Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0269.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-14803 Description: The updated package fixes a security vulnerability: Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. (CVE-2026-14803) References: - https://bugs.mageia.org/show_bug.cgi?id=35835 - https://www.openwall.com/lists/oss-security/2026/07/06/2 - https://metacpan.org/release/SRI/Mojolicious-9.47/changes - https://www.cve.org/CVERecord?id=CVE-2026-14803 SRPMS: - 10/core/perl-Mojolicious-9.420.0-1.1.mga10 - 9/core/perl-Mojolicious-9.310.0-1.1.mga9 . Update for Mageia addresses critical memory exhaustion flaw in perl-Mojolicious, improving overall system safety.. Mageia security update, memory exhaustion, perl-Mojolicious, CVE-2026-14803, security advisory. . Severity: Critical. LinuxSecurity.com Team
An update that solves seven vulnerabilities can now be installed.. # Security update for python-Pillow Announcement ID: SUSE-SU-2026:3084-1 Release Date: 2026-07-16T17:46:49Z Rating: moderate References: * bsc#1271418 * bsc#1271419 * bsc#1271420 * bsc#1271421 * bsc#1271422 * bsc#1271424 * bsc#1271425 Cross-References: * CVE-2026-54058 * CVE-2026-59197 * CVE-2026-59198 * CVE-2026-59199 * CVE-2026-59200 * CVE-2026-59204 * CVE-2026-59205 CVSS scores: * CVE-2026-54058 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-54058 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-54058 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59197 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-59197 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-59197 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-59198 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-59198 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59198 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59198 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-59199 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59199 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59200 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59200 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59200 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59204 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59204 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59204 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59205 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59205 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59205 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves seven vulnerabilities can now be installed. ## Description: This update for python-Pillow fixes the following issues * CVE-2026-54058: out-of-bounds read via attacker-controlled row stride on `mmap` path (bsc#1271419). * CVE-2026-59197: heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` (bsc#1271418). * CVE-2026-59198: out-of-bounds heap data copied into file generated by TGA RLE encoder (bsc#1271420). * CVE-2026-59199: heap out-of-bounds write in `Image.paste()` and `Image.crop()` via signed coordinate overflow (bsc#1271421). * CVE-2026-59200: decompression bomb DoS via `PdfParser.PdfStream.decode()` (bsc#1271422). * CVE-2026-59204: denial of service through memory exhaustion via JPEG2000 tiled decoder (bsc#1271424). * CVE-2026-59205: controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypperpatch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-3084=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3084=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * python3-Pillow-debuginfo-7.2.0-150300.3.30.1 * python-Pillow-debuginfo-7.2.0-150300.3.30.1 * python3-Pillow-tk-debuginfo-7.2.0-150300.3.30.1 * python-Pillow-debugsource-7.2.0-150300.3.30.1 * python3-Pillow-7.2.0-150300.3.30.1 * python3-Pillow-tk-7.2.0-150300.3.30.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-Pillow-debuginfo-7.2.0-150300.3.30.1 * python-Pillow-debugsource-7.2.0-150300.3.30.1 * python-Pillow-debuginfo-7.2.0-150300.3.30.1 * python3-Pillow-7.2.0-150300.3.30.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54058.html * https://www.suse.com/security/cve/CVE-2026-59197.html * https://www.suse.com/security/cve/CVE-2026-59198.html * https://www.suse.com/security/cve/CVE-2026-59199.html * https://www.suse.com/security/cve/CVE-2026-59200.html * https://www.suse.com/security/cve/CVE-2026-59204.html * https://www.suse.com/security/cve/CVE-2026-59205.html * https://bugzilla.suse.com/show_bug.cgi?id=1271418 * https://bugzilla.suse.com/show_bug.cgi?id=1271419 * https://bugzilla.suse.com/show_bug.cgi?id=1271420 * https://bugzilla.suse.com/show_bug.cgi?id=1271421 * https://bugzilla.suse.com/show_bug.cgi?id=1271422 * https://bugzilla.suse.com/show_bug.cgi?id=1271424 * https://bugzilla.suse.com/show_bug.cgi?id=1271425 . Update for openSUSE fixes seven vulnerabilities in python-Pillow, addressing issues from memory exhaustion to out-of-bounds writes.. openSUSE update, python-Pillow security, software patch updates, moderate severity issues. . Severity: moderate. LinuxSecurity.com Team
