Multiple openSUSE Vulnerabilities Addressed in September 2026 Security Updates

Multiple openSUSE Vulnerabilities Addressed in September 2026 Security Updates

First seen 2 Sep 2026, 19:43 UTC Linuxsecurity 45.8

Article Content

Browse articles
ThreatCluster

On September 2, 2026, openSUSE released multiple security updates addressing vulnerabilities across various packages, including incus, httpcomponents-client, kernel-devel, snpguest, tuxguitar, wget, and snphost. The updates include fixes for moderate security issues, with CVE identifiers for some vulnerabilities. The affected packages are part of the openSUSE Tumbleweed distribution, which is a rolling release. Administrators are urged to apply the patches to maintain system security. Specific CVEs include 2026-11651 for incus, 2026-11647 for httpcomponents-client, 2026-11648 for kernel-devel, 2026-11653 for snpguest, 2026-11645 for tuxguitar, 2026-11646 for wget, and 2026-11654 for snphost. Each update addresses vulnerabilities that could potentially be exploited if not patched. The updates are available on the GA media of openSUSE Tumbleweed.

Key Points: • Multiple moderate vulnerabilities fixed in openSUSE Tumbleweed packages. • Patches released for incus, httpcomponents-client, kernel-devel, and others. • System administrators are advised to apply updates promptly.

Timeline

2026-09-02
openSUSE security updates released
openSUSE published security updates addressing multiple vulnerabilities across various packages, including incus and wget.
Linuxsecurity
2026-09-02
CVE-2026-11651 disclosed
A moderate security vulnerability in the incus package was disclosed and patched in version 7.4-1.1.
Linuxsecurity
2026-09-02
CVE-2026-11647 disclosed
A security advisory for httpcomponents-client was released, addressing vulnerabilities in version 4.5.14-2.1.
Linuxsecurity
2026-09-02
CVE-2026-11648 disclosed
Kernel-devel package vulnerabilities were addressed with the release of version 7.2.2-1.1.
Linuxsecurity
2026-09-02
CVE-2026-11653 disclosed
A moderate fix was issued for the snpguest package, version 0.10.0-3.1, to address security issues.
Linuxsecurity
2026-09-02
CVE-2026-11645 disclosed
Tuxguitar package vulnerabilities were patched in version 2.1.0-1.1, addressing moderate security issues.
Linuxsecurity
2026-09-02
CVE-2026-11646 disclosed
The wget package was updated to version 1.25.0-7.1 to fix moderate security vulnerabilities.
Linuxsecurity
2026-09-02
CVE-2026-11654 disclosed
A buffer overflow vulnerability in the snphost package was patched in version 0.7.0-3.1.
Linuxsecurity