Security update for sccache
This update for sccache fixes the following issues: Update to version 0.15.0~17. - CVE-2023-26964: hyper,h2: high resource consumption due to stream stacking when H2 component processes `HTTP2 RST_STREAM` frames (bsc#1210346). - CVE-2024-32650: rust-rustls: infinite loop in `rustls::conn::ConnectionCommon:complete_io()` when processing client input network input (bsc#1223238). - CVE-2025-3416: openssl: use-after-free in `Md::fetch` and `Cipher::fetch` (bsc#1242611). - CVE-2026-25727: time: stack exhaustion in the RFC 2822 date parser when processing certain user provided input (bsc#1257923). - CVE-2026-41676: openssl: short buffer overflow via `Deriver:derive` and `PkeyCtxRef:derive` when using OpenSSL 1.1.1 (bsc#1270206). - CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270559). - CVE-2026-41678: openssl: OOB write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270693). - CVE-2026-41681: openssl: stack corruption due to `MdCtxRef::digest_final()` writing past caller buffer with no length check (bsc#1270736). - CVE-2026-41898: openssl: information leak to network peers due to unchecked callback-returned length in PSK and cookie generate trampolines (bsc#1270869). - CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270512). - CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding (bsc#1270938). - CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers (bsc#1270948).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for sccache fixes the following issues: Update to version 0.15.0~17. - CVE-2023-26964: hyper,h2: high resource consumption due to stream stacking when H2 component processes `HTTP2 RST_STREAM` frames (bsc#1210346). - CVE-2024-32650: rust-rustls: infinite loop in `rustls::conn::ConnectionCommon:complete_io()` when processing client input network input (bsc#1223238). - CVE-2025-3416: openssl: use-after-free in `Md::fetch` and `Cipher::fetch` (bsc#1242611). - CVE-2026-25727: time: stack exhaustion in the RFC 2822 date parser when processing certain user provided input (bsc#1257923). - CVE-2026-41676: openssl: short buffer overflow via `Deriver:derive` and `PkeyCtxRef:derive` when using OpenSSL 1.1.1 (bsc#1270206). - CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270559). - CVE-2026-41678: openssl: OOB write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270693). - CVE-2026-41681: openssl: stack corruption due to `MdCtxRef::digest_final()` writing past caller buffer with no length check (bsc#1270736). - CVE-2026-41898: openssl: information leak to network peers due to unchecked callback-returned length in PSK and cookie generate trampolines (bsc#1270869). - CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270512). - CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding (bsc#1270938). - CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers (bsc#1270948).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1210346
- https://bugzilla.suse.com/1223238
- https://bugzilla.suse.com/1229955
- https://bugzilla.suse.com/1242611
- https://bugzilla.suse.com/1243868
- https://bugzilla.suse.com/1257923
- https://bugzilla.suse.com/1270206
- https://bugzilla.suse.com/1270512
- https://bugzilla.suse.com/1270559
- https://bugzilla.suse.com/1270693
- https://bugzilla.suse.com/1270736
- https://bugzilla.suse.com/1270869
- https://bugzilla.suse.com/1270938
- https://bugzilla.suse.com/1270948
- https://www.suse.com/security/cve/CVE-2023-26964
- https://www.suse.com/security/cve/CVE-2024-12224
- https://www.suse.com/security/cve/CVE-2024-32650
- https://www.suse.com/security/cve/CVE-2024-43806
- https://www.suse.com/security/cve/CVE-2025-3416
- https://www.suse.com/security/cve/CVE-2026-25727
- https://www.suse.com/security/cve/CVE-2026-41676
- https://www.suse.com/security/cve/CVE-2026-41677
- https://www.suse.com/security/cve/CVE-2026-41678
- https://www.suse.com/security/cve/CVE-2026-41681
- https://www.suse.com/security/cve/CVE-2026-41898
- https://www.suse.com/security/cve/CVE-2026-42327
- https://www.suse.com/security/cve/CVE-2026-44662
- https://www.suse.com/security/cve/CVE-2026-45784
- https://www.suse.com/support/update/announcement/2026/suse-su-20263022-1/