Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Are host-based firewalls still worth using?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/158-are-host-based-firewalls-still-worth-using?task=poll.vote&format=json
158
radio
0
[{"id":510,"title":"Yes \u2014 every server needs one.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":511,"title":"No \u2014 perimeter and cloud security are enough.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":512,"title":"Only Internet-facing systems really benefit.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":513,"title":"iptables.conf is my security policy.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 498 articles for you...
89

Fedora 43 opkssh Low GQ-commitment PK Tokens Advisory 2026-168280f3c4

Fedora has released an update for opkssh version 0.16.0, fixing a security vulnerability in GQ-commitment PK Tokens, while updating dependencies and maintaining low severity due to limited exposure.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-168280f3c4 2026-07-28 01:18:17.119965+00:00 -------------------------------------------------------------------------------- Name : opkssh Product : Fedora 43 Version : 0.16.0 Release : 1.fc43 URL : https://github.com/openpubkey/opkssh Summary : OpenPubkey SSH Description : OpenPubkey SSH is a tool which enables ssh to be used with OpenID Connect allowing SSH access to be managed via identities like This email address is being protected from spambots. You need JavaScript enabled to view it. instead of long-lived SSH keys. -------------------------------------------------------------------------------- Update Information: Update to 0.16.0. This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively. -------------------------------------------------------------------------------- ChangeLog: * Sun Jul 19 2026 Till Hofmann - 0.16.0-1 - Update to 0.16.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2500487 - opkssh-0.16.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2500487 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-168280f3c4' at the command line. For more information, referto the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . A minor security fix in opkssh 0.16.0 addresses GitLab-CI GQ-commitment PK Tokens vulnerability for Fedora.. opkssh security, Fedora updates, GitLab integration, openpubkey dependency. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Jul 27, 2026 Low Fedora
89

Fedora 43 Perl-Mojolicious Important CSRF Token Fix FEDORA-2026-6f12b08313

The Fedora update for perl-Mojolicious version 9.48 addresses a security flaw related to CSRF tokens, enhancing protection against BREACH attacks by masking tokens with random values per request.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6f12b08313 2026-07-28 01:18:17.119958+00:00 -------------------------------------------------------------------------------- Name : perl-Mojolicious Product : Fedora 43 Version : 9.48 Release : 1.fc43 URL : https://metacpan.org/release/Mojolicious Summary : A next generation web framework for Perl Description : Back in the early days of the web there was this wonderful Perl library called CGI, many people only learned Perl because of it. It was simple enough to get started without knowing much about the language and powerful enough to keep you going, learning by doing was much fun. While most of the techniques used are outdated now, the idea behind it is not. Mojolicious is a new attempt at implementing this idea using state of the art technology. -------------------------------------------------------------------------------- Update Information: Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session. -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 14 2026 Emmanuel Seyman - 9.48-1 - Update to 9.48 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2500953 - CVE-2026-15747 perl-Mojolicious: Mojolicious: Information disclosure via BREACH compression oracle [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500953 -------------------------------------------------------------------------------- This update can be installed with the "dnf" updateprogram. Use su -c 'dnf upgrade --advisory FEDORA-2026-6f12b08313' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Mojolicious 9.48 improves security by masking CSRF tokens, preventing BREACH attacks and enhancing session handling.. Mojolicious security update, Fedora security advisory, CSRF token protection. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 27, 2026 Important Fedora
89

Fedora 43 RPM Heap Overflow and Command Injection Vulnerability Advisory

Fedora 43 has released an update for the RPM package management system, rebasing it to version 6.0.2, addressing security issues like heap buffer overflow and command injection.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a9f0d5370e 2026-07-28 01:18:17.119933+00:00 -------------------------------------------------------------------------------- Name : rpm Product : Fedora 43 Version : 6.0.2 Release : 1.fc43 URL : https://rpm.org/ Summary : The RPM package management system Description : The RPM Package Manager (RPM) is a powerful command line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages. Each software package consists of an archive of files along with information about the package like its version, a description, etc. -------------------------------------------------------------------------------- Update Information: Rebase to 6.0.2 (https://rpm.org/releases/6.0.2) -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 16 2026 Michal Domonkos - 6.0.2-1 - Rebase to 6.0.2 (https://rpm.org/releases/6.0.2) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2482483 - CVE-2026-44605 rpm: heap buffer overflow in NDB slot table parsing [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2482483 [ 2 ] Bug #2482484 - CVE-2026-44604 rpm: Command injection in rpmuncompress doUntar() via unescaped archive top-level directory name in popen() shell command [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2482484 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a9f0d5370e' at the command line. For more information, refer to the dnfdocumentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Critical updates for rpm in Fedora 43 resolve heap overflow and command injection issues. Get the latest fixes now.. Fedora RPM Package Management Heap Overflow Command Injection. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 27, 2026 Critical Fedora
89

