Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
streamlink 8.4.0 (2026-05-06) SECURITY: fixed arbitrary local file read via file:// URI in HLS and DASH (CVE-2026-44353 / GHSA-hgqw-6m45-hw5f) Added: --stream-passthrough-encrypted for passing through encrypted HLS/DASH segments to the output stream without any checks (#6896). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b9232006bb 2026-07-05 01:07:02.694144+00:00 -------------------------------------------------------------------------------- Name : python-streamlink Product : Fedora 44 Version : 8.4.0 Release : 1.fc44 URL : https://streamlink.github.io Summary : Python library for extracting streams from various websites Description : Streamlink is a command-line utility that pipes video streams from various services into a video player, such as VLC. The main purpose of Streamlink is to allow the user to avoid buggy and CPU heavy flash plugins but still be able to enjoy various streamed content. There is also an API available for developers who want access to the video stream data. This project was forked from Livestreamer, which is no longer maintained. -------------------------------------------------------------------------------- Update Information: streamlink 8.4.0 (2026-05-06) SECURITY: fixed arbitrary local file read via file:// URI in HLS and DASH (CVE-2026-44353 / GHSA-hgqw-6m45-hw5f) Added: --stream-passthrough-encrypted for passing through encrypted HLS/DASH segments to the output stream without any checks (#6896) Fixed: --interface selection by name on macOS (#6908) Fixed: --interface not being applied to adapters mounted after session init (#6915) Updated plugins: goltelevision: rewritten and fixed plugin (#6916) twitcasting: improved ad segment filtering (#6910) Full changelog streamlink 8.3.0 (2026-04-10) Added: support for choosing the --interface by name on non-Windows systems, with optional prefixes, similar to curl (#6862) Added: support foralso checking stream segments in HLSStream.parse_variant_playlist() by setting check_streams="segments" (#6878) Fixed: stdout/stderr streams in ProcessOutput not being fully line-buffered (#6868) Updated plugins: cdnbg: rewritten and fixed plugin (#6890) nicolive: added websocket reconnect attempts on HLS decryption key retrieval failure (#6871) soop: migrated to sooplive.com (#6876) telefe: rewritten and fixed plugin (#6891) Full changelog -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 25 2026 Mohamed El Morabity - 8.4.0-1 - Update to 8.4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2457332 - python-streamlink-8.4.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2457332 [ 2 ] Bug #2458672 - python-streamlink fails to build with Python 3.15: test_help_color: TypeError: TestPrint._color. . () got an unexpected keyword argument 'file' https://bugzilla.redhat.com/show_bug.cgi?id=2458672 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b9232006bb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability can now be installed.. # Security update for golang-github-docker-libnetwork Announcement ID: SUSE-SU-2026:2740-1 Release Date: 2026-07-03T09:07:54Z Rating: moderate References: * bsc#1259566 Cross-References: * CVE-2026-2808 CVSS scores: * CVE-2026-2808 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-2808 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2026-2808 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for golang-github-docker-libnetwork fixes the following issue * CVE-2026-2808: github.com/hashicorp/consul: unvalidated user-supplied file paths can lead to arbitrary file reads through the Vault Kubernetes authentication provider (bsc#1259566). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2740=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2740=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2740=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2740=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * docker-libnetwork-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * docker-libnetwork-debuginfo-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) *docker-libnetwork-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * docker-libnetwork-debuginfo-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * docker-libnetwork-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * docker-libnetwork-debuginfo-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * docker-libnetwork-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * docker-libnetwork-debuginfo-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2808.html * https://bugzilla.suse.com/show_bug.cgi?id=1259566 . Critical update for SUSE addressing arbitrary file read in golang-github-docker-libnetwork. Install to ensure system security.. SUSE Docker Libnetwork Update, Moderate Security Update, CVE-2026-2808 Fix, SUSE Vulnerability Patch. . Severity: moderate. LinuxSecurity.com Team
