Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 14 articles for you...
100

SUSE 16.0 Bouncycastle Important Security Fix DoS 2026-21404-1

An update that solves five vulnerabilities can now be installed.. # Security update for bouncycastle Announcement ID: SUSE-SU-2026:21404-1 Release Date: 2026-04-24T15:26:29Z Rating: important References: * bsc#1262225 * bsc#1262226 * bsc#1262227 * bsc#1262228 * bsc#1262232 Cross-References: * CVE-2025-14813 * CVE-2026-0636 * CVE-2026-3505 * CVE-2026-5588 * CVE-2026-5598 CVSS scores: * CVE-2025-14813 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-14813 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2025-14813 ( NVD ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Red * CVE-2026-0636 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-0636 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-0636 ( NVD ): 5.5 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:X/RE:M/U:Amber * CVE-2026-3505 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3505 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3505 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-5588 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-5588 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-5588 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber * CVE-2026-5598 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-5598 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-5598 ( NVD ): 8.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Red Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for bouncycastle fixes the following issues: * Update to version 1.84: * CVE-2025-14813: GOSTCTR implementation unable to process more than 255 blocks correctly (bsc#1262225). * CVE-2026-0636: LDAP Injection Vulnerability in LDAPStoreHelper.java (bsc#1262226). * CVE-2026-3505: Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion (bsc#1262232). * CVE-2026-5588: PKIX draft CompositeVerifier accepts empty signature sequence as valid (bsc#1262228). * CVE-2026-5598: Non-constant time comparisons risk private key leakage in FrodoKEM (bsc#1262227). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-643=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-643=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * bouncycastle-util-1.84-160000.1.1 * bouncycastle-pkix-1.84-160000.1.1 * bouncycastle-jmail-1.84-160000.1.1 * bouncycastle-pg-1.84-160000.1.1 * bouncycastle-tls-1.84-160000.1.1 * bouncycastle-mail-1.84-160000.1.1 * bouncycastle-javadoc-1.84-160000.1.1 * bouncycastle-1.84-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) *bouncycastle-util-1.84-160000.1.1 * bouncycastle-pkix-1.84-160000.1.1 * bouncycastle-jmail-1.84-160000.1.1 * bouncycastle-pg-1.84-160000.1.1 * bouncycastle-tls-1.84-160000.1.1 * bouncycastle-mail-1.84-160000.1.1 * bouncycastle-javadoc-1.84-160000.1.1 * bouncycastle-1.84-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-14813.html * https://www.suse.com/security/cve/CVE-2026-0636.html * https://www.suse.com/security/cve/CVE-2026-3505.html * https://www.suse.com/security/cve/CVE-2026-5588.html * https://www.suse.com/security/cve/CVE-2026-5598.html * https://bugzilla.suse.com/show_bug.cgi?id=1262225 * https://bugzilla.suse.com/show_bug.cgi?id=1262226 * https://bugzilla.suse.com/show_bug.cgi?id=1262227 * https://bugzilla.suse.com/show_bug.cgi?id=1262228 * https://bugzilla.suse.com/show_bug.cgi?id=1262232 . An update addressing multiple security issues in BouncyCastle for SUSE systems, including important patches and installation guidance.. SUSE BouncyCastle vulnerabilities update important security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 30, 2026 Important SuSE
100