Fedora 44 opkssh Low GQ-commitment PK Tokens Issue Advisory 2026-a0bf40ecfe

Fedora 44 has updated OpenPubkey SSH to version 0.16.0, which includes a security fix for GQ-commitment PK Tokens, although vulnerability risk for opkssh is low.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a0bf40ecfe 2026-07-28 01:00:27.224333+00:00 -------------------------------------------------------------------------------- Name : opkssh Product : Fedora 44 Version : 0.16.0 Release : 1.fc44 URL : https://github.com/openpubkey/opkssh Summary : OpenPubkey SSH Description : OpenPubkey SSH is a tool which enables ssh to be used with OpenID Connect allowing SSH access to be managed via identities like This email address is being protected from spambots. You need JavaScript enabled to view it. instead of long-lived SSH keys. -------------------------------------------------------------------------------- Update Information: Update to 0.16.0. This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively. -------------------------------------------------------------------------------- ChangeLog: * Sun Jul 19 2026 Till Hofmann - 0.16.0-1 - Update to 0.16.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2500487 - opkssh-0.16.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2500487 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a0bf40ecfe' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . A security advisory for Fedora 44 notifying an update for opkssh to fix GQ-commitment PK Tokens affecting GitLab.. opkssh security update GQ-commitment PK Tokens Fedora. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Jul 27, 2026 Low Fedora
89

Fedora 44 perl-Mojolicious Critical CSRF Attack Mitigation 2026-4334fd85bc

The Fedora update for perl-Mojolicious 9.48 addresses a security issue with CSRF tokens vulnerable to BREACH attacks by masking tokens with a fresh random value for each request.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-4334fd85bc 2026-07-28 01:00:27.224317+00:00 -------------------------------------------------------------------------------- Name : perl-Mojolicious Product : Fedora 44 Version : 9.48 Release : 1.fc44 URL : https://metacpan.org/release/Mojolicious Summary : A next generation web framework for Perl Description : Back in the early days of the web there was this wonderful Perl library called CGI, many people only learned Perl because of it. It was simple enough to get started without knowing much about the language and powerful enough to keep you going, learning by doing was much fun. While most of the techniques used are outdated now, the idea behind it is not. Mojolicious is a new attempt at implementing this idea using state of the art technology. -------------------------------------------------------------------------------- Update Information: Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session. -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 14 2026 Emmanuel Seyman - 9.48-1 - Update to 9.48 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2500953 - CVE-2026-15747 perl-Mojolicious: Mojolicious: Information disclosure via BREACH compression oracle [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500953 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su-c 'dnf upgrade --advisory FEDORA-2026-4334fd85bc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Mojolicious 9.48 addresses a critical CSRF token issue by masking tokens with fresh random values. Update recommended.. perl mojolicious security patch fedora csrf. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 27, 2026 Important Fedora
89

Fedora 44 rpm Command Injection Buffer Overflow Fix for 2026-9985882270

Fedora 44 has released an update for the RPM package management system, rebased to version 6.0.2, addressing two critical vulnerabilities and offering installation instructions via dnf.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9985882270 2026-07-28 01:00:27.224294+00:00 -------------------------------------------------------------------------------- Name : rpm Product : Fedora 44 Version : 6.0.2 Release : 1.fc44 URL : https://rpm.org/ Summary : The RPM package management system Description : The RPM Package Manager (RPM) is a powerful command line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages. Each software package consists of an archive of files along with information about the package like its version, a description, etc. -------------------------------------------------------------------------------- Update Information: Rebase to 6.0.2 (https://rpm.org/releases/6.0.2) -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 16 2026 Michal Domonkos - 6.0.2-1 - Rebase to 6.0.2 (https://rpm.org/releases/6.0.2) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2482482 - CVE-2026-44605 rpm: heap buffer overflow in NDB slot table parsing [fedora-44] https://bugzilla.redhat.com/show_bug.cgi?id=2482482 [ 2 ] Bug #2482485 - CVE-2026-44604 rpm: Command injection in rpmuncompress doUntar() via unescaped archive top-level directory name in popen() shell command [fedora-44] https://bugzilla.redhat.com/show_bug.cgi?id=2482485 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9985882270' at the command line. For more information, refer tothe dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fedora 44 rpm update addresses critical security issues, including buffer overflow and command injection vulnerabilities. Learn more.. Buffer Overflow, Command Injection, Package Management, Fedora Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 27, 2026 Important Fedora
100

