Multiple Vulnerabilities in openSUSE Leap 16.0 Affecting Key Components

Multiple Vulnerabilities in openSUSE Leap 16.0 Affecting Key Components

First seen 23 Jul 2026, 18:34 UTC Linuxsecurity 75% similarity 57.9

Article Content

Browse articles
ThreatCluster

Recent security updates for openSUSE Leap 16.0 address multiple vulnerabilities across key components. The updates include CVE-2026-57825 in opam, CVE-2026-41989 in libgcrypt, and CVE-2026-57062 in gpg2. CVE-2026-41989, published on 2026-04-23, allows crafted ECDH ciphertext to cause denial of service. CVE-2026-41082, published on 2026-04-16, affects opam and has been addressed in version 2.5.1. CVE-2026-57062, published on 2026-06-23, involves a parsing issue in gpgsm related to the CMS format for AES-GCM. Users are advised to apply the updates using recommended installation methods to mitigate risks. The vulnerabilities could lead to system-wide damage if exploited, emphasizing the importance of auditing Linux privileges.

Key Points: • Three vulnerabilities in openSUSE Leap 16.0 have been patched, affecting opam, libgcrypt, and gpg2. • CVE-2026-41989 can lead to denial of service through crafted ECDH ciphertext. • Immediate updates are recommended to mitigate potential system-wide damage from these vulnerabilities.

ThreatCluster AI

Timeline

2026-04-16
CVE-2026-41082 published
Vulnerability in opam addressed in version 2.5.1, potentially affecting user privileges.
Linuxsecurity
2026-04-23
CVE-2026-41989 published
Denial of service vulnerability in libgcrypt allows crafted ECDH ciphertext exploitation.
Linuxsecurity
2026-06-23
CVE-2026-57062 published
gpg2 vulnerability involves CMS parsing mishandling for AES-GCM, requiring urgent patching.
Linuxsecurity
2026-07-21
openSUSE security update for opam released
Update to version 2.5.2 released to fix CVE-2026-57825 and other vulnerabilities.
Linuxsecurity
2026-07-23
openSUSE security updates for libgcrypt and gpg2 released
Updates released to address CVE-2026-41989 and CVE-2026-57062, urging users to patch immediately.
Linuxsecurity

Community

Browse all →