SUSE bouncycastle Important Vulnerabilities Fix 2026-1639-1

An update that solves five vulnerabilities can now be installed.. # Security update for bouncycastle Announcement ID: SUSE-SU-2026:1639-1 Release Date: 2026-04-28T11:10:38Z Rating: important References: * bsc#1262225 * bsc#1262226 * bsc#1262227 * bsc#1262228 * bsc#1262232 Cross-References: * CVE-2025-14813 * CVE-2026-0636 * CVE-2026-3505 * CVE-2026-5588 * CVE-2026-5598 CVSS scores: * CVE-2025-14813 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-14813 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2025-14813 ( NVD ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Red * CVE-2026-0636 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-0636 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-0636 ( NVD ): 5.5 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:X/RE:M/U:Amber * CVE-2026-3505 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3505 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3505 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-5588 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-5588 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-5588 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber * CVE-2026-5598 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-5598 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-5598 ( NVD ): 8.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Red Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves five vulnerabilities can now be installed. ## Description: This update for bouncycastle fixes the following issues: Update to version 1.84. Security issues fixed: * CVE-2025-14813: GOSTCTR implementation unable to process more than 255 blocks correctly (bsc#1262225). * CVE-2026-0636: LDAP injection in LDAPStoreHelper.java leads to information disclosure (bsc#1262226). * CVE-2026-3505: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion (bsc#1262232). * CVE-2026-5588: PKIX draft CompositeVerifier accepts empty signature sequence as valid(bsc#1262228). * CVE-2026-5598: non-constant time comparisons risks private key leakage in FrodoKEM (bsc#1262227). Other updates and bugfixes: * Version 1.84: * In line with JVM changes, KEM support has been backported to Java 17. * BCJSSE: Configurable (client) early key_share groups via BCSSLParameters.earlyKeyShares or 'org.bouncycastle.jsse.client.earlyKeyShares' system property. * BCJSSE: Support for curveSM2MLKEM768 hybrid NamedGroup in TLS 1.3 per draft- yang-tls-hybrid-sm2-mlkem-03. * BCJSSE: Log when default cipher suites are disabled. * BCJSSE: Experimental support for ShangMi crypto in TLS 1.3 per RFC 8998 (not enabled by default). * CMS: Added CMSAuthEnvelopedDataStreamGenerator.open taking an explicit content type. * HKDF: Provider support for HKDFParameterSpec.Expand. * Added initial support for RFC 9380 (Hashing to Elliptic Curves); see org.bouncycastle.crypto.hash2curve . * PKCS12: Added default max iteration count of 5,000,000 (configurable via 'org.bouncycastle.pkcs12.max_it_count' property). * TLS: Use javax.crypto.KEM API (when available) to access ML-KEM implementation (incl. hybrids). * A new KeyStore, PKCS12-PBMAC1, has been added which defaults to using PBMAC1 and supports RFC 9879. * A new property 'org.bouncycastle.asn1.max_cons_depth' has been added to allow setting of the maximum nesting for SETs/SEQUENCESs in ASN.1. Default is 32. * A new property 'org.bouncycastle.asn1.max_limit' has been added to allow setting of the stream size of ASN.1 encodings. The value can be either in bytes, or appended with k (1 kilobyte blocks), m (1 megabyte blocks), or g (1 gigabyte blocks). * Added NTRU+ support to the lightweight PQC API and the BCPQC provider. * Added SM4 key wrap/unwrap mode, SM2 key exchange, and logging to SM2Signer. * OpenPGP: Added encryption-key filtering by purpose, a new OpenPGPKey constructor, KeyPassphraseProvider-based passphrase change, wildcard (anonymous) recipienthandling, and Web-of-Trust methods for third-party signature chains and delegations. * CMSSignedDataStreamGenerator can now support the generation of DER/DL encoded SignedData objects (note memory restrictions still apply). * It is now possible to add extra digest alorithm IDs to CMSSignedDataStreamGenerator when required. * Random numbers being generated for DSTU4145 signature calculations were 1 bit shorter than they could be. The code has been corrected to allow the generated numbers to occupy the full numeric range available. * HKDF implementation has been corrected to use multiple IKMs if available. * CompositePublic/PrivateKey builders had an issue identifying brainpool and EdDSA curves from the algorithm names due to an error in the OID mapping