Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
202

openSUSE Kanidm Moderate Buffer Overflow Issue 2025-0152-1

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for kanidm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0152-1 Rating: moderate References: #1242642 Cross-References: CVE-2025-3416 CVSS scores: CVE-2025-3416 (SUSE): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for kanidm fixes the following issues: - Update to version 1.6.2~git0.a20663ea8: * Release 1.6.2 * fix: clippy * maint: typo in log message * Set kid manually to prevent divergence * Order keys in application JWKS / Fix rotation bug * Fix toml issues with strings - Update to version 1.6.1~git0.2e4429eca: * Release 1.6.1 * Resolve reload of oauth2 on startup (#3604) - CVE-2025-3416: Fixed openssl use after free (boo#1242642) - Update to version 1.6.0~git0.d7ae0f336: * Release 1.6.0 * Avoid openssl for md4 * Fixes #3586, inverts the navbar button color (#3593) * Release 1.6.0-pre * chore: Release Notes (#3588) * Do not require instances to exist during optional config load (#3591) * Fix std::fmt::Display for some objects (#3587) * Drop fernet in favour of JWE (#3577) * docs: document how to configure oauth2 for opkssh (#3566) * Add kanidm_ssh_authorizedkeys_direct to client deb (#3585) * Bump the all group in /pykanidm with 2 updates (#3581) * Update dependencies, fix a bunch of clippy lints (#3576) * Support spaces in ssh key comments (#3575) * 20250402 3423 proxy protocol (#3542) * fix(web): Preserve SSH key content on form validation error (#3574) * Bump the all group in /pykanidm with 3updates (#3572) * Bump the all group in /pykanidm with 2 updates (#3564) * Bump crossbeam-channel from 0.5.14 to 0.5.15 in the cargo group (#3560) * Improve token handling (#3553) * Bump tokio from 1.44.1 to 1.44.2 in the cargo group (#3549) * Update fs4 and improve klock handling (#3551) * Less footguns (#3552) * Unify unix config parser (#3533) * Bump openssl from 0.10.71 to 0.10.72 in the cargo group (#3544) * Bump the all group in /pykanidm with 8 updates (#3547) * implement notify-reload protocol (#3540) * Allow versioning of server configs (#3515) * 20250314 remove protected plugin (#3504) * Bump the all group with 10 updates (#3539) * Bump mozilla-actions/sccache-action from 0.0.8 to 0.0.9 in the all group (#3538) * Bump the all group in /pykanidm with 4 updates (#3537) * Add max_ber_size to freeipa sync (#3530) * Bump the all group in /pykanidm with 5 updates (#3524) * Update Concread * Update developer_ethics.md (#3520) * Update examples.md (#3519) * Make schema indexing a boolean instead of index types (#3517) * Add missing lld dependency and fix syntax typo (#3490) * Update shell.nix to work with stable nixpkgs (#3514) * Improve unixd tasks channel comments (#3510) * Update kanidm_ppa_automation reference to latest (#3512) * Add set-description to group tooling (#3511) * packaging: Add kanidmd deb package, update documentation (#3506) * Bump the all group in /pykanidm with 5 updates (#3508) * 20250313 unixd system cache (#3501) * Support rfc2307 memberUid in sync operations. (#3466) * Bump mozilla-actions/sccache-action from 0.0.7 to 0.0.8 in the all group (#3496) * Update Traefik config example to remove invalid label (#3500) * Add uid/gid allocation table (#3498) * 20250225 ldap testing in testkit (#3460) * Bump the all group in /pykanidm with 5 updates (#3494) * Bump ring from 0.17.10 to 0.17.13 in the cargogroup (#3491) * Handle form-post as a response mode (#3467) * book: fix english (#3487) * Correct paths with Kanidm Tools Container (#3486) * 20250225 improve test performance (#3459) * Bump the all group in /pykanidm with 8 updates (#3484) * Use lld by default on linux (#3477) * 20250213 patch used wrong acp (#3432) * Android support (#3475) * Changed all CI/CD builds to locked (#3471) * Make it a bit clearer that providers are needed (#3468) * Fix incorrect credential generation in radius docs (#3465) * Add crypt formats for password import (#3458) * build: Create daemon image from scratch (#3452) * address webfinger doc feedbacks (#3446) * Bump the all group across 1 directory with 5 updates (#3453) * [htmx] Admin ui for groups and users management (#3019) * Fixes #3406: add configurable maximum queryable attributes for LDAP (#3431) * Accept invalid certs and fix token_cache_path (#3439) * Accept lowercase ldap pwd hashes (#3444) * TOTP label verification (#3419) * Rewrite WebFinger docs (#3443) * doc: fix formatting of URL table, remove Caddyfile instructions (#3442) * book: add OAuth2 Proxy example (#3434) * Exempt idm_admin and admin from denied names. (#3429) * Book fixes (#3433) * ci: uniform Docker builds (#3430) * 20240213 3413 domain displayname (#3425) * Correct path to kanidm config example in documentation. (#3424) * Support redirect uris with query parameters (#3422) * Update to 1.6.0-dev (#3418) * Remove white background from square logo. (#3417) * feat: Added webfinger implementation (#3410) * Bump the all group in /pykanidm with 7 updates (#3412) - Update to version 1.5.0~git2.21c2a1bd0: * fix: documentation fail (#3555) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run thecommand listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-152=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 x86_64): kanidm-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-clients-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-clients-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-debugsource-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-docs-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-server-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-server-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-unixd-clients-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-unixd-clients-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 References: https://www.suse.com/security/cve/CVE-2025-3416.html https://bugzilla.suse.com/1242642 . Security update for openSUSE kanidm addresses moderate threat from CVE-2025-3416, improving system stability.. openSUSE kanidm security patch moderate CVE-2025-3416 update. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 11, 2026 moderate OpenSUSE
202

