Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 39 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:2212-1 Release Date: 2026-06-01T17:05:30Z Rating: important References: * bsc#1264096 Cross-References: * CVE-2025-54518 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.153 fixes one security issue The following security issue was fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2212=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-2212=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_163-default-2-150500.2.1 * kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-2-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_39-debugsource-2-150500.2.1 * SUSE LinuxEnterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_163-default-2-150500.2.1 * kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-2-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_39-debugsource-2-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://bugzilla.suse.com/show_bug.cgi?id=1264096 . Critical update for openSUSE 15 SP5 kernel addressing important CPU cache corruption issue with detailed instructions.. openSUSE Kernel Security Patch, CPU Cache Corruption Fix, Live Patching update. . Severity: Important. LinuxSecurity.com Team
A HTTP/1 client-side desync vulnerability has been fixed in Varnish, a caching HTTP reverse proxy. For Debian 11 bullseye, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4101-1
Important: bind security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:4099", "synopsis": "Important: bind security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for bind.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.\n\nSecurity Fix(es):\n\n* bind: named's configured cache size limit can be significantly exceeded (CVE-2023-2828)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2216227", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2216227", "description": ""}], "cves": [{"name": "CVE-2023-2828", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-2828", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2023-08-08T12:34:57.744690Z", "rpms": {"Rocky Linux 9": {"nvras": ["bind-devel-32:9.16.23-11.el9_2.1.aarch64.rpm", "bind-32:9.16.23-11.el9_2.1.aarch64.rpm", "bind-32:9.16.23-11.el9_2.1.ppc64le.rpm", "bind-32:9.16.23-11.el9_2.1.s390x.rpm", "bind-32:9.16.23-11.el9_2.1.src.rpm", "bind-32:9.16.23-11.el9_2.1.x86_64.rpm", "bind-chroot-32:9.16.23-11.el9_2.1.aarch64.rpm", "bind-chroot-32:9.16.23-11.el9_2.1.ppc64le.rpm", "bind-chroot-32:9.16.23-11.el9_2.1.s390x.rpm", "bind-chroot-32:9.16.23-11.el9_2.1.x86_64.rpm","bind-debuginfo-32:9.16.23-11.el9_2.1.aarch64.rpm", "bind-debuginfo-32:9.16.23-11.el9_2.1.ppc64le.rpm", "bind-debuginfo-32:9.16.23-11.el9_2.1.s390x.rpm", "bind-debuginfo-32:9.16.23-11.el9_2.1.x86_64.rpm", "bind-debugsource-32:9.16.23-11.el9_2.1.aarch64.rpm", "bind-debugsource-32:9.16.23-11.el9_2.1.ppc64le.rpm", "bind-debugsource-32:9.16.23-11.el9_2.1.s390x.rpm", "bind-debugsource-32:9.16.23-11.el9_2.1.x86_64.rpm", "bind-devel-32:9.16.23-11.el9_2.1.i686.rpm", "bind-devel-32:9.16.23-11.el9_2.1.ppc64le.rpm", "bind-devel-32:9.16.23-11.el9_2.1.s390x.rpm", "bind-devel-32:9.16.23-11.el9_2.1.x86_64.rpm", "bind-dnssec-doc-32:9.16.23-11.el9_2.1.noarch.rpm", "bind-dnssec-utils-32:9.16.23-11.el9_2.1.aarch64.rpm", "bind-dnssec-utils-32:9.16.23-11.el9_2.1.ppc64le.rpm", "bind-dnssec-utils-32:9.16.23-11.el9_2.1.s390x.rpm", "bind-dnssec-utils-32:9.16.23-11.el9_2.1.x86_64.rpm", "bind-dnssec-utils-debuginfo-32:9.16.23-11.el9_2.1.aarch64.rpm", "bind-dnssec-utils-debuginfo-32:9.16.23-11.el9_2.1.ppc64le.rpm", "bind-dnssec-utils-debuginfo-32:9.16.23-11.el9_2.1.s390x.rpm", "bind-dnssec-utils-debuginfo-32:9.16.23-11.el9_2.1.x86_64.rpm", "bind-doc-32:9.16.23-11.el9_2.1.noarch.rpm", "bind-libs-32:9.16.23-11.el9_2.1.aarch64.rpm", "bind-libs-32:9.16.23-11.el9_2.1.i686.rpm", "bind-libs-32:9.16.23-11.el9_2.1.ppc64le.rpm", "bind-libs-32:9.16.23-11.el9_2.1.s390x.rpm", "bind-libs-32:9.16.23-11.el9_2.1.x86_64.rpm", "bind-libs-debuginfo-32:9.16.23-11.el9_2.1.aarch64.rpm", "bind-libs-debuginfo-32:9.16.23-11.el9_2.1.ppc64le.rpm", "bind-libs-debuginfo-32:9.16.23-11.el9_2.1.s390x.rpm", "bind-libs-debuginfo-32:9.16.23-11.el9_2.1.x86_64.rpm", "bind-license-32:9.16.23-11.el9_2.1.noarch.rpm", "bind-utils-32:9.16.23-11.el9_2.1.aarch64.rpm", "bind-utils-32:9.16.23-11.el9_2.1.ppc64le.rpm", "bind-utils-32:9.16.23-11.el9_2.1.s390x.rpm", "bind-utils-32:9.16.23-11.el9_2.1.x86_64.rpm", "bind-utils-debuginfo-32:9.16.23-11.el9_2.1.aarch64.rpm", "bind-utils-debuginfo-32:9.16.23-11.el9_2.1.ppc64le.rpm", "bind-utils-debuginfo-32:9.16.23-11.el9_2.1.s390x.rpm","bind-utils-debuginfo-32:9.16.23-11.el9_2.1.x86_64.rpm", "python3-bind-32:9.16.23-11.el9_2.1.noarch.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Critical BIND security patch released for Rocky Linux 9 to resolve serious cache overflow vulnerabilities and improve overall system security.. BIND Update,Rack Linux Security,Cache Limit Issues,Security Update 2023,Rocky Linux Advisory. . Severity: Important. LinuxSecurity.com Team
