gpp_maybe
Security update for libkrun
SUSE-SLES-16.0-1364
This update for libkrun fixes the following issues: - CVE-2025-24898: openssl: use-after-free in `ssl::select_next_proto` due to improper lifetime handling (bsc#1270429). - CVE-2026-41676: openssl: short buffer overflow via `Deriver:derive` and `PkeyCtxRef:derive` when using OpenSSL 1.1.1 (bsc#1270198). - CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270582). - CVE-2026-41678: openssl: OOB write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270683). - CVE-2026-41681: openssl: stack corruption due to `MdCtxRef::digest_final()` writing past caller buffer with no length check (bsc#1270721). - CVE-2026-41898: openssl: information leak to network peers due to unchecked callback-returned length in PSK and cookie generate trampolines (bsc#1270831). - CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270470). - CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding (bsc#1270877).
-
Release DateJul 28 2026
-
ReferencesBugzilla: 1270198, 1270429, 1270470, 1270582, 1270683, 1270721, 1270831, 1270877, 1271911
CVEs: CVE-2025-24898, CVE-2026-41676, CVE-2026-41677, CVE-2026-41678, CVE-2026-41681, CVE-2026-41898, CVE-2026-42327, CVE-2026-44662 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Server for SAP applications 16.0 x86_64
-
Packageslibkrun-devel
Header files and libraries for libkrun developmentlibkrun-sev-devel1.4.10-160000.3.1 lock rpm
Header files and libraries for libkrun developmentlibkrun-sev11.4.10-160000.3.1 lock rpm
Dynamic library providing Virtualization-based process isolation capabilities (SEV variant)libkrun11.4.10-160000.3.1 lock rpm
A dynamic library providing KVM-based process isolation capabilities1.4.10-160000.3.1 lock rpm
SUSE Linux Enterprise Server 16.0 aarch64
-
Packageslibkrun-devel
Header files and libraries for libkrun developmentlibkrun11.4.10-160000.3.1 lock rpm
A dynamic library providing KVM-based process isolation capabilities1.4.10-160000.3.1 lock rpm
SUSE Linux Enterprise Server 16.0 x86_64
-
Packageslibkrun-devel
Header files and libraries for libkrun developmentlibkrun-sev-devel1.4.10-160000.3.1 lock rpm
Header files and libraries for libkrun developmentlibkrun-sev11.4.10-160000.3.1 lock rpm
Dynamic library providing Virtualization-based process isolation capabilities (SEV variant)libkrun11.4.10-160000.3.1 lock rpm
A dynamic library providing KVM-based process isolation capabilities1.4.10-160000.3.1 lock rpm