table. This has been fixed. * S/MIME: Fix AuthEnveloped support for AES192/GCM and AES256/GCM. * CMS: Use implicit tag for AuthEnvelopedData.authEncryptedContentInfo.encryptedContent. * Fixed Strings.split to handle delimiters at position 0. * Fixed FrodoKEM error sampling to be constant-time. * Fixed PKIXNameConstraintValidator to treat a DNS name as intersecting itself. * Fixed PKCS12 key stores not calling getInstance with the original provider (which was forcing provider registration). * A resource leak due to the SMIMESigned constructor leaving background threads hanging on MessagingException has been fixed. * OpenPGP: Fixed an issue where a custom signature creation time was ignored when generating message signatures. * OpenPGP: Fixed SKESK encoding for direct-S2K-encrypted messages. * Version 1.83: * Attempting to check a password on a stripped PGP would throw an exception. Checking the password on such a key will now always return false. * Fixed an issue in KangarooTwelve where premature absorption caused erroneous 168-byte padding; absorption is now delayed so correct final-byte padding is applied. * BCJSSE: Fix supported_versions creation for renegotiationhandshake. * (D)TLS: Reneg info now oly offered with pre-1.3. * A generic "COMPOSITE" algorithm name has been added as a JCA Signature algorithm. The algorithm will identify the composite signature to use from the composite key passed in. * The composite signatures implementation has been updated to the final draft and now follows the submitted standard. * Support for the generation and use as trust anchors has been added for certificate signatures with id-alg-unsigned as the signature type. * Support for CMP direct POP for encryption keys using challenge/response has been added to the CMP/CRMF APIs. * Support for SupportedCurves attribute to the BC provider * BCJSSE: Added support for SLH-DSA signature schemes in TLS 1.3 per draft- reddy-tls-slhdsa-01. * Support has been added for the Java 25 KDF API (current algorithms, PBKDF2, SCRYPT, and HKDF). * Support for composite signatures is now included in CMS and timestamping. * It is now possible to disable the Lenstra check in RSA where the public key is not available via the system/security property "org.bouncycastle.rsa.no_lenstra_check". * Version 1.82: * SNOVA and MAYO are now correctly added to the JCA provider module-info file. * TLS: Avoid nonce reuse error in JCE AEAD workaround for pre-Java7. * BCJSSE: Session binding map is now shared across all stages of the session lifecycle (SunJSSE compatibility). * The CMCEPrivateKeyParameters#reconstructPublicKey method was returning an empty byte array. It now returns an encoding of the public key. * CBZip2InputStream no longer auto-closes at end-of-contents. * The BC CertPath implementation was eliminating certificates on the bases of the Key-ID. This is not in accordance with RFC 4158. * Support for the previous set of libOQS Falcon OIDs has been restored. * The BC CipherInputStream could throw an exception if asked to handle an AEAD stream consisting of the MAC only. * Some KeyAgreement classes were missing in the Java11 class hierarchy. * Fix typo in a constant name in the HPKE class and deprecate the old constant. * Fuzzing analysis has been done on the OpenPGP API and additional code has been added to prevent escaping exceptions. * SHA3Digest, CSHAKE, TupleHash, KMAC now provide support for Memoable and EncodableService. * BCJSSE: Added support for integrity-only cipher suites in TLS 1.3 per RFC 9150. * BCJSSE: Added support for system properties "jdk.tls.{client,server}.maxInboundCertificateChainLength" * BCJSSE: Added support for ML-DSA signature schemes in TLS 1.3 per draft- ietf-tls-mldsa-00. * The Composite post-quantum signatures implementation has been updated to the latest draft (07) draft-ietf-lamps-pq-composite-sigs. * "_PREHASH" implementations are now provided for all composite signatures to allow the hash of the date to be used instead of the actual data in signature calculation. * The gradle build can now be used to generate an Bill of Materials (BOM) file. * It is now possible to configure the SignerInfoVerifierBuilder used by the SignedMailValidator class. * The Ascon family of algorithms has been updated with the latest published changes. * Composite signature keys can now be constructed from the individual keys of the algorithms composing the composite. * PGPSecretKey, PGPSignatureGenerator now support version 6. * Further optimisation work has been done on ML-KEM public key validation. * Zeroization of passwords in the JCA PKCS12 key store has been improved. * The "org.bouncycastle.drbg.effective_256bits_entropy" property has been added for platforms where the