Explore top 10 tips to secure your open-source projects now. Read More
×
Bump golang.org/x/crypto to v0.52.0 and golang.org/x/net to v0.55.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-4890ba29de 2026-07-10 00:52:14.826387+00:00 -------------------------------------------------------------------------------- Name : k9s Product : Fedora 44 Version : 0.51.0 Release : 2.fc44 URL : https://github.com/derailed/k9s Summary : Kubernetes CLI To Manage Your Clusters In Style Description : Kubernetes CLI To Manage Your Clusters In Style! -------------------------------------------------------------------------------- Update Information: Bump golang.org/x/crypto to v0.52.0 and golang.org/x/net to v0.55.0 -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 7 2026 blinxen - 0.51.0-2 - Bump golang.org/x/crypto to v0.52.0 and golang.org/x/net to v0.55.0 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-4890ba29de' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Rebase to OpenSSL 3.5.7. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-840334a045 2026-06-21 01:09:26.438169+00:00 -------------------------------------------------------------------------------- Name : openssl Product : Fedora 43 Version : 3.5.7 Release : 1.fc43 URL : http://www.openssl.org/ Summary : Utilities from the general purpose cryptography library with TLS implementation Description : The OpenSSL toolkit provides support for secure communications between machines. OpenSSL includes a certificate management tool and shared libraries which provide various cryptographic algorithms and protocols. -------------------------------------------------------------------------------- Update Information: Rebase to OpenSSL 3.5.7 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 10 2026 Dmitry Belyavskiy - 1:3.5.7-1 - Rebase to OpenSSL 3.5.7 Resolves: CVE-2026-45447 Resolves: CVE-2026-34182 Resolves: CVE-2026-34183 Resolves: CVE-2026-42764 Resolves: CVE-2026-45445 Resolves: CVE-2026-7383 Resolves: CVE-2026-9076 Resolves: CVE-2026-34180 Resolves: CVE-2026-34181 Resolves: CVE-2026-42766 Resolves: CVE-2026-42767 Resolves: CVE-2026-42768 Resolves: CVE-2026-42769 Resolves: CVE-2026-42770 Resolves: CVE-2026-45446 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-840334a045' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Crypt-SaltedHash incorrectly generated random numbers.. ========================================================================== Ubuntu Security Notice USN-8418-1 June 10, 2026 libcrypt-saltedhash-perl vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Crypt-SaltedHash incorrectly generated random numbers. Software Description: - libcrypt-saltedhash-perl: module for handling salted hashes Details: It was discovered that Crypt-SaltedHash incorrectly generated salts using a cryptographically weak pseudo-random number generator. An attacker could possibly use this issue to predict generated salts, leading to a weakening of cryptographic protections. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libcrypt-saltedhash-perl 0.09-3ubuntu0.26.04.1~esm1 Available with Ubuntu Pro Ubuntu 25.10 libcrypt-saltedhash-perl 0.09-3ubuntu0.25.10.1 Ubuntu 24.04 LTS libcrypt-saltedhash-perl 0.09-3ubuntu0.24.04.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS libcrypt-saltedhash-perl 0.09-1.1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS libcrypt-saltedhash-perl 0.09-1ubuntu0.20.04.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libcrypt-saltedhash-perl 0.09-1ubuntu0.18.04.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libcrypt-saltedhash-perl 0.09-1ubuntu0.16.04.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8418-1 CVE-2026-47372 Package Information: https://launchpad.net/ubuntu/+source/libcrypt-saltedhash-perl/0.09-3ubuntu0.25.10.1 . Latest Ubuntu advisory for Crypt-SaltedHash addresses critical issues in random number generation impacting cryptographic security.. Ubuntu Security, Crypt-SaltedHash, Random Number Generation, Security Advisory. . Severity: Important. LinuxSecurity.com Team
Security update. Publication date: 02 Jun 2026 URL: https://advisories.mageia.org/MGAA-2026-0031.html Type: bugfix Affected Mageia releases: 9 CVE: CVE-2026-22007, CVE-2026-22008, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-23865, CVE-2026-34268, CVE-2026-34282 Description: Enhance crypto algorithm support. (CVE-2026-22007) Improved Arena allocations. (CVE-2026-22008) Improve Kerberos credentialing. (CVE-2026-22013) Enhance Path Factories Redux. (CVE-2026-22016) Enhance Zip file reading. (CVE-2026-22018) Enhance certificate chain validation. (CVE-2026-22021) Updating FreeType 2.14.1 . (CVE-2026-23865) Enhance key generation. (CVE-2026-34268) Enhance TLS connection handling. (CVE-2026-34282) References: - https://bugs.mageia.org/show_bug.cgi?id=35402 - https://access.redhat.com/errata/RHSA-2026:9682 - https://access.redhat.com/errata/RHSA-2026:9254 - https://access.redhat.com/errata/RHSA-2026:9686 - https://access.redhat.com/errata/RHSA-2026:9690 - https://access.redhat.com/errata/RHSA-2026:9693 - https://www.oracle.com/security-alerts/cpuapr2026.html#AppendixJAVA - https://www.cve.org/CVERecord?id=CVE-2026-22007 - https://www.cve.org/CVERecord?id=CVE-2026-22008 - https://www.cve.org/CVERecord?id=CVE-2026-22013 - https://www.cve.org/CVERecord?id=CVE-2026-22016 - https://www.cve.org/CVERecord?id=CVE-2026-22018 - https://www.cve.org/CVERecord?id=CVE-2026-22021 - https://www.cve.org/CVERecord?id=CVE-2026-23865 - https://www.cve.org/CVERecord?id=CVE-2026-34268 - https://www.cve.org/CVERecord?id=CVE-2026-34282 SRPMS: - 9/core/java-1.8.0-openjdk-1.8.0.492.b09-1.mga9 - 9/core/java-11-openjdk-11.0.31.0.11-1.mga9 - 9/core/java-17-openjdk-17.0.19.0.10-1.mga9 - 9/core/java-latest-openjdk-25.0.3.0.9-1.rolling.1.mga9 . Mageia update enhances crypto support and improves various components to ensure better security.. Mageia Java update, security advisory, crypto enhancements, bugfix improvements. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-8350-1 June 01, 2026 linux-nvidia-tegra vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-nvidia-tegra: Linux kernel for NVIDIA Tegra systems Details: It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Ethernet bonding driver; - Packet sockets; - TLS protocol; (CVE-2026-31419, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078, CVE-2026-46028) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS linux-image-6.8.0-1025-nvidia-tegra 6.8.0-1025.25 linux-image-6.8.0-1025-nvidia-tegra-rt 6.8.0-1025.25 linux-image-nvidia-tegra 6.8.0-1025.25 linux-image-nvidia-tegra-6.8 6.8.0-1025.25 linux-image-nvidia-tegra-rt 6.8.0-1025.25 linux-image-nvidia-tegra-rt-6.8 6.8.0-1025.25 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE,linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8350-1 CVE-2026-31419, CVE-2026-31431, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078, CVE-2026-46028 Package Information: https://launchpad.net/ubuntu/+source/linux-nvidia-tegra/6.8.0-1025.25 . Fixes for several security issues in the Linux kernel for Ubuntu 24.04 LTS, including privilege escalation risks.. ubuntu kernel issues, linux security updates, privilege escalation, nvidia tegra, cryptographic vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Important: fence-agents security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:13672", "synopsis": "Important: fence-agents security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for fence-agents.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. \n\nSecurity Fix(es):\n\n* cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves (CVE-2026-26007)\n\n* pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 ?4.1.11 MUST violation) (CVE-2026-32597)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2438762", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2438762", "description": ""}, {"ticket": "2447194", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2447194", "description": ""}], "cves": [{"name": "CVE-2026-26007", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26007", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "cvss3BaseScore": "7.4", "cwe": "CWE-354"}, {"name": "CVE-2026-32597", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32597", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "cvss3BaseScore": "7.5", "cwe": "CWE-347"}], "references": [], "publishedAt": "2026-05-06T06:02:14.811706Z", "rpms": {"Rocky Linux 9": {"nvras":["fence-agents-0:4.10.0-98.el9_7.12.src.rpm", "fence-agents-aliyun-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-agents-all-0:4.10.0-98.el9_7.12.aarch64.rpm", "fence-agents-all-0:4.10.0-98.el9_7.12.ppc64le.rpm", "fence-agents-all-0:4.10.0-98.el9_7.12.s390x.rpm", "fence-agents-all-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-agents-amt-ws-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-apc-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-apc-snmp-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-aws-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-agents-azure-arm-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-agents-bladecenter-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-brocade-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-cisco-mds-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-cisco-ucs-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-common-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-compute-0:4.10.0-98.el9_7.12.ppc64le.rpm", "fence-agents-compute-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-agents-debuginfo-0:4.10.0-98.el9_7.12.aarch64.rpm", "fence-agents-debuginfo-0:4.10.0-98.el9_7.12.ppc64le.rpm", "fence-agents-debuginfo-0:4.10.0-98.el9_7.12.s390x.rpm", "fence-agents-debuginfo-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-agents-debugsource-0:4.10.0-98.el9_7.12.aarch64.rpm", "fence-agents-debugsource-0:4.10.0-98.el9_7.12.ppc64le.rpm", "fence-agents-debugsource-0:4.10.0-98.el9_7.12.s390x.rpm", "fence-agents-debugsource-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-agents-drac5-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-eaton-snmp-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-emerson-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-eps-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-gce-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-agents-heuristics-ping-