Explore top 10 tips to secure your open-source projects now. Read More
×
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-21757 http://linux.oracle.com/errata/ELSA-2026-21757.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: flatpak-1.16.0-9.el10_2.1.x86_64.rpm flatpak-devel-1.16.0-9.el10_2.1.x86_64.rpm flatpak-libs-1.16.0-9.el10_2.1.x86_64.rpm flatpak-selinux-1.16.0-9.el10_2.1.noarch.rpm flatpak-session-helper-1.16.0-9.el10_2.1.x86_64.rpm aarch64: flatpak-1.16.0-9.el10_2.1.aarch64.rpm flatpak-devel-1.16.0-9.el10_2.1.aarch64.rpm flatpak-libs-1.16.0-9.el10_2.1.aarch64.rpm flatpak-selinux-1.16.0-9.el10_2.1.noarch.rpm flatpak-session-helper-1.16.0-9.el10_2.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/flatpak-1.16.0-9.el10_2.1.src.rpm Related CVEs: CVE-2026-34078 CVE-2026-34079 Description of changes: [1.16.0-9.1] - Fix arbitrary code execution via crafted symlinks in sandbox-expose options Resolves: RHEL-165630 - Fix arbitrary file deletion on host via improper cache file path validation Resolves: RHEL-170157 _______________________________________________ El-errata mailing list
An update that solves one vulnerability can now be installed.. # Security update for xdg-desktop-portal Announcement ID: SUSE-SU-2026:2712-1 Release Date: 2026-06-30T12:01:01Z Rating: moderate References: * bsc#1262045 Cross-References: * CVE-2026-40354 CVSS scores: * CVE-2026-40354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-40354 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40354 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for xdg-desktop-portal fixes the following issue: * CVE-2026-40354: File deletion via symlink attack (bsc#1262045). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2712=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2712=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * xdg-desktop-portal-debugsource-1.18.2-150600.4.6.1 * xdg-desktop-portal-1.18.2-150600.4.6.1 * xdg-desktop-portal-debuginfo-1.18.2-150600.4.6.1 * xdg-desktop-portal-devel-1.18.2-150600.4.6.1 * openSUSE Leap 15.6 (noarch) * xdg-desktop-portal-lang-1.18.2-150600.4.6.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * xdg-desktop-portal-debugsource-1.18.2-150600.4.6.1 * xdg-desktop-portal-1.18.2-150600.4.6.1 * xdg-desktop-portal-debuginfo-1.18.2-150600.4.6.1 *xdg-desktop-portal-devel-1.18.2-150600.4.6.1 * Desktop Applications Module 15-SP7 (noarch) * xdg-desktop-portal-lang-1.18.2-150600.4.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40354.html * https://bugzilla.suse.com/show_bug.cgi?id=1262045 . Update resolves moderate risk posed by CVE-2026-40354 affecting xdg-desktop-portal in openSUSE.. xdg-desktop-portal security update, openSUSE CVE-2026-40354, patch xdg-desktop-portal, file deletion vulnerability, moderate severity patch. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for xdg-desktop-portal Announcement ID: SUSE-SU-2026:2712-1 Release Date: 2026-06-30T12:01:01Z Rating: moderate References: * bsc#1262045 Cross-References: * CVE-2026-40354 CVSS scores: * CVE-2026-40354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-40354 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40354 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for xdg-desktop-portal fixes the following issue: * CVE-2026-40354: File deletion via symlink attack (bsc#1262045). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2712=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2712=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * xdg-desktop-portal-debugsource-1.18.2-150600.4.6.1 * xdg-desktop-portal-1.18.2-150600.4.6.1 * xdg-desktop-portal-debuginfo-1.18.2-150600.4.6.1 * xdg-desktop-portal-devel-1.18.2-150600.4.6.1 * openSUSE Leap 15.6 (noarch) * xdg-desktop-portal-lang-1.18.2-150600.4.6.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * xdg-desktop-portal-debugsource-1.18.2-150600.4.6.1 * xdg-desktop-portal-1.18.2-150600.4.6.1 * xdg-desktop-portal-debuginfo-1.18.2-150600.4.6.1 *xdg-desktop-portal-devel-1.18.2-150600.4.6.1 * Desktop Applications Module 15-SP7 (noarch) * xdg-desktop-portal-lang-1.18.2-150600.4.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40354.html * https://bugzilla.suse.com/show_bug.cgi?id=1262045 . Update for xdg-desktop-portal addresses moderate risk of file deletion via symlink attack in SUSE Linux.. SUSE Linux Security Patch XDG Desktop Portal Update. . Severity: moderate. LinuxSecurity.com Team
Several security issues were fixed in Robocode.. ========================================================================== Ubuntu Security Notice USN-8385-1 June 04, 2026 robocode vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Robocode. Software Description: - robocode: An engaging and educational programming game Details: It was discovered that Robocode could be tricked into making network requests to attacker-controlled systems. An attacker could possibly use this issue to cause external service interaction, resulting in information disclosure. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-10648) Lim Sim Yee discovered that Robocode did not properly validate file paths in the CacheCleaner component. An attacker could possibly use this issue to delete arbitrary files. (CVE-2025-14306) Lim Sim Yee discovered that Robocode did not securely create temporary files in the AutoExtract component. An attacker could possibly use this issue to manipulate temporary files, resulting in arbitrary code execution. (CVE-2025-14307) Lim Sim Yee discovered that Robocode did not properly validate data lengths in the Buffer class. An attacker could possibly use this issue to trigger an integer overflow, resulting in arbitrary code execution. (CVE-2025-14308) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS robocode 1.9.3.9-4ubuntu0.26.04.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS robocode 1.9.3.9-3ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS robocode 1.9.3.9-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS robocode 1.9.3.7-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS robocode 1.9.3.1-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS robocode 1.9.2.5-2ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8385-1 CVE-2019-10648, CVE-2025-14306, CVE-2025-14307, CVE-2025-14308 . Several vulnerabilities in Robocode could lead to external service interactions, file deletion, or arbitrary code execution.. Ubuntu Security, Robocode Vulnerabilities, Critical Ubuntu Advisory, Security Fixes, Information Disclosure. . Severity: Critical. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-21756 http://linux.oracle.com/errata/ELSA-2026-21756.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: flatpak-1.12.9-4.el8_10.i686.rpm flatpak-1.12.9-4.el8_10.x86_64.rpm flatpak-devel-1.12.9-4.el8_10.i686.rpm flatpak-devel-1.12.9-4.el8_10.x86_64.rpm flatpak-libs-1.12.9-4.el8_10.i686.rpm flatpak-libs-1.12.9-4.el8_10.x86_64.rpm flatpak-selinux-1.12.9-4.el8_10.noarch.rpm flatpak-session-helper-1.12.9-4.el8_10.i686.rpm flatpak-session-helper-1.12.9-4.el8_10.x86_64.rpm aarch64: flatpak-1.12.9-4.el8_10.aarch64.rpm flatpak-devel-1.12.9-4.el8_10.aarch64.rpm flatpak-libs-1.12.9-4.el8_10.aarch64.rpm flatpak-selinux-1.12.9-4.el8_10.noarch.rpm flatpak-session-helper-1.12.9-4.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/flatpak-1.12.9-4.el8_10.src.rpm Related CVEs: CVE-2026-34078 CVE-2026-34079 Description of changes: [1.12.9-4] - Fix arbitrary code execution via crafted symlinks in sandbox-expose options Resolves: RHEL-165633 - Fix arbitrary file deletion on host via improper cache file path validation Resolves: RHEL-170160 _______________________________________________ El-errata mailing list
An update that solves one vulnerability can now be installed.. # Security update for xdg-desktop-portal Announcement ID: SUSE-SU-2026:2105-1 Release Date: 2026-05-28T16:04:00Z Rating: moderate References: * bsc#1262045 Cross-References: * CVE-2026-40354 CVSS scores: * CVE-2026-40354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-40354 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40354 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for xdg-desktop-portal fixes the following issue: * CVE-2026-40354: File deletion via symlink attack (bsc#1262045). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2105=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * xdg-desktop-portal-1.10.1-150400.3.11.1 * xdg-desktop-portal-debugsource-1.10.1-150400.3.11.1 * xdg-desktop-portal-debuginfo-1.10.1-150400.3.11.1 * xdg-desktop-portal-devel-1.10.1-150400.3.11.1 * openSUSE Leap 15.4 (noarch) * xdg-desktop-portal-lang-1.10.1-150400.3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40354.html * https://bugzilla.suse.com/show_bug.cgi?id=1262045 . Critical security update for xdg-desktop-portal addresses file deletion risk through symlink attacks in openSUSE Leap 15.4.. xdg desktop portal, openSUSE Leap, file deletion, symlink attack, security update. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for xdg-desktop-portal Announcement ID: SUSE-SU-2026:2105-1 Release Date: 2026-05-28T16:04:00Z Rating: moderate References: * bsc#1262045 Cross-References: * CVE-2026-40354 CVSS scores: * CVE-2026-40354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-40354 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40354 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for xdg-desktop-portal fixes the following issue: * CVE-2026-40354: File deletion via symlink attack (bsc#1262045). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2105=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * xdg-desktop-portal-1.10.1-150400.3.11.1 * xdg-desktop-portal-debugsource-1.10.1-150400.3.11.1 * xdg-desktop-portal-debuginfo-1.10.1-150400.3.11.1 * xdg-desktop-portal-devel-1.10.1-150400.3.11.1 * openSUSE Leap 15.4 (noarch) * xdg-desktop-portal-lang-1.10.1-150400.3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40354.html * https://bugzilla.suse.com/show_bug.cgi?id=1262045 . SUSE update addresses moderate file deletion risk in xdg-desktop-portal, enhancing system security against symlink attacks.. openSUSE updates, xdg-desktop-portal security, moderate risk patches, symlink vulnerability. . Severity: moderate. LinuxSecurity.com Team
XDG Desktop Portal could be made to delete files.. ========================================================================== Ubuntu Security Notice USN-8287-1 May 20, 2026 xdg-desktop-portal vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS Summary: XDG Desktop Portal could be made to delete files. Software Description: - xdg-desktop-portal: A portal frontend service for Flatpak and other desktop containment frameworks Details: It was discovered that XDG Desktop Portal incorrectly handled trashing files. A local attacker could possibly use this issue to delete arbitrary files on the host file system via a symlink attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 xdg-desktop-portal 1.20.3+ds-1ubuntu1.1 xdg-desktop-portal-dev 1.20.3+ds-1ubuntu1.1 Ubuntu 24.04 LTS xdg-desktop-portal 1.18.4-1ubuntu2.24.04.2 xdg-desktop-portal-dev 1.18.4-1ubuntu2.24.04.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8287-1 CVE-2026-40354 Package Information: https://launchpad.net/ubuntu/+source/xdg-desktop-portal/1.20.3+ds-1ubuntu1.1 https://launchpad.net/ubuntu/+source/xdg-desktop-portal/1.18.4-1ubuntu2.24.04.2 . XDG Desktop Portal flaw allows local attackers to delete files via symlink attacks in Ubuntu. Critical updates are advised.. Ubuntu, XDG Desktop Portal, local attack, important security, file deletion. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.