Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 8 vulnerabilities and has 8 bug fixes can now be installed.. openSUSE security update: security update for wireshark ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20151-1 Rating: moderate References: * bsc#1249090 * bsc#1251933 * bsc#1254108 * bsc#1254471 * bsc#1254472 * bsc#1256734 * bsc#1256738 * bsc#1256739 Cross-References: * CVE-2025-11626 * CVE-2025-13499 * CVE-2025-13945 * CVE-2025-13946 * CVE-2025-9817 * CVE-2026-0959 * CVE-2026-0961 * CVE-2026-0962 CVSS scores: * CVE-2025-11626 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-11626 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-13499 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2025-13499 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-13945 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13946 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-9817 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-9817 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-0959 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-0959 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-0961 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-0961 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-0962 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-0962 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 8 vulnerabilities and has 8 bug fixes can now be installed. Description: This update for wireshark fixes the followingissues: Update to Wireshark 4.4.13: - CVE-2025-11626: MONGO dissector infinite loop (bsc#1251933). - CVE-2025-13499: Kafka dissector crash (bsc#1254108). - CVE-2025-13945: HTTP3 dissector crash (bsc#1254471). - CVE-2025-13946: MEGACO dissector infinite loop (bsc#1254472). - CVE-2025-9817: SSH dissector crash (bsc#1249090). - CVE-2026-0959: IEEE 802.11 dissector crash (bsc#1256734). - CVE-2026-0961: BLF file parser crash (bsc#1256738). - CVE-2026-0962: SOME/IP-SD dissector crash (bsc#1256739). Full changelog: https://www.wireshark.org/docs/relnotes/wireshark-4.4.13.html Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-236=1 Package List: - openSUSE Leap 16.0: libwireshark18-4.4.13-160000.1.1 libwiretap15-4.4.13-160000.1.1 libwsutil16-4.4.13-160000.1.1 wireshark-4.4.13-160000.1.1 wireshark-devel-4.4.13-160000.1.1 wireshark-ui-qt-4.4.13-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2025-11626.html * https://www.suse.com/security/cve/CVE-2025-13499.html * https://www.suse.com/security/cve/CVE-2025-13945.html * https://www.suse.com/security/cve/CVE-2025-13946.html * https://www.suse.com/security/cve/CVE-2025-9817.html * https://www.suse.com/security/cve/CVE-2026-0959.html * https://www.suse.com/security/cve/CVE-2026-0961.html * https://www.suse.com/security/cve/CVE-2026-0962.html . Explore the latest openSUSE update addressing multiple low-risk issues in Wireshark, ensuring optimal performance.. openSUSE update, Wireshark security, network analysis, bug fixes, moderate severity. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # iputils-20240905-3.1 on GA media Announcement ID: openSUSE-SU-2025:15089-1 Rating: moderate Cross-References: * CVE-2025-47268 CVSS scores: * CVE-2025-47268 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-47268 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the iputils-20240905-3.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * iputils 20240905-3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-47268.html . Unveil the recent essential security enhancement for openSUSE's iputils software, targeting significant vulnerabilities.. openSUSE Security, iputils Update, moderate Advisory, Network Tool Fix. . LinuxSecurity.com Team
curl a command line tool for transferring data with URL syntax was affected by CVE-2024-8096. When the TLS backend is GnuTLS, curl may incorrectly handle OCSP stapling. If the OCSP status reports an error . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3951-1
Announcing v4.5.1 This release contains contributions from a record number of new contributors. This is greatly appreciated since I am a team of one, and do Tcpreplay maintenance in my spare time. There are many bug fixes and new features. Most notable features:. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-740d26aaf7 2024-07-21 02:14:42.426456 -------------------------------------------------------------------------------- Name : tcpreplay Product : Fedora 39 Version : 4.5.1 Release : 1.fc39 URL : http://tcpreplay.appneta.com/ Summary : Replay captured network traffic Description : Tcpreplay is a tool to replay captured network traffic. Currently, tcpreplay supports pcap (tcpdump) and snoop capture formats. Also included, is tcpprep a tool to pre-process capture files to allow increased performance under certain conditions as well as capinfo which provides basic information about capture files. -------------------------------------------------------------------------------- Update Information: Announcing v4.5.1 This release contains contributions from a record number of new contributors. This is greatly appreciated since I am a team of one, and do Tcpreplay maintenance in my spare time. There are many bug fixes and new features. Most notable features: AF_XDP socket support - if you have a newer Linux kernel, you will be able to transmit at line rates without having to install 3rd party kernel modules (e.g. netmap, PF_RING) -w tcpreplay option - this overrides the -i option, and allows you to write to a PCAP file rather than an interface --include and --exclude tcpreplay options - allows replay of a list of specific packet numbers to replay. This may slow things down, so consider using in combination with -w. --fixhdrlen tcpreplay option - added to control action on packet length changes -W tcpreplay option - suppress warnings when replaying SLL2( Linux "cooked"capture encapsulation v2) Haiku support What's Changed Add support for LINUX_SLL2 by @btriller in #728 Feature #727 - Linux SLL v2 by @fklassen in #820 Bug #779 - honour overflow for all PPS values by @fklassen in #821 AF_XDP socket extension using libxdp api by @plangarbalint in #797 Feature #822 - AF_XDP socket extension by @fklassen in #823 Nanosec accurate packet processing by @plangarbalint in #796 Handle IPv6 fragment extension header by @ChuckCottrill in #832 Bug #837 - handle IPv6 fragment extension header by @fklassen in #838 Feature #796 - nanosecond packet processing by @fklassen in #836 configure.ac: unify search dirs for pcap and add lib32 by @shr-project in #819 Feature #839 - add pull request template by @fklassen in #840 ipv6 - add check for extension header length by @GabrielGanne in #842 Bug #827 PR #842 IPv6 extension header - staging by @fklassen in #859 add check for empty cidr by @GabrielGanne in #843 Bug #824 and PR #843: check for empty CIDR by @fklassen in #860 Add option to turn on/off fix packet header length by @ChuckCottrill in #846 Bug #703 #844 PR #846: optionally fix packet header length --fixhdrlen by @fklassen in #861 Bug 863: fix nansecond timestamp regression by @fklassen in #865 autotools - AC_HELP_STRING is obsolete in 2.70 by @GabrielGanne in #856 some Haiku support by @infrastation in #847 configure.ac: do not run conftest in case of cross compilation by @ChenQi1989 in #849 dlt_jnpr_ether_cleanup: check config before cleanup by @Marsman1996 in #851 Fix recursive tcpedit cleanup by @GabrielGanne in #855 Bug #813: back out PR #855 by @fklassen in #866 Bug #867 - run regfree() on close by @fklassen in #868 Bug #869 tcpprep memory leak include exclude by @fklassen in #870 Bug #811 - add check for invalid jnpr header length by @fklassen in #872 Bug #792 avoid assertion and other fixes by @fklassen in #873 Bug #844 tap: ignore TUNSETIFF EBUSY errors by @fklassen in #874 Bug #876 - add missing free_umem_and_xsk function by @fklassen in#877 Feature #878 - add -w / --suppress-warning option by @fklassen in #879 Bug #835 false unsupported dlt warnings on 802.3 (Ethernet I) and LLC by @fklassen in #880 Feature #884 include exclude options by @fklassen in #885 Feature #853 direct traffic to pcap by @fklassen in #871 Feature #853 restore missing -P command by @fklassen in #887 Bug #888: check for map == NULL in cidr.c by @fklassen in #889 -------------------------------------------------------------------------------- ChangeLog: * Sat Jul 13 2024 Bojan Smojver - 4.5.1-1 - Update to 4.5.1 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-740d26aaf7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Patch CVE-2023-4256 and CVE-2023-43279. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-b3b2a95168 2024-03-24 01:35:11.754564 -------------------------------------------------------------------------------- Name : tcpreplay Product : Fedora 38 Version : 4.4.4 Release : 5.fc38 URL : http://tcpreplay.appneta.com/ Summary : Replay captured network traffic Description : Tcpreplay is a tool to replay captured network traffic. Currently, tcpreplay supports pcap (tcpdump) and snoop capture formats. Also included, is tcpprep a tool to pre-process capture files to allow increased performance under certain conditions as well as capinfo which provides basic information about capture files. -------------------------------------------------------------------------------- Update Information: Patch CVE-2023-4256 and CVE-2023-43279 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 16 2024 Bojan Smojver - 4.4.1-5 - Patch CVE-2023-4256 * Sat Mar 16 2024 Bojan Smojver - 4.4.1-4 - Patch CVE-2023-43279 * Sat Jan 27 2024 Fedora Release Engineering - 4.4.4-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sat Jul 22 2023 Fedora Release Engineering - 4.4.4-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2255213 - CVE-2023-4256 tcpreplay: tcprewrite: double free in tcpedit_dlt_cleanup() in plugins/dlt_plugins.c [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2255213 [ 2 ] Bug #2255214 - CVE-2023-4256 tcpreplay: tcprewrite: double free in tcpedit_dlt_cleanup() in plugins/dlt_plugins.