Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 485
Alerts This Week
Warning Icon 1 485

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 22 articles for you...
100

SUSE Python-pip Important Path Traversal Issue 2026-22300-1

An update that solves one vulnerability can now be installed.. # Security update for python-pip Announcement ID: SUSE-SU-2026:22300-1 Release Date: 2026-06-20T18:17:57Z Rating: important References: * bsc#1266669 Cross-References: * CVE-2026-8643 CVSS scores: * CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-8643 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8643 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-pip fixes the following issue * CVE-2026-8643: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (bsc#1266669). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1005=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1005=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-pip-25.0.1-160000.5.1 * python313-pip-wheel-25.0.1-160000.5.1 * SUSE Linux Enterprise Server 16.0 (noarch) * python313-pip-25.0.1-160000.5.1 * python313-pip-wheel-25.0.1-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8643.html * https://bugzilla.suse.com/show_bug.cgi?id=1266669 . Update addresses an important security risk in python-pip affecting SUSE 16.0 relatedto file overwrite.. SUSE python-pip security update, SUSE 16.0 important advisory, python-pip vulnerability fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 01, 2026 Important SuSE
202

openSUSE Leap 16.0 python-pip Important Path Traversal Fix CVE-2026-8643

An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for python-pip ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20993-1 Rating: important References: * bsc#1266669 Cross-References: * CVE-2026-8643 CVSS scores: * CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for python-pip fixes the following issue - CVE-2026-8643: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (bsc#1266669). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1005=1 Package List: - openSUSE Leap 16.0: python313-pip-25.0.1-160000.5.1 python313-pip-wheel-25.0.1-160000.5.1 References: * https://www.suse.com/security/cve/CVE-2026-8643.html . This update for openSUSE addresses an important issue with python-pip, preventing arbitrary file overwrite risk.. openSUSE update, python-pip security, path traversal issue, important security patch, arbitrary file overwrite. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 Important OpenSUSE
202