openSUSE 2026-0198-1 Kanidm Urgent Fix for User Auth Privilege Escalation

An update that contains security fixes can now be installed.. openSUSE Security Update: Security update for kanidm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0198-1 Rating: critical References: Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for kanidm fixes the following issues: - Update to version 1.10.2~git0.f3dc9ef1f: * Release 1.10.2 * Security - CRITICAL - authenticated user privilege escalation * Refactor modification access paths to remove duplication * Revert ClientID header (#4334) * Disable prompt=login (#4340) * Add missing `/sbin/kanidm-mail-sender` (#4323) * Remove debug symbols in release builds. (#4319) - Update to version 1.10.1~git0.d02660a98: * Release 1.10.1 * Fix copy in TOTP removal prompt and align TOTP case (#4314) * Resolve base64 encoding of webauthn fields (#4312) - Update to version 1.10.0-pre~git1.32e2f8ec6: * Release 1.10.0 * Release 1.10.0-pre * Release notes (#4304) * Update ldap3/webauthn-rs (#4302) * Merge commit from fork * Merge commit from fork * Merge commit from fork * Merge commit from fork * Add notes on server migration (#4301) * 20260517 sparkle (#4280) * Bump mozilla-actions/sccache-action in the all group (#4298) * Bump the all group with 6 updates (#4299) * Bump the all group across 1 directory with 3 updates (#4283) * 20260331 send account recovery emails (#4259) * Update oauth2 well known urls (#4296) * Clippy for Rust 1.95 (#4291) * Invert incorrect thread count logic (#4294) * Allow modification of OAuth2 Refresh Expiry (#4276) * 20260327 Introspection token auth metadata (#4230) * fix: add missingkanidm-mail-sender binary (#4279) * Correctly handle deleted accounts during page visits (#4275) * don't fail auth when passed ui_locales (#4288) * Bump actions/upload-pages-artifact from 4 to 5 in the all group (#4284) * Fix link formatting in oauth2.rs documentation (#4278) * Feat: Add OIDC Prompt Support (#4224) * Handle multivalue URLs in SCIM (#4271) * Correctly encode ssh tag values (#4272) * Bump the all group with 2 updates (#4263) * Bump the all group in /rlm_python with 4 updates (#4262) * Bump the all group with 8 updates (#4264) * Update deployment.md with configuration notes (#4258) * Add .well-known/passkey-endpoints (#4255) * show repl cert metadata and also handle socket timeouts (#4252) * Update docs regarding replication cert lifetime (#4251) * Log cleanup (#4248) * adding timeouts and tests and port docs for mail_sender (#4246) * Bump the all group with 5 updates (#4247) * add dependency data to released containers (#4239) * Fix to end code block and render remaining md correctly (#4241) * Update readme.md for replication (#4236) * Added note on primary email address and email aliases (#4237) * Bump the all group with 6 updates (#4235) * Bump the all group with 2 updates (#4234) * Bump the uv group across 1 directory with 2 updates (#4231) * cli: allow clearing person's legalname attribute (#4228) * Add shell diagnostics (#4220) * OpenSSL shall be vanquished (#4219) * Bump the all group across 1 directory with 16 updates (#4225) * Bump rustls-webpki from 0.103.9 to 0.103.10 (#4223) * Bump flatted (#4222) * Tabular data is tabular (#4221) * Example sshd-config fragment, deployment de-activated on Debian (#4214) * Update RELEASE_NOTES.md (#4215) * fix(debian): Use correct bin path for kanidmd reload (#4212) * Allow urlencoded client_id in basic auth (#4141) * add nsswitch config check to unixd (#4210) * 20260311zxcvbn check (#4206) * Enhance Traefik documentation (#4194) * Re-add incorrectly removed utopia feature flag (#4207) * Update ldap3 to 0.7.0 to resolve config filter issue (#4205) * Added PasswordChangedTime attribute and database field (#3999) * Defer on some routes (#4202) * Remove thread local storage (#4204) * Improve FreeBSD building, fully drop ring as a dependency. * 20260218 credential reset emails (authenticated only) (#4151) * android support for cli (#4197) * Bump the