Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for kanidm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0152-1 Rating: moderate References: #1242642 Cross-References: CVE-2025-3416 CVSS scores: CVE-2025-3416 (SUSE): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for kanidm fixes the following issues: - Update to version 1.6.2~git0.a20663ea8: * Release 1.6.2 * fix: clippy * maint: typo in log message * Set kid manually to prevent divergence * Order keys in application JWKS / Fix rotation bug * Fix toml issues with strings - Update to version 1.6.1~git0.2e4429eca: * Release 1.6.1 * Resolve reload of oauth2 on startup (#3604) - CVE-2025-3416: Fixed openssl use after free (boo#1242642) - Update to version 1.6.0~git0.d7ae0f336: * Release 1.6.0 * Avoid openssl for md4 * Fixes #3586, inverts the navbar button color (#3593) * Release 1.6.0-pre * chore: Release Notes (#3588) * Do not require instances to exist during optional config load (#3591) * Fix std::fmt::Display for some objects (#3587) * Drop fernet in favour of JWE (#3577) * docs: document how to configure oauth2 for opkssh (#3566) * Add kanidm_ssh_authorizedkeys_direct to client deb (#3585) * Bump the all group in /pykanidm with 2 updates (#3581) * Update dependencies, fix a bunch of clippy lints (#3576) * Support spaces in ssh key comments (#3575) * 20250402 3423 proxy protocol (#3542) * fix(web): Preserve SSH key content on form validation error (#3574) * Bump the all group in /pykanidm with 3updates (#3572) * Bump the all group in /pykanidm with 2 updates (#3564) * Bump crossbeam-channel from 0.5.14 to 0.5.15 in the cargo group (#3560) * Improve token handling (#3553) * Bump tokio from 1.44.1 to 1.44.2 in the cargo group (#3549) * Update fs4 and improve klock handling (#3551) * Less footguns (#3552) * Unify unix config parser (#3533) * Bump openssl from 0.10.71 to 0.10.72 in the cargo group (#3544) * Bump the all group in /pykanidm with 8 updates (#3547) * implement notify-reload protocol (#3540) * Allow versioning of server configs (#3515) * 20250314 remove protected plugin (#3504) * Bump the all group with 10 updates (#3539) * Bump mozilla-actions/sccache-action from 0.0.8 to 0.0.9 in the all group (#3538) * Bump the all group in /pykanidm with 4 updates (#3537) * Add max_ber_size to freeipa sync (#3530) * Bump the all group in /pykanidm with 5 updates (#3524) * Update Concread * Update developer_ethics.md (#3520) * Update examples.md (#3519) * Make schema indexing a boolean instead of index types (#3517) * Add missing lld dependency and fix syntax typo (#3490) * Update shell.nix to work with stable nixpkgs (#3514) * Improve unixd tasks channel comments (#3510) * Update kanidm_ppa_automation reference to latest (#3512) * Add set-description to group tooling (#3511) * packaging: Add kanidmd deb package, update documentation (#3506) * Bump the all group in /pykanidm with 5 updates (#3508) * 20250313 unixd system cache (#3501) * Support rfc2307 memberUid in sync operations. (#3466) * Bump mozilla-actions/sccache-action from 0.0.7 to 0.0.8 in the all group (#3496) * Update Traefik config example to remove invalid label (#3500) * Add uid/gid allocation table (#3498) * 20250225 ldap testing in testkit (#3460) * Bump the all group in /pykanidm with 5 updates (#3494) * Bump ring from 0.17.10 to 0.17.13 in the cargogroup (#3491) * Handle form-post as a response mode (#3467) * book: fix english (#3487) * Correct paths with Kanidm Tools Container (#3486) * 20250225 improve test performance (#3459) * Bump the all group in /pykanidm with 8 updates (#3484) * Use lld by default on linux (#3477) * 20250213 patch used wrong acp (#3432) * Android support (#3475) * Changed all CI/CD builds to locked (#3471) * Make it a bit clearer that providers are needed (#3468) * Fix incorrect credential generation in radius docs (#3465) * Add crypt formats for password import (#3458) * build: Create daemon image from scratch (#3452) * address webfinger doc feedbacks (#3446) * Bump the all group across 1 directory with 5 updates (#3453) * [htmx] Admin ui for groups and users management (#3019) * Fixes #3406: add configurable maximum queryable attributes for LDAP (#3431) * Accept invalid certs and fix token_cache_path (#3439) * Accept lowercase ldap pwd hashes (#3444) * TOTP label verification (#3419) * Rewrite WebFinger docs (#3443) * doc: fix formatting of URL table, remove Caddyfile instructions (#3442) * book: add OAuth2 Proxy example (#3434) * Exempt idm_admin and admin from denied names. (#3429) * Book fixes (#3433) * ci: uniform Docker builds (#3430) * 20240213 3413 domain displayname (#3425) * Correct path to kanidm config example in documentation. (#3424) * Support redirect uris with query parameters (#3422) * Update to 1.6.0-dev (#3418) * Remove white background from square logo. (#3417) * feat: Added webfinger implementation (#3410) * Bump the all group in /pykanidm with 7 updates (#3412) - Update to version 