Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 27 articles for you...
89

Fedora 42 rust-sequoia-octopus-librnp Important RUSTSEC-2025-0136 Patch

Rebuild with sequoia-openpgp v2.1.0 to apply fixes for RUSTSEC-2025-0136 / CVE-2025-67897.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-304a740a0b 2026-02-04 02:04:17.337391+00:00 -------------------------------------------------------------------------------- Name : rust-sequoia-octopus-librnp Product : Fedora 42 Version : 1.11.1 Release : 4.fc42 URL : https://crates.io/crates/sequoia-octopus-librnp Summary : Reimplementation of RNP's interface using Sequoia for use with Thunderbird Description : Reimplementation of RNP's interface using Sequoia for use with Thunderbird. -------------------------------------------------------------------------------- Update Information: Rebuild with sequoia-openpgp v2.1.0 to apply fixes for RUSTSEC-2025-0136 / CVE-2025-67897. -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 26 2026 Fabio Valentini - 1.11.1-4 - Rebuild for sequoia-openpgp v2.1.0 (RUSTSEC-2025-0136 / CVE-2025-67897) * Sat Jan 17 2026 Fedora Release Engineering - 1.11.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Fri Jul 25 2025 Fedora Release Engineering - 1.11.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-304a740a0b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Apply critical fixes for rust-sequoia-octopus related to CVE-2025-67897 in Fedora 42 for enhanced security.. Fedora Update, rust-sequoia-octopus, CVE-2025, security patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 04, 2026 Important Fedora
100

SUSE Linux Helm Critical Security Notice SUSE-SU-2026-1234-0

# Security update for helm Announcement ID: SUSE-SU-2026:0326-1 Release Date: 2026-01-28T14:55:41Z Rating: important References:. # Security update for helm Announcement ID: SUSE-SU-2026:0326-1 Release Date: 2026-01-28T14:55:41Z Rating: important References: Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that can now be installed. ## Description: This update for helm rebuilds it against the current GO security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-326=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-326=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-326=1 * SUSEPackage Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-326=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-326=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-326=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-326=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-326=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-326=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-326=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-326=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-326=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-326=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-326=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.19.1-150000.1.62.1 * helm-3.19.1-150000.1.62.1 * openSUSE Leap 15.6 (noarch) * helm-zsh-completion-3.19.1-150000.1.62.1 * helm-fish-completion-3.19.1-150000.1.62.1 * helm-bash-completion-3.19.1-150000.1.62.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.19.1-150000.1.62.1 * helm-3.19.1-150000.1.62.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * helm-bash-completion-3.19.1-150000.1.62.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.19.1-150000.1.62.1 * helm-3.19.1-150000.1.62.1 * Containers Module 15-SP7 (noarch) * helm-zsh-completion-3.19.1-150000.1.62.1 * helm-bash-completion-3.19.1-150000.1.62.1 * SUSE Package Hub 15 15-SP7 (noarch) * helm-fish-completion-3.19.1-150000.1.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * helm-debuginfo-3.19.1-150000.1.62.1 * helm-3.19.1-150000.1.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * helm-zsh-completion-3.19.1-150000.1.62.1 * helm-bash-completion-3.19.1-150000.1.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * helm-debuginfo-3.19.1-150000.1.62.1 * helm-3.19.1-150000.1.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * helm-zsh-completion-3.19.1-150000.1.62.1 * helm-bash-completion-3.19.1-150000.1.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * helm-debuginfo-3.19.1-150000.1.62.1 * helm-3.19.1-150000.1.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * helm-zsh-completion-3.19.1-150000.1.62.1 * helm-bash-completion-3.19.1-150000.1.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * helm-debuginfo-3.19.1-150000.1.62.1 * helm-3.19.1-150000.1.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * helm-zsh-completion-3.19.1-150000.1.62.1 * helm-bash-completion-3.19.1-150000.1.62.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.19.1-150000.1.62.1 * helm-3.19.1-150000.1.62.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * helm-zsh-completion-3.19.1-150000.1.62.1 * helm-bash-completion-3.19.1-150000.1.62.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.19.1-150000.1.62.1 * helm-3.19.1-150000.1.62.1 * SUSE Linux EnterpriseServer 15 SP5 LTSS (noarch) * helm-zsh-completion-3.19.1-150000.1.62.1 * helm-bash-completion-3.19.1-150000.1.62.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.19.1-150000.1.62.1 * helm-3.19.1-150000.1.62.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * helm-zsh-completion-3.19.1-150000.1.62.1 * helm-bash-completion-3.19.1-150000.1.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * helm-debuginfo-3.19.1-150000.1.62.1 * helm-3.19.1-150000.1.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * helm-zsh-completion-3.19.1-150000.1.62.1 * helm-bash-completion-3.19.1-150000.1.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * helm-debuginfo-3.19.1-150000.1.62.1 * helm-3.19.1-150000.1.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * helm-zsh-completion-3.19.1-150000.1.62.1 * helm-bash-completion-3.19.1-150000.1.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * helm-debuginfo-3.19.1-150000.1.62.1 * helm-3.19.1-150000.1.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * helm-zsh-completion-3.19.1-150000.1.62.1 * helm-bash-completion-3.19.1-150000.1.62.1 . Critical security update for helm on SUSE targets important vulnerabilities across multiple versions.. SUSE helm security update patch important. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 28, 2026 Important SuSE
202

