Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
An update that solves one vulnerability can now be installed.. # Security update for libxslt Announcement ID: SUSE-SU-2026:2585-1 Release Date: 2026-06-23T13:28:00Z Rating: moderate References: * bsc#1238591 Cross-References: * CVE-2023-40403 CVSS scores: * CVE-2023-40403 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2023-40403 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libxslt fixes the following issue * CVE-2023-40403: Processing web content may disclose sensitive information (bsc#1238591). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2585=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libxslt1-32bit-1.1.28-17.24.1 * libxslt1-1.1.28-17.24.1 * libxslt-devel-1.1.28-17.24.1 * libxslt-tools-1.1.28-17.24.1 * libxslt-tools-debuginfo-1.1.28-17.24.1 * libxslt1-debuginfo-1.1.28-17.24.1 * libxslt1-debuginfo-32bit-1.1.28-17.24.1 * libxslt-debugsource-1.1.28-17.24.1 ## References: * https://www.suse.com/security/cve/CVE-2023-40403.html * https://bugzilla.suse.com/show_bug.cgi?id=1238591 . SUSE Linux update fixes a moderate issue in libxslt allowing potential information disclosure. Install to mitigate risk.. SUSE Linux, libxslt Security, moderate update, information disclosure, security patch. . Severity: moderate. LinuxSecurity.com Team
An update that solves five vulnerabilities can now be installed.. # Security update for dovecot24 Announcement ID: SUSE-SU-2026:22185-1 Release Date: 2026-06-19T17:08:41Z Rating: important References: * bsc#1265146 * bsc#1265147 * bsc#1265148 * bsc#1265149 * bsc#1265150 Cross-References: * CVE-2026-27851 * CVE-2026-33603 * CVE-2026-40016 * CVE-2026-40020 * CVE-2026-42006 CVSS scores: * CVE-2026-27851 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-27851 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-27851 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-27851 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33603 ( SUSE ): 7.6 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33603 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33603 ( NVD ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33603 ( NVD ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-40016 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40016 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40016 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40016 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40020 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-40020 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40020 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40020 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42006 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42006 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42006 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L AffectedProducts: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for dovecot24 fixes the following issues * CVE-2026-27851: lib-var-expand: safe filter leaks to all following pipelines (bsc#1265146). * CVE-2026-33603: login: base64 input can contain tabs that bypass IPC protection (bsc#1265147). * CVE-2026-40016: Sieve: contains/: matches O(NxM) substring match bypasses sieve_max_cpu_time limit (bsc#1265148). * CVE-2026-40020: IMAP folders can be shared-spammed to everyone (bsc#1265149). * CVE-2026-42006: imap-login: uncontrolled memory usage with excessive bracing over IMAP (bsc#1265150). Changes for dovecot24: * Update to 2.4.4 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-974=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-974=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dovecot24-debugsource-2.4.4-160000.1.1 * dovecot24-fts-solr-debuginfo-2.4.4-160000.1.1 * dovecot24-devel-2.4.4-160000.1.1 * dovecot24-backend-mysql-debuginfo-2.4.4-160000.1.1 * dovecot24-backend-mysql-2.4.4-160000.1.1 * dovecot24-backend-pgsql-debuginfo-2.4.4-160000.1.1 * dovecot24-backend-pgsql-2.4.4-160000.1.1 * dovecot24-backend-sqlite-debuginfo-2.4.4-160000.1.1 * dovecot24-debuginfo-2.4.4-160000.1.1 * dovecot24-2.4.4-160000.1.1 * dovecot24-fts-2.4.4-160000.1.1 * dovecot24-backend-sqlite-2.4.4-160000.1.1 * dovecot24-fts-debuginfo-2.4.4-160000.1.1 * dovecot24-fts-solr-2.4.4-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) *dovecot24-debugsource-2.4.4-160000.1.1 * dovecot24-fts-solr-debuginfo-2.4.4-160000.1.1 * dovecot24-devel-2.4.4-160000.1.1 * dovecot24-backend-mysql-debuginfo-2.4.4-160000.1.1 * dovecot24-backend-mysql-2.4.4-160000.1.1 * dovecot24-backend-pgsql-debuginfo-2.4.4-160000.1.1 * dovecot24-backend-pgsql-2.4.4-160000.1.1 * dovecot24-backend-sqlite-debuginfo-2.4.4-160000.1.1 * dovecot24-debuginfo-2.4.4-160000.1.1 * dovecot24-2.4.4-160000.1.1 * dovecot24-fts-2.4.4-160000.1.1 * dovecot24-backend-sqlite-2.4.4-160000.1.1 * dovecot24-fts-debuginfo-2.4.4-160000.1.1 * dovecot24-fts-solr-2.4.4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27851.html * https://www.suse.com/security/cve/CVE-2026-33603.html * https://www.suse.com/security/cve/CVE-2026-40016.html * https://www.suse.com/security/cve/CVE-2026-40020.html * https://www.suse.com/security/cve/CVE-2026-42006.html * https://bugzilla.suse.com/show_bug.cgi?id=1265146 * https://bugzilla.suse.com/show_bug.cgi?id=1265147 * https://bugzilla.suse.com/show_bug.cgi?id=1265148 * https://bugzilla.suse.com/show_bug.cgi?id=1265149 * https://bugzilla.suse.com/show_bug.cgi?id=1265150 . SUSE's important update addresses five vulnerabilities in dovecot24, enhancing security for users and systems.. SUSE Dovecot24 Security Update, Important Security Patch, SUSE Vulnerability Management. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for openCryptoki Announcement ID: SUSE-SU-2026:2355-1 Release Date: 2026-06-10T15:08:36Z Rating: moderate References: * bsc#1262283 Cross-References: * CVE-2026-40253 CVSS scores: * CVE-2026-40253 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40253 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for openCryptoki fixes the following issue: * CVE-2026-40253: malformed BER-encoded cryptographic objects can lead to information disclosure and denial of service (bsc#1262283). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2355=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2355=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2355=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * openCryptoki-3.17.0-150400.4.16.1 * openCryptoki-debugsource-3.17.0-150400.4.16.1 * openCryptoki-devel-3.17.0-150400.4.16.1 * openCryptoki-debuginfo-3.17.0-150400.4.16.1 * openSUSE Leap 15.4 (i586) * openCryptoki-32bit-debuginfo-3.17.0-150400.4.16.1 * openCryptoki-32bit-3.17.0-150400.4.16.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * openCryptoki-64bit-debuginfo-3.17.0-150400.4.16.1 *openCryptoki-64bit-3.17.0-150400.4.16.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (s390x) * openCryptoki-3.17.0-150400.4.16.1 * openCryptoki-debugsource-3.17.0-150400.4.16.1 * openCryptoki-debuginfo-3.17.0-150400.4.16.1 * SUSE Linux Enterprise Micro 5.4 (s390x) * openCryptoki-3.17.0-150400.4.16.1 * openCryptoki-debugsource-3.17.0-150400.4.16.1 * openCryptoki-debuginfo-3.17.0-150400.4.16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40253.html * https://bugzilla.suse.com/show_bug.cgi?id=1262283 . Update for openCryptoki addresses a moderate data leakage issue with denial of service risk. Install promptly for security.. openSUSE security, data protection, application update, openCryptoki fixes. . Severity: moderate. LinuxSecurity.com Team
An update that solves three vulnerabilities can now be installed.. # Security update for glibc Announcement ID: SUSE-SU-2026:21682-1 Release Date: 2026-05-15T11:10:41Z Rating: important References: * bsc#1261206 * bsc#1262464 * bsc#1262465 Cross-References: * CVE-2026-4046 * CVE-2026-5450 * CVE-2026-5928 CVSS scores: * CVE-2026-4046 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-4046 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4046 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5450 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-5450 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-5450 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-5928 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-5928 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-5928 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for glibc fixes the following issues * CVE-2026-4046: assertion failure when converting inputs may be used to remotely crash an application (bsc#1261206). * CVE-2026-5450: stdio-common: scanf %mc pattern will cause heap overflow when width > 1024 (bsc#1262465). * CVE-2026-5928: libio: ungetwc could be used to leak data on special conditions (bsc#1262464). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-710=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * glibc-locale-2.38-13.1 *glibc-locale-base-2.38-13.1 * glibc-devel-debuginfo-2.38-13.1 * glibc-devel-2.38-13.1 * glibc-debugsource-2.38-13.1 * glibc-locale-base-debuginfo-2.38-13.1 * glibc-debuginfo-2.38-13.1 * glibc-2.38-13.