Update uv and python-uv-build to 0.11.2. Version 0.11 includes changes to the networking stack used by uv. While its developers think that breakage will be rare, it is possible that these changes will result in the rejection of certificates previously trusted by uv so, they have marked the change as breaking out of an abundance of caution. The changes are largely driven by the. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b8b59dcf44 2026-03-28 00:15:26.019955+00:00 -------------------------------------------------------------------------------- Name : rust-reqsign-file-read-tokio Product : Fedora 44 Version : 3.0.0 Release : 1.fc44 URL : https://crates.io/crates/reqsign-file-read-tokio Summary : Tokio-based file reader implementation for reqsign Description : Tokio-based file reader implementation for reqsign. -------------------------------------------------------------------------------- Update Information: Update uv and python-uv-build to 0.11.2. Version 0.11 includes changes to the networking stack used by uv. While its developers think that breakage will be rare, it is possible that these changes will result in the rejection of certificates previously trusted by uv so, they have marked the change as breaking out of an abundance of caution. The changes are largely driven by the upgrade of reqwest, which powers uv's HTTP clients, to v0.13, which included some breaking changes to TLS certificate verification. This update also includes updates for several of uv\u2019s Rust library dependencies. Update rust-openssl-probe to 0.2.1, including breaking changes introduced in 0.2.0, and introduce a new rust-openssl-probe0.1 compat package. Update rust-rustls-native-certs to 0.8.3, now using openssl-probe 0.2. Update rust-native-tls to 0.2.18. Version 0.2.16 added TLS 1.3 as an option, added stack_from_pem, and upgraded openssl-probe to 0.2. Version 0.2.17 added support for ALPN on the server side. Version0.2.18 fixed min/max protocol selection fallback for very old OpenSSL versions. Add an initial package for rust-webpki-root-certs. -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 24 2026 Benjamin A. Beasley - 3.0.0-1 - Update to version 3.0.0; Fixes RHBZ#2432774 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2425802 - rust-openssl-probe-0.2.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2425802 [ 2 ] Bug #2425819 - rust-rustls-native-certs-0.8.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2425819 [ 3 ] Bug #2432768 - rust-reqsign-aliyun-oss-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432768 [ 4 ] Bug #2432769 - rust-reqsign-core-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432769 [ 5 ] Bug #2432770 - rust-reqsign-0.20.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432770 [ 6 ] Bug #2432771 - rust-reqsign-azure-storage-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432771 [ 7 ] Bug #2432772 - rust-reqsign-http-send-reqwest-4.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432772 [ 8 ] Bug #2432773 - rust-reqsign-google-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432773 [ 9 ] Bug #2432774 - rust-reqsign-file-read-tokio-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432774 [ 10 ] Bug #2432775 - rust-reqsign-command-execute-tokio-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432775 [ 11 ] Bug #2432776 - rust-reqsign-aws-v4-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432776 [ 12 ] Bug #2432777 - rust-reqsign-huaweicloud-obs-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432777 [ 13 ] Bug #2432779 - rust-reqsign-tencent-cos-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432779 [ 14 ] Bug #2436289 - rust-ambient-id-0.0.11 is available https://bugzilla.redhat.com/show_bug.cgi?id=2436289 [ 15 ] Bug #2437941 - rust-astral-reqwest-middleware-0.5.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2437941 [ 16 ] Bug #2437942 - rust-astral-reqwest-retry-0.9.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2437942 [ 17 ] Bug #2437976 - rust-astral_async_http_range_reader-0.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2437976 [ 18 ] Bug #2439752 - rust-native-tls-0.2.18 is available https://bugzilla.redhat.com/show_bug.cgi?id=2439752 [ 19 ] Bug #2450541 - python-uv-build-0.11.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2450541 [ 20 ] Bug #2450582 - uv-0.11.