This update includes a fix for CVE-2026-39977. See also: the upstream advisory. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5e62b78a0c 2026-04-25 01:21:36.173141+00:00 -------------------------------------------------------------------------------- Name : flatpak-builder Product : Fedora 44 Version : 1.4.8 Release : 1.fc44 URL : https://flatpak.org/ Summary : Tool to build flatpaks from source Description : Flatpak-builder is a tool for building flatpaks from sources. See https://flatpak.org/ for more information. -------------------------------------------------------------------------------- Update Information: This update includes a fix for CVE-2026-39977. See also: the upstream advisory -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 15 2026 Adrian Vovk - 1.4.8-1 - Update to 1.4.8 (#2457166) * Wed Mar 25 2026 Jan Grulich - 1.4.7-5 - Add configuration for release-monitoring -------------------------------------------------------------------------------- References: [ 1 ] Bug #2457166 - flatpak-builder-1.4.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=2457166 [ 2 ] Bug #2457894 - CVE-2026-39977 flatpak-builder: path traversal leading to arbitrary file read on host when installing licence files [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2457894 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5e62b78a0c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update includes a fix for CVE-2026-39977. See also: the upstream advisory. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-631b9d535c 2026-04-24 01:06:05.765099+00:00 -------------------------------------------------------------------------------- Name : flatpak-builder Product : Fedora 42 Version : 1.4.8 Release : 1.fc42 URL : https://flatpak.org/ Summary : Tool to build flatpaks from source Description : Flatpak-builder is a tool for building flatpaks from sources. See https://flatpak.org/ for more information. -------------------------------------------------------------------------------- Update Information: This update includes a fix for CVE-2026-39977. See also: the upstream advisory -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 14 2026 Adrian Vovk - 1.4.8-1 - Update to 1.4.8 (#2457166) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2457166 - flatpak-builder-1.4.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=2457166 [ 2 ] Bug #2457894 - CVE-2026-39977 flatpak-builder: path traversal leading to arbitrary file read on host when installing licence files [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2457894 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-631b9d535c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
* bsc#1240688 Cross-References: * CVE-2025-3155 . # Security update for yelp Announcement ID: SUSE-SU-2025:2169-1 Release Date: 2025-11-26T14:47:36Z Rating: important References: * bsc#1240688 Cross-References: * CVE-2025-3155 CVSS scores: * CVE-2025-3155 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2025-3155 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2025-3155 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for yelp fixes the following issues: * CVE-2025-3155: JavaScript code execution and arbitrary file read through specially crafted help files and ghelp scheme URLs (bsc#1240688). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-2169=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libyelp0-debuginfo-3.20.1-7.3.1 * libyelp0-3.20.1-7.3.1 * yelp-debugsource-3.20.1-7.3.1 * yelp-devel-3.20.1-7.3.1 * yelp-debuginfo-3.20.1-7.3.1 * yelp-3.20.1-7.3.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * yelp-lang-3.20.1-7.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-3155.html * https://bugzilla.suse.com/show_bug.cgi?id=1240688 . Critical update for yelp addresses JavaScript code execution risk and arbitrary file reads. Stay secure with timely patching!. SUSE Linux, Yelp Security, JavaScript Vulnerability, CodeExecution Risk. . Severity: Important. LinuxSecurity.com Team
Update to 1.10.7. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-c555ce4089 2025-11-15 01:40:44.715722+00:00 -------------------------------------------------------------------------------- Name : opentofu Product : Fedora 41 Version : 1.10.7 Release : 1.fc41 URL : https://github.com/opentofu/opentofu Summary : OpenTofu lets you declaratively manage your cloud infrastructure Description : OpenTofu lets you declaratively manage your cloud infrastructure. -------------------------------------------------------------------------------- Update Information: Update to 1.10.7 -------------------------------------------------------------------------------- ChangeLog: * Thu Nov 6 2025 Mikel Olasagasti Uranga - 1.10.7-1 - Update to 1.10.7 - Closes rhbz#2413156 * Fri Oct 10 2025 Alejandro Sez - 1.10.6-2 - rebuild * Thu Sep 4 2025 Mikel Olasagasti Uranga - 1.10.6-1 - Update to 1.10.6 - Closes rhbz#2385775 * Fri Aug 15 2025 Maxwell G - 1.10.3-2 - Rebuild for golang-1.25.0 * Sat Jul 26 2025 Mikel Olasagasti Uranga - 1.10.3-1 - Update to 1.10.3 - Closes rhbz#2380221 * Thu Jul 24 2025 Fedora Release Engineering - 1.10.