OPENSUSE-SU-2026:21866-1
Vulnerability from csaf_opensuse - Published: 2026-09-16 15:14 - Updated: 2026-09-17 17:44Summary
Security update for chirp
Severity
Important
Notes
Title of the patch: Security update for chirp
Description of the patch: This update for chirp fixes the following issues:
Changes in chirp:
- Update to version 20260911:
* ftm300d: Experimental Yaesu FTM-300DR driver
* Update Ukrainian localization
* ar8200: Fix importing memories with AM mode
* Unify Baofeng setting descriptions across drivers
* Add Yaesu FT5D
* uvb5: Fix Reverse setting
- Update to version 20260904:
* Fix RB28/RB628 tone and DTCS index mapping
* Retevis RB28/RB628: Fix Busy Channel Lockout display
* various bug fixes
- Update to version 20260821:
* Add Kenwood NX-800 driver
* CVE-2026-78136: kenwood_itm: Fix DCS parsing (boo#1280123)
* tmd710: various bug fixes
* Add TK-3180E support
* tk8180: various updates
* Support Shift+F10 convention for context menu in memedit
* Add Baofeng BF-T20, BF-T20FRS setting descriptions
* Add QYT KT-8900 setting documentation
* Add user-friendly Baofeng UV-5R setting descriptions
- Update to version 20260626:
* uvk5_egzumer: Fix battery_text and mic_bar never being saved
* Fix open filter translated string
- Update to version 20260619:
* Add Baofeng BF-5RH as alias of UV-5RH
* locale: Added Czech translation
* generic_csv: Fix ImmutableValueError when exporting special memories
- Update to version 20260612:
* Add test image for Bajeton BJ7800
* Update RT-920 test image for FM,AM & HF memories
* Add new model Bajeton BJ7800 as a sub-class of RT-920
- Update to version 20260605:
* Update boot, zone, scan and alarm channels on channel deletion
* Add GM-15Pro extended UHF range
- Update to version 20260529:
* Fix RT-900 non-BT, increase to 999 channels.
* Fix escape character in log message for UV-5R Mini
- Update to version 20260522:
* tdh8: Fix loading out-of-range group code values
* baofeng_uv17Pro: Fix uploading over BLE for supported models
* Add BLE serial detection
* mp31: Add support for Baofeng MP31
- Update to version 20260515:
* ha2: Fix defaulting empty memories to sane values
- Update to version 20260508:
* Don't complain about incompatible tones on import if no tone mode selected
* ic2730: Add IC-2730E (European variant) support
* ar8200: Add new driver for AOR AR8200
* Updated Italian Translation
- Update to version 20260501:
* tdh8: Fix VFO A/B BCL setting not reading properly
* tdh8: Add offset dir in VFO settings and fix VFO TX freq
* h777v4: Fix detected models
- Update to version 20260425:
* Use common "no response" exception in drivers
* vx150: Add driver for Vertex Standard VX-150
* Update 935 and XS20 power handling
* Fix 935/XS20 new channel creation
* Fix exporting DV memories from RepeaterBook to CSV
* TK7162: add initial support
* tk8160: Fix upload clobbering memory
* tk8160: Cleanup key definitions
- Update to version 20260417:
* Add Wouxun XS20 series channel memory support
* Wouxun 935/8h series extra memory settings
* TK-372G correct variants and names
* Add BF-V12D support
* Improve cache performance for RepeaterBook queries
* Improve reliability of network source requests and bug reports
* radtel_rt900: Fix flake8 E501 line too long in FHSS Code setting
* radtel_rt900: Fix FHSS Code init crash on out-of-range image values
* radtel_rt900: Expose FHSS Code per-channel setting
* radtel_rt900: Expose LearnFHSS per-channel setting
- Update to version 20260410:
* Fix RB query for non-NA countries when translated
* Update Turkish translation
* Update Japanese translations
* vx8: Fix 6.25kHz step channels being off frequency
- Update to version 20260403:
* Add common KenwoodToneModel and move a number of supported
modeels to it
* Add Baofeng UV-5RM Plus
- Update to version 20260327:
* Add Retevis C2 driver
* Add Radioddity GS-10B
* Updated Italian Translation
* repeaterbook: Fix query parameters for RoW countries
* Squash error about "unsure if rtone is valid"
- Update to version 20260320:
* Fix hiding Tone column on radios that support no tones
* Add Radioddity DB40-G driver
* Add support for Retevis HA2 model
* ha1: Fix mem.duplex="off" setting
* ha1: Fix dtmfsignalinglist
* Add Radio Amateur Satellites query source, integrate it into
the UI.
