Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Wget could be made to connect to unintended network resources.. ========================================================================== Ubuntu Security Notice USN-8572-1 July 20, 2026 wget vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Wget could be made to connect to unintended network resources. Software Description: - wget: retrieves files from the web Details: It was discovered that Wget did not properly validate the IP address provided in an FTP PASV response when operating in FTP passive mode. A remote attacker controlling a malicious FTP server, or an HTTP server that redirects to an FTP URL, could possibly use this issue to redirect Wget's data connection to an arbitrary address and perform server-side request forgery, potentially accessing localhost services or internal network resources. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS wget 1.25.0-2ubuntu4.3 Ubuntu 24.04 LTS wget 1.21.4-1ubuntu4.4 Ubuntu 22.04 LTS wget 1.21.2-2ubuntu1.4 Ubuntu 20.04 LTS wget 1.20.3-1ubuntu2.1+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS wget 1.19.4-1ubuntu2.2+esm4 Available with Ubuntu Pro Ubuntu 16.04 LTS wget 1.17.1-1ubuntu1.5+esm4 Available with Ubuntu Pro Ubuntu 14.04 LTS wget 1.15-1ubuntu1.14.04.5+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8572-1 CVE-2026-15146 Package Information: https://launchpad.net/ubuntu/+source/wget/1.25.0-2ubuntu4.3 https://launchpad.net/ubuntu/+source/wget/1.21.4-1ubuntu4.4 https://launchpad.net/ubuntu/+source/wget/1.21.2-2ubuntu1.4 . Address a Wget issue in Ubuntu which could allow unintended network connections, exposing internal resources.. Ubuntu Wget security update, network vulnerability fix, server-side request forgery mitigation. . Severity: Important. LinuxSecurity.com Team
Go Cryptography could be made to crash if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-8519-1 July 09, 2026 golang-go.crypto vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Go Cryptography could be made to crash if it received specially crafted network traffic. Software Description: - golang-go.crypto: Supplementary Go cryptography libraries Details: Jakub Ciolek and Nicola Murino discovered that Go Cryptography incorrectly handled SSH agent responses. An attacker could use this to cause a denial of service. (CVE-2025-47913) Yuichi Watanabe discovered that Go Cryptography incorrectly handled SSH key exchanges. An attacker could use this to cause a denial of service. (CVE-2025-22869) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 golang-golang-x-crypto-dev 1:0.25.0-1ubuntu0.1 Ubuntu 24.04 LTS golang-golang-x-crypto-dev 1:0.19.0-1ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 22.04 LTS golang-golang-x-crypto-dev 1:0.0~git20211202.5770296-1ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 20.04 LTS golang-golang-x-crypto-dev 1:0.0~git20200221.2aa609c-1ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS golang-go.crypto-dev 1:0.0~git20170629.0.5ef0053-2ubuntu0.1~esm3 Available with Ubuntu Pro golang-golang-x-crypto-dev 1:0.0~git20170629.0.5ef0053-2ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS golang-go.crypto-dev 1:0.0~git20151201.0.7b85b09-2ubuntu0.1~esm3 Available with Ubuntu Pro golang-golang-x-crypto-dev 1:0.0~git20151201.0.7b85b09-2ubuntu0.1~esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8519-1 CVE-2025-22869, CVE-2025-47913 Package Information: https://launchpad.net/ubuntu/+source/golang-go.crypto/1:0.25.0-1ubuntu0.1 . Go Cryptography on Ubuntu faces significant risk from crafted traffic, leading to potential crashes requiring urgent updates.. Ubuntu security, Go Cryptography, denial of service, update instructions, security vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves five vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 53 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2511-1 