Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
An update that solves two vulnerabilities and has two fixes is now available.. openSUSE Security Update: Security update for glusterfs ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0104-1 Rating: important References: #1208517 #1208519 #1210894 #1212476 Cross-References: CVE-2022-48340 CVE-2023-26253 CVSS scores: CVE-2022-48340 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2023-26253 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that solves two vulnerabilities and has two fixes is now available. Description: This update for glusterfs fixes the following issues: - Update to release 11.2 * Next minor release tentative date: Release will be based on requirement only * Users are highly encouraged to upgrade to newer releases of GlusterFS. * Important fixes in this release - Regression suite tests failures are addressed - Fixed notify stack-based buffer over-read (boo#1208519, CVE-2023-26253) - Update to release 11.1 * Fix upgrade issue by reverting posix change related to storage.reserve value * Fix possible data loss during rebalance if there is any linkfile on the system - Disable IO_uring for now [boo#1210894] - Update to release 11 [boo#1208517] [boo#1208519] * Major performance impovement of ~36% with rmdir operations * Extension of ZFS support for snapshots * Qouta implimentation based on namespace * Major cleanups and readdir/readdirp improvements * Fixed use-after-free in dht_setxattr_mds_cbk (CVE-2022-48340) - Update to release 10.2 * Some 165 bugfixes with none particularly sticking out Patch Instructions: To install this openSUSE Security Update usethe SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2026-104=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64): glusterfs-11.2-bp156.4.3.1 glusterfs-devel-11.2-bp156.4.3.1 libgfapi0-11.2-bp156.4.3.1 libgfchangelog0-11.2-bp156.4.3.1 libgfrpc0-11.2-bp156.4.3.1 libgfxdr0-11.2-bp156.4.3.1 libglusterfs0-11.2-bp156.4.3.1 - openSUSE Backports SLE-15-SP6 (noarch): python3-gluster-11.2-bp156.4.3.1 References: https://www.suse.com/security/cve/CVE-2022-48340.html https://www.suse.com/security/cve/CVE-2023-26253.html https://bugzilla.suse.com/1208517 https://bugzilla.suse.com/1208519 https://bugzilla.suse.com/1210894 https://bugzilla.suse.com/1212476 . Critical update for openSUSE glusterfs resolves important issues and two fixes, enhancing security and performance.. openSUSE glusterfs update important fixes security risk. . Severity: Important. LinuxSecurity.com Team
Nova could be made to destroy data.. ========================================================================== Ubuntu Security Notice USN-8049-1 February 17, 2026 nova vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Nova could be made to destroy data. Software Description: - nova: OpenStack Compute cloud infrastructure Details: Dan Smith discovered that Nova incorrectly called qemu-img without a format restriction when resizing disks. An attacker could possibly use this issue to destroy data on the host system. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 nova-common 3:32.0.0-0ubuntu1.1 python3-nova 3:32.0.0-0ubuntu1.1 Ubuntu 24.04 LTS nova-common 3:29.2.0-0ubuntu1.3 python3-nova 3:29.2.0-0ubuntu1.3 Ubuntu 22.04 LTS nova-common 3:25.2.1-0ubuntu2.10 python3-nova 3:25.2.1-0ubuntu2.10 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8049-1 CVE-2026-24708 Package Information: https://launchpad.net/ubuntu/+source/nova/3:32.0.0-0ubuntu1.1 https://launchpad.net/ubuntu/+source/nova/3:29.2.0-0ubuntu1.3 https://launchpad.net/ubuntu/+source/nova/3:25.2.1-0ubuntu2.10 . Critical advisory for Ubuntu on Nova identifies a severe data destruction risk leading to potential data loss.. Ubuntu Nova Cloud Data Loss Security Critical. . Severity: Critical. LinuxSecurity.com Team
An update that solves one vulnerability, contains two features and has three fixes can now be installed.. # Security update for docker Announcement ID: SUSE-SU-2026:20095-1 Release Date: 2026-01-17T13:20:26Z Rating: critical References: * bsc#1247367 * bsc#1247594 * bsc#1248373 * bsc#1250508 * jsc#PED-12534 * jsc#PED-8905 Cross-References: * CVE-2025-54388 CVSS scores: * CVE-2025-54388 ( SUSE ): 5.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2025-54388 ( SUSE ): 5.2 CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-54388 ( NVD ): 5.