Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update that solves 3 vulnerabilities and has 5 bug fixes can now be installed.. openSUSE security update: security update for hplip ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20858-1 Rating: critical References: * bsc#1250481 * bsc#1257529 * bsc#1266023 * bsc#1266024 * bsc#1266031 Cross-References: * CVE-2025-43023 * CVE-2026-8631 * CVE-2026-8632 CVSS scores: * CVE-2025-43023 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-43023 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-8631 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-8631 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8632 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-8632 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has 5 bug fixes can now be installed. Description: This update for hplip fixes the following issues: Changes in hplip: - Update to HPLIP 3.26.4 * CVE-2026-8631: Fixed privileges escalation and/or arbitrary code execution via an integer overflow in the hpcups processing path (bsc#1266023) * CVE-2026-8632: Fixed privileges escalation and/or arbitrary code execution via operating system command injection (bsc#1266024) - Add support for the following new printers: * HP LaserJet Pro MFP 3106sdw * HP LaserJet Pro MFP 3105sdw * HP Envy 6500e series * HP Envy 6500 series * HP OfficeJet Pro 9730 Series * HP OfficeJet Pro 9730e Series * HP OfficeJet Pro 9720 Series * HPOfficeJet Pro 9720e Series * HP OfficeJet Pro 8130e All-in-One series * HP OfficeJet Pro 8130 All-in-One series * HP OfficeJet 8130e All-in-One series * HP OfficeJet 8130 All-in-One series * HP OfficeJet Pro 8120e All-in-One series * HP OfficeJet Pro 8120 All-in-One series * HP OfficeJet 8120e All-in-One series * HP OfficeJet 8120 All-in-One series * HP DeskJet Ink Advantage ultra 5800 All-in-One Printer series * HP DeskJet Ink Advantage ultra 5100 All-in-One Printer series * HP DeskJet 4300e All-in-One Printer series * HP DeskJet Ink Advantage 4300 All-in-One Printer series * HP DeskJet 4300 All-in-One Printer series * HP DeskJet 2900e All-in-One Printer series * HP DeskJet Ink Advantage 2900 All-in-One Printer series * HP DeskJet 2900 All-in-One Printer series - Update to HPLIP 3.25.8 - Added support for the following new Printers: * HP LaserJet Enterprise Flow MFP 8601z * HP LaserJet Enterprise 5501 * HP LaserJet Enterprise MFP 5601dn * HP LaserJet Enterprise 6500dn * HP LaserJet Enterprise 5501n * HP LaserJet Enterprise MFP 5601 * HP LaserJet Enterprise 6500 * HP LaserJet Enterprise 5502dn * HP LaserJet Enterprise MFP 5602dn * HP LaserJet Enterprise 6500n * HP LaserJet Enterprise 5502 * HP LaserJet Enterprise MFP 5602f * HP LaserJet Enterprise 6501dn * HP LaserJet Enterprise X50452dn * HP LaserJet Enterprise Flow MFP 5602zfw * HP LaserJet Enterprise 6501 * HP LaserJet Enterprise X50452 * HP LaserJet Enterprise MFP 5602 * HP LaserJet Enterprise X60257dn * HP LaserJet Enterprise MFP X53052dn * HP LaserJet Enterprise Flow MFP X530 * HP LaserJet Enterprise X60257 * HP LaserJet Enterprise MFP X53052 * HP LaserJet Enterprise X60357dn * HP LaserJet Enterprise X60357 * HP LaserJet Enterprise MFP 6600dn * HP LaserJet Enterprise Flow MFP 6600zfw * HP LaserJet Enterprise MFP 6600 * HP LaserJet Enterprise Flow MFP 6600zfsw * HP LaserJet Enterprise MFP X62757dn * HP LaserJet Enterprise Flow MFP X62757zs * HP LaserJetEnterprise MFP X62757 * DEX D50452dn * DEX MFP D53052dn - Fix handling of readfp() and read_filke() for ConfigParser objects, avoiding confusing error messages (lp#2139771) - Fix compiler warnings on SLE15 - Fix "Found No Section" error with python (lp#2095776) - Fix PPD lookup by moving PPDs from manufacturer-PPDs/hplip-fax to manufacturer-PPDs/hplip/fax etc (boo#1257529) - Move