Search

Find a vulnerability

Search criteria

    300 vulnerabilities

    CVE-2026-88804 (GCVE-0-2026-88804)

    Vulnerability from cvelistv5 – Published: 2026-09-28 15:58 – Updated: 2026-09-28 18:02
    VLAI
    Title
    Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher
    Summary
    An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 16:31 UTC
    CWE
    • CWE-79 - Improper neutralization of input during web page generation ('cross-site scripting')
    References
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 2.15.0 , < 2.15.2 (semver)
    Affected: 2.14.0 , < 2.14.6 (semver)
    Affected: 2.13.0 , < 2.13.10 (semver)
    Affected: 2.12.0 , < 2.12.14 (semver)
    Affected: 2.11.0se , < 2.11.18 (semver)
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 15:53
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88804",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T16:31:06.472253Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T18:02:56.882Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "Rancher",
              "product": "Rancher",
              "repo": "https://github.com/rancher/rancher/",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.15.2",
                  "status": "affected",
                  "version": "2.15.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.14.6",
                  "status": "affected",
                  "version": "2.14.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.13.10",
                  "status": "affected",
                  "version": "2.13.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.12.14",
                  "status": "affected",
                  "version": "2.12.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.11.18",
                  "status": "affected",
                  "version": "2.11.0se",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.15.2",
                      "versionStartIncluding": "2.15.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.14.6",
                      "versionStartIncluding": "2.14.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.13.10",
                      "versionStartIncluding": "2.13.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.12.14",
                      "versionStartIncluding": "2.12.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.11.18",
                      "versionStartIncluding": "2.11.0se",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "stopvvar@proton.me"
            }
          ],
          "datePublic": "2026-09-28T15:53:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18."
                }
              ],
              "value": "An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-104",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-104 Cross Zone Scripting"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.6,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper neutralization of input during web page generation (\u0027cross-site scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T15:58:34.657Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/rancher/rancher/security/advisories/GHSA-992f-xh8r-jg2f"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-88804",
        "datePublished": "2026-09-28T15:58:34.657Z",
        "dateReserved": "2026-09-10T08:35:07.010Z",
        "dateUpdated": "2026-09-28T18:02:56.882Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88805 (GCVE-0-2026-88805)

    Vulnerability from cvelistv5 – Published: 2026-09-28 15:50 – Updated: 2026-09-29 03:55
    VLAI
    Title
    Session Not Revoked Server-Side on Logout in Rancher
    Summary
    Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 00:00 UTC
    CWE
    • CWE-613 - Insufficient session expiration
    References
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 2.15.0 , < 2.15.2 (semver)
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 15:40
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88805",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T03:55:25.070Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "Rancher",
              "product": "Rancher",
              "repo": "https://github.com/rancher/rancher/",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.15.2",
                  "status": "affected",
                  "version": "2.15.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.15.2",
                      "versionStartIncluding": "2.15.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "info@cyberobserve.com"
            }
          ],
          "datePublic": "2026-09-28T15:40:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2."
                }
              ],
              "value": "Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-21",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-21 Exploitation of Trusted Identifiers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-613",
                  "description": "CWE-613 Insufficient session expiration",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T15:50:34.591Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/rancher/rancher/security/advisories/GHSA-6vpq-mf48-9794"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Session Not Revoked Server-Side on Logout in Rancher",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-88805",
        "datePublished": "2026-09-28T15:50:34.591Z",
        "dateReserved": "2026-09-10T08:35:07.010Z",
        "dateUpdated": "2026-09-29T03:55:25.070Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88808 (GCVE-0-2026-88808)

    Vulnerability from cvelistv5 – Published: 2026-09-28 15:36 – Updated: 2026-09-29 03:55
    VLAI
    Title
    Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-namespace writes on downstream clusters
    Summary
    A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This could lead to overwritten configuration files. This issue affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, and 0.14 before 0.14.11.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 00:00 UTC
    CWE
    • CWE-250 - Execution with unnecessary privileges
    References
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0.16.0 , < 0.16.2 (semver)
    Affected: 0.15.0 , < 0.15.7 (semver)
    Affected: 0.14.0 , < 0.14.11 (semver)
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 15:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88808",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T03:55:24.347Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "Fleet",
              "product": "Rancher",
              "repo": "https://github.com/rancher/fleet/",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "0.16.2",
                  "status": "affected",
                  "version": "0.16.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.15.7",
                  "status": "affected",
                  "version": "0.15.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.14.11",
                  "status": "affected",
                  "version": "0.14.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.16.2",
                      "versionStartIncluding": "0.16.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.15.7",
                      "versionStartIncluding": "0.15.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.14.11",
                      "versionStartIncluding": "0.14.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "g.mygenie@gmail.com"
            }
          ],
          "datePublic": "2026-09-28T15:21:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003eA vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This could lead to overwritten configuration files.\u003c/div\u003e\u003cdiv\u003eThis issue affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, and 0.14 before 0.14.11.\u003c/div\u003e"
                }
              ],
              "value": "A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This could lead to overwritten configuration files.\n\nThis issue affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, and 0.14 before 0.14.11."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-180",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-250",
                  "description": "CWE-250 Execution with unnecessary privileges",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T15:36:13.506Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/rancher/fleet/security/advisories/GHSA-q9v4-358v-r8q5"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-namespace writes on downstream clusters",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-88808",
        "datePublished": "2026-09-28T15:36:13.506Z",
        "dateReserved": "2026-09-10T08:35:07.010Z",
        "dateUpdated": "2026-09-29T03:55:24.347Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93540 (GCVE-0-2026-93540)

    Vulnerability from cvelistv5 – Published: 2026-09-28 14:45 – Updated: 2026-09-28 16:22
    VLAI
    Title
    Fleet applies namespace labels and annotations without the bundle's service account privileges
    Summary
    A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorization as the rest of the bundle's deployment. As a result, a bundle could change labels and annotations on a target namespace even when the identity it was pinned to was not authorized to modify that namespace. This affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16 and potentially older versions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 15:25 UTC
    CWE
    • CWE-266 - Incorrect privilege assignment
    References
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0.16.0 , < 0.16.1 (semver)
    Affected: 0.15.0 , < 0.15.7 (semver)
    Affected: 0.14.0 , < 0.14.11 (semver)
    Affected: 0.13.0 , < 0.13.16 (semver)
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 14:28
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93540",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T15:25:53.294940Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T16:22:25.780Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "Fleet",
              "product": "Rancher",
              "repo": "https://github.com/rancher/fleet/",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "0.16.1",
                  "status": "affected",
                  "version": "0.16.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.15.7",
                  "status": "affected",
                  "version": "0.15.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.14.11",
                  "status": "affected",
                  "version": "0.14.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.13.16",
                  "status": "affected",
                  "version": "0.13.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.16.1",
                      "versionStartIncluding": "0.16.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.15.7",
                      "versionStartIncluding": "0.15.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.14.11",
                      "versionStartIncluding": "0.14.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.13.16",
                      "versionStartIncluding": "0.13.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "g.mygenie@gmail.com"
            }
          ],
          "datePublic": "2026-09-28T14:28:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003eA privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the \u003ccode\u003enamespaceLabels\u003c/code\u003e and \u003ccode\u003enamespaceAnnotations\u003c/code\u003e options, the resulting namespace metadata update was not subject to the same authorization as the rest of the bundle\u0027s deployment. As a result, a bundle could change labels and annotations on a target namespace even when the identity it was pinned to was not authorized to modify that namespace.\u003c/div\u003e\u003cdiv\u003eThis affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16 and potentially older versions.\u003c/div\u003e"
                }
              ],
              "value": "A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorization as the rest of the bundle\u0027s deployment. As a result, a bundle could change labels and annotations on a target namespace even when the identity it was pinned to was not authorized to modify that namespace.\n\nThis affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16 and potentially older versions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-690",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-690 Metadata Spoofing"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-266",
                  "description": "CWE-266 Incorrect privilege assignment",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T14:45:42.336Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/rancher/fleet/security/advisories/GHSA-m93g-8438-2cgg"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Fleet applies namespace labels and annotations without the bundle\u0027s service account privileges",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-93540",
        "datePublished": "2026-09-28T14:45:42.336Z",
        "dateReserved": "2026-09-18T09:08:10.294Z",
        "dateUpdated": "2026-09-28T16:22:25.780Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93539 (GCVE-0-2026-93539)

    Vulnerability from cvelistv5 – Published: 2026-09-28 14:19 – Updated: 2026-09-28 16:22
    VLAI
    Title
    Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver
    Summary
    A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInterval field of a matching GitRepo resource in any namespace. A caller with network access to the webhook service and no Kubernetes credentials can therefore alter GitRepo configuration outside the namespaces they are authorized for.  This only affects SUSE Rancher Fleet 0.16 before 0.16.2, older versions are not affected.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 14:59 UTC
    CWE
    • CWE-306 - Missing authentication for critical function
    References
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0.16.0 , < 0.16.2 (semver)
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 14:16
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93539",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T14:59:38.674475Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T16:22:26.433Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "Fleet",
              "product": "Rancher",
              "repo": "https://github.com/rancher/fleet/",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "0.16.2",
                  "status": "affected",
                  "version": "0.16.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.16.2",
                      "versionStartIncluding": "0.16.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "https://github.com/Pig-Tail"
            }
          ],
          "datePublic": "2026-09-28T14:16:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A vulnerability was discovered in Fleet\u0027s Git webhook receiver (the \u003ccode\u003egitjob\u003c/code\u003e webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the \u003ccode\u003espec.pollingInterval\u003c/code\u003e field of a matching \u003ccode\u003eGitRepo\u003c/code\u003e resource in any namespace. A caller with network access to the webhook service and no Kubernetes credentials can therefore alter \u003ccode\u003eGitRepo\u003c/code\u003e configuration outside\u003cbr\u003e\nthe namespaces they are authorized for.\u0026nbsp; This only affects SUSE Rancher Fleet 0.16 before 0.16.2, older versions are not affected."
                }
              ],
              "value": "A vulnerability was discovered in Fleet\u0027s Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInterval field of a matching GitRepo resource in any namespace. A caller with network access to the webhook service and no Kubernetes credentials can therefore alter GitRepo configuration outside\n\nthe namespaces they are authorized for.\u00a0 This only affects SUSE Rancher Fleet 0.16 before 0.16.2, older versions are not affected."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-176",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-176 Configuration/Environment Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing authentication for critical function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T14:19:55.071Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/rancher/fleet/security/advisories/GHSA-8vfv-33cg-g75q"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-93539",
        "datePublished": "2026-09-28T14:19:55.071Z",
        "dateReserved": "2026-09-18T09:08:10.294Z",
        "dateUpdated": "2026-09-28T16:22:26.433Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93538 (GCVE-0-2026-93538)

    Vulnerability from cvelistv5 – Published: 2026-09-28 14:10 – Updated: 2026-09-28 16:22
    VLAI
    Title
    Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration in Fleet
    Summary
    A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster. This affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 15:46 UTC
    CWE
    • CWE-290 - Authentication bypass by spoofing
    • CWE-639 - Authorization bypass through User-Controlled key
    References
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0.16.0 , < 0.16.1 (semver)
    Affected: 0.15.0 , < 0.15.6 (semver)
    Affected: 0.14.0 , < 0.14.10 (semver)
    Affected: 0.13.0 , < 0.13.15 (semver)
    Affected: 0.12.0 , < 0.12.19 (semver)
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 14:05
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93538",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T15:46:41.479078Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T16:22:26.562Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "Fleet",
              "product": "Rancher",
              "repo": "https://github.com/rancher/fleet/",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "0.16.1",
                  "status": "affected",
                  "version": "0.16.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.15.6",
                  "status": "affected",
                  "version": "0.15.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.14.10",
                  "status": "affected",
                  "version": "0.14.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.13.15",
                  "status": "affected",
                  "version": "0.13.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.12.19",
                  "status": "affected",
                  "version": "0.12.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.16.1",
                      "versionStartIncluding": "0.16.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.15.6",
                      "versionStartIncluding": "0.15.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.14.10",
                      "versionStartIncluding": "0.14.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.13.15",
                      "versionStartIncluding": "0.13.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.12.19",
                      "versionStartIncluding": "0.12.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "https://github.com/Pig-Tail"
            }
          ],
          "datePublic": "2026-09-28T14:05:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated\u0026nbsp;cluster registration, cluster labels supplied by the registering agent, including labels in the reserved \u003ccode\u003emanagement.cattle.io/\u003c/code\u003e namespace such as the cluster display name label, were applied to the resulting upstream \u003ccode\u003eCluster\u003c/code\u003e object. Because Fleet resolves \u003ccode\u003eGitRepo\u003c/code\u003e and \u003ccode\u003eBundle\u003c/code\u003e targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster.\u003cbr\u003eThis affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions."
                }
              ],
              "value": "A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated\u00a0cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster.\nThis affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-122",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-122 Privilege Abuse"
                }
              ]
            },
            {
              "capecId": "CAPEC-195",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-195 Principal Spoof"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-290",
                  "description": "CWE-290 Authentication bypass by spoofing",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639 Authorization bypass through User-Controlled key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T14:10:21.720Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/rancher/fleet/security/advisories/GHSA-h9p5-fp5h-qpqr"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration in Fleet",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-93538",
        "datePublished": "2026-09-28T14:10:21.720Z",
        "dateReserved": "2026-09-18T09:08:10.294Z",
        "dateUpdated": "2026-09-28T16:22:26.562Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93537 (GCVE-0-2026-93537)

    Vulnerability from cvelistv5 – Published: 2026-09-28 13:29 – Updated: 2026-09-28 17:54
    VLAI
    Title
    Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle directory
    Summary
    A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include their contents in the generated Bundle resource. This can expose configuration or credential material that the user has no Kubernetes RBAC permission to read, including Helm registry credentials made available to the bundle-processing job when per-path Helm credentials are configured. This affects Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16, 0.12 before 0.12.20 and potentially older unsupported versions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 17:54 UTC
    CWE
    • CWE-23 - Relative path traversal
    References
    Impacted products
    Vendor Product Version
    SUSE Rancher Affected: 0.16.0 , < 0.16.2 (semver)
    Affected: 0.15.0 , < 0.15.7 (semver)
    Affected: 0.14.0 , < 0.14.11 (semver)
    Affected: 0.13.0 , < 0.13.16 (semver)
    Affected: 0.12.0 , < 0.12.20 (semver)
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 12:15
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93537",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T17:54:00.943037Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T17:54:22.754Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "Fleet",
              "product": "Rancher",
              "repo": "https://github.com/rancher/fleet/",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "0.16.2",
                  "status": "affected",
                  "version": "0.16.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.15.7",
                  "status": "affected",
                  "version": "0.15.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.14.11",
                  "status": "affected",
                  "version": "0.14.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.13.16",
                  "status": "affected",
                  "version": "0.13.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "0.12.20",
                  "status": "affected",
                  "version": "0.12.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.16.2",
                      "versionStartIncluding": "0.16.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.15.7",
                      "versionStartIncluding": "0.15.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.14.11",
                      "versionStartIncluding": "0.14.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.13.16",
                      "versionStartIncluding": "0.13.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.12.20",
                      "versionStartIncluding": "0.12.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "https://github.com/Pig-Tail"
            }
          ],
          "datePublic": "2026-09-28T12:15:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A user who can supply bundle content to a repository referenced by a \u003ccode\u003eGitRepo\u003c/code\u003e resource, for example through Git push access, or through permission to create or modify a \u003ccode\u003eGitRepo\u003c/code\u003e, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include their contents in the generated \u003ccode\u003eBundle\u003c/code\u003e resource. This can expose configuration or credential material that the user has no Kubernetes RBAC permission to read, including Helm registry credentials made available to the bundle-processing job when per-path Helm credentials are configured.\u003cbr\u003eThis affects Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16, 0.12 before 0.12.20 and potentially older unsupported versions."
                }
              ],
              "value": "A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include their contents in the generated Bundle resource. This can expose configuration or credential material that the user has no Kubernetes RBAC permission to read, including Helm registry credentials made available to the bundle-processing job when per-path Helm credentials are configured.\nThis affects Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16, 0.12 before 0.12.20 and potentially older unsupported versions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-122",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-122 Privilege Abuse"
                }
              ]
            },
            {
              "capecId": "CAPEC-180",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-180"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-23",
                  "description": "CWE-23 Relative path traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T13:29:10.263Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/rancher/fleet/security/advisories/GHSA-wpfm-r97v-3j4h"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle directory",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-93537",
        "datePublished": "2026-09-28T13:29:10.263Z",
        "dateReserved": "2026-09-18T09:08:10.294Z",
        "dateUpdated": "2026-09-28T17:54:22.754Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78424 (GCVE-0-2026-78424)

