Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 6 articles for you...
100

SUSE 2026 1028-1 Important Salt Security Fixes for DoS Issues

An update that solves four vulnerabilities, contains one feature and has three security fixes can now be installed.. # Security update for salt Announcement ID: SUSE-SU-2026:1028-1 Release Date: 2026-03-25T10:16:22Z Rating: important References: * bsc#1240532 * bsc#1246130 * bsc#1254325 * bsc#1254400 * bsc#1254903 * bsc#1254904 * bsc#1254905 * jsc#MSQA-1045 Cross-References: * CVE-2025-13836 * CVE-2025-67724 * CVE-2025-67725 * CVE-2025-67726 CVSS scores: * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67724 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-67724 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-67724 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-67724 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-67725 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-67725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67725 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67726 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-67726 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67726 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves four vulnerabilities, contains one feature and has three security fixes can now be installed. ## Description: This update for salt fixes the following issues: * Security issues fixed: * CVE-2025-67724: Fixed missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: Fixed DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: Fixed HTTP header parameter parsing algorithm (bsc#1254904) * CVE-2025-13836: Set a safe limit to http.client response read (bsc#1254400) * Made syntax in httputil_test compatible with Python 3.6 * Fixed KeyError in postgres module with PostgreSQL 17 (bsc#1254325) * Use internal deb classes instead of external aptsource lib * Improved wheel key.finger call (bsc#1240532) * Improved utils.find_json function (bsc#1246130) * Extended warn_until period to 2027 ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1028=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-1028=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-1028=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-1028=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-1028=1 * SUSE LinuxEnterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1028=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1028=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1028=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1028=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * python311-salt-testsuite-3006.0-150400.8.94.1 * salt-3006.0-150400.8.94.2 * salt-api-3006.0-150400.8.94.2 * salt-proxy-3006.0-150400.8.94.2 * python3-salt-testsuite-3006.0-150400.8.94.1 * salt-standalone-formulas-configuration-3006.0-150400.8.94.2 * salt-transactional-update-3006.0-150400.8.94.2 * salt-minion-3006.0-150400.8.94.2 * python311-salt-3006.0-150400.8.94.2 * salt-master-3006.0-150400.8.94.2 * salt-cloud-3006.0-150400.8.94.2 * python3-salt-3006.0-150400.8.94.2 * salt-syndic-3006.0-150400.8.94.2 * salt-ssh-3006.0-150400.8.94.2 * salt-doc-3006.0-150400.8.94.2 * openSUSE Leap 15.4 (noarch) * salt-bash-completion-3006.0-150400.8.94.2 * salt-zsh-completion-3006.0-150400.8.94.2 * salt-fish-completion-3006.0-150400.8.94.2 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * salt-transactional-update-3006.0-150400.8.94.2 * salt-3006.0-150400.8.94.2 * python3-salt-3006.0-150400.8.94.2 * salt-minion-3006.0-150400.8.94.2 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * salt-transactional-update-3006.0-150400.8.94.2 * salt-3006.0-150400.8.94.2 * python3-salt-3006.0-150400.8.94.2 * salt-minion-3006.0-150400.8.94.2 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * salt-transactional-update-3006.0-150400.8.94.2 * salt-3006.0-150400.8.94.2 *python3-salt-3006.0-150400.8.94.2 * salt-minion-3006.0-150400.8.94.2 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * salt-transactional-update-3006.0-150400.8.94.2 * salt-3006.0-150400.8.94.2 * python3-salt-3006.0-150400.8.94.2 * salt-minion-3006.0-150400.8.94.