Explore top 10 tips to secure your open-source projects now. Read More
×An update that solves 18 vulnerabilities and has 18 bug fixes can now be installed.. openSUSE security update: security update for dnsdist ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21015-1 Rating: moderate References: * bsc#1261236 * bsc#1261237 * bsc#1261238 * bsc#1261239 * bsc#1261240 * bsc#1261241 * bsc#1261243 * bsc#1262536 * bsc#1262537 * bsc#1262538 * bsc#1262539 * bsc#1262540 * bsc#1262541 * bsc#1262542 * bsc#1262543 * bsc#1262544 * bsc#1262545 * bsc#1262546 Cross-References: * CVE-2026-0396 * CVE-2026-0397 * CVE-2026-24028 * CVE-2026-24029 * CVE-2026-24030 * CVE-2026-27853 * CVE-2026-27854 * CVE-2026-33254 * CVE-2026-33257 * CVE-2026-33260 * CVE-2026-33593 * CVE-2026-33594 * CVE-2026-33595 * CVE-2026-33596 * CVE-2026-33597 * CVE-2026-33598 * CVE-2026-33599 * CVE-2026-33602 CVSS scores: * CVE-2026-0396 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-0396 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-0397 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-0397 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-24028 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-24028 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-24029 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-24029 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-24030 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-24030 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27853 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27853 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27854 ( SUSE ): 4.8CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-27854 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-33257 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33260 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 18 vulnerabilities and has 18 bug fixes can now be installed. Description: This update for dnsdist fixes the following issues - CVE-2026-0396: crafted DNS queries can allow to inject HTML content (bsc#1261236). - CVE-2026-0397: CORS misconfiguration can lead to information disclosure (bsc#1261237). - CVE-2026-24028: crafted DNS response packet can lead to an out-of-bounds read (bsc#1261238). - CVE-2026-24029: HTTPS ACL bypass can allow clients to send DoH queries (bsc#1261239). - CVE-2026-24030: allocating too much memory while processing DNS can result in a denial of service (bsc#1261240). - CVE-2026-27853: crafted DNS responses can lead to an out-of-bounds write (bsc#1261241). - CVE-2026-27854: crafted DNS queries can be used to trigger a use-after-free (bsc#1261243). - CVE-2026-33254: Resource exhaustion via DoQ/DoH3 connections (bsc#1262538). - CVE-2026-33257: Insufficient input validation of internal webserver (bsc#1262536). - CVE-2026-33260: Insufficient input validation of internal webserver (bsc#1262537). - CVE-2026-33593: Denial of service via crafted DNSCrypt query (bsc#1262546). - CVE-2026-33594: Outgoing DoH excessive memory allocation (bsc#1262545). - CVE-2026-33595: DoQ/DoH3 excessive memory allocation (bsc#1262544). - CVE-2026-33596: TCP backend stream ID overflow (bsc#1262543). - CVE-2026-33597: PRSD detection denial of service (bsc#1262542). - CVE-2026-33598: Out-of-bounds read in cache inspection via Lua (bsc#1262541). - CVE-2026-33599: Out-of-bounds read in service discovery (bsc#1262540). - CVE-2026-33602: Off-by-one access when processing crafted UDP responses(bsc#1262539). Changes for dnsdist: - Updated to 1.9.13 Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1027=1 Package List: - openSUSE Leap 16.0: dnsdist-1.9.13-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-0396.html * https://www.suse.com/security/cve/CVE-2026-0397.html * https://www.suse.com/security/cve/CVE-2026-24028.html * https://www.suse.com/security/cve/CVE-2026-24029.html * https://www.suse.com/security/cve/CVE-2026-24030.html * https://www.suse.com/security/cve/CVE-2026-27853.html * https://www.suse.com/security/cve/CVE-2026-27854.html * https://www.suse.com/security/cve/CVE-2026-33254.html * https://www.suse.com/security/cve/CVE-2026-33257.html * https://www.suse.com/security/cve/CVE-2026-33260.html * https://www.suse.com/security/cve/CVE-2026-33593.html * https://www.suse.com/security/cve/CVE-2026-33594.html * https://www.suse.com/security/cve/CVE-2026-33595.html * https://www.suse.com/security/cve/CVE-2026-33596.html * https://www.suse.com/security/cve/CVE-2026-33597.html * https://www.suse.com/security/cve/CVE-2026-33598.html * https://www.suse.com/security/cve/CVE-2026-33599.html * https://www.suse.com/security/cve/CVE-2026-33602.html . This security advisory addresses 18 vulnerabilities and bug fixes in dnsdist for openSUSE, emphasizing moderate risks.. dnsdist update, openSUSE patch, moderate security risk, information disclosure, memory issues. . Severity: moderate. LinuxSecurity.com Team
An update that solves 10 vulnerabilities, contains one feature and has two fixes can now be installed.. # Security update for postgresql17 Announcement ID: SUSE-SU-2026:22149-1 Release Date: 2026-06-16T23:06:32Z Rating: important References: * bsc#1245875 * bsc#1263804 * bsc#1265172 * bsc#1265173 * bsc#1265174 * bsc#1265175 * bsc#1265176 * bsc#1265177 * bsc#1265178 * bsc#1265179 * bsc#1265181 * bsc#1265182 * jsc#PED-14825 Cross-References: * CVE-2026-6472 * CVE-2026-6473 * CVE-2026-6474 * CVE-2026-6475 * CVE-2026-6476 * CVE-2026-6477 * CVE-2026-6478 * CVE-2026-6479 * CVE-2026-6637 * CVE-2026-6638 CVSS scores: * CVE-2026-6472 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6472 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6473 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6473 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6474 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6474 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6475 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6475 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6476 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6476 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6477 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6477 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6478 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6478 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6479 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6479 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6637 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6637 ( NVD ): 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6638 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-6638 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-6638 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 10 vulnerabilities, contains one feature and has two fixes can now be installed. ## Description: This update for postgresql17 fixes the following issues Security issues: * CVE-2026-6472: ensure the user has CREATE privilege on the schema specified (bsc#1265172). * CVE-2026-6473: integer overflows in memory-allocation calculations (bsc#1265173). * CVE-2026-6474: Guard against malicious time zone names (bsc#1265174). * CVE-2026-6475: Prevent path traversal in pg_basebackup and pg_rewind (bsc#1265175). * CVE-2026-6476: Properly quote subscription names in pg_createsubscriber (bsc#1265176). * CVE-2026-6477: Mark PQfn() as unsafe, and avoid using it within libpq (bsc#1265177). * CVE-2026-6478: Use timing-safe string comparisons in authentication code (bsc#1265178). * CVE-2026-6479: Prevent unbounded recursion while processing startup packets (bsc#1265179). * CVE-2026-6637: Prevent SQL injection and buffer overruns in contrib/spi (bsc#1265181). * CVE-2026-6638: Properly quote object names in logical replication origin checks (bsc#1265182). Non security issue: * Update to version 17.10. * Get rid of update-alternatives for openSUSE/SLE 16.0 and newer to support immutable systems and transactional updates (jsc#PED-14825, bsc#1245875). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-935=1 * SUSELinux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-935=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * postgresql17-devel-debuginfo-17.10-160000.1.1 * postgresql17-server-17.10-160000.1.1 * postgresql17-debuginfo-17.10-160000.1.1 * postgresql17-server-devel-debuginfo-17.10-160000.1.1 * postgresql17-contrib-debuginfo-17.10-160000.1.1 * postgresql17-pltcl-debuginfo-17.10-160000.1.1 * postgresql17-debugsource-17.10-160000.1.1 * postgresql17-plpython-17.10-160000.1.1 * postgresql17-server-debuginfo-17.10-160000.1.1 * postgresql17-pltcl-17.10-160000.1.1 * postgresql17-plperl-17.10-160000.1.1 * postgresql17-contrib-17.10-160000.1.1 * postgresql17-devel-17.10-160000.1.1 * postgresql17-17.10-160000.1.1 * postgresql17-plperl-debuginfo-17.10-160000.1.1 * postgresql17-plpython-debuginfo-17.10-160000.1.1 * postgresql17-server-devel-17.10-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * postgresql17-docs-17.10-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * postgresql17-devel-debuginfo-17.10-160000.1.1 * postgresql17-server-17.10-160000.1.1 * postgresql17-debuginfo-17.10-160000.1.1 * postgresql17-server-devel-debuginfo-17.10-160000.1.1 * postgresql17-contrib-debuginfo-17.10-160000.1.1 * postgresql17-pltcl-debuginfo-17.10-160000.1.1 * postgresql17-debugsource-17.10-160000.1.1 * postgresql17-plpython-17.10-160000.1.1 * postgresql17-server-debuginfo-17.10-160000.1.1 * postgresql17-pltcl-17.10-160000.1.1 * postgresql17-plperl-17.10-160000.1.1 * postgresql17-contrib-17.10-160000.1.1 * postgresql17-devel-17.10-160000.1.1 * postgresql17-17.10-160000.1.1 * postgresql17-plperl-debuginfo-17.10-160000.1.1 * postgresql17-plpython-debuginfo-17.10-160000.1.1 * postgresql17-server-devel-17.10-160000.1.1 * SUSE Linux Enterprise Server 16.0(noarch) * postgresql17-docs-17.10-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6472.html * https://www.suse.com/security/cve/CVE-2026-6473.html * https://www.suse.com/security/cve/CVE-2026-6474.html * https://www.suse.com/security/cve/CVE-2026-6475.html * https://www.suse.com/security/cve/CVE-2026-6476.html * https://www.suse.com/security/cve/CVE-2026-6477.html * https://www.suse.com/security/cve/CVE-2026-6478.html * https://www.suse.com/security/cve/CVE-2026-6479.html * https://www.suse.com/security/cve/CVE-2026-6637.html * https://www.suse.com/security/cve/CVE-2026-6638.html * https://bugzilla.suse.com/show_bug.cgi?id=1245875 * https://bugzilla.suse.com/show_bug.cgi?id=1263804 * https://bugzilla.suse.com/show_bug.cgi?id=1265172 * https://bugzilla.suse.com/show_bug.cgi?id=1265173 * https://bugzilla.suse.com/show_bug.cgi?id=1265174 * https://bugzilla.suse.com/show_bug.cgi?id=1265175 * https://bugzilla.suse.com/show_bug.cgi?id=1265176 * https://bugzilla.suse.com/show_bug.cgi?id=1265177 * https://bugzilla.suse.com/show_bug.cgi?id=1265178 * https://bugzilla.suse.com/show_bug.cgi?id=1265179 * https://bugzilla.suse.com/show_bug.cgi?id=1265181 * https://bugzilla.suse.com/show_bug.cgi?id=1265182 * https://jira.suse.com/browse/PED-14825 . SUSE addresses multiple vulnerabilities in postgresql17 with important security updates and fixes for version 17.10.. SUSE Security Update, PostgreSQL Security Fix, SUSE Linux Advisory. . Severity: Important. LinuxSecurity.com Team
