SUSE Linux Vulnerabilities: Buffer Overflow and Privilege Escalation Issues

SUSE Linux Vulnerabilities: Buffer Overflow and Privilege Escalation Issues

First seen 9 Sep 2026, 18:45 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

Two vulnerabilities in SUSE Linux systems have been disclosed, affecting opensc and fuse-overlayfs. The first, CVE-2026-40510, is a stack buffer overflow in `piv_process_history()` that allows physical attackers to exploit crafted PIV smart cards or USB devices, leading to memory corruption. The second, CVE-2026-52791, involves privilege escalation due to SUID/SGID bit preservation after a truncate operation. Both vulnerabilities are rated as moderate in severity and require immediate patching. SUSE has provided patch instructions for both vulnerabilities, urging users to update their systems promptly. The opensc vulnerability was published on May 29, 2026, while the fuse-overlayfs issue was published on July 29, 2026. Users of SUSE Linux Micro 6.0 and 6.2 are specifically affected by these vulnerabilities.

Key Points: • CVE-2026-40510 allows memory corruption via crafted PIV devices. • CVE-2026-52791 enables privilege escalation due to improper file handling. • Immediate patching is recommended for affected SUSE Linux Micro versions.

Ask AI about this cluster

Timeline

2026-05-29
CVE-2026-40510 published
A stack buffer overflow vulnerability in opensc was disclosed, allowing physical attacks via crafted devices.
Linuxsecurity
2026-07-29
CVE-2026-52791 published
A privilege escalation vulnerability in fuse-overlayfs was disclosed due to SUID/SGID bit preservation.
Linuxsecurity
2026-09-08
Patch released for CVE-2026-40510
SUSE released an update for opensc to address the buffer overflow vulnerability, urging users to apply it immediately.
Linuxsecurity
2026-09-08
Patch released for CVE-2026-52791
SUSE released an update for fuse-overlayfs to mitigate the privilege escalation vulnerability, recommending immediate application.
Linuxsecurity