Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # Security update for glib-networking Announcement ID: SUSE-SU-2026:22102-1 Release Date: 2026-06-12T09:03:23Z Rating: moderate References: * bsc#1267979 Cross-References: * CVE-2026-10028 CVSS scores: * CVE-2026-10028 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-10028 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-10028 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for glib-networking fixes the following issue * CVE-2026-10028: two certificates which are each signed by the other can lead to an infinite loop (bsc#1267979). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-753=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * glib-networking-2.76.0-4.1 * glib-networking-debuginfo-2.76.0-4.1 * glib-networking-debugsource-2.76.0-4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10028.html * https://bugzilla.suse.com/show_bug.cgi?id=1267979 . An update for glib-networking addresses a moderate security issue related to certificates causing an infinite loop. Stay secure!. SUSE Linux Micro 6.0, glib-networking, security update, CVE-2026-10028. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for NetworkManager Announcement ID: SUSE-SU-2026:1821-1 Release Date: 2026-05-12T08:00:19Z Rating: moderate References: * bsc#1257359 Cross-References: * CVE-2025-9615 CVSS scores: * CVE-2025-9615 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-9615 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for NetworkManager fixes the following issue: * CVE-2025-9615: Fixed non-admin user using others' certificates (bsc#1257359). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1821=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libnm0-debuginfo-1.32.12-150400.3.3.1 * NetworkManager-1.32.12-150400.3.3.1 * typelib-1_0-NM-1_0-1.32.12-150400.3.3.1 * libnm0-1.32.12-150400.3.3.1 * NetworkManager-debugsource-1.32.12-150400.3.3.1 * NetworkManager-debuginfo-1.32.12-150400.3.3.1 * NetworkManager-devel-1.32.12-150400.3.3.1 * openSUSE Leap 15.4 (noarch) * NetworkManager-branding-upstream-1.32.12-150400.3.3.1 * NetworkManager-lang-1.32.12-150400.3.3.1 * openSUSE Leap 15.4 (x86_64) * NetworkManager-devel-32bit-1.32.12-150400.3.3.1 * libnm0-32bit-1.32.12-150400.3.3.1 * libnm0-32bit-debuginfo-1.32.12-150400.3.3.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libnm0-64bit-1.32.12-150400.3.3.1 * libnm0-64bit-debuginfo-1.32.12-150400.3.3.1 * NetworkManager-devel-64bit-1.32.12-150400.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-9615.html * https://bugzilla.suse.com/show_bug.cgi?id=1257359 . This update addresses amoderate threat in NetworkManager affecting openSUSE Leap 15.4, resolving a user privilege issue.. openSUSE NetworkManager update, security patch, certificate vulnerability, moderate risk advisory. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for NetworkManager Announcement ID: SUSE-SU-2026:21121-1 Release Date: 2026-04-10T12:43:49Z Rating: moderate References: * bsc#1257359 Cross-References: * CVE-2025-9615 CVSS scores: * CVE-2025-9615 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-9615 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for NetworkManager fixes the following issues: * CVE-2025-9615: Fixed non-admin user using others' certificates (bsc#1257359). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-662=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * NetworkManager-cloud-setup-debuginfo-1.42.6-8.1 * NetworkManager-1.42.6-8.1 * NetworkManager-bluetooth-1.42.6-8.1 * NetworkManager-cloud-setup-1.42.6-8.1 * libnm0-1.42.6-8.1 * typelib-1_0-NM-1_0-1.42.6-8.1 * NetworkManager-debuginfo-1.42.6-8.1 * NetworkManager-wwan-1.42.6-8.1 * NetworkManager-wwan-debuginfo-1.42.6-8.1 * NetworkManager-tui-debuginfo-1.42.6-8.1 * NetworkManager-pppoe-1.42.6-8.1 * NetworkManager-tui-1.42.6-8.1 * libnm0-debuginfo-1.42.6-8.1 * NetworkManager-bluetooth-debuginfo-1.42.6-8.1 * NetworkManager-debugsource-1.42.6-8.1 * NetworkManager-pppoe-debuginfo-1.42.6-8.1 ## References: * https://www.suse.com/security/cve/CVE-2025-9615.html * https://bugzilla.suse.com/show_bug.cgi?id=1257359 . Update for SUSE NetworkManager resolves a moderate issue related to non-admin users accessing certificates. Install now.. NetworkManager update,SUSE Linux vulnerability,moderatesecurity issue,certificate access problem. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for NetworkManager Announcement ID: SUSE-SU-2026:1420-1 Release Date: 2026-04-16T16:44:58Z Rating: moderate References: * bsc#1257359 Cross-References: * CVE-2025-9615 CVSS scores: * CVE-2025-9615 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-9615 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for NetworkManager fixes the following issues: * CVE-2025-9615: non-admin users are allowed to use certificates from other users (bsc#1257359). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-1420=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-1420=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * NetworkManager-wwan-debuginfo-1.38.2-150400.3.6.1 * libnm0-1.38.2-150400.3.6.1 * libnm0-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-cloud-setup-1.38.2-150400.3.6.1 * NetworkManager-bluetooth-1.38.2-150400.3.6.1 * NetworkManager-pppoe-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-tui-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-tui-1.38.2-150400.3.6.1 * NetworkManager-debugsource-1.38.2-150400.3.6.1 * NetworkManager-1.38.2-150400.3.6.1 * NetworkManager-pppoe-1.38.2-150400.3.6.1 * typelib-1_0-NM-1_0-1.38.2-150400.3.6.1 * NetworkManager-wwan-1.38.2-150400.3.6.1 * NetworkManager-cloud-setup-debuginfo-1.38.2-150400.3.6.1 *NetworkManager-bluetooth-debuginfo-1.38.2-150400.3.6.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * NetworkManager-wwan-debuginfo-1.38.2-150400.3.6.1 * libnm0-1.38.2-150400.3.6.1 * libnm0-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-cloud-setup-1.38.2-150400.3.6.1 * NetworkManager-bluetooth-1.38.2-150400.3.6.1 * NetworkManager-pppoe-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-tui-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-tui-1.38.2-150400.3.6.1 * NetworkManager-debugsource-1.38.2-150400.3.6.1 * NetworkManager-1.38.2-150400.3.6.1 * NetworkManager-pppoe-1.38.2-150400.3.6.1 * typelib-1_0-NM-1_0-1.38.2-150400.3.6.1 * NetworkManager-wwan-1.38.2-150400.3.6.1 * NetworkManager-cloud-setup-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-bluetooth-debuginfo-1.38.2-150400.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-9615.html * https://bugzilla.suse.com/show_bug.cgi?id=1257359 . Security update for SUSE NetworkManager addresses moderate issues with user certificate access. Update recommended now.. SUSE NetworkManager moderate update access control user certificate. . LinuxSecurity.com Team
MGASA-2026-0025 - Updated ceph packages fix security vulnerability. MGASA-2026-0025 - Updated ceph packages fix security vulnerability Publication date: 29 Jan 2026 URL: https://advisories.mageia.org/MGASA-2026-0025.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-31884 Description: Updated ceph packages fix a security issue allowing an attacker to make Ceph accept any certificate. References: - https://bugs.mageia.org/show_bug.cgi?id=35051 - https://www.openwall.com/lists/oss-security/2026/01/21/6 - https://www.cve.org/CVERecord?id=CVE-2024-31884 SRPMS: - 9/core/ceph-18.2.7-2.2.mga9 . Updated ceph packages for Mageia 9 fix significant security risk allowing any certificate acceptance by Ceph.. Mageia Security Advisory,Critical Ceph Update,Certificate Acceptance Issue,Security Vulnerability Report. . Severity: Important. LinuxSecurity.com Team
