Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
updated to 1.6.58 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a109a9ac2c 2026-06-02 01:10:43.197462+00:00 -------------------------------------------------------------------------------- Name : libpng Product : Fedora 43 Version : 1.6.58 Release : 1.fc43 URL : http://www.libpng.org/pub/png/ Summary : A library of functions for manipulating PNG image format files Description : The libpng package contains a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. PNG is a bit-mapped graphics format similar to the GIF format. PNG was created to replace the GIF format, since GIF uses a patented data compression algorithm. Libpng should be installed if you need to manipulate PNG format image files. -------------------------------------------------------------------------------- Update Information: updated to 1.6.58 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the fix for CVE-2026-33416 in 1.6.56. 1.6.57 is released with fixes for the following security vulnerability: CVE-2026-34757 (medium severity): Use-after-free memory bug in the chunk setter API. The hIST variant has existed since version 1.0.9, but the PLTE and tRNS ones are regressions introduced in the fix for CVE-2026-33416 in 1.6.56(oops). -------------------------------------------------------------------------------- ChangeLog: * Thu May 21 2026 Michal Hlavinka - 2:1.6.58-1 - updated to 1.6.58 (#2456815) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2460625 - CVE-2026-22020 libpng: OpenJDK: Update LibPNG (Oracle CPU 2026-04) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460625 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a109a9ac2c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for python-orjson ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20407-1 Rating: moderate References: * bsc#1257121 Cross-References: * CVE-2025-67221 CVSS scores: * CVE-2025-67221 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67221 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for python-orjson fixes the following issues: - CVE-2025-67221: Fixed write outsize of allocated memory on json dump (bsc#1257121). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-421=1 Package List: - openSUSE Leap 16.0: python313-orjson-3.10.15-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2025-67221.html . This security update addresses a moderate issue in python-orjson on openSUSE Leap 16.0, with details on the fix provided.. python orjson, openSUSE update, memory bug fix. . LinuxSecurity.com Team
Important: firefox security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:1337", "synopsis": "Important: firefox security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for firefox.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.\n\nThis update upgrades Firefox to version 102.9.0 ESR.\n\nSecurity Fix(es):\n\n* Mozilla: Incorrect code generation during JIT compilation (CVE-2023-25751)\n\n* Mozilla: Memory safety bugs fixed in Firefox 111 and Firefox ESR 102.9 (CVE-2023-28176)\n\n* Mozilla: Potential out-of-bounds when accessing throttled streams (CVE-2023-25752)\n\n* Mozilla: Invalid downcast in Worklets (CVE-2023-28162)\n\n* Mozilla: URL being dragged from a removed cross-origin iframe into the same tab triggered navigation (CVE-2023-28164)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2178458", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2178458", "description": ""}, {"ticket": "2178460", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2178460", "description": ""}, {"ticket": "2178466", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2178466", "description": ""}, {"ticket": "2178470", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2178470", "description": ""}, {"ticket": "2178472", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2178472", "description": ""}], "cves": [{"name": "CVE-2023-25751","sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-25751", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-94"}, {"name": "CVE-2023-25752", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-25752", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "cvss3BaseScore": "6.1", "cwe": "CWE-125"}, {"name": "CVE-2023-28162", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-28162", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "cvss3BaseScore": "6.1", "cwe": "CWE-704"}, {"name": "CVE-2023-28164", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-28164", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "cvss3BaseScore": "6.1", "cwe": "CWE-829"}, {"name": "CVE-2023-28176", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-28176", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-120"}], "references": [], "publishedAt": "2023-04-06T15:53:36.002725Z", "rpms": {"Rocky