Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4676-1
An update that solves one vulnerability and contains one feature can now be installed.. # Security update for wicked Announcement ID: SUSE-SU-2026:2353-1 Release Date: 2026-06-10T14:55:06Z Rating: important References: * bsc#1265221 * jsc#PED-1942 Cross-References: * CVE-2026-44932 CVSS scores: * CVE-2026-44932 ( SUSE ): 5.8 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H * CVE-2026-44932 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability and contains one feature can now be installed. ## Description: This update for wicked fixes the following issues: * CVE-2026-44932: Fixed indirect remote shell command injection via unsanitized DHCP options (bsc#1265221). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2353=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2353=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2353=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2353=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2353=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patchSUSE-SLE-Product-SLES_SAP-15-SP5-2026-2353=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * wicked-debugsource-0.6.79-150500.3.42.1 * wicked-nbft-0.6.79-150500.3.42.1 * wicked-0.6.79-150500.3.42.1 * wicked-debuginfo-0.6.79-150500.3.42.1 * wicked-service-0.6.79-150500.3.42.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * wicked-0.6.79-150500.3.42.1 * wicked-service-0.6.79-150500.3.42.1 * wicked-debugsource-0.6.79-150500.3.42.1 * wicked-debuginfo-0.6.79-150500.3.42.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * wicked-debugsource-0.6.79-150500.3.42.1 * wicked-nbft-0.6.79-150500.3.42.1 * wicked-0.6.79-150500.3.42.1 * wicked-debuginfo-0.6.79-150500.3.42.1 * wicked-service-0.6.79-150500.3.42.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * wicked-debugsource-0.6.79-150500.3.42.1 * wicked-nbft-0.6.79-150500.3.42.1 * wicked-0.6.79-150500.3.42.1 * wicked-debuginfo-0.6.79-150500.3.42.1 * wicked-service-0.6.79-150500.3.42.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * wicked-debugsource-0.6.79-150500.3.42.1 * wicked-nbft-0.6.79-150500.3.42.1 * wicked-0.6.79-150500.3.42.1 * wicked-debuginfo-0.6.79-150500.3.42.1 * wicked-service-0.6.79-150500.3.42.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * wicked-debugsource-0.6.79-150500.3.42.1 * wicked-nbft-0.6.79-150500.3.42.1 * wicked-0.6.79-150500.3.42.1 * wicked-debuginfo-0.6.79-150500.3.42.1 * wicked-service-0.6.79-150500.3.42.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44932.html * https://bugzilla.suse.com/show_bug.cgi?id=1265221 * https://jira.suse.com/browse/PED-1942 . An important security update for wicked addresses a remote command injection flaw. Install to enhance system safety.. SUSE Wicked Update, Remote Command Injection,OpenSUSE Security. . Severity: Important. LinuxSecurity.com Team
Frameworks 6.25.0 + KDE Plasma 6.6.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fe3d8d4767 2026-04-16 23:40:54.273526+00:00 -------------------------------------------------------------------------------- Name : plasma-nm Product : Fedora 44 Version : 6.6.4 Release : 1.fc44 URL : https://invent.kde.org/plasma/plasma-nm Summary : Plasma for managing network connections Description : Plasma applet and editor for managing your network connections in KDE 4 using the default NetworkManager service. -------------------------------------------------------------------------------- Update Information: Frameworks 6.25.0 + KDE Plasma 6.6.4 -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 10 2026 Steve Cossette - 6.6.4-1 - 6.6.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455469 - Configuring WifI network via Network pane appears to not work https://bugzilla.redhat.com/show_bug.cgi?id=2455469 [ 2 ] Bug #2457573 - FE: KDE Frameworks 6.25.0 + Plasma 6.6.4 https://bugzilla.redhat.com/show_bug.cgi?id=2457573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fe3d8d4767' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Frameworks 6.25.0 + KDE Plasma 6.6.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fe3d8d4767 2026-04-16 23:40:54.273526+00:00 -------------------------------------------------------------------------------- Name : kf6-solid Product : Fedora 44 Version : 6.25.0 Release : 1.fc44 URL : https://solid.kde.org/ Summary : KDE Frameworks 6 Tier 1 integration module that provides hardware information Description : Solid provides the following features for application developers: - Hardware Discovery - Power Management - Network Management -------------------------------------------------------------------------------- Update Information: Frameworks 6.25.0 + KDE Plasma 6.6.4 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 9 2026 Steve Cossette - 6.25.0-1 - 6.25.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455469 - Configuring WifI network via Network pane appears to not work https://bugzilla.redhat.com/show_bug.cgi?id=2455469 [ 2 ] Bug #2457573 - FE: KDE Frameworks 6.25.0 + Plasma 6.6.4 https://bugzilla.redhat.com/show_bug.cgi?id=2457573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fe3d8d4767' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-8353 http://linux.oracle.com/errata/ELSA-2024-8353.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: NetworkManager-libreswan-1.2.10-7.el8_10.x86_64.rpm NetworkManager-libreswan-gnome-1.2.10-7.el8_10.x86_64.rpm aarch64: NetworkManager-libreswan-1.2.10-7.el8_10.aarch64.rpm NetworkManager-libreswan-gnome-1.2.10-7.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//NetworkManager-libreswan-1.2.10-7.el8_10.src.rpm Related CVEs: CVE-2024-9050 Description of changes: [1.2.10-7] - Unbreak validation of unknown keys [1.2.10-6] - Fix improper escaping of Libreswan configuration (CVE-2024-9050) _______________________________________________ El-errata mailing list
