Suse Linux Enterprise Server Ltss Extended Security
35 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Suse Linux Enterprise Server Ltss Extended Security, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Suse Linux Enterprise Server Ltss Extended Security CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 12 |
| 2024-11 | 0 |
| 2024-12 | 2 |
| 2025-01 | 0 |
| 2025-02 | 1 |
| 2025-03 | 2 |
| 2025-04 | 3 |
| 2025-05 | 0 |
| 2025-06 | 4 |
| 2025-07 | 4 |
| 2025-08 | 1 |
| 2025-09 | 1 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 35 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High17
- Medium15
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Suse Linux Enterprise Server Ltss Extended Security.
- CVE-2026-34757LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure5.1
- CVE-2026-0891Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 1478.1
- CVE-2025-58060cups has Authentication bypass with AuthType Negotiate8.0
- CVE-2025-50952openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.6.5
- CVE-2025-50106Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8...8.1
- CVE-2025-30749Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8...8.1
- CVE-2025-53367DjVuLibre OOB-Write Vulnerability in MMRDecoder7.8
- CVE-2025-38173crypto: marvell/cesa - Handle zero-length skcipher requests7.8
- CVE-2025-4565Unbounded recursion in Python Protobuf5.3
- CVE-2025-49125Apache Tomcat: Security constraint bypass for pre/post-resources7.5
- CVE-2025-49709Memory corruption in canvas surfaces9.8
- CVE-2025-4517Arbitrary writes via tarfile realpath overflow9.4
- CVE-2025-3891Mod_auth_openidc: dos via empty post in mod_auth_openidc with oidcpreservepost enabled7.5
- CVE-2025-3034Memory safety bugs fixed in Firefox 137 and Thunderbird 1378.1
- CVE-2025-3032Leaking file descriptors from the fork server7.4
Product grouping is registry-driven, with AI assist and human review. How it works