Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves five vulnerabilities can now be installed.. # Security update for openssl-1_1 Announcement ID: SUSE-SU-2026:2403-1 Release Date: 2026-06-16T06:53:41Z Rating: important References: * bsc#1266340 * bsc#1266341 * bsc#1266342 * bsc#1266349 * bsc#1266357 Cross-References: * CVE-2026-34180 * CVE-2026-42766 * CVE-2026-45447 * CVE-2026-7383 * CVE-2026-9076 CVSS scores: * CVE-2026-34180 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34180 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34180 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42766 ( SUSE ): 6.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42766 ( SUSE ): 5.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42766 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45447 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45447 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45447 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-7383 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7383 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7383 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9076 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-9076 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-9076 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves fivevulnerabilities can now be installed. ## Description: This update for openssl-1_1 fixes the following issues: * CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266357). * CVE-2026-42766: Possible NULL Dereference in Password-Based CMS Decryption (bsc#1266349). * CVE-2026-9076: Out-of-Bounds Read in CMS Password-Based Decryption (bsc#1266341). * CVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion (bsc#1266340). * CVE-2026-34180: Heap Buffer Over-read in ASN.1 Content Parsing (bsc#1266342). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2403=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2403=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl1_1-debuginfo-1.1.1d-2.131.1 * libopenssl1_1-1.1.1d-2.131.1 * libopenssl-1_1-devel-1.1.1d-2.131.1 * libopenssl1_1-hmac-1.1.1d-2.131.1 * openssl-1_1-debugsource-1.1.1d-2.131.1 * openssl-1_1-1.1.1d-2.131.1 * openssl-1_1-debuginfo-1.1.1d-2.131.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libopenssl1_1-32bit-1.1.1d-2.131.1 * libopenssl1_1-debuginfo-32bit-1.1.1d-2.131.1 * libopenssl1_1-hmac-32bit-1.1.1d-2.131.1 * libopenssl-1_1-devel-32bit-1.1.1d-2.131.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libopenssl1_1-debuginfo-1.1.1d-2.131.1 * libopenssl1_1-1.1.1d-2.131.1 * libopenssl1_1-hmac-32bit-1.1.1d-2.131.1 * libopenssl-1_1-devel-32bit-1.1.1d-2.131.1 * libopenssl-1_1-devel-1.1.1d-2.131.1 * libopenssl1_1-32bit-1.1.1d-2.131.1 * libopenssl1_1-debuginfo-32bit-1.1.1d-2.131.1 *libopenssl1_1-hmac-1.1.1d-2.131.1 * openssl-1_1-debugsource-1.1.1d-2.131.1 * openssl-1_1-1.1.1d-2.131.1 * openssl-1_1-debuginfo-1.1.1d-2.131.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34180.html * https://www.suse.com/security/cve/CVE-2026-42766.html * https://www.suse.com/security/cve/CVE-2026-45447.html * https://www.suse.com/security/cve/CVE-2026-7383.html * https://www.suse.com/security/cve/CVE-2026-9076.html * https://bugzilla.suse.com/show_bug.cgi?id=1266340 * https://bugzilla.suse.com/show_bug.cgi?id=1266341 * https://bugzilla.suse.com/show_bug.cgi?id=1266342 * https://bugzilla.suse.com/show_bug.cgi?id=1266349 * https://bugzilla.suse.com/show_bug.cgi?id=1266357 . SUSE releases security update for openssl-1_1 addressing five critical threats with detailed patch instructions.. SUSE Security Update OpenSSL Threats Patching Instructions. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:1906-1 Release Date: 2026-05-17T19:34:13Z Rating: important References: * bsc#1264459 Cross-References: * CVE-2026-43284 CVSS scores: * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.164 fixes one security issue The following security issue was fixed: * CVE-2026-43284: xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-1906=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1910=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-1910=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5(ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_299-default-3-2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_40-debugsource-19-150400.2.1 * kernel-livepatch-5_14_21-150400_24_164-default-19-150400.2.1 * kernel-livepatch-5_14_21-150400_24_164-default-debuginfo-19-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_40-debugsource-19-150400.2.1 * kernel-livepatch-5_14_21-150400_24_164-default-19-150400.2.1 * kernel-livepatch-5_14_21-150400_24_164-default-debuginfo-19-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43284.html * https://bugzilla.suse.com/show_bug.cgi?id=1264459 . SUSE Linux kernel update addresses CVE-2026-43284 critical issue, enhancing system security and stability.. SUSE kernel update, CVE-2026-43284, important security patch, Linux kernel vulnerabilities, system update notes. . Severity: Important. LinuxSecurity.com Team
