SUSE libgcrypt Denial of Service Vulnerability Advisory

SUSE libgcrypt Denial of Service Vulnerability Advisory

First seen 2 Sep 2026, 19:43 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

A moderate denial of service vulnerability has been identified in libgcrypt, tracked as CVE-2026-41989. This vulnerability allows crafted ECDH ciphertext to lead to a denial of service condition. Affected systems include SUSE Linux Enterprise Micro 5.3, 5.4, and openSUSE Leap 15.4. The issue was published on April 23, 2026, and has been addressed with patches available for various SUSE products. Administrators are advised to apply the patches using recommended installation methods such as YaST or zypper. The vulnerability has a CVSS score of 6.3, indicating a moderate severity level. No active exploitation has been reported at this time. The advisory emphasizes the importance of keeping systems up to date to mitigate potential risks.

Key Points: • CVE-2026-41989 allows denial of service via crafted ECDH ciphertext. • Affected systems include SUSE Linux Enterprise Micro and openSUSE Leap. • Patches are available and should be applied promptly.

Timeline

2026-04-23
CVE-2026-41989 published
A denial of service vulnerability in libgcrypt was published, affecting multiple SUSE products.
Linuxsecurity
2026-09-02
Patch released for libgcrypt
SUSE released patches for libgcrypt to address CVE-2026-41989, urging users to update their systems.
Linuxsecurity