all group with 4 updates (#4198) * Bump the all group with 7 updates (#4199) * feat: bind mount home strategy (#3997) * Bump the all group with 2 updates (#4183) * Bump the all group with 8 updates (#4184) * Bump minimatch (#4180) * Disable multithreading on RADIUS when DEBUG is False. (#4177) * Don't revert admin changes in some groups during migrcation (#4176) * Fix bug where DEBUG is always true in RADIUS entrypoint. (#4169) * 20260220 prevent migration accidents (#4156) * Bump the all group across 1 directory with 20 updates (#4163) * Move the grafana group creation step (#4160) * Alert on unsaved changes (#4155) * pykanidm v1.3.0 - major rewrite to use openapi-generated codebase based on 1.9.0 spec (#4149) * Warn about systemd-userdb (#4147) * Dont require basic auth on token introspection (#4142) * Dont be as upset when migration dir doesnt exist (#4146) * Add AGENTS.md instructions (#4148) * Feature OIDC updated at (#4007) * pykanidm: clarify token use with service accounts (#4043) * Fixed small typo in how_does_oauth2_work.md (#4138) * Bye bye lazy static (#4134) * Allow LDAP CA verification to be disabled in sync (#4133) * Add oauth2 example, fix inter-migration reference handling (#4136) * Add missing future migration in domain check (#4132) * Corrected recycle_bin.md typo (#4135) * 20260211 dev version (#4131) - Update to version1.9.3~git0.7d4108698: * Release 1.9.3 * Security - High: SCIM Filters did not contain a bound on their parsing depth allowing stack exhaustion to occur leading to Denial of Service by an unauthenticated user * Security - Moderate: PNG Image validation did not correctly handle short images allowing a panic to occur in a worker thread. This may lead to system instability over time * Security - Low: HTML injection via user DisplayName in Passkey enrolment dialogs. This allows an admin to execute JS in the context of a users browser. Since the admin already can reset the users credentials, the impact of this is minimal. * Security - Low: non-constant time comparison of OAuth2 client secret may allow a remote attacker to remotely recovery the bytes of the secret. Due to the length of the secret (48 chars) this is infeasible practically. * Security - Low: incorrect handling of origin validation in Webauthn-RS allowed a malicious domain to collide with a valid one (badexample.com would match with example.com). This is mitigated by browsers detecting the forgery and preventing the authentication from proceeding. * Security - High: LDAP Filters did not contain a bound on their parsing depth allowing stack exhaustion to occur leading to Denial of Service by an unauthenticated user. * Update two vulnerable dependencies * Release 1.9.2 * Allow urlencoded client_id in basic auth (#4141) * Update ldap3 to 0.7.0 to resolve config filter issue (#4205) * Remove thread local storage (#4204) - Update to version 1.9.2~git6.896acba35: * Release 1.9.3 * Merge commit from fork * Merge commit from fork * Merge commit from fork * Merge commit from fork * Update two vulnerable dependencies - Update to version 1.9.2~git0.6a2bb66bd: * Release 1.9.2 * Allow urlencoded client_id in basic auth (#4141) * Update ldap3 to 0.7.0 toresolve config filter issue (#4205) * Remove thread local storage (#4204) * Disable multithreading on RADIUS when DEBUG is False. (#4177) * Fix bug where DEBUG is always true in RADIUS entrypoint. (#4169) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2026-198=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 x86_64): kanidm-1.10.2~git0.f3dc9ef1f-bp156.64.1 kanidm-clients-1.10.2~git0.f3dc9ef1f-bp156.64.1 kanidm-docs-1.10.2~git0.f3dc9ef1f-bp156.64.1 kanidm-server-1.10.2~git0.f3dc9ef1f-bp156.64.1 kanidm-unixd-clients-1.10.2~git0.f3dc9ef1f-bp156.64.1 References: . Critical security update for kanidm on openSUSE prevents privilege escalation and enhances stability.. openSUSE kanidm critical update privilege escalation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 10, 2026 Critical OpenSUSE
202