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4046.html * https://www.suse.com/security/cve/CVE-2026-5450.html * https://www.suse.com/security/cve/CVE-2026-5928.html * https://bugzilla.suse.com/show_bug.cgi?id=1261206 * https://bugzilla.suse.com/show_bug.cgi?id=1262464 * https://bugzilla.suse.com/show_bug.cgi?id=1262465 . Important update for SUSE Linux Micro 6.0 addressing critical glibc vulnerabilities. Enhance security now.. SUSE Linux Micro, glibc update, security vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves 10 vulnerabilities and has 12 bug fixes can now be installed.. openSUSE security update: security update for tree-sitter ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20749-1 Rating: important References: * bsc#1259205 * bsc#1261839 * bsc#1261871 * bsc#1261894 * bsc#1261954 * bsc#1261963 * bsc#1261968 * bsc#1261974 * bsc#1262007 * bsc#1262032 * bsc#1262036 * bsc#1262040 Cross-References: * CVE-2026-34941 * CVE-2026-34942 * CVE-2026-34943 * CVE-2026-34944 * CVE-2026-34945 * CVE-2026-34946 * CVE-2026-34987 * CVE-2026-34988 * CVE-2026-35186 * CVE-2026-35195 CVSS scores: * CVE-2026-34941 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34941 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34942 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34942 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34943 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34943 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34944 ( SUSE ): 5 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-34944 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34945 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-34945 ( SUSE ): 7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-34946 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34987 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-34987 ( SUSE ): 9 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-34988 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-34988 ( SUSE ): 7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-35186 ( SUSE ): 6.4CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-35186 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-35195 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-35195 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 10 vulnerabilities and has 12 bug fixes can now be installed. Description: This update for tree-sitter fixes the following issues Security issues: - CVE-2026-34941: wasmtime: crafted input string can lead to an out-of-bound read (bsc#1261871). - CVE-2026-34942: wasmtime: unaligned pointers can lead to a denial of service (bsc#1261894). - CVE-2026-34943: wasmtime: lifting `flags` component value can lead to a denial of service (bsc#1261954). - CVE-2026-34944: wasmtime: out-of-bounds read during WebAssembly compilation can lead to a denial of service (bsc#1261963). - CVE-2026-34945: wasmtime: incorrectly translated table.size could lead to disclosing data (bsc#1262007). - CVE-2026-34946: wasmtime: denial of service due to WebAssembly compilation error (bsc#1261974). - CVE-2026-34987: wasmtime: winch compiler backend may allow a sandbox-escaping memory access (bsc#1262032). - CVE-2026-34988: wasmtime: pooling allocator instances can cause data leakage (bsc#1261968). - CVE-2026-35186: wasmtime: translating the table.grow operator can cause a masked return value (bsc#1262036). - CVE-2026-35195: wasmtime: transcoding strings can lead to an out of bound write or a crash (bsc#1262040). Changes for tree-sitter: - update to 0.26.8: * fix(generate): allow disabling qjs-rt feature from CLI by @WillLillis in #5448 * fix(lib): document invariants that must be upheld for TSInputEdit by @WillLillis in #5452 * fix(cli): correct typo in parse command's help text by @WillLillis in #5465 * perf(cli): misc. improvements by @tree-sitter-ci-bot[bot] in #5476 * Fix wasm loadingof languages w/ multiple reserved word sets by @tree-sitter-ci-bot[bot] in #5477 * generate: avoid panicking when a supertype only has hidden external token children by @tree-sitter-ci-bot[bot] in #5478 Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-743=1 Package List: - openSUSE Leap 16.0: libtree-sitter0_26-0.26.8-160000.1.1 libtree-sitter0_26-x86-64-v3-0.26.8-160000.1.1 tree-sitter-0.26.8-160000.1.1 tree-sitter-devel-0.26.8-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-34941.html * https://www.suse.com/security/cve/CVE-2026-34942.html * https://www.suse.com/security/cve/CVE-2026-34943.html * https://www.suse.com/security/cve/CVE-2026-34944.html * https://www.suse.com/security/cve/CVE-2026-34945.html * https://www.suse.com/security/cve/CVE-2026-34946.html * https://www.suse.com/security/cve/CVE-2026-34987.html * https://www.suse.com/security/cve/CVE-2026-34988.html * https://www.suse.com/security/cve/CVE-2026-35186.html * https://www.suse.com/security/cve/CVE-2026-35195.html . This update resolves 10 vulnerabilities in openSUSE's tree-sitter software, ensuring enhanced security and stability.. openSUSE update tree-sitter vulnerabilities important. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in OpenJDK 8.. ========================================================================== Ubuntu Security Notice USN-7881-1 November 24, 2025 openjdk-8 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in OpenJDK 8. Software Description: - openjdk-8: Open Source Java implementation Details: Jinfeng Guo discovered that the Security component of OpenJDK 8 did not correctly handle certain representations of encoded strings. An unauthenticated remote attacker could possibly use this issue to modify files or leak sensitive information. (CVE-2025-53057) Darius Bohni discovered that the JAXP component of OpenJDK 8 was vulnerable to a XML External Entity (XEE) attack. An unauthenticated remote attacker could possibly use this issue to modify files or leak sensitive information. (CVE-2025-53066) In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://openjdk.org/groups/vulnerability/advisories/2025-10-21 Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 openjdk-8-jdk 8u472-ga-1~25.10 openjdk-8-jdk-headless 8u472-ga-1~25.10 openjdk-8-jre 8u472-ga-1~25.10 openjdk-8-jre-headless 8u472-ga-1~25.10 openjdk-8-jre-zero 8u472-ga-1~25.10 Ubuntu 25.04 openjdk-8-jdk 8u472-ga-1~25.04 openjdk-8-jdk-headless 8u472-ga-1~25.04 openjdk-8-jre 8u472-ga-1~25.04 openjdk-8-jre-headless 8u472-ga-1~25.04 openjdk-8-jre-zero 8u472-ga-1~25.04 Ubuntu 24.04 LTS openjdk-8-jdk 8u472-ga-1~24.04 openjdk-8-jdk-headless 8u472-ga-1~24.04 openjdk-8-jre 8u472-ga-1~24.04 openjdk-8-jre-headless 8u472-ga-1~24.04 openjdk-8-jre-zero 8u472-ga-1~24.04 Ubuntu 22.04 LTS openjdk-8-jdk 8u472-ga-1~22.04 openjdk-8-jdk-headless 8u472-ga-1~22.04 openjdk-8-jre 8u472-ga-1~22.04 openjdk-8-jre-headless 8u472-ga-1~22.04 openjdk-8-jre-zero 8u472-ga-1~22.04 Ubuntu 20.04 LTS openjdk-8-jdk 8u472-ga-1~20.04 Available with Ubuntu Pro openjdk-8-jdk-headless 8u472-ga-1~20.04 Available with Ubuntu Pro openjdk-8-jre 8u472-ga-1~20.04 Available with Ubuntu Pro openjdk-8-jre-headless 8u472-ga-1~20.04 Available with Ubuntu Pro openjdk-8-jre-zero 8u472-ga-1~20.04 Available with Ubuntu Pro Ubuntu 18.04 LTS openjdk-8-jdk 8u472-ga-1~18.04 Available with Ubuntu Pro openjdk-8-jdk-headless 8u472-ga-1~18.04 Available with Ubuntu Pro openjdk-8-jre 8u472-ga-1~18.04 Available with Ubuntu Pro openjdk-8-jre-headless 8u472-ga-1~18.04 Available with Ubuntu Pro openjdk-8-jre-zero 8u472-ga-1~18.04 Available with Ubuntu Pro Ubuntu 16.04 LTS openjdk-8-jdk 8u472-ga-1~16.04 Available with Ubuntu Pro openjdk-8-jdk-headless 8u472-ga-1~16.04 Available with Ubuntu Pro openjdk-8-jre 8u472-ga-1~16.04 Available with Ubuntu Pro openjdk-8-jre-headless 8u472-ga-1~16.04 Available with Ubuntu Pro openjdk-8-jre-jamvm 8u472-ga-1~16.04 Available with Ubuntu Pro openjdk-8-jre-zero 8u472-ga-1~16.04 Available with Ubuntu Pro This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart Java applications to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7881-1 CVE-2025-53057, CVE-2025-53066 Package Information: https://launchpad.net/ubuntu/+source/openjdk-8/8u472-ga-1~25.10 https://launchpad.net/ubuntu/+source/openjdk-8/8u472-ga-1~25.04 https://launchpad.net/ubuntu/+source/openjdk-8/8u472-ga-1~24.04 https://launchpad.net/ubuntu/+source/openjdk-8/8u472-ga-1~22.04 . Multiple security issues in OpenJDK 8 affect Ubuntu. Critical updates necessary for secure operations.. OpenJDK 8 security. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7856-1 November 04, 2025 linux-hwe-6.14 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-hwe-6.14: Linux hardware enablement (HWE) kernel Details: Oleksii Oleksenko, Cedric Fournet, Jana Hofmann, Boris Köpf, Stavros Volos, and Flavien Solt discovered that some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information. A local attacker could possibly use this to expose sensitive information. (CVE-2024-36350, CVE-2024-36357) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - PowerPC architecture; - RISC-V architecture; - S390 architecture; - x86 architecture; - ACPI drivers; - Serial ATA and Parallel ATA drivers; - ATM drivers; - Drivers core; - ATA over ethernet (AOE) driver; - Ublk userspace block driver; - Bus devices; - DMA engine subsystem; - Arm Firmware Framework for ARMv8-A(FFA); - Cirrus firmware drivers; - GPU drivers; - HID