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Thu Jun 26 2025 Mikel Olasagasti Uranga - 1.10.1-1 - Update to 1.10.1 - Closes rhbz#2374763 * Tue Jun 24 2025 Mikel Olasagasti Uranga - 1.10.0-1 - Update to 1.10.0 - Closes rhbz#2374600 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2375615 - opentofu: mapstructure May Leak Sensitive Information [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2375615 [ 2 ] Bug #2384150 - opentofu: go-viper information leak [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2384150 [ 3 ] Bug #2386297 - CVE-2025-8556 opentofu: CIRCL-Fourq: Missing and wrong validation can lead to incorrect results [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2386297 [ 4 ] Bug #2388884 - CVE-2025-8959 opentofu: HashiCorp go-getter Arbitrary File Read [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2388884 [ 5 ] Bug #2390857 - opentofu: go-viper's mapstructure May Leak Sensitive Information in Logs [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2390857 [ 6 ] Bug #2391634 - CVE-2025-58058 opentofu: github.com/ulikunitz/xz leaks memory [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2391634 [ 7 ] Bug #2398604 - CVE-2025-47910 opentofu: CrossOriginProtection bypass in net/http [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2398604 [ 8 ] Bug #2399268 - CVE-2025-47906 opentofu: Unexpected paths returned from LookPath in os/exec [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2399268 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-c555ce4089' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 41 update for OpenTofu version 1.10.7 addresses information leaks and validation issues.. OpenTofu 1.10.7, Fedora 41, information leak, arbitrary file read, software update. . Severity: Important. LinuxSecurity.com Team
Update to 1.10.7. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-6ab111452f 2025-11-15 01:30:31.747758+00:00 -------------------------------------------------------------------------------- Name : opentofu Product : Fedora 42 Version : 1.10.7 Release : 1.fc42 URL : https://github.com/opentofu/opentofu Summary : OpenTofu lets you declaratively manage your cloud infrastructure Description : OpenTofu lets you declaratively manage your cloud infrastructure. -------------------------------------------------------------------------------- Update Information: Update to 1.10.7 -------------------------------------------------------------------------------- ChangeLog: * Thu Nov 6 2025 Mikel Olasagasti Uranga - 1.10.7-1 - Update to 1.10.7 - Closes rhbz#2413156 * Fri Oct 10 2025 Alejandro Sez - 1.10.6-2 - rebuild * Thu Sep 4 2025 Mikel Olasagasti Uranga - 1.10.6-1 - Update to 1.10.6 - Closes rhbz#2385775 * Fri Aug 15 2025 Maxwell G - 1.10.3-2 - Rebuild for golang-1.25.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2375630 - opentofu: mapstructure May Leak Sensitive Information [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2375630 [ 2 ] Bug #2386309 - CVE-2025-8556 opentofu: CIRCL-Fourq: Missing and wrong validation can lead to incorrect results [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2386309 [ 3 ] Bug #2388887 - CVE-2025-8959 opentofu: HashiCorp go-getter Arbitrary File Read [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2388887 [ 4 ] Bug #2390878 - opentofu: go-viper's mapstructure May Leak Sensitive Information in Logs [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2390878 [ 5 ] Bug #2391666 - CVE-2025-58058 opentofu: github.com/ulikunitz/xz leaks memory [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2391666 [ 6 ] Bug #2398870 -CVE-2025-47910 opentofu: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398870 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-6ab111452f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . The opentofu 1.10.7 update resolves several critical issues identified in Fedora 42, enhancing stability and security for users. opentofu update,Fedora security advisory,cloud management,opentofu vulnerabilities. . Severity: Important. LinuxSecurity.com Team
* bsc#1240688 Cross-References: * CVE-2025-3155 . # Security update for yelp Announcement ID: SUSE-SU-2025:02169-1 Release Date: 2025-06-30T07:15:20Z Rating: moderate References: * bsc#1240688 Cross-References: * CVE-2025-3155 CVSS scores: * CVE-2025-3155 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-3155 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-3155 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for yelp fixes the following issues: * CVE-2025-3155: JavaScript code execution and arbitrary file read through specially crafted help files and ghelp scheme URLs (bsc#1240688). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-2169=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libyelp0-3.20.1-7.3.1 * libyelp0-debuginfo-3.20.1-7.3.1 * yelp-debugsource-3.20.1-7.3.1 * yelp-devel-3.20.1-7.3.1 * yelp-debuginfo-3.20.1-7.3.1 * yelp-3.20.1-7.3.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * yelp-lang-3.20.1-7.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-3155.html * https://bugzilla.suse.com/show_bug.cgi?id=1240688 . An update for Yelp on SUSE has been released to address CVE-2025-3155, which is a vulnerability categorized as moderate risk, potentially allowing for remote code execution.. SUSE yelpsecurity update JavaScript execution threat. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.