    Vulnerability from cvelistv5 – Published: 2026-09-28 11:44 – Updated: 2026-09-29 03:55
    VLAI
    Title
    OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution on Kubernetes Nodes
    Summary
    Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container, which can lead to the complete compromise of the worker node. This affects NeuVector 5.4 before 5.4.11, NeuVector 5.5 before 5.5.4, NeuVector 5.6 before 5.6.2 and potentially older versions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 00:00 UTC
    CWE
    • CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
    References
    Impacted products
    Vendor Product Version
    SUSE NeuVector Affected: 0 , < 5.4.11 (semver)
    Affected: 5.5.0 , < 5.5.4 (semver)
    Affected: 5.6.0 , < 5.6.2 (semver)
        cpe:2.3:a:suse:neuvector:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:neuvector:*:*:*:*:*:*:*:*
        cpe:2.3:a:suse:neuvector:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 11:39
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78424",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T03:55:17.618Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "neuvector",
              "product": "NeuVector",
              "repo": "https://github.com/neuvector/neuvector/",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "5.4.11",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.5.4",
                  "status": "affected",
                  "version": "5.5.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.6.2",
                  "status": "affected",
                  "version": "5.6.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:neuvector:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.11",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:neuvector:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.5.4",
                      "versionStartIncluding": "5.5.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:suse:neuvector:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.6.2",
                      "versionStartIncluding": "5.6.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Sergey Kanibor"
            }
          ],
          "datePublic": "2026-09-28T11:39:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector\u2019s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container, which can lead to the complete compromise of the worker node. This affects NeuVector 5.4 before 5.4.11, NeuVector 5.5 before 5.5.4, NeuVector 5.6 before 5.6.2 and potentially older versions."
                }
              ],
              "value": "Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector\u2019s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container, which can lead to the complete compromise of the worker node. This affects NeuVector 5.4 before 5.4.11, NeuVector 5.5 before 5.5.4, NeuVector 5.6 before 5.6.2 and potentially older versions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-549",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-549 Local Execution of Code"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T11:44:05.235Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/neuvector/neuvector/security/advisories/GHSA-vr77-8vmq-qfmj"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution on Kubernetes Nodes",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-78424",
        "datePublished": "2026-09-28T11:44:05.235Z",
        "dateReserved": "2026-08-24T15:33:13.665Z",
        "dateUpdated": "2026-09-29T03:55:17.618Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-94287 (GCVE-0-2026-94287)

    Vulnerability from cvelistv5 – Published: 2026-09-28 08:57 – Updated: 2026-09-28 13:31
    VLAI
    Title
    Denial of service via unsigned underflow in libXpm's write path
    Summary
    A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 13:05 UTC
    CWE
    • CWE-1050 - Excessive platform resource consumption within a loop
    References
    Impacted products
    Vendor Product Version
    x.org libXpm Affected: 0 , < 3.5.19 (rpm)
        cpe:2.3:a:x.org:libxpm:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 08:54
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-94287",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T13:05:04.782454Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T13:31:29.548Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libXpm",
              "product": "libXpm",
              "repo": "https://gitlab.freedesktop.org/xorg/lib/libxpm",
              "vendor": "x.org",
              "versions": [
                {
                  "lessThan": "3.5.19",
                  "status": "affected",
                  "version": "0",
                  "versionType": "rpm"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:x.org:libxpm:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.19",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "AISLE in partnership with Red Hat"
            }
          ],
          "datePublic": "2026-09-28T08:54:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A denial of service via unsigned underflow in libXpm\u0027s write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion."
                }
              ],
              "value": "A denial of service via unsigned underflow in libXpm\u0027s write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-92",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-92 Forced Integer Overflow"
                }
              ]
            },
            {
              "capecId": "CAPEC-130",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-130 Excessive Allocation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1050",
                  "description": "CWE-1050 Excessive platform resource consumption within a loop",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T08:57:24.943Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://gitlab.freedesktop.org/xorg/lib/libxpm/-/merge_requests/32/diffs?commit_id=3a68f818b1628d7ad96245b0f4d15a32a015b0ab"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Denial of service via unsigned underflow in libXpm\u0027s write path",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-94287",
        "datePublished": "2026-09-28T08:57:24.943Z",
        "dateReserved": "2026-09-21T09:33:25.369Z",
        "dateUpdated": "2026-09-28T13:31:29.548Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-94286 (GCVE-0-2026-94286)

    Vulnerability from cvelistv5 – Published: 2026-09-28 08:50 – Updated: 2026-09-30 13:02
    VLAI
    Title
    Out-of-bounds read in libXtst's RECORD reply parser
    Summary
    An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 12:58 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    x.org libXtst Affected: 0 , < 1.2.6 (rpm)
        cpe:2.3:a:x.org:libxtst:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 08:48
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-94286",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T12:58:55.309961Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T13:02:00.302Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libXtst",
              "product": "libXtst",
              "repo": "https://gitlab.freedesktop.org/xorg/lib/libxtst",
              "vendor": "x.org",
              "versions": [
                {
                  "lessThan": "1.2.6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "rpm"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:x.org:libxtst:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.2.6",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "AISLE in partnership with Red Hat"
            }
          ],
          "datePublic": "2026-09-28T08:48:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn out-of-bounds read in libXtst\u0027s RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.\u003c/p\u003e\u003cbr\u003e"
                }
              ],
              "value": "An out-of-bounds read in libXtst\u0027s RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-540",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-540 Overread Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-126",
                  "description": "CWE-126 Buffer over-read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T08:50:35.900Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://gitlab.freedesktop.org/xorg/lib/libxtst/-/merge_requests/10/diffs?commit_id=16023c86070e6af9407330deea3938fcef75815b"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Out-of-bounds read in libXtst\u0027s RECORD reply parser",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-94286",
        "datePublished": "2026-09-28T08:50:35.900Z",
        "dateReserved": "2026-09-21T09:33:25.369Z",
        "dateUpdated": "2026-09-30T13:02:00.302Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-94285 (GCVE-0-2026-94285)

