Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves two vulnerabilities and has one fix can now be installed.. # Security update for tar Announcement ID: SUSE-SU-2026:22377-1 Release Date: 2026-06-26T09:13:30Z Rating: important References: * bsc#1261900 * bsc#1265450 * bsc#1267189 Cross-References: * CVE-2025-45582 * CVE-2026-5704 CVSS scores: * CVE-2025-45582 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-45582 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-45582 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L * CVE-2026-5704 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-5704 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-5704 ( NVD ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N * CVE-2026-5704 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities and has one fix can now be installed. ## Description: This update for tar fixes the following issues * CVE-2026-5704: crafted archives can be used to to hide file injection (bsc#1261900). * Fix --dereference/-h not working properly after CVE-2025-45582 fix (bsc#1265450). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1092=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1092=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * tar-debugsource-1.35-160000.4.1 * tar-rmt-debuginfo-1.35-160000.4.1 * tar-debuginfo-1.35-160000.4.1 * tar-1.35-160000.4.1 *tar-rmt-1.35-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * tar-backup-scripts-1.35-160000.4.1 * tar-lang-1.35-160000.4.1 * tar-doc-1.35-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * tar-backup-scripts-1.35-160000.4.1 * tar-lang-1.35-160000.4.1 * tar-doc-1.35-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * tar-debugsource-1.35-160000.4.1 * tar-rmt-debuginfo-1.35-160000.4.1 * tar-debuginfo-1.35-160000.4.1 * tar-1.35-160000.4.1 * tar-rmt-1.35-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2025-45582.html * https://www.suse.com/security/cve/CVE-2026-5704.html * https://bugzilla.suse.com/show_bug.cgi?id=1261900 * https://bugzilla.suse.com/show_bug.cgi?id=1265450 * https://bugzilla.suse.com/show_bug.cgi?id=1267189 . SUSE updates the tar package fixing critical injection issues and improving security on Enterprise Server 16.0.. SUSE Linux update, tar security patch, important vulnerabilities, SUSE advisory, Linux application security. . Severity: Important. LinuxSecurity.com Team
Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result privilege escalation, information disclosure, SQL injections, LDAP authentication bypass, cross-site scripting or spreadsheet (CSV/formula) injection. For the oldstable distribution (bookworm), these problems have been fixed. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6324-1
An update that solves 8 vulnerabilities and has 8 bug fixes can now be installed.. openSUSE security update: security update for roundcubemail ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20852-1 Rating: important References: * bsc#1266329 * bsc#1266331 * bsc#1266332 * bsc#1266333 * bsc#1266334 * bsc#1266335 * bsc#1266336 * bsc#1266337 Cross-References: * CVE-2026-48842 * CVE-2026-48843 * CVE-2026-48844 * CVE-2026-48845 * CVE-2026-48846 * CVE-2026-48847 * CVE-2026-48848 * CVE-2026-48849 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 8 vulnerabilities and has 8 bug fixes can now be installed. Description: This update for roundcubemail fixes the following issues: Changes in roundcubemail: - update to 1.6.16 + Fix potential too long value in IMAP ID command (#10136) + Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog [CVE-2026-48849] [bsc#1266337] + Security: Fix CSS injection bypass in HTML sanitizer via SVG 'animate attributeName="style"' [CVE-2026-48848] [bsc#1266336] + Security: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass [CVE-2026-48842] [bsc#1266329] + Security: Fix SSRF bypass via specific local address URLs [CVE-2026-48843] [bsc#1266331] + Security: Fix bypass of remote image blocking via CSS var() [CVE-2026-48846] [bsc#1266334] + Security: Fix local/private URL fetch bypass when remote resources were not allowed [CVE-2026-48845] [bsc#1266333] + Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass [CVE-2026-48847] [bsc#1266335] + Security: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option [CVE-2026-48844] [bsc#1266332] Patch instructions: To install this openSUSE security update use the suse recommended installation methods likeYaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-282=1 Package List: - openSUSE Leap 16.0: roundcubemail-1.6.16-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2026-48842.html * https://www.suse.com/security/cve/CVE-2026-48843.html * https://www.suse.com/security/cve/CVE-2026-48844.html * https://www.suse.com/security/cve/CVE-2026-48845.html * https://www.suse.com/security/cve/CVE-2026-48846.html * https://www.suse.com/security/cve/CVE-2026-48847.html * https://www.suse.com/security/cve/CVE-2026-48848.html * https://www.suse.com/security/cve/CVE-2026-48849.html . Update released for roundcubemail on openSUSE addresses multiple security issues and fixes bugs efficiently.. Roundcube Email OpenSUSE Security Fix Injection Updates. . Severity: Important. LinuxSecurity.com Team
Brief introduction CVE-2025-67733 A flaw in the Lua scripting error path allowed an authenticated user to embed CR/LF byte sequences in an error reply produced via redis.error_reply() or the Lua error() function. Because RESP uses. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6279-1
Vincent Lefèvre discovered that, in the Perl programming language, at thread creation the current directory may temporarily change in other threads, altering file accesses. Under some conditions, a local attacker may leverage this to access unauthorized data or even inject arbitrary code.. Debian LTS Advisory DLA-4538-1
Security fix for CVE-2026-4519.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b79ae5877b 2026-03-29 00:15:07.927190+00:00 -------------------------------------------------------------------------------- Name : python3.6 Product : Fedora 44 Version : 3.6.15 Release : 55.fc44 URL : https://www.python.org/ Summary : Version 3.6 of the Python interpreter Description : Python is an accessible, high-level, dynamically typed, interpreted programming language, designed with an emphasis on code readability. It includes an extensive standard library, and has a vast ecosystem of third-party libraries. The python3.6 package provides the "python3" executable: the reference interpreter for the Python language, version 3. The majority of its standard library is provided in the python3.6-libs package, which should be installed automatically along with python3.6. The remaining parts of the Python standard library are broken out into the python3.6-tkinter and python3.6-test packages, which may need to be installed separately. Documentation for Python is provided in the python3.6-docs package. Packages containing additional libraries for Python are generally named with the "python3.6-" prefix. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2026-4519. -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 26 2026 Lumr Balhar - 3.6.15-55 - Security fix for CVE-2026-4519 (rhbz#2449733) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2449733 - CVE-2026-4519 python3.6: Python: Command-line option injection in webbrowser.open() via crafted URLs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449733 -------------------------------------------------------------------------------- This update can be installed with the "dnf"update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b79ae5877b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical security advisory for Fedora 44 addressing CVE-2026-4519 in Python 3.6 to prevent command-line injection issues.. Fedora 44, Python 3.6, security fix, command injection. . Severity: Critical. LinuxSecurity.com Team
An update that solves seven vulnerabilities can now be installed.. # Security update for python311 Announcement ID: SUSE-SU-2026:0693-1 Release Date: 2026-02-27T15:14:10Z Rating: important References: * bsc#1257029 * bsc#1257031 * bsc#1257041 * bsc#1257042 * bsc#1257044 * bsc#1257046 * bsc#1257108 Cross-References: * CVE-2025-11468 * CVE-2025-12781 * CVE-2025-15282 * CVE-2025-15366 * CVE-2025-15367 * CVE-2026-0672 * CVE-2026-0865 CVSS scores: * CVE-2025-11468 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-11468 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-11468 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12781 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-12781 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-12781 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12781 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-15282 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15282 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2025-15282 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15366 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15366 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H * CVE-2025-15366 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15367 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15367 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H * CVE-2025-15367 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0672 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0672 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0672 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0865 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-0865 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-0865 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSELinux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves seven vulnerabilities can now be installed. ## Description: This update for python311 fixes the following issues: * CVE-2025-11468: header injection when folding a long comment in an email header containing exclusively unfoldable characters (bsc#1257029). * CVE-2025-12781: inadequate parameter check can cause data integrity issues (bsc#1257108). * CVE-2025-15282: user-controlled data URLs parsed may allow injecting headers (bsc#1257046). * CVE-2025-15366: user-controlled command can allow additional commands injected using newlines (bsc#1257044). * CVE-2025-15367: control characters may allow the injection of additional commands (bsc#1257041). * CVE-2026-0672: HTTP header injection via user-controlled cookie values and parameters when using http.cookies.Morsel (bsc#1257031). * CVE-2026-0865: user-controlled header containing newlines can allow injecting HTTP headers (bsc#1257042). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-693=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-693=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-693=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-693=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-693=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-693=1 * SUSELinux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-693=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-693=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-693=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-693=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * python311-testsuite-debuginfo-3.11.14-150400.9.75.1 * python311-devel-3.11.14-150400.9.75.1 * python311-doc-devhelp-3.11.14-150400.9.75.1 * python311-base-3.11.14-150400.9.75.1 * libpython3_11-1_0-debuginfo-3.11.14-150400.9.75.1 * python311-testsuite-3.11.14-150400.9.75.1 * python311-tools-3.11.14-150400.9.75.1 * python311-curses-3.11.14-150400.9.75.1 * python311-dbm-3.11.14-150400.9.75.1 * python311-dbm-debuginfo-3.11.14-150400.9.75.1 * libpython3_11-1_0-3.11.14-150400.9.75.1 * python311-debugsource-3.11.14-150400.9.75.1 * python311-idle-3.11.14-150400.9.75.1 * python311-core-debugsource-3.11.14-150400.9.75.1 * python311-doc-3.11.14-150400.9.75.1 * python311-3.11.14-150400.9.75.1 * python311-curses-debuginfo-3.11.14-150400.9.75.1 * python311-tk-debuginfo-3.11.14-150400.9.75.1 * python311-debuginfo-3.11.14-150400.9.75.1 * python311-base-debuginfo-3.11.14-150400.9.75.1 * python311-tk-3.11.14-150400.9.75.1 * openSUSE Leap 15.4 (x86_64) * python311-32bit-debuginfo-3.11.14-150400.9.75.1 * libpython3_11-1_0-32bit-3.11.14-150400.9.75.1 * libpython3_11-1_0-32bit-debuginfo-3.11.14-150400.9.75.1 * python311-32bit-3.11.14-150400.9.75.1 * python311-base-32bit-3.11.14-150400.9.75.1 * python311-base-32bit-debuginfo-3.11.14-150400.9.75.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libpython3_11-1_0-64bit-3.11.14-150400.9.75.1 *python311-64bit-debuginfo-3.11.14-150400.9.75.1 * python311-base-64bit-debuginfo-3.11.14-150400.9.75.1 * libpython3_11-1_0-64bit-debuginfo-3.11.14-150400.9.75.1 * python311-base-64bit-3.11.14-150400.9.75.1 * python311-64bit-3.11.14-150400.9.75.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * libpython3_11-1_0-3.11.14-150400.9.75.1 * python311-3.11.14-150400.9.75.1 * python311-base-3.11.14-150400.9.75.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libpython3_11-1_0-3.11.14-150400.9.75.1 * python311-core-debugsource-3.11.14-150400.9.75.1 * python311-base-3.11.14-150400.9.75.1 * python311-doc-3.11.14-150400.9.75.1 * python311-debugsource-3.11.14-150400.9.75.1 * python311-tools-3.11.14-150400.9.75.1 * python311-3.11.14-150400.9.75.1 * python311-curses-3.11.14-150400.9.75.1 * python311-curses-debuginfo-3.11.14-150400.9.75.1 * python311-debuginfo-3.11.14-150400.9.75.1 * python311-dbm-3.11.14-150400.9.75.1 * python311-devel-3.11.14-150400.9.75.1 * python311-doc-devhelp-3.11.14-150400.9.75.1 * python311-tk-debuginfo-3.11.14-150400.9.75.1 * python311-base-debuginfo-3.11.14-150400.9.75.1 * libpython3_11-1_0-debuginfo-3.11.14-150400.9.75.1 * python311-tk-3.11.14-150400.9.75.1 * python311-idle-3.11.14-150400.9.75.1 * python311-dbm-debuginfo-3.11.14-150400.9.75.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libpython3_11-1_0-3.11.14-150400.9.75.1 * python311-core-debugsource-3.11.14-150400.9.75.1 * python311-base-3.11.14-150400.9.75.1 * python311-doc-3.11.14-150400.9.75.1 * python311-debugsource-3.11.14-150400.9.75.1 * python311-tools-3.11.14-150400.9.75.1 * python311-3.11.14-150400.9.75.1 * python311-curses-3.11.14-150400.9.75.1 * python311-curses-debuginfo-3.11.14-150400.9.75.1 * python311-debuginfo-3.11.14-150400.9.75.1 * python311-dbm-3.11.14-150400.9.75.1 *python311-devel-3.11.14-150400.9.75.1 * python311-doc-devhelp-3.11.14-150400.9.75.1 * python311-tk-debuginfo-3.11.14-150400.9.75.1 * python311-base-debuginfo-3.11.14-150400.9.75.1 * libpython3_11-1_0-debuginfo-3.11.14-150400.9.75.1 * python311-tk-3.11.14-150400.9.75.1 * python311-idle-3.11.14-150400.9.75.1 * python311-dbm-debuginfo-3.11.14-150400.9.75.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libpython3_11-1_0-3.11.14-150400.9.75.1 * python311-core-debugsource-3.11.14-150400.9.75.1 * python311-base-3.11.14-150400.9.75.1 * python311-doc-3.11.14-150400.9.75.1 * python311-debugsource-3.11.14-150400.9.75.1 * python311-tools-3.11.14-150400.9.75.1 * python311-3.11.14-150400.9.75.1 * python311-curses-3.11.14-150400.9.75.1 * python311-curses-debuginfo-3.11.14-150400.9.75.1 * python311-debuginfo-3.11.14-150400.9.75.1 * python311-dbm-3.11.14-150400.9.75.1 * python311-devel-3.11.14-150400.9.75.1 * python311-doc-devhelp-3.11.14-150400.9.75.1 * python311-tk-debuginfo-3.11.14-150400.9.75.1 * python311-base-debuginfo-3.11.14-150400.9.75.1 * libpython3_11-1_0-debuginfo-3.11.14-150400.9.75.1 * python311-tk-3.11.14-150400.9.75.1 * python311-idle-3.11.14-150400.9.75.1 * python311-dbm-debuginfo-3.11.14-150400.9.75.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libpython3_11-1_0-3.11.14-150400.9.75.1 * python311-core-debugsource-3.11.14-150400.9.75.1 * python311-base-3.11.14-150400.9.75.1 * python311-doc-3.11.14-150400.9.75.1 * python311-debugsource-3.11.14-150400.9.75.1 * python311-tools-3.11.14-150400.9.75.1 * python311-3.11.14-150400.9.75.1 * python311-curses-3.11.14-150400.9.75.1 * python311-curses-debuginfo-3.11.14-150400.9.75.1 * python311-debuginfo-3.11.14-150400.9.75.1 * python311-dbm-3.11.14-150400.9.75.1 * python311-devel-3.11.14-150400.9.75.1 *python311-doc-devhelp-3.11.14-150400.9.75.1 * python311-tk-debuginfo-3.11.14-150400.9.75.1 * python311-base-debuginfo-3.11.14-150400.9.75.1 * libpython3_11-1_0-debuginfo-3.11.14-150400.9.75.1 * python311-tk-3.11.14-150400.9.75.1 * python311-idle-3.11.14-150400.9.75.1 * python311-dbm-debuginfo-3.11.14-150400.9.75.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libpython3_11-1_0-3.11.14-150400.9.75.1 * python311-core-debugsource-3.11.14-150400.9.75.1 * python311-base-3.11.14-150400.9.75.1 * python311-doc-3.11.14-150400.9.75.1 * python311-debugsource-3.11.14-150400.9.75.1 * python311-tools-3.11.14-150400.9.75.1 * python311-3.11.14-150400.9.75.1 * python311-curses-3.11.14-150400.9.75.1 * python311-curses-debuginfo-3.11.14-150400.9.75.1 * python311-debuginfo-3.11.14-150400.9.75.1 * python311-dbm-3.11.14-150400.9.75.1 * python311-devel-3.11.14-150400.9.75.1 * python311-doc-devhelp-3.11.14-150400.9.75.1 * python311-tk-debuginfo-3.11.14-150400.9.75.1 * python311-base-debuginfo-3.11.14-150400.9.75.1 * libpython3_11-1_0-debuginfo-3.11.14-150400.9.75.1 * python311-tk-3.11.14-150400.9.75.1 * python311-idle-3.11.14-150400.9.75.1 * python311-dbm-debuginfo-3.11.14-150400.9.75.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libpython3_11-1_0-3.11.14-150400.9.75.1 * python311-core-debugsource-3.11.14-150400.9.75.1 * python311-base-3.11.14-150400.9.75.1 * python311-doc-3.11.14-150400.9.75.1 * python311-debugsource-3.11.14-150400.9.75.1 * python311-tools-3.11.14-150400.9.75.1 * python311-3.11.14-150400.9.75.1 * python311-curses-3.11.14-150400.9.75.1 * python311-curses-debuginfo-3.11.14-150400.9.75.1 * python311-debuginfo-3.11.14-150400.9.75.1 * python311-dbm-3.11.14-150400.9.75.1 * python311-devel-3.11.14-150400.9.75.1 * python311-doc-devhelp-3.11.14-150400.9.75.1 * python311-tk-debuginfo-3.11.14-150400.9.75.1 * python311-base-debuginfo-3.11.14-150400.9.75.1 * libpython3_11-1_0-debuginfo-3.11.14-150400.9.75.1 * python311-tk-3.11.14-150400.9.75.1 * python311-idle-3.11.14-150400.9.75.1 * python311-dbm-debuginfo-3.11.14-150400.9.75.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libpython3_11-1_0-3.11.14-150400.9.75.1 * python311-core-debugsource-3.11.14-150400.9.75.1 * python311-base-3.11.14-150400.9.75.1 * python311-doc-3.11.14-150400.9.75.1 * python311-debugsource-3.11.14-150400.9.75.1 * python311-tools-3.11.14-150400.9.75.1 * python311-3.11.14-150400.9.75.1 * python311-curses-3.11.14-150400.9.75.1 * python311-curses-debuginfo-3.11.14-150400.9.75.1 * python311-debuginfo-3.11.14-150400.9.75.1 * python311-dbm-3.11.14-150400.9.75.1 * python311-devel-3.11.14-150400.9.75.1 * python311-doc-devhelp-3.11.14-150400.9.75.1 * python311-tk-debuginfo-3.11.14-150400.9.75.1 * python311-base-debuginfo-3.11.14-150400.9.75.1 * libpython3_11-1_0-debuginfo-3.11.14-150400.9.75.1 * python311-tk-3.11.14-150400.9.75.1 * python311-idle-3.11.14-150400.9.75.1 * python311-dbm-debuginfo-3.11.14-150400.9.75.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libpython3_11-1_0-3.11.14-150400.9.75.1 * python311-core-debugsource-3.11.14-150400.9.75.1 * python311-base-3.11.14-150400.9.75.1 * python311-doc-3.11.14-150400.9.75.1 * python311-debugsource-3.11.14-150400.9.75.1 * python311-tools-3.11.14-150400.9.75.1 * python311-3.11.14-150400.9.75.1 * python311-curses-3.11.14-150400.9.75.1 * python311-curses-debuginfo-3.11.14-150400.9.75.1 * python311-debuginfo-3.11.14-150400.9.75.1 * python311-dbm-3.11.14-150400.9.75.1 * python311-devel-3.11.14-150400.9.75.1 * python311-doc-devhelp-3.11.14-150400.9.75.1 * python311-tk-debuginfo-3.11.14-150400.9.75.1 * python311-base-debuginfo-3.11.14-150400.9.75.1 *libpython3_11-1_0-debuginfo-3.11.14-150400.9.75.1 * python311-tk-3.11.14-150400.9.75.1 * python311-idle-3.11.14-150400.9.75.1 * python311-dbm-debuginfo-3.11.14-150400.9.75.1 ## References: * https://www.suse.com/security/cve/CVE-2025-11468.html * https://www.suse.com/security/cve/CVE-2025-12781.html * https://www.suse.com/security/cve/CVE-2025-15282.html * https://www.suse.com/security/cve/CVE-2025-15366.html * https://www.suse.com/security/cve/CVE-2025-15367.html * https://www.suse.com/security/cve/CVE-2026-0672.html * https://www.suse.com/security/cve/CVE-2026-0865.html * https://bugzilla.suse.com/show_bug.cgi?id=1257029 * https://bugzilla.suse.com/show_bug.cgi?id=1257031 * https://bugzilla.suse.com/show_bug.cgi?id=1257041 * https://bugzilla.suse.com/show_bug.cgi?id=1257042 * https://bugzilla.suse.com/show_bug.cgi?id=1257044 * https://bugzilla.suse.com/show_bug.cgi?id=1257046 * https://bugzilla.suse.com/show_bug.cgi?id=1257108 . An important update for python311 resolves seven vulnerabilities and enhances system security on SUSE Linux.. python patch security python311 injection issues SUSE vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for avahi Announcement ID: SUSE-SU-2026:20491-1 Release Date: 2026-02-17T09:42:11Z Rating: moderate References: * bsc#1233421 Cross-References: * CVE-2024-52615 CVSS scores: * CVE-2024-52615 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-52615 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-52615 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for avahi fixes the following issues: * CVE-2024-52615: Fixed possible DNS response injection via the use of fixed source ports for wide-area DNS queries (bsc#1233421). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-397=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libavahi-common3-debuginfo-0.8-slfo.1.1_4.1 * libavahi-core7-0.8-slfo.1.1_4.1 * libavahi-client3-debuginfo-0.8-slfo.1.1_4.1 * libavahi-core7-debuginfo-0.8-slfo.1.1_4.1 * avahi-debugsource-0.8-slfo.1.1_4.1 * avahi-debuginfo-0.8-slfo.1.1_4.1 * libavahi-client3-0.8-slfo.1.1_4.1 * libavahi-common3-0.8-slfo.1.1_4.1 * avahi-0.8-slfo.1.1_4.1 ## References: * https://www.suse.com/security/cve/CVE-2024-52615.html * https://bugzilla.suse.com/show_bug.cgi?id=1233421 . An update for SUSE avahi addresses a moderate security risk involving DNS response injection. Learn more and patch now.. SUSE Linux Micro,avahi software,DNS security update,security patch,moderate vulnerability. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.