more utilities from hplip-utils to hplip-base. * hplip-base now contains all utilities that are not totally useless and can run without the Qt GUI. - Update fix for support of new GPG key, as the key has now been uploaded to GPG keyservers (lp#2120738) - This fixes CVE-2025-43023 (bsc#1266031) - Drop dependency on cups-ppdc. It isn't necessary, as PPD generation on target system is done by cups-driverd. - The old and outdated 'hpijs' driver support is finally dropped (the 'hpcups' driver is the default driver since 2009) so that there is no need for foomatic-filters (boo#1250481) - Continue refactoring: * move GUI tools to "hplip-utils" subpackage * convert "hplip" into an empty metapackage that pulls in hplip-utils and all drivers / PPDs (except hpijs PPDs). - Refactor package structure: * hplip: full set of utilities. Pulls in almost all subpackages to deliver the "traditional" hplip experience * hplip-base: small set of basic utilities that can be run without GUI. Includes hp-probe and hp-plugin * hplip-cups: minimal package for printing, without PPDs or setup helpers * hplip-sane: scanning support (unchanged) * hplip-driver-hpcups: hpcups.drv for generating hpcups PPDs on the fly (requires ppdc). The functionality of this package is similar to the old (misnamed) "hplip-hpijs" package. * hplip-driver-hpijs: hpijs.drv for generating PPDs for the deprecated hpijs / foomatic_rip filter. Note that this functionality was not part of the late hplip-hpijs package, because upstream hasn't ship foomatic PPDs since hplip 3.17.11. *hplip-ppds-{hpcups,hpps,postscript,hpijs,fax,plugin}: static PPD files for different printer types. hplip-ppds-hpcups is an alternative to hplip-driver-hpcups. * libhplip0: shared library package, used by hplip-cups and hplip-sane * hplip-common: configuration files and directories used by all hplip packages. - Other spec file changes: * Skip deprecated suse_update_desktop_file by default on TW * Don't mess with sane configuration in udev rules * Only the hpijs packages depend on foomatic-rip, which is only provided by cups-filters-1.x. The other packages can be used with cups-filters2. * Remove Obsoletes: for ancient predecessor packages * Remove outdated comments from spec file * Shorten package descriptions * Fix a couple of rpmlint issues - Fix printer probing using avahi (lp#2120947) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-288=1 Package List: - openSUSE Leap 16.0: hplip-3.26.4-bp160.1.1 hplip-base-3.26.4-bp160.1.1 hplip-common-3.26.4-bp160.1.1 hplip-cups-3.26.4-bp160.1.1 hplip-devel-3.26.4-bp160.1.1 hplip-driver-hpcups-3.26.4-bp160.1.1 hplip-ppds-fax-3.26.4-bp160.1.1 hplip-ppds-hpcups-3.26.4-bp160.1.1 hplip-ppds-hpps-3.26.4-bp160.1.1 hplip-ppds-plugin-3.26.4-bp160.1.1 hplip-ppds-postscript-3.26.4-bp160.1.1 hplip-sane-3.26.4-bp160.1.1 hplip-utils-3.26.4-bp160.1.1 libhplip0-3.26.4-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2025-43023.html * https://www.suse.com/security/cve/CVE-2026-8631.html * https://www.suse.com/security/cve/CVE-2026-8632.html . OpenSUSE announces a critical security update for HPLIP fixing multiple serious bugs and vulnerabilities.. OpenSUSE HPLIP Patch Critical Security Updates. . Severity: Critical. LinuxSecurity.com Team
