Explore top 10 tips to secure your open-source projects now. Read More
×Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0272.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-14895 Description: The updated package fixes a security vulnerability: String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. (CVE-2026-14895) References: - https://bugs.mageia.org/show_bug.cgi?id=35858 - https://www.openwall.com/lists/oss-security/2026/07/07/18 - https://www.cve.org/CVERecord?id=CVE-2026-14895 SRPMS: - 10/core/perl-String-Util-1.350.0-2.1.mga10 - 9/core/perl-String-Util-1.340.0-1.1.mga9 . This update addresses a critical denial of service flaw in Perl String::Util affecting Mageia 10 and 9. Discover more.. Mageia, Perl, Denial of Service. . Severity: Critical. LinuxSecurity.com Team
33.0.6 Release. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-ee50c21f92 2026-07-05 01:07:02.694223+00:00 -------------------------------------------------------------------------------- Name : nextcloud Product : Fedora 44 Version : 33.0.6 Release : 1.fc44 URL : http://nextcloud.com Summary : Private file sync and share server Description : NextCloud gives you universal access to your files through a web interface or WebDAV. It also provides a platform to easily view & sync your contacts, calendars and bookmarks across all your devices and enables basic editing right on the web. NextCloud is extendable via a simple but powerful API for applications and plugins. -------------------------------------------------------------------------------- Update Information: 33.0.6 Release -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 26 2026 Andrew Bauer - 33.0.6-1 - 33.0.6 release * Tue Jun 9 2026 Brian J. Murrell - 33.0.5-2 - Dynamically determine which .map file to update the occ upgrade command in -------------------------------------------------------------------------------- References: [ 1 ] Bug #2486357 - nextcloud-34.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2486357 [ 2 ] Bug #2486491 - CVE-2026-41150 nextcloud: Mermaid: Denial of Service via specially crafted gantt charts [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486491 [ 3 ] Bug #2486496 - CVE-2026-41150 nextcloud: Mermaid: Denial of Service via specially crafted gantt charts [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486496 [ 4 ] Bug #2487344 - .map file update is fragile https://bugzilla.redhat.com/show_bug.cgi?id=2487344 [ 5 ] Bug #2487477 - CVE-2026-8723 nextcloud: qs: Denial of Service due to improper handling of null/undefined array elements [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2487477 [ 6 ] Bug #2487498 - CVE-2026-8723 nextcloud: qs: Denial of Service due to improper handling of null/undefined array elements [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2487498 [ 7 ] Bug #2488103 - CVE-2026-44495 nextcloud: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488103 [ 8 ] Bug #2488116 - CVE-2026-44489 nextcloud: Axios: Information disclosure via Prototype Pollution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488116 [ 9 ] Bug #2488118 - CVE-2026-44495 nextcloud: Axios: Information disclosure due to prototype pollution vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488118 [ 10 ] Bug #2488119 - CVE-2026-44489 nextcloud: Axios: Information disclosure via Prototype Pollution [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488119 [ 11 ] Bug #2488129 - CVE-2026-44490 nextcloud: Axios: Information disclosure and denial of service due to prototype pollution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488129 [ 12 ] Bug #2488137 - CVE-2026-44490 nextcloud: Axios: Information disclosure and denial of service due to prototype pollution [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488137 [ 13 ] Bug #2488146 - CVE-2026-44488 nextcloud: Axios: Denial of Service due to unenforced request and response size limits [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488146 [ 14 ] Bug #2488154 - CVE-2026-44488 nextcloud: Axios: Denial of Service due to unenforced request and response size limits [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488154 [ 15 ] Bug #2488159 - CVE-2026-44487 nextcloud: Axios: Information disclosure of proxy credentials via redirect flows [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488159 [ 16 ] Bug #2488171 - CVE-2026-44487nextcloud: Axios: Information disclosure of proxy credentials via redirect flows [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488171 [ 17 ] Bug #2488186 - CVE-2026-44494 nextcloud: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488186 [ 18 ] Bug #2488188 - CVE-2026-44494 nextcloud: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488188 [ 19 ] Bug #2488192 - CVE-2026-44486 nextcloud: Axios: Information disclosure of proxy credentials via HTTP redirects [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488192 [ 20 ] Bug #2488196 - CVE-2026-44486 nextcloud: Axios: Information disclosure of proxy credentials via HTTP redirects [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488196 [ 21 ] Bug #2488202 - CVE-2026-44496 nextcloud: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488202 [ 22 ] Bug #2488207 - CVE-2026-44496 nextcloud: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488207 [ 23 ] Bug #2488219 - CVE-2026-44492 nextcloud: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488219 [ 24 ] Bug #2488224 - CVE-2026-44492 nextcloud: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488224 [ 25 ] Bug #2488275 - CVE-2026-48998 nextcloud: guzzlehttp/psr7: Information disclosure via improper Host header validation [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488275 [ 26 ] Bug #2488278 - CVE-2026-48998 nextcloud: guzzlehttp/psr7: Information disclosure via improper Host headervalidation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488278 [ 27 ] Bug #2489107 - CVE-2026-49214 nextcloud: `guzzlehttp/psr7`: Request Smuggling and Cache Poisoning via HTTP Header Injection [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489107 [ 28 ] Bug #2489108 - CVE-2026-49214 nextcloud: `guzzlehttp/psr7`: Request Smuggling and Cache Poisoning via HTTP Header Injection [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489108 [ 29 ] Bug #2489147 - CVE-2026-41148 nextcloud: Mermaid: CSS injection vulnerability allows page defacement and information disclosure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489147 [ 30 ] Bug #2489154 - CVE-2026-41148 nextcloud: Mermaid: CSS injection vulnerability allows page defacement and information disclosure [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489154 [ 31 ] Bug #2489164 - CVE-2026-54133 nextcloud: jmespath.php has CompilerRuntime code injection via unescaped function names [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489164 [ 32 ] Bug #2489165 - CVE-2026-54133 nextcloud: jmespath.php has CompilerRuntime code injection via unescaped function names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489165 [ 33 ] Bug #2489259 - CVE-2026-41149 nextcloud: Mermaid: HTML injection via classDef directive in state diagrams [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489259 [ 34 ] Bug #2489262 - CVE-2026-41149 nextcloud: Mermaid: HTML injection via classDef directive in state diagrams [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489262 [ 35 ] Bug #2491652 - CVE-2026-42040 nextcloud: Axios: Incorrect null byte handling can lead to data integrity issues [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491652 [ 36 ] Bug #2491660 - CVE-2026-42040 nextcloud: Axios: Incorrect null byte handling can lead to data integrity issues [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491660 [ 37 ] Bug #2491781 - CVE-2026-55766 nextcloud: guzzlehttp/psr7: Information disclosure due to improper handling of CR/LF characters in HTTP start-line fields [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491781 [ 38 ] Bug #2491785 - CVE-2026-55766 nextcloud: guzzlehttp/psr7: Information disclosure due to improper handling of CR/LF characters in HTTP start-line fields [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491785 [ 39 ] Bug #2491789 - CVE-2026-55568 nextcloud: Guzzle: Information disclosure via cleartext proxy communication [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491789 [ 40 ] Bug #2491790 - CVE-2026-55767 nextcloud: Guzzle: Cookie injection and session fixation due to improper domain validation [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491790 [ 41 ] Bug #2491791 - CVE-2026-55568 nextcloud: Guzzle: Information disclosure via cleartext proxy communication [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491791 [ 42 ] Bug #2491792 - CVE-2026-55767 nextcloud: Guzzle: Cookie injection and session fixation due to improper domain validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491792 [ 43 ] Bug #2492891 - CVE-2026-42264 nextcloud: Axios: Prototype pollution allows information disclosure and request manipulation [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2492891 [ 44 ] Bug #2492905 - CVE-2026-42264 nextcloud: Axios: Prototype pollution allows information disclosure and request manipulation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2492905 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ee50c21f92' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Several security issues were fixed in Google Guest Agent.. ========================================================================== Ubuntu Security Notice USN-8447-3 June 22, 2026 google-guest-agent vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Google Guest Agent. Software Description: - google-guest-agent: Google Compute Engine Guest Agent Details: USN-8447-1 fixed vulnerabilities in Go Cryptography. This update provides the corresponding updates for Go Cryptography code embedded in Google Guest Agent. Original advisory details: It was discovered that Go Cryptography did not properly handle SSH global request responses. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-39830) It was discovered that Go Cryptography did not properly verify user presence when using FIDO/U2F security keys. An attacker could possibly use this issue to bypass user presence verification for hardware security keys. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-39831) It was discovered that Go Cryptography did not properly serialize SSH agent key constraint extensions. An attacker could possibly use this issue to bypass intended key usage restrictions. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-39832) It was discovered that Go Cryptography did not properly enforce the confirm-before-use constraint in the SSH agent keyring. An attacker could possibly use this issue to use SSH keys without the required user confirmation. (CVE-2026-39833) It was discovered that Go Cryptography had an integer overflow when handling large SSH channel writes. A remoteattacker could possibly use this issue to cause a denial of service. (CVE-2026-39834) It was discovered that Go Cryptography did not properly check certificate authority key revocation. An attacker could possibly use this issue to bypass certificate authority revocation checks. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42508) It was discovered that Go Cryptography did not properly enforce the source- address critical option for all SSH server callback types. An attacker could possibly use this issue to bypass source address authorization restrictions. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-46595) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS google-guest-agent 20250506.01-0ubuntu2.1 Ubuntu 25.10 google-guest-agent 20250506.01-0ubuntu1.2 Ubuntu 24.04 LTS google-guest-agent 20250116.00-0ubuntu1~24.04.4 Ubuntu 22.04 LTS google-guest-agent 20250116.00-0ubuntu1~22.04.3 Ubuntu 20.04 LTS google-guest-agent 20250116.00-0ubuntu1~20.04.0+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS google-guest-agent 20241011.01-0ubuntu1~18.04.0+esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS google-guest-agent 20240716.00-0ubuntu1~16.04.0+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8447-3 https://ubuntu.com/security/notices/USN-8447-2 https://ubuntu.com/security/notices/USN-8447-1 CVE-2026-39830, CVE-2026-39831, CVE-2026-39834, CVE-2026-46595 Package Information: https://launchpad.net/ubuntu/+source/google-guest-agent/20250506.01-0ubuntu2.1 https://launchpad.net/ubuntu/+source/google-guest-agent/20250506.01-0ubuntu1.2 https://launchpad.net/ubuntu/+source/google-guest-agent/20250116.00-0ubuntu1~24.04.4 https://launchpad.net/ubuntu/+source/google-guest-agent/20250116.00-0ubuntu1~22.04.3 . Explore the critical updates for Google Guest Agent on Ubuntu addressing several security issues and their impacts.. Google Guest Agent vulnerabilities, Ubuntu security updates, SSH issues. . Severity: Important. LinuxSecurity.com Team
Kea DHCP could be made to crash if it received specially crafted messages.. ========================================================================== Ubuntu Security Notice USN-8403-1 June 08, 2026 isc-kea vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS Summary: Kea DHCP could be made to crash if it received specially crafted messages. Software Description: - isc-kea: Standards-based DHCP server Details: Ali Norouzi discovered that Kea DHCP did not properly handle maliciously crafted messages over configured API sockets and HA listeners. A remote attacker could possibly use this issue to cause Kea DHCP to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 kea-admin 2.6.3-2ubuntu0.1 kea-common 2.6.3-2ubuntu0.1 kea-dhcp-ddns-server 2.6.3-2ubuntu0.1 kea-dhcp4-server 2.6.3-2ubuntu0.1 kea-dhcp6-server 2.6.3-2ubuntu0.1 Ubuntu 24.04 LTS kea-admin 2.4.1-3ubuntu0.2 kea-common 2.4.1-3ubuntu0.2 kea-dhcp-ddns-server 2.4.1-3ubuntu0.2 kea-dhcp4-server 2.4.1-3ubuntu0.2 kea-dhcp6-server 2.4.1-3ubuntu0.2 After a standard system update you may need to restart Kea DHCP server instances to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8403-1 CVE-2026-3608 Package Information: https://launchpad.net/ubuntu/+source/isc-kea/2.6.3-2ubuntu0.1 https://launchpad.net/ubuntu/+source/isc-kea/2.4.1-3ubuntu0.2 . Kea DHCP has a significant issue where crafted messages can cause crashes, impacting service availability. Update recommended.. Kea DHCP Denial of Service, Ubuntu Security Notice, isc-kea vulnerability, Update Required, SoftwareIssue. . Severity: Important. LinuxSecurity.com Team
New httpd packages are available for Slackware 15.0 and -current to fix a security issue.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] httpd (SSA:2026-154-01) New httpd packages are available for Slackware 15.0 and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/httpd-2.4.67-i586-2_slack15.0.txz: Rebuilt. This update fixes "HTTP/2 Bomb", a resource exhaustion denial-of-service attack against HTTP/2. For more information, see: https://seclists.org/oss-sec/2026/q2/790 https://www.cve.org/CVERecord?id=CVE-2026-49975 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://slackware.com for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/httpd-2.4.67-i586-2_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/httpd-2.4.67-x86_64-2_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/httpd-2.4.67-i686-2.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/httpd-2.4.67-x86_64-2.txz MD5 signatures: +-------------+ Slackware 15.0 package: fe1db72c286841174ff38534c6e6918d httpd-2.4.67-i586-2_slack15.0.txz Slackware x86_64 15.0 package: b14dd1a6d97a842eee7a5ecd7b8f0855 httpd-2.4.67-x86_64-2_slack15.0.txz Slackware -current package: eee9bd40cb210f87590334e724d2bde0 n/httpd-2.4.67-i686-2.txz Slackware x86_64 -current package: 594fcc2edd5ca2f41a3aade3b7d467bb n/httpd-2.4.67-x86_64-2.txz Installationinstructions: +------------------------+ Upgrade the package as root: # upgradepkg httpd-2.4.67-i586-2_slack15.0.txz Then, restart Apache httpd: # /etc/rc.d/rc.httpd stop # /etc/rc.d/rc.httpd start +-----+ . New httpd packages address security issues in Slackware 15.0 and -current ensuring system stability. Updates recommended.. HTTPD Security Update, Slackware Linux, Resource Exhaustion, Denial of Service, Security Advisory. . Severity: Important. LinuxSecurity.com Team
Important: fence-agents security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:13917", "synopsis": "Important: fence-agents security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for fence-agents.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. \n\nSecurity Fix(es):\n\n* pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2448553", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448553", "description": ""}], "cves": [{"name": "CVE-2026-30922", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-30922", "cvss3ScoringVector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-835"}], "references": [], "publishedAt": "2026-05-07T12:03:39.445016Z", "rpms": {"Rocky Linux 9": {"nvras": ["fence-agents-0:4.10.0-98.el9_7.13.src.rpm", "fence-agents-aliyun-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-all-0:4.10.0-98.el9_7.13.aarch64.rpm", "fence-agents-all-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-all-0:4.10.0-98.el9_7.13.s390x.rpm", "fence-agents-all-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-amt-ws-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-apc-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-apc-snmp-0:4.10.0-98.el9_7.13.noarch.rpm","fence-agents-aws-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-azure-arm-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-bladecenter-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-brocade-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-cisco-mds-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-cisco-ucs-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-common-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-compute-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-compute-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-debuginfo-0:4.10.0-98.el9_7.13.aarch64.rpm", "fence-agents-debuginfo-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-debuginfo-0:4.10.0-98.el9_7.13.s390x.rpm", "fence-agents-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-debugsource-0:4.10.0-98.el9_7.13.aarch64.rpm", "fence-agents-debugsource-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-debugsource-0:4.10.0-98.el9_7.13.s390x.rpm", "fence-agents-debugsource-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-drac5-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-eaton-snmp-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-emerson-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-eps-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-gce-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-heuristics-ping-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-hpblade-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ibmblade-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ibm-powervs-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ibm-vpc-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ifmib-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ilo2-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ilo-moonshot-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ilo-mp-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ilo-ssh-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-intelmodular-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ipdu-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ipmilan-0:4.10.0-98.el9_7.13.noarch.rpm","fence-agents-kdump-0:4.10.0-98.el9_7.13.aarch64.rpm", "fence-agents-kdump-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-kdump-0:4.10.0-98.el9_7.13.s390x.rpm", "fence-agents-kdump-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-kdump-debuginfo-0:4.10.0-98.el9_7.13.aarch64.rpm", "fence-agents-kdump-debuginfo-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-kdump-debuginfo-0:4.10.0-98.el9_7.