Linuxsecurity
SUSE Security Updates Address Multiple Denial of Service Vulnerabilities
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
SUSE released security updates for python-Pillow and CUPS addressing several vulnerabilities. The python-Pillow update fixes three CVEs: CVE-2026-42308, CVE-2026-42309, and CVE-2026-42310, which involve integer overflow, heap buffer overflow, and infinite loops, potentially leading to denial of service. The CUPS update addresses six vulnerabilities, including CVE-2026-34979, a heap overflow in `get_options()`, and CVE-2026-39314, which can also cause denial of service. These vulnerabilities affect SUSE Linux Enterprise Server and other products. Admins are advised to apply the patches using SUSE's recommended methods. The updates were released on May 28 and May 26, 2026, respectively. The vulnerabilities have varying CVSS scores, indicating differing levels of severity.
Key Points: • SUSE patches critical vulnerabilities in python-Pillow and CUPS affecting multiple systems. • CVE-2026-42310 and CVE-2026-39314 can lead to denial of service under specific conditions. • System administrators are urged to apply patches immediately to mitigate risks.