1.5.0~git2.21c2a1bd0: * fix: documentation fail (#3555) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run thecommand listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-152=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 x86_64): kanidm-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-clients-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-clients-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-debugsource-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-docs-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-server-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-server-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-unixd-clients-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-unixd-clients-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 References: https://www.suse.com/security/cve/CVE-2025-3416.html https://bugzilla.suse.com/1242642 . Security update for openSUSE kanidm addresses moderate threat from CVE-2025-3416, improving system stability.. openSUSE kanidm security patch moderate CVE-2025-3416 update. . Severity: moderate. LinuxSecurity.com Team
An update that contains security fixes can now be installed.. openSUSE Security Update: Security update for kanidm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0198-1 Rating: critical References: Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for kanidm fixes the following issues: - Update to version 1.10.2~git0.f3dc9ef1f: * Release 1.10.2 * Security - CRITICAL - authenticated user privilege escalation * Refactor modification access paths to remove duplication * Revert ClientID header (#4334) * Disable prompt=login (#4340) * Add missing `/sbin/kanidm-mail-sender` (#4323) * Remove debug symbols in release builds. (#4319) - Update to version 1.10.1~git0.d02660a98: * Release 1.10.1 * Fix copy in TOTP removal prompt and align TOTP case (#4314) * Resolve base64 encoding of webauthn fields (#4312) - Update to version 1.10.0-pre~git1.32e2f8ec6: * Release 1.10.0 * Release 1.10.0-pre * Release notes (#4304) * Update ldap3/webauthn-rs (#4302) * Merge commit from fork * Merge commit from fork * Merge commit from fork * Merge commit from fork * Add notes on server migration (#4301) * 20260517 sparkle (#4280) * Bump mozilla-actions/sccache-action in the all group (#4298) * Bump the all group with 6 updates (#4299) * Bump the all group across 1 directory with 3 updates (#4283) * 20260331 send account recovery emails (#4259) * Update oauth2 well known urls (#4296) * Clippy for Rust 1.95 (#4291) * Invert incorrect thread count logic (#4294) * Allow modification of OAuth2 Refresh Expiry (#4276) * 20260327 Introspection token auth metadata (#4230) * fix: add missingkanidm-mail-sender binary (#4279) * Correctly handle deleted accounts during page visits (#4275) * don't fail auth when passed ui_locales (#4288) * Bump actions/upload-pages-artifact from 4 to 5 in the all group (#4284) * Fix link formatting in oauth2.rs documentation (#4278) * Feat: Add OIDC Prompt Support (#4224) * Handle multivalue URLs in SCIM (#4271) * Correctly encode ssh tag values (#4272) * Bump the all group with 2 updates (#4263) * Bump the all group in /rlm_python with 4 updates (#4262) * Bump the all group with 8 updates (#4264) * Update deployment.md with configuration notes (#4258) * Add .well-known/passkey-endpoints (#4255) * show repl cert metadata and also handle socket timeouts (#4252) * Update docs regarding replication cert lifetime (#4251) * Log cleanup (#4248) * adding timeouts and tests and port docs for mail_sender (#4246) * Bump the all group with 5 updates (#4247) * add dependency data to released containers (#4239) * Fix to end code block and render remaining md correctly (#4241) * Update readme.md for replication (#4236) * Added note on primary email address and email aliases (#4237) * Bump the all group with 6 updates (#4235) * Bump the all group with 2 updates (#4234) * Bump the uv group across 1 directory with 2 updates (#4231) * cli: allow clearing person's legalname attribute (#4228) * Add shell diagnostics (#4220) * OpenSSL shall be vanquished (#4219) * Bump the all group across 1 directory with 16 updates (#4225) * Bump rustls-webpki from 0.103.9 to 0.103.10 (#4223) * Bump flatted (#4222) * Tabular data is tabular (#4221) * Example sshd-config fragment, deployment de-activated on Debian (#4214) * Update RELEASE_NOTES.md (#4215) * fix(debian): Use correct bin path for kanidmd reload (#4212) * Allow urlencoded client_id in basic auth (#4141) * add nsswitch config check to unixd (#4210) * 20260311zxcvbn check (#4206) * Enhance Traefik documentation (#4194) * Re-add incorrectly removed utopia feature flag (#4207) * Update ldap3 to 0.7.0 to resolve config filter issue (#4205) * Added PasswordChangedTime attribute and database field (#3999) * Defer on some routes (#4202) * Remove thread local storage (#4204) * Improve FreeBSD building, fully drop ring as a dependency. * 20260218 