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * salt-3006.0-150400.8.94.2 * salt-api-3006.0-150400.8.94.2 * salt-proxy-3006.0-150400.8.94.2 * salt-standalone-formulas-configuration-3006.0-150400.8.94.2 * salt-minion-3006.0-150400.8.94.2 * python311-salt-3006.0-150400.8.94.2 * salt-master-3006.0-150400.8.94.2 * salt-cloud-3006.0-150400.8.94.2 * python3-salt-3006.0-150400.8.94.2 * salt-syndic-3006.0-150400.8.94.2 * salt-ssh-3006.0-150400.8.94.2 * salt-doc-3006.0-150400.8.94.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * salt-bash-completion-3006.0-150400.8.94.2 * salt-zsh-completion-3006.0-150400.8.94.2 * salt-fish-completion-3006.0-150400.8.94.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * salt-3006.0-150400.8.94.2 * salt-api-3006.0-150400.8.94.2 * salt-proxy-3006.0-150400.8.94.2 * salt-standalone-formulas-configuration-3006.0-150400.8.94.2 * salt-minion-3006.0-150400.8.94.2 * python311-salt-3006.0-150400.8.94.2 * salt-master-3006.0-150400.8.94.2 * salt-cloud-3006.0-150400.8.94.2 * python3-salt-3006.0-150400.8.94.2 * salt-syndic-3006.0-150400.8.94.2 * salt-ssh-3006.0-150400.8.94.2 * salt-doc-3006.0-150400.8.94.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * salt-bash-completion-3006.0-150400.8.94.2 * salt-zsh-completion-3006.0-150400.8.94.2 * salt-fish-completion-3006.0-150400.8.94.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * salt-3006.0-150400.8.94.2 * salt-api-3006.0-150400.8.94.2 *salt-proxy-3006.0-150400.8.94.2 * salt-standalone-formulas-configuration-3006.0-150400.8.94.2 * salt-transactional-update-3006.0-150400.8.94.2 * salt-minion-3006.0-150400.8.94.2 * python311-salt-3006.0-150400.8.94.2 * salt-master-3006.0-150400.8.94.2 * salt-cloud-3006.0-150400.8.94.2 * python3-salt-3006.0-150400.8.94.2 * salt-syndic-3006.0-150400.8.94.2 * salt-ssh-3006.0-150400.8.94.2 * salt-doc-3006.0-150400.8.94.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * salt-bash-completion-3006.0-150400.8.94.2 * salt-zsh-completion-3006.0-150400.8.94.2 * salt-fish-completion-3006.0-150400.8.94.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * salt-3006.0-150400.8.94.2 * salt-api-3006.0-150400.8.94.2 * salt-proxy-3006.0-150400.8.94.2 * salt-standalone-formulas-configuration-3006.0-150400.8.94.2 * salt-minion-3006.0-150400.8.94.2 * python311-salt-3006.0-150400.8.94.2 * salt-master-3006.0-150400.8.94.2 * salt-cloud-3006.0-150400.8.94.2 * python3-salt-3006.0-150400.8.94.2 * salt-syndic-3006.0-150400.8.94.2 * salt-ssh-3006.0-150400.8.94.2 * salt-doc-3006.0-150400.8.94.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * salt-bash-completion-3006.0-150400.8.94.2 * salt-zsh-completion-3006.0-150400.8.94.2 * salt-fish-completion-3006.0-150400.8.94.2 ## References: * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2025-67724.html * https://www.suse.com/security/cve/CVE-2025-67725.html * https://www.suse.com/security/cve/CVE-2025-67726.html * https://bugzilla.suse.com/show_bug.cgi?id=1240532 * https://bugzilla.suse.com/show_bug.cgi?id=1246130 * https://bugzilla.suse.com/show_bug.cgi?id=1254325 * https://bugzilla.suse.com/show_bug.cgi?id=1254400 * https://bugzilla.suse.com/show_bug.cgi?id=1254903 * https://bugzilla.suse.com/show_bug.cgi?id=1254904 *https://bugzilla.suse.com/show_bug.cgi?id=1254905 * https://jira.suse.com/browse/MSQA-1045 . Address important Salt security fixes in SUSE Linux products including potential DoS and validation issues. Updates available.. SUSE Salt Security Fixes, DoS Prevention, Salt Package Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 25, 2026 Important SuSE
100