New curl packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] curl (SSA:2025-148-01) New curl packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/curl-8.14.0-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: No QUIC certificate pinning with wolfSSL. QUIC certificate check skip with wolfSSL. Please note that curl can be built to use one out of twelve different TLS libraries. The selection is done both at build-time and also optionally at runtime. This vulnerability only affects curl made to use this specific TLS (wolfSSL) backend. For more information, see: https://curl.se/docs/CVE-2025-5025.html https://curl.se/docs/CVE-2025-4947.html https://www.cve.org/CVERecord?id=CVE-2025-5025 https://www.cve.org/CVERecord?id=CVE-2025-4947 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/curl-8.14.0-i586-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/curl-8.14.0-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/curl-8.14.0-i686-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/curl-8.14.0-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: b5f5d5311fede2732ce956c7c8ff37b2 curl-8.14.0-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 49ce3e5df9e6d9f6e8e2c313de7bf0e5 curl-8.14.0-x86_64-1_slack15.0.txz Slackware -current package: 18272e8babf1d31f59f68d051494decf n/curl-8.14.0-i686-1.txz Slackware x86_64 -current package: 2409be9d130145d6da089cd0e0a86be8 n/curl-8.14.0-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg curl-8.14.0-i586-1_slack15.0.txz +-----+ . Updated curl versions have now been released for Slackware to address vulnerabilities linked to certificate management, enhancing overall security.. Curl Security Fix, Slackware Packages, TLS Library Update, Open Source Advisory. . LinuxSecurity.com Team
Cryptography vulnerable to NULL-dereference when loading PKCS7 certificates. (CVE-2023-49083) Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659. (CVE-2023-50782) Cryptography NULL pointer deference with . MGASA-2025-0069 - Updated python-cryptography & openssl packages fix security vulnerabilities Publication date: 17 Feb 2025 URL: https://advisories.mageia.org/MGASA-2025-0069.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-49083, CVE-2023-50782, CVE-2024-26130 Cryptography vulnerable to NULL-dereference when loading PKCS7 certificates. (CVE-2023-49083) Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659. (CVE-2023-50782) Cryptography NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override. (CVE-2024-26130) References: - https://bugs.mageia.org/show_bug.cgi?id=32584 - https://www.openwall.com/lists/oss-security/2023/11/29/2 - https://ubuntu.com/security/notices/USN-6673-1 - https://ubuntu.com/security/notices/USN-6673-3 - https://www.cve.org/CVERecord?id=CVE-2023-49083 - https://www.cve.org/CVERecord?id=CVE-2023-50782 - https://www.cve.org/CVERecord?id=CVE-2024-26130 SRPMS: - 9/core/openssl-3.0.15-1.3.mga9 - 9/core/python-cryptography-39.0.1-1.1.mga9 . Revamped python-cryptography and openssl libraries rectify significant security threats in Mageia.. Mageia Security, Python Cryptography, OpenSSL Update, NULL Dereference, Timing Attack. . Severity: Important. LinuxSecurity.com Team
qBittorrent, on all platforms, did not verify any SSL certificates in its DownloadManager class from 2010 until October 2024. If it failed to verify a cert, it simply logged an error and proceeded. References: . MGASA-2024-0359 - Updated qbittorrent packages fix security vulnerabilities Publication date: 12 Nov 2024 URL: https://advisories.mageia.org/MGASA-2024-0359.html Type: security Affected Mageia releases: 9 qBittorrent, on all platforms, did not verify any SSL certificates in its DownloadManager class from 2010 until October 2024. If it failed to verify a cert, it simply logged an error and proceeded. References: - https://bugs.mageia.org/show_bug.cgi?id=33712 - https://www.openwall.com/lists/oss-security/2024/10/30/4 - https://www.openwall.com/lists/oss-security/2024/10/31/3 SRPMS: - 9/core/qbittorrent-4.6.7-1.mga9 . The latest Mageia advisory points out vulnerabilities related to SSL certificates in qBittorrent which compromise security; fixes can be found in the updates.. qBittorrent Security, Mageia Advisory, SSL Fixes, Certificate Issues Updates. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.