openSUSE libsolv Important Buffer Overflow Path Traversal Vuln 2026-2674-1

An update that solves seven vulnerabilities, contains three features and has 14 security fixes can now be installed.. # Security update for libsolv, libzypp, zypper Announcement ID: SUSE-SU-2026:2674-1 Release Date: 2026-06-29T09:41:17Z Rating: important References: * bsc#1158038 * bsc#1239718 * bsc#1246504 * bsc#1247948 * bsc#1249435 * bsc#1252744 * bsc#1253193 * bsc#1253740 * bsc#1257068 * bsc#1257882 * bsc#1258193 * bsc#1259311 * bsc#1259706 * bsc#1259802 * bsc#1259842 * bsc#1265223 * bsc#1265935 * bsc#1265938 * bsc#1266039 * bsc#1267426 * bsc#1267874 * jsc#PED-13680 * jsc#PED-14658 * jsc#PED-15607 Cross-References: * CVE-2026-25707 * CVE-2026-44933 * CVE-2026-44941 * CVE-2026-44942 * CVE-2026-48863 * CVE-2026-9149 * CVE-2026-9150 CVSS scores: * CVE-2026-25707 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-25707 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44933 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44933 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44933 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44941 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44941 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-44942 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44942 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44942 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48863 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48863 ( SUSE ): 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9149 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9149 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9149 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9150 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9150 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves seven vulnerabilities, contains three features and has 14 security fixes can now be installed. ## Description: This update for libsolv, libzypp, zypper fixes the following issues * CVE-2026-9149: Heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file (bsc#1265935). * CVE-2026-9150: Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums (bsc#1265938). * CVE-2026-25707: Handcrafted repo metadata may cause arbitrary local files to be overwritten (bsc#1259802). * CVE-2026-44933: scan of the Mandatory signature verification plugin support (bsc#1265223). * CVE-2026-44941: path traversal via "keyhint" (bsc#1267426). * CVE-2026-44942: .repo files can have an optional path which can lead to path traversal attacks (bsc#1267874). * CVE-2026-48863: Fix buffer overflow whenparsing EdDSA signature (bsc#1266039). Changes in libzypp: Updated to version 17.38.13 (35): * A .repo files "path=" entry must not refer to a location outside the repo (bsc#1267874, CVE-2026-44942) A "path=" entry may solely denote a sub- directory of the baseurl where the metadata are located. A relative path trying to access data outside the baseurl is reported and sanitized. * Fix potential crash on malformed or malicious repository metadata (fixes #740) * Repo metadata: discard entries referring to a location outside the repo (bsc#1259802, CVE-2026-25707) Mirroring those data locally would refer to a location outside the repo's local cache directory. Those data entries are reported and discarded. * zypp.conf: Allow [env] section to add environment variables. This feature is designed to enable environment-specific settings or debugging options over an extended period. See zypp.conf(5). * Prevent configured scripts from escaping the sigcheck directory (bsc#1265223, CVE-2026-44933) * StringV: guard hasPrefix/hasPrefixCI against reading past the view end (fixes #735) * Mandatory signature verification plugin support (PED#11922) * Fix purge-kernel -rc kernel handling (bsc#1239718) * Explicitly_set_pool_DISTTYPE_RPM (fixes #726) * Check for trusted key updates when updating the general keyring (bsc#1259706) * Support multiple MirroredOrigin authorities (bsc#1253193) * Workaround doxygen bug: doxygen/doxygen#12057 * libzypp.spec: Add missing graphviz-gd BuildRequires (boo#1259842) * Fix preloader not caching packages from arch specific subrepos (bsc#1253740) * Deprioritize invalid mirrors (fixes openSUSE/zypper#636) * Fix Product::referencePackage lookup (bsc#1259311) Use a provided autoproduct() as hint to the package name of the release package. It might be that not just multiple versions of the same release package provide the same product version, but also different release packages. * specfile: on fedora use%{_prefix}/share as zyppconfdir if %{_distconfdir} is undefined (fixes #693) This will set '-DZYPPCONFDIR=%{zyppconfdir}' for cmake. * Fall back to a writable location when precaching packages without root (bsc#1247948) * Prepare a legacy /etc/zypp/zypp.conf to be installed on old distros. See the ZYPP.CONF(5) man page for details. * Fix runtime check for broken rpm --runposttrans (bsc#1257068) * Avoid libcurl-mini4 when building as it does not support ftp protocol. * Translation: updated .pot file. * zypp.conf: follow the UAPI configuration file specification (PED-14658) In short terms it means we will no longer ship an /etc/zypp/zypp.conf, but store our own defaults in /usr/etc/zypp/zypp.conf. The systems administrator may choose to keep a full copy in /etc/zypp/zypp.conf ignoring our config file settings completely, or - the preferred way - to overwrite specific settings via /etc/zypp/zypp.conf.d/*.conf overlay files. See the ZYPP.CONF(5) man page for details. * cmake: correctly detect rpm6 (fixes #689) * Use 'zypp.tmp' as temp directory component to ease setting up SELinux policies (bsc#1249435) * zyppng: Update Provider to current MediaCurl2 download approach, drop Metalink ( fixes #682 ) Changes in libsolv: Updated to version 0.7.39: * fix solv_chksum_free segfault when called with a NULL pointer * made repo_add_solv more robust against corrupt files [bsc#1265935] [CVE-2026-9149] * fix potential buffer overflow when verifying EdDSA signatures [bsc#1266039] [CVE-2026-48863] * added limit checks in multiple places to catch overflows * reduce the size of the language id cache * fixed Debian canon selection * fixed dbpath detection in repo_rpmdb_librpm * reduced stack usage in repo page compression (needed for musl) * fix parsing of sha512 checksums in debian repositories [bsc#1265938] [CVE-2026-9150] * improve speed of dirpool_add_dir makeing parsing of filelists.xml twice as fast * fix parsing ofrecommends in the old Mandriva synthesis format * respect the "default" attribute in environment optionlist in the comps parser * support suse namespace deps in boolean dependencies [bsc#1258193] * support for the Elbrus2000 (e2k) architecture * support language() suse namespace rewriting Changes in zypper: Update to version 1.14.98: * Transactional systems: Delegate rw-commands to transactional-wrapper if available (jsc#PED-13680, jsc#PED-15607) On a transactional system where the root filesystem is mounted read-only, zypper commands that modify the system cannot be executed directly. If the system provides a transactional-wrapper utility, zypper will automatically attempt to invoke it. The wrapper transparently executes the zypper command within a new, writable snapshot and manages the lifecycle of that snapshot based on the command's exit status. On transactional systems lacking a transactional-wrapper, users must manually invoke specialized tools -such as transactional-update- to install, update, or remove software. * Add --filter-version-change to zypper lu. Adds filtering by version change significance to reduce noise in update listings. Supports levels: rebuild (hides rebuild-only changes) and package (hides all release-only changes). * Autorefresh ris-services the way as plugin-services (bsc#1246504) It's actually wrong to treat service refreshes different depending on the service type. For the purpose of a service it makes no difference how the data about the repos to use are acquired. * Report download progress for command line rpms (fixes #613) * Hint to '-vv ref' to see the mirrors used to download the metadata (bsc#1257882) * Service: Allow "zypper ls SERVICE ..." to test whether a service with this alias is defined (bsc#1252744) The command prints an abstract of all services passed on the command line. It returns 3-ZYPPER_EXIT_ERR_INVALID_ARGS if some argument does not name an existing service. * Keep repo data when updating the service settings (bsc#1252744) * info: Enhance pattern content table (bsc#1158038) Alternatives (multiple packages providing the same requirement) are now listed as a single entry in the content table. The entry shows either the installed package which satisfies the requirement or the requirement itself as type 'Provides'. Listing all potential alternatives was miss leading, especially if the alternatives were mutual exclusive. It looked like an installed pattern had not-installed requirements and it was not possible to install all requirements at the same time. ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-2674=1 * SUSE Linux Enterprise Server 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-2674=1 * SUSE Linux Enterprise High Performance Computing 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-2674=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2674=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2674=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2674=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2674=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-2674=1 SUSE-SLE-Product- SLES_SAP-15-SP4-2026-2674=1 * SUSE Linux Enterprise Desktop 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-2674=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-2674=1 * SUSE Manager Proxy 4.3 zypper in -t patchSUSE-SLE-INSTALLER-15-SP4-2026-2674=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2674=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2674=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2674=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2674=1 ## Package List: * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * libsolv-tools-base-0.7.39-150400.3.46.1 * libsolv-tools-0.7.39-150400.3.46.1 * libzypp-17.38.13-150400.3.158.1 * SUSE Manager Server 4.3 (ppc64le) * libsolv-tools-base-debuginfo-0.7.39-150400.3.46.