Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Moderate: cups security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:39302", "synopsis": "Moderate: cups security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for cups.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The Common UNIX Printing System (CUPS) provides a portable printing layer for Linux, UNIX, and similar operating systems.\n\nSecurity Fix(es):\n\n* cups: OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network (CVE-2026-34980)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2454954", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2454954", "description": ""}], "cves": [{"name": "CVE-2026-34980", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34980", "cvss3ScoringVector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L", "cvss3BaseScore": "6.4", "cwe": "CWE-78"}], "references": [], "publishedAt": "2026-07-15T12:06:01.640959Z", "rpms": {"Rocky Linux 10": {"nvras": ["cups-debuginfo-1:2.4.10-18.el10_2.s390x.rpm", "cups-lpd-1:2.4.10-18.el10_2.x86_64.rpm", "cups-libs-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-client-debuginfo-1:2.4.10-18.el10_2.x86_64.rpm", "cups-printerapp-debuginfo-1:2.4.10-18.el10_2.s390x.rpm", "cups-ipptool-debuginfo-1:2.4.10-18.el10_2.s390x.rpm", "cups-client-1:2.4.10-18.el10_2.x86_64.rpm", "cups-devel-1:2.4.10-18.el10_2.x86_64.rpm", "cups-debugsource-1:2.4.10-18.el10_2.s390x.rpm", "cups-printerapp-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-1:2.4.10-18.el10_2.x86_64.rpm", "cups-lpd-1:2.4.10-18.el10_2.ppc64le.rpm","cups-libs-1:2.4.10-18.el10_2.s390x.rpm", "cups-client-1:2.4.10-18.el10_2.s390x.rpm", "cups-ipptool-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-debuginfo-1:2.4.10-18.el10_2.aarch64.rpm", "cups-client-1:2.4.10-18.el10_2.aarch64.rpm", "cups-ipptool-debuginfo-1:2.4.10-18.el10_2.x86_64.rpm", "cups-client-debuginfo-1:2.4.10-18.el10_2.s390x.rpm", "cups-libs-debuginfo-1:2.4.10-18.el10_2.aarch64.rpm", "cups-lpd-debuginfo-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-1:2.4.10-18.el10_2.src.rpm", "cups-ipptool-1:2.4.10-18.el10_2.s390x.rpm", "cups-filesystem-1:2.4.10-18.el10_2.noarch.rpm", "cups-client-debuginfo-1:2.4.10-18.el10_2.aarch64.rpm", "cups-debugsource-1:2.4.10-18.el10_2.x86_64.rpm", "cups-printerapp-1:2.4.10-18.el10_2.x86_64.rpm", "cups-debugsource-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-ipptool-1:2.4.10-18.el10_2.aarch64.rpm", "cups-libs-debuginfo-1:2.4.10-18.el10_2.x86_64.rpm", "cups-libs-debuginfo-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-debugsource-1:2.4.10-18.el10_2.aarch64.rpm", "cups-debuginfo-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-devel-1:2.4.10-18.el10_2.s390x.rpm", "cups-libs-1:2.4.10-18.el10_2.aarch64.rpm", "cups-lpd-1:2.4.10-18.el10_2.s390x.rpm", "cups-lpd-debuginfo-1:2.4.10-18.el10_2.s390x.rpm", "cups-client-debuginfo-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-debuginfo-1:2.4.10-18.el10_2.x86_64.rpm", "cups-1:2.4.10-18.el10_2.aarch64.rpm", "cups-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-printerapp-debuginfo-1:2.4.10-18.el10_2.aarch64.rpm", "cups-printerapp-1:2.4.10-18.el10_2.s390x.rpm", "cups-client-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-ipptool-1:2.4.10-18.el10_2.x86_64.rpm", "cups-printerapp-debuginfo-1:2.4.10-18.el10_2.x86_64.rpm", "cups-printerapp-1:2.4.10-18.el10_2.aarch64.rpm", "cups-devel-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-lpd-1:2.4.10-18.el10_2.aarch64.rpm", "cups-lpd-debuginfo-1:2.4.10-18.el10_2.aarch64.rpm", "cups-ipptool-debuginfo-1:2.4.10-18.el10_2.aarch64.rpm", "cups-ipptool-debuginfo-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-1:2.4.10-18.el10_2.s390x.rpm", "cups-lpd-debuginfo-1:2.4.10-18.el10_2.x86_64.rpm","cups-devel-1:2.4.10-18.el10_2.aarch64.rpm", "cups-libs-debuginfo-1:2.4.10-18.el10_2.s390x.rpm", "cups-printerapp-debuginfo-1:2.4.10-18.el10_2.ppc64le.rpm", "cups-libs-1:2.4.10-18.el10_2.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. An important security advisory detailing a moderate CUPS update for Rocky Linux, addressing network access vulnerabilities.. Rocky Linux security update, CUPS security advisory, network vulnerability. . Severity: moderate. LinuxSecurity.com Team