openSUSE kanidm Critical Privilege Escalation Vulnerability 2026-0192-1

An update that contains security fixes can now be installed.. openSUSE Security Update: Security update for kanidm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0192-1 Rating: critical References: Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for kanidm fixes the following issues: - Update to version 1.10.2~git0.f3dc9ef1f: * Release 1.10.2 * Security - CRITICAL - authenticated user privilege escalation * Refactor modification access paths to remove duplication * Revert ClientID header (#4334) * Disable prompt=login (#4340) * Add missing `/sbin/kanidm-mail-sender` (#4323) * Remove debug symbols in release builds. (#4319) - Update to version 1.10.1~git0.d02660a98: * Release 1.10.1 * Fix copy in TOTP removal prompt and align TOTP case (#4314) * Resolve base64 encoding of webauthn fields (#4312) - Update to version 1.10.0-pre~git1.32e2f8ec6: * Release 1.10.0 * Release 1.10.0-pre * Release notes (#4304) * Update ldap3/webauthn-rs (#4302) * Merge commit from fork * Merge commit from fork * Merge commit from fork * Merge commit from fork * Add notes on server migration (#4301) * 20260517 sparkle (#4280) * Bump mozilla-actions/sccache-action in the all group (#4298) * Bump the all group with 6 updates (#4299) * Bump the all group across 1 directory with 3 updates (#4283) * 20260331 send account recovery emails (#4259) * Update oauth2 well known urls (#4296) * Clippy for Rust 1.95 (#4291) * Invert incorrect thread count logic (#4294) * Allow modification of OAuth2 Refresh Expiry (#4276) * 20260327 Introspection token auth metadata (#4230) * fix: add missingkanidm-mail-sender binary (#4279) * Correctly handle deleted accounts during page visits (#4275) * don't fail auth when passed ui_locales (#4288) * Bump actions/upload-pages-artifact from 4 to 5 in the all group (#4284) * Fix link formatting in oauth2.rs documentation (#4278) * Feat: Add OIDC Prompt Support (#4224) * Handle multivalue URLs in SCIM (#4271) * Correctly encode ssh tag values (#4272) * Bump the all group with 2 updates (#4263) * Bump the all group in /rlm_python with 4 updates (#4262) * Bump the all group with 8 updates (#4264) * Update deployment.md with configuration notes (#4258) * Add .well-known/passkey-endpoints (#4255) * show repl cert metadata and also handle socket timeouts (#4252) * Update docs regarding replication cert lifetime (#4251) * Log cleanup (#4248) * adding timeouts and tests and port docs for mail_sender (#4246) * Bump the all group with 5 updates (#4247) * add dependency data to released containers (#4239) * Fix to end code block and render remaining md correctly (#4241) * Update readme.md for replication (#4236) * Added note on primary email address and email aliases (#4237) * Bump the all group with 6 updates (#4235) * Bump the all group with 2 updates (#4234) * Bump the uv group across 1 directory with 2 updates (#4231) * cli: allow clearing person's legalname attribute (#4228) * Add shell diagnostics (#4220) * OpenSSL shall be vanquished (#4219) * Bump the all group across 1 directory with 16 updates (#4225) * Bump rustls-webpki from 0.103.9 to 0.103.10 (#4223) * Bump flatted (#4222) * Tabular data is tabular (#4221) * Example sshd-config fragment, deployment de-activated on Debian (#4214) * Update RELEASE_NOTES.md (#4215) * fix(debian): Use correct bin path for kanidmd reload (#4212) * Allow urlencoded client_id in basic auth (#4141) * add nsswitch config check to unixd (#4210) * 20260311zxcvbn check (#4206) * Enhance Traefik documentation (#4194) * Re-add incorrectly removed utopia feature flag (#4207) * Update ldap3 to 0.7.0 to resolve config filter issue (#4205) * Added PasswordChangedTime attribute and database field (#3999) * Defer on some routes (#4202) * Remove thread local storage (#4204) * Improve FreeBSD building, fully drop ring as a dependency. * 20260218 credential reset emails (authenticated only) (#4151) * android support for cli (#4197) * Bump the all group with 4 updates (#4198) * Bump the all group with 7 updates (#4199) * feat: bind mount home strategy (#3997) * Bump the all group with 2 updates (#4183) * Bump the all group with 8 updates (#4184) * Bump minimatch (#4180) * Disable multithreading on RADIUS when DEBUG is False. (#4177) * Don't revert admin changes in some groups during migrcation (#4176) * Fix bug where DEBUG is always true in RADIUS entrypoint. (#4169) * 20260220 prevent migration accidents (#4156) * Bump the all group across 1 directory with 20 updates (#4163) * Move the grafana group creation step (#4160) * Alert on unsaved changes (#4155) * pykanidm v1.3.0 - major rewrite to use openapi-generated codebase based on 1.9.0 spec (#4149) * Warn about systemd-userdb (#4147) * Dont require basic auth on token introspection (#4142) * Dont be as upset when migration dir doesnt exist (#4146) * Add AGENTS.md instructions (#4148) * Feature OIDC updated at (#4007) * pykanidm: clarify token use with service accounts (#4043) * Fixed small typo in how_does_oauth2_work.md (#4138) * Bye bye lazy static (#4134) * Allow LDAP CA verification to be disabled in sync (#4133) * Add oauth2 example, fix inter-migration reference handling (#4136) * Add missing future migration in domain check (#4132) * Corrected recycle_bin.md typo (#4135) * 20260211 dev version (#4131) - Update to version1.9.3~git0.7d4108698: * Release 1.9.3 * Security - High: SCIM Filters did not contain a bound on their parsing depth allowing stack exhaustion to occur leading to Denial of Service by an unauthenticated user * Security - Moderate: PNG Image validation did not correctly handle short images allowing a panic to occur in a worker thread. This may lead to system instability over time * Security - Low: HTML injection via user DisplayName in Passkey enrolment dialogs. This allows an admin to execute JS in the context of a users browser. Since the admin already can reset the users credentials, the impact of this is minimal. * Security - Low: non-constant time comparison of OAuth2 client secret may allow a remote attacker to remotely recovery the bytes of the secret. Due to the length of the secret (48 chars) this is infeasible practically. * Security - Low: incorrect handling of origin validation in Webauthn-RS allowed a malicious domain to collide with a valid one (badexample.com would match with example.com). This is mitigated by browsers detecting the forgery and preventing the authentication from proceeding. * Security - High: LDAP Filters did not contain a bound on their parsing depth allowing stack exhaustion to occur leading to Denial of Service by an unauthenticated user. * Update two vulnerable dependencies * Release 1.9.2 * Allow urlencoded client_id in basic auth (#4141) * Update ldap3 to 0.7.0 to resolve config filter issue (#4205) * Remove thread local storage (#4204) - Update to version 1.9.2~git6.896acba35: * Release 1.9.3 * Merge commit from fork * Merge commit from fork * Merge commit from fork * Merge commit from fork * Update two vulnerable dependencies - Update to version 1.9.2~git0.6a2bb66bd: * Release 1.9.2 * Allow urlencoded client_id in basic auth (#4141) * Update ldap3 to 0.7.0 toresolve config filter issue (#4205) * Remove thread local storage (#4204) * Disable multithreading on RADIUS when DEBUG is False. (#4177) * Fix bug where DEBUG is always true in RADIUS entrypoint. (#4169) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-192=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 x86_64): kanidm-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 kanidm-clients-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 kanidm-docs-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 kanidm-server-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 kanidm-unixd-clients-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 References: . Security update for kanidm on openSUSE addresses critical privilege escalation issues and other vulnerabilities.. openSUSE kanidm security update critical vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 05, 2026 Critical OpenSUSE
202