Mesa could be made to crash or run programs if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8427-1 June 15, 2026 mesa vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Mesa could be made to crash or run programs if it received specially crafted input. Software Description: - mesa: free implementation of the EGL API Details: It was discovered that Mesa did not properly validate memory allocation sizes in WebGPU under certain circumstances. An attacker could use this issue to cause Mesa to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 libegl-mesa0 25.2.8-0ubuntu0.25.10.2 libgbm1 25.2.8-0ubuntu0.25.10.2 libgl1-mesa-dri 25.2.8-0ubuntu0.25.10.2 libglx-mesa0 25.2.8-0ubuntu0.25.10.2 mesa-drm-shim 25.2.8-0ubuntu0.25.10.2 mesa-libgallium 25.2.8-0ubuntu0.25.10.2 mesa-opencl-icd 25.2.8-0ubuntu0.25.10.2 mesa-teflon-delegate 25.2.8-0ubuntu0.25.10.2 mesa-va-drivers 25.2.8-0ubuntu0.25.10.2 mesa-vdpau-drivers 25.2.8-0ubuntu0.25.10.2 mesa-vulkan-drivers 25.2.8-0ubuntu0.25.10.2 Ubuntu 24.04 LTS libegl-mesa0 25.2.8-0ubuntu0.24.04.2 libgbm1 25.2.8-0ubuntu0.24.04.2 libgl1-mesa-dri 25.2.8-0ubuntu0.24.04.2 libglx-mesa0 25.2.8-0ubuntu0.24.04.2 mesa-drm-shim 25.2.8-0ubuntu0.24.04.2 mesa-libgallium 25.2.8-0ubuntu0.24.04.2 mesa-opencl-icd 25.2.8-0ubuntu0.24.04.2 mesa-teflon-delegate 25.2.8-0ubuntu0.24.04.2 mesa-va-drivers 25.2.8-0ubuntu0.24.04.2 mesa-vdpau-drivers 25.2.8-0ubuntu0.24.04.2 mesa-vulkan-drivers 25.2.8-0ubuntu0.24.04.2 Ubuntu 22.04 LTS libd3dadapter9-mesa 23.2.1-1ubuntu3.1~22.04.4 libegl-mesa0 23.2.1-1ubuntu3.1~22.04.4 libgbm1 23.2.1-1ubuntu3.1~22.04.4 libgl1-mesa-dri 23.2.1-1ubuntu3.1~22.04.4 libglapi-mesa 23.2.1-1ubuntu3.1~22.04.4 libglx-mesa0 23.2.1-1ubuntu3.1~22.04.4 libosmesa6 23.2.1-1ubuntu3.1~22.04.4 libxatracker2 23.2.1-1ubuntu3.1~22.04.4 mesa-drm-shim 23.2.1-1ubuntu3.1~22.04.4 mesa-opencl-icd 23.2.1-1ubuntu3.1~22.04.4 mesa-va-drivers 23.2.1-1ubuntu3.1~22.04.4 mesa-vdpau-drivers 23.2.1-1ubuntu3.1~22.04.4 mesa-vulkan-drivers 23.2.1-1ubuntu3.1~22.04.4 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8427-1 CVE-2026-40393 Package Information: https://launchpad.net/ubuntu/+source/mesa/25.2.8-0ubuntu0.25.10.2 https://launchpad.net/ubuntu/+source/mesa/25.2.8-0ubuntu0.24.04.2 https://launchpad.net/ubuntu/+source/mesa/23.2.1-1ubuntu3.1~22.04.4 . Mesa in Ubuntu may crash or execute arbitrary code from crafted input. Update now for protection.. mesa security, Ubuntu advisory, software vulnerability, memory management, application update. . Severity: Important. LinuxSecurity.com Team
Bug Fixes: CVE-2026-33254: An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are disabled by default CVE-2026-33257: An attacker can send a web request that causes unlimited memory. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-51cdd1292b 2026-06-15 00:48:35.285145+00:00 -------------------------------------------------------------------------------- Name : dnsdist Product : Fedora 44 Version : 2.0.6 Release : 1.fc44 URL : https://dnsdist.org Summary : Highly DNS-, DoS- and abuse-aware loadbalancer Description : dnsdist is a highly DNS-, DoS- and abuse-aware loadbalancer. Its goal in life is to route traffic to the best server, delivering top performance to legitimate users while shunting or blocking abusive traffic. -------------------------------------------------------------------------------- Update Information: Bug Fixes: CVE-2026-33254: An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are disabled by default CVE-2026-33257: An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The web server is disabled and restricted by an ACL by default CVE-2026-33260: An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The web server is disabled and restricted by an ACL by default CVE-2026-33593: A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query CVE-2026-33595: A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources were not properly released until the end of the connection.DOQ and DoH3 are disabled by default CVE-2026-33596: A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly timed queries that are routed to a TCP-only or DNS over TLS backend CVE-2026-33597: A crafted query containing an invalid DNS label can prevent the PRSD detection