Important: vim security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:11510", "synopsis": "Important: vim security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for vim.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Vim (Vi IMproved) is an updated and improved version of the vi editor.\n\nSecurity Fix(es):\n\n* vim: arbitrary command execution via modeline sandbox bypass (CVE-2026-34982)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2455400", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2455400", "description": ""}], "cves": [{"name": "CVE-2026-34982", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34982", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N", "cvss3BaseScore": "8.2", "cwe": "CWE-78"}], "references": [], "publishedAt": "2026-04-30T12:03:33.126838Z", "rpms": {"Rocky Linux 9": {"nvras": ["vim-2:8.2.2637-23.el9_7.3.src.rpm", "vim-common-2:8.2.2637-23.el9_7.3.aarch64.rpm", "vim-common-2:8.2.2637-23.el9_7.3.ppc64le.rpm", "vim-common-2:8.2.2637-23.el9_7.3.s390x.rpm", "vim-common-2:8.2.2637-23.el9_7.3.x86_64.rpm", "vim-common-debuginfo-2:8.2.2637-23.el9_7.3.aarch64.rpm", "vim-common-debuginfo-2:8.2.2637-23.el9_7.3.ppc64le.rpm", "vim-common-debuginfo-2:8.2.2637-23.el9_7.3.s390x.rpm", "vim-common-debuginfo-2:8.2.2637-23.el9_7.3.x86_64.rpm", "vim-debuginfo-2:8.2.2637-23.el9_7.3.aarch64.rpm", "vim-debuginfo-2:8.2.2637-23.el9_7.3.ppc64le.rpm", "vim-debuginfo-2:8.2.2637-23.el9_7.3.s390x.rpm", "vim-debuginfo-2:8.2.2637-23.el9_7.3.x86_64.rpm","vim-debugsource-2:8.2.2637-23.el9_7.3.aarch64.rpm", "vim-debugsource-2:8.2.2637-23.el9_7.3.ppc64le.rpm", "vim-debugsource-2:8.2.2637-23.el9_7.3.s390x.rpm", "vim-debugsource-2:8.2.2637-23.el9_7.3.x86_64.rpm", "vim-enhanced-2:8.2.2637-23.el9_7.3.aarch64.rpm", "vim-enhanced-2:8.2.2637-23.el9_7.3.ppc64le.rpm", "vim-enhanced-2:8.2.2637-23.el9_7.3.s390x.rpm", "vim-enhanced-2:8.2.2637-23.el9_7.3.x86_64.rpm", "vim-enhanced-debuginfo-2:8.2.2637-23.el9_7.3.aarch64.rpm", "vim-enhanced-debuginfo-2:8.2.2637-23.el9_7.3.ppc64le.rpm", "vim-enhanced-debuginfo-2:8.2.2637-23.el9_7.3.s390x.rpm", "vim-enhanced-debuginfo-2:8.2.2637-23.el9_7.3.x86_64.rpm", "vim-filesystem-2:8.2.2637-23.el9_7.3.noarch.rpm", "vim-minimal-2:8.2.2637-23.el9_7.3.aarch64.rpm", "vim-minimal-2:8.2.2637-23.el9_7.3.ppc64le.rpm", "vim-minimal-2:8.2.2637-23.el9_7.3.s390x.rpm", "vim-minimal-2:8.2.2637-23.el9_7.3.x86_64.rpm", "vim-minimal-debuginfo-2:8.2.2637-23.el9_7.3.aarch64.rpm", "vim-minimal-debuginfo-2:8.2.2637-23.el9_7.3.ppc64le.rpm", "vim-minimal-debuginfo-2:8.2.2637-23.el9_7.3.s390x.rpm", "vim-minimal-debuginfo-2:8.2.2637-23.el9_7.3.x86_64.rpm", "vim-X11-2:8.2.2637-23.el9_7.3.aarch64.rpm", "vim-X11-2:8.2.2637-23.el9_7.3.ppc64le.rpm", "vim-X11-2:8.2.2637-23.el9_7.3.s390x.rpm", "vim-X11-2:8.2.2637-23.el9_7.3.x86_64.rpm", "vim-X11-debuginfo-2:8.2.2637-23.el9_7.3.aarch64.rpm", "vim-X11-debuginfo-2:8.2.2637-23.el9_7.3.ppc64le.rpm", "vim-X11-debuginfo-2:8.2.2637-23.el9_7.3.s390x.rpm", "vim-X11-debuginfo-2:8.2.2637-23.el9_7.3.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Vim security update for Rocky Linux 9 addressing significant command execution risks. Ensure your systems are protected!. Rocky Linux 9,Vim security update,command execution risk. . Severity: Important. LinuxSecurity.com Team
Update goose to fix fedora#2449678. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6ff3ef2d32 2026-04-25 01:21:36.171379+00:00 -------------------------------------------------------------------------------- Name : goose Product : Fedora 44 Version : 1.23.2 Release : 8.fc44 URL : https://github.com/block/goose Summary : Extensible AI agent client Description : Goose is your on-machine AI agent, capable of automating complex development tasks from start to finish. More than just code suggestions, goose can build entire projects from scratch, write and execute code, debug failures, orchestrate workflows, and interact with external APIs - autonomously. Whether you're prototyping an idea, refining existing code, or managing intricate engineering pipelines, goose adapts to your workflow and executes tasks with precision. Designed for maximum flexibility, goose works with any LLM and supports multi-model configuration to optimize performance and cost, seamlessly integrates with MCP servers, and is available as