    Vulnerability from cvelistv5 – Published: 2026-09-28 08:45 – Updated: 2026-09-30 12:55
    VLAI
    Title
    Out-of-bounds read in libX11's byte-oriented codeset parser
    Summary
    An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 12:52 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    x.org libX11 Affected: 0 , < 1.8.14 (rpm)
        cpe:2.3:a:x.org:libx11:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 08:43
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-94285",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T12:52:16.275635Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T12:55:05.396Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libX11",
              "product": "libX11",
              "repo": "https://gitlab.freedesktop.org/xorg/lib/libx11",
              "vendor": "x.org",
              "versions": [
                {
                  "lessThan": "1.8.14",
                  "status": "affected",
                  "version": "0",
                  "versionType": "rpm"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:x.org:libx11:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.8.14",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "AISLE in partnership with Red Hat"
            }
          ],
          "datePublic": "2026-09-28T08:43:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn out-of-bounds read in libX11\u0027s byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.\u003c/p\u003e\u003cbr\u003e"
                }
              ],
              "value": "An out-of-bounds read in libX11\u0027s byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-540",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-540 Overread Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "LOW",
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T08:45:47.752Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=980868483446f24f9658d26aa5bfa42f3da6dd3a"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Out-of-bounds read in libX11\u0027s byte-oriented codeset parser",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-94285",
        "datePublished": "2026-09-28T08:45:47.752Z",
        "dateReserved": "2026-09-21T09:33:25.369Z",
        "dateUpdated": "2026-09-30T12:55:05.396Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-94284 (GCVE-0-2026-94284)

    Vulnerability from cvelistv5 – Published: 2026-09-28 08:42 – Updated: 2026-09-30 12:48
    VLAI
    Title
    Out-of-bounds read vulnerability in libX11's XIM trigger-keyregistration parser.registration parser
    Summary
    An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 12:46 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    x.org libX11 Affected: 0 , < 1.8.14 (rpm)
        cpe:2.3:a:x.org:libx11:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 08:34
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-94284",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T12:46:23.332148Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T12:48:29.140Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libX11",
              "product": "libX11",
              "repo": "https://gitlab.freedesktop.org/xorg/lib/libx11",
              "vendor": "x.org",
              "versions": [
                {
                  "lessThan": "1.8.14",
                  "status": "affected",
                  "version": "0",
                  "versionType": "rpm"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:x.org:libx11:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.8.14",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "AISLE in partnership with Red Hat"
            }
          ],
          "datePublic": "2026-09-28T08:34:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn out-of-bounds read vulnerability in libX11\u0027s XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.\u003c/p\u003e\u003cbr\u003e"
                }
              ],
              "value": "An out-of-bounds read vulnerability in libX11\u0027s XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-540",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-540 Overread Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T08:42:56.885Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=1b7904002d212eed40949ccf4e8e7156f9fec0e2"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Out-of-bounds read vulnerability in libX11\u0027s XIM trigger-keyregistration parser.registration parser",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-94284",
        "datePublished": "2026-09-28T08:42:56.885Z",
        "dateReserved": "2026-09-21T09:33:25.369Z",
        "dateUpdated": "2026-09-30T12:48:29.140Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-94283 (GCVE-0-2026-94283)

    Vulnerability from cvelistv5 – Published: 2026-09-28 08:34 – Updated: 2026-09-30 12:44
    VLAI
    Title
    Out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser
    Summary
    An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 12:43 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    x.org libX11 Affected: 0 , < 1.8.14 (rpm)
        cpe:2.3:a:x.org:libx11:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 08:31
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-94283",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T12:43:54.129297Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T12:44:15.454Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libX11",
              "product": "libX11",
              "repo": "https://gitlab.freedesktop.org/xorg/lib/libx11",
              "vendor": "x.org",
              "versions": [
                {
                  "lessThan": "1.8.14",
                  "status": "affected",
                  "version": "0",
                  "versionType": "rpm"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:x.org:libx11:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.8.14",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "AISLE in partnership with Red Hat"
            }
          ],
          "datePublic": "2026-09-28T08:31:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn out-of-bounds read vulnerability in libX11\u0027s XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.\u003c/p\u003e\u003cbr\u003e"
                }
              ],
              "value": "An out-of-bounds read vulnerability in libX11\u0027s XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-540",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-540 Overread Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T08:34:14.230Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=42d0303f243002a9856c76060569a61893c670dd"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Out-of-bounds read vulnerability in libX11\u0027s XIM (X Input Method) attribute parser",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-94283",
        "datePublished": "2026-09-28T08:34:14.230Z",
        "dateReserved": "2026-09-21T09:33:25.369Z",
        "dateUpdated": "2026-09-30T12:44:15.454Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-94282 (GCVE-0-2026-94282)

    Vulnerability from cvelistv5 – Published: 2026-09-28 08:18 – Updated: 2026-09-30 12:41
    VLAI
    Title
    Out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion
    Summary
    An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 12:41 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    x.org libXi Affected: 0 , < 1.8.4 (rpm)
        cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 08:15
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-94282",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T12:41:02.923257Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T12:41:41.238Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libXi",
              "product": "libXi",
              "repo": "https://gitlab.freedesktop.org/xorg/lib/libxi",
              "vendor": "x.org",
              "versions": [
                {
                  "lessThan": "1.8.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "rpm"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.8.4",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "AISLE in partnership with Red Hat"
            }
          ],
          "datePublic": "2026-09-28T08:15:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn out-of-bounds read in libXi\u0027s XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client.\u003c/p\u003e\u003cbr\u003e"
                }
              ],
              "value": "An out-of-bounds read in libXi\u0027s XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-540",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-540 Overread Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 5.6,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T08:18:13.987Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=cecf160e9731fe01f3632f875f29ffcb598b052a"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Out-of-bounds read in libXi\u0027s XI2 enter/leave/focus cookie conversion",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-94282",
        "datePublished": "2026-09-28T08:18:13.987Z",
        "dateReserved": "2026-09-21T09:33:25.369Z",
        "dateUpdated": "2026-09-30T12:41:41.238Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-94281 (GCVE-0-2026-94281)

    Vulnerability from cvelistv5 – Published: 2026-09-24 16:23 – Updated: 2026-09-24 17:14
    VLAI
    Title
    Out-of-bounds read in libXi's XListInputDevices() class parsing
    Summary
    An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 17:14 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    x.org libXi Affected: 0 , < 1.8.4 (rpm)
        cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-24 16:22
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-94281",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T17:14:08.828973Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T17:14:17.652Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libXi",
              "product": "libXi",
              "repo": "https://gitlab.freedesktop.org/xorg/lib/libxi",
              "vendor": "x.org",
              "versions": [
                {
                  "lessThan": "1.8.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "rpm"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.8.4",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "AISLE-Report-PSIRTSUPT-14718"
            }
          ],
          "datePublic": "2026-09-24T16:22:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn out-of-bounds read in libXi\u0027s XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.\u003c/p\u003e\u003cbr\u003e"
                }
              ],
              "value": "An out-of-bounds read in libXi\u0027s XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-540",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-540 Overread Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-24T16:23:50.110Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=605f419d013153bf9e026cd100752ffbe930f3c1"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Out-of-bounds read in libXi\u0027s XListInputDevices() class parsing",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-94281",
        "datePublished": "2026-09-24T16:23:50.110Z",
        "dateReserved": "2026-09-21T09:33:25.369Z",
        "dateUpdated": "2026-09-24T17:14:17.652Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93545 (GCVE-0-2026-93545)

    Vulnerability from cvelistv5 – Published: 2026-09-24 16:20 – Updated: 2026-09-24 17:14
    VLAI
    Title
    Out-of-bounds read in libXi's XListInputDevices()
    Summary
    An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 17:14 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    x.org libXi Affected: 0 , < 1.8.4 (rpm)
        cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-24 16:18
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93545",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T17:14:35.552977Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T17:14:46.750Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libXi",
              "product": "libXi",
              "repo": "https://gitlab.freedesktop.org/xorg/lib/libxi",
              "vendor": "x.org",
              "versions": [
                {
                  "lessThan": "1.8.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "rpm"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.8.4",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "AISLE in partnership with Red Hat"
            }
          ],
          "datePublic": "2026-09-24T16:18:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn out-of-bounds read in libXi\u0027s XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.\u003c/p\u003e\u003cbr\u003e"
                }
              ],
              "value": "An out-of-bounds read in libXi\u0027s XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-540",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-540 Overread Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-24T16:20:35.334Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=234ce17d95c42d75f7f7fdb2bf7a24875451bc0a"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Out-of-bounds read in libXi\u0027s XListInputDevices()",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-93545",
        "datePublished": "2026-09-24T16:20:35.334Z",
        "dateReserved": "2026-09-18T09:08:10.295Z",
        "dateUpdated": "2026-09-24T17:14:46.750Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93544 (GCVE-0-2026-93544)

