Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-500004 http://linux.oracle.com/errata/ELSA-2026-500004.html The following updated rpms for have been uploaded to the Unbreakable LinuxNetwork: x86_64: kernel-uek-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-core-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-devel-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-doc-6.12.0-204.92.4.3.el10uek.noarch.rpm kernel-uek-modules-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-modules-core-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-modules-deprecated-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-modules-desktop-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-modules-extra-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-modules-extra-netfilter-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-modules-usb-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-modules-wireless-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-tools-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-debug-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-debug-core-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-debug-devel-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-debug-modules-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-debug-modules-core-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-debug-modules-deprecated-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-debug-modules-desktop-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-debug-modules-extra-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-debug-modules-extra-netfilter-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-debug-modules-usb-6.12.0-204.92.4.3.el10uek.x86_64.rpm kernel-uek-debug-modules-wireless-6.12.0-204.92.4.3.el10uek.x86_64.rpm aarch64: kernel-uek-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-core-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-devel-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-doc-6.12.0-204.92.4.3.el10uek.noarch.rpm kernel-uek-modules-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-modules-core-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-modules-deprecated-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-modules-desktop-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-modules-extra-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-modules-extra-netfilter-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-modules-usb-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-modules-wireless-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-tools-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-debug-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-debug-core-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-debug-devel-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-debug-modules-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-debug-modules-core-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-debug-modules-deprecated-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-debug-modules-desktop-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-debug-modules-extra-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-debug-modules-extra-netfilter-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-debug-modules-usb-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek-debug-modules-wireless-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek64k-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek64k-core-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek64k-devel-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek64k-modules-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek64k-modules-core-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek64k-modules-deprecated-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek64k-modules-desktop-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek64k-modules-extra-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek64k-modules-extra-netfilter-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek64k-modules-usb-6.12.0-204.92.4.3.el10uek.aarch64.rpm kernel-uek64k-modules-wireless-6.12.0-204.92.4.3.el10uek.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/kernel-uek-6.12.0-204.92.4.3.el10uek.src.rpm Related CVEs: CVE-2026-31663 CVE-2026-46316 CVE-2026-53362 Description of changes: [6.12.0-204.92.4.3] - xfrm: hold dev ref until after transport_finish NF_HOOK (Qi Tang) [Orabug: 39727259] {CVE-2026-31663} - xfrm: hold device only for theasynchronous decryption (Jianbo Liu) [Orabug: 39727259] - KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (Hyunwoo Kim) [Orabug: 39727258] {CVE-2026-46316} - ipv6: account for fraggap on the paged allocation path (Wongi Lee) [Orabug: 39727239] {CVE-2026-53362} _______________________________________________ El-errata mailing list