* Move repeaterbook to cached/proxied service
* Add Baofeng UV-28Plus
- Update to version 20260313:
* RT-910 non-BT increase channels to 960 for Fw V0.11
* RT-880G follow-up fixes
* Fixed the issue of incorrect values for dtmfcomm and zoneinfo.
- Update to version 20260306:
* repeaterbook: Edits to country list
* ha1g: Fix offset bank issue
* Fix disabled item color in dark mode
* Support Radtel RT880G
- Update to version 20260227:
* add Retevis RT21H
* d7: Avoid breaking settings load for individual failures
- Update to version 20260220:
* Add TD-M11 test .img files
* Add new models TIDRADIO TD-M11 22 FRS and TD-M11 16 PMR
* th9800: Fix newer variant with short ident block
* Add Baofeng GM-21 and Radioddity GM-30 Pro
* Fix bulk-editing memories where empties are included
* Baofeng GM-15Pro as subclass of Radioddity GM-30
* Update Japanese translation
- Update to version 20260213:
* Fix sorting confusing empty state of some rows
* th9800: Fix crash while logging version mismatch
* ft4: Fix clearing unknown memory regions
* Update German translations
- Update to version 20260206:
* Add IARU R1 VHF/UHF bands to bandplan
* kguv980p: Fix string comparison for power==None
* Updated Italian, Spanish translations
- Update to version 20260130:
* uvk5: Improve read-only warning strategy
* uvk5: Bless new found firmware versions 7.00.x
* vx1: Fixes for compatibility
* Update Italian Translation
* Updated Spanish translation for "frequency out of range" message
- Update to version 20260123:
* Add Radioddity GM-30 Plus driver
* btech: update default timeout for download/upload
* f8hp-pro: Fix validate_memory for AM/aircraft
* Account for start bits in baud calculation
- Update to version 20260116:
* Add support for Baofeng BF-F8HP PRO firmware v0.52
* BTech UV-25X2_G2 lengthen timeout when downloading
* ha1g - Add bank support
* anytone779: support sql_mode when setting
- Update to version 20260109:
* uv5r: Avoid breaking if VFOn frequency is invalid
* support additional fingerprint for Retevis RT86S
* support Retevis RB626 settings
* Updated Translations
* Fixes for 8.33kHz frequency and channel handling
* Add VX1R driver
- Update to version 20260102:
* uv17Pro: Add new model UV-5G Mini
* uv17pro: Refactor to support multiple idents
* ha1g: Airband Support
* Fix exporting CSV from drivers with negative specials
- Update to version 20251219:
* Fix test_clone to distinguish clone in/out
* uv-k1: Add memory programming
- Update to version 20251212:
* tmd710: Fix failure to identify
* tk11: Fix download/upload progress bar is not updating
* translation updates
- Update to version 20251205:
* Add driver for Quansheng TK11
* Include Baofeng K63 and K6A in model mappings
* Updated Spanish Translation
- Update to version 20251128:
* Fix mouseover error when setting is None
* Fixes #12274 TD-H8 Gen 3, add missing MID to channel power
settings
* Update pt_BR translation
- Update to version 20251121:
* ha1g: Re-add scan/alarm/dtmf lists
* ha1g: Check firmware compatibility during clone
* retevis.py: add new ident fingerprint
* dr135: Extend range to 174MHz
- Update to version 20251106:
* ha1g: Remove non-reentrant alarm/dtmf list code
- ensure backwards compatibility for 15.6
- Use pyproject macros to build and install.