openSUSE Kanidm Critical Privilege Escalation Vulnern 2026-0192-1

An update that contains security fixes can now be installed.. openSUSE Security Update: Security update for kanidm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0192-1 Rating: critical References: Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for kanidm fixes the following issues: - Update to version 1.10.2~git0.f3dc9ef1f: * Release 1.10.2 * Security - CRITICAL - authenticated user privilege escalation * Refactor modification access paths to remove duplication * Revert ClientID header (#4334) * Disable prompt=login (#4340) * Add missing `/sbin/kanidm-mail-sender` (#4323) * Remove debug symbols in release builds. (#4319) - Update to version 1.10.1~git0.d02660a98: * Release 1.10.1 * Fix copy in TOTP removal prompt and align TOTP case (#4314) * Resolve base64 encoding of webauthn fields (#4312) - Update to version 1.10.0-pre~git1.32e2f8ec6: * Release 1.10.0 * Release 1.10.0-pre * Release notes (#4304) * Update ldap3/webauthn-rs (#4302) * Merge commit from fork * Merge commit from fork * Merge commit from fork * Merge commit from fork * Add notes on server migration (#4301) * 20260517 sparkle (#4280) * Bump mozilla-actions/sccache-action in the all group (#4298) * Bump the all group with 6 updates (#4299) * Bump the all group across 1 directory with 3 updates (#4283) * 20260331 send account recovery emails (#4259) * Update oauth2 well known urls (#4296) * Clippy for Rust 1.95 (#4291) * Invert incorrect thread count logic (#4294) * Allow modification of OAuth2 Refresh Expiry (#4276) * 20260327 Introspection token auth metadata (#4230) * fix: add missingkanidm-mail-sender binary (#4279) * Correctly handle deleted accounts during page visits (#4275) * don't fail auth when passed ui_locales (#4288) * Bump actions/upload-pages-artifact from 4 to 5 in the all group (#4284) * Fix link formatting in oauth2.rs documentation (#4278) * Feat: Add OIDC Prompt Support (#4224) * Handle multivalue URLs in SCIM (#4271) * Correctly encode ssh tag values (#4272) * Bump the all group with 2 updates (#4263) * Bump the all group in /rlm_python with 4 updates (#4262) * Bump the all group with 8 updates (#4264) * Update deployment.md with configuration notes (#4258) * Add .well-known/passkey-endpoints (#4255) * show repl cert metadata and also handle socket timeouts (#4252) * Update docs regarding replication cert lifetime (#4251) * Log cleanup (#4248) * adding timeouts and tests and port docs for mail_sender (#4246) * Bump the all group with 5 updates (#4247) * add dependency data to released containers (#4239) * Fix to end code block and render remaining md correctly (#4241) * Update readme.md for replication (#4236) * Added note on primary email address and email aliases (#4237) * Bump the all group with 6 updates (#4235) * Bump the all group with 2 updates (#4234) * Bump the uv group across 1 directory with 2 updates (#4231) * cli: allow clearing person's legalname attribute (#4228) * Add shell diagnostics (#4220) * OpenSSL shall be vanquished (#4219) * Bump the all group across 1 directory with 16 updates (#4225) * Bump rustls-webpki from 0.103.9 to 0.103.10 (#4223) * Bump flatted (#4222) * Tabular data is tabular (#4221) * Example sshd-config fragment, deployment de-activated on Debian (#4214) * Update RELEASE_NOTES.md (#4215) * fix(debian): Use correct bin path for kanidmd reload (#4212) * Allow urlencoded client_id in basic auth (#4141) * add nsswitch config check to unixd (#4210) * 20260311zxcvbn check (#4206) * Enhance Traefik documentation (#4194) * Re-add incorrectly removed utopia feature flag (#4207) * Update ldap3 to 0.7.0 to resolve config filter issue (#4205) * Added PasswordChangedTime attribute and database field (#3999) * Defer on some routes (#4202) * Remove thread local storage (#4204) * Improve FreeBSD building, fully drop ring as a dependency. * 20260218 credential reset emails (authenticated only) (#4151) * android support for cli (#4197) * Bump the all group with 4 updates (#4198) * Bump the all group with 7 updates (#4199) * feat: bind mount home strategy (#3997) * Bump the all group with 2 updates (#4183) * Bump the all group with 8 updates (#4184) * Bump minimatch (#4180) * Disable multithreading on RADIUS when DEBUG is False. (#4177) * Don't revert admin changes in some groups during migrcation (#4176) * Fix bug where DEBUG is always true in RADIUS entrypoint. (#4169) * 20260220 prevent migration accidents (#4156) * Bump the all group across 1 directory with 20 updates (#4163) * Move the grafana group creation step (#4160) * Alert on unsaved changes (#4155) * pykanidm v1.3.0 - major rewrite to use openapi-generated codebase based on 1.9.0 spec (#4149) * Warn about systemd-userdb (#4147) * Dont require basic auth on token introspection (#4142) * Dont be as upset when migration dir doesnt exist (#4146) * Add AGENTS.md instructions (#4148) * Feature OIDC updated at (#4007) * pykanidm: clarify token use with service accounts (#4043) * Fixed small typo in how_does_oauth2_work.md (#4138) * Bye bye lazy static (#4134) * Allow LDAP CA verification to be disabled in sync (#4133) * Add oauth2 example, fix inter-migration reference handling (#4136) * Add missing future migration in domain check (#4132) * Corrected recycle_bin.md typo (#4135) * 20260211 dev version (#4131) - Update to version1.9.3~git0.7d4108698: * Release 1.9.3 * Security - High: SCIM Filters did not contain a bound on their parsing depth allowing stack exhaustion to occur leading to Denial of Service by an unauthenticated user * Security - Moderate: PNG Image validation did not correctly handle short images allowing a panic to occur in a worker thread. This may lead to system instability over time * Security - Low: HTML injection via user DisplayName in Passkey enrolment dialogs. This allows an admin to execute JS in the context of a users browser. Since the admin already can reset the users credentials, the impact of this is minimal. * Security - Low: non-constant time comparison of OAuth2 client secret may allow a remote attacker to remotely recovery the bytes of the secret. Due to the length of the secret (48 chars) this is infeasible practically. * Security - Low: incorrect handling of origin validation in Webauthn-RS allowed a malicious domain to collide with a valid one (badexample.com would match with example.com). This is mitigated by browsers detecting the forgery and preventing the authentication from proceeding. * Security - High: LDAP Filters did not contain a bound on their parsing depth allowing stack exhaustion to occur leading to Denial of Service by an unauthenticated user. * Update two vulnerable dependencies * Release 1.9.2 * Allow urlencoded client_id in basic auth (#4141) * Update ldap3 to 0.7.0 to resolve config filter issue (#4205) * Remove thread local storage (#4204) - Update to version 1.9.2~git6.896acba35: * Release 1.9.3 * Merge commit from fork * Merge commit from fork * Merge commit from fork * Merge commit from fork * Update two vulnerable dependencies - Update to version 1.9.2~git0.6a2bb66bd: * Release 1.9.2 * Allow urlencoded client_id in basic auth (#4141) * Update ldap3 to 0.7.0 toresolve config filter issue (#4205) * Remove thread local storage (#4204) * Disable multithreading on RADIUS when DEBUG is False. (#4177) * Fix bug where DEBUG is always true in RADIUS entrypoint. (#4169) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-192=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 x86_64): kanidm-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 kanidm-clients-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 kanidm-docs-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 kanidm-server-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 kanidm-unixd-clients-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 References: . Critical security update for openSUSE fixing privilege escalation risks in kanidm software. Install promptly to ensure protection.. openSUSE update, kanidm security, privilege escalation, software patch, Linux advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 05, 2026 Critical OpenSUSE
202

