Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Fedora has released an update for opkssh version 0.16.0, fixing a security vulnerability in GQ-commitment PK Tokens, while updating dependencies and maintaining low severity due to limited exposure.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-168280f3c4 2026-07-28 01:18:17.119965+00:00 -------------------------------------------------------------------------------- Name : opkssh Product : Fedora 43 Version : 0.16.0 Release : 1.fc43 URL : https://github.com/openpubkey/opkssh Summary : OpenPubkey SSH Description : OpenPubkey SSH is a tool which enables ssh to be used with OpenID Connect allowing SSH access to be managed via identities like
The Fedora update for perl-Mojolicious version 9.48 addresses a security flaw related to CSRF tokens, enhancing protection against BREACH attacks by masking tokens with random values per request.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6f12b08313 2026-07-28 01:18:17.119958+00:00 -------------------------------------------------------------------------------- Name : perl-Mojolicious Product : Fedora 43 Version : 9.48 Release : 1.fc43 URL : https://metacpan.org/release/Mojolicious Summary : A next generation web framework for Perl Description : Back in the early days of the web there was this wonderful Perl library called CGI, many people only learned Perl because of it. It was simple enough to get started without knowing much about the language and powerful enough to keep you going, learning by doing was much fun. While most of the techniques used are outdated now, the idea behind it is not. Mojolicious is a new attempt at implementing this idea using state of the art technology. -------------------------------------------------------------------------------- Update Information: Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session. -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 14 2026 Emmanuel Seyman - 9.48-1 - Update to 9.48 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2500953 - CVE-2026-15747 perl-Mojolicious: Mojolicious: Information disclosure via BREACH compression oracle [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500953 -------------------------------------------------------------------------------- This update can be installed with the "dnf" updateprogram. Use su -c 'dnf upgrade --advisory FEDORA-2026-6f12b08313' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fedora 43 has released an update for the RPM package management system, rebasing it to version 6.0.2, addressing security issues like heap buffer overflow and command injection.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a9f0d5370e 2026-07-28 01:18:17.119933+00:00 -------------------------------------------------------------------------------- Name : rpm Product : Fedora 43 Version : 6.0.2 Release : 1.fc43 URL : https://rpm.org/ Summary : The RPM package management system Description : The RPM Package Manager (RPM) is a powerful command line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages. Each software package consists of an archive of files along with information about the package like its version, a description, etc. -------------------------------------------------------------------------------- Update Information: Rebase to 6.0.2 (https://rpm.org/releases/6.0.2) -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 16 2026 Michal Domonkos - 6.0.2-1 - Rebase to 6.0.2 (https://rpm.org/releases/6.0.2) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2482483 - CVE-2026-44605 rpm: heap buffer overflow in NDB slot table parsing [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2482483 [ 2 ] Bug #2482484 - CVE-2026-44604 rpm: Command injection in rpmuncompress doUntar() via unescaped archive top-level directory name in popen() shell command [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2482484 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a9f0d5370e' at the command line. For more information, refer to the dnfdocumentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fedora 44 has updated OpenPubkey SSH to version 0.16.0, which includes a security fix for GQ-commitment PK Tokens, although vulnerability risk for opkssh is low.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a0bf40ecfe 2026-07-28 01:00:27.224333+00:00 -------------------------------------------------------------------------------- Name : opkssh Product : Fedora 44 Version : 0.16.0 Release : 1.fc44 URL : https://github.com/openpubkey/opkssh Summary : OpenPubkey SSH Description : OpenPubkey SSH is a tool which enables ssh to be used with OpenID Connect allowing SSH access to be managed via identities like
The Fedora update for perl-Mojolicious 9.48 addresses a security issue with CSRF tokens vulnerable to BREACH attacks by masking tokens with a fresh random value for each request.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-4334fd85bc 2026-07-28 01:00:27.224317+00:00 -------------------------------------------------------------------------------- Name : perl-Mojolicious Product : Fedora 44 Version : 9.48 Release : 1.fc44 URL : https://metacpan.org/release/Mojolicious Summary : A next generation web framework for Perl Description : Back in the early days of the web there was this wonderful Perl library called CGI, many people only learned Perl because of it. It was simple enough to get started without knowing much about the language and powerful enough to keep you going, learning by doing was much fun. While most of the techniques used are outdated now, the idea behind it is not. Mojolicious is a new attempt at implementing this idea using state of the art technology. -------------------------------------------------------------------------------- Update Information: Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session. -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 14 2026 Emmanuel Seyman - 9.48-1 - Update to 9.48 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2500953 - CVE-2026-15747 perl-Mojolicious: Mojolicious: Information disclosure via BREACH compression oracle [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500953 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su-c 'dnf upgrade --advisory FEDORA-2026-4334fd85bc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fedora 44 has released an update for the RPM package management system, rebased to version 6.0.2, addressing two critical vulnerabilities and offering installation instructions via dnf.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9985882270 2026-07-28 01:00:27.224294+00:00 -------------------------------------------------------------------------------- Name : rpm Product : Fedora 44 Version : 6.0.2 Release : 1.fc44 URL : https://rpm.org/ Summary : The RPM package management system Description : The RPM Package Manager (RPM) is a powerful command line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages. Each software package consists of an archive of files along with information about the package like its version, a description, etc. -------------------------------------------------------------------------------- Update Information: Rebase to 6.0.2 (https://rpm.org/releases/6.0.2) -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 16 2026 Michal Domonkos - 6.0.2-1 - Rebase to 6.0.2 (https://rpm.org/releases/6.0.2) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2482482 - CVE-2026-44605 rpm: heap buffer overflow in NDB slot table parsing [fedora-44] https://bugzilla.redhat.com/show_bug.cgi?id=2482482 [ 2 ] Bug #2482485 - CVE-2026-44604 rpm: Command injection in rpmuncompress doUntar() via unescaped archive top-level directory name in popen() shell command [fedora-44] https://bugzilla.redhat.com/show_bug.cgi?id=2482485 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9985882270' at the command line. For more information, refer tothe dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
