Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves two vulnerabilities, contains one feature and has three fixes can now be installed.. # Security update for systemd Announcement ID: SUSE-SU-2026:20998-1 Release Date: 2026-04-07T15:10:12Z Rating: important References: * bsc#1255326 * bsc#1258344 * bsc#1259418 * bsc#1259650 * bsc#1259697 * jsc#PED-14853 Cross-References: * CVE-2026-29111 * CVE-2026-4105 CVSS scores: * CVE-2026-29111 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-29111 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-29111 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4105 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-4105 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4105 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that solves two vulnerabilities, contains one feature and has three fixes can now be installed. ## Description: This update for systemd fixes the following issues: Update to systemd v257.13: Security issues: * CVE-2026-4105: privilege escalation due to improper access control in RegisterMachine D-Bus method (bsc#1259650). * CVE-2026-29111: local unprivileged user can trigger an assert in systemd (bsc#1259418). * udev: local root execution via malicious hardware devices and unsanitized kernel output (bsc#1259697). Non security issues: * Avoid shipping (empty) directories and ghost files in /var (jsc#PED-14853). * Sign systemd-boot EFI binary on aarch64 (bsc#1258344) * terminal-util: stop doing 0/upper bound check in tty_is_vc() (bsc#1255326) Changelog: * 6941d92dc2 machined: reject invalid class types when registering machines (bsc#1259650 CVE-2026-4105) * 03bb697b8d udev: check for invalid chars in various fields received from the kernel(bsc#1259697) * 54588d2ded core: validate input cgroup path more prudently (bsc#1259418 CVE-2026-29111) * fb9d92682b terminal-util: stop doing 0/upper bound check in tty_is_vc() (bsc#1255326) For a complete list of changes, visit: ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-485=1 ## Package List: * SUSE Linux Micro Extras 6.2 (aarch64 ppc64le s390x x86_64) * systemd-debuginfo-257.13-160000.1.1 * systemd-devel-257.13-160000.1.1 * systemd-debugsource-257.13-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-29111.html * https://www.suse.com/security/cve/CVE-2026-4105.html * https://bugzilla.suse.com/show_bug.cgi?id=1255326 * https://bugzilla.suse.com/show_bug.cgi?id=1258344 * https://bugzilla.suse.com/show_bug.cgi?id=1259418 * https://bugzilla.suse.com/show_bug.cgi?id=1259650 * https://bugzilla.suse.com/show_bug.cgi?id=1259697 * https://jira.suse.com/browse/PED-14853 . SUSE updates systemd to fix privilege escalation issues and more for Linux Micro 6.2.. SUSE systemd update important security. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities, contains one feature and has three fixes can now be installed.. # Security update for systemd Announcement ID: SUSE-SU-2026:21003-1 Release Date: 2026-04-07T15:08:39Z Rating: important References: * bsc#1255326 * bsc#1258344 * bsc#1259418 * bsc#1259650 * bsc#1259697 * jsc#PED-14853 Cross-References: * CVE-2026-29111 * CVE-2026-4105 CVSS scores: * CVE-2026-29111 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-29111 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-29111 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4105 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-4105 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4105 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities, contains one feature and has three fixes can now be installed. ## Description: This update for systemd fixes the following issues: Update to systemd v257.13: Security issues: * CVE-2026-4105: privilege escalation due to improper access control in RegisterMachine D-Bus method (bsc#1259650). * CVE-2026-29111: local unprivileged user can trigger an assert in systemd (bsc#1259418). * udev: local root execution via malicious hardware devices and unsanitized kernel output (bsc#1259697). Non security issues: * Avoid shipping (empty) directories and ghost files in /var (jsc#PED-14853). * Sign systemd-boot EFI binary on aarch64 (bsc#1258344) * terminal-util: stop doing 0/upper bound check in tty_is_vc() (bsc#1255326) Changelog: * 6941d92dc2 machined: reject invalid class types when registering machines (bsc#1259650 CVE-2026-4105) * 03bb697b8d udev: check for invalid chars in various fields received from the kernel (bsc#1259697) * 54588d2ded core:validate input cgroup path more prudently (bsc#1259418 CVE-2026-29111) * fb9d92682b terminal-util: stop doing 0/upper bound check in tty_is_vc() (bsc#1255326) For a complete list of changes, visit: ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-485=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * systemd-portable-257.13-160000.1.1 * libsystemd0-debuginfo-257.13-160000.1.1 * libsystemd0-257.13-160000.1.1 * udev-257.13-160000.1.1 * systemd-debugsource-257.13-160000.1.1 * libudev1-debuginfo-257.13-160000.1.1 * systemd-container-257.13-160000.1.1 * systemd-experimental-debuginfo-257.13-160000.1.1 * udev-debuginfo-257.13-160000.1.1 * systemd-experimental-257.13-160000.1.1 * systemd-container-debuginfo-257.13-160000.1.1 * systemd-journal-remote-257.13-160000.1.1 * systemd-portable-debuginfo-257.13-160000.1.1 * systemd-journal-remote-debuginfo-257.13-160000.1.1 * systemd-debuginfo-257.13-160000.1.1 * systemd-257.13-160000.1.1 * libudev1-257.13-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-29111.html * https://www.suse.com/security/cve/CVE-2026-4105.html * https://bugzilla.suse.com/show_bug.cgi?id=1255326 * https://bugzilla.suse.com/show_bug.cgi?id=1258344 * https://bugzilla.suse.com/show_bug.cgi?id=1259418 * https://bugzilla.suse.com/show_bug.cgi?id=1259650 * https://bugzilla.suse.com/show_bug.cgi?id=1259697 * https://jira.suse.com/browse/PED-14853 . An important update for SUSE systemd fixes security flaws allowing privilege escalation and local execution risks.. SUSE Linux systemd update privilege escalation security. . Severity: Important.LinuxSecurity.com Team
* bsc#1247582 * bsc#1248117 * bsc#1248330 Cross-References: . # Security update for tiff Announcement ID: SUSE-SU-2025:03345-1 Release Date: 2025-09-24T13:56:00Z Rating: low References: * bsc#1247582 * bsc#1248117 * bsc#1248330 Cross-References: * CVE-2025-8534 * CVE-2025-8961 * CVE-2025-9165 CVSS scores: * CVE-2025-8534 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-8534 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-8534 ( NVD ): 1.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8534 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-8961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-8961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-8961 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8961 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-9165 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-9165 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-9165 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-9165 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for tiff fixes the following issues: * CVE-2025-9165: local execution manipulation leading to memory leak (bsc#1248330). * CVE-2025-8534: null pointer dereference in function PS_Lvl2page (bsc#1247582). * CVE-2025-8961: segmentation fault via main function of tiffcrop utility (bsc#1248117). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3345=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3345=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3345=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3345=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-3345=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-3345=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-3345=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-3345=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-3345=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) *libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 * Basesystem Module 15-SP6 (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.55.1 * libtiff5-32bit-4.0.9-150000.45.55.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 * Basesystem Module 15-SP7 (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.55.1 * libtiff5-32bit-4.0.9-150000.45.55.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 * SUSELinux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 ## References: * https://www.suse.com/security/cve/CVE-2025-8534.html * https://www.suse.com/security/cve/CVE-2025-8961.html * https://www.suse.com/security/cve/CVE-2025-9165.html * https://bugzilla.suse.com/show_bug.cgi?id=1247582 * https://bugzilla.suse.com/show_bug.cgi?id=1248117 * https://bugzilla.suse.com/show_bug.cgi?id=1248330 . New release for tiff addresses several problems such as memory corruption and crash issues on SUSE platforms. Installation is advised.. SUSE update TIFF memory leak segmentation fault. . Severity: Low. LinuxSecurity.com Team
Marcin Nowak discovered that dbclient(1) hostname arguments with a comma (for multihop) are passed to the shell which could result in running arbitrary shell commands locally. That could be a security issue in situations where dbclient(1) is passed untrusted hostname arguments. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4169-1
