Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
A security update for Python 3.14 addresses a Denial of Service vulnerability in Rocky Linux 9, emphasizing the need for users to apply the fix as soon as possible.. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:41949", "synopsis": "Important: python3.14 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for python3.14.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.\n\nSecurity Fix(es):\n\n* python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations (CVE-2026-15308)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2498608", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2498608", "description": ""}], "cves": [{"name": "CVE-2026-15308", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15308", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-835"}], "references": [], "publishedAt": "2026-07-22T12:03:41.844500Z", "rpms": {"Rocky Linux 9": {"nvras": ["python3.14-0:3.14.5-1.el9_8.1.aarch64.rpm", "python3.14-0:3.14.5-1.el9_8.1.i686.rpm", "python3.14-0:3.14.5-1.el9_8.1.src.rpm", "python3.14-0:3.14.5-1.el9_8.1.x86_64.rpm", "python3.14-debug-0:3.14.5-1.el9_8.1.aarch64.rpm", "python3.14-debug-0:3.14.5-1.el9_8.1.i686.rpm","python3.14-debug-0:3.14.5-1.el9_8.1.s390x.rpm", "python3.14-debug-0:3.14.5-1.el9_8.1.x86_64.rpm", "python3.14-debuginfo-0:3.14.5-1.el9_8.1.aarch64.rpm", "python3.14-debuginfo-0:3.14.5-1.el9_8.1.i686.rpm", "python3.14-debuginfo-0:3.14.5-1.el9_8.1.x86_64.rpm", "python3.14-debugsource-0:3.14.5-1.el9_8.1.aarch64.rpm", "python3.14-debugsource-0:3.14.5-1.el9_8.1.i686.rpm", "python3.14-debugsource-0:3.14.5-1.el9_8.1.x86_64.rpm", "python3.14-devel-0:3.14.5-1.el9_8.1.aarch64.rpm", "python3.14-devel-0:3.14.5-1.el9_8.1.i686.rpm", "python3.14-devel-0:3.14.5-1.el9_8.1.x86_64.rpm", "python3.14-freethreading-0:3.14.5-1.el9_8.1.aarch64.rpm", "python3.14-freethreading-0:3.14.5-1.el9_8.1.i686.rpm", "python3.14-freethreading-0:3.14.5-1.el9_8.1.s390x.rpm", "python3.14-freethreading-0:3.14.5-1.el9_8.1.x86_64.rpm", "python3.14-freethreading-debug-0:3.14.5-1.el9_8.1.aarch64.rpm", "python3.14-freethreading-debug-0:3.14.5-1.el9_8.1.i686.rpm", "python3.14-freethreading-debug-0:3.14.5-1.el9_8.1.s390x.rpm", "python3.14-freethreading-debug-0:3.14.5-1.el9_8.1.x86_64.rpm", "python3.14-freethreading-devel-0:3.14.5-1.el9_8.1.aarch64.rpm", "python3.14-freethreading-devel-0:3.14.5-1.el9_8.1.i686.rpm", "python3.14-freethreading-devel-0:3.14.5-1.el9_8.1.s390x.rpm", "python3.14-freethreading-devel-0:3.14.5-1.el9_8.1.x86_64.rpm", "python3.14-freethreading-idle-0:3.14.5-1.el9_8.1.aarch64.rpm", "python3.14-freethreading-idle-0:3.14.5-1.el9_8.1.i686.rpm", "python3.14-freethreading-idle-0:3.14.5-1.el9_8.1.s390x.rpm", "python3.14-freethreading-idle-0:3.14.5-1.el9_8.1.x86_64.rpm", "python3.14-freethreading-libs-0:3.14.5-1.el9_8.1.aarch64.rpm", "python3.14-freethreading-libs-0:3.14.5-1.el9_8.1.i686.rpm", "python3.14-freethreading-libs-0:3.14.5-1.el9_8.1.s390x.rpm", "python3.14-freethreading-libs-0:3.14.5-1.el9_8.1.x86_64.rpm", "python3.14-freethreading-test-0:3.14.5-1.el9_8.1.aarch64.rpm", "python3.14-freethreading-test-0:3.14.5-1.el9_8.1.i686.rpm", "python3.14-freethreading-test-0:3.14.5-1.el9_8.1.s390x.rpm","python3.14-freethreading-test-0:3.14.5-1.el9_8.1.x86_64.rpm", "python3.14-freethreading-tkinter-0:3.14.5-1.el9_8.1.aarch64.rpm", "python3.14-freethreading-tkinter-0:3.14.5-1.el9_8.1.i686.rpm", "python3.14-freethreading-tkinter-0:3.14.5-1.el9_8.1.s390x.rpm", "python3.14-freethreading-tkinter-0:3.14.5-1.el9_8.1.x86_64.rpm", "python3.14-idle-0:3.14.5-1.el9_8.1.aarch64.rpm", "python3.14-idle