021-31810 CVE-2021-32066 CVE-2020-10933 CVE-2021-28965  +5 more Upstream summary: CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow […]

Read more
Red Hat Enterprise Linux 7 — vim — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Red Hat Enterprise Linux 7

Red Hat Enterprise Linux 7 — vim — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Red Hat Enterprise Linux 7 📖 ~4 min read  •  Source: Red Hat advisory RHSA RHSA-2026:6617 Related CVEs: CVE-2026-25749 CVE-2026-28417 CVE-2026-28421 CVE-2026-33412 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix […]

Read more
SLES 16 — expat — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — expat — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 12 February 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:695-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-9063 CVE-2026-32776 CVE-2026-32777 CVE-2025-59375 CVE-2009-2625 CVE-2016-5300 CVE-2017-9233 CVE-2019-15903  +12 more Upstream summary: An integer overflow during the parsing of XML using the Expat library. This […]

Read more
CHAT