Explore top 10 tips to secure your open-source projects now. Read More
×Security update. Publication date: 18 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0259.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-6039, CVE-2026-6040, CVE-2026-6045, CVE-2026-8356, CVE-2026-8357, CVE-2026-8358 Description: The updated packages fix security vulnerabilities: Heap buffer overflow in DXF polyline import. (CVE-2026-6039) Heap use-after-free in ODF number-format blank-width parsing. (CVE-2026-6040) Heap buffer overflow in EMF+ gradient brush import. (CVE-2026-6045) Stack buffer overflow in PPT presentation import. (CVE-2026-8356) Heap buffer overflow in Calc formula compilation. (CVE-2026-8357) Heap buffer overflow in spreadsheet tracked-changes import. (CVE-2026-8358) References: - https://bugs.mageia.org/show_bug.cgi?id=35709 - https://lists.debian.org/debian-security-announce/2026/msg00257.html - https://www.libreoffice.org/security/ - https://www.cve.org/CVERecord?id=CVE-2026-6039 - https://www.cve.org/CVERecord?id=CVE-2026-6040 - https://www.cve.org/CVERecord?id=CVE-2026-6045 - https://www.cve.org/CVERecord?id=CVE-2026-8356 - https://www.cve.org/CVERecord?id=CVE-2026-8357 - https://www.cve.org/CVERecord?id=CVE-2026-8358 SRPMS: - 10/core/libreoffice-26.2.4.2-1.mga10 - 9/core/libreoffice-24.2.7.2-1.5.mga9 . Fixes important security issues in LibreOffice for Mageia 10 and 9, addressing various heap buffer overflows.. Mageia LibreOffice security buffer overflow important update. . Severity: Important. LinuxSecurity.com Team
Cumulative bug-fix update, including several buffer overflow fixes.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-75a8969e55 2026-07-18 00:27:50.464547+00:00 -------------------------------------------------------------------------------- Name : proftpd Product : Fedora 43 Version : 1.3.9c Release : 1.fc43 URL : http://www.proftpd.org/ Summary : Flexible, stable and highly-configurable FTP server Description : ProFTPD is an enhanced FTP server with a focus toward simplicity, security, and ease of configuration. It features a very Apache-like configuration syntax, and a highly customizable server infrastructure, including support for multiple 'virtual' FTP servers, anonymous FTP, and permission-based directory visibility. This package defaults to the standalone behavior of ProFTPD, but all the needed scripts to have it run by systemd instead are included. -------------------------------------------------------------------------------- Update Information: Cumulative bug-fix update, including several buffer overflow fixes. -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 8 2026 Paul Howarth - 1.3.9c-1 - Update to 1.3.9c - ExecEnviron values not passed due to regression since 1.3.8.d (GH#2135) - Stack buffer overflow in MLSD/MLST handling for long path names (GH#2146) - MaxTransfersPerUser no longer enforces configured limits (GH#2158) - AdminControlsACLs for config, get actions not honored as they should be (GH#2163) - Memcached/Redis-cached JSON TLS session/OCSP entries decoded into fixed buffers without bounds checking (GH#2166) - RewriteMap unescape builtin use causes one-byte out-of-bounds write, fails to reject illegal characters (GH#2173) - SQL group name lookup concatenates client-provided group names without escaping (GH#2188) - Authenticated SFTP sessions can overflowthe SFTP packet buffer (GH#2190) - Default Controls socket ACLs unintentionally allow all users access for sending Controls requests (GH#2210) * Fri Jun 12 2026 Yaakov Selkowitz - 1.3.9b-2 - Rebuilt for openssl 4.0 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-75a8969e55' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Cumulative bug-fix update, including several buffer overflow fixes.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-2f95481529 2026-07-18 00:26:14.272998+00:00 -------------------------------------------------------------------------------- Name : proftpd Product : Fedora 44 Version : 1.3.9c Release : 1.fc44 URL : http://www.proftpd.org/ Summary : Flexible, stable and highly-configurable FTP server Description : ProFTPD is an enhanced FTP server with a focus toward simplicity, security, and ease of configuration. It features a very Apache-like configuration syntax, and a highly customizable server infrastructure, including support for multiple 'virtual' FTP servers, anonymous FTP, and permission-based directory visibility. This package defaults to the standalone behavior of ProFTPD, but all the needed scripts to have it run by systemd instead are included. -------------------------------------------------------------------------------- Update Information: Cumulative bug-fix update, including several buffer overflow fixes. -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 8 2026 Paul Howarth - 1.3.9c-1 - Update to 1.3.9c - ExecEnviron values not passed due to regression since 1.3.8.d (GH#2135) - Stack buffer overflow in MLSD/MLST handling for long path names (GH#2146) - MaxTransfersPerUser no longer enforces configured limits (GH#2158) - AdminControlsACLs for config, get actions not honored as they should be (GH#2163) - Memcached/Redis-cached JSON TLS session/OCSP entries decoded into fixed buffers without bounds checking (GH#2166) - RewriteMap unescape builtin use causes one-byte out-of-bounds write, fails