Release Date: 2026-06-23T05:04:26Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.214 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2513=1 SUSE-SLE- Module-Live-Patching-15-SP4-2026-2510=1 SUSE-SLE-Module-Live- Patching-15-SP4-2026-2511=1 SUSE-SLE-Module-Live-Patching-15-SP4-2026-2512=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2510=1 SUSE-2026-2511=1 SUSE-2026-2512=1 SUSE-2026-2513=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_197-default-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-debuginfo-4-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_47-debugsource-9-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_49-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-debuginfo-9-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_53-debugsource-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-2-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_51-debugsource-4-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-debuginfo-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-debuginfo-5-150400.2.1 *kernel-livepatch-5_14_21-150400_24_205-default-4-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-9-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_197-default-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-debuginfo-4-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_47-debugsource-9-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_49-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-debuginfo-9-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_53-debugsource-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-2-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_51-debugsource-4-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-debuginfo-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-4-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-9-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 . Update for openSUSE fixing five security issues in the kernel addressing important vulnerabilities for system integrity.. openSUSE Kernel Update, Security Issues, Kernel Vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Postfix could be made to crash if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-8253-2 June 03, 2026 postfix vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Postfix could be made to crash if it received specially crafted network traffic. Software Description: - postfix: High-performance mail transport agent Details: USN-8253-1 fixed a vulnerability in Postfix. This update provides the corresponding fix for Postfix on Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: Kamil Frankowicz discovered that Postfix incorrectly handled certain enhanced status codes. A remote attacker could possibly use this issue to cause Postfix to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS postfix 3.4.13-0ubuntu1.4+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS postfix 3.3.0-1ubuntu0.4+esm4 Available with Ubuntu Pro Ubuntu 16.04 LTS postfix 3.1.0-3ubuntu0.4+esm4 Available with Ubuntu Pro Ubuntu 14.04 LTS postfix 2.11.0-1ubuntu1.2+esm4 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8253-2 https://ubuntu.com/security/notices/USN-8253-1 CVE-2026-43964 . A critical update for Postfix helps mitigate denial of service on Ubuntu 14.04 to 20.04 LTS against crafted traffic.. Postfix Security Update, Ubuntu20.04 Advisory, Denial of Service Threat. . Severity: Critical. LinuxSecurity.com Team