-0:3.14.5-1.el9_8.1.i686.rpm", "python3.14-idle-0:3.14.5-1.el9_8.1.s390x.rpm", "python3.14-idle-0:3.14.5-1.el9_8.1.x86_64.rpm", "python3.14-libs-0:3.14.5-1.el9_8.1.aarch64.rpm", "python3.14-libs-0:3.14.5-1.el9_8.1.i686.rpm", "python3.14-libs-0:3.14.5-1.el9_8.1.x86_64.rpm", "python3.14-test-0:3.14.5-1.el9_8.1.aarch64.rpm", "python3.14-test-0:3.14.5-1.el9_8.1.i686.rpm", "python3.14-test-0:3.14.5-1.el9_8.1.s390x.rpm", "python3.14-test-0:3.14.5-1.el9_8.1.x86_64.rpm", "python3.14-tkinter-0:3.14.5-1.el9_8.1.aarch64.rpm", "python3.14-tkinter-0:3.14.5-1.el9_8.1.i686.rpm", "python3.14-tkinter-0:3.14.5-1.el9_8.1.x86_64.rpm", "python3.14-0:3.14.5-1.el9_8.1.ppc64le.rpm", "python3.14-0:3.14.5-1.el9_8.1.s390x.rpm", "python3.14-debug-0:3.14.5-1.el9_8.1.ppc64le.rpm", "python3.14-debuginfo-0:3.14.5-1.el9_8.1.ppc64le.rpm", "python3.14-debuginfo-0:3.14.5-1.el9_8.1.s390x.rpm", "python3.14-debugsource-0:3.14.5-1.el9_8.1.ppc64le.rpm", "python3.14-debugsource-0:3.14.5-1.el9_8.1.s390x.rpm", "python3.14-devel-0:3.14.5-1.el9_8.1.ppc64le.rpm", "python3.14-devel-0:3.14.5-1.el9_8.1.s390x.rpm", "python3.14-freethreading-0:3.14.5-1.el9_8.1.ppc64le.rpm", "python3.14-freethreading-debug-0:3.14.5-1.el9_8.1.ppc64le.rpm", "python3.14-freethreading-devel-0:3.14.5-1.el9_8.1.ppc64le.rpm", "python3.14-freethreading-idle-0:3.14.5-1.el9_8.1.ppc64le.rpm", "python3.14-freethreading-libs-0:3.14.5-1.el9_8.1.ppc64le.rpm", "python3.14-freethreading-test-0:3.14.5-1.el9_8.1.ppc64le.rpm", "python3.14-freethreading-tkinter-0:3.14.5-1.el9_8.1.ppc64le.rpm", "python3.14-idle-0:3.14.5-1.el9_8.1.ppc64le.rpm", "python3.14-libs-0:3.14.5-1.el9_8.1.ppc64le.rpm","python3.14-libs-0:3.14.5-1.el9_8.1.s390x.rpm", "python3.14-test-0:3.14.5-1.el9_8.1.ppc64le.rpm", "python3.14-tkinter-0:3.14.5-1.el9_8.1.ppc64le.rpm", "python3.14-tkinter-0:3.14.5-1.el9_8.1.s390x.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. An important security update for Python 3.14 addresses denial of service threats in Rocky Linux, requiring prompt action.. python security update, denial of service threat, rocky linux advisory. . Severity: Important. LinuxSecurity.com Team
1.650 bump - Fix CVE-2026-14739, CVE-2026-14740 and CVE-2026-14380. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9fdda5018f 2026-07-10 00:52:14.826398+00:00 -------------------------------------------------------------------------------- Name : perl-DBI Product : Fedora 44 Version : 1.650 Release : 1.fc44 URL : http://dbi.perl.org/ Summary : A database access API for perl Description : DBI is a database access Application Programming Interface (API) for the Perl Language. The DBI API Specification defines a set of functions, variables and conventions that provide a consistent database interface independent of the actual database being used. -------------------------------------------------------------------------------- Update Information: 1.650 bump - Fix CVE-2026-14739, CVE-2026-14740 and CVE-2026-14380 -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 8 2026 Jitka Plesnikova - 1.650-1 - 1.650 bump (rhbz#2497765) - Fix CVE-2026-14739, CVE-2026-14740 and CVE-2026-14380 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2497765 - perl-DBI-1.650 is available https://bugzilla.redhat.com/show_bug.cgi?id=2497765 [ 2 ] Bug #2498112 - CVE-2026-14739 perl-DBI: DBI: Heap overflow when preparsing SQL statements with excessive placeholders [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2498112 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9fdda5018f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keysused by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update quick-xml for two security advisories, rebuild dependents, and update sandogasa to the latest https://rustsec.org/advisories/RUSTSEC-2026-0194.html https://rustsec.org/advisories/RUSTSEC-2026-0195.html sandogasa. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b25dca4806 2026-07-06 14:53:30.168848+00:00 -------------------------------------------------------------------------------- Name : sandogasa Product : Fedora 44 Version : 0.15.3 Release : 2.fc44 URL : https://github.com/slopfest/sandogasa Summary : A collection of Fedora and CentOS packaging tools Description : A collection of tools and libraries for Fedora package maintenance and contributor activity tracking, built around shared API clients for Bugzilla, Bodhi, NVD, dist-git, Discourse, FASJSON, and HyperKitty. The name **sandogasa** (菅笠) refers to a Japanese straw hat often associated with "slum" or post-apocalyptic robots in popular culture. -------------------------------------------------------------------------------- Update Information: Update quick-xml for two security advisories, rebuild dependents, and update sandogasa to the latest https://rustsec.org/advisories/RUSTSEC-2026-0194.html https://rustsec.org/advisories/RUSTSEC-2026-0195.html sandogasa v0.15.3 ebranch base-distro guard — resolve/file-requests now know EPEL must not replace RHEL/CentOS Stream packages: deps present in the base at a too-old version are blocked with clear options (alternate package via --override, or lower the requirement) instead of becoming CANTFIX branch requests; file-requests re-checks the base before filing New sandogasa-sourcehut crate — sr.ht GraphQL client; sandogasa-report gains a Sourcehut section (patches, tickets, commits split yours vs third-party, git_emails attribution) ebranch check-crate — human report on stderr alongside --koji/--copr machine output, so build scripts stay pipeable dbranch rebuild — createsdebian/gbp.conf when the Debian branch has none and handles the modern single-line salsa-ci.yml Robustness: 120s HTTP timeout on every client; --version on every tool; quick-xml bumped to 0.41 for RUSTSEC-2026-0194/-0195 sandogasa-report: consistent commit detail levels across forges Full details: https://github.com/slopfest/sandogasa/blob/v0.15.3/CHANGELOG.md#v0153 v0.15.2 New sandogasa-review crate — shared keep/explain/remove resolution for reviewer-curated findings; adopted by fedora-review-digest, ebranch check-update, and fedora-cve-triage New sandogasa-forgejo crate — Forgejo/Gitea REST API client (PR activity issue filing); powers sandogasa-report's Forgejo accounting ebranch check-update overhaul — condensed output (counts + version grouping), reviewer curation of blocking findings before karma, branch inference for Fedora side tags (EPEL still needs -b al9 -r @epel), plus fixes for stale-side-tag and rich-dep installability false positives and large-update performance fedora-cve-triage — per-bug keep/explain/remove review before closing detected false positives sandogasa-report — Forgejo PR-merge and issue accounting Full details: https://github.com/slopfest/sandogasa/blob/v0.15.2/CHANGELOG.md#v0152 -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 3 2026 Michel Lind - 0.15.3-2 - Rebuild for rust-quick-xml 0.41.0 * Fri Jul 3 2026 Michel Lind - 0.15.3-1 - Update to version 0.15.3 * Mon Jun 29 2026 Michel Lind - 0.15.2-1 - Update to version 0.15.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2494601 - rust-quick-xml-0.41.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2494601 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b25dca4806' at the command line. For more information, refer to the dnfdocumentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update sandogasa in Fedora 44 addressing security advisories for quick-xml with rebuilds and improvements included.. Fedora Security Advisory, Sandogasa Update, Quick-XML Vulnerability. . Severity: Informational. LinuxSecurity.com Team
