SUSE Security Advisories · January 2026 — SUSE Security Advisories
5 advisories 5 CVEs

SUSE-SU-* / openSUSE-SU-* / Rancher errata for 2026-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

Advisories

OPENSUSE-RU-2026:20168-1

openSUSEHIGH2026-01-23

Recommended update for gimp

CVEs:CVE-2025-15059

Affected products

ProductStatusVendorPackageEcosystem
gimp-3.0.8-bp160.1.1.aarch64 as component of openSUSE Leap 16.0 affected SUSE
gimp-3.0.8-bp160.1.1.ppc64le as component of openSUSE Leap 16.0 affected SUSE
gimp-3.0.8-bp160.1.1.x86_64 as component of openSUSE Leap 16.0 affected SUSE
gimp-devel-3.0.8-bp160.1.1.aarch64 as component of openSUSE Leap 16.0 affected SUSE
gimp-devel-3.0.8-bp160.1.1.ppc64le as component of openSUSE Leap 16.0 affected SUSE
gimp-devel-3.0.8-bp160.1.1.x86_64 as component of openSUSE Leap 16.0 affected SUSE
gimp-extension-goat-excercises-3.0.8-bp160.1.1.aarch64 as component of openSUSE Leap 16.0 affected SUSE
gimp-extension-goat-excercises-3.0.8-bp160.1.1.ppc64le as component of openSUSE Leap 16.0 affected SUSE
gimp-extension-goat-excercises-3.0.8-bp160.1.1.x86_64 as component of openSUSE Leap 16.0 affected SUSE
gimp-lang-3.0.8-bp160.1.1.noarch as component of openSUSE Leap 16.0 affected SUSE
gimp-plugin-aa-3.0.8-bp160.1.1.aarch64 as component of openSUSE Leap 16.0 affected SUSE
gimp-plugin-aa-3.0.8-bp160.1.1.ppc64le as component of openSUSE Leap 16.0 affected SUSE
gimp-plugin-aa-3.0.8-bp160.1.1.x86_64 as component of openSUSE Leap 16.0 affected SUSE
gimp-plugin-python3-3.0.8-bp160.1.1.aarch64 as component of openSUSE Leap 16.0 affected SUSE
gimp-plugin-python3-3.0.8-bp160.1.1.ppc64le as component of openSUSE Leap 16.0 affected SUSE
gimp-plugin-python3-3.0.8-bp160.1.1.x86_64 as component of openSUSE Leap 16.0 affected SUSE
gimp-vala-3.0.8-bp160.1.1.aarch64 as component of openSUSE Leap 16.0 affected SUSE
gimp-vala-3.0.8-bp160.1.1.ppc64le as component of openSUSE Leap 16.0 affected SUSE
gimp-vala-3.0.8-bp160.1.1.x86_64 as component of openSUSE Leap 16.0 affected SUSE
libgimp-3_0-0-3.0.8-bp160.1.1.aarch64 as component of openSUSE Leap 16.0 affected SUSE
libgimp-3_0-0-3.0.8-bp160.1.1.ppc64le as component of openSUSE Leap 16.0 affected SUSE
libgimp-3_0-0-3.0.8-bp160.1.1.x86_64 as component of openSUSE Leap 16.0 affected SUSE
libgimpui-3_0-0-3.0.8-bp160.1.1.aarch64 as component of openSUSE Leap 16.0 affected SUSE
libgimpui-3_0-0-3.0.8-bp160.1.1.ppc64le as component of openSUSE Leap 16.0 affected SUSE
libgimpui-3_0-0-3.0.8-bp160.1.1.x86_64 as component of openSUSE Leap 16.0 affected SUSE
Upstream advisory

OPENSUSE-RU-2026:20767-1

openSUSENONE2026-01-14

Recommended update for tlp

CVEs:CVE-2025-67859

Affected products

ProductStatusVendorPackageEcosystem
tlp-1.9.1-bp160.1.1.noarch as component of openSUSE Leap 16.0 affected SUSE
tlp-bash-completion-1.9.1-bp160.1.1.noarch as component of openSUSE Leap 16.0 affected SUSE
tlpctl-bash-completion-1.9.1-bp160.1.1.noarch as component of openSUSE Leap 16.0 affected SUSE
tlpctl-fish-completion-1.9.1-bp160.1.1.noarch as component of openSUSE Leap 16.0 affected SUSE
tlpctl-zsh-completion-1.9.1-bp160.1.1.noarch as component of openSUSE Leap 16.0 affected SUSE
tlp-fish-completion-1.9.1-bp160.1.1.noarch as component of openSUSE Leap 16.0 affected SUSE
tlp-pd-1.9.1-bp160.1.1.noarch as component of openSUSE Leap 16.0 affected SUSE
tlp-rdw-1.9.1-bp160.1.1.noarch as component of openSUSE Leap 16.0 affected SUSE
tlp-rdw-bash-completion-1.9.1-bp160.1.1.noarch as component of openSUSE Leap 16.0 affected SUSE
tlp-rdw-fish-completion-1.9.1-bp160.1.1.noarch as component of openSUSE Leap 16.0 affected SUSE
tlp-rdw-zsh-completion-1.9.1-bp160.1.1.noarch as component of openSUSE Leap 16.0 affected SUSE
tlp-zsh-completion-1.9.1-bp160.1.1.noarch as component of openSUSE Leap 16.0 affected SUSE
Upstream advisory

OPENSUSE-RU-2026:20161-1

openSUSEMEDIUM2026-01-12

Recommended update for hauler

CVEs:CVE-2026-22772

Affected products

ProductStatusVendorPackageEcosystem
hauler-1.4.1-bp160.1.1.aarch64 as component of openSUSE Leap 16.0 affected SUSE
hauler-1.4.1-bp160.1.1.x86_64 as component of openSUSE Leap 16.0 affected SUSE
Upstream advisory

OPENSUSE-RU-2026:20010-1

openSUSEMEDIUM2026-01-08

Recommended update for trivy

CVEs:CVE-2025-47911

Affected products

ProductStatusVendorPackageEcosystem
trivy-0.68.2-bp160.1.1.aarch64 as component of openSUSE Leap 16.0 affected SUSE
trivy-0.68.2-bp160.1.1.ppc64le as component of openSUSE Leap 16.0 affected SUSE
trivy-0.68.2-bp160.1.1.s390x as component of openSUSE Leap 16.0 affected SUSE
trivy-0.68.2-bp160.1.1.x86_64 as component of openSUSE Leap 16.0 affected SUSE
Upstream advisory

OPENSUSE-RU-2026:20010-1

openSUSEMEDIUM2026-01-08

Recommended update for trivy

CVEs:CVE-2025-58190

Affected products

ProductStatusVendorPackageEcosystem
trivy-0.68.2-bp160.1.1.aarch64 as component of openSUSE Leap 16.0 affected SUSE
trivy-0.68.2-bp160.1.1.ppc64le as component of openSUSE Leap 16.0 affected SUSE
trivy-0.68.2-bp160.1.1.s390x as component of openSUSE Leap 16.0 affected SUSE
trivy-0.68.2-bp160.1.1.x86_64 as component of openSUSE Leap 16.0 affected SUSE
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.