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2255214 [ 3 ] Bug #2269309 - CVE-2023-43279 tcpreplay: null pointer dereference in mask_cidr6 component at cidr.c[fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2269309 [ 4 ] Bug #2269310 - CVE-2023-43279 tcpreplay: null pointer dereference in mask_cidr6 component at cidr.c [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2269310 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-b3b2a95168' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Patch CVE-2023-4256 and CVE-2023-43279. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ec1fba69c2 2024-03-24 01:05:50.706342 -------------------------------------------------------------------------------- Name : tcpreplay Product : Fedora 39 Version : 4.4.4 Release : 5.fc39 URL : http://tcpreplay.appneta.com/ Summary : Replay captured network traffic Description : Tcpreplay is a tool to replay captured network traffic. Currently, tcpreplay supports pcap (tcpdump) and snoop capture formats. Also included, is tcpprep a tool to pre-process capture files to allow increased performance under certain conditions as well as capinfo which provides basic information about capture files. -------------------------------------------------------------------------------- Update Information: Patch CVE-2023-4256 and CVE-2023-43279 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 16 2024 Bojan Smojver - 4.4.1-5 - Patch CVE-2023-4256 * Sat Mar 16 2024 Bojan Smojver - 4.4.1-4 - Patch CVE-2023-43279 * Sat Jan 27 2024 Fedora Release Engineering - 4.4.4-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2255213 - CVE-2023-4256 tcpreplay: tcprewrite: double free in tcpedit_dlt_cleanup() in plugins/dlt_plugins.c [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2255213 [ 2 ] Bug #2255214 - CVE-2023-4256 tcpreplay: tcprewrite: double free in tcpedit_dlt_cleanup() in plugins/dlt_plugins.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2255214 [ 3 ] Bug #2269309 - CVE-2023-43279 tcpreplay: null pointer dereference in mask_cidr6 component at cidr.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2269309 [ 4 ] Bug #2269310 - CVE-2023-43279 tcpreplay: nullpointer dereference in mask_cidr6 component at cidr.c [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2269310 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ec1fba69c2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 2.1.3. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-b870a4de82 2023-09-29 00:18:30.089942 -------------------------------------------------------------------------------- Name : traceroute Product : Fedora 39 Version : 2.1.3 Release : 1.fc39 URL : Summary : Traces the route taken by packets over an IPv4/IPv6 network Description : The traceroute utility displays the route used by IP packets on their way to a specified network (or Internet) host. Traceroute displays the IP number and host name (if possible) of the machines along the route taken by the packets. Traceroute is used as a network debugging tool. If you're having network connectivity problems, traceroute will show you where the trouble is coming from along the route. Install traceroute if you need a tool for diagnosing network connectivity problems. -------------------------------------------------------------------------------- Update Information: Update to 2.1.3 -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 21 2023 Dmitry Butskoy - 3:2.1.3-1 - update to 2.1.3 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-b870a4de82' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Important: iperf3 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:4571", "synopsis": "Important: iperf3 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for iperf3.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Iperf is a tool which can measure maximum TCP bandwidth and tune various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, and data-gram loss.\n\nSecurity Fix(es):\n\n* iperf3: memory allocation hazard and crash (CVE-2023-38403)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2222204", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2222204", "description": ""}], "cves": [{"name": "CVE-2023-38403", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-38403", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2023-08-24T04:21:37.458838Z", "rpms": {"Rocky Linux 9": {"nvras": ["iperf3-0:3.9-10.el9_2.aarch64.rpm", "iperf3-0:3.9-10.el9_2.src.rpm", "iperf3-debuginfo-0:3.9-10.el9_2.aarch64.rpm", "iperf3-debugsource-0:3.9-10.el9_2.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A security enhancement for Iperf3 on Rocky Linux resolves memory management vulnerabilities, essential for optimizing network efficiency.. iperf3 Security Update, Rocky Linux 9, Memory Hazard Fix, Network Protocol Security, Important Security Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.