Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 266 articles for you...
172

Ubuntu 26.04 Wget Important Server-Side Request Forgery Vuln USN-8572-1

Wget could be made to connect to unintended network resources.. ========================================================================== Ubuntu Security Notice USN-8572-1 July 20, 2026 wget vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Wget could be made to connect to unintended network resources. Software Description: - wget: retrieves files from the web Details: It was discovered that Wget did not properly validate the IP address provided in an FTP PASV response when operating in FTP passive mode. A remote attacker controlling a malicious FTP server, or an HTTP server that redirects to an FTP URL, could possibly use this issue to redirect Wget's data connection to an arbitrary address and perform server-side request forgery, potentially accessing localhost services or internal network resources. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS wget 1.25.0-2ubuntu4.3 Ubuntu 24.04 LTS wget 1.21.4-1ubuntu4.4 Ubuntu 22.04 LTS wget 1.21.2-2ubuntu1.4 Ubuntu 20.04 LTS wget 1.20.3-1ubuntu2.1+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS wget 1.19.4-1ubuntu2.2+esm4 Available with Ubuntu Pro Ubuntu 16.04 LTS wget 1.17.1-1ubuntu1.5+esm4 Available with Ubuntu Pro Ubuntu 14.04 LTS wget 1.15-1ubuntu1.14.04.5+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8572-1 CVE-2026-15146 Package Information: https://launchpad.net/ubuntu/+source/wget/1.25.0-2ubuntu4.3 https://launchpad.net/ubuntu/+source/wget/1.21.4-1ubuntu4.4 https://launchpad.net/ubuntu/+source/wget/1.21.2-2ubuntu1.4 . Address a Wget issue in Ubuntu which could allow unintended network connections, exposing internal resources.. Ubuntu Wget security update, network vulnerability fix, server-side request forgery mitigation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 20, 2026 Important Ubuntu
172

Ubuntu 25.10 Go Cryptography Important Denial of Service Vuln USN-8519-1

Go Cryptography could be made to crash if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-8519-1 July 09, 2026 golang-go.crypto vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Go Cryptography could be made to crash if it received specially crafted network traffic. Software Description: - golang-go.crypto: Supplementary Go cryptography libraries Details: Jakub Ciolek and Nicola Murino discovered that Go Cryptography incorrectly handled SSH agent responses. An attacker could use this to cause a denial of service. (CVE-2025-47913) Yuichi Watanabe discovered that Go Cryptography incorrectly handled SSH key exchanges. An attacker could use this to cause a denial of service. (CVE-2025-22869) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 golang-golang-x-crypto-dev 1:0.25.0-1ubuntu0.1 Ubuntu 24.04 LTS golang-golang-x-crypto-dev 1:0.19.0-1ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 22.04 LTS golang-golang-x-crypto-dev 1:0.0~git20211202.5770296-1ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 20.04 LTS golang-golang-x-crypto-dev 1:0.0~git20200221.2aa609c-1ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS golang-go.crypto-dev 1:0.0~git20170629.0.5ef0053-2ubuntu0.1~esm3 Available with Ubuntu Pro golang-golang-x-crypto-dev 1:0.0~git20170629.0.5ef0053-2ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS golang-go.crypto-dev 1:0.0~git20151201.0.7b85b09-2ubuntu0.1~esm3 Available with Ubuntu Pro golang-golang-x-crypto-dev 1:0.0~git20151201.0.7b85b09-2ubuntu0.1~esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8519-1 CVE-2025-22869, CVE-2025-47913 Package Information: https://launchpad.net/ubuntu/+source/golang-go.crypto/1:0.25.0-1ubuntu0.1 . Go Cryptography on Ubuntu faces significant risk from crafted traffic, leading to potential crashes requiring urgent updates.. Ubuntu security, Go Cryptography, denial of service, update instructions, security vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 09, 2026 Important Ubuntu
202

