SUSE-SU-2026:1952-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20261952-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1952-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:1952-1
Upstream
CVE (4)
Related
Published
2026-05-18T07:52:55Z
Modified
2026-05-19T08:45:08Z
Summary
Security update for ovmf
Details

This update for ovmf fixes the following issues

  • CVE-2026-25833: mbedtls: buffer underflow in x509_inet_pton_ipv6() (bsc#1261476).
  • CVE-2026-25834: mbedtls: Algorithm downgrade vulnerability (bsc#1261477).
  • CVE-2026-25835: mbedtls: PSA random generator cloning (bsc#1261478).
  • CVE-2026-34874: mbedtls: NULL pointer dereference when setting a distinguished name (bsc#1261469).

Changes for ovmf:

  • Update mbedtls to 3.6.6.
References

Affected packages