Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for python-soupsieve ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21342-1 Rating: important References: * bsc#1271187 * bsc#1271188 Cross-References: * CVE-2026-49476 * CVE-2026-49477 CVSS scores: * CVE-2026-49476 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49477 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for python-soupsieve fixes the following issues - CVE-2026-49476: Memory Exhaustion via Large Comma-Separated Selector Lists (bsc#1271187). - CVE-2026-49477: Regular Expression Denial of Service (ReDoS) via Selector Parser (bsc#1271188). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1246=1 Package List: - openSUSE Leap 16.0: python313-soupsieve-2.6-160000.4.1 References: * https://www.suse.com/security/cve/CVE-2026-49476.html * https://www.suse.com/security/cve/CVE-2026-49477.html . A security update for openSUSE addresses 2 vulnerabilities in python-soupsieve with important fixes for memory exhaustion and denial of service issues.. openSUSE python-soupsieve vulnerabilities important updates. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-19372 http://linux.oracle.com/errata/ELSA-2026-19372.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: nginx-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.x86_64.rpm nginx-all-modules-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.noarch.rpm nginx-core-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.x86_64.rpm nginx-filesystem-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.noarch.rpm nginx-mod-devel-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.x86_64.rpm nginx-mod-http-image-filter-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.x86_64.rpm nginx-mod-http-perl-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.x86_64.rpm nginx-mod-http-xslt-filter-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.x86_64.rpm nginx-mod-mail-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.x86_64.rpm nginx-mod-stream-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.x86_64.rpm aarch64: nginx-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.aarch64.rpm nginx-all-modules-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.noarch.rpm nginx-core-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.aarch64.rpm nginx-filesystem-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.noarch.rpm nginx-mod-devel-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.aarch64.rpm nginx-mod-http-image-filter-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.aarch64.rpm nginx-mod-http-perl-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.aarch64.rpm nginx-mod-http-xslt-filter-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.aarch64.rpm nginx-mod-mail-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.aarch64.rpm nginx-mod-stream-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/nginx-1.26.3-9.0.1.module+el9.8.0+90902+e2e6d896.src.rpm Related CVEs: CVE-2026-42945 Description of changes: [1.26.3-9.0.1] - Require oracle-indexhtml [2:1.26.3-9] - Resolves: RHEL-176218 - nginx:1.26/nginx: NGINX: Arbitrary CodeExecution Vulnerability (CVE-2026-42945) [2:1.26.3-8] - CVE-2026-32647 nginx:1.26/nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files [2:1.26.3-7] - CVE-2026-27651 nginx:1.26/nginx: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled [2:1.26.3-6] - CVE-2026-27784 nginx:1.26/nginx: NGINX: Denial of Service due to memory corruption via crafted MP4 file [2:1.26.3-5] - CVE-2026-27654 nginx:1.26/nginx: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module [2:1.26.3-4] - CVE-2026-1642 nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections [2:1.26.3-3] - Resolves: RHEL-144454 - Clarify binding behavior of -t option [2:1.26.3-2] - Add tmpfiles.d rules for /var directories (bootc compatibility) [2:1.26.3-1] - New version 1.26.3 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-26534 http://linux.oracle.com/errata/ELSA-2026-26534.