openSUSE-SU-2026:0307-1: important: Security update for v2ray-core

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for v2ray-core
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0307-1
Rating:             important
References:         #1258546 #1266787 #1276119 
Cross-References:   CVE-2026-27017 CVE-2026-39821 CVE-2026-72815
                    CVE-2026-72816 CVE-2026-72817
CVSS scores:
                    CVE-2026-39821 (SUSE): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
                    CVE-2026-72815 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
                    CVE-2026-72816 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
                    CVE-2026-72817 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that fixes 5 vulnerabilities is now available.

Description:

   This update for v2ray-core fixes the following issues:

   - Update version to 5.53.0
     * Add X-Forwarded-For support to gRPC transport
     * Add Stream based Packet Addr for UDP Connections
     * rrpit: compact session, async send, session recovery
     * Add socks5ify engineering command
     * Fix bugs
     * Update modules (boo#1276119 and CVE-2026-72817, CVE-2026-72815,
       CVE-2026-72816)

   - Update version to 5.51.2
     * Wireguard Add TCP Listener support for wireguard outbound
     * Stun Nat Type Testing
     * Better server failure detection and
       PreserveSourceIPPortWhenDestNATMapping detection
     * Improve API instance support
     * feat: grpc: allow configurable keepalive and initial windows size
     * Add RRPIT - Rapid Reliable Packet Interactive Transport
     * Add WebRTC Tunnel Support in V2Ray(unreleased)
     * also parse X-Forwarded-For in httpupgrade
     * gdocsviewer: Add Google Docs Viewer based transport
     * gdocsviewer: Refine poll logic and allow custom headers to reduce rate
       limiting
     * gdocsviewer: allow adding headers in public config
     * Fix bugs (boo#1258546 and CVE-2026-27017)

   - Update golang.org/x/net to 0.55.0 to fix boo#1266787 and CVE-2026-39821


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-307=1



Package List:

   - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

      v2ray-core-5.53.0-bp157.2.9.1

   - openSUSE Backports SLE-15-SP7 (noarch):

      golang-github-v2fly-v2ray-core-5.53.0-bp157.2.9.1


References:

   https://www.suse.com/security/cve/CVE-2026-27017.html
   https://www.suse.com/security/cve/CVE-2026-39821.html
   https://www.suse.com/security/cve/CVE-2026-72815.html
   https://www.suse.com/security/cve/CVE-2026-72816.html
   https://www.suse.com/security/cve/CVE-2026-72817.html
   https://bugzilla.suse.com/1258546
   https://bugzilla.suse.com/1266787
   https://bugzilla.suse.com/1276119
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.