Update to v3.0.50; contains fix for CVE-2026-32935. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b7d9416ec4 2026-03-30 00:53:25.964738+00:00 -------------------------------------------------------------------------------- Name : php-phpseclib3 Product : Fedora 43 Version : 3.0.50 Release : 1.fc43 URL : https://github.com/phpseclib/phpseclib Summary : PHP Secure Communications Library Description : MIT-licensed pure-PHP implementations of an arbitrary-precision integer arithmetic library, fully PKCS#1 (v2.1) compliant RSA, DES, 3DES, RC4, Rijndael, AES, Blowfish, Twofish, SSH-1, SSH-2, SFTP, and X.509 -------------------------------------------------------------------------------- Update Information: Update to v3.0.50; contains fix for CVE-2026-32935 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 21 2026 Artur Frenszek-Iwicki - 3.0.50-1 - Update to v3.0.50 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2448961 - php-phpseclib3-3.0.50 is available https://bugzilla.redhat.com/show_bug.cgi?id=2448961 [ 2 ] Bug #2449637 - CVE-2026-32935 php-phpseclib3: phpseclib: Information disclosure via padding oracle timing attack when using AES in CBC mode [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2449637 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b7d9416ec4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to v2.0.52. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d1feefa819 2026-03-28 00:45:01.878008+00:00 -------------------------------------------------------------------------------- Name : php-phpseclib Product : Fedora 43 Version : 2.0.52 Release : 1.fc43 URL : https://github.com/phpseclib/phpseclib Summary : PHP Secure Communications Library Description : MIT-licensed pure-PHP implementations of an arbitrary-precision integer arithmetic library, fully PKCS#1 (v2.1) compliant RSA, DES, 3DES, RC4, Rijndael, AES, Blowfish, Twofish, SSH-1, SSH-2, SFTP, and X.509 -------------------------------------------------------------------------------- Update Information: Update to v2.0.52 -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 19 2026 Artur Frenszek-Iwicki - 2.0.52-1 - Update to v2.0.52 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2449636 - CVE-2026-32935 php-phpseclib: phpseclib: Information disclosure via padding oracle timing attack when using AES in CBC mode [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2449636 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d1feefa819' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for openssl-1_1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2311-1 Rating: important References: #1201099 Cross-References: CVE-2022-2097 CVSS scores: CVE-2022-2097 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: SUSE CaaS Platform 4.0 SUSE Enterprise Storage 6 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server for SAP 15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for openssl-1_1 fixes the following issues: - CVE-2022-2097: Fixed partial missing encryption in AES OCB mode (bsc#1201099). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2022-2311=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2022-2311=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2022-2311=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2022-2311=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patchSUSE-SLE-Product-HPC-15-SP1-ESPOS-2022-2311=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2022-2311=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE Linux Enterprise Server for SAP 15-SP1 (ppc64le x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.36.1 libopenssl1_1-1.1.0i-150100.14.36.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-1.1.0i-150100.14.36.1 openssl-1_1-1.1.0i-150100.14.36.1 openssl-1_1-debuginfo-1.1.0i-150100.14.36.1 openssl-1_1-debugsource-1.1.0i-150100.14.36.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.36.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (aarch64 ppc64le s390x x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.36.1 libopenssl1_1-1.1.0i-150100.14.36.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-1.1.0i-150100.14.36.1 openssl-1_1-1.1.0i-150100.14.36.1 openssl-1_1-debuginfo-1.1.0i-150100.14.36.1 openssl-1_1-debugsource-1.1.0i-150100.14.36.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.36.1 - SUSE Linux Enterprise Server 15-SP1-BCL (x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.36.1 libopenssl-1_1-devel-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.36.1 openssl-1_1-1.1.0i-150100.14.36.1 openssl-1_1-debuginfo-1.1.0i-150100.14.36.1 openssl-1_1-debugsource-1.1.0i-150100.14.36.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (aarch64 x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.36.1 libopenssl1_1-1.1.0i-150100.14.36.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-1.1.0i-150100.14.36.1 openssl-1_1-1.1.0i-150100.14.36.1 openssl-1_1-debuginfo-1.1.0i-150100.14.36.1 openssl-1_1-debugsource-1.1.0i-150100.14.36.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.36.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (aarch64 x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.36.1 libopenssl1_1-1.1.0i-150100.14.36.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-1.1.0i-150100.14.36.1 openssl-1_1-1.1.0i-150100.14.36.1 openssl-1_1-debuginfo-1.1.0i-150100.14.36.1 openssl-1_1-debugsource-1.1.0i-150100.14.36.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.36.1 - SUSE Enterprise Storage 6 (aarch64 x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.36.1 libopenssl1_1-1.1.0i-150100.14.36.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-1.1.0i-150100.14.36.1 openssl-1_1-1.1.0i-150100.14.36.1 openssl-1_1-debuginfo-1.1.0i-150100.14.36.1 openssl-1_1-debugsource-1.1.0i-150100.14.36.1 - SUSE Enterprise Storage 6 (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.36.1 - SUSE CaaS Platform 4.0 (x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.36.1 libopenssl-1_1-devel-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.36.1 openssl-1_1-1.1.0i-150100.14.36.1 openssl-1_1-debuginfo-1.1.0i-150100.14.36.1 openssl-1_1-debugsource-1.1.0i-150100.14.36.1 References: https://www.suse.com/security/cve/CVE-2022-2097.html https://bugzilla.suse.com/1201099 . SUSE Security Notification: Crucial patch for openssl-1_1 addressing AES GCM encryption vulnerabilities has been released.. SUSE OpenSSL Security Update, Important Updates SUSE, openssl AES Fix. . Severity: Important. LinuxSecurity.com Team
tpm2: CryptSym: fix AES output IV; a CVE has been filed for this issue. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-caf9e04ef1 2021-03-10 00:41:43.224986 --------------------------------------------------------------------------------Name : libtpms Product : Fedora 33 Version : 0.7.7 Release : 0.20210302gitfd5bd3fb1d.fc33 URL : https://github.com/stefanberger/libtpms Summary : Library providing Trusted Platform Module (TPM) functionality Description : A library providing TPM functionality for VMs. Targeted for integration into Qemu. --------------------------------------------------------------------------------Update Information: tpm2: CryptSym: fix AES output IV; a CVE has been filed for this issue --------------------------------------------------------------------------------ChangeLog: * Tue Mar 2 2021 Stefan Breger - 0.7.7-0.20210302gitfd5bd3fb1d - tpm2: CryptSym: fix AES output IV; a CVE has been filed for this issue - tpm2: fixes a suspend/resume problem when public keys are loaded --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-caf9e04ef1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Several vulnerabilities were discovered in OpenSSL, a Secure Socket Layer toolkit. CVE-2016-2105 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3566-1
Get the latest Linux and open source security news straight to your inbox.