Explore top 10 tips to secure your open-source projects now. Read More
×An update that solves 8 vulnerabilities can now be installed.. # ImageMagick-7.1.2.27-2.1 on GA media Announcement ID: openSUSE-SU-2026:11273-1 Rating: moderate Cross-References: * CVE-2026-56366 * CVE-2026-56372 * CVE-2026-56373 * CVE-2026-61465 * CVE-2026-61857 * CVE-2026-61858 * CVE-2026-61861 * CVE-2026-61870 CVSS scores: * CVE-2026-56366 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56366 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56372 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56372 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56373 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56373 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61465 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61465 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61857 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61857 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61858 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61858 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-61861 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61861 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61870 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61870 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 8 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the ImageMagick-7.1.2.27-2.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: *ImageMagick 7.1.2.27-2.1 * ImageMagick-config-7-SUSE 7.1.2.27-2.1 * ImageMagick-devel 7.1.2.27-2.1 * ImageMagick-devel-32bit 7.1.2.27-2.1 * ImageMagick-doc 7.1.2.27-2.1 * ImageMagick-extra 7.1.2.27-2.1 * libMagick++-7_Q16HDRI5 7.1.2.27-2.1 * libMagick++-7_Q16HDRI5-32bit 7.1.2.27-2.1 * libMagick++-devel 7.1.2.27-2.1 * libMagick++-devel-32bit 7.1.2.27-2.1 * libMagickCore-7_Q16HDRI10 7.1.2.27-2.1 * libMagickCore-7_Q16HDRI10-32bit 7.1.2.27-2.1 * libMagickWand-7_Q16HDRI10 7.1.2.27-2.1 * libMagickWand-7_Q16HDRI10-32bit 7.1.2.27-2.1 * perl-PerlMagick 7.1.2.27-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56366.html * https://www.suse.com/security/cve/CVE-2026-56372.html * https://www.suse.com/security/cve/CVE-2026-56373.html * https://www.suse.com/security/cve/CVE-2026-61465.html * https://www.suse.com/security/cve/CVE-2026-61857.html * https://www.suse.com/security/cve/CVE-2026-61858.html * https://www.suse.com/security/cve/CVE-2026-61861.html * https://www.suse.com/security/cve/CVE-2026-61870.html . An update for ImageMagick on openSUSE fixes 8 security issues, including several CVE vulnerabilities.. ImageMagick security updates, openSUSE vulnerabilities, moderate threat patches, Linux application security. . Severity: moderate. LinuxSecurity.com Team
Update to 5.0.6 CVE-2026-42005 Security Advisory: https://doc.powerdns.com/authoritative/security- advisories/powerdns-advisory-2026-07.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5ce1370aca 2026-07-04 01:06:18.979270+00:00 -------------------------------------------------------------------------------- Name : pdns Product : Fedora 43 Version : 5.0.6 Release : 1.fc43 URL : http://powerdns.com Summary : A modern, advanced and high performance authoritative-only name server Description : The PowerDNS Nameserver is a modern, advanced and high performance authoritative-only name server. It is written from scratch and conforms to all relevant DNS standards documents. Furthermore, PowerDNS interfaces with almost any database. -------------------------------------------------------------------------------- Update Information: Update to 5.0.6 CVE-2026-42005 Security Advisory: https://doc.powerdns.com/authoritative/security- advisories/powerdns-advisory-2026-07.html -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 25 2026 Morten Stevens - 5.0.6-1 - Update to 5.0.6 * Fri Jun 12 2026 Yaakov Selkowitz - 5.0.5-3 - Rebuilt for openssl 4.0 * Fri May 29 2026 Miroslav Suchy - 5.0.5-2 - rebuild for https://fedoraproject.org/wiki/Changes/Protobuf_5.x/6.x -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5ce1370aca' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to upstream 1.5.2. Also fixes CVE-2026-27145 because golang was new enough.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-ca1825e29e 2026-07-03 00:54:50.177247+00:00 -------------------------------------------------------------------------------- Name : apptainer Product : Fedora 44 Version : 1.5.2 Release : 1.fc44 URL : https://apptainer.org Summary : Application and environment virtualization formerly known as Singularity Description : Apptainer provides functionality to make portable containers that can be used across host environments. -------------------------------------------------------------------------------- Update Information: Update to upstream 1.5.2. Also fixes CVE-2026-27145 because golang was new enough. -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 23 2026 Dave Dykstra - 1.5.2 - Update to upstream 1.5.2 * Mon Jun 22 2026 Dave Dykstra - 1.5.1-2 - Rebuild after applying patch to skip PRoot on x86_64 f45. -------------------------------------------------------------------------------- References: [ 1 ] Bug #2437258 - Apptainer is compiled without FIPS support https://bugzilla.redhat.com/show_bug.cgi?id=2437258 [ 2 ] Bug #2489307 - Apptainer persistently segfaults during SIF file compression using mksquashfs https://bugzilla.redhat.com/show_bug.cgi?id=2489307 [ 3 ] Bug #2494375 - CVE-2026-27145 apptainer: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494375 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ca1825e29e' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves 3 vulnerabilities can now be installed.. # chromedriver-149.0.7827.200-1.1 on GA media Announcement ID: openSUSE-SU-2026:11139-1 Rating: moderate Cross-References: * CVE-2026-13281 * CVE-2026-13282 * CVE-2026-13283 Affected Products: * openSUSE Tumbleweed An update that solves 3 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the chromedriver-149.0.7827.200-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * chromedriver 149.0.7827.200-1.1 * chromium 149.0.7827.200-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13281.html * https://www.suse.com/security/cve/CVE-2026-13282.html * https://www.suse.com/security/cve/CVE-2026-13283.html . An update for openSUSE Tumbleweed fixes 3 moderate security issues in chromedriver version 149.0.7827.200-1.1.. Chromedriver Update, openSUSE Security, moderate issue, package update. . Severity: moderate. LinuxSecurity.com Team