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libsolv-devel-debuginfo-0.7.39-150400.3.46.1 * perl-solv-0.7.39-150400.3.46.1 * libsolv-debugsource-0.7.39-150400.3.46.1 * libzypp-devel-17.38.13-150400.3.158.1 * libsolv-tools-0.7.39-150400.3.46.1 * libsolv-tools-base-debuginfo-0.7.39-150400.3.46.1 * libzypp-17.38.13-150400.3.158.1 * libsolv-debuginfo-0.7.39-150400.3.46.1 * libsolv-tools-debuginfo-0.7.39-150400.3.46.1 * libsolv-tools-base-0.7.39-150400.3.46.1 * perl-solv-debuginfo-0.7.39-150400.3.46.1 * ruby-solv-0.7.39-150400.3.46.1 * libzypp-debugsource-17.38.13-150400.3.158.1 * python3-solv-debuginfo-0.7.39-150400.3.46.1 * python3-solv-0.7.39-150400.3.46.1 * zypper-debugsource-1.14.98-150400.3.104.1 * libsolv-devel-0.7.39-150400.3.46.1 * libzypp-debuginfo-17.38.13-150400.3.158.1 * zypper-debuginfo-1.14.98-150400.3.104.1 * zypper-1.14.98-150400.3.104.1 * ruby-solv-debuginfo-0.7.39-150400.3.46.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * zypper-needs-restarting-1.14.98-150400.3.104.1 * zypper-log-1.14.98-150400.3.104.1 * SUSE Linux Enterprise High Performance Computing 15 SP4 (aarch64x86_64) * libsolv-tools-base-0.7.39-150400.3.46.1 * libsolv-tools-0.7.39-150400.3.46.1 * libzypp-17.38.13-150400.3.158.1 * SUSE Linux Enterprise High Performance Computing 15 SP4 (aarch64) * libsolv-tools-base-debuginfo-0.7.39-150400.3.46.1 * SUSE Linux Enterprise Desktop 15 SP4 (x86_64) * libsolv-tools-base-0.7.39-150400.3.46.1 * libsolv-tools-0.7.39-150400.3.46.1 * libzypp-17.38.13-150400.3.158.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * libsolv-tools-base-0.7.39-150400.3.46.1 * libsolv-tools-0.7.39-150400.3.46.1 * libzypp-17.38.13-150400.3.158.1 * SUSE Manager Proxy 4.3 (x86_64) * libsolv-tools-base-0.7.39-150400.3.46.1 * libsolv-tools-0.7.39-150400.3.46.1 * libzypp-17.38.13-150400.3.158.1 * SUSE Linux Enterprise Server 15 SP4 (aarch64 ppc64le s390x x86_64) * libsolv-tools-base-0.7.39-150400.3.46.1 * libsolv-tools-0.7.39-150400.3.46.1 * libzypp-17.38.13-150400.3.158.1 * SUSE Linux Enterprise Server 15 SP4 (aarch64 ppc64le) * libsolv-tools-base-debuginfo-0.7.39-150400.3.46.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libsolv-devel-debuginfo-0.7.39-150400.3.46.1 * perl-solv-0.7.39-150400.3.46.1 * libsolv-debugsource-0.7.39-150400.3.46.1 * libzypp-devel-17.38.13-150400.3.158.1 * libsolv-tools-0.7.39-150400.3.46.1 * libsolv-tools-base-debuginfo-0.7.39-150400.3.46.1 * libzypp-17.38.13-150400.3.158.1 * libsolv-debuginfo-0.7.39-150400.3.46.1 * libsolv-tools-debuginfo-0.7.39-150400.3.46.1 * libsolv-tools-base-0.7.39-150400.3.46.1 * perl-solv-debuginfo-0.7.39-150400.3.46.1 * ruby-solv-0.7.39-150400.3.46.1 * libzypp-debugsource-17.38.13-150400.3.158.1 * python3-solv-debuginfo-0.7.39-150400.3.46.1 * python3-solv-0.7.39-150400.3.46.1 * zypper-debugsource-1.14.98-150400.3.104.1 * libsolv-devel-0.7.39-150400.3.46.1 * libzypp-debuginfo-17.38.13-150400.3.158.1 * zypper-debuginfo-1.14.98-150400.3.104.1 *zypper-1.14.98-150400.3.104.1 * ruby-solv-debuginfo-0.7.39-150400.3.46.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * zypper-needs-restarting-1.14.98-150400.3.104.1 * zypper-log-1.14.98-150400.3.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libsolv-devel-debuginfo-0.7.39-150400.3.46.1 * perl-solv-0.7.39-150400.3.46.1 * libsolv-debugsource-0.7.39-150400.3.46.1 * libzypp-devel-17.38.13-150400.3.158.1 * libsolv-tools-0.7.39-150400.3.46.1 * libsolv-tools-base-debuginfo-0.7.39-150400.3.46.1 * libzypp-17.38.13-150400.3.158.1 * libsolv-debuginfo-0.7.39-150400.3.46.1 * libsolv-tools-debuginfo-0.7.39-150400.3.46.1 * libsolv-tools-base-0.7.39-150400.3.46.1 * perl-solv-debuginfo-0.7.39-150400.3.46.1 * ruby-solv-0.7.39-150400.3.46.1 * libzypp-debugsource-17.38.13-150400.3.158.1 * python3-solv-debuginfo-0.7.39-150400.3.46.1 * python3-solv-0.7.39-150400.3.46.1 * zypper-debugsource-1.14.98-150400.3.104.1 * libsolv-devel-0.7.39-150400.3.46.1 * libzypp-debuginfo-17.38.13-150400.3.158.1 * zypper-debuginfo-1.14.98-150400.3.104.1 * zypper-1.14.98-150400.3.104.1 * ruby-solv-debuginfo-0.7.39-150400.3.46.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * zypper-needs-restarting-1.14.98-150400.3.104.1 * zypper-log-1.14.98-150400.3.104.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libsolv-devel-debuginfo-0.7.39-150400.3.46.1 * perl-solv-0.7.39-150400.3.46.1 * libsolv-debugsource-0.7.39-150400.3.46.1 * libzypp-devel-17.38.13-150400.3.158.1 * libsolv-tools-0.7.39-150400.3.46.1 * libsolv-tools-base-debuginfo-0.7.39-150400.3.46.1 * libzypp-17.38.13-150400.3.158.1 * libsolv-debuginfo-0.7.39-150400.3.46.1 * libzypp-devel-doc-17.38.13-150400.3.158.1 * libsolv-tools-debuginfo-0.7.39-150400.3.46.1 * libsolv-tools-base-0.7.39-150400.3.46.1 *perl-solv-debuginfo-0.7.39-150400.3.46.1 * python311-solv-debuginfo-0.7.39-150400.3.46.1 * ruby-solv-0.7.39-150400.3.46.1 * libzypp-debugsource-17.38.13-150400.3.158.1 * python3-solv-debuginfo-0.7.39-150400.3.46.1 * python3-solv-0.7.39-150400.3.46.1 * zypper-debugsource-1.14.98-150400.3.104.1 * libsolv-devel-0.7.39-150400.3.46.1 * libzypp-debuginfo-17.38.13-150400.3.158.1 * zypper-debuginfo-1.14.98-150400.3.104.1 * libsolv-demo-0.7.39-150400.3.46.1 * libsolv-demo-debuginfo-0.7.39-150400.3.46.1 * zypper-1.14.98-150400.3.104.1 * ruby-solv-debuginfo-0.7.39-150400.3.46.1 * python311-solv-0.7.39-150400.3.46.1 * openSUSE Leap 15.4 (noarch) * zypper-needs-restarting-1.14.98-150400.3.104.1 * zypper-log-1.14.98-150400.3.104.1 * zypper-aptitude-1.14.98-150400.3.104.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libzypp-17.38.13-150400.3.158.1 * libzypp-debugsource-17.38.13-150400.3.158.1 * libsolv-debuginfo-0.7.39-150400.3.46.1 * libzypp-debuginfo-17.38.13-150400.3.158.1 * zypper-debuginfo-1.14.98-150400.3.104.1 * libsolv-tools-debuginfo-0.7.39-150400.3.46.1 * libsolv-debugsource-0.7.39-150400.3.46.1 * libsolv-tools-base-0.7.39-150400.3.46.1 * zypper-1.14.98-150400.3.104.1 * libsolv-tools-0.7.39-150400.3.46.1 * libsolv-tools-base-debuginfo-0.7.39-150400.3.46.1 * zypper-debugsource-1.14.98-150400.3.104.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * zypper-needs-restarting-1.14.98-150400.3.104.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libzypp-17.38.13-150400.3.158.1 * libzypp-debugsource-17.38.13-150400.3.158.1 * libsolv-debuginfo-0.7.39-150400.3.46.1 * libzypp-debuginfo-17.38.13-150400.3.158.1 * zypper-debuginfo-1.14.98-150400.3.104.1 * libsolv-tools-debuginfo-0.7.39-150400.3.46.1 * libsolv-debugsource-0.7.39-150400.3.46.1 * libsolv-tools-base-0.7.39-150400.3.46.1 * zypper-1.14.98-150400.3.104.1 *libsolv-tools-0.7.39-150400.3.46.1 * libsolv-tools-base-debuginfo-0.7.39-150400.3.46.1 * zypper-debugsource-1.14.98-150400.3.104.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * zypper-needs-restarting-1.14.98-150400.3.104.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libzypp-17.38.13-150400.3.158.1 * libzypp-debugsource-17.38.13-150400.3.158.1 * libsolv-debuginfo-0.7.39-150400.3.46.1 * libzypp-debuginfo-17.38.13-150400.3.158.1 * zypper-debuginfo-1.14.98-150400.3.104.1 * libsolv-tools-debuginfo-0.7.39-150400.3.46.1 * libsolv-debugsource-0.7.39-150400.3.46.1 * libsolv-tools-base-0.7.39-150400.3.46.1 * zypper-1.14.98-150400.3.104.1 * libsolv-tools-0.7.39-150400.3.46.1 * libsolv-tools-base-debuginfo-0.7.39-150400.3.46.1 * zypper-debugsource-1.14.98-150400.3.104.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * zypper-needs-restarting-1.14.98-150400.3.104.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libzypp-17.38.13-150400.3.158.1 * libzypp-debugsource-17.38.13-150400.3.158.1 * libsolv-debuginfo-0.7.39-150400.3.46.1 * libzypp-debuginfo-17.38.13-150400.3.158.1 * zypper-debuginfo-1.14.98-150400.3.104.1 * libsolv-tools-debuginfo-0.7.39-150400.3.46.1 * libsolv-debugsource-0.7.39-150400.3.46.1 * libsolv-tools-base-0.7.39-150400.3.46.1 * zypper-1.14.98-150400.3.104.1 * libsolv-tools-0.7.39-150400.3.46.1 * libsolv-tools-base-debuginfo-0.7.39-150400.3.46.1 * zypper-debugsource-1.14.98-150400.3.104.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * zypper-needs-restarting-1.14.98-150400.3.104.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libsolv-devel-debuginfo-0.7.39-150400.3.46.1 * perl-solv-0.7.39-150400.3.46.1 * libsolv-debugsource-0.7.39-150400.3.46.1 * libzypp-devel-17.38.13-150400.3.158.1 * libsolv-tools-0.7.39-150400.3.46.1 * libsolv-tools-base-debuginfo-0.7.39-150400.3.46.1 *libzypp-17.38.13-150400.3.158.1 * libsolv-debuginfo-0.7.39-150400.3.46.1 * libsolv-tools-debuginfo-0.7.39-150400.3.46.1 * libsolv-tools-base-0.7.39-150400.3.46.1 * perl-solv-debuginfo-0.7.39-150400.3.46.1 * ruby-solv-0.7.39-150400.3.46.1 * libzypp-debugsource-17.38.13-150400.3.158.1 * python3-solv-debuginfo-0.7.39-150400.3.46.1 * python3-solv-0.7.39-150400.3.46.1 * zypper-debugsource-1.14.98-150400.3.104.1 * libsolv-devel-0.7.39-150400.3.46.1 * libzypp-debuginfo-17.38.13-150400.3.158.1 * zypper-debuginfo-1.14.98-150400.3.104.1 * zypper-1.14.98-150400.3.104.1 * ruby-solv-debuginfo-0.7.39-150400.3.46.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * zypper-needs-restarting-1.14.98-150400.3.104.1 * zypper-log-1.14.98-150400.3.104.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25707.html * https://www.suse.com/security/cve/CVE-2026-44933.html * https://www.suse.com/security/cve/CVE-2026-44941.html * https://www.suse.com/security/cve/CVE-2026-44942.html * https://www.suse.com/security/cve/CVE-2026-48863.html * https://www.suse.com/security/cve/CVE-2026-9149.html * https://www.suse.com/security/cve/CVE-2026-9150.html * https://bugzilla.suse.com/show_bug.cgi?id=1158038 * https://bugzilla.suse.com/show_bug.cgi?id=1239718 * https://bugzilla.suse.com/show_bug.cgi?id=1246504 * https://bugzilla.suse.com/show_bug.cgi?id=1247948 * https://bugzilla.suse.com/show_bug.cgi?id=1249435 * https://bugzilla.suse.com/show_bug.cgi?id=1252744 * https://bugzilla.suse.com/show_bug.cgi?id=1253193 * https://bugzilla.suse.com/show_bug.cgi?id=1253740 * https://bugzilla.suse.com/show_bug.cgi?id=1257068 * https://bugzilla.suse.com/show_bug.cgi?id=1257882 * https://bugzilla.suse.com/show_bug.cgi?id=1258193 * https://bugzilla.suse.com/show_bug.cgi?id=1259311 * https://bugzilla.suse.com/show_bug.cgi?id=1259706 * https://bugzilla.suse.com/show_bug.cgi?id=1259802 * https://bugzilla.suse.com/show_bug.cgi?id=1259842 *https://bugzilla.suse.com/show_bug.cgi?id=1265223 * https://bugzilla.suse.com/show_bug.cgi?id=1265935 * https://bugzilla.suse.com/show_bug.cgi?id=1265938 * https://bugzilla.suse.com/show_bug.cgi?id=1266039 * https://bugzilla.suse.com/show_bug.cgi?id=1267426 * https://bugzilla.suse.com/show_bug.cgi?id=1267874 * https://jira.suse.com/browse/PED-13680 * https://jira.suse.com/browse/PED-14658 * https://jira.suse.com/browse/PED-15607 . # Security update for libsolv, libzypp, zypper Announcement ID: SUSE-SU-2026:2674-1 Release Date: 20. update, solves, seven, vulnerabilities, three, features, security, fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 29, 2026 Important OpenSUSE
217

