Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Security update. Publication date: 01 Jul 2026 URL: https://advisories.mageia.org/MGAA-2026-0036.html Type: bugfix Affected Mageia releases: 10 Description: Upstream changes to adwaita-icon-theme and a missing requirement on adwaita-icon-theme-legacy makes some applications not show icons for some actions. This update fixes the reported issue. References: - https://bugs.mageia.org/show_bug.cgi?id=35743 SRPMS: - 10/core/adwaita-icon-theme-legacy-46.2-1.mga10 - 10/core/adwaita-icon-theme-49.0-2.mga10 . Fix for icon display issues in applications using adwaita-icon-theme on Mageia 10. Resolve missing requirements.. Adwaita Icon Theme, Mageia Security, Application Update, Bug Fix, Icon Display Issues. . LinuxSecurity.com Team
Update to .NET SDK 8.0.128 and Runtime 8.0.28 Fixes: CVE-2026-45490,CVE-2026-45491,CVE-2026-45591 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.28/8.0.128.md. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-041785a779 2026-06-28 00:56:23.048185+00:00 -------------------------------------------------------------------------------- Name : dotnet8.0 Product : Fedora 44 Version : 8.0.128 Release : 1.fc44 URL : https://github.com/dotnet/ Summary : .NET Runtime and SDK Description : .NET is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything. -------------------------------------------------------------------------------- Update Information: Update to .NET SDK 8.0.128 and Runtime 8.0.28 Fixes: CVE-2026-45490,CVE-2026-45491,CVE-2026-45591 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.28/8.0.128.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.28/8.0.28.md -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 17 2026 Omair Majid - 8.0.128-1 - Update to .NET SDK 8.0.128 and Runtime 8.0.28 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-041785a779' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key.More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 9.21.22 (rhbz#2480122) Security Fixes: Limit resolver server list size. (CVE-2026-3592) Fix GSS-API resource leak. (CVE-2026-3039) Disable recursion, UPDATE, and NOTIFY for non-IN views. (CVE-2026-5946). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-ec095a4675 2026-06-15 01:10:25.755874+00:00 -------------------------------------------------------------------------------- Name : bind9-next Product : Fedora 43 Version : 9.21.22 Release : 2.fc43 URL : https://www.isc.org/downloads/bind/ Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly. -------------------------------------------------------------------------------- Update Information: Update to 9.21.22 (rhbz#2480122) Security Fixes: Limit resolver server list size. (CVE-2026-3592) Fix GSS-API resource leak. (CVE-2026-3039) Disable recursion, UPDATE, and NOTIFY for non-IN views. (CVE-2026-5946) Avoid unbounded recursion loop. (CVE-2026-5950) Fix crash in resolver when SIG(0)-signed responses are received under load. (CVE-2026-5947) Fix use-after-free error in DNS-over-HTTPS when processing HTTP/2 SETTINGS frames. (CVE-2026-3593) Fix outgoing zone transfers' quota issue. Feature Changes: Fix CPU spikes and slow queries when cache approaches memory limit. Implement RFC 3645 Section 4.1.1 key expiry check in TKEY. Reduce memory footprint by actively returning unused memory to the OS. multiplebugfixes. Source: https://downloads.isc.org/isc/bind9/9.21.22/doc/arm/html/notes.html#notes-for- bind-9-21-22 -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 5 2026 Petr Menšík - 32:9.21.22-2 - Switch downstream change to upstream for 32b mem check * Fri Jun 5 2026 Petr Menšík - 32:9.21.22-1 - Update to 9.21.22 (rhbz#2480122) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2480122 - bind9-next-9.21.22 is available https://bugzilla.redhat.com/show_bug.cgi?id=2480122 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ec095a4675' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 43 updates BIND with crucial security fixes addressing resource leaks and potential exploits improving DNS reliability.. BIND DNS update, Fedora security patch, resolver leak fix, DNS security enhancement. . Severity: Important. LinuxSecurity.com Team