SUSE wpa_supplicant Low RADIUS Auth Security Issue 2026-3281-1

A security update for wpa_supplicant addresses vulnerability CVE-2025-24912, enabling crafted RADIUS packet injection. Affected products include SUSE Linux Enterprise Micro 5.3 and 5.4.. # Security update for wpa_supplicant Announcement ID: SUSE-SU-2026:3281-1 Release Date: 2026-07-27T13:40:46Z Rating: low References: * bsc#1239461 Cross-References: * CVE-2025-24912 CVSS scores: * CVE-2025-24912 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-24912 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for wpa_supplicant fixes the following issues * CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user in between the hostapd and the RADIUS server to inject crafted RADIUS packets and force RADIUS authentications to fail (bsc#1239461). * Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3281=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3281=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3281=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3281=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * wpa_supplicant-debugsource-2.9-150000.4.42.1 * wpa_supplicant-debuginfo-2.9-150000.4.42.1 *wpa_supplicant-2.9-150000.4.42.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * wpa_supplicant-debugsource-2.9-150000.4.42.1 * wpa_supplicant-debuginfo-2.9-150000.4.42.1 * wpa_supplicant-2.9-150000.4.42.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * wpa_supplicant-debugsource-2.9-150000.4.42.1 * wpa_supplicant-debuginfo-2.9-150000.4.42.1 * wpa_supplicant-2.9-150000.4.42.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * wpa_supplicant-debugsource-2.9-150000.4.42.1 * wpa_supplicant-debuginfo-2.9-150000.4.42.1 * wpa_supplicant-2.9-150000.4.42.1 ## References: * https://www.suse.com/security/cve/CVE-2025-24912.html * https://bugzilla.suse.com/show_bug.cgi?id=1239461 . A low-severity security update for wpa_supplicant addresses one vulnerability related to RADIUS authentication issues in SUSE.. wpa_supplicant update, SUSE Linux, RADIUS security, network patch, authentication fix. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Jul 27, 2026 Low SuSE
100

SUSE perl-DBI Important Code Execution DoS Issues 2026-3283-1

A security update for perl-DBI addresses six vulnerabilities, including potential code execution and process crashes, impacting various SUSE Linux Enterprise products, effective July 27, 2026.. # Security update for perl-DBI Announcement ID: SUSE-SU-2026:3283-1 Release Date: 2026-07-27T13:45:37Z Rating: important References: * bsc#1271017 * bsc#1271018 * bsc#1271399 * bsc#1271458 * bsc#1271459 * bsc#1271629 Cross-References: * CVE-2026-14380 * CVE-2026-14740 * CVE-2026-15043 * CVE-2026-15392 * CVE-2026-60081 * CVE-2026-60082 CVSS scores: * CVE-2026-14380 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-14380 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14740 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-14740 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-15043 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-15043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-15043 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15392 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-15392 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-60081 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-60081 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-60082 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-60082 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSELinux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for perl-DBI fixes the following issues * CVE-2026-14380: unvalidated string eval interpolation of the Profile package name can lead to arbitrary Perl code execution (bsc#1271018). * CVE-2026-14740: one-byte out-of-bounds read when deleting an initial SQL comment line can lead to a process crash (bsc#1271017). * CVE-2026-15043: incorrect predicate evaluation in `DBI:SQL:Nano` can lead to bypass of file-backed filters (bsc#1271399). * CVE-2026-15392: missing checks to ensure the table file is not a symlink to an untrusted location in `DBD::File` allows for arbitrary file reads and writes (bsc#1271629). * CVE-2026-60081: no limiting of the path index in profile parser of `DBI:ProfileData` can enable small-file memory-amplification DoS (bsc#1271458). * CVE-2026-60082: out-of-bounds access in `_set_fbav` when a statement handle has zero fields but a non-empty row can lead to a process crash (bsc#1271459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3283=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3283=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3283=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patchSUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3283=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3283=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3283=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3283=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3283=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 *perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14380.html * https://www.suse.com/security/cve/CVE-2026-14740.html * https://www.suse.com/security/cve/CVE-2026-15043.html * https://www.suse.com/security/cve/CVE-2026-15392.html * https://www.suse.com/security/cve/CVE-2026-60081.html * https://www.suse.com/security/cve/CVE-2026-60082.html * https://bugzilla.suse.com/show_bug.cgi?id=1271017 * https://bugzilla.suse.com/show_bug.cgi?id=1271018 * https://bugzilla.suse.com/show_bug.cgi?id=1271399 * https://bugzilla.suse.com/show_bug.cgi?id=1271458 * https://bugzilla.suse.com/show_bug.cgi?id=1271459 * https://bugzilla.suse.com/show_bug.cgi?id=1271629 . Multiple issues in perl-DBI addressed in SUSE's important security update, safeguarding system functions and performance.. SUSE Perl DBI Update Security Critical. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 27, 2026 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Are host-based firewalls still worth using?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/158-are-host-based-firewalls-still-worth-using?task=poll.vote&format=json
158
radio
0
[{"id":510,"title":"Yes \u2014 every server needs one.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":511,"title":"No \u2014 perimeter and cloud security are enough.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":512,"title":"Only Internet-facing systems really benefit.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":513,"title":"iptables.conf is my security policy.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200