Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Fedora has released an update for the .NET Runtime and SDK, version 9.0.119, addressing multiple security vulnerabilities and enhancing the platform for cross-platform application development.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d6b061ad69 2026-07-24 00:56:22.694806+00:00 -------------------------------------------------------------------------------- Name : dotnet9.0 Product : Fedora 44 Version : 9.0.119 Release : 1.fc44 URL : https://github.com/dotnet/ Summary : .NET Runtime and SDK Description : .NET is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything. -------------------------------------------------------------------------------- Update Information: Update to .NET SDK 9.0.119 and Runtime 9.0.18 Fixes: CVE-2026-47300,CVE-2026-47302,CVE-2026-47303,CVE-2026-47304,CVE-2026- 50524,CVE-2026-50525,CVE-2026-50526,CVE-2026-50527,CVE-2026-50528,CVE-2026- 50646,CVE-2026-50648,CVE-2026-50649,CVE-2026-50650,CVE-2026-50651,CVE-2026- 50659,CVE-2026-56158,CVE-2026-57108 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.18/9.0.119.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.18/9.0.18.md -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 14 2026 Omair Majid - 9.0.119-1 - Update to .NET SDK 9.0.119 and Runtime 9.0.18 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d6b061ad69' at thecommand line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fedora 44 has updated cryptlib to version 3.4.9.3, enhancing encryption and authentication services while preparing for the deprecation of obsolete algorithms in the upcoming release.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-e4349a03b1 2026-07-24 00:56:22.694797+00:00 -------------------------------------------------------------------------------- Name : cryptlib Product : Fedora 44 Version : 3.4.9.3 Release : 1.fc44 URL : https://github.com/cryptlib/cryptlib Summary : Security library and toolkit for encryption and authentication services Description : Cryptlib is a powerful security toolkit that allows even inexperienced crypto programmers to easily add encryption and authentication services to their software. The high-level interface provides anyone with the ability to add strong security capabilities to an application in as little as half an hour, without needing to know any of the low-level details that make the encryption or authentication work. Because of this, cryptlib dramatically reduces the cost involved in adding security to new or existing applications. At the highest level, cryptlib provides implementations of complete security services such as S/MIME and PGP/OpenPGP secure enveloping, SSL/TLS and SSH secure sessions, CA services such as CMP, SCEP, RTCS, and OCSP, and other security operations such as secure time-stamping. Since cryptlib uses industry-standard X.509, S/MIME, PGP/OpenPGP, and SSH/SSL/TLS data formats, the resulting encrypted or signed data can be easily transported to other systems and processed there, and cryptlib itself runs on virtually any operating system - cryptlib doesn't tie you to a single system. This allows email, files and EDI transactions to be authenticated with digital signatures and encrypted in an industry-standard format. -------------------------------------------------------------------------------- UpdateInformation: A third update after 3.4.9 to prepare for deprecation of obsolete algorithms and attributes in the upcoming 3.5 release. -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 14 2026 Ralf Senderek 3.4.9.3-1 - Update Cryptlib to version 3.4.9.3 * Sat Jun 27 2026 Ralf Senderek 3.4.9.2-2 - Add cltls version 1.0 to the cryptlib tools * Wed Jun 10 2026 Ralf Senderek 3.4.9.2-1 - update Cryptlib to version 3.4.9.2 * Wed Jun 3 2026 Python Maint - 3.4.9.1-2 - Rebuilt for Python 3.15 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e4349a03b1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fedora 44 updated python-black to version 26.5.1, addressing vulnerabilities CVE-2026-31900 and CVE-2026-32274, enhancing functionality as a Python code formatter.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3805ba3721 2026-07-24 00:56:22.694785+00:00 -------------------------------------------------------------------------------- Name : python-black Product : Fedora 44 Version : 26.5.1 Release : 1.fc44 URL : https://github.com/psf/black Summary : The uncompromising code formatter Description : Black is the uncompromising Python code formatter. By using it, you agree to cease control over minutiae of hand-formatting. In return, Black gives you speed, determinism, and freedom from pycodestyle nagging about formatting. You will save time and mental energy for more important matters. -------------------------------------------------------------------------------- Update Information: Upgrade to 26.5.1, solves serious vulnerabilities such as: CVE-2026-31900 CVE-2026-32274 -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 9 2026 Simone Tollardo - 26.5.1-1 - Update python-black to 26.5.1 - Fixes: rhbz#2396612 * Thu Jun 4 2026 Python Maint - 25.1.0-9 - Rebuilt for Python 3.15 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3805ba3721' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The Fedora update for python-pytokens version 0.4.1 addresses serious vulnerabilities, ensuring compliance and functionality across Python versions, with installation instructions provided.