openSUSE Kernel Important Fix Heap Overflow and More 2026-2511-1

An update that solves five vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 53 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2511-1 Release Date: 2026-06-23T05:04:26Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.214 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2513=1 SUSE-SLE- Module-Live-Patching-15-SP4-2026-2510=1 SUSE-SLE-Module-Live- Patching-15-SP4-2026-2511=1 SUSE-SLE-Module-Live-Patching-15-SP4-2026-2512=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2510=1 SUSE-2026-2511=1 SUSE-2026-2512=1 SUSE-2026-2513=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_197-default-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-debuginfo-4-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_47-debugsource-9-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_49-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-debuginfo-9-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_53-debugsource-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-2-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_51-debugsource-4-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-debuginfo-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-debuginfo-5-150400.2.1 *kernel-livepatch-5_14_21-150400_24_205-default-4-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-9-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_197-default-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-debuginfo-4-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_47-debugsource-9-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_49-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-debuginfo-9-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_53-debugsource-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-2-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_51-debugsource-4-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-debuginfo-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-4-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-9-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 . Update for openSUSE fixing five security issues in the kernel addressing important vulnerabilities for system integrity.. openSUSE Kernel Update, Security Issues, Kernel Vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 23, 2026 Important OpenSUSE
172

Ubuntu 20.04 Postfix Critical Denial of Service USN-8253-2 CVE-2026-43964

Postfix could be made to crash if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-8253-2 June 03, 2026 postfix vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Postfix could be made to crash if it received specially crafted network traffic. Software Description: - postfix: High-performance mail transport agent Details: USN-8253-1 fixed a vulnerability in Postfix. This update provides the corresponding fix for Postfix on Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: Kamil Frankowicz discovered that Postfix incorrectly handled certain enhanced status codes. A remote attacker could possibly use this issue to cause Postfix to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS postfix 3.4.13-0ubuntu1.4+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS postfix 3.3.0-1ubuntu0.4+esm4 Available with Ubuntu Pro Ubuntu 16.04 LTS postfix 3.1.0-3ubuntu0.4+esm4 Available with Ubuntu Pro Ubuntu 14.04 LTS postfix 2.11.0-1ubuntu1.2+esm4 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8253-2 https://ubuntu.com/security/notices/USN-8253-1 CVE-2026-43964 . A critical update for Postfix helps mitigate denial of service on Ubuntu 14.04 to 20.04 LTS against crafted traffic.. Postfix Security Update, Ubuntu20.04 Advisory, Denial of Service Threat. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 05, 2026 Critical Ubuntu
172

