Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Moderate: wireshark security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:9666", "synopsis": "Moderate: wireshark security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for wireshark.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The wireshark packages contain a network protocol analyzer used to capture and browse the traffic running on a computer network.\n\nSecurity Fix(es):\n\n* wireshark: Buffer Over-read in Wireshark (CVE-2026-3203)\n\n* wireshark: Improperly Controlled Sequential Memory Allocation in Wireshark (CVE-2026-3201)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2442639", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2442639", "description": ""}, {"ticket": "2442641", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2442641", "description": ""}], "cves": [{"name": "CVE-2026-3201", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3201", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "CWE-1325"}, {"name": "CVE-2026-3203", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3203", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "CWE-126"}], "references": [], "publishedAt": "2026-04-24T12:06:29.039644Z", "rpms": {"Rocky Linux 10": {"nvras": ["wireshark-cli-1:4.4.2-4.el10_1.4.aarch64.rpm", "wireshark-1:4.4.2-4.el10_1.4.aarch64.rpm", "wireshark-debuginfo-1:4.4.2-4.el10_1.4.aarch64.rpm","wireshark-devel-1:4.4.2-4.el10_1.4.x86_64.rpm", "wireshark-debuginfo-1:4.4.2-4.el10_1.4.x86_64.rpm", "wireshark-cli-debuginfo-1:4.4.2-4.el10_1.4.s390x.rpm", "wireshark-debuginfo-1:4.4.2-4.el10_1.4.s390x.rpm", "wireshark-cli-debuginfo-1:4.4.2-4.el10_1.4.ppc64le.rpm", "wireshark-cli-1:4.4.2-4.el10_1.4.ppc64le.rpm", "wireshark-devel-1:4.4.2-4.el10_1.4.ppc64le.rpm", "wireshark-1:4.4.2-4.el10_1.4.x86_64.rpm", "wireshark-devel-1:4.4.2-4.el10_1.4.s390x.rpm", "wireshark-devel-1:4.4.2-4.el10_1.4.aarch64.rpm", "wireshark-debugsource-1:4.4.2-4.el10_1.4.s390x.rpm", "wireshark-debuginfo-1:4.4.2-4.el10_1.4.ppc64le.rpm", "wireshark-debugsource-1:4.4.2-4.el10_1.4.ppc64le.rpm", "wireshark-1:4.4.2-4.el10_1.4.ppc64le.rpm", "wireshark-cli-1:4.4.2-4.el10_1.4.x86_64.rpm", "wireshark-1:4.4.2-4.el10_1.4.s390x.rpm", "wireshark-cli-1:4.4.2-4.el10_1.4.s390x.rpm", "wireshark-cli-debuginfo-1:4.4.2-4.el10_1.4.x86_64.rpm", "wireshark-cli-debuginfo-1:4.4.2-4.el10_1.4.aarch64.rpm", "wireshark-debugsource-1:4.4.2-4.el10_1.4.x86_64.rpm", "wireshark-debugsource-1:4.4.2-4.el10_1.4.aarch64.rpm", "wireshark-1:4.4.2-4.el10_1.4.src.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Wireshark update for Rocky Linux addresses moderate buffer over-read and memory issues. Critical security measures for safety.. Wireshark Rocky Linux Security Update Protocol Analysis Buffer Overread. . LinuxSecurity.com Team
An update that solves 2 vulnerabilities can now be installed.. # gnutls-3.8.12-1.1 on GA media Announcement ID: openSUSE-SU-2026:10177-1 Rating: moderate Cross-References: * CVE-2025-14831 * CVE-2026-1584 CVSS scores: * CVE-2025-14831 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-14831 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-1584 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the gnutls-3.8.12-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * gnutls 3.8.12-1.1 * libgnutls-dane-devel 3.8.12-1.1 * libgnutls-dane0 3.8.12-1.1 * libgnutls-devel 3.8.12-1.1 * libgnutls-devel-32bit 3.8.12-1.1 * libgnutls-devel-doc 3.8.12-1.1 * libgnutls30 3.8.12-1.1 * libgnutls30-32bit 3.8.12-1.1 * libgnutlsxx-devel 3.8.12-1.1 * libgnutlsxx30 3.8.12-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-14831.html * https://www.suse.com/security/cve/CVE-2026-1584.html . Update gnutls-3.8.12-1.1 on openSUSE Tumbleweed addresses two vulnerabilities rated moderate.. openSUSE, gnutls update, moderate vulnerability, network security, software update. . LinuxSecurity.com Team
Multiple vulnerabilities have been discocvered in Wireshark, a network protocol analyzer which could result in denial of service or the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in version 4.4.13-0+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6124-1
Update to 0.2.8. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-89758d1b13 2025-12-20 00:52:30.902726+00:00 -------------------------------------------------------------------------------- Name : mqttcli Product : Fedora 43 Version : 0.2.8 Release : 1.fc43 URL : https://github.com/subpop/mqttcli Summary : A simple MQTT command-line client Description : mqttcli provides two programs (pub and sub) that allow command-line access to an MQTT broker. sub subscribes to a topic and prints messages received to standard output. pub publishes the provided message to the provided topic. Both programs accept flags that can be provided as a config file. -------------------------------------------------------------------------------- Update Information: Update to 0.2.8 -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 17 2025 Link Dupont - 0.2.8-1 - Update to 0.2.8 (RHBZ#2423020, RHBZ#2423010, RHBZ#2411647, RHBZ#2410751, RHBZ#2409801, RHBZ#2408328) * Wed Dec 17 2025 Link Dupont - 0.2.7-1 - Update to 0.2.7 * Fri Oct 10 2025 Alejandro Sez - 0.2.5-9 - rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2408328 - CVE-2025-58189 mqttcli: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408328 [ 2 ] Bug #2409801 - CVE-2025-61723 mqttcli: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409801 [ 3 ] Bug #2410751 - CVE-2025-58185 mqttcli: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410751 [ 4 ] Bug #2411647 - CVE-2025-58188 mqttcli: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411647 [ 5 ] Bug #2423010 - CVE-2025-10543 mqttcli: paho.mqtt.golang: Integer Overflow in UTF-8 String Encoding [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2423010 [ 6 ] Bug #2423020 - CVE-2025-10543 mqttcli: paho.mqtt.golang: Integer Overflow in UTF-8 String Encoding [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2423020 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-89758d1b13' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update mqttcli on Fedora 43 fixes critical integer overflow threats in the software, ensuring better reliability.. mqttcli integer overflow security patch Fedora 43 update. . Severity: Critical. LinuxSecurity.com Team
