Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 561
Alerts This Week
Warning Icon 1 561

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Are host-based firewalls still worth using?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/158-are-host-based-firewalls-still-worth-using?task=poll.vote&format=json
158
radio
0
[{"id":510,"title":"Yes \u2014 every server needs one.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":511,"title":"No \u2014 perimeter and cloud security are enough.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":512,"title":"Only Internet-facing systems really benefit.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":513,"title":"iptables.conf is my security policy.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 28 articles for you...
100

SUSE glib2 Important Out-Of-Bounds Access Vulnern 2026-22846-1

A security update for glib2 addresses six vulnerabilities impacting SUSE Linux Enterprise Server 16.0, allowing users to apply safeguards against possible out-of-bounds access and integer overflows.. # Security update for glib2 Announcement ID: SUSE-SU-2026:22846-1 Release Date: 2026-07-22T08:35:52Z Rating: important References: * bsc#1270008 * bsc#1270009 * bsc#1270010 * bsc#1270016 * bsc#1270018 * bsc#1270021 Cross-References: * CVE-2026-58010 * CVE-2026-58011 * CVE-2026-58012 * CVE-2026-58013 * CVE-2026-58014 * CVE-2026-58016 CVSS scores: * CVE-2026-58010 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58010 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58010 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58010 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58011 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-58011 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-58011 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58012 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58012 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58012 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58012 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58013 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58013 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-58013 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58014 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-58014 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-58014 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-58016 ( SUSE ): 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58016 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). * CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). * CVE-2026-58012: raw byte regex matches with UTF-8 functions during case- change replacements could cause an out-of- bounds read (bsc#1270016). * CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). * CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). * CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1320=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1320=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * typelib-1_0-GModule-2_0-2.84.4-160000.4.1 * glib2-tools-2.84.4-160000.4.1 * glib2-doc-2.84.4-160000.4.1 * libgio-2_0-0-2.84.4-160000.4.1 * glib2-devel-debuginfo-2.84.4-160000.4.1 * libgobject-2_0-0-debuginfo-2.84.4-160000.4.1 *glib2-devel-2.84.4-160000.4.1 * glib2-debugsource-2.84.4-160000.4.1 * libgthread-2_0-0-debuginfo-2.84.4-160000.4.1 * libgmodule-2_0-0-debuginfo-2.84.4-160000.4.1 * typelib-1_0-GIRepository-3_0-2.84.4-160000.4.1 * libgirepository-2_0-0-2.84.4-160000.4.1 * libgthread-2_0-0-2.84.4-160000.4.1 * glib2-devel-static-2.84.4-160000.4.1 * libglib-2_0-0-2.84.4-160000.4.1 * libgmodule-2_0-0-2.84.4-160000.4.1 * typelib-1_0-GObject-2_0-2.84.4-160000.4.1 * typelib-1_0-Gio-2_0-2.84.4-160000.4.1 * libgirepository-2_0-0-debuginfo-2.84.4-160000.4.1 * libgio-2_0-0-debuginfo-2.84.4-160000.4.1 * libgobject-2_0-0-2.84.4-160000.4.1 * libglib-2_0-0-debuginfo-2.84.4-160000.4.1 * glib2-tools-debuginfo-2.84.4-160000.4.1 * typelib-1_0-GLib-2_0-2.84.4-160000.4.1 * typelib-1_0-GLibUnix-2_0-2.84.4-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * glib2-lang-2.84.4-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * typelib-1_0-GModule-2_0-2.84.4-160000.4.1 * glib2-tools-2.84.4-160000.4.1 * glib2-doc-2.84.4-160000.4.1 * libgio-2_0-0-2.84.4-160000.4.1 * libgobject-2_0-0-debuginfo-2.84.4-160000.4.1 * glib2-devel-debuginfo-2.84.4-160000.4.1 * glib2-devel-2.84.4-160000.4.1 * glib2-debugsource-2.84.4-160000.4.1 * libgthread-2_0-0-debuginfo-2.84.4-160000.4.1 * libgmodule-2_0-0-debuginfo-2.84.4-160000.4.1 * libgirepository-2_0-0-2.84.4-160000.4.1 * libgthread-2_0-0-2.84.4-160000.4.1 * typelib-1_0-GIRepository-3_0-2.84.4-160000.4.1 * glib2-devel-static-2.84.4-160000.4.1 * libglib-2_0-0-2.84.4-160000.4.1 * libgmodule-2_0-0-2.84.4-160000.4.1 * typelib-1_0-GObject-2_0-2.84.4-160000.4.1 * libgirepository-2_0-0-debuginfo-2.84.4-160000.4.1 * typelib-1_0-Gio-2_0-2.84.4-160000.4.1 * libgio-2_0-0-debuginfo-2.84.4-160000.4.1 * libgobject-2_0-0-2.84.4-160000.4.1 * libglib-2_0-0-debuginfo-2.84.4-160000.4.1 * glib2-tools-debuginfo-2.84.4-160000.4.1 *typelib-1_0-GLib-2_0-2.84.4-160000.4.1 * typelib-1_0-GLibUnix-2_0-2.84.4-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * glib2-lang-2.84.4-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58010.html * https://www.suse.com/security/cve/CVE-2026-58011.html * https://www.suse.com/security/cve/CVE-2026-58012.html * https://www.suse.com/security/cve/CVE-2026-58013.html * https://www.suse.com/security/cve/CVE-2026-58014.html * https://www.suse.com/security/cve/CVE-2026-58016.html * https://bugzilla.suse.com/show_bug.cgi?id=1270008 * https://bugzilla.suse.com/show_bug.cgi?id=1270009 * https://bugzilla.suse.com/show_bug.cgi?id=1270010 * https://bugzilla.suse.com/show_bug.cgi?id=1270016 * https://bugzilla.suse.