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54388 ( NVD ): 4.6 CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves one vulnerability, contains two features and has three fixes can now be installed. ## Description: This update for docker fixes the following issues: Changes in docker: * Update to Docker 28.5.1-ce. See upstream changelog online at * Update to Docker 28.5.0-ce. See upstream changelog online at * Update to docker-buildx v0.29.0. Upstream changelog: * Remove git-core recommends on SLE. Most SLE systems have installRecommends=yes by default and thus end up installing git with Docker. bsc#1250508 This feature is mostly intended for developers ("docker build git://") so most users already have the dependency installed, and the error when git is missing is fairly straightforward (so they can easily figure out what they need to install). * Update to docker-buildx v0.28.0. Upstream changelog: * Update to Docker 28.4.0-ce. See upstream changelog online at * Fixes a nil pointer panic in "docker push". bsc#1248373 * Update warnings and errorsrelated to "docker buildx ..." so that they reference our openSUSE docker-buildx packages. * Enable building docker-buildx for SLE15 systems with SUSEConnect secret injection enabled. PED-12534 PED-8905 bsc#1247594 As docker-buildx does not support our SUSEConnect secret injection (and some users depend "docker build" working transparently), patch the docker CLI so that "docker build" will no longer automatically call "docker buildx build", effectively making DOCKER_BUILDKIT=0 the default configuration. Users can manually use "docker buildx ..." commands or set DOCKER_BUILDKIT=1 in order to opt-in to using docker-buildx. Users can silence the "docker build" warning by setting DOCKER_BUILDKIT=0 explicitly. In order to inject SCC credentials with docker-buildx, users should use RUN --mount=type=secret,id=SCCcredentials zypper -n ... in their Dockerfiles, and docker buildx build --secret id=SCCcredentials,src=/etc/zypp/credentials.d/SCCcredentials,type=file . when doing their builds. * Update to Docker 28.3.3-ce. See upstream changelog online at CVE-2025-54388 bsc#1247367 * Update to docker-buildx v0.26.1. Upstream changelog: * Update to docker-buildx v0.26.0. Upstream changelog: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-151=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-151=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * docker-buildx-0.29.0-160000.4.1 * docker-debuginfo-28.5.1_ce-160000.4.1 * docker-28.5.1_ce-160000.4.1 * docker-buildx-debuginfo-0.29.0-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * docker-zsh-completion-28.5.1_ce-160000.4.1 *docker-bash-completion-28.5.1_ce-160000.4.1 * docker-rootless-extras-28.5.1_ce-160000.4.1 * docker-fish-completion-28.5.1_ce-160000.4.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * docker-buildx-0.29.0-160000.4.1 * docker-debuginfo-28.5.1_ce-160000.4.1 * docker-28.5.1_ce-160000.4.1 * docker-buildx-debuginfo-0.29.0-160000.4.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (noarch) * docker-zsh-completion-28.5.1_ce-160000.4.1 * docker-bash-completion-28.5.1_ce-160000.4.1 * docker-rootless-extras-28.5.1_ce-160000.4.1 * docker-fish-completion-28.5.1_ce-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54388.html * https://bugzilla.suse.com/show_bug.cgi?id=1247367 * https://bugzilla.suse.com/show_bug.cgi?id=1247594 * https://bugzilla.suse.com/show_bug.cgi?id=1248373 * https://bugzilla.suse.com/show_bug.cgi?id=1250508 * https://jira.suse.com/browse/PED-12534 * https://jira.suse.com/browse/PED-8905 . Critical update for SUSE Docker addresses a major security issue and introduces additional features and fixes.. Docker security update, SUSE Linux advisory, Linux critical patch. . Severity: Critical. LinuxSecurity.com Team
* bsc#1248672 * bsc#1249537 Cross-References: * CVE-2025-38500 . # Security update for kernel-livepatch-MICRO-6-0_Update_8 Announcement ID: SUSE-SU-2025:21111-1 Release Date: 2025-11-28T08:19:28Z Rating: important References: * bsc#1248672 * bsc#1249537 Cross-References: * CVE-2025-38500 * CVE-2025-38616 CVSS scores: * CVE-2025-38500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38616 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2025-38616 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_8 fixes the following issues: * CVE-2025-38500: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (bsc#1248672) * CVE-2025-38616: tls: handle data disappearing from under the TLS ULP (bsc#1249537) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-223=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-30-default-debuginfo-9-1.2 * kernel-livepatch-6_4_0-30-default-9-1.2 * kernel-livepatch-MICRO-6-0_Update_8-debugsource-9-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-38500.html * https://www.suse.com/security/cve/CVE-2025-38616.html * https://bugzilla.suse.com/show_bug.cgi?id=1248672 * https://bugzilla.suse.com/show_bug.cgi?id=1249537 . Security update for SUSE Linux Micro addresses important kernel issues improving overall systemintegrity and security.. kernel-livepatch SUSE Linux security patch important update. . Severity: Important. LinuxSecurity.com Team
