SUSE Security Updates Address Multiple Denial of Service Vulnerabilities

SUSE Security Updates Address Multiple Denial of Service Vulnerabilities

First seen 2 Jun 2026, 02:57 UTC Linuxsecurity 76% similarity 57.9

Article Content

Browse articles
ThreatCluster

SUSE released security updates for python-Pillow and CUPS addressing several vulnerabilities. The python-Pillow update fixes three CVEs: CVE-2026-42308, CVE-2026-42309, and CVE-2026-42310, which involve integer overflow, heap buffer overflow, and infinite loops, potentially leading to denial of service. The CUPS update addresses six vulnerabilities, including CVE-2026-34979, a heap overflow in `get_options()`, and CVE-2026-39314, which can also cause denial of service. These vulnerabilities affect SUSE Linux Enterprise Server and other products. Admins are advised to apply the patches using SUSE's recommended methods. The updates were released on May 28 and May 26, 2026, respectively. The vulnerabilities have varying CVSS scores, indicating differing levels of severity.

Key Points: • SUSE patches critical vulnerabilities in python-Pillow and CUPS affecting multiple systems. • CVE-2026-42310 and CVE-2026-39314 can lead to denial of service under specific conditions. • System administrators are urged to apply patches immediately to mitigate risks.

ThreatCluster AI

Timeline

2026-04-03
CVE-2026-34979 published
Heap overflow vulnerability in CUPS identified, affecting multiple configurations.
Linuxsecurity
2026-04-03
CVE-2026-27447 published
Authorization bypass vulnerability in CUPS disclosed, impacting user permissions.
Linuxsecurity
2026-04-03
CVE-2026-34980 published
Path traversal vulnerability in CUPS allows unauthorized file writes.
Linuxsecurity
2026-04-03
CVE-2026-34990 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-03
CVE-2026-34978 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-07
CVE-2026-39316 published
Dangling subscription pointer vulnerability in CUPS leads to denial of service.
Linuxsecurity
2026-04-07
CVE-2026-39314 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-09
CVE-2026-42310 published
Infinite loop vulnerability in python-Pillow discovered, risking resource exhaustion.
Linuxsecurity
2026-05-09
CVE-2026-42308 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-09
CVE-2026-42309 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

Community

Browse all →