Linux 9": {"nvras": ["firefox-0:102.9.0-3.el9_1.aarch64.rpm", "firefox-0:102.9.0-3.el9_1.ppc64le.rpm", "firefox-0:102.9.0-3.el9_1.s390x.rpm", "firefox-0:102.9.0-3.el9_1.src.rpm", "firefox-0:102.9.0-3.el9_1.x86_64.rpm", "firefox-debuginfo-0:102.9.0-3.el9_1.aarch64.rpm", "firefox-debuginfo-0:102.9.0-3.el9_1.ppc64le.rpm", "firefox-debuginfo-0:102.9.0-3.el9_1.s390x.rpm", "firefox-debuginfo-0:102.9.0-3.el9_1.x86_64.rpm", "firefox-debugsource-0:102.9.0-3.el9_1.aarch64.rpm", "firefox-debugsource-0:102.9.0-3.el9_1.ppc64le.rpm", "firefox-debugsource-0:102.9.0-3.el9_1.s390x.rpm", "firefox-debugsource-0:102.9.0-3.el9_1.x86_64.rpm", "firefox-x11-0:102.9.0-3.el9_1.aarch64.rpm", "firefox-x11-0:102.9.0-3.el9_1.ppc64le.rpm", "firefox-x11-0:102.9.0-3.el9_1.s390x.rpm", "firefox-x11-0:102.9.0-3.el9_1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}.Crucial security patch for Firefox on Rocky Linux 9 tackles multiple major vulnerabilities. Stay informed for comprehensive insights on essential updates.. Firefox Security Updates, Rocky Linux Patches, Browser Security Fixes, Important Updates. . Severity: Important. LinuxSecurity.com Team
An update that fixes 6 vulnerabilities is now available. . SUSE Security Update: Security update for MozillaThunderbird ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0245-1 Rating: important References: #1181414 Cross-References: CVE-2020-15685 CVE-2020-26976 CVE-2021-23953 CVE-2021-23954 CVE-2021-23960 CVE-2021-23964 Affected Products: SUSE Linux Enterprise Workstation Extension 15-SP1 ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: This update for MozillaThunderbird fixes the following issues: - Mozilla Thunderbird was updated to 78.7.0 ESR (MFSA 2021-05, bsc#1181414) * CVE-2021-23953: Fixed a Cross-origin information leakage via redirected PDF requests * CVE-2021-23954: Fixed a type confusion when using logical assignment operators in JavaScript switch statements * CVE-2020-26976: Fixed an issue where HTTPS pages could have been intercepted by a registered service worker when they should not have been * CVE-2021-23960: Fixed a use-after-poison for incorrectly redeclared JavaScript variables during GC * CVE-2021-23964: Fixed Memory safety bugs * CVE-2020-15685: Fixed an IMAP Response Injection when using STARTTLS Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 15-SP1: zypper in -t patch SUSE-SLE-Product-WE-15-SP1-2021-245=1 Package List: - SUSE Linux Enterprise Workstation Extension 15-SP1 (x86_64): MozillaThunderbird-78.7.0-3.119.1 MozillaThunderbird-debuginfo-78.7.0-3.119.1 MozillaThunderbird-debugsource-78.7.0-3.119.1 MozillaThunderbird-translations-common-78.7.0-3.119.1 MozillaThunderbird-translations-other-78.7.0-3.119.1 References: https://www.suse.com/security/cve/CVE-2020-15685.html https://www.suse.com/security/cve/CVE-2020-26976.html https://www.suse.com/security/cve/CVE-2021-23953.html https://www.suse.com/security/cve/CVE-2021-23954.html https://www.suse.com/security/cve/CVE-2021-23960.html https://www.suse.com/security/cve/CVE-2021-23964.html https://bugzilla.suse.com/1181414 . Important patch for MozillaThunderbird resolves various vulnerabilities, including information exposure and memory flaws.. MozillaThunderbird Update,SUSE Security Advisory,Security Issues Fix. . Severity: Important. LinuxSecurity.com Team
