openSUSE Vulnerabilities: Memory Leak and DoS Threats Identified

openSUSE Vulnerabilities: Memory Leak and DoS Threats Identified

First seen 2 Sep 2026, 19:43 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

Recent updates for openSUSE address critical vulnerabilities in OpenVPN and c-ares. The OpenVPN vulnerabilities (CVE-2026-12932 and CVE-2026-35058) involve a moderate memory leak and improper validation of packet lengths, potentially leading to denial of service. These vulnerabilities affect openSUSE Leap 15.4 systems. The c-ares update introduces several denial of service vulnerabilities (CVE-2026-33630, CVE-2026-69184, CVE-2026-69186) that can be remotely triggered, impacting openSUSE Leap 16.0. Users are advised to apply patches immediately to mitigate these risks. The vulnerabilities were published between June and July 2026, with patches available for both affected systems. Current status indicates that these vulnerabilities are disclosed and patched, but users must act promptly to secure their systems.

Key Points: • OpenVPN vulnerabilities can lead to denial of service on openSUSE Leap 15.4. • c-ares vulnerabilities pose remote denial of service threats on openSUSE Leap 16.0. • Patches are available; immediate application is recommended to mitigate risks.

Timeline

2026-06-08
CVE-2026-35058 published
Improper validation of packet length in OpenVPN could lead to denial of service.
Linuxsecurity
2026-07-30
CVE-2026-12932 published
Memory leak vulnerability in OpenVPN using --tls-crypt-v2 could be exploited.
Linuxsecurity
2026-08-31
OpenVPN patch released
SUSE released an update to fix memory leak and packet length vulnerabilities in OpenVPN.
Linuxsecurity
2026-09-02
c-ares vulnerabilities disclosed
Multiple denial of service vulnerabilities in c-ares were reported, affecting openSUSE Leap 16.0.
Linuxsecurity
2026-09-02
c-ares patch released
SUSE released an update to address denial of service vulnerabilities in c-ares.
Linuxsecurity