to reject illegal characters (GH#2173) - SQL group name lookup concatenates client-provided group names without escaping (GH#2188) - Authenticated SFTP sessions can overflowthe SFTP packet buffer (GH#2190) - Default Controls socket ACLs unintentionally allow all users access for sending Controls requests (GH#2210) * Fri Jun 12 2026 Yaakov Selkowitz - 1.3.9b-2 - Rebuilt for openssl 4.0 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2f95481529' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability can now be installed.. # Security update for libxml2 Announcement ID: SUSE-SU-2026:3095-1 Release Date: 2026-07-17T11:38:38Z Rating: important References: * bsc#1269790 Cross-References: * CVE-2026-11979 CVSS scores: * CVE-2026-11979 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-11979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11979 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability can now be installed. ## Description: This update for libxml2 fixes the following issue * CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3095=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3095=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3095=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3095=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3095=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3095=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3095=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3095=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3095=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libxml2-devel-2.9.14-150400.5.58.1 * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * python311-libxml2-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * python311-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libxml2-2-32bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-32bit-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-python-debugsource-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 *libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-python-debugsource-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libxml2-devel-2.9.14-150400.5.58.1 * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * python311-libxml2-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-python-debugsource-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * python311-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libxml2-2-64bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-64bit-2.9.14-150400.5.58.1 * libxml2-devel-64bit-2.9.14-150400.5.58.1 * openSUSE Leap 15.4 (noarch) * libxml2-doc-2.9.14-150400.5.58.1 * openSUSE Leap 15.4 (x86_64) * libxml2-2-32bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-32bit-2.9.14-150400.5.58.1 * libxml2-devel-32bit-2.9.14-150400.5.58.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libxml2-devel-2.9.14-150400.5.58.1 * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * python311-libxml2-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * python311-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libxml2-2-32bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-32bit-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Server for SAPApplications 15 SP4 (ppc64le x86_64) * libxml2-devel-2.9.14-150400.5.58.1 * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * python311-libxml2-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * python311-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libxml2-2-32bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-32bit-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-python-debugsource-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-python-debugsource-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libxml2-devel-2.9.14-150400.5.58.1 * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * python311-libxml2-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * python311-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libxml2-2-32bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-32bit-2.9.14-150400.5.58.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11979.html * https://bugzilla.suse.com/show_bug.cgi?id=1269790 . Update for openSUSE libxml2 addresses important buffer overflow issue, available for various versions.. OpenSUSE libxml2 update, Security advisory for libxml2, buffer overflow fix. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for libxml2 Announcement ID: SUSE-SU-2026:3096-1 Release Date: 2026-07-17T11:39:17Z Rating: important References: * bsc#1269790 Cross-References: * CVE-2026-11979 CVSS scores: * CVE-2026-11979 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-11979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11979 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for libxml2 fixes the following issue * CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3096=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patchSUSE-SLE-Product-SLES_SAP-15-SP5-2026-3096=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3096=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3096=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3096=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3096=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3096=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3096=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 *python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * openSUSE Leap 15.5 (x86_64) * libxml2-devel-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * openSUSE Leap 15.5 (noarch) * libxml2-doc-2.10.3-150500.5.41.