.NET could be made to consume excessive resources if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-8298-1 May 25, 2026 dotnet8, dotnet9, dotnet10 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: .NET could be made to consume excessive resources if it received specially crafted network traffic. Software Description: - dotnet10: .NET CLI tools and runtime - dotnet8: .NET CLI tools and runtime - dotnet9: .NET CLI tools and runtime Details: Muhammad Abdul Rehman discovered that .NET incorrectly handled certain network requests, leading to a loop with an unreachable exit condition. A remote attacker could possibly use this issue to consume excessive resources, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS aspnetcore-runtime-10.0 10.0.8-0ubuntu1~26.04.1 dotnet-host-10.0 10.0.8-0ubuntu1~26.04.1 dotnet-hostfxr-10.0 10.0.8-0ubuntu1~26.04.1 dotnet-runtime-10.0 10.0.8-0ubuntu1~26.04.1 dotnet-sdk-10.0 10.0.108-0ubuntu1~26.04.1 dotnet-sdk-aot-10.0 10.0.108-0ubuntu1~26.04.1 dotnet-sdk-dbg-10.0 10.0.108-0ubuntu1~26.04.1 dotnet10 10.0.108-10.0.8-0ubuntu1~26.04.1 Ubuntu 25.10 aspnetcore-runtime-10.0 10.0.8-0ubuntu1~25.10.1 aspnetcore-runtime-8.0 8.0.27-0ubuntu1~25.10.1 aspnetcore-runtime-9.0 9.0.16-0ubuntu1~25.10.1 dotnet-host-10.0 10.0.8-0ubuntu1~25.10.1 dotnet-host-8.0 8.0.27-0ubuntu1~25.10.1 dotnet-host-9.0 9.0.16-0ubuntu1~25.10.1 dotnet-hostfxr-10.0 10.0.8-0ubuntu1~25.10.1 dotnet-hostfxr-8.0 8.0.27-0ubuntu1~25.10.1 dotnet-hostfxr-9.0 9.0.16-0ubuntu1~25.10.1 dotnet-runtime-10.0 10.0.8-0ubuntu1~25.10.1 dotnet-runtime-8.0 8.0.27-0ubuntu1~25.10.1 dotnet-runtime-9.0 9.0.16-0ubuntu1~25.10.1 dotnet-sdk-10.0 10.0.108-0ubuntu1~25.10.1 dotnet-sdk-8.0 8.0.127-0ubuntu1~25.10.1 dotnet-sdk-9.0 9.0.117-0ubuntu1~25.10.1 dotnet-sdk-aot-10.0 10.0.108-0ubuntu1~25.10.1 dotnet-sdk-aot-9.0 9.0.117-0ubuntu1~25.10.1 dotnet-sdk-dbg-10.0 10.0.108-0ubuntu1~25.10.1 dotnet-sdk-dbg-8.0 8.0.127-0ubuntu1~25.10.1 dotnet-sdk-dbg-9.0 9.0.117-0ubuntu1~25.10.1 dotnet10 10.0.108-10.0.8-0ubuntu1~25.10.1 dotnet8 8.0.127-8.0.27-0ubuntu1~25.10.1 dotnet9 9.0.117-9.0.16-0ubuntu1~25.10.1 Ubuntu 24.04 LTS aspnetcore-runtime-10.0 10.0.8-0ubuntu1~24.04.1 aspnetcore-runtime-8.0 8.0.27-0ubuntu1~24.04.1 dotnet-host-10.0 10.0.8-0ubuntu1~24.04.1 dotnet-host-8.0 8.0.27-0ubuntu1~24.04.1 dotnet-hostfxr-10.0 10.0.8-0ubuntu1~24.04.1 dotnet-hostfxr-8.0 8.0.27-0ubuntu1~24.04.1 dotnet-runtime-10.0 10.0.8-0ubuntu1~24.04.1 dotnet-runtime-8.0 8.0.27-0ubuntu1~24.04.1 dotnet-sdk-10.0 10.0.108-0ubuntu1~24.04.1 dotnet-sdk-8.0 8.0.127-0ubuntu1~24.04.1 dotnet-sdk-aot-10.0 10.0.108-0ubuntu1~24.04.1 dotnet-sdk-dbg-10.0 10.0.108-0ubuntu1~24.04.1 dotnet10 10.0.108-10.0.8-0ubuntu1~24.04.1 dotnet8 8.0.127-8.0.27-0ubuntu1~24.04.1 Ubuntu 22.04 LTS aspnetcore-runtime-8.0 8.0.27-0ubuntu1~22.04.1 dotnet-host-8.0 8.0.27-0ubuntu1~22.04.1 dotnet-hostfxr-8.0 8.0.27-0ubuntu1~22.04.1 dotnet-runtime-8.0 8.0.27-0ubuntu1~22.04.1 dotnet-sdk-8.0 8.0.127-0ubuntu1~22.04.1 dotnet8 8.0.127-8.0.27-0ubuntu1~22.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8298-1 CVE-2026-42899 Package Information: https://launchpad.net/ubuntu/+source/dotnet10/10.0.108-10.0.8-0ubuntu1~26.04.1 https://launchpad.net/ubuntu/+source/dotnet10/10.0.108-10.0.8-0ubuntu1~25.10.1 https://launchpad.net/ubuntu/+source/dotnet8/8.0.127-8.0.27-0ubuntu1~25.10.1 https://launchpad.net/ubuntu/+source/dotnet9/9.0.117-9.0.16-0ubuntu1~25.10.1 https://launchpad.net/ubuntu/+source/dotnet10/10.0.108-10.0.8-0ubuntu1~24.04.1 https://launchpad.net/ubuntu/+source/dotnet8/8.0.127-8.0.27-0ubuntu1~24.04.1 https://launchpad.net/ubuntu/+source/dotnet8/8.0.127-8.0.27-0ubuntu1~22.04.1 . A critical security advisory for Ubuntu .NET handling excessive resource consumption due to crafted network traffic.. Ubuntu .NET Security, excessive resources, denial of service. . Severity: Critical. LinuxSecurity.com Team
