Explore top 10 tips to secure your open-source projects now. Read More
×update to version 2.24.0 Fix CVE-2026-54590: Unauthorized file modification via authorized-keys directory escape Fix CVE-2026-54591: Arbitrary file write via path traversal in SCP client. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-1f248487e4 2026-07-20 00:53:11.635396+00:00 -------------------------------------------------------------------------------- Name : python-asyncssh Product : Fedora 44 Version : 2.24.0 Release : 1.fc44 URL : https://github.com/ronf/asyncssh Summary : Asynchronous SSH for Python Description : Python 3 library for asynchronous client and server-side SSH communication. It uses the Python asyncio module and implements many SSH protocol features such as the various channels, SFTP, SCP, forwarding, session multiplexing over a connection and more. -------------------------------------------------------------------------------- Update Information: update to version 2.24.0 Fix CVE-2026-54590: Unauthorized file modification via authorized-keys directory escape Fix CVE-2026-54591: Arbitrary file write via path traversal in SCP client -------------------------------------------------------------------------------- ChangeLog: * Sun Jun 28 2026 Georg Sauthoff - 2.24.0-1 - update to version 2.24.0 (fixes fedora#2468438) * Fri Jun 12 2026 Yaakov Selkowitz - 2.22.0-6 - Rebuilt for openssl 4.0 * Thu Jun 4 2026 Python Maint - 2.22.0-5 - Rebuilt for Python 3.15 * Wed May 6 2026 Miro Hrončok - 2.22.0-4 - Properly filter out test dependency on uvloop and python-pkcs11 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2468438 - python-asyncssh-2.24.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2468438 [ 2 ] Bug #2498421 - CVE-2026-54590 python-asyncssh: AsyncSSH: Unauthorized file modification via authorized-keys directory escape [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2498421 [ 3] Bug #2498423 - CVE-2026-54590 python-asyncssh: AsyncSSH: Unauthorized file modification via authorized-keys directory escape [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2498423 [ 4 ] Bug #2498488 - CVE-2026-54591 python-asyncssh: AsyncSSH: Arbitrary file write via path traversal in SCP client [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2498488 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1f248487e4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update to python-asyncssh 2.24.0 fixes unauthorized file modification and path traversal vulnerabilities in Fedora.. python-asyncssh security fix, Fedora python updates, CVE updates for python. . Severity: Important. LinuxSecurity.com Team
Security update. Publication date: 18 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0265.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-29518, CVE-2026-43617, CVE-2026-43618, CVE-2026-43619, CVE-2026-43620, CVE-2026-45232 Description: The updated package fixes security vulnerabilities: Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write. (CVE-2026-29518) Rsync < 3.4.3 Authorization Bypass via Hostname Resolution. (CVE-2026-43617) Rsync < 3.4.3 Integer Overflow Information Disclosure. (CVE-2026-43618) Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls. (CVE-2026-43619) Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files(). (CVE-2026-43620) Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy. (CVE-2026-45232) References: - https://bugs.mageia.org/show_bug.cgi?id=35562 - https://www.openwall.com/lists/oss-security/2026/05/20/6 - https://lists.debian.org/debian-security-announce/2026/msg00193.html - https://lists.opensuse.org/archives/list/
1.2.9, CVE fixes. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fbd55e52fb 2026-07-12 01:10:38.798647+00:00 -------------------------------------------------------------------------------- Name : python-dulwich Product : Fedora 44 Version : 1.2.9 Release : 1.fc44 URL : https://www.dulwich.io/ Summary : Python implementation of the Git file formats and protocols Description : Dulwich is a Python implementation of the Git file formats and protocols. The project is named after the village in which Mr. and Mrs. Git live in the Monty Python sketch. -------------------------------------------------------------------------------- Update Information: 1.2.9, CVE fixes -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 7 2026 Gwyn Ciesla - 1.2.9-1 - 1.2.9 * Mon Jul 6 2026 Gwyn Ciesla - 1.2.8-1 - 1.2.8 * Tue Jun 30 2026 Gwyn Ciesla - 1.2.7-1 - 1.2.7 * Tue Jun 30 2026 Benjamin A. Beasley - 1.2.6-3 - Allow PyO3 0.29 - Update the `License` expression * Thu Jun 4 2026 Python Maint - 1.2.6-2 - Rebuilt for Python 3.15 * Tue Jun 2 2026 Gwyn Ciesla - 1.2.6-1 - 1.2.6 * Fri May 29 2026 Gwyn Ciesla - 1.2.5-1 - 1.2.5 * Thu May 21 2026 Gwyn Ciesla - 1.2.3-1 - 1.2.3 * Wed Apr 29 2026 Gwyn Ciesla - 1.2.1-1 - 1.2.1 * Thu Apr 23 2026 Gwyn Ciesla - 1.2.0-1 - 1.2.0 * Wed Feb 18 2026 Gwyn Ciesla - 1.1.0-1 - 1.1.