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: dracut-049-244.git20260529.0.1.el8_10.x86_64.rpm dracut-caps-049-244.git20260529.0.1.el8_10.x86_64.rpm dracut-config-generic-049-244.git20260529.0.1.el8_10.x86_64.rpm dracut-config-rescue-049-244.git20260529.0.1.el8_10.x86_64.rpm dracut-live-049-244.git20260529.0.1.el8_10.x86_64.rpm dracut-network-049-244.git20260529.0.1.el8_10.x86_64.rpm dracut-squash-049-244.git20260529.0.1.el8_10.x86_64.rpm dracut-tools-049-244.git20260529.0.1.el8_10.x86_64.rpm aarch64: dracut-049-244.git20260529.0.1.el8_10.aarch64.rpm dracut-caps-049-244.git20260529.0.1.el8_10.aarch64.rpm dracut-config-generic-049-244.git20260529.0.1.el8_10.aarch64.rpm dracut-config-rescue-049-244.git20260529.0.1.el8_10.aarch64.rpm dracut-live-049-244.git20260529.0.1.el8_10.aarch64.rpm dracut-network-049-244.git20260529.0.1.el8_10.aarch64.rpm dracut-squash-049-244.git20260529.0.1.el8_10.aarch64.rpm dracut-tools-049-244.git20260529.0.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/dracut-049-244.git20260529.0.1.el8_10.src.rpm Related CVEs: CVE-2026-6893 Description of changes: [049-244.git20260529.0.1] - Refactor get_ucode_file [Orabug: 36989953] - Revert the fixes for bugs 33676753 and 33888951 due to regressions [Orabug: 35656614] - Fix typo in orabug33888951-dracut-Enable-the-code-to-create-ifcfg-file.patch [Orabug: 35268918] - Enable the code to create ifcfg file [Orabug: 33888951] - Skip parse iscsiroot.sh on PV VMs [Orabug: 33676753] - Add blk_mq_alloc_disk and blk_cleanup_disk to blockfuncs [Orabug: 33603682] - Change installation dir in network legacy module-setup so that file is never missing [Orabug: 33516170] - Fix paths in squash module, so that correct modprobe is installed [Orabug: 33514517] - Restore51-dracut-rescue-postinst.sh for anaconda compatibility - Install missing 68-del-part-node.rules [Orabug: 32827579] - Add manpage for single-dhcp [Orabug 32201686] - Fix permission denied error while upgrading from OL8u2 to OL8u3 [Orabug 32160196] - Use pgrep in dhcp-multi.sh to make efficient and error free [Orabug 32254008] - Send DHCP request in parallel on all interfaces for 80% boot time improvement [Orabug: 32034110] - Revert fix for [Orabug: 31404167] - drop 51-dracut-rescue.install patch - Send DHCP query only on min BDF device to improve boot times by 50-60 secs [Orabug: 31404167] - add ofb and cts to 01fips kernel module list [Orabug: 30622737] - dracut-shutdown.service should run before shutdown.target is invoked [Orabug: 29629738] - Fix kernel-core POSTTRANS script issues with kernel command line [Orabug: 29542203] - Update list of necessary files after squashfs execution [Orabug: 29864620] - Supress iscsidm error output during non-debug PV boot [Orabug: 29846195] - Stop block device service in case system is dropped to emergency shell [Orabug: 29851988] - Enable booting from block device if netroot=iscsi has failed [Orabug: 29478156] - Fix BOOTPROTO calculation for iscsi [Orabug: 29518713] - Calculate relative path for kernel and initrd in 51-dracut-rescue.instal [Orabug: 29503293] - 40network scripts ifup and netlib updates for iSCSI [Orabug: 28502725] - Increase timeout when waiting for carrier detection on a network interface [Orabug: 24657828] (
33.0.5 Release. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-cb3feafe41 2026-06-17 08:24:34.389285+00:00 -------------------------------------------------------------------------------- Name : nextcloud Product : Fedora 43 Version : 33.0.5 Release : 1.fc43 URL : http://nextcloud.com Summary : Private file sync and share server Description : NextCloud gives you universal access to your files through a web interface or WebDAV. It also provides a platform to easily view & sync your contacts, calendars and bookmarks across all your devices and enables basic editing right on the web. NextCloud is extendable via a simple but powerful API for applications and plugins. -------------------------------------------------------------------------------- Update Information: 33.0.5 Release -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 8 2026 Andrew Bauer - 33.0.5-1 - 33.0.5 Release -------------------------------------------------------------------------------- References: [ 1 ] Bug #2483840 - CVE-2026-45690 nextcloud: Nextcloud Server: Authentication bypass allows unauthorized access by circumventing two-factor authentication. [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2483840 [ 2 ] Bug #2483841 - CVE-2026-45690 nextcloud: Nextcloud Server: Authentication bypass allows unauthorized access by circumventing two-factor authentication. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2483841 [ 3 ] Bug #2483842 - CVE-2026-45810 nextcloud: Nextcloud Server: Information disclosure via missing relation check in file comments [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2483842 [ 4 ] Bug #2483843 - CVE-2026-45285 nextcloud: Nextcloud: Unauthorized data access and modification via unlisted public links [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2483843 [ 5 ] Bug #2483844 - CVE-2026-45691 nextcloud: Nextcloud Server: Two-factor authentication bypass via session cookie reuse [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2483844 [ 6 ] Bug #2483845 - CVE-2026-45279 nextcloud: Nextcloud Server: Path traversal vulnerability allows unauthorized file copying [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2483845 [ 7 ] Bug #2483846 - CVE-2026-45810 nextcloud: Nextcloud Server: Information disclosure via missing relation check in file comments [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2483846 [ 8 ] Bug #2483847 - CVE-2026-45281 nextcloud: Nextcloud Server: Authenticated users can gain full calendar access due to improper authorization. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2483847 [ 9 ] Bug #2483848 - CVE-2026-45281 nextcloud: Nextcloud Server: Authenticated users can gain full calendar access due to improper authorization. [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2483848 [ 10 ] Bug #2483849 - CVE-2026-45285 nextcloud: Nextcloud: Unauthorized data access and modification via unlisted public links [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2483849 [ 11 ] Bug #2483850 - CVE-2026-45279 nextcloud: Nextcloud Server: Path traversal vulnerability allows unauthorized file copying [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2483850 [ 12 ] Bug #2483851 - CVE-2026-45691 nextcloud: Nextcloud Server: Two-factor authentication bypass via session cookie reuse [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2483851 [ 13 ] Bug #2484167 - CVE-2026-45155 nextcloud: Nextcloud Server: Information disclosure due to missing API access check [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2484167 [ 14 ] Bug #2484168 - CVE-2026-45157 nextcloud: Nextcloud Server: Information disclosure via file share token [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2484168 [ 15 ] Bug #2484169 - CVE-2026-45155 nextcloud: Nextcloud Server: Information disclosure due to missing API access check [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2484169 [ 16 ] Bug #2484170 - CVE-2026-45283 nextcloud: Nextcloud Server: Unauthorized file modification and denial of service via improper WebDAV handling [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2484170 [ 17 ] Bug #2484171 - CVE-2026-45157 nextcloud: Nextcloud Server: Information disclosure via file share token [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2484171 [ 18 ] Bug #2484172 - CVE-2026-45283 nextcloud: Nextcloud Server: Unauthorized file modification and denial of service via improper WebDAV handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2484172 [ 19 ] Bug #2484572 - CVE-2026-45282 nextcloud: Nextcloud Server: Information disclosure via circumventing link share protections [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2484572 [ 20 ] Bug #2484573 - CVE-2026-45282 nextcloud: Nextcloud Server: Information disclosure via circumventing link share protections [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2484573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-cb3feafe41' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