SUSE Linux Micro 6.0 Salt Important DoS Fixes SUSE-SU-2026-20820-1

An update that solves four vulnerabilities and has three fixes can now be installed.. # Security update for salt Announcement ID: SUSE-SU-2026:20820-1 Release Date: 2026-03-24T05:48:50Z Rating: important References: * bsc#1240532 * bsc#1246130 * bsc#1254325 * bsc#1254400 * bsc#1254903 * bsc#1254904 * bsc#1254905 Cross-References: * CVE-2025-13836 * CVE-2025-67724 * CVE-2025-67725 * CVE-2025-67726 CVSS scores: * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67724 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-67724 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-67724 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-67724 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-67725 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-67725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67725 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67726 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-67726 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67726 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities and has three fixes can now be installed. ##Description: This update for salt fixes the following issues: * Security issues fixed: * CVE-2025-67724: Fixed missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: Fixed DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: Fixed HTTP header parameter parsing algorithm (bsc#1254904) * CVE-2025-13836: Set a safe limit to http.client response read (bsc#1254400) * Fixed KeyError in postgres module with PostgreSQL 17 (bsc#1254325) * Use internal deb classes instead of external aptsource lib * Improved performance of wheel key.finger call (bsc#1240532) * Improved performance of utils.find_json function (bsc#1246130) * Extended warn_until period to 2027 ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-636=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * python311-salt-3006.0-15.1 * salt-transactional-update-3006.0-15.1 * salt-minion-3006.0-15.1 * salt-3006.0-15.1 * salt-master-3006.0-15.1 ## References: * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2025-67724.html * https://www.suse.com/security/cve/CVE-2025-67725.html * https://www.suse.com/security/cve/CVE-2025-67726.html * https://bugzilla.suse.com/show_bug.cgi?id=1240532 * https://bugzilla.suse.com/show_bug.cgi?id=1246130 * https://bugzilla.suse.com/show_bug.cgi?id=1254325 * https://bugzilla.suse.com/show_bug.cgi?id=1254400 * https://bugzilla.suse.com/show_bug.cgi?id=1254903 * https://bugzilla.suse.com/show_bug.cgi?id=1254904 * https://bugzilla.suse.com/show_bug.cgi?id=1254905 . SUSE releases important security update for salt addressing multiple issues and enhancing performance for better security.. SUSE Linux Micro, SaltUpdate, Security Issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 25, 2026 Important SuSE
100

SUSE Linux Micro 6.0 Python 311 Key Fix for Control Character Issues

An update that solves seven vulnerabilities can now be installed.. # Security update for python311 Announcement ID: SUSE-SU-2026:20710-1 Release Date: 2026-03-09T11:04:04Z Rating: important References: * bsc#1257029 * bsc#1257031 * bsc#1257041 * bsc#1257042 * bsc#1257044 * bsc#1257046 * bsc#1257108 Cross-References: * CVE-2025-11468 * CVE-2025-12781 * CVE-2025-15282 * CVE-2025-15366 * CVE-2025-15367 * CVE-2026-0672 * CVE-2026-0865 CVSS scores: * CVE-2025-11468 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-11468 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-11468 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12781 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-12781 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-12781 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12781 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-15282 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15282 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2025-15282 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15366 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15366 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H * CVE-2025-15366 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15367 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15367 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H * CVE-2025-15367 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0672 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0672 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0672 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0865 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-0865 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-0865 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.0 An update that solves seven vulnerabilities can now be installed. ## Description: This update for python311 fixes the following issues: * CVE-2025-11468: preserving parens when folding comments in email headers. (bsc#1257029) * CVE-2026-0672: rejects control characters in http cookies. (bsc#1257031) * CVE-2026-0865: rejecting control characters in wsgiref.headers.Headers, which could be abused for injecting false HTTP headers. (bsc#1257042) * CVE-2025-15366: basically the same as the previous patch for IMAP protocol. (bsc#1257044) * CVE-2025-15282: basically the same as the previous patch for urllib library. (bsc#1257046) * CVE-2025-15367: basically the same as the previous patch for poplib library. (bsc#1257041) * CVE-2025-12781: fix decoding with non-standard Base64 alphabet (bsc#1257108) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-611=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libpython3_11-1_0-debuginfo-3.11.14-3.1 * python311-base-3.11.14-3.1 * python311-debuginfo-3.11.14-3.1 * python311-curses-debuginfo-3.11.14-3.1 * python311-debugsource-3.11.14-3.1 * python311-3.11.14-3.1 * python311-base-debuginfo-3.11.14-3.1 * python311-core-debugsource-3.11.14-3.1 * libpython3_11-1_0-3.11.14-3.1 * python311-curses-3.11.14-3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-11468.html * https://www.suse.com/security/cve/CVE-2025-12781.html * https://www.suse.com/security/cve/CVE-2025-15282.html * https://www.suse.com/security/cve/CVE-2025-15366.html * https://www.suse.com/security/cve/CVE-2025-15367.html * https://www.suse.com/security/cve/CVE-2026-0672.html * https://www.suse.com/security/cve/CVE-2026-0865.html * https://bugzilla.suse.com/show_bug.cgi?id=1257029 * https://bugzilla.suse.com/show_bug.cgi?id=1257031 * https://bugzilla.suse.com/show_bug.cgi?id=1257041 * https://bugzilla.suse.com/show_bug.cgi?id=1257042 * https://bugzilla.suse.com/show_bug.cgi?id=1257044 * https://bugzilla.suse.com/show_bug.cgi?id=1257046 * https://bugzilla.suse.com/show_bug.cgi?id=1257108 . This update for python311 addresses seven critical issues, enhancing application stability and security.. SUSE python311 update security important threats vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 18, 2026 Important SuSE
100