* bsc#1218564 Cross-References: * CVE-2023-52323 . # Security update for python-pycryptodomex Announcement ID: SUSE-SU-2024:0557-1 Rating: moderate References: * bsc#1218564 Cross-References: * CVE-2023-52323 CVSS scores: * CVE-2023-52323 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2023-52323 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.5 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Package Hub 15 15-SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python-pycryptodomex fixes the following issues: * CVE-2023-52323: Fixed a side-channel in the OAEP decryption, exploitable by a Manger attack (bsc#1218564). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-557=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-557=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-557=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-557=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * python3-pycryptodomex-3.9.9-150300.3.3.1 * python-pycryptodomex-debugsource-3.9.9-150300.3.3.1 * python-pycryptodomex-debuginfo-3.9.9-150300.3.3.1 * python3-pycryptodomex-debuginfo-3.9.9-150300.3.3.1 * python2-pycryptodomex-3.9.9-150300.3.3.1 *python2-pycryptodomex-debuginfo-3.9.9-150300.3.3.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * python-pycryptodomex-debuginfo-3.9.9-150300.3.3.1 * python3-pycryptodomex-3.9.9-150300.3.3.1 * python3-pycryptodomex-debuginfo-3.9.9-150300.3.3.1 * python-pycryptodomex-debugsource-3.9.9-150300.3.3.1 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * python-pycryptodomex-debuginfo-3.9.9-150300.3.3.1 * python3-pycryptodomex-3.9.9-150300.3.3.1 * python3-pycryptodomex-debuginfo-3.9.9-150300.3.3.1 * python-pycryptodomex-debugsource-3.9.9-150300.3.3.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * python-pycryptodomex-debuginfo-3.9.9-150300.3.3.1 * python3-pycryptodomex-3.9.9-150300.3.3.1 * python3-pycryptodomex-debuginfo-3.9.9-150300.3.3.1 * python-pycryptodomex-debugsource-3.9.9-150300.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-52323.html * https://bugzilla.suse.com/show_bug.cgi?id=1218564 . A security patch for python-pycryptodomex resolves a medium-risk side-channel vulnerability. Act promptly!. Python security update, Pycryptodomex patch, SUSE advisory update. . Severity: Important. LinuxSecurity.com Team
The updated packages fix a security vulnerability: The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The spec says that a fixed length of 16 octets must be applied. Therefore this bug allows an attacker to provide a truncated Authentication Tag and to modify the JWE . MGASA-2023-0350 - Updated cjose packages fix a security vulnerability Publication date: 18 Dec 2023 URL: https://advisories.mageia.org/MGASA-2023-0350.html Type: security Affected Mageia releases: 8, 9 CVE: CVE-2023-37464 The updated packages fix a security vulnerability: The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The spec says that a fixed length of 16 octets must be applied. Therefore this bug allows an attacker to provide a truncated Authentication Tag and to modify the JWE accordingly. (CVE-2023-37464) References: - https://bugs.mageia.org/show_bug.cgi?id=32274 - https://lists.fedoraproject.org/archives/list/
Security fix for CVE-2023-37464. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-151d5b3da1 2023-09-10 01:18:51.874158 -------------------------------------------------------------------------------- Name : cjose Product : Fedora 38 Version : 0.6.2.2 Release : 2.fc38 URL : https://github.com/OpenIDC/cjose Summary : C library implementing the Javascript Object Signing and Encryption (JOSE) Description : Implementation of JOSE for C/C++ -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-37464 -------------------------------------------------------------------------------- ChangeLog: * Fri Sep 1 2023 Tomas Halman - 0.6.2.2-2 - migrated to SPDX license * Wed Jul 26 2023 Tomas Halman - 0.6.2.2-1 - Rebase to version 0.6.2.2. Solves CVE-2023-37464. Resolves: rhbz#2223330 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2223330 - TRIAGE-CVE-2023-37464 cjose: AES GCM decryption uses the Tag length from the actual Authentication Tag provided in the JWE [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2223330 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-151d5b3da1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
