| openSUSE-2026-338 |
important |
security |
2026-09-21 |
This update for mkvtoolnix fixes the following issues:
- CVE-2026-90783: heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic (bo
...
|
- mkvtoolnix-84.0-bp157.2.3.1
|
| openSUSE-2026-337 |
moderate |
security |
2026-09-21 |
This update for hugo fixes the following issues:
- update to 0.163.3 (boo#1269014):
* markup/highlight: Escape lang in default code block rendering
ce1a7e0b @bep thanks to @k0ngj1 for reporting
...
|
|
| openSUSE-2026-336 |
important |
security |
2026-09-21 |
This update for mbedtls-2 fixes the following issues:
- CVE-2025-52496: race condition in AESNI support detection, AES key
disclosure / GCM forgery in multithreaded programs (boo#1245810)
- CVE-20
...
|
- mbedtls-2-2.28.10-bp157.2.6.1
|
| openSUSE-2026-335 |
important |
security |
2026-09-21 |
This update for trivy fixes the following issues:
Update vendor.tar to address:
* boo#1278624, CVE-2026-56855,CVE-2026-56854,CVE-2026-78662:
golang.org/x/crypto/ssh: authentication bypass and
...
|
- trivy-0.74.0-bp157.2.21.1
|
| openSUSE-2026-334 |
important |
security |
2026-09-21 |
This update for keybase-client fixes the following issues:
- CVE-2026-56855,CVE-2026-56854,CVE-2026-78662: authentication bypass and deadlocks in the crypto/ssh library
- Update to go 1.26 as requir
...
|
- keybase-client-6.6.3-bp157.2.15.1
|
| openSUSE-2026-333 |
important |
security |
2026-09-21 |
This update for gh fixes the following issues:
- Update to version 2.100.0, fixing two deadlock issues in the vendored
golang.org/x/crypto/ssh library reachable via crafted SSH channel
messages (
...
|
|
| openSUSE-2026-332 |
moderate |
recommended |
2026-09-21 |
This update for openQA, os-autoinst fixes the following issues:
Changes in openQA:
- Update to version 5.1788605562.29b45941:
* chore(deps): Dependency cron 2026-09-05
* style: Enforce perlcriti
...
|
- openQA-5.1788605562.29b45941-bp157.2.36.1
- openQA-client-test-5.1788605562.29b45941-bp157.2.36.1
- openQA-test-5.1788605562.29b45941-bp157.2.36.1
- openQA-worker-test-5.1788605562.29b45941-bp157.2.36.1
- os-autoinst-5.1788768889.879c500-bp157.2.24.1
- os-autoinst-openvswitch-test-5.1788768889.879c500-bp157.2.24.1
- os-autoinst-test-5.1788768889.879c500-bp157.2.24.1
|
| openSUSE-2026-331 |
important |
security |
2026-09-21 |
This update for tree-sitter fixes the following issues:
- Revendored to the latest versions of dependencies (including bytes-1.12.1 to fix boo#1274132, CVE-2026-25541).
|
- tree-sitter-0.20.8-bp157.2.3.1
|
| openSUSE-2026-330 |
important |
security |
2026-09-21 |
This update for sofia-sip fixes the following issues:
- CVE-2022-31003: out of bounds write via malformed sdp message (boo#1200118)
- CVE-2022-31002: out of bounds read via malformed URL (boo#1200117
...
|
- sofia-sip-1.12.11+20110422-bp157.2.3.1
|
| openSUSE-2026-329 |
moderate |
security |
2026-09-21 |
This update for python-asteval fixes the following issues:
- CVE-2026-55244: Sandbox Escape via BaseException Subclasses (boo#1273147)
|
- python-asteval-1.0.6-bp157.2.3.1
|