Back Linuxsecurity openSUSE Apache2 Mod Auth OpenID Connect Critical Out Of Bounds Issue
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
This update for apache2-mod_auth_openidc fixes the following issue:
- CVE-2026-54789: out-of-bounds read and one-byte out-of-bounds write in the state-cookie parser of `mod_auth_openidc`
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
zypper in -t patch openSUSE-Leap-16.0-1575=1
- openSUSE Leap 16.0:
apache2-mod_auth_openidc-2.4.17.1-160000.2.1
*
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
