openSUSE-SU-2026:0245-1: important: Security update for enc

[email protected] Wed, 15 Jul 2026 00:04:49 +0200 (CEST)
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for enc
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0245-1
Rating:             important
References:         #1265533 
Cross-References:   CVE-2026-1229
CVSS scores:
                    CVE-2026-1229 (SUSE): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N

Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that fixes one vulnerability is now available.

Description:

   This update for enc fixes the following issues:

   - CVE-2026-1229: Fix incorrect value produced by CombinedMult() in
     ecc/p384 (boo#1265533) Bump circl to 1.6.3

   - Update to 1.1.5:
     * Update dependencies #10

   - Update to 1.1.4:
     * Update all dependencies #9

   - Update to 1.1.3:
     * Fix typo in README #7
     * Update all dependencies #8


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-245=1



Package List:

   - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

      enc-1.1.5-bp157.2.3.1


References:

   https://www.suse.com/security/cve/CVE-2026-1229.html
   https://bugzilla.suse.com/1265533