Explore top 10 tips to secure your open-source projects now. Read More
×
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-35830 http://linux.oracle.com/errata/ELSA-2026-35830.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: grafana-9.2.10-31.0.1.el8_10.x86_64.rpm grafana-selinux-9.2.10-31.0.1.el8_10.x86_64.rpm aarch64: grafana-9.2.10-31.0.1.el8_10.aarch64.rpm grafana-selinux-9.2.10-31.0.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/grafana-9.2.10-31.0.1.el8_10.src.rpm Related CVEs: CVE-2026-39821 Description of changes: [9.2.10-31.0.1] - Fixes CVE-2024-1442 Add email verification when updating user email [Orabug: 38550520] [9.2.10-31] - Resolves RHEL-183728: CVE-2026-39821 _______________________________________________ El-errata mailing list
Security update. Publication date: 04 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0235.html Type: security Affected Mageia releases: 10 CVE: CVE-2026-44168, CVE-2026-44169, CVE-2026-44170, CVE-2026-44171, CVE-2026-44172, CVE-2026-44173 Description: This update to the latest LTS version fixes some severe security vulnerabilities. References: - https://bugs.mageia.org/show_bug.cgi?id=35675 - https://mariadb.com/docs/release-notes/community-server/12.3/12.3.2 - https://www.cve.org/CVERecord?id=CVE-2026-44168 - https://www.cve.org/CVERecord?id=CVE-2026-44169 - https://www.cve.org/CVERecord?id=CVE-2026-44170 - https://www.cve.org/CVERecord?id=CVE-2026-44171 - https://www.cve.org/CVERecord?id=CVE-2026-44172 - https://www.cve.org/CVERecord?id=CVE-2026-44173 SRPMS: - 10/core/mariadb-12.3.2-1.mga10 . A critical security advisory for Mageia addressing multiple severe issues in MariaDB. Immediate updates recommended.. Mageia MariaDB security critical vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # perl-CGI-Session-4.490.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:11168-1 Rating: moderate Cross-References: * CVE-2026-56016 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the perl-CGI-Session-4.490.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * perl-CGI-Session 4.490.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56016.html . An update for openSUSE covers a moderate security issue in the perl-CGI-Session package. Learn how to address it now.. perl-cgi-session security update openSUSE moderate fix. . Severity: moderate. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for libtpms Announcement ID: SUSE-SU-2026:21581-1 Release Date: 2026-05-06T18:19:25Z Rating: moderate References: * bsc#1244528 * bsc#1260439 Cross-References: * CVE-2025-49133 * CVE-2026-21444 CVSS scores: * CVE-2025-49133 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2025-49133 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2025-49133 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21444 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-21444 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-21444 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for libtpms fixes the following issues: * CVE-2025-49133: Fixed potential out of bounds (OOB) read vulnerability (bsc#1244528). * CVE-2026-21444: Fixed remote data confidentiality compromise via incorrect Initialization Vector (IV) handling (bsc#1260439). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-714=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libtpms-debugsource-0.10.0-160000.5.1 * libtpms0-debuginfo-0.10.0-160000.5.1 * libtpms0-0.10.0-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49133.html * https://www.suse.com/security/cve/CVE-2026-21444.html * https://bugzilla.suse.com/show_bug.cgi?id=1244528 * https://bugzilla.suse.com/show_bug.cgi?id=1260439 . SUSE provides a security update for libtpms addressing moderate vulnerabilities enhancingsystem integrity and safety.. SUSE libtpms update security issues moderate vulnerabilities. . LinuxSecurity.com Team
Important: grafana security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:10223", "synopsis": "Important: grafana security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for grafana.