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3805ba3721 2026-07-24 00:56:22.694785+00:00 -------------------------------------------------------------------------------- Name : python-pytokens Product : Fedora 44 Version : 0.4.1 Release : 4.fc44 URL : https://github.com/tusharsadhwani/pytokens Summary : A fast, spec compliant Python 3.14+ tokenizer Description : A Fast, spec compliant Python 3.14+ tokenizer that runs on older Pythons. -------------------------------------------------------------------------------- Update Information: Upgrade to 26.5.1, solves serious vulnerabilities such as: CVE-2026-31900 CVE-2026-32274 -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 8 2026 Simone Tollardo - 0.4.1-4 - spec: add newline EOF * Wed Jul 8 2026 Simone Tollardo - 0.4.1-3 - ignore: ignore local build folder, match all pytokens tar versions * Wed Jul 8 2026 Simone Tollardo - 0.4.1-2 - Add rpmlintrc * Wed Jul 8 2026 Simone Tollardo - 0.4.1-1 - Initial import (fedora#2497706). -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3805ba3721' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The Fedora 44 update for python-lsp-black version 2.0.0 addresses serious vulnerabilities, enhances compatibility with black autoformatter, and can be installed using the dnf update tool.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3805ba3721 2026-07-24 00:56:22.694785+00:00 -------------------------------------------------------------------------------- Name : python-lsp-black Product : Fedora 44 Version : 2.0.0 Release : 17.fc44 URL : https://github.com/python-lsp/python-lsp-black Summary : A python-lsp-server plugin that adds support to black autoformatter Description : lsp-black is a python-lsp-server plugin that adds support to black autoformatter. This is forked from pyls-black to be compatible wth community maintained language-server (python-lsp-server). -------------------------------------------------------------------------------- Update Information: Upgrade to 26.5.1, solves serious vulnerabilities such as: CVE-2026-31900 CVE-2026-32274 -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 14 2026 Benjamin A. Beasley - 2.0.0-17 - Fix compatibility with black≥26.5 (fixes RHBZ#2485891) * Tue Jul 14 2026 Benjamin A. Beasley - 2.0.0-16 - Patch for pkg_resources removal from setuptools * Tue Jul 14 2026 Tomáš Hrnčiar - 2.0.0-15 - Fix invalid extras in %pyproject_buildrequires -x * Tue Jun 16 2026 Python Maint - 2.0.0-14 - Rebuilt for Python 3.15 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3805ba3721' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Upgrade python-lsp-black in Fedora 44 to address critical vulnerabilities like CVE-2026-31900 and CVE-2026-32274.. python-lsp-black update, Fedora security alert, CVE-2026-31900, CVE-2026-32274. . Severity: Critical. LinuxSecurity.com Team
SUSE released a security update for python-aiohttp addressing 19 vulnerabilities, including memory usage issues and denial of service risks across multiple SUSE products and enterprise servers.. # Security update for python-aiohttp Announcement ID: SUSE-SU-2026:3207-1 Release Date: 2026-07-23T14:10:51Z Rating: important References: * bsc#1261320 * bsc#1261321 * bsc#1261322 * bsc#1261329 * bsc#1261331 * bsc#1261332 * bsc#1261334 * bsc#1261335 * bsc#1261343 * bsc#1267471 * bsc#1267561 * bsc#1268398 * bsc#1268543 * bsc#1268544 * bsc#1268549 * bsc#1268556 * bsc#1268559 * bsc#1268560 * bsc#1268561 Cross-References: * CVE-2026-22815 * CVE-2026-34513 * CVE-2026-34514 * CVE-2026-34516 * CVE-2026-34517 * CVE-2026-34518 * CVE-2026-34519 * CVE-2026-34520 * CVE-2026-34525 * CVE-2026-34993 * CVE-2026-47265 * CVE-2026-50269 * CVE-2026-54273 * CVE-2026-54274 * CVE-2026-54275 * CVE-2026-54277 * CVE-2026-54278 * CVE-2026-54279 * CVE-2026-54280 CVSS scores: * CVE-2026-22815 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22815 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22815 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-22815 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34513 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34513 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34513 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34513 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34514 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-34514 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-34514 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34514 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34516 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34516 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34516 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34516 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34517 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34517 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-34517 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34517 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34518 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34518 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34518 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34518 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34519 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34519 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34519 (NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34519 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34520 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34520 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34520 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34520 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-34525 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-34525 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-34525 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34525 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34993 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-34993 ( NVD ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H * CVE-2026-34993 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L * CVE-2026-34993 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-47265 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-47265 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47265 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-50269 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-50269 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-50269 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54273 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54273 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54273 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54274 ( SUSE ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U * CVE-2026-54274 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54274 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54274 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54275 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-54275 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54275 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54277 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54277 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54277 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54278 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-54278 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54278 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54278 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54279 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-54279 ( NVD ): 1.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54279 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54280 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-54280 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54280 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAPApplications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for python-aiohttp fixes the following issues * CVE-2026-22815: insufficient restrictions in header/trailer handling can cause uncapped memory usage and a denial of service (bsc#1261320). * CVE-2026-34513: unbounded DNS cache can cause a excessive memory usage and lead to a denial of service (bsc#1261321). * CVE-2026-34514: `content_type` parameter manipulation can lead to header injection (bsc#1261322). * CVE-2026-34516: response with excessive multipart headers can use more memory than intended and cause a denial of service (bsc#1261329). * CVE-2026-34517: large multipart form fields read into memory without size check can cause a denial of service (bsc#1261331). * CVE-2026-34518: retained `Cookie` and `Proxy-Authorization` headers when following redirects can lead to information disclosure (bsc#1261332). * CVE-2026-34519: response `reason` parameter can be use to perform header injection (bsc#1261334). * CVE-2026-34520: improper character handling by C parser can lead to header injection (bsc#1261335). * CVE-2026-34525: multiple `Host` headers allow for potential security bypass in proxy servers (bsc#1261343). * CVE-2026-34993: loading untrusted input in `CookieJar.load()` can lead to arbitrary code execution (bsc#1267471). * CVE-2026-47265: cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect and can leak sensitive data (bsc#1267561). * CVE-2026-50269: improper validation of user-controlled strings allows for CRLF injection in multipart headers (bsc#1268398). * CVE-2026-54273: no limit in the HTTP/1 pipelined request queue can lead to excessive resource consumption (bsc#1268543). * CVE-2026-54274: incomplete websocket frame payloads can bypass memory use limits and cause a DoS via excessive resource consumption (bsc#1268544). * CVE-2026-54275: `server_hostname` TLS SNI check bypass when an existing connection is reused (bsc#1268549). * CVE-2026-54277: `max_line_size` bypass when using the optimised C HTTP parser can lead to excessive resource consumption (bsc#1268556). * CVE-2026-54278: unread compressed request bodies can bypass `client_max_size` during cleanup and cause a DoS (bsc#1268559). * CVE-2026-54279: host-only cookies become domain cookies after `CookieJar` persistence (bsc#1268560). * CVE-2026-54280: payload resources are not closed correctly when a client disconnects in the middle of a write and can cause resource starvation (bsc#1268561). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3207=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3207=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3207=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3207=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3207=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3207=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3207=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3207=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3207=1 * SUSE Linux Enterprise HighPerformance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3207=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3207=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3207=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3207=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5(ppc64le x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python311-aiohttp-3.9.3-150400.10.43.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.43.1 * python-aiohttp-debugsource-3.9.3-150400.10.43.