entropy source is not producing 1 full bit of entropy per bit and additional bits are required (default value 282). * OpenPGPKeyGenerator now allows for the use of empty UserIDs (version 4 compatibility). * The HQC KEM has been updated with the latest draft updates. * The legacy post-quantum package has now been removed. * Version 1.81: * Apotention NullPointerException in the KEM KDF KemUtil class has been removed. * Overlapping input/output buffers in doFinal could result in data corruption. * Fixed Grain-128AEAD decryption incorrectly handle MAC verification. * Add configurable header validation to prevent malicious header injection in PGP cleartext signed messages; Fix signature packet encoding issues in PGPSignature.join() and embedded signatures while phasing out legacy format. * Fixed ParallelHash initialization stall when using block size B=0. * The PRF from the PBKDF2 function was been lost when PBMAC1 was initialized from protectionAlgorithm. This has been fixed. * The lowlevel DigestFactory was cloning MD5 when being asked to clone SHA1. * XWing implementation updated to draft-connolly-cfrg-xwing-kem/07/ * Further support has been added for generation and use of PGP V6 keys * Additional validation has been added for armored headers in Cleartext Signed Messages. * The PQC signature algorithm proposal Mayo has been added to the low-level API and the BCPQC provider. * The PQC signature algorithm proposal Snova has been added to the low-level API and the BCPQC provider. * Support for ChaCha20-Poly1305 has been added to the CMS/SMIME APIs. * The Falcon implementation has been updated to the latest draft. * Support has been added for generating keys which encode as seed-only and expanded-key-only for ML-KEM and ML-DSA private keys. * Private key encoding of ML-DSA and ML-KEM private keys now follows the latest IETF draft. * The Ascon family of algorithms has been updated to the initial draft of SP 800-232. Some additional optimisation work has been done. * Support for ML-DSA's external-mu calculation and signing has been added to the BC provider. * CMS now supports ML-DSA for SignedData generation. * Introduce high-level OpenPGP API for message creation/consumption and certificate evaluation. * Added JDK21 KEM API implementation for HQC algorithm. *BCJSSE: Strip trailing dot from hostname for SNI, endpointID checks. * BCJSSE: Draft support for ML-KEM updated (draft-connolly-tls-mlkem-key- agreement-05). * BCJSSE: Draft support for hybrid ECDHE-MLKEM (draft-ietf-tls-ecdhe- mlkem-00). * BCJSSE: Optionally prefer TLS 1.3 server's supported_groups order (BCSSLParameters.useNamedGroupsOrder). * Version 1.80: * A splitting issue for ML-KEM led to an incorrect size for kemct in KEMRecipientInfos. This has been fixed. * The PKCS12 KeyStore has been adjusted to prevent accidental doubling of the Oracle trusted certificate attribute (results in an IOException when used with the JVM PKCS12 implementation). * The SignerInfoGenerator copy constructor was ignoring the certHolder field. * The getAlgorithm() method return value for a CompositePrivateKey was not consistent with the corresponding getAlgorithm() return value for the CompositePrivateKey. This has been fixed. * The international property files were missing from the bcjmail distribution. * Issues with ElephantEngine failing on processing large/multi-block messages have been addressed. * GCFB mode now fully resets on a reset. * The lightweight algorithm contestants: Elephant, ISAP, PhotonBeetle, Xoodyak now support the use of the AEADParameters class and provide accurate update/doFinal output lengths. * An unnecessary downcast in CertPathValidatorUtilities was resulting in the ignoring of URLs for FTP based CRLs. * A regression in the OpenPGP API could cause NoSuchAlgorithmException to be thrown when attempting to use SHA-256 in some contexts. * EtsiTs1029411TypesAuthorization was missing an extension field. * Interoperability issues with single depth LMS keys have been addressed. * CompositeSignatures now updated to draft-ietf-lamps-pq-composite-sigs-03. * ML-KEM, ML-DSA, SLH-DSA, and Composite private keys now use raw encodings as per the latest drafts from IETF 121: draft-ietf-lamps-kyber-certificates-06, draft-ietf-lamps-dilithium-certificates-05, and draft-ietf- lamps-x509-slhdsa. * Initial support has been added for RFC 9579 PBMAC1 in the PKCS API. * Support has been added for EC-JPAKE to the lightweight API. * Support has been added for the direct construction of S/MIME AuthEnvelopedData objects, via the SMIMEAuthEnvelopedData class. * An override "org.bouncycastle.asn1.allow_wrong_oid_enc" property has been added to disable new OID encoding checks (use with caution). * Support has been added