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. \n\nSecurity Fix(es):\n\n* grafana: Grafana: Information disclosure of data-source passwords via public dashboards (CVE-2026-27877)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2452293", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2452293", "description": ""}], "cves": [{"name": "CVE-2026-27877", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27877", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "7.5", "cwe": "CWE-201"}], "references": [], "publishedAt": "2026-04-28T12:06:44.835475Z", "rpms": {"Rocky Linux 10": {"nvras": ["grafana-0:10.2.6-24.el10_1.ppc64le.rpm", "grafana-0:10.2.6-24.el10_1.src.rpm", "grafana-selinux-0:10.2.6-24.el10_1.x86_64.rpm", "grafana-selinux-0:10.2.6-24.el10_1.ppc64le.rpm", "grafana-selinux-0:10.2.6-24.el10_1.aarch64.rpm", "grafana-debuginfo-0:10.2.6-24.el10_1.x86_64.rpm", "grafana-debugsource-0:10.2.6-24.el10_1.x86_64.rpm", "grafana-0:10.2.6-24.el10_1.x86_64.rpm", "grafana-debugsource-0:10.2.6-24.el10_1.ppc64le.rpm", "grafana-debugsource-0:10.2.6-24.el10_1.s390x.rpm", "grafana-0:10.2.6-24.el10_1.s390x.rpm", "grafana-debuginfo-0:10.2.6-24.el10_1.s390x.rpm","grafana-debuginfo-0:10.2.6-24.el10_1.aarch64.rpm", "grafana-0:10.2.6-24.el10_1.aarch64.rpm", "grafana-selinux-0:10.2.6-24.el10_1.s390x.rpm", "grafana-debugsource-0:10.2.6-24.el10_1.aarch64.rpm", "grafana-debuginfo-0:10.2.6-24.el10_1.ppc64le.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Grafana security update addresses information disclosure risks in Rocky Linux 10. Stay informed on CVEs and solutions.. grafana security, Rocky Linux update, CVSS score, information disclosure. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-5581 http://linux.oracle.com/errata/ELSA-2026-5581.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: nginx-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.x86_64.rpm nginx-all-modules-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.noarch.rpm nginx-filesystem-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.noarch.rpm nginx-mod-devel-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.x86_64.rpm nginx-mod-http-image-filter-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.x86_64.rpm nginx-mod-http-perl-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.x86_64.rpm nginx-mod-http-xslt-filter-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.x86_64.rpm nginx-mod-mail-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.x86_64.rpm nginx-mod-stream-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.x86_64.rpm aarch64: nginx-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.aarch64.rpm nginx-all-modules-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.noarch.rpm nginx-filesystem-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.noarch.rpm nginx-mod-devel-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.aarch64.rpm nginx-mod-http-image-filter-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.aarch64.rpm nginx-mod-http-perl-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.aarch64.rpm nginx-mod-http-xslt-filter-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.aarch64.rpm nginx-mod-mail-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.aarch64.rpm nginx-mod-stream-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/nginx-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.src.rpm Related CVEs: CVE-2026-1642 Description of changes: [1.24.0-2.0.1] - Remove Red Hat references [Orabug: 29498217] [1:1.24.0-2] - Resolves: RHEL-146517 - nginx:1.24/nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections (CVE-2026-1642) [1:1.24.0-1] -Resolves: RHEL-14714 - add nginx:1.24 to RHEL 8.10 [1:1.22.1-2] - Resolves: RHEL-12728 - nginx:1.22/nginx: HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)(CVE-2023-44487) [1:1.22.1-1] - Resolves: #2112345 - nginx:1.22 for RHEL 8 - add stream_geoip_module and stream_realip_module - remove obsolete --with-ipv6 [1:1.20.1-1] - rebase to 1.20.1 (addressing CVE-2021-23017) [1:1.20.0-4] - add delaycompress to logrotate config (#2015243) [1:1.20.0-3] - Add -mod-devel subpackage for building external nginx modules (Neal Gompa) Resolves: #1991787 [1:1.20.0-2] - Resolves: #1991796 - build nginx with --with-compat [1:1.20.0-1] - new version 1.20.0 - Resolves: #1945671 - RFE: add nginx:1.20 module stream _______________________________________________ El-errata mailing list
