openSUSE

openSUSE Tumbleweed — python39-pip — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — python39-pip — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:4334-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-5752 Upstream summary: When installing a package from a Mercurial VCS URL (ie "pip install hg+…") with pip prior to v23.3, the specified Mercurial revision […]

Read more
openSUSE Tumbleweed — ruby3.1 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — ruby3.1 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2025:14621-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-28738 CVE-2021-33621 CVE-2023-28755 CVE-2022-28739 Upstream summary: A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If […]

Read more
openSUSE Tumbleweed — apache-commons-text — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — apache-commons-text — vulnerability — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:712-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-42889 Upstream summary: Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where […]

Read more
openSUSE Tumbleweed — fish — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — fish — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2022:0096-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-20001 CVE-2014-2905 CVE-2014-2906 CVE-2014-2914 CVE-2014-3219 CVE-2023-49284 CVE-2014-3856 Upstream summary: fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary […]

Read more
openSUSE Tumbleweed — autotrace — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — autotrace — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2022:10197-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-32323 CVE-2019-19005 CVE-2017-9182 CVE-2019-19004 Upstream summary: AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660. Table of contents Symptom […]

Read more
openSUSE Tumbleweed — shadowsocks-rust — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — shadowsocks-rust — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:4060-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-42811 Upstream summary: aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES GCM […]

Read more
openSUSE Tumbleweed — wpa_supplicant — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — wpa_supplicant — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2021:0284-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-0326 CVE-2021-27803 CVE-2023-52160 CVE-2015-4146 CVE-2015-5310 CVE-2015-5315 CVE-2015-5316 CVE-2016-4477  +6 more Upstream summary: In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due […]

Read more
openSUSE Tumbleweed — libSDL2_ttf — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — libSDL2_ttf — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2022-27470 Upstream summary: SDL_ttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTF_RenderText_Solid(). This vulnerability is triggered via a […]

Read more
openSUSE Tumbleweed — libsass — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — libsass — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2019:1791-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-11499 CVE-2018-19827 CVE-2022-26592 CVE-2022-43357 CVE-2022-43358 CVE-2018-19797 CVE-2018-19837 CVE-2018-19838  +7 more Upstream summary: A use-after-free vulnerability exists in handle_error() in sass_context.cpp in LibSass 3.4.x and 3.5.x […]

Read more
openSUSE Tumbleweed — libcjose0 — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — libcjose0 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:3030-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-37464 Upstream summary: OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag […]

Read more
CHAT