Explore top 10 tips to secure your open-source projects now. Read More
×An update that solves two vulnerabilities can now be installed.. # Security update for openvswitch Announcement ID: SUSE-SU-2026:2481-1 Release Date: 2026-06-22T10:55:16Z Rating: important References: * bsc#1262498 * bsc#1262499 Cross-References: * CVE-2026-5265 * CVE-2026-5367 CVSS scores: * CVE-2026-5265 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-5265 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-5367 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-5367 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for openvswitch fixes the following issues * CVE-2026-5265: heap over-read in ICMP error response generation (bsc#1262498). * CVE-2026-5367: heap over-read in OVN DHCPv6 client ID processing (bsc#1262499). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2481=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2481=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patchSUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2481=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2481=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2481=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2481=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2481=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * openvswitch-devel-2.14.2-150400.24.35.1 * openvswitch-test-2.14.2-150400.24.35.1 * ovn-vtep-debuginfo-20.06.2-150400.24.35.1 * openvswitch-debuginfo-2.14.2-150400.24.35.1 * libopenvswitch-2_14-0-debuginfo-2.14.2-150400.24.35.1 * openvswitch-debugsource-2.14.2-150400.24.35.1 * ovn-host-20.06.2-150400.24.35.1 * libovn-20_06-0-debuginfo-20.06.2-150400.24.35.1 * ovn-debuginfo-20.06.2-150400.24.35.1 * libopenvswitch-2_14-0-2.14.2-150400.24.35.1 * ovn-host-debuginfo-20.06.2-150400.24.35.1 * openvswitch-2.14.2-150400.24.35.1 * ovn-central-debuginfo-20.06.2-150400.24.35.1 * openvswitch-test-debuginfo-2.14.2-150400.24.35.1 * openvswitch-pki-2.14.2-150400.24.35.1 * python3-ovs-2.14.2-150400.24.35.1 * libovn-20_06-0-20.06.2-150400.24.35.1 * ovn-20.06.2-150400.24.35.1 * openvswitch-ipsec-2.14.2-150400.24.35.1 * ovn-vtep-20.06.2-150400.24.35.1 * openvswitch-vtep-2.14.2-150400.24.35.1 * ovn-docker-20.06.2-150400.24.35.1 * ovn-central-20.06.2-150400.24.35.1 * ovn-devel-20.06.2-150400.24.35.1 * openvswitch-vtep-debuginfo-2.14.2-150400.24.35.1 * openSUSE Leap 15.4 (noarch) * ovn-doc-20.06.2-150400.24.35.1 * openvswitch-doc-2.14.2-150400.24.35.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * openvswitch-devel-2.14.2-150400.24.35.1 * openvswitch-test-2.14.2-150400.24.35.1 *ovn-vtep-debuginfo-20.06.2-150400.24.35.1 * openvswitch-debuginfo-2.14.2-150400.24.35.1 * libopenvswitch-2_14-0-debuginfo-2.14.2-150400.24.35.1 * openvswitch-debugsource-2.14.2-150400.24.35.1 * ovn-host-20.06.2-150400.24.35.1 * libovn-20_06-0-debuginfo-20.06.2-150400.24.35.1 * ovn-debuginfo-20.06.2-150400.24.35.1 * libopenvswitch-2_14-0-2.14.2-150400.24.35.1 * ovn-host-debuginfo-20.06.2-150400.24.35.1 * openvswitch-2.14.2-150400.24.35.1 * ovn-central-debuginfo-20.06.2-150400.24.35.1 * openvswitch-test-debuginfo-2.14.2-150400.24.35.1 * openvswitch-pki-2.14.2-150400.24.35.1 * python3-ovs-2.14.2-150400.24.35.1 * libovn-20_06-0-20.06.2-150400.24.35.1 * ovn-20.06.2-150400.24.35.1 * openvswitch-ipsec-2.14.2-150400.24.35.1 * ovn-vtep-20.06.2-150400.24.35.1 * openvswitch-vtep-2.14.2-150400.24.35.1 * ovn-docker-20.06.2-150400.24.35.1 * ovn-central-20.06.2-150400.24.35.1 * ovn-devel-20.06.2-150400.24.35.1 * openvswitch-vtep-debuginfo-2.14.2-150400.24.35.