An update that solves five vulnerabilities can now be installed.. # Security update for curl Announcement ID: SUSE-SU-2026:20110-1 Release Date: 2026-01-14T10:57:51Z Rating: moderate References: * bsc#1255731 * bsc#1255732 * bsc#1255733 * bsc#1255734 * bsc#1256105 Cross-References: * CVE-2025-14017 * CVE-2025-14524 * CVE-2025-14819 * CVE-2025-15079 * CVE-2025-15224 CVSS scores: * CVE-2025-14017 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-14017 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-14017 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-14524 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-14524 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-14524 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-14819 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-14819 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-14819 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-15079 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-15079 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-15079 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-15224 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-15224 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-15224 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves five vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues: This update for curl fixes the following issues: * CVE-2025-14017: broken TLS options for threaded LDAPS (bsc#1256105). *CVE-2025-14524: bearer token leak on cross-protocol redirect (bsc#1255731). * CVE-2025-14819: libssh global knownhost override (bsc#1255732). * CVE-2025-15079: libssh key passphrase bypass without agent set (bsc#1255733). * CVE-2025-15224: OpenSSL partial chain store policy bypass (bsc#1255734). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-140=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * curl-8.14.1-160000.4.1 * libcurl4-8.14.1-160000.4.1 * libcurl4-debuginfo-8.14.1-160000.4.1 * curl-debugsource-8.14.1-160000.4.1 * curl-debuginfo-8.14.1-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2025-14017.html * https://www.suse.com/security/cve/CVE-2025-14524.html * https://www.suse.com/security/cve/CVE-2025-14819.html * https://www.suse.com/security/cve/CVE-2025-15079.html * https://www.suse.com/security/cve/CVE-2025-15224.html * https://bugzilla.suse.com/show_bug.cgi?id=1255731 * https://bugzilla.suse.com/show_bug.cgi?id=1255732 * https://bugzilla.suse.com/show_bug.cgi?id=1255733 * https://bugzilla.suse.com/show_bug.cgi?id=1255734 * https://bugzilla.suse.com/show_bug.cgi?id=1256105 . SUSE Linux Micro 6.2 updates curl fixing five security issues including TLS options and token leaks. Essential patch available.. SUSE Linux Micro curl update patch security leaks TLS. . Severity: Important. LinuxSecurity.com Team
* bsc#1246806 * bsc#1252414 * bsc#1252417 Cross-References: . # Security update for java-11-openjdk Announcement ID: SUSE-SU-2025:3835-1 Release Date: 2025-10-28T10:31:15Z Rating: important References: * bsc#1246806 * bsc#1252414 * bsc#1252417 Cross-References: * CVE-2025-53057 * CVE-2025-53066 CVSS scores: * CVE-2025-53057 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-53057 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53057 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53066 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-53066 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-53066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for java-11-openjdk fixes the following issues: Upgrade to upstream tag jdk-11.0.29+7 (October 2025 CPU): * CVE-2025-53057: Fixed unauthenticated attacker can achieve unauthorized creation, deletion or modification access to critical data (bsc#1252414). * CVE-2025-53066: Fixed unauthenticated attacker can achive unauthorized access to critical data or complete access (bsc#1252417). Other bug fixes: * Do not embed rebuild counter (bsc#1246806) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patchSUSE-SLE-SERVER-12-SP5-LTSS-2025-3835=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-3835=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-debuginfo-11.0.29.0-3.93.1 * java-11-openjdk-devel-11.0.29.0-3.93.1 * java-11-openjdk-11.0.29.0-3.93.1 * java-11-openjdk-demo-11.0.29.0-3.93.1 * java-11-openjdk-headless-11.0.29.0-3.93.1 * java-11-openjdk-debugsource-11.0.29.0-3.93.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * java-11-openjdk-debuginfo-11.0.29.0-3.93.1 * java-11-openjdk-devel-11.0.29.0-3.93.1 * java-11-openjdk-11.0.29.0-3.93.1 * java-11-openjdk-demo-11.0.29.0-3.93.1 * java-11-openjdk-headless-11.0.29.0-3.93.1 * java-11-openjdk-debugsource-11.0.29.0-3.93.1 ## References: * https://www.suse.com/security/cve/CVE-2025-53057.html * https://www.suse.com/security/cve/CVE-2025-53066.html * https://bugzilla.suse.com/show_bug.cgi?id=1246806 * https://bugzilla.suse.com/show_bug.cgi?id=1252414 * https://bugzilla.suse.com/show_bug.cgi?id=1252417 . Critical updates available for java-11-openjdk on SUSE due to important security issues requiring prompt attention.. Java Security Patch, SUSE Update, Linux Vulnerability, OpenJDK Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.