13.s390x.rpm", "fence-agents-kdump-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-kubevirt-0:4.10.0-98.el9_7.13.aarch64.rpm", "fence-agents-kubevirt-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-kubevirt-0:4.10.0-98.el9_7.13.s390x.rpm", "fence-agents-kubevirt-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-kubevirt-debuginfo-0:4.10.0-98.el9_7.13.aarch64.rpm", "fence-agents-kubevirt-debuginfo-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-kubevirt-debuginfo-0:4.10.0-98.el9_7.13.s390x.rpm", "fence-agents-kubevirt-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-lpar-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-mpath-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-nutanix-ahv-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-openstack-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-openstack-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-redfish-0:4.10.0-98.el9_7.13.aarch64.rpm", "fence-agents-redfish-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-redfish-0:4.10.0-98.el9_7.13.s390x.rpm", "fence-agents-redfish-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-rhevm-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-rsa-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-rsb-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-sbd-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-scsi-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-virsh-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-vmware-rest-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-vmware-soap-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-wti-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-zvm-0:4.10.0-98.el9_7.13.s390x.rpm","fence-virt-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-cpg-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-cpg-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virt-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-libvirt-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-libvirt-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-multicast-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-multicast-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-serial-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-serial-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-tcp-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-tcp-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "ha-cloud-support-0:4.10.0-98.el9_7.13.ppc64le.rpm", "ha-cloud-support-0:4.10.0-98.el9_7.13.x86_64.rpm", "ha-cloud-support-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Security update for fence-agents on Rocky Linux addressing denial of service risks with CVE-2026-30922. Immediate action required.. Rocky Linux update, fence-agents security, important Linux security. . Severity: Important. LinuxSecurity.com Team
Important: resource-agents security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:13902", "synopsis": "Important: resource-agents security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for resource-agents.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The resource-agents packages provide the Pacemaker and RGManager service managers with a set of scripts. These scripts interface with several services to allow operating in a high-availability (HA) environment.\n\nSecurity Fix(es):\n\n* pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2448553", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448553", "description": ""}], "cves": [{"name": "CVE-2026-30922", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-30922", "cvss3ScoringVector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-835"}], "references": [], "publishedAt": "2026-05-07T06:01:03.840543Z", "rpms": {"Rocky Linux 8": {"nvras": ["resource-agents-0:4.9.0-54.el8_10.33.aarch64.rpm", "resource-agents-0:4.9.0-54.el8_10.33.src.rpm", "resource-agents-0:4.9.0-54.el8_10.33.x86_64.rpm", "resource-agents-aliyun-0:4.9.0-54.el8_10.33.x86_64.rpm", "resource-agents-aliyun-debuginfo-0:4.9.0-54.el8_10.33.x86_64.rpm", "resource-agents-debuginfo-0:4.9.0-54.el8_10.33.aarch64.rpm", "resource-agents-debuginfo-0:4.9.0-54.el8_10.33.x86_64.rpm", "resource-agents-debugsource-0:4.9.0-54.el8_10.33.aarch64.rpm","resource-agents-debugsource-0:4.9.0-54.el8_10.33.x86_64.rpm", "resource-agents-gcp-0:4.9.0-54.el8_10.33.x86_64.rpm", "resource-agents-paf-0:4.9.0-54.el8_10.33.aarch64.rpm", "resource-agents-paf-0:4.9.0-54.el8_10.33.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Critical security update for Rocky Linux addressing a denial of service threat in resource-agents. Act now!. Rocky Linux 8 security update denial of service resource-agents. . Severity: Important. LinuxSecurity.com Team
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For Debian 11 bullseye, these problems have been fixed in version 6.1.170-1~deb11u1.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4561-1
Get the latest Linux and open source security news straight to your inbox.