    Vulnerability from cvelistv5 – Published: 2026-09-24 16:13 – Updated: 2026-09-24 17:16
    VLAI
    Title
    Out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing
    Summary
    An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 17:16 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    x.org libXi Affected: 0 , < 1.8.4 (rpm)
        cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-24 16:11
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93544",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T17:16:25.106730Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T17:16:35.659Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libXi",
              "product": "libXi",
              "repo": "https://gitlab.freedesktop.org/xorg/lib/libxi",
              "vendor": "x.org",
              "versions": [
                {
                  "lessThan": "1.8.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "rpm"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.8.4",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "AISLE in partnership with Red Hat"
            }
          ],
          "datePublic": "2026-09-24T16:11:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn out-of-bounds read in libXi\u0027s XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.\u003c/p\u003e\u003cbr\u003e"
                }
              ],
              "value": "An out-of-bounds read in libXi\u0027s XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-540",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-540 Overread Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-24T16:13:29.067Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=a88a341135b79f6ed450f481e4a5d6ba502382af"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Out-of-bounds read in libXi\u0027s XI2 XIQueryDevice reply parsing",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-93544",
        "datePublished": "2026-09-24T16:13:29.067Z",
        "dateReserved": "2026-09-18T09:08:10.295Z",
        "dateUpdated": "2026-09-24T17:16:35.659Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93543 (GCVE-0-2026-93543)

    Vulnerability from cvelistv5 – Published: 2026-09-24 16:09 – Updated: 2026-09-24 17:17
    VLAI
    Title
    Out-of-bounds read in libXi's XI2 class parser
    Summary
    An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 17:16 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    x.org libXi Affected: 0 , < 1.8.4 (rpm)
        cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-24 16:06
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93543",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T17:16:58.657195Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T17:17:07.094Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libXi",
              "product": "libXi",
              "repo": "https://gitlab.freedesktop.org/xorg/lib/libxi",
              "vendor": "x.org",
              "versions": [
                {
                  "lessThan": "1.8.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "rpm"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.8.4",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "AISLE in partnership with Red Hat"
            }
          ],
          "datePublic": "2026-09-24T16:06:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn out-of-bounds read in libXi\u0027s XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.\u003c/p\u003e"
                }
              ],
              "value": "An out-of-bounds read in libXi\u0027s XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-540",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-540 Overread Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-24T16:09:51.221Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=e2089ab748828273f916bbffd4e65b506aa50fdc"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Out-of-bounds read in libXi\u0027s XI2 class parser",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-93543",
        "datePublished": "2026-09-24T16:09:51.221Z",
        "dateReserved": "2026-09-18T09:08:10.295Z",
        "dateUpdated": "2026-09-24T17:17:07.094Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93542 (GCVE-0-2026-93542)

    Vulnerability from cvelistv5 – Published: 2026-09-24 16:03 – Updated: 2026-09-24 17:18
    VLAI
    Title
    Out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes()
    Summary
    An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 17:18 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    x.org libXi Affected: 0 , < 1.8.4 (rpm)
        cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-24 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93542",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T17:18:15.511330Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T17:18:26.217Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libXi",
              "product": "libXi",
              "repo": "https://gitlab.freedesktop.org/xorg/lib/libxi",
              "vendor": "x.org",
              "versions": [
                {
                  "lessThan": "1.8.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "rpm"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.8.4",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "AISLE in partnership with Red Hat"
            }
          ],
          "datePublic": "2026-09-24T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An o\u003cspan\u003eut-of-bounds read in libXi\u0027s XI2 class parsing via size_classes()\u003c/span\u003e\u003cspan\u003e and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client.\u003c/span\u003e"
                }
              ],
              "value": "An out-of-bounds read in libXi\u0027s XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-540",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-540 Overread Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-24T16:03:00.095Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=f499944ad595b9bd7e7571c810842244caf150aa"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Out-of-bounds read in libXi\u0027s XI2 class parsing via size_classes() and copy_classes()",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-93542",
        "datePublished": "2026-09-24T16:03:00.095Z",
        "dateReserved": "2026-09-18T09:08:10.294Z",
        "dateUpdated": "2026-09-24T17:18:26.217Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93541 (GCVE-0-2026-93541)

    Vulnerability from cvelistv5 – Published: 2026-09-24 15:58 – Updated: 2026-09-24 17:19
    VLAI
    Title
    Out-of-bounds read in libXi's XQueryDeviceState()
    Summary
    An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 17:19 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    X.org libXi Affected: 0 , < 1.8.4 (rpm)
        cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93541",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T17:19:51.914504Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T17:19:59.080Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libXi",
              "product": "libXi",
              "repo": "https://gitlab.freedesktop.org/xorg/lib/libxi",
              "vendor": "X.org",
              "versions": [
                {
                  "lessThan": "1.8.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "rpm"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:x.org:libxi:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.8.4",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "AISLE in partnership with Red Hat"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An out\u003cspan\u003e\u003cspan\u003e-of-bounds read in libXi\u0027s XQueryDeviceState() in libXi before 1.8.4 could be used by a\u0026nbsp;\u003c/span\u003e\u003c/span\u003e"
                }
              ],
              "value": "An out-of-bounds read in libXi\u0027s XQueryDeviceState() in libXi before 1.8.4 could be used by a"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-540",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-540 Overread Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-24T15:58:58.788Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=7b6fffd13fd3914e0b39f3a4f131913da7f066e7"
            }
          ],
          "source": {
            "defect": [
              "AISLE in partnership with Red Hat"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Out-of-bounds read in libXi\u0027s XQueryDeviceState()",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-93541",
        "datePublished": "2026-09-24T15:58:58.788Z",
        "dateReserved": "2026-09-18T09:08:10.294Z",
        "dateUpdated": "2026-09-24T17:19:59.080Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88807 (GCVE-0-2026-88807)

    Vulnerability from cvelistv5 – Published: 2026-09-21 13:49 – Updated: 2026-09-22 03:55
    VLAI
    Title
    libXrender RenderQueryPictFormats Reply Heap-based Buffer Overflow
    Summary
    A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-21 00:00 UTC
    CWE
    • CWE-122 - Heap-based buffer overflow
    References
    Impacted products
    Vendor Product Version
    X.org libXrender Affected: 0 , < 0.9.13 (rpmver)
        cpe:2.3:a:x.org:libxrender:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-18 13:42
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88807",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-21T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T03:55:46.845Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libXrender",
              "product": "libXrender",
              "repo": "https://gitlab.freedesktop.org/xorg/lib/libxrender",
              "vendor": "X.org",
              "versions": [
                {
                  "lessThan": "0.9.13",
                  "status": "affected",
                  "version": "0",
                  "versionType": "rpmver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:x.org:libxrender:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "0.9.13",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Adam Bedard working with TrendAI Zero Day Initiative"
            },
            {
              "lang": "en",
              "type": "tool",
              "value": "Claude:claude-opus-4-6"
            }
          ],
          "datePublic": "2026-09-18T13:42:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A heap overflow in libXrender before 0.9.13 in\u0026nbsp;RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients."
                }
              ],
              "value": "A heap overflow in libXrender before 0.9.13 in\u00a0RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-242",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-242 Code Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.9,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122 Heap-based buffer overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-21T13:49:21.327Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://gitlab.freedesktop.org/xorg/lib/libxrender/-/merge_requests/19"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "libXrender RenderQueryPictFormats Reply Heap-based Buffer Overflow",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-88807",
        "datePublished": "2026-09-21T13:49:21.327Z",
        "dateReserved": "2026-09-10T08:35:07.010Z",
        "dateUpdated": "2026-09-22T03:55:46.845Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-88806 (GCVE-0-2026-88806)