for the PBEParemeterSpec.getParameterSpec() method where supported by the JVM. * ML-DSA/SLH-DSA now return null for Signature.getParameters() if no context is provided. This allows the algorithms to be used with the existing Java key tool. * HQC has been updated to reflect the reference implementation released on 2024-10-30. * Support has been added to the low-level APIs for the OASIS Shamir Secret Splitting algorithms. * BCJSSE: System property "org.bouncycastle.jsse.fips.allowGCMCiphersIn12" no longer used. FIPS TLS 1.2 GCM suites can now be enabled according to JcaTlsCrypto#getFipsGCMNonceGeneratorFactory (see JavaDoc for details) if done in alignment with FIPS requirements. * Support has been added for OpenPGP V6 PKESK and message encryption. * PGPSecretKey.copyWithNewPassword() now includes AEAD support. * The ASCON family of algorithms have been updated in accordance with the published FIPS SP 800-232 draft. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-1639=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1639=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -tpatch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1639=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1639=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1639=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1639=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1639=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1639=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1639=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-1639=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1639=1 ## Package List: * Development Tools Module 15-SP7 (noarch) * bouncycastle-1.84-150200.3.35.1 * bouncycastle-pkix-1.84-150200.3.35.1 * bouncycastle-util-1.84-150200.3.35.1 * bouncycastle-pg-1.84-150200.3.35.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * bouncycastle-1.84-150200.3.35.1 * bouncycastle-pkix-1.84-150200.3.35.1 * bouncycastle-util-1.84-150200.3.35.1 * bouncycastle-pg-1.84-150200.3.35.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * bouncycastle-1.84-150200.3.35.1 * bouncycastle-pkix-1.84-150200.3.35.1 * bouncycastle-util-1.84-150200.3.35.1 * bouncycastle-pg-1.84-150200.3.35.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * bouncycastle-1.84-150200.3.35.1 * bouncycastle-pkix-1.84-150200.3.35.1 * bouncycastle-util-1.84-150200.3.35.1 * bouncycastle-pg-1.84-150200.3.35.1 * SUSE Linux EnterpriseHigh Performance Computing LTSS 15 SP5 (noarch) * bouncycastle-1.84-150200.3.35.1 * bouncycastle-pkix-1.84-150200.3.35.1 * bouncycastle-util-1.84-150200.3.35.1 * bouncycastle-pg-1.84-150200.3.35.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * bouncycastle-1.84-150200.3.35.1 * bouncycastle-pkix-1.84-150200.3.35.1 * bouncycastle-util-1.84-150200.3.35.1 * bouncycastle-pg-1.84-150200.3.35.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * bouncycastle-1.84-150200.3.35.1 * bouncycastle-pkix-1.84-150200.3.35.1 * bouncycastle-util-1.84-150200.3.35.1 * bouncycastle-pg-1.84-150200.3.35.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * bouncycastle-1.84-150200.3.35.1 * bouncycastle-pkix-1.84-150200.3.35.1 * bouncycastle-util-1.84-150200.3.35.1 * bouncycastle-pg-1.84-150200.3.35.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * bouncycastle-1.84-150200.3.35.1 * bouncycastle-pkix-1.84-150200.3.35.1 * bouncycastle-util-1.84-150200.3.35.1 * bouncycastle-pg-1.84-150200.3.35.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * bouncycastle-1.84-150200.3.35.1 * bouncycastle-pkix-1.84-150200.3.35.1 * bouncycastle-util-1.84-150200.3.35.1 * bouncycastle-pg-1.84-150200.3.35.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * bouncycastle-1.84-150200.3.35.1 * bouncycastle-pkix-1.84-150200.3.35.1 * bouncycastle-util-1.84-150200.3.35.1 * bouncycastle-pg-1.84-150200.3.35.1 ## References: * https://www.suse.com/security/cve/CVE-2025-14813.html * https://www.suse.com/security/cve/CVE-2026-0636.html * https://www.suse.com/security/cve/CVE-2026-3505.html * https://www.suse.com/security/cve/CVE-2026-5588.html * https://www.suse.com/security/cve/CVE-2026-5598.html * https://bugzilla.suse.com/show_bug.cgi?id=1262225 * https://bugzilla.suse.com/show_bug.cgi?id=1262226 * https://bugzilla.suse.com/show_bug.cgi?id=1262227 *https://bugzilla.suse.com/show_bug.cgi?id=1262228 * https://bugzilla.suse.com/show_bug.cgi?id=1262232 . Explore the SUSE bouncycastle security update addressing five important vulnerabilities with patch instructions.. bouncycastle update, SUSE security advisory, bouncycastle vulnerabilities, SUSE Linux patch instructions, important security updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 28, 2026 Important SuSE
202