algorithm executed via DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI from being executed CVE-2026-33598: A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache CVE-2026-33599: A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to newServer or auto_upgrade (YAML) settings. DDR upgrade is not enabled by default CVE-2026-33602: A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write leading to a denial of service CVE-2026-33594: A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate into a buffer that will not be released until the end of the connection. Outgoing DoH is disabled by default -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 5 2026 Filipe Rosset - 2.0.6-1 - update to 2.0.6 fixes rhbz#2460540 * Fri May 29 2026 Miroslav Suchý - 2.0.3-2 - rebuild for https://fedoraproject.org/wiki/Changes/Protobuf_5.x/6.x -------------------------------------------------------------------------------- References: [ 1 ] Bug #2460830 - CVE-2026-33260 dnsdist: insufficient input validation of internal webserver [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460830 [ 2 ] Bug #2460831 - CVE-2026-33260 dnsdist: insufficient input validation of internal webserver[fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460831 [ 3 ] Bug #2460832 - CVE-2026-33257 dnsdist: insufficient input validation of internal webserver [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460832 [ 4 ] Bug #2460833 - CVE-2026-33257 dnsdist: insufficient input validation of internal webserver [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460833 [ 5 ] Bug #2460834 - CVE-2026-33596 dnsdist: TCP backend stream ID overflow [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460834 [ 6 ] Bug #2460835 - CVE-2026-33596 dnsdist: TCP backend stream ID overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460835 [ 7 ] Bug #2460836 - CVE-2026-33599 dnsdist: out-of-bounds read in service discovery [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460836 [ 8 ] Bug #2460837 - CVE-2026-33599 dnsdist: out-of-bounds read in service discovery [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460837 [ 9 ] Bug #2460838 - CVE-2026-33597 dnsdist: insufficient input validation of internal webserver [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460838 [ 10 ] Bug #2460839 - CVE-2026-33597 dnsdist: insufficient input validation of internal webserver [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460839 [ 11 ] Bug #2460840 - CVE-2026-33595 dnsdist: DoQ/DoH3 excessive memory allocation [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460840 [ 12 ] Bug #2460841 - CVE-2026-33595 dnsdist: DoQ/DoH3 excessive memory allocation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460841 [ 13 ] Bug #2460842 - CVE-2026-33594 dnsdist: outgoing DoH excessive memory allocation [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460842 [ 14 ] Bug #2460843 - CVE-2026-33594 dnsdist: outgoing DoH excessive memory allocation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460843 [ 15 ] Bug #2460844 -CVE-2026-33602 dnsdist: off-by-one access when processing crafted UDP responses [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460844 [ 16 ] Bug #2460845 - CVE-2026-33602 dnsdist: off-by-one access when processing crafted UDP responses [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460845 [ 17 ] Bug #2460846 - CVE-2026-33254 dnsdist: resource exhaustion via DoQ/DoH3 connections [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460846 [ 18 ] Bug #2460847 - CVE-2026-33254 dnsdist: resource exhaustion via DoQ/DoH3 connections [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460847 [ 19 ] Bug #2460848 - CVE-2026-33598 dnsdist: out-of-bounds read in cache inspection via Lua [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460848 [ 20 ] Bug #2460849 - CVE-2026-33598 dnsdist: out-of-bounds read in cache