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for python-soupsieve ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21342-1 Rating: important References: * bsc#1271187 * bsc#1271188 Cross-References: * CVE-2026-49476 * CVE-2026-49477 CVSS scores: * CVE-2026-49476 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49477 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for python-soupsieve fixes the following issues - CVE-2026-49476: Memory Exhaustion via Large Comma-Separated Selector Lists (bsc#1271187). - CVE-2026-49477: Regular Expression Denial of Service (ReDoS) via Selector Parser (bsc#1271188). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1246=1 Package List: - openSUSE Leap 16.0: python313-soupsieve-2.6-160000.4.1 References: * https://www.suse.com/security/cve/CVE-2026-49476.html * https://www.suse.com/security/cve/CVE-2026-49477.html . A security update for openSUSE addresses 2 vulnerabilities in python-soupsieve with important fixes for memory exhaustion and denial of service issues.. openSUSE python-soupsieve vulnerabilities important updates. . Severity: Important. LinuxSecurity.com Team
An update that solves three vulnerabilities can now be installed.. # Security update for bind Announcement ID: SUSE-SU-2026:2779-1 Release Date: 2026-07-06T14:07:45Z Rating: important References: * bsc#1265591 * bsc#1265592 * bsc#1265594 Cross-References: * CVE-2026-3039 * CVE-2026-3592 * CVE-2026-5946 CVSS scores: * CVE-2026-3039 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3039 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3039 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3592 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-3592 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-5946 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for bind fixes the following issues: * CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (bsc#1265591). * CVE-2026-3592: Amplification vulnerabilities via self-pointed glue records (bsc#1265592). * CVE-2026-5946: Invalid handling of CLASS != IN (bsc#1265594). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patchSUSE-SLE-Module-Basesystem-15-SP7-2026-2779=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2779=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2779=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-2779=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * libirs1601-debuginfo-9.16.6-150300.22.59.1 * libdns1605-9.16.6-150300.22.59.1 * libdns1605-debuginfo-9.16.6-150300.22.59.1 * libisc1606-9.16.6-150300.22.59.1 * bind-9.16.6-150300.22.59.1 * bind-debugsource-9.16.6-150300.22.59.1 * bind-devel-9.16.6-150300.22.59.1 * libisccfg1600-debuginfo-9.16.6-150300.22.59.1 * bind-utils-9.16.6-150300.22.59.1 * libirs-devel-9.16.6-150300.22.59.1 * libbind9-1600-9.16.6-150300.22.59.1 * libbind9-1600-debuginfo-9.16.6-150300.22.59.1 * libns1604-9.16.6-150300.22.59.1 * libirs1601-9.16.6-150300.22.59.1 * libisccc1600-debuginfo-9.16.6-150300.22.59.1 * libisccc1600-9.16.6-150300.22.59.1 * bind-utils-debuginfo-9.16.6-150300.22.59.1 * bind-chrootenv-9.16.6-150300.22.59.1 * libisccfg1600-9.16.6-150300.22.59.1 * libisc1606-debuginfo-9.16.6-150300.22.59.1 * bind-debuginfo-9.16.6-150300.22.59.1 * libns1604-debuginfo-9.16.6-150300.22.59.1 * openSUSE Leap 15.3 (noarch) * python3-bind-9.16.6-150300.22.59.1 * bind-doc-9.16.6-150300.22.59.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libisccfg1600-9.16.6-150300.22.59.1 * libisc1606-debuginfo-9.16.6-150300.22.59.1 * libisccfg1600-debuginfo-9.16.6-150300.22.59.1 * libirs1601-debuginfo-9.16.6-150300.22.59.1 * bind-debuginfo-9.16.6-150300.22.59.1 * libirs-devel-9.16.6-150300.22.59.1 * libdns1605-9.16.6-150300.22.59.1 * libisc1606-9.16.6-150300.22.59.1 * libdns1605-debuginfo-9.16.6-150300.22.59.1 * bind-debugsource-9.16.6-150300.22.59.1 *libirs1601-9.16.6-150300.22.59.