openSUSE Tumbleweed Bouncycastle Moderate Threats Update 2026-10571-1

An update that solves 5 vulnerabilities can now be installed.. # bouncycastle-1.84-1.1 on GA media Announcement ID: openSUSE-SU-2026:10571-1 Rating: moderate Cross-References: * CVE-2025-14813 * CVE-2026-0636 * CVE-2026-3505 * CVE-2026-5588 * CVE-2026-5598 CVSS scores: * CVE-2025-14813 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2025-14813 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-0636 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-0636 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-3505 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3505 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-5588 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-5588 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-5598 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-5598 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 5 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the bouncycastle-1.84-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * bouncycastle 1.84-1.1 * bouncycastle-javadoc 1.84-1.1 * bouncycastle-jmail 1.84-1.1 * bouncycastle-mail 1.84-1.1 * bouncycastle-pg 1.84-1.1 * bouncycastle-pkix 1.84-1.1 * bouncycastle-tls 1.84-1.1 * bouncycastle-util 1.84-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-14813.html * https://www.suse.com/security/cve/CVE-2026-0636.html * https://www.suse.com/security/cve/CVE-2026-3505.html * https://www.suse.com/security/cve/CVE-2026-5588.html * https://www.suse.com/security/cve/CVE-2026-5598.html . 5 security flaws addressed by an updatefor openSUSE's bouncycastle package; recommended for installation.. openSUSE Tumbleweed,bouncycastle security update,moderate rating,security cross-references. . LinuxSecurity.com Team

Calendar%202 Apr 19, 2026 OpenSUSE
100

SUSE: 2024:1539-2 Moderate: Bouncycastle Timing Attack Update

* bsc#1223252 Cross-References: * CVE-2024-30171 . # Security update for bouncycastle Announcement ID: SUSE-SU-2024:1539-2 Rating: moderate References: * bsc#1223252 Cross-References: * CVE-2024-30171 CVSS scores: * CVE-2024-30171 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * Development Tools Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for bouncycastle fixes the following issues: Update to version 1.78.1, including fixes for: * CVE-2024-30171: Fixed timing side-channel attacks against RSA decryption (both PKCS#1v1.5 and OAEP). (bsc#1223252) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2024-1539=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-1539=1 ## Package List: * Development Tools Module 15-SP6 (noarch) * bouncycastle-pg-1.78.1-150200.3.29.1 * bouncycastle-util-1.78.1-150200.3.29.1 * bouncycastle-pkix-1.78.1-150200.3.29.1 * bouncycastle-1.78.1-150200.3.29.1 * openSUSE Leap 15.6 (noarch) * bouncycastle-javadoc-1.78.1-150200.3.29.1 * bouncycastle-jmail-1.78.1-150200.3.29.1 * bouncycastle-tls-1.78.1-150200.3.29.1 * bouncycastle-pg-1.78.1-150200.3.29.1 * bouncycastle-1.78.1-150200.3.29.1 * bouncycastle-mail-1.78.1-150200.3.29.1 * bouncycastle-util-1.78.1-150200.3.29.1 * bouncycastle-pkix-1.78.1-150200.3.29.1 ## References: * https://www.suse.com/security/cve/CVE-2024-30171.html *https://bugzilla.suse.com/show_bug.cgi?id=1223252 . Recent enhancements in BouncyCastle address severe vulnerabilities tied to RSA decryption timing attacks. It is advised to apply the necessary updates on SUSE-based systems.. bouncycastle update, moderate security advisory, timing attack fixes, SUSE updates. . LinuxSecurity.com Team