subsystem; - Hardware monitoring drivers; - I2C subsystem; - InfiniBand drivers; - Input Device (Miscellaneous) drivers; - Multiple devices driver; - Media drivers; - TI TPS6594 PFSM driver; - MMC subsystem; - MTD block device drivers; - Network drivers; - NVME drivers; - x86 platform drivers; - RapidIO drivers; - Voltage and Current Regulator drivers; - Remote Processor subsystem; - S/390 drivers; - SCSIsubsystem; - TCM subsystem; - Trusted Execution Environment drivers; - TTY drivers; - ChipIdea USB driver; - USB Type-C support driver; - Framebuffer layer; - TSM Common Guest driver; - File systems infrastructure; - BTRFS file system; - Ceph distributed file system; - Ext4 file system; - F2FS file system; - JFFS2 file system; - JFS file system; - Network file systems library; - Network file system (NFS) client; - Network file system (NFS) server daemon; - SMB network file system; - Asynchronous Transfer Mode (ATM) subsystem; - Memory Management; - Bluetooth subsystem; - Tracing infrastructure; - io_uring subsystem; - IPC subsystem; - BPF subsystem; - Perf events; - Kernel exit() syscall; - IRQ subsystem; - Scheduler infrastructure; - Maple Tree data structure library; - Memory management; - Ethernet bridge; - Networking core; - IPv6 networking; - MultiProtocol Label Switching driver; - Netfilter; - NFC subsystem; - Rose network layer; - Network traffic control; - Sun RPC protocol; - TIPC protocol; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - WCD audio codecs; - USB sound devices; (CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38087, CVE-2025-38089, CVE-2025-38090, CVE-2025-38179, CVE-2025-38180, CVE-2025-38181, CVE-2025-38182, CVE-2025-38183, CVE-2025-38184, CVE-2025-38185, CVE-2025-38186, CVE-2025-38188, CVE-2025-38189, CVE-2025-38190, CVE-2025-38191, CVE-2025-38192, CVE-2025-38193, CVE-2025-38194, CVE-2025-38196, CVE-2025-38197, CVE-2025-38198, CVE-2025-38199, CVE-2025-38200, CVE-2025-38201, CVE-2025-38202, CVE-2025-38203, CVE-2025-38204, CVE-2025-38205, CVE-2025-38206, CVE-2025-38208, CVE-2025-38210, CVE-2025-38211, CVE-2025-38212, CVE-2025-38214, CVE-2025-38215, CVE-2025-38217, CVE-2025-38218, CVE-2025-38219, CVE-2025-38220, CVE-2025-38222, CVE-2025-38223, CVE-2025-38224,CVE-2025-38225, CVE-2025-38226, CVE-2025-38227, CVE-2025-38228, CVE-2025-38229, CVE-2025-38230, CVE-2025-38231, CVE-2025-38232, CVE-2025-38233, CVE-2025-38234, CVE-2025-38236, CVE-2025-38237, CVE-2025-38238, CVE-2025-38239, CVE-2025-38241, CVE-2025-38242, CVE-2025-38244, CVE-2025-38245, CVE-2025-38246, CVE-2025-38248, CVE-2025-38249, CVE-2025-38250, CVE-2025-38251, CVE-2025-38253, CVE-2025-38254, CVE-2025-38255, CVE-2025-38256, CVE-2025-38257, CVE-2025-38258, CVE-2025-38259, CVE-2025-38260, CVE-2025-38261, CVE-2025-38262, CVE-2025-38263, CVE-2025-38264, CVE-2025-38320, CVE-2025-38321, CVE-2025-38322, CVE-2025-38323, CVE-2025-38324, CVE-2025-38325, CVE-2025-38326, CVE-2025-38328, CVE-2025-38329, CVE-2025-38330, CVE-2025-38331, CVE-2025-38332, CVE-2025-38333, CVE-2025-38334, CVE-2025-38336, CVE-2025-38337, CVE-2025-38338, CVE-2025-38339, CVE-2025-38340, CVE-2025-38341, CVE-2025-38342, CVE-2025-38343, CVE-2025-38344, CVE-2025-38345, CVE-2025-38346, CVE-2025-38347, CVE-2025-38348, CVE-2025-38353, CVE-2025-38354, CVE-2025-38355, CVE-2025-38356, CVE-2025-38359, CVE-2025-38360, CVE-2025-38361, CVE-2025-38362, CVE-2025-38363, CVE-2025-38364, CVE-2025-38365, CVE-2025-38368, CVE-2025-38369, CVE-2025-38370, CVE-2025-38371, CVE-2025-38372, CVE-2025-38373, CVE-2025-38374, CVE-2025-38375, CVE-2025-38376, CVE-2025-38377, CVE-2025-38381, CVE-2025-38382, CVE-2025-38383, CVE-2025-38384, CVE-2025-38385, CVE-2025-38386, CVE-2025-38387, CVE-2025-38388, CVE-2025-38389, CVE-2025-38390, CVE-2025-38391, CVE-2025-38392, CVE-2025-38393, CVE-2025-38395, CVE-2025-38396, CVE-2025-38399, CVE-2025-38400, CVE-2025-38401, CVE-2025-38402, CVE-2025-38403, CVE-2025-38405, CVE-2025-38406, CVE-2025-38407, CVE-2025-38408, CVE-2025-38409, CVE-2025-38410, CVE-2025-38411, CVE-2025-38412, CVE-2025-38413, CVE-2025-38416, CVE-2025-38417, CVE-2025-38418, CVE-2025-38419, CVE-2025-38420, CVE-2025-38421, CVE-2025-38422, CVE-2025-38423, CVE-2025-38424, CVE-2025-38425, CVE-2025-38426, CVE-2025-38427, CVE-2025-38428, CVE-2025-38429,CVE-2025-38430, CVE-2025-38431, CVE-2025-38434, CVE-2025-38435, CVE-2025-38436, CVE-2025-38523, CVE-2025-38541, CVE-2025-39682) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS linux-image-6.14.0-34-generic 6.14.0-34.34~24.04.1 linux-image-6.14.0-34-generic-64k 6.14.0-34.34~24.04.1 linux-image-generic-6.14 6.14.0-34.34~24.04.1 linux-image-generic-64k-6.14 6.14.0-34.34~24.04.1 linux-image-generic-64k-hwe-24.04 6.14.0-34.34~24.04.1 linux-image-generic-hwe-24.04 6.14.0-34.34~24.04.1 linux-image-virtual-6.14 6.14.0-34.34~24.04.1 linux-image-virtual-hwe-24.04 6.14.0-34.34~24.