openSUSE

openSUSE Tumbleweed — munge — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — munge — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:2918 (see also SUSE bugzilla) Related CVEs: CVE-2026-25506 CVE-2019-3691 Upstream summary: MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer […]

Read more
openSUSE Tumbleweed — ruby3.4 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — ruby3.4 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:23063 (see also SUSE bugzilla) Related CVEs: CVE-2025-61594 CVE-2025-58767 Upstream summary: URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) […]

Read more
openSUSE Leap 15.6 — python311-CairoSVG — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.6

openSUSE Leap 15.6 — python311-CairoSVG — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.6 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:1421-1 (see also SUSE bugzilla) Related CVEs: CVE-2026-31899 Upstream summary: CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of service via […]

Read more
openSUSE Leap 15.6 — roundcubemail — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.6

openSUSE Leap 15.6 — roundcubemail — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.6 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2024:0328-1 Related CVEs: CVE-2024-42008 CVE-2024-42009 CVE-2026-35537 CVE-2025-68460 CVE-2025-68461 CVE-2026-25916 CVE-2026-26079 CVE-2024-42010 Upstream summary: A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker […]

Read more
openSUSE Leap 15.6 — libcfg6 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.6

openSUSE Leap 15.6 — libcfg6 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.6 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2025:14933-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-30472 CVE-2026-35091 CVE-2026-35092 Upstream summary: Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow […]

Read more
openSUSE Tumbleweed — runc — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — runc — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:19927 (see also SUSE bugzilla) Related CVEs: CVE-2025-31133 CVE-2025-52565 CVE-2025-52881 CVE-2023-27561 CVE-2019-19921 CVE-2021-30465 CVE-2023-25809 CVE-2023-28642  +5 more Upstream summary: runc is a CLI tool for spawning and running containers according to the […]

Read more
openSUSE Tumbleweed — libpng16 — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — libpng16 — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:14790 (see also SUSE bugzilla) Related CVEs: CVE-2026-33636 CVE-2026-25646 CVE-2025-66293 CVE-2011-2690 CVE-2011-2692 CVE-2026-22695 CVE-2026-22801 CVE-2025-64506  +8 more Upstream summary: LIBPNG is a reference library for use in applications that read, create, and […]

Read more
openSUSE Tumbleweed — libIex — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — libIex — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2026-41142 CVE-2026-42216 CVE-2026-40244 CVE-2026-40250 CVE-2026-34545 CVE-2026-34588 CVE-2026-34589 CVE-2026-27622  +12 more Upstream summary: OpenEXR provides the specification and reference implementation of the EXR file format, an […]

Read more
openSUSE Leap 15.6 — perf — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.6

openSUSE Leap 15.6 — perf — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.6 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:21195-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-0840 CVE-2025-11083 CVE-2025-11412 CVE-2025-11413 CVE-2025-11414 CVE-2025-1182 CVE-2025-3198 CVE-2025-5244  +12 more Upstream summary: A vulnerability, which was classified as problematic, was found in GNU Binutils […]

Read more
openSUSE Tumbleweed — net-tools — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — net-tools — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:02974-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-46836 Upstream summary: net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operating system. Inn […]

Read more
CHAT