inspection via Lua [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460849 [ 21 ] Bug #2460851 - CVE-2026-33593 dnsdist: denial of service via crafted DNSCrypt query [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460851 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-51cdd1292b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical security advisory on Fedora 44 for dnsdist addressing multiple denial of service vulnerabilities. Updates advised.. dnsdist security, Fedora update, denial of service, memory leak, critical security advisory. . Severity: Critical. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-17618 http://linux.oracle.com/errata/ELSA-2026-17618.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: ImageMagick-6.9.10.68-7.0.11.el7_9.i686.rpm ImageMagick-6.9.10.68-7.0.11.el7_9.x86_64.rpm ImageMagick-c++-6.9.10.68-7.0.11.el7_9.i686.rpm ImageMagick-c++-6.9.10.68-7.0.11.el7_9.x86_64.rpm ImageMagick-c++-devel-6.9.10.68-7.0.11.el7_9.i686.rpm ImageMagick-c++-devel-6.9.10.68-7.0.11.el7_9.x86_64.rpm ImageMagick-devel-6.9.10.68-7.0.11.el7_9.i686.rpm ImageMagick-devel-6.9.10.68-7.0.11.el7_9.x86_64.rpm ImageMagick-doc-6.9.10.68-7.0.11.el7_9.x86_64.rpm ImageMagick-perl-6.9.10.68-7.0.11.el7_9.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/ImageMagick-6.9.10.68-7.0.11.el7_9.src.rpm Related CVEs: CVE-2026-32636 Description of changes: [6.9.10.68-7.0.11] - Fix CVE-2026-32636 [Orabug: 39375225] [6.9.10.68-7.0.9] - Fix CVE-2026-28691 and CVE-2026-28693 [Orabug: 39174244] [6.9.10.68-7.0.7] - Fixes Local File Disclosure via Path Traversal (CVE-2026-25965) [Orabug: 39118995] - Fixes Memory allocation with excessive without limits in the internal SVG decoder (CVE-2026-25985) [6.9.10.68-7.0.5] - Fix CVE-2025-62171 and CVE-2026-23876 [Orabug: 38997140] [6.9.10.68-7.0.3] - Security update CVE-2025-57803 [Orabug: 38455460] [6.9.10.68-7.0.1] - Fix for CVE-2025-55154 [Orabug: 38417011] _______________________________________________ El-errata mailing list
An update that solves 11 vulnerabilities, contains one feature and has one security fix can now be installed.. # Security update for postgresql18 Announcement ID: SUSE-SU-2026:1946-1 Release Date: 2026-05-18T07:49:01Z Rating: important References: * bsc#1263804 * bsc#1265172 * bsc#1265173 * bsc#1265174 * bsc#1265175 * bsc#1265176 * bsc#1265177 * bsc#1265178 * bsc#1265179 * bsc#1265180 * bsc#1265181 * bsc#1265182 * jsc#PED-14820 Cross-References: * CVE-2026-6472 * CVE-2026-6473 * CVE-2026-6474 * CVE-2026-6475 * CVE-2026-6476 * CVE-2026-6477 * CVE-2026-6478 * CVE-2026-6479 * CVE-2026-6575 * CVE-2026-6637 * CVE-2026-6638 CVSS scores: * CVE-2026-6472 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6472 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6473 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6473 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6474 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6474 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6475 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6475 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6476 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6476 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6477 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6477 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6478 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6478 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6479 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6479 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6575 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6575 (NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6637 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6637 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6638 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-6638 