Skip to content
openSUSE Leap 16.0 Advisory 2026-21324

openSUSE Leap 16.0 Advisory 2026-21324

Linuxsecurity LinuxSecurity Advisories July 15, 2026

- CVE-2026-25679: net/url: reject IPv6 literal not at start of host (bsc#1259264).

- CVE-2026-27139: os: FileInfo can escape from a Root (bsc#1259268).

- CVE-2026-27142: html/template: URLs in meta content attribute actions are not escaped (bsc#1259265).

- CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014).

- CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015).

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

zypper in -t patch openSUSE-Leap-16.0-1228=1

- openSUSE Leap 16.0:

go1.25-1.25.12-160000.1.1

go1.25-doc-1.25.12-160000.1.1

go1.25-race-1.25.12-160000.1.1

*

*

*

*

*

Get the latest Linux and open source security news straight to your inbox.