Avatar photo
By: Marcus Meissner

June 10, 2026 1:27 pm

134 views

SUSE Security Data considerations

SUSE provides security data for the CVE issues affecting the SUSE Linux products and the openSUSE distributions. We provide the data in OVAL, CVRF and CSAF formats under the Creative Commons license. The security data is generated from released updates, updates in QA, and our security tracking and scoring data. The same data sources are […]

Read More


Avatar photo
By: Marcus Meissner

April 30, 2026 7:13 am

13,151 views

SUSE responds to the copy.fail vulnerability

Copy Fail (tracked as CVE-2026-31431) is a critical vulnerability in the Linux kernel that allows a local non-root user to gain full root access to the system. It is considered extremely dangerous because it is a pure logic error - unlike other known holes like Dirty Pipe or Dirty COW, it does not require complex […]

Read More


Avatar photo
By: Marcus Meissner

January 15, 2026 2:08 pm

926 views

Installing FIPS certified packages on SUSE Linux Enterprise Server 15 SP6 and SP7

SUSE has certified and is currently certifying various cryptographic modules for FIPS 140-3 on SUSE Linux Enterprise Server 15 SP6. Nearly all of those modules certified on SLES 15 SP6 can also be used on SLES 15 SP7, and for this purpose they are delivered to the SLES 15 SP7 Certifications Module. The modules consists […]

Read More


Avatar photo
By: Marcus Meissner

December 4, 2025 9:42 am

1,623 views

SUSE state of and strategy for Post Quantum Cryptography at the end of 2025

SUSE's strategy on implementing post quantum cryptography (PQC) has been to adopt standards and upstream implementations when they become available, and deliver support to customers via maintenance or newer product revisions. Standardization status Cryptography and protocols on top of it needs to interoperate world wide between a wide range of third parties. This requires that […]

Read More


Avatar photo
By: Marcus Meissner

March 20, 2025 3:33 pm

1,790 views

Statement on CVE-2024-22033 – Compromise of Open Build Service via source services

Maxime Rinaudo of Fenrisk (http://fenrisk.com) found a security vulnerability in one of the services that are available on the open build service (https://build.opensuse.org/). He disclosed this to us privately to allow us to fix it before he publicly discloses it. We appreciate this very much and would like to thank him for […]

Read More


Avatar photo
By: Marcus Meissner

September 20, 2024 1:54 pm

3,294 views

SUSE has received first FIPS 140-3 cryptographic certificates

After several years of work the NIST CMVP agency has improved upon the existing FIPS 140-2 certification and established the FIPS 140-3 certification. The new standard brings many changes which are described in the Implementation Guidance. They established new requirements on lifecycle of cryptographic primitives and extended in the area of self-tests. They also took […]

Read More


Avatar photo
By: Marcus Meissner

March 29, 2024 5:33 pm

9,907 views

SUSE addresses supply chain attack against xz compression library

SUSE received notification of a supply chain attack against the "xz" compression tool and "liblzma5" library. Background Security Researcher Andres Freund reported to Debian that the xz / liblzma library had been backdoored. This backdoor was introduced in the upstream github xz project with release 5.6.0 in February 2024. For the […]

Read More


Avatar photo
By: Marcus Meissner

December 18, 2023 4:08 pm

13,869 views

SUSE addresses the SSH v2 protocol Terrapin Attack aka CVE-2023-48795

Today, on December 18th 2023, researchers from the Ruhr University Bochum published a protocol flaw in the SSH v2 protocol, codenamed Terrapin Attack. The flaw allows removing encrypted SSH messages at the begin of the communication, allowing downgrade of some security aspects of SSH connections. The flaw does not allow injecting new traffic or commands. […]

Read More


Avatar photo
By: Marcus Meissner

September 20, 2023 2:30 pm

6,197 views

GO and FIPS 140-2 / 140-3 certified cryptography

The current FIPS 140-2 and ongoing FIPS 140-3 certification efforts by SUSE cover a wide range of system libraries and its users, and the Linux Kernel. One gap recently closed is the missing FIPS 140 support for applications written in the GO language. To allow building GO binaries with cryptography compliant to FIPS 140, SUSE […]

Read More