Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · suse

suse

· 63 Critical

Total CVEs

1,188

Critical

63

Products

119

Search All CVEs →

1,188

Products (119)

linux enterprise server500 CVEslinux enterprise desktop466 CVEslinux enterprise software development kit302 CVEssuse linux217 CVEssuse linux enterprise server143 CVEslinux enterprise139 CVEslinux enterprise workstation extension105 CVEssuse linux enterprise desktop82 CVEslinux enterprise real time extension58 CVEslinux enterprise debuginfo56 CVEspackage hub39 CVEssuse linux enterprise software development kit35 CVEsopenstack cloud35 CVEslinux enterprise high availability extension29 CVEsrancher28 CVEsstudio onsite22 CVEsmanager22 CVEsmanager proxy19 CVEslinux enterprise sdk19 CVEsmanager server17 CVEssuse linux workstation extension17 CVEslinux enterprise point of sale14 CVEslinux enterprise high performance computing12 CVEscaas platform8 CVEslinux enterprise real time7 CVEsopenstack cloud crowbar7 CVEssuse linux connectivity server6 CVEslinux enterprise server for sap6 CVEssuse email server6 CVEssuse linux office server6 CVEssuse linux database server6 CVEssuse linux firewall cd5 CVEsopensuse5 CVEsenterprise storage5 CVEssuse linux admin-cd for firewall5 CVEslinux enterprise java5 CVEsstudio extension for system z5 CVEssuse open enterprise server4 CVEslinux enterprise server for raspberry pi4 CVEsopen suse4 CVEssuse linux openexchange server4 CVEsopensuse factory4 CVEswebyast4 CVEslinux enterprise module for public cloud3 CVEssubscription management tool3 CVEssuse linux enterprise high availability extension3 CVEssuse office server3 CVEssuse united linux3 CVEslinux enterprise live patching3 CVEslinux enterprise micro3 CVEslinux enterprise module for legacy3 CVEskiwi3 CVEssuse sled beagle2 CVEssuse openstack cloud2 CVEssuse linux standard server2 CVEssuse linux school server2 CVEsmanager retail branch server2 CVEslinux2 CVEscloud2 CVEslinux enterprise module for web scripting2 CVEssuse enterprise storage2 CVEsrancher rke22 CVEsportus2 CVEswrangler2 CVEsbackports2 CVEslinux enterprise high availability2 CVEssusestudio-ui-server2 CVEsyast2-security1 CVEsbasesystem module1 CVEscups1 CVEsdevelopment tools module1 CVEshawk21 CVEsinn1 CVEskeystone-json-assignment1 CVEslegacy module1 CVEslifecycle management server1 CVEslinux enterprise for sap1 CVEslinux enterprise module for containers1 CVEslinux enterprise module for sap applications1 CVEslinux enterprise point of service1 CVEslinux enterprise storage1 CVEslinux micro1 CVEsmailman1 CVEsmunin1 CVEsnovell linux pos1 CVEsobs-service-tar scm1 CVEsoffice server1 CVEsopen enterprise server1 CVEsopenqa1 CVEsopensuse leap1 CVEsopensuse osc1 CVEspam-config1 CVEspublic cloud module1 CVEsrancher backup and restore operator1 CVEsrancher desktop1 CVEsrancher k3s1 CVEsrealtime module1 CVEsrepository mirroring tool1 CVEss390-tools1 CVEssalt-netapi-client1 CVEsshadow1 CVEsstudio1 CVEsstudio onsite appliance1 CVEssuse cvsup1 CVEssuse iptables1 CVEssuse linux desktop1 CVEssuse linux enterprise live patching1 CVEssuse linux enterprise module for public cloud1 CVEssuse linux enterprise real time extension1 CVEssuse linux enterprise workstation extension1 CVEssuse linux firewall1 CVEssuse linux firewall live-cd1 CVEssuse linux imap server1 CVEssusefirewall21 CVEstrousers1 CVEsvpnc1 CVEsyast21 CVEsyast2-backup1 CVEsarpwatch1 CVEs

Recent Vulnerabilities

View all 1,188
CVE-2026-31431HIGH 7.8KEV

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

CVE-2026-25702HIGH 7.3

A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via nftables to not be effective.This issue affects SUSE Linux Enterprise Server: from 9e6d9d4601768c75fdb0bad3fbbe636e748939c2 before 9c294edb7085fb91650bc12233495a8974c5ff2d.

