Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 38 articles for you...
100

SUSE Python-Tornado6 Important Authorization Memory Fix 2026-2725-1

An update that solves three vulnerabilities can now be installed.. # Security update for python-tornado6 Announcement ID: SUSE-SU-2026:2725-1 Release Date: 2026-07-02T13:52:50Z Rating: important References: * bsc#1268395 * bsc#1268396 * bsc#1268397 Cross-References: * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 CVSS scores: * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-tornado6 fixes the following issues * CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395). * CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396). * CVE-2026-49855: AsyncHTTPClient accumulatesdecompressed chunks without size limit (bsc#1268397). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2725=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2725=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2725=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2725=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2725=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2725=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2725=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2725=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2725=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2725=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2725=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2725=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS(aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 . Update for python-tornado6 addressing three critical issues like memory access. Essential for SUSE users.. python-tornado6 update, SUSE security patch, important security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 02, 2026 Important SuSE
202

openSUSE Python-Tornado6 Important Memory Access Issue 2026-2725-1

An update that solves three vulnerabilities can now be installed.. # Security update for python-tornado6 Announcement ID: SUSE-SU-2026:2725-1 Release Date: 2026-07-02T13:52:50Z Rating: important References: * bsc#1268395 * bsc#1268396 * bsc#1268397 Cross-References: * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 CVSS scores: * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-tornado6 fixes the following issues * CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395). * CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396). * CVE-2026-49855: AsyncHTTPClient accumulatesdecompressed chunks without size limit (bsc#1268397). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2725=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2725=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2725=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2725=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2725=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2725=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2725=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2725=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2725=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2725=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2725=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2725=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS(aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 . Three important vulnerabilities in python-tornado6 for openSUSE have available updates to enhance security against potential threats.. openSUSE Python Tornado6 Update Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 02, 2026 Important OpenSUSE
100

SUSE Docker Important Security Update for Multiple Issues 2026-2692-1

An update that solves four vulnerabilities can now be installed.. # Security update for docker Announcement ID: SUSE-SU-2026:2692-1 Release Date: 2026-06-30T08:53:39Z Rating: important References: * bsc#1262346 * bsc#1265782 * bsc#1266625 * bsc#1267827 Cross-References: * CVE-2026-33814 * CVE-2026-39821 * CVE-2026-39984 * CVE-2026-41567 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39984 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39984 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-39984 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41567 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-41567 ( NVD ): 7.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-41567 ( NVD ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * Containers Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSELinux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for docker fixes the following issues * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265782). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266625). * CVE-2026-39984: github.com/sigstore/timestamp-authority/v2/pkg/verification: improper certificate validation can be used to bypass some authorization controls (bsc#1262346). * CVE-2026-41567: arbitrary code execution with full daemon privileges when a user uploads a compressed archive into that container (bsc#1267827). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2692=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2692=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2692=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2692=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2692=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2692=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2692=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2692=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2692=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-2692=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2692=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2692=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2692=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2692=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2692=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2692=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2692=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * docker-buildx-0.33.0-150000.253.1 * docker-29.4.0_ce-150000.253.1 * docker-debuginfo-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) *docker-rootless-extras-29.4.0_ce-150000.253.1 * docker-bash-completion-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * docker-buildx-0.33.0-150000.253.1 * docker-29.4.0_ce-150000.253.1 * docker-debuginfo-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * docker-rootless-extras-29.4.0_ce-150000.253.1 * docker-bash-completion-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * docker-buildx-0.33.0-150000.253.1 * docker-29.4.0_ce-150000.253.1 * docker-debuginfo-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * docker-rootless-extras-29.4.0_ce-150000.253.1 * docker-bash-completion-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * docker-buildx-0.33.0-150000.253.1 * docker-29.4.0_ce-150000.253.1 * docker-debuginfo-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * docker-buildx-0.33.0-150000.253.1 * docker-29.4.0_ce-150000.253.1 * docker-debuginfo-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * docker-buildx-0.33.0-150000.253.1 * docker-29.4.0_ce-150000.253.1 * docker-debuginfo-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * docker-rootless-extras-29.4.0_ce-150000.253.1 * docker-bash-completion-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * docker-buildx-0.33.0-150000.253.1 * docker-29.4.0_ce-150000.253.1 * docker-debuginfo-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * docker-rootless-extras-29.4.0_ce-150000.253.1 * docker-bash-completion-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise HighPerformance Computing LTSS 15 SP5 (aarch64 x86_64) * docker-buildx-0.33.0-150000.253.1 * docker-29.4.0_ce-150000.253.1 * docker-debuginfo-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * docker-rootless-extras-29.4.0_ce-150000.253.1 * docker-bash-completion-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * docker-buildx-0.33.0-150000.253.1 * docker-29.4.0_ce-150000.253.1 * docker-debuginfo-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * docker-buildx-0.33.0-150000.253.1 * docker-29.4.0_ce-150000.253.1 * docker-debuginfo-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * docker-buildx-0.33.0-150000.253.1 * docker-29.4.0_ce-150000.253.1 * docker-debuginfo-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * docker-rootless-extras-29.4.0_ce-150000.253.1 * docker-bash-completion-29.4.0_ce-150000.253.1 * docker-zsh-completion-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * docker-buildx-0.33.0-150000.253.1 * docker-29.4.0_ce-150000.253.1 * docker-debuginfo-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * docker-buildx-0.33.0-150000.253.1 * docker-29.4.0_ce-150000.253.1 * docker-debuginfo-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * docker-rootless-extras-29.4.0_ce-150000.253.1 * docker-bash-completion-29.4.0_ce-150000.253.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * docker-buildx-0.33.0-150000.253.1 * docker-29.4.0_ce-150000.253.1 * docker-debuginfo-29.4.0_ce-150000.253.1 * Containers Module 15-SP7 (noarch) * docker-rootless-extras-29.4.0_ce-150000.253.1 * docker-bash-completion-29.4.0_ce-150000.253.1 *docker-zsh-completion-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * docker-buildx-0.33.0-150000.253.1 * docker-29.4.0_ce-150000.253.1 * docker-debuginfo-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * docker-rootless-extras-29.4.0_ce-150000.253.1 * docker-bash-completion-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * docker-buildx-0.33.0-150000.253.1 * docker-29.4.0_ce-150000.253.1 * docker-debuginfo-29.4.0_ce-150000.253.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * docker-rootless-extras-29.4.0_ce-150000.253.1 * docker-bash-completion-29.4.0_ce-150000.253.1 * docker-zsh-completion-29.4.0_ce-150000.253.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39984.html * https://www.suse.com/security/cve/CVE-2026-41567.html * https://bugzilla.suse.com/show_bug.cgi?id=1262346 * https://bugzilla.suse.com/show_bug.cgi?id=1265782 * https://bugzilla.suse.com/show_bug.cgi?id=1266625 * https://bugzilla.suse.com/show_bug.cgi?id=1267827 . Install the important security update for Docker to fix multiple vulnerabilities and enhance system security.. SUSE Docker Update Security Patch Vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 Important SuSE
172

