Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
A vulnerability was found in the Python SDK for Sentry.io The issue results in the unintentional exposure of environment variables to subprocesses despite the env={} setting. For Debian 11 bullseye, this problem has been fixed in version 0.13.2-1+deb11u1.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4612-1
Multiple vulnerabilities have been found in Keystone, the OpenStack identity service, including privilege escalation and authorization and access control flaws. CVE-2026-33551 An authenticated user with only a reader role may obtain an EC2/S3. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4611-1
Two security vulnerabilities have been discovered in Cyborg, the OpenStack component for management of hardware accelerators, which could result in incomplete access controls. For the stable distribution (trixie), these problems have been fixed in version 14.0.0-3+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6315-1
Alistair Coles discovered that the s3api middleware of Swift, a distributed virtual object store, was susceptible to denial of service. The oldstable distribution (bookworm) is not affected. For the stable distribution (trixie), this problem has been fixed in version 2.35.1-0+deb13u2.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6314-1
Multiple vulnerabilities have been discovered in the Dovecot IMAP server which way result in denial of service, SQL injection or man-in-the-midddle attacks For the oldstable distribution (bookworm), these problems have been fixed in version 1:2.3.19.1+dfsg1-2.1+deb12u6.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6313-1
In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository's working tree with the contents of Git LFS objects, certain Git LFS commands could write to files visible outside the current Git working tree if symbolic or hard links existed which collided with the paths of files tracked by Git LFS.. Debian LTS Advisory DLA-4610-1
Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to a bypass of security controls, cross-site scripting, denial of service, SQL injection, email header injection, information disclosure or code execution via PHP object deserialization. For the stable distribution (trixie), these problems have been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6312-1
4.4.3 Release. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9fd50b2ff1 2026-05-31 01:13:21.121569+00:00 -------------------------------------------------------------------------------- Name : netatalk Product : Fedora 43 Version : 4.4.3 Release : 1.fc43 URL : http://netatalk.sourceforge.net Summary : Open Source Apple Filing Protocol(AFP) File Server Description : Netatalk is a freely-available Open Source AFP file server. A *NIX/*BSD system running Netatalk is capable of serving many Macintosh clients simultaneously as an AppleShare file server (AFP). In addition to the AFP file server daemon, the following utility programs are also included: * ad - AppleDouble file utility suite * afpldaptest - validate Netatalk LDAP parameters * afppasswd - RandNum UAM password management * afpstats - inquire AFP server usage stats * asip-status - inquire AFP server capabilities * dbd - CNID database maintenance * macusers - list connected AFP server users -------------------------------------------------------------------------------- Update Information: 4.4.3 Release -------------------------------------------------------------------------------- ChangeLog: -------------------------------------------------------------------------------- References: [ 1 ] Bug #2459261 - netatalk-4.4.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2459261 [ 2 ] Bug #2480439 - CVE-2026-44057 netatalk: Netatalk: Information disclosure via crafted Spotlight RPC requests [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480439 [ 3 ] Bug #2480440 - CVE-2026-44057 netatalk: Netatalk: Information disclosure via crafted Spotlight RPC requests [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480440 [ 4 ] Bug #2480449 - CVE-2026-44049 netatalk: Netatalk: Arbitrary code execution via out-of-bounds write[fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480449 [ 5 ] Bug #2480450 - CVE-2026-44049 netatalk: Netatalk: Arbitrary code execution via out-of-bounds write [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480450 [ 6 ] Bug #2480467 - CVE-2026-44069 netatalk: Netatalk: Integer underflow vulnerability in volxlate function [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480467 [ 7 ] Bug #2480470 - CVE-2026-44052 netatalk: Netatalk: Information Disclosure via ldap simple-bind password exposure in logs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480470 [ 8 ] Bug #2480471 - CVE-2026-44052 netatalk: Netatalk: Information Disclosure via ldap simple-bind password exposure in logs [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480471 [ 9 ] Bug #2480472 - CVE-2026-44054 netatalk: Netatalk: Denial of Service via predictable session token [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480472 [ 10 ] Bug #2480473 - CVE-2026-44054 netatalk: Netatalk: Denial of Service via predictable session token [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480473 [ 11 ] Bug #2480478 - CVE-2026-44062 netatalk: Netatalk: Arbitrary code execution or denial of service due to missing bounds check [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480478 [ 12 ] Bug #2480479 - CVE-2026-44062 netatalk: Netatalk: Arbitrary code execution or denial of service due to missing bounds check [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480479 [ 13 ] Bug #2480483 - CVE-2026-44068 netatalk: Netatalk: Arbitrary file access via path traversal [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480483 [ 14 ] Bug #2480486 - CVE-2026-44076 netatalk: Netatalk: Arbitrary Code Execution via shell injection in volume path [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480486 [ 15 ] Bug #2480487 - CVE-2026-44076 netatalk: Netatalk:Arbitrary Code Execution via shell injection in volume path [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480487 [ 16 ] Bug #2480488 - CVE-2026-44060 netatalk: Netatalk: Denial of Service via integer underflow [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480488 [ 17 ] Bug #2480489 - CVE-2026-44060 netatalk: Netatalk: Denial of Service via integer underflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480489 [ 18 ] Bug #2480490 - CVE-2026-44055 netatalk: Netatalk: Arbitrary code execution via shell injection [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480490 [ 19 ] Bug #2480491 - CVE-2026-44055 netatalk: Netatalk: Arbitrary code execution via shell injection [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480491 [ 20 ] Bug #2480496 - CVE-2026-44050 netatalk: Netatalk: Arbitrary code execution via heap buffer overflow in cnid daemon [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480496 [ 21 ] Bug #2480497 - CVE-2026-44050 netatalk: Netatalk: Arbitrary code execution via heap buffer overflow in cnid daemon [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480497 [ 22 ] Bug #2480501 - CVE-2026-44047 netatalk: Netatalk: Arbitrary code execution and data compromise via SQL injection [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480501 [ 23 ] Bug #2480502 - CVE-2026-44047 netatalk: Netatalk: Arbitrary code execution and data compromise via SQL injection [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480502 [ 24 ] Bug #2480624 - CVE-2026-44048 netatalk: stack buffer overflow via UCS-2 type confusion in convert_charset() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480624 [ 25 ] Bug #2480625 - CVE-2026-44048 netatalk: stack buffer overflow via UCS-2 type confusion in convert_charset() [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480625 [ 26 ] Bug #2480626 - CVE-2026-44066netatalk: heap out-of-bounds reads in Spotlight RPC unmarshalling [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480626 [ 27 ] Bug #2480627 - CVE-2026-44066 netatalk: heap out-of-bounds reads in Spotlight RPC unmarshalling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480627 [ 28 ] Bug #2480628 - CVE-2026-44064 netatalk: ASP session ID out-of-bounds access [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480628 [ 29 ] Bug #2480629 - CVE-2026-44064 netatalk: ASP session ID out-of-bounds access [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480629 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9fd50b2ff1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.