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22815.html * https://www.suse.com/security/cve/CVE-2026-34513.html * https://www.suse.com/security/cve/CVE-2026-34514.html * https://www.suse.com/security/cve/CVE-2026-34516.html * https://www.suse.com/security/cve/CVE-2026-34517.html * https://www.suse.com/security/cve/CVE-2026-34518.html * https://www.suse.com/security/cve/CVE-2026-34519.html * https://www.suse.com/security/cve/CVE-2026-34520.html * https://www.suse.com/security/cve/CVE-2026-34525.html * https://www.suse.com/security/cve/CVE-2026-34993.html * https://www.suse.com/security/cve/CVE-2026-47265.html * https://www.suse.com/security/cve/CVE-2026-50269.html *https://www.suse.com/security/cve/CVE-2026-54273.html * https://www.suse.com/security/cve/CVE-2026-54274.html * https://www.suse.com/security/cve/CVE-2026-54275.html * https://www.suse.com/security/cve/CVE-2026-54277.html * https://www.suse.com/security/cve/CVE-2026-54278.html * https://www.suse.com/security/cve/CVE-2026-54279.html * https://www.suse.com/security/cve/CVE-2026-54280.html * https://bugzilla.suse.com/show_bug.cgi?id=1261320 * https://bugzilla.suse.com/show_bug.cgi?id=1261321 * https://bugzilla.suse.com/show_bug.cgi?id=1261322 * https://bugzilla.suse.com/show_bug.cgi?id=1261329 * https://bugzilla.suse.com/show_bug.cgi?id=1261331 * https://bugzilla.suse.com/show_bug.cgi?id=1261332 * https://bugzilla.suse.com/show_bug.cgi?id=1261334 * https://bugzilla.suse.com/show_bug.cgi?id=1261335 * https://bugzilla.suse.com/show_bug.cgi?id=1261343 * https://bugzilla.suse.com/show_bug.cgi?id=1267471 * https://bugzilla.suse.com/show_bug.cgi?id=1267561 * https://bugzilla.suse.com/show_bug.cgi?id=1268398 * https://bugzilla.suse.com/show_bug.cgi?id=1268543 * https://bugzilla.suse.com/show_bug.cgi?id=1268544 * https://bugzilla.suse.com/show_bug.cgi?id=1268549 * https://bugzilla.suse.com/show_bug.cgi?id=1268556 * https://bugzilla.suse.com/show_bug.cgi?id=1268559 * https://bugzilla.suse.com/show_bug.cgi?id=1268560 * https://bugzilla.suse.com/show_bug.cgi?id=1268561 . This update for python-aiohttp addresses 19 critical vulnerabilities associated with potential denial of service risks. openSUSE patches, python-aiohttp updates, security advisories, Linux application security, SUSE vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Multiple security vulnerabilities in the Squid proxy server were addressed, leading to information disclosure and denial of service. Users are advised to update their packages for Debian 11 and 12.. Debian LTS Advisory DLA-4697-1
Slackware has released updated mozilla-thunderbird packages for version 15.0 and -current, addressing various security issues and improvements in the software.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] mozilla-thunderbird (SSA:2026-204-01) New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/mozilla-thunderbird-140.13.0esr-i686-1_slack15.0.txz: Upgraded. This release contains security fixes and improvements. For more information, see: https://www.mozilla.org/en-US/thunderbird/140.13.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/ https://www.cve.org/CVERecord?id=CVE-2026-14899 https://www.cve.org/CVERecord?id=CVE-2026-15718 https://www.cve.org/CVERecord?id=CVE-2026-15719 https://www.cve.org/CVERecord?id=CVE-2026-16349 https://www.cve.org/CVERecord?id=CVE-2026-16350 https://www.cve.org/CVERecord?id=CVE-2026-16362 https://www.cve.org/CVERecord?id=CVE-2026-16351 https://www.cve.org/CVERecord?id=CVE-2026-16352 https://www.cve.org/CVERecord?id=CVE-2026-16363 https://www.cve.org/CVERecord?id=CVE-2026-16353 https://www.cve.org/CVERecord?id=CVE-2026-16354 https://www.cve.org/CVERecord?id=CVE-2026-16368 https://www.cve.org/CVERecord?id=CVE-2026-16369 https://www.cve.org/CVERecord?id=CVE-2026-16355 https://www.cve.org/CVERecord?id=CVE-2026-16356 https://www.cve.org/CVERecord?id=CVE-2026-16357 https://www.cve.org/CVERecord?id=CVE-2026-16371 https://www.cve.org/CVERecord?id=CVE-2026-16374 https://www.cve.org/CVERecord?id=CVE-2026-16375 https://www.cve.org/CVERecord?id=CVE-2026-16377 https://www.cve.org/CVERecord?id=CVE-2026-16379 https://www.cve.org/CVERecord?id=CVE-2026-16358 https://www.cve.org/CVERecord?id=CVE-2026-16381 https://www.cve.org/CVERecord?id=CVE-2026-16383 https://www.cve.org/CVERecord?id=CVE-2026-16387 https://www.cve.org/CVERecord?id=CVE-2026-16390 https://www.cve.org/CVERecord?id=CVE-2026-16391 https://www.cve.org/CVERecord?id=CVE-2026-16359 https://www.cve.org/CVERecord?id=CVE-2026-16396 https://www.cve.org/CVERecord?id=CVE-2026-16405 https://www.cve.org/CVERecord?id=CVE-2026-16412 https://www.cve.org/CVERecord?id=CVE-2026-16360 https://www.cve.org/CVERecord?id=CVE-2026-16361 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://slackware.com for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mozilla-thunderbird-140.13.0esr-i686-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/mozilla-thunderbird-140.13.0esr-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/mozilla-thunderbird-140.13.0esr-i686-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/mozilla-thunderbird-140.13.0esr-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: a8c3c2cdc9a5760ca4e65321f2d7a814 mozilla-thunderbird-140.13.0esr-i686-1_slack15.0.txz Slackware x86_64 15.0 package: 806fdd91963f3dafdacdc43146fa8d5b mozilla-thunderbird-140.13.0esr-x86_64-1_slack15.0.txz Slackware -current package: 505652efc7e0741a944e543d8c03c95a xap/mozilla-thunderbird-140.13.0esr-i686-1.txz Slackware x86_64 -current package: c1bc63c6b4adcc6960bc1f5584027d3e xap/mozilla-thunderbird-140.13.0esr-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package asroot: # upgradepkg mozilla-thunderbird-140.13.0esr-i686-1_slack15.0.txz +-----+ . New mozilla-thunderbird packages have been released for Slackware 15.0 to address critical security issues and improvements.. Mozilla Thunderbird Packages, Slackware Security Update, Security Issues Fix, Package Upgrades. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.