Ubuntu 26.04 LTS Dotnet Critical Denial Service Issue USN-8298-1

.NET could be made to consume excessive resources if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-8298-1 May 25, 2026 dotnet8, dotnet9, dotnet10 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: .NET could be made to consume excessive resources if it received specially crafted network traffic. Software Description: - dotnet10: .NET CLI tools and runtime - dotnet8: .NET CLI tools and runtime - dotnet9: .NET CLI tools and runtime Details: Muhammad Abdul Rehman discovered that .NET incorrectly handled certain network requests, leading to a loop with an unreachable exit condition. A remote attacker could possibly use this issue to consume excessive resources, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS aspnetcore-runtime-10.0 10.0.8-0ubuntu1~26.04.1 dotnet-host-10.0 10.0.8-0ubuntu1~26.04.1 dotnet-hostfxr-10.0 10.0.8-0ubuntu1~26.04.1 dotnet-runtime-10.0 10.0.8-0ubuntu1~26.04.1 dotnet-sdk-10.0 10.0.108-0ubuntu1~26.04.1 dotnet-sdk-aot-10.0 10.0.108-0ubuntu1~26.04.1 dotnet-sdk-dbg-10.0 10.0.108-0ubuntu1~26.04.1 dotnet10 10.0.108-10.0.8-0ubuntu1~26.04.1 Ubuntu 25.10 aspnetcore-runtime-10.0 10.0.8-0ubuntu1~25.10.1 aspnetcore-runtime-8.0 8.0.27-0ubuntu1~25.10.1 aspnetcore-runtime-9.0 9.0.16-0ubuntu1~25.10.1 dotnet-host-10.0 10.0.8-0ubuntu1~25.10.1 dotnet-host-8.0 8.0.27-0ubuntu1~25.10.1 dotnet-host-9.0 9.0.16-0ubuntu1~25.10.1 dotnet-hostfxr-10.0 10.0.8-0ubuntu1~25.10.1 dotnet-hostfxr-8.0 8.0.27-0ubuntu1~25.10.1 dotnet-hostfxr-9.0 9.0.16-0ubuntu1~25.10.1 dotnet-runtime-10.0 10.0.8-0ubuntu1~25.10.1 dotnet-runtime-8.0 8.0.27-0ubuntu1~25.10.1 dotnet-runtime-9.0 9.0.16-0ubuntu1~25.10.1 dotnet-sdk-10.0 10.0.108-0ubuntu1~25.10.1 dotnet-sdk-8.0 8.0.127-0ubuntu1~25.10.1 dotnet-sdk-9.0 9.0.117-0ubuntu1~25.10.1 dotnet-sdk-aot-10.0 10.0.108-0ubuntu1~25.10.1 dotnet-sdk-aot-9.0 9.0.117-0ubuntu1~25.10.1 dotnet-sdk-dbg-10.0 10.0.108-0ubuntu1~25.10.1 dotnet-sdk-dbg-8.0 8.0.127-0ubuntu1~25.10.1 dotnet-sdk-dbg-9.0 9.0.117-0ubuntu1~25.10.1 dotnet10 10.0.108-10.0.8-0ubuntu1~25.10.1 dotnet8 8.0.127-8.0.27-0ubuntu1~25.10.1 dotnet9 9.0.117-9.0.16-0ubuntu1~25.10.1 Ubuntu 24.04 LTS aspnetcore-runtime-10.0 10.0.8-0ubuntu1~24.04.1 aspnetcore-runtime-8.0 8.0.27-0ubuntu1~24.04.1 dotnet-host-10.0 10.0.8-0ubuntu1~24.04.1 dotnet-host-8.0 8.0.27-0ubuntu1~24.04.1 dotnet-hostfxr-10.0 10.0.8-0ubuntu1~24.04.1 dotnet-hostfxr-8.0 8.0.27-0ubuntu1~24.04.1 dotnet-runtime-10.0 10.0.8-0ubuntu1~24.04.1 dotnet-runtime-8.0 8.0.27-0ubuntu1~24.04.1 dotnet-sdk-10.0 10.0.108-0ubuntu1~24.04.1 dotnet-sdk-8.0 8.0.127-0ubuntu1~24.04.1 dotnet-sdk-aot-10.0 10.0.108-0ubuntu1~24.04.1 dotnet-sdk-dbg-10.0 10.0.108-0ubuntu1~24.04.1 dotnet10 10.0.108-10.0.8-0ubuntu1~24.04.1 dotnet8 8.0.127-8.0.27-0ubuntu1~24.04.1 Ubuntu 22.04 LTS aspnetcore-runtime-8.0 8.0.27-0ubuntu1~22.04.1 dotnet-host-8.0 8.0.27-0ubuntu1~22.04.1 dotnet-hostfxr-8.0 8.0.27-0ubuntu1~22.04.1 dotnet-runtime-8.0 8.0.27-0ubuntu1~22.04.1 dotnet-sdk-8.0 8.0.127-0ubuntu1~22.04.1 dotnet8 8.0.127-8.0.27-0ubuntu1~22.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8298-1 CVE-2026-42899 Package Information: https://launchpad.net/ubuntu/+source/dotnet10/10.0.108-10.0.8-0ubuntu1~26.04.1 https://launchpad.net/ubuntu/+source/dotnet10/10.0.108-10.0.8-0ubuntu1~25.10.1 https://launchpad.net/ubuntu/+source/dotnet8/8.0.127-8.0.27-0ubuntu1~25.10.1 https://launchpad.net/ubuntu/+source/dotnet9/9.0.117-9.0.16-0ubuntu1~25.10.1 https://launchpad.net/ubuntu/+source/dotnet10/10.0.108-10.0.8-0ubuntu1~24.04.1 https://launchpad.net/ubuntu/+source/dotnet8/8.0.127-8.0.27-0ubuntu1~24.04.1 https://launchpad.net/ubuntu/+source/dotnet8/8.0.127-8.0.27-0ubuntu1~22.04.1 . A critical security advisory for Ubuntu .NET handling excessive resource consumption due to crafted network traffic.. Ubuntu .NET Security, excessive resources, denial of service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 25, 2026 Critical Ubuntu
202