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2450582 [ 21 ] Bug #2451103 - Review Request: rust-webpki-root-certs - Mozilla trusted certificate authorities in self-signed X.509 format https://bugzilla.redhat.com/show_bug.cgi?id=2451103 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b8b59dcf44' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical updates for Fedora 44 addressing network stack changes likely impacting trusted certificates for uv and python-uv-build.. Fedora 44 Updates, Rust Reqsign, Network Stack Changes, Python UV Build. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:20508-1 Release Date: 2026-02-19T09:17:44Z Rating: important References: * bsc#1253439 * bsc#1253473 Cross-References: * CVE-2025-40129 * CVE-2025-40186 CVSS scores: * CVE-2025-40129 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-40129 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-40186 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40186 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 6.4.0-36.1 fixes various security issues The following security issues were fixed: * CVE-2025-40129: sunrpc: fix null pointer dereference on zero-length checksum (bsc#1253473). * CVE-2025-40186: tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request() (bsc#1253439). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-279=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-36-default-3-1.1 * kernel-livepatch-MICRO-6-0_Update_13-debugsource-3-1.1 * kernel-livepatch-6_4_0-36-default-debuginfo-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40129.html * https://www.suse.com/security/cve/CVE-2025-40186.html * https://bugzilla.suse.com/show_bug.cgi?id=1253439 * https://bugzilla.suse.com/show_bug.cgi?id=1253473 . This advisory covers an important kernel update for SUSE Linux Micro 6.0addressing two significant vulnerabilities.. SUSE Linux Micro, kernel update, security patch, important advisory. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in CRaC JDK 17.. ========================================================================== Ubuntu Security Notice USN-7997-1 February 02, 2026 openjdk-17-crac vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 Summary: Several security issues were fixed in CRaC JDK 17. Software Description: - openjdk-17-crac: Open Source Java implementation with Coordinated Restore at Checkpoints Details: It was discovered that the RMI component of CRaC JDK 17 would establish RMI TCP endpoint connections to a remote host without setting an endpoint identification algorithm. An unauthenticated remote attacker could possibly use this issue to steal sensitive information. (CVE-2026-21925) Mingijung discovered that the AWT and JavaFX componenets of CRaC JDK 17 could run programs if Desktop.browse() was supplied a filename as a URI. An unauthenticated remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-21932) Zhihui Chen discovered that the Networking component of CRaC JDK 17 was suceptible to a CRLF injection vulnerability via the HttpServer class. An unauthenticated remote attacker could possibly use this issue to modify files or leak sensitive information. (CVE-2026-21933) Ireneusz Pastusiak discovered that the Security component of CRaC JDK 17 failed to verify provided URIs point to a legitimate source when AIA is enabled. An unauthenticated remote attacker could possibly use this issue to redirect users to malicious hosts. (CVE-2026-21945) In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://openjdk.org/groups/vulnerability/advisories/2026-01-20 Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 openjdk-17-crac-jdk 17.0.18+8-0ubuntu1~25.10 openjdk-17-crac-jdk-headless 17.0.18+8-0ubuntu1~25.10 openjdk-17-crac-jre 17.0.18+8-0ubuntu1~25.10 openjdk-17-crac-jre-headless 17.0.18+8-0ubuntu1~25.10 openjdk-17-crac-jre-zero 17.0.18+8-0ubuntu1~25.10 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart Java applications to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7997-1 CVE-2026-21925, CVE-2026-21932, CVE-2026-21933, CVE-2026-21945 Package Information: https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.18+8-0ubuntu1~25.10 . Address several security issues in CRaC JDK 17 on Ubuntu 25.10 with critical fixes and updates.. openjdk 17 CRaC, Ubuntu JDK updates, Java security fixes, remote code execution, security vulnerabilities. . Severity: Important. LinuxSecurity.com Team
