Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 1,029
Alerts This Week
Warning Icon 1 1,029

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1,020 articles for you...
203

Mageia 9 RoundCube Webmail Critical Security Issues CVE-2026-48849

Security update. Publication date: 11 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0194.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-48842, CVE-2026-48843, CVE-2026-48844, CVE-2026-48845, CVE-2026-48846, CVE-2026-48847, CVE-2026-48848, CVE-2026-48849 Description: Multiple security vulnerabilities were discovered in RoundCube Webmail, which could result in cross-site scripting, SQL injection, SSRF bypass, information disclosure, denial of service or code injection. References: - https://bugs.mageia.org/show_bug.cgi?id=35599 - https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1 - https://lists.debian.org/debian-security-announce/2026/msg00212.html - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/HYFEOBDMYY7JRKWNFYSC7KT2TT2XXNBE/ - https://www.openwall.com/lists/oss-security/2026/06/03/17 - https://www.cve.org/CVERecord?id=CVE-2026-48842 - https://www.cve.org/CVERecord?id=CVE-2026-48843 - https://www.cve.org/CVERecord?id=CVE-2026-48844 - https://www.cve.org/CVERecord?id=CVE-2026-48845 - https://www.cve.org/CVERecord?id=CVE-2026-48846 - https://www.cve.org/CVERecord?id=CVE-2026-48847 - https://www.cve.org/CVERecord?id=CVE-2026-48848 - https://www.cve.org/CVERecord?id=CVE-2026-48849 SRPMS: - 9/core/roundcubemail-1.6.16-1.mga9 . Update alerts for Mageia 9 addressing multiple critical security issues in RoundCube Webmail applications.. Mageia Security Update, RoundCube Webmail, Cross-Site Scripting, SQL Injection, Denial of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 10, 2026 Critical Mageia
89

Fedora 43 xmlstarlet Important XML Entity Issue Fix FEDORA-2026-3c78c99467

Fixes XML external entity vulnerability. For more information, refer to https://src.fedoraproject.org/rpms/xmlstarlet/pull-request/4.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3c78c99467 2026-06-11 01:08:40.189444+00:00 -------------------------------------------------------------------------------- Name : xmlstarlet Product : Fedora 43 Version : 1.6.1 Release : 30.fc43 URL : http://xmlstar.sourceforge.net/ Summary : Command Line XML Toolkit Description : XMLStarlet is a set of command line utilities which can be used to transform, query, validate, and edit XML documents and files using simple set of shell commands in similar way it is done for plain text files using UNIX grep, sed, awk, diff, patch, join, etc commands. -------------------------------------------------------------------------------- Update Information: Fixes XML external entity vulnerability. For more information, refer to https://src.fedoraproject.org/rpms/xmlstarlet/pull-request/4. -------------------------------------------------------------------------------- ChangeLog: * Wed May 27 2026 Vitezslav Crhonek - 1.6.1-30 - Fix XXE (XML External Entity) vulnerability * Sat Jan 17 2026 Fedora Release Engineering - 1.6.1-29 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3c78c99467' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fixes XML external entity threat in xmlstarlet for Fedora 43. Stay updated and secure your systems.. xmlstarlet security, Fedora updates, external entity vulnerability, command line toolkit, software patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 10, 2026 Important Fedora
89

