Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
202

openSUSE 2026 Critical osslsigncode Memory Corruption DoS 2026-0115-1

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for osslsigncode ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0115-1 Rating: critical References: #1260680 Cross-References: CVE-2025-70888 Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for osslsigncode fixes the following issues: - Update to 2.13 (boo#1260680, CVE-2025-70888): * fixed integer overflows when processing APPX compressed data streams * fixed double-free vulnerabilities in APPX file processing * fixed multiple memory corruption issues in PE page hash computation - Changes from 2.12: * fixed a buffer overflow while extracting message digests - Changes from 2.11: * added keyUsage validation for signer certificate * added printing CRL details during signature verification * implemented a workaround for CRL servers returning the HTTP Content-Type header other than application/pkix-crl * fixed HTTP keep-alive handling * fixed macOS compiler and linker flags * fixed undefined BIO_get_fp() behavior with BIO_FLAGS_UPLINK_INTERNAL - update to 2.10: * added JavaScript signing * added PKCS#11 provider support (requires OpenSSL 3.0+) * added support for providers without specifying "-pkcs11module" option * (OpenSSL 3.0+, e.g., for the upcoming CNG provider) * added compatibility with the CNG engine version 1.1 or later * added the "-engineCtrl" option to control hardware and CNG engines * added the '-blobFile' option to specify a file containing the blob content * improved unauthenticated blob support (thanks to Asger Hautop Drewsen) * improved UTF-8 handling for certificate subjects and issuers *fixed support for multiple signerInfo contentType OIDs (CTL and Authenticode) * fixed tests for python-cryptography > = 43.0.0 - update to version 2.9: * added a 64 bit long pseudo-random NONCE in the TSA request * missing NID_pkcs9_signingTime is no longer an error * added support for PEM-encoded CRLs * fixed the APPX central directory sorting order * added a special "-" file name to read the passphrase from stdin * used native HTTP client with OpenSSL 3.x, removing libcurl dependency * added '-login' option to force a login to PKCS11 engines * added the "-ignore-crl" option to disable fetching and verifying CRL Distribution Points * changed error output to stderr instead of stdout * various testing framework improvements * various memory corruption fixes - update to version 2.8: * Microsoft PowerShell signing sponsored by Cisco Systems, Inc. * fixed setting unauthenticated attributes (Countersignature, Unauthenticated * Data Blob) in a nested signature * added the "-index" option to verify a specific signature or modify its unauthenticated attributes * added CAT file verification * added listing the contents of a CAT file with the "-verbose" option * added the new "extract-data" command to extract a PKCS#7 data content to be signed with "sign" and attached with "attach-signature" * added PKCS9_SEQUENCE_NUMBER authenticated attribute support * added the "-ignore-cdp" option to disable CRL Distribution Points (CDP) online verification * unsuccessful CRL retrieval and verification changed into a critical error the "-p" option modified to also use to configured proxy to connect CRL Distribution Points * added implicit allowlisting of the Microsoft Root Authority serial number 00C1008B3C3C8811D13EF663ECDF40 * added listing of certificate chain retrieved from the signature in case of verification failure -update to 2.7.0 * fixed signing CAB files (by Michael Brown) * fixed handling of unsupported commands (by Maxim Bagryantsev) * fixed writing DIFAT sectors * added APPX support (by Maciej Panek and Ma\u0142gorzata Olszwka) * added a built-in TSA response generation (-TSA-certs, -TSA-key and -TSA-time options) * added verification of CRLs specified in the signing certificate * added MSI DIFAT sectors support (by Max Bagryantsev) * added the "-h" option to set the cryptographic hash function for the "attach -signature" and "add" commands * set the default hash function to "sha256" * added the "attach-signature" option to compute and compare the leaf certificate hash for the "add" command * renamed the "-st" option "-time" * updated the "-time" option to also set explicit verification time * added the "-ignore-timestamp" option * removed the "-timestamp-expiration" option * numerous bugfixes * documentation updates Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2026-115=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64): osslsigncode-2.13-bp156.2.3.1 References: https://www.suse.com/security/cve/CVE-2025-70888.html https://bugzilla.suse.com/1260680 . Critical security update for openSUSE's osslsigncode fixes multiple memory issues and buffer overflow risks effectively.. openSUSE osslsigncode critical security update memory overflow. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 03, 2026 Critical OpenSUSE
202

openSUSE Tumbleweed osslsigncode Moderate Update CVE-2025-70888

An update that solves one vulnerability can now be installed.. # osslsigncode-2.13-1.1 on GA media Announcement ID: openSUSE-SU-2026:10482-1 Rating: moderate Cross-References: * CVE-2025-70888 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the osslsigncode-2.13-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * osslsigncode 2.13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-70888.html . Update for openSUSE Tumbleweed addresses moderate issues in osslsigncode. Install to secure your system.. openSUSE Tumbleweed osslsigncode security update. . LinuxSecurity.com Team

Calendar 2 Apr 03, 2026 OpenSUSE
89

Fedora 42 OSSLSIGNCODE Update 2026-ab67a4d8b3 for Version 2.12

See commit history. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-ab67a4d8b3 2026-02-12 01:09:28.578783+00:00 -------------------------------------------------------------------------------- Name : osslsigncode Product : Fedora 42 Version : 2.12 Release : 1.fc42 URL : https://github.com/mtrojnar/osslsigncode Summary : OpenSSL-based Authenticode signing for PE, CAB, CAT, MSI, APPX Description : osslsigncode is a small tool that implements part of the functionality of the Microsoft tool signtool.exe - more exactly the Authenticode signing and timestamping. But osslsigncode is based on OpenSSL and cURL, and thus should be able to compile on most platforms where these exist. -------------------------------------------------------------------------------- Update Information: See commit history -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 2 2026 Packit - 2.12-1 - Update to 2.12 upstream release - Resolves: rhbz#2436077 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2436077 - osslsigncode-2.12 is available https://bugzilla.redhat.com/show_bug.cgi?id=2436077 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ab67a4d8b3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Explore the latest Fedora 42 update for osslsigncode, version 2.12, enhancing Authenticode signing features.. Fedora Update, osslsigncode, OpenSSL Authenticode, security advisory. . LinuxSecurity.com Team

Calendar 2 Feb 12, 2026 Fedora
89

Debian 12 OpenSSL 3.0.3 Security Update for 2026-5b7da93a41 Released

See commit history. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3c6cc85b52 2026-02-12 00:51:45.032320+00:00 -------------------------------------------------------------------------------- Name : osslsigncode Product : Fedora 43 Version : 2.12 Release : 1.fc43 URL : https://github.com/mtrojnar/osslsigncode Summary : OpenSSL-based Authenticode signing for PE, CAB, CAT, MSI, APPX Description : osslsigncode is a small tool that implements part of the functionality of the Microsoft tool signtool.exe - more exactly the Authenticode signing and timestamping. But osslsigncode is based on OpenSSL and cURL, and thus should be able to compile on most platforms where these exist. -------------------------------------------------------------------------------- Update Information: See commit history -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 2 2026 Packit - 2.12-1 - Update to 2.12 upstream release - Resolves: rhbz#2436077 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2436077 - osslsigncode-2.12 is available https://bugzilla.redhat.com/show_bug.cgi?id=2436077 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3c6cc85b52' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Keep your Fedora 43 system secure with the osslsigncode 2.12 update and apply important changes.. Fedora 43 Update, osslsigncode Tool, OpenSSL Authenticode Signing, System Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 12, 2026 Important Fedora
197

Debian 11 osslsigncode Important Update CVE-2023-36377 DLA-4426-2

. Debian LTS Advisory DLA-4426-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Abhijith PA January 23, 2026 https://wiki.debian.org/LTS Package : osslsigncode Version : 2.5-4~deb11u1+really2.9-1+deb11u2 Debian Bug : 1076785 Fix for vulnerability CVE-2023-36377 was released in DLA 4426-1 by upgrading to version 2.5-4, which had a known bug #1076785. This issue is fixed by updating to version 2.9. https://bugs.debian.org/1076785 For Debian 11 bullseye, this problem has been fixed in version 2.5-4~deb11u1+really2.9-1+deb11u2. We recommend that you upgrade your osslsigncode packages. For the detailed security status of osslsigncode please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/osslsigncode Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Important Debian LTS advisory DLA-4426-2 provides an update to osslsigncode addressing CVE-2023-36377 security issue.. Debian LTS, osslsigncode, DLA-4426-2, CVE-2023-36377, security update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 23, 2026 Important Debian LTS
197

Debian 11: Serious Buffer Overflow Flaw Detected in osslsigncode DLA-4426-1

A Buffer Overflow vulnerability has been found in osslsigncode, a OpenSSL based Authenticode signing tool for PE/MSI/Java CAB files, which possibly allows an malicious attacker to execute arbitrary code when signing a crafted file. For Debian 11 bullseye, this problem has been fixed in version. Debian LTS Advisory DLA-4426-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Abhijith PA December 30, 2025 https://wiki.debian.org/LTS Package : osslsigncode Version : 2.5-4~deb11u1 CVE ID : CVE-2023-36377 Debian Bug : 1035875 A Buffer Overflow vulnerability has been found in osslsigncode, a OpenSSL based Authenticode signing tool for PE/MSI/Java CAB files, which possibly allows an malicious attacker to execute arbitrary code when signing a crafted file. For Debian 11 bullseye, this problem has been fixed in version 2.5-4~deb11u1. We recommend that you upgrade your osslsigncode packages. For the detailed security status of osslsigncode please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/osslsigncode Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Fix for Buffer Overflow in osslsigncode on Debian 11; critical update against code execution threats.. Debian 11, osslsigncode, buffer overflow, security update, malicious code. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 30, 2025 Important Debian LTS
197

Debian 10: DLA-3693-1 critical: osslsigncode buffer overflow

A Buffer Overflow vulnerability has been found in osslsigncode, a OpenSSL based Authenticode signing tool for PE/MSI/Java CAB files, which possibly allows an malicious attacker to execute arbitrary code when signing a crafted file. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3693-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Tobias Frost December 23, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : osslsigncode Version : 2.0+really2.5-4+deb10u1 CVE ID : CVE-2023-36377 Debian Bug : 1035875 A Buffer Overflow vulnerability has been found in osslsigncode, a OpenSSL based Authenticode signing tool for PE/MSI/Java CAB files, which possibly allows an malicious attacker to execute arbitrary code when signing a crafted file. For Debian 10 buster, this problem has been fixed in version 2.0+really2.5-4+deb10u1. We recommend that you upgrade your osslsigncode packages. For the detailed security status of osslsigncode please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/osslsigncode Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3693-1 reveals a critical buffer overflow risk in osslsigncode allowing remote code execution.. Debian Security Update, Buffer Overflow, Osslsigncode Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 23, 2023 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here