Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 10 vulnerabilities and has 11 bug fixes can now be installed.. openSUSE security update: security update for go1.26 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20571-1 Rating: important References: * bsc#1255111 * bsc#1261653 * bsc#1261654 * bsc#1261655 * bsc#1261656 * bsc#1261657 * bsc#1261658 * bsc#1261659 * bsc#1261660 * bsc#1261661 * bsc#1261662 Cross-References: * CVE-2026-27140 * CVE-2026-27143 * CVE-2026-27144 * CVE-2026-32280 * CVE-2026-32281 * CVE-2026-32282 * CVE-2026-32283 * CVE-2026-32288 * CVE-2026-32289 * CVE-2026-33810 CVSS scores: * CVE-2026-27140 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-27143 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-27144 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-32280 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32281 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32282 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-32283 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32288 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-32289 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-33810 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 10 vulnerabilities and has 11 bug fixes can now be installed. Description: This update for go1.26 fixes the following issues: - Update to version go1.26.2 (bsc#1255111). - CVE-2026-27140: cmd/go: trust layer bypass when using cgo and SWIG (bsc#1261653). - CVE-2026-27143: cmd/compile: possible memory corruption after bound check elimination (bsc#1261654). - CVE-2026-27144: cmd/compile: no-op interface conversion bypasses overlap checking(bsc#1261655). - CVE-2026-32280: crypto/x509: unexpected work during chain building (bsc#1261656). - CVE-2026-32281: crypto/x509: inefficient policy validation (bsc#1261657). - CVE-2026-32282: os: Root.Chmod can follow symlinks out of the root on Linux (bsc#1261658). - CVE-2026-32283: crypto/tls: multiple key update handshake messages can cause connection to deadlock (bsc#1261659). - CVE-2026-32288: archive/tar: unbounded allocation when parsing old format GNU sparse map (bsc#1261660). - CVE-2026-32289: html/template: JS template literal context incorrectly tracked (bsc#1261661). - CVE-2026-33810: crypto/x509: excluded DNS constraints not properly applied to wildcard domains (bsc#1261662). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-595=1 Package List: - openSUSE Leap 16.0: go1.26-1.26.2-160000.1.1 go1.26-doc-1.26.2-160000.1.1 go1.26-libstd-1.26.2-160000.1.1 go1.26-race-1.26.2-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-27140.html * https://www.suse.com/security/cve/CVE-2026-27143.html * https://www.suse.com/security/cve/CVE-2026-27144.html * https://www.suse.com/security/cve/CVE-2026-32280.html * https://www.suse.com/security/cve/CVE-2026-32281.html * https://www.suse.com/security/cve/CVE-2026-32282.html * https://www.suse.com/security/cve/CVE-2026-32283.html * https://www.suse.com/security/cve/CVE-2026-32288.html * https://www.suse.com/security/cve/CVE-2026-32289.html * https://www.suse.com/security/cve/CVE-2026-33810.html . Install important update for openSUSE go1.26 to fix 10 security issues and 11 bugs effectively. Get the details here.. openSUSE security fix, go1.26 update, important patches. . Severity: Important. LinuxSecurity.com Team
MGASA-2026-0070 - Updated libpng packages fix security vulnerabilities. MGASA-2026-0070 - Updated libpng packages fix security vulnerabilities Publication date: 28 Mar 2026 URL: https://advisories.mageia.org/MGASA-2026-0070.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-33416, CVE-2026-33636 Description: Use-after-free via pointer aliasing in png_set_tRNS and png_set_PLTE. (CVE-2026-33416) Out-of-bounds read/write in the palette expansion on ARM Neon. (CVE-2026-33636) References: - https://bugs.mageia.org/show_bug.cgi?id=35279 - https://www.openwall.com/lists/oss-security/2026/03/26/1 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33416 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33636 SRPMS: - 9/core/libpng-1.6.38-1.5.mga9 . Mageia 9 security advisory MGASA-2026-0070 addresses critical libpng vulnerabilities affecting package integrity.. Mageia, libpng, security advisory, cybersecurity, vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Security fix for CVE-2025-13836. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-06aa85da91 2026-01-25 00:53:48.092825+00:00 -------------------------------------------------------------------------------- Name : python3.12 Product : Fedora 43 Version : 3.12.12 Release : 3.fc43 URL : https://www.python.org/ Summary : Version 3.12 of the Python interpreter Description : Python 3.12 is an accessible, high-level, dynamically typed, interpreted programming language, designed with an emphasis on code readability. It includes an extensive standard library, and has a vast ecosystem of third-party libraries. The python3.12 package provides the "python3.12" executable: the reference interpreter for the Python language, version 3. The majority of its standard library is provided in the python3.12-libs package, which should be installed automatically along with python3.12. The remaining parts of the Python standard library are broken out into the python3.12-tkinter and python3.12-test packages, which may need to be installed separately. Documentation for Python is provided in the python3.12-docs package. Packages containing additional libraries for Python are generally named with the "python3.12-" prefix. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2025-13836 -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 16 2026 Lumr Balhar - 3.12.12-3 - Security fix for CVE-2025-13836 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2428943 - CVE-2025-13836 python3.12: Excessive read buffering DoS in http.client [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2428943 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnfupgrade --advisory FEDORA-2026-06aa85da91' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Security fix for python3.12 addresses excessive read buffering issue in Fedora 43, enhancing system stability.. Fedora Update, Python Security Fix, python3.12, DoS vulnerability, Fedora 43 advisory. . Severity: Important. LinuxSecurity.com Team
Several vulnerabilities were discovered in the resolver in nginx, a small, powerful, scalable web/proxy server, leading to denial of service or, potentially, to arbitrary code execution. These only affect nginx if the "resolver" directive is used in a configuration file. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3473-1
Get the latest Linux and open source security news straight to your inbox.