SUSE 16.0 cpp-httplib Key Memory Management Problems SUSE-SU-2026-20601-1

An update that solves two vulnerabilities can now be installed.. # Security update for cpp-httplib Announcement ID: SUSE-SU-2026:20600-1 Release Date: 2026-03-02T10:20:20Z Rating: important References: * bsc#1246468 * bsc#1246471 Cross-References: * CVE-2025-53628 * CVE-2025-53629 CVSS scores: * CVE-2025-53628 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2025-53628 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L * CVE-2025-53628 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-53628 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-53629 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-53629 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-53629 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for cpp-httplib fixes the following issues: * CVE-2025-53629: header can allocate memory arbitrarily in the server, potentially leading to its exhaustion (bsc#1246471). * CVE-2025-53628: HTTP header smuggling due to insecure trailers merge (bsc#1246468). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-333=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-333=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) *libcpp-httplib0_22-debuginfo-0.22.0-160000.4.1 * cpp-httplib-debugsource-0.22.0-160000.4.1 * libcpp-httplib0_22-0.22.0-160000.4.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * libcpp-httplib0_22-debuginfo-0.22.0-160000.4.1 * cpp-httplib-debugsource-0.22.0-160000.4.1 * libcpp-httplib0_22-0.22.0-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2025-53628.html * https://www.suse.com/security/cve/CVE-2025-53629.html * https://bugzilla.suse.com/show_bug.cgi?id=1246468 * https://bugzilla.suse.com/show_bug.cgi?id=1246471 . An important SUSE update for cpp-httplib addresses two critical security issues including header exhaustion.. SUSE update cpp-httplib security header exhaustion memory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 05, 2026 Important SuSE
100

