🛡️ SUSE-SU-2026:2777-1 — cryptsetup (CVE-2026-41676)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for cryptsetup, s390-tools

This update for cryptsetup, s390-tools fixes the following issue

Security fixes:

  • CVE-2026-41676: openssl: Deriver:derive and PkeyCtxRef:derive can overflow short buffers on OpenSSL 1.1.1 (bsc#1270185).

Changes for s390-tools:

  • Upgrade s390-tools to version 2.41.0 (jsc#PED-15860)
  • Automatically set appropriate MTU for HSCI (bsc#1259314)
  • Changes of existing tools:
  • chreipl: Make --bootparms work for ECKD re-IPL
  • cpacfstats: Add 'unauthorized' state to CPU-MF counters
  • cpictl: Detect RHCOS using VARIANT_ID
  • hsci: Automatically set appropriate MTU for HSCI
  • libutil: Add util_readlink() and util_readlinkat() helpers
  • libutil: Add util_startswith() to util_str
  • libutil: Add utility parsing functions
  • lschp: Add support for structured output (--format)
  • lsreipl: Suppress 'clear' output if not supported
  • pvimg: Add '--format text' support to 'pvimg info'
  • pvimg: Add '--print-schema ' option to 'pvimg info'
  • pvimg: Add '--show-secrets' flag to 'pvimg info'
  • pvimg: Provide improved JSON output to 'pvimg info --format json'
  • pvinfo: Improve User experience on non-SE enabled systems
  • zipl/ngdump: Ensure ext4 file system is used on dump partition
  • zkey: Add support for integrity protected disks using HMAC keys
  • Bug Fixes:
  • cpumf/pai: Handle different size of perf_event_attr
  • lscss: Fix memory leak
  • zipl: Fix dump job on tape devices

--- s390-tools 2.40 includes ---

  • Add new tools / libraries:
  • Add project-wide .clang-tidy configuration
  • libutil: Introduce util_time for time related functionality
  • libutil: Introduce zsh/bash autocompletion tooling based on util_opt
  • pvinfo: Tool to display Secure Execution system information
  • pvverify: Tool to verify host-key documents
  • Changes of existing tools:
  • cpumf: Implement zsh and bash autocompletion
  • dasdfmt: Implement zsh and bash autocompletion
  • dbginfo.sh: Add NetworkManager and netplan
  • dbginfo.sh: Add kvm_stat
  • dbginfo.sh: Adding stp time information
  • dbginfo.sh: Simplify procfs collection
  • hyptop: Add physical information row
  • hyptop: Calculate sample time delta for physical partition
  • hyptop: Replace long option names using _ with - for consistency

For example: --cpu_types > --cpu-types

(Options with _ are still supported for backward compatibility)

  • libekmfweb: Add function to validate a certificate against the identity key
  • netboot: Add longer kernel command lines support
  • udev/rules.d: Make virtio-blk devices non-rotational
  • udev/rules.d: Set default io scheduler to 'none' for virtio-blk
  • ziomon: Add support to sample device symlinks (/dev/disk/...)
  • ziorep_config: Add fcp-lun details to -M option output
  • ziorep_config: Add port_id and failed attributes to -A option output
  • netboot: Install on non-s390 architectures
  • Bug Fixes:
  • lib(ekmfweb|kmipclient): Use ln without -r
  • s390-tools: Fix various compilation issues with musl libc
  • zipl/boot: Fix unused loadparm when SCLP line-mode console is absent

--- s390-tools 2.39 includes ---

  • Changes of existing tools:
  • chpstat: Add options to select IEC units for scaling (SI units are default)
  • chzdev: Introduce --no-module-load option
  • cpi: Disable CPI for SEL guests by default
  • dbginfo.sh: Enhance logging on timeout triggered
  • iucvterm: Install symlink for lsiucvallow.8 man page
  • lshwc: Add command line flag to specify individual counters
  • lspai: Add command line flag for delta values
  • lspai: Add command line flag for short counter names
  • lspai: Add command line flag to specify individual counters
  • lspai: Add command line flags for all cpus
  • lspai: Add command line flags for hexadecimal output
  • man: Use CR for constant width font
  • pvimg: Add '--image-key' option
  • zdev: Allow dynamic control of module load
  • zipl/boot: Fix EBCDIC code page 500 conversion and decrease size by 200 bytes
  • zipl: Add support of heterogeneous mirrors (remove technical limitations

on mirrored targets, thus allowing mirrored devices consist of partitions

at different offsets on disks of different types and geometry).

  • zkey: Add support for generating and importing exportable secure keys
  • Bug Fixes:
  • chpstat: Fix scaling of DPU utilization calculation
  • zdev/dracut: Prevent loading of unused kernel modules
  • zdev: Fix double device configuration on DPM systems
  • zdev: Fix double device configuration with rd.dasd
  • zipl_helper.device-mapper: Fix segfault in an error path

--- s390-tools 2.38 includes ---

  • Add new tools
  • udev: New rule to set newly hotplugged CPUs online
  • zmemtopo: Display memory topology information
  • zpwr: Display power readings of a partition and CPC
  • Removed tools / features
  • check_hostkeydoc: Remove installation target
  • scsi_logging_level: Delete SCSI logging script (available in sg3_utils)
  • zdump: Drop build_arch for s390 DAS

Affected software

SUSE-SU-2026:2777-1 is recorded against 2 packages.

  • cryptsetup (fixed in 2.8.4-150700.6.4.4)
  • s390-tools (fixed in 2.41.0-150700.4.26.2)

Timeline and source

Published on 6 July 2026 and last revised on 7 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-06
Updated 2026-08-20
Modified 2026-07-07
Fix URL N/A

Affected Packages

Software From version Fixed in
cryptsetup 2.8.4-150700.6.4.4
s390-tools 2.41.0-150700.4.26.2

Similar Threats

Free Vulnerability Check

Is your site affected by SUSE-SU-2026:2777-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:2777-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2026