Opensuse tumbleweed
This hub aggregates every CVE we track for Opensuse tumbleweed, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
633
CVEs tracked
62
Critical
283
High
7
In CISA KEV
Severity distribution
HIGH283MEDIUM267CRITICAL62LOW20
Monthly trend
64
24
19
40
18
21
18
8
19
17
11
3
8
2
2
4
1
1
4
2
0
1
0
2
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Opensuse tumbleweed.
- CVE-2026-44950fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont29.0
- CVE-2026-59679fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont29.0
- CVE-2026-59674LPE from suricata user to root due to chown in %post in suricata packaging
- CVE-2026-43502net/rds: handle zerocopy send cleanup before the message is queued7.8
- CVE-2026-41051csync2 uses insecure temporary directories when compiled with C99 or later5.0
- CVE-2026-3832Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response3.7
- CVE-2026-3833Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison6.5
- CVE-2026-22008Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with n...3.7
- CVE-2026-34757LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure5.1
- CVE-2026-33636LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch647.6
- CVE-2025-22873Improper access to parent directory of root in os3.8
- CVE-2025-11065Github.com/go-viper/mapstructure/v2: go-viper's mapstructure may leak sensitive information in logs in github.com/go-viper/mapstructure5.3
- CVE-2025-43904In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user to Administrator.4.2
- CVE-2026-0892Memory safety bugs fixed in Firefox 147 and Thunderbird 1479.8
- CVE-2026-0891Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 1478.1
Product normalization is registry-driven with AI assist and human review. How it works