SUSE-SU-2026:3992-1
Dashboard / Vulnerabilities / SUSE-SU-2026:3992-1
SUSE-SU-2026:3992-1
Summary: Security update for aws-nitro-enclaves-cli
Details: This update for aws-nitro-enclaves-cli fixes the following issues: - CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to undefined behavior and crashes (bsc#1274300). - CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257933). - CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270202). Changes for aws-nitro-enclaves-cli: - Update to version 1.5.0
References: https://www.suse.com/support/update/announcement/2026/suse-su-20263992-1/, https://bugzilla.suse.com/1257933, https://bugzilla.suse.com/1270202, https://bugzilla.suse.com/1274300, https://www.suse.com/security/cve/CVE-2026-25541, https://www.suse.com/security/cve/CVE-2026-25727, https://www.suse.com/security/cve/CVE-2026-41676
Affected packages
Package
Name: aws-nitro-enclaves-cli
Purl: pkg:rpm/suse/aws-nitro-enclaves-cli&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP6
Affected ranges
Type: ECOSYSTEM
Events:
