gpp_maybe Security update for apache2-mod_auth_openidc
SUSE-SLE-Module-Server-Applications-15-SP7-2026-3952


This update for apache2-mod_auth_openidc fixes the following issue: - CVE-2026-54789: out-of-bounds read and one-byte out-of-bounds write in the state-cookie parser of `mod_auth_openidc` (bsc#1276217).

  • Release Date
    Sep 3 2026
  • References
    Bugzilla: 1276217
    CVEs: CVE-2026-54789
  • Type
    security
  • Severity
    important

cloud_download Downloads

Server Applications Module 15.7 s390x
  • Packages
    apache2-mod_auth_openidc
    Apache2.x module for an OpenID Connect enabled Identity Provider
    2.4.17.1-150600.16.20.1 lock rpm lock src
Server Applications Module 15.7 aarch64
  • Packages
    apache2-mod_auth_openidc
    Apache2.x module for an OpenID Connect enabled Identity Provider
    2.4.17.1-150600.16.20.1 lock rpm lock src
Server Applications Module 15.7 ppc64le
  • Packages
    apache2-mod_auth_openidc
    Apache2.x module for an OpenID Connect enabled Identity Provider
    2.4.17.1-150600.16.20.1 lock rpm lock src
Server Applications Module 15.7 x86_64
  • Packages
    apache2-mod_auth_openidc
    Apache2.x module for an OpenID Connect enabled Identity Provider
    2.4.17.1-150600.16.20.1 lock rpm lock src