The entry for the new CVE-2026-24072 from two days ago mentions openSUSE Leap 15.3, 15.4 and 15.5 as no longer supported but omits Leap 15.6, 16.0, 16.1 and Tumbleweed altogether.
I have a somewhat uncomfortable feeling with a distribution no longer offering CVE tracking in those challenging times like now or did I overlook something obvious.
A possible explanation is, the time stamps – the SUSE statement published via Planet openSUSE, is dated the 3rd of May 2026 – the CVE page was last modified on the 7th of May 2026 …
Possibly the CVE page will receive some more changes …
*) SECURITY: CVE-2026-24072: Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr [boo#1263935]
An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
Users are recommended to upgrade to version 2.4.67, which fixes this issue.
Thanks for the information which was quite helpful. What still remains uncertain to me is why the official SUSE CVE still no longer mentions the latest openSUSE editions.
In the past it was very helpful to have a single place (SUSE CVE Website) where status of all vulnerabilites could have been tracked from a single place.
AFAICS, the Apache2 change related to CVE-2026-24072 are in a “waiting for release” state – about 23 hours ago the “factory-maintainer” submitted the changes for a final review before release – <https://build.opensuse.org/requests/1353166>
At a guess, the CVE status will be change once the repair hits the streets …
I’m not quite sure about that. If you take a look at the CVE page in question you could see, that openSuse 15.6 and up and also Tumbleweed are not even mentioned with status “affected”.
In the past you were able to track lifecycle of an CVE also for openSUSE on the SUSE CVE page, starting with “affected” and then transitioning to “released” over time with links to the related packages.
The repair has been released for Tumbleweed with snapshot 20260516 …
Currently here with Apache version 2.4.67-1.1 and the repair for CVE-2026-24072 is included.
The SUSE CVE-2026-24072 URL now mentions the Tumbleweed change – presumably the rest of the affected systems will mentioned soon – <CVE-2026-24072>
two things: openSUSE Leap 15.6 is now EOL and not receiving updates anymore.
openSUSE Leap 16.0 had a problem where the patches were not published correctly, but this has happened today and CVE pages have been updated with recent updates.
two things: openSUSE Leap 15.6 is now EOL and not receiving updates anymore.
Two things: This does not explain why Leap 15.6 is missing in the CVE at all. Leap 15.3, 15.4 and 15.5 are mentioned there as being affected and not receiving any updates as being EoL. Leap 16.0 was now added as being affected and receiving updates.
In the past Leap versions sometimes received updates although being EoL especially if it was the last release before a major release. Update repo of Leap 15.6 was last updated just two days ago on 18th May 2026.
openSUSE Leap 16.0 had a problem where the patches were not published correctly, but this has happened today and CVE pages have been updated with recent updates.
Thank you for that information. Can you share the link of that CVE you mentioned where the update for 16.0 is stated as being released? In the CVE link I shared here in the forum it is still mentioned as “Affected” and not even as “In progress” which would be the next status in lifecycle.
I have no problem dealing with CVE-2026-24072. However i had the perhaps naive expectation that a patch would show up after a while if it had been published.
Just for the record. CVE was updated today, mentioning that a package was released for openSuse Leap 15.6. Leap 16.0 however is still only stated as “Affected”. Repo of 16.0 shows apache packages only two days old but they all show version number “2.4.66-160000.1.1”.