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-hpblade-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-ibmblade-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-ibm-powervs-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-ibm-vpc-0:4.10.0-98.el9_7.12.noarch.rpm","fence-agents-ifmib-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-ilo2-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-ilo-moonshot-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-ilo-mp-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-ilo-ssh-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-intelmodular-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-ipdu-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-ipmilan-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-kdump-0:4.10.0-98.el9_7.12.aarch64.rpm", "fence-agents-kdump-0:4.10.0-98.el9_7.12.ppc64le.rpm", "fence-agents-kdump-0:4.10.0-98.el9_7.12.s390x.rpm", "fence-agents-kdump-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-agents-kdump-debuginfo-0:4.10.0-98.el9_7.12.aarch64.rpm", "fence-agents-kdump-debuginfo-0:4.10.0-98.el9_7.12.ppc64le.rpm", "fence-agents-kdump-debuginfo-0:4.10.0-98.el9_7.12.s390x.rpm", "fence-agents-kdump-debuginfo-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-agents-kubevirt-0:4.10.0-98.el9_7.12.aarch64.rpm", "fence-agents-kubevirt-0:4.10.0-98.el9_7.12.ppc64le.rpm", "fence-agents-kubevirt-0:4.10.0-98.el9_7.12.s390x.rpm", "fence-agents-kubevirt-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-agents-kubevirt-debuginfo-0:4.10.0-98.el9_7.12.aarch64.rpm", "fence-agents-kubevirt-debuginfo-0:4.10.0-98.el9_7.12.ppc64le.rpm", "fence-agents-kubevirt-debuginfo-0:4.10.0-98.el9_7.12.s390x.rpm", "fence-agents-kubevirt-debuginfo-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-agents-lpar-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-mpath-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-nutanix-ahv-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-openstack-0:4.10.0-98.el9_7.12.ppc64le.rpm", "fence-agents-openstack-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-agents-redfish-0:4.10.0-98.el9_7.12.aarch64.rpm", "fence-agents-redfish-0:4.10.0-98.el9_7.12.ppc64le.rpm", "fence-agents-redfish-0:4.10.0-98.el9_7.12.s390x.rpm", "fence-agents-redfish-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-agents-rhevm-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-rsa-0:4.10.0-98.el9_7.12.noarch.rpm","fence-agents-rsb-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-sbd-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-scsi-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-virsh-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-vmware-rest-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-vmware-soap-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-wti-0:4.10.0-98.el9_7.12.noarch.rpm", "fence-agents-zvm-0:4.10.0-98.el9_7.12.s390x.rpm", "fence-virt-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-virtd-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-virtd-cpg-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-virtd-cpg-debuginfo-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-virtd-debuginfo-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-virt-debuginfo-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-virtd-libvirt-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-virtd-libvirt-debuginfo-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-virtd-multicast-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-virtd-multicast-debuginfo-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-virtd-serial-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-virtd-serial-debuginfo-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-virtd-tcp-0:4.10.0-98.el9_7.12.x86_64.rpm", "fence-virtd-tcp-debuginfo-0:4.10.0-98.el9_7.12.x86_64.rpm", "ha-cloud-support-0:4.10.0-98.el9_7.12.ppc64le.rpm", "ha-cloud-support-0:4.10.0-98.el9_7.12.x86_64.rpm", "ha-cloud-support-debuginfo-0:4.10.0-98.el9_7.12.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Stay updated with the latest important fence-agents security fix for Rocky Linux 9 and its potential impacts.. fence-agents update, Rocky Linux security, important security updates. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for libsodium Announcement ID: SUSE-SU-2026:21422-1 Release Date: 2026-04-28T15:27:44Z Rating: moderate References: * bsc#1255764 * bsc#1256070 Cross-References: * CVE-2025-15444 * CVE-2025-69277 CVSS scores: * CVE-2025-15444 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2025-15444 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-69277 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-69277 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2025-69277 ( NVD ): 4.