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libisccfg1600-9.16.6-150300.22.59.1 * libisc1606-debuginfo-9.16.6-150300.22.59.1 * libisccfg1600-debuginfo-9.16.6-150300.22.59.1 * libirs1601-debuginfo-9.16.6-150300.22.59.1 * bind-debuginfo-9.16.6-150300.22.59.1 * libirs-devel-9.16.6-150300.22.59.1 * libdns1605-9.16.6-150300.22.59.1 * libdns1605-debuginfo-9.16.6-150300.22.59.1 * libisc1606-9.16.6-150300.22.59.1 * bind-debugsource-9.16.6-150300.22.59.1 * libirs1601-9.16.6-150300.22.59.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libisccfg1600-9.16.6-150300.22.59.1 * libisc1606-debuginfo-9.16.6-150300.22.59.1 * libisccfg1600-debuginfo-9.16.6-150300.22.59.1 * libirs1601-debuginfo-9.16.6-150300.22.59.1 * bind-debuginfo-9.16.6-150300.22.59.1 * libirs-devel-9.16.6-150300.22.59.1 * libdns1605-9.16.6-150300.22.59.1 * libisc1606-9.16.6-150300.22.59.1 * libdns1605-debuginfo-9.16.6-150300.22.59.1 * bind-debugsource-9.16.6-150300.22.59.1 * libirs1601-9.16.6-150300.22.59.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3039.html * https://www.suse.com/security/cve/CVE-2026-3592.html * https://www.suse.com/security/cve/CVE-2026-5946.html * https://bugzilla.suse.com/show_bug.cgi?id=1265591 * https://bugzilla.suse.com/show_bug.cgi?id=1265592 * https://bugzilla.suse.com/show_bug.cgi?id=1265594 . SUSE releases an important security advisory for BIND covering critical memory exhaustion and amplification issues.. BIND security update,SUSE security advisory,BIND vulnerabilities,important security update,suse linux security. . Severity: Important. LinuxSecurity.com Team
New c-ares packages are available for Slackware 15.0 and -current to fix security issues.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] c-ares (SSA:2026-187-01) New c-ares packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/c-ares-1.34.7-i586-1_slack15.0.txz: Upgraded. This release fixes the following security issues: Use-after-free / double-free in c-ares' query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP. CPU-exhaustion denial of service via unbounded DNS name compression pointer chains. Memory-amplification denial of service via unvalidated DNS header record counts. For more information, see: https://www.cve.org/CVERecord?id=CVE-2026-33630 https://github.com/c-ares/c-ares/security/advisories/GHSA-6wfj-rwm7-3542 https://github.com/c-ares/c-ares/security/advisories/GHSA-pjmc-gx33-gc76 https://github.com/c-ares/c-ares/security/advisories/GHSA-jv8r-gqr9-68wj (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://slackware.com for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/c-ares-1.34.7-i586-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/c-ares-1.34.7-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/c-ares-1.34.7-i686-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/c-ares-1.34.7-x86_64-1.txz MD5signatures: +-------------+ Slackware 15.0 package: e2e1d5fa19673361d0a09124739b7c36 c-ares-1.34.7-i586-1_slack15.0.txz Slackware x86_64 15.0 package: f5288e7966693f035164baddcfadb33e c-ares-1.34.7-x86_64-1_slack15.0.txz Slackware -current package: ece3bd50d8242ed6d3508cf1f2d773dd n/c-ares-1.34.7-i686-1.txz Slackware x86_64 -current package: dc2284c8f9da14be6ca705b9dc74116c n/c-ares-1.34.7-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg c-ares-1.34.7-i586-1_slack15.0.txz +-----+ . New c-ares packages for Slackware 15.0 address critical security issues related to DoS attacks.. c-ares security,c-ares patch,Slackware security alert. . Severity: Critical. LinuxSecurity.com Team
-------------------------------------------------------------. openSUSE security update: security update for jline3 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21221-1 Rating: moderate References: * bsc#1269021 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that has one bug fix can now be installed. Description: This update for jline3 fixes the following issues: Changes in jline3: * unauthenticated remote memory exhaustion via unbounded Telnet 'NEW-ENVIRON variables (bsc#1269021) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1148=1 Package List: - openSUSE Leap 16.0: jline3-3.30.13-160000.3.1 jline3-builtins-3.30.13-160000.3.1 jline3-console-3.30.13-160000.3.1 jline3-console-ui-3.30.13-160000.3.1 jline3-curses-3.30.13-160000.3.1 jline3-jansi-3.30.13-160000.3.1 jline3-jansi-core-3.30.13-160000.3.1 jline3-javadoc-3.30.13-160000.3.1 jline3-native-3.30.13-160000.3.1 jline3-reader-3.30.13-160000.3.1 jline3-remote-telnet-3.30.13-160000.3.1 jline3-style-3.30.13-160000.3.1 jline3-terminal-3.30.13-160000.3.1 jline3-terminal-jansi-3.30.13-160000.3.1 jline3-terminal-jna-3.30.13-160000.3.1 jline3-terminal-jni-3.30.13-160000.3.1 . This openSUSE advisory details a moderate security update for jline3 addressing unauthenticated remote memory issues.. openSUSE security,jline3 update,remote memory exhaustion. . Severity: moderate. LinuxSecurity.com Team