credential reset emails (authenticated only) (#4151) * android support for cli (#4197) * Bump the all group with 4 updates (#4198) * Bump the all group with 7 updates (#4199) * feat: bind mount home strategy (#3997) * Bump the all group with 2 updates (#4183) * Bump the all group with 8 updates (#4184) * Bump minimatch (#4180) * Disable multithreading on RADIUS when DEBUG is False. (#4177) * Don't revert admin changes in some groups during migrcation (#4176) * Fix bug where DEBUG is always true in RADIUS entrypoint. (#4169) * 20260220 prevent migration accidents (#4156) * Bump the all group across 1 directory with 20 updates (#4163) * Move the grafana group creation step (#4160) * Alert on unsaved changes (#4155) * pykanidm v1.3.0 - major rewrite to use openapi-generated codebase based on 1.9.0 spec (#4149) * Warn about systemd-userdb (#4147) * Dont require basic auth on token introspection (#4142) * Dont be as upset when migration dir doesnt exist (#4146) * Add AGENTS.md instructions (#4148) * Feature OIDC updated at (#4007) * pykanidm: clarify token use with service accounts (#4043) * Fixed small typo in how_does_oauth2_work.md (#4138) * Bye bye lazy static (#4134) * Allow LDAP CA verification to be disabled in sync (#4133) * Add oauth2 example, fix inter-migration reference handling (#4136) * Add missing future migration in domain check (#4132) * Corrected recycle_bin.md typo (#4135) * 20260211 dev version (#4131) - Update to version1.9.3~git0.7d4108698: * Release 1.9.3 * Security - High: SCIM Filters did not contain a bound on their parsing depth allowing stack exhaustion to occur leading to Denial of Service by an unauthenticated user * Security - Moderate: PNG Image validation did not correctly handle short images allowing a panic to occur in a worker thread. This may lead to system instability over time * Security - Low: HTML injection via user DisplayName in Passkey enrolment dialogs. This allows an admin to execute JS in the context of a users browser. Since the admin already can reset the users credentials, the impact of this is minimal. * Security - Low: non-constant time comparison of OAuth2 client secret may allow a remote attacker to remotely recovery the bytes of the secret. Due to the length of the secret (48 chars) this is infeasible practically. * Security - Low: incorrect handling of origin validation in Webauthn-RS allowed a malicious domain to collide with a valid one (badexample.com would match with example.com). This is mitigated by browsers detecting the forgery and preventing the authentication from proceeding. * Security - High: LDAP Filters did not contain a bound on their parsing depth allowing stack exhaustion to occur leading to Denial of Service by an unauthenticated user. * Update two vulnerable dependencies * Release 1.9.2 * Allow urlencoded client_id in basic auth (#4141) * Update ldap3 to 0.7.0 to resolve config filter issue (#4205) * Remove thread local storage (#4204) - Update to version 1.9.2~git6.896acba35: * Release 1.9.3 * Merge commit from fork * Merge commit from fork * Merge commit from fork * Merge commit from fork * Update two vulnerable dependencies - Update to version 1.9.2~git0.6a2bb66bd: * Release 1.9.2 * Allow urlencoded client_id in basic auth (#4141) * Update ldap3 to 0.7.0 toresolve config filter issue (#4205) * Remove thread local storage (#4204) * Disable multithreading on RADIUS when DEBUG is False. (#4177) * Fix bug where DEBUG is always true in RADIUS entrypoint. (#4169) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2026-198=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 x86_64): kanidm-1.10.2~git0.f3dc9ef1f-bp156.64.1 kanidm-clients-1.10.2~git0.f3dc9ef1f-bp156.64.1 kanidm-docs-1.10.2~git0.f3dc9ef1f-bp156.64.1 kanidm-server-1.10.2~git0.f3dc9ef1f-bp156.64.1 kanidm-unixd-clients-1.10.2~git0.f3dc9ef1f-bp156.64.1 References: . Critical security update for kanidm on openSUSE prevents privilege escalation and enhances stability.. openSUSE kanidm critical update privilege escalation. . Severity: Critical. LinuxSecurity.com Team
An update that contains security fixes can now be installed.. openSUSE Security Update: Security update for kanidm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0192-1 Rating: critical References: Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for kanidm fixes the following issues: - Update to version 1.10.2~git0.f3dc9ef1f: * Release 1.10.2 * Security - CRITICAL - authenticated user privilege escalation * Refactor modification access paths to remove duplication * Revert ClientID header (#4334) * Disable prompt=login (#4340) * Add missing `/sbin/kanidm-mail-sender` (#4323) * Remove debug symbols in release builds. (#4319) - Update to version 1.10.1~git0.d02660a98: * Release 1.10.1 * Fix copy in TOTP removal prompt and align TOTP case (#4314) * Resolve base64 encoding of webauthn fields (#4312) - Update to version 1.10.0-pre~git1.32e2f8ec6: * Release 1.10.0 * Release 