Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 214 articles for you...
172

Ubuntu 26.04 OpenVPN Critical Security Issues CVE-2026-11771

Several security issues were fixed in OpenVPN.. ========================================================================== Ubuntu Security Notice USN-8540-1 July 14, 2026 openvpn vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in OpenVPN. Software Description: - openvpn: virtual private network software Details: It was discovered that OpenVPN had a 1-byte buffer overrun when handling NTLMv2 proxy responses. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-11771) It was discovered that OpenVPN incorrectly handled metadata when extracting tls-crypt-v2 client keys. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-12932) It was discovered that OpenVPN had a use-after-free in the ack_write_buf handling. An attacker could use this issue to cause OpenVPN to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-12996) It was discovered that OpenVPN had a use-after-free in the tls_wrap_reneg handling. An attacker could use this issue to cause OpenVPN to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-13117) It was discovered that OpenVPN incorrectly validated authentication tokens when external authentication was enabled. A remote attacker could possibly use this issue to cause OpenVPN to crash, resulting in a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-13122) It was discovered that OpenVPN had a memory leak when handling tls-crypt-v2 client keys. A remote attacker with a valid tls-crypt-v2 client key could possibly use this issue to cause OpenVPN to consumeexcessive resources, leading to a denial of service. (CVE-2026-13698) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS openvpn 2.7.0-1ubuntu1.2 Ubuntu 24.04 LTS openvpn 2.6.19-0ubuntu0.24.04.3 Ubuntu 22.04 LTS openvpn 2.5.11-0ubuntu0.22.04.4 After a standard system update you need to restart OpenVPN to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8540-1 CVE-2026-11771, CVE-2026-12932, CVE-2026-12996, CVE-2026-13117, CVE-2026-13122, CVE-2026-13698 Package Information: https://launchpad.net/ubuntu/+source/openvpn/2.7.0-1ubuntu1.2 https://launchpad.net/ubuntu/+source/openvpn/2.6.19-0ubuntu0.24.04.3 https://launchpad.net/ubuntu/+source/openvpn/2.5.11-0ubuntu0.22.04.4 . OpenVPN fixes critical security issues in Ubuntu with potential code execution and denial of service risks. Prompt updates are advisable.. OpenVPN security update, Ubuntu vulnerability fix, critical advisory 2026, denial of service risk. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 14, 2026 Critical Ubuntu
100

