openSUSE Tumbleweed

openSUSE Tumbleweed — libggml — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — libggml — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2025-49847 CVE-2025-53630 Upstream summary: llama.cpp is an inference of several LLM models in C/C++. Prior to version b5662, an attacker‐supplied GGUF model vocabulary can trigger […]

Read more
openSUSE Tumbleweed — grype — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — grype — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2021:1188-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-3711 CVE-2025-5702 CVE-2024-3154 CVE-2023-45853 CVE-2022-2068 CVE-2025-12183 Upstream summary: In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). […]

Read more
openSUSE Tumbleweed — qbittorrent — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — qbittorrent — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2023:0391-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-30801 CVE-2024-51774 Upstream summary: All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is […]

Read more
openSUSE Tumbleweed — kwctl — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — kwctl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2025-53901 Upstream summary: Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.4, 33.0.2, and 34.0.2, a bug in Wasmtime's implementation of the WASIp1 set […]

Read more
openSUSE Tumbleweed — xorg-x11-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — xorg-x11-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-SA:2008:027 (see also SUSE bugzilla) Related CVEs: CVE-2008-2362 CVE-2024-31082 CVE-2022-2319 CVE-2022-2320 CVE-2008-2360 CVE-2018-14665 CVE-2020-14345 CVE-2020-14346  +12 more Upstream summary: Multiple integer overflows in the Render extension in the X server 1.4 in […]

Read more
openSUSE Tumbleweed — pdns-recursor — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — pdns-recursor — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2025-30192 CVE-2024-25590 CVE-2024-25583 CVE-2023-22617 CVE-2018-16855 CVE-2023-26437 CVE-2022-37428 CVE-2009-4009  +12 more Upstream summary: An attacker spoofing answers to ECS enabled requests sent out by the Recursor […]

Read more
openSUSE Tumbleweed — libnbd — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — libnbd — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2025-14946 CVE-2024-7383 CVE-2023-5871 CVE-2023-5215 CVE-2022-0485 CVE-2021-20286 Upstream summary: A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open […]

Read more
openSUSE Tumbleweed — libndp — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — libndp — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2283-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-5564 CVE-2016-3698 Upstream summary: A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered […]

Read more
openSUSE Tumbleweed — perl-Spreadsheet-ParseXLSX — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — perl-Spreadsheet-ParseXLSX — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2024-23525 CVE-2024-22368 Upstream summary: The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig. Table of contents Symptom & […]

Read more
openSUSE Tumbleweed — libpcap1 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — libpcap1 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3210-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-7256 CVE-2024-8006 CVE-2019-15161 CVE-2025-11961 Upstream summary: In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and […]

Read more
CHAT