gpp_maybe Security update for libvirt
SUSE-SLE-Micro-5.4-2026-4004


This update for libvirt fixes the following issues: - CVE-2026-18917: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow (bsc#1275863). - CVE-2026-61477: newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection (bsc#1274576). - CVE-2026-63622: `swtpm` privilege escalation via symlink following (bsc#1275264). - CVE-2026-63623: information disclosure via world-readable storage volume images during clone/convert (bsc#1275265). - CVE-2026-77159: root `chown()` on `swtpm` logfile follows symlinks (bsc#1274946).


cloud_download Downloads

SUSE Linux Enterprise Micro 5.4 s390x
SUSE Linux Enterprise Micro 5.4 aarch64
SUSE Linux Enterprise Micro 5.4 x86_64