critical
Security update for openssl-3-livepatches
SUSE-SLES-16.0-298
This update for openssl-3-livepatches fixes the following issues: - CVE-2025-11187: Fixed improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256878). - CVE-2025-15467: Fixed stack buffer overflow in CMS AuthEnvelopedData parsing (bsc#1256876). - CVE-2025-15468: Fixed NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256880). - CVE-2025-9230: Fixed out-of-bounds read & write in RFC 3211 KEK Unwrap (bsc#1250410).
-
Release DateFeb 18 2026
-
ReferencesBugzilla: 1250410, 1256878, 1256880, 1256876
CVEs: CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-9230 -
Typesecurity
-
Severitycritical
cloud_download Downloads
To download packages, you need to log in and have a valid subscription.
SUSE Linux Enterprise Server for SAP applications 16.0 x86_64
-
Packages
SUSE Linux Enterprise Server for SAP applications 16.0 ppc64le
-
Packages
SUSE Linux Enterprise Server 16.0 x86_64
-
Packages
SUSE Linux Enterprise Server 16.0 ppc64le
-
Packages