libcap could be made to modify capabilities on arbitrary files.. ========================================================================== Ubuntu Security Notice USN-8193-2 June 23, 2026 libcap2 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: libcap could be made to modify capabilities on arbitrary files. Software Description: - libcap2: POSIX 1003.1e capabilities library Details: USN-8193-1 fixed a vulnerability in libcap. This update provides the corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: Ali Raza discovered that libcap incorrectly handled file capability updates. A local attacker could possibly use this issue to inject or strip capabilities into arbitrary executables and escalate privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS libcap-dev 1:2.32-1ubuntu0.2+esm1 Available with Ubuntu Pro libcap2 1:2.32-1ubuntu0.2+esm1 Available with Ubuntu Pro libcap2-bin 1:2.32-1ubuntu0.2+esm1 Available with Ubuntu Pro libpam-cap 1:2.32-1ubuntu0.2+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libcap-dev 1:2.25-1.2ubuntu0.1~esm2 Available with Ubuntu Pro libcap2 1:2.25-1.2ubuntu0.1~esm2 Available with Ubuntu Pro libcap2-bin 1:2.25-1.2ubuntu0.1~esm2 Available with Ubuntu Pro libpam-cap 1:2.25-1.2ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS libcap-dev 1:2.24-12ubuntu0.1~esm2 Available with Ubuntu Pro libcap2 1:2.24-12ubuntu0.1~esm2 Available with Ubuntu Pro libcap2-bin 1:2.24-12ubuntu0.1~esm2 Available with Ubuntu Pro libpam-cap 1:2.24-12ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 14.04 LTS libcap-dev 1:2.24-0ubuntu2+esm2 Available with Ubuntu Pro libcap2 1:2.24-0ubuntu2+esm2 Available with Ubuntu Pro libcap2-bin 1:2.24-0ubuntu2+esm2 Available with Ubuntu Pro libpam-cap 1:2.24-0ubuntu2+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8193-2 https://ubuntu.com/security/notices/USN-8193-1 CVE-2026-4878 . modification of file capabilities could allow unprivileged users to escalate privileges on Ubuntu systems. Update recommended!. Ubuntu Security Notice, libcap vulnerability, privilege escalation, capability modification. . Severity: Critical. LinuxSecurity.com Team
Security update. Publication date: 10 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0185.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-40959, CVE-2026-40960 Description: Mod security sandbox escape. (CVE-2026-40959) HTTP API and insecure environment access control bypass. (CVE-2026-40960) References: - https://bugs.mageia.org/show_bug.cgi?id=35422 - https://lists.fedoraproject.org/archives/list/
An update that solves one vulnerability can now be installed.. # Security update for firewalld Announcement ID: SUSE-SU-2026:21418-1 Release Date: 2026-04-29T11:32:57Z Rating: moderate References: * bsc#1260903 Cross-References: * CVE-2026-4948 CVSS scores: * CVE-2026-4948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for firewalld fixes the following issues: * CVE-2026-4948: local unprivileged users can modify the runtime firewall state without proper authentication due to D-Bus setter mis-authorizations (bsc#1260903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-694=1 ## Package List: * SUSE Linux Micro 6.0 (noarch) * python3-firewall-2.0.0-2.1 * firewalld-2.0.0-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4948.html * https://bugzilla.suse.com/show_bug.cgi?id=1260903 . SUSE updates firewalld to address CVE-2026-4948 with moderate severity, enhancing protection against unauthorized access.. SUSE Firewalld Security Update Authentication Vulnerability. . LinuxSecurity.com Team
An update that solves four vulnerabilities can now be installed.. # Security update for openssl-1_0_0 Announcement ID: SUSE-SU-2026:0332-1 Release Date: 2026-01-29T06:05:07Z Rating: moderate References: * bsc#1256834 * bsc#1256837 * bsc#1256838 * bsc#1256840 Cross-References: * CVE-2025-68160 * CVE-2025-69420 * CVE-2025-69421 * CVE-2026-22796 CVSS scores: * CVE-2025-68160 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-68160 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-69420 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-69420 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-69420 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-69421 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-69421 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-22796 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22796 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Legacy Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities can now beinstalled. ## Description: This update for openssl-1_0_0 fixes the following issues: * CVE-2025-68160: Heap out-of-bounds write in BIO_f_linebuffer on short writes (bsc#1256834). * CVE-2025-69420: Missing ASN1_TYPE validation in TS_RESP_verify_response() function (bsc#1256837). * CVE-2025-69421: NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function (bsc#1256838). * CVE-2026-22796: ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function (bsc#1256840). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-332=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-332=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-332=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-332=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-332=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-332=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-332=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-332=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-332=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-332=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libopenssl10-1.0.2p-150000.3.102.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.102.1 * libopenssl1_0_0-1.0.2p-150000.3.102.1 * libopenssl1_0_0-hmac-1.0.2p-150000.3.102.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.102.1 * openssl-1_0_0-1.0.2p-150000.3.102.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.102.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.102.1 * libopenssl10-debuginfo-1.0.2p-150000.3.102.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libopenssl10-1.0.2p-150000.3.102.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.102.1 * libopenssl1_0_0-1.0.2p-150000.3.102.1 * libopenssl1_0_0-hmac-1.0.2p-150000.3.102.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.102.1 * openssl-1_0_0-1.0.2p-150000.3.102.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.102.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.102.1 * libopenssl10-debuginfo-1.0.2p-150000.3.102.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl10-1.0.2p-150000.3.102.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.102.1 * libopenssl1_0_0-1.0.2p-150000.3.102.1 * libopenssl1_0_0-hmac-1.0.2p-150000.3.102.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.102.1 * openssl-1_0_0-1.0.2p-150000.3.102.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.102.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.102.1 * libopenssl10-debuginfo-1.0.2p-150000.3.102.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl10-1.0.2p-150000.3.102.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.102.1 * libopenssl1_0_0-1.0.2p-150000.3.102.1 * libopenssl1_0_0-hmac-1.0.2p-150000.3.102.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.102.1 * openssl-1_0_0-1.0.2p-150000.3.102.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.102.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.102.1 * libopenssl10-debuginfo-1.0.2p-150000.3.102.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) *libopenssl10-1.0.2p-150000.3.102.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.102.1 * libopenssl1_0_0-1.0.2p-150000.3.102.1 * libopenssl1_0_0-hmac-1.0.2p-150000.3.102.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.102.1 * openssl-1_0_0-1.0.2p-150000.3.102.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.102.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.102.1 * libopenssl10-debuginfo-1.0.2p-150000.3.102.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libopenssl10-1.0.2p-150000.3.102.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.102.1 * libopenssl1_0_0-1.0.2p-150000.3.102.1 * libopenssl1_0_0-hmac-1.0.2p-150000.3.102.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.102.1 * openssl-1_0_0-1.0.2p-150000.3.102.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.102.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.102.1 * libopenssl10-debuginfo-1.0.2p-150000.3.102.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libopenssl10-1.0.2p-150000.3.102.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.102.1 * libopenssl1_0_0-1.0.2p-150000.3.102.1 * libopenssl1_0_0-hmac-1.0.2p-150000.3.102.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.102.1 * openssl-1_0_0-1.0.2p-150000.3.102.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.102.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.102.1 * libopenssl10-debuginfo-1.0.2p-150000.3.102.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libopenssl10-1.0.2p-150000.3.102.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.102.1 * libopenssl1_0_0-1.0.2p-150000.3.102.1 * libopenssl1_0_0-hmac-1.0.2p-150000.3.102.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.102.1 * openssl-1_0_0-1.0.2p-150000.3.102.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.102.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.102.1 * libopenssl10-debuginfo-1.0.2p-150000.3.102.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) *libopenssl1_0_0-steam-1.0.2p-150000.3.102.1 * libopenssl10-1.0.2p-150000.3.102.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.102.1 * libopenssl1_0_0-1.0.2p-150000.3.102.1 * libopenssl1_0_0-hmac-1.0.2p-150000.3.102.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.102.1 * openssl-1_0_0-1.0.2p-150000.3.102.