An update that fixes 8 vulnerabilities is now available. . openSUSE Security Update: Security update for MozillaFirefox ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:2325-1 Rating: critical References: #1180039 Cross-References: CVE-2020-16042 CVE-2020-26971 CVE-2020-26973 CVE-2020-26974 CVE-2020-26978 CVE-2020-35111 CVE-2020-35112 CVE-2020-35113 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes 8 vulnerabilities is now available. Description: This update for MozillaFirefox fixes the following issues: - Firefox Extended Support Release 78.6.0 ESR * Fixed: Various stability, functionality, and security fixes MFSA 2020-55 (bsc#1180039) * CVE-2020-16042 (bmo#1679003) Operations on a BigInt could have caused uninitialized memory to be exposed * CVE-2020-26971 (bmo#1663466) Heap buffer overflow in WebGL * CVE-2020-26973 (bmo#1680084) CSS Sanitizer performed incorrect sanitization * CVE-2020-26974 (bmo#1681022) Incorrect cast of StyleGenericFlexBasis resulted in a heap use-after-free * CVE-2020-26978 (bmo#1677047) Internal network hosts could have been probed by a malicious webpage * CVE-2020-35111 (bmo#1657916) The proxy.onRequest API did not catch view-source URLs * CVE-2020-35112 (bmo#1661365) Opening an extension-less download may have inadvertently launched an executable instead * CVE-2020-35113 (bmo#1664831, bmo#1673589) Memory safety bugs fixed in Firefox 84 and Firefox ESR 78.6 This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-2325=1 Package List: - openSUSE Leap 15.1 (x86_64): MozillaFirefox-78.6.0-lp151.2.82.1 MozillaFirefox-branding-upstream-78.6.0-lp151.2.82.1 MozillaFirefox-buildsymbols-78.6.0-lp151.2.82.1 MozillaFirefox-debuginfo-78.6.0-lp151.2.82.1 MozillaFirefox-debugsource-78.6.0-lp151.2.82.1 MozillaFirefox-devel-78.6.0-lp151.2.82.1 MozillaFirefox-translations-common-78.6.0-lp151.2.82.1 MozillaFirefox-translations-other-78.6.0-lp151.2.82.1 References: https://www.suse.com/security/cve/CVE-2020-16042.html https://www.suse.com/security/cve/CVE-2020-26971.html https://www.suse.com/security/cve/CVE-2020-26973.html https://www.suse.com/security/cve/CVE-2020-26974.html https://www.suse.com/security/cve/CVE-2020-26978.html https://www.suse.com/security/cve/CVE-2020-35111.html https://www.suse.com/security/cve/CVE-2020-35112.html https://www.suse.com/security/cve/CVE-2020-35113.html https://bugzilla.suse.com/1180039 _______________________________________________ openSUSE Security Announce mailing list --
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for MozillaFirefox ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:3021-1 Rating: important References: #1176756 #1177872 Cross-References: CVE-2020-15683 CVE-2020-15969 Affected Products: SUSE Linux Enterprise Module for Desktop Applications 15-SP2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for MozillaFirefox fixes the following issues: - Firefox Extended Support Release 78.4.0 ESR * Fixed: Various stability, functionality, and security fixes MFSA 2020-46 (bsc#1177872, bsc#1176756) * CVE-2020-15969 Use-after-free in usersctp * CVE-2020-15683 Memory safety bugs fixed in Firefox 82 and Firefox ESR 78.4 * Fixed: Fixed legacy preferences not being properly applied when set via GPO Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Desktop Applications 15-SP2: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP2-2020-3021=1 Package List: - SUSE Linux Enterprise Module for Desktop Applications 15-SP2 (aarch64 ppc64le s390x x86_64): MozillaFirefox-78.4.0-8.11.2 MozillaFirefox-debuginfo-78.4.0-8.11.2 MozillaFirefox-debugsource-78.4.0-8.11.2 MozillaFirefox-devel-78.4.0-8.11.2 MozillaFirefox-translations-common-78.4.0-8.11.2 MozillaFirefox-translations-other-78.4.0-8.11.2 References: https://www.suse.com/security/cve/CVE-2020-15683.html https://www.suse.com/security/cve/CVE-2020-15969.html https://bugzilla.suse.com/1176756 https://bugzilla.suse.com/1177872 .Fedora Security Patch: Update resolves performance glitches and reliability concerns in GoogleChrome.. MozillaFirefox Update, SUSE Linux Security, Memory Bugs Fix, Security Advisory. . Severity: Important. LinuxSecurity.com Team
Mozilla: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5 (CVE-2020-6800) Mozilla: Out-of-bounds read when processing certain email messages (CVE-2020-6793) Mozilla: Setting a master password post-Thunderbird 52 does not delete unencrypted previously stored passwords (CVE-2020-6794) Mozilla: Crash processing S/MIME messages with multiple signatures (CVE-2020-6795) Mozilla: Incorrect p [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2020:0574-1 Issue Date: 2020-02-24 CVE Numbers: None -- Security Fix(es): Mozilla: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5 (CVE-2020-6800) Mozilla: Out-of-bounds read when processing certain email messages (CVE-2020-6793) Mozilla: Setting a master password post-Thunderbird 52 does not delete unencrypted previously stored passwords (CVE-2020-6794) Mozilla: Crash processing S/MIME messages with multiple signatures (CVE-2020-6795) Mozilla: Incorrect parsing of template tag could result in JavaScript injection (CVE-2020-6798) Mozilla: Message ID calculation was based on uninitialized data (CVE-2020-6792) -- SL6 x86_64 thunderbird-68.5.0-1.el6_10.x86_64.rpm thunderbird-debuginfo-68.5.0-1.el6_10.x86_64.rpm i386 thunderbird-68.5.0-1.el6_10.i686.rpm thunderbird-debuginfo-68.5.0-1.el6_10.i686.rpm - Scientific Linux Development Team . Scientists must immediately apply the security update for Thunderbird to fix critical email processing bugs on SL6.. Mozilla, Thunderbird, Memory Safety, Email Security, SL6. . Severity: Important. LinuxSecurity.com Team