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7856-1 CVE-2024-36350, CVE-2024-36357, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38087, CVE-2025-38089, CVE-2025-38090, CVE-2025-38179, CVE-2025-38180, CVE-2025-38181, CVE-2025-38182, CVE-2025-38183, CVE-2025-38184, CVE-2025-38185, CVE-2025-38186, CVE-2025-38188, CVE-2025-38189, CVE-2025-38190, CVE-2025-38191, CVE-2025-38192, CVE-2025-38193, CVE-2025-38194, CVE-2025-38196, CVE-2025-38197, CVE-2025-38198, CVE-2025-38199, CVE-2025-38200, CVE-2025-38201, CVE-2025-38202, CVE-2025-38203, CVE-2025-38204, CVE-2025-38205, CVE-2025-38206, CVE-2025-38208, CVE-2025-38210, CVE-2025-38211, CVE-2025-38212, CVE-2025-38214, CVE-2025-38215, CVE-2025-38217, CVE-2025-38218,CVE-2025-38219, CVE-2025-38220, CVE-2025-38222, CVE-2025-38223, CVE-2025-38224, CVE-2025-38225, CVE-2025-38226, CVE-2025-38227, CVE-2025-38228, CVE-2025-38229, CVE-2025-38230, CVE-2025-38231, CVE-2025-38232, CVE-2025-38233, CVE-2025-38234, CVE-2025-38236, CVE-2025-38237, CVE-2025-38238, CVE-2025-38239, CVE-2025-38241, CVE-2025-38242, CVE-2025-38244, CVE-2025-38245, CVE-2025-38246, CVE-2025-38248, CVE-2025-38249, CVE-2025-38250, CVE-2025-38251, CVE-2025-38253, CVE-2025-38254, CVE-2025-38255, CVE-2025-38256, CVE-2025-38257, CVE-2025-38258, CVE-2025-38259, CVE-2025-38260, CVE-2025-38261, CVE-2025-38262, CVE-2025-38263, CVE-2025-38264, CVE-2025-38320, CVE-2025-38321, CVE-2025-38322, CVE-2025-38323, CVE-2025-38324, CVE-2025-38325, CVE-2025-38326, CVE-2025-38328, CVE-2025-38329, CVE-2025-38330, CVE-2025-38331, CVE-2025-38332, CVE-2025-38333, CVE-2025-38334, CVE-2025-38336, CVE-2025-38337, CVE-2025-38338, CVE-2025-38339, CVE-2025-38340, CVE-2025-38341, CVE-2025-38342, CVE-2025-38343, CVE-2025-38344, CVE-2025-38345, CVE-2025-38346, CVE-2025-38347, CVE-2025-38348, CVE-2025-38353, CVE-2025-38354, CVE-2025-38355, CVE-2025-38356, CVE-2025-38359, CVE-2025-38360, CVE-2025-38361, CVE-2025-38362, CVE-2025-38363, CVE-2025-38364, CVE-2025-38365, CVE-2025-38368, CVE-2025-38369, CVE-2025-38370, CVE-2025-38371, CVE-2025-38372, CVE-2025-38373, CVE-2025-38374, CVE-2025-38375, CVE-2025-38376, CVE-2025-38377, CVE-2025-38381, CVE-2025-38382, CVE-2025-38383, CVE-2025-38384, CVE-2025-38385, CVE-2025-38386, CVE-2025-38387, CVE-2025-38388, CVE-2025-38389, CVE-2025-38390, CVE-2025-38391, CVE-2025-38392, CVE-2025-38393, CVE-2025-38395, CVE-2025-38396, CVE-2025-38399, CVE-2025-38400, CVE-2025-38401, CVE-2025-38402, CVE-2025-38403, CVE-2025-38405, CVE-2025-38406, CVE-2025-38407, CVE-2025-38408, CVE-2025-38409, CVE-2025-38410, CVE-2025-38411, CVE-2025-38412, CVE-2025-38413, CVE-2025-38416, CVE-2025-38417, CVE-2025-38418,CVE-2025-38419, CVE-2025-38420, CVE-2025-38421, CVE-2025-38422, CVE-2025-38423, CVE-2025-38424, CVE-2025-38425, CVE-2025-38426, CVE-2025-38427, CVE-2025-38428, CVE-2025-38429, CVE-2025-38430, CVE-2025-38431, CVE-2025-38434, CVE-2025-38435, CVE-2025-38436, CVE-2025-38523, CVE-2025-38541, CVE-2025-39682 Package Information: . Urgent updates for Ubuntu 24.04 address multiple critical issues in the Linux kernel, enhancing system security.. kernel security updates, Ubuntu 24.04 advisory, local privilege escalation. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7833-1 October 21, 2025 linux, linux-aws, linux-gcp, linux-oem-6.14, linux-oracle, linux-oracle-6.14, linux-raspi, linux-realtime vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-oracle: Linux kernel for Oracle Cloud systems - linux-raspi: Linux kernel for Raspberry Pi systems - linux-realtime: Linux kernel for Real-time systems - linux-oem-6.14: Linux kernel for OEM systems - linux-oracle-6.14: Linux kernel for Oracle Cloud systems Details: Oleksii Oleksenko, Cedric Fournet, Jana Hofmann, Boris Köpf, Stavros Volos, and Flavien Solt discovered that some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information. A local attacker could possibly use this to expose sensitive information. (CVE-2024-36350, CVE-2024-36357) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - PowerPC architecture; - RISC-V architecture; - S390 architecture; - x86 architecture; - ACPI drivers; - Serial ATA and Parallel ATA drivers; - Drivers core; - ATA over ethernet (AOE) driver; - Ublk userspace block driver; - Bus devices; - DMA engine subsystem; - Arm Firmware Framework for ARMv8-A(FFA); - Cirrus firmware drivers; - GPU drivers; - HID subsystem; -Hardware monitoring drivers; - I2C subsystem; - InfiniBand drivers; - Input