opensuse
Latest CVEs
The 15 most recently published vulnerabilities affecting opensuse.
- CVE-2026-48863Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service7.5
- CVE-2026-44941libzypp path traversal via "keyhint" in repomd.xml8.4
- CVE-2026-56004obs-service-tar_scm: command injection via mercurial handler10.0
- CVE-2026-25707Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp8.8
- CVE-2026-48864Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data7.8
- CVE-2026-9149Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file6.5
- CVE-2026-9150Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums6.5
- CVE-2026-31431crypto: algif_aead - Revert to operating out-of-placeKEV7.8
- CVE-2026-25701An Insecure Temporary File vulnerability in openSUSE sdbootutil allows local users to pre-create a directory to achieve various effects like: * gain access to possible private information found...
- CVE-2026-25506MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery7.7
- CVE-2025-62875Local DoS in OpenSMTPD via UNIX domain socket smtpd.sock5.5
- CVE-2025-53881SUSE-specific logrotate configuration allows escalation from mail user/group to root
- CVE-2025-46810A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate to root. This issue affects Tumbleweed: from ? before 2....
- CVE-2025-32463Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.KEV9.3
- CVE-2024-49505XSS vulnerability found in OpenSuse MirrorCache6.1