openSUSE: 2025:0152-1 moderate update for kanidm openssl security fix

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for kanidm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0152-1 Rating: moderate References: #1242642 Cross-References: CVE-2025-3416 CVSS scores: CVE-2025-3416 (SUSE): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for kanidm fixes the following issues: - Update to version 1.6.2~git0.a20663ea8: * Release 1.6.2 * fix: clippy * maint: typo in log message * Set kid manually to prevent divergence * Order keys in application JWKS / Fix rotation bug * Fix toml issues with strings - Update to version 1.6.1~git0.2e4429eca: * Release 1.6.1 * Resolve reload of oauth2 on startup (#3604) - CVE-2025-3416: Fixed openssl use after free (boo#1242642) - Update to version 1.6.0~git0.d7ae0f336: * Release 1.6.0 * Avoid openssl for md4 * Fixes #3586, inverts the navbar button color (#3593) * Release 1.6.0-pre * chore: Release Notes (#3588) * Do not require instances to exist during optional config load (#3591) * Fix std::fmt::Display for some objects (#3587) * Drop fernet in favour of JWE (#3577) * docs: document how to configure oauth2 for opkssh (#3566) * Add kanidm_ssh_authorizedkeys_direct to client deb (#3585) * Bump the all group in /pykanidm with 2 updates (#3581) * Update dependencies, fix a bunch of clippy lints (#3576) * Support spaces in ssh key comments (#3575) * 20250402 3423 proxy protocol (#3542) * fix(web): Preserve SSH key content on form validation error (#3574) * Bump the all group in /pykanidm with 3updates (#3572) * Bump the all group in /pykanidm with 2 updates (#3564) * Bump crossbeam-channel from 0.5.14 to 0.5.15 in the cargo group (#3560) * Improve token handling (#3553) * Bump tokio from 1.44.1 to 1.44.2 in the cargo group (#3549) * Update fs4 and improve klock handling (#3551) * Less footguns (#3552) * Unify unix config parser (#3533) * Bump openssl from 0.10.71 to 0.10.72 in the cargo group (#3544) * Bump the all group in /pykanidm with 8 updates (#3547) * implement notify-reload protocol (#3540) * Allow versioning of server configs (#3515) * 20250314 remove protected plugin (#3504) * Bump the all group with 10 updates (#3539) * Bump mozilla-actions/sccache-action from 0.0.8 to 0.0.9 in the all group (#3538) * Bump the all group in /pykanidm with 4 updates (#3537) * Add max_ber_size to freeipa sync (#3530) * Bump the all group in /pykanidm with 5 updates (#3524) * Update Concread * Update developer_ethics.md (#3520) * Update examples.md (#3519) * Make schema indexing a boolean instead of index types (#3517) * Add missing lld dependency and fix syntax typo (#3490) * Update shell.nix to work with stable nixpkgs (#3514) * Improve unixd tasks channel comments (#3510) * Update kanidm_ppa_automation reference to latest (#3512) * Add set-description to group tooling (#3511) * packaging: Add kanidmd deb package, update documentation (#3506) * Bump the all group in /pykanidm with 5 updates (#3508) * 20250313 unixd system cache (#3501) * Support rfc2307 memberUid in sync operations. (#3466) * Bump mozilla-actions/sccache-action from 0.0.7 to 0.0.8 in the all group (#3496) * Update Traefik config example to remove invalid label (#3500) * Add uid/gid allocation table (#3498) * 20250225 ldap testing in testkit (#3460) * Bump the all group in /pykanidm with 5 updates (#3494) * Bump ring from 0.17.10 to 0.17.13 in the cargogroup (#3491) * Handle form-post as a response mode (#3467) * book: fix english (#3487) * Correct paths with Kanidm Tools Container (#3486) * 20250225 improve test performance (#3459) * Bump the all group in /pykanidm with 8 updates (#3484) * Use lld by default on linux (#3477) * 20250213 patch used wrong acp (#3432) * Android support (#3475) * Changed all CI/CD builds to locked (#3471) * Make it a bit clearer that providers are needed (#3468) * Fix incorrect credential generation in radius docs (#3465) * Add crypt formats for password import (#3458) * build: Create daemon image from scratch (#3452) * address webfinger doc feedbacks (#3446) * Bump the all group across 1 directory with 5 updates (#3453) * [htmx] Admin ui for groups and users management (#3019) * Fixes #3406: add configurable maximum queryable attributes for LDAP (#3431) * Accept invalid certs and fix token_cache_path (#3439) * Accept lowercase ldap pwd hashes (#3444) * TOTP label verification (#3419) * Rewrite WebFinger docs (#3443) * doc: fix formatting of URL table, remove Caddyfile instructions (#3442) * book: add OAuth2 Proxy example (#3434) * Exempt idm_admin and admin from denied names. (#3429) * Book fixes (#3433) * ci: uniform Docker builds (#3430) * 20240213 3413 domain displayname (#3425) * Correct path to kanidm config example in documentation. (#3424) * Support redirect uris with query parameters (#3422) * Update to 1.6.0-dev (#3418) * Remove white background from square logo. (#3417) * feat: Added webfinger implementation (#3410) * Bump the all group in /pykanidm with 7 updates (#3412) - Update to version 1.5.0~git2.21c2a1bd0: * fix: documentation fail (#3555) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run thecommand listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-152=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 x86_64): kanidm-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-clients-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-clients-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-debugsource-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-docs-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-server-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-server-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-unixd-clients-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-unixd-clients-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 References: https://www.suse.com/security/cve/CVE-2025-3416.html https://bugzilla.suse.com/1242642 . A recent openSUSE patch resolves a notable security flaw in kanidm concerning openssl vulnerabilities.. openSUSE Updates, Kanidm Security, OpenSSL Patch, Linux Security Advisories. . LinuxSecurity.com Team

