Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # Security update for firewalld Announcement ID: SUSE-SU-2026:22343-1 Release Date: 2026-06-22T15:10:04Z Rating: moderate References: * bsc#1260903 Cross-References: * CVE-2026-4948 CVSS scores: * CVE-2026-4948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for firewalld fixes the following issue * CVE-2026-4948: local unprivileged users can modify firewall state due to D-Bus setter mis-authorizations (bsc#1260903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1045=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1045=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python3-firewall-2.1.2-160000.3.1 * firewalld-2.1.2-160000.3.1 * firewalld-zsh-completion-2.1.2-160000.3.1 * firewalld-bash-completion-2.1.2-160000.3.1 * firewalld-lang-2.1.2-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python3-firewall-2.1.2-160000.3.1 * firewalld-2.1.2-160000.3.1 * firewalld-zsh-completion-2.1.2-160000.3.1 * firewalld-bash-completion-2.1.2-160000.3.1 * firewalld-lang-2.1.2-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4948.html * https://bugzilla.suse.com/show_bug.cgi?id=1260903 . Update released to fix moderatesecurity issue in firewalld affecting SUSE systems. Install promptly to mitigate risk.. SUSE Linux Enterprise Server, firewalld update, local user privileges. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for firewalld ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21032-1 Rating: moderate References: * bsc#1260903 Cross-References: * CVE-2026-4948 CVSS scores: * CVE-2026-4948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for firewalld fixes the following issue - CVE-2026-4948: local unprivileged users can modify firewall state due to D-Bus setter mis-authorizations (bsc#1260903). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1045=1 Package List: - openSUSE Leap 16.0: firewall-applet-2.1.2-160000.3.1 firewall-config-2.1.2-160000.3.1 firewall-macros-2.1.2-160000.3.1 firewalld-2.1.2-160000.3.1 firewalld-bash-completion-2.1.2-160000.3.1 firewalld-lang-2.1.2-160000.3.1 firewalld-test-2.1.2-160000.3.1 firewalld-zsh-completion-2.1.2-160000.3.1 python3-firewall-2.1.2-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-4948.html . A security update for openSUSE addresses moderate vulnerabilities in firewalld, enhancing system protection.. openSUSE firewalld update, moderate security patch, local privilege escalation fix, Linux firewall security, openSUSE vulnerability management. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for firewalld Announcement ID: SUSE-SU-2026:22263-1 Release Date: 2026-06-22T15:08:58Z Rating: moderate References: * bsc#1260903 Cross-References: * CVE-2026-4948 CVSS scores: * CVE-2026-4948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for firewalld fixes the following issue * CVE-2026-4948: local unprivileged users can modify firewall state due to D-Bus setter mis-authorizations (bsc#1260903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1045=1 ## Package List: * SUSE Linux Micro 6.2 (noarch) * python3-firewall-2.1.2-160000.3.1 * firewalld-2.1.2-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4948.html * https://bugzilla.suse.com/show_bug.cgi?id=1260903 . Install the latest SUSE security update for firewalld to address critical issues including unauthorized local modifications.. SUSE firewalld update Security Patch. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability and has two fixes can now be installed.. # Security update for firewalld Announcement ID: SUSE-SU-2026:22060-1 Release Date: 2026-06-04T08:24:04Z Rating: moderate References: * bsc#1117217 * bsc#1260903 * bsc#1267212 Cross-References: * CVE-2026-4948 CVSS scores: * CVE-2026-4948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 An update that solves one vulnerability and has two fixes can now be installed. ## Security update for firewalld ### Description: This update for firewalld fixes the following issue * CVE-2026-4948: local unprivileged users can modify firewall state due to D-Bus setter mis-authorizations (bsc#1260903). ## Security update for rpcbind ### Description: This update for rpcbind fixes the following issues Update to rpcbind 1.2.9: Security issue: * Fix several memory leaks and buffer overflows (bsc#1267212). Non security issue: * rpcbind fails to start (tumbleweed snapshot 20181120) (bsc#1117217). Changes: * rpcinfo: stack buffer overflow in rpcinfo rpcbaddrlist() * rpcbind: Stop unauthenticated oversized allocation in PMAPPROC_CALLIT decode * rpcbind: fix memory leak in read_warmstart() * rpcbind: fix memory leaks in network_init() * rpcbind: fix memory leak in init_transport() * Added -v (print version and compile flags) * rpcinfo: Removed a number of "old-style function definition" warnings * man/rpcbind: Update list of options * Comment out ListenStream=@/run/rpcbind.sock * [nfs/nfs-utils/rpcbind] rpcbind: avoid dereferencing NULL from realloc() * systemd/rpcbind.service.in: Add various hardenings options * man/rpcbind: Add Files section to manpage * Moved rpcbind.lock and default configs to /run instead of/var/run * rpcinfo: try connecting using abstract address * Listen on an AF_UNIX abstract address if supported * autotools/systemd: call rpcbind with -w only on enabled warm starts * rpcbind: fix double free in init_transport ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-562=1 * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-742=1 ## Package List: * SUSE Linux Micro 6.1 (noarch) * firewalld-2.0.0-slfo.1.1_2.1 * python3-firewall-2.0.0-slfo.1.1_2.1 * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * rpcbind-1.2.9-1.1 * rpcbind-debuginfo-1.2.9-1.1 * rpcbind-debugsource-1.2.9-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4948.html * https://bugzilla.suse.com/show_bug.cgi?id=1117217 * https://bugzilla.suse.com/show_bug.cgi?id=1260903 * https://bugzilla.suse.com/show_bug.cgi?id=1267212 . Address security issues in firewalld and rpcbind with the latest SUSE updates for local attack vectors.. firewalld update, SUSE security advisory, local access control, SUSE Linux Micro. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for firewalld Announcement ID: SUSE-SU-2026:2302-1 Release Date: 2026-06-08T15:27:07Z Rating: moderate References: * bsc#1260903 Cross-References: * CVE-2026-4948 CVSS scores: * CVE-2026-4948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for firewalld fixes the following issue: * CVE-2026-4948: local unprivileged users can modify the runtime firewall state without proper authentication due to D-Bus setter mis-authorizations (bsc#1260903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2302=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2302=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2302=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2302=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2302=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2302=1 ## Package List: * openSUSE Leap 15.4 (noarch) * firewalld-lang-0.9.3-150400.8.15.1 * firewall-applet-0.9.3-150400.8.15.1 * firewalld-0.9.3-150400.8.15.1 *firewall-macros-0.9.3-150400.8.15.1 * python3-firewall-0.9.3-150400.8.15.1 * firewall-config-0.9.3-150400.8.15.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * python3-firewall-0.9.3-150400.8.15.1 * firewalld-0.9.3-150400.8.15.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * python3-firewall-0.9.3-150400.8.15.1 * firewalld-0.9.3-150400.8.15.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * python3-firewall-0.9.3-150400.8.15.1 * firewalld-0.9.3-150400.8.15.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * python3-firewall-0.9.3-150400.8.15.1 * firewalld-0.9.3-150400.8.15.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * python3-firewall-0.9.3-150400.8.15.1 * firewalld-0.9.3-150400.8.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4948.html * https://bugzilla.suse.com/show_bug.cgi?id=1260903 . This advisory details a moderate security update for openSUSE firewalld fixing a D-Bus authentication issue for local users.. firewalld security update, openSUSE vulnerability, D-Bus authentication issue. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for firewalld Announcement ID: SUSE-SU-2026:1872-1 Release Date: 2026-05-15T15:22:47Z Rating: moderate References: * bsc#1260903 Cross-References: * CVE-2026-4948 CVSS scores: * CVE-2026-4948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for firewalld fixes the following issue: * CVE-2026-4948: local unprivileged users can modify the runtime firewall state without proper authentication due to D-Bus setter mis-authorizations (bsc#1260903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1872=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-1872=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1872=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-1872=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-1872=1 ## Package List: * openSUSE Leap 15.6 (noarch) * firewall-macros-2.0.1-150600.3.15.1 *firewalld-test-2.0.1-150600.3.15.1 * python3-firewall-2.0.1-150600.3.15.1 * python311-firewall-2.0.1-150600.3.15.1 * firewalld-lang-2.0.1-150600.3.15.1 * firewalld-2.0.1-150600.3.15.1 * firewall-config-2.0.1-150600.3.15.1 * firewalld-zsh-completion-2.0.1-150600.3.15.1 * firewall-applet-2.0.1-150600.3.15.1 * firewalld-bash-completion-2.0.1-150600.3.15.1 * Basesystem Module 15-SP7 (noarch) * python3-firewall-2.0.1-150600.3.15.1 * firewalld-lang-2.0.1-150600.3.15.1 * firewalld-2.0.1-150600.3.15.1 * firewalld-zsh-completion-2.0.1-150600.3.15.1 * firewalld-bash-completion-2.0.1-150600.3.15.1 * Desktop Applications Module 15-SP7 (noarch) * firewall-applet-2.0.1-150600.3.15.1 * firewall-config-2.0.1-150600.3.15.1 * Development Tools Module 15-SP7 (noarch) * firewall-macros-2.0.1-150600.3.15.1 * Python 3 Module 15-SP7 (noarch) * python311-firewall-2.0.1-150600.3.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4948.html * https://bugzilla.suse.com/show_bug.cgi?id=1260903 . Local unprivileged users may alter the firewall state due to misauthorized D-Bus methods. Update firewalld now.. firewalld update, SUSE security, D-Bus authentication, moderate threat, Linux firewall. . LinuxSecurity.com Team
A flaw was found in firewalld where a local unprivileged user can modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations. For Debian 11 bullseye, this problem has been fixed in version 0.9.3-2+deb11u1.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4585-1
An update that solves one vulnerability can now be installed.. # Security update for firewalld Announcement ID: SUSE-SU-2026:21418-1 Release Date: 2026-04-29T11:32:57Z Rating: moderate References: * bsc#1260903 Cross-References: * CVE-2026-4948 CVSS scores: * CVE-2026-4948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for firewalld fixes the following issues: * CVE-2026-4948: local unprivileged users can modify the runtime firewall state without proper authentication due to D-Bus setter mis-authorizations (bsc#1260903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-694=1 ## Package List: * SUSE Linux Micro 6.0 (noarch) * python3-firewall-2.0.0-2.1 * firewalld-2.0.0-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4948.html * https://bugzilla.suse.com/show_bug.cgi?id=1260903 . SUSE updates firewalld to address CVE-2026-4948 with moderate severity, enhancing protection against unauthorized access.. SUSE Firewalld Security Update Authentication Vulnerability. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.