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for libsodium fixes the following issues: Security fixes: * CVE-2025-15444: Cryptographic bypass via improper elliptic curve point validation (bsc#1256070). * CVE-2025-69277: incorrect validation of elliptic curve points certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point function (bsc#1255764). Other fixes: * Update to 1.0.21 * The new crypto_ipcrypt_* functions implement mechanisms for securely encrypting and anonymizing IP addresses. * The sodium_bin2ip and sodium_ip2bin helper functions have been added to complement the crypto_ipcrypt_* functions and easily convert addresses between bytes and strings. * XOF: the crypto_xof_shake _and crypto_xof_turboshake_ functions are * standard extendable output functions. From input of any length, they can derive output of any length with the same properties as hash functions. These primitives are required by many post-quantum mechanisms, but can also be used for a wide range of applications, including key derivation, session encryption andmore. * Performance of AES256-GCM and AEGIS on ARM has been improved with some compilers * Security: optblockers have been introduced in critical code paths to prevent compilers from introducing unwanted side channels via conditional jumps. This was observed on RISC-V targets with specific compilers and options. * Security: crypto_core_ed25519_is_valid_point() now properly rejects small- order points that are not in the main subgroup * ((nonnull)) attributes have been relaxed on some crypto_stream* functions to allow NULL output buffers when the output length is zero * A cross-compilation issue with old clang versions has been fixed * crypto_aead_aes256gcm_is_available is exported to JavaScript * Security: memory fences have been added after MAC verification in AEAD to prevent speculative access to plaintext before authentication is complete * Assembly files now include .gnu.property notes for proper IBT and Shadow Stack support when building with CET instrumentation. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-649=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-649=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libsodium26-debuginfo-1.0.21-160000.1.1 * libsodium26-1.0.21-160000.1.1 * libsodium-devel-1.0.21-160000.1.1 * libsodium-debugsource-1.0.21-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libsodium26-debuginfo-1.0.21-160000.1.1 * libsodium26-1.0.21-160000.1.1 * libsodium-devel-1.0.21-160000.1.1 * libsodium-debugsource-1.0.21-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-15444.html *https://www.suse.com/security/cve/CVE-2025-69277.html * https://bugzilla.suse.com/show_bug.cgi?id=1255764 * https://bugzilla.suse.com/show_bug.cgi?id=1256070 . SUSE releases update for libsodium addressing two moderate issues. Install to ensure system integrity through cryptographic fixes.. libsodium update, SUSE security advisory, cryptographic fixes, moderate vulnerability, package management. . LinuxSecurity.com Team
An update that solves one vulnerability, contains one feature and has two fixes can now be installed.. # Security update for python-PyNaCl Announcement ID: SUSE-SU-2026:21431-1 Release Date: 2026-04-29T14:15:43Z Rating: moderate References: * bsc#1161557 * bsc#1199282 * bsc#1255764 * jsc#SLE-24629 Cross-References: * CVE-2025-69277 CVSS scores: * CVE-2025-69277 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-69277 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2025-69277 ( NVD ): 4.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability, contains one feature and has two fixes can now be installed. ## Description: This update for python-PyNaCl fixes the following issues: Security fixes: * CVE-2025-69277: incorrect validation of elliptic curve points certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point function (bsc#1255764). Other fixes: * update to 1.6.2 (bsc#1255764, CVE-2025-69277): * Updated libsodium to 1.0.20-stable (2025-12-31 build) * Update to 1.6.1 * The `MAKE` environment variable can now be used to specify the `make` binary that should be used in the build process. * update to 1.6.0: * BACKWARDS INCOMPATIBLE: Removed support for Python 3.6 and 3.7. * Added support for the low level AEAD AES bindings. * Added support for crypto_core_ed25519_from_uniform. * Update libsodium to 1.0.20-stable (2025-08-27 build). * Added support for free-threaded Python 3.14. * Added support for Windows on ARM wheels. * Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) * python-PyNaCl requires python-cffi [bsc#1161557] ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively youcan run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-658=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-658=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python313-PyNaCl-debuginfo-1.6.2-160000.1.1 * python-PyNaCl-debugsource-1.6.2-160000.1.1 * python313-PyNaCl-1.6.2-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python313-PyNaCl-debuginfo-1.6.2-160000.1.1 * python-PyNaCl-debugsource-1.6.2-160000.1.1 * python313-PyNaCl-1.6.2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-69277.html * https://bugzilla.suse.com/show_bug.cgi?id=1161557 * https://bugzilla.suse.com/show_bug.cgi?id=1199282 * https://bugzilla.suse.com/show_bug.cgi?id=1255764 * https://jira.suse.com/browse/SLE-24629 . An update for python-PyNaCl addresses a moderate issue, enhancing security with fixes and improvements.. python-PyNaCl update, SUSE security advisory, elliptic curve issue, cryptography fix. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.