An update that solves 11 vulnerabilities and has 13 bug fixes can now be installed.. openSUSE security update: security update for go1.26 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20762-1 Rating: important References: * bsc#1170826 * bsc#1255111 * bsc#1264499 * bsc#1264500 * bsc#1264501 * bsc#1264502 * bsc#1264503 * bsc#1264504 * bsc#1264505 * bsc#1264506 * bsc#1264507 * bsc#1264508 * bsc#1264509 Cross-References: * CVE-2026-33811 * CVE-2026-33814 * CVE-2026-39817 * CVE-2026-39819 * CVE-2026-39820 * CVE-2026-39823 * CVE-2026-39825 * CVE-2026-39826 * CVE-2026-39836 * CVE-2026-42499 * CVE-2026-42501 CVSS scores: * CVE-2026-33811 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39817 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N * CVE-2026-39819 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-39820 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39823 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39825 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-39826 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39836 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42499 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42501 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 11 vulnerabilities and has 13 bug fixes can now be installed. Description: This update for go1.26 fixes the following issues Security issues: - CVE-2026-33811: net: crash when handling long CNAME response (bsc#1264508). - CVE-2026-33814: net/http: infinite loop in HTTP/2 transport when given badSETTINGS_MAX_FRAME_SIZE (bsc#1264506). - CVE-2026-39817: cmd/go: "go tool pack" does not sanitize output paths (bsc#1264505). - CVE-2026-39819: cmd/go: "go bug" follows symlinks in predictable temporary filenames (bsc#1264504). - CVE-2026-39820: net/mail: quadratic string concatentation in consumeComment (bsc#1264503). - CVE-2026-39823: html/template: bypass of meta content URL escaping causes XSS (bsc#1264509). - CVE-2026-39825: net/http/httputil: ReverseProxy forwards queries with more than urlmaxqueryparams parameters (bsc#1264500). - CVE-2026-39826: html/template: escaper bypass leads to XSS (bsc#1264507). - CVE-2026-39836: net: panic in Dial and LookupPort when handling NUL byte on Windows (bsc#1264501). - CVE-2026-42499: net/mail: quadratic string concatenation in consumePhrase (bsc#1264502). - CVE-2026-42501: cmd/go: malicious module proxy can bypass checksum database (bsc#1264499). Non security issues: - Updated to go1.26.3 (bsc#1255111). - Go packages miss binutils-gold dependency (bsc#1170826). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-758=1 Package List: - openSUSE Leap 16.0: go1.26-1.26.3-160000.1.1 go1.26-doc-1.26.3-160000.1.1 go1.26-libstd-1.26.3-160000.1.1 go1.26-race-1.26.3-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-33811.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39817.html * https://www.suse.com/security/cve/CVE-2026-39819.html * https://www.suse.com/security/cve/CVE-2026-39820.html * https://www.suse.com/security/cve/CVE-2026-39823.html * https://www.suse.com/security/cve/CVE-2026-39825.html * https://www.suse.com/security/cve/CVE-2026-39826.html * https://www.suse.com/security/cve/CVE-2026-39836.html *https://www.suse.com/security/cve/CVE-2026-42499.html * https://www.suse.com/security/cve/CVE-2026-42501.html . An update for openSUSE addressing 11 vulnerabilities and 13 bug fixes is now available for installation.. openSUSE security update, go1.26 vulnerabilities, network security fixes. . Severity: Important. LinuxSecurity.com Team
An update that fixes 6 vulnerabilities is now available.. openSUSE Security Update: Security update for tor ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0164-1 Rating: critical References: #1264341 #1264342 #1264343 #1264344 #1264345 #1264346 Cross-References: CVE-2026-44597 CVE-2026-44599 CVE-2026-44600 CVE-2026-44601 CVE-2026-44602 CVE-2026-44603 Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: This update for tor fixes the following issues: - Update to 0.4.9.8 * Fix out-of-bounds read (boo#1264341, CVE-2026-44597, TROVE-2026-011) * Do not attempt or accept BEGIN_DIR via conflux legs (boo#1264342, CVE-2026-44599,TROVE-2026-008) * Adjust conflux out-of-order queue accounting when clearing a queue (boo#1264343, CVE-2026-44600, TROVE-2026-010) * Fix a client-side crash caused by double-close of a circuit while under circuit queue memory pressure (boo#1264344, CVE-2026-44601, TROVE-2026-009) * Fix null pointer dereference when receiving a CERT cell out of order (boo#1264345, CVE-2026-44602, TROVE-2026-006) * Fix off-by-one out-of-bounds read if a malformed BEGIN cell is received (boo#1264346, CVE-2026-44603, TROVE-2026-007) - upate to 0.4.9.5: * first stable release in the 0.4.9 series * introduces a new circuit-level encryption design for better client security * introduce a more scalable way for large relay operators to annotate which relays they run so clients can avoid using too many of them in a single circuit Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypperpatch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-164=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 ppc64le s390x x86_64): tor-0.4.9.8-bp157.2.9.1 References: https://www.suse.com/security/cve/CVE-2026-44597.html https://www.suse.com/security/cve/CVE-2026-44599.html https://www.suse.com/security/cve/CVE-2026-44600.html https://www.suse.com/security/cve/CVE-2026-44601.html https://www.suse.com/security/cve/CVE-2026-44602.html https://www.suse.com/security/cve/CVE-2026-44603.html https://bugzilla.suse.com/1264341 https://bugzilla.suse.com/1264342 https://bugzilla.suse.com/1264343 https://bugzilla.suse.com/1264344 https://bugzilla.suse.com/1264345 https://bugzilla.suse.com/1264346 . Critical openSUSE update for tor addresses 6 vulnerabilities, enhancing security and functionality. Install recommended patches.. openSUSE Security,Tor Update,Critical Patch,Network Security. . Severity: Critical. LinuxSecurity.com Team
An update that solves four vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 67 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:1780-1 Release Date: 2026-05-08T17:04:05Z Rating: important References: * bsc#1258073 * bsc#1258655 * bsc#1259126 * bsc#1263689 Cross-References: * CVE-2025-38375 * CVE-2026-23004 * CVE-2026-23204 * CVE-2026-31431 CVSS scores: * CVE-2025-38375 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38375 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38375 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23004 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23004 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23004 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23204 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-23204 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23204 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23204 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31431 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31431 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 4.12.14-122.255 fixes various security issues The following security issues were fixed: * CVE-2025-38375: virtio-net: ensure thereceived length does not exceed allocated size (bsc#1258073). * CVE-2026-23004: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() (bsc#1258655). * CVE-2026-23204: net/sched: cls_u32: use skb_header_pointer_careful() (bsc#1259126). * CVE-2026-31431: crypto: algif_aead - Revert to operating out-of-place (bsc#1263689). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-1780=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_255-default-17-2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-38375.html * https://www.suse.com/security/cve/CVE-2026-23004.html * https://www.suse.com/security/cve/CVE-2026-23204.html * https://www.suse.com/security/cve/CVE-2026-31431.html * https://bugzilla.suse.com/show_bug.cgi?id=1258073 * https://bugzilla.suse.com/show_bug.cgi?id=1258655 * https://bugzilla.suse.com/show_bug.cgi?id=1259126 * https://bugzilla.suse.com/show_bug.cgi?id=1263689 . Four vulnerabilities in SUSE Linux kernel now patched; critical update for kernel security.. SUSE Linux Enterprise, kernel update, security patch, remote access, Linux vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.