Device (Miscellaneous) drivers; - Multiple devices driver; - Media drivers; - TI TPS6594 PFSM driver; - MMC subsystem; - MTD block device drivers; - Network drivers; - NVME drivers; - x86 platform drivers; - RapidIO drivers; - Voltage and Current Regulator drivers; - Remote Processor subsystem; - S/390 drivers; - SCSI subsystem; - TCM subsystem; - Trusted Execution Environment drivers; - TTY drivers; - ChipIdea USB driver; - USB Type-C support driver; - Framebuffer layer; - TSM Common Guest driver; - File systems infrastructure; - BTRFS file system; - Ceph distributed file system; - Ext4 file system; - F2FS file system; - JFFS2 file system; - JFS file system; - Network file systems library; - Network file system (NFS) client; - Network file system (NFS) server daemon; - SMB network file system; - Memory Management; - Bluetooth subsystem; - Tracing infrastructure; - io_uring subsystem; - IPC subsystem; - BPF subsystem; - Perf events; - Kernel exit() syscall; - IRQ subsystem; - Scheduler infrastructure; - Maple Tree data structure library; - Memory management; - Asynchronous Transfer Mode (ATM) subsystem; - Ethernet bridge; - Networking core; - IPv6 networking; - MultiProtocol Label Switching driver; - Netfilter; - NFC subsystem; - Rose network layer; - Network traffic control; - Sun RPC protocol; - TIPC protocol; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - WCD audio codecs; - USB sound devices; (CVE-2025-38339, CVE-2025-38391, CVE-2025-38262, CVE-2025-38345, CVE-2025-38387, CVE-2025-38373, CVE-2025-38395, CVE-2025-38330, CVE-2025-38425, CVE-2025-38210, CVE-2025-38206, CVE-2025-38219, CVE-2025-38245, CVE-2025-38253, CVE-2025-38401, CVE-2025-38410, CVE-2025-38086,CVE-2025-38340, CVE-2025-38368, CVE-2025-38385, CVE-2025-38384, CVE-2025-38326, CVE-2025-38224, CVE-2025-38338, CVE-2025-38191, CVE-2025-39682, CVE-2025-38343, CVE-2025-38090, CVE-2025-38228, CVE-2025-38182, CVE-2025-38231, CVE-2025-38183, CVE-2025-38184, CVE-2025-38237, CVE-2025-38413, CVE-2025-38356, CVE-2025-38246, CVE-2025-38202, CVE-2025-38248, CVE-2025-38254, CVE-2025-38426, CVE-2025-38429, CVE-2025-38364, CVE-2025-38388, CVE-2025-38435, CVE-2025-38403, CVE-2025-38186, CVE-2025-38199, CVE-2025-38402, CVE-2025-38181, CVE-2025-38264, CVE-2025-38362, CVE-2025-38341, CVE-2025-38422, CVE-2025-38331, CVE-2025-38423, CVE-2025-38233, CVE-2025-38337, CVE-2025-38328, CVE-2025-38196, CVE-2025-38412, CVE-2025-38205, CVE-2025-38242, CVE-2025-38324, CVE-2025-38354, CVE-2025-38347, CVE-2025-38217, CVE-2025-38393, CVE-2025-38392, CVE-2025-38390, CVE-2025-38321, CVE-2025-38541, CVE-2025-38363, CVE-2025-38203, CVE-2025-38250, CVE-2025-38418, CVE-2025-38336, CVE-2025-38333, CVE-2025-38194, CVE-2025-38372, CVE-2025-38348, CVE-2025-38370, CVE-2025-38411, CVE-2025-38188, CVE-2025-38365, CVE-2025-38241, CVE-2025-38201, CVE-2025-38259, CVE-2025-38355, CVE-2025-38227, CVE-2025-38225, CVE-2025-38405, CVE-2025-38329, CVE-2025-38232, CVE-2025-38344, CVE-2025-38238, CVE-2025-38239, CVE-2025-38260, CVE-2025-38257, CVE-2025-38399, CVE-2025-38419, CVE-2025-38430, CVE-2025-38251, CVE-2025-38332, CVE-2025-38220, CVE-2025-38417, CVE-2025-38396, CVE-2025-38234, CVE-2025-38434, CVE-2025-38197, CVE-2025-38436, CVE-2025-38408, CVE-2025-38204, CVE-2025-38222, CVE-2025-38361, CVE-2025-38218, CVE-2025-38212, CVE-2025-38198, CVE-2025-38255, CVE-2025-38389, CVE-2025-38085, CVE-2025-38244, CVE-2025-38089, CVE-2025-38428, CVE-2025-38369, CVE-2025-38189, CVE-2025-38084, CVE-2025-38400, CVE-2025-38382, CVE-2025-38223, CVE-2025-38325, CVE-2025-38263, CVE-2025-38249, CVE-2025-38346, CVE-2025-38320, CVE-2025-38409, CVE-2025-38374, CVE-2025-38208, CVE-2025-38256, CVE-2025-38371, CVE-2025-38192, CVE-2025-38406, CVE-2025-38360,CVE-2025-38258, CVE-2025-38226, CVE-2025-38376, CVE-2025-38375, CVE-2025-38200, CVE-2025-38523, CVE-2025-38334, CVE-2025-38236, CVE-2025-38386, CVE-2025-38421, CVE-2025-38087, CVE-2025-38416, CVE-2025-38179, CVE-2025-38420, CVE-2025-38424, CVE-2025-38377, CVE-2025-38359, CVE-2025-38342, CVE-2025-38431, CVE-2025-38407, CVE-2025-38427, CVE-2025-38229, CVE-2025-38353, CVE-2025-38383, CVE-2025-38211, CVE-2025-38322, CVE-2025-38381, CVE-2025-38261) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 linux-image-6.14.0-1014-realtime 6.14.0-1014.14 linux-image-6.14.0-1015-aws 6.14.0-1015.15 linux-image-6.14.0-1015-aws-64k 6.14.0-1015.15 linux-image-6.14.0-1015-oracle 6.14.0-1015.15 linux-image-6.14.0-1015-oracle-64k 6.14.0-1015.15 linux-image-6.14.0-1016-raspi 6.14.0-1016.16 linux-image-6.14.0-1018-gcp 6.14.0-1018.19 linux-image-6.14.0-1018-gcp-64k 6.14.0-1018.19 linux-image-6.14.0-34-generic 6.14.0-34.34 