Fedora 43 Rust 1.96.0 Update with New Features and CVEs

Update to Rust 1.96.0: New Range* types Assert matching patterns Changes to WebAssembly targets Stabilized APIs. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d7436d12ae 2026-06-11 01:08:40.189427+00:00 -------------------------------------------------------------------------------- Name : rust Product : Fedora 43 Version : 1.96.0 Release : 1.fc43 URL : https://www.rust-lang.org Summary : The Rust Programming Language Description : Rust is a systems programming language that runs blazingly fast, prevents segfaults, and guarantees thread safety. This package includes the Rust compiler and documentation generator. -------------------------------------------------------------------------------- Update Information: Update to Rust 1.96.0: New Range* types Assert matching patterns Changes to WebAssembly targets Stabilized APIs Cargo CVE-2026-5222 and CVE-2026-5223 for third-party registries. See the blog post and release notes for more details. -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 1 2026 Josh Stone - 1.96.0-1 - Update to Rust 1.96.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2458926 - rust-1.96.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2458926 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d7436d12ae' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update to Rust 1.96.0 enhances performance and stabilizes APIs with new features and key improvements.. Rust Programming Language,Fedora 43 update,CVE-2026-5222,Rust 1.96.0 features. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Jun 10, 2026 Informational Fedora
89

Fedora 44 httpd 2.4.68 Important Security Issues Advisory 2026-d4136fe979

new version 2.4.68 fixes various security issues. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d4136fe979 2026-06-11 00:54:51.286493+00:00 -------------------------------------------------------------------------------- Name : httpd Product : Fedora 44 Version : 2.4.68 Release : 1.fc44 URL : https://httpd.apache.org/ Summary : Apache HTTP Server Description : The Apache HTTP Server is a powerful, efficient, and extensible web server. -------------------------------------------------------------------------------- Update Information: new version 2.4.68 fixes various security issues -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 9 2026 Luboš Uhliarik - 2.4.68-1 - new version 2.4.68 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2486351 - httpd-2.4.68 is available https://bugzilla.redhat.com/show_bug.cgi?id=2486351 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d4136fe979' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 44 Apache httpd version 2.4.68 includes fixes for various security issues. Stay updated with this release.. Fedora 44, httpd 2.4.68, security updates, Apache fixes. . LinuxSecurity.com Team

Calendar%202 Jun 10, 2026 Fedora
89

Fedora 44 XMLStarlet Critical XML Entity Issue Vuln 2026-dbf44e0b72

Fixes XML external entity vulnerability. For more information, refer to https://src.fedoraproject.org/rpms/xmlstarlet/pull-request/4.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-dbf44e0b72 2026-06-11 00:54:51.286484+00:00 -------------------------------------------------------------------------------- Name : xmlstarlet Product : Fedora 44 Version : 1.6.1 Release : 30.fc44 URL : http://xmlstar.sourceforge.net/ Summary : Command Line XML Toolkit Description : XMLStarlet is a set of command line utilities which can be used to transform, query, validate, and edit XML documents and files using simple set of shell commands in similar way it is done for plain text files using UNIX grep, sed, awk, diff, patch, join, etc commands. -------------------------------------------------------------------------------- Update Information: Fixes XML external entity vulnerability. For more information, refer to https://src.fedoraproject.org/rpms/xmlstarlet/pull-request/4. -------------------------------------------------------------------------------- ChangeLog: * Wed May 27 2026 Vitezslav Crhonek - 1.6.1-30 - Fix XXE (XML External Entity) vulnerability -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-dbf44e0b72' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. Tounsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fixes XML external entity issue in xmlstarlet for Fedora 44 with update instructions. Learn more about the patch.. xmlstarlet security update, Fedora XML issue, XML external entity fix, xmlstarlet vulnerability patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 10, 2026 Important Fedora
202

