Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves six vulnerabilities can now be installed.. # Security update for opensc Announcement ID: SUSE-SU-2026:2697-1 Release Date: 2026-06-30T09:15:07Z Rating: important References: * bsc#1261214 * bsc#1261218 * bsc#1261219 * bsc#1261220 * bsc#1266963 * bsc#1267246 Cross-References: * CVE-2025-49010 * CVE-2025-66037 * CVE-2025-66038 * CVE-2025-66215 * CVE-2026-10275 * CVE-2026-40528 CVSS scores: * CVE-2025-49010 ( SUSE ): 1.0 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-49010 ( SUSE ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-49010 ( NVD ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-49010 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-66037 ( SUSE ): 1.0 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-66037 ( SUSE ): 3.9 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-66037 ( NVD ): 3.9 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-66037 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-66038 ( SUSE ): 1.0 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-66038 ( SUSE ): 3.9 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-66038 ( NVD ): 3.9 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-66038 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-66215 ( SUSE ): 1.0 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-66215 ( SUSE ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-66215 ( NVD ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-66215 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-10275 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-10275 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-10275 ( NVD ): 1.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10275 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-40528 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-40528 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40528 ( NVD ): 1.0 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40528 ( NVD ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-40528 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for opensc fixes the following issues * CVE-2025-49010: stack-buffer-overflow via crafted smart card or USB device responses (bsc#1261214). * CVE-2025-66037: crafted input can cause an out-of-bounds read (bsc#1261218). * CVE-2025-66038: improper compact-TLV length validation can lead to crash or unexpected behavior (bsc#1261219). * CVE-2025-66215: crafted smart card or USB device can cause a stack-buffer- overflow write (bsc#1261220). * CVE-2026-10275: global buffer overflow during key pair generation tests due to missing input validation (bsc#1267246). * CVE-2026-40528: stack and heap buffer overrun in the `do_key_value()` function due to missing length check allows for memory corruption via a crafted profile configuration file (bsc#1266963). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2697=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2697=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2697=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2697=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * opensc-0.22.0-150600.11.11.1 * opensc-debuginfo-0.22.0-150600.11.11.1 * opensc-debugsource-0.22.0-150600.11.11.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * opensc-0.22.0-150600.11.11.1 * opensc-debuginfo-0.22.0-150600.11.11.1 * opensc-debugsource-0.22.0-150600.11.11.1 * openSUSE Leap 15.6 (x86_64) * opensc-32bit-0.22.0-150600.11.11.1 * opensc-32bit-debuginfo-0.22.0-150600.11.11.1 * openSUSE Leap 15.6 (aarch64_ilp32) * opensc-64bit-debuginfo-0.22.0-150600.11.11.1 * opensc-64bit-0.22.0-150600.11.11.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * opensc-0.22.0-150600.11.11.1 * opensc-debuginfo-0.22.0-150600.11.11.1 * opensc-debugsource-0.22.0-150600.11.11.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * opensc-0.22.0-150600.11.11.1 * opensc-debuginfo-0.22.0-150600.11.11.1 * opensc-debugsource-0.22.0-150600.11.11.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49010.html * https://www.suse.com/security/cve/CVE-2025-66037.html * https://www.suse.com/security/cve/CVE-2025-66038.html * https://www.suse.com/security/cve/CVE-2025-66215.html * https://www.suse.com/security/cve/CVE-2026-10275.html *https://www.suse.com/security/cve/CVE-2026-40528.html * https://bugzilla.suse.com/show_bug.cgi?id=1261214 * https://bugzilla.suse.com/show_bug.cgi?id=1261218 * https://bugzilla.suse.com/show_bug.cgi?id=1261219 * https://bugzilla.suse.com/show_bug.cgi?id=1261220 * https://bugzilla.suse.com/show_bug.cgi?id=1266963 * https://bugzilla.suse.com/show_bug.cgi?id=1267246 . # Security update for opensc Announcement ID: SUSE-SU-2026:2697-1 Release Date: 2026-06-30T09:15:07Z. update, solves, vulnerabilities, installed, security, opensc, announc. . Severity: Important. LinuxSecurity.com Team