* bsc#1249537 Cross-References: * CVE-2025-38616 . # Security update for kernel-livepatch-MICRO-6-0_Update_11 Announcement ID: SUSE-SU-2025:21113-1 Release Date: 2025-11-28T08:20:11Z Rating: important References: * bsc#1249537 Cross-References: * CVE-2025-38616 CVSS scores: * CVE-2025-38616 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2025-38616 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_11 fixes the following issues: * CVE-2025-38616: tls: handle data disappearing from under the TLS ULP (bsc#1249537) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-226=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_11-debugsource-3-1.1 * kernel-livepatch-6_4_0-34-default-debuginfo-3-1.1 * kernel-livepatch-6_4_0-34-default-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-38616.html * https://bugzilla.suse.com/show_bug.cgi?id=1249537 . SUSE kernel-livepatch update resolves important security flaw CVE-2025-38616 in Micro 6.1. Patch recommended for users.. SUSE Linux Micro 6.1, kernel-livepatch-MICRO, CVE-2025-38616, security update, important patch. . Severity: Important. LinuxSecurity.com Team
* bsc#1248672 * bsc#1249537 Cross-References: * CVE-2025-38500 . # Security update for kernel-livepatch-MICRO-6-0-RT_Update_8 Announcement ID: SUSE-SU-2025:21120-1 Release Date: 2025-11-28T08:19:29Z Rating: important References: * bsc#1248672 * bsc#1249537 Cross-References: * CVE-2025-38500 * CVE-2025-38616 CVSS scores: * CVE-2025-38500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38616 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2025-38616 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_8 fixes the following issues: * CVE-2025-38500: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (bsc#1248672) * CVE-2025-38616: tls: handle data disappearing from under the TLS ULP (bsc#1249537) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-213=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_8-debugsource-9-1.2 * kernel-livepatch-6_4_0-31-rt-debuginfo-9-1.2 * kernel-livepatch-6_4_0-31-rt-9-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-38500.html * https://www.suse.com/security/cve/CVE-2025-38616.html * https://bugzilla.suse.com/show_bug.cgi?id=1248672 * https://bugzilla.suse.com/show_bug.cgi?id=1249537 . This advisory details a critical security update for SUSE Linux Micro, addressing important kernel issuesrelated to data handling.. SUSE Linux Micro, kernel-livepatch, security update, data loss, important advisory. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2025:4268-1 Release Date: 2025-11-26T19:33:48Z Rating: important References: * bsc#1248672 * bsc#1249537 Cross-References: * CVE-2025-38500 * CVE-2025-38616 CVSS scores: * CVE-2025-38500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38616 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2025-38616 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 6.4.0-150600.23.60 fixes various security issues The following security issues were fixed: * CVE-2025-38500: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (bsc#1248672). * CVE-2025-38616: tls: handle data disappearing from under the TLS ULP (bsc#1249537). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-4268=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-4268=1 ## Package List: * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_60-default-debuginfo-8-150600.2.1 *kernel-livepatch-SLE15-SP6_Update_13-debugsource-8-150600.2.1 * kernel-livepatch-6_4_0-150600_23_60-default-8-150600.2.1 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_60-default-debuginfo-8-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_13-debugsource-8-150600.2.1 * kernel-livepatch-6_4_0-150600_23_60-default-8-150600.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-38500.html * https://www.suse.com/security/cve/CVE-2025-38616.html * https://bugzilla.suse.com/show_bug.cgi?id=1248672 * https://bugzilla.suse.com/show_bug.cgi?id=1249537 . Critical SUSE Linux kernel update addresses two important security flaws affecting multiple products and releases.. SUSE Linux, kernel security, important update, SUSE vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # tomcat11-11.0.10-1.1 on GA media Announcement ID: openSUSE-SU-2025:15491-1 Rating: moderate Cross-References: * CVE-2025-48989 CVSS scores: * CVE-2025-48989 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-48989 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the tomcat11-11.0.10-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * tomcat11 11.0.10-1.1 * tomcat11-admin-webapps 11.0.10-1.1 * tomcat11-doc 11.0.10-1.1 * tomcat11-docs-webapp 11.0.10-1.1 * tomcat11-el-6_0-api 11.0.10-1.1 * tomcat11-embed 11.0.10-1.1 * tomcat11-jsp-4_0-api 11.0.10-1.1 * tomcat11-jsvc 11.0.10-1.1 * tomcat11-lib 11.0.10-1.1 * tomcat11-servlet-6_1-api 11.0.10-1.1 * tomcat11-webapps 11.0.10-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-48989.html . An enhancement for openSUSE Tumbleweed addressing a significant vulnerability in Tomcat 11 (CVE-2025-48989) is now available.. openSUSE Tomcat11 update, security advisory, moderate severity. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.