    Vulnerability from cvelistv5 – Published: 2026-09-21 13:42 – Updated: 2026-09-22 03:55
    VLAI
    Title
    libX11 XkbGetMap Reply Heap-based Buffer Overflow
    Summary
    A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-21 00:00 UTC
    CWE
    • CWE-122 - Heap-based buffer overflow
    References
    Impacted products
    Vendor Product Version
    x.org libX11 Affected: 0 , < 1.8.14 (semver)
        cpe:2.3:a:x.org:libx11:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-18 13:33
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-88806",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-21T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T03:55:48.003Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libX11",
              "product": "libX11",
              "repo": "https://gitlab.freedesktop.org/xorg/lib/libx11",
              "vendor": "x.org",
              "versions": [
                {
                  "lessThan": "1.8.14",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:x.org:libx11:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.8.14",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Adam Bedard working with TrendAI Zero Day Initiative"
            },
            {
              "lang": "en",
              "type": "tool",
              "value": "Claude:claude-opus-4-6"
            }
          ],
          "datePublic": "2026-09-18T13:33:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003eA malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.\u003c/div\u003e"
                }
              ],
              "value": "A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-242",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-242 Code Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122 Heap-based buffer overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-21T13:42:12.700Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "libX11 XkbGetMap Reply Heap-based Buffer Overflow",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-88806",
        "datePublished": "2026-09-21T13:42:12.700Z",
        "dateReserved": "2026-09-10T08:35:07.010Z",
        "dateUpdated": "2026-09-22T03:55:48.003Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78427 (GCVE-0-2026-78427)

    Vulnerability from cvelistv5 – Published: 2026-09-17 09:33 – Updated: 2026-09-28 12:06
    VLAI
    Title
    Admission Control Bypass via Hardcoded Sidecar Image Exemption
    Summary
    The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can evade admission deny rules simply by naming their image path after one of these sidecar images.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 12:10 UTC
    CWE
    • CWE-807 - Reliance on Untrusted Inputs in a Security Decision
    Impacted products
    Vendor Product Version
    SUSE github.com/neuvector/neuvector Affected: 0 , ≤ v5.6.1 (custom)
        cpe:2.3:a:suse:github.com_neuvector_neuvector:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 12:05
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78427",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T12:10:23.202569Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T12:10:55.525Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "github.com/neuvector/neuvector",
              "vendor": "SUSE",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "5.6.2",
                      "status": "unaffected"
                    },
                    {
                      "at": "5.5.4",
                      "status": "unaffected"
                    },
                    {
                      "at": "5.4.11",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "v5.6.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:github.com_neuvector_neuvector:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "v5.6.1",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "datePublic": "2026-09-28T12:05:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cspan\u003eThe NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can evade admission deny rules simply by naming their image path after one of these sidecar images.\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can evade admission deny rules simply by naming their image path after one of these sidecar images."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-807",
                  "description": "CWE-807 Reliance on Untrusted Inputs in a Security Decision",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T12:06:08.210Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "url": "https://github.com/neuvector/neuvector/security/advisories/GHSA-78r4-3wfq-r2xm"
            },
            {
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-78427"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Admission Control Bypass via Hardcoded Sidecar Image Exemption",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-78427",
        "datePublished": "2026-09-17T09:33:26.318Z",
        "dateReserved": "2026-08-24T15:33:13.665Z",
        "dateUpdated": "2026-09-28T12:06:08.210Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78425 (GCVE-0-2026-78425)

    Vulnerability from cvelistv5 – Published: 2026-09-17 09:32 – Updated: 2026-09-28 12:04
    VLAI
    Title
    SAML Audience Confusion Allows Cross-SP Authentication
    Summary
    Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SSO. The IdP issues an assertion to them. If that assertion is presented to NeuVector, NeuVector accepts it because the only thing distinguishing "an assertion for NeuVector" from "an assertion for the wiki" is the element, and the `NotInAudience` warning that reports the mismatch is never read.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 12:12 UTC
    CWE
    • CWE-287 - Improper Authentication
    Impacted products
    Vendor Product Version
    SUSE github.com/neuvector/neuvector Affected: 0 , ≤ v5.6.1 (custom)
        cpe:2.3:a:suse:github.com_neuvector_neuvector:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 12:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78425",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T12:12:10.344911Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T12:13:08.680Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "github.com/neuvector/neuvector",
              "vendor": "SUSE",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "5.6.2",
                      "status": "unaffected"
                    },
                    {
                      "at": "5.5.4",
                      "status": "unaffected"
                    },
                    {
                      "at": "5.4.11",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "v5.6.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:github.com_neuvector_neuvector:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "v5.6.1",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "datePublic": "2026-09-28T12:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cspan\u003eAuthorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SSO. The IdP issues an assertion to them. If that assertion is presented to NeuVector, NeuVector accepts it because the only thing distinguishing \"an assertion for NeuVector\" from \"an assertion for the wiki\" is the element, and the `NotInAudience` warning that reports the mismatch is never read.\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SSO. The IdP issues an assertion to them. If that assertion is presented to NeuVector, NeuVector accepts it because the only thing distinguishing \"an assertion for NeuVector\" from \"an assertion for the wiki\" is the element, and the `NotInAudience` warning that reports the mismatch is never read."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 7.6,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287 Improper Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T12:04:24.695Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/neuvector/neuvector/security/advisories/GHSA-wgg5-24xq-px35"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-78425"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "SAML Audience Confusion Allows Cross-SP Authentication",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-78425",
        "datePublished": "2026-09-17T09:32:21.383Z",
        "dateReserved": "2026-08-24T15:33:13.665Z",
        "dateUpdated": "2026-09-28T12:04:24.695Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78426 (GCVE-0-2026-78426)

    Vulnerability from cvelistv5 – Published: 2026-09-17 09:28 – Updated: 2026-09-28 12:03
    VLAI
    Title
    Logout bypass via alternate JWT spelling
    Summary
    The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 12:40 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    SUSE neuvector Affected: 0 , ≤ v5.6.1 (custom)
        cpe:2.3:a:suse:neuvector:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78426",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T12:40:12.782525Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T12:40:32.383Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "neuvector",
              "product": "neuvector",
              "repo": "https://github.com/neuvector/neuvector/security/",
              "vendor": "SUSE",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "5.6.2",
                      "status": "unaffected"
                    },
                    {
                      "at": "5.5.4",
                      "status": "unaffected"
                    },
                    {
                      "at": "5.4.11",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "v5.6.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:neuvector:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "v5.6.1",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cspan\u003eThe NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 2,
                "baseSeverity": "LOW",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863 Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T12:03:54.563Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/neuvector/neuvector/security/advisories/GHSA-wcx5-mq6c-c54j"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-78426"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Logout bypass via alternate JWT spelling",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-78426",
        "datePublished": "2026-09-17T09:28:19.683Z",
        "dateReserved": "2026-08-24T15:33:13.665Z",
        "dateUpdated": "2026-09-28T12:03:54.563Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78428 (GCVE-0-2026-78428)

    Vulnerability from cvelistv5 – Published: 2026-09-17 09:19 – Updated: 2026-09-28 12:07
    VLAI
    Title
    Flaw in Neuvector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
    Summary
    For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 12:15 UTC
    CWE
    Impacted products
    Vendor Product Version
    SUSE neuvector Affected: <5.6.1 (custom)
        cpe:2.3:a:suse:neuvector:_5.6.1:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-28 12:06
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78428",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T12:15:03.788838Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-384",
                    "description": "CWE-384 Session Fixation",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T15:16:41.723Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "neuvector",
              "product": "neuvector",
              "vendor": "SUSE",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c5.6.1",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:suse:neuvector:_5.6.1:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "datePublic": "2026-09-28T12:06:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cspan\u003eFor users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user\u0027s authenticated session when multiple SSO login attempts occur concurrently\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user\u0027s authenticated session when multiple SSO login attempts occur concurrently"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T12:07:55.498Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/neuvector/neuvector/security/advisories/GHSA-c6rx-pmvf-m3jx"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=1279937"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Flaw in Neuvector can result in one user receiving another user\u0027s authenticated session when multiple SSO login attempts occur concurrently",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-78428",
        "datePublished": "2026-09-17T09:19:21.262Z",
        "dateReserved": "2026-08-24T15:33:13.665Z",
        "dateUpdated": "2026-09-28T12:07:55.498Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-44940 (GCVE-0-2026-44940)