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * openvswitch-devel-2.14.2-150400.24.35.1 * openvswitch-test-2.14.2-150400.24.35.1 * ovn-vtep-debuginfo-20.06.2-150400.24.35.1 * openvswitch-debuginfo-2.14.2-150400.24.35.1 * libopenvswitch-2_14-0-debuginfo-2.14.2-150400.24.35.1 * openvswitch-debugsource-2.14.2-150400.24.35.1 * ovn-host-20.06.2-150400.24.35.1 * libovn-20_06-0-debuginfo-20.06.2-150400.24.35.1 * ovn-debuginfo-20.06.2-150400.24.35.1 * libopenvswitch-2_14-0-2.14.2-150400.24.35.1 * ovn-host-debuginfo-20.06.2-150400.24.35.1 * openvswitch-2.14.2-150400.24.35.1 * ovn-central-debuginfo-20.06.2-150400.24.35.1 * openvswitch-test-debuginfo-2.14.2-150400.24.35.1 * openvswitch-pki-2.14.2-150400.24.35.1 * python3-ovs-2.14.2-150400.24.35.1 * libovn-20_06-0-20.06.2-150400.24.35.1 * ovn-20.06.2-150400.24.35.1 * openvswitch-ipsec-2.14.2-150400.24.35.1 *ovn-vtep-20.06.2-150400.24.35.1 * openvswitch-vtep-2.14.2-150400.24.35.1 * ovn-docker-20.06.2-150400.24.35.1 * ovn-central-20.06.2-150400.24.35.1 * ovn-devel-20.06.2-150400.24.35.1 * openvswitch-vtep-debuginfo-2.14.2-150400.24.35.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * openvswitch-devel-2.14.2-150400.24.35.1 * openvswitch-test-2.14.2-150400.24.35.1 * ovn-vtep-debuginfo-20.06.2-150400.24.35.1 * openvswitch-debuginfo-2.14.2-150400.24.35.1 * libopenvswitch-2_14-0-debuginfo-2.14.2-150400.24.35.1 * openvswitch-debugsource-2.14.2-150400.24.35.1 * ovn-host-20.06.2-150400.24.35.1 * libovn-20_06-0-debuginfo-20.06.2-150400.24.35.1 * ovn-debuginfo-20.06.2-150400.24.35.1 * libopenvswitch-2_14-0-2.14.2-150400.24.35.1 * ovn-host-debuginfo-20.06.2-150400.24.35.1 * ovn-central-debuginfo-20.06.2-150400.24.35.1 * openvswitch-2.14.2-150400.24.35.1 * openvswitch-test-debuginfo-2.14.2-150400.24.35.1 * openvswitch-pki-2.14.2-150400.24.35.1 * python3-ovs-2.14.2-150400.24.35.1 * libovn-20_06-0-20.06.2-150400.24.35.1 * ovn-20.06.2-150400.24.35.1 * openvswitch-ipsec-2.14.2-150400.24.35.1 * ovn-vtep-20.06.2-150400.24.35.1 * openvswitch-vtep-2.14.2-150400.24.35.1 * ovn-docker-20.06.2-150400.24.35.1 * ovn-central-20.06.2-150400.24.35.1 * ovn-devel-20.06.2-150400.24.35.1 * openvswitch-vtep-debuginfo-2.14.2-150400.24.35.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * openvswitch-devel-2.14.2-150400.24.35.1 * openvswitch-test-2.14.2-150400.24.35.1 * ovn-vtep-debuginfo-20.06.2-150400.24.35.1 * openvswitch-debuginfo-2.14.2-150400.24.35.1 * libopenvswitch-2_14-0-debuginfo-2.14.2-150400.24.35.1 * openvswitch-debugsource-2.14.2-150400.24.35.1 * ovn-host-20.06.2-150400.24.35.1 * libovn-20_06-0-debuginfo-20.06.2-150400.24.35.1 * ovn-debuginfo-20.06.2-150400.24.35.1 * libopenvswitch-2_14-0-2.14.2-150400.24.35.1 * ovn-host-debuginfo-20.06.2-150400.24.35.1 * ovn-central-debuginfo-20.06.2-150400.24.35.1 * openvswitch-2.14.2-150400.24.35.1 * openvswitch-test-debuginfo-2.14.2-150400.24.35.1 * openvswitch-pki-2.14.2-150400.24.35.1 * python3-ovs-2.14.2-150400.24.35.1 * libovn-20_06-0-20.06.2-150400.24.35.1 * ovn-20.06.2-150400.24.35.1 * openvswitch-ipsec-2.14.2-150400.24.35.1 * ovn-vtep-20.06.2-150400.24.35.1 * openvswitch-vtep-2.14.2-150400.24.35.1 * ovn-docker-20.06.2-150400.24.35.1 * ovn-central-20.06.2-150400.24.35.1 * ovn-devel-20.06.2-150400.24.35.1 * openvswitch-vtep-debuginfo-2.14.2-150400.24.35.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * openvswitch-devel-2.14.2-150400.24.35.1 * openvswitch-test-2.14.2-150400.24.35.1 * ovn-vtep-debuginfo-20.06.2-150400.24.35.1 * openvswitch-debuginfo-2.14.2-150400.24.35.1 * libopenvswitch-2_14-0-debuginfo-2.14.2-150400.24.35.1 * openvswitch-debugsource-2.14.2-150400.24.35.1 * ovn-host-20.06.2-150400.24.35.1 * libovn-20_06-0-debuginfo-20.06.2-150400.24.35.1 * ovn-debuginfo-20.06.2-150400.24.35.1 * libopenvswitch-2_14-0-2.14.2-150400.24.35.1 * ovn-host-debuginfo-20.06.2-150400.24.35.1 * openvswitch-2.14.2-150400.24.35.1 * ovn-central-debuginfo-20.06.2-150400.24.35.1 * openvswitch-test-debuginfo-2.14.2-150400.24.35.1 * openvswitch-pki-2.14.2-150400.24.35.1 * python3-ovs-2.14.2-150400.24.35.1 * libovn-20_06-0-20.06.2-150400.24.35.1 * ovn-20.06.2-150400.24.35.1 * openvswitch-ipsec-2.14.2-150400.24.35.1 * ovn-vtep-20.06.2-150400.24.35.1 * openvswitch-vtep-2.14.2-150400.24.35.1 * ovn-docker-20.06.2-150400.24.35.1 * ovn-central-20.06.2-150400.24.35.1 * ovn-devel-20.06.2-150400.24.35.1 * openvswitch-vtep-debuginfo-2.14.2-150400.24.35.