Update quick-xml for two security advisories, rebuild dependents, and update sandogasa to the latest https://rustsec.org/advisories/RUSTSEC-2026-0194.html https://rustsec.org/advisories/RUSTSEC-2026-0195.html sandogasa. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b25dca4806 2026-07-06 14:53:30.168848+00:00 -------------------------------------------------------------------------------- Name : rust-ashpd Product : Fedora 44 Version : 0.13.12 Release : 2.fc44 URL : https://crates.io/crates/ashpd Summary : XDG portals wrapper in Rust using zbus Description : XDG portals wrapper in Rust using zbus. -------------------------------------------------------------------------------- Update Information: Update quick-xml for two security advisories, rebuild dependents, and update sandogasa to the latest https://rustsec.org/advisories/RUSTSEC-2026-0194.html https://rustsec.org/advisories/RUSTSEC-2026-0195.html sandogasa v0.15.3 ebranch base-distro guard — resolve/file-requests now know EPEL must not replace RHEL/CentOS Stream packages: deps present in the base at a too-old version are blocked with clear options (alternate package via --override, or lower the requirement) instead of becoming CANTFIX branch requests; file-requests re-checks the base before filing New sandogasa-sourcehut crate — sr.ht GraphQL client; sandogasa-report gains a Sourcehut section (patches, tickets, commits split yours vs third-party, git_emails attribution) ebranch check-crate — human report on stderr alongside --koji/--copr machine output, so build scripts stay pipeable dbranch rebuild — creates debian/gbp.conf when the Debian branch has none and handles the modern single-line salsa-ci.yml Robustness: 120s HTTP timeout on every client; --version on every tool; quick-xml bumped to 0.41 for RUSTSEC-2026-0194/-0195 sandogasa-report: consistent commit detail levels across forges Fulldetails: https://github.com/slopfest/sandogasa/blob/v0.15.3/CHANGELOG.md#v0153 v0.15.2 New sandogasa-review crate — shared keep/explain/remove resolution for reviewer-curated findings; adopted by fedora-review-digest, ebranch check-update, and fedora-cve-triage New sandogasa-forgejo crate — Forgejo/Gitea REST API client (PR activity issue filing); powers sandogasa-report's Forgejo accounting ebranch check-update overhaul — condensed output (counts + version grouping), reviewer curation of blocking findings before karma, branch inference for Fedora side tags (EPEL still needs -b al9 -r @epel), plus fixes for stale-side-tag and rich-dep installability false positives and large-update performance fedora-cve-triage — per-bug keep/explain/remove review before closing detected false positives sandogasa-report — Forgejo PR-merge and issue accounting Full details: https://github.com/slopfest/sandogasa/blob/v0.15.2/CHANGELOG.md#v0152 -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 3 2026 Michel Lind - 0.13.12-2 - Allow building against quick-xml 0.41 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2494601 - rust-quick-xml-0.41.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2494601 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b25dca4806' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical update for Fedora 44 addressing security issues in rust-ashpd involvingquick-xml and sandogasa.. Fedora security update, rust-ashpd advisory, quick-xml vulnerabilities, sandogasa update. . Severity: Critical. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-21378 http://linux.oracle.com/errata/ELSA-2026-21378.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: firefox-140.12.0-1.0.1.el9_8.x86_64.rpm firefox-x11-140.12.0-1.0.1.el9_8.x86_64.rpm aarch64: firefox-140.12.0-1.0.1.el9_8.aarch64.rpm firefox-x11-140.12.0-1.0.1.el9_8.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/firefox-140.12.0-1.0.1.el9_8.src.rpm Related CVEs: CVE-2026-8388 CVE-2026-8391 CVE-2026-8401 CVE-2026-8946 CVE-2026-8947 CVE-2026-8950 CVE-2026-8953 CVE-2026-8954 CVE-2026-8955 CVE-2026-8956 CVE-2026-8957 CVE-2026-8958 CVE-2026-8961 CVE-2026-8962 CVE-2026-8968 CVE-2026-8970 CVE-2026-8974 CVE-2026-8975 Description of changes: [140.12.0-1.0.1] - Fix firefox-oracle-default-prefs.js for new nss [Orabug: 37079773] - Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat file [140.12.0] - Add debranding patches (Mustafa Gezen) - Add OpenELA default preferences (Louis Abel) [140.12.0-1] - Update to 140.12.0 ESR [140.11.0-1] - Update to 140.11.0 ESR [140.10.2-1] - Update to 140.10.2 ESR [140.10.1-1] - Update to 140.10.1 ESR _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-29703 http://linux.oracle.com/errata/ELSA-2026-29703.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: containernetworking-plugins-1.9.0-3.el9_8.x86_64.rpm aarch64: containernetworking-plugins-1.9.0-3.el9_8.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/containernetworking-plugins-1.9.0-3.el9_8.src.rpm Related CVEs: CVE-2026-25679 CVE-2026-32280 CVE-2026-32281 CVE-2026-32283 Description of changes: [1:1.9.0-3] - Rebuild for CVE-2026-25679 - Resolves: RHEL-158763 _______________________________________________ El-errata mailing list
libinput 1.31.3, fixes a udev property inject via uinput devices that can lead to local privilege escalation. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5e2446b30f 2026-06-06 01:02:02.289317+00:00 -------------------------------------------------------------------------------- Name : libinput Product : Fedora 44 Version : 1.31.3 Release : 1.fc44 URL : http://www.freedesktop.org/wiki/Software/libinput/ Summary : Input device library Description : libinput is a library that handles input devices for display servers and other applications that need to directly deal with input devices. It provides device detection, device handling, input device event processing and abstraction so minimize the amount of custom input code the user of libinput need to provide the common set of functionality that users expect. -------------------------------------------------------------------------------- Update Information: libinput 1.31.3, fixes a udev property inject via uinput devices that can lead to local privilege escalation -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 4 2026 Peter Hutterer - 1.31.3-1 - libinput 1.31.3 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5e2446b30f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Qualys released an advisory called CrackArmor reporting that in sudo, an application that provide limited super user privileges to specific users, a failure during a privilege drop before running the mailer is not a fatal error, which could lead to privilege escalation. For Debian 11 bullseye, this problem has been fixed in version. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4614-1
Get the latest Linux and open source security news straight to your inbox.