Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 9 articles for you...
89

Fedora 44 openbao Important DoS Fix Advisory 2026-84ff0044db

Update to upstream 2.5.5. Also fixes CVE-2026-55770, CVE-2026-55774, CVE-2026-55775, and CVE-2026-55776.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-84ff0044db 2026-06-27 01:10:00.374787+00:00 -------------------------------------------------------------------------------- Name : openbao Product : Fedora 44 Version : 2.5.5 Release : 1.fc44 URL : https://openbao.org Summary : A tool for securely accessing secrets Description : Openbao secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets in modern computing. Openbao handles leasing, key revocation, key rolling, and auditing. Through a unified API, users can access an encrypted Key/Value store and network encryption-as-a-service, or generate AWS IAM/STS credentials, SQL/NoSQL databases, X.509 certificates, SSH credentials, and more. -------------------------------------------------------------------------------- Update Information: Update to upstream 2.5.5. Also fixes CVE-2026-55770, CVE-2026-55774, CVE-2026-55775, and CVE-2026-55776. -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 17 2026 Dave Dykstra - 2.5.5-1 - update to upstream 2.5.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2489817 - openbao-2.5.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2489817 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-84ff0044db' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the FedoraProject can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fedora 44 critical update for Openbao fixes multiple issues and enhances security features. Install updates for optimal protection.. Fedora Update, Openbao Upgrade, Security Issues, Key Management, API Key Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 26, 2026 Important Fedora
89

Fedora 44 Openbao Significant CVE Resolutions 2026-bf7889aec6

Update to upstream-2.5.4, including fixes for CVE-2026-46358, CVE-2026-46405, and CVE-2026-45808. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-bf7889aec6 2026-05-29 01:10:57.991167+00:00 -------------------------------------------------------------------------------- Name : openbao Product : Fedora 44 Version : 2.5.4 Release : 1.fc44 URL : https://openbao.org Summary : A tool for securely accessing secrets Description : Openbao secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets in modern computing. Openbao handles leasing, key revocation, key rolling, and auditing. Through a unified API, users can access an encrypted Key/Value store and network encryption-as-a-service, or generate AWS IAM/STS credentials, SQL/NoSQL databases, X.509 certificates, SSH credentials, and more. -------------------------------------------------------------------------------- Update Information: Update to upstream-2.5.4, including fixes for CVE-2026-46358, CVE-2026-46405, and CVE-2026-45808 -------------------------------------------------------------------------------- ChangeLog: * Wed May 20 2026 Dave Dykstra - 2.5.4-1 - update to upstream 2.5.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2480200 - openbao-2.5.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2480200 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bf7889aec6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can befound at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Upgrade for openbao in Fedora 44 addresses critical CVEs for better secret management and secure access.. Fedora openbao CVE update security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 29, 2026 Important Fedora
89

Fedora 44 Openbao Critical Sec Fix DoS Token Management 2026-c7450bfed6

Update to upstream 2.5.3, fix CVE-2026-34986, CVE-2026-39388, CVE-2026-39396, CVE-2026-40264. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-c7450bfed6 2026-05-01 03:11:02.715680+00:00 -------------------------------------------------------------------------------- Name : openbao Product : Fedora 44 Version : 2.5.3 Release : 1.fc44 URL : https://openbao.org Summary : A tool for securely accessing secrets Description : Openbao secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets in modern computing. Openbao handles leasing, key revocation, key rolling, and auditing. Through a unified API, users can access an encrypted Key/Value store and network encryption-as-a-service, or generate AWS IAM/STS credentials, SQL/NoSQL databases, X.509 certificates, SSH credentials, and more. -------------------------------------------------------------------------------- Update Information: Update to upstream 2.5.3, fix CVE-2026-34986, CVE-2026-39388, CVE-2026-39396, CVE-2026-40264 -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 21 2026 Dave Dykstra - 2.5.3-1 - update to upstream 2.5.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455630 - CVE-2026-34986 openbao: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455630 [ 2 ] Bug #2459846 - openbao-2.5.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2459846 [ 3 ] Bug #2460057 - CVE-2026-39388 openbao: OpenBao: Token renewal vulnerability via incorrect certificate matching in Certificate authentication. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460057 [ 4 ] Bug #2460059 - CVE-2026-39396 openbao: OpenBao: Denial of Service viadecompression bomb in OCI plugin extraction [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460059 [ 5 ] Bug #2460061 - CVE-2026-40264 openbao: OpenBao: Unauthorized token management by privileged administrator [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460061 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-c7450bfed6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Critical security updates for Openbao on Fedora 44 improving protection against multiple threats.. Fedora openbao security update DoS threat management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 01, 2026 Critical Fedora
89

