Explore top 10 tips to secure your open-source projects now. Read More
×Several security issues were fixed in OpenSSH.. ========================================================================== Ubuntu Security Notice USN-8533-1 July 13, 2026 openssh vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in OpenSSH. Software Description: - openssh: secure shell (SSH) for secure access to remote machines Details: It was discovered that OpenSSH sftp did not properly constrain the location of downloaded files when connecting to an attacker-controlled server. An attacker could possibly use this issue to write files to unintended locations on the file system. (CVE-2026-59995) It was discovered that OpenSSH scp could place files in the parent directory of the intended destination when copying between two remote hosts. An attacker could possibly use this issue to write files to unintended locations. (CVE-2026-59996) It was discovered that OpenSSH internal-sftp only recognized the first nine command-line arguments, This could result in certain security-sensitive arguments being ignored, contrary to expectations. (CVE-2026-59997) It was discovered that OpenSSH had undocumented behaviour regarding the GSSAPIStrictAcceptorCheck option in environments using Windows Active Directory. The documentation has been updated to clarify use of the option. (CVE-2026-59998) It was discovered that OpenSSH did not properly enforce precedence of DisableForwarding=yes over PermitTunnel=yes in server configurations. This could possibly result in intended network forwarding restrictions being bypassed, contrary to expectations. (CVE-2026-59999) It was discovered that OpenSSH mishandled the MaxAuthTries limit for GSSAPI authentication. A remote attacker could use this issue to perform excessive authentication attempts. (CVE-2026-60000) It was discovered that OpenSSH did not always honour theminimum authentication delay. An attacker could possibly use this issue to perform brute-force attacks more efficiently. (CVE-2026-60001) It was discovered that the OpenSSH client had a use-after-free vulnerability when a server changed its host key during a key re-exchange. An attacker able to intercept communications could possibly use this issue to execute arbitrary code or obtain sensitive information. (CVE-2026-60002) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS openssh-client 1:10.2p1-2ubuntu3.4 openssh-server 1:10.2p1-2ubuntu3.4 Ubuntu 24.04 LTS openssh-client 1:9.6p1-3ubuntu13.18 openssh-server 1:9.6p1-3ubuntu13.18 Ubuntu 22.04 LTS openssh-client 1:8.9p1-3ubuntu0.16 openssh-server 1:8.9p1-3ubuntu0.16 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8533-1 CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, CVE-2026-60002 Package Information: https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4 https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.18 https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.16 . Multiple security issues in OpenSSH patched for Ubuntu to enhance protection against potential attacks.. OpenSSH Security, Ubuntu SSH Issues, SSH Client Server Fix, File Transfer Vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for openssh Announcement ID: SUSE-SU-2026:1876-1 Release Date: 2026-05-15T22:06:52Z Rating: important References: * bsc#1261427 * bsc#1261430 Cross-References: * CVE-2026-35385 * CVE-2026-35414 CVSS scores: * CVE-2026-35385 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-35385 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-35385 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-35385 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-35414 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-35414 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-35414 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-35414 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for openssh fixes the following issues * CVE-2026-35385: a file downloaded by scp may be installed setuid or setgid (bsc#1261427). * CVE-2026-35414: mishandling of authorized_keys principals option (bsc#1261430). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1876=1 * SUSELinux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1876=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-1876=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1876=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1876=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * openssh-common-9.6p1-150600.6.37.1 * openssh-askpass-gnome-debuginfo-9.6p1-150600.6.37.1 * openssh-clients-9.6p1-150600.6.37.1 * openssh-common-debuginfo-9.6p1-150600.6.37.1 * openssh-debuginfo-9.6p1-150600.6.37.1 * openssh-debugsource-9.6p1-150600.6.37.1 * openssh-helpers-debuginfo-9.6p1-150600.6.37.1 * openssh-cavs-9.6p1-150600.6.37.1 * openssh-server-9.6p1-150600.6.37.1 * openssh-askpass-gnome-9.6p1-150600.6.37.1 * openssh-server-config-disallow-rootlogin-9.6p1-150600.6.37.1 * openssh-cavs-debuginfo-9.6p1-150600.6.37.1 * openssh-9.6p1-150600.6.37.1 * openssh-clients-debuginfo-9.6p1-150600.6.37.1 * openssh-server-debuginfo-9.6p1-150600.6.37.1 * openssh-helpers-9.6p1-150600.6.37.1 * openssh-askpass-gnome-debugsource-9.6p1-150600.6.37.1 * openssh-fips-9.6p1-150600.6.37.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * openssh-common-9.6p1-150600.6.37.1 * openssh-askpass-gnome-debuginfo-9.6p1-150600.6.37.1 * openssh-clients-9.6p1-150600.6.37.1 * openssh-common-debuginfo-9.6p1-150600.6.37.1 * openssh-debuginfo-9.6p1-150600.6.37.1 * openssh-debugsource-9.6p1-150600.6.37.1 * openssh-helpers-debuginfo-9.6p1-150600.6.37.1 * openssh-server-9.6p1-150600.6.37.1 * openssh-server-config-disallow-rootlogin-9.6p1-150600.6.37.1 * openssh-askpass-gnome-9.6p1-150600.6.37.1 * openssh-clients-debuginfo-9.6p1-150600.6.37.1 * openssh-9.6p1-150600.6.37.1 * openssh-server-debuginfo-9.6p1-150600.6.37.1 * openssh-helpers-9.6p1-150600.6.37.1 * openssh-askpass-gnome-debugsource-9.6p1-150600.6.37.1 * openssh-fips-9.6p1-150600.6.37.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * openssh-common-9.6p1-150600.6.37.1 * openssh-server-config-disallow-rootlogin-9.6p1-150600.6.37.1 * openssh-clients-9.6p1-150600.6.37.1 * openssh-common-debuginfo-9.6p1-150600.6.37.1 * openssh-debuginfo-9.6p1-150600.6.37.1 * openssh-debugsource-9.6p1-150600.6.37.1 * openssh-helpers-debuginfo-9.6p1-150600.6.37.1 * openssh-server-9.6p1-150600.6.37.1 * openssh-9.6p1-150600.6.37.1 * openssh-server-debuginfo-9.6p1-150600.6.37.1 * openssh-clients-debuginfo-9.6p1-150600.6.37.1 * openssh-helpers-9.6p1-150600.6.37.1 * openssh-fips-9.6p1-150600.6.37.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * openssh-askpass-gnome-debuginfo-9.6p1-150600.6.37.1 * openssh-askpass-gnome-9.6p1-150600.6.37.1 * openssh-askpass-gnome-debugsource-9.6p1-150600.6.37.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * openssh-common-9.6p1-150600.6.37.1 * openssh-askpass-gnome-debuginfo-9.6p1-150600.6.37.1 * openssh-clients-9.6p1-150600.6.37.1 * openssh-common-debuginfo-9.6p1-150600.6.37.1 * openssh-debuginfo-9.6p1-150600.6.37.1 * openssh-debugsource-9.6p1-150600.6.37.1 * openssh-helpers-debuginfo-9.6p1-150600.6.37.1 * openssh-server-9.6p1-150600.6.37.1 * openssh-server-config-disallow-rootlogin-9.6p1-150600.6.37.1 * openssh-askpass-gnome-9.6p1-150600.6.37.1 * openssh-9.6p1-150600.6.37.1 * openssh-clients-debuginfo-9.6p1-150600.6.37.1 * openssh-server-debuginfo-9.6p1-150600.6.37.1 * openssh-helpers-9.6p1-150600.6.37.1 * openssh-askpass-gnome-debugsource-9.6p1-150600.6.37.1 * openssh-fips-9.6p1-150600.6.37.1 ## References: * https://www.suse.com/security/cve/CVE-2026-35385.html *https://www.suse.com/security/cve/CVE-2026-35414.html * https://bugzilla.suse.com/show_bug.cgi?id=1261427 * https://bugzilla.suse.com/show_bug.cgi?id=1261430 . Critical update for OpenSSH in openSUSE addressing multiple vulnerabilities for better system security.. OpenSSH fix, security update, openSUSE vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for openssh Announcement ID: SUSE-SU-2026:21634-1 Release Date: 2026-05-12T10:19:47Z Rating: important References: * bsc#1261427 * bsc#1261430 Cross-References: * CVE-2026-35385 * CVE-2026-35414 CVSS scores: * CVE-2026-35385 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-35385 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-35385 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-35385 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-35414 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-35414 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-35414 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-35414 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for openssh fixes the following issues * CVE-2026-35385: a file downloaded by scp may be installed setuid or setgid (bsc#1261427). * CVE-2026-35414: mishandling of authorized_keys principals option (bsc#1261430). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-524=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * openssh-9.6p1-slfo.1.1_4.1 * openssh-clients-debuginfo-9.6p1-slfo.1.1_4.1 * openssh-common-debuginfo-9.6p1-slfo.1.1_4.1 * openssh-debuginfo-9.6p1-slfo.1.1_4.1 * openssh-debugsource-9.6p1-slfo.1.1_4.1 * openssh-server-debuginfo-9.6p1-slfo.1.1_4.1 * openssh-fips-9.6p1-slfo.1.1_4.1 *openssh-clients-9.6p1-slfo.1.1_4.1 * openssh-server-9.6p1-slfo.1.1_4.1 * openssh-common-9.6p1-slfo.1.1_4.1 * openssh-server-config-rootlogin-9.6p1-slfo.1.1_4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-35385.html * https://www.suse.com/security/cve/CVE-2026-35414.html * https://bugzilla.suse.com/show_bug.cgi?id=1261427 * https://bugzilla.suse.com/show_bug.cgi?id=1261430 . An important update for openssh on SUSE resolves critical file handling issues and enhances security.. SUSE Openssh update, Important security advisory, Openssh vulnerabilities. . Severity: Important. LinuxSecurity.com Team
wheel could be made to crash or run programs as your login if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-8221-1 April 29, 2026 wheel vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: wheel could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - wheel: Command line tool for manipulating Python wheel files Details: It was discovered that wheel did not correctly handle certain file paths. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python-wheel-common 0.42.0-2ubuntu0.1~esm1 Available with Ubuntu Pro python3-wheel 0.42.0-2ubuntu0.1~esm1 Available with Ubuntu Pro python3-wheel-whl 0.42.0-2ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8221-1 CVE-2026-24049 . A critical issue with Ubuntu's wheel allows remote code execution from crafted files. Update immediately for security.. Ubuntu 24.04 LTS, wheel application, remote code execution, security update. . Severity: Critical. LinuxSecurity.com Team
tracker-miners could be made to crash or run programs as your login if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-8019-1 February 05, 2026 tracker-miners vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: tracker-miners could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - tracker-miners: Metadata database, indexer and search tool Details: Fatih �elik discovered that tracker-miners incorrectly handled certain malformed MP3 files. An attacker could use this issue to cause tracker-miners to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 tracker-extract 3.8.2-4ubuntu2.1 Ubuntu 24.04 LTS tracker-extract 3.7.1-1ubuntu0.1 Ubuntu 22.04 LTS tracker-extract 3.3.3-0ubuntu0.20.04.4 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8019-1 CVE-2026-1764, CVE-2026-1765, CVE-2026-1766, CVE-2026-1767 Package Information: https://launchpad.net/ubuntu/+source/tracker-miners/3.8.2-4ubuntu2.1 https://launchpad.net/ubuntu/+source/tracker-miners/3.7.1-1ubuntu0.1 https://launchpad.net/ubuntu/+source/tracker-miners/3.3.3-0ubuntu0.20.04.4 . Critical updates for tracker-miners on various Ubuntu versions to prevent exploitation risks and crashes.. tracker-miners security update, Ubuntu security announcement, denial of service tracker-miners, Ubuntu 25.10 24.04 22.04 security. . Severity: Important. LinuxSecurity.com Team