Ubuntu 16.04 LTS Tomcat Critical Auth Bypass Issues USN-8383-1

Several security issues were fixed in Tomcat.. ========================================================================== Ubuntu Security Notice USN-8383-1 June 04, 2026 tomcat6, tomcat7 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Tomcat. Software Description: - tomcat7: Servlet and JSP engine - tomcat6: Servlet and JSP engine Details: It was discovered that Tomcat incorrectly handled digest authentication. A remote attacker could possibly use this issue to bypass authentication restrictions. (CVE-2026-43512) It was discovered that Tomcat incorrectly handled case sensitivity in LockOutRealm. A remote attacker could possibly use this issue to bypass account lockout protections and obtain sensitive information. (CVE-2026-43513) It was discovered that Tomcat incorrectly handled authorization when multiple method constraints defined the same HTTP method. A remote attacker could possibly use this issue to bypass authorization restrictions. (CVE-2026-43515) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS libtomcat7-java 7.0.68-1ubuntu0.4+esm4 Available with Ubuntu Pro tomcat7 7.0.68-1ubuntu0.4+esm4 Available with Ubuntu Pro Ubuntu 14.04 LTS libtomcat6-java 6.0.39-1ubuntu0.1+esm3 Available with Ubuntu Pro libtomcat7-java 7.0.52-1ubuntu0.16+esm2 Available with Ubuntu Pro tomcat6 6.0.39-1ubuntu0.1+esm3 Available with Ubuntu Pro tomcat7 7.0.52-1ubuntu0.16+esm2 Available with Ubuntu Pro After astandard system update you need to restart Tomcat to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8383-1 CVE-2026-43512, CVE-2026-43513, CVE-2026-43515 . Several security issues in Tomcat found in Ubuntu 14.04 and 16.04 require immediate attention to maintain system integrity.. Ubuntu security, Tomcat updates, system vulnerabilities, authentication risks, Linux server management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 05, 2026 Critical Ubuntu
172

