SUSE Linux Micro Updates Address Critical Privilege Escalation Vulnerabilities
ID: dc7e7964-653b-5147-9297-b9bb5ac0f77f
STIX ID: report--dc7e7964-653b-5147-9297-b9bb5ac0f77f
Feed Name: ThreatCluster
Threat Score
SUSE Linux Micro 6.0 patches address two critical vulnerabilities—CVE-2026-14474 (privilege escalation via the sudo LDAP provider) and CVE-2026-14476 (Kerberos authentication bypass via path traversal)—published on July 7, 2026 with CVSS scores 8.8 and 8.0, respectively, plus a moderate pam_userdb timing issue (CVE-2026-54411). Administrators are urged to apply updates (YaST online_update or zypper patch) immediately; affected architectures include aarch64, s390x, and x86_64.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