1.10.0-pre * Release notes (#4304) * Update ldap3/webauthn-rs (#4302) * Merge commit from fork * Merge commit from fork * Merge commit from fork * Merge commit from fork * Add notes on server migration (#4301) * 20260517 sparkle (#4280) * Bump mozilla-actions/sccache-action in the all group (#4298) * Bump the all group with 6 updates (#4299) * Bump the all group across 1 directory with 3 updates (#4283) * 20260331 send account recovery emails (#4259) * Update oauth2 well known urls (#4296) * Clippy for Rust 1.95 (#4291) * Invert incorrect thread count logic (#4294) * Allow modification of OAuth2 Refresh Expiry (#4276) * 20260327 Introspection token auth metadata (#4230) * fix: add missingkanidm-mail-sender binary (#4279) * Correctly handle deleted accounts during page visits (#4275) * don't fail auth when passed ui_locales (#4288) * Bump actions/upload-pages-artifact from 4 to 5 in the all group (#4284) * Fix link formatting in oauth2.rs documentation (#4278) * Feat: Add OIDC Prompt Support (#4224) * Handle multivalue URLs in SCIM (#4271) * Correctly encode ssh tag values (#4272) * Bump the all group with 2 updates (#4263) * Bump the all group in /rlm_python with 4 updates (#4262) * Bump the all group with 8 updates (#4264) * Update deployment.md with configuration notes (#4258) * Add .well-known/passkey-endpoints (#4255) * show repl cert metadata and also handle socket timeouts (#4252) * Update docs regarding replication cert lifetime (#4251) * Log cleanup (#4248) * adding timeouts and tests and port docs for mail_sender (#4246) * Bump the all group with 5 updates (#4247) * add dependency data to released containers (#4239) * Fix to end code block and render remaining md correctly (#4241) * Update readme.md for replication (#4236) * Added note on primary email address and email aliases (#4237) * Bump the all group with 6 updates (#4235) * Bump the all group with 2 updates (#4234) * Bump the uv group across 1 directory with 2 updates (#4231) * cli: allow clearing person's legalname attribute (#4228) * Add shell diagnostics (#4220) * OpenSSL shall be vanquished (#4219) * Bump the all group across 1 directory with 16 updates (#4225) * Bump rustls-webpki from 0.103.9 to 0.103.10 (#4223) * Bump flatted (#4222) * Tabular data is tabular (#4221) * Example sshd-config fragment, deployment de-activated on Debian (#4214) * Update RELEASE_NOTES.md (#4215) * fix(debian): Use correct bin path for kanidmd reload (#4212) * Allow urlencoded client_id in basic auth (#4141) * add nsswitch config check to unixd (#4210) * 20260311zxcvbn check (#4206) * Enhance Traefik documentation (#4194) * Re-add incorrectly removed utopia feature flag (#4207) * Update ldap3 to 0.7.0 to resolve config filter issue (#4205) * Added PasswordChangedTime attribute and database field (#3999) * Defer on some routes (#4202) * Remove thread local storage (#4204) * Improve FreeBSD building, fully drop ring as a dependency. * 20260218 credential reset emails (authenticated only) (#4151) * android support for cli (#4197) * Bump the all group with 4 updates (#4198) * Bump the all group with 7 updates (#4199) * feat: bind mount home strategy (#3997) * Bump the all group with 2 updates (#4183) * Bump the all group with 8 updates (#4184) * Bump minimatch (#4180) * Disable multithreading on RADIUS when DEBUG is False. (#4177) * Don't revert admin changes in some groups during migrcation (#4176) * Fix bug where DEBUG is always true in RADIUS entrypoint. (#4169) * 20260220 prevent migration accidents (#4156) * Bump the all group across 1 directory with 20 updates (#4163) * Move the grafana group creation step (#4160) * Alert on unsaved changes (#4155) * pykanidm v1.3.0 - major rewrite to use openapi-generated codebase based on 1.9.0 spec (#4149) * Warn about systemd-userdb (#4147) * Dont require basic auth on token introspection (#4142) * Dont be as upset when migration dir doesnt exist (#4146) * Add AGENTS.md instructions (#4148) * Feature OIDC updated at (#4007) * pykanidm: clarify token use with service accounts (#4043) * Fixed small typo in how_does_oauth2_work.md (#4138) * Bye bye lazy static (#4134) * Allow LDAP CA verification to be disabled in sync (#4133) * Add oauth2 example, fix inter-migration reference handling (#4136) * Add missing future migration in domain check (#4132) * Corrected recycle_bin.md typo (#4135) * 20260211 dev version (#4131) - Update to version1.9.3~git0.7d4108698: * Release 1.9.3 * Security - High: SCIM Filters did not contain a bound on their parsing depth allowing stack exhaustion to occur leading to Denial of Service by an unauthenticated user * Security - Moderate: PNG Image validation did not correctly handle short images allowing a panic to occur in a worker thread. This may lead to system instability over time * Security - Low: HTML injection via user DisplayName in Passkey enrolment dialogs. This allows an admin to execute JS in the context of a users browser. Since the admin