Security update. Publication date: 05 Jun 2026 URL: https://advisories.mageia.org/MGAA-2026-0033.html Type: bugfix Affected Mageia releases: 9 Description: Closing windows of applications launched from Mageia Control Center (aka MCC) should return to the main MCC window; currently that does not happen. This update fixes the reported issue. References: - https://bugs.mageia.org/show_bug.cgi?id=20387 SRPMS: - 9/core/drakxtools-18.66.1-1.mga9 . Mageia 9 security update resolves issues with application window management in the Mageia Control Center for enhanced usability.. Mageia, Drakxtools, Security Update. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # google-guest-agent-20260402.00-2.1 on GA media Announcement ID: openSUSE-SU-2026:10654-1 Rating: moderate Cross-References: * CVE-2026-34986 CVSS scores: * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the google-guest-agent-20260402.00-2.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * google-guest-agent 20260402.00-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34986.html . An important update for openSUSE Tumbleweed addressing a moderate risk in google-guest-agent software. Install now.. openSUSE Tumbleweed google-guest-agent security update CVE-2026-34986. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # python314-3.14.3-3.1 on GA media Announcement ID: openSUSE-SU-2026:10405-1 Rating: moderate Cross-References: * CVE-2026-2297 CVSS scores: * CVE-2026-2297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-2297 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the python314-3.14.3-3.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * python314 3.14.3-3.1 * python314-32bit 3.14.3-3.1 * python314-curses 3.14.3-3.1 * python314-dbm 3.14.3-3.1 * python314-idle 3.14.3-3.1 * python314-tk 3.14.3-3.1 * python314-x86-64-v3 3.14.3-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2297.html . This update addresses a moderate security issue in python314 for openSUSE Tumbleweed. Install it for improved safety.. python314 security openSUSE update application fix. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for cups Announcement ID: SUSE-SU-2025:4319-1 Release Date: 2025-12-03T12:34:37Z Rating: important References: * bsc#1254353 Cross-References: * CVE-2025-58436 CVSS scores: * CVE-2025-58436 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-58436 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-58436 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP6 * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP6 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for cups fixes the following issues: * The fix for CVE-2025-58436 causes a regression where GTK applications will hang. (bsc#1254353) See also https://github.com/OpenPrinting/cups/issues/1429 The fix has been temporary disabled. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patchopenSUSE-SLE-15.6-2025-4319=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-4319=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-4319=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-4319=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-4319=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-4319=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-4319=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-4319=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-4319=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-4319=1 * Development Tools Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-4319=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2025-4319=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-4319=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-4319=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * cups-2.2.7-150000.3.80.1 * cups-config-2.2.7-150000.3.80.1 * cups-ddk-debuginfo-2.2.7-150000.3.80.1 * libcupscgi1-debuginfo-2.2.7-150000.3.80.1 * cups-client-debuginfo-2.2.7-150000.3.80.1 * cups-client-2.2.7-150000.3.80.1 * cups-debuginfo-2.2.7-150000.3.80.1 * libcupsimage2-2.2.7-150000.3.80.1 * libcups2-2.2.7-150000.3.80.1 * libcupscgi1-2.2.7-150000.3.80.1 * libcups2-debuginfo-2.2.7-150000.3.80.1 * libcupsmime1-debuginfo-2.2.7-150000.3.80.1 * libcupsmime1-2.2.7-150000.3.80.1 * libcupsppdc1-2.2.7-150000.3.80.1 * libcupsimage2-debuginfo-2.2.7-150000.3.80.1 * cups-devel-2.2.7-150000.3.80.1 * libcupsppdc1-debuginfo-2.2.7-150000.3.80.1 * cups-debugsource-2.2.7-150000.3.80.1 * cups-ddk-2.2.7-150000.3.80.1 * openSUSE Leap 15.6 (x86_64) * libcupsmime1-32bit-debuginfo-2.2.7-150000.3.80.1 * libcupsimage2-32bit-2.2.7-150000.3.80.1 * cups-devel-32bit-2.2.7-150000.3.80.1 * libcupscgi1-32bit-2.2.7-150000.3.80.1 * libcupsmime1-32bit-2.2.7-150000.3.80.1 * libcupsimage2-32bit-debuginfo-2.2.7-150000.3.80.1 * libcups2-32bit-debuginfo-2.2.7-150000.3.80.1 * libcupsppdc1-32bit-2.2.7-150000.3.80.1 * libcupsppdc1-32bit-debuginfo-2.2.7-150000.3.80.1 * libcups2-32bit-2.2.7-150000.3.80.1 * libcupscgi1-32bit-debuginfo-2.2.7-150000.3.80.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * cups-config-2.2.7-150000.3.80.1 * cups-debuginfo-2.2.7-150000.3.80.1 * libcups2-2.2.7-150000.3.80.1 * libcups2-debuginfo-2.2.7-150000.3.80.1 * cups-debugsource-2.2.7-150000.3.80.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * cups-config-2.2.7-150000.3.80.1 * cups-debuginfo-2.2.7-150000.3.80.1 * libcups2-2.2.7-150000.3.80.1 * libcups2-debuginfo-2.2.7-150000.3.80.1 * cups-debugsource-2.2.7-150000.3.80.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * cups-config-2.2.7-150000.3.80.1 * cups-debuginfo-2.2.7-150000.3.80.1 * libcups2-2.2.7-150000.3.80.1 * libcups2-debuginfo-2.2.7-150000.3.80.1 * cups-debugsource-2.2.7-150000.3.80.