- Update to version 20251031:
* Remove Vertex Standard radio drivers
* ft8800: Add settings support
* anytone778uv: Fix duplex and tmode decode logging
* tk760g: Fix long-standing typo in base class name
* tk760g: Add odd TK-260G lower-p variant support
* Update Italian Translation
- Update to version 20251024:
* th9800.py: Add Retevis_MA1
* Fix applying band defaults to immutable fields
* Yaesu FT-1D, FT2D, FT3D fixes WiresX settings to handle all
rooms in category
* ft1d: multiple fixes
* Added Retevis HA1G and HA1UV models
* uvk5: Add new wild-found 1.02.x firmware blessing
* Fix 8.33kHz step calculation
* Update supported model list for Wouxun radios
- Update to version 20251010:
* Allow loading modules from additional states
* tdh8: Remove forced NOAA channels at top of range
* tdh8: Fix GMRS G3 detection
* Fix export to CSV aborting on invalid memories
* Fix writing CSVs with more than 1000 memories
- Update to version 20251003:
* uvk5: Fix step index list
* bitwise: Add memory union support
- Update to version 20250926:
* Fix US Aviation Frequencies stock config mode
* tdh8: Add support for TD-H8 Gen 3
* tdh8: Fix VFO offset setting
- Update to version 20250912:
* Add Retevis RA86 mobile radio
* at779UV: Fix setting empty memories
* thd74: multiple fixes
* Fix column sort order with numeric values
- Update to version 20250905:
* tk270: Fix for python3
* bff8hppro: Fix high power level watts
* ft8900: decouple from ft8800
* ft8800: fix memory issues
* Updated Italian and Spanish translations
* Improved autocomplete for memory structure objects
- Update to version 20250829:
* Add Baofeng UV-5R Mini
* Add Retevis RT86S
* Enable has_offset for Icom IC-7100
- Update to version 20250822:
* Various models: Remove verbose debug logging and use trace
instead
* Add generic serial tracing for debug
* Allow hexprint with variable line length
- Update to version 20250815:
* icv80: Fix duplex/tx-inhibit setting
* add Baofeng BF-F8HP PRO firmware V0.44 support
Patchnames: openSUSE-Leap-16.0-packagehub-598
Terms of use: CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
Affected products
Recommended
1 product
| Product | Identifier | Version | Remediation |
|---|---|---|---|
| Unresolved product id: openSUSE Leap 16.0:chirp-0:20260911-bp160.1.1.noarch | — |
Vendor Fix
|
Threats
Impact
important
References
6 references
{
"document": {
"aggregate_severity": {
"namespace": "https://www.suse.com/support/security/rating/",
"text": "important"
},
"category": "csaf_security_advisory",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright 2024 SUSE LLC. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "summary",
"text": "Security update for chirp",
"title": "Title of the patch"
},
{
"category": "description",
"text": "This update for chirp fixes the following issues:\n\nChanges in chirp:\n\n- Update to version 20260911:\n * ftm300d: Experimental Yaesu FTM-300DR driver\n * Update Ukrainian localization\n * ar8200: Fix importing memories with AM mode\n * Unify Baofeng setting descriptions across drivers\n * Add Yaesu FT5D\n * uvb5: Fix Reverse setting\n\n- Update to version 20260904:\n * Fix RB28/RB628 tone and DTCS index mapping\n * Retevis RB28/RB628: Fix Busy Channel Lockout display\n * various bug fixes\n\n- Update to version 20260821:\n * Add Kenwood NX-800 driver\n * CVE-2026-78136: kenwood_itm: Fix DCS parsing (boo#1280123)\n * tmd710: various bug fixes\n * Add TK-3180E support\n * tk8180: various updates\n * Support Shift+F10 convention for context menu in memedit\n * Add Baofeng BF-T20, BF-T20FRS setting descriptions\n * Add QYT KT-8900 setting documentation\n * Add user-friendly Baofeng UV-5R setting descriptions\n\n- Update to version 20260626:\n * uvk5_egzumer: Fix battery_text and mic_bar never being saved\n * Fix open filter translated string\n\n- Update to version 20260619:\n * Add Baofeng BF-5RH as alias of UV-5RH\n * locale: Added Czech translation\n * generic_csv: Fix ImmutableValueError when exporting special memories\n\n- Update to version 20260612:\n * Add test image for Bajeton BJ7800\n * Update RT-920 test image for FM,AM \u0026 HF memories\n * Add new model Bajeton BJ7800 as a sub-class of RT-920\n\n- Update to version 20260605:\n * Update boot, zone, scan and alarm channels on channel deletion\n * Add GM-15Pro extended UHF range\n\n- Update to version 20260529:\n * Fix RT-900 non-BT, increase to 999 channels.