openSUSE Leap 16.0: Real-time Security Update for go1.25 2025-20157-1

An update that solves 13 vulnerabilities and has 19 bug fixes can now be installed.. openSUSE security update: security update for go1.25 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2025-20157-1 Rating: important References: * bsc#1244485 * bsc#1245878 * bsc#1247816 * bsc#1248082 * bsc#1249141 * bsc#1249985 * bsc#1251253 * bsc#1251254 * bsc#1251255 * bsc#1251256 * bsc#1251257 * bsc#1251258 * bsc#1251259 * bsc#1251260 * bsc#1251261 * bsc#1251262 * bsc#1254227 * bsc#1254430 * bsc#1254431 Cross-References: * CVE-2025-47910 * CVE-2025-47912 * CVE-2025-58183 * CVE-2025-58185 * CVE-2025-58186 * CVE-2025-58187 * CVE-2025-58188 * CVE-2025-58189 * CVE-2025-61723 * CVE-2025-61724 * CVE-2025-61725 * CVE-2025-61727 * CVE-2025-61729 CVSS scores: * CVE-2025-47910 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-47912 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2025-47912 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-58183 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-58183 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58185 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58185 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58186 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58186 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58187 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58187 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58188 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-58188 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-58189 ( SUSE ): 4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N * CVE-2025-58189 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N * CVE-2025-61723 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-61723 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-61724 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-61724 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-61725 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-61725 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-61727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-61727 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-61729 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-61729 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 13 vulnerabilities and has 19 bug fixes can now be installed. Description: This update for go1.25 fixes the following issues: Update to go1.25.5. Security issues fixed: - CVE-2025-61729: crypto/x509: excessive resource consumption in printing error string for host certificate validation (bsc#1254431). - CVE-2025-61727: crypto/x509: excluded subdomain constraint doesn't preclude wildcard SAN (bsc#1254430). - CVE-2025-61725: net/mail: excessive CPU consumption in ParseAddress (bsc#1251253). - CVE-2025-61724: net/textproto: excessive CPU consumption in Reader.ReadResponse (bsc#1251262). - CVE-2025-61723: encoding/pem: quadratic complexity when parsing some invalid inputs (bsc#1251256). - CVE-2025-58189: crypto/tls: ALPN negotiation error contains attacker controlled information (bsc#1251255). - CVE-2025-58188: crypto/x509: panic when validating certificates with DSA public keys(bsc#1251260). - CVE-2025-58187: crypto/x509: quadratic complexity when checking name constraints (bsc#1251254). - CVE-2025-58186: net/http: lack of limit when parsing cookies can cause memory exhaustion (bsc#1251259). - CVE-2025-58185: encoding/asn1: pre-allocating memory when parsing DER payload can cause memory exhaustion (bsc#1251258). - CVE-2025-58183: archive/tar: unbounded allocation when parsing GNU sparse map (bsc#1251261). - CVE-2025-47912: net/url: insufficient validation of bracketed IPv6 hostnames (bsc#1251257). - CVE-2025-47910: net/http: CrossOriginProtection insecure bypass patterns not limited to exact matches (bsc#1249141). Other issues fixed and changes: - Version 1.25.5: * go#76245 mime: FormatMediaType and ParseMediaType not compatible across 