already can reset the users credentials, the impact of this is minimal. * Security - Low: non-constant time comparison of OAuth2 client secret may allow a remote attacker to remotely recovery the bytes of the secret. Due to the length of the secret (48 chars) this is infeasible practically. * Security - Low: incorrect handling of origin validation in Webauthn-RS allowed a malicious domain to collide with a valid one (badexample.com would match with example.com). This is mitigated by browsers detecting the forgery and preventing the authentication from proceeding. * Security - High: LDAP Filters did not contain a bound on their parsing depth allowing stack exhaustion to occur leading to Denial of Service by an unauthenticated user. * Update two vulnerable dependencies * Release 1.9.2 * Allow urlencoded client_id in basic auth (#4141) * Update ldap3 to 0.7.0 to resolve config filter issue (#4205) * Remove thread local storage (#4204) - Update to version 1.9.2~git6.896acba35: * Release 1.9.3 * Merge commit from fork * Merge commit from fork * Merge commit from fork * Merge commit from fork * Update two vulnerable dependencies - Update to version 1.9.2~git0.6a2bb66bd: * Release 1.9.2 * Allow urlencoded client_id in basic auth (#4141) * Update ldap3 to 0.7.0 toresolve config filter issue (#4205) * Remove thread local storage (#4204) * Disable multithreading on RADIUS when DEBUG is False. (#4177) * Fix bug where DEBUG is always true in RADIUS entrypoint. (#4169) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-192=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 x86_64): kanidm-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 kanidm-clients-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 kanidm-docs-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 kanidm-server-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 kanidm-unixd-clients-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 References: . Security update for kanidm on openSUSE addresses critical privilege escalation issues and other vulnerabilities.. openSUSE kanidm security update critical vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
An update that contains security fixes can now be installed.. openSUSE Security Update: Security update for kanidm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0192-1 Rating: critical References: Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for kanidm fixes the following issues: - Update to version 1.10.2~git0.f3dc9ef1f: * Release 1.10.2 * Security - CRITICAL - authenticated user privilege escalation * Refactor modification access paths to remove duplication * Revert ClientID header (#4334) * Disable prompt=login (#4340) * Add missing `/sbin/kanidm-mail-sender` (#4323) * Remove debug symbols in release builds. (#4319) - Update to version 1.10.1~git0.d02660a98: * Release 1.10.1 * Fix copy in TOTP removal prompt and align TOTP case (#4314) * Resolve base64 encoding of webauthn fields (#4312) - Update to version 1.10.0-pre~git1.32e2f8ec6: * Release 1.10.0 * Release 1.10.0-pre * Release notes (#4304) * Update ldap3/webauthn-rs (#4302) * Merge commit from fork * Merge commit from fork * Merge commit from fork * Merge commit from fork * Add notes on server migration (#4301) * 20260517 sparkle (#4280) * Bump mozilla-actions/sccache-action in the all group (#4298) * Bump the all group with 6 updates (#4299) * Bump the all group across 1 directory with 3 updates (#4283) * 20260331 send account recovery emails (#4259) * Update oauth2 well known urls (#4296) * Clippy for Rust 1.95 (#4291) * Invert incorrect thread count logic (#4294) * Allow modification of OAuth2 Refresh Expiry (#4276) * 20260327 Introspection token auth metadata (#4230) * fix: add missingkanidm-mail-sender binary (#4279) * Correctly handle deleted accounts during page visits (#4275) * don't fail auth when passed ui_locales (#4288) * Bump actions/upload-pages-artifact from 4 to 5 in the all group (#4284) * Fix link formatting in oauth2.rs documentation (#4278) * Feat: Add OIDC Prompt Support (#4224) * Handle multivalue URLs in SCIM (#4271) * Correctly encode ssh tag values (#4272) * Bump the all group with 2 updates (#4263) * Bump the all group in /rlm_python with 4 updates (#4262) * Bump the all group with 8 updates (#4264) * Update deployment.md with configuration notes (#4258) * Add .well-known/passkey-endpoints (#4255) * show repl cert metadata and also handle socket timeouts (#4252) * Update docs regarding replication cert lifetime (#4251) * Log cleanup (#4248) * adding timeouts and tests and port docs for mail_sender (#4246) * Bump the all group with 5 updates (#4247) * add dependency data to released containers (#4239) * Fix to end code block and render remaining md correctly (#4241) * Update readme.md for replication (#4236) * Added note on primary email address and email aliases (#4237) * Bump the all group with 6 updates (#4235) * Bump the all group with 2 updates (#4234) * Bump the uv group across 1 directory with 2 updates (#4231) * cli: allow clearing person's legalname attribute (#4228) * Add shell diagnostics (#4220) * OpenSSL shall be vanquished (#4219) * Bump the all group across 1 directory with 16 updates (#4225) * Bump rustls-webpki from 0.103.9 to 0.103.10 (#4223) * Bump flatted (#4222) * Tabular data is tabular (#4221) * Example sshd-config fragment, deployment de-activated on Debian (#4214) * Update RELEASE_NOTES.md (#4215) * fix(debian): Use correct bin path for kanidmd reload (#4212) * Allow urlencoded client_id in basic auth (#4141) * add nsswitch config check to unixd (#4210) * 20260311zxcvbn check (#4206) * Enhance Traefik documentation (#4194) * Re-add incorrectly removed utopia feature flag (#4207) * Update ldap3 to 0.7.0 to resolve config filter issue (#4205) * Added PasswordChangedTime attribute and database field (#3999) * Defer on some routes (#4202) * Remove thread local storage (#4204) * Improve FreeBSD building, fully drop ring as a dependency. * 20260218 credential reset emails (authenticated only) (#4151) * android support for cli (#4197) * Bump the all group with 4 updates (#4198) * Bump the all group with 7 updates (#4199) * feat: bind mount home strategy (#3997) * Bump the all group with 2 updates (#4183) * Bump the all group with 8 updates (#4184) * Bump minimatch (#4180) * Disable multithreading on RADIUS when DEBUG is False. (#4177) * Don't revert admin changes in some groups during migrcation (#4176) * Fix bug where DEBUG is always true in RADIUS entrypoint. (#4169) * 20260220 prevent migration accidents (#4156) * Bump the all group across 1 directory with 20 updates (#4163) * Move the grafana group creation step (#4160) * Alert on unsaved changes (#4155) * pykanidm v1.3.0 - major rewrite to use openapi-generated codebase based on 1.9.0 spec (#4149) * Warn about systemd-userdb (#4147) * Dont require basic auth on token introspection (#4142) * Dont be as upset when migration dir doesnt exist (#4146) * Add AGENTS.md instructions (#4148) * Feature OIDC updated at (#4007) * pykanidm: clarify token use with service accounts (#4043) * Fixed small typo in how_does_oauth2_work.md (#4138) * Bye bye lazy static (#4134) * Allow LDAP CA verification to be disabled in sync (#4133) * Add oauth2 example, fix inter-migration reference handling (#4136) * Add missing future migration in domain check (#4132) * Corrected recycle_bin.md typo (#4135) * 20260211 dev version (#4131) - Update to version1.9.3~git0.7d4108698: * Release 1.9.3 * Security - High: SCIM Filters did not contain a bound on their parsing depth allowing stack exhaustion to occur leading to Denial of Service by an unauthenticated user * Security - Moderate: PNG Image validation did not correctly handle short images allowing a panic to occur in a worker thread. This may lead to system instability over time * Security - Low: HTML injection via user DisplayName in Passkey enrolment dialogs. This allows an admin to execute JS in the context of a users browser. Since the admin already can reset the users credentials, the impact of this is minimal. * Security - Low: non-constant time comparison of OAuth2 client secret may allow a remote attacker to remotely recovery the bytes of the secret. Due to the length of the secret (48 chars) this is infeasible practically. * Security - Low: incorrect handling of origin validation in Webauthn-RS allowed a malicious domain to collide with a valid one (badexample.com would match with example.com). This is mitigated by browsers detecting the forgery and preventing the authentication from proceeding. * Security - High: LDAP Filters did not contain a bound on their parsing depth allowing stack exhaustion to occur leading to Denial of Service by an unauthenticated user. * Update two vulnerable dependencies * Release 1.9.2 * Allow urlencoded client_id in basic auth (#4141) * Update ldap3 to 0.7.0 to resolve config filter issue (#4205) * Remove thread local storage (#4204) - Update to version 1.9.2~git6.896acba35: * Release 1.9.3 * Merge commit from fork * Merge commit from fork * Merge commit from fork * Merge commit from fork * Update two vulnerable dependencies - Update to version 1.9.2~git0.6a2bb66bd: * Release 1.9.2 * Allow urlencoded client_id in basic auth (#4141) * Update ldap3 to 0.7.0 toresolve config filter issue (#4205) * Remove thread local storage (#4204) * Disable multithreading on RADIUS when DEBUG is False. (#4177) * Fix bug where DEBUG is always true in RADIUS entrypoint. (#4169) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-192=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 x86_64): kanidm-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 kanidm-clients-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 kanidm-docs-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 kanidm-server-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 kanidm-unixd-clients-1.10.2~git0.f3dc9ef1f-bp157.2.32.1 References: . Critical security update for openSUSE fixing privilege escalation risks in kanidm software. Install promptly to ensure protection.. openSUSE update, kanidm security, privilege escalation, software patch, Linux advisory. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for kanidm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0152-1 Rating: moderate References: #1242642 Cross-References: CVE-2025-3416 CVSS scores: CVE-2025-3416 (SUSE): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for kanidm fixes the following issues: - Update to version 1.6.2~git0.a20663ea8: * Release 1.6.2 * fix: clippy * maint: typo in log message * Set kid manually to prevent divergence * Order keys in application JWKS / Fix rotation bug * Fix toml issues with strings - Update to version 1.6.1~git0.2e4429eca: * Release 1.6.1 * Resolve reload of oauth2 on startup (#3604) - CVE-2025-3416: Fixed openssl use after free (boo#1242642) - Update to version 1.6.0~git0.d7ae0f336: * Release 1.6.0 * Avoid openssl for md4 * Fixes #3586, inverts the navbar button color (#3593) * Release 1.6.0-pre * chore: Release Notes (#3588) * Do not require instances to exist during optional config load (#3591) * Fix std::fmt::Display for some objects (#3587) * Drop fernet in favour of JWE (#3577) * docs: document how to configure oauth2 for opkssh (#3566) * Add kanidm_ssh_authorizedkeys_direct to client deb (#3585) * Bump the all group in /pykanidm with 2 updates (#3581) * Update dependencies, fix a bunch of clippy lints (#3576) * Support spaces in ssh key comments (#3575) * 20250402 3423 proxy protocol (#3542) * fix(web): Preserve SSH key content on form validation error (#3574) * Bump the all group in /pykanidm with 3updates (#3572) * Bump the all group in /pykanidm with 2 updates (#3564) * Bump crossbeam-channel from 0.5.14 to 0.5.15 in the cargo group (#3560) * Improve token handling (#3553) * Bump tokio from 1.44.1 to 1.44.2 in the cargo group (#3549) * Update fs4 and improve klock handling (#3551) * Less footguns (#3552) * Unify unix config parser (#3533) * Bump openssl from 0.10.71 to 0.10.72 in the cargo group (#3544) * Bump the all group in /pykanidm with 8 updates (#3547) * implement notify-reload protocol (#3540) * Allow versioning of server configs (#3515) * 20250314 remove protected plugin (#3504) * Bump the all group with 10 updates (#3539) * Bump mozilla-actions/sccache-action from 0.0.8 to 0.0.9 in the all group (#3538) * Bump the all group in /pykanidm with 4 updates (#3537) * Add max_ber_size to freeipa sync (#3530) * Bump the all group in /pykanidm with 5 updates (#3524) * Update Concread * Update developer_ethics.md (#3520) * Update examples.md (#3519) * Make schema indexing a boolean instead of index types (#3517) * Add missing lld dependency and fix syntax typo (#3490) * Update shell.nix to work with stable nixpkgs (#3514) * Improve unixd tasks channel comments (#3510) * Update kanidm_ppa_automation reference to latest (#3512) * Add set-description to group tooling (#3511) * packaging: Add kanidmd deb package, update documentation (#3506) * Bump the all group in /pykanidm with 5 updates (#3508) * 20250313 unixd system cache (#3501) * Support rfc2307 memberUid in sync operations. (#3466) * Bump mozilla-actions/sccache-action from 0.0.7 to 0.0.8 in the all group (#3496) * Update Traefik config example to remove invalid label (#3500) * Add uid/gid allocation table (#3498) * 20250225 ldap testing in testkit (#3460) * Bump the all group in /pykanidm with 5 updates (#3494) * Bump ring from 0.17.10 to 0.17.13 in the cargogroup (#3491) * Handle form-post as a response mode (#3467) * book: fix english (#3487) * Correct paths with Kanidm Tools Container (#3486) * 20250225 improve test performance (#3459) * Bump the all group in /pykanidm with 8 updates (#3484) * Use lld by default on linux (#3477) * 20250213 patch used wrong acp (#3432) * Android support (#3475) * Changed all CI/CD builds to locked (#3471) * Make it a bit clearer that providers are needed (#3468) * Fix incorrect credential generation in radius docs (#3465) * Add crypt formats for password import (#3458) * build: Create daemon image from scratch (#3452) * address webfinger doc feedbacks (#3446) * Bump the all group across 1 directory with 5 updates (#3453) * [htmx] Admin ui for groups and users management (#3019) * Fixes #3406: add configurable maximum queryable attributes for LDAP (#3431) * Accept invalid certs and fix token_cache_path (#3439) * Accept lowercase ldap pwd hashes (#3444) * TOTP label verification (#3419) * Rewrite WebFinger docs (#3443) * doc: fix formatting of URL table, remove Caddyfile instructions (#3442) * book: add OAuth2 Proxy example (#3434) * Exempt idm_admin and admin from denied names. (#3429) * Book fixes (#3433) * ci: uniform Docker builds (#3430) * 20240213 3413 domain displayname (#3425) * Correct path to kanidm config example in documentation. (#3424) * Support redirect uris