\n * Fix escape character in log message for UV-5R Mini\n\n- Update to version 20260522:\n * tdh8: Fix loading out-of-range group code values\n * baofeng_uv17Pro: Fix uploading over BLE for supported models\n * Add BLE serial detection\n * mp31: Add support for Baofeng MP31\n\n- Update to version 20260515:\n * ha2: Fix defaulting empty memories to sane values\n\n- Update to version 20260508:\n * Don\u0027t complain about incompatible tones on import if no tone mode selected\n * ic2730: Add IC-2730E (European variant) support\n * ar8200: Add new driver for AOR AR8200\n * Updated Italian Translation\n\n- Update to version 20260501:\n * tdh8: Fix VFO A/B BCL setting not reading properly\n * tdh8: Add offset dir in VFO settings and fix VFO TX freq\n * h777v4: Fix detected models\n\n- Update to version 20260425:\n * Use common \"no response\" exception in drivers\n * vx150: Add driver for Vertex Standard VX-150\n * Update 935 and XS20 power handling\n * Fix 935/XS20 new channel creation\n * Fix exporting DV memories from RepeaterBook to CSV\n * TK7162: add initial support\n * tk8160: Fix upload clobbering memory\n * tk8160: Cleanup key definitions\n\n- Update to version 20260417:\n * Add Wouxun XS20 series channel memory support\n * Wouxun 935/8h series extra memory settings\n * TK-372G correct variants and names\n * Add BF-V12D support\n * Improve cache performance for RepeaterBook queries\n * Improve reliability of network source requests and bug reports\n * radtel_rt900: Fix flake8 E501 line too long in FHSS Code setting\n * radtel_rt900: Fix FHSS Code init crash on out-of-range image values\n * radtel_rt900: Expose FHSS Code per-channel setting\n * radtel_rt900: Expose LearnFHSS per-channel setting\n\n- Update to version 20260410:\n * Fix RB query for non-NA countries when translated\n * Update Turkish translation\n * Update Japanese translations\n * vx8: Fix 6.25kHz step channels being off frequency\n\n- Update to version 20260403:\n * Add common KenwoodToneModel and move a number of supported\n modeels to it\n * Add Baofeng UV-5RM Plus\n\n- Update to version 20260327:\n * Add Retevis C2 driver\n * Add Radioddity GS-10B\n * Updated Italian Translation\n * repeaterbook: Fix query parameters for RoW countries\n * Squash error about \"unsure if rtone is valid\"\n\n- Update to version 20260320:\n * Fix hiding Tone column on radios that support no tones\n * Add Radioddity DB40-G driver\n * Add support for Retevis HA2 model\n * ha1: Fix mem.duplex=\"off\" setting\n * ha1: Fix dtmfsignalinglist\n * Add Radio Amateur Satellites query source, integrate it into\n the UI.\n * Move repeaterbook to cached/proxied service\n * Add Baofeng UV-28Plus\n\n- Update to version 20260313:\n * RT-910 non-BT increase channels to 960 for Fw V0.11\n * RT-880G follow-up fixes\n * Fixed the issue of incorrect values for dtmfcomm and zoneinfo.