.NET could be made to consume excessive resources if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-8298-1 May 25, 2026 dotnet8, dotnet9, dotnet10 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: .NET could be made to consume excessive resources if it received specially crafted network traffic. Software Description: - dotnet10: .NET CLI tools and runtime - dotnet8: .NET CLI tools and runtime - dotnet9: .NET CLI tools and runtime Details: Muhammad Abdul Rehman discovered that .NET incorrectly handled certain network requests, leading to a loop with an unreachable exit condition. A remote attacker could possibly use this issue to consume excessive resources, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS aspnetcore-runtime-10.0 10.0.8-0ubuntu1~26.04.1 dotnet-host-10.0 10.0.8-0ubuntu1~26.04.1 dotnet-hostfxr-10.0 10.0.8-0ubuntu1~26.04.1 dotnet-runtime-10.0 10.0.8-0ubuntu1~26.04.1 dotnet-sdk-10.0 10.0.108-0ubuntu1~26.04.1 dotnet-sdk-aot-10.0 10.0.108-0ubuntu1~26.04.1 dotnet-sdk-dbg-10.0 10.0.108-0ubuntu1~26.04.1 dotnet10 10.0.108-10.0.8-0ubuntu1~26.04.1 Ubuntu 25.10 aspnetcore-runtime-10.0 10.0.8-0ubuntu1~25.10.1 aspnetcore-runtime-8.0 8.0.27-0ubuntu1~25.10.1 aspnetcore-runtime-9.0 9.0.16-0ubuntu1~25.10.1 dotnet-host-10.0 10.0.8-0ubuntu1~25.10.1 dotnet-host-8.0 8.0.27-0ubuntu1~25.10.1 dotnet-host-9.0 9.0.16-0ubuntu1~25.10.1 dotnet-hostfxr-10.0 10.0.8-0ubuntu1~25.10.1 dotnet-hostfxr-8.0 8.0.27-0ubuntu1~25.10.1 dotnet-hostfxr-9.0 9.0.16-0ubuntu1~25.10.1 dotnet-runtime-10.0 10.0.8-0ubuntu1~25.10.1 dotnet-runtime-8.0 8.0.27-0ubuntu1~25.10.1 dotnet-runtime-9.0 9.0.16-0ubuntu1~25.10.1 dotnet-sdk-10.0 10.0.108-0ubuntu1~25.10.1 dotnet-sdk-8.0 8.0.127-0ubuntu1~25.10.1 dotnet-sdk-9.0 9.0.117-0ubuntu1~25.10.1 dotnet-sdk-aot-10.0 10.0.108-0ubuntu1~25.10.1 dotnet-sdk-aot-9.0 9.0.117-0ubuntu1~25.10.1 dotnet-sdk-dbg-10.0 10.0.108-0ubuntu1~25.10.1 dotnet-sdk-dbg-8.0 8.0.127-0ubuntu1~25.10.1 dotnet-sdk-dbg-9.0 9.0.117-0ubuntu1~25.10.1 dotnet10 10.0.108-10.0.8-0ubuntu1~25.10.1 dotnet8 8.0.127-8.0.27-0ubuntu1~25.10.1 dotnet9 9.0.117-9.0.16-0ubuntu1~25.10.1 Ubuntu 24.04 LTS aspnetcore-runtime-10.0 10.0.8-0ubuntu1~24.04.1 aspnetcore-runtime-8.0 8.0.27-0ubuntu1~24.04.1 dotnet-host-10.0 10.0.8-0ubuntu1~24.04.1 dotnet-host-8.0 8.0.27-0ubuntu1~24.04.1 dotnet-hostfxr-10.0 10.0.8-0ubuntu1~24.04.1 dotnet-hostfxr-8.0 8.0.27-0ubuntu1~24.04.1 dotnet-runtime-10.0 10.0.8-0ubuntu1~24.04.1 dotnet-runtime-8.0 8.0.27-0ubuntu1~24.04.1 dotnet-sdk-10.0 10.0.108-0ubuntu1~24.04.1 dotnet-sdk-8.0 8.0.127-0ubuntu1~24.04.1 dotnet-sdk-aot-10.0 10.0.108-0ubuntu1~24.04.1 dotnet-sdk-dbg-10.0 10.0.108-0ubuntu1~24.04.1 dotnet10 10.0.108-10.0.8-0ubuntu1~24.04.1 dotnet8 8.0.127-8.0.27-0ubuntu1~24.04.1 Ubuntu 22.04 LTS aspnetcore-runtime-8.0 8.0.27-0ubuntu1~22.04.1 dotnet-host-8.0 8.0.27-0ubuntu1~22.04.1 dotnet-hostfxr-8.0 8.0.27-0ubuntu1~22.04.1 dotnet-runtime-8.0 8.0.27-0ubuntu1~22.04.1 dotnet-sdk-8.0 8.0.127-0ubuntu1~22.04.1 dotnet8 8.0.127-8.0.27-0ubuntu1~22.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8298-1 CVE-2026-42899 Package Information: https://launchpad.net/ubuntu/+source/dotnet10/10.0.108-10.0.8-0ubuntu1~26.04.1 https://launchpad.net/ubuntu/+source/dotnet10/10.0.108-10.0.8-0ubuntu1~25.10.1 https://launchpad.net/ubuntu/+source/dotnet8/8.0.127-8.0.27-0ubuntu1~25.10.1 https://launchpad.net/ubuntu/+source/dotnet9/9.0.117-9.0.16-0ubuntu1~25.10.1 https://launchpad.net/ubuntu/+source/dotnet10/10.0.108-10.0.8-0ubuntu1~24.04.1 https://launchpad.net/ubuntu/+source/dotnet8/8.0.127-8.0.27-0ubuntu1~24.04.1 https://launchpad.net/ubuntu/+source/dotnet8/8.0.127-8.0.27-0ubuntu1~22.04.1 . A critical security advisory for Ubuntu .NET handling excessive resource consumption due to crafted network traffic.. Ubuntu .NET Security, excessive resources, denial of service. . Severity: Critical. LinuxSecurity.com Team
Important: firefox security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:8052", "synopsis": "Important: firefox security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for firefox.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.\n\nSecurity Fix(es):\n\n* libpng: libpng: Arbitrary code execution due to use-after-free vulnerability (CVE-2026-33416)\n\n* libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion (CVE-2026-33636)\n\n* thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 (CVE-2026-5734)\n\n* thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 (CVE-2026-5731)\n\n* firefox: thunderbird: Incorrect boundary conditions, integer overflow in the Graphics: Text component (CVE-2026-5732)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2451805", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2451805", "description": ""}, {"ticket": "2451819", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2451819", "description": ""}, {"ticket": "2455897", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2455897", "description": ""}, {"ticket": "2455901", "sourceBy": "Red Hat", "sourceLink":"https://bugzilla.redhat.com/show_bug.cgi?id=2455901", "description": ""}, {"ticket": "2455908", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2455908", "description": ""}], "cves": [{"name": "CVE-2026-33416", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-33416", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-825"}, {"name": "CVE-2026-33636", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-33636", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H", "cvss3BaseScore": "7.6", "cwe": "CWE-124"}, {"name": "CVE-2026-5731", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-5731", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-787"}, {"name": "CVE-2026-5732", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-5732", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-190"}, {"name": "CVE-2026-5734", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-5734", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-787"}], "references": [], "publishedAt": "2026-04-16T12:00:34.288576Z", "rpms": {"Rocky Linux 8": {"nvras": ["firefox-0:140.9.1-1.el8_10.aarch64.rpm", "firefox-0:140.9.1-1.el8_10.src.rpm", "firefox-0:140.9.1-1.el8_10.x86_64.rpm", "firefox-debuginfo-0:140.9.1-1.el8_10.aarch64.rpm", "firefox-debuginfo-0:140.9.1-1.el8_10.x86_64.rpm", "firefox-debugsource-0:140.9.1-1.el8_10.aarch64.rpm", "firefox-debugsource-0:140.9.1-1.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important security update for Firefox in Rocky Linux 8 addresses critical vulnerabilities affecting users. Update now!. Rocky Linux Firefox Security Update Arbitrary Code Execution Denial of Service. . Severity:Important. LinuxSecurity.com Team
An update that solves four vulnerabilities can now be installed.. # Security update for libsoup Announcement ID: SUSE-SU-2026:0658-1 Release Date: 2026-02-26T15:07:42Z Rating: important References: * bsc#1240751 * bsc#1258120 * bsc#1258170 * bsc#1258508 Cross-References: * CVE-2025-32049 * CVE-2026-2369 * CVE-2026-2443 * CVE-2026-2708 CVSS scores: * CVE-2025-32049 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-32049 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-32049 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-2369 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-2369 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-2443 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-2443 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-2443 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-2708 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-2708 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N Affected Products: * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves four vulnerabilities can now be installed. ## Description: This update for libsoup fixes the following issues: * CVE-2025-32049: denial of Service attack to websocket server (bsc#1240751). * CVE-2026-2369: buffer overread due to integer underflow when handling zero- length resources (bsc#1258120). * CVE-2026-2443: out-of-bounds read when processing specially crafted HTTP Range headers can lead to heap information disclosure to remote attackers (bsc#1258170). * CVE-2026-2708: HTTP request smuggling via duplicate Content-Length headers (bsc#1258508). ## Patch Instructions: To install this SUSE update use the SUSErecommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-658=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-658=1 ## Package List: * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libsoup-2_4-1-2.68.4-150200.4.30.1 * libsoup-debugsource-2.68.4-150200.4.30.1 * libsoup-2_4-1-debuginfo-2.68.4-150200.4.30.