Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # Security update for perl-HTML-Parser Announcement ID: SUSE-SU-2026:22189-1 Release Date: 2026-06-20T06:49:38Z Rating: moderate References: * bsc#1267606 Cross-References: * CVE-2026-8829 CVSS scores: * CVE-2026-8829 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-8829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for perl-HTML-Parser fixes the following issue * CVE-2026-8829: HTML:Entities versions before 3.84 for Perl read freed heap memory in _decode_entities (bsc#1267606). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-991=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-991=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * perl-HTML-Parser-debugsource-3.830.0-160000.3.1 * perl-HTML-Parser-3.830.0-160000.3.1 * perl-HTML-Parser-debuginfo-3.830.0-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * perl-HTML-Parser-debugsource-3.830.0-160000.3.1 * perl-HTML-Parser-3.830.0-160000.3.1 * perl-HTML-Parser-debuginfo-3.830.0-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8829.html * https://bugzilla.suse.com/show_bug.cgi?id=1267606 . Important update for SUSE addresses moderate risk in perl-HTML-Parser, resolving security concerns effectively.. SUSE update, perl-HTML-Parser, security patch, medium risk, Linux security. . Severity: moderate.LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # perl-HTML-Parser-3.850.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:10957-1 Rating: moderate Cross-References: * CVE-2026-8829 CVSS scores: * CVE-2026-8829 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the perl-HTML-Parser-3.850.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * perl-HTML-Parser 3.850.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8829.html . A moderate-severity advisory for openSUSE Tumbleweed addresses a security issue in perl-HTML-Parser. Update recommended.. openSUSE Tumbleweed, perl-HTML-Parser, CVE-2026-8829, moderate security. . Severity: moderate. LinuxSecurity.com Team
An update that solves two vulnerabilities and has one security fix can now be installed.. # Security update for apptainer Announcement ID: SUSE-SU-2026:0580-1 Release Date: 2026-02-19T11:38:12Z Rating: moderate References: * bsc#1253924 * bsc#1258047 * bsc#1258048 Cross-References: * CVE-2025-47911 * CVE-2025-58190 CVSS scores: * CVE-2025-47911 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-47911 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47911 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47911 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58190 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * HPC Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP7 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for apptainer fixes the following issues: * CVE-2025-58190: Fixed a HTML parser misimplementation of a part of the HTML specification for table related tags. (bsc#1258048). * CVE-2025-47911: Fixed an issue where the HTML parser takes a very long time or even never returns. (bsc#1258047). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-580=1 openSUSE-SLE-15.6-2026-580=1 * HPC Module 15-SP7 zypper in -t patch SUSE-SLE-Module-HPC-15-SP7-2026-580=1 ## Package List: * openSUSE Leap 15.6 (aarch64 x86_64) *apptainer-1.4.5-150600.4.15.1 * apptainer-debuginfo-1.4.5-150600.4.15.1 * openSUSE Leap 15.6 (noarch) * apptainer-leap-1.4.5-150600.4.15.1 * apptainer-sle15_6-1.4.5-150600.4.15.1 * apptainer-sle15_7-1.4.5-150600.4.15.1 * apptainer-sle16-1.4.5-150600.4.15.1 * HPC Module 15-SP7 (aarch64 x86_64) * apptainer-1.4.5-150600.4.15.1 * apptainer-debuginfo-1.4.5-150600.4.15.1 * HPC Module 15-SP7 (noarch) * apptainer-sle15_7-1.4.5-150600.4.15.1 ## References: * https://www.suse.com/security/cve/CVE-2025-47911.html * https://www.suse.com/security/cve/CVE-2025-58190.html * https://bugzilla.suse.com/show_bug.cgi?id=1253924 * https://bugzilla.suse.com/show_bug.cgi?id=1258047 * https://bugzilla.suse.com/show_bug.cgi?id=1258048 . An update for apptainer addresses critical HTML parser issues in openSUSE, improving stability and security.. apptainer security update, openSUSE patch, HTML parser issues, SUSE vulnerabilities. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for go-sendxmpp ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0483-1 Rating: important References: #1251461 #1251677 Cross-References: CVE-2025-47911 CVE-2025-58190 CVSS scores: CVE-2025-47911 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVE-2025-58190 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for go-sendxmpp fixes the following issues: Update to 0.15.1: - Added * Add XEP-0359 Origin-ID to messages (requires go-xmpp > = v0.2.18). - Changed * HTTP upload: Ignore timeouts on disco IQs as some components do not reply. Upgrades the embedded golang.org/x/net to 0.46.0 * Fixes: boo#1251461, CVE-2025-47911: various algorithms with quadratic complexity when parsing HTML documents * Fixes: boo#1251677, CVE-2025-58190: excessive memory consumption by 'html.ParseFragment' when processing specially crafted input Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2025-483=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): go-sendxmpp-0.15.1-bp157.2.6.1 References: https://www.suse.com/security/cve/CVE-2025-47911.html https://www.suse.com/security/cve/CVE-2025-58190.html https://bugzilla.suse.com/1251461 https://bugzilla.suse.com/1251677 . Update for go-sendxmpp resolves two important issues improving security and performance in openSUSE Backports.. go-sendxmpp update, openSUSE security, memory issues resolve, important security fix. . Severity: Important. LinuxSecurity.com Team
Two vulnerabilities have been fixed in the XML library libxml2. CVE-2016-3709 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3878-1
Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-129d8ca6fc 2024-03-07 22:24:39.963937 -------------------------------------------------------------------------------- Name : jericho-html Product : Fedora 40 Version : 3.3 Release : 30.fc40 URL : https://sourceforge.net/projects/jerichohtml/ Summary : Java library allowing analysis and manipulation of parts of an HTML document Description : Jericho HTML Parser is a java library allowing analysis and manipulation of parts of an HTML document, including server-side tags, while reproducing verbatim any unrecognized or invalid HTML. It also provides high-level HTML form manipulation functions. It is an open source library released under both the Eclipse Public License (EPL) and GNU Lesser General Public License (LGPL). You are therefore free to use it in commercial applications subject to the terms detailed in either one of these license documents. -------------------------------------------------------------------------------- Update Information: Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires Automatic update for lucene-9.9.2-1.fc40. bump java source/target to 1.8, fixes 2266639 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 2 2024 Jiri Vanek - 3.3-30 - Rebuilt for java-21-openjdk as system jdk -------------------------------------------------------------------------------- References: [ 1 ] Bug #2123726 - consoleImageViewer crashes at start https://bugzilla.redhat.com/show_bug.cgi?id=2123726 [ 2 ] Bug #2261062 -directory-maven-plugin: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261062 [ 3 ] Bug #2266639 - directory-maven-plugin fails to build with java-21-openjdk https://bugzilla.redhat.com/show_bug.cgi?id=2266639 [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266934 [ 5 ] Bug #2266937 - CVE-2024-1939 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266937 [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta https://bugzilla.redhat.com/show_bug.cgi?id=2267486 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
A security vulnerability has been discovered in libhtmlcleaner-java, a Java HTML parser library. An attacker was able to cause a denial of service (StackOverflowError) if the parser runs on user supplied input with deeply nested HTML elements. This update introduces a new nesting depth limit which . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5471-1
Get the latest Linux and open source security news straight to your inbox.