openSUSE Kubernetes 1.27 Major Denial of Service Fix CVE-2026-2339-1

An update that solves two vulnerabilities and has one security fix can now be installed.. # Security update for kubernetes1.27 Announcement ID: SUSE-SU-2026:2339-1 Release Date: 2026-06-10T13:14:18Z Rating: important References: * bsc#1251168 * bsc#1262271 * bsc#1265740 Cross-References: * CVE-2026-33814 * CVE-2026-35469 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35469 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for kubernetes1.27 fixes the following issues * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265740). * CVE-2026-35469:github.com/moby/spdystream: memory amplification in SPDY frame parsing leads to denial of service (bsc#1262271). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2339=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2339=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2339=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2339=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2339=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2339=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2339=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2339=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2339=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * kubernetes1.27-proxy-1.27.16-150400.9.21.1 * kubernetes1.27-client-1.27.16-150400.9.21.1 * kubernetes1.27-apiserver-1.27.16-150400.9.21.1 * kubernetes1.27-kubeadm-1.27.16-150400.9.21.1 * kubernetes1.27-kubelet-1.27.16-150400.9.21.1 * kubernetes1.27-scheduler-1.27.16-150400.9.21.1 * kubernetes1.27-kubelet-common-1.27.16-150400.9.21.1 * kubernetes1.27-controller-manager-1.27.16-150400.9.21.1 * kubernetes1.27-client-common-1.27.16-150400.9.21.1 * openSUSE Leap 15.4 (noarch) *kubernetes1.27-client-fish-completion-1.27.16-150400.9.21.1 * kubernetes1.27-client-bash-completion-1.27.16-150400.9.21.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * kubernetes1.27-client-1.27.16-150400.9.21.1 * kubernetes1.27-client-common-1.27.16-150400.9.21.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * kubernetes1.27-client-1.27.16-150400.9.21.1 * kubernetes1.27-client-common-1.27.16-150400.9.21.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * kubernetes1.27-client-1.27.16-150400.9.21.1 * kubernetes1.27-client-common-1.27.16-150400.9.21.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * kubernetes1.27-client-1.27.16-150400.9.21.1 * kubernetes1.27-client-common-1.27.16-150400.9.21.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * kubernetes1.27-client-1.27.16-150400.9.21.1 * kubernetes1.27-client-common-1.27.16-150400.9.21.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * kubernetes1.27-client-1.27.16-150400.9.21.1 * kubernetes1.27-client-common-1.27.16-150400.9.21.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * kubernetes1.27-client-1.27.16-150400.9.21.1 * kubernetes1.27-client-common-1.27.16-150400.9.21.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * kubernetes1.27-client-1.27.16-150400.9.21.1 * kubernetes1.27-client-common-1.27.16-150400.9.21.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-35469.html * https://bugzilla.suse.com/show_bug.cgi?id=1251168 * https://bugzilla.suse.com/show_bug.cgi?id=1262271 * https://bugzilla.suse.com/show_bug.cgi?id=1265740 . # Security update for kubernetes1.27 Announcement ID: SUSE-SU-2026:2339-1 Release Date: 2026-06-10T1. security,update, solves, vulnerabilities, installed. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 10, 2026 Important OpenSUSE
100