Oracle Linux 9 Vim Moderate Arbitrary File Overwrite Vuln ELSA-2026-22717

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-22717 http://linux.oracle.com/errata/ELSA-2026-22717.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: vim-X11-8.2.2637-26.0.1.el9_8.5.x86_64.rpm vim-common-8.2.2637-26.0.1.el9_8.5.x86_64.rpm vim-enhanced-8.2.2637-26.0.1.el9_8.5.x86_64.rpm vim-filesystem-8.2.2637-26.0.1.el9_8.5.noarch.rpm vim-minimal-8.2.2637-26.0.1.el9_8.5.x86_64.rpm aarch64: vim-X11-8.2.2637-26.0.1.el9_8.5.aarch64.rpm vim-common-8.2.2637-26.0.1.el9_8.5.aarch64.rpm vim-enhanced-8.2.2637-26.0.1.el9_8.5.aarch64.rpm vim-filesystem-8.2.2637-26.0.1.el9_8.5.noarch.rpm vim-minimal-8.2.2637-26.0.1.el9_8.5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/vim-8.2.2637-26.0.1.el9_8.5.src.rpm Related CVEs: CVE-2026-35177 Description of changes: [8.2.2637-26.0.1.el9_8.5] - Remove upstream references [Orabug: 31197557] [2:8.2.2637-26.5] - RHEL-170136 CVE-2026-35177 vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass [2:8.2.2637-26.4] - Resolves: RHEL-164966 vim: arbitrary command execution via modeline sandbox bypass [2:8.2.2637-26.3] - Related: RHEL-159630 rebuild to build with exception target [2:8.2.2637-26.2] - remove -O0 from flags [2:8.2.2637-26.1] - RHEL-159630 CVE-2026-33412 vim: Vim: Arbitrary code execution via command injection in glob() function _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 9 updates for vim address medium severity issues including file overwrite vulnerabilities. Install now!. Oracle Linux Vim Security Update, File Overwrite Vulnerability Fix, Oracle Security Advisory. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 26, 2026 moderate Oracle
100

SUSE python-pip Critical Arbitrary File Overwrite Vulnerability Alert

An update that solves three vulnerabilities can now be installed.. # Security update for python-pip Announcement ID: SUSE-SU-2026:2634-1 Release Date: 2026-06-25T13:55:49Z Rating: important References: * bsc#1262429 * bsc#1263442 * bsc#1266669 Cross-References: * CVE-2026-3219 * CVE-2026-6357 * CVE-2026-8643 CVSS scores: * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6357 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6357 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2026-6357 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-8643 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE LinuxEnterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-pip fixes the following issues * CVE-2026-3219: pip doesn't reject concatenated ZIP (bsc#1262429). * CVE-2026-6357: pip self-update functionality can import newly installed modules after wheel installation (bsc#1263442). * CVE-2026-8643: path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (bsc#1266669). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2634=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2634=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2634=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2634=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2634=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2634=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -tpatch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2634=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2634=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-2634=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2634=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2634=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2634=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2634=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python311-pip-22.3.1-150400.17.26.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python311-pip-22.3.1-150400.17.26.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python311-pip-22.3.1-150400.17.26.1 * Public Cloud Module 15-SP4 (noarch) * python311-pip-22.3.1-150400.17.26.1 * openSUSE Leap 15.4 (noarch) * python311-pip-22.3.1-150400.17.26.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python311-pip-22.3.1-150400.17.26.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python311-pip-22.3.1-150400.17.26.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python311-pip-22.3.1-150400.17.26.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python311-pip-22.3.1-150400.17.26.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python311-pip-22.3.1-150400.17.26.1 * Python 3 Module 15-SP7 (noarch) * python311-pip-22.3.1-150400.17.26.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) *python311-pip-22.3.1-150400.17.26.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python311-pip-22.3.1-150400.17.26.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3219.html * https://www.suse.com/security/cve/CVE-2026-6357.html * https://www.suse.com/security/cve/CVE-2026-8643.html * https://bugzilla.suse.com/show_bug.cgi?id=1262429 * https://bugzilla.suse.com/show_bug.cgi?id=1263442 * https://bugzilla.suse.com/show_bug.cgi?id=1266669 . Update for python-pip addresses important vulnerabilities to enhance security. Immediate installation is recommended for SUSE users.. SUSE Security Update, python pip vulnerabilities, important security patch, SUSE advisory, system security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 25, 2026 Important SuSE
202