Calendar%202 Jun 18, 2024 SuSE
100

SUSE: 2024:1539-1 Moderate: Bouncycastle Timing Side-Channel Attack

* bsc#1223252 Cross-References: * CVE-2024-30171 . # Security update for bouncycastle Announcement ID: SUSE-SU-2024:1539-1 Rating: moderate References: * bsc#1223252 Cross-References: * CVE-2024-30171 CVSS scores: * CVE-2024-30171 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * Development Tools Module 15-SP5 * openSUSE Leap 15.5 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for bouncycastle fixes the following issues: Update to version 1.78.1, including fixes for: * CVE-2024-30171: Fixed timing side-channel attacks against RSA decryption (both PKCS#1v1.5 and OAEP). (bsc#1223252) ## Patch Instructions: To install this SUSE update use the SUSE recommended installationmethods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-1539=1 * Development Tools Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2024-1539=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-1539=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-1539=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-1539=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-1539=1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-1539=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-1539=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-1539=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-1539=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-1539=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-1539=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-1539=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-1539=1 ## Package List: * openSUSE Leap 15.5 (noarch) * bouncycastle-mail-1.78.1-150200.3.29.1 * bouncycastle-tls-1.78.1-150200.3.29.1 * bouncycastle-jmail-1.78.1-150200.3.29.1 *bouncycastle-pg-1.78.1-150200.3.29.1 * bouncycastle-javadoc-1.78.1-150200.3.29.1 * bouncycastle-util-1.78.1-150200.3.29.1 * bouncycastle-pkix-1.78.1-150200.3.29.1 * bouncycastle-1.78.1-150200.3.29.1 * Development Tools Module 15-SP5 (noarch) * bouncycastle-pg-1.78.1-150200.3.29.1 * bouncycastle-pkix-1.78.1-150200.3.29.1 * bouncycastle-1.78.1-150200.3.29.1 * bouncycastle-util-1.78.1-150200.3.29.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (noarch) * bouncycastle-pg-1.78.1-150200.3.29.1 * bouncycastle-pkix-1.78.1-150200.3.29.1 * bouncycastle-1.78.1-150200.3.29.1 * bouncycastle-util-1.78.1-150200.3.29.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * bouncycastle-pg-1.78.1-150200.3.29.1 * bouncycastle-pkix-1.78.1-150200.3.29.1 * bouncycastle-1.78.1-150200.3.29.1 * bouncycastle-util-1.78.1-150200.3.29.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * bouncycastle-pg-1.78.1-150200.3.29.1 * bouncycastle-pkix-1.78.1-150200.3.29.1 * bouncycastle-1.78.1-150200.3.29.1 * bouncycastle-util-1.78.1-150200.3.29.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * bouncycastle-pg-1.78.1-150200.3.29.1 * bouncycastle-pkix-1.78.1-150200.3.29.1 * bouncycastle-1.78.1-150200.3.29.1 * bouncycastle-util-1.78.1-150200.3.29.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (noarch) * bouncycastle-pg-1.78.1-150200.3.29.1 * bouncycastle-pkix-1.78.1-150200.3.29.1 * bouncycastle-1.78.1-150200.3.29.1 * bouncycastle-util-1.78.1-150200.3.29.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (noarch) * bouncycastle-pg-1.78.1-150200.3.29.1 * bouncycastle-pkix-1.78.1-150200.3.29.1 * bouncycastle-1.78.1-150200.3.29.1 * bouncycastle-util-1.78.1-150200.3.29.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch) * bouncycastle-pg-1.78.1-150200.3.29.1 * bouncycastle-pkix-1.78.1-150200.3.29.1 * bouncycastle-1.78.1-150200.3.29.1 * bouncycastle-util-1.78.1-150200.3.29.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (noarch) * bouncycastle-pg-1.78.1-150200.3.29.1 * bouncycastle-pkix-1.78.1-150200.3.29.1 * bouncycastle-1.78.1-150200.3.29.1 * bouncycastle-util-1.78.1-150200.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch) * bouncycastle-pg-1.78.1-150200.3.29.1 * bouncycastle-pkix-1.78.1-150200.3.29.1 * bouncycastle-1.78.1-150200.3.29.1 * bouncycastle-util-1.78.1-150200.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * bouncycastle-pg-1.78.1-150200.3.29.1 * bouncycastle-pkix-1.78.1-150200.3.29.1 * bouncycastle-1.78.1-150200.3.29.1 * bouncycastle-util-1.78.1-150200.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * bouncycastle-pg-1.78.1-150200.3.29.1 * bouncycastle-pkix-1.78.1-150200.3.29.1 * bouncycastle-1.78.1-150200.3.29.1 * bouncycastle-util-1.78.1-150200.3.29.1 * SUSE Enterprise Storage 7.1 (noarch) * bouncycastle-pg-1.78.1-150200.3.29.1 * bouncycastle-pkix-1.78.1-150200.3.29.1 * bouncycastle-1.78.1-150200.3.29.1 * bouncycastle-util-1.78.1-150200.3.29.1 ## References: * https://www.suse.com/security/cve/CVE-2024-30171.html * https://bugzilla.suse.com/show_bug.cgi?id=1223252 . Updated security measures for bouncycastle targeting CVE-2024-30171 across several SUSE offerings. Implementation of the patch is advised.. bouncycastle Update, SUSE Advisory, Threat Management, Security Patch, Moderate Severity. . LinuxSecurity.com Team