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 11 vulnerabilities, contains one feature and has one security fix can now be installed. ## Description: This update for postgresql18 fixes the following issues Update to version 18.4. Security issues: * CVE-2026-6472: ensure the user has CREATE privilege on the schema specified (bsc#1265172). * CVE-2026-6473: integer overflows in memory-allocation calculations (bsc#1265173). * CVE-2026-6474: Guard against malicious time zone names (bsc#1265174). * CVE-2026-6475: Prevent path traversal in pg_basebackup and pg_rewind (bsc#1265175). * CVE-2026-6476: Properly quote subscription names in pg_createsubscriber (bsc#1265176). * CVE-2026-6477: Mark PQfn() as unsafe, and avoid using it within libpq (bsc#1265177). * CVE-2026-6478: Use timing-safe string comparisons in authentication code (bsc#1265178). * CVE-2026-6479: Prevent unbounded recursion while processing startup packets (bsc#1265179). * CVE-2026-6575: Detect faulty input when restoring attribute MCV statistics (bsc#1265180). * CVE-2026-6637: Prevent SQL injection and buffer overruns in contrib/spi (bsc#1265181). * CVE-2026-6638: Properly quote object names in logical replication origin checks (bsc#1265182). Non security issue: * Get rid of update-alternatives for openSUSE/SLE 16.0 and newer to support immutablesystems and transactional updates (jsc#PED-14820). * /usr/bin/pg_config is missing after migrating away from update-alternatives (bsc#1263804). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-1946=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-1946=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libecpg6-debuginfo-18.4-8.12.1 * libpq5-18.4-8.12.1 * libpq5-debuginfo-18.4-8.12.1 * libecpg6-18.4-8.12.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libpq5-debuginfo-32bit-18.4-8.12.1 * libecpg6-32bit-18.4-8.12.1 * libpq5-32bit-18.4-8.12.1 * libecpg6-debuginfo-32bit-18.4-8.12.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libpq5-18.4-8.12.1 * libecpg6-18.4-8.12.1 * libpq5-debuginfo-18.4-8.12.1 * libecpg6-debuginfo-32bit-18.4-8.12.1 * libpq5-32bit-18.4-8.12.1 * libpq5-debuginfo-32bit-18.4-8.12.1 * libecpg6-debuginfo-18.4-8.12.1 * libecpg6-32bit-18.4-8.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6472.html * https://www.suse.com/security/cve/CVE-2026-6473.html * https://www.suse.com/security/cve/CVE-2026-6474.html * https://www.suse.com/security/cve/CVE-2026-6475.html * https://www.suse.com/security/cve/CVE-2026-6476.html * https://www.suse.com/security/cve/CVE-2026-6477.html * https://www.suse.com/security/cve/CVE-2026-6478.html * https://www.suse.com/security/cve/CVE-2026-6479.html * https://www.suse.com/security/cve/CVE-2026-6575.html * https://www.suse.com/security/cve/CVE-2026-6637.html * https://www.suse.com/security/cve/CVE-2026-6638.html *https://bugzilla.suse.com/show_bug.cgi?id=1263804 * https://bugzilla.suse.com/show_bug.cgi?id=1265172 * https://bugzilla.suse.com/show_bug.cgi?id=1265173 * https://bugzilla.suse.com/show_bug.cgi?id=1265174 * https://bugzilla.suse.com/show_bug.cgi?id=1265175 * https://bugzilla.suse.com/show_bug.cgi?id=1265176 * https://bugzilla.suse.com/show_bug.cgi?id=1265177 * https://bugzilla.suse.com/show_bug.cgi?id=1265178 * https://bugzilla.suse.com/show_bug.cgi?id=1265179 * https://bugzilla.suse.com/show_bug.cgi?id=1265180 * https://bugzilla.suse.com/show_bug.cgi?id=1265181 * https://bugzilla.suse.com/show_bug.cgi?id=1265182 * https://jira.suse.com/browse/PED-14820 . Patch for important issues in postgresql18 on SUSE addressing multiple vulnerabilities and enhancing security measures.. Security Update, PostgreSQL, Vulnerability Fixed, SUSE Patch. . Severity: Important. LinuxSecurity.com Team