openSUSE 2026-2575-1 Libsolv Libzypp Zypper Important Buffer Overflows

An update that solves seven vulnerabilities, contains three features and has 14 security fixes can now be installed.. # Security update for libsolv, libzypp, zypper Announcement ID: SUSE-SU-2026:2575-1 Release Date: 2026-06-23T12:48:49Z Rating: important References: * bsc#1158038 * bsc#1239718 * bsc#1246504 * bsc#1247948 * bsc#1249435 * bsc#1252744 * bsc#1253193 * bsc#1253740 * bsc#1257068 * bsc#1257882 * bsc#1258193 * bsc#1259311 * bsc#1259706 * bsc#1259802 * bsc#1259842 * bsc#1265223 * bsc#1265935 * bsc#1265938 * bsc#1266039 * bsc#1267426 * bsc#1267874 * jsc#PED-13680 * jsc#PED-14658 * jsc#PED-15607 Cross-References: * CVE-2026-25707 * CVE-2026-44933 * CVE-2026-44941 * CVE-2026-44942 * CVE-2026-48863 * CVE-2026-9149 * CVE-2026-9150 CVSS scores: * CVE-2026-25707 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44933 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44933 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44933 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44941 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44941 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-44942 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44942 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44942 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48863 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48863 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9149 ( SUSE ): 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9149 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9149 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9150 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9150 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves seven vulnerabilities, contains three features and has 14 security fixes can now be installed. ## Description: This update for libsolv, libzypp, zypper fixes the following issues * CVE-2026-9149: Heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file (bsc#1265935). * CVE-2026-9150: Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums (bsc#1265938). * CVE-2026-25707: Handcrafted repo metadata may cause arbitrary local files to be overwritten (bsc#1259802). * CVE-2026-44933: scan of the Mandatory signature verification plugin support (bsc#1265223). * CVE-2026-44941: path traversal via "keyhint" (bsc#1267426). * CVE-2026-44942: .repo files can have an optional path which can lead to path traversal attacks (bsc#1267874). * CVE-2026-48863: Fix buffer overflow when parsing EdDSA signature (bsc#1266039). Changes in libzypp: Updated to version 17.38.13 (35): * A .repo files "path=" entry must not refer to a location outside the repo (bsc#1267874, CVE-2026-44942) A "path=" entry may solely denote a sub- directory of the baseurl where the metadata arelocated. A relative path trying to access data outside the baseurl is reported and sanitized. * Fix potential crash on malformed or malicious repository metadata (fixes #740) * Repo metadata: discard entries referring to a location outside the repo (bsc#1259802, CVE-2026-25707) Mirroring those data locally would refer to a location outside the repo's local cache directory. Those data entries are reported and discarded. * zypp.conf: Allow [env] section to add environment variables. This feature is designed to enable environment-specific settings or debugging options over an extended period. See zypp.conf(5). * Prevent configured scripts from escaping the sigcheck directory (bsc#1265223, CVE-2026-44933) * StringV: guard hasPrefix/hasPrefixCI against reading past the view end (fixes #735) * Mandatory signature verification plugin support (PED#11922) * Fix purge-kernel -rc kernel handling (bsc#1239718) * Explicitly_set_pool_DISTTYPE_RPM (fixes #726) * Check for trusted key updates when updating the general keyring (bsc#1259706) * Support multiple MirroredOrigin authorities (bsc#1253193) * Workaround doxygen bug: doxygen/doxygen#12057 * libzypp.spec: Add missing graphviz-gd BuildRequires (boo#1259842) * Fix preloader not caching packages from arch specific subrepos (bsc#1253740) * Deprioritize invalid mirrors (fixes openSUSE/zypper#636) * Fix Product::referencePackage lookup (bsc#1259311) Use a provided autoproduct() as hint to the package name of the release package. It might be that not just multiple versions of the same release package provide the same product version, but also different release packages. * specfile: on fedora use %{_prefix}/share as zyppconfdir if %{_distconfdir} is undefined (fixes #693) This will set '-DZYPPCONFDIR=%{zyppconfdir}' for cmake. * Fall back to a writable location when precaching packages without root (bsc#1247948) * Prepare a legacy /etc/zypp/zypp.conf to be installed on old distros.See the ZYPP.CONF(5) man page for details. * Fix runtime check for broken rpm --runposttrans (bsc#1257068) * Avoid libcurl-mini4 when building as it does not support ftp protocol. * Translation: updated .pot file. * zypp.conf: follow the UAPI configuration file specification (PED-14658) In short terms it means we will no longer ship an /etc/zypp/zypp.conf, but store our own defaults in /usr/etc/zypp/zypp.conf. The systems administrator may choose to keep a full copy in /etc/zypp/zypp.conf ignoring our config file settings completely, or - the preferred way - to overwrite specific settings via /etc/zypp/zypp.conf.d/*.conf overlay files. See the ZYPP.CONF(5) man page for details. * cmake: correctly detect rpm6 (fixes #689) * Use 'zypp.tmp' as temp directory component to ease setting up SELinux policies (bsc#1249435) * zyppng: Update Provider to current MediaCurl2 download approach, drop Metalink ( fixes #682 ) Changes in libsolv: Updated to version 0.7.39: * fix solv_chksum_free segfault when called with a NULL pointer * made repo_add_solv more robust against corrupt files [bsc#1265935] [CVE-2026-9149] * fix potential buffer overflow when verifying EdDSA signatures [bsc#1266039] [CVE-2026-48863] * added limit checks in multiple places to catch overflows * reduce the size of the language id cache * fixed Debian canon selection * fixed dbpath detection in repo_rpmdb_librpm * reduced stack usage in repo page compression (needed for musl) * fix parsing of sha512 checksums in debian repositories [bsc#1265938] [CVE-2026-9150] * improve speed of dirpool_add_dir makeing parsing of filelists.xml twice as fast * fix parsing of recommends in the old Mandriva synthesis format * respect the "default" attribute in environment optionlist in the comps parser * support suse namespace deps in boolean dependencies [bsc#1258193] * support for the Elbrus2000 (e2k) architecture * support language() suse namespace rewriting Changes inzypper: Update to version 1.14.98: * Transactional systems: Delegate rw-commands to transactional-wrapper if available (jsc#PED-13680, jsc#PED-15607) On a transactional system where the root filesystem is mounted read-only, zypper commands that modify the system cannot be executed directly. If the system provides a transactional-wrapper utility, zypper will automatically attempt to invoke it. The wrapper transparently executes the zypper command within a new, writable snapshot and manages the lifecycle of that snapshot based on the command's exit status. On transactional systems lacking a transactional-wrapper, users must manually invoke specialized tools -such as transactional-update- to install, update, or remove software. * Add --filter-version-change to zypper lu. Adds filtering by version change significance to reduce noise in update listings. Supports levels: rebuild (hides rebuild-only changes) and package (hides all release-only changes). * Autorefresh ris-services the way as plugin-services (bsc#1246504) It's actually wrong to treat service refreshes different depending on the service type. For the purpose of a service it makes no difference how the data about the repos to use are acquired. * Report download progress for command line rpms (fixes #613) * Hint to '-vv ref' to see the mirrors used to download the metadata (bsc#1257882) * Service: Allow "zypper ls SERVICE ..." to test whether a service with this alias is defined (bsc#1252744) The command prints an abstract of all services passed on the command line. It returns 