nghttp2 could allow unintended access to network services.. ========================================================================== Ubuntu Security Notice USN-8495-1 July 02, 2026 nghttp2 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: nghttp2 could allow unintended access to network services. Software Description: - nghttp2: HTTP/2 C Library and tools Details: It was discovered that the nghttp2 nghttpx proxy incorrectly handled HTTP/1.1 Upgrade requests that included a Content-Length header and body. A remote attacker could possibly use this issue to perform HTTP request and response smuggling attacks against backend services. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS nghttp2 1.68.0-2ubuntu0.2 Ubuntu 25.10 nghttp2 1.64.0-1.1ubuntu1.2 Ubuntu 24.04 LTS nghttp2 1.59.0-1ubuntu0.4 Ubuntu 22.04 LTS nghttp2 1.43.0-1ubuntu0.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8495-1 CVE-2026-58055 Package Information: https://launchpad.net/ubuntu/+source/nghttp2/1.68.0-2ubuntu0.2 https://launchpad.net/ubuntu/+source/nghttp2/1.64.0-1.1ubuntu1.2 https://launchpad.net/ubuntu/+source/nghttp2/1.59.0-1ubuntu0.4 https://launchpad.net/ubuntu/+source/nghttp2/1.43.0-1ubuntu0.4 . Unintended access through nghttp2 could expose network services. Update now to secure your Ubuntu system against risks.. nghttp2 security issue, Ubuntu network service access, HTTP/2 library vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Ruby could allow unintended access to network services.. ========================================================================== Ubuntu Security Notice USN-8478-1 June 29, 2025 ruby2.7, ruby3.0, ruby3.2, ruby3.3 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Ruby could allow unintended access to network services. Software Description: - ruby3.3: Object-oriented scripting language - ruby3.2: Object-oriented scripting language - ruby3.0: Object-oriented scripting language - ruby2.7: Object-oriented scripting language Details: It was discovered that Ruby's Net::IMAP library did not properly verify that TLS encryption was started after issuing a STARTTLS command. A remote attacker could use this to perform a machine-in-the-middle attack and silently bypass TLS encryption. (CVE-2026-42246) It was discovered that Ruby's Net::IMAP library did not validate string arguments passed to certain commands. A remote attacker could use this to inject arbitrary IMAP commands. (CVE-2026-42257) It was discovered that Ruby's Net::IMAP library was vulnerable to a denial of service attack when authenticating with SCRAM-SHA1 or SCRAM-SHA256. A hostile server could send a very large iteration count value to cause excessive computation in the client. This issue only affected ruby3.3. (CVE-2026-42256) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libruby3.3 3.3.8-2ubuntu3.1 ruby3.3 3.3.8-2ubuntu3.1 Ubuntu 24.04 LTS libruby3.2 3.2.3-1ubuntu0.24.04.8 ruby3.2 3.2.3-1ubuntu0.24.04.8 Ubuntu 22.04 LTS libruby3.0 3.0.2-7ubuntu2.13 ruby3.0 3.0.2-7ubuntu2.13 Ubuntu 20.04 LTS libruby2.7 2.7.0-5ubuntu1.18+esm5 Available with Ubuntu Pro ruby2.7 2.7.0-5ubuntu1.18+esm5 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8478-1 CVE-2026-42246, CVE-2026-42256, CVE-2026-42257 Package Information: https://launchpad.net/ubuntu/+source/ruby3.3/3.3.8-2ubuntu3.1 https://launchpad.net/ubuntu/+source/ruby3.2/3.2.3-1ubuntu0.24.04.8 https://launchpad.net/ubuntu/+source/ruby3.0/3.0.2-7ubuntu2.13 . Update your Ubuntu systems to address critical Ruby security issues including unauthorized access and DoS risks.. Ruby security update Ubuntu network services DoS. . Severity: Important. LinuxSecurity.com Team
Go Networking could allow unintended access to network services.. ========================================================================== Ubuntu Security Notice USN-8416-1 June 09, 2026 golang-golang-x-net-dev vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Go Networking could allow unintended access to network services. Software Description: - golang-golang-x-net-dev: Supplementary Go networking development files Details: It was discovered that Go Networking incorrectly handled certain Punycode-encoded labels in the idna package. An attacker could possibly use this issue to bypass hostname-based access restrictions. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS golang-go.net-dev 1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3 Available with Ubuntu Pro golang-golang-x-net-dev 1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS golang-go.net-dev 1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3 Available with Ubuntu Pro golang-golang-x-net-dev 1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8416-1 CVE-2026-39821 . Update Ubuntu systems to resolve critical Go Networking issues, preventing unauthorized network access.. Ubuntu Pro, Go Networking, golang-golang-x-net-dev, security update. . Severity: Critical. LinuxSecurity.com Team
