[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:20152-1":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T17:35:29.592Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":38,"duplicates":39,"related":40,"reserved_at":9,"published_at":53,"modified_at":54,"state":9,"summary":55,"references_raw":57,"kevs":161,"epss":9,"epss_history":162,"metrics":163,"affected":164},"OPENSUSE-SU-2026:20152-1","Security update for openssl-3\n\nThis update for openssl-3 fixes the following issues:\n\nSecurity fixes:\n\n - CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829).\n - CVE-2025-15467: Stack buffer overflow in CMS AuthEnvelopedData parsing (bsc#1256830).\n - CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831).\n - CVE-2025-15469: \"openssl dgst\" one-shot codepath silently truncates inputs >16MB (bsc#1256832).\n - CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833).\n - CVE-2025-68160: Heap out-of-bounds write in BIO_f_linebuffer on short writes (bsc#1256834).\n - CVE-2025-69418: Unauthenticated/unencrypted trailing bytes with low-level OCB function calls (bsc#1256835).\n - CVE-2025-69419: Out of bounds write in PKCS12_get_friendlyname() UTF-8 conversion (bsc#1256836).\n - CVE-2025-69420: Missing ASN1_TYPE validation in TS_RESP_verify_response() function (bsc#1256837).\n - CVE-2025-69421: NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function (bsc#1256838).\n - CVE-2026-22795: Missing ASN1_TYPE validation in PKCS#12 parsing (bsc#1256839).\n - CVE-2026-22796: ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function (bsc#1256840).\n\nOther fixes:\n\n- Enable livepatching support for ppc64le (bsc#1257274).\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36],{"_key":15},"CVE-2025-11187",{"_key":17},"CVE-2025-15467",{"_key":19},"CVE-2025-15468",{"_key":21},"CVE-2025-15469",{"_key":23},"CVE-2025-66199",{"_key":25},"CVE-2025-68160",{"_key":27},"CVE-2025-69418",{"_key":29},"CVE-2025-69419",{"_key":31},"CVE-2025-69420",{"_key":33},"CVE-2025-69421",{"_key":35},"CVE-2026-22795",{"_key":37},"CVE-2026-22796",[],[],[41,42,43,44,45,46,47,48,49,50,51,52],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},"2026-02-02T13:00:02Z","2026-03-23T04:54:46.190377Z",{"cisa_kev":56,"cisa_ransomware":56,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[58,64,68,72,76,80,84,88,92,96,100,104,108,112,117,121,125,129,133,137,141,145,149,153,157],{"url":59,"sources":60,"tags":62},"https://bugzilla.suse.com/1256829",[61],"osv_opensuse",[63],"REPORT",{"url":65,"sources":66,"tags":67},"https://bugzilla.suse.com/1256830",[61],[63],{"url":69,"sources":70,"tags":71},"https://bugzilla.suse.com/1256831",[61],[63],{"url":73,"sources":74,"tags":75},"https://bugzilla.suse.com/1256832",[61],[63],{"url":77,"sources":78,"tags":79},"https://bugzilla.suse.com/1256833",[61],[63],{"url":81,"sources":82,"tags":83},"https://bugzilla.suse.com/1256834",[61],[63],{"url":85,"sources":86,"tags":87},"https://bugzilla.suse.com/1256835",[61],[63],{"url":89,"sources":90,"tags":91},"https://bugzilla.suse.com/1256836",[61],[63],{"url":93,"sources":94,"tags":95},"https://bugzilla.suse.com/1256837",[61],[63],{"url":97,"sources":98,"tags":99},"https://bugzilla.suse.com/1256838",[61],[63],{"url":101,"sources":102,"tags":103},"https://bugzilla.suse.com/1256839",[61],[63],{"url":105,"sources":106,"tags":107},"https://bugzilla.suse.com/1256840",[61],[63],{"url":109,"sources":110,"tags":111},"https://bugzilla.suse.com/1257274",[61],[63],{"url":113,"sources":114,"tags":115},"https://www.suse.com/security/cve/CVE-2025-11187",[61],[116],"WEB",{"url":118,"sources":119,"tags":120},"https://www.suse.com/security/cve/CVE-2025-15467",[61],[116],{"url":122,"sources":123,"tags":124},"https://www.suse.com/security/cve/CVE-2025-15468",[61],[116],{"url":126,"sources":127,"tags":128},"https://www.suse.com/security/cve/CVE-2025-15469",[61],[116],{"url":130,"sources":131,"tags":132},"https://www.suse.com/security/cve/CVE-2025-66199",[61],[116],{"url":134,"sources":135,"tags":136},"https://www.suse.com/security/cve/CVE-2025-68160",[61],[116],{"url":138,"sources":139,"tags":140},"https://www.suse.com/security/cve/CVE-2025-69418",[61],[116],{"url":142,"sources":143,"tags":144},"https://www.suse.com/security/cve/CVE-2025-69419",[61],[116],{"url":146,"sources":147,"tags":148},"https://www.suse.com/security/cve/CVE-2025-69420",[61],[116],{"url":150,"sources":151,"tags":152},"https://www.suse.com/security/cve/CVE-2025-69421",[61],[116],{"url":154,"sources":155,"tags":156},"https://www.suse.com/security/cve/CVE-2026-22795",[61],[116],{"url":158,"sources":159,"tags":160},"https://www.suse.com/security/cve/CVE-2026-22796",[61],[116],[],[],[],[165],{"ecosystem":166,"name":167,"vendor":168,"product":169,"cpe_part":9,"purl_type":170,"purl_namespace":168,"purl_name":169,"source":9,"versions":171},"openSUSE","openssl-3","opensuse","openssl-3&distro=openSUSE Leap 16.0","rpm",[172],{"version":173,"is_range":174,"range_type":175,"version_start":9,"version_start_type":9,"version_end":176,"version_end_type":177,"fixed_in":9},"lt3_5_0_160000_5_1",true,"ecosystem","3.5.0-160000.5.1","excluding"]