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * openvswitch-devel-2.14.2-150400.24.35.1 *openvswitch-test-2.14.2-150400.24.35.1 * ovn-vtep-debuginfo-20.06.2-150400.24.35.1 * openvswitch-debuginfo-2.14.2-150400.24.35.1 * libopenvswitch-2_14-0-debuginfo-2.14.2-150400.24.35.1 * openvswitch-debugsource-2.14.2-150400.24.35.1 * ovn-host-20.06.2-150400.24.35.1 * libovn-20_06-0-debuginfo-20.06.2-150400.24.35.1 * ovn-debuginfo-20.06.2-150400.24.35.1 * libopenvswitch-2_14-0-2.14.2-150400.24.35.1 * ovn-host-debuginfo-20.06.2-150400.24.35.1 * openvswitch-2.14.2-150400.24.35.1 * ovn-central-debuginfo-20.06.2-150400.24.35.1 * openvswitch-test-debuginfo-2.14.2-150400.24.35.1 * openvswitch-pki-2.14.2-150400.24.35.1 * python3-ovs-2.14.2-150400.24.35.1 * libovn-20_06-0-20.06.2-150400.24.35.1 * ovn-20.06.2-150400.24.35.1 * openvswitch-ipsec-2.14.2-150400.24.35.1 * ovn-vtep-20.06.2-150400.24.35.1 * openvswitch-vtep-2.14.2-150400.24.35.1 * ovn-docker-20.06.2-150400.24.35.1 * ovn-central-20.06.2-150400.24.35.1 * ovn-devel-20.06.2-150400.24.35.1 * openvswitch-vtep-debuginfo-2.14.2-150400.24.35.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5265.html * https://www.suse.com/security/cve/CVE-2026-5367.html * https://bugzilla.suse.com/show_bug.cgi?id=1262498 * https://bugzilla.suse.com/show_bug.cgi?id=1262499 . Important security update for openvswitch on openSUSE addressing heap over-read issues. Install promptly.. openvswitch security patch, SUSE important update, heap over-read vulnerability. . Severity: Important. LinuxSecurity.com Team
An update that solves 3 vulnerabilities can now be installed.. # tinyproxy-1.11.3-3.1 on GA media Announcement ID: openSUSE-SU-2026:11060-1 Rating: moderate Cross-References: * CVE-2026-54387 * CVE-2026-54388 * CVE-2026-55202 Affected Products: * openSUSE Tumbleweed An update that solves 3 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the tinyproxy-1.11.3-3.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * tinyproxy 1.11.3-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54387.html * https://www.suse.com/security/cve/CVE-2026-54388.html * https://www.suse.com/security/cve/CVE-2026-55202.html . An update for openSUSE Tumbleweed fixes three vulnerabilities in tinyproxy version 1.11.3-3.1, enhancing system security.. OpenSUSE, tinyproxy, security update, system vulnerabilities, networking. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # flannel-0.28.5-1.1 on GA media Announcement ID: openSUSE-SU-2026:10980-1 Rating: moderate Cross-References: * CVE-2026-44283 CVSS scores: * CVE-2026-44283 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44283 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the flannel-0.28.5-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * flannel 0.28.5-1.1 * flannel-k8s-yaml 0.28.5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44283.html . Update for openSUSE Tumbleweed resolves moderate vulnerability in flannel 0.28.5-1.1. Immediate installation recommended.. openSUSE Tumbleweed flannel update security patch moderate. . Severity: moderate. LinuxSecurity.com Team
