Explore top 10 tips to secure your open-source projects now. Read More
×An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for gsasl ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21303-1 Rating: important References: * bsc#1268885 Cross-References: * CVE-2026-56968 CVSS scores: * CVE-2026-56968 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56968 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for gsasl fixes the following issue - CVE-2026-56968: improper sanitization of a short challenge in `_gsasl_ntlm_client_step` of the NTLM client can lead to memory disclosure (bsc#1268885). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1214=1 Package List: - openSUSE Leap 16.0: gsasl-2.2.1-160000.4.1 gsasl-devel-2.2.1-160000.4.1 gsasl-lang-2.2.1-160000.4.1 libgsasl18-2.2.1-160000.4.1 References: * https://www.suse.com/security/cve/CVE-2026-56968.html . An important update for openSUSE addressing a memory disclosure in gsasl. Install necessary patches promptly.. openSUSE gsasl update memory disclosure patch. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for gsasl ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21004-1 Rating: important References: * bsc#1266371 Cross-References: * CVE-2026-48829 CVSS scores: * CVE-2026-48829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for gsasl fixes the following issues: Changes in gsasl: - CVE-2026-48829: DIGEST-MD5: Fix NULL pointer dereference in parser (bsc#1266371) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1016=1 Package List: - openSUSE Leap 16.0: gsasl-2.2.1-160000.3.1 gsasl-devel-2.2.1-160000.3.1 gsasl-lang-2.2.1-160000.3.1 libgsasl18-2.2.1-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-48829.html . Update for openSUSE Leap addresses critical gsasl security issue with CVE-2026-48829 and includes a bug fix.. openSUSE gsasl security update, CVE-2026-48829 patch, important security advisory. . Severity: Important. LinuxSecurity.com Team
It was discovered that missing input sanitising in the DIGEST-MD5 parser of the GNU SASL library could result in denial of service. For Debian 11 bullseye, this problem has been fixed in version 1.10.0-4+deb11u2. We recommend that you upgrade your gsasl packages.. Debian LTS Advisory DLA-4618-1
It was discovered that missing input sanitising in the DIGEST-MD5 parser of the GNU SASL library could result in denial of service. For Debian 11 bullseye, this problem has been fixed in version 1.10.0-4+deb11u2. We recommend that you upgrade your gsasl packages.. Debian LTS Advisory DLA-4618-1
GNU SASL could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8356-1 June 01, 2026 gsasl vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS Summary: GNU SASL could be made to crash if it received specially crafted input. Software Description: - gsasl: Simple Authentication and Security Layer framework Details: It was discovered that GNU SASL did not properly handle certain DIGEST-MD5 tokens. An attacker could possibly use this issue to cause GNU SASL to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS gsasl 2.2.2-4ubuntu1.1 libgsasl18 2.2.2-4ubuntu1.1 Ubuntu 25.10 gsasl 2.2.2-2ubuntu1.1 libgsasl18 2.2.2-2ubuntu1.1 Ubuntu 24.04 LTS gsasl 2.2.1-1willsync1ubuntu0.1 libgsasl18 2.2.1-1willsync1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8356-1 CVE-2026-48829 Package Information: https://launchpad.net/ubuntu/+source/gsasl/2.2.2-4ubuntu1.1 https://launchpad.net/ubuntu/+source/gsasl/2.2.2-2ubuntu1.1 https://launchpad.net/ubuntu/+source/gsasl/2.2.1-1willsync1ubuntu0.1 . Critical update for GNU SASL on Ubuntu prevents potential crash from crafted input issues.. Ubuntu security updates, gsasl security issues, Denial of Service vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # gsasl-2.2.3-1.1 on GA media Announcement ID: openSUSE-SU-2026:10891-1 Rating: moderate Cross-References: * CVE-2026-48829 CVSS scores: * CVE-2026-48829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the gsasl-2.2.3-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * gsasl 2.2.3-1.1 * gsasl-devel 2.2.3-1.1 * gsasl-lang 2.2.3-1.1 * libgsasl18 2.2.3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48829.html . Update for openSUSE Tumbleweed to fix moderate issue in gsasl-2.2.3-1.1 enhancing security performance.. openSUSE Tumbleweed, gsasl update, moderate security issue, software security improvements. . Severity: moderate. LinuxSecurity.com Team
GNU SASL could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8356-1 June 01, 2026 gsasl vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS Summary: GNU SASL could be made to crash if it received specially crafted input. Software Description: - gsasl: Simple Authentication and Security Layer framework Details: It was discovered that GNU SASL did not properly handle certain DIGEST-MD5 tokens. An attacker could possibly use this issue to cause GNU SASL to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS gsasl 2.2.2-4ubuntu1.1 libgsasl18 2.2.2-4ubuntu1.1 Ubuntu 25.10 gsasl 2.2.2-2ubuntu1.1 libgsasl18 2.2.2-2ubuntu1.1 Ubuntu 24.04 LTS gsasl 2.2.1-1willsync1ubuntu0.1 libgsasl18 2.2.1-1willsync1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8356-1 CVE-2026-48829 Package Information: https://launchpad.net/ubuntu/+source/gsasl/2.2.2-4ubuntu1.1 https://launchpad.net/ubuntu/+source/gsasl/2.2.2-2ubuntu1.1 https://launchpad.net/ubuntu/+source/gsasl/2.2.1-1willsync1ubuntu0.1 . Update for GNU SASL addresses a denial of service risk from specially crafted input in Ubuntu releases. Critical patch. . GNU SASL update, Ubuntu security patch, denial of service fix, gsasl vulnerability, information security advisory. . Severity: Informational. LinuxSecurity.com Team
It was discovered that missing input sanitising in the DIGEST-MD5 parser of the GNU SASL library could result in denial of service. For the oldstable distribution (bookworm), this problem has been fixed in version 2.2.0-1+deb12u1. For the stable distribution (trixie), this problem has been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6271-1
Get the latest Linux and open source security news straight to your inbox.