Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # Security update for openssl-3 Announcement ID: SUSE-SU-2026:3004-1 Release Date: 2026-07-15T07:26:12Z Rating: moderate References: * bsc#1266350 Cross-References: * CVE-2026-42767 CVSS scores: * CVE-2026-42767 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42767 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for openssl-3 fixes the following issue * CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3004=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3004=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3004=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libopenssl-3-devel-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-3.1.4-150600.5.56.1 * libopenssl3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-3.1.4-150600.5.56.1 * libopenssl3-3.1.4-150600.5.56.1 * openssl-3-debugsource-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.56.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) *libopenssl-3-fips-provider-32bit-3.1.4-150600.5.56.1 * libopenssl3-32bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-32bit-debuginfo-3.1.4-150600.5.56.1 * libopenssl3-32bit-debuginfo-3.1.4-150600.5.56.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libopenssl-3-devel-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-3.1.4-150600.5.56.1 * libopenssl3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-3.1.4-150600.5.56.1 * libopenssl3-3.1.4-150600.5.56.1 * openssl-3-debugsource-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.56.1 * openSUSE Leap 15.6 (x86_64) * libopenssl-3-devel-32bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-32bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-32bit-debuginfo-3.1.4-150600.5.56.1 * libopenssl3-32bit-3.1.4-150600.5.56.1 * libopenssl3-32bit-debuginfo-3.1.4-150600.5.56.1 * openSUSE Leap 15.6 (noarch) * openssl-3-doc-3.1.4-150600.5.56.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libopenssl-3-devel-64bit-3.1.4-150600.5.56.1 * libopenssl3-64bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-64bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-64bit-debuginfo-3.1.4-150600.5.56.1 * libopenssl3-64bit-debuginfo-3.1.4-150600.5.56.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libopenssl-3-fips-provider-32bit-3.1.4-150600.5.56.1 * libopenssl3-32bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-32bit-debuginfo-3.1.4-150600.5.56.1 * libopenssl3-32bit-debuginfo-3.1.4-150600.5.56.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl-3-devel-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-3.1.4-150600.5.56.1 * libopenssl3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-3.1.4-150600.5.56.1 * libopenssl3-3.1.4-150600.5.56.1 * openssl-3-debugsource-3.1.4-150600.5.56.1 *libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.56.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42767.html * https://bugzilla.suse.com/show_bug.cgi?id=1266350 . Update for openssl-3 fixes NULL Pointer Dereference CVE-2026-42767 in openSUSE. Follow recommended patch instructions.. openssl update, decryption vulnerability, SUSE advisory, openSUSE Leap, security update. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for openssl-3 Announcement ID: SUSE-SU-2026:22437-1 Release Date: 2026-07-01T09:35:35Z Rating: moderate References: * bsc#1266350 Cross-References: * CVE-2026-42767 CVSS scores: * CVE-2026-42767 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42767 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for openssl-3 fixes the following issue * CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-776=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * openssl-3-debuginfo-3.1.4-15.1 * openssl-3-3.1.4-15.1 * libopenssl-3-devel-3.1.4-15.1 * libopenssl3-debuginfo-3.1.4-15.1 * openssl-3-debugsource-3.1.4-15.1 * libopenssl-3-fips-provider-3.1.4-15.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-15.1 * libopenssl3-3.1.4-15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42767.html * https://bugzilla.suse.com/show_bug.cgi?id=1266350 . Update available for openssl-3 on SUSE addressing moderate severity NULL Pointer issue.. SUSE security update, OpenSSL patch, decryption security, Linux Micro update. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:21696-1 Release Date: 2026-05-14T07:21:19Z Rating: important References: * bsc#1264459 Cross-References: * CVE-2026-43284 CVSS scores: * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes one security issue The following security issue was fixed: * CVE-2026-43284: xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-417=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-32-default-11-1.1 * kernel-livepatch-MICRO-6-0_Update_10-debugsource-11-1.1 * kernel-livepatch-6_4_0-32-default-debuginfo-11-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43284.html * https://bugzilla.suse.com/show_bug.cgi?id=1264459 . Important SUSE update addresses a critical xfrm decryption issue in Linux Kernel Live Patch 10 for better security.. SUSE Linux Micro Kernel Update, Security Patch, Decryption Issue, Kernel Live Patch. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:21712-1 Release Date: 2026-05-14T06:30:06Z Rating: important References: * bsc#1264459 Cross-References: * CVE-2026-43284 CVSS scores: * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-37.1 fixes one security issue The following security issue was fixed: * CVE-2026-43284: xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-406=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-37-rt-debuginfo-6-1.1 * kernel-livepatch-6_4_0-37-rt-6-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_13-debugsource-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43284.html * https://bugzilla.suse.com/show_bug.cgi?id=1264459 . Important patch for SUSE Linux Micro 6.0 addressing CVE-2026-43284 and enhancing system security.. kernel update, Linux Micro patch, SUSE security advisory, CVE-2026-43284. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:21715-1 Release Date: 2026-05-14T07:19:09Z Rating: important References: * bsc#1264459 Cross-References: * CVE-2026-43284 CVSS scores: * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes one security issue The following security issue was fixed: * CVE-2026-43284: xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-413=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_20-debugsource-2-1.1 * kernel-livepatch-6_4_0-42-rt-debuginfo-2-1.1 * kernel-livepatch-6_4_0-42-rt-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43284.html * https://bugzilla.suse.com/show_bug.cgi?id=1264459 . SUSE Linux Enterprise Micro 6.0 updates important security issue related to kernel RT, enhancing system integrity and security.. SUSE Linux, Kernel RT, Security Update, Live Patch, CVE-2026-43284. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 35 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:1877-1 Release Date: 2026-05-16T07:04:53Z Rating: important References: * bsc#1264459 Cross-References: * CVE-2026-43284 CVSS scores: * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.136 fixes one security issue The following security issue was fixed: * CVE-2026-43284: xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-1877=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-1877=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_136-default-debuginfo-6-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_35-debugsource-6-150500.2.1 * kernel-livepatch-5_14_21-150500_55_136-default-6-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_136-default-debuginfo-6-150500.2.1 *kernel-livepatch-SLE15-SP5_Update_35-debugsource-6-150500.2.1 * kernel-livepatch-5_14_21-150500_55_136-default-6-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43284.html * https://bugzilla.suse.com/show_bug.cgi?id=1264459 . SUSE Linux Kernel Live Patch 35 addresses an important issue, improving system security with a key update.. SUSE Linux, Kernel Update, Security Issue, Live Patch 35. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-28026 http://linux.oracle.com/errata/ELSA-2025-28026.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-5.4.17-2136.349.3.2.el7uek.x86_64.rpm kernel-uek-container-5.4.17-2136.349.3.2.el7uek.x86_64.rpm kernel-uek-container-debug-5.4.17-2136.349.3.2.el7uek.x86_64.rpm kernel-uek-debug-5.4.17-2136.349.3.2.el7uek.x86_64.rpm kernel-uek-debug-devel-5.4.17-2136.349.3.2.el7uek.x86_64.rpm kernel-uek-devel-5.4.17-2136.349.3.2.el7uek.x86_64.rpm kernel-uek-doc-5.4.17-2136.349.3.2.el7uek.noarch.rpm kernel-uek-tools-5.4.17-2136.349.3.2.el7uek.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/kernel-uek-5.4.17-2136.349.3.2.el7uek.src.rpm Related CVEs: CVE-2025-40019 Description of changes: [5.4.17-2136.349.3.2] - crypto: essiv - Check ssize for decryption and in-place encryption (Herbert Xu) [Orabug: 38705546] {CVE-2025-40019} _______________________________________________ El-errata mailing list
Version 0.18.1 Security Fixed critical issue where PKESK (public-key encrypted) session keys were generated as all-zero, allowing trivial decryption of messages encrypted with public keys only (CVE-2025-13402). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-bc8b81c28d 2025-11-29 19:57:40.628634+00:00 -------------------------------------------------------------------------------- Name : rnp Product : Fedora 41 Version : 0.18.1 Release : 1.fc41 URL : https://github.com/rnpgp/rnp Summary : OpenPGP (RFC4880) tools Description : RNP is a set of OpenPGP (RFC4880) tools. -------------------------------------------------------------------------------- Update Information: Version 0.18.1 Security Fixed critical issue where PKESK (public-key encrypted) session keys were generated as all-zero, allowing trivial decryption of messages encrypted with public keys only (CVE-2025-13402) -------------------------------------------------------------------------------- ChangeLog: * Fri Nov 21 2025 Remi Collet - 0.18.1-1 - update to 0.18.1 for CVE-2025-13402 - disable gpg check reported as https://github.com/rnpgp/rnp/issues/2375 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2415868 - CVE-2025-13402 rnp: RNP PKESK Session Keys Generated as All\u2011Zero [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2415868 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-bc8b81c28d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical fix for RNP in Fedora 41 addresses all-zero PKESK session key issue, enhancing message encryption security.. Fedora 41, RNP 0.18.1, encryption, security fix, PKESK issue. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.