1.24 to 1.25 * go#76360 os: on windows RemoveAll removing directories containing read-only files errors with unlinkat ... Access is denied, ReOpenFile error handling followup - Version 1.25.4: * go#75480 cmd/link: linker panic and relocation errors with complex generics inlining * go#75775 runtime: build fails when run via QEMU for linux/amd64 running on linux/arm64 * go#75790 crypto/internal/fips140/subtle: Go 1.25 subtle.xorBytes panic on MIPS * go#75832 net/url: ipv4 mapped ipv6 addresses should be valid in square brackets * go#75952 encoding/pem: regression when decoding blocks with leading garbage * go#75989 os: on windows RemoveAll removing directories containing read-only files errors with unlinkat ... Access is denied * go#76010 cmd/compile: any(func(){})==any(func(){}) does not panic but should * go#76029 pem/encoding: malformed line endings can cause panics - Version 1.25.3: * go#75861 crypto/x509: TLS validation fails for FQDNs with trailing dot * go#75777 spec: Go1.25 spec should be dated closer to actual release date - Version 1.25.2: * go#75111 os, syscall: volume handles with FILE_FLAG_OVERLAPPED fail when calling ReadAt * go#75116 os: Root.MkdirAll can return "file exists" when calledconcurrently on the same path * go#75139 os: Root.OpenRoot sets incorrect name, losing prefix of original root * go#75221 debug/pe: pe.Open fails on object files produced by llvm-mingw 21 * go#75255 cmd/compile: export to DWARF types only referenced through interfaces * go#75347 testing/synctest: test timeout with no runnable goroutines * go#75357 net: new test TestIPv4WriteMsgUDPAddrPortTargetAddrIPVersion fails on plan9 * go#75524 crypto/internal/fips140/rsa: requires a panic if self-tests fail * go#75537 context: Err can return non-nil before Done channel is closed * go#75539 net/http: internal error: connCount underflow * go#75595 cmd/compile: internal compiler error with GOEXPERIMENT=cgocheck2 on github.com/leodido/go-urn * go#75610 sync/atomic: comment for Uintptr.Or incorrectly describes return value * go#75669 runtime: debug.decoratemappings don't work as expected - Version 1.25.1: * go#74822 cmd/go: "get toolchain@latest" should ignore release candidates * go#74999 net: WriteMsgUDPAddrPort should accept IPv4-mapped IPv6 destination addresses on IPv4 UDP sockets * go#75008 os/exec: TestLookPath fails on plan9 after CL 685755 * go#75021 testing/synctest: bubble not terminating * go#75083 os: File.Seek doesn't set the correct offset with Windows overlapped handles - Packaging: migrate from update-alternatives to libalternatives (bsc#1245878). - Fix runtime condition for gcc/gcc7 dependency. - Use at least gcc 7 for all architectures (bsc#1254227). - Package svgpan.js to fix issues with "go tool pprof" (boo#1249985). - Drop unused gccgo bootstrap code in go1.22+ (bsc#1248082). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-102=1 Package List: - openSUSE Leap 16.0: go1.25-1.25.5-160000.1.1 go1.25-doc-1.25.5-160000.1.1 go1.25-libstd-1.25.5-160000.1.1 go1.25-race-1.25.5-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2025-47910.html * https://www.suse.com/security/cve/CVE-2025-47912.html * https://www.suse.com/security/cve/CVE-2025-58183.html * https://www.suse.com/security/cve/CVE-2025-58185.html * https://www.suse.com/security/cve/CVE-2025-58186.html * https://www.suse.com/security/cve/CVE-2025-58187.html * https://www.suse.com/security/cve/CVE-2025-58188.html * https://www.suse.com/security/cve/CVE-2025-58189.html * https://www.suse.com/security/cve/CVE-2025-61723.html * https://www.suse.com/security/cve/CVE-2025-61724.html * https://www.suse.com/security/cve/CVE-2025-61725.html * https://www.suse.com/security/cve/CVE-2025-61727.html * https://www.suse.com/security/cve/CVE-2025-61729.html . This advisory details 13 security fixes for go1.25 on openSUSE 16.0, addressing important vulnerabilities.. openSUSE security update go1.25 critical vulnerabilities patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 14, 2025 Important OpenSUSE
197