Calendar%202 May 12, 2025 OpenSUSE
202

openSUSE Tumbleweed: 2025:15060-1 moderate: kanidm 1.6.0 update

An update that solves one vulnerability can now be installed.. # kanidm-1.6.0~git0.d7ae0f336-1.1 on GA media Announcement ID: openSUSE-SU-2025:15060-1 Rating: moderate Cross-References: * CVE-2025-3416 CVSS scores: * CVE-2025-3416 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-3416 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the kanidm-1.6.0~git0.d7ae0f336-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * kanidm 1.6.0~git0.d7ae0f336-1.1 * kanidm-clients 1.6.0~git0.d7ae0f336-1.1 * kanidm-docs 1.6.0~git0.d7ae0f336-1.1 * kanidm-server 1.6.0~git0.d7ae0f336-1.1 * kanidm-unixd-clients 1.6.0~git0.d7ae0f336-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-3416.html . # kanidm-1.6.0~git0.d7ae0f336-1.1 on GA media Announcement ID: openSUSE-SU-2025:15060-1 Rating: mode. update, solves, vulnerability, installed, kanidm-1, 0~git0, d7ae0f336-1. . LinuxSecurity.com Team

Calendar%202 May 08, 2025 OpenSUSE
202

openSUSE: 2024:0294-1 Moderate: Kanidm Security Update Advisory

An update that solves three vulnerabilities and has one errata is now available. . openSUSE Security Update: Security update for kanidm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0294-1 Rating: moderate References: #1191031 #1194119 #1196972 #1210356 Cross-References: CVE-2021-45710 CVE-2022-24713 CVE-2023-26964 CVSS scores: CVE-2021-45710 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVE-2022-24713 (SUSE): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVE-2023-26964 (SUSE): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that solves three vulnerabilities and has one errata is now available. Description: This update for kanidm fixes the following issues: - kanidm version 1.3.3~git0.f075d13: * Release 1.3.3 * Mail substr index (#2981) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2024-294=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 x86_64): kanidm-1.3.3~git0.f075d13-bp156.4.1 kanidm-clients-1.3.3~git0.f075d13-bp156.4.1 kanidm-docs-1.3.3~git0.f075d13-bp156.4.1 kanidm-server-1.3.3~git0.f075d13-bp156.4.1 kanidm-unixd-clients-1.3.3~git0.f075d13-bp156.4.1 References: https://www.suse.com/security/cve/CVE-2021-45710.html https://www.suse.com/security/cve/CVE-2022-24713.html https://www.suse.com/security/cve/CVE-2023-26964.html https://bugzilla.suse.com/1191031 https://bugzilla.suse.com/1194119 https://bugzilla.suse.com/1196972 https://bugzilla.suse.com/1210356 . A security patch resolves flaws in kanidm on openSUSE. Utilize zypper for installation to ensure system upkeep.. openSUSE Updates, Kanidm Security, Linux Security Updates, Patch Instructions. . LinuxSecurity.com Team

Calendar%202 Sep 09, 2024 OpenSUSE
202

openSUSE: 2024:0100-1 Moderate: LibXYZ Memory Leak Resolution

An update that contains security fixes can now be installed. . openSUSE Security Update: Security update for kanidm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0095-1 Rating: moderate References: Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for kanidm fixes the following issues: Update to version 1.1.0~rc16~git6.e51d0de: * [SECURITY: LOW] Administrator triggered thread crash in oauth2 claim maps #2686 (#2686) * return consent map to service account (#2604) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-95=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 x86_64): kanidm-1.1.0~rc16~git6.e51d0de-bp155.14.1 kanidm-clients-1.1.0~rc16~git6.e51d0de-bp155.14.1 kanidm-docs-1.1.0~rc16~git6.e51d0de-bp155.14.1 kanidm-server-1.1.0~rc16~git6.e51d0de-bp155.14.1 kanidm-unixd-clients-1.1.0~rc16~git6.e51d0de-bp155.14.1 References: . openSUSE Security Release for kanidm tackles several moderate vulnerabilities, and detailed installation guidelines are included for applying the patches.. openSUSE Kanidm Patch Instructions Update. . LinuxSecurity.com Team

Calendar%202 Mar 30, 2024 OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200