A buffer overflow was discovered in libndp, a library implementing the IPv6 Neighbor Discovery Protocol (NDP), which could result in denial of service or potentially the execution of arbitrary code if malformed IPv6 router advertisements are processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5713-1
* bsc#1218499 * bsc#1218502 * jsc#PED-4981 Cross-References: . # Security update for sevctl Announcement ID: SUSE-SU-2024:0250-1 Rating: important References: * bsc#1218499 * bsc#1218502 * jsc#PED-4981 Cross-References: * CVE-2023-50711 CVSS scores: * CVE-2023-50711 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L * CVE-2023-50711 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * Server Applications Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability, contains one feature and has one security fix can now be installed. ## Description: This update for sevctl fixes the following issues: * CVE-2023-50711: Fixed out of bounds memory accesses in vmm-sys-util (bsc#1218502, bsc#1218499) Non-security fixes: * Updated to version 0.4.3 (jsc#PED-4981) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-250=1 openSUSE-SLE-15.5-2024-250=1 * Server Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP5-2024-250=1 ## Package List: * openSUSE Leap 15.5 (x86_64) * sevctl-debuginfo-0.4.3-150500.3.3.1 * sevctl-debugsource-0.4.3-150500.3.3.1 * sevctl-0.4.3-150500.3.3.1 * Server Applications Module 15-SP5 (x86_64) * sevctl-debuginfo-0.4.3-150500.3.3.1 * sevctl-debugsource-0.4.3-150500.3.3.1 * sevctl-0.4.3-150500.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-50711.html * https://bugzilla.suse.com/show_bug.cgi?id=1218499 * https://bugzilla.suse.com/show_bug.cgi?id=1218502 * . Important update rollout for sevctl addressing CVE-2023-50712 affecting multiple SUSE LinuxEnterprise products.. SUSE Security Update, Sevctl Patch, Memory Access Fix, SUSE Linux Products. . Severity: Critical. LinuxSecurity.com Team
A buffer overflow vulnerability has been found in lwip, a small independent implementation of the TCP/IPv4/IPv6 protocol suite, which allows an attacker to access information via a crafted ICMPv6 package. This vulnerability has been assigned CVE-2020-22283. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3655-1
Update Folly stack to the latest 2023.10.16.00 tag proxygen: Security fix for CVE-2023-44487. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-17efd3f2cd 2023-10-24 01:21:22.156597 -------------------------------------------------------------------------------- Name : mvfst Product : Fedora 38 Version : 2023.10.16.00 Release : 1.fc38 URL : https://github.com/facebook/mvfst Summary : An implementation of the QUIC transport protocol Description : mvfst (Pronounced move fast) is a client and server implementation of IETF QUIC protocol in C++ by Facebook. QUIC is a UDP based reliable, multiplexed transport protocol that will become an internet standard. The goal of mvfst is to build a performant implementation of the QUIC transport protocol that applications could adapt for use cases on both the internet and the data-center. mvfst has been tested at scale on android, iOS apps, as well as servers and has several features to support large scale deployments. -------------------------------------------------------------------------------- Update Information: Update Folly stack to the latest 2023.10.16.00 tag proxygen: Security fix for CVE-2023-44487 -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 17 2023 Michel Lind - 2023.10.16.00-1 - Update to 2023.10.16.00 * Tue Oct 17 2023 Michel Lind - 2023.10.09.00-1 - Update to 2023.10.09.00 * Sat Oct 7 2023 Michel Lind - 2023.09.11.00-2 - Rebuild for new libsodium * Tue Sep 12 2023 Michel Lind - 2023.09.11.00-1 - Initial package -------------------------------------------------------------------------------- References: [ 1 ] Bug #2221799 - mcrouter-2023.10.09.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2221799 [ 2 ] Bug #2239431 - proxygen-2023.10.16.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239431 [ 3 ] Bug#2239594 - wangle-2023.10.16.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239594 [ 4 ] Bug #2239613 - fb303-2023.10.09.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239613 [ 5 ] Bug #2239614 - fbthrift-2023.10.09.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239614 [ 6 ] Bug #2239623 - fizz-2023.10.09.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239623 [ 7 ] Bug #2239624 - folly-2023.10.09.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=2239624 [ 8 ] Bug #2243253 - [Major Incident] CVE-2023-44487 proxygen: HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2243253 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-17efd3f2cd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.