Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Important: python-urllib3 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:28158", "synopsis": "Important: python-urllib3 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for python-urllib3.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.\n\nSecurity Fix(es):\n\n* urllib3: urllib3: Denial of Service due to excessive HTTP response decompression (CVE-2026-44432)\n\n* urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers (CVE-2026-44431)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2477154", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2477154", "description": ""}, {"ticket": "2477167", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2477167", "description": ""}], "cves": [{"name": "CVE-2026-44431", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44431", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "5.9", "cwe": "CWE-201"}, {"name": "CVE-2026-44432", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44432", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-409"}], "references": [], "publishedAt":"2026-06-24T12:03:32.106524Z", "rpms": {"Rocky Linux 9": {"nvras": ["python3-urllib3-0:1.26.5-8.el9_8.noarch.rpm", "python-urllib3-0:1.26.5-8.el9_8.src.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Explore the python-urllib3 security update for Rocky Linux 9, addressing important vulnerabilities like DoS and info disclosure.. Rocky Linux advisory, python-urllib3 update, security patch important, DoS info disclosure. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-11510 http://linux.oracle.com/errata/ELSA-2026-11510.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: vim-X11-8.2.2637-23.0.1.el9_7.3.x86_64.rpm vim-common-8.2.2637-23.0.1.el9_7.3.x86_64.rpm vim-enhanced-8.2.2637-23.0.1.el9_7.3.x86_64.rpm vim-filesystem-8.2.2637-23.0.1.el9_7.3.noarch.rpm vim-minimal-8.2.2637-23.0.1.el9_7.3.x86_64.rpm aarch64: vim-X11-8.2.2637-23.0.1.el9_7.3.aarch64.rpm vim-common-8.2.2637-23.0.1.el9_7.3.aarch64.rpm vim-enhanced-8.2.2637-23.0.1.el9_7.3.aarch64.rpm vim-filesystem-8.2.2637-23.0.1.el9_7.3.noarch.rpm vim-minimal-8.2.2637-23.0.1.el9_7.3.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/vim-8.2.2637-23.0.1.el9_7.3.src.rpm Related CVEs: CVE-2026-34982 Description of changes: [8.2.2637-23.0.1.el9_7.3] - Remove upstream references [Orabug: 31197557] [2:8.2.2637-23.3] - Resolves: RHEL-164965 vim: arbitrary command execution via modeline sandbox bypass [2:8.2.2637-23.2] - RHEL-155437 CVE-2026-28417 vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin - RHEL-155422 CVE-2026-28421 vim: Vim: Denial of service and information disclosure via crafted swap file - RHEL-159629 CVE-2026-33412 vim: Vim: Arbitrary code execution via command injection in glob() function [2:8.2.2637-23.1] - RHEL-147940 CVE-2026-25749 vim: Heap Overflow in Vim _______________________________________________ El-errata mailing list
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 1:140.9.0esr-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6179-1
A security issue was discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure. Google is aware that an exploit for CVE-2024-4761 exists in the wild. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5689-1
Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5577-1
Openstack manilla owning a Ceph File system "share", enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. (CVE-2022-0670) . MGASA-2023-0139 - Updated ceph packages fix security vulnerability Publication date: 15 Apr 2023 URL: https://advisories.mageia.org/MGASA-2023-0139.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-0670, CVE-2022-3650 Openstack manilla owning a Ceph File system "share", enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. (CVE-2022-0670) Privilege escalation and privileged information disclosure (CVE-2022-3650) References: - https://bugs.mageia.org/show_bug.cgi?id=30677 - https://docs.ceph.com/en/latest/security/CVE-2022-0670/ - - https://www.cve.org/CVERecord?id=CVE-2022-0670 - https://www.cve.org/CVERecord?id=CVE-2022-3650 SRPMS: - 8/core/ceph-15.2.17-1.mga8 . Latest ceph software updates for Mageia address security vulnerabilities impacting confidentiality and integrity as of April 15, 2023.. Mageia, Ceph, Privilege Escalation, Security Advisory, Info Disclosure. . LinuxSecurity.com Team
Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5317-1
An update for libuv is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: libuv security update Advisory ID: RHSA-2021:3075-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:3075 Issue date: 2021-08-10 CVE Names: CVE-2021-22918 ==================================================================== 1. Summary: An update for libuv is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 8) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: libuv is a multi-platform support library with a focus on asynchronous I/O. Security Fix(es): * libuv: out-of-bounds read in uv__idna_toascii() can lead to information disclosures or crashes (CVE-2021-22918) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1979338 - CVE-2021-22918 libuv: out-of-bounds read in uv__idna_toascii() can lead to informationdisclosures or crashes 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: libuv-1.41.1-1.el8_4.src.rpm aarch64: libuv-1.41.1-1.el8_4.aarch64.rpm libuv-debuginfo-1.41.1-1.el8_4.aarch64.rpm libuv-debugsource-1.41.1-1.el8_4.aarch64.rpm ppc64le: libuv-1.41.1-1.el8_4.ppc64le.rpm libuv-debuginfo-1.41.1-1.el8_4.ppc64le.rpm libuv-debugsource-1.41.1-1.el8_4.ppc64le.rpm s390x: libuv-1.41.1-1.el8_4.s390x.rpm libuv-debuginfo-1.41.1-1.el8_4.s390x.rpm libuv-debugsource-1.41.1-1.el8_4.s390x.rpm x86_64: libuv-1.41.1-1.el8_4.i686.rpm libuv-1.41.1-1.el8_4.x86_64.rpm libuv-debuginfo-1.41.1-1.el8_4.i686.rpm libuv-debuginfo-1.41.1-1.el8_4.x86_64.rpm libuv-debugsource-1.41.1-1.el8_4.i686.rpm libuv-debugsource-1.41.1-1.el8_4.x86_64.rpm Red Hat CodeReady Linux Builder (v. 8): aarch64: libuv-debuginfo-1.41.1-1.el8_4.aarch64.rpm libuv-debugsource-1.41.1-1.el8_4.aarch64.rpm libuv-devel-1.41.1-1.el8_4.aarch64.rpm ppc64le: libuv-debuginfo-1.41.1-1.el8_4.ppc64le.rpm libuv-debugsource-1.41.1-1.el8_4.ppc64le.rpm libuv-devel-1.41.1-1.el8_4.ppc64le.rpm s390x: libuv-debuginfo-1.41.1-1.el8_4.s390x.rpm libuv-debugsource-1.41.1-1.el8_4.s390x.rpm libuv-devel-1.41.1-1.el8_4.s390x.rpm x86_64: libuv-debuginfo-1.41.1-1.el8_4.i686.rpm libuv-debuginfo-1.41.1-1.el8_4.x86_64.rpm libuv-debugsource-1.41.1-1.el8_4.i686.rpm libuv-debugsource-1.41.1-1.el8_4.x86_64.rpm libuv-devel-1.41.1-1.el8_4.i686.rpm libuv-devel-1.41.1-1.el8_4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-22918 https://access.redhat.com/security/updates/classification/#low 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYRKHF9zjgjWX9erEAQgFSg/9G7tl+zmuvPat250k5lMMjMAjXEORullZ 2BLXDewnevV/kWxe4+GkRdG97GYtC8qpWoGnfq0zZoZKgP1Jd5KdYl6kZWDZ5I0W h2IDewyI84nKVF/rOHXFIssCdIDDRsyNH22x9C29AxkVeAtkGILKzFg/syjjhPNl 5joJquPNwOp3a/7zD1BEjROMAoZERm7EEjEeVbpY+bX7FiVlZws9gCnfmL6eLKoR cfjQB+JSesJN1XK0QX5iisVrM3LXu3NSPKH1tzgZwjuw7GwSukuqW5hEWfaey/0v JBsv8zUJ7zPaJIFCZGM8ic90GWVDzF7hDH4qMcygSHTRGb7QqoZoq8juzDeVPUfA iT0CJr5Qejhsioykoydhn/2RTG9RHaIkHsQNO371ltsa7wRVIKNhffa5JbbhHiXn 87OF8JbEM89ei23lls8NHVeg+5WxZH7iO8Ef1Vu5QcG9vL0pq5F5Krjz7wcaTZG0 o1TayLV2mMaAJwE8uBBtr3meh1uoGk0crQYThr9OHvlL3Gfd0MQyRP0NNkhP0DS4 p6r3ogDxGDqiDRgWBRheNDLrCfwd/69KqvqidV5AH7CVo+YcI5J2WkFu4fQZbTiy grKhy9zeiyukKIpPL5ohmle1EYSEKcgBw+fxJI0XTF6CzmCtmJGRS+e5xulJly5+ qvzHYz1a8Sw=yxIS -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.