CVE-2019-18898: Opensuse Leap

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.

Affected products

  • Opensuse Leap: version 15.1 only
  • Suse Trousers: before 0.3.14-6.3.1 (fixed in 0.3.14-6.3.1); before 0.3.14-7.1 (fixed in 0.3.14-7.1)

Published 2020-01-23. Last modified 2026-06-17.