openSUSE Go1.26 Important Security Update Advisory 2026-20762-1

An update that solves 11 vulnerabilities and has 13 bug fixes can now be installed.. openSUSE security update: security update for go1.26 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20762-1 Rating: important References: * bsc#1170826 * bsc#1255111 * bsc#1264499 * bsc#1264500 * bsc#1264501 * bsc#1264502 * bsc#1264503 * bsc#1264504 * bsc#1264505 * bsc#1264506 * bsc#1264507 * bsc#1264508 * bsc#1264509 Cross-References: * CVE-2026-33811 * CVE-2026-33814 * CVE-2026-39817 * CVE-2026-39819 * CVE-2026-39820 * CVE-2026-39823 * CVE-2026-39825 * CVE-2026-39826 * CVE-2026-39836 * CVE-2026-42499 * CVE-2026-42501 CVSS scores: * CVE-2026-33811 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39817 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N * CVE-2026-39819 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-39820 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39823 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39825 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-39826 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39836 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42499 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42501 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 11 vulnerabilities and has 13 bug fixes can now be installed. Description: This update for go1.26 fixes the following issues Security issues: - CVE-2026-33811: net: crash when handling long CNAME response (bsc#1264508). - CVE-2026-33814: net/http: infinite loop in HTTP/2 transport when given badSETTINGS_MAX_FRAME_SIZE (bsc#1264506). - CVE-2026-39817: cmd/go: "go tool pack" does not sanitize output paths (bsc#1264505). - CVE-2026-39819: cmd/go: "go bug" follows symlinks in predictable temporary filenames (bsc#1264504). - CVE-2026-39820: net/mail: quadratic string concatentation in consumeComment (bsc#1264503). - CVE-2026-39823: html/template: bypass of meta content URL escaping causes XSS (bsc#1264509). - CVE-2026-39825: net/http/httputil: ReverseProxy forwards queries with more than urlmaxqueryparams parameters (bsc#1264500). - CVE-2026-39826: html/template: escaper bypass leads to XSS (bsc#1264507). - CVE-2026-39836: net: panic in Dial and LookupPort when handling NUL byte on Windows (bsc#1264501). - CVE-2026-42499: net/mail: quadratic string concatenation in consumePhrase (bsc#1264502). - CVE-2026-42501: cmd/go: malicious module proxy can bypass checksum database (bsc#1264499). Non security issues: - Updated to go1.26.3 (bsc#1255111). - Go packages miss binutils-gold dependency (bsc#1170826). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-758=1 Package List: - openSUSE Leap 16.0: go1.26-1.26.3-160000.1.1 go1.26-doc-1.26.3-160000.1.1 go1.26-libstd-1.26.3-160000.1.1 go1.26-race-1.26.3-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-33811.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39817.html * https://www.suse.com/security/cve/CVE-2026-39819.html * https://www.suse.com/security/cve/CVE-2026-39820.html * https://www.suse.com/security/cve/CVE-2026-39823.html * https://www.suse.com/security/cve/CVE-2026-39825.html * https://www.suse.com/security/cve/CVE-2026-39826.html * https://www.suse.com/security/cve/CVE-2026-39836.html *https://www.suse.com/security/cve/CVE-2026-42499.html * https://www.suse.com/security/cve/CVE-2026-42501.html . An update for openSUSE addressing 11 vulnerabilities and 13 bug fixes is now available for installation.. openSUSE security update, go1.26 vulnerabilities, network security fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 19, 2026 Important OpenSUSE
202