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * cups-config-2.2.7-150000.3.80.1 * cups-debuginfo-2.2.7-150000.3.80.1 * libcups2-2.2.7-150000.3.80.1 * libcups2-debuginfo-2.2.7-150000.3.80.1 * cups-debugsource-2.2.7-150000.3.80.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * cups-config-2.2.7-150000.3.80.1 * cups-debuginfo-2.2.7-150000.3.80.1 * libcups2-2.2.7-150000.3.80.1 *libcups2-debuginfo-2.2.7-150000.3.80.1 * cups-debugsource-2.2.7-150000.3.80.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * cups-2.2.7-150000.3.80.1 * cups-config-2.2.7-150000.3.80.1 * libcupscgi1-debuginfo-2.2.7-150000.3.80.1 * cups-client-debuginfo-2.2.7-150000.3.80.1 * cups-client-2.2.7-150000.3.80.1 * cups-debuginfo-2.2.7-150000.3.80.1 * libcupsimage2-2.2.7-150000.3.80.1 * libcups2-2.2.7-150000.3.80.1 * libcupscgi1-2.2.7-150000.3.80.1 * libcups2-debuginfo-2.2.7-150000.3.80.1 * libcupsmime1-debuginfo-2.2.7-150000.3.80.1 * libcupsmime1-2.2.7-150000.3.80.1 * libcupsppdc1-2.2.7-150000.3.80.1 * libcupsimage2-debuginfo-2.2.7-150000.3.80.1 * cups-devel-2.2.7-150000.3.80.1 * cups-debugsource-2.2.7-150000.3.80.1 * libcupsppdc1-debuginfo-2.2.7-150000.3.80.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cups-2.2.7-150000.3.80.1 * cups-config-2.2.7-150000.3.80.1 * libcupscgi1-debuginfo-2.2.7-150000.3.80.1 * cups-client-debuginfo-2.2.7-150000.3.80.1 * cups-client-2.2.7-150000.3.80.1 * cups-debuginfo-2.2.7-150000.3.80.1 * libcupsimage2-2.2.7-150000.3.80.1 * libcups2-2.2.7-150000.3.80.1 * libcupscgi1-2.2.7-150000.3.80.1 * libcups2-debuginfo-2.2.7-150000.3.80.1 * libcupsmime1-debuginfo-2.2.7-150000.3.80.1 * libcupsmime1-2.2.7-150000.3.80.1 * libcupsppdc1-2.2.7-150000.3.80.1 * libcupsimage2-debuginfo-2.2.7-150000.3.80.1 * cups-devel-2.2.7-150000.3.80.1 * cups-debugsource-2.2.7-150000.3.80.1 * libcupsppdc1-debuginfo-2.2.7-150000.3.80.1 * Desktop Applications Module 15-SP6 (x86_64) * libcups2-32bit-debuginfo-2.2.7-150000.3.80.1 * libcups2-32bit-2.2.7-150000.3.80.1 * Desktop Applications Module 15-SP7 (x86_64) * libcups2-32bit-debuginfo-2.2.7-150000.3.80.1 * libcups2-32bit-2.2.7-150000.3.80.1 * Development Tools Module 15-SP6 (aarch64 ppc64le s390x x86_64) * cups-ddk-debuginfo-2.2.7-150000.3.80.1 *cups-debuginfo-2.2.7-150000.3.80.1 * cups-debugsource-2.2.7-150000.3.80.1 * cups-ddk-2.2.7-150000.3.80.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cups-ddk-debuginfo-2.2.7-150000.3.80.1 * cups-debuginfo-2.2.7-150000.3.80.1 * cups-debugsource-2.2.7-150000.3.80.1 * cups-ddk-2.2.7-150000.3.80.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * cups-config-2.2.7-150000.3.80.1 * cups-debuginfo-2.2.7-150000.3.80.1 * libcups2-2.2.7-150000.3.80.1 * libcups2-debuginfo-2.2.7-150000.3.80.1 * cups-debugsource-2.2.7-150000.3.80.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * cups-config-2.2.7-150000.3.80.1 * cups-debuginfo-2.2.7-150000.3.80.1 * libcups2-2.2.7-150000.3.80.1 * libcups2-debuginfo-2.2.7-150000.3.80.1 * cups-debugsource-2.2.7-150000.3.80.1 ## References: * https://www.suse.com/security/cve/CVE-2025-58436.html * https://bugzilla.suse.com/show_bug.cgi?id=1254353 . Installation instructions for the important security update for cups on openSUSE to resolve CVE-2025-58436 issues.. cups security fix, openSUSE update, application vulnerability, Linux security patch. . Severity: Important. LinuxSecurity.com Team
New version 3.0.2 (rhbz#2407048) Fixes CVE-2025-11232 (rhbz#2407228). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e121742c9d 2025-11-08 01:27:10.727077+00:00 -------------------------------------------------------------------------------- Name : kea Product : Fedora 42 Version : 3.0.2 Release : 1.fc42 URL : http://kea.isc.org Summary : DHCPv4, DHCPv6 and DDNS server from ISC Description : DHCP implementation from Internet Systems Consortium, Inc. that features fully functional DHCPv4, DHCPv6 and Dynamic DNS servers. Both DHCP servers fully support server discovery, address assignment, renewal, rebinding and release. The DHCPv6 server supports prefix delegation. Both servers support DNS Update mechanism, using stand-alone DDNS daemon. -------------------------------------------------------------------------------- Update Information: New version 3.0.2 (rhbz#2407048) Fixes CVE-2025-11232 (rhbz#2407228) -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 30 2025 Martin Osvald - 3.0.2-1 - New version 3.0.2 (rhbz#2407048) - Fixes CVE-2025-11232 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2407048 - kea-3.0.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2407048 [ 2 ] Bug #2407228 - CVE-2025-11232 kea: Invalid characters cause assert [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2407228 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e121742c9d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details onthe GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.