both a desktop app as well as CLI - making it the ultimate AI assistant for developers who want to move faster and focus on innovation. -------------------------------------------------------------------------------- Update Information: Update goose to fix fedora#2449678 -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 27 2026 Manuel Moran - 1.23.2-8 - [skip changelog] Fix gating * Fri Mar 27 2026 Martin Litwora - 1.23.2-7 - Change the test plan URL to point directly to centos-stream test repository * Thu Mar 26 2026 Sam Doran - 1.23.2-6 - Fix CVE-2026-33056 for tar dependency * Wed Mar 25 2026 Sam Doran - 1.23.2-5 - Raise recursion limit on server_test.rs * Tue Mar 24 2026 Sam Doran - 1.23.2-4 - Add basic goose config * Mon Mar 23 2026 Manuel Moran - 1.23.2-3 - Addgating -------------------------------------------------------------------------------- References: [ 1 ] Bug #2449678 - CVE-2026-33056 goose: tar-rs: Arbitrary directory permission modification via crafted tar archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449678 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6ff3ef2d32' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update goose to fix fedora#2449678. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a45f438402 2026-04-08 00:52:24.173289+00:00 -------------------------------------------------------------------------------- Name : goose Product : Fedora 43 Version : 1.23.2 Release : 7.fc43 URL : https://github.com/aaif-goose/goose Summary : Extensible AI agent client Description : Goose is your on-machine AI agent, capable of automating complex development tasks from start to finish. More than just code suggestions, goose can build entire projects from scratch, write and execute code, debug failures, orchestrate workflows, and interact with external APIs - autonomously. Whether you're prototyping an idea, refining existing code, or managing intricate engineering pipelines, goose adapts to your workflow and executes tasks with precision. Designed for maximum flexibility, goose works with any LLM and supports multi-model configuration to optimize performance and cost, seamlessly integrates with MCP servers, and is available as both a desktop app as well as CLI - making it the ultimate AI assistant for developers who want to move faster and focus on innovation. -------------------------------------------------------------------------------- Update Information: Update goose to fix fedora#2449678 -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 27 2026 Manuel Moran - 1.23.2-7 - [skip changelog] Fix gating * Fri Mar 27 2026 Martin Litwora - 1.23.2-6 - Change the test plan URL to point directly to centos-stream test repository * Fri Mar 27 2026 Sam Doran - 1.23.2-5 - Fix CVE-2026-33056 for tar dependency * Thu Mar 26 2026 Sam Doran - 1.23.2-4 - Raise recursion limit on server_test.rs * Mon Mar 23 2026 Manuel Moran - 1.23.2-3 - Addgating -------------------------------------------------------------------------------- References: [ 1 ] Bug #2449678 - CVE-2026-33056 goose: tar-rs: Arbitrary directory permission modification via crafted tar archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449678 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a45f438402' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Important: postgresql:12 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:4064", "synopsis": "Important: postgresql:12 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for pg_repack, pgaudit, module.postgres-decoderbufs, module.pgaudit, module.pg_repack, postgres-decoderbufs.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "PostgreSQL is an advanced object-relational database management system (DBMS).