The system could be made to run programs as an administrator.. ========================================================================== Ubuntu Security Notice USN-8390-1 June 04, 2026 linux, linux-azure, linux-azure-4.15, linux-azure-fips, linux-fips, linux-gcp-4.15, linux-gcp-fips, linux-kvm, linux-oracle vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 14.04 LTS Summary: The system could be made to run programs as an administrator. Software Description: - linux: Linux kernel - linux-azure-4.15: Linux kernel for Microsoft Azure Cloud systems - linux-azure-fips: Linux kernel for Microsoft Azure Cloud systems with FIPS - linux-fips: Linux kernel with FIPS - linux-gcp-4.15: Linux kernel for Google Cloud Platform (GCP) systems - linux-gcp-fips: Linux kernel for Google Cloud Platform (GCP) systems with FIPS - linux-kvm: Linux kernel for cloud environments - linux-oracle: Linux kernel for Oracle Cloud systems - linux-azure: Linux kernel for Microsoft Azure Cloud systems Details: It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could use this to escalate privileges, or possibly escape a container. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS linux-image-4.15.0-1148-fips 4.15.0-1148.160 Available with Ubuntu Pro linux-image-4.15.0-1155-oracle 4.15.0-1155.166 Available with Ubuntu Pro linux-image-4.15.0-1175-kvm 4.15.0-1175.180 Available with Ubuntu Pro linux-image-4.15.0-1186-gcp 4.15.0-1186.203 Available with Ubuntu Pro linux-image-4.15.0-1202-azure 4.15.0-1202.217 Available with Ubuntu Pro linux-image-4.15.0-2094-gcp-fips 4.15.0-2094.100 Available with Ubuntu Pro linux-image-4.15.0-2111-azure-fips 4.15.0-2111.117 Available with Ubuntu Pro linux-image-4.15.0-251-generic 4.15.0-251.263 Available with Ubuntu Pro linux-image-4.15.0-251-lowlatency 4.15.0-251.263 Available with Ubuntu Pro linux-image-azure-4.15 4.15.0.1202.170 Available with Ubuntu Pro linux-image-azure-fips 4.15.0.2111.107 Available with Ubuntu Pro linux-image-azure-fips-4.15 4.15.0.2111.107 Available with Ubuntu Pro linux-image-azure-lts-18.04 4.15.0.1202.170 Available with Ubuntu Pro linux-image-fips 4.15.0.1148.145 Available with Ubuntu Pro linux-image-gcp-4.15 4.15.0.1186.199 Available with Ubuntu Pro linux-image-gcp-fips 4.15.0.2094.92 Available with Ubuntu Pro linux-image-gcp-fips-4.15 4.15.0.2094.92 Available with Ubuntu Pro linux-image-gcp-lts-18.04 4.15.0.1186.199 Available with Ubuntu Pro linux-image-generic 4.15.0.251.235 Available with Ubuntu Pro linux-image-kvm 4.15.0.1175.166 Available with Ubuntu Pro linux-image-lowlatency 4.15.0.251.235 Available with Ubuntu Pro linux-image-oracle-4.15 4.15.0.1155.160 Available withUbuntu Pro linux-image-oracle-lts-18.04 4.15.0.1155.160 Available with Ubuntu Pro linux-image-virtual 4.15.0.251.235 Available with Ubuntu Pro Ubuntu 14.04 LTS linux-image-4.15.0-1202-azure 4.15.0-1202.217~14.04.1 Available with Ubuntu Pro linux-image-azure 4.15.0.1202.217~14.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8390-1 CVE-2026-43284 . Address critical privilege escalation in Ubuntu Linux kernel through timely updates. Security notice USN-8390-1 provides details.. Linux kernel update, Ubuntu security issues, privilege escalation fixes, critical security updates. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-8277-2 May 22, 2026 linux-oracle-6.17 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-oracle-6.17: Linux kernel for Oracle Cloud systems Details: It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - S390 architecture; - Cryptographic API; - GPU drivers; - Ethernet bonding driver; - Network file system (NFS) server daemon; - Distributed Switch Architecture; - Netfilter; - Control group (cgroup); - Kernel kexec() syscall; - Memory management; - MAC80211 subsystem; - Multipath TCP; - Packet sockets; - TLS protocol; - Unix domain sockets; (CVE-2025-71088, CVE-2025-71090, CVE-2025-71127, CVE-2025-71134, CVE-2025-71139, CVE-2025-71141, CVE-2025-71142, CVE-2025-71144, CVE-2025-71152, CVE-2025-71155, CVE-2026-23274, CVE-2026-23351, CVE-2026-23394, CVE-2026-31419, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS linux-image-6.17.0-1014-oracle 6.17.0-1014.14~24.04.1 linux-image-6.17.0-1014-oracle-64k 6.17.0-1014.14~24.04.1 linux-image-oracle 6.17.0-1014.14~24.04.1 linux-image-oracle-6.17 6.17.0-1014.14~24.04.1 linux-image-oracle-64k 6.17.0-1014.14~24.04.1 linux-image-oracle-64k-6.17 6.17.0-1014.14~24.