openSUSE Kubernetes Important DDoS Fix CVE-2026-33814 2026-2340-1

An update that solves two vulnerabilities and has one security fix can now be installed.. # Security update for kubernetes1.23 Announcement ID: SUSE-SU-2026:2340-1 Release Date: 2026-06-10T13:14:46Z Rating: important References: * bsc#1251168 * bsc#1262271 * bsc#1265740 Cross-References: * CVE-2026-33814 * CVE-2026-35469 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35469 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for kubernetes1.23 fixes the following issues * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265740). * CVE-2026-35469: github.com/moby/spdystream: memory amplification in SPDY frame parsing leads to denial of service (bsc#1262271). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSELeap 15.5 zypper in -t patch SUSE-2026-2340=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2340=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2340=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2340=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2340=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * kubernetes1.23-client-1.23.17-150500.3.26.1 * kubernetes1.23-apiserver-1.23.17-150500.3.26.1 * kubernetes1.23-scheduler-1.23.17-150500.3.26.1 * kubernetes1.23-kubelet-1.23.17-150500.3.26.1 * kubernetes1.23-kubeadm-1.23.17-150500.3.26.1 * kubernetes1.23-kubelet-common-1.23.17-150500.3.26.1 * kubernetes1.23-proxy-1.23.17-150500.3.26.1 * kubernetes1.23-client-common-1.23.17-150500.3.26.1 * kubernetes1.23-controller-manager-1.23.17-150500.3.26.1 * openSUSE Leap 15.5 (noarch) * kubernetes1.23-client-bash-completion-1.23.17-150500.3.26.1 * kubernetes1.23-client-fish-completion-1.23.17-150500.3.26.1 * openSUSE Leap 15.5 (ppc64le) * kubernetes1.23-scheduler-debuginfo-1.23.17-150500.3.26.1 * kubernetes1.23-client-debuginfo-1.23.17-150500.3.26.1 * kubernetes1.23-kubeadm-debuginfo-1.23.17-150500.3.26.1 * kubernetes1.23-proxy-debuginfo-1.23.17-150500.3.26.1 * kubernetes1.23-controller-manager-debuginfo-1.23.17-150500.3.26.1 * kubernetes1.23-apiserver-debuginfo-1.23.17-150500.3.26.1 * kubernetes1.23-kubelet-debuginfo-1.23.17-150500.3.26.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * kubernetes1.23-client-1.23.17-150500.3.26.1 * kubernetes1.23-client-common-1.23.17-150500.3.26.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * kubernetes1.23-client-1.23.17-150500.3.26.1 * kubernetes1.23-client-common-1.23.17-150500.3.26.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * kubernetes1.23-client-1.23.17-150500.3.26.1 * kubernetes1.23-client-common-1.23.17-150500.3.26.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (ppc64le) * kubernetes1.23-client-debuginfo-1.23.17-150500.3.26.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * kubernetes1.23-client-1.23.17-150500.3.26.1 * kubernetes1.23-client-common-1.23.17-150500.3.26.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le) * kubernetes1.23-client-debuginfo-1.23.17-150500.3.26.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-35469.html * https://bugzilla.suse.com/show_bug.cgi?id=1251168 * https://bugzilla.suse.com/show_bug.cgi?id=1262271 * https://bugzilla.suse.com/show_bug.cgi?id=1265740 . SUSE Update 2026:2340-1 addresses two issues in kubernetes1.23. Install the patch to enhance security effectively.. SUSE update kubernetes security CVE patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 10, 2026 Important SuSE
202

openSUSE 15.6 Kubernetes Important DoS Infinite Loop Vuln 2026-2342-1

An update that solves two vulnerabilities can now be installed.. # Security update for kubernetes Announcement ID: SUSE-SU-2026:2342-1 Release Date: 2026-06-10T13:15:04Z Rating: important References: * bsc#1262270 * bsc#1265748 Cross-References: * CVE-2026-33814 * CVE-2026-35469 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35469 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for kubernetes fixes the following issues * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265748). * CVE-2026-35469: github.com/moby/spdystream: memory amplification in SPDY frame parsing leads to denial of service (bsc#1262270). Changes for kubernetes: * Update to version 1.35.4: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2342=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-2342=1 ## Package List: * openSUSELeap 15.6 (aarch64 ppc64le s390x x86_64) * kubernetes1.35-client-common-1.35.4-150600.13.34.1 * kubernetes1.35-client-1.35.4-150600.13.34.1 * openSUSE Leap 15.6 (noarch) * kubernetes1.35-client-bash-completion-1.35.4-150600.13.34.1 * kubernetes1.35-client-fish-completion-1.35.4-150600.13.34.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kubernetes1.35-client-common-1.35.4-150600.13.34.1 * kubernetes1.35-client-1.35.4-150600.13.34.1 * Containers Module 15-SP7 (noarch) * kubernetes1.35-client-bash-completion-1.35.4-150600.13.34.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-35469.html * https://bugzilla.suse.com/show_bug.cgi?id=1262270 * https://bugzilla.suse.com/show_bug.cgi?id=1265748 . Important update for openSUSE addresses two critical security issues in Kubernetes. Install recommended patches now.. openSUSE Kubernetes security update vulnerabilities DenialOfService infiniteLoop. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 10, 2026 Important OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200