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.102.1 * openssl-1_0_0-cavs-1.0.2p-150000.3.102.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.102.1 * libopenssl1_0_0-steam-debuginfo-1.0.2p-150000.3.102.1 * libopenssl10-debuginfo-1.0.2p-150000.3.102.1 * openssl-1_0_0-cavs-debuginfo-1.0.2p-150000.3.102.1 * openSUSE Leap 15.6 (x86_64) * libopenssl1_0_0-32bit-1.0.2p-150000.3.102.1 * libopenssl1_0_0-hmac-32bit-1.0.2p-150000.3.102.1 * libopenssl1_0_0-steam-32bit-1.0.2p-150000.3.102.1 * libopenssl1_0_0-32bit-debuginfo-1.0.2p-150000.3.102.1 * libopenssl-1_0_0-devel-32bit-1.0.2p-150000.3.102.1 * libopenssl1_0_0-steam-32bit-debuginfo-1.0.2p-150000.3.102.1 * openSUSE Leap 15.6 (noarch) * openssl-1_0_0-doc-1.0.2p-150000.3.102.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libopenssl10-1.0.2p-150000.3.102.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.102.1 * libopenssl1_0_0-1.0.2p-150000.3.102.1 * libopenssl1_0_0-hmac-1.0.2p-150000.3.102.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.102.1 * openssl-1_0_0-1.0.2p-150000.3.102.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.102.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.102.1 * libopenssl10-debuginfo-1.0.2p-150000.3.102.1 ## References: * https://www.suse.com/security/cve/CVE-2025-68160.html * https://www.suse.com/security/cve/CVE-2025-69420.html * https://www.suse.com/security/cve/CVE-2025-69421.html * https://www.suse.com/security/cve/CVE-2026-22796.html * https://bugzilla.suse.com/show_bug.cgi?id=1256834 * https://bugzilla.suse.com/show_bug.cgi?id=1256837 * https://bugzilla.suse.com/show_bug.cgi?id=1256838 *https://bugzilla.suse.com/show_bug.cgi?id=1256840 . Update for openSUSE addresses four issues in openssl-1_0_0, enhancing stability and security for users.. openSUSE updates, openssl patches, moderate security updates. . LinuxSecurity.com Team
An update that solves three vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 15 for SLE 15 SP5) Announcement ID: SUSE-SU-2025:0656-1 Release Date: 2025-02-22T20:04:03Z Rating: important References: * bsc#1227371 * bsc#1228585 * bsc#1236783 Cross-References: * CVE-2024-36974 * CVE-2024-40956 * CVE-2024-53104 CVSS scores: * CVE-2024-36974 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-40956 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-40956 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53104 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.14.21-150500_55_68 fixes several issues. The following security issues were fixed: * CVE-2024-40956: dmaengine: idxd: Fix possible Use-After-Free in irq_process_work_list (bsc#1228585). * CVE-2024-36974: net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP (bsc#1227371). * CVE-2024-53104: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format (bsc#1236783). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2025-656=1 SUSE-2025-654=1 * SUSE LinuxEnterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2025-656=1 SUSE-SLE- Module-Live-Patching-15-SP5-2025-654=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_14-debugsource-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_68-default-debuginfo-10-150500.2.1 * kernel-livepatch-5_14_21-150500_55_65-default-debuginfo-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_65-default-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_15-debugsource-10-150500.2.1 * kernel-livepatch-5_14_21-150500_55_68-default-10-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_14-debugsource-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_68-default-debuginfo-10-150500.2.1 * kernel-livepatch-5_14_21-150500_55_65-default-debuginfo-11-150500.2.1 * kernel-livepatch-5_14_21-150500_55_65-default-11-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_15-debugsource-10-150500.2.1 * kernel-livepatch-5_14_21-150500_55_68-default-10-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-36974.html * https://www.suse.com/security/cve/CVE-2024-40956.html * https://www.suse.com/security/cve/CVE-2024-53104.html * https://bugzilla.suse.com/show_bug.cgi?id=1227371 * https://bugzilla.suse.com/show_bug.cgi?id=1228585 * https://bugzilla.suse.com/show_bug.cgi?id=1236783 . An essential system upgrade for openSUSE Leap enhancing security by resolving multiple vulnerabilities. Apply through recommended procedures.. openSUSE Leap; Kernel Update; Live Patching; Important Security Fixes. . Severity: Important. LinuxSecurity.com Team