Fedora 43 openbao Security Update 2026-41918b2b57 CVE Fixes DoS

Update to upstream 2.5.3, fix CVE-2026-34986, CVE-2026-39388, CVE-2026-39396, CVE-2026-40264. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-41918b2b57 2026-05-01 03:01:50.286480+00:00 -------------------------------------------------------------------------------- Name : openbao Product : Fedora 43 Version : 2.5.3 Release : 1.fc43 URL : https://openbao.org Summary : A tool for securely accessing secrets Description : Openbao secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets in modern computing. Openbao handles leasing, key revocation, key rolling, and auditing. Through a unified API, users can access an encrypted Key/Value store and network encryption-as-a-service, or generate AWS IAM/STS credentials, SQL/NoSQL databases, X.509 certificates, SSH credentials, and more. -------------------------------------------------------------------------------- Update Information: Update to upstream 2.5.3, fix CVE-2026-34986, CVE-2026-39388, CVE-2026-39396, CVE-2026-40264 -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 21 2026 Dave Dykstra - 2.5.3-1 - update to upstream 2.5.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455630 - CVE-2026-34986 openbao: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455630 [ 2 ] Bug #2459846 - openbao-2.5.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2459846 [ 3 ] Bug #2460057 - CVE-2026-39388 openbao: OpenBao: Token renewal vulnerability via incorrect certificate matching in Certificate authentication. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460057 [ 4 ] Bug #2460059 - CVE-2026-39396 openbao: OpenBao: Denial of Service viadecompression bomb in OCI plugin extraction [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460059 [ 5 ] Bug #2460061 - CVE-2026-40264 openbao: OpenBao: Unauthorized token management by privileged administrator [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460061 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-41918b2b57' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update openbao on Fedora 43 to fix critical issues including DoS and unauthorized token management vulnerabilities.. Fedora 43 openbao update, openbao security fix, DoS vulnerability patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 01, 2026 Critical Fedora
89

Fedora 42 openbao 2.5.3 Security Advisory FEDORA-2026-c008e6a5da

Update to upstream 2.5.3, fix CVE-2026-34986, CVE-2026-39388, CVE-2026-39396, CVE-2026-40264. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-c008e6a5da 2026-05-01 01:22:47.586665+00:00 -------------------------------------------------------------------------------- Name : openbao Product : Fedora 42 Version : 2.5.3 Release : 1.fc42 URL : https://openbao.org Summary : A tool for securely accessing secrets Description : Openbao secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets in modern computing. Openbao handles leasing, key revocation, key rolling, and auditing. Through a unified API, users can access an encrypted Key/Value store and network encryption-as-a-service, or generate AWS IAM/STS credentials, SQL/NoSQL databases, X.509 certificates, SSH credentials, and more. -------------------------------------------------------------------------------- Update Information: Update to upstream 2.5.3, fix CVE-2026-34986, CVE-2026-39388, CVE-2026-39396, CVE-2026-40264 -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 21 2026 Dave Dykstra - 2.5.3-1 - update to upstream 2.5.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455630 - CVE-2026-34986 openbao: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455630 [ 2 ] Bug #2459846 - openbao-2.5.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2459846 [ 3 ] Bug #2460057 - CVE-2026-39388 openbao: OpenBao: Token renewal vulnerability via incorrect certificate matching in Certificate authentication. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460057 [ 4 ] Bug #2460059 - CVE-2026-39396 openbao: OpenBao: Denial of Service viadecompression bomb in OCI plugin extraction [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460059 [ 5 ] Bug #2460061 - CVE-2026-40264 openbao: OpenBao: Unauthorized token management by privileged administrator [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460061 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-c008e6a5da' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update to openbao 2.5.3 resolves multiple critical issues including DoS and unauthorized token management risks.. openbao update, Fedora security, Denial of Service, token management, software patching. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 01, 2026 Important Fedora
89