MGASA-2025-0280 - Updated python3 packages fix security vulnerabilities. MGASA-2025-0280 - Updated python3 packages fix security vulnerabilities Publication date: 12 Nov 2025 URL: https://advisories.mageia.org/MGASA-2025-0280.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-0938, CVE-2025-1795, CVE-2024-9287, CVE-2025-4516, CVE-2024-12718, CVE-2025-4138, CVE-2025-4330, CVE-2025-4435, CVE-2025-4517, CVE-2025-8194 Description: URL parser allowed square brackets in domain names. (CVE-2025-0938) Mishandling of comma during folding and unicode-encoding of email headers. (CVE-2025-1795) Virtual environment (venv) activation scripts don't quote paths. (CVE-2024-9287) Use-after-free in "unicode_escape" decoder with error handler. (CVE-2025-4516) Bypass extraction filter to modify file metadata outside extraction directory. (CVE-2024-12718) Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory. (CVE-2025-4138) Extraction filter bypass for linking outside extraction directory. (CVE-2025-4330) Tarfile extracts filtered members when errorlevel=0. (CVE-2025-4435) Arbitrary writes via tarfile realpath overflow. (CVE-2025-4517) Tarfile infinite loop during parsing with negative member offset. (CVE-2025-8194) References: - https://bugs.mageia.org/show_bug.cgi?id=34285 - https://bugs.mageia.org/show_bug.cgi?id=34007 - https://lists.fedoraproject.org/archives/list/
* bsc#1192051 * bsc#1214960 * bsc#1221050 * bsc#1230092 . # Security update for runc Announcement ID: SUSE-SU-2025:20046-1 Release Date: 2025-02-03T08:56:20Z Rating: important References: * bsc#1192051 * bsc#1214960 * bsc#1221050 * bsc#1230092 Cross-References: * CVE-2024-45310 CVSS scores: * CVE-2024-45310 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N * CVE-2024-45310 ( NVD ): 3.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability and has three fixes can now be installed. ## Description: This update for runc fixes the following issues: Update to runc v1.1.14. Upstream changelog is available from . * CVE-2024-45310: Fixed that runc can be tricked into creating empty files/directories on host ( bsc#1230092) Update to runc v1.1.13. Upstream changelog is available from . * Fixed a performance issue when running lots of containers, caused by systemd getting too many mount notifications. bsc#1214960 * Fixed -ENOSYS stub on ppc64le. bsc#1192051 bsc#1221050 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-62=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * runc-debuginfo-1.1.14-1.1 * runc-1.1.14-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-45310.html * https://bugzilla.suse.com/show_bug.cgi?id=1192051 * https://bugzilla.suse.com/show_bug.cgi?id=1214960 * https://bugzilla.suse.com/show_bug.cgi?id=1221050 * https://bugzilla.suse.com/show_bug.cgi?id=1230092 . SUSE tackles significant container challenges, providing solutions and enhancements to improve efficacy and defensive protocols.. runc security update, SUSE Linux Micro patch, performance fixes. . Severity: Important.LinuxSecurity.com Team
VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM. (CVE-2025-22247) . MGASA-2025-0166 - Updated open-vm-tools packages fix security vulnerability Publication date: 27 May 2025 URL: https://advisories.mageia.org/MGASA-2025-0166.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-22247 VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM. (CVE-2025-22247) References: - https://bugs.mageia.org/show_bug.cgi?id=34271 - https://www.openwall.com/lists/oss-security/2025/05/12/2 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.