3-ZYPPER_EXIT_ERR_INVALID_ARGS if some argument does not name an existing service. * Keep repo data when updating the service settings (bsc#1252744) * info: Enhance pattern content table (bsc#1158038) Alternatives (multiple packages providing the same requirement) are now listed as a single entry in the content table. The entry shows either the installed package which satisfiesthe requirement or the requirement itself as type 'Provides'. Listing all potential alternatives was miss leading, especially if the alternatives were mutual exclusive. It looked like an installed pattern had not-installed requirements and it was not possible to install all requirements at the same time. Original description from SUSE:Maintenance:44536: This update for libsolv, libzypp fixes the following issues Security issues: * CVE-2026-9149: Heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file (bsc#1265935). * CVE-2026-9150: Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums (bsc#1265938). * CVE-2026-25707: Handcrafted repo metadata may cause arbitrary local files to be overwritten (bsc#1259802). * CVE-2026-44933: scan of the Mandatory signature verification plugin support (bsc#1265223). * CVE-2026-44942: .repo files can have an optional path which can lead to path traversal attacks (bsc#1267874). * CVE-2026-48863: Fix bufffer overflow when parsing EdDSA signature (bsc#1266039). Changes in libzypp: Updated to version 17.38.13 (35): * Fix potential crash on malformed or malicious repository metadata (fixes #740) * Repo metadata: discard entries referring to a location outside the repo (bsc#1259802, CVE-2026-25707) Mirroring those data locally would refer to a location outside the repo's local cache directory. Those data entries are reported and discarded. * zypp.conf: Allow [env] section to add environment variables. This feature is designed to enable environment-specific settings or debugging options over an extended period. See zypp.conf(5). * Prevent configured scripts from escaping the sigcheck directory (bsc#1265223, CVE-2026-44933) * StringV: guard hasPrefix/hasPrefixCI against reading past the view end (fixes #735) * Mandatory signature verification plugin support (PED#11922) * Fix purge-kernel -rc kernelhandling (bsc#1239718) * Explicitly_set_pool_DISTTYPE_RPM (fixes #726) * Check for trusted key updates when updating the general keyring (bsc#1259706) * Support multiple MirroredOrigin authorities (bsc#1253193) * Workaround doxygen bug: doxygen/doxygen#12057 * libzypp.spec: Add missing graphviz-gd BuildRequires (boo#1259842) * Fix preloader not caching packages from arch specific subrepos (bsc#1253740) * Deprioritize invalid mirrors (fixes openSUSE/zypper#636) * Fix Product::referencePackage lookup (bsc#1259311) Use a provided autoproduct() as hint to the package name of the release package. It might be that not just multiple versions of the same release package provide the same product version, but also different release packages. * specfile: on fedora use %{_prefix}/share as zyppconfdir if %{_distconfdir} is undefined (fixes #693) This will set '-DZYPPCONFDIR=%{zyppconfdir}' for cmake. * Fall back to a writable location when precaching packages without root (bsc#1247948) * Prepare a legacy /etc/zypp/zypp.conf to be installed on old distros. See the ZYPP.CONF(5) man page for details. * Fix runtime check for broken rpm --runposttrans (bsc#1257068) * Avoid libcurl-mini4 when building as it does not support ftp protocol. * Translation: updated .pot file. * zypp.conf: follow the UAPI configuration file specification (PED-14658) In short terms it means we will no longer ship an /etc/zypp/zypp.conf, but store our own defaults in /usr/etc/zypp/zypp.conf. The systems administrator may choose to keep a full copy in /etc/zypp/zypp.conf ignoring our config file settings completely, or - the preferred way - to overwrite specific settings via /etc/zypp/zypp.conf.d/*.conf overlay files. See the ZYPP.CONF(5) man page for details. * cmake: correctly detect rpm6 (fixes #689) * Use 'zypp.tmp' as temp directory component to ease setting up SELinux policies (bsc#1249435) * zyppng: Update Provider to current MediaCurl2 download approach,drop Metalink ( fixes #682 ) Changes in libsolv: Updated to version 0.7.39: * fix solv_chksum_free segfault when called with a NULL pointer * made repo_add_solv more robust against corrupt files [bsc#1265935] [CVE-2026-9149] * fix potential buffer overflow when verifying EdDSA signatures [bsc#1266039] [CVE-2026-48863] * added limit checks in multiple places to catch overflows * reduce the size of the language id cache * fixed Debian canon selection * fixed dbpath detection in repo_rpmdb_librpm * reduced stack usage in repo page compression (needed for musl) * fix parsing of sha512 checksums in debian repositories [bsc#1265938] [CVE-2026-9150] * improve speed of dirpool_add_dir makeing parsing of filelists.xml twice as fast * fix parsing of recommends in the old Mandriva synthesis format * respect the "default" attribute in environment optionlist in the comps parser * support suse namespace deps in boolean dependencies [bsc#1258193] * support for the Elbrus2000 (e2k) architecture * support language() suse namespace rewriting Update to version 1.14.98: * Transactional systems: Delegate rw-commands to transactional-wrapper if available (jsc#PED-13680, jsc#PED-15607) On a transactional system where the root filesystem is mounted read-only, zypper commands that modify the system cannot be executed directly. If the system provides a transactional-wrapper utility, zypper will automatically attempt to invoke it. The wrapper transparently executes the zypper command within a new, writable snapshot and manages the lifecycle of that snapshot based on the command's exit status. On transactional systems lacking a transactional-wrapper, users must manually invoke specialized tools -such as transactional-update- to install, update, or remove software. * Add --filter-version-change to zypper lu. Adds filtering by version change significance to reduce noise in update listings. Supports levels: rebuild (hides rebuild-onlychanges) and package (hides all release-only changes). * Autorefresh ris-services the way as plugin-services (bsc#1246504) It's actually wrong to treat service refreshes different depending on the service type. For the purpose of a service it makes no difference how the data about the repos to use are acquired. * Report download progress for command line rpms (fixes #613) * Hint to '-vv ref' to see the mirrors used to download the metadata (bsc#1257882) * Service: Allow "zypper ls SERVICE ..." to test whether a service with this alias is defined (bsc#1252744) The command prints an abstract of all services passed on the command line. It returns 3-ZYPPER_EXIT_ERR_INVALID_ARGS if some argument does not name an existing service. * Keep repo data when updating the service settings (bsc#1252744) * info: Enhance pattern content table (bsc#1158038) Alternatives (multiple packages providing the same requirement) are now listed as a single entry in the content table. The entry shows either the installed package which satisfies the requirement or the requirement itself as type 'Provides'. Listing all potential alternatives was miss leading, especially if the alternatives were mutual exclusive. It looked like an installed pattern had not-installed requirements and it was not possible to install all requirements at the same time. ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2575=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2575=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2575=1SUSE-SLE- INSTALLER-15-SP5-2026-2575=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2575=1 * SUSE Linux Enterprise Server 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-2575=1 * SUSE Linux Enterprise High Performance Computing 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-2575=1 * SUSE Linux Enterprise Desktop 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-2575=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2575=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2575=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 15 SP5 (aarch64 x86_64) * libsolv-tools-base-0.7.39-150500.6.17.1 * libzypp-17.38.13-150500.6.74.1 * libsolv-tools-0.7.39-150500.6.17.1 * SUSE Linux Enterprise Desktop 15 SP5 (x86_64) * libsolv-tools-base-0.7.39-150500.6.17.1 * libzypp-17.38.13-150500.6.74.1 * libsolv-tools-0.7.39-150500.6.17.1 * SUSE Linux Enterprise Server 15 SP5 (aarch64 ppc64le s390x x86_64) * libsolv-tools-base-0.7.39-150500.6.17.1 * libzypp-17.38.13-150500.6.74.1 * libsolv-tools-0.7.39-150500.6.