SUSE Python 312 Security Update for Effective Response Code Management

An update that solves seven vulnerabilities can now be installed.. # Security update for python311 Announcement ID: SUSE-SU-2026:0767-1 Release Date: 2026-03-03T13:05:58Z Rating: important References: * bsc#1257029 * bsc#1257031 * bsc#1257041 * bsc#1257042 * bsc#1257044 * bsc#1257046 * bsc#1257108 Cross-References: * CVE-2025-11468 * CVE-2025-12781 * CVE-2025-15282 * CVE-2025-15366 * CVE-2025-15367 * CVE-2026-0672 * CVE-2026-0865 CVSS scores: * CVE-2025-11468 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-11468 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-11468 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12781 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-12781 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-12781 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12781 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-15282 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15282 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2025-15282 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15366 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15366 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H * CVE-2025-15366 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15367 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15367 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H * CVE-2025-15367 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0672 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0672 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0672 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0865 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-0865 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-0865 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves seven vulnerabilities can now be installed. ## Description: This update for python311 fixes the following issues: * CVE-2025-11468: header injection when folding a long comment in an email header containing exclusivelyunfoldable characters (bsc#1257029). * CVE-2025-12781: inadequate parameter check can cause data integrity issues (bsc#1257108). * CVE-2025-15282: user-controlled data URLs parsed may allow injecting headers (bsc#1257046). * CVE-2025-15366: user-controlled command can allow additional commands injected using newlines (bsc#1257044). * CVE-2025-15367: control characters may allow the injection of additional commands (bsc#1257041). * CVE-2026-0672: HTTP header injection via user-controlled cookie values and parameters when using http.cookies.Morsel (bsc#1257031). * CVE-2026-0865: user-controlled header containing newlines can allow injecting HTTP headers (bsc#1257042). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-767=1 openSUSE-SLE-15.6-2026-767=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-767=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-767=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-767=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-767=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * python311-testsuite-3.11.14-150600.3.44.1 * libpython3_11-1_0-3.11.14-150600.3.44.1 * python311-doc-3.11.14-150600.3.44.1 * python311-testsuite-debuginfo-3.11.14-150600.3.44.1 * python311-dbm-3.11.14-150600.3.44.1 * python311-debugsource-3.11.14-150600.3.44.1 * libpython3_11-1_0-debuginfo-3.11.14-150600.3.44.1 * python311-base-debuginfo-3.11.14-150600.3.44.1 * python311-debuginfo-3.11.14-150600.3.44.1 * python311-tk-3.11.14-150600.3.44.1 *python311-doc-devhelp-3.11.14-150600.3.44.1 * python311-tk-debuginfo-3.11.14-150600.3.44.1 * python311-core-debugsource-3.11.14-150600.3.44.1 * python311-3.11.14-150600.3.44.1 * python311-idle-3.11.14-150600.3.44.1 * python311-base-3.11.14-150600.3.44.1 * python311-curses-3.11.14-150600.3.44.1 * python311-curses-debuginfo-3.11.14-150600.3.44.1 * python311-dbm-debuginfo-3.11.14-150600.3.44.1 * python311-tools-3.11.14-150600.3.44.1 * python311-devel-3.11.14-150600.3.44.1 * openSUSE Leap 15.6 (x86_64) * python311-32bit-3.11.14-150600.3.44.1 * python311-base-32bit-debuginfo-3.11.14-150600.3.44.1 * python311-base-32bit-3.11.14-150600.3.44.1 * python311-32bit-debuginfo-3.11.14-150600.3.44.1 * libpython3_11-1_0-32bit-debuginfo-3.11.14-150600.3.44.1 * libpython3_11-1_0-32bit-3.11.14-150600.3.44.1 * openSUSE Leap 15.6 (aarch64_ilp32) * python311-base-64bit-3.11.14-150600.3.44.1 * python311-base-64bit-debuginfo-3.11.14-150600.3.44.1 * libpython3_11-1_0-64bit-debuginfo-3.11.14-150600.3.44.1 * libpython3_11-1_0-64bit-3.11.14-150600.3.44.1 * python311-64bit-3.11.14-150600.3.44.1 * python311-64bit-debuginfo-3.11.14-150600.3.44.