* bsc#1200731 * bsc#1238322 * bsc#1246126 * bsc#1249152 * bsc#430790 . # Security update for powerpc-utils Announcement ID: SUSE-SU-2025:21067-1 Release Date: 2025-11-10T14:24:22Z Rating: moderate References: * bsc#1200731 * bsc#1238322 * bsc#1246126 * bsc#1249152 * bsc#430790 * bsc#866675 * bsc#869852 * bsc#883174 * bsc#886123 * bsc#887275 * bsc#933651 * jsc#PED-3946 Cross-References: * CVE-2014-4040 CVSS scores: Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability, contains one feature and has 10 fixes can now be installed. ## Description: This update for powerpc-utils fixes the following issues: * Start SMT service after networking (bsc#1249152 ltc#214730) * Fix inconsistent Core Online/Offline States Observed in lscpu and ppc64_cpu --info Command Outputs During DLPAR Operation (bsc#1246126 ltc#214064) * Fix HNV installation network conflicts across all distributions (jsc#PED-3946) * Fix negative values of idle PURR (bsc#1238322 ltc#210808) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-335=1 ## Package List: * SUSE Linux Micro 6.1 (ppc64le) * powerpc-utils-1.3.12-slfo.1.1_5.1 * powerpc-utils-debugsource-1.3.12-slfo.1.1_5.1 * powerpc-utils-debuginfo-1.3.12-slfo.1.1_5.1 ## References: * https://www.suse.com/security/cve/CVE-2014-4040.html * https://bugzilla.suse.com/show_bug.cgi?id=1200731 * https://bugzilla.suse.com/show_bug.cgi?id=1238322 * https://bugzilla.suse.com/show_bug.cgi?id=1246126 * https://bugzilla.suse.com/show_bug.cgi?id=1249152 * https://bugzilla.suse.com/show_bug.cgi?id=430790 * https://bugzilla.suse.com/show_bug.cgi?id=866675 * https://bugzilla.suse.com/show_bug.cgi?id=869852 *https://bugzilla.suse.com/show_bug.cgi?id=883174 * https://bugzilla.suse.com/show_bug.cgi?id=886123 * https://bugzilla.suse.com/show_bug.cgi?id=887275 * https://bugzilla.suse.com/show_bug.cgi?id=933651 * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=https%3A%2F%2Fjira.suse.com%2Fbrowse%2FPED-3946 . Update for SUSE powerpc-utils addresses fixes and a vulnerability, ensuring improved stability and security on systems.. SUSE powerpc-utils update, security fixes, Linux patching, SUSE Micro 6.1. . LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7408-4 April 07, 2025 linux-hwe-5.4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-hwe-5.4: Linux hardware enablement (HWE) kernel Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - SMB network file system; - Network namespace; - Networking core; (CVE-2024-56658, CVE-2024-35864, CVE-2024-26928) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS linux-image-5.4.0-212-generic 5.4.0-212.232~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-212-lowlatency 5.4.0-212.232~18.04.1 Available with Ubuntu Pro linux-image-generic-hwe-18.04 5.4.0.212.232~18.04.1 Available with Ubuntu Pro linux-image-lowlatency-hwe-18.04 5.4.0.212.232~18.04.1 Available with Ubuntu Pro linux-image-oem 5.4.0.212.232~18.04.1 Available with Ubuntu Pro linux-image-oem-osp1 5.4.0.212.232~18.04.1 Available with Ubuntu Pro linux-image-snapdragon-hwe-18.04 5.4.0.212.232~18.04.1 Available with Ubuntu Pro linux-image-virtual-hwe-18.04 5.4.0.212.232~18.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer tomake all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7408-4 https://ubuntu.com/security/notices/USN-7408-3 https://ubuntu.com/security/notices/USN-7408-2 https://ubuntu.com/security/notices/USN-7408-1 CVE-2024-26928, CVE-2024-35864, CVE-2024-56658 . Discover critical security updates for the Ubuntu 18.04 LTS addressing multiple kernel issues and risks.. Ubuntu Security Notice, linux-hwe-5.4, kernel update, security issues, system compromise. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7408-2 April 02, 2025 linux-fips vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-fips: Linux kernel with FIPS Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - SMB network file system; - Network namespace; - Networking core; (CVE-2024-56658, CVE-2024-35864, CVE-2024-26928) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.4.0-1117-fips 5.4.0-1117.127 Available with Ubuntu Pro linux-image-fips 5.4.0.1117.114 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7408-2 https://ubuntu.com/security/notices/USN-7408-1 CVE-2024-26928, CVE-2024-35864, CVE-2024-56658 . Several concerns addressed in Ubuntu's FIPS kernel upgrade; crucial for safeguarding system integrity and security.. kernelvulnerabilities, ubuntu update, linux security issues, fips kernel, network vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in CRaC JDK 17.. ========================================================================== Ubuntu Security Notice USN-7338-1 March 11, 2025 openjdk-17-crac vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 Summary: Several security issues were fixed in CRaC JDK 17. Software Description: - openjdk-17-crac: Open Source Java implementation with Coordinated Restore at Checkpoints Details: Andy Boothe discovered that the Networking component of CRaC JDK 17 did not properly handle access under certain circumstances. An unauthenticated attacker could possibly use this issue to cause a denial of service. (CVE-2024-21208) It was discovered that the Hotspot component of CRaC JDK 17 did not properly handle vectorization under certain circumstances. An unauthenticated attacker could possibly use this issue to access unauthorized resources and expose sensitive information. (CVE-2024-21210, CVE-2024-21235) It was discovered that the Serialization component of CRaC JDK 17 did not properly handle deserialization under certain circumstances. An unauthenticated attacker could possibly use this issue to cause a denial of service. (CVE-2024-21217) It was discovered that the Hotspot component of CRaC JDK 17 did not properly handle API access under certain circumstances. An unauthenticated attacker could possibly use this issue to access unauthorized resources and expose sensitive information. (CVE-2025-21502) In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://openjdk.org/groups/vulnerability/advisories/2024-10-15 https://openjdk.org/groups/vulnerability/advisories/2025-01-21 Update instructions: The problem can be corrected by updating your system to the following packageversions: Ubuntu 24.10 openjdk-17-crac-jdk 17.0.14+7-0ubuntu1~24.10 openjdk-17-crac-jdk-headless 17.0.14+7-0ubuntu1~24.10 openjdk-17-crac-jre 17.0.14+7-0ubuntu1~24.10 openjdk-17-crac-jre-headless 17.0.14+7-0ubuntu1~24.10 openjdk-17-crac-jre-zero 17.0.14+7-0ubuntu1~24.10 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart Java applications to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7338-1 CVE-2024-21208, CVE-2024-21210, CVE-2024-21217, CVE-2024-21235, CVE-2025-21502 Package Information: https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.14+7-0ubuntu1~24.10 . Multiple vulnerabilities were resolved within Ubuntu's CRaC JDK 17 impacting the networking and Hotspot modules.. OpenJDK Updates, Security Fixes, Java Vulnerabilities, Ubuntu Security. . LinuxSecurity.com Team
Several security issues were fixed in Linux kernel.. ========================================================================== Ubuntu Security Notice USN-6925-1 July 29, 2024 linux vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Linux kernel. Software Description: - linux: Linux kernel Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - IPv4 networking; (CVE-2024-26882) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS linux-image-3.13.0-198-generic 3.13.0-198.249 Available with Ubuntu Pro linux-image-3.13.0-198-lowlatency 3.13.0-198.249 Available with Ubuntu Pro linux-image-generic 3.13.0.198.208 Available with Ubuntu Pro linux-image-generic-lts-quantal 3.13.0.198.208 Available with Ubuntu Pro linux-image-generic-lts-raring 3.13.0.198.208 Available with Ubuntu Pro linux-image-generic-lts-saucy 3.13.0.198.208 Available with Ubuntu Pro linux-image-generic-lts-trusty 3.13.0.198.208 Available with Ubuntu Pro linux-image-lowlatency 3.13.0.198.208 Available with Ubuntu Pro linux-image-server 3.13.0.198.208 Available with Ubuntu Pro linux-image-virtual 3.13.0.198.208 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due toan unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-6925-1 CVE-2024-26882 . Ubuntu 20.04 LTS updates resolve various vulnerabilities in the Linux kernel; restarting the system is required for updates to apply.. Linux kernel Updates, Ubuntu Security, System Compromise Fixes. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.