Skip to content
openSUSE yast2-users Important OS Command Injection Fix 2026-3946

openSUSE yast2-users Important OS Command Injection Fix 2026-3946

Linuxsecurity •LinuxSecurity Advisories • September 3, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

This update for yast2-users fixes the following issue:

Update to version 4.4.17.

* CVE-2026-59680: OS command injection via LDAP-supplied

`shadowLastChange`/`shadowExpire` attribute (bsc#1272839).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4

zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3946=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4

zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3946=1

* SUSE Manager Server 4.3

zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3946=1

* SUSE Linux Enterprise Server 15 SP4

zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3946=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4

zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3946=1 SUSE-SLE-Product-

SLES_SAP-15-SP4-2026-3946=1

* SUSE Linux Enterprise High Performance Computing 15 SP4

zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3946=1

* SUSE Linux Enterprise Desktop 15 SP4

zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3946=1

* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)

* yast2-users-4.4.17-150400.3.21.1

* yast2-users-debugsource-4.4.17-150400.3.21.1

* yast2-users-debuginfo-4.4.17-150400.3.21.1

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)

* yast2-users-debuginfo-4.4.17-150400.3.21.1

* yast2-users-4.4.17-150400.3.21.1

* yast2-users-debugsource-4.4.17-150400.3.21.1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)

* yast2-users-4.4.17-150400.3.21.1

* yast2-users-debugsource-4.4.17-150400.3.21.1

* yast2-users-debuginfo-4.4.17-150400.3.21.1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64

* yast2-users-4.4.17-150400.3.21.1

* yast2-users-debugsource-4.4.17-150400.3.21.1

* yast2-users-debuginfo-4.4.17-150400.3.21.1

* SUSE Manager Server 4.3 (ppc64le s390x x86_64)

* yast2-users-4.4.17-150400.3.21.1

* SUSE Linux Enterprise Server 15 SP4 (aarch64 ppc64le s390x x86_64)

* yast2-users-4.4.17-150400.3.21.1

* SUSE Linux Enterprise High...

*

*

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities

Attack Types (1)

Companies (1)

Platforms (1)