SUSE Linux security advisory (AV26-968)
Canadian Cyber Centre warns SUSE NeuVector packet-capture filter command injection enables remote code execution on Kubernetes nodes; update advised.
The Canadian Centre for Cyber Security issued advisory AV26-968 on September 28, 2026, covering a vulnerability in SUSE NeuVector affecting versions prior to 5.4.11, 5.5.4, and 5.6.2. The flaw is an OS command injection in the packet-capture (sniffer) filter that can lead to remote code execution on Kubernetes nodes. Users and administrators are encouraged to review the linked SUSE update advisories and apply patches.
- Affects NeuVector before 5.4.11, 5.5.4, and 5.6.2
- OS command injection in sniffer filter leads to RCE on Kubernetes nodes
- Cyber Centre urges applying SUSE updates as they become available
Full article72 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-968
Date: September 28, 2026
As of September 28, 2026, SUSE is affected by a vulnerability in the following product:
- NeuVector
- Prior to 5.4.11
- Prior to 5.5.4
- Prior to 5.6.2
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/suse-linux-security-advisory-av26-968