SUSE Linux Micro Vulnerabilities Addressed in Recent Updates

SUSE Linux Micro Vulnerabilities Addressed in Recent Updates

First seen 2 Sep 2026, 19:43 UTC Linuxsecurity 42.9

Article Content

Browse articles
ThreatCluster

Recent updates for SUSE Linux Micro address multiple vulnerabilities in cpio and gzip utilities. The cpio update, identified as SUSE-SU-2026:23355-1, fixes three CVEs: CVE-2026-66484, CVE-2026-66485, and CVE-2026-66486, which involve issues like improper sanitization and memory management, potentially allowing for denial of service and terminal control sequence injection. The gzip update, SUSE-SU-2026:23392-1, resolves CVE-2026-41992, a global buffer overflow vulnerability due to improper state management in decompression logic. Both updates are rated as moderate in severity and are applicable to SUSE Linux Micro versions 6.1 and 6.2. Users are advised to apply the patches using recommended installation methods. The vulnerabilities were disclosed in August 2026, with CVE-2026-41992 having been published earlier in June 2026.

Key Points: • SUSE Linux Micro updates address vulnerabilities in cpio and gzip utilities. • CVE-2026-66484, CVE-2026-66485, and CVE-2026-66486 are related to cpio, while CVE-2026-41992 affects gzip. • Users should apply the patches promptly to mitigate risks associated with these vulnerabilities.

Timeline

2026-06-29
CVE-2026-41992 published
Global buffer overflow vulnerability in gzip due to improper state management disclosed.
Linuxsecurity
2026-08-10
CVE-2026-66484, 66485, 66486 published
Multiple vulnerabilities in cpio disclosed, including improper sanitization and memory management issues.
Linuxsecurity
2026-08-10
CVE-2026-66486 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-10
CVE-2026-66485 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-27
Gzip update released
SUSE released an update for gzip addressing CVE-2026-41992, rated moderate in severity.
Linuxsecurity
2026-08-28
Cpio update released
SUSE released an update for cpio addressing CVE-2026-66484, 66485, and 66486, rated moderate in severity.
Linuxsecurity