Skip to content
openSUSE YAST2-Users Important OS Command Injection Fix 2026-3948

openSUSE YAST2-Users Important OS Command Injection Fix 2026-3948

Linuxsecurity LinuxSecurity Advisories September 3, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

This update for yast2-users fixes the following issue:

Update to version 4.6.7.

* CVE-2026-59680: OS command injection via LDAP-supplied

`shadowLastChange`/`shadowExpire` attribute (bsc#1272839).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 15 SP6 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3948=1

zypper in -t patch SUSE-2026-3948=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3948=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)

* yast2-users-4.6.7-150600.3.6.1

* yast2-users-debugsource-4.6.7-150600.3.6.1

* yast2-users-debuginfo-4.6.7-150600.3.6.1

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)

* yast2-users-4.6.7-150600.3.6.1

* yast2-users-debugsource-4.6.7-150600.3.6.1

* yast2-users-debuginfo-4.6.7-150600.3.6.1

* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)

* yast2-users-4.6.7-150600.3.6.1

* yast2-users-debugsource-4.6.7-150600.3.6.1

* yast2-users-debuginfo-4.6.7-150600.3.6.1

*

*

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases