Critical OpenSSL Vulnerabilities Affecting openSUSE and SUSE snphost

Critical OpenSSL Vulnerabilities Affecting openSUSE and SUSE snphost

First seen 1 Sep 2026, 02:01 UTC Linuxsecurity 64.5

Article Content

Browse articles
ThreatCluster

Two important advisories were released addressing multiple vulnerabilities in OpenSSL affecting openSUSE and SUSE snphost. The advisories detail several CVEs, including CVE-2026-54874 and CVE-2026-63072 for openSUSE, and CVE-2026-41677 and CVE-2026-41898 for SUSE snphost. The vulnerabilities range from buffer overflows to out-of-bounds reads, potentially allowing attackers to exploit these flaws for unauthorized access or denial of service. The patches are critical for systems running SUSE Linux Enterprise Server and openSUSE Leap. Administrators are urged to apply the patches immediately to mitigate risks. The vulnerabilities were disclosed between April and August 2026, with some having proof-of-concept code available. Current status indicates that while some vulnerabilities are patched, others may still pose a risk if not addressed promptly.

Key Points: • Multiple critical OpenSSL vulnerabilities disclosed affecting openSUSE and SUSE snphost. • Patches are available; immediate application is recommended to mitigate risks. • CVE-2026-63072 has a public proof-of-concept, increasing urgency for remediation.

Timeline

2026-04-24
CVE-2026-41677 published
An out-of-bounds read vulnerability in PEM password callback was disclosed.
Linuxsecurity
2026-04-24
CVE-2026-41898 published
An information leak vulnerability in PSK and cookie generate trampolines was disclosed.
Linuxsecurity
2026-04-24
CVE-2026-41678 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-24
CVE-2026-41681 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-14
CVE-2026-42327 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-54874 published
A vulnerability causing excessive memory use in DTLS records was disclosed.
Linuxsecurity
2026-08-25
CVE-2026-63072 published
A heap buffer overflow in CMS key unwrapping was disclosed, with a PoC available.
Linuxsecurity
2026-08-25
CVE-2026-75803 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-63074 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-63076 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE