Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Security update. Publication date: 20 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0281.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-54293 Description: URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read. (CVE-2026-54293) References: - https://bugs.mageia.org/show_bug.cgi?id=35762 - https://lists.opensuse.org/archives/list/
Security update. Publication date: 18 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0260.html Type: security Affected Mageia releases: 10 CVE: CVE-2026-58203 Description: The updated packages fix a security vulnerability: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size. (CVE-2026-58203) References: - https://bugs.mageia.org/show_bug.cgi?id=35774 - https://lists.fedoraproject.org/archives/list/
streamlink 8.4.0 (2026-05-06) SECURITY: fixed arbitrary local file read via file:// URI in HLS and DASH (CVE-2026-44353 / GHSA-hgqw-6m45-hw5f) Added: --stream-passthrough-encrypted for passing through encrypted HLS/DASH segments to the output stream without any checks (#6896). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-4d6aae2d33 2026-07-05 00:49:16.510756+00:00 -------------------------------------------------------------------------------- Name : python-streamlink Product : Fedora 43 Version : 8.4.0 Release : 1.fc43 URL : https://streamlink.github.io Summary : Python library for extracting streams from various websites Description : Streamlink is a command-line utility that pipes video streams from various services into a video player, such as VLC. The main purpose of Streamlink is to allow the user to avoid buggy and CPU heavy flash plugins but still be able to enjoy various streamed content. There is also an API available for developers who want access to the video stream data. This project was forked from Livestreamer, which is no longer maintained. -------------------------------------------------------------------------------- Update Information: streamlink 8.4.0 (2026-05-06) SECURITY: fixed arbitrary local file read via file:// URI in HLS and DASH (CVE-2026-44353 / GHSA-hgqw-6m45-hw5f) Added: --stream-passthrough-encrypted for passing through encrypted HLS/DASH segments to the output stream without any checks (#6896) Fixed: --interface selection by name on macOS (#6908) Fixed: --interface not being applied to adapters mounted after session init (#6915) Updated plugins: goltelevision: rewritten and fixed plugin (#6916) twitcasting: improved ad segment filtering (#6910) Full changelog streamlink 8.3.0 (2026-04-10) Added: support for choosing the --interface by name on non-Windows systems, with optional prefixes, similar to curl (#6862) Added: support foralso checking stream segments in HLSStream.parse_variant_playlist() by setting check_streams="segments" (#6878) Fixed: stdout/stderr streams in ProcessOutput not being fully line-buffered (#6868) Updated plugins: cdnbg: rewritten and fixed plugin (#6890) nicolive: added websocket reconnect attempts on HLS decryption key retrieval failure (#6871) soop: migrated to sooplive.com (#6876) telefe: rewritten and fixed plugin (#6891) Full changelog -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 25 2026 Mohamed El Morabity - 8.4.0-1 - Update to 8.4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2457332 - python-streamlink-8.4.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2457332 [ 2 ] Bug #2458672 - python-streamlink fails to build with Python 3.15: test_help_color: TypeError: TestPrint._color. . () got an unexpected keyword argument 'file' https://bugzilla.redhat.com/show_bug.cgi?id=2458672 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-4d6aae2d33' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves two vulnerabilities can now be installed.. # Security update for zypper-docker Announcement ID: SUSE-SU-2026:1951-1 Release Date: 2026-05-18T07:52:41Z Rating: important References: * bsc#1259563 * bsc#1260086 Cross-References: * CVE-2026-2808 * CVE-2026-33186 CVSS scores: * CVE-2026-2808 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-2808 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2026-2808 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for zypper-docker fixes the following issues * CVE-2026-2808: github.com/hashicorp/consul: unvalidated user-supplied file paths can lead to arbitrary file reads through the Vault Kubernetes authentication provider (bsc#1259563). * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo- header (bsc#1260086). Changes forzypper-docker: * Bump to version 2.0.2 * update vendor provided docker to v28.5.2 * update go sources to use new docker api * update vendor directory to reflect docker update * Bump to version 2.0.1 * Fix golint import path * migrate to go 1.11 module * ci: use registry.opensuse.org ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1951=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1951=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1951=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1951=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1951=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1951=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1951=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-1951=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * zypper-docker-debuginfo-2.0.2-150000.3.8.1 * zypper-docker-2.0.2-150000.3.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * zypper-docker-debuginfo-2.0.2-150000.3.8.1 * zypper-docker-2.0.2-150000.3.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) *zypper-docker-debuginfo-2.0.2-150000.3.8.1 * zypper-docker-2.0.2-150000.3.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * zypper-docker-debuginfo-2.0.2-150000.3.8.1 * zypper-docker-2.0.2-150000.3.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * zypper-docker-debuginfo-2.0.2-150000.3.8.1 * zypper-docker-2.0.2-150000.3.8.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * zypper-docker-debuginfo-2.0.2-150000.3.8.1 * zypper-docker-2.0.2-150000.3.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * zypper-docker-debuginfo-2.0.2-150000.3.8.1 * zypper-docker-2.0.2-150000.3.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * zypper-docker-debuginfo-2.0.2-150000.3.8.1 * zypper-docker-2.0.2-150000.3.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2808.html * https://www.suse.com/security/cve/CVE-2026-33186.html * https://bugzilla.suse.com/show_bug.cgi?id=1259563 * https://bugzilla.suse.com/show_bug.cgi?id=1260086 . SUSE updates for zypper-docker resolve two important issues addressing security concerns and vulnerabilities.. SUSE updates, zypper-docker security, software vulnerabilities, Linux security patches. . Severity: Important. LinuxSecurity.com Team
This update includes a fix for CVE-2026-39977. See also: the upstream advisory. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-25ff246b4f 2026-04-24 00:53:58.937391+00:00 -------------------------------------------------------------------------------- Name : flatpak-builder Product : Fedora 43 Version : 1.4.8 Release : 1.fc43 URL : https://flatpak.org/ Summary : Tool to build flatpaks from source Description : Flatpak-builder is a tool for building flatpaks from sources. See https://flatpak.org/ for more information. -------------------------------------------------------------------------------- Update Information: This update includes a fix for CVE-2026-39977. See also: the upstream advisory -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 15 2026 Adrian Vovk - 1.4.8-1 - Update to 1.4.8 (#2457166) * Wed Mar 25 2026 Jan Grulich - 1.4.7-5 - Add configuration for release-monitoring * Fri Jan 16 2026 Fedora Release Engineering - 1.4.7-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2457166 - flatpak-builder-1.4.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=2457166 [ 2 ] Bug #2457894 - CVE-2026-39977 flatpak-builder: path traversal leading to arbitrary file read on host when installing licence files [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2457894 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-25ff246b4f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed withthe Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
uv / python-uv-build 0.9.7 https://github.com/astral-sh/uv/releases/tag/0.9.7 0.9.6 This release contains an upgrade to Astral's fork of async_zip, which addresses. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e60a4ba4d7 2025-11-15 01:30:31.747715+00:00 -------------------------------------------------------------------------------- Name : rust-reqsign-file-read-tokio Product : Fedora 42 Version : 2.0.1 Release : 1.fc42 URL : https://crates.io/crates/reqsign-file-read-tokio Summary : Tokio-based file reader implementation for reqsign Description : Tokio-based file reader implementation for reqsign. -------------------------------------------------------------------------------- Update Information: uv / python-uv-build 0.9.7 https://github.com/astral-sh/uv/releases/tag/0.9.7 0.9.6 This release contains an upgrade to Astral's fork of async_zip, which addresses potential sources of ZIP parsing differentials between uv and other Python packaging tooling. See GHSA-pqhf-p39g-3x64 for additional details. https://github.com/astral-sh/uv/releases/tag/0.9.6 ruff 0.14.3 https://github.com/astral-sh/ruff/releases/tag/0.14.3 Update rust-get-size2/rust-get-size-derive2 to 0.7.1 (implement GetSize for RefCell). Update rust-reqsign to 0.18.1 and rust-reqsign-* to 2.0.1. Update rust-regex to 1.12.2 and rust-regex-automata to 0.4.13. -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 5 2025 Benjamin A. Beasley - 2.0.1-1 - Update to version 2.0.1; Fixes RHBZ#2411983 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2403244 - rust-regex-1.12.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2403244 [ 2 ] Bug #2403245 - rust-regex-automata-0.4.13 is available https://bugzilla.redhat.com/show_bug.cgi?id=2403245 [ 3 ] Bug #2406419 -rust-get-size2-0.7.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2406419 [ 4 ] Bug #2406420 - rust-get-size-derive2-0.7.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2406420 [ 5 ] Bug #2411978 - rust-reqsign-core-2.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2411978 [ 6 ] Bug #2411979 - rust-reqsign-command-execute-tokio-2.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2411979 [ 7 ] Bug #2411980 - rust-reqsign-aws-v4-2.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2411980 [ 8 ] Bug #2411981 - rust-reqsign-0.18.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2411981 [ 9 ] Bug #2411982 - rust-reqsign-http-send-reqwest-2.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2411982 [ 10 ] Bug #2411983 - rust-reqsign-file-read-tokio-2.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2411983 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e60a4ba4d7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Pydantic 2.12.4 This is the fourth 2.12 patch release, fixing more regressions, and reverting a change in the build() method of the AnyUrl and Dsn types.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-312ac3e645 2025-11-10 00:46:08.034331+00:00 -------------------------------------------------------------------------------- Name : rust-reqsign-file-read-tokio Product : Fedora 43 Version : 2.0.1 Release : 1.fc43 URL : https://crates.io/crates/reqsign-file-read-tokio Summary : Tokio-based file reader implementation for reqsign Description : Tokio-based file reader implementation for reqsign. -------------------------------------------------------------------------------- Update Information: Pydantic 2.12.4 This is the fourth 2.12 patch release, fixing more regressions, and reverting a change in the build() method of the AnyUrl and Dsn types. This patch release also fixes an issue with the serialization of IP address types, when serialize_as_any is used. The next patch release will try to address the remaining issues with serialize as any behavior by introducing a new polymorphic serialization feature, that should be used in most cases in place of serialize as any. https://github.com/pydantic/pydantic/releases/tag/v2.12.4 uv / python-uv-build 0.9.7 https://github.com/astral-sh/uv/releases/tag/0.9.7 0.9.6 This release contains an upgrade to Astral's fork of async_zip, which addresses potential sources of ZIP parsing differentials between uv and other Python packaging tooling. See GHSA-pqhf-p39g-3x64 for additional details. https://github.com/astral-sh/uv/releases/tag/0.9.6 ruff 0.14.3 https://github.com/astral-sh/ruff/releases/tag/0.14.3 Update rust-get-size2/rust-get-size-derive2 to 0.7.1 (implement GetSize for RefCell). Update rust-reqsign to 0.18.1 and rust-reqsign-* to 2.0.1. Update rust-regex to 1.12.2 and rust-regex-automata to0.4.13. -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 5 2025 Benjamin A. Beasley - 2.0.1-1 - Update to version 2.0.1; Fixes RHBZ#2411983 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2403244 - rust-regex-1.12.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2403244 [ 2 ] Bug #2403245 - rust-regex-automata-0.4.13 is available https://bugzilla.redhat.com/show_bug.cgi?id=2403245 [ 3 ] Bug #2406419 - rust-get-size2-0.7.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2406419 [ 4 ] Bug #2406420 - rust-get-size-derive2-0.7.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2406420 [ 5 ] Bug #2411957 - python-cloudpickle-3.1.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2411957 [ 6 ] Bug #2411978 - rust-reqsign-core-2.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2411978 [ 7 ] Bug #2411979 - rust-reqsign-command-execute-tokio-2.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2411979 [ 8 ] Bug #2411980 - rust-reqsign-aws-v4-2.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2411980 [ 9 ] Bug #2411981 - rust-reqsign-0.18.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2411981 [ 10 ] Bug #2411982 - rust-reqsign-http-send-reqwest-2.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2411982 [ 11 ] Bug #2411983 - rust-reqsign-file-read-tokio-2.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2411983 [ 12 ] Bug #2412643 - python-pydantic-2.12.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2412643 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-312ac3e645' at the command line. For moreinformation, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
uv / python-uv-build 0.9.5 https://github.com/astral-sh/uv/blob/0.9.5/CHANGELOG.md ruff 0.14.2 https://github.com/astral-sh/ruff/blob/0.14.2/CHANGELOG.md Pydantic 2.12.3. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-4154ea83d0 2025-11-05 02:09:57.817569+00:00 -------------------------------------------------------------------------------- Name : rust-reqsign-file-read-tokio Product : Fedora 43 Version : 2.0.0 Release : 1.fc43 URL : https://crates.io/crates/reqsign-file-read-tokio Summary : Tokio-based file reader implementation for reqsign Description : Tokio-based file reader implementation for reqsign. -------------------------------------------------------------------------------- Update Information: uv / python-uv-build 0.9.5 https://github.com/astral-sh/uv/blob/0.9.5/CHANGELOG.md ruff 0.14.2 https://github.com/astral-sh/ruff/blob/0.14.2/CHANGELOG.md Pydantic 2.12.3 Blog post maturin 1.9.6 https://github.com/PyO3/maturin/blob/v1.9.6/Changelog.md python-typing-inspection 0.4.2 (2025-10-01) Add typing_objects.is_noextraitems() python-jiter 0.11.0 https://github.com/pydantic/jiter/releases/tag/v0.11.0 python-pydantic-extra-types 2.10.6 https://github.com/pydantic/pydantic-extra-types/releases/tag/v2.10.6 Typer 0.20.0 Features \u2728 Enable command suggestions on typo by default. Upgrades \u2b06\ufe0f Add (official) support for Python 3.14. Internal Assorted small enhancements. FastAPI 0.120.1 Upgrades \u2b06\ufe0f Bump Starlette to
Get the latest Linux and open source security news straight to your inbox.