Calendar%202 May 07, 2024 SuSE
89

Fedora 40: FEDORA-2024-129d8ca6fc High: Bouncy Castle Type Confusion

Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-129d8ca6fc 2024-03-07 22:24:39.963937 -------------------------------------------------------------------------------- Name : bouncycastle Product : Fedora 40 Version : 1.70 Release : 13.fc40 URL : https://www.bouncycastle.org/ Summary : Bouncy Castle Cryptography APIs for Java Description : The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5 to JDK 1.8. -------------------------------------------------------------------------------- Update Information: Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires Automatic update for lucene-9.9.2-1.fc40. bump java source/target to 1.8, fixes 2266639 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 2 2024 Jiri Vanek - 1.70-13 - Rebuilt for java-21-openjdk as system jdk -------------------------------------------------------------------------------- References: [ 1 ] Bug #2123726 - consoleImageViewer crashes at start https://bugzilla.redhat.com/show_bug.cgi?id=2123726 [ 2 ] Bug #2261062 - directory-maven-plugin: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261062 [ 3 ] Bug #2266639 - directory-maven-plugin fails to build with java-21-openjdk https://bugzilla.redhat.com/show_bug.cgi?id=2266639 [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266934 [ 5 ] Bug #2266937 - CVE-2024-1939 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266937 [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta https://bugzilla.redhat.com/show_bug.cgi?id=2267486 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Major security patches rolled out for Bouncy Castle Java API in Fedora 40, addressing critical type confusion vulnerabilities.. Bouncy Castle, Fedora 40, Java Updates, Type Confusion, Security Fixes. . LinuxSecurity.com Team

Calendar%202 Mar 07, 2024 Fedora
100

SUSE: 2024:0327-1 Important: Jsch and Bouncycastle Security Issue

* bsc#1218134 Cross-References: * CVE-2023-48795 . # Security update for bouncycastle, jsch Announcement ID: SUSE-SU-2024:0327-1 Rating: important References: * bsc#1218134 Cross-References: * CVE-2023-48795 CVSS scores: * CVE-2023-48795 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-48795 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * Development Tools Module 15-SP5 * openSUSE Leap 15.5 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Server 4.3 * SUSE Manager Server 4.3 Module 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for bouncycastle, jsch fixes the following issues: * Updated jsch to version 0.2.15: * CVE-2023-48795: Fixed a prefix truncation issue that could leadto disclosure of sensitive information (bsc#1218134). * Updated bouncycastle to version 1.77. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-327=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-327=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-327=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-327=1 * Development Tools Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2024-327=1 * SUSE Manager Server 4.3 Module 4.3 zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Server-4.3-2024-327=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-327=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-327=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-327=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-327=1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-327=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-327=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-327=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-327=1 * SUSE Linux Enterprise Server for SAPApplications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-327=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Enterprise Storage 7.1 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * openSUSE Leap 15.5 (noarch) * bouncycastle-mail-1.77-150200.3.24.1 * bouncycastle-1.77-150200.3.24.1 * bouncycastle-tls-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-jmail-1.77-150200.3.24.1 * bouncycastle-javadoc-1.77-150200.3.24.1 * jsch-javadoc-0.2.15-150200.11.13.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * jsch-demo-0.2.15-150200.11.13.1 * Development Tools Module 15-SP5 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Manager Server 4.3 Module 4.3 (noarch) * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 ##References: * https://www.suse.com/security/cve/CVE-2023-48795.html * https://bugzilla.suse.com/show_bug.cgi?id=1218134 . An important announcement pertains to the resolution of a prefix cutting problem in jsch and bouncycastle. Discover further details.. jsch Security Patch, bouncycastle Fix, SUSE Important Update, Linux Software Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 05, 2024 Important SuSE
197

Debian 10 Buster DLA-3514-1 Moderate: Bouncy Castle LDAP Injection

It was discovered that there was a protential LDAP injection vulnerability in Bouncy Castle, a cryptographic library for Java. During the certificate validation process, bouncycastle used the certificate's "Subject Name" into an LDAP search filter without any . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3514-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Chris Lamb August 02, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : bouncycastle Version : 1.60-1+deb10u1 CVE ID : CVE-2023-33201 Debian Bug : 1040050 It was discovered that there was a protential LDAP injection vulnerability in Bouncy Castle, a cryptographic library for Java. During the certificate validation process, bouncycastle used the certificate's "Subject Name" into an LDAP search filter without any escaping. For Debian 10 buster, this problem has been fixed in version 1.60-1+deb10u1. We recommend that you upgrade your bouncycastle packages. For the detailed security status of bouncycastle please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/bouncycastle Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Debian LTS security notice for Bouncy Castle highlights a vulnerability related to LDAP injection and advises users to upgrade their packages accordingly.. Bouncy Castle, LDAP Injection, Debian Advisory, Cryptographic Library. . LinuxSecurity.com Team

Calendar%202 Aug 02, 2023 Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200