openSUSE

openSUSE Tumbleweed — expat — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — expat — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2016:2861-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-9063 CVE-2026-32776 CVE-2026-32777 CVE-2025-59375 CVE-2024-8176 CVE-2024-28757 CVE-2022-43680 CVE-2022-40674  +12 more Upstream summary: An integer overflow during the parsing of XML using the Expat library. This […]

Read more
openSUSE Tumbleweed — cups — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — cups — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2010:023 (see also SUSE bugzilla) Related CVEs: CVE-2010-2941 CVE-2012-6094 CVE-2026-34990 CVE-2025-58060 CVE-2024-35235 CVE-2023-4504 CVE-2023-34241 CVE-2022-26691  +12 more Upstream summary: ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory […]

Read more
openSUSE Tumbleweed — goshs — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — goshs — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2026-40189 CVE-2026-40188 CVE-2026-35392 CVE-2026-35393 CVE-2026-35471 Upstream summary: goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/basic-auth mechanism […]

Read more
openSUSE Tumbleweed — element-web — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — element-web — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2023-2251 CVE-2023-28427 CVE-2022-39236 CVE-2022-39249 CVE-2022-39250 CVE-2022-39251 CVE-2022-36059 CVE-2025-59161  +6 more Upstream summary: Uncaught Exception in GitHub repository eemeli/yaml prior to 2.0.0-5. Table of contents Symptom […]

Read more
openSUSE Tumbleweed — coturn — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — coturn — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2025-69217 CVE-2026-27624 CVE-2020-26262 CVE-2020-6061 CVE-2020-4067 Upstream summary: coturn is a free open source implementation of TURN and STUN Server. Versions 4.6.2r5 through 4.7.0-r4 have a […]

Read more
openSUSE Tumbleweed — python311-pyOpenSSL — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — python311-pyOpenSSL — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:1192-1 (see also SUSE bugzilla) Related CVEs: CVE-2026-27459 CVE-2026-40475 CVE-2026-27448 Upstream summary: pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a […]

Read more
openSUSE Tumbleweed — strongswan — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — strongswan — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2023-26463 CVE-2026-35328 CVE-2026-35332 CVE-2026-25075 CVE-2025-62291 CVE-2021-41990 CVE-2021-41991 CVE-2013-6075  +12 more Upstream summary: strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a […]

Read more
openSUSE Leap 15.6 — aws-efs-utils — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.6

openSUSE Leap 15.6 — aws-efs-utils — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.6 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2025:14951-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-35881 CVE-2025-55159 Upstream summary: An issue was discovered in the traitobject crate through 2020-06-01 for Rust. It has false expectations about fat pointers, possibly […]

Read more
openSUSE Leap 15.6 — libz1 — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.6

openSUSE Leap 15.6 — libz1 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.6 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:0783-1 (see also SUSE bugzilla) Related CVEs: CVE-2026-27171 Upstream summary: zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has […]

Read more
openSUSE Leap 15.6 — varnish — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.6

openSUSE Leap 15.6 — varnish — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.6 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2024-30156 CVE-2013-4484 CVE-2025-30346 Upstream summary: Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows […]

Read more
CHAT