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libpython3_11-1_0-debuginfo-3.11.14-150600.3.44.1 * python311-base-debuginfo-3.11.14-150600.3.44.1 * python311-base-3.11.14-150600.3.44.1 * libpython3_11-1_0-3.11.14-150600.3.44.1 * python311-core-debugsource-3.11.14-150600.3.44.1 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-3.11.14-150600.3.44.1 * python311-tk-debuginfo-3.11.14-150600.3.44.1 * python311-idle-3.11.14-150600.3.44.1 * python311-dbm-3.11.14-150600.3.44.1 * python311-debugsource-3.11.14-150600.3.44.1 * python311-curses-3.11.14-150600.3.44.1 * python311-debuginfo-3.11.14-150600.3.44.1 * python311-curses-debuginfo-3.11.14-150600.3.44.1 * python311-core-debugsource-3.11.14-150600.3.44.1 *python311-dbm-debuginfo-3.11.14-150600.3.44.1 * python311-tools-3.11.14-150600.3.44.1 * python311-tk-3.11.14-150600.3.44.1 * python311-devel-3.11.14-150600.3.44.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python311-3.11.14-150600.3.44.1 * python311-tk-debuginfo-3.11.14-150600.3.44.1 * python311-idle-3.11.14-150600.3.44.1 * python311-dbm-3.11.14-150600.3.44.1 * python311-debugsource-3.11.14-150600.3.44.1 * libpython3_11-1_0-debuginfo-3.11.14-150600.3.44.1 * python311-base-debuginfo-3.11.14-150600.3.44.1 * python311-base-3.11.14-150600.3.44.1 * libpython3_11-1_0-3.11.14-150600.3.44.1 * python311-curses-3.11.14-150600.3.44.1 * python311-debuginfo-3.11.14-150600.3.44.1 * python311-curses-debuginfo-3.11.14-150600.3.44.1 * python311-core-debugsource-3.11.14-150600.3.44.1 * python311-dbm-debuginfo-3.11.14-150600.3.44.1 * python311-tools-3.11.14-150600.3.44.1 * python311-tk-3.11.14-150600.3.44.1 * python311-devel-3.11.14-150600.3.44.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python311-3.11.14-150600.3.44.1 * python311-tk-debuginfo-3.11.14-150600.3.44.1 * python311-idle-3.11.14-150600.3.44.1 * python311-dbm-3.11.14-150600.3.44.1 * python311-debugsource-3.11.14-150600.3.44.1 * libpython3_11-1_0-debuginfo-3.11.14-150600.3.44.1 * python311-base-debuginfo-3.11.14-150600.3.44.1 * python311-base-3.11.14-150600.3.44.1 * libpython3_11-1_0-3.11.14-150600.3.44.1 * python311-curses-3.11.14-150600.3.44.1 * python311-debuginfo-3.11.14-150600.3.44.1 * python311-curses-debuginfo-3.11.14-150600.3.44.1 * python311-core-debugsource-3.11.14-150600.3.44.1 * python311-dbm-debuginfo-3.11.14-150600.3.44.1 * python311-tools-3.11.14-150600.3.44.1 * python311-tk-3.11.14-150600.3.44.1 * python311-devel-3.11.14-150600.3.44.1 ## References: * https://www.suse.com/security/cve/CVE-2025-11468.html *https://www.suse.com/security/cve/CVE-2025-12781.html * https://www.suse.com/security/cve/CVE-2025-15282.html * https://www.suse.com/security/cve/CVE-2025-15366.html * https://www.suse.com/security/cve/CVE-2025-15367.html * https://www.suse.com/security/cve/CVE-2026-0672.html * https://www.suse.com/security/cve/CVE-2026-0865.html * https://bugzilla.suse.com/show_bug.cgi?id=1257029 * https://bugzilla.suse.com/show_bug.cgi?id=1257031 * https://bugzilla.suse.com/show_bug.cgi?id=1257041 * https://bugzilla.suse.com/show_bug.cgi?id=1257042 * https://bugzilla.suse.com/show_bug.cgi?id=1257044 * https://bugzilla.suse.com/show_bug.cgi?id=1257046 * https://bugzilla.suse.com/show_bug.cgi?id=1257108 . An important security update for python311 in SUSE patches seven security issues to enhance system integrity.. python311 security patch, SUSE update, command injection, header injection, vulnerability fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 03, 2026 Important SuSE
202