with query parameters (#3422) * Update to 1.6.0-dev (#3418) * Remove white background from square logo. (#3417) * feat: Added webfinger implementation (#3410) * Bump the all group in /pykanidm with 7 updates (#3412) - Update to version 1.5.0~git2.21c2a1bd0: * fix: documentation fail (#3555) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run thecommand listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-152=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 x86_64): kanidm-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-clients-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-clients-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-debugsource-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-docs-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-server-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-server-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-unixd-clients-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-unixd-clients-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 References: https://www.suse.com/security/cve/CVE-2025-3416.html https://bugzilla.suse.com/1242642 . A recent openSUSE patch resolves a notable security flaw in kanidm concerning openssl vulnerabilities.. openSUSE Updates, Kanidm Security, OpenSSL Patch, Linux Security Advisories. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # kanidm-1.6.0~git0.d7ae0f336-1.1 on GA media Announcement ID: openSUSE-SU-2025:15060-1 Rating: moderate Cross-References: * CVE-2025-3416 CVSS scores: * CVE-2025-3416 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-3416 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the kanidm-1.6.0~git0.d7ae0f336-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * kanidm 1.6.0~git0.d7ae0f336-1.1 * kanidm-clients 1.6.0~git0.d7ae0f336-1.1 * kanidm-docs 1.6.0~git0.d7ae0f336-1.1 * kanidm-server 1.6.0~git0.d7ae0f336-1.1 * kanidm-unixd-clients 1.6.0~git0.d7ae0f336-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-3416.html . # kanidm-1.6.0~git0.d7ae0f336-1.1 on GA media Announcement ID: openSUSE-SU-2025:15060-1 Rating: mode. update, solves, vulnerability, installed, kanidm-1, 0~git0, d7ae0f336-1. . LinuxSecurity.com Team
An update that solves three vulnerabilities and has one errata is now available. . openSUSE Security Update: Security update for kanidm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0294-1 Rating: moderate References: #1191031 #1194119 #1196972 #1210356 Cross-References: CVE-2021-45710 CVE-2022-24713 CVE-2023-26964 CVSS scores: CVE-2021-45710 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVE-2022-24713 (SUSE): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVE-2023-26964 (SUSE): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that solves three vulnerabilities and has one errata is now available. Description: This update for kanidm fixes the following issues: - kanidm version 1.3.3~git0.f075d13: * Release 1.3.3 * Mail substr index (#2981) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2024-294=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 x86_64): kanidm-1.3.3~git0.f075d13-bp156.4.1 kanidm-clients-1.3.3~git0.f075d13-bp156.4.1 kanidm-docs-1.3.3~git0.f075d13-bp156.4.1 kanidm-server-1.3.3~git0.f075d13-bp156.4.1 kanidm-unixd-clients-1.3.3~git0.f075d13-bp156.4.1 References: https://www.suse.com/security/cve/CVE-2021-45710.html https://www.suse.com/security/cve/CVE-2022-24713.html https://www.suse.com/security/cve/CVE-2023-26964.html https://bugzilla.suse.com/1191031 https://bugzilla.suse.com/1194119 https://bugzilla.suse.com/1196972 https://bugzilla.suse.com/1210356 . A security patch resolves flaws in kanidm on openSUSE. Utilize zypper for installation to ensure system upkeep.. openSUSE Updates, Kanidm Security, Linux Security Updates, Patch Instructions. . LinuxSecurity.com Team
An update that contains security fixes can now be installed. . openSUSE Security Update: Security update for kanidm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0095-1 Rating: moderate References: Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for kanidm fixes the following issues: Update to version 1.1.0~rc16~git6.e51d0de: * [SECURITY: LOW] Administrator triggered thread crash in oauth2 claim maps #2686 (#2686) * return consent map to service account (#2604) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-95=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 x86_64): kanidm-1.1.0~rc16~git6.e51d0de-bp155.14.1 kanidm-clients-1.1.0~rc16~git6.e51d0de-bp155.14.1 kanidm-docs-1.1.0~rc16~git6.e51d0de-bp155.14.1 kanidm-server-1.1.0~rc16~git6.e51d0de-bp155.14.1 kanidm-unixd-clients-1.1.0~rc16~git6.e51d0de-bp155.14.1 References: . openSUSE Security Release for kanidm tackles several moderate vulnerabilities, and detailed installation guidelines are included for applying the patches.. openSUSE Kanidm Patch Instructions Update. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.