Latest upstream release. It adds support for tiles and fixes reading images generated by iOS 18+. See https://github.com/strukturag/libheif/releases for more details about the changes since 1.17.6. NOTE: heif-convert tool was renamed to heif-dec. How to test:. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-8fdb7be3cb 2025-02-15 02:35:33.711225+00:00 -------------------------------------------------------------------------------- Name : libheif Product : Fedora 41 Version : 1.19.5 Release : 3.fc41 URL : https://github.com/strukturag/libheif Summary : HEIF and AVIF file format decoder and encoder Description : libheif is an ISO/IEC 23008-12:2017 HEIF and AVIF (AV1 Image File Format) file format decoder and encoder. -------------------------------------------------------------------------------- Update Information: Latest upstream release. It adds support for tiles and fixes reading images generated by iOS 18+. See https://github.com/strukturag/libheif/releases for more details about the changes since 1.17.6. NOTE: heif-convert tool was renamed to heif-dec. How to test: Download and unzip sample images from mastodon issue #31570. Try opening them with e.g. loupe or gimp. They fail to open with libheif-1.17.6, but should open successfully with libheif-1.19.5. Fixes CVE-2024-41311 . -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 5 2025 Robert-André Mauchin - 1.19.5-3 - Rebuilt for aom 3.11.0 * Fri Jan 17 2025 Fedora Release Engineering - 1.19.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Sun Nov 24 2024 Packit - 1.19.5-1 - Update to version 1.19.5 - Resolves: rhbz#2327307 * Sun Nov 17 2024 Dominik Mierzejewski - 1.19.3-3 - disable OpenJPH encoder support to work-around crashes * Sat Nov 16 2024 Sérgio Basto - 1.19.3-2 - Add support to multilib in devel sub-package - Resolves: rhbz#2279891 * Tue Nov 12 2024Dominik Mierzejewski - 1.19.3-1 - update to 1.19.3 (resolves rhbz#2295525) - drop obsolete patches - enable OpenH264, OpenJPH (64-bit only) and Brotli decoders - run tests unconditionally, they no longer require special build options - drop conditional hevc subpackage - use fewer wildcards in the file lists - stop building rav1e and svt AV1 encoders as plugins -------------------------------------------------------------------------------- References: [ 1 ] Bug #2319289 - CVE-2024-41311 libheif: OOB read and write via ImageOverlay::parse() [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2319289 [ 2 ] Bug #2332519 - Update libheif https://bugzilla.redhat.com/show_bug.cgi?id=2332519 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-8fdb7be3cb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- . The recent Libheif enhancements for Fedora 41 address issues related to iOS image handling and additional features. Keep your software current to maintain the highest level of security.. Fedora 41, libheif update, security advisory, encoder security fixes. . LinuxSecurity.com Team
Update to 6.2.8, fixing CVE-2022-48257 and CVE-2022-48258 Unbundle cpp-httlib, fixing CVE-2023-26130. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-94a155818c 2024-05-02 01:36:55.268644 -------------------------------------------------------------------------------- Name : et Product : Fedora 39 Version : 6.2.8 Release : 1.fc39 URL : https://eternalterminal.dev/ Summary : Remote shell that survives IP roaming and disconnect Description : Eternal Terminal (ET) is a remote shell that automatically reconnects without interrupting the session. -------------------------------------------------------------------------------- Update Information: Update to 6.2.8, fixing CVE-2022-48257 and CVE-2022-48258 Unbundle cpp-httlib, fixing CVE-2023-26130 -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 30 2024 Michel Lind - 6.2.8-1 - Update to 6.2.8 (rhbz#2162155) - Temporarily rebundle catch2; the version in Fedora is too old * Fri Apr 26 2024 Michel Lind - 6.2.1-15 - Disable unwind on s390x * Fri Apr 26 2024 Michel Lind - 6.2.1-14 - Unbundle cpp-httplib (rhbz#2169585) - Eliminate almost all sed usage - Use find_package to find cxxopts - Use pkg_check_modules to find easylogging++ - Enable SELinux support - Enable unwind support * Thu Apr 25 2024 Michel Lind - 6.2.1-13 - Use SPDX license identifier * Wed Jan 24 2024 Fedora Release Engineering - 6.2.1-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 Fedora Release Engineering - 6.2.1-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2161247 - CVE-2022-48257 et: EternalTerminal: information exposure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2161247 [ 2 ] Bug #2161251 -CVE-2022-48258 et: MisterTea/EternalTerminal: information exposure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2161251 [ 3 ] Bug #2162155 - et-6.2.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=2162155 [ 4 ] Bug #2169585 - Please try to use cpp-httplib-devel package https://bugzilla.redhat.com/show_bug.cgi?id=2169585 [ 5 ] Bug #2211077 - CVE-2023-26130 et: cpp-httplib: CRLF Injection [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2211077 [ 6 ] Bug #2211079 - CVE-2023-26130 et: cpp-httplib: CRLF Injection [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2211079 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-94a155818c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.