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2487904 - CVE-2026-47712 python-dulwich: Dulwich: Arbitrary file write via malicious commit subject in format_patch [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2487904 [ 2 ] Bug #2487907 - CVE-2026-47734 python-dulwich: Dulwich: Denial of Service via crafted Git thin pack [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2487907 [ 3 ] Bug #2498479 -CVE-2026-42305 python-dulwich: Dulwich: Remote Code Execution via Malicious Git Repository [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2498479 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fbd55e52fb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for trivy ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21249-1 Rating: important References: * bsc#1269269 * bsc#1269271 Cross-References: * CVE-2026-54448 * CVE-2026-55092 CVSS scores: * CVE-2026-54448 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-54448 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55092 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-55092 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for trivy fixes the following issues Update to version 0.72.0. - CVE-2026-54448: tar unpacker reads scanned Helm chart archives (.tgz) with `io.ReadAll(tr)` and defines no size limit, which can lead to a DoS (bsc#1269271). - CVE-2026-55092: `org.opencontainers.image.title` annotation from OCI artifact manifest is used as a destination filename without validation and can lead to arbitrary file writes (bsc#1269269). Other updates and bugfixes: - Version 0.72.0: * feat(bottlerocket): add vulnerability matching for Bottlerocket OS (#10893) * fix(misconf): support github_repository_vulnerability_alerts resource (#10680) * feat(java): detect JAR licenses from packaged LICENSE files (#10856) * fix(nodejs): parse project dependencies from multi-document pnpm-lock.yaml (#10861) * fix(server): propagate package repository class in client/server mode (#10874) * chore(deps): bump github.com/containerd/containerd/v2 from 2.3.1 to 2.3.2 (#10888) * fix(vuln): fall back to UNKNOWN severity when vulnerability details are missing (#10795) * feat(java): detect JARlicenses from the embedded pom.xml (#10851) * chore(deps): Upgrade github.com/cenkalti/backoff to v6 (#10863) * ci(helm): bump Trivy version to 0.71.2 for Trivy Helm Chart 0.23.2 (#10873) * chore(deps): bump alpine to 3.24.1 (#10868) * docs: fix article typo in plugin developer guide (#10860) * feat(misconf): Adds CloudFront standard logging v2 support to AVD-AWS-0010 (#10848) * docs: fix typos (#10857) * fix(terraform): avoid data race on global getter.Getters in remote module resolver (#10843) * feat(secret): support new stateless format for GitHub App installation tokens (#10826) * fix: correct format verbs in diagnostic messages (#10805) * ci(helm): bump Trivy version to 0.71.1 for Trivy Helm Chart 0.23.1 (#10845) * refactor: use ParseErrorsAllowlist instead of ParseErrorsWhitelist (#10830) * docs: fix repository scan heading typo (#10828) * fix: forward ospkg detector options through ospkg.NewScanner (#10811) * chore(deps): bump github.com/bufbuild/buf to v1.70.0 (#10801) * fix(vex): load VEX documents from within the repository directory (#10820) * ci!: migrate docker config to dockers_v2 (#10783) * feat(dotnet): detect bundled runtime in self-contained deployments (#10786) * feat(secret): add OpenAI secret detection rules (#10798) * ci: expect GitHub App bot as backport PR author (#10813) * fix: surface the original analysis error instead of context cancellation (#10793) * chore(deps): bump the github-actions group across 1 directory with 11 updates (#10803) * chore(deps): bump the common group with 4 updates (#10797) * chore(deps): bump the aws group with 4 updates (#10796) * fix: use random suffix for process temp directory instead of PID (#10431) * docs: update signature verification for deb and rpm packages (#10784) * fix(image): lookup origin layer for custom resources in merged layers (#10788) * ci: bump GoReleaser to v2.16.0 (#10774) * docs: fix broken nixpkgs reference link in installation guide (#10776) * fix(image): deterministic OSpackage deduplication for images with embedded SBOMs (#10777) * fix(spdx): guard against nil root component in SPDX marshaler (#10771) * ci(helm): bump Trivy version to 0.71.0 for Trivy Helm Chart 0.23.0 (#10768) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1170=1 Package List: - openSUSE Leap 16.0: trivy-0.72.0-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-54448.html * https://www.suse.com/security/cve/CVE-2026-55092.html . Updates for openSUSE's trivy resolve significant issues including denial of service and file write vulnerabilities. Stay secure!. openSUSE security. . Severity: Important. LinuxSecurity.com Team
Update to 4.2.2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5b642da12e 2026-07-08 00:57:00.088478+00:00 -------------------------------------------------------------------------------- Name : helm Product : Fedora 44 Version : 4.2.2 Release : 1.fc44 URL : https://github.com/helm/helm Summary : The Kubernetes Package Manager Description : Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. Use Helm to: - Find and use popular software packaged as Helm Charts to run in Kubernetes - Share your own applications as Helm Charts - Create reproducible builds of your Kubernetes applications - Intelligently manage your Kubernetes manifest files - Manage releases of Helm packages. -------------------------------------------------------------------------------- Update Information: Update to 4.2.2 -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 29 2026 Mikel Olasagasti Uranga - 4.2.2-1 - Update to 4.2.2 - Closes rhbz#2488246 * Thu May 14 2026 Mikel Olasagasti Uranga - 4.2.0-1 - Update to 4.2.0 - Closes rhbz#2446841 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2457445 - CVE-2026-35204 helm: Helm: Arbitrary file write via specially crafted plugin [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2457445 [ 2 ] Bug #2457446 - CVE-2026-35205 helm: Helm: Arbitrary code execution due to insufficient plugin provenance verification [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2457446 [ 3 ] Bug #2486237 - CVE-2026-45287 helm: OpenTelemetry-Go: Denial of Service due to file descriptor leak [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486237 -------------------------------------------------------------------------------- This update can be installed with the"dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5b642da12e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to release v5.1.4 Resolves: rhbz#2480186 Upstream fixes Update to release v5.1.3 Resolves rhbz#2458697. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3316f97296 2026-05-30 00:54:46.011360+00:00 -------------------------------------------------------------------------------- Name : docker-compose Product : Fedora 44 Version : 5.1.4 Release : 1.fc44 URL : https://github.com/docker/compose Summary : Define and run multi-container applications with Docker Description : Define and run multi-container applications with Docker. -------------------------------------------------------------------------------- Update Information: Update to release v5.1.4 Resolves: rhbz#2480186 Upstream fixes Update to release v5.1.3 Resolves rhbz#2458697 Resolves CVE-2026-33747: rhbz#2452188, rhbz#2452199 Resolves CVE-2026-33748: rhbz#2453089 Upstream fixes -------------------------------------------------------------------------------- ChangeLog: * Wed May 20 2026 Bradley G Smith - 5.1.4-1 - Update to release v5.1.4 - Resolves: rhbz#2480186 - Upstream fixes * Wed Apr 15 2026 Bradley G Smith - 5.1.3-1 - Update to release v5.1.3 - Resolves rhbz#2458697 - Resolves CVE-2026-33747: rhbz#2452188, rhbz#2452199 - Resolves CVE-2026-33748: rhbz#2453089 - Upstream fixes -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452188 - CVE-2026-33747 docker-compose: BuildKit: Arbitrary file write and code execution via untrusted frontend [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2452188 [ 2 ] Bug #2452199 - CVE-2026-33747 docker-compose: BuildKit: Arbitrary file write and code execution via untrusted frontend [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2452199 [ 3 ] Bug #2453089 - CVE-2026-33748 docker-compose: BuildKit: Unauthorized file access via Git URL fragment subdir components[fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453089 [ 4 ] Bug #2458697 - docker-compose-5.1.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2458697 [ 5 ] Bug #2480186 - docker-compose-5.1.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2480186 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3316f97296' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
update to 1.154.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-729f84f3b6 2026-04-10 01:10:26.730895+00:00 -------------------------------------------------------------------------------- Name : doctl Product : Fedora 42 Version : 1.154.0 Release : 1.fc42 URL : https://github.com/digitalocean/doctl Summary : The official command line interface for the DigitalOcean API Description : The official command line interface for the DigitalOcean API. -------------------------------------------------------------------------------- Update Information: update to 1.154.0 -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 1 2026 Mikel Olasagasti Uranga - 1.154.0-1 - Update to 1.154.0 - Closes rhbz#2448615 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452189 - CVE-2026-33747 doctl: BuildKit: Arbitrary file write and code execution via untrusted frontend [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2452189 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-729f84f3b6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
update to 1.154.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6ad76ebb29 2026-04-10 00:59:15.834450+00:00 -------------------------------------------------------------------------------- Name : doctl Product : Fedora 43 Version : 1.154.0 Release : 1.fc43 URL : https://github.com/digitalocean/doctl Summary : The official command line interface for the DigitalOcean API Description : The official command line interface for the DigitalOcean API. -------------------------------------------------------------------------------- Update Information: update to 1.154.0 -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 1 2026 Mikel Olasagasti Uranga - 1.154.0-1 - Update to 1.154.0 - Closes rhbz#2448615 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452200 - CVE-2026-33747 doctl: BuildKit: Arbitrary file write and code execution via untrusted frontend [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2452200 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6ad76ebb29' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.