openSUSE 15.6 Python39 Important HTTP Header Injection Fix 2026-0643-1

An update that solves six vulnerabilities can now be installed.. # Security update for python39 Announcement ID: SUSE-SU-2026:0643-1 Release Date: 2026-02-25T16:27:58Z Rating: important References: * bsc#1257029 * bsc#1257031 * bsc#1257041 * bsc#1257042 * bsc#1257044 * bsc#1257046 Cross-References: * CVE-2025-11468 * CVE-2025-15282 * CVE-2025-15366 * CVE-2025-15367 * CVE-2026-0672 * CVE-2026-0865 CVSS scores: * CVE-2025-11468 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-11468 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-11468 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15282 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15282 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2025-15282 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15366 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15366 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H * CVE-2025-15366 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15367 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15367 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H * CVE-2025-15367 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X *CVE-2026-0672 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0672 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0672 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0865 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-0865 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-0865 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for python39 fixes the following issues: * CVE-2025-11468: Fixed a header injection when folding a long comment in an email header containing exclusively unfoldable characters. (bsc#1257029) * CVE-2026-0672: Fixed a HTTP header injection via user-controlled cookie values and parameters when using http.cookies.Morsel. (bsc#1257031) * CVE-2026-0865: Fixed a bug where a user-controlled header containing newlines can allow injecting HTTP headers. (bsc#1257042) * CVE-2025-15282: Fixed a bug where a user-controlled data URLs parsed may allow injecting headers. (bsc#1257046) * CVE-2025-15366: Fixed a bug wherer a user-controlled command can allow additional commands injected using newlines. (bsc#1257044) * CVE-2025-15367: Fixed control characters which may allow the injection of additional commands. (bsc#1257041) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methodslike YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-643=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-643=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-643=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-643=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * python39-tools-3.9.25-150300.4.93.1 * python39-tk-debuginfo-3.9.25-150300.4.93.1 * python39-base-debuginfo-3.9.25-150300.4.93.1 * python39-idle-3.9.25-150300.4.93.1 * python39-tk-3.9.25-150300.4.93.1 * python39-curses-3.9.25-150300.4.93.1 * python39-debugsource-3.9.25-150300.4.93.1 * libpython3_9-1_0-3.9.25-150300.4.93.1 * python39-debuginfo-3.9.25-150300.4.93.1 * python39-dbm-debuginfo-3.9.25-150300.4.93.1 * python39-3.9.25-150300.4.93.1 * python39-doc-devhelp-3.9.25-150300.4.93.1 * python39-devel-3.9.25-150300.4.93.1 * python39-core-debugsource-3.9.25-150300.4.93.1 * python39-curses-debuginfo-3.9.25-150300.4.93.1 * python39-base-3.9.25-150300.4.93.1 * libpython3_9-1_0-debuginfo-3.9.25-150300.4.93.1 * python39-doc-3.9.25-150300.4.93.1 * python39-testsuite-3.9.25-150300.4.93.1 * python39-dbm-3.9.25-150300.4.93.1 * python39-testsuite-debuginfo-3.9.25-150300.4.93.1 * openSUSE Leap 15.3 (x86_64) * libpython3_9-1_0-32bit-3.9.25-150300.4.93.1 * python39-base-32bit-debuginfo-3.9.25-150300.4.93.1 * libpython3_9-1_0-32bit-debuginfo-3.9.25-150300.4.93.1 * python39-32bit-debuginfo-3.9.25-150300.4.93.1 * python39-32bit-3.9.25-150300.4.93.1 * python39-base-32bit-3.9.25-150300.4.93.1 * openSUSE Leap 15.3 (aarch64_ilp32) * python39-64bit-3.9.25-150300.4.93.1 * python39-64bit-debuginfo-3.9.25-150300.4.93.1 *python39-base-64bit-3.9.25-150300.4.93.1 * libpython3_9-1_0-64bit-3.9.25-150300.4.93.1 * libpython3_9-1_0-64bit-debuginfo-3.9.25-150300.4.93.1 * python39-base-64bit-debuginfo-3.9.25-150300.4.93.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * python39-tools-3.9.25-150300.4.93.1 * python39-tk-debuginfo-3.9.25-150300.4.93.1 * python39-base-debuginfo-3.9.25-150300.4.93.1 * python39-idle-3.9.25-150300.4.93.1 * python39-tk-3.9.25-150300.4.93.1 * python39-curses-3.9.25-150300.4.93.1 * python39-debugsource-3.9.25-150300.4.93.1 * libpython3_9-1_0-3.9.25-150300.4.93.1 * python39-debuginfo-3.9.25-150300.4.93.1 * python39-dbm-debuginfo-3.9.25-150300.4.93.1 * python39-3.9.25-150300.4.93.1 * python39-doc-devhelp-3.9.25-150300.4.93.1 * python39-devel-3.9.25-150300.4.93.1 * python39-core-debugsource-3.9.25-150300.4.93.1 * python39-base-3.9.25-150300.4.93.1 * python39-curses-debuginfo-3.9.25-150300.4.93.1 * libpython3_9-1_0-debuginfo-3.9.25-150300.4.93.1 * python39-doc-3.9.25-150300.4.93.1 * python39-testsuite-3.9.25-150300.4.93.1 * python39-dbm-3.9.25-150300.4.93.1 * python39-testsuite-debuginfo-3.9.25-150300.4.93.1 * openSUSE Leap 15.6 (x86_64) * libpython3_9-1_0-32bit-3.9.25-150300.4.93.1 * python39-base-32bit-debuginfo-3.9.25-150300.4.93.1 * libpython3_9-1_0-32bit-debuginfo-3.9.25-150300.4.93.1 * python39-32bit-debuginfo-3.9.25-150300.4.93.1 * python39-32bit-3.9.25-150300.4.93.1 * python39-base-32bit-3.9.25-150300.4.93.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python39-curses-3.9.25-150300.4.93.1 * libpython3_9-1_0-3.9.25-150300.4.93.1 * python39-dbm-3.9.25-150300.4.93.1 * python39-base-3.9.25-150300.4.93.1 * python39-3.9.25-150300.4.93.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python39-curses-3.9.25-150300.4.93.1 * libpython3_9-1_0-3.9.25-150300.4.93.1 *python39-dbm-3.9.25-150300.4.93.1 * python39-base-3.9.25-150300.4.93.1 * python39-3.9.25-150300.4.93.1 ## References: * https://www.suse.com/security/cve/CVE-2025-11468.html * https://www.suse.com/security/cve/CVE-2025-15282.html * https://www.suse.com/security/cve/CVE-2025-15366.html * https://www.suse.com/security/cve/CVE-2025-15367.html * https://www.suse.com/security/cve/CVE-2026-0672.html * https://www.suse.com/security/cve/CVE-2026-0865.html * https://bugzilla.suse.com/show_bug.cgi?id=1257029 * https://bugzilla.suse.com/show_bug.cgi?id=1257031 * https://bugzilla.suse.com/show_bug.cgi?id=1257041 * https://bugzilla.suse.com/show_bug.cgi?id=1257042 * https://bugzilla.suse.com/show_bug.cgi?id=1257044 * https://bugzilla.suse.com/show_bug.cgi?id=1257046 . Critical Python39 security patch for openSUSE fixes six important vulnerabilities related to header injection.. openSUSE Python39 injection security patch vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 26, 2026 Important OpenSUSE
89

Fedora 43: cpp-httplib Critical DOS and HTTP Header Issues 2026-e50e41fcea

Update to 0.30.1 Denial of service (DOS) using zip bomb (CVE-2026-22776) CRLF injection in http headers (CVE-2026-21428) Untrusted HTTP Header Handling: X-Forwarded-For/X-Real-IP Trust (CVE-2025-66577) https://github.com/yhirose/cpp-httplib/releases/tag/v0.30.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-e50e41fcea 2026-01-22 01:06:41.044206+00:00 -------------------------------------------------------------------------------- Name : cpp-httplib Product : Fedora 43 Version : 0.30.1 Release : 5.fc43 URL : https://github.com/yhirose/cpp-httplib Summary : A C++11 single-file header-only cross platform HTTP/HTTPS library Description : A C++11 single-file header-only cross platform HTTP/HTTPS library. It's extremely easy to setup. Just include the httplib.h file in your code! -------------------------------------------------------------------------------- Update Information: Update to 0.30.1 Denial of service (DOS) using zip bomb (CVE-2026-22776) CRLF injection in http headers (CVE-2026-21428) Untrusted HTTP Header Handling: X-Forwarded-For/X-Real-IP Trust (CVE-2025-66577) https://github.com/yhirose/cpp-httplib/releases/tag/v0.30.1 -------------------------------------------------------------------------------- ChangeLog: * Tue Jan 13 2026 Petr Men\u0161k - 0.30.1-5 - Switch to GCC 15 test fix with active PR * Tue Jan 13 2026 Petr Men\u0161k - 0.30.1-4 - Drop 32 bit support like upstream did * Mon Jan 12 2026 Petr Men\u0161k - 0.30.1-3 - fixup! Fix tests in last release * Mon Jan 12 2026 Petr Men\u0161k - 0.30.1-2 - Fix tests in last release * Mon Jan 12 2026 Petr Men\u0161k - 0.30.1-1 - Update to 0.30.1 (rhbz#2406686) * Sat Aug 30 2025 Orion Poplawski - 0.26.0-1 - Update to 0.26.0 (CVE-2025-53629) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2338561 - cpp-httplib-0.26.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2338561 [ 2 ] Bug #2419549 - CVE-2025-66570 cpp-httplib: cpp-httplib Untrusted HTTP Header Handling [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2419549 [ 3 ] Bug #2419632 - CVE-2025-66577 cpp-httplib: cpp-httplib Untrusted HTTP Header Handling: X-Forwarded-For/X-Real-IP Trust [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2419632 [ 4 ] Bug #2426700 - CVE-2026-21428 cpp-httplib: cpp-httplib: Server-Side Request Forgery via header injection [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2426700 [ 5 ] Bug #2428894 - CVE-2026-22776 cpp-httplib: cpp-httplib: Denial of Service due to excessive memory usage from compressed HTTP request bodies [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2428894 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e50e41fcea' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical update for cpp-httplib on Fedora 43 addressing multiple security issues such as denial of service and header injections.. cpp-httplib update,Fedora 43 security,denial of service,HTTP headers,C++ library fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 22, 2026 Critical Fedora
100

SUSE: cpp-httplib Urgent IP Spoofing and Log Corruption Patch 2026:20090-2

An update that solves two vulnerabilities can now be installed.. # Security update for cpp-httplib Announcement ID: SUSE-SU-2026:20090-1 Release Date: 2026-01-15T22:11:25Z Rating: critical References: * bsc#1254734 * bsc#1254735 Cross-References: * CVE-2025-66570 * CVE-2025-66577 CVSS scores: * CVE-2025-66570 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-66570 ( SUSE ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2025-66570 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-66570 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2025-66577 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-66577 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-66577 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for cpp-httplib fixes the following issues: * CVE-2025-66570: IP spoofing, log poisoning, and authorization bypass via header shadowing due to acceptance and parsing of client-controlled injected HTTP headers in incoming requests (bsc#1254734). * CVE-2025-66577: access and error log poisoning with spoofed client IPs due to unconditional acceptance of client-controlled `X-Forwarded-For` and `X-Real-IP` headers (bsc#1254735). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-150=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-150=1 ## Package List: * SUSE Linux Enterprise Server 16.0(aarch64 ppc64le s390x x86_64) * cpp-httplib-debugsource-0.22.0-160000.3.1 * libcpp-httplib0_22-0.22.0-160000.3.1 * libcpp-httplib0_22-debuginfo-0.22.0-160000.3.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * cpp-httplib-debugsource-0.22.0-160000.3.1 * libcpp-httplib0_22-0.22.0-160000.3.1 * libcpp-httplib0_22-debuginfo-0.22.0-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-66570.html * https://www.suse.com/security/cve/CVE-2025-66577.html * https://bugzilla.suse.com/show_bug.cgi?id=1254734 * https://bugzilla.suse.com/show_bug.cgi?id=1254735 . Critical security update available for cpp-httplib addressing IP spoofing and log poisoning issues in SUSE.. cpp-httplib update,SUSE critical vulnerabilities,security patch,IP spoofing fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 20, 2026 Critical SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here