    Vulnerability from cvelistv5 – Published: 2026-09-17 06:43 – Updated: 2026-09-29 16:07
    VLAI
    Title
    Service token exposure and potential privilege escalation in SUSE Observability
    Summary
    The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 12:34 UTC
    CWE
    • CWE-312 - Cleartext Storage of Sensitive Information
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    Impacted products
    Vendor Product Version
    SUSE SUSE Observability Affected: 0 , < 2.13.6 (custom)
    Affected: 2.14.0 , < 2.14.2 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-44940",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T12:34:04.290434Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T16:07:34.098Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "rancher-extension-stackstate",
              "product": "SUSE Observability",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.13.6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2.14.2",
                  "status": "affected",
                  "version": "2.14.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment.\u003c/p\u003e"
                }
              ],
              "value": "The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.7,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-312",
                  "description": "CWE-312: Cleartext Storage of Sensitive Information",
                  "lang": "en",
                  "type": "CWE"
                },
                {
                  "cweId": "CWE-200",
                  "description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T06:43:19.297Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44940"
            },
            {
              "url": "https://github.com/StackVista/rancher-extension-stackstate/security/advisories/GHSA-7c27-jc6w-pw95"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Service token exposure and potential privilege escalation in SUSE Observability",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eRevoke the existing service token inside SUSE Observability. Generate a new service token assigned to the `stackstate-guest` role (which enforces read-only access) rather than the default `stackstate-k8s-troubleshooter` role.\u003c/p\u003e"
                }
              ],
              "value": "Revoke the existing service token inside SUSE Observability. Generate a new service token assigned to the `stackstate-guest` role (which enforces read-only access) rather than the default `stackstate-k8s-troubleshooter` role."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-44940",
        "datePublished": "2026-09-17T06:43:19.297Z",
        "dateReserved": "2026-05-08T12:29:48.968Z",
        "dateUpdated": "2026-09-29T16:07:34.098Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-44950 (GCVE-0-2026-44950)

    Vulnerability from cvelistv5 – Published: 2026-09-10 08:19 – Updated: 2026-09-10 18:26
    VLAI
    Title
    fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2
    Summary
    fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation. A malicious font server can send overlapping source offsets -- for example 1000 glyphs each referencing {position:0, length:64} with nbytes=64. Each individual source range passes the existing validation, but the cumulative writes total 64000 bytes into a 64-byte destination buffer. This is a heap buffer overflow with attacker-controlled content.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 17:19 UTC
    CWE
    • CWE-122 - Heap-based Buffer Overflow
    Impacted products
    Vendor Product Version
    SUSE Container suse/kiosk/tigervnc-x11vnc:1.14-63.8 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Container suse/kiosk/xorg:21.1-83.7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Azure-3P Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-BYOS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-BYOS-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-BYOS-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-BYOS-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-BYOS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-BYOS-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-BYOS-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-BYOS-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAPCAL Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAPCAL-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAPCAL-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAPCAL-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Azure-3P Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-BYOS-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-BYOS-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-BYOS-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-GCE-3P Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-BYOS-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-BYOS-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-BYOS-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAPCAL-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAPCAL-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAPCAL-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-Azure Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-Azure-3P Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-BYOS-Azure Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-BYOS-EC2 Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-BYOS-GCE Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-GCE Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-GCE-3P Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAPCAL-GCE Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-Azure-SAP-BYOS Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-Azure-SAP-On-Demand Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-EC2-SAP-BYOS Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-EC2-SAP-On-Demand Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-GCE-SAP-BYOS Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-GCE-SAP-On-Demand Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Liberty Linux 10 Affected: ? , < 2.0.6-5.el10_2.3 (custom)
    Create a notification for this product.
    SUSE SUSE Liberty Linux 8 Affected: ? , < 2.0.3-2.el8_10.3 (custom)
    Create a notification for this product.
    SUSE SUSE Liberty Linux 9 Affected: ? , < 2.0.3-12.el9_8.3 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Desktop 15 SP7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Module for Basesystem 15 SP7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 15 SP7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 12 SP5-LTSS Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 15 SP4-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 15 SP5-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 15 SP6-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 16.0 Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP applications 16.0 Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server LTSS Extended Security 12 SP5 Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP4 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP5 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP6 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Manager Proxy LTS 4.3 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Manager Retail Branch Server LTS 4.3 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Manager Server LTS 4.3 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE openSUSE Leap 16.0 Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE openSUSE Tumbleweed Affected: ? , < 2.0.7-3.1 (custom)
    Create a notification for this product.
    libXfont libXfont Affected: ? , ≤ 2.0.8 (custom)
    Create a notification for this product.
    Date Public
    2026-08-05 08:17
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-44950",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T17:19:50.287306Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-122",
                    "description": "CWE-122 Heap-based Buffer Overflow",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T18:26:50.408Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Container suse/kiosk/tigervnc-x11vnc:1.14-63.8",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Container suse/kiosk/xorg:21.1-83.7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Azure-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAPCAL",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAPCAL-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAPCAL-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAPCAL-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Azure-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-GCE-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAPCAL-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAPCAL-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAPCAL-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-Azure-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-GCE-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAPCAL-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-Azure-SAP-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-Azure-SAP-On-Demand",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-EC2-SAP-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-EC2-SAP-On-Demand",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-GCE-SAP-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-GCE-SAP-On-Demand",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2",
              "product": "SUSE Liberty Linux 10",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.6-5.el10_2.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Liberty Linux 10",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.6-5.el10_2.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2",
              "product": "SUSE Liberty Linux 8",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-2.el8_10.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Liberty Linux 8",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-2.el8_10.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2",
              "product": "SUSE Liberty Linux 9",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-12.el9_8.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Liberty Linux 9",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-12.el9_8.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Desktop 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Desktop 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Module for Basesystem 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Module for Basesystem 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 12 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 15 SP4-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 15 SP4-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 15 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 15 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 15 SP6-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 15 SP6-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP applications 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP applications 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server LTSS Extended Security 12 SP5",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP4",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP4",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP5",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP5",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP6",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP6",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Manager Proxy LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Manager Proxy LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Manager Retail Branch Server LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Manager Retail Branch Server LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Manager Server LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Manager Server LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "openSUSE Leap 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "openSUSE Leap 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "openSUSE Tumbleweed",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-3.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2-32bit",
              "product": "openSUSE Tumbleweed",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-3.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "openSUSE Tumbleweed",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-3.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel-32bit",
              "product": "openSUSE Tumbleweed",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-3.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont",
              "product": "libXfont",
              "vendor": "libXfont",
              "versions": [
                {
                  "lessThanOrEqual": "2.0.8",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "zx (Jace)"
            }
          ],
          "datePublic": "2026-08-05T08:17:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cpre\u003efs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph\u0027s bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation.\n\nA malicious font server can send overlapping source offsets -- for example 1000 glyphs each referencing {position:0, length:64} with nbytes=64. Each individual source range passes the existing validation, but the cumulative writes total 64000 bytes into a 64-byte destination buffer. This is a heap buffer overflow with attacker-controlled content.\u003c/pre\u003e"
                }
              ],
              "value": "fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph\u0027s bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation.\n\nA malicious font server can send overlapping source offsets -- for example 1000 glyphs each referencing {position:0, length:64} with nbytes=64. Each individual source range passes the existing validation, but the cumulative writes total 64000 bytes into a 64-byte destination buffer. This is a heap buffer overflow with attacker-controlled content."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 9.5,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:19:55.462Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44950"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-44950",
        "datePublished": "2026-09-10T08:19:55.462Z",
        "dateReserved": "2026-05-08T12:29:48.969Z",
        "dateUpdated": "2026-09-10T18:26:50.408Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-59679 (GCVE-0-2026-59679)