Multiple vulnerabilities were discovered in Django, a popular Python-based web development framework: * CVE-2020-24583: Fix incorrect permissions on intermediate-level . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3164-1
Knot Resolver 2.1.0 (2018-02-16) changes -------------------- - stats: remove tracking of expiring records (predict uses another way) - systemd: re-use a single kresd.socket and kresd- tls.socket - ta_sentinel: implement protocol draft-ietf-dnsop-kskroll- sentinel-01 (our draft-ietf-dnsop-kskroll-sentinel-00 implementation had. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-fe5a6ed3b7 2018-02-27 17:16:42.082266 --------------------------------------------------------------------------------Name : knot-resolver Product : Fedora 27 Version : 2.1.0 Release : 1.fc27 URL : https://www.knot-resolver.cz/ Summary : Caching full DNS Resolver Description : The Knot DNS Resolver is a caching full resolver implementation written in C and LuaJIT, including both a resolver library and a daemon. Modular architecture of the library keeps the core tiny and efficient, and provides a state-machine like API for extensions. The package is pre-configured as local caching resolver. To start using it, start a single kresd instance: If you run into issues with activation of the service or its sockets, either update your selinux-policy package or turn off selinux (setenforce 0). https://bugzilla.redhat.com/show_bug.cgi?id=1366968 https://bugzilla.redhat.com/show_bug.cgi?id=1543049 --------------------------------------------------------------------------------Update Information: Knot Resolver 2.1.0 (2018-02-16) ================================ Incompatible changes -------------------- - stats: remove tracking of expiring records (predict uses another way) - systemd: re-use a single kresd.socket and kresd-tls.socket - ta_sentinel: implement protocol draft-ietf-dnsop-kskroll-sentinel-01 (our draft-ietf-dnsop-kskroll-sentinel-00 implementation had inverted logic) - libknot: require version 2.6.4 or newer to get bugfixes for DNS-over-TLS Bugfixes -------- - detect_time_jump module: don't clear cacheon suspend-resume (#284) - stats module: fix stats.list() returning nothing, regressed in 2.0.0 - policy.TLS_FORWARD: refusal when configuring with multiple IPs (#306) - cache: fix broken refresh of insecure records that were about to expire - fix the hints module on some systems, e.g. Fedora (came back on 2.0.0) - build with older gnutls (conditionally disable features) - fix the predict module to work with insecure records & cleanup code Knot Resolver 2.0.0 (2018-01-31) ================================ Incompatible changes -------------------- - systemd: change unit files to allow running multiple instances, deployments with single instance now must use `
Update to upstream version 1.3.1.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-081fc9ad77 2017-07-20 13:50:14.517600 --------------------------------------------------------------------------------Name : knot-resolver Product : Fedora 24 Version : 1.3.1 Release : 1.fc24 URL : https://www.knot-resolver.cz/ Summary : Caching full DNS Resolver Description : The Knot DNS Resolver is a caching full resolver implementation written in C and LuaJIT, including both a resolver library and a daemon. Modular architecture of the library keeps the core tiny and efficient, and provides a state-machine like API for extensions. The package is pre-configured as local caching resolver. To start using it, just start the local DNS socket: BEWARE: Because of https://bugzilla.redhat.com/show_bug.cgi?id=1366968 you need to switch your system to SELinux permissive mode. --------------------------------------------------------------------------------Update Information: Update to upstream version 1.3.1. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade knot-resolver' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.