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libxml2-2-64bit-debuginfo-2.10.3-150500.5.41.1 * libxml2-2-64bit-2.10.3-150500.5.41.1 * libxml2-devel-64bit-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 *libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSELinux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11979.html * https://bugzilla.suse.com/show_bug.cgi?id=1269790 . The update for libxml2 addresses a critical buffer overflow issue that poses security risks with strong recommendations for users.. openSUSE security, libxml2 update, buffer overflow, important patch. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-34109 http://linux.oracle.com/errata/ELSA-2026-34109.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: httpd-2.4.63-13.0.1.el10_2.4.x86_64.rpm httpd-core-2.4.63-13.0.1.el10_2.4.x86_64.rpm httpd-devel-2.4.63-13.0.1.el10_2.4.x86_64.rpm httpd-filesystem-2.4.63-13.0.1.el10_2.4.noarch.rpm httpd-manual-2.4.63-13.0.1.el10_2.4.noarch.rpm httpd-tools-2.4.63-13.0.1.el10_2.4.x86_64.rpm mod_ldap-2.4.63-13.0.1.el10_2.4.x86_64.rpm mod_lua-2.4.63-13.0.1.el10_2.4.x86_64.rpm mod_proxy_html-2.4.63-13.0.1.el10_2.4.x86_64.rpm mod_session-2.4.63-13.0.1.el10_2.4.x86_64.rpm mod_ssl-2.4.63-13.0.1.el10_2.4.x86_64.rpm aarch64: httpd-2.4.63-13.0.1.el10_2.4.aarch64.rpm httpd-core-2.4.63-13.0.1.el10_2.4.aarch64.rpm httpd-devel-2.4.63-13.0.1.el10_2.4.aarch64.rpm httpd-filesystem-2.4.63-13.0.1.el10_2.4.noarch.rpm httpd-manual-2.4.63-13.0.1.el10_2.4.noarch.rpm httpd-tools-2.4.63-13.0.1.el10_2.4.aarch64.rpm mod_ldap-2.4.63-13.0.1.el10_2.4.aarch64.rpm mod_lua-2.4.63-13.0.1.el10_2.4.aarch64.rpm mod_proxy_html-2.4.63-13.0.1.el10_2.4.aarch64.rpm mod_session-2.4.63-13.0.1.el10_2.4.aarch64.rpm mod_ssl-2.4.63-13.0.1.el10_2.4.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/httpd-2.4.63-13.0.1.el10_2.4.src.rpm Related CVEs: CVE-2024-42516 CVE-2026-29169 CVE-2026-34355 CVE-2026-34356 CVE-2026-42536 CVE-2026-44185 CVE-2026-44631 Description of changes: [2.4.63-13.0.1.el10_2.4] - Replace index.html with Oracle's index page oracle_index.html. [2.4.63-13.4] - Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356) - Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536) - Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass(CVE-2026-34355) - Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185) - Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631) - Resolves : RHEL-182581 - httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) - Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169) - Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535, CVE-2026-24072, CVE-2026-33006, CVE-2026-43951 [2.4.63-13.1] - Resolves: RHEL-173549 - httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780) - Resolves: RHEL-175065 - httpd: NULL pointer dereference can cause a child process crash (CVE-2026-33007) - Resolves: RHEL-175095 - httpd: off-by-one out-of-bounds reads in AJP getter functions (CVE-2026-33857) - Resolves: RHEL-175039 - httpd: heap-based buffer over-read due to missing null-termination check (CVE-2026-34032) - Resolves: RHEL-175050 - httpd: heap-based buffer over-read and memory disclosure in ajp_parse_data() (CVE-2026-34059) _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-33502 http://linux.oracle.com/errata/ELSA-2026-33502.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: giflib-5.2.1-25.el10_2.x86_64.rpm giflib-devel-5.2.1-25.el10_2.x86_64.rpm aarch64: giflib-5.2.1-25.el10_2.aarch64.rpm giflib-devel-5.2.1-25.el10_2.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/giflib-5.2.1-25.el10_2.src.rpm Related CVEs: CVE-2026-26740 Description of changes: [5.2.1-25] - fix CVE-2026-26740: buffer overflow in EGifGCBToExtension (RHEL-157086) [5.2.1-24] - rebuild [5.2.1-23] - fix CVE-2026-23868: double free in GifMakeSavedImage (RHEL-154850) _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-25930 http://linux.oracle.com/errata/ELSA-2026-25930.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: postfix-3.8.5-10.el10_2.x86_64.rpm postfix-cdb-3.8.5-10.el10_2.x86_64.rpm postfix-ldap-3.8.5-10.el10_2.x86_64.rpm postfix-lmdb-3.8.5-10.el10_2.x86_64.rpm postfix-mysql-3.8.5-10.el10_2.x86_64.rpm postfix-pcre-3.8.5-10.el10_2.x86_64.rpm postfix-perl-scripts-3.8.5-10.el10_2.x86_64.rpm postfix-pgsql-3.8.5-10.el10_2.x86_64.rpm postfix-sqlite-3.8.5-10.el10_2.x86_64.rpm aarch64: postfix-3.8.5-10.el10_2.aarch64.rpm postfix-cdb-3.8.5-10.el10_2.aarch64.rpm postfix-ldap-3.8.5-10.el10_2.aarch64.rpm postfix-lmdb-3.8.5-10.el10_2.aarch64.rpm postfix-mysql-3.8.5-10.el10_2.aarch64.rpm postfix-pcre-3.8.5-10.el10_2.aarch64.rpm postfix-perl-scripts-3.8.5-10.el10_2.aarch64.rpm postfix-pgsql-3.8.5-10.el10_2.aarch64.rpm postfix-sqlite-3.8.5-10.el10_2.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/postfix-3.8.5-10.el10_2.src.rpm Related CVEs: CVE-2026-43964 Description of changes: [2:3.8.5-10] - Fix for CVE-2026-43964: buffer over-read via malformed enhanced status code. Resolves: RHEL-176554 _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.