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libsoup-2_4-1-2.68.4-150200.4.30.1 * libsoup-debugsource-2.68.4-150200.4.30.1 * libsoup-2_4-1-debuginfo-2.68.4-150200.4.30.1 ## References: * https://www.suse.com/security/cve/CVE-2025-32049.html * https://www.suse.com/security/cve/CVE-2026-2369.html * https://www.suse.com/security/cve/CVE-2026-2443.html * https://www.suse.com/security/cve/CVE-2026-2708.html * https://bugzilla.suse.com/show_bug.cgi?id=1240751 * https://bugzilla.suse.com/show_bug.cgi?id=1258120 * https://bugzilla.suse.com/show_bug.cgi?id=1258170 * https://bugzilla.suse.com/show_bug.cgi?id=1258508 . Update for SUSE addresses important issues in libsoup to enhance system protection against threats.. SUSE Update, libsoup Security, Denial of Service, Security Fix, Important Patch. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for krb5 Announcement ID: SUSE-SU-2025:3729-1 Release Date: 2025-10-22T13:19:36Z Rating: moderate References: * bsc#1241219 Cross-References: * CVE-2025-3576 CVSS scores: * CVE-2025-3576 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-3576 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-3576 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for krb5 fixes the following issues: * CVE-2025-3576: weakness in the MD5 checksum design allows for spoofing of GSSAPI-protected messages that are using RC4-HMAC-MD5 (bsc#1241219). Krb5 as very old protocol supported quite a number of ciphers that are not longer up to current cryptographic standards. To avoid problems with those, SUSE has by default now disabled those alorithms. The following algorithms have been removed from valid krb5 enctypes: * des3-cbc-sha1 * arcfour-hmac-md5 To reenable those algorithms, you can use allow options in krb5.conf: [libdefaults] allow_des3 = true allow_rc4 = true to reenable them. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3729=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3729=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-3729=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patchSUSE-SLE-Micro-5.3-2025-3729=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3729=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * krb5-1.19.2-150400.3.18.1 * krb5-debugsource-1.19.2-150400.3.18.1 * krb5-debuginfo-1.19.2-150400.3.18.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * krb5-1.19.2-150400.3.18.1 * krb5-debugsource-1.19.2-150400.3.18.1 * krb5-debuginfo-1.19.2-150400.3.18.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * krb5-devel-1.19.2-150400.3.18.1 * krb5-mini-debugsource-1.19.2-150400.3.18.1 * krb5-client-debuginfo-1.19.2-150400.3.18.1 * krb5-client-1.19.2-150400.3.18.1 * krb5-plugin-preauth-pkinit-1.19.2-150400.3.18.1 * krb5-plugin-preauth-spake-debuginfo-1.19.2-150400.3.18.1 * krb5-mini-debuginfo-1.19.2-150400.3.18.1 * krb5-plugin-preauth-spake-1.19.2-150400.3.18.1 * krb5-plugin-kdb-ldap-1.19.2-150400.3.18.1 * krb5-debuginfo-1.19.2-150400.3.18.1 * krb5-mini-1.19.2-150400.3.18.1 * krb5-plugin-preauth-pkinit-debuginfo-1.19.2-150400.3.18.1 * krb5-mini-devel-1.19.2-150400.3.18.1 * krb5-1.19.2-150400.3.18.1 * krb5-plugin-preauth-otp-debuginfo-1.19.2-150400.3.18.1 * krb5-debugsource-1.19.2-150400.3.18.1 * krb5-server-debuginfo-1.19.2-150400.3.18.1 * krb5-plugin-preauth-otp-1.19.2-150400.3.18.1 * krb5-plugin-kdb-ldap-debuginfo-1.19.2-150400.3.18.1 * krb5-server-1.19.2-150400.3.18.1 * openSUSE Leap 15.4 (x86_64) * krb5-32bit-1.19.2-150400.3.18.1 * krb5-devel-32bit-1.19.2-150400.3.18.1 * krb5-32bit-debuginfo-1.19.2-150400.3.18.1 * openSUSE Leap 15.4 (aarch64_ilp32) * krb5-devel-64bit-1.19.2-150400.3.18.1 * krb5-64bit-1.19.2-150400.3.18.1 * krb5-64bit-debuginfo-1.19.2-150400.3.18.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * krb5-1.19.2-150400.3.18.1 * krb5-debugsource-1.19.2-150400.3.18.1 *krb5-debuginfo-1.19.2-150400.3.18.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * krb5-1.19.2-150400.3.18.1 * krb5-debugsource-1.19.2-150400.3.18.1 * krb5-debuginfo-1.19.2-150400.3.18.1 ## References: * https://www.suse.com/security/cve/CVE-2025-3576.html * https://bugzilla.suse.com/show_bug.cgi?id=1241219 . Krb5 security fix for openSUSE mitigates spoofing risks in GSSAPI messaging. Update suggested for enhanced protection.. Krb5 Update, openSUSE Security Fix, GSSAPI Mitigation. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.