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libzypp-devel-17.38.13-150500.6.74.1 * libzypp-17.38.13-150500.6.74.1 * python3-solv-0.7.39-150500.6.17.1 * libzypp-debugsource-17.38.13-150500.6.74.1 * libsolv-tools-debuginfo-0.7.39-150500.6.17.1 * ruby-solv-0.7.39-150500.6.17.1 * ruby-solv-debuginfo-0.7.39-150500.6.17.1 * perl-solv-debuginfo-0.7.39-150500.6.17.1 * libsolv-debugsource-0.7.39-150500.6.17.1 * libsolv-tools-0.7.39-150500.6.17.1 * perl-solv-0.7.39-150500.6.17.1 * zypper-debuginfo-1.14.98-150500.6.45.1 * libsolv-tools-base-debuginfo-0.7.39-150500.6.17.1 * libsolv-devel-debuginfo-0.7.39-150500.6.17.1 * libsolv-debuginfo-0.7.39-150500.6.17.1 *zypper-debugsource-1.14.98-150500.6.45.1 * libsolv-devel-0.7.39-150500.6.17.1 * zypper-1.14.98-150500.6.45.1 * libsolv-tools-base-0.7.39-150500.6.17.1 * libzypp-debuginfo-17.38.13-150500.6.74.1 * python3-solv-debuginfo-0.7.39-150500.6.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * zypper-needs-restarting-1.14.98-150500.6.45.1 * zypper-log-1.14.98-150500.6.45.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libzypp-devel-17.38.13-150500.6.74.1 * libzypp-17.38.13-150500.6.74.1 * python3-solv-0.7.39-150500.6.17.1 * libzypp-debugsource-17.38.13-150500.6.74.1 * libsolv-tools-debuginfo-0.7.39-150500.6.17.1 * ruby-solv-0.7.39-150500.6.17.1 * ruby-solv-debuginfo-0.7.39-150500.6.17.1 * perl-solv-debuginfo-0.7.39-150500.6.17.1 * libsolv-debugsource-0.7.39-150500.6.17.1 * libsolv-tools-0.7.39-150500.6.17.1 * perl-solv-0.7.39-150500.6.17.1 * zypper-debuginfo-1.14.98-150500.6.45.1 * libsolv-tools-base-debuginfo-0.7.39-150500.6.17.1 * libsolv-devel-debuginfo-0.7.39-150500.6.17.1 * libsolv-debuginfo-0.7.39-150500.6.17.1 * zypper-debugsource-1.14.98-150500.6.45.1 * libsolv-devel-0.7.39-150500.6.17.1 * zypper-1.14.98-150500.6.45.1 * libsolv-tools-base-0.7.39-150500.6.17.1 * libzypp-debuginfo-17.38.13-150500.6.74.1 * python3-solv-debuginfo-0.7.39-150500.6.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * zypper-needs-restarting-1.14.98-150500.6.45.1 * zypper-log-1.14.98-150500.6.45.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libzypp-devel-17.38.13-150500.6.74.1 * libzypp-17.38.13-150500.6.74.1 * python3-solv-0.7.39-150500.6.17.1 * libzypp-debugsource-17.38.13-150500.6.74.1 * libsolv-tools-debuginfo-0.7.39-150500.6.17.1 * ruby-solv-0.7.39-150500.6.17.1 * ruby-solv-debuginfo-0.7.39-150500.6.17.1 *perl-solv-debuginfo-0.7.39-150500.6.17.1 * libsolv-debugsource-0.7.39-150500.6.17.1 * libsolv-tools-0.7.39-150500.6.17.1 * perl-solv-0.7.39-150500.6.17.1 * zypper-debuginfo-1.14.98-150500.6.45.1 * libsolv-tools-base-debuginfo-0.7.39-150500.6.17.1 * libsolv-devel-debuginfo-0.7.39-150500.6.17.1 * libsolv-debuginfo-0.7.39-150500.6.17.1 * zypper-debugsource-1.14.98-150500.6.45.1 * libsolv-devel-0.7.39-150500.6.17.1 * zypper-1.14.98-150500.6.45.1 * libsolv-tools-base-0.7.39-150500.6.17.1 * libzypp-debuginfo-17.38.13-150500.6.74.1 * python3-solv-debuginfo-0.7.39-150500.6.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * zypper-needs-restarting-1.14.98-150500.6.45.1 * zypper-log-1.14.98-150500.6.45.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * libzypp-devel-17.38.13-150500.6.74.1 * libsolv-demo-debuginfo-0.7.39-150500.6.17.1 * libzypp-17.38.13-150500.6.74.1 * python3-solv-0.7.39-150500.6.17.1 * libsolv-demo-0.7.39-150500.6.17.1 * libzypp-debugsource-17.38.13-150500.6.74.1 * python311-solv-0.7.39-150500.6.17.1 * python311-solv-debuginfo-0.7.39-150500.6.17.1 * libsolv-tools-debuginfo-0.7.39-150500.6.17.1 * ruby-solv-0.7.39-150500.6.17.1 * ruby-solv-debuginfo-0.7.39-150500.6.17.1 * perl-solv-debuginfo-0.7.39-150500.6.17.1 * libsolv-debugsource-0.7.39-150500.6.17.1 * libsolv-tools-0.7.39-150500.6.17.1 * perl-solv-0.7.39-150500.6.17.1 * zypper-debuginfo-1.14.98-150500.6.45.1 * libsolv-tools-base-debuginfo-0.7.39-150500.6.17.1 * libsolv-devel-debuginfo-0.7.39-150500.6.17.1 * libsolv-debuginfo-0.7.39-150500.6.17.1 * zypper-debugsource-1.14.98-150500.6.45.1 * libsolv-devel-0.7.39-150500.6.17.1 * zypper-1.14.98-150500.6.45.1 * libsolv-tools-base-0.7.39-150500.6.17.1 * libzypp-debuginfo-17.38.13-150500.6.74.1 * libzypp-devel-doc-17.38.13-150500.6.74.1 * python3-solv-debuginfo-0.7.39-150500.6.17.1 * openSUSE Leap 15.5(noarch) * zypper-needs-restarting-1.14.98-150500.6.45.1 * zypper-aptitude-1.14.98-150500.6.45.1 * zypper-log-1.14.98-150500.6.45.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libsolv-debugsource-0.7.39-150500.6.17.1 * libsolv-debuginfo-0.7.39-150500.6.17.1 * libsolv-tools-0.7.39-150500.6.17.1 * zypper-debugsource-1.14.98-150500.6.45.1 * zypper-1.14.98-150500.6.45.1 * zypper-debuginfo-1.14.98-150500.6.45.1 * libzypp-debugsource-17.38.13-150500.6.74.1 * libsolv-tools-base-0.7.39-150500.6.17.1 * libzypp-17.38.13-150500.6.74.1 * libsolv-tools-debuginfo-0.7.39-150500.6.17.1 * libzypp-debuginfo-17.38.13-150500.6.74.1 * libsolv-tools-base-debuginfo-0.7.39-150500.6.17.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * zypper-needs-restarting-1.14.98-150500.6.45.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libzypp-devel-17.38.13-150500.6.74.1 * libzypp-17.38.13-150500.6.74.1 * python3-solv-0.7.39-150500.6.17.1 * libzypp-debugsource-17.38.13-150500.6.74.1 * libsolv-tools-debuginfo-0.7.39-150500.6.17.1 * ruby-solv-0.7.39-150500.6.17.1 * ruby-solv-debuginfo-0.7.39-150500.6.17.1 * perl-solv-debuginfo-0.7.39-150500.6.17.1 * libsolv-debugsource-0.7.39-150500.6.17.1 * libsolv-tools-0.7.39-150500.6.17.1 * perl-solv-0.7.39-150500.6.17.1 * zypper-debuginfo-1.14.98-150500.6.45.1 * libsolv-tools-base-debuginfo-0.7.39-150500.6.17.1 * libsolv-devel-debuginfo-0.7.39-150500.6.17.1 * libsolv-debuginfo-0.7.39-150500.6.17.1 * zypper-debugsource-1.14.98-150500.6.45.1 * libsolv-devel-0.7.39-150500.6.17.1 * zypper-1.14.98-150500.6.45.1 * libsolv-tools-base-0.7.39-150500.6.17.1 * libzypp-debuginfo-17.38.13-150500.6.74.1 * python3-solv-debuginfo-0.7.39-150500.6.17.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * zypper-needs-restarting-1.14.98-150500.6.45.1 * zypper-log-1.14.98-150500.6.45.1 ## References: *https://www.suse.com/security/cve/CVE-2026-25707.html * https://www.suse.com/security/cve/CVE-2026-44933.html * https://www.suse.com/security/cve/CVE-2026-44941.html * https://www.suse.com/security/cve/CVE-2026-44942.html * https://www.suse.com/security/cve/CVE-2026-48863.html * https://www.suse.com/security/cve/CVE-2026-9149.html * https://www.suse.com/security/cve/CVE-2026-9150.html * https://bugzilla.suse.com/show_bug.cgi?id=1158038 * https://bugzilla.suse.com/show_bug.cgi?id=1239718 * https://bugzilla.suse.com/show_bug.cgi?id=1246504 * https://bugzilla.suse.com/show_bug.cgi?id=1247948 * https://bugzilla.suse.com/show_bug.cgi?id=1249435 * https://bugzilla.suse.com/show_bug.cgi?id=1252744 * https://bugzilla.suse.com/show_bug.cgi?id=1253193 * https://bugzilla.suse.com/show_bug.cgi?id=1253740 * https://bugzilla.suse.com/show_bug.cgi?id=1257068 * https://bugzilla.suse.com/show_bug.cgi?id=1257882 * https://bugzilla.suse.com/show_bug.cgi?id=1258193 * https://bugzilla.suse.com/show_bug.cgi?id=1259311 * https://bugzilla.suse.com/show_bug.cgi?id=1259706 * https://bugzilla.suse.com/show_bug.cgi?id=1259802 * https://bugzilla.suse.com/show_bug.cgi?id=1259842 * https://bugzilla.suse.com/show_bug.cgi?id=1265223 * https://bugzilla.suse.com/show_bug.cgi?id=1265935 * https://bugzilla.suse.com/show_bug.cgi?id=1265938 * https://bugzilla.suse.com/show_bug.cgi?id=1266039 * https://bugzilla.suse.com/show_bug.cgi?id=1267426 * https://bugzilla.suse.com/show_bug.cgi?id=1267874 * https://jira.suse.com/browse/PED-13680 * https://jira.suse.com/browse/PED-14658 * https://jira.suse.com/browse/PED-15607 . # Security update for libsolv, libzypp, zypper Announcement ID: SUSE-SU-2026:2575-1 Release Date: 20. update, solves, seven, vulnerabilities, three, features, security, fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 23, 2026 Important OpenSUSE
87

