Linuxsecurity
SUSE Linux Micro Vulnerabilities Addressed in Recent Updates
Article Content
Recent updates for SUSE Linux Micro address multiple vulnerabilities in cpio and gzip utilities. The cpio update, identified as SUSE-SU-2026:23355-1, fixes three CVEs: CVE-2026-66484, CVE-2026-66485, and CVE-2026-66486, which involve issues like improper sanitization and memory management, potentially allowing for denial of service and terminal control sequence injection. The gzip update, SUSE-SU-2026:23392-1, resolves CVE-2026-41992, a global buffer overflow vulnerability due to improper state management in decompression logic. Both updates are rated as moderate in severity and are applicable to SUSE Linux Micro versions 6.1 and 6.2. Users are advised to apply the patches using recommended installation methods. The vulnerabilities were disclosed in August 2026, with CVE-2026-41992 having been published earlier in June 2026.
Key Points: • SUSE Linux Micro updates address vulnerabilities in cpio and gzip utilities. • CVE-2026-66484, CVE-2026-66485, and CVE-2026-66486 are related to cpio, while CVE-2026-41992 affects gzip. • Users should apply the patches promptly to mitigate risks associated with these vulnerabilities.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.