Security update for firebird
| Announcement ID: | SUSE-SU-2026:1868-1 |
|---|---|
| Release Date: | 2026-05-15T07:50:01Z |
| Rating: | critical |
| References: | |
| Cross-References: | |
| CVSS scores: |
|
| Affected Products: |
|
An update that solves nine vulnerabilities can now be installed.
Description:
This update for firebird fixes the following issues
- CVE-2025-65104: Information leak vulnerability in firebird3 client when used with newer (>= 4) server (bsc#1262330).
- CVE-2026-27890: Pre-Auth DOS (bsc#1262328).
- CVE-2026-28212: One packet DoS (bsc#1262329).
- CVE-2026-28214: Server hangs when using specific clumplet on batch creation (bsc#1262327).
- CVE-2026-28224: CryptCallback DOS (bsc#1262326).
- CVE-2026-33337: Buffer overflow on parsing corrupted slice packet (bsc#1262325).
- CVE-2026-34232: DoS via
op_responsepacket from client (bsc#1262324). - CVE-2026-35215: DoS via malicious slice descriptor in slice packet (bsc#1262322).
- CVE-2026-40342: Path traversal when declaring external routine (bsc#1262320).
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-1868=1
Package List:
-
SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
- firebird-3.0.14.33856-150200.3.9.1
- firebird-debugsource-3.0.14.33856-150200.3.9.1
- libib_util-3.0.14.33856-150200.3.9.1
- firebird-examples-3.0.14.33856-150200.3.9.1
- libfbclient2-3.0.14.33856-150200.3.9.1
- libib_util-debuginfo-3.0.14.33856-150200.3.9.1
- firebird-utils-3.0.14.33856-150200.3.9.1
- firebird-server-3.0.14.33856-150200.3.9.1
- libib_util-devel-3.0.14.33856-150200.3.9.1
- libfbclient2-debuginfo-3.0.14.33856-150200.3.9.1
- firebird-server-debuginfo-3.0.14.33856-150200.3.9.1
- firebird-utils-debuginfo-3.0.14.33856-150200.3.9.1
- libfbclient-devel-3.0.14.33856-150200.3.9.1
- firebird-debuginfo-3.0.14.33856-150200.3.9.1
References:
- https://www.suse.com/security/cve/CVE-2025-65104.html
- https://www.suse.com/security/cve/CVE-2026-27890.html
- https://www.suse.com/security/cve/CVE-2026-28212.html
- https://www.suse.com/security/cve/CVE-2026-28214.html
- https://www.suse.com/security/cve/CVE-2026-28224.html
- https://www.suse.com/security/cve/CVE-2026-33337.html
- https://www.suse.com/security/cve/CVE-2026-34232.html
- https://www.suse.com/security/cve/CVE-2026-35215.html
- https://www.suse.com/security/cve/CVE-2026-40342.html
- https://bugzilla.suse.com/show_bug.cgi?id=1262320
- https://bugzilla.suse.com/show_bug.cgi?id=1262322
- https://bugzilla.suse.com/show_bug.cgi?id=1262324
- https://bugzilla.suse.com/show_bug.cgi?id=1262325
- https://bugzilla.suse.com/show_bug.cgi?id=1262326
- https://bugzilla.suse.com/show_bug.cgi?id=1262327
- https://bugzilla.suse.com/show_bug.cgi?id=1262328
- https://bugzilla.suse.com/show_bug.cgi?id=1262329
- https://bugzilla.suse.com/show_bug.cgi?id=1262330