openSUSE postgresql18 Important Security Update SUSE-SU-2026-1944-1

An update that solves 11 vulnerabilities, contains one feature and has one security fix can now be installed.. # Security update for postgresql18 Announcement ID: SUSE-SU-2026:1944-1 Release Date: 2026-05-18T07:47:51Z Rating: important References: * bsc#1263804 * bsc#1265172 * bsc#1265173 * bsc#1265174 * bsc#1265175 * bsc#1265176 * bsc#1265177 * bsc#1265178 * bsc#1265179 * bsc#1265180 * bsc#1265181 * bsc#1265182 * jsc#PED-14820 Cross-References: * CVE-2026-6472 * CVE-2026-6473 * CVE-2026-6474 * CVE-2026-6475 * CVE-2026-6476 * CVE-2026-6477 * CVE-2026-6478 * CVE-2026-6479 * CVE-2026-6575 * CVE-2026-6637 * CVE-2026-6638 CVSS scores: * CVE-2026-6472 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6472 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6473 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6473 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6474 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6474 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6475 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6475 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6476 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6476 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6477 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6477 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6478 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6478 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6479 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6479 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6575 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6575 (NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6637 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6637 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6638 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-6638 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 11 vulnerabilities, contains one feature and has one security fix can now be installed. ## Description: This update for postgresql18 fixes the following issues Update to version 18.4. Security issues: * CVE-2026-6472: ensure the user has CREATE privilege on the schema specified (bsc#1265172). * CVE-2026-6473: integer overflows in memory-allocation calculations (bsc#1265173). * CVE-2026-6474: Guard against malicious time zone names (bsc#1265174). * CVE-2026-6475: Prevent path traversal in pg_basebackup and pg_rewind (bsc#1265175). * CVE-2026-6476: Properly quote subscription names in pg_createsubscriber (bsc#1265176). * CVE-2026-6477: Mark PQfn() as unsafe, and avoid using it within libpq (bsc#1265177). * CVE-2026-6478: Use timing-safe string comparisons in authentication code (bsc#1265178). * CVE-2026-6479: Prevent unbounded recursion while processing startup packets (bsc#1265179). * CVE-2026-6575: Detect faulty input when restoring attribute MCV statistics (bsc#1265180). * CVE-2026-6637: Prevent SQL injection and buffer overruns in contrib/spi (bsc#1265181). * CVE-2026-6638: Properly quoteobject names in logical replication origin checks (bsc#1265182). Non security issue: * Get rid of update-alternatives for openSUSE/SLE 16.0 and newer to support immutable systems and transactional updates (jsc#PED-14820). * /usr/bin/pg_config is missing after migrating away from update-alternatives (bsc#1263804). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1944=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-1944=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1944=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1944=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-1944=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-1944=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * postgresql18-pltcl-18.4-150600.13.11.1 * postgresql18-18.4-150600.13.11.1 * postgresql18-devel-mini-debuginfo-18.4-150600.13.11.1 * postgresql18-plpython-18.4-150600.13.11.1 * postgresql18-llvmjit-18.4-150600.13.11.1 * postgresql18-server-devel-18.4-150600.13.11.1 * postgresql18-contrib-debuginfo-18.4-150600.13.11.1 * postgresql18-devel-debuginfo-18.4-150600.13.11.1 * postgresql18-plperl-18.4-150600.13.11.1 * postgresql18-mini-debugsource-18.4-150600.13.11.1 * libecpg6-18.4-150600.13.11.1 * postgresql18-llvmjit-devel-18.4-150600.13.11.1 * postgresql18-devel-18.4-150600.13.11.1 * postgresql18-contrib-18.4-150600.13.11.1 * postgresql18-test-18.4-150600.13.11.1 *postgresql18-plperl-debuginfo-18.4-150600.13.11.1 * postgresql18-server-debuginfo-18.4-150600.13.11.1 * libpq5-18.4-150600.13.11.1 * postgresql18-devel-mini-18.4-150600.13.11.1 * postgresql18-plpython-debuginfo-18.4-150600.13.11.1 * postgresql18-pltcl-debuginfo-18.4-150600.13.11.1 * postgresql18-debuginfo-18.4-150600.13.11.1 * postgresql18-server-18.4-150600.13.11.1 * libecpg6-debuginfo-18.4-150600.13.11.1 * postgresql18-server-devel-debuginfo-18.4-150600.13.11.1 * libpq5-debuginfo-18.4-150600.13.11.1 * postgresql18-debugsource-18.4-150600.13.11.1 * postgresql18-llvmjit-debuginfo-18.4-150600.13.11.1 * openSUSE Leap 15.6 (x86_64) * libpq5-32bit-18.4-150600.13.11.1 * libpq5-32bit-debuginfo-18.4-150600.13.11.1 * libecpg6-32bit-18.4-150600.13.11.1 * libecpg6-32bit-debuginfo-18.4-150600.13.11.1 * openSUSE Leap 15.6 (noarch) * postgresql18-docs-18.4-150600.13.11.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libecpg6-64bit-18.4-150600.13.11.1 * libpq5-64bit-debuginfo-18.4-150600.13.11.1 * libecpg6-64bit-debuginfo-18.4-150600.13.11.1 * libpq5-64bit-18.4-150600.13.11.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libecpg6-debuginfo-18.4-150600.13.11.1 * postgresql18-devel-debuginfo-18.4-150600.13.11.1 * postgresql18-server-devel-debuginfo-18.4-150600.13.11.1 * postgresql18-server-18.4-150600.13.11.1 * postgresql18-plperl-18.4-150600.13.11.1 * postgresql18-server-debuginfo-18.4-150600.13.11.1 * postgresql18-pltcl-18.4-150600.13.11.1 * postgresql18-debugsource-18.4-150600.13.11.1 * postgresql18-contrib-debuginfo-18.4-150600.13.11.1 * postgresql18-plpython-debuginfo-18.4-150600.13.11.1 * postgresql18-debuginfo-18.4-150600.13.11.1 * postgresql18-pltcl-debuginfo-18.4-150600.13.11.1 * libecpg6-18.4-150600.13.11.1 * postgresql18-devel-18.4-150600.13.11.1 * postgresql18-plpython-18.4-150600.13.11.1 * postgresql18-contrib-18.4-150600.13.11.1 *postgresql18-server-devel-18.4-150600.13.11.1 * postgresql18-plperl-debuginfo-18.4-150600.13.11.1 * Server Applications Module 15-SP7 (noarch) * postgresql18-docs-18.4-150600.13.11.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * postgresql18-pltcl-18.4-150600.13.11.1 * postgresql18-18.4-150600.13.11.1 * postgresql18-plpython-18.4-150600.13.11.1 * postgresql18-server-devel-18.4-150600.13.11.1 * postgresql18-contrib-debuginfo-18.4-150600.13.11.1 * postgresql18-devel-debuginfo-18.4-150600.13.11.1 * postgresql18-plperl-18.4-150600.13.11.1 * libecpg6-18.4-150600.13.11.1 * postgresql18-devel-18.4-150600.13.11.1 * postgresql18-contrib-18.4-150600.13.11.1 * postgresql18-plperl-debuginfo-18.4-150600.13.11.1 * postgresql18-server-debuginfo-18.4-150600.13.11.1 * libpq5-18.4-150600.13.11.1 * postgresql18-plpython-debuginfo-18.4-150600.13.11.1 * postgresql18-pltcl-debuginfo-18.4-150600.13.11.1 * postgresql18-debuginfo-18.4-150600.13.11.1 * postgresql18-server-18.4-150600.13.11.1 * libecpg6-debuginfo-18.4-150600.13.11.1 * postgresql18-server-devel-debuginfo-18.4-150600.13.11.1 * libpq5-debuginfo-18.4-150600.13.11.1 * postgresql18-debugsource-18.4-150600.13.11.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * postgresql18-docs-18.4-150600.13.11.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libpq5-32bit-18.4-150600.13.11.1 * libpq5-32bit-debuginfo-18.4-150600.13.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * postgresql18-pltcl-18.4-150600.13.11.1 * postgresql18-18.4-150600.13.11.1 * postgresql18-plpython-18.4-150600.13.11.1 * postgresql18-server-devel-18.4-150600.13.11.1 * postgresql18-contrib-debuginfo-18.4-150600.13.11.1 * postgresql18-devel-debuginfo-18.4-150600.13.11.1 * postgresql18-plperl-18.4-150600.13.11.1 * libecpg6-18.4-150600.13.11.1 * postgresql18-devel-18.4-150600.13.11.1 *postgresql18-contrib-18.4-150600.13.11.1 * postgresql18-plperl-debuginfo-18.4-150600.13.11.1 * postgresql18-server-debuginfo-18.4-150600.13.11.1 * libpq5-18.4-150600.13.11.1 * postgresql18-plpython-debuginfo-18.4-150600.13.11.1 * postgresql18-pltcl-debuginfo-18.4-150600.13.11.1 * postgresql18-debuginfo-18.4-150600.13.11.1 * postgresql18-server-18.4-150600.13.11.1 * libecpg6-debuginfo-18.4-150600.13.11.1 * postgresql18-server-devel-debuginfo-18.4-150600.13.11.1 * libpq5-debuginfo-18.4-150600.13.11.1 * postgresql18-debugsource-18.4-150600.13.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * postgresql18-docs-18.4-150600.13.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libpq5-32bit-18.4-150600.13.11.1 * libpq5-32bit-debuginfo-18.4-150600.13.11.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libpq5-debuginfo-18.4-150600.13.11.1 * postgresql18-debugsource-18.4-150600.13.11.1 * libpq5-18.4-150600.13.11.1 * postgresql18-18.4-150600.13.11.1 * postgresql18-debuginfo-18.4-150600.13.11.1 * Basesystem Module 15-SP7 (x86_64) * libpq5-32bit-18.4-150600.13.11.1 * libpq5-32bit-debuginfo-18.4-150600.13.11.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * postgresql18-llvmjit-debuginfo-18.4-150600.13.11.1 * postgresql18-llvmjit-devel-18.4-150600.13.11.1 * postgresql18-llvmjit-18.4-150600.13.11.1 * postgresql18-test-18.4-150600.13.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6472.html * https://www.suse.com/security/cve/CVE-2026-6473.html * https://www.suse.com/security/cve/CVE-2026-6474.html * https://www.suse.com/security/cve/CVE-2026-6475.html * https://www.suse.com/security/cve/CVE-2026-6476.html * https://www.suse.com/security/cve/CVE-2026-6477.html * https://www.suse.com/security/cve/CVE-2026-6478.html * https://www.suse.com/security/cve/CVE-2026-6479.html *https://www.suse.com/security/cve/CVE-2026-6575.html * https://www.suse.com/security/cve/CVE-2026-6637.html * https://www.suse.com/security/cve/CVE-2026-6638.html * https://bugzilla.suse.com/show_bug.cgi?id=1263804 * https://bugzilla.suse.com/show_bug.cgi?id=1265172 * https://bugzilla.suse.com/show_bug.cgi?id=1265173 * https://bugzilla.suse.com/show_bug.cgi?id=1265174 * https://bugzilla.suse.com/show_bug.cgi?id=1265175 * https://bugzilla.suse.com/show_bug.cgi?id=1265176 * https://bugzilla.suse.com/show_bug.cgi?id=1265177 * https://bugzilla.suse.com/show_bug.cgi?id=1265178 * https://bugzilla.suse.com/show_bug.cgi?id=1265179 * https://bugzilla.suse.com/show_bug.cgi?id=1265180 * https://bugzilla.suse.com/show_bug.cgi?id=1265181 * https://bugzilla.suse.com/show_bug.cgi?id=1265182 * https://jira.suse.com/browse/PED-14820 . SUSE introduces important security update for postgresql18, fixing multiple issues including SQL injection vulnerabilities.. SUSE, PostgreSQL, Security Update, openSUSE, Vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 18, 2026 Important SuSE
202

openSUSE Leap 16.0 Radare2 Critical Threat Advisory 2026-20653-1

An update that solves 6 vulnerabilities and has 6 bug fixes can now be installed.. openSUSE security update: security update for radare2 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20653-1 Rating: critical References: * bsc#1234065 * bsc#1237250 * bsc#1238075 * bsc#1238451 * bsc#1244121 * bsc#1262142 Cross-References: * CVE-2024-29645 * CVE-2025-1378 * CVE-2025-1744 * CVE-2025-1864 * CVE-2025-5641 * CVE-2026-40499 CVSS scores: * CVE-2025-1378 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-1378 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-1744 ( SUSE ): 10 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2025-1744 ( SUSE ): 10 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-5641 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-5641 ( SUSE ): 2 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 6 vulnerabilities and has 6 bug fixes can now be installed. Description: This update for radare2 fixes the following issues: Changes in radare2: - Update to version 6.1.4 (bsc#1262142, CVE-2026-40499): * Analysis: improve autoname scoring, jmptbl detection, and performance * Add callargs modifier, rnum expressions, and typed function context * Refactor autoname into plugin; extend RAnalPlugin hooks * Fix leaks, overflows, and command injection in analysis scripts * Improve string detection, wide strings, and switch/case analysis * Arch: fix v850/nds32 ESIL, optimize to O(1), improve pseudo support * Cache capstone options and improve multi-arch disassembly * ASM: add camel syntax support, unify via RArch API * Bin: major parser fixes(ELF, Mach-O, PE, DEX, PDB, WAD, XCOFF) * Fix leaks, OOB reads/writes, overflows, and improve bounds checks * Improve Swift demangling, ARM hints, relocations, and imports * Add nds32 reloc support and optimize kernelcache parsing * Build: install to lib64, fix illumos and packaging issues * CI: add GitHub Actions and FilC builds * Console: fix multiple overflows, OOB issues, and improve performance * Core: API renames, plugin load order, sandbox/config fixes * Crash: extensive fixes (UAF, OOB, overflows, injections, fuzz bugs) * Harden ELF, PDB, kernelcache, regex, disassemblers, and webserver * Debug: improve ptrace, winkd support, breakpoints, checkpoints * Disasm: cache flag lookups for performance * FS/IO: fix leaks, bounds, sparse IO, and device handling * HTTP/socket: webserver fixes and SSL fallback handling * Print/projects: improve formatting, endian handling, project metadata * Pseudo: add while/switch support and cleaner control flow * Search/shell: improve commands, parsing, and usability * Security: fix widespread command injection and sandbox escapes * Tests/tools: improve r2r, CLI tools, fuzzing, and plugin support * Types/util: parsing improvements, JSON/base64 updates, optimizations * Visual: fix UAF/leaks, improve panels and UX * Full changelog is available at: https://github.com/radareorg/radare2/releases/tag/6.1.4 - Update to version 6.1.2: * Analysis: preserve timeouts, improve bb/jmptbl validation and limits * Optimize string detection and hot-path functions * Add APIs for function signatures, vars limits, and instruction hints * Fix overlapped functions, invalid code checks, and large bb handling * API: remove deprecated librmagic/filetype APIs and name filter * Arch: fix Thumb/endianness issues, add Python pseudo plugin * ASM: unify settings via RArch, fix directives, add bf pseudo plugin * Bin: improve ELF/Mach-O stripped detection and parsing safety * Harden Mach-O bounds, optimize kernelcache and XNU parsing * Fix manyleaks (DEX, demangler, parsers) and infinite loops * Improve DWARF handling and symbol/type extraction * Build: improve meson, toolchains, and add ISO/docker support * Console: preserve timeout, fix themes and UTF-8 handling * Core: fix config bugs, improve startup and addressing support * Crash: fix UAF, OOB, race conditions, regex bugs, and overflows * Add safety checks across dotnet, Mach-O, DWARF, and webserver * Debug/ESIL: safer execution and divide-by-zero handling * FS/IO: fix HFS+, dyldcache speedups, safer zip handling * Graph: add bb size limit option * Print: merge commands, improve UTF-8 and formatting * Projects/tools: new configs, plugin support, CLI improvements * Search: faster analysis search and block buffering * Shell: improve grep/macros and file operations * Types: lazy-load, cache, and improve parsing (varargs, structs) * Tests: expand fuzzing and test suites * General cleanup, performance tuning, and safety improvements * Full changelog is available at: https://github.com/radareorg/radare2/releases/tag/6.1.4 - Update to version 6.1.0: * Reimplement RBufRef using RRef; fix RLibDelHandler API * Remove stale JAY code; improve analysis performance and CI speed * Optimize type propagation, jump tables, and plugin integration * Fix infinite loops, antidisasm tricks, and function autonaming * Add new analysis options and trace import plugin (DRCOV) * Improve RCore seek operations and naming APIs * API: add RNum.getErr, enforce safe alloc macros, new helpers * Arch: update ARC disasm, refactor sessions, remove unsafe string ops * ASM: improve x86 validation, add CIL and ARC pseudo plugins * Bin: major fixes for PE, ELF, Java, MDMP, LE, DEX; reduce memory use * Add/import DWARF types, improve relocations and symbol handling * Extensive memory leak fixes and parser hardening across formats * Improve string handling, caching, and zero-copy optimizations * Build: improve meson, remove zip deps, add 3rd-party plugin support *Console: fix UTF-8 graphs and color propagation * Core: improve plugin handling and background task stability * Crash: fix multiple UAF, OOB, overflows, and injection issues * Sanitize inputs (function names, demangler, callconv) * Debug: add source breakpoints, ARM64/XNU support, FPU regs * Disasm: improve string handling, comments, and color logic * ESIL: extend x86 FPU emulation * FS/IO: fixes and plugin reorganizations * HTTP: fix sandbox webserver issues * Hash/tools: minor fixes and output improvements * General cleanup, safety checks, and performance optimizations * Full changelog is available at: https://github.com/radareorg/radare2/releases/tag/6.1.0 - Update to version 6.0.8: * Migrate r_vector to RVec across core components * Refactor and optimize type propagation (now plugin-based) * Remove redundant anal.a2f and related duplication * Improve caching, memoization, and performance in analysis * Fix file corruption, null asserts, and command issues * Enhance x86 (AT&T syntax, enter instruction) and z80 support * Add initial .NET (CIL) disasm/asm support * Improve Java, ELF, Mach-O, APK, and PDB handling * Fix demangling, symbols, and relocation issues * Resolve multiple memory leaks and parser bugs * Fix UAF, OOB, overflows, and command injection vulnerabilities * Improve GDB debugging and breakpoint handling * Enhance disassembly visuals and color options * Update ESIL operators and behavior * Add support for APFS, GPT, BSD, APM partitions * Improve IO handling and add new plugins * Optimize performance (strbuf, memory usage) * Improve console UI, themes, and terminal handling * Refine SDK builds and CI pipelines * Improve CLI tools (rabin2, rasm2, rafs2) * Add JSON support and better help/version info * Expand type parsing (typedef, enum, union) * Improve socket/HTTP handling and downloads * Add and refine tests and reporting * General cleanup, safety checks, and code modernization * Full changelog is available at: https://github.com/radareorg/radare2/releases/tag/6.0.8 - Update to version 6.0.7: * shell: Fix parsing r2 -H$(VARNAME) without a space - Update to version 6.0.6: * Full changelog is available at: https://github.com/radareorg/radare2/releases/tag/6.0.6 - Update to version 6.0.4: * Full changelog is available at: https://github.com/radareorg/radare2/releases/tag/6.0.4 - Update to version 6.0.2: * Full changelog is available at: https://github.com/radareorg/radare2/releases/tag/6.0.2 - Update to version 6.0.0: * ABI changes: ~ RCorePlugins now have a session ~ Finish the RKons refactoring, all r_cons calls take instance instead of global ~ Rename RCrypto to RMuta ~ Use RCons instance from RLine ~ Rename RIOPlugin.widget to RIOPlugin.data ~ Refactor the RRegAlias api ~ Camelcase all the RCoreBind methods * Breaking API changes: ~ Boolify r_cons_rgb_parse ~ Add RLogLevel.fromString() and use it from -e log.level=? ~ Deprecate r_bin_addr2line ~ Rename RBinDbgItem into RBinAddrline ~ RNumCalc is now known as RNumMath ~ Move RFlagItem.alias into the Meta ~ Rename core-> offset into core-> addr (asm.offset and more!) ~ Rename RFlagItem.offset -> addr * API changes: ~ Boolify r_cons_rgb_parse ~ Add RLogLevel.fromString() and use it from -e log.level=? ~ Deprecate r_bin_addr2line ~ Rename RBinDbgItem into RBinAddrline ~ RNumCalc is now known as RNumMath ~ Move RFlagItem.alias into the Meta ~ Rename core-> offset into core-> addr (asm.offset and more!) ~ Rename RFlagItem.offset -> addr ~ Deprecate RLang.list() ~ Unified function to jsonify the plugin meta + more fields ~ Redesign the REvent API * Full changelog is available at: https://github.com/radareorg/radare2/releases/tag/6.0.0 - CVE-2025-5641: Fix memory corruption by manipulation of the argument -T (bsc#1244121) - CVE-2025-1864: Fix buffer overflow and potential code execution (bsc#bsc#1238451) - CVE-2025-1744: Fixheap-based buffer over-read or buffer overflow (bsc#1238075) - CVE-2025-1378: Fix memory corruption (bsc#1237250) - Update to version 5.9.8: * Resolved CVE: - CVE-2024-29645: buffer overflow vulnerability allows an attacker to execute arbitrary code via the parse_die function (boo#1234065). For details, check full release notes: https://github.com/radareorg/radare2/releases/tag/5.9.8 https://github.com/radareorg/radare2/releases/tag/5.9.6 https://github.com/radareorg/radare2/releases/tag/5.9.4 https://github.com/radareorg/radare2/releases/tag/5.9.2 https://github.com/radareorg/radare2/releases/tag/5.9.0 Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-224=1 Package List: - openSUSE Leap 16.0: libsdb2_4_2-6.1.4-bp160.1.1 radare2-6.1.4-bp160.1.1 radare2-devel-6.1.4-bp160.1.1 radare2-zsh-completion-6.1.4-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2024-29645.html * https://www.suse.com/security/cve/CVE-2025-1378.html * https://www.suse.com/security/cve/CVE-2025-1744.html * https://www.suse.com/security/cve/CVE-2025-1864.html * https://www.suse.com/security/cve/CVE-2025-5641.html * https://www.suse.com/security/cve/CVE-2026-40499.html . OpenSUSE security update addressing 6 flaws in radare2, with critical improvements and bug fixes for enhanced safety.. opensuse update, radare2 security, critical vulnerabilities, opensuse patch, security fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 30, 2026 Critical OpenSUSE
219

Ubuntu Server 20.04 USN-2023-5678 python Security Advisory CVE

Moderate: ruby:2.5 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:7025", "synopsis": "Moderate: ruby:2.5 security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for rubygem-bson, module.rubygem-bundler, rubygem-bundler, rubygem-abrt, module.rubygem-mongo, module.rubygem-pg, rubygem-mysql2, module.rubygem-mysql2, ruby, module.rubygem-abrt, module.rubygem-bson, rubygem-pg, module.ruby, rubygem-mongo.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.\n\nSecurity Fix(es):\n\n* ruby/cgi-gem: HTTP response splitting in CGI (CVE-2021-33621)\n\n* ruby: Buffer overrun in String-to-Float conversion (CVE-2022-28739)\n\n* ruby: ReDoS vulnerability in URI (CVE-2023-28755)\n\n* ruby: ReDoS vulnerability in Time (CVE-2023-28756)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Rocky Linux 8.9 Release Notes linked from the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2075687", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2075687", "description": ""}, {"ticket": "2149706", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2149706", "description": ""}, {"ticket": "2184059", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2184059", "description": ""}, {"ticket": "2184061", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2184061", "description": ""}],"cves": [{"name": "CVE-2021-33621", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2021-33621", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-113"}, {"name": "CVE-2022-28739", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-28739", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "6.2", "cwe": "CWE-125"}, {"name": "CVE-2023-28755", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-28755", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "cvss3BaseScore": "5.3", "cwe": "CWE-20"}, {"name": "CVE-2023-28756", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-28756", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "cvss3BaseScore": "5.3", "cwe": "CWE-20"}], "references": [], "publishedAt": "2026-04-14T18:01:10.838937Z", "rpms": {"Rocky Linux 8": {"nvras": ["rubygem-mongo-0:2.5.1-2.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-mongo-0:2.5.1-2.module+el8.9.0+1536+5f79634e.src.rpm", "rubygem-mongo-doc-0:2.5.1-2.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-mysql2-0:0.4.10-4.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-mysql2-0:0.4.10-4.module+el8.9.0+1536+5f79634e.src.rpm", "ruby-0:2.5.9-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "ruby-0:2.5.9-111.module+el8.9.0+1536+5f79634e.i686.rpm", "ruby-0:2.5.9-111.module+el8.9.0+1536+5f79634e.src.rpm", "ruby-0:2.5.9-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "ruby-debuginfo-0:2.5.9-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "ruby-debuginfo-0:2.5.9-111.module+el8.9.0+1536+5f79634e.i686.rpm", "ruby-debuginfo-0:2.5.9-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "ruby-debugsource-0:2.5.9-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "ruby-debugsource-0:2.5.9-111.module+el8.9.0+1536+5f79634e.i686.rpm", "ruby-debugsource-0:2.5.9-111.module+el8.9.0+1536+5f79634e.x86_64.rpm","ruby-devel-0:2.5.9-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "ruby-devel-0:2.5.9-111.module+el8.9.0+1536+5f79634e.i686.rpm", "ruby-devel-0:2.5.9-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "ruby-doc-0:2.5.9-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-abrt-0:0.3.0-4.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-abrt-0:0.3.0-4.module+el8.5.0+738+032c9c02.noarch.rpm", "rubygem-abrt-0:0.3.0-4.module+el8.9.0+1536+5f79634e.src.rpm", "rubygem-abrt-0:0.3.0-4.module+el8.5.0+738+032c9c02.src.rpm", "rubygem-abrt-doc-0:0.3.0-4.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-abrt-doc-0:0.3.0-4.module+el8.5.0+738+032c9c02.noarch.rpm", "rubygem-bigdecimal-0:1.3.4-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-bigdecimal-0:1.3.4-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-bigdecimal-0:1.3.4-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-bigdecimal-debuginfo-0:1.3.4-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-bigdecimal-debuginfo-0:1.3.4-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-bigdecimal-debuginfo-0:1.3.4-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-bson-0:4.3.0-2.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-bson-0:4.3.0-2.module+el8.9.0+1536+5f79634e.src.rpm", "rubygem-bson-0:4.3.0-2.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-bson-debuginfo-0:4.3.0-2.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-bson-debuginfo-0:4.3.0-2.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-bson-debugsource-0:4.3.0-2.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-bson-debugsource-0:4.3.0-2.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-bson-doc-0:4.3.0-2.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-bundler-0:1.16.1-4.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-bundler-0:1.16.1-4.module+el8.9.0+1536+5f79634e.src.rpm", "rubygem-bundler-doc-0:1.16.1-4.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-did_you_mean-0:1.2.0-111.module+el8.9.0+1536+5f79634e.noarch.rpm","rubygem-io-console-0:0.4.6-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-io-console-0:0.4.6-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-io-console-0:0.4.6-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-io-console-debuginfo-0:0.4.6-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-io-console-debuginfo-0:0.4.6-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-io-console-debuginfo-0:0.4.6-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-json-0:2.1.0-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-json-0:2.1.0-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-json-0:2.1.0-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-json-debuginfo-0:2.1.0-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-json-debuginfo-0:2.1.0-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-json-debuginfo-0:2.1.0-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-minitest-0:5.10.3-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-mysql2-0:0.4.10-4.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-mysql2-debuginfo-0:0.4.10-4.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-mysql2-debuginfo-0:0.4.10-4.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-mysql2-debugsource-0:0.4.10-4.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-mysql2-debugsource-0:0.4.10-4.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-mysql2-doc-0:0.4.10-4.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-net-telnet-0:0.1.1-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-openssl-0:2.1.2-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-openssl-0:2.1.2-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-openssl-0:2.1.2-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-openssl-debuginfo-0:2.1.2-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-openssl-debuginfo-0:2.1.2-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-openssl-debuginfo-0:2.1.2-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-pg-0:1.0.0-3.module+el8.9.0+1536+5f79634e.aarch64.rpm","rubygem-pg-0:1.0.0-3.module+el8.9.0+1536+5f79634e.src.rpm", "rubygem-pg-0:1.0.0-3.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-pg-debuginfo-0:1.0.0-3.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-pg-debuginfo-0:1.0.0-3.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-pg-debugsource-0:1.0.0-3.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-pg-debugsource-0:1.0.0-3.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-pg-doc-0:1.0.0-3.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-power_assert-0:1.1.1-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-psych-0:3.0.2-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-psych-0:3.0.2-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-psych-0:3.0.2-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-psych-debuginfo-0:3.0.2-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-psych-debuginfo-0:3.0.2-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-psych-debuginfo-0:3.0.2-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-rake-0:12.3.3-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-rdoc-0:6.0.1.1-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygems-0:2.7.6.3-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygems-devel-0:2.7.6.3-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-test-unit-0:3.2.7-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-xmlrpc-0:0.3.0-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "ruby-irb-0:2.5.9-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "ruby-libs-0:2.5.9-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "ruby-libs-0:2.5.9-111.module+el8.9.0+1536+5f79634e.i686.rpm", "ruby-libs-0:2.5.9-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "ruby-libs-debuginfo-0:2.5.9-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "ruby-libs-debuginfo-0:2.5.9-111.module+el8.9.0+1536+5f79634e.i686.rpm", "ruby-libs-debuginfo-0:2.5.9-111.module+el8.9.0+1536+5f79634e.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Moderate ruby security updates for Rocky Linux address buffer overflow and HTTPresponse splitting vulnerabilities.. Rocky Linux ruby security patch updates, buffer overflow, HTTP response vulnerability, ruby security advisory. . LinuxSecurity.com Team

Calendar%202 Apr 14, 2026 Rocky Linux
89

Fedora 44 kf5-libkdcraw Denial of Service Fix 2026-bef0050737

LibRaw 0.22.1 and rebuilds Release 3.1.12.0 (Apr 1, 2026) -- compared to 3.1.11.0 oiiotool: Better type understanding with -i:ch= and other cleanup #5056 texture: Fix texture overblur with st-blur parameters #5071 #5080 (by Pascal Lecocq) (3.1.12.0, 3.0.17.0). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-bef0050737 2026-04-13 21:06:00.498961+00:00 -------------------------------------------------------------------------------- Name : kf5-libkdcraw Product : Fedora 44 Version : 23.08.5 Release : 7.fc44 URL : https://invent.kde.org/graphics/libkdcraw Summary : A C++ interface around LibRaw library Description : Libkdcraw is a C++ interface around LibRaw library used to decode RAW picture files. More information about LibRaw can be found at http://www.libraw.org. -------------------------------------------------------------------------------- Update Information: LibRaw 0.22.1 and rebuilds Release 3.1.12.0 (Apr 1, 2026) -- compared to 3.1.11.0 oiiotool: Better type understanding with -i:ch= and other cleanup #5056 texture: Fix texture overblur with st-blur parameters #5071 #5080 (by Pascal Lecocq) (3.1.12.0, 3.0.17.0) IBA: Handle offset data windows in fillholes_pushpull #5105 (3.1.12.0, 3.0.17.0) ImageInput: check_open fixes and new validity checks #5087 (3.1.12.0, 3.0.17.0) bmp: Use check_open to guard against corrupt resolutions #5086 (3.1.12.0, 3.0.17.0) heif: Fix invalid read writing 8-bit images with dimensions not a multiple of 64 #5095 (by Brecht Van Lommel) ico: Various validity checks and error handling for corruptions #5088 (3.1.12.0, 3.0.17.0) jpeg: Improved safety and error reporting for jpeg and iptc #5081 jpeg2000: Suppress leak when reading with OpenJPH #5098 psd: Fixes against corrupt files with better validation #5089 (3.1.12.0, 3.0.17.0) rla: Lots of additional validity checking and safety #5094 (3.1.12.0, 3.0.17.0) tiff: Support GPS fields, and othermetadata enhancements #5050 tiff: Fix buffer overrun and improve error reporting #5082, fix wrong number of values passed to invert_photometric #5083, check for invalid bit depth in palette images #5091 ImageSpec: metadata_val improved safety #5096 (3.1.12.0, 3.0.17.0) fix: Fix UB-sanitizer warning about alignment #5097 fix: Catch exceptions in print-uncaught-messages destructor #5103 fix: Enhanced exception safety for our use of OpenColorIO #5114 fix: Fix possible fmt exceptions where we might have passed null string #5115 build: Test building with clang 22.1, fix warnings uncovered #5067 build: Improve security by pinning auto-build dependencies by hash #5076 build: Include idiff in the python wheels we build #5104 (3.1.12.0, 3.0.17.0) build(pybind11): Address new pybind11 float/int auto-conversion behavior #5058 build(win): Embed manifest in OIIO executables to enable long path handling #5066 (by Nathan Rusch) ci: Add CI test for MSVS 2026 #5060 (3.1.12.0, 3.0.17.0) ci: For security, replace workflow substitutions with safer env substitutions #5070 ci: Speed up slow benchmarks for debug and sanitizer CI tests #5077 ci: On Mac Intel CI variant, don't install openvdb, for speed #5065 (3.1.12.0, 3.0.17.0) ci: Bump GitHub Actions to latest versions #5078 #5110 #5119 ci: Fix broken Mac CI and wheel building by specifying full compiler paths #5100 #5101 (3.1.12.0, 3.0.17.0) ci: Update certificates to be able to install icc #5122 (3.1.12.0, 3.0.17.0) ci: Turn off nightly workflows for user forks #5042 tests: New ref outputs for tiff-misc, heif no-avif, and ffmpeg 8.1 cases #5075 #5079 #5099 #5112 docs: Update description for dwaCompressionLevel #5074 (by Aamir Raza) docs: Fix formatting examples for version macros #5073 docs: Keep TextureSystem docs in sync with ImageCache #5085 (3.1.12.0, 3.0.17.0) docs: Fix typos and incorrect attribute name in a comment #5093 (3.1.12.0, 3.0.17.0) docs: Fix misstatement about oiiotool --if #5102 (3.1.12.0, 3.0.17.0) admin: Draft policy on use ofAI coding assistants #5072 (3.1.12.0, 3.0.17.0) ci: Freetype adjustments #4999 Update to 5.1 (#2451401) Update to 5.0 (#2447841) -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 8 2026 Gwyn Ciesla - 23.08.5-7 - Libraw rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2447841 - swayimg-.5.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2447841 [ 2 ] Bug #2451401 - swayimg-5.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2451401 [ 3 ] Bug #2454235 - CVE-2026-5318 LibRaw: LibRaw: Denial of Service via out-of-bounds write in JPEG DHT Parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454235 [ 4 ] Bug #2454464 - CVE-2026-5342 LibRaw: LibRaw: Out-of-bounds read via `load_flags/raw_width` argument manipulation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454464 [ 5 ] Bug #2455346 - LibRaw-0.22.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2455346 [ 6 ] Bug #2456557 - CVE-2026-20884 LibRaw: LibRaw: Arbitrary code execution via integer overflow in deflate_dng_load_raw [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2456557 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bef0050737' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . LibRaw update in Fedora 44 addresses security issues to enhance performance and reliability in decoding RAW files.. LibRaw Security Update Fedora 44. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 13, 2026 Important Fedora
89

Fedora 44 ImageMagick Security Advisory FEDORA-2026-bef0050737

LibRaw 0.22.1 and rebuilds Release 3.1.12.0 (Apr 1, 2026) -- compared to 3.1.11.0 oiiotool: Better type understanding with -i:ch= and other cleanup #5056 texture: Fix texture overblur with st-blur parameters #5071 #5080 (by Pascal Lecocq) (3.1.12.0, 3.0.17.0). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-bef0050737 2026-04-13 21:06:00.498961+00:00 -------------------------------------------------------------------------------- Name : ImageMagick Product : Fedora 44 Version : 7.1.2.13 Release : 2.fc44 URL : https://imagemagick.org/ Summary : An X application for displaying and manipulating images Description : ImageMagick is an image display and manipulation tool for the X Window System. ImageMagick can read and write JPEG, TIFF, PNM, GIF, and Photo CD image formats. It can resize, rotate, sharpen, color reduce, or add special effects to an image, and when finished you can either save the completed work in the original format or a different one. ImageMagick also includes command line programs for creating animated or transparent .gifs, creating composite images, creating thumbnail images, and more. ImageMagick is one of your choices if you need a program to manipulate and display images. If you want to develop your own applications which use ImageMagick code or APIs, you need to install ImageMagick-devel as well. -------------------------------------------------------------------------------- Update Information: LibRaw 0.22.1 and rebuilds Release 3.1.12.0 (Apr 1, 2026) -- compared to 3.1.11.0 oiiotool: Better type understanding with -i:ch= and other cleanup #5056 texture: Fix texture overblur with st-blur parameters #5071 #5080 (by Pascal Lecocq) (3.1.12.0, 3.0.17.0) IBA: Handle offset data windows in fillholes_pushpull #5105 (3.1.12.0, 3.0.17.0) ImageInput: check_open fixes and new validity checks #5087 (3.1.12.0, 3.0.17.0) bmp: Use check_open to guard againstcorrupt resolutions #5086 (3.1.12.0, 3.0.17.0) heif: Fix invalid read writing 8-bit images with dimensions not a multiple of 64 #5095 (by Brecht Van Lommel) ico: Various validity checks and error handling for corruptions #5088 (3.1.12.0, 3.0.17.0) jpeg: Improved safety and error reporting for jpeg and iptc #5081 jpeg2000: Suppress leak when reading with OpenJPH #5098 psd: Fixes against corrupt files with better validation #5089 (3.1.12.0, 3.0.17.0) rla: Lots of additional validity checking and safety #5094 (3.1.12.0, 3.0.17.0) tiff: Support GPS fields, and other metadata enhancements #5050 tiff: Fix buffer overrun and improve error reporting #5082, fix wrong number of values passed to invert_photometric #5083, check for invalid bit depth in palette images #5091 ImageSpec: metadata_val improved safety #5096 (3.1.12.0, 3.0.17.0) fix: Fix UB-sanitizer warning about alignment #5097 fix: Catch exceptions in print-uncaught-messages destructor #5103 fix: Enhanced exception safety for our use of OpenColorIO #5114 fix: Fix possible fmt exceptions where we might have passed null string #5115 build: Test building with clang 22.1, fix warnings uncovered #5067 build: Improve security by pinning auto-build dependencies by hash #5076 build: Include idiff in the python wheels we build #5104 (3.1.12.0, 3.0.17.0) build(pybind11): Address new pybind11 float/int auto-conversion behavior #5058 build(win): Embed manifest in OIIO executables to enable long path handling #5066 (by Nathan Rusch) ci: Add CI test for MSVS 2026 #5060 (3.1.12.0, 3.0.17.0) ci: For security, replace workflow substitutions with safer env substitutions #5070 ci: Speed up slow benchmarks for debug and sanitizer CI tests #5077 ci: On Mac Intel CI variant, don't install openvdb, for speed #5065 (3.1.12.0, 3.0.17.0) ci: Bump GitHub Actions to latest versions #5078 #5110 #5119 ci: Fix broken Mac CI and wheel building by specifying full compiler paths #5100 #5101 (3.1.12.0, 3.0.17.0) ci: Update certificates to be able to install icc#5122 (3.1.12.0, 3.0.17.0) ci: Turn off nightly workflows for user forks #5042 tests: New ref outputs for tiff-misc, heif no-avif, and ffmpeg 8.1 cases #5075 #5079 #5099 #5112 docs: Update description for dwaCompressionLevel #5074 (by Aamir Raza) docs: Fix formatting examples for version macros #5073 docs: Keep TextureSystem docs in sync with ImageCache #5085 (3.1.12.0, 3.0.17.0) docs: Fix typos and incorrect attribute name in a comment #5093 (3.1.12.0, 3.0.17.0) docs: Fix misstatement about oiiotool --if #5102 (3.1.12.0, 3.0.17.0) admin: Draft policy on use of AI coding assistants #5072 (3.1.12.0, 3.0.17.0) ci: Freetype adjustments #4999 Update to 5.1 (#2451401) Update to 5.0 (#2447841) -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 8 2026 Gwyn Ciesla - 1:7.1.2.13-2 - Libraw rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2447841 - swayimg-.5.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2447841 [ 2 ] Bug #2451401 - swayimg-5.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2451401 [ 3 ] Bug #2454235 - CVE-2026-5318 LibRaw: LibRaw: Denial of Service via out-of-bounds write in JPEG DHT Parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454235 [ 4 ] Bug #2454464 - CVE-2026-5342 LibRaw: LibRaw: Out-of-bounds read via `load_flags/raw_width` argument manipulation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454464 [ 5 ] Bug #2455346 - LibRaw-0.22.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2455346 [ 6 ] Bug #2456557 - CVE-2026-20884 LibRaw: LibRaw: Arbitrary code execution via integer overflow in deflate_dng_load_raw [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2456557 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnfupgrade --advisory FEDORA-2026-bef0050737' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Improve security with Fedora 44 ImageMagick update addressing multiple issues including out-of-bounds writes.. Fedora ImageMagick security patch Denial of Service buffer overrun. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 13, 2026 Critical Fedora
89

Fedora 44 LibRaw Critical DoS and Buffer Overrun Vulnerab 2026-bef0050737

LibRaw 0.22.1 and rebuilds Release 3.1.12.0 (Apr 1, 2026) -- compared to 3.1.11.0 oiiotool: Better type understanding with -i:ch= and other cleanup #5056 texture: Fix texture overblur with st-blur parameters #5071 #5080 (by Pascal Lecocq) (3.1.12.0, 3.0.17.0). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-bef0050737 2026-04-13 21:06:00.498961+00:00 -------------------------------------------------------------------------------- Name : gegl04 Product : Fedora 44 Version : 0.4.70 Release : 2.fc44 URL : https://www.gegl.org/ Summary : Graph based image processing framework Description : GEGL (Generic Graphics Library) is a graph based image processing framework. GEGLs original design was made to scratch GIMP's itches for a new compositing and processing core. This core is being designed to have minimal dependencies and a simple well defined API. -------------------------------------------------------------------------------- Update Information: LibRaw 0.22.1 and rebuilds Release 3.1.12.0 (Apr 1, 2026) -- compared to 3.1.11.0 oiiotool: Better type understanding with -i:ch= and other cleanup #5056 texture: Fix texture overblur with st-blur parameters #5071 #5080 (by Pascal Lecocq) (3.1.12.0, 3.0.17.0) IBA: Handle offset data windows in fillholes_pushpull #5105 (3.1.12.0, 3.0.17.0) ImageInput: check_open fixes and new validity checks #5087 (3.1.12.0, 3.0.17.0) bmp: Use check_open to guard against corrupt resolutions #5086 (3.1.12.0, 3.0.17.0) heif: Fix invalid read writing 8-bit images with dimensions not a multiple of 64 #5095 (by Brecht Van Lommel) ico: Various validity checks and error handling for corruptions #5088 (3.1.12.0, 3.0.17.0) jpeg: Improved safety and error reporting for jpeg and iptc #5081 jpeg2000: Suppress leak when reading with OpenJPH #5098 psd: Fixes against corrupt files with better validation #5089 (3.1.12.0, 3.0.17.0) rla: Lots of additional validitychecking and safety #5094 (3.1.12.0, 3.0.17.0) tiff: Support GPS fields, and other metadata enhancements #5050 tiff: Fix buffer overrun and improve error reporting #5082, fix wrong number of values passed to invert_photometric #5083, check for invalid bit depth in palette images #5091 ImageSpec: metadata_val improved safety #5096 (3.1.12.0, 3.0.17.0) fix: Fix UB-sanitizer warning about alignment #5097 fix: Catch exceptions in print-uncaught-messages destructor #5103 fix: Enhanced exception safety for our use of OpenColorIO #5114 fix: Fix possible fmt exceptions where we might have passed null string #5115 build: Test building with clang 22.1, fix warnings uncovered #5067 build: Improve security by pinning auto-build dependencies by hash #5076 build: Include idiff in the python wheels we build #5104 (3.1.12.0, 3.0.17.0) build(pybind11): Address new pybind11 float/int auto-conversion behavior #5058 build(win): Embed manifest in OIIO executables to enable long path handling #5066 (by Nathan Rusch) ci: Add CI test for MSVS 2026 #5060 (3.1.12.0, 3.0.17.0) ci: For security, replace workflow substitutions with safer env substitutions #5070 ci: Speed up slow benchmarks for debug and sanitizer CI tests #5077 ci: On Mac Intel CI variant, don't install openvdb, for speed #5065 (3.1.12.0, 3.0.17.0) ci: Bump GitHub Actions to latest versions #5078 #5110 #5119 ci: Fix broken Mac CI and wheel building by specifying full compiler paths #5100 #5101 (3.1.12.0, 3.0.17.0) ci: Update certificates to be able to install icc #5122 (3.1.12.0, 3.0.17.0) ci: Turn off nightly workflows for user forks #5042 tests: New ref outputs for tiff-misc, heif no-avif, and ffmpeg 8.1 cases #5075 #5079 #5099 #5112 docs: Update description for dwaCompressionLevel #5074 (by Aamir Raza) docs: Fix formatting examples for version macros #5073 docs: Keep TextureSystem docs in sync with ImageCache #5085 (3.1.12.0, 3.0.17.0) docs: Fix typos and incorrect attribute name in a comment #5093 (3.1.12.0, 3.0.17.0) docs: Fixmisstatement about oiiotool --if #5102 (3.1.12.0, 3.0.17.0) admin: Draft policy on use of AI coding assistants #5072 (3.1.12.0, 3.0.17.0) ci: Freetype adjustments #4999 Update to 5.1 (#2451401) Update to 5.0 (#2447841) -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 8 2026 Gwyn Ciesla - 0.4.70-2 - Libraw rebuild * Mon Mar 30 2026 Nils Philippsen - 0.4.70-1 - Update to 0.4.70 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2447841 - swayimg-.5.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2447841 [ 2 ] Bug #2451401 - swayimg-5.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2451401 [ 3 ] Bug #2454235 - CVE-2026-5318 LibRaw: LibRaw: Denial of Service via out-of-bounds write in JPEG DHT Parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454235 [ 4 ] Bug #2454464 - CVE-2026-5342 LibRaw: LibRaw: Out-of-bounds read via `load_flags/raw_width` argument manipulation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454464 [ 5 ] Bug #2455346 - LibRaw-0.22.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2455346 [ 6 ] Bug #2456557 - CVE-2026-20884 LibRaw: LibRaw: Arbitrary code execution via integer overflow in deflate_dng_load_raw [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2456557 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bef0050737' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . LibRaw update in Fedora 44 addresses critical Denial of Service issues and enhances security measures.. LibRaw update, Fedora security, Denial of Service, buffer overrun, software vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 13, 2026 Critical Fedora
100

SUSE PostgreSQL 16.13 Important Update for Multiple Issues 2026-20983-1

An update that solves four vulnerabilities and has one fix can now be installed.. # Security update for postgresql16 Announcement ID: SUSE-SU-2026:20983-1 Release Date: 2026-03-30T14:27:44Z Rating: important References: * bsc#1258008 * bsc#1258009 * bsc#1258010 * bsc#1258011 * bsc#1258754 Cross-References: * CVE-2026-2003 * CVE-2026-2004 * CVE-2026-2005 * CVE-2026-2006 CVSS scores: * CVE-2026-2003 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-2003 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-2004 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2004 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2005 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2005 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2006 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2006 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server - BCI 16.0 An update that solves four vulnerabilities and has one fix can now be installed. ## Description: This update for postgresql16 fixes the following issues: * Update to versio 16.13. (bsc#1258754) * CVE-2026-2003: Guard against unexpected dimensions of oidvector/int2vector (bsc#1258008) * CVE-2026-2004: Harden selectivity estimators against being attached to operators that accept unexpected data types. (bsc#1258009) * CVE-2026-2005: Fix buffer overrun in contrib/pgcrypto's PGP decryption functions. (bsc#1258010) * CVE-2026-2006: Fix inadequate validation of multibyte character lengths. (bsc#1258011) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server - BCI 16.0 zypper in -t patchSUSE-SLES-16.0-465=1 ## Package List: * SUSE Linux Enterprise Server - BCI 16.0 (aarch64 ppc64le s390x x86_64) * postgresql16-16.13-160000.1.1 * postgresql16-plperl-16.13-160000.1.1 * postgresql16-server-16.13-160000.1.1 * postgresql16-contrib-debuginfo-16.13-160000.1.1 * postgresql16-server-devel-16.13-160000.1.1 * postgresql16-debugsource-16.13-160000.1.1 * postgresql16-contrib-16.13-160000.1.1 * postgresql16-pltcl-debuginfo-16.13-160000.1.1 * postgresql16-server-debuginfo-16.13-160000.1.1 * postgresql16-devel-debuginfo-16.13-160000.1.1 * postgresql16-plpython-16.13-160000.1.1 * postgresql16-plpython-debuginfo-16.13-160000.1.1 * postgresql16-pltcl-16.13-160000.1.1 * postgresql16-plperl-debuginfo-16.13-160000.1.1 * postgresql16-debuginfo-16.13-160000.1.1 * postgresql16-server-devel-debuginfo-16.13-160000.1.1 * postgresql16-devel-16.13-160000.1.1 * SUSE Linux Enterprise Server - BCI 16.0 (noarch) * postgresql16-docs-16.13-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2003.html * https://www.suse.com/security/cve/CVE-2026-2004.html * https://www.suse.com/security/cve/CVE-2026-2005.html * https://www.suse.com/security/cve/CVE-2026-2006.html * https://bugzilla.suse.com/show_bug.cgi?id=1258008 * https://bugzilla.suse.com/show_bug.cgi?id=1258009 * https://bugzilla.suse.com/show_bug.cgi?id=1258010 * https://bugzilla.suse.com/show_bug.cgi?id=1258011 * https://bugzilla.suse.com/show_bug.cgi?id=1258754 . Important SUSE security advisory for PostgreSQL 16.13 addressing multiple issues, ensuring data protection and stability.. SUSE PostgreSQL Update, Security Patch SUSE, Postgres Security Release. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 09, 2026 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200