An update that fixes 7 vulnerabilities is now available.. openSUSE Security Update: Security update for MozillaThunderbird ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0231-1 Rating: important References: #1162777 #1163368 Cross-References: CVE-2020-6792 CVE-2020-6793 CVE-2020-6794 CVE-2020-6795 CVE-2020-6797 CVE-2020-6798 CVE-2020-6800 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes 7 vulnerabilities is now available. Description: This update for MozillaThunderbird fixes the following issues: - Mozilla Thunderbird 68.5 (bsc#1162777) MFSA 2020-07 (bsc#1163368) * CVE-2020-6793 (bmo#1608539) Out-of-bounds read when processing certain email messages * CVE-2020-6794 (bmo#1606619) Setting a master password post-Thunderbird 52 does not delete unencrypted previously stored passwords * CVE-2020-6795 (bmo#1611105) Crash processing S/MIME messages with multiple signatures * CVE-2020-6797 (bmo#1596668) Extensions granted downloads.open permission could open arbitrary applications on Mac OSX * CVE-2020-6798 (bmo#1602944) Incorrect parsing of template tag could result in JavaScript injection * CVE-2020-6792 (bmo#1609607) Message ID calculcation was based on uninitialized data * CVE-2020-6800 (bmo#1595786, bmo#1596706, bmo#1598543, bmo#1604851, bmo#1605777, bmo#1608580, bmo#1608785) Memory safety bugs fixed in Thunderbird 68.5 * new: Support for Client Identity IMAP/SMTP Service Extension (bmo#1532388) * new: Support for OAuth 2.0 authentication for POP3 accounts (bmo#1538409) * fixed: Status area goes blank during account setup (bmo#1593122) * fixed: Calendar: Could not remove color for default categories (bmo#1584853) * fixed:Calendar: Prevent calendar component loading multiple times (bmo#1606375) * fixed: Calendar: Today pane did not retain width between sessions (bmo#1610207) * unresolved: When upgrading from Thunderbird version 60 to version 68, add-ons are not automatically updated during the upgrade process. They will however be updated during the add- on update check. It is of course possible to reinstall compatible add-ons via the Add-ons Manager or via addons.thunderbird.net. (bmo#1574183) * changed: Calendar: Task and Event tree colours adjusted for the dark theme (bmo#1608344) * fixed: Retrieval of S/MIME certificates from LDAP failed (bmo#1604773) * fixed: Address-parsing crash on some IMAP servers when preference mail.imap.use_envelope_cmd was set (bmo#1609690) * fixed: Incorrect forwarding of HTML messages caused SMTP servers to respond with a timeout (bmo#1222046) * fixed: Calendar: Various parts of the calendar UI stopped working when a second Thunderbird window opened (bmo#1608407) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-231=1 Package List: - openSUSE Leap 15.1 (x86_64): MozillaThunderbird-68.5.0-lp151.2.25.1 MozillaThunderbird-debuginfo-68.5.0-lp151.2.25.1 MozillaThunderbird-debugsource-68.5.0-lp151.2.25.1 MozillaThunderbird-translations-common-68.5.0-lp151.2.25.1 MozillaThunderbird-translations-other-68.5.0-lp151.2.25.1 References: https://www.suse.com/security/cve/CVE-2020-6792.html https://www.suse.com/security/cve/CVE-2020-6793.html https://www.suse.com/security/cve/CVE-2020-6794.html https://www.suse.com/security/cve/CVE-2020-6795.html https://www.suse.com/security/cve/CVE-2020-6797.html https://www.suse.com/security/cve/CVE-2020-6798.html https://www.suse.com/security/cve/CVE-2020-6800.html https://bugzilla.suse.com/1162777 https://bugzilla.suse.com/1163368 -- . The latest update for Mozilla Thunderbird addresses several security concerns, notably enhancing memory protection and fixing authentication flaws.. openSUSE, MozillaThunderbird, security update, memory safety, authentication. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.