Debian 11: gst-plugins-base1.0 Critical DoS Fix DLA-4371-1 CVE-2025-47806

Multiple vulnerabilities were fixed in the subparse plugin of gst-plugins-base1.0. GStreamer is a popular multimedia framework. CVE-2025-47806: Fix DoS via stack overflow in subparse plugin . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4371-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Jeremy Bícha November 14, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : gst-plugins-base1.0 Version : 1.18.4-2+deb11u4 CVE ID : CVE-2025-47806 CVE-2025-47807 CVE-2025-47808 Multiple vulnerabilities were fixed in the subparse plugin of gst-plugins-base1.0. GStreamer is a popular multimedia framework. CVE-2025-47806: Fix DoS via stack overflow in subparse plugin CVE-2025-47807: Fix DoS via null-deref in subparse plugin CVE-2025-47808: Fix DoS via null-deref in subparse plugin For Debian 11 bullseye, these problems have been fixed in version 1.18.4-2+deb11u4. We recommend that you upgrade your gst-plugins-base1.0 packages. For the detailed security status of gst-plugins-base1.0 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/gst-plugins-base1.0 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Multiple security issues fixed in gst-plugins-base1.0 for Debian LTS, enhancing stability and protection against exploits.. gst-plugins-base1.0 update, Debian security patch, stack overflow fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 14, 2025 Critical Debian LTS
100

SUSE: go1.24 Moderate Security Fix 2025:02760-1 for CVE-2025-47906

* bsc#1236217 * bsc#1247719 * bsc#1247720 Cross-References: . # Security update for go1.24 Announcement ID: SUSE-SU-2025:02760-1 Release Date: 2025-08-12T12:09:45Z Rating: moderate References: * bsc#1236217 * bsc#1247719 * bsc#1247720 Cross-References: * CVE-2025-47906 * CVE-2025-47907 CVSS scores: * CVE-2025-47906 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-47906 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2025-47907 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-47907 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2025-47907 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L Affected Products: * Development Tools Module 15-SP6 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for go1.24 fixes the following issues: * Update to go1.24.6: * CVE-2025-47906: Fixed LookPath returning unexpected paths (bsc#1247719) * CVE-2025-47907: Fixed incorrect results returned from Rows.Scan (bsc#1247720) * go#73800 runtime: RSS seems to have increased in Go 1.24 while the runtime accounting has not * go#74416 runtime: use-after-free of allpSnapshot in findRunnable * go#74694 runtime: segfaults in runtime.(*unwinder).next * go#74760 os/user:nolibgcc: TestGroupIdsTestUser failures ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-2760=1 * Development Tools Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-2760=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2025-2760=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-2760=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-2760=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-2760=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-2760=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-2760=1 * SUSELinux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-2760=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-2760=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-2760=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-2760=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-2760=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-2760=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-2760=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * go1.24-1.24.6-150000.1.32.1 * go1.24-race-1.24.6-150000.1.32.1 * go1.24-doc-1.24.6-150000.1.32.1 * Development Tools Module 15-SP6 (aarch64 ppc64le s390x x86_64) * go1.24-1.24.6-150000.1.32.1 * go1.24-race-1.24.6-150000.1.32.1 * go1.24-doc-1.24.6-150000.1.32.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * go1.24-1.24.6-150000.1.32.1 * go1.24-race-1.24.6-150000.1.32.1 * go1.24-doc-1.24.6-150000.1.32.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * go1.24-1.24.6-150000.1.32.1 * go1.24-race-1.24.6-150000.1.32.1 * go1.24-doc-1.24.6-150000.1.32.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * go1.24-1.24.6-150000.1.32.1 * go1.24-race-1.24.6-150000.1.32.1 * go1.24-doc-1.24.6-150000.1.32.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * go1.24-1.24.6-150000.1.32.1 * go1.24-race-1.24.6-150000.1.32.1 * go1.24-doc-1.24.6-150000.1.32.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * go1.24-1.24.6-150000.1.32.1 * go1.24-race-1.24.6-150000.1.32.1 * go1.24-doc-1.24.6-150000.1.32.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * go1.24-1.24.6-150000.1.32.1 * go1.24-race-1.24.6-150000.1.32.1 * go1.24-doc-1.24.6-150000.1.32.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * go1.24-1.24.6-150000.1.32.1 * go1.24-race-1.24.6-150000.1.32.1 * go1.24-doc-1.24.6-150000.1.32.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * go1.24-1.24.6-150000.1.32.1 * go1.24-race-1.24.6-150000.1.32.1 * go1.24-doc-1.24.6-150000.1.32.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * go1.24-1.24.6-150000.1.32.1 * go1.24-race-1.24.6-150000.1.32.1 * go1.24-doc-1.24.6-150000.1.32.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * go1.24-1.24.6-150000.1.32.1 * go1.24-race-1.24.6-150000.1.32.1 * go1.24-doc-1.24.6-150000.1.32.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * go1.24-1.24.6-150000.1.32.1 * go1.24-race-1.24.6-150000.1.32.1 * go1.24-doc-1.24.6-150000.1.32.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * go1.24-1.24.6-150000.1.32.1 * go1.24-race-1.24.6-150000.1.32.1 * go1.24-doc-1.24.6-150000.1.32.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * go1.24-1.24.6-150000.1.32.1 * go1.24-race-1.24.6-150000.1.32.1 * go1.24-doc-1.24.6-150000.1.32.1 ## References: * https://www.suse.com/security/cve/CVE-2025-47906.html * https://www.suse.com/security/cve/CVE-2025-47907.html * https://bugzilla.suse.com/show_bug.cgi?id=1236217 * https://bugzilla.suse.com/show_bug.cgi?id=1247719 * https://bugzilla.suse.com/show_bug.cgi?id=1247720 . The Ubuntu security patch resolves significant vulnerabilities in python3.10, enhancing overall system protection. Update today for increased safety!. SUSESecurity Update, go1.24 Patch, Linux Application Security, SUSE Linux Update, patch management. . LinuxSecurity.com Team

