Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SUSE — Vulnerabilities & Security Advisories 214

Browse all 214 CVE security advisories affecting SUSE. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SUSE operates primarily as a provider of enterprise Linux distributions and cloud-native solutions, serving critical infrastructure in hybrid and multi-cloud environments. With 185 recorded CVEs, its vulnerability profile reflects the complexity of managing large-scale open-source codebases. Historically, common flaw classes include remote code execution (RCE), buffer overflows, and privilege escalation vulnerabilities, often stemming from misconfigurations or outdated dependencies within its core operating system components. Notable security characteristics involve its focus on container security and Kubernetes integration, which introduces attack surfaces related to orchestration layers. While no single catastrophic incident defines its history, the sheer volume of vulnerabilities highlights the ongoing challenge of maintaining security in widely deployed, long-term support releases. This necessitates rigorous patch management and continuous monitoring to mitigate risks associated with its extensive ecosystem of integrated services and third-party libraries.

CVE ID Title CVSS Severity Published
CVE-2026-44945 Cross-Cluster Impersonation Confused-Deputy Privilege Escalation — Rancher CWE-441 9.1 Critical 2026-08-05
CVE-2026-25703 Potential information leakage from manager /network/graph API in NeuVector — NeuVector CWE-306 7.3 High 2026-08-05
CVE-2026-55998 Cluster Existence Oracle via Unauthenticated Import Endpoint — Rancher CWE-204 5.3 Medium 2026-08-05
CVE-2026-59675 Rancher Audit-Log Middleware Unauthenticated Memory Exhaustion Denial of Service — Rancher CWE-770 7.5 High 2026-08-05
CVE-2026-55996 Unauthenticated Denial-of-Service via TLS SAN Stuffing in Rancher and cattle-cluster-agent — Rancher 4.3 Medium 2026-08-05
CVE-2025-8412 VMDP: Potential buffer overflow in the RtlQueryRegistryValues function — Virtual Machine Driver Pack CWE-120 - - 2026-07-14
CVE-2026-59674 LPE from suricata user to root due to chown in %post in suricata packaging — openSUSE Tumbleweed CWE-61 - - 2026-07-14
CVE-2026-44938 Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent — Rancher CWE-522 8.8 High 2026-07-07
CVE-2026-44937 SUSE Rancher Fleet had an Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components — Rancher CWE-918 - - 2026-07-06
CVE-2026-44936 Rancher Fleet SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml — Rancher CWE-918 5.0 Medium 2026-07-06
CVE-2026-44934 Exposed tokens in SUSE Rancher AI Agent logs — Rancher CWE-215 - - 2026-07-06
CVE-2026-44935 Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer — Rancher CWE-1287 9.9 Critical 2026-07-02
CVE-2026-44941 libzypp path traversal via "keyhint" in repomd.xml — libzypp CWE-23 8.4 High 2026-07-02
CVE-2026-44948 Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler — Rancher CWE-23 - - 2026-06-30
CVE-2026-44949 Unauthenticated namespace creation and RBAC injection via rancher-webhook FleetWorkspace mutating webhook — Rancher CWE-306 - - 2026-06-30
CVE-2026-44947 Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher — Rancher CWE-281 - - 2026-06-30
CVE-2026-44946 SAML Authentication Replay in Rancher — Rancher CWE-294 - - 2026-06-30
CVE-2026-41053 Over-inclusive team membership expansion in GitHub App authentication provider for Rancher — Rancher CWE-303 8.8 High 2026-06-30
CVE-2026-41052 Rancher Privilege Escalation from Project Owner to Host — Rancher CWE-305 - - 2026-06-29
CVE-2026-25707 Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp — libzypp CWE-23 8.8 High 2026-06-29
CVE-2026-44939 Command injection through unsanitized YAML parameter in Rancher — Rancher CWE-95 - - 2026-06-19
CVE-2026-44942 libzypp .repo files can have an optional path which can lead to path traversal attacks — libzypp CWE-24 6.5 Medium 2026-06-18
CVE-2025-71261 Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS — Harvester CWE-295 8.6 High 2026-06-16
CVE-2026-44932 indirect remote shell command injection via unsanitized DHCP options in wicked — wicked CWE-78 8.8 High 2026-06-16
CVE-2026-41054 Missing exit out of permission check in haveged could lead to root exploit — Container suse/sle-micro-rancher/5.3:latest CWE-305 7.8 High 2026-05-20
CVE-2026-44933 Path Traversal in Plugin Loading in libzypp — SUSE Linux Enterprise CWE-35 7.8 High 2026-05-20
CVE-2026-41051 csync2 uses insecure temporary directories when compiled with C99 or later — openSUSE Tumbleweed 5.0 Medium 2026-05-13
CVE-2026-41050 Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering — Rancher CWE-863 9.9 Critical 2026-05-13
CVE-2026-25705 Rancher Extensions have arbitrary file access via path traversal — rancher CWE-35 8.4 High 2026-05-13
CVE-2026-25702 nftables disabled due to incorrect kernel backport — SUSE Linux Enterprise Server CWE-284 7.3 High 2026-03-05

This page lists every published CVE security advisory associated with SUSE. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.