Debian libhttp-daemon-perl Important Exec Command Flaw DSA-6358-1

A flaw was discovered in libhttp-daemon-perl, a simple http server class for Perl, which may result in the execution of arbitrary shell commands or file overwrite when processing specially crafted input. For the stable distribution (trixie), this problem has been fixed in version 6.16-1+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6358-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso June 21, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libhttp-daemon-perl CVE ID : CVE-2026-8450 Debian Bug : 1138050 A flaw was discovered in libhttp-daemon-perl, a simple http server class for Perl, which may result in the execution of arbitrary shell commands or file overwrite when processing specially crafted input. For the stable distribution (trixie), this problem has been fixed in version 6.16-1+deb13u1. We recommend that you upgrade your libhttp-daemon-perl packages. For the detailed security status of libhttp-daemon-perl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libhttp-daemon-perl Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Flaw in libhttp-daemon-perl on Debian may let attackers execute commands or overwrite files; upgrade recommended.. Debian advisory, libhttp-daemon-perl, security issue, command execution, file overwrite. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 21, 2026 Important Debian
217

Oracle Linux 8 vim Moderate Path Traversal Risk ELSA-2026-22730

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-22730 http://linux.oracle.com/errata/ELSA-2026-22730.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: vim-X11-8.0.1763-23.0.1.el8_10.x86_64.rpm vim-common-8.0.1763-23.0.1.el8_10.x86_64.rpm vim-enhanced-8.0.1763-23.0.1.el8_10.x86_64.rpm vim-filesystem-8.0.1763-23.0.1.el8_10.noarch.rpm vim-minimal-8.0.1763-23.0.1.el8_10.x86_64.rpm aarch64: vim-X11-8.0.1763-23.0.1.el8_10.aarch64.rpm vim-common-8.0.1763-23.0.1.el8_10.aarch64.rpm vim-enhanced-8.0.1763-23.0.1.el8_10.aarch64.rpm vim-filesystem-8.0.1763-23.0.1.el8_10.noarch.rpm vim-minimal-8.0.1763-23.0.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/vim-8.0.1763-23.0.1.el8_10.src.rpm Related CVEs: CVE-2026-35177 Description of changes: [8.0.1763-23.0.1] - Remove upstream references [Orabug: 31197557] - Added glibc-gconv-extra to common requires to provide ISO-8859-2 [Orabug: 34114984] [2:8.0.1763-23] - RHEL-170126 CVE-2026-35177 vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass [2:8.0.1763-22.3] - Relates: RHEL-164956 vim: arbitrary command execution via modeline sandbox bypass [2:8.0.1763-22.2] - Resolves: RHEL-164956 vim: arbitrary command execution via modeline sandbox bypass [2:8.0.1763-22.1] - RHEL-159620 CVE-2026-33412 vim: Vim: Arbitrary code execution via command injection in glob() function - RHEL-155428 CVE-2026-28417 vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin - RHEL-155412 CVE-2026-28421 vim: Vim: Denial of service and information disclosure via crafted swap file _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Explore Oracle Linux 8 updates addressing moderate risks in vim alongside crucial fixes for path traversal issues.. Oracle Linux vim updates. .Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 08, 2026 moderate Oracle
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200