Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed.. openSUSE security update: security update for python-pdm ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21161-1 Rating: moderate References: * bsc#1268384 * bsc#1268385 * bsc#1268386 Cross-References: * CVE-2026-47763 * CVE-2026-47764 * CVE-2026-47781 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed. Description: This update for python-pdm fixes the following issues: Changes in python-pdm: - CVE-2026-47763: Do not follow symlinks when writing config files (bsc#1268384) - CVE-2026-47763: Do not write to paths outside the scheme dir (bsc#1268385) - CVE-2026-47781: Update plugin installation path to use project_plugins_dir (bsc#1268386) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-356=1 Package List: - openSUSE Leap 16.0: python313-pdm-2.22.3-bp160.2.1 References: * https://www.suse.com/security/cve/CVE-2026-47763.html * https://www.suse.com/security/cve/CVE-2026-47764.html * https://www.suse.com/security/cve/CVE-2026-47781.html . openSUSE security update for python-pdm addresses multiple issues including moderate risks and important patching instructions.. security update, python-pdm, openSUSE, vulnerability fix, patch instructions. . Severity: moderate. LinuxSecurity.com Team
An update that solves 2 vulnerabilities can now be installed.. # lemon-3.53.2-2.1 on GA media Announcement ID: openSUSE-SU-2026:11059-1 Rating: moderate Cross-References: * CVE-2026-11822 * CVE-2026-11824 CVSS scores: * CVE-2026-11822 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11824 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the lemon-3.53.2-2.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * lemon 3.53.2-2.1 * libsqlite3-0 3.53.2-2.1 * libsqlite3-0-32bit 3.53.2-2.1 * libsqlite3-0-x86-64-v3 3.53.2-2.1 * sqlite3 3.53.2-2.1 * sqlite3-devel 3.53.2-2.1 * sqlite3-doc 3.53.2-2.1 * sqlite3-tcl 3.53.2-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11822.html * https://www.suse.com/security/cve/CVE-2026-11824.html . An important update for openSUSE addressing two vulnerabilities in the lemon application, enhancing system security.. openSUSE update, lemon security, moderate threat, CVE exploits. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # libpodofo-devel-1.1.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:10970-1 Rating: moderate Cross-References: * CVE-2026-44348 CVSS scores: * CVE-2026-44348 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-44348 ( SUSE ): 2 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the libpodofo-devel-1.1.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * libpodofo-devel 1.1.0-1.1 * libpodofo4 1.1.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44348.html . An update is available for openSUSE Tumbleweed addressing a moderate vulnerability in libpodofo-devel package.. openSUSE Tumbleweed, libpodofo development, security update. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # glibc-2.43-2.1 on GA media Announcement ID: openSUSE-SU-2026:10722-1 Rating: moderate Cross-References: * CVE-2026-4046 CVSS scores: * CVE-2026-4046 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4046 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the glibc-2.43-2.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * glibc 2.43-2.1 * glibc-devel 2.43-2.1 * glibc-devel-static 2.43-2.1 * glibc-extra 2.43-2.1 * glibc-gconv-modules-extra 2.43-2.1 * glibc-html 2.43-2.1 * glibc-i18ndata 2.43-2.1 * glibc-info 2.43-2.1 * glibc-lang 2.43-2.1 * glibc-locale 2.43-2.1 * glibc-locale-base 2.43-2.1 * glibc-profile 2.43-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4046.html . An update available for openSUSE resolves a moderate security issue in glibc, addressing CVE-2026-4046.. openSUSE Tumbleweed, glibc update, moderate severity. . LinuxSecurity.com Team
An update that solves 4 vulnerabilities can now be installed.. # mutt-2.3.2-1.1 on GA media Announcement ID: openSUSE-SU-2026:10695-1 Rating: moderate Cross-References: * CVE-2026-43859 * CVE-2026-43861 * CVE-2026-43862 * CVE-2026-43863 CVSS scores: * CVE-2026-43859 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-43859 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43861 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-43861 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43862 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-43862 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43863 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-43863 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 4 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the mutt-2.3.2-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * mutt 2.3.2-1.1 * mutt-doc 2.3.2-1.1 * mutt-lang 2.3.2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43859.html * https://www.suse.com/security/cve/CVE-2026-43861.html * https://www.suse.com/security/cve/CVE-2026-43862.html * https://www.suse.com/security/cve/CVE-2026-43863.html . Explore the recent openSUSE Tumbleweed update that fixes 4 moderate security issues in mutt-2.3.2-1.1 package.. openSUSE Tumbleweed mutt vulnerabilities. . LinuxSecurity.com Team
An update that solves six vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 30 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:1733-1 Release Date: 2026-05-07T09:04:22Z Rating: important References: * bsc#1252048 * bsc#1258005 * bsc#1258073 * bsc#1258655 * bsc#1259126 * bsc#1263689 Cross-References: * CVE-2025-38375 * CVE-2025-39977 * CVE-2025-71066 * CVE-2026-23004 * CVE-2026-23204 * CVE-2026-31431 CVSS scores: * CVE-2025-38375 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38375 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38375 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-39977 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-39977 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71066 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23004 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23004 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23004 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23204 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-23204 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23204 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23204 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31431 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31431 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High PerformanceComputing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 5.14.21-150500.55.121 fixes various security issues The following security issues were fixed: * CVE-2025-38375: virtio-net: ensure the received length does not exceed allocated size (bsc#1258073). * CVE-2025-39977: futex: Prevent use-after-free during requeue-PI (bsc#1252048). * CVE-2025-71066: net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change (bsc#1258005). * CVE-2026-23004: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() (bsc#1258655). * CVE-2026-23204: net/sched: cls_u32: use skb_header_pointer_careful() (bsc#1259126). * CVE-2026-31431: crypto: algif_aead - Revert to operating out-of-place (bsc#1263689). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1733=1 SUSE-2026-1734=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-1733=1 SUSE-SLE- Module-Live-Patching-15-SP4-2026-1734=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-1739=1 SUSE-2026-1746=1 SUSE-2026-1747=1 SUSE-2026-1738=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patchSUSE-SLE-Module-Live-Patching-15-SP5-2026-1738=1 SUSE-SLE- Module-Live-Patching-15-SP5-2026-1739=1 SUSE-SLE-Module-Live- Patching-15-SP5-2026-1746=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-1747=1 ## Package List: * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_184-default-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-12-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-debuginfo-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_46-debugsource-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_44-debugsource-12-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-debuginfo-12-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_184-default-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-12-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-debuginfo-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_46-debugsource-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_44-debugsource-12-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-debuginfo-12-150400.2.1 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_103-default-debuginfo-18-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_29-debugsource-14-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_26-debugsource-18-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_27-debugsource-17-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-17-150500.2.1 * kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-14-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_30-debugsource-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-17-150500.2.1 * kernel-livepatch-5_14_21-150500_55_103-default-18-150500.2.1 *kernel-livepatch-5_14_21-150500_55_116-default-14-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_103-default-debuginfo-18-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_26-debugsource-18-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_27-debugsource-17-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-17-150500.2.1 * kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-14-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_30-debugsource-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-17-150500.2.1 * kernel-livepatch-5_14_21-150500_55_103-default-18-150500.2.1 * kernel-livepatch-5_14_21-150500_55_116-default-14-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x) * kernel-livepatch-SLE15-SP5_Update_29-debugsource-14-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-38375.html * https://www.suse.com/security/cve/CVE-2025-39977.html * https://www.suse.com/security/cve/CVE-2025-71066.html * https://www.suse.com/security/cve/CVE-2026-23004.html * https://www.suse.com/security/cve/CVE-2026-23204.html * https://www.suse.com/security/cve/CVE-2026-31431.html * https://bugzilla.suse.com/show_bug.cgi?id=1252048 * https://bugzilla.suse.com/show_bug.cgi?id=1258005 * https://bugzilla.suse.com/show_bug.cgi?id=1258073 * https://bugzilla.suse.com/show_bug.cgi?id=1258655 * https://bugzilla.suse.com/show_bug.cgi?id=1259126 * https://bugzilla.suse.com/show_bug.cgi?id=1263689 . Important update for SUSE Linux Kernel addressing six critical vulnerabilities. Install this release patch now!. SUSE Linux Kernel, security advisory, important update, kernel patch, vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # python311-pyOpenSSL-26.1.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:10646-1 Rating: moderate Cross-References: * CVE-2026-40475 CVSS scores: * CVE-2026-40475 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40475 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the python311-pyOpenSSL-26.1.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * python311-pyOpenSSL 26.1.0-1.1 * python313-pyOpenSSL 26.1.0-1.1 * python314-pyOpenSSL 26.1.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40475.html . An important update for openSUSE addresses a moderate severity security issue in the python311-pyOpenSSL package.. openSUSE, python311-pyOpenSSL, moderate security update, CVE-2026-40475, Linux application. . Severity: Important. LinuxSecurity.com Team
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for cjson ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20340-1 Rating: important References: * bsc#1241502 * bsc#1249112 Cross-References: * CVE-2023-26819 * CVE-2025-57052 CVSS scores: * CVE-2023-26819 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2023-26819 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-57052 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-57052 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for cJSON fixes the following issues: - Update to version 1.7.19 * Check for NULL in cJSON_DetachItemViaPointer. * Check overlap before calling strcpy in cJSON_SetValuestring. * Fix Max recursion depth for cJSON_Duplicate to prevent stack exhaustion. * Allocate memory for the temporary buffer when paring numbers. This fixes CVE-2023-26819. (bsc#1241502) * Fix the incorrect check in decode_array_index_from_pointer. This fixes CVE-2025-57052. (bsc#1249112) - Remove not longer needed patch for NULL to deallocated pointers. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-369=1 Package List: - openSUSE Leap 16.0: cJSON-devel-1.7.19-160000.1.1 libcjson1-1.7.19-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2023-26819.html * https://www.suse.com/security/cve/CVE-2025-57052.html . Importantsecurity update for openSUSE containing fixes for cJSON vulnerabilities and bug fixes to enhance system stability.. openSUSE security cJSON vulnerability fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.