Calendar%202 Aug 12, 2025 SuSE
202

openSUSE Tumbleweed: 2025:15154-1 moderate: python313 CVE-2025-4516

An update that solves one vulnerability can now be installed.. # python313-3.13.3-3.1 on GA media Announcement ID: openSUSE-SU-2025:15154-1 Rating: moderate Cross-References: * CVE-2025-4516 CVSS scores: * CVE-2025-4516 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4516 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the python313-3.13.3-3.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * python313 3.13.3-3.1 * python313-32bit 3.13.3-3.1 * python313-curses 3.13.3-3.1 * python313-dbm 3.13.3-3.1 * python313-idle 3.13.3-3.1 * python313-tk 3.13.3-3.1 * python313-x86-64-v3 3.13.3-3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-4516.html . Stay informed with the latest security advisory for openSUSE Tumbleweed, highlighting essential updates to the Python 3.13 package to enhance system integrity. openSUSE Security Advisory, python software update, moderate CVE issue. . LinuxSecurity.com Team

Calendar%202 May 24, 2025 OpenSUSE
217

Oracle Linux 9: ELSA-2025-7598 critical: .NET 8.0 update

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-7598 http://linux.oracle.com/errata/ELSA-2025-7598.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: aspnetcore-runtime-8.0-8.0.16-1.0.1.el9_6.x86_64.rpm aspnetcore-runtime-dbg-8.0-8.0.16-1.0.1.el9_6.x86_64.rpm aspnetcore-targeting-pack-8.0-8.0.16-1.0.1.el9_6.x86_64.rpm dotnet-apphost-pack-8.0-8.0.16-1.0.1.el9_6.x86_64.rpm dotnet-hostfxr-8.0-8.0.16-1.0.1.el9_6.x86_64.rpm dotnet-runtime-8.0-8.0.16-1.0.1.el9_6.x86_64.rpm dotnet-runtime-dbg-8.0-8.0.16-1.0.1.el9_6.x86_64.rpm dotnet-sdk-8.0-8.0.116-1.0.1.el9_6.x86_64.rpm dotnet-sdk-dbg-8.0-8.0.116-1.0.1.el9_6.x86_64.rpm dotnet-targeting-pack-8.0-8.0.16-1.0.1.el9_6.x86_64.rpm dotnet-templates-8.0-8.0.116-1.0.1.el9_6.x86_64.rpm dotnet-sdk-8.0-source-built-artifacts-8.0.116-1.0.1.el9_6.x86_64.rpm aarch64: aspnetcore-runtime-8.0-8.0.16-1.0.1.el9_6.aarch64.rpm aspnetcore-runtime-dbg-8.0-8.0.16-1.0.1.el9_6.aarch64.rpm aspnetcore-targeting-pack-8.0-8.0.16-1.0.1.el9_6.aarch64.rpm dotnet-apphost-pack-8.0-8.0.16-1.0.1.el9_6.aarch64.rpm dotnet-hostfxr-8.0-8.0.16-1.0.1.el9_6.aarch64.rpm dotnet-runtime-8.0-8.0.16-1.0.1.el9_6.aarch64.rpm dotnet-runtime-dbg-8.0-8.0.16-1.0.1.el9_6.aarch64.rpm dotnet-sdk-8.0-8.0.116-1.0.1.el9_6.aarch64.rpm dotnet-sdk-dbg-8.0-8.0.116-1.0.1.el9_6.aarch64.rpm dotnet-targeting-pack-8.0-8.0.16-1.0.1.el9_6.aarch64.rpm dotnet-templates-8.0-8.0.116-1.0.1.el9_6.aarch64.rpm dotnet-sdk-8.0-source-built-artifacts-8.0.116-1.0.1.el9_6.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//dotnet8.0-8.0.116-1.0.1.el9_6.src.rpm Related CVEs: CVE-2025-26646 Description of changes: [8.0.116-1.0.1] - Add support for Oracle Linux [8.0.116-1] - Update to .NET SDK 8.0.116 and Runtime 8.0.16 - Resolves: RHEL-89448 _______________________________________________ El-errata mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Red Hat Linux Security Notice ELSA-2025-6327 offers enhancements for .NET 8.1 to maintain overall system integrity and performance.. Oracle Security Advisory, Linux Updates, .NET Runtime, Application Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 23, 2025 Critical Oracle
217