Ubuntu Tomcat Important Auth Bypass and Security Fix USN-8383-1

Several security issues were fixed in Tomcat.. ========================================================================== Ubuntu Security Notice USN-8383-1 June 04, 2026 tomcat6, tomcat7 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Tomcat. Software Description: - tomcat7: Servlet and JSP engine - tomcat6: Servlet and JSP engine Details: It was discovered that Tomcat incorrectly handled digest authentication. A remote attacker could possibly use this issue to bypass authentication restrictions. (CVE-2026-43512) It was discovered that Tomcat incorrectly handled case sensitivity in LockOutRealm. A remote attacker could possibly use this issue to bypass account lockout protections and obtain sensitive information. (CVE-2026-43513) It was discovered that Tomcat incorrectly handled authorization when multiple method constraints defined the same HTTP method. A remote attacker could possibly use this issue to bypass authorization restrictions. (CVE-2026-43515) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS libtomcat7-java 7.0.68-1ubuntu0.4+esm4 Available with Ubuntu Pro tomcat7 7.0.68-1ubuntu0.4+esm4 Available with Ubuntu Pro Ubuntu 14.04 LTS libtomcat6-java 6.0.39-1ubuntu0.1+esm3 Available with Ubuntu Pro libtomcat7-java 7.0.52-1ubuntu0.16+esm2 Available with Ubuntu Pro tomcat6 6.0.39-1ubuntu0.1+esm3 Available with Ubuntu Pro tomcat7 7.0.52-1ubuntu0.16+esm2 Available with Ubuntu Pro After astandard system update you need to restart Tomcat to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8383-1 CVE-2026-43512, CVE-2026-43513, CVE-2026-43515 . Explore security issues addressed in Tomcat for Ubuntu, focusing on authentication bypass and authorization flaws.. Tomcat security, Ubuntu Ghost vulnerabilities, Tomcat update, Ubuntu advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 05, 2026 Important Ubuntu
100

SUSE Linux Micro 6.1 Google-Guest-Agent Major Auth Bypass 2026-21732-1

An update that solves one vulnerability can now be installed.. # Security update for google-guest-agent Announcement ID: SUSE-SU-2026:21732-1 Release Date: 2026-05-18T08:59:28Z Rating: important References: * bsc#1260264 Cross-References: * CVE-2026-33186 CVSS scores: * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for google-guest-agent fixes the following issue * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo- header (bsc#1260264). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-532=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20250506.01-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33186.html * https://bugzilla.suse.com/show_bug.cgi?id=1260264 . Important update for SUSE Linux Micro 6.1 addressing a critical authorization bypass issue in google-guest-agent.. SUSE Linux Micro, google-guest-agent, authorization bypass, security patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 22, 2026 Important SuSE
100

SUSE 2026 Ignition Critical Authorization Bypass CVE-2026-33186 Issues

An update that solves one vulnerability can now be installed.. # Security update for ignition Announcement ID: SUSE-SU-2026:1198-1 Release Date: 2026-04-07T10:25:22Z Rating: important References: * bsc#1260251 Cross-References: * CVE-2026-33186 CVSS scores: * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves one vulnerability can now be installed. ## Description: This update for ignition fixes the following issue: * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo- header (bsc#1260251) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-1198=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-1198=1 ## Package List: * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * ignition-2.14.0-150300.6.19.1 * ignition-dracut-grub2-2.14.0-150300.6.19.1 * ignition-debuginfo-2.14.0-150300.6.19.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * ignition-2.14.0-150300.6.19.1 * ignition-dracut-grub2-2.14.0-150300.6.19.1 * ignition-debuginfo-2.14.0-150300.6.19.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33186.html * https://bugzilla.suse.com/show_bug.cgi?id=1260251 . An important security update for the Ignition application on SUSE addresses a critical authorization bypass issue.. SUSE Ignition Update, ImportantSecurity Advisory, Authorization Bypass Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 07, 2026 Important SuSE
89

Fedora 42 scitokens-cpp Update FEDORA-2026-a6d1791c49 Scope Path Fix

Fix scope path boundary validation to deny sibling-prefix authorization bypasses Reject parent-directory traversal in scope paths, including encoded traversal forms Add regression tests covering sibling-prefix and traversal authorization checks. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a6d1791c49 2026-03-23 00:54:11.125976+00:00 -------------------------------------------------------------------------------- Name : scitokens-cpp Product : Fedora 42 Version : 1.4.1 Release : 1.fc42 URL : https://github.com/scitokens/scitokens-cpp Summary : C++ Implementation of the SciTokens Library Description : C++ Implementation of the SciTokens Library -------------------------------------------------------------------------------- Update Information: Fix scope path boundary validation to deny sibling-prefix authorization bypasses Reject parent-directory traversal in scope paths, including encoded traversal forms Add regression tests covering sibling-prefix and traversal authorization checks -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 13 2026 Derek Weitzel - 1.4.1-1 - Fix scope path boundary validation to deny sibling-prefix authorization bypasses - Reject parent-directory traversal in scope paths, including encoded traversal forms - Add regression tests covering sibling-prefix and traversal authorization checks -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a6d1791c49' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fixes to sibling-prefix authorization bypasses and scope path validations in scitokens-cpp for Fedora 42.. scitokens-cpp, authorization bypass, boundary validation, Fedora 42, security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 23, 2026 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200