\n\n- Update to version 20260306:\n * repeaterbook: Edits to country list\n * ha1g: Fix offset bank issue\n * Fix disabled item color in dark mode\n * Support Radtel RT880G\n\n- Update to version 20260227:\n * add Retevis RT21H\n * d7: Avoid breaking settings load for individual failures\n\n- Update to version 20260220:\n * Add TD-M11 test .img files\n * Add new models TIDRADIO TD-M11 22 FRS and TD-M11 16 PMR\n * th9800: Fix newer variant with short ident block\n * Add Baofeng GM-21 and Radioddity GM-30 Pro\n * Fix bulk-editing memories where empties are included\n * Baofeng GM-15Pro as subclass of Radioddity GM-30\n * Update Japanese translation\n\n- Update to version 20260213:\n * Fix sorting confusing empty state of some rows\n * th9800: Fix crash while logging version mismatch\n * ft4: Fix clearing unknown memory regions\n * Update German translations\n\n- Update to version 20260206:\n * Add IARU R1 VHF/UHF bands to bandplan\n * kguv980p: Fix string comparison for power==None\n * Updated Italian, Spanish translations\n\n- Update to version 20260130:\n * uvk5: Improve read-only warning strategy\n * uvk5: Bless new found firmware versions 7.00.x\n * vx1: Fixes for compatibility\n * Update Italian Translation\n * Updated Spanish translation for \"frequency out of range\" message\n\n- Update to version 20260123:\n * Add Radioddity GM-30 Plus driver\n * btech: update default timeout for download/upload\n * f8hp-pro: Fix validate_memory for AM/aircraft\n * Account for start bits in baud calculation\n\n- Update to version 20260116:\n * Add support for Baofeng BF-F8HP PRO firmware v0.52\n * BTech UV-25X2_G2 lengthen timeout when downloading\n * ha1g - Add bank support\n * anytone779: support sql_mode when setting\n\n- Update to version 20260109:\n * uv5r: Avoid breaking if VFOn frequency is invalid\n * support additional fingerprint for Retevis RT86S\n * support Retevis RB626 settings\n * Updated Translations\n * Fixes for 8.33kHz frequency and channel handling\n * Add VX1R driver\n\n- Update to version 20260102:\n * uv17Pro: Add new model UV-5G Mini\n * uv17pro: Refactor to support multiple idents\n * ha1g: Airband Support\n * Fix exporting CSV from drivers with negative specials\n\n- Update to version 20251219:\n * Fix test_clone to distinguish clone in/out\n * uv-k1: Add memory programming\n\n- Update to version 20251212:\n * tmd710: Fix failure to identify\n * tk11: Fix download/upload progress bar is not updating\n * translation updates\n\n- Update to version 20251205:\n * Add driver for Quansheng TK11\n * Include Baofeng K63 and K6A in model mappings\n * Updated Spanish Translation\n\n- Update to version 20251128:\n * Fix mouseover error when setting is None\n * Fixes #12274 TD-H8 Gen 3, add missing MID to channel power\n settings\n * Update pt_BR translation\n\n- Update to version 20251121:\n * ha1g: Re-add scan/alarm/dtmf lists\n * ha1g: Check firmware compatibility during clone\n * retevis.py: add new ident fingerprint\n * dr135: Extend range to 174MHz\n\n- Update to version 20251106:\n * ha1g: Remove non-reentrant alarm/dtmf list code\n\n- ensure backwards compatibility for 15.6\n\n- Use pyproject macros to build and install.\n\n- Update to version 20251031:\n * Remove Vertex Standard radio drivers\n * ft8800: Add settings support\n * anytone778uv: Fix duplex and tmode decode logging\n * tk760g: Fix long-standing typo in base class name\n * tk760g: Add odd TK-260G lower-p variant support\n * Update Italian Translation\n\n- Update to version 20251024:\n * th9800.py: Add Retevis_MA1\n * Fix applying band defaults to immutable fields\n * Yaesu FT-1D, FT2D, FT3D fixes WiresX settings to handle all\n rooms in category\n * ft1d: multiple fixes\n * Added Retevis HA1G and HA1UV models\n * uvk5: Add new wild-found 1.02.x firmware blessing\n * Fix 8.33kHz step calculation\n * Update supported model list for Wouxun radios\n\n- Update to version 20251010:\n * Allow loading modules from additional states\n * tdh8: Remove forced NOAA channels at top of range\n * tdh8: Fix GMRS G3 detection\n * Fix export to CSV aborting on invalid memories\n * Fix writing CSVs with more than 1000 memories\n\n- Update to version 20251003:\n * uvk5: Fix step index list\n * bitwise: Add memory union support\n\n- Update to version 20250926:\n * Fix US Aviation Frequencies stock config mode\n * tdh8: Add support for TD-H8 Gen 3\n * tdh8: Fix VFO offset setting\n\n- Update to version 20250912:\n * Add Retevis RA86 mobile radio\n * at779UV: Fix