An update that solves three vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:21978-1 Release Date: 2026-06-02T07:41:04Z Rating: important References: * bsc#1261630 * bsc#1261845 * bsc#1265384 Cross-References: * CVE-2026-23437 * CVE-2026-31406 * CVE-2026-46333 CVSS scores: * CVE-2026-23437 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23437 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23437 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31406 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31406 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31406 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.31.1 fixes various security issues The following security issues were fixed: * CVE-2026-23437: net: shaper: protect late read accesses to the hierarchy (bsc#1261845). * CVE-2026-31406: xfrm: Fix work re-schedule after cancel in xfrm_nat_keepalive_net_fini() (bsc#1261630). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-862=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_31-default-2-160000.1.1 * kernel-livepatch-SLE16_Update_10-debugsource-2-160000.1.1 * kernel-livepatch-6_12_0-160000_31-default-debuginfo-2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23437.html * https://www.suse.com/security/cve/CVE-2026-31406.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261630 * https://bugzilla.suse.com/show_bug.cgi?id=1261845 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 . Important update for SUSE Linux kernel addressing multiple security issues with recommended installation instructions.. SUSE Linux Kernel Patch Security Update Important. . Severity: Important. LinuxSecurity.com Team
An update that solves eight vulnerabilities and contains one feature can now be installed.. # Security update for java-17-openjdk Announcement ID: SUSE-SU-2026:1732-1 Release Date: 2026-05-07T00:43:53Z Rating: important References: * bsc#1259118 * bsc#1262490 * bsc#1262494 * bsc#1262495 * bsc#1262496 * bsc#1262497 * bsc#1262500 * bsc#1262501 * jsc#PED-15898 Cross-References: * CVE-2026-22007 * CVE-2026-22013 * CVE-2026-22016 * CVE-2026-22018 * CVE-2026-22021 * CVE-2026-23865 * CVE-2026-34268 * CVE-2026-34282 CVSS scores: * CVE-2026-22007 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22007 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22007 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22013 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22013 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22013 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22016 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22018 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22018 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22018 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23865 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-23865 ( SUSE ): 5.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-23865 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-34268 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34268 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34268 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34282 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34282 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34282 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Legacy Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities and contains one feature can now be installed. ## Description: This update for java-17-openjdk fixes the following issues: Upgrade to upstream tag jdk-17.0.19+10 (April 2026 CPU). Security issues fixed: * CVE-2026-22007: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of accessible data (bsc#1262490). * CVE-2026-22013: JGSS: unauthenticated attacker with network access via multiple protocols can gain unauthorized access to critical data (bsc#1262494). * CVE-2026-22016: JAXP: unauthenticated attacker with network access via multiple protocols can gain unauthorized to access critical data (bsc#1262495). * CVE-2026-22018: Libraries: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1262496). * CVE-2026-22021: JSSE: unauthenticated attacker with network access via HTTPS can cause a partial denial of service (bsc#1262497). * CVE-2026-23865: freetype2: integer overflow in the `tt_var_load_item_variation_store` function allows for an out-of-bounds read when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts(bsc#1259118). * CVE-2026-34268: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of data (bsc#1262500). * CVE-2026-34282: Networking: unauthenticated attacker with network access via multiple protocols can cause a hang or frequently repeatable crash (bsc#1262501). Other updates and bugfixes: * Provide the timezone-java and tzdata-java (jsc#PED-15898). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1732=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-1732=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1732=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1732=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypperin -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1732=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1732=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1732=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1732=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1732=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1732=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-1732=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1732=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-src-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-jmods-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * openSUSE Leap 15.4 (noarch) * java-17-openjdk-javadoc-17.0.19.0-150400.3.66.2 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 *java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 *java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 ## References: * https://www.suse.com/security/cve/CVE-2026-22007.html * https://www.suse.com/security/cve/CVE-2026-22013.html * https://www.suse.com/security/cve/CVE-2026-22016.html * https://www.suse.com/security/cve/CVE-2026-22018.html * https://www.suse.com/security/cve/CVE-2026-22021.html * https://www.suse.com/security/cve/CVE-2026-23865.html * https://www.suse.com/security/cve/CVE-2026-34268.html * https://www.suse.com/security/cve/CVE-2026-34282.html * https://bugzilla.suse.com/show_bug.cgi?id=1259118 * https://bugzilla.suse.com/show_bug.cgi?id=1262490 * https://bugzilla.suse.com/show_bug.cgi?id=1262494 * https://bugzilla.suse.com/show_bug.cgi?id=1262495 *https://bugzilla.suse.com/show_bug.cgi?id=1262496 * https://bugzilla.suse.com/show_bug.cgi?id=1262497 * https://bugzilla.suse.com/show_bug.cgi?id=1262500 * https://bugzilla.suse.com/show_bug.cgi?id=1262501 * https://jira.suse.com/browse/PED-15898 . Fixes eight security issues and one feature update for java-17-openjdk on SUSE. Critical updates recommended.. java security patch, SUSE update, openjdk vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves eight vulnerabilities and contains one feature can now be installed.. # Security update for java-11-openjdk Announcement ID: SUSE-SU-2026:1703-1 Release Date: 2026-05-06T08:45:05Z Rating: important References: * bsc#1259118 * bsc#1262490 * bsc#1262494 * bsc#1262495 * bsc#1262496 * bsc#1262497 * bsc#1262500 * bsc#1262501 * jsc#PED-15898 Cross-References: * CVE-2026-22007 * CVE-2026-22013 * CVE-2026-22016 * CVE-2026-22018 * CVE-2026-22021 * CVE-2026-23865 * CVE-2026-34268 * CVE-2026-34282 CVSS scores: * CVE-2026-22007 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22007 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22007 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22013 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22013 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22013 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22016 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22018 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22018 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22018 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23865 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-23865 ( SUSE ): 5.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-23865 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-34268 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34268 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34268 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34282 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34282 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34282 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves eight vulnerabilities and contains one feature can now be installed. ## Description: This update for java-11-openjdk fixes the following issues: Upgrade to upstream tag jdk-11.0.31+11 (April 2026 CPU). Security issues fixed: * CVE-2026-22007: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of accessible data (bsc#1262490). * CVE-2026-22013: JGSS: unauthenticated attacker with network access via multiple protocols can gain unauthorized access to critical data (bsc#1262494). * CVE-2026-22016: JAXP: unauthenticated attacker with network access via multiple protocols can gain unauthorized to access critical data (bsc#1262495). * CVE-2026-22018: Libraries: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1262496). * CVE-2026-22021: JSSE: unauthenticated attacker with network access via HTTPS can cause a partial denial of service (bsc#1262497). * CVE-2026-23865: freetype2: integeroverflow in the `tt_var_load_item_variation_store` function allows for an out-of-bounds read when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts(bsc#1259118). * CVE-2026-34268: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of data (bsc#1262500). * CVE-2026-34282: Networking: unauthenticated attacker with network access via multiple protocols can cause a hang or frequently repeatable crash (bsc#1262501). Other updates and bugfixes: * Provide the timezone-java and tzdata-java (jsc#PED-15898). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-1703=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-1703=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-headless-11.0.31.0-3.99.1 * java-11-openjdk-debuginfo-11.0.31.0-3.99.1 * java-11-openjdk-11.0.31.0-3.99.1 * java-11-openjdk-demo-11.0.31.0-3.99.1 * java-11-openjdk-devel-11.0.31.0-3.99.1 * java-11-openjdk-debugsource-11.0.31.0-3.99.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * java-11-openjdk-headless-11.0.31.0-3.99.1 * java-11-openjdk-debuginfo-11.0.31.0-3.99.1 * java-11-openjdk-11.0.31.0-3.99.1 * java-11-openjdk-demo-11.0.31.0-3.99.1 * java-11-openjdk-devel-11.0.31.0-3.99.1 * java-11-openjdk-debugsource-11.0.31.0-3.99.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22007.html * https://www.suse.com/security/cve/CVE-2026-22013.html * https://www.suse.com/security/cve/CVE-2026-22016.html *https://www.suse.com/security/cve/CVE-2026-22018.html * https://www.suse.com/security/cve/CVE-2026-22021.html * https://www.suse.com/security/cve/CVE-2026-23865.html * https://www.suse.com/security/cve/CVE-2026-34268.html * https://www.suse.com/security/cve/CVE-2026-34282.html * https://bugzilla.suse.com/show_bug.cgi?id=1259118 * https://bugzilla.suse.com/show_bug.cgi?id=1262490 * https://bugzilla.suse.com/show_bug.cgi?id=1262494 * https://bugzilla.suse.com/show_bug.cgi?id=1262495 * https://bugzilla.suse.com/show_bug.cgi?id=1262496 * https://bugzilla.suse.com/show_bug.cgi?id=1262497 * https://bugzilla.suse.com/show_bug.cgi?id=1262500 * https://bugzilla.suse.com/show_bug.cgi?id=1262501 * https://jira.suse.com/browse/PED-15898 . Update for java-11-openjdk resolves eight issues and enhances security against unauthorized access on SUSE.. SUSE Security, java-11-openjdk, network vulnerability, update patch, SUSE Linux recommendation. . Severity: Important. LinuxSecurity.com Team
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for strongswan ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20547-1 Rating: important References: * bsc#1257359 * bsc#1259472 Cross-References: * CVE-2025-9615 * CVE-2026-25075 CVSS scores: * CVE-2025-9615 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-25075 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25075 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for strongswan fixes the following issues: Update to strongswan 6.0.4: - CVE-2025-9615: NetworkManager File Access (bsc#1257359). - CVE-2026-25075: Integer Underflow When Handling EAP-TTLS AVP (bsc#1259472). Changes for strongswan: - Fixed a vulnerability in the NetworkManager plugin that potentially allows using credentials of other local users. This vulnerability has been registered as CVE-2025-9615. - The maximum supported length for section names in swanctl.conf has been increased to the upper limit of 256 characters that's enforced by VICI. - Prevent a crash if a confused peer rekeys a Child SA twice before sending a delete. - Fixed a memory leak if a peer's self-signed certificate is untrusted. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-570=1 Package List: - openSUSE Leap 16.0: strongswan-6.0.4-160000.1.1 strongswan-doc-6.0.4-160000.1.1 strongswan-fips-6.0.4-160000.1.1 strongswan-ipsec-6.0.4-160000.1.1 strongswan-mysql-6.0.4-160000.1.1 strongswan-nm-6.0.4-160000.1.1 strongswan-sqlite-6.0.4-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2025-9615.html * https://www.suse.com/security/cve/CVE-2026-25075.html . Important security advisory for openSUSE strongswan fixes issues including network access vulnerabilities and integer underflow.. strongswan update, openSUSE advisory, security patch. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.