Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in OpenSSL.. ========================================================================== Ubuntu Security Notice USN-7980-2 January 27, 2026 openssl, openssl1.0 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in OpenSSL. Software Description: - openssl: Secure Socket Layer (SSL) cryptographic library and tools - openssl1.0: Secure Socket Layer (SSL) cryptographic library and tools Details: USN-7980-2 fixed vulnerabilities in OpenSSL. This update provides the corresponding updates for CVE-2025-68160 for openssl and openssl1.0, CVE-2025-69418 for openssl on Ubuntu 18.04 LTS and Ubuntu 20.04 LTS, CVE-2025-69419 for openssl on Ubuntu 18.04 LTS and Ubuntu 20.04 LTS, CVE-2025-69420 for openssl on Ubuntu 18.04 LTS and Ubuntu 20.04 LTS, CVE-2025-69421 for openssl and openssl1.0, CVE-2026-22795 for openssl on Ubuntu 18.04 LTS and Ubuntu 20.04 LTS, and CVE-2026-22796 for openssl and openssl1.0. Original advisory details: Stanislav Fort, Petr \u0160ime\u010dek, and Hamza discovered that OpenSSL incorrectly validated PBMAC1 parameters when doing PKCS#12 MAC verification. An attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. This issue only affected Ubuntu 25.10. (CVE-2025-11187) Stanislav Fort discovered that OpenSSL incorrectly parsed CMS AuthEnvelopedData messages. An attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2025-15467) Stanislav Fort discovered that OpenSSL incorrectly handled memory in the SSL_CIPHER_find() function. An attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. This issue only affected Ubuntu 25.10. (CVE-2025-15468) Stanislav Fort discovered that the OpenSSL"openssl dgst" command line tool incorrectly truncated data to 16MB. An attacker could posibly use this issue to hide unauthenticated data beyond the 16MB limit. This issue only affected Ubuntu 25.10. (CVE-2025-15469) Tomas Dulka and Stanislav Fort discovered that OpenSSL incorrectly handled memory with TLS 1.3 connections using certificate compression. An attacker could possibly use this issue to consume resources, leading to a denial of service. This issue only affected Ubuntu 25.10. (CVE-2025-66199) Petr Simecek and Stanislav Fort discovered that OpenSSL incorrectly handled memory when writing large data into a BIO chain. An attacker could possibly use this issue to consume resources, leading to a denial of service. (CVE-2025-68160) Stanislav Fort discovered that the OpenSSL OCB API could incorrectly leave final partial blocks unencrypted and unauthenticated. An attacker could possibly use this issue to read or tamper with the affected final bytes. (CVE-2025-69418) Stanislav Fort discovered that OpenSSL incorrectly handled the PKCS12_get_friendlyname() utf-8 conversion. An attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2025-69419) Luigino Camastra discovered that OpenSSL incorrectly handled ASN1_TYPE validation in the TS_RESP_verify_response() function. An attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2025-69420) Luigino Camastra discovered that OpenSSL incorrectly handled memory in the PKCS12_item_decrypt_d2i_ex function. An attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2025-69421) Luigino Camastra discovered that OpenSSL incorrectly handled ASN1_TYPE validation in PKCS#12 parsing. An attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2026-22795) Luigino Camastra discovered that OpenSSL incorrectly handled ASN1_TYPE validation in thePKCS7_digest_from_attributes() function. An attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2026-22796) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS libssl1.1 1.1.1f-1ubuntu2.24+esm2 Available with Ubuntu Pro openssl 1.1.1f-1ubuntu2.24+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS libssl1.0.0 1.0.2n-1ubuntu5.13+esm3 Available with Ubuntu Pro libssl1.1 1.1.1-1ubuntu2.1~18.04.23+esm7 Available with Ubuntu Pro openssl 1.1.1-1ubuntu2.1~18.04.23+esm7 Available with Ubuntu Pro openssl1.0 1.0.2n-1ubuntu5.13+esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS libssl1.0.0 1.0.2g-1ubuntu4.20+esm14 Available with Ubuntu Pro openssl 1.0.2g-1ubuntu4.20+esm14 Available with Ubuntu Pro Ubuntu 14.04 LTS libssl1.0.0 1.0.1f-1ubuntu2.27+esm12 Available with Ubuntu Pro openssl 1.0.1f-1ubuntu2.27+esm12 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7980-2 https://ubuntu.com/security/notices/USN-7980-1 CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 . Explore Ubuntu's security advisory on OpenSSL fixes for multiple vulnerabilities and potential denial of service risks.. OpenSSL Denial Of Service Ubuntu Security Update Cryptography. . Severity:Critical. LinuxSecurity.com Team
Rebase to 3.2.4, fix CVE-2024-12797. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e0e44b1b98 2025-02-14 01:35:06.429296+00:00 -------------------------------------------------------------------------------- Name : openssl Product : Fedora 41 Version : 3.2.4 Release : 1.fc41 URL : http://www.openssl.org/ Summary : Utilities from the general purpose cryptography library with TLS implementation Description : The OpenSSL toolkit provides support for secure communications between machines. OpenSSL includes a certificate management tool and shared libraries which provide various cryptographic algorithms and protocols. -------------------------------------------------------------------------------- Update Information: Rebase to 3.2.4, fix CVE-2024-12797 -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 12 2025 Dmitry Belyavskiy - 1:3.2.4-1 - Rebase to 3.2.4 Resolves: rhbz#2345073 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2345073 - [Minor Incident] CVE-2024-12797 openssl: RFC7250 handshakes with unauthenticated servers don't abort as expected [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2345073 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e0e44b1b98' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update for ruby is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: ruby security update Advisory ID: RHSA-2019:2565-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:2565 Issue date: 2019-08-27 CVE Names: CVE-2018-16395 ==================================================================== 1. Summary: An update for ruby is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.5) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.5) - noarch, x86_64 Red Hat Enterprise Linux Server EUS (v. 7.5) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.5) - noarch, ppc64, ppc64le, s390x, x86_64 3. Description: Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. Security Fix(es): * ruby: OpenSSL::X509::Name equality check does not work correctly (CVE-2018-16395) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in thisadvisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1643086 - CVE-2018-16395 ruby: OpenSSL::X509::Name equality check does not work correctly 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.5): Source: ruby-2.0.0.648-34.el7_5.src.rpm noarch: ruby-irb-2.0.0.648-34.el7_5.noarch.rpm rubygem-rdoc-4.0.0-34.el7_5.noarch.rpm rubygems-2.0.14.1-34.el7_5.noarch.rpm x86_64: ruby-2.0.0.648-34.el7_5.x86_64.rpm ruby-debuginfo-2.0.0.648-34.el7_5.i686.rpm ruby-debuginfo-2.0.0.648-34.el7_5.x86_64.rpm ruby-libs-2.0.0.648-34.el7_5.i686.rpm ruby-libs-2.0.0.648-34.el7_5.x86_64.rpm rubygem-bigdecimal-1.2.0-34.el7_5.x86_64.rpm rubygem-io-console-0.4.2-34.el7_5.x86_64.rpm rubygem-json-1.7.7-34.el7_5.x86_64.rpm rubygem-psych-2.0.0-34.el7_5.