critical
Security update for openssl-3-livepatches
SUSE-SLE-Module-Live-Patching-15-SP7-2026-2662
This update for openssl-3-livepatches fixes the following issues - CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256878). - CVE-2025-15467: Stack buffer overflow in CMS AuthEnvelopedData parsing (bsc#1256876). - CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256880). - CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266389, bsc#1266357).
-
Release DateJun 26 2026
-
ReferencesBugzilla: 1256876, 1256878, 1256880, 1266357, 1266389
CVEs: CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2026-45447 -
Typesecurity
-
Severitycritical
cloud_download Downloads
To download packages, you need to log in and have a valid subscription.
SUSE Linux Enterprise Live Patching 15.7 ppc64le
-
Packages
SUSE Linux Enterprise Live Patching 15.7 x86_64
-
Packages