iwd 2.15: Fix issue with notice events for connection timeouts. Fix issue with reason code and deauthenticate event. Fix issue with handling basename() functionality. libell 0.63:. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-fdce971b84 2024-03-08 01:18:13.751618 -------------------------------------------------------------------------------- Name : iwd Product : Fedora 39 Version : 2.15 Release : 1.fc39 URL : https://archive.kernel.org/oldwiki/iwd.wiki.kernel.org/ Summary : Wireless daemon for Linux Description : The daemon and utilities for controlling and configuring the Wi-Fi network hardware. -------------------------------------------------------------------------------- Update Information: iwd 2.15: Fix issue with notice events for connection timeouts. Fix issue with reason code and deauthenticate event. Fix issue with handling basename() functionality. libell 0.63: Fix issue with handling ending boundary of the PEM. -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 28 2024 Peter Robinson - 2.15-1 - Update to 2.15 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2263042 - libell-0.63 is available https://bugzilla.redhat.com/show_bug.cgi?id=2263042 [ 2 ] Bug #2263573 - iwd-2.15 is available https://bugzilla.redhat.com/show_bug.cgi?id=2263573 [ 3 ] Bug #2264597 - TRIAGE CVE-2023-52161 iwd: potential authorization bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2264597 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-fdce971b84' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for connman ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0369-1 Rating: important References: #1210395 Cross-References: CVE-2023-28488 CVSS scores: CVE-2023-28488 (NVD) : 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for connman fixes the following issues: Update to 1.42 * Fix issue with iwd and signal strength calculation. * Fix issue with iwd and handling service removal. * Fix issue with iwd and handling new connections. * Fix issue with handling default online check URL. * Fix issue with handling nameservers refresh. * Fix issue with handling proxy from DHCP lease. (boo#1210395 CVE-2023-28488) * Fix issue with handling multiple proxies from PAC. * Fix issue with handling manual time update changes. * Fix issue with handling invalid gateway routes. * Fix issue with handling hidden WiFi agent requests. * Fix issue with handling WiFi SAE authentication failure. * Fix issue with handling DNS Proxy and TCP server replies. * Add support for regulatory domain following timezone. * Add support for localtime configuration option. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2023-369=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): connman-1.42-bp155.4.3.1 connman-client-1.42-bp155.4.3.1 connman-devel-1.42-bp155.4.3.1 connman-doc-1.42-bp155.4.3.1 connman-nmcompat-1.42-bp155.4.3.1 connman-plugin-iospm-1.42-bp155.4.3.1 connman-plugin-l2tp-1.42-bp155.4.3.1 connman-plugin-openvpn-1.42-bp155.4.3.1 connman-plugin-polkit-1.42-bp155.4.3.1 connman-plugin-pptp-1.42-bp155.4.3.1 connman-plugin-wireguard-1.42-bp155.4.3.1 connman-test-1.42-bp155.4.3.1 - openSUSE Backports SLE-15-SP5 (aarch64 ppc64le s390x x86_64): connman-plugin-vpnc-1.42-bp155.4.3.1 - openSUSE Backports SLE-15-SP5 (aarch64 i586 s390x x86_64): connman-plugin-hh2serial-gps-1.42-bp155.4.3.1 connman-plugin-tist-1.42-bp155.4.3.1 References: https://www.suse.com/security/cve/CVE-2023-28488.html https://bugzilla.suse.com/1210395 . This patch targets a significant flaw within connman on openSUSE, successfully rectifying security vulnerabilities and fortifying protection.. openSUSE Update, Connman Security, Important Fix, SLE-15-SP5, Security Patch. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for connman ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0370-1 Rating: important References: #1210395 Cross-References: CVE-2023-28488 CVSS scores: CVE-2023-28488 (NVD) : 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for connman fixes the following issues: - Update to 1.42 * Fix issue with iwd and signal strength calculation. * Fix issue with iwd and handling service removal. * Fix issue with iwd and handling new connections. * Fix issue with handling default online check URL. * Fix issue with handling nameservers refresh. * Fix issue with handling proxy from DHCP lease. (boo#1210395 CVE-2023-28488) * Fix issue with handling multiple proxies from PAC. * Fix issue with handling manual time update changes. * Fix issue with handling invalid gateway routes. * Fix issue with handling hidden WiFi agent requests. * Fix issue with handling WiFi SAE authentication failure. * Fix issue with handling DNS Proxy and TCP server replies. * Add support for regulatory domain following timezone. * Add support for localtime configuration option. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2023-370=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): connman-1.42-bp154.2.6.1 connman-client-1.42-bp154.2.6.1 connman-devel-1.42-bp154.2.6.1 connman-doc-1.42-bp154.2.6.1 connman-nmcompat-1.42-bp154.2.6.1 connman-plugin-iospm-1.42-bp154.2.6.1 connman-plugin-l2tp-1.42-bp154.2.6.1 connman-plugin-openvpn-1.42-bp154.2.6.1 connman-plugin-polkit-1.42-bp154.2.6.1 connman-plugin-pptp-1.42-bp154.2.6.1 connman-plugin-wireguard-1.42-bp154.2.6.1 connman-test-1.42-bp154.2.6.1 - openSUSE Backports SLE-15-SP4 (aarch64 ppc64le s390x x86_64): connman-plugin-vpnc-1.42-bp154.2.6.1 - openSUSE Backports SLE-15-SP4 (aarch64 i586 s390x x86_64): connman-plugin-hh2serial-gps-1.42-bp154.2.6.1 connman-plugin-tist-1.42-bp154.2.6.1 References: https://www.suse.com/security/cve/CVE-2023-28488.html https://bugzilla.suse.com/1210395 . Upgrade released for connman to tackle critical problems along with several corrections in network handling.. openSUSE Connman Update, Connman Security Fix, Network Management Linux, openSUSE Backports Security Update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.