PCL could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-7227-1 January 23, 2025 PCL vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: PCL could be made to crash if it received specially crafted input. Software Description: - pcl: Point Cloud Library for 2D/3D image and point cloud processing Details: It was discovered that PCL incorrectly handled certain malformed files. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly exploit this to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 libpcl-io1.14 1.14.0+dfsg-3ubuntu0.2 libpcl-recognition1.14 1.14.0+dfsg-3ubuntu0.2 libpcl-visualization1.14 1.14.0+dfsg-3ubuntu0.2 pcl-tools 1.14.0+dfsg-3ubuntu0.2 Ubuntu 24.04 LTS libpcl-io1.14 1.14.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro libpcl-recognition1.14 1.14.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro libpcl-visualization1.14 1.14.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro pcl-tools 1.14.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS libpcl-io1.12 1.12.1+dfsg-3ubuntu0.1~esm2 Available with Ubuntu Pro libpcl-recognition1.12 1.12.1+dfsg-3ubuntu0.1~esm2 Available with Ubuntu Pro libpcl-visualization1.12 1.12.1+dfsg-3ubuntu0.1~esm2 Available with Ubuntu Pro pcl-tools 1.12.1+dfsg-3ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 20.04 LTS libpcl-io1.10 1.10.0+dfsg-5ubuntu1+esm2 Available with Ubuntu Pro libpcl-recognition1.10 1.10.0+dfsg-5ubuntu1+esm2 Available with Ubuntu Pro libpcl-visualization1.10 1.10.0+dfsg-5ubuntu1+esm2 Available with Ubuntu Pro pcl-tools 1.10.0+dfsg-5ubuntu1+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS libpcl-io1.8 1.8.1+dfsg1-2ubuntu2.18.04.1+esm1 Available with Ubuntu Pro libpcl-recognition1.8 1.8.1+dfsg1-2ubuntu2.18.04.1+esm1 Available with Ubuntu Pro libpcl-visualization1.8 1.8.1+dfsg1-2ubuntu2.18.04.1+esm1 Available with Ubuntu Pro pcl-tools 1.8.1+dfsg1-2ubuntu2.18.04.1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libpcl-io1.7 1.7.2-14ubuntu0.1+esm1 Available with Ubuntu Pro libpcl-recognition1.7 1.7.2-14ubuntu0.1+esm1 Available with Ubuntu Pro libpcl-visualization1.7 1.7.2-14ubuntu0.1+esm1 Available with Ubuntu Pro pcl-tools 1.7.2-14ubuntu0.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7227-1 CVE-2024-53432 Package Information: https://launchpad.net/ubuntu/+source/pcl/1.14.0+dfsg-3ubuntu0.2 . Important patch released for Ubuntu tackling vulnerabilities in PCL that might expose the system to potential security threats via manipulated input flaws.. PCL security update, Ubuntu vulnerability advisory, denial of service patch, software update instructions. . Severity: Critical. LinuxSecurity.com Team
OpenSSH could be made to crash or run programs as your login if it received a specially crafted input.. ========================================================================== Ubuntu Security Notice USN-6560-3 September 16, 2024 openssh vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: OpenSSH could be made to crash or run programs as your login if it received a specially crafted input. Software Description: - openssh: secure shell (SSH) for secure access to remote machines Details: USN-6560-2 fixed a vulnerability in OpenSSH. This update provides the corresponding update for Ubuntu 16.04 LTS. Original advisory details: It was discovered that OpenSSH incorrectly handled user names or host names with shell metacharacters. An attacker could possibly use this issue to perform OS command injection. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS openssh-client 1:7.2p2-4ubuntu2.10+esm6 Available with Ubuntu Pro openssh-server 1:7.2p2-4ubuntu2.10+esm6 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6560-3 https://ubuntu.com/security/notices/USN-6560-2 https://ubuntu.com/security/notices/USN-6560-1 CVE-2023-51385 . Ubuntu has released Security Notice USN-6560-3 addressing a vulnerability in OpenSSH that permits attackers to leverage malicious input.. OpenSSH Vulnerability, Ubuntu Security Notice, Command Injection, System Update, Openssh Updates. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.