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.5): noarch: ruby-doc-2.0.0.648-34.el7_5.noarch.rpm rubygem-minitest-4.3.2-34.el7_5.noarch.rpm rubygem-rake-0.9.6-34.el7_5.noarch.rpm rubygems-devel-2.0.14.1-34.el7_5.noarch.rpm x86_64: ruby-debuginfo-2.0.0.648-34.el7_5.x86_64.rpm ruby-devel-2.0.0.648-34.el7_5.x86_64.rpm ruby-tcltk-2.0.0.648-34.el7_5.x86_64.rpm Red Hat Enterprise Linux Server EUS (v.7.5): Source: ruby-2.0.0.648-34.el7_5.src.rpm noarch: ruby-irb-2.0.0.648-34.el7_5.noarch.rpm rubygem-rdoc-4.0.0-34.el7_5.noarch.rpm rubygems-2.0.14.1-34.el7_5.noarch.rpm ppc64: ruby-2.0.0.648-34.el7_5.ppc64.rpm ruby-debuginfo-2.0.0.648-34.el7_5.ppc.rpm ruby-debuginfo-2.0.0.648-34.el7_5.ppc64.rpm ruby-libs-2.0.0.648-34.el7_5.ppc.rpm ruby-libs-2.0.0.648-34.el7_5.ppc64.rpm rubygem-bigdecimal-1.2.0-34.el7_5.ppc64.rpm rubygem-io-console-0.4.2-34.el7_5.ppc64.rpm rubygem-json-1.7.7-34.el7_5.ppc64.rpm rubygem-psych-2.0.0-34.el7_5.ppc64.rpm ppc64le: ruby-2.0.0.648-34.el7_5.ppc64le.rpm ruby-debuginfo-2.0.0.648-34.el7_5.ppc64le.rpm ruby-libs-2.0.0.648-34.el7_5.ppc64le.rpm rubygem-bigdecimal-1.2.0-34.el7_5.ppc64le.rpm rubygem-io-console-0.4.2-34.el7_5.ppc64le.rpm rubygem-json-1.7.7-34.el7_5.ppc64le.rpm rubygem-psych-2.0.0-34.el7_5.ppc64le.rpm s390x: ruby-2.0.0.648-34.el7_5.s390x.rpm ruby-debuginfo-2.0.0.648-34.el7_5.s390.rpm ruby-debuginfo-2.0.0.648-34.el7_5.s390x.rpm ruby-libs-2.0.0.648-34.el7_5.s390.rpm ruby-libs-2.0.0.648-34.el7_5.s390x.rpm rubygem-bigdecimal-1.2.0-34.el7_5.s390x.rpm rubygem-io-console-0.4.2-34.el7_5.s390x.rpm rubygem-json-1.7.7-34.el7_5.s390x.rpm rubygem-psych-2.0.0-34.el7_5.s390x.rpm x86_64: ruby-2.0.0.648-34.el7_5.x86_64.rpm ruby-debuginfo-2.0.0.648-34.el7_5.i686.rpm ruby-debuginfo-2.0.0.648-34.el7_5.x86_64.rpm ruby-libs-2.0.0.648-34.el7_5.i686.rpm ruby-libs-2.0.0.648-34.el7_5.x86_64.rpm rubygem-bigdecimal-1.2.0-34.el7_5.x86_64.rpm rubygem-io-console-0.4.2-34.el7_5.x86_64.rpm rubygem-json-1.7.7-34.el7_5.x86_64.rpm rubygem-psych-2.0.0-34.el7_5.x86_64.rpm Red Hat Enterprise Linux Server Optional EUS (v.7.5): noarch: ruby-doc-2.0.0.648-34.el7_5.noarch.rpm rubygem-minitest-4.3.2-34.el7_5.noarch.rpm rubygem-rake-0.9.6-34.el7_5.noarch.rpm rubygems-devel-2.0.14.1-34.el7_5.noarch.rpm ppc64: ruby-debuginfo-2.0.0.648-34.el7_5.ppc64.rpm ruby-devel-2.0.0.648-34.el7_5.ppc64.rpm ruby-tcltk-2.0.0.648-34.el7_5.ppc64.rpm ppc64le: ruby-debuginfo-2.0.0.648-34.el7_5.ppc64le.rpm ruby-devel-2.0.0.648-34.el7_5.ppc64le.rpm ruby-tcltk-2.0.0.648-34.el7_5.ppc64le.rpm s390x: ruby-debuginfo-2.0.0.648-34.el7_5.s390x.rpm ruby-devel-2.0.0.648-34.el7_5.s390x.rpm ruby-tcltk-2.0.0.648-34.el7_5.s390x.rpm x86_64: ruby-debuginfo-2.0.0.648-34.el7_5.x86_64.rpm ruby-devel-2.0.0.648-34.el7_5.x86_64.rpm ruby-tcltk-2.0.0.648-34.el7_5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-16395 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXWUPIdzjgjWX9erEAQgKbhAAgPvWE6UDfm5KbBdHHhzGDxlOM9TBfq6C lpaFh/r55fzRgq9wV/sfg/t6is5gxBHPakZWuPjuFyE+9iNKfsPXNk3DbMoBjI1A pLfIltnIBMaXzKkZDXKYSEkjuI5a1rb9j1HsclQEXMpQMEtK7/GglWj+ZZNPRSjM NDiwk6qrnVZ/9y793FjWmelhLJQpCsrF8UySsMxtxbq6V5gx4YWPV10Ek1jHGpDf DWA+ouLQcMuSR+v8xARpg9IQIwxytPxdGTydFZShuSRpszY1+6Qd0M/G9af1JOWe 1aOKwENdtaj/9rvJXNStQVKyN02TneIaXfo1zGBGac/7F8KejlMAaW9R27SeoR4g yHkTH2q16U+OWv+UFptxp+I6MhAfA7pvuAYs8fvb3jui1UWPExLONjHqbx0GNGxI MD5+srqeEjCtkUS8p5WrPJclp54UozzVX5+n6Vp6tX3TOp98qAQmVP+vtdBO7dwT QMzNjCD+kCclxp5oPqSoWaPyJr8AQ5VC5WbYDWdVrahvXexXX1xbjPgOuSa/EsYs tviNd2vi1ocw/2fWvb5xum+CczgcjziMbdIaBDi5P4sZTNUkbwC+kL/60zCHgoNA pdb0l1/Zxdf2MI6VEaQSQrBXftqLyIYNpg/k8RjIOmCEqA3Pmo/hDz5JSJpQMGvQ 8vR47qKSSDU=a0vT -----END PGP SIGNATURE----- -- RHSA-announce mailinglist
Get the latest Linux and open source security news straight to your inbox.