CVE-2021-4122 Milan Broz, its maintainer, discovered an issue in cryptsetup, the disk encryption configuration tool for Linux. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5070-1 security@debian.org https://www.debian.org/security/ Yves-Alexis Perez February 10, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : cryptsetup CVE ID : CVE-2021-4122 Debian Bug : 1003686 949336 CVE-2021-4122 Milan Broz, its maintainer, discovered an issue in cryptsetup, the disk encryption configuration tool for Linux. LUKS2 (an on-disk format) online reencryption is an optional extension to allow a user to change the data reencryption key while the data device is available for use during the whole reencryption process. An attacker can modify on-disk metadata to simulate decryption in progress with crashed (unfinished) reencryption step and persistently decrypt part of the LUKS2 device (LUKS1 devices are indirectly affected as well, see below). This attack requires repeated physical access to the LUKS2 device but no knowledge of user passphrases. The decryption step is performed after a valid user activates the device with a correct passphrase and modified metadata. The size of possible decrypted data per attack step depends on configured LUKS2 header size (metadata size is configurable for LUKS2). With the default LUKS2 parameters (16 MiB header) and only one allocated keyslot (512 bit key for AES-XTS), simulated decryption with checksum resilience SHA1 (20 bytes checksum for 4096-byte blocks), the maximal decrypted size can be over 3GiB. The attack is not applicable to LUKS1 format, but the attacker can update metadata in place to LUKS2 format as an additional step. For such a converted LUKS2header, the keyslot area is limited to decrypted size (with SHA1 checksums) over 300 MiB. LUKS devices that were formatted using a cryptsetup binary from Debian Stretch or earlier are using LUKS1. However since Debian Buster the default on-disk LUKS format version is LUKS2. In particular, encrypted devices formatted by the Debian Buster and Bullseye installers are using LUKS2 by default. Key truncation in dm-integrity This update additionaly fixes a key truncation issue for standalone dm-integrity devices using HMAC integrity protection. For existing such devices with extra long HMAC keys (typically > 106 bytes of length), one might need to manually truncate the key using integritysetup(8)'s `--integrity-key-size` option in order to properly map the device under 2:2.3.7-1+deb11u1 and later. Only standalone dm-integrity devices are affected. dm-crypt devices, including those using authenticated disk encryption, are unaffected. For the oldstable distribution (buster), this problem is not present. For the stable distribution (bullseye), this problem has been fixed in in version 2:2.3.7-1+deb11u1. We recommend that you upgrade your cryptsetup packages. For the detailed security status of cryptsetup please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/cryptsetup Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list:
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for bcm43xx-firmware ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:4003-1 Rating: important References: #1167162 Cross-References: CVE-2019-15126 CVSS scores: CVE-2019-15126 (NVD) : 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2019-15126 (SUSE): 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4-LTSS ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for bcm43xx-firmware fixes the following issues: - CVE-2019-15126: Fixed a bug which could have allowed unauthorized decryption of some WPA2-encrypted traffic (bsc#1167162). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-4003=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2021-4003=1 Package List: - SUSE Linux Enterprise Server 12-SP5 (noarch): bcm43xx-firmware-20180314-4.6.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (noarch): bcm43xx-firmware-20180314-4.6.1 References: https://www.suse.com/security/cve/CVE-2019-15126.html https://bugzilla.suse.com/1167162 . The latest bcm43xx-firmware release tackles a critical vulnerability in WPA2 encryption, enhancing security measures to guard against unauthorized network breaches.. bcm43xx-firmware update,SUSE advisory,WPA2 encryption fix. . Severity: Important.LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-rsa ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2237-1 Rating: important References: #1172389 Cross-References: CVE-2020-13757 CVSS scores: CVE-2020-13757 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2020-13757 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: SUSE OpenStack Cloud 7 SUSE Linux Enterprise Module for Public Cloud 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-rsa fixes the following issues: - CVE-2020-13757: Proper handling of leading '\0' bytes during decryption of ciphertext (bsc#1172389) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2021-2237=1 - SUSE Linux Enterprise Module for Public Cloud 12: zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2021-2237=1 Package List: - SUSE OpenStack Cloud 7 (noarch): python-rsa-3.1.4-12.16.1 - SUSE Linux Enterprise Module for Public Cloud 12 (noarch): python-rsa-3.1.4-12.16.1 References: https://www.suse.com/security/cve/CVE-2020-13757.html https://bugzilla.suse.com/1172389 . SUSE unveiled a significant security patch for python-rsa that resolves a pivotal decryption vulnerability.. SUSE Security Update, Python-RSA, OpenStack Cloud, Cloud Security. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.