\n\nSecurity Fix(es):\n\n* postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code (CVE-2026-2006)\n\n* postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code (CVE-2026-2004)\n\n* postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code (CVE-2026-2005)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2439324", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2439324", "description": ""}, {"ticket": "2439325", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2439325", "description": ""}, {"ticket": "2439326", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2439326", "description": ""}], "cves": [{"name": "CVE-2026-2004", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-2004", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-1287"}, {"name": "CVE-2026-2005", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-2005", "cvss3ScoringVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-120"}, {"name": "CVE-2026-2006", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-2006", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-1285"}], "references": [], "publishedAt": "2026-03-09T18:01:13.830662Z", "rpms": {"Rocky Linux 8": {"nvras": ["pgaudit-0:1.4.0-7.module+el8.9.0+1735+a332307b.aarch64.rpm", "pgaudit-0:1.4.0-7.module+el8.9.0+1735+a332307b.src.rpm", "pgaudit-0:1.4.0-7.module+el8.9.0+1735+a332307b.x86_64.rpm", "pgaudit-debuginfo-0:1.4.0-7.module+el8.9.0+1735+a332307b.aarch64.rpm", "pgaudit-debuginfo-0:1.4.0-7.module+el8.9.0+1735+a332307b.x86_64.rpm", "pgaudit-debugsource-0:1.4.0-7.module+el8.9.0+1735+a332307b.aarch64.rpm", "pgaudit-debugsource-0:1.4.0-7.module+el8.9.0+1735+a332307b.x86_64.rpm", "pg_repack-0:1.4.6-3.module+el8.9.0+1594+4a6adae9.aarch64.rpm", "pg_repack-0:1.4.6-3.module+el8.9.0+1603+444d1b54.aarch64.rpm", "pg_repack-0:1.4.6-3.module+el8.10.0+1862+29bef648.aarch64.rpm", "pg_repack-0:1.4.6-3.module+el8.10.0+40055+b85d5ce2.aarch64.rpm", "pg_repack-0:1.4.6-3.module+el8.9.0+1603+444d1b54.src.rpm", "pg_repack-0:1.4.6-3.module+el8.10.0+1862+29bef648.src.rpm", "pg_repack-0:1.4.6-3.module+el8.9.0+1594+4a6adae9.src.rpm", "pg_repack-0:1.4.6-3.module+el8.10.0+40055+b85d5ce2.src.rpm", "pg_repack-0:1.4.6-3.module+el8.9.0+1603+444d1b54.x86_64.rpm", "pg_repack-0:1.4.6-3.module+el8.9.0+1594+4a6adae9.x86_64.rpm", "pg_repack-0:1.4.6-3.module+el8.10.0+40055+b85d5ce2.x86_64.rpm", "pg_repack-0:1.4.6-3.module+el8.10.0+1862+29bef648.x86_64.rpm", "pg_repack-debuginfo-0:1.4.6-3.module+el8.10.0+40055+b85d5ce2.aarch64.rpm", "pg_repack-debuginfo-0:1.4.6-3.module+el8.10.0+1862+29bef648.aarch64.rpm", "pg_repack-debuginfo-0:1.4.6-3.module+el8.9.0+1603+444d1b54.aarch64.rpm", "pg_repack-debuginfo-0:1.4.6-3.module+el8.9.0+1594+4a6adae9.aarch64.rpm", "pg_repack-debuginfo-0:1.4.6-3.module+el8.9.0+1603+444d1b54.x86_64.rpm","pg_repack-debuginfo-0:1.4.6-3.module+el8.9.0+1594+4a6adae9.x86_64.rpm", "pg_repack-debuginfo-0:1.4.6-3.module+el8.10.0+1862+29bef648.x86_64.rpm", "pg_repack-debuginfo-0:1.4.6-3.module+el8.10.0+40055+b85d5ce2.x86_64.rpm", "pg_repack-debugsource-0:1.4.6-3.module+el8.10.0+40055+b85d5ce2.aarch64.rpm", "pg_repack-debugsource-0:1.4.6-3.module+el8.10.0+1862+29bef648.aarch64.rpm", "pg_repack-debugsource-0:1.4.6-3.module+el8.9.0+1594+4a6adae9.aarch64.rpm", "pg_repack-debugsource-0:1.4.6-3.module+el8.9.0+1603+444d1b54.aarch64.rpm", "pg_repack-debugsource-0:1.4.6-3.module+el8.9.0+1603+444d1b54.x86_64.rpm", "pg_repack-debugsource-0:1.4.6-3.module+el8.9.0+1594+4a6adae9.x86_64.rpm", "pg_repack-debugsource-0:1.4.6-3.module+el8.10.0+1862+29bef648.x86_64.rpm", "pg_repack-debugsource-0:1.4.6-3.module+el8.10.0+40055+b85d5ce2.x86_64.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.9.0+1594+4a6adae9.aarch64.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.10.0+40055+b85d5ce2.aarch64.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.10.0+1862+29bef648.aarch64.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.9.0+1603+444d1b54.aarch64.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.9.0+1594+4a6adae9.src.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.10.0+1862+29bef648.src.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.10.0+40055+b85d5ce2.src.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.9.0+1603+444d1b54.src.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.9.0+1594+4a6adae9.x86_64.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.10.0+1862+29bef648.x86_64.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.9.0+1603+444d1b54.x86_64.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.10.0+40055+b85d5ce2.x86_64.rpm", "postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.10.0+1862+29bef648.aarch64.rpm", "postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.9.0+1594+4a6adae9.aarch64.rpm", "postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.9.0+1603+444d1b54.aarch64.rpm","postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.10.0+40055+b85d5ce2.aarch64.rpm", "postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.9.0+1603+444d1b54.x86_64.rpm", "postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.10.0+1862+29bef648.x86_64.rpm", "postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.10.0+40055+b85d5ce2.x86_64.rpm", "postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.9.0+1594+4a6adae9.x86_64.rpm", "postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.9.0+1603+444d1b54.aarch64.rpm", "postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.9.0+1594+4a6adae9.aarch64.rpm", "postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.10.0+1862+29bef648.aarch64.rpm", "postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.10.0+40055+b85d5ce2.aarch64.rpm", "postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.9.0+1594+4a6adae9.x86_64.rpm", "postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.9.0+1603+444d1b54.x86_64.rpm", "postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.10.0+1862+29bef648.x86_64.rpm", "postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.10.0+40055+b85d5ce2.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Critical PostgreSQL updates for Rocky Linux address multiple security concerns with important risks. Immediate action advised.. PostgreSQL security update Rock Linux vulnerabilities code execution. . Severity: Important. LinuxSecurity.com Team
The package webkit2gtk before version 2.30.3-1 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-202011-28 ========================================= Severity: Medium Date : 2020-11-26 CVE-ID : CVE-2020-9983 CVE-2020-13543 CVE-2020-13584 Package : webkit2gtk Type : arbitrary code execution Remote : Yes Link : https://security.archlinux.org/AVG-1291 Summary ====== The package webkit2gtk before version 2.30.3-1 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 2.30.3-1. # pacman -Syu "webkit2gtk> =2.30.3-1" The problems have been fixed upstream in version 2.30.3. Workaround ========= None. Description ========== - CVE-2020-9983 (arbitrary code execution) An out-of-bounds write issue was found in webkit2gtk before 2.30.3. Processing maliciously crafted web content may have lead to code execution. - CVE-2020-13543 (arbitrary code execution) A use after free issue was found in webkit2gtk before 2.30.3. Processing maliciously crafted web content may lead to arbitrary code execution. - CVE-2020-13584 (arbitrary code execution) A use after free issue was found in webkit2gtk before 2.30.3. Processing maliciously crafted web content may have lead to arbitrary code execution. Impact ===== A remote attacker might be able to execute arbitrary code via crafted web content. References ========= https://webkitgtk.org/security/WSA-2020-0008.html https://www.cve.org/CVERecord?id=CVE-2020-9983 https://webkitgtk.org/security/WSA-2020-0009.html#CVE-2020-13543 https://www.cve.org/CVERecord?id=CVE-2020-13584 https://security.archlinux.org/CVE-2020-9983 https://security.archlinux.org/CVE-2020-13543 https://security.archlinux.org/CVE-2020-13584 . Arch Linux Security Notice on webkit2gtk's vulnerability to unauthorized code execution, advising users to update promptly to reduce risks.. Arch Linux, webkit2gtk, code execution threat, security update, software vulnerability. . Severity: Medium. LinuxSecurity.com Team
Multiple vulnerabilities have been found in WebKitGTK+, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202006-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: WebKitGTK+: Multiple vulnerabilities Date: June 13, 2020 Bugs: #712260 ID: 202006-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in WebKitGTK+, the worst of which could result in the arbitrary execution of code. Background ========= WebKitGTK+ is a full-featured port of the WebKit rendering engine, suitable for projects requiring any kind of web integration, from hybrid HTML/CSS applications to full-fledged web browsers. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-libs/webkit-gtk < 2.28.2 > = 2.28.2 Description ========== Multiple vulnerabilities have been discovered in WebKitGTK+. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All WebKitGTK+ users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-libs/webkit-gtk-2.28.2" References ========= [ 1 ] CVE-2020-10018 https://nvd.nist.gov/vuln/detail/CVE-2020-10018 [ 2 ] CVE-2020-10018 https://nvd.nist.gov/vuln/detail/CVE-2020-10018 [ 3 ] CVE-2020-11793 https://nvd.nist.gov/vuln/detail/CVE-2020-11793 [ 4 ] CVE-2020-11793 https://nvd.nist.gov/vuln/detail/CVE-2020-11793 [ 5 ] CVE-2020-3885 https://nvd.nist.gov/vuln/detail/CVE-2020-3885 [ 6 ] CVE-2020-3894 https://nvd.nist.gov/vuln/detail/CVE-2020-3894 [ 7 ] CVE-2020-3895 https://nvd.nist.gov/vuln/detail/CVE-2020-3895 [ 8 ] CVE-2020-3897 https://nvd.nist.gov/vuln/detail/CVE-2020-3897 [ 9 ] CVE-2020-3899 https://nvd.nist.gov/vuln/detail/CVE-2020-3899 [ 10 ] CVE-2020-3900 https://nvd.nist.gov/vuln/detail/CVE-2020-3900 [ 11 ] CVE-2020-3901 https://nvd.nist.gov/vuln/detail/CVE-2020-3901 [ 12 ] CVE-2020-3902 https://nvd.nist.gov/vuln/detail/CVE-2020-3902 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202006-08 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been found in CUPS, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201908-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: CUPS: Multiple vulnerabilities Date: August 15, 2019 Bugs: #660954 ID: 201908-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in CUPS, the worst of which could result in the arbitrary execution of code. Background ========= CUPS, the Common Unix Printing System, is a full-featured print server. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-print/cups < 2.2.8 > = 2.2.8 Description ========== Multiple vulnerabilities have been discovered in CUPS. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All CUPS users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-print/cups-2.2.8" References ========= [ 1 ] CVE-2017-15400 https://nvd.nist.gov/vuln/detail/CVE-2017-15400 [ 2 ] CVE-2018-4180 https://nvd.nist.gov/vuln/detail/CVE-2018-4180 [ 3 ] CVE-2018-4181 https://nvd.nist.gov/vuln/detail/CVE-2018-4181 [ 4 ] CVE-2018-4182 https://nvd.nist.gov/vuln/detail/CVE-2018-4182 [ 5 ] CVE-2018-4183 https://nvd.nist.gov/vuln/detail/CVE-2018-4183 [ 6 ] CVE-2018-6553 https://nvd.nist.gov/vuln/detail/CVE-2018-6553 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201908-08 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.