linux-image-6.14.0-34-generic-64k 6.14.0-34.34 linux-image-aws 6.14.0-1015.15 linux-image-aws-6.14 6.14.0-1015.15 linux-image-aws-64k 6.14.0-1015.15 linux-image-aws-64k-6.14 6.14.0-1015.15 linux-image-gcp 6.14.0-1018.19 linux-image-gcp-6.14 6.14.0-1018.19 linux-image-gcp-64k 6.14.0-1018.19 linux-image-gcp-64k-6.14 6.14.0-1018.19 linux-image-generic 6.14.0-34.34 linux-image-generic-6.14 6.14.0-34.34 linux-image-generic-64k 6.14.0-34.34 linux-image-generic-64k-6.14 6.14.0-34.34 linux-image-oracle 6.14.0-1015.15 linux-image-oracle-6.14 6.14.0-1015.15 linux-image-oracle-64k 6.14.0-1015.15 linux-image-oracle-64k-6.14 6.14.0-1015.15 linux-image-raspi 6.14.0-1016.16 linux-image-raspi-6.14 6.14.0-1016.16 linux-image-realtime 6.14.0-1014.14 linux-image-realtime-6.14 6.14.0-1014.14 linux-image-virtual 6.14.0-34.34 linux-image-virtual-6.14 6.14.0-34.34 Ubuntu 24.04 LTS linux-image-6.14.0-1014-oem 6.14.0-1014.14 linux-image-6.14.0-1015-oracle 6.14.0-1015.15~24.04.1 linux-image-6.14.0-1015-oracle-64k 6.14.0-1015.15~24.04.1 linux-image-oem-24.04 6.14.0-1014.14 linux-image-oem-24.04a 6.14.0-1014.14 linux-image-oem-24.04b 6.14.0-1014.14 linux-image-oem-24.04c 6.14.0-1014.14 linux-image-oem-6.14 6.14.0-1014.14 linux-image-oracle 6.14.0-1015.15~24.04.1 linux-image-oracle-6.14 6.14.0-1015.15~24.04.1 linux-image-oracle-64k 6.14.0-1015.15~24.04.1 linux-image-oracle-64k-6.14 6.14.0-1015.15~24.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7833-1 CVE-2024-36350, CVE-2024-36357, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38087, CVE-2025-38089, CVE-2025-38090, CVE-2025-38179, CVE-2025-38181, CVE-2025-38182, CVE-2025-38183, CVE-2025-38184, CVE-2025-38186, CVE-2025-38188, CVE-2025-38189, CVE-2025-38191, CVE-2025-38192, CVE-2025-38194, CVE-2025-38196, CVE-2025-38197, CVE-2025-38198, CVE-2025-38199, CVE-2025-38200, CVE-2025-38201, CVE-2025-38202, CVE-2025-38203, CVE-2025-38204, CVE-2025-38205, CVE-2025-38206, CVE-2025-38208, CVE-2025-38210, CVE-2025-38211, CVE-2025-38212, CVE-2025-38217,CVE-2025-38218, CVE-2025-38219, CVE-2025-38220, CVE-2025-38222, CVE-2025-38223, CVE-2025-38224, CVE-2025-38225, CVE-2025-38226, CVE-2025-38227, CVE-2025-38228, CVE-2025-38229, CVE-2025-38231, CVE-2025-38232, CVE-2025-38233, CVE-2025-38234, CVE-2025-38236, CVE-2025-38237, CVE-2025-38238, CVE-2025-38239, CVE-2025-38241, CVE-2025-38242, CVE-2025-38244, CVE-2025-38245, CVE-2025-38246, CVE-2025-38248, CVE-2025-38249, CVE-2025-38250, CVE-2025-38251, CVE-2025-38253, CVE-2025-38254, CVE-2025-38255, CVE-2025-38256, CVE-2025-38257, CVE-2025-38258, CVE-2025-38259, CVE-2025-38260, CVE-2025-38261, CVE-2025-38262, CVE-2025-38263, CVE-2025-38264, CVE-2025-38320, CVE-2025-38321, CVE-2025-38322, CVE-2025-38324, CVE-2025-38325, CVE-2025-38326, CVE-2025-38328, CVE-2025-38329, CVE-2025-38330, CVE-2025-38331, CVE-2025-38332, CVE-2025-38333, CVE-2025-38334, CVE-2025-38336, CVE-2025-38337, CVE-2025-38338, CVE-2025-38339, CVE-2025-38340, CVE-2025-38341, CVE-2025-38342, CVE-2025-38343, CVE-2025-38344, CVE-2025-38345, CVE-2025-38346, CVE-2025-38347, CVE-2025-38348, CVE-2025-38353, CVE-2025-38354, CVE-2025-38355, CVE-2025-38356, CVE-2025-38359, CVE-2025-38360, CVE-2025-38361, CVE-2025-38362, CVE-2025-38363, CVE-2025-38364, CVE-2025-38365, CVE-2025-38368, CVE-2025-38369, CVE-2025-38370, CVE-2025-38371, CVE-2025-38372, CVE-2025-38373, CVE-2025-38374, CVE-2025-38375, CVE-2025-38376, CVE-2025-38377, CVE-2025-38381, CVE-2025-38382, CVE-2025-38383, CVE-2025-38384, CVE-2025-38385, CVE-2025-38386, CVE-2025-38387, CVE-2025-38388, CVE-2025-38389, CVE-2025-38390, CVE-2025-38391, CVE-2025-38392, CVE-2025-38393, CVE-2025-38395, CVE-2025-38396, CVE-2025-38399, CVE-2025-38400, CVE-2025-38401, CVE-2025-38402, CVE-2025-38403, CVE-2025-38405, CVE-2025-38406, CVE-2025-38407, CVE-2025-38408, CVE-2025-38409, CVE-2025-38410, CVE-2025-38411, CVE-2025-38412, CVE-2025-38413, CVE-2025-38416, CVE-2025-38417, CVE-2025-38418, CVE-2025-38419,CVE-2025-38420, CVE-2025-38421, CVE-2025-38422, CVE-2025-38423, CVE-2025-38424, CVE-2025-38425, CVE-2025-38426, CVE-2025-38427, CVE-2025-38428, CVE-2025-38429, CVE-2025-38430, CVE-2025-38431, CVE-2025-38434, CVE-2025-38435, CVE-2025-38436, CVE-2025-38523, CVE-2025-38541, CVE-2025-39682 Package Information: https://launchpad.net/ubuntu/+source/linux/6.14.0-34.34 https://launchpad.net/ubuntu/+source/linux-aws/6.14.0-1015.15 https://launchpad.net/ubuntu/+source/linux-gcp/6.14.0-1018.19 . Critical fixes for the Linux kernel address multiple serious issues in Ubuntu 24.04 and 25.04 versions. Stay updated!. Linux Kernel Security Ubuntu Updates 2025. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.