setting empty memories\n * thd74: multiple fixes\n * Fix column sort order with numeric values\n\n- Update to version 20250905:\n * tk270: Fix for python3\n * bff8hppro: Fix high power level watts\n * ft8900: decouple from ft8800\n * ft8800: fix memory issues\n * Updated Italian and Spanish translations\n * Improved autocomplete for memory structure objects\n\n- Update to version 20250829:\n * Add Baofeng UV-5R Mini\n * Add Retevis RT86S\n * Enable has_offset for Icom IC-7100\n\n- Update to version 20250822:\n * Various models: Remove verbose debug logging and use trace\n instead\n * Add generic serial tracing for debug\n * Allow hexprint with variable line length\n\n- Update to version 20250815:\n * icv80: Fix duplex/tx-inhibit setting\n * add Baofeng BF-F8HP PRO firmware V0.44 support\n",
"title": "Description of the patch"
},
{
"category": "details",
"text": "openSUSE-Leap-16.0-packagehub-598",
"title": "Patchnames"
},
{
"category": "legal_disclaimer",
"text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
"title": "Terms of use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://www.suse.com/support/security/contact/",
"name": "SUSE Product Security Team",
"namespace": "https://www.suse.com/"
},
"references": [
{
"category": "external",
"summary": "SUSE ratings",
"url": "https://www.suse.com/support/security/rating/"
},
{
"category": "self",
"summary": "URL of this CSAF notice",
"url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_21866-1.json"
},
{
"category": "self",
"summary": "SUSE Bug 1280123",
"url": "https://bugzilla.suse.com/1280123"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-78136 page",
"url": "https://www.suse.com/security/cve/CVE-2026-78136/"
}
],
"title": "Security update for chirp",
"tracking": {
"current_release_date": "2026-09-17T17:44:51Z",
"generator": {
"date": "2026-09-16T15:14:49Z",
"engine": {
"name": "cve-database.git:bin/generate-csaf.pl",
"version": "1"
}
},
"id": "openSUSE-SU-2026:21866-1",
"initial_release_date": "2026-09-16T15:14:49Z",
"revision_history": [
{
"date": "2026-09-16T15:14:49Z",
"number": "1",
"summary": "Current version"
},
{
"date": "2026-09-17T17:44:51Z",
"number": "2",
"summary": "unknown changes"
}
],
"status": "final",
"version": "2"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "chirp-0:20260911-bp160.1.1.noarch",
"product": {
"name": "chirp-0:20260911-bp160.1.1.noarch",
"product_id": "chirp-0:20260911-bp160.1.1.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/chirp@20260911-bp160.1.1?arch=noarch"
}
}
}
],
"category": "architecture",
"name": "noarch"
},
{
"branches": [
{
"category": "product_name",
"name": "openSUSE Leap 16.0",
"product": {
"name": "openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0"
}
}
],
"category": "product_family",
"name": "SUSE Linux Enterprise"
}
],
"category": "vendor",
"name": "SUSE"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "chirp-0:20260911-bp160.1.1.noarch as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:chirp-0:20260911-bp160.1.1.noarch"
},
"product_reference": "chirp-0:20260911-bp160.1.1.noarch",
"relates_to_product_reference": "openSUSE Leap 16.0"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-78136",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-78136"
}
],
"notes": [
{
"category": "general",
"text": "chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chirp-0:20260911-bp160.1.1.noarch"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-78136",
"url": "https://www.suse.com/security/cve/CVE-2026-78136"
},
{
"category": "external",
"summary": "SUSE Bug 1280123 for CVE-2026-78136",
"url": "https://bugzilla.suse.com/1280123"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chirp-0:20260911-bp160.1.1.noarch"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-09-16T15:14:49Z",
"details": "important"
}
],
"title": "CVE-2026-78136"
}
]
}
Loading…
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…