An update that solves 5 vulnerabilities and has 5 bug fixes can now be installed.. openSUSE security update: security update for python-zeroconf ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21175-1 Rating: moderate References: * bsc#1268235 * bsc#1268341 * bsc#1268342 * bsc#1268343 * bsc#1268388 Cross-References: * CVE-2026-47180 * CVE-2026-47183 * CVE-2026-47184 * CVE-2026-48045 * CVE-2026-48487 CVSS scores: * CVE-2026-47180 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-47183 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-47184 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 5 vulnerabilities and has 5 bug fixes can now be installed. Description: This update for python-zeroconf fixes the following issues: Changes in python-zeroconf: - CVE-2026-47180: zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of service (bsc#1268341) - CVE-2026-47183: zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion (bsc#1268342) - CVE-2026-47184: zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood (bsc#1268343) - CVE-2026-48045: python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood (bsc#1268388) - CVE-2026-48487: python-zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet (bsc#1268235) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patchopenSUSE-Leap-16.0-packagehub-370=1 Package List: - openSUSE Leap 16.0: python313-zeroconf-0.136.0-bp160.2.1 References: * https://www.suse.com/security/cve/CVE-2026-47180.html * https://www.suse.com/security/cve/CVE-2026-47183.html * https://www.suse.com/security/cve/CVE-2026-47184.html * https://www.suse.com/security/cve/CVE-2026-48045.html * https://www.suse.com/security/cve/CVE-2026-48487.html . This openSUSE update resolves multiple issues in python-zeroconf and includes bug fixes for improved stability.. openSUSE update, python-zeroconf security, memory exhaustion fix, denial of service patch. . Severity: moderate. LinuxSecurity.com Team
See https://github.com/jupytext/jupytext/releases/tag/v1.19.4 for changes in version 1.19.4. Notable, this update fixes CVE-2026-45736 and CVE-2026-48779.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-31e6b85f4e 2026-07-01 01:21:48.846190+00:00 -------------------------------------------------------------------------------- Name : python-jupytext Product : Fedora 43 Version : 1.19.4 Release : 1.fc43 URL : https://jupytext.org/ Summary : Save Jupyter notebooks as text documents or scripts Description : Have you always wished Jupyter notebooks were plain text documents? Wished you could edit them in your favorite IDE? And get clear and meaningful diffs when doing version control? Then... Jupytext may well be the tool you're looking for! Jupytext is a plugin for Jupyter that can save Jupyter notebooks as - Markdown files (or MyST Markdown files, or R Markdown or Quarto text notebooks) - Scripts in many languages. Common use cases for Jupytext are: - Doing version control on Jupyter Notebooks - Editing, merging or refactoring notebooks in your favorite text editor - Applying Q&A checks on notebooks. -------------------------------------------------------------------------------- Update Information: See https://github.com/jupytext/jupytext/releases/tag/v1.19.4 for changes in version 1.19.4. Notable, this update fixes CVE-2026-45736 and CVE-2026-48779. -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 22 2026 Jerry James - 1.19.4-1 - Version 1.19.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2489680 - CVE-2026-48779 python-jupytext: ws: Denial of Service via memory exhaustion from small WebSocket fragments [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489680 [ 2 ] Bug #2491250 - python-jupytext-1.19.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2491250 [ 3 ] Bug #2491597 - CVE-2026-45736 python-jupytext: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray` [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491597 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-31e6b85f4e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.