openSUSE Backports SLE-15-SP7 Tor Major Security Patch 2026-XYZ-2

An update that fixes 6 vulnerabilities is now available.. openSUSE Security Update: Security update for tor ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0164-1 Rating: critical References: #1264341 #1264342 #1264343 #1264344 #1264345 #1264346 Cross-References: CVE-2026-44597 CVE-2026-44599 CVE-2026-44600 CVE-2026-44601 CVE-2026-44602 CVE-2026-44603 Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: This update for tor fixes the following issues: - Update to 0.4.9.8 * Fix out-of-bounds read (boo#1264341, CVE-2026-44597, TROVE-2026-011) * Do not attempt or accept BEGIN_DIR via conflux legs (boo#1264342, CVE-2026-44599,TROVE-2026-008) * Adjust conflux out-of-order queue accounting when clearing a queue (boo#1264343, CVE-2026-44600, TROVE-2026-010) * Fix a client-side crash caused by double-close of a circuit while under circuit queue memory pressure (boo#1264344, CVE-2026-44601, TROVE-2026-009) * Fix null pointer dereference when receiving a CERT cell out of order (boo#1264345, CVE-2026-44602, TROVE-2026-006) * Fix off-by-one out-of-bounds read if a malformed BEGIN cell is received (boo#1264346, CVE-2026-44603, TROVE-2026-007) - upate to 0.4.9.5: * first stable release in the 0.4.9 series * introduces a new circuit-level encryption design for better client security * introduce a more scalable way for large relay operators to annotate which relays they run so clients can avoid using too many of them in a single circuit Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypperpatch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-164=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 ppc64le s390x x86_64): tor-0.4.9.8-bp157.2.9.1 References: https://www.suse.com/security/cve/CVE-2026-44597.html https://www.suse.com/security/cve/CVE-2026-44599.html https://www.suse.com/security/cve/CVE-2026-44600.html https://www.suse.com/security/cve/CVE-2026-44601.html https://www.suse.com/security/cve/CVE-2026-44602.html https://www.suse.com/security/cve/CVE-2026-44603.html https://bugzilla.suse.com/1264341 https://bugzilla.suse.com/1264342 https://bugzilla.suse.com/1264343 https://bugzilla.suse.com/1264344 https://bugzilla.suse.com/1264345 https://bugzilla.suse.com/1264346 . Critical openSUSE update for tor addresses 6 vulnerabilities, enhancing security and functionality. Install recommended patches.. openSUSE Security,Tor Update,Critical Patch,Network Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 13, 2026 Critical OpenSUSE
100

SUSE OS 12 SP5 Kernel Vulnerability Fix SUSE-SU-2026-1781-2

An update that solves four vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 67 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:1780-1 Release Date: 2026-05-08T17:04:05Z Rating: important References: * bsc#1258073 * bsc#1258655 * bsc#1259126 * bsc#1263689 Cross-References: * CVE-2025-38375 * CVE-2026-23004 * CVE-2026-23204 * CVE-2026-31431 CVSS scores: * CVE-2025-38375 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38375 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38375 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23004 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23004 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23004 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23204 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-23204 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23204 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23204 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31431 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31431 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 4.12.14-122.255 fixes various security issues The following security issues were fixed: * CVE-2025-38375: virtio-net: ensure thereceived length does not exceed allocated size (bsc#1258073). * CVE-2026-23004: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() (bsc#1258655). * CVE-2026-23204: net/sched: cls_u32: use skb_header_pointer_careful() (bsc#1259126). * CVE-2026-31431: crypto: algif_aead - Revert to operating out-of-place (bsc#1263689). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-1780=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_255-default-17-2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-38375.html * https://www.suse.com/security/cve/CVE-2026-23004.html * https://www.suse.com/security/cve/CVE-2026-23204.html * https://www.suse.com/security/cve/CVE-2026-31431.html * https://bugzilla.suse.com/show_bug.cgi?id=1258073 * https://bugzilla.suse.com/show_bug.cgi?id=1258655 * https://bugzilla.suse.com/show_bug.cgi?id=1259126 * https://bugzilla.suse.com/show_bug.cgi?id=1263689 . Four vulnerabilities in SUSE Linux kernel now patched; critical update for kernel security.. SUSE Linux Enterprise, kernel update, security patch, remote access, Linux vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 11, 2026 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200