A security update for wpa_supplicant addresses vulnerability CVE-2025-24912, enabling crafted RADIUS packet injection. Affected products include SUSE Linux Enterprise Micro 5.3 and 5.4.. # Security update for wpa_supplicant Announcement ID: SUSE-SU-2026:3281-1 Release Date: 2026-07-27T13:40:46Z Rating: low References: * bsc#1239461 Cross-References: * CVE-2025-24912 CVSS scores: * CVE-2025-24912 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-24912 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for wpa_supplicant fixes the following issues * CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user in between the hostapd and the RADIUS server to inject crafted RADIUS packets and force RADIUS authentications to fail (bsc#1239461). * Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3281=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3281=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3281=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3281=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * wpa_supplicant-debugsource-2.9-150000.4.42.1 * wpa_supplicant-debuginfo-2.9-150000.4.42.1 *wpa_supplicant-2.9-150000.4.42.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * wpa_supplicant-debugsource-2.9-150000.4.42.1 * wpa_supplicant-debuginfo-2.9-150000.4.42.1 * wpa_supplicant-2.9-150000.4.42.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * wpa_supplicant-debugsource-2.9-150000.4.42.1 * wpa_supplicant-debuginfo-2.9-150000.4.42.1 * wpa_supplicant-2.9-150000.4.42.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * wpa_supplicant-debugsource-2.9-150000.4.42.1 * wpa_supplicant-debuginfo-2.9-150000.4.42.1 * wpa_supplicant-2.9-150000.4.42.1 ## References: * https://www.suse.com/security/cve/CVE-2025-24912.html * https://bugzilla.suse.com/show_bug.cgi?id=1239461 . A low-severity security update for wpa_supplicant addresses one vulnerability related to RADIUS authentication issues in SUSE.. wpa_supplicant update, SUSE Linux, RADIUS security, network patch, authentication fix. . Severity: Low. LinuxSecurity.com Team
A security update for perl-DBI addresses six vulnerabilities, including potential code execution and process crashes, impacting various SUSE Linux Enterprise products, effective July 27, 2026.. # Security update for perl-DBI Announcement ID: SUSE-SU-2026:3283-1 Release Date: 2026-07-27T13:45:37Z Rating: important References: * bsc#1271017 * bsc#1271018 * bsc#1271399 * bsc#1271458 * bsc#1271459 * bsc#1271629 Cross-References: * CVE-2026-14380 * CVE-2026-14740 * CVE-2026-15043 * CVE-2026-15392 * CVE-2026-60081 * CVE-2026-60082 CVSS scores: * CVE-2026-14380 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-14380 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14740 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-14740 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-15043 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-15043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-15043 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15392 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-15392 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-60081 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-60081 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-60082 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-60082 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSELinux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for perl-DBI fixes the following issues * CVE-2026-14380: unvalidated string eval interpolation of the Profile package name can lead to arbitrary Perl code execution (bsc#1271018). * CVE-2026-14740: one-byte out-of-bounds read when deleting an initial SQL comment line can lead to a process crash (bsc#1271017). * CVE-2026-15043: incorrect predicate evaluation in `DBI:SQL:Nano` can lead to bypass of file-backed filters (bsc#1271399). * CVE-2026-15392: missing checks to ensure the table file is not a symlink to an untrusted location in `DBD::File` allows for arbitrary file reads and writes (bsc#1271629). * CVE-2026-60081: no limiting of the path index in profile parser of `DBI:ProfileData` can enable small-file memory-amplification DoS (bsc#1271458). * CVE-2026-60082: out-of-bounds access in `_set_fbav` when a statement handle has zero fields but a non-empty row can lead to a process crash (bsc#1271459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3283=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3283=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3283=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patchSUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3283=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3283=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3283=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3283=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3283=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 *perl-DBI-1.642-150200.3.19.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * perl-DBI-debugsource-1.642-150200.3.19.1 * perl-DBI-debuginfo-1.642-150200.3.19.1 * perl-DBI-1.642-150200.3.19.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14380.html * https://www.suse.com/security/cve/CVE-2026-14740.html * https://www.suse.com/security/cve/CVE-2026-15043.html * https://www.suse.com/security/cve/CVE-2026-15392.html * https://www.suse.com/security/cve/CVE-2026-60081.html * https://www.suse.com/security/cve/CVE-2026-60082.html * https://bugzilla.suse.com/show_bug.cgi?id=1271017 * https://bugzilla.suse.com/show_bug.cgi?id=1271018 * https://bugzilla.suse.com/show_bug.cgi?id=1271399 * https://bugzilla.suse.com/show_bug.cgi?id=1271458 * https://bugzilla.suse.com/show_bug.cgi?id=1271459 * https://bugzilla.suse.com/show_bug.cgi?id=1271629 . Multiple issues in perl-DBI addressed in SUSE's important security update, safeguarding system functions and performance.. SUSE Perl DBI Update Security Critical. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.