Fedora 44 Openbao Critical XSS Fixes for CVE-2026-33757 CVE-2026-33758

Update to upstream 2.5.2, including fixes for CVE-2026-33757 and CVE-2026-33758. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-bb074cb239 2026-04-25 01:21:36.170948+00:00 -------------------------------------------------------------------------------- Name : openbao Product : Fedora 44 Version : 2.5.2 Release : 1.fc44 URL : https://openbao.org Summary : A tool for securely accessing secrets Description : Openbao secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets in modern computing. Openbao handles leasing, key revocation, key rolling, and auditing. Through a unified API, users can access an encrypted Key/Value store and network encryption-as-a-service, or generate AWS IAM/STS credentials, SQL/NoSQL databases, X.509 certificates, SSH credentials, and more. -------------------------------------------------------------------------------- Update Information: Update to upstream 2.5.2, including fixes for CVE-2026-33757 and CVE-2026-33758 -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 25 2026 Dave Dykstra - 2.5.2-1 - update to upstream 2.5.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452352 - CVE-2026-33757 openbao: lack of user confirmation for OpenBao OIDC direct callback mode [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452352 [ 2 ] Bug #2452355 - CVE-2026-33758 openbao: reflected XSS in OpenBao OIDC authentication error message [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452355 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bb074cb239' at the command line. For more information, refer to the dnfdocumentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update on Fedora 44 Openbao version 2.5.2 fixes critical security issues including XSS vulnerabilities and more.. Fedora Update, Openbao, Security Fix, API Key Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 25, 2026 Critical Fedora
89

Fedora 43 Openbao Critical XSS Weaknesses Fix 2026-a9c2a486a6

Update to upstream 2.5.2, including fixes for CVE-2026-33757 and CVE-2026-33758. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a9c2a486a6 2026-04-03 00:50:26.407477+00:00 -------------------------------------------------------------------------------- Name : openbao Product : Fedora 43 Version : 2.5.2 Release : 1.fc43 URL : https://openbao.org Summary : A tool for securely accessing secrets Description : Openbao secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets in modern computing. Openbao handles leasing, key revocation, key rolling, and auditing. Through a unified API, users can access an encrypted Key/Value store and network encryption-as-a-service, or generate AWS IAM/STS credentials, SQL/NoSQL databases, X.509 certificates, SSH credentials, and more. -------------------------------------------------------------------------------- Update Information: Update to upstream 2.5.2, including fixes for CVE-2026-33757 and CVE-2026-33758 -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 25 2026 Dave Dykstra - 2.5.2-1 - update to upstream 2.5.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452352 - CVE-2026-33757 openbao: lack of user confirmation for OpenBao OIDC direct callback mode [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452352 [ 2 ] Bug #2452355 - CVE-2026-33758 openbao: reflected XSS in OpenBao OIDC authentication error message [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452355 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a9c2a486a6' at the command line. For more information, refer to the dnfdocumentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fedora 43 Openbao update addresses Critical XSS and authentication issues for secure secret access.. Openbao update, Fedora security advisory, Openbao vulnerabilities, security fix, Openbao authentication. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 03, 2026 Critical Fedora
202

openSUSE Tumbleweed openbao Moderate Security Issues 2026-10438-1

An update that solves 2 vulnerabilities can now be installed.. # openbao-2.5.2-1.1 on GA media Announcement ID: openSUSE-SU-2026:10438-1 Rating: moderate Cross-References: * CVE-2026-33757 * CVE-2026-33758 Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the openbao-2.5.2-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * openbao 2.5.2-1.1 * openbao-agent 2.5.2-1.1 * openbao-cassandra-database-plugin 2.5.2-1.1 * openbao-influxdb-database-plugin 2.5.2-1.1 * openbao-mysql-database-plugin 2.5.2-1.1 * openbao-mysql-legacy-database-plugin 2.5.2-1.1 * openbao-postgresql-database-plugin 2.5.2-1.1 * openbao-server 2.5.2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33757.html * https://www.suse.com/security/cve/CVE-2026-33758.html . OpenSUSE updates address moderate security issues in openbao 2.5.2-1.1. Critical patch availability with details inside.. openSUSE,Tumbleweed,openbao,security advisory,patch release. . LinuxSecurity.com Team

Calendar%202 Mar 30, 2026 OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200