Oracle Linux 8: ELSA-2025-7589 Important: .NET 8.0 Runtime Patch

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-7589 http://linux.oracle.com/errata/ELSA-2025-7589.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: aspnetcore-runtime-8.0-8.0.16-1.0.1.el8_10.x86_64.rpm aspnetcore-runtime-dbg-8.0-8.0.16-1.0.1.el8_10.x86_64.rpm aspnetcore-targeting-pack-8.0-8.0.16-1.0.1.el8_10.x86_64.rpm dotnet-apphost-pack-8.0-8.0.16-1.0.1.el8_10.x86_64.rpm dotnet-hostfxr-8.0-8.0.16-1.0.1.el8_10.x86_64.rpm dotnet-runtime-8.0-8.0.16-1.0.1.el8_10.x86_64.rpm dotnet-runtime-dbg-8.0-8.0.16-1.0.1.el8_10.x86_64.rpm dotnet-sdk-8.0-8.0.116-1.0.1.el8_10.x86_64.rpm dotnet-sdk-dbg-8.0-8.0.116-1.0.1.el8_10.x86_64.rpm dotnet-targeting-pack-8.0-8.0.16-1.0.1.el8_10.x86_64.rpm dotnet-templates-8.0-8.0.116-1.0.1.el8_10.x86_64.rpm dotnet-sdk-8.0-source-built-artifacts-8.0.116-1.0.1.el8_10.x86_64.rpm aarch64: aspnetcore-runtime-8.0-8.0.16-1.0.1.el8_10.aarch64.rpm aspnetcore-runtime-dbg-8.0-8.0.16-1.0.1.el8_10.aarch64.rpm aspnetcore-targeting-pack-8.0-8.0.16-1.0.1.el8_10.aarch64.rpm dotnet-apphost-pack-8.0-8.0.16-1.0.1.el8_10.aarch64.rpm dotnet-hostfxr-8.0-8.0.16-1.0.1.el8_10.aarch64.rpm dotnet-runtime-8.0-8.0.16-1.0.1.el8_10.aarch64.rpm dotnet-runtime-dbg-8.0-8.0.16-1.0.1.el8_10.aarch64.rpm dotnet-sdk-8.0-8.0.116-1.0.1.el8_10.aarch64.rpm dotnet-sdk-dbg-8.0-8.0.116-1.0.1.el8_10.aarch64.rpm dotnet-targeting-pack-8.0-8.0.16-1.0.1.el8_10.aarch64.rpm dotnet-templates-8.0-8.0.116-1.0.1.el8_10.aarch64.rpm dotnet-sdk-8.0-source-built-artifacts-8.0.116-1.0.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//dotnet8.0-8.0.116-1.0.1.el8_10.src.rpm Related CVEs: CVE-2025-26646 Description of changes: [8.0.116-1.0.1] - Add support for Oracle Linux [8.0.116-1] - Update to .NET SDK 8.0.116 and Runtime 8.0.16 - Resolves: RHEL-89446 _______________________________________________ El-errata mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . New enhancements for Oracle Linux 8 regarding .NET 8.0 have been released, focusing on significant updates and bolstering security for its users.. Oracle Linux, .NET 8.0, software updates, security patches. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 21, 2025 Important Oracle
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200