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libnl-1_1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3207-1 Rating: moderate References: #1020123 Cross-References: CVE-2017-0386 CVSS scores: CVE-2017-0386 (NVD) : 7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2017-0386 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libnl-1_1 fixes the following issues: - CVE-2017-0386: Fixed an issue that could enable a local malicious application to execute arbitrary code within the context of a different process. This only affects setups were libnl is passed untrusted arguments. (bsc#1020123) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-3207=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-3207=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libnl-1_1-debugsource-1.1.4-6.3.1 libnl-1_1-devel-1.1.4-6.3.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libnl-1_1-debugsource-1.1.4-6.3.1 libnl1-1.1.4-6.3.1 libnl1-debuginfo-1.1.4-6.3.1 - SUSE Linux EnterpriseServer 12-SP5 (s390x x86_64): libnl1-32bit-1.1.4-6.3.1 libnl1-debuginfo-32bit-1.1.4-6.3.1 References: https://www.suse.com/security/cve/CVE-2017-0386.html https://bugzilla.suse.com/1020123 . Patch for libnl-1_1 resolves localized execution flaws in SUSE 12-SP5, mitigating arbitrary code execution dangers.. SUSE Update, libnl Security, Local Execution Fix, Security Patch. . Severity: Important. LinuxSecurity.com Team
needrestart could be made to run programs.. =========================================================================Ubuntu Security Notice USN-5426-1 May 17, 2022 needrestart vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 21.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: needrestart could be made to run programs. Software Description: - needrestart: check which daemons need to be restarted after library upgrades Details: Jakub Wilk discovered that needrestart incorrectly used some regular expressions. A local attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: needrestart 3.5-5ubuntu2.1 Ubuntu 21.10: needrestart 3.5-4ubuntu2.1 Ubuntu 20.04 LTS: needrestart 3.4-6ubuntu0.1 Ubuntu 18.04 LTS: needrestart 3.1-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5426-1 CVE-2022-30688 Package Information: https://launchpad.net/ubuntu/+source/needrestart/3.5-5ubuntu2.1 https://launchpad.net/ubuntu/+source/needrestart/3.5-4ubuntu2.1 https://launchpad.net/ubuntu/+source/needrestart/3.4-6ubuntu0.1 https://launchpad.net/ubuntu/+source/needrestart/3.1-1ubuntu0.1 . Critical notice for Ubuntu users concerning the needrestart flaw that permits local exploits to run unauthorized applications.. Needrestart Vulnerability, Local Execution Risk, Ubuntu Security Notice. . Severity: Critical. LinuxSecurity.com Team
An insecure temporary file usage has been reported in libqb possibly allowing local code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202107-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: libqb: Insecure temporary file Date: July 03, 2021 Bugs: #699860 ID: 202107-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An insecure temporary file usage has been reported in libqb possibly allowing local code execution. Background ========= libqb is a library with the primary purpose of providing high-performance, reusable features for client-server architecture, such as logging, tracing, inter-process communication (IPC), and polling. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-cluster/libqb < 1.0.5 > = 1.0.5 Description ========== It was discovered that libqb used predictable filenames (under /dev/shm and /tmp) without O_EXCL. Impact ===== A local attacker could perform symlink attacks to overwrite arbitrary files with the privileges of the user running the application linked against libqb. Workaround ========= There is no known workaround at this time. Resolution ========= All libqb users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-cluster/libqb-1.0.5" References ========= [ 1 ] CVE-2019-12779 https://nvd.nist.gov/vuln/detail/CVE-2019-12779 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo SecurityWebsite: https://security.gentoo.org/glsa/202107-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context (CVE-2021-3410). References: - https://bugs.mageia.org/show_bug.cgi?id=28556 . MGASA-2021-0128 - Updated libcaca packages fix a security vulnerability Publication date: 12 Mar 2021 URL: https://advisories.mageia.org/MGASA-2021-0128.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-3410 A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context (CVE-2021-3410). References: - https://bugs.mageia.org/show_bug.cgi?id=28556 - https://lists.debian.org/debian-lts-announce/2021/03/msg00006.html - https://www.cve.org/CVERecord?id=CVE-2021-3410 SRPMS: - 8/core/libcaca-0.99-0.beta19.5.1.mga8 - 7/core/libcaca-0.99-0.beta19.3.1.mga7 . Revised libcaca distributions fix a buffer overflow vulnerability, enabling local arbitrary code execution in Mageia systems. Discover further details.. libcaca security update, buffer overflow fix, Mageia security advisory, software vulnerability update, caca_resize issue. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.