|
|
Log in / Subscribe / Register

SUSE alert openSUSE-SU-2026:21190-1 (openbabel)

From:  null@suse.de
To:  security-announce@lists.opensuse.org
Subject:  openSUSE-SU-2026:21190-1: critical: Security update for openbabel
Date:  Thu, 02 Jul 2026 17:51:27 +0200
Message-ID:  <20260702155127.EA91DFCE5@maintenance.suse.de>
Archive-link:  Article

openSUSE security update: security update for openbabel ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21190-1 Rating: critical References: * bsc#1217676 * bsc#1258501 * bsc#1258507 * bsc#1259041 Cross-References: * CVE-2022-37331 * CVE-2022-41793 * CVE-2022-42885 * CVE-2022-43467 * CVE-2022-43607 * CVE-2022-44451 * CVE-2022-46280 * CVE-2022-46289 * CVE-2022-46290 * CVE-2022-46291 * CVE-2022-46292 * CVE-2022-46294 * CVE-2022-46295 * CVE-2025-10994 * CVE-2025-10995 * CVE-2025-10996 * CVE-2025-10997 * CVE-2025-10998 * CVE-2025-10999 * CVE-2025-11000 * CVE-2026-2704 * CVE-2026-2705 * CVE-2026-3408 CVSS scores: * CVE-2025-10994 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2025-10995 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2025-10996 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2025-10997 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2025-10998 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-10999 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 23 vulnerabilities and has 4 bug fixes can now be installed. Description: This update for openbabel fixes the following issues: Changes in openbabel: - Update to version 3.2.0: * Add an L-BFGS optimizer, used by default for gen3d and conformer searches * New macrocycle ring builder (Dale codes) for better initial 3D geometry of large rings * Add KET (Ketcher JSON) and ChemicalJSON (.cjson) format support * Drop Python 2 support; Python 3.13 supported * Faster, vectorized distance-geometry implementation * Full CMake 4 compatibility and modernized build * Backwards compatible with 3.0 and 3.1 * Fix many crash and memory-safety bugs found via OSS-Fuzz and TALOS, including the following security issues: CVE-2022-37331 (boo#1217676), CVE-2022-41793, CVE-2022-42885, CVE-2022-43467, CVE-2022-43607, CVE-2022-44451, CVE-2022-46280, CVE-2022-46289, CVE-2022-46290, CVE-2022-46291, CVE-2022-46292, CVE-2022-46294, CVE-2022-46295, CVE-2025-10994, CVE-2025-10995, CVE-2025-10996, CVE-2025-10997, CVE-2025-10998, CVE-2025-10999, CVE-2025-11000, CVE-2026-2704 (boo#1258501), CVE-2026-2705 (boo#1258507) and CVE-2026-3408 (boo#1259041) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-385=1 Package List: - openSUSE Leap 16.0: libopenbabel8-3.2.0-bp160.1.1 openbabel-3.2.0-bp160.1.1 openbabel-devel-3.2.0-bp160.1.1 openbabel-gui-3.2.0-bp160.1.1 python3-openbabel-3.2.0-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2022-37331.html * https://www.suse.com/security/cve/CVE-2022-41793.html * https://www.suse.com/security/cve/CVE-2022-42885.html * https://www.suse.com/security/cve/CVE-2022-43467.html * https://www.suse.com/security/cve/CVE-2022-43607.html * https://www.suse.com/security/cve/CVE-2022-44451.html * https://www.suse.com/security/cve/CVE-2022-46280.html * https://www.suse.com/security/cve/CVE-2022-46289.html * https://www.suse.com/security/cve/CVE-2022-46290.html * https://www.suse.com/security/cve/CVE-2022-46291.html * https://www.suse.com/security/cve/CVE-2022-46292.html * https://www.suse.com/security/cve/CVE-2022-46294.html * https://www.suse.com/security/cve/CVE-2022-46295.html * https://www.suse.com/security/cve/CVE-2025-10994.html * https://www.suse.com/security/cve/CVE-2025-10995.html * https://www.suse.com/security/cve/CVE-2025-10996.html * https://www.suse.com/security/cve/CVE-2025-10997.html * https://www.suse.com/security/cve/CVE-2025-10998.html * https://www.suse.com/security/cve/CVE-2025-10999.html * https://www.suse.com/security/cve/CVE-2025-11000.html * https://www.suse.com/security/cve/CVE-2026-2704.html * https://www.suse.com/security/cve/CVE-2026-2705.html * https://www.suse.com/security/cve/CVE-2026-3408.html


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds