Explore top 10 tips to secure your open-source projects now. Read More
×
Added sanitization of inputs of the metadata fields.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-4a8ed954a6 2026-05-01 03:11:02.715677+00:00 -------------------------------------------------------------------------------- Name : pyp2spec Product : Fedora 44 Version : 0.14.1 Release : 1.fc44 URL : https://github.com/befeleme/pyp2spec Summary : Generate Fedora RPM spec files for Python projects Description : pyp2spec is a tech preview. It is a tool generating Fedora RPM spec files for Python distributions. It utilizes the benefits of pyproject-rpm-macros. -------------------------------------------------------------------------------- Update Information: Added sanitization of inputs of the metadata fields. -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 21 2026 Packit - 0.14.1-1 - Update to 0.14.1 upstream release - Resolves: rhbz#2460051 - Resolves: rhbz#2449892 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-4a8ed954a6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Added sanitization of inputs of the metadata fields.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-1f68c09a18 2026-05-01 03:01:50.286469+00:00 -------------------------------------------------------------------------------- Name : pyp2spec Product : Fedora 43 Version : 0.14.1 Release : 1.fc43 URL : https://github.com/befeleme/pyp2spec Summary : Generate Fedora RPM spec files for Python projects Description : pyp2spec is a tech preview. It is a tool generating Fedora RPM spec files for Python distributions. It utilizes the benefits of pyproject-rpm-macros. -------------------------------------------------------------------------------- Update Information: Added sanitization of inputs of the metadata fields. -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 21 2026 Packit - 0.14.1-1 - Update to 0.14.1 upstream release - Resolves: rhbz#2460051 - Resolves: rhbz#2449892 * Sat Jan 17 2026 Fedora Release Engineering - 0.13.0-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1f68c09a18' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves three vulnerabilities can now be installed.. # Security update for libsoup2 Announcement ID: SUSE-SU-2026:0811-1 Release Date: 2026-03-05T03:05:33Z Rating: important References: * bsc#1257398 * bsc#1257441 * bsc#1257597 Cross-References: * CVE-2026-1467 * CVE-2026-1539 * CVE-2026-1760 CVSS scores: * CVE-2026-1467 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N * CVE-2026-1467 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-1467 ( NVD ): 5.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N * CVE-2026-1539 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N * CVE-2026-1539 ( SUSE ): 5.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N * CVE-2026-1539 ( NVD ): 5.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N * CVE-2026-1760 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-1760 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L * CVE-2026-1760 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for libsoup2 fixes the following issues: * CVE-2026-1467: lack of input sanitization can lead to unintended or unauthorized HTTP requests (bsc#1257398). * CVE-2026-1539: proxy authentication credentials leaked via the Proxy- Authorization header when handling HTTP redirects (bsc#1257441). * CVE-2026-1760: improper handling of HTTP requests combining certain headers by SoupServer can lead toHTTP request smuggling and potential DoS (bsc#1257597). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-811=1 openSUSE-SLE-15.6-2026-811=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-811=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-811=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-811=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libsoup-2_4-1-debuginfo-2.74.3-150600.4.30.1 * typelib-1_0-Soup-2_4-2.74.3-150600.4.30.1 * libsoup2-debugsource-2.74.3-150600.4.30.1 * libsoup-2_4-1-2.74.3-150600.4.30.1 * libsoup2-devel-2.74.3-150600.4.30.1 * openSUSE Leap 15.6 (x86_64) * libsoup-2_4-1-32bit-2.74.3-150600.4.30.1 * libsoup2-devel-32bit-2.74.3-150600.4.30.1 * libsoup-2_4-1-32bit-debuginfo-2.74.3-150600.4.30.1 * openSUSE Leap 15.6 (noarch) * libsoup2-lang-2.74.3-150600.4.30.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libsoup-2_4-1-64bit-debuginfo-2.74.3-150600.4.30.1 * libsoup2-devel-64bit-2.74.3-150600.4.30.1 * libsoup-2_4-1-64bit-2.74.3-150600.4.30.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libsoup-2_4-1-debuginfo-2.74.3-150600.4.30.1 * typelib-1_0-Soup-2_4-2.74.3-150600.4.30.1 * libsoup2-debugsource-2.74.3-150600.4.30.1 * libsoup-2_4-1-2.74.3-150600.4.30.1 * libsoup2-devel-2.74.3-150600.4.30.1 * Basesystem Module 15-SP7 (noarch) * libsoup2-lang-2.74.3-150600.4.30.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libsoup-2_4-1-debuginfo-2.74.3-150600.4.30.1 * typelib-1_0-Soup-2_4-2.74.3-150600.4.30.1 *libsoup2-debugsource-2.74.3-150600.4.30.1 * libsoup-2_4-1-2.74.3-150600.4.30.1 * libsoup2-devel-2.74.3-150600.4.30.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * libsoup2-lang-2.74.3-150600.4.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libsoup-2_4-1-debuginfo-2.74.3-150600.4.30.1 * typelib-1_0-Soup-2_4-2.74.3-150600.4.30.1 * libsoup2-debugsource-2.74.3-150600.4.30.1 * libsoup-2_4-1-2.74.3-150600.4.30.1 * libsoup2-devel-2.74.3-150600.4.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * libsoup2-lang-2.74.3-150600.4.30.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1467.html * https://www.suse.com/security/cve/CVE-2026-1539.html * https://www.suse.com/security/cve/CVE-2026-1760.html * https://bugzilla.suse.com/show_bug.cgi?id=1257398 * https://bugzilla.suse.com/show_bug.cgi?id=1257441 * https://bugzilla.suse.com/show_bug.cgi?id=1257597 . Update for openSUSE fixes three critical issues in libsoup2 with important severity levels. Install recommended patches now.. openSUSE libsoup2 security update important DoS input sanitization. . Severity: Important. LinuxSecurity.com Team
An update that solves three vulnerabilities can now be installed.. # Security update for libsoup Announcement ID: SUSE-SU-2026:0792-1 Release Date: 2026-03-04T01:04:14Z Rating: important References: * bsc#1257398 * bsc#1257441 * bsc#1257597 Cross-References: * CVE-2026-1467 * CVE-2026-1539 * CVE-2026-1760 CVSS scores: * CVE-2026-1467 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N * CVE-2026-1467 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-1467 ( NVD ): 5.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N * CVE-2026-1539 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N * CVE-2026-1539 ( SUSE ): 5.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N * CVE-2026-1539 ( NVD ): 5.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N * CVE-2026-1760 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-1760 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L * CVE-2026-1760 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves three vulnerabilities can now be installed. ## Description: This update for libsoup fixes the following issues: * CVE-2026-1467: lack of input sanitization can lead to unintended or unauthorized HTTP requests (bsc#1257398). * CVE-2026-1539: proxy authentication credentials leaked via the Proxy- Authorization header when handling HTTP redirects (bsc#1257441). * CVE-2026-1760: improper handling of HTTP requests combining certain headers by SoupServer can lead to HTTP request smuggling and potential DoS (bsc#1257597). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-792=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-792=1 ## Package List: * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libsoup-2_4-1-2.68.4-150200.4.33.1 * libsoup-debugsource-2.68.4-150200.4.33.1 * libsoup-2_4-1-debuginfo-2.68.4-150200.4.33.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libsoup-2_4-1-2.68.4-150200.4.33.1 * libsoup-debugsource-2.68.4-150200.4.33.1 * libsoup-2_4-1-debuginfo-2.68.4-150200.4.33.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1467.html * https://www.suse.com/security/cve/CVE-2026-1539.html * https://www.suse.com/security/cve/CVE-2026-1760.html * https://bugzilla.suse.com/show_bug.cgi?id=1257398 * https://bugzilla.suse.com/show_bug.cgi?id=1257441 * https://bugzilla.suse.com/show_bug.cgi?id=1257597 . An important advisory for libsoup addressing three important vulnerabilities. Patch instructions included.. SUSE Linux, libsoup security, software vulnerabilities, patch management. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability, contains one feature is now available.. openSUSE Security Update: Security update for python-djangorestframework ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0038-1 Rating: moderate References: #1227077 PED-8919 Cross-References: CVE-2024-21520 CVSS scores: CVE-2024-21520 (SUSE): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability, contains one feature is now available. Description: This update for python-djangorestframework fixes the following issues: - CVE-2024-21520: Fixed improper input sanitization before splitting and joining with 'br' tags (boo#1227077) - Tests can be run only on (newer) python311 stack - Make it at least installable on python3 stack (no guarantees for it to run) - Use sle15allpythons to get the Python 3.6 packages (jsc#PED-8919) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-38=1 Package List: - openSUSE Backports SLE-15-SP7 (noarch): python3-djangorestframework-3.14.0-bp157.2.3.1 python311-djangorestframework-3.14.0-bp157.2.3.1 References: https://www.suse.com/security/cve/CVE-2024-21520.html https://bugzilla.suse.com/1227077 . Update for openSUSE addresses moderate security issue in python-djangorestframework. Patch and details provided.. openSUSE update, python-djangorestframework, security patch. . LinuxSecurity.com Team
* bsc#1248807 * bsc#1251271 Cross-References: * CVE-2025-27466 . # Security update for xen Announcement ID: SUSE-SU-2025:3843-1 Release Date: 2025-10-28T16:40:50Z Rating: important References: * bsc#1248807 * bsc#1251271 Cross-References: * CVE-2025-27466 * CVE-2025-58142 * CVE-2025-58143 * CVE-2025-58147 * CVE-2025-58148 CVSS scores: * CVE-2025-27466 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-27466 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-58142 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-58142 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-58143 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-58143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-58147 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H * CVE-2025-58148 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Proxy 4.3 LTS * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Retail Branch Server 4.3 LTS * SUSE Manager Server 4.3 * SUSE Manager Server 4.3 LTS An update that solves five vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2025-58147, CVE-2025-58148: Fixed incorrect input sanitisation in Viridian hypercalls (bsc#1251271, XSA-475) * CVE-2025-27466,CVE-2025-58142, CVE-2025-58143: Fixed mutiple vulnerabilities in the Viridian interface (bsc#1248807, XSA-472) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-3843=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3843=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3843=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3843=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3843=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-3843=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-3843=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-3843=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-3843=1 * SUSE Manager Proxy 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-LTS-2025-3843=1 * SUSE Manager Retail Branch Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-LTS-2025-3843=1 * SUSE Manager Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-LTS-2025-3843=1 ## Package List: * openSUSE Leap 15.4 (aarch64 x86_64 i586) * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * openSUSE Leap 15.4(x86_64) * xen-libs-32bit-4.16.7_04-150400.4.75.1 * xen-libs-32bit-debuginfo-4.16.7_04-150400.4.75.1 * openSUSE Leap 15.4 (aarch64 x86_64) * xen-doc-html-4.16.7_04-150400.4.75.1 * xen-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * openSUSE Leap 15.4 (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * openSUSE Leap 15.4 (aarch64_ilp32) * xen-libs-64bit-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-64bit-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Micro 5.4 (x86_64) * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Manager Proxy 4.3 LTS (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 *xen-tools-4.16.7_04-150400.4.75.1 * SUSE Manager Proxy 4.3 LTS (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Manager Retail Branch Server 4.3 LTS (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Manager Retail Branch Server 4.3 LTS (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Manager Server 4.3 LTS (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Manager Server 4.3 LTS (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 ## References: * https://www.suse.com/security/cve/CVE-2025-27466.html * https://www.suse.com/security/cve/CVE-2025-58142.html * https://www.suse.com/security/cve/CVE-2025-58143.html * https://www.suse.com/security/cve/CVE-2025-58147.html * https://www.suse.com/security/cve/CVE-2025-58148.html * https://bugzilla.suse.com/show_bug.cgi?id=1248807 * https://bugzilla.suse.com/show_bug.cgi?id=1251271 . This security update addresses multiple vulnerabilities in Xen, including input sanitization issues and more.. SUSE Linux, Xen Security, Update Patch. . Severity: Important. LinuxSecurity.com Team
Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-22fd93478b 2025-10-28 00:58:14.247378+00:00 -------------------------------------------------------------------------------- Name : xen Product : Fedora 43 Version : 4.20.1 Release : 8.fc43 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148] -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 24 2025 Michael Young - 4.20.1-8 - Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] * Tue Oct 21 2025 Michael Young - 4.20.1-7 - x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148] -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-22fd93478b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Add shell-completions Update to 4.47.1 and adopt go-vendor-tools. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-99309ef35f 2025-09-07 00:51:16.113251+00:00 -------------------------------------------------------------------------------- Name : yq Product : Fedora 42 Version : 4.47.1 Release : 2.fc42 URL : https://github.com/mikefarah/yq Summary : Yq is a portable command-line YAML, JSON, XML, CSV, TOML and properties processor Description : Yq is a portable command-line YAML, JSON, XML, CSV, TOML and properties processor. -------------------------------------------------------------------------------- Update Information: Add shell-completions Update to 4.47.1 and adopt go-vendor-tools -------------------------------------------------------------------------------- ChangeLog: * Fri Aug 29 2025 Mikel Olasagasti Uranga - 4.47.1-2 - Add shell completions * Thu Aug 21 2025 Romain Geissler - 4.47.1-1 - Upgrade to upstream version 4.47.1 and use vendoring (rhbz#2282002). * Fri Aug 15 2025 Maxwell G - 4.43.1-7 - Rebuild for golang-1.25.0 * Fri Jul 25 2025 Fedora Release Engineering - 4.43.1-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2282002 - v4.44.1 of yq was released https://bugzilla.redhat.com/show_bug.cgi?id=2282002 [ 2 ] Bug #2360655 - CVE-2025-22872 yq: Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2360655 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-99309ef35f' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.