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8277-2 https://ubuntu.com/security/notices/USN-8277-1 CVE-2025-71088, CVE-2025-71090, CVE-2025-71127, CVE-2025-71134, CVE-2025-71139, CVE-2025-71141, CVE-2025-71142, CVE-2025-71144, CVE-2025-71152, CVE-2025-71155, CVE-2026-23274, CVE-2026-23351, CVE-2026-23394, CVE-2026-31419, CVE-2026-31431, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078 Package Information: https://launchpad.net/ubuntu/+source/linux-oracle-6.17/6.17.0-1014.14~24.04.1 . Several security issues were found in Ubuntu's Linux kernel, requiring immediate updates to maintain system integrity and security.. Ubuntu Security Notice, Linux Kernel, Privilege Escalation, Security Updates. . Severity: Important. LinuxSecurity.com Team
An update that solves 4 vulnerabilities and has one bug fix can now be installed.. openSUSE security update: security update for mozillafirefox ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20741-1 Rating: moderate References: * bsc#1264378 Cross-References: * CVE-2026-8090 * CVE-2026-8091 * CVE-2026-8092 * CVE-2026-8094 CVSS scores: * CVE-2026-8090 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8091 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8092 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8094 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 4 vulnerabilities and has one bug fix can now be installed. Description: This update for MozillaFirefox fixes the following issues Updated to Firefox Extended Support Release 140.10.2 ESR (bsc#1264378,MFSA 2026-41): - CVE-2026-8090: Use-after-free in the DOM: Networking component. - CVE-2026-8091: Incorrect boundary conditions in the Audio/Video: Playback component. - CVE-2026-8092: Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2. - CVE-2026-8094: Other issue in the WebRTC component. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-732=1 Package List: - openSUSE Leap 16.0: MozillaFirefox-140.10.2-160000.1.1 MozillaFirefox-branding-upstream-140.10.2-160000.1.1 MozillaFirefox-devel-140.10.2-160000.1.2 MozillaFirefox-translations-common-140.10.2-160000.1.1 MozillaFirefox-translations-other-140.10.2-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-8090.html *https://www.suse.com/security/cve/CVE-2026-8091.html * https://www.suse.com/security/cve/CVE-2026-8092.html * https://www.suse.com/security/cve/CVE-2026-8094.html . Update for openSUSE fixes Mozilla Firefox issues and addresses four vulnerabilities with moderate severity recommendations.. openSUSE MozillaFirefox Update, MozillaFirefox Security, Firefox Vulnerabilities, OpenSUSE Vulnerabilities, Mozilla Security Advisory. . LinuxSecurity.com Team