CVE-2025-62879MEDIUM 6.8

A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs.

CVE-2025-67601HIGH 8.3

A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts.

CVE-2025-6018HIGH 7.8

A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw allows an unprivileged local attacker (for example, a user logged in via SSH) to obtain the elevated privileges normally reserved for a physically present, "allow_active" user. The highest risk is that the attacker can then perform all allow_active yes Polkit actions, which are typically restricted to console users, potentially gaining unauthorized control over system configurations, services, or other sensitive operations.

CVE-2025-32463CRITICAL 9.3KEV

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

CVE-2024-12085HIGH 7.5

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVE-2024-12087MEDIUM 6.5

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.

CVE-2024-12086MEDIUM 6.1

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to determine what data needs to be sent to the server. By sending specially constructed checksum values for arbitrary files, an attacker may be able to reconstruct the data of those files byte-by-byte based on the responses from the client.

CVE-2024-46956HIGH 7.8

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

CVE-2024-46955MEDIUM 5.5

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.

CVE-2024-46953HIGH 7.8

An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.

CVE-2024-46951HIGH 7.8

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.

CVE-2023-22649HIGH 8.4

A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log) is an opt-in feature, only deployments that have it enabled and have [AUDIT_LEVEL](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log#audit-log-levels) set to `1 or above` are impacted by this issue.

CVE-2024-6387HIGH 8.1

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

CVE-2024-23301MEDIUM 5.5

Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.

CVE-2020-10676HIGH 8.8

In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a different project.

CVE-2023-22644MEDIUM 5.5

A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.

CVE-2023-32182MEDIUM 5.9

A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux Enterprise High Performance Computing 15 SP5 postfix, SUSE openSUSE Leap 15.5 postfix.This issue affects SUSE Linux Enterprise Desktop 15 SP5: before 3.7.3-150500.3.5.1; SUSE Linux Enterprise High Performance Computing 15 SP5: before 3.7.3-150500.3.5.1; openSUSE Leap 15.5 : before 3.7.3-150500.3.5.1.

CVE-2023-32186HIGH 7.5

A Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s servers apiserver/supervisor port (TCP 6443) cause denial of service. This issue affects RKE2: from 1.24.0 before 1.24.17+rke2r1, from v1.25.0 before v1.25.13+rke2r1, from v1.26.0 before v1.26.8+rke2r1, from v1.27.0 before v1.27.5+rke2r1, from v1.28.0 before v1.28.1+rke2r1.

CVE-2023-22648HIGH 8.0

A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they are logged in the Rancher UI. This would cause the users to retain their previous permissions in Rancher, even if they change groups on Azure AD, for example, to a lower privileged group, or are removed from a group, thus retaining their access to Rancher instead of losing it. This issue affects Rancher: from >= 2.6.7 before < 2.6.13, from >= 2.7.0 before < 2.7.4.

CVE-2023-22647CRITICAL 9.9

An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate Kubernetes secrets in the local cluster, resulting in the secret being deleted, but their read-level permissions to the secret being preserved. When this operation was followed-up by other specially crafted commands, it could result in the user gaining access to tokens belonging to service accounts in the local cluster. This issue affects Rancher: from >= 2.6.0 before < 2.6.13, from >= 2.7.0 before < 2.7.4.

CVE-2022-43760HIGH 8.4

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SUSE Rancher allows users in some higher-privileged groups to to inject code that is executed within another user's browser, allowing the attacker to steal sensitive information, manipulate web content, or perform other malicious activities on behalf of the victims. This could result in a user with write access to the affected areas being able to act on behalf of an administrator, once an administrator opens the affected web page. This issue affects Rancher: from >= 2.6.0 before < 2.6.13, from >= 2.7.0 before < 2.7.4.

CVE-2023-34256MEDIUM 5.5

An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4_group_desc_csum does not properly check an offset. NOTE: this is disputed by third parties because the kernel is not intended to defend against attackers with the stated "When modifying the block device while it is mounted by the filesystem" access.

CVE-2023-22651CRITICAL 9.9

Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfiguration of the Webhook. This component enforces validation rules and security checks before resources are admitted into the Kubernetes cluster. The issue only affects users that upgrade from 2.6.x or 2.7.x to 2.7.2. Users that did a fresh install of 2.7.2 (and did not follow an upgrade path) are not affected.