    Vulnerability from cvelistv5 – Published: 2026-09-10 08:15 – Updated: 2026-09-10 12:45
    VLAI
    Title
    fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2
    Summary
    fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked. A malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 12:44 UTC
    CWE
    Impacted products
    Vendor Product Version
    SUSE Container suse/kiosk/tigervnc-x11vnc:1.14-63.8 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Container suse/kiosk/xorg:21.1-83.7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Azure-3P Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-BYOS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-BYOS-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-BYOS-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-BYOS-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-BYOS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-BYOS-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-BYOS-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-BYOS-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAP-Hardened-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAPCAL Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAPCAL-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAPCAL-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP6-SAPCAL-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Azure-3P Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-BYOS-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-BYOS-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-BYOS-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-GCE-3P Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-BYOS-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-BYOS-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-BYOS-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAP-Hardened-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAPCAL-Azure Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAPCAL-EC2 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES15-SP7-SAPCAL-GCE Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-Azure Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-Azure-3P Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-BYOS-Azure Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-BYOS-EC2 Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-BYOS-GCE Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-GCE Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAP-GCE-3P Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES-SAPCAL-GCE Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-Azure-SAP-BYOS Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-Azure-SAP-On-Demand Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-EC2-SAP-BYOS Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-EC2-SAP-On-Demand Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-GCE-SAP-BYOS Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE Image SLES12-SP5-GCE-SAP-On-Demand Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Liberty Linux 10 Affected: ? , < 2.0.6-5.el10_2.3 (custom)
    Create a notification for this product.
    SUSE SUSE Liberty Linux 8 Affected: ? , < 2.0.3-2.el8_10.3 (custom)
    Create a notification for this product.
    SUSE SUSE Liberty Linux 9 Affected: ? , < 2.0.3-12.el9_8.3 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Desktop 15 SP7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Module for Basesystem 15 SP7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 15 SP7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP7 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 12 SP5-LTSS Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 15 SP4-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 15 SP5-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 15 SP6-LTSS Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server 16.0 Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP applications 16.0 Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server LTSS Extended Security 12 SP5 Affected: ? , < 2.0.3-3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP4 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP5 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Linux Enterprise Server for SAP Applications 15 SP6 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Manager Proxy LTS 4.3 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Manager Retail Branch Server LTS 4.3 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE SUSE Manager Server LTS 4.3 Affected: ? , < 2.0.3-150000.3.6.1 (custom)
    Create a notification for this product.
    SUSE openSUSE Leap 16.0 Affected: ? , < 2.0.7-160000.5.1 (custom)
    Create a notification for this product.
    SUSE openSUSE Tumbleweed Affected: ? , < 2.0.7-3.1 (custom)
    Create a notification for this product.
    libXfont2 libXfont2 Affected: ? , ≤ 2.0.8 (custom)
    Create a notification for this product.
    Date Public
    2026-08-05 08:10
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-59679",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T12:44:48.987855Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-787",
                    "description": "CWE-787 Out-of-bounds Write",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T12:45:33.969Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Container suse/kiosk/tigervnc-x11vnc:1.14-63.8",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Container suse/kiosk/xorg:21.1-83.7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Azure-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAP-Hardened-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAPCAL",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAPCAL-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAPCAL-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP6-SAPCAL-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Azure-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-GCE-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAP-Hardened-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAPCAL-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAPCAL-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES15-SP7-SAPCAL-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-Azure-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-BYOS-Azure",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-BYOS-EC2",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-BYOS-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAP-GCE-3P",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES-SAPCAL-GCE",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-Azure-SAP-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-Azure-SAP-On-Demand",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-EC2-SAP-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-EC2-SAP-On-Demand",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-GCE-SAP-BYOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "Image SLES12-SP5-GCE-SAP-On-Demand",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2",
              "product": "SUSE Liberty Linux 10",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.6-5.el10_2.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Liberty Linux 10",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.6-5.el10_2.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2",
              "product": "SUSE Liberty Linux 8",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-2.el8_10.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Liberty Linux 8",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-2.el8_10.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2",
              "product": "SUSE Liberty Linux 9",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-12.el9_8.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Liberty Linux 9",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-12.el9_8.3",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Desktop 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Desktop 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Module for Basesystem 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Module for Basesystem 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP7",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 12 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 15 SP4-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 15 SP4-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 15 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 15 SP5-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 15 SP6-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 15 SP6-LTSS",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP applications 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP applications 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server LTSS Extended Security 12 SP5",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP4",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP4",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP5",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP5",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP6",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP6",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Manager Proxy LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Manager Proxy LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Manager Retail Branch Server LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Manager Retail Branch Server LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "SUSE Manager Server LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "SUSE Manager Server LTS 4.3",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.3-150000.3.6.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "openSUSE Leap 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "openSUSE Leap 16.0",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-160000.5.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2",
              "product": "openSUSE Tumbleweed",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-3.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-2-32bit",
              "product": "openSUSE Tumbleweed",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-3.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel",
              "product": "openSUSE Tumbleweed",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-3.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2-devel-32bit",
              "product": "openSUSE Tumbleweed",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "2.0.7-3.1",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageName": "libXfont2",
              "product": "libXfont2",
              "vendor": "libXfont2",
              "versions": [
                {
                  "lessThanOrEqual": "2.0.8",
                  "status": "affected",
                  "version": "?",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "zx (Jace)"
            }
          ],
          "datePublic": "2026-08-05T08:10:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cpre\u003efs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked.\u003cbr\u003eA malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes. \u003c/pre\u003e"
                }
              ],
              "value": "fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked.\nA malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.2,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-10T08:15:24.892Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-59679"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2026-59679",
        "datePublished": "2026-09-10T08:15:24.892Z",
        "dateReserved": "2026-07-06T11:59:28.119Z",
        "dateUpdated": "2026-09-10T12:45:33.969Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-46808 (GCVE-0-2025-46808)

    Vulnerability from cvelistv5 – Published: 2026-09-09 08:25 – Updated: 2026-09-10 14:06
    VLAI
    Title
    Sensitive information is leaked into NeuVector’s manager container logs
    Summary
    An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 14:05 UTC
    CWE
    • CWE-532 - Insertion of Sensitive Information into Log File
    Impacted products
    Vendor Product Version
    SUSE neuvector Affected: 0 , < 5.4.5 (semver)
    Create a notification for this product.
    Date Public
    2025-11-07 09:21
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-46808",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T14:05:27.065483Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T14:06:23.527Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "manager",
              "product": "neuvector",
              "vendor": "SUSE",
              "versions": [
                {
                  "lessThan": "5.4.5",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "datePublic": "2025-11-07T09:21:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003eAn Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container\u2019s log\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cp\u003eThis issue affects neuvector: before 5.4.5.\u003c/p\u003e"
                }
              ],
              "value": "An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container\u2019s log\n\n\n\n\n\n\nThis issue affects neuvector: before 5.4.5."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-532",
                  "description": "CWE-532: Insertion of Sensitive Information into Log File",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-09T08:25:42.467Z",
            "orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
            "shortName": "suse"
          },
          "references": [
            {
              "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-46808"
            },
            {
              "url": "https://github.com/neuvector/manager/security/advisories/GHSA-fggw-hv56-8m6r"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Sensitive information is leaked into NeuVector\u2019s manager container logs",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb",
        "assignerShortName": "suse",
        "cveId": "CVE-2025-46808",
        "datePublished": "2026-09-09T08:25:42.467Z",
        "dateReserved": "2025-04-30T11:28:04.728Z",
        "dateUpdated": "2026-09-10T14:06:23.527Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }