Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 30 articles for you...
217

Oracle Linux 10 OpenCryptoki Moderate Access Fix ELSA-2026-28231

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-28231 http://linux.oracle.com/errata/ELSA-2026-28231.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: opencryptoki-3.26.0-3.el10_2.1.x86_64.rpm opencryptoki-ccatok-3.26.0-3.el10_2.1.x86_64.rpm opencryptoki-devel-3.26.0-3.el10_2.1.x86_64.rpm opencryptoki-icsftok-3.26.0-3.el10_2.1.x86_64.rpm opencryptoki-libs-3.26.0-3.el10_2.1.x86_64.rpm opencryptoki-swtok-3.26.0-3.el10_2.1.x86_64.rpm aarch64: opencryptoki-3.26.0-3.el10_2.1.aarch64.rpm opencryptoki-devel-3.26.0-3.el10_2.1.aarch64.rpm opencryptoki-icsftok-3.26.0-3.el10_2.1.aarch64.rpm opencryptoki-libs-3.26.0-3.el10_2.1.aarch64.rpm opencryptoki-swtok-3.26.0-3.el10_2.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/opencryptoki-3.26.0-3.el10_2.1.src.rpm Related CVEs: CVE-2026-40253 Description of changes: [3.26.0-3.1] - Resolves: RHEL-171556, Fix possible out-of-bounds access in BER decode functions [3.26.0-3] - Resolves: RHEL-169565, Fix syslog message printing about different CPs _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Updated OpenCryptoki packages address moderate risk and system access issues in Oracle Linux 10. Learn more about the advisory.. Oracle Linux, OpenCryptoki, security update, advisory, system access. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 17, 2026 moderate Oracle
100

SUSE openCryptoki Moderate Info Discl Denial of Service Vuln 2026-2757-1

An update that solves one vulnerability can now be installed.. # Security update for openCryptoki Announcement ID: SUSE-SU-2026:2757-1 Release Date: 2026-07-03T19:29:23Z Rating: moderate References: * bsc#1262283 Cross-References: * CVE-2026-40253 CVSS scores: * CVE-2026-40253 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40253 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H Affected Products: * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for openCryptoki fixes the following issue: * CVE-2026-40253: malformed BER-encoded cryptographic objects can lead to information disclosure and denial of service (bsc#1262283). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2757=1 ## Package List: * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * openCryptoki-64bit-debuginfo-3.26.0-150700.5.17.1 * openCryptoki-64bit-3.26.0-150700.5.17.1 * openCryptoki-devel-3.26.0-150700.5.17.1 * openCryptoki-debugsource-3.26.0-150700.5.17.1 * openCryptoki-debuginfo-3.26.0-150700.5.17.1 * openCryptoki-3.26.0-150700.5.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40253.html * https://bugzilla.suse.com/show_bug.cgi?id=1262283 . This update for openCryptoki addresses a moderate security risk with information disclosure anddenial of service weaknesses.. openCryptoki security, SUSE updates, information disclosure, denial of service, patch installation. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 06, 2026 moderate SuSE
100

SUSE openCryptoki Significant Security Update for Multiple CVEs Identified

An update that solves three vulnerabilities and contains one feature can now be installed.. # Security update for openCryptoki Announcement ID: SUSE-SU-2026:22365-1 Release Date: 2026-06-25T11:51:43Z Rating: important References: * bsc#1268745 * jsc#PED-14609 Cross-References: * CVE-2026-22791 * CVE-2026-23893 * CVE-2026-40253 CVSS scores: * CVE-2026-22791 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-22791 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-22791 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-22791 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-23893 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L * CVE-2026-23893 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L * CVE-2026-40253 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40253 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities and contains one feature can now be installed. ## Description: This update for openCryptoki fixes the following issues Upgrade openCryptoki to version 3.27 (jsc#PED-14609): * Add base support for PKCS#11 v3.2. * Add support for PKCS#11 v3.2 C_VerifySignature[Init|Update|Final]. * Add support for PKCS#11 v3.2 C_EncapsulateKey/C_DecapsulateKey. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with RSA- PKCS and RSA-OAEP mechanisms. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with the ECDH mechanism. * Soft/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with the DH-PKCS mechanism. * Soft: Addsupport for PKCS#11 v3.2 ML-DSA and ML-KEM key types and mechanisms (requires OpenSSL 3.5 or later, or the OQS-provider must be configured). * CCA: Add support for PKCS#11 v3.2 ML-DSA key type and mechanisms (requires CCA v8.4 or later) * EP11: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types and mechanisms (requires an EP11 host library v4.2 or later, and a CEX8P crypto card with firmware v9.6 or later on IBM z17, and v8.39 or later on IBM z16). * p11sak: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types. * Soft/ICA: Add support for PKCS#11 v3.2 mechanisms CKM_ECDH_X_AES_KEY_WRAP and CKM_ECDH_COF_AES_KEY_WRAP. * p11sak: Add support for key wrapping with PKCS#11 v3.2 mechanisms CKM_ECDH_X_AES_KEY_WRAP and CKM_ECDH_COF_AES_KEY_WRAP. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 mechanism CKM_PUB_KEY_FROM_PRIV_KEY. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.0 Edwards and Montgomery key types and mechanisms. * Soft/ICA: Support CKM_ECDH_AES_KEY_WRAP also for Montgomery keys. * p11sak: Add support for PKCS#11 v3.0 Edwards and Montgomery key types. * Soft: Add support for CKM_ECDH1_COFACTOR_DERIVE. * CCA: Add support for additional RSA public exponent values 5, 17, or 257. * p11sak: Add option to list-key command to show EP11 session IDs. * Make the maximum number of token objects supported configurable. * Fixes for CVE-2026-40253, CVE-2026-23893, and CVE-2026-22791. * Bug fixes. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1080=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1080=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * openCryptoki-devel-3.27.0-160000.1.1 *openCryptoki-64bit-debuginfo-3.27.0-160000.1.1 * openCryptoki-debuginfo-3.27.0-160000.1.1 * openCryptoki-3.27.0-160000.1.1 * openCryptoki-debugsource-3.27.0-160000.1.1 * openCryptoki-64bit-3.27.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * openCryptoki-devel-3.27.0-160000.1.1 * openCryptoki-64bit-debuginfo-3.27.0-160000.1.1 * openCryptoki-debuginfo-3.27.0-160000.1.1 * openCryptoki-3.27.0-160000.1.1 * openCryptoki-debugsource-3.27.0-160000.1.1 * openCryptoki-64bit-3.27.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22791.html * https://www.suse.com/security/cve/CVE-2026-23893.html * https://www.suse.com/security/cve/CVE-2026-40253.html * https://bugzilla.suse.com/show_bug.cgi?id=1268745 * https://jira.suse.com/browse/PED-14609 . Critical security update for openCryptoki addresses three vulnerabilities and introduces new features for SUSE. Act now!. SUSE security update, openCryptoki vulnerabilities, Linux security patch, important advisory, SUSE vulnerability fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 01, 2026 Important SuSE
202

openSUSE 16.0 openCryptoki Important Security Fixes 2026-21059-1

An update that solves 3 vulnerabilities and has one bug fix can now be installed.. openSUSE security update: security update for opencryptoki ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21059-1 Rating: important References: * bsc#1268745 Cross-References: * CVE-2026-22791 * CVE-2026-23893 * CVE-2026-40253 CVSS scores: * CVE-2026-22791 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-22791 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23893 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L * CVE-2026-40253 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( SUSE ): 7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has one bug fix can now be installed. Description: This update for openCryptoki fixes the following issues Upgrade openCryptoki to version 3.27 (jsc#PED-14609): * Add base support for PKCS#11 v3.2. * Add support for PKCS#11 v3.2 C_VerifySignature[Init|Update|Final]. * Add support for PKCS#11 v3.2 C_EncapsulateKey/C_DecapsulateKey. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with RSA-PKCS and RSA-OAEP mechanisms. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with the ECDH mechanism. * Soft/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with the DH-PKCS mechanism. * Soft: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types and mechanisms (requires OpenSSL 3.5 or later, or the OQS-provider must be configured). * CCA: Add support for PKCS#11 v3.2 ML-DSA key type and mechanisms (requires CCA v8.4 or later) * EP11: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types and mechanisms (requires an EP11 host library v4.2 or later, and a CEX8P crypto card with firmware v9.6 or later on IBM z17, andv8.39 or later on IBM z16). * p11sak: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types. * Soft/ICA: Add support for PKCS#11 v3.2 mechanisms CKM_ECDH_X_AES_KEY_WRAP and CKM_ECDH_COF_AES_KEY_WRAP. * p11sak: Add support for key wrapping with PKCS#11 v3.2 mechanisms CKM_ECDH_X_AES_KEY_WRAP and CKM_ECDH_COF_AES_KEY_WRAP. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 mechanism CKM_PUB_KEY_FROM_PRIV_KEY. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.0 Edwards and Montgomery key types and mechanisms. * Soft/ICA: Support CKM_ECDH_AES_KEY_WRAP also for Montgomery keys. * p11sak: Add support for PKCS#11 v3.0 Edwards and Montgomery key types. * Soft: Add support for CKM_ECDH1_COFACTOR_DERIVE. * CCA: Add support for additional RSA public exponent values 5, 17, or 257. * p11sak: Add option to list-key command to show EP11 session IDs. * Make the maximum number of token objects supported configurable. * Fixes for CVE-2026-40253, CVE-2026-23893, and CVE-2026-22791. * Bug fixes. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1080=1 Package List: - openSUSE Leap 16.0: openCryptoki-3.27.0-160000.1.1 openCryptoki-64bit-3.27.0-160000.1.1 openCryptoki-devel-3.27.0-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-22791.html * https://www.suse.com/security/cve/CVE-2026-23893.html * https://www.suse.com/security/cve/CVE-2026-40253.html . This update for openSUSE addresses three vulnerabilities in openCryptoki and includes a crucial bug fix.. openSUSE update, openCryptoki vulnerabilities, important security patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 Important OpenSUSE
100

SUSE 2026-2685-1 openCryptoki Moderate Information Disclosure DoS

An update that solves one vulnerability can now be installed.. # Security update for openCryptoki Announcement ID: SUSE-SU-2026:2685-1 Release Date: 2026-06-29T15:19:10Z Rating: moderate References: * bsc#1262283 Cross-References: * CVE-2026-40253 CVSS scores: * CVE-2026-40253 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40253 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for openCryptoki fixes the following issue: * CVE-2026-40253: malformed BER-encoded cryptographic objects can lead to information disclosure and denial of service (bsc#1262283). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2685=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * openCryptoki-debuginfo-3.17.0-5.24.1 * openCryptoki-devel-3.17.0-5.24.1 * openCryptoki-64bit-3.17.0-5.24.1 * openCryptoki-3.17.0-5.24.1 * openCryptoki-debugsource-3.17.0-5.24.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40253.html * https://bugzilla.suse.com/show_bug.cgi?id=1262283 . This update resolves a moderate security issue in openCryptoki affecting SUSE Linux systems.. openCryptoki security update, SUSE patch, information disclosure issue. .Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 29, 2026 moderate SuSE
100

SUSE openCryptoki Important Fix Multiple Issues Vuln 2026-22293-1

An update that solves three vulnerabilities and contains one feature can now be installed.. # Security update for openCryptoki Announcement ID: SUSE-SU-2026:22293-1 Release Date: 2026-06-25T11:53:53Z Rating: important References: * bsc#1268745 * jsc#PED-14609 Cross-References: * CVE-2026-22791 * CVE-2026-23893 * CVE-2026-40253 CVSS scores: * CVE-2026-22791 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-22791 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-22791 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-22791 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-23893 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L * CVE-2026-23893 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L * CVE-2026-40253 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40253 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities and contains one feature can now be installed. ## Description: This update for openCryptoki fixes the following issues Upgrade openCryptoki to version 3.27 (jsc#PED-14609): * Add base support for PKCS#11 v3.2. * Add support for PKCS#11 v3.2 C_VerifySignature[Init|Update|Final]. * Add support for PKCS#11 v3.2 C_EncapsulateKey/C_DecapsulateKey. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with RSA- PKCS and RSA-OAEP mechanisms. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with the ECDH mechanism. * Soft/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with the DH-PKCS mechanism. * Soft: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types and mechanisms(requires OpenSSL 3.5 or later, or the OQS-provider must be configured). * CCA: Add support for PKCS#11 v3.2 ML-DSA key type and mechanisms (requires CCA v8.4 or later) * EP11: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types and mechanisms (requires an EP11 host library v4.2 or later, and a CEX8P crypto card with firmware v9.6 or later on IBM z17, and v8.39 or later on IBM z16). * p11sak: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types. * Soft/ICA: Add support for PKCS#11 v3.2 mechanisms CKM_ECDH_X_AES_KEY_WRAP and CKM_ECDH_COF_AES_KEY_WRAP. * p11sak: Add support for key wrapping with PKCS#11 v3.2 mechanisms CKM_ECDH_X_AES_KEY_WRAP and CKM_ECDH_COF_AES_KEY_WRAP. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 mechanism CKM_PUB_KEY_FROM_PRIV_KEY. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.0 Edwards and Montgomery key types and mechanisms. * Soft/ICA: Support CKM_ECDH_AES_KEY_WRAP also for Montgomery keys. * p11sak: Add support for PKCS#11 v3.0 Edwards and Montgomery key types. * Soft: Add support for CKM_ECDH1_COFACTOR_DERIVE. * CCA: Add support for additional RSA public exponent values 5, 17, or 257. * p11sak: Add option to list-key command to show EP11 session IDs. * Make the maximum number of token objects supported configurable. * Fixes for CVE-2026-40253, CVE-2026-23893, and CVE-2026-22791. * Bug fixes. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1080=1 ## Package List: * SUSE Linux Micro 6.2 (s390x) * openCryptoki-3.27.0-160000.1.1 * openCryptoki-debuginfo-3.27.0-160000.1.1 * openCryptoki-debugsource-3.27.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22791.html * https://www.suse.com/security/cve/CVE-2026-23893.html *https://www.suse.com/security/cve/CVE-2026-40253.html * https://bugzilla.suse.com/show_bug.cgi?id=1268745 * https://jira.suse.com/browse/PED-14609 . A critical security update for SUSE's openCryptoki fixes multiple issues and introduces new features.. SUSE Linux, openCryptoki update, important security patch, 2026 vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 29, 2026 Important SuSE
217

Oracle Linux 9 Opencryptoki Moderate Out-of-Bounds Fix ELSA-2026-28256

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-28256 http://linux.oracle.com/errata/ELSA-2026-28256.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: opencryptoki-3.26.0-2.el9_8.2.x86_64.rpm opencryptoki-ccatok-3.26.0-2.el9_8.2.x86_64.rpm opencryptoki-devel-3.26.0-2.el9_8.2.i686.rpm opencryptoki-devel-3.26.0-2.el9_8.2.x86_64.rpm opencryptoki-icsftok-3.26.0-2.el9_8.2.x86_64.rpm opencryptoki-libs-3.26.0-2.el9_8.2.i686.rpm opencryptoki-libs-3.26.0-2.el9_8.2.x86_64.rpm opencryptoki-swtok-3.26.0-2.el9_8.2.x86_64.rpm aarch64: opencryptoki-3.26.0-2.el9_8.2.aarch64.rpm opencryptoki-devel-3.26.0-2.el9_8.2.aarch64.rpm opencryptoki-icsftok-3.26.0-2.el9_8.2.aarch64.rpm opencryptoki-libs-3.26.0-2.el9_8.2.aarch64.rpm opencryptoki-swtok-3.26.0-2.el9_8.2.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/opencryptoki-3.26.0-2.el9_8.2.src.rpm Related CVEs: CVE-2026-40253 Description of changes: [3.26.0-2.2] - Resolves: RHEL-171562, Fix CVE-2026-40253, possible out-of-bounds access in BER decode functions [3.26.0-2.1] - Resolves: RHEL-169586, Fix syslog message printing about different CPs _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Updated Oracle Linux 9 packages for opencryptoki fix out-of-bounds access. Get essential security details now!. Oracle Linux 9, opencryptoki update, out-of-bounds access fix, security advisory ELSA-2026-28256. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 26, 2026 moderate Oracle
219

Rocky Linux opencryptoki Moderate Denial of Service Issue RLSA-2026-28231

Moderate: opencryptoki security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:28231", "synopsis": "Moderate: opencryptoki security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for opencryptoki.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The opencryptoki packages contain version 2.11 of the PKCS#11 API, implemented for IBM Cryptocards, such as IBM 4764 and 4765 crypto cards. These packages includes support for the IBM 4758 Cryptographic CoProcessor (with the PKCS#11 firmware loaded), the IBM eServer Cryptographic Accelerator (FC 4960 on IBM eServer System p), the IBM Crypto Express2 (FC 0863 or FC 0870 on IBM System z), and the IBM CP Assist for Cryptographic Function (FC 3863 on IBM System z). The opencryptoki packages also bring a software token implementation that can be used without any cryptographic hardware. These packages contain the Slot Daemon (pkcsslotd) and general utilities.\n\nSecurity Fix(es):\n\n* openCryptoki: openCryptoki: Information disclosure and Denial of Service via malformed BER-encoded cryptographic objects (CVE-2026-40253)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2459076", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2459076", "description": ""}], "cves": [{"name": "CVE-2026-40253", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40253", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "cvss3BaseScore": "6.8", "cwe": "CWE-125"}], "references": [], "publishedAt": "2026-06-24T12:05:16.082804Z", "rpms": {"Rocky Linux 10": {"nvras":["opencryptoki-icatok-debuginfo-0:3.26.0-3.el10_2.1.s390x.rpm", "opencryptoki-swtok-debuginfo-0:3.26.0-3.el10_2.1.x86_64.rpm", "opencryptoki-libs-debuginfo-0:3.26.0-3.el10_2.1.x86_64.rpm", "opencryptoki-swtok-debuginfo-0:3.26.0-3.el10_2.1.ppc64le.rpm", "opencryptoki-icsftok-0:3.26.0-3.el10_2.1.aarch64.rpm", "opencryptoki-icatok-0:3.26.0-3.el10_2.1.s390x.rpm", "opencryptoki-swtok-0:3.26.0-3.el10_2.1.ppc64le.rpm", "opencryptoki-icsftok-0:3.26.0-3.el10_2.1.x86_64.rpm", "opencryptoki-swtok-0:3.26.0-3.el10_2.1.x86_64.rpm", "opencryptoki-icsftok-0:3.26.0-3.el10_2.1.s390x.rpm", "opencryptoki-devel-0:3.26.0-3.el10_2.1.s390x.rpm", "opencryptoki-debuginfo-0:3.26.0-3.el10_2.1.aarch64.rpm", "opencryptoki-libs-0:3.26.0-3.el10_2.1.s390x.rpm", "opencryptoki-ccatok-debuginfo-0:3.26.0-3.el10_2.1.s390x.rpm", "opencryptoki-debuginfo-0:3.26.0-3.el10_2.1.s390x.rpm", "opencryptoki-devel-0:3.26.0-3.el10_2.1.ppc64le.rpm", "opencryptoki-debugsource-0:3.26.0-3.el10_2.1.aarch64.rpm", "opencryptoki-debugsource-0:3.26.0-3.el10_2.1.x86_64.rpm", "opencryptoki-devel-0:3.26.0-3.el10_2.1.aarch64.rpm", "opencryptoki-icsftok-debuginfo-0:3.26.0-3.el10_2.1.aarch64.rpm", "opencryptoki-libs-0:3.26.0-3.el10_2.1.aarch64.rpm", "opencryptoki-ccatok-0:3.26.0-3.el10_2.1.x86_64.rpm", "opencryptoki-icsftok-debuginfo-0:3.26.0-3.el10_2.1.ppc64le.rpm", "opencryptoki-swtok-0:3.26.0-3.el10_2.1.s390x.rpm", "opencryptoki-ccatok-0:3.26.0-3.el10_2.1.s390x.rpm", "opencryptoki-devel-0:3.26.0-3.el10_2.1.x86_64.rpm", "opencryptoki-ep11tok-0:3.26.0-3.el10_2.1.s390x.rpm", "opencryptoki-ep11tok-debuginfo-0:3.26.0-3.el10_2.1.s390x.rpm", "opencryptoki-ccatok-debuginfo-0:3.26.0-3.el10_2.1.x86_64.rpm", "opencryptoki-ccatok-debuginfo-0:3.26.0-3.el10_2.1.ppc64le.rpm", "opencryptoki-swtok-0:3.26.0-3.el10_2.1.aarch64.rpm", "opencryptoki-0:3.26.0-3.el10_2.1.ppc64le.rpm", "opencryptoki-swtok-debuginfo-0:3.26.0-3.el10_2.1.s390x.rpm", "opencryptoki-libs-0:3.26.0-3.el10_2.1.ppc64le.rpm", "opencryptoki-libs-debuginfo-0:3.26.0-3.el10_2.1.ppc64le.rpm","opencryptoki-icsftok-debuginfo-0:3.26.0-3.el10_2.1.s390x.rpm", "opencryptoki-libs-debuginfo-0:3.26.0-3.el10_2.1.s390x.rpm", "opencryptoki-libs-0:3.26.0-3.el10_2.1.x86_64.rpm", "opencryptoki-icsftok-debuginfo-0:3.26.0-3.el10_2.1.x86_64.rpm", "opencryptoki-0:3.26.0-3.el10_2.1.s390x.rpm", "opencryptoki-debuginfo-0:3.26.0-3.el10_2.1.ppc64le.rpm", "opencryptoki-ccatok-0:3.26.0-3.el10_2.1.ppc64le.rpm", "opencryptoki-icsftok-0:3.26.0-3.el10_2.1.ppc64le.rpm", "opencryptoki-debuginfo-0:3.26.0-3.el10_2.1.x86_64.rpm", "opencryptoki-0:3.26.0-3.el10_2.1.x86_64.rpm", "opencryptoki-debugsource-0:3.26.0-3.el10_2.1.ppc64le.rpm", "opencryptoki-0:3.26.0-3.el10_2.1.aarch64.rpm", "opencryptoki-swtok-debuginfo-0:3.26.0-3.el10_2.1.aarch64.rpm", "opencryptoki-libs-debuginfo-0:3.26.0-3.el10_2.1.aarch64.rpm", "opencryptoki-debugsource-0:3.26.0-3.el10_2.1.s390x.rpm", "opencryptoki-0:3.26.0-3.el10_2.1.src.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Update available for opencryptoki on Rocky Linux to fix moderate security issues including denial of service risks.. Rocky Linux opencryptoki update moderate security. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 24, 2026 moderate Rocky Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200