An update that solves eight vulnerabilities can now be installed.. # Security update for MozillaFirefox Announcement ID: SUSE-SU-2026:1830-1 Release Date: 2026-05-12T12:00:51Z Rating: important References: * bsc#1263110 * bsc#1264378 Cross-References: * CVE-2026-7320 * CVE-2026-7321 * CVE-2026-7322 * CVE-2026-7323 * CVE-2026-8090 * CVE-2026-8091 * CVE-2026-8092 * CVE-2026-8094 CVSS scores: * CVE-2026-7320 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-7321 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-7322 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-7323 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-8090 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8090 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-8091 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8091 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-8092 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8092 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-8094 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8094 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issues Updated to Firefox Extended Support Release 140.10.2 ESR (bsc#1264378,MFSA 2026-41): * CVE-2026-8090: Use-after-free in the DOM: Networking component. * CVE-2026-8092: Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2. * CVE-2026-8094: Other issue in the WebRTC component. Updated to Firefox Extended Support Release 140.10.1 ESR (bsc#1263110,MFSA 2026-36): * CVE-2026-7320: Information disclosure due to incorrect boundary conditions in the Audio/Video component. * CVE-2026-7321: Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. * CVE-2026-7322: Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. * CVE-2026-7323: Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1. * CVE-2026-8091: Incorrect boundary conditions in the Audio/Video: Playback component. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-1830=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-1830=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-140.10.2-112.313.1 * MozillaFirefox-debugsource-140.10.2-112.313.1 * MozillaFirefox-translations-common-140.10.2-112.313.1 * MozillaFirefox-debuginfo-140.10.2-112.313.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * MozillaFirefox-devel-140.10.2-112.313.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * MozillaFirefox-140.10.2-112.313.1 * MozillaFirefox-debugsource-140.10.2-112.313.1 * MozillaFirefox-translations-common-140.10.2-112.313.1 * MozillaFirefox-debuginfo-140.10.2-112.313.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * MozillaFirefox-devel-140.10.2-112.313.1 ## References: * https://www.suse.com/security/cve/CVE-2026-7320.html *https://www.suse.com/security/cve/CVE-2026-7321.html * https://www.suse.com/security/cve/CVE-2026-7322.html * https://www.suse.com/security/cve/CVE-2026-7323.html * https://www.suse.com/security/cve/CVE-2026-8090.html * https://www.suse.com/security/cve/CVE-2026-8091.html * https://www.suse.com/security/cve/CVE-2026-8092.html * https://www.suse.com/security/cve/CVE-2026-8094.html * https://bugzilla.suse.com/show_bug.cgi?id=1263110 * https://bugzilla.suse.com/show_bug.cgi?id=1264378 . Important update for MozillaFirefox resolves multiple issues with significant security implications. Upgrade recommended.. MozillaFirefox Update, SUSE Security Patch, CVSS Important, Security Advisory Notification. . Severity: Important. LinuxSecurity.com Team
MGASA-2026-0124 - Updated rootcerts, nss & firefox packages fix security vulnerabilities. MGASA-2026-0124 - Updated rootcerts, nss & firefox packages fix security vulnerabilities Publication date: 09 May 2026 URL: https://advisories.mageia.org/MGASA-2026-0124.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-6746, CVE-2026-6747, CVE-2026-6748, CVE-2026-6749, CVE-2026-6750, CVE-2026-6751, CVE-2026-6752, CVE-2026-6753, CVE-2026-6754, CVE-2026-6757, CVE-2026-6759, CVE-2026-6761, CVE-2026-6762, CVE-2026-6763, CVE-2026-6764, CVE-2026-6765, CVE-2026-6766 Description: Use-after-free in the DOM: Core & HTML component. (CVE-2026-6746) Use-after-free in the WebRTC component. (CVE-2026-6747) Uninitialized memory in the Audio/Video: Web Codecs component. (CVE-2026-6748) Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. (CVE-2026-6749) Privilege escalation in the Graphics: WebRender component. (CVE-2026-6750) Uninitialized memory in the Audio/Video: Web Codecs component. (CVE-2026-6751) Incorrect boundary conditions in the WebRTC component. (CVE-2026-6752) Incorrect boundary conditions in the WebRTC component. (CVE-2026-6753) Use-after-free in the JavaScript Engine component. (CVE-2026-6754) Invalid pointer in the JavaScript: WebAssembly component. (CVE-2026-6757) Use-after-free in the Widget: Cocoa component. (CVE-2026-6759) Privilege escalation in the Networking component. (CVE-2026-6761) Spoofing issue in the DOM: Core & HTML component. (CVE-2026-6762) Mitigation bypass in the File Handling component. (CVE-2026-6763) Incorrect boundary conditions in the DOM: Device Interfaces component. (CVE-2026-6764) Information disclosure in the Form Autofill component. (CVE-2026-6765) Incorrect boundary conditions in the Libraries component in NSS. (CVE-2026-6766) Other issue in the Libraries component in NSS. (CVE-2026-6767) Privilege escalation in the Debugger component. (CVE-2026-6769) Other issue inthe Storage: IndexedDB component. (CVE-2026-6770) Mitigation bypass in the DOM: Security component. (CVE-2026-6771) Incorrect boundary conditions in the Libraries component in NSS. (CVE-2026-6772) Incorrect boundary conditions in the WebRTC: Networking component. (CVE-2026-6776) Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150. (CVE-2026-6785) Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150. (CVE-2026-6786) Information disclosure due to incorrect boundary conditions in the Audio/Video component. (CVE-2026-7320) Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. (CVE-2026-7321) Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. (CVE-2026-7322) Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1. (CVE-2026-7323) References: - https://bugs.mageia.org/show_bug.cgi?id=35403 - https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_123.html - https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_123_1.html - https://www.firefox.com/en-US/firefox/140.10.0/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa2026-32/ - https://www.firefox.com/en-US/firefox/140.10.1/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa2026-36/ - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6746 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6747 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6748 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6749 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6750 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6751 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6752 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6753 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6754 -https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6757 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6759 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6761 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6762 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6763 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6764 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6765 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6766 SRPMS: - 9/core/rootcerts-20260412.00-1.mga9 - 9/core/nss-3.123.1-1.mga9 - 9/core/firefox-140.10.1-1.mga9 - 9/core/firefox-l10n-140.10.1-1.mga9 . Updated rootcerts and Firefox packages in Mageia address multiple security concerns with varying severity levels.. Mageia Security Advisory, Firefox Updates, Rootcerts Vulnerability, Networking Issues. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.