VendorsopenSUSEtumbleweedall versions
Vulnerabilities

openSUSE Tumbleweed

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2021-25315
salt-api unauthenticated remote code execution
Published 2021-03-03 · Modified
9.8EPSS 0.023
CVE-2022-28321
The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via DNS. In such conditions, a user with denied access to a machine can still get access. NOTE: the relevance of this issue is largely limited to openSUSE Tumbleweed and openSUSE Factory; it does not affect Linux-PAM upstream.
Published 2022-09-19 · Modified
9.8EPSS 0.015
CVE-2020-8026
inn: non-root owned files
Published 2020-08-07 · Modified
8.4EPSS 0.004
CVE-2022-31250
keylime %post scriplet allows for privilege escalation from keylime user to root
Published 2022-07-20 · Modified
7.8EPSS 0.003
CVE-2023-32183
Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root This issue affects openSUSE Tumbleweed.
Published 2023-07-07 · Modified
7.8EPSS 0.002
CVE-2025-62875
Local DoS in OpenSMTPD via UNIX domain socket smtpd.sock
Published 2025-11-20 · Analyzed
6.9EPSS 0.002