updated to latest version for F43 and F44. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9a7f59fa7c 2026-06-23 00:52:30.610748+00:00 -------------------------------------------------------------------------------- Name : python-scrapy Product : Fedora 43 Version : 2.13.4 Release : 1.fc43 URL : https://scrapy.org Summary : A high-level Python Screen Scraping framework Description : Scrapy is a fast high-level screen scraping and web crawling framework, used to crawl websites and extract structured data from their pages. It can be used for a wide range of purposes, from data mining to monitoring and automated testing. -------------------------------------------------------------------------------- Update Information: updated to latest version for F43 and F44 -------------------------------------------------------------------------------- ChangeLog: * Sat Jun 13 2026 Filipe Rosset - 2.13.4-1 - Updated to latest 2.13.x series for F43 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2411735 - CVE-2025-6176 python-scrapy: Brotli decompression bomb DoS in scrapy/scrapy [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411735 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9a7f59fa7c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailinglist --
Update to 1.5.5, containing many bug fixes, some also security related.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-729e540d74 2026-06-09 01:21:40.783749+00:00 -------------------------------------------------------------------------------- Name : objfw Product : Fedora 44 Version : 1.5.5 Release : 1.fc44 URL : https://objfw.nil.im Summary : Portable, lightweight framework for the Objective-C language Description : ObjFW is a portable, lightweight framework for the Objective-C language. It enables you to write an application in Objective-C that will run on any platform supported by ObjFW without having to worry about differences between operating systems or various frameworks you would otherwise need if you want to be portable. It supports all modern Objective-C features when using Clang, but is also compatible with GCC ≥ 4.6 to allow maximum portability. ObjFW also comes with its own lightweight and extremely fast Objective-C runtime, which in real world use cases was found to be significantly faster than both GNU's and Apple's runtime. -------------------------------------------------------------------------------- Update Information: Update to 1.5.5, containing many bug fixes, some also security related. -------------------------------------------------------------------------------- ChangeLog: * Sun May 31 2026 Jonathan Schleifer - 1.5.5-1 - Update to 1.5.5 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-729e540d74' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update to Fedora 44 objfw 1.5.5 includes numerous bug fixes, enhancing security and performance.. Fedora updates, ObjFW framework, bug fixes, software enhancements, security improvements. . Severity: Critical. LinuxSecurity.com Team
Update sequoia-openpgp to version 2.3.0. This includes three security relevant fixes (assigned CVE-2026-42783, CVE-2026-42784, and CVE-not-assigned-yet), see "Notable fixes" in the release notes: https://gitlab.com/sequoia-pgp/sequoia/-/raw/openpgp/v2.3.0/openpgp/NEWS This update includes rebuilds of all affected applications to pick up the fixes. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5619c60e85 2026-05-15 02:33:10.357479+00:00 -------------------------------------------------------------------------------- Name : rust-sequoia-sqv Product : Fedora 44 Version : 1.3.0 Release : 6.fc44 URL : https://crates.io/crates/sequoia-sqv Summary : Simple OpenPGP signature verification program Description : A simple OpenPGP signature verification program. -------------------------------------------------------------------------------- Update Information: Update sequoia-openpgp to version 2.3.0. This includes three security relevant fixes (assigned CVE-2026-42783, CVE-2026-42784, and CVE-not-assigned-yet), see "Notable fixes" in the release notes: https://gitlab.com/sequoia-pgp/sequoia/-/raw/openpgp/v2.3.0/openpgp/NEWS This update includes rebuilds of all affected applications to pick up the fixes for these issues. -------------------------------------------------------------------------------- ChangeLog: * Mon May 11 2026 Fabio Valentini - 1.3.0-6 - Rebuild for sequoia-openpgp v2.3.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2469048 - rust-sequoia-openpgp-2.3.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2469048 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5619c60e85' at the command line. For more information, refer to the dnf documentationavailable at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-17075 http://linux.oracle.com/errata/ELSA-2026-17075.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: yggdrasil-0.4.8-5.el10_1.x86_64.rpm yggdrasil-devel-0.4.8-5.el10_1.x86_64.rpm aarch64: yggdrasil-0.4.8-5.el10_1.aarch64.rpm yggdrasil-devel-0.4.8-5.el10_1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/yggdrasil-0.4.8-5.el10_1.src.rpm Related CVEs: CVE-2026-32282 CVE-2026-32283 Description of changes: [0.4.8-5] - Bump release for rebuild _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.