Moderate: wireshark security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:9666", "synopsis": "Moderate: wireshark security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for wireshark.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The wireshark packages contain a network protocol analyzer used to capture and browse the traffic running on a computer network.\n\nSecurity Fix(es):\n\n* wireshark: Buffer Over-read in Wireshark (CVE-2026-3203)\n\n* wireshark: Improperly Controlled Sequential Memory Allocation in Wireshark (CVE-2026-3201)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2442639", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2442639", "description": ""}, {"ticket": "2442641", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2442641", "description": ""}], "cves": [{"name": "CVE-2026-3201", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3201", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "CWE-1325"}, {"name": "CVE-2026-3203", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3203", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "CWE-126"}], "references": [], "publishedAt": "2026-04-24T12:06:29.039644Z", "rpms": {"Rocky Linux 10": {"nvras": ["wireshark-cli-1:4.4.2-4.el10_1.4.aarch64.rpm", "wireshark-1:4.4.2-4.el10_1.4.aarch64.rpm", "wireshark-debuginfo-1:4.4.2-4.el10_1.4.aarch64.rpm","wireshark-devel-1:4.4.2-4.el10_1.4.x86_64.rpm", "wireshark-debuginfo-1:4.4.2-4.el10_1.4.x86_64.rpm", "wireshark-cli-debuginfo-1:4.4.2-4.el10_1.4.s390x.rpm", "wireshark-debuginfo-1:4.4.2-4.el10_1.4.s390x.rpm", "wireshark-cli-debuginfo-1:4.4.2-4.el10_1.4.ppc64le.rpm", "wireshark-cli-1:4.4.2-4.el10_1.4.ppc64le.rpm", "wireshark-devel-1:4.4.2-4.el10_1.4.ppc64le.rpm", "wireshark-1:4.4.2-4.el10_1.4.x86_64.rpm", "wireshark-devel-1:4.4.2-4.el10_1.4.s390x.rpm", "wireshark-devel-1:4.4.2-4.el10_1.4.aarch64.rpm", "wireshark-debugsource-1:4.4.2-4.el10_1.4.s390x.rpm", "wireshark-debuginfo-1:4.4.2-4.el10_1.4.ppc64le.rpm", "wireshark-debugsource-1:4.4.2-4.el10_1.4.ppc64le.rpm", "wireshark-1:4.4.2-4.el10_1.4.ppc64le.rpm", "wireshark-cli-1:4.4.2-4.el10_1.4.x86_64.rpm", "wireshark-1:4.4.2-4.el10_1.4.s390x.rpm", "wireshark-cli-1:4.4.2-4.el10_1.4.s390x.rpm", "wireshark-cli-debuginfo-1:4.4.2-4.el10_1.4.x86_64.rpm", "wireshark-cli-debuginfo-1:4.4.2-4.el10_1.4.aarch64.rpm", "wireshark-debugsource-1:4.4.2-4.el10_1.4.x86_64.rpm", "wireshark-debugsource-1:4.4.2-4.el10_1.4.aarch64.rpm", "wireshark-1:4.4.2-4.el10_1.4.src.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Wireshark update for Rocky Linux addresses moderate buffer over-read and memory issues. Critical security measures for safety.. Wireshark Rocky Linux Security Update Protocol Analysis Buffer Overread. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-6713 http://linux.oracle.com/errata/ELSA-2026-6713.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: ImageMagick-6.9.10.68-7.0.9.el7_9.i686.rpm ImageMagick-6.9.10.68-7.0.9.el7_9.x86_64.rpm ImageMagick-c++-6.9.10.68-7.0.9.el7_9.i686.rpm ImageMagick-c++-6.9.10.68-7.0.9.el7_9.x86_64.rpm ImageMagick-c++-devel-6.9.10.68-7.0.9.el7_9.i686.rpm ImageMagick-c++-devel-6.9.10.68-7.0.9.el7_9.x86_64.rpm ImageMagick-devel-6.9.10.68-7.0.9.el7_9.i686.rpm ImageMagick-devel-6.9.10.68-7.0.9.el7_9.x86_64.rpm ImageMagick-doc-6.9.10.68-7.0.9.el7_9.x86_64.rpm ImageMagick-perl-6.9.10.68-7.0.9.el7_9.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/ImageMagick-6.9.10.68-7.0.9.el7_9.src.rpm Related CVEs: CVE-2026-28691 CVE-2026-28693 Description of changes: [6.9.10.68-7.0.9] - Fix CVE-2026-28691 and CVE-2026-28693 [Orabug: 39174244] [6.9.10.68-7.0.7] - Fixes Local File Disclosure via Path Traversal (CVE-2026-25965) [Orabug: 39118995] - Fixes Memory allocation with excessive without limits in the internal SVG decoder (CVE-2026-25985) [6.9.10.68-7.0.5] - Fix CVE-2025-62171 and CVE-2026-23876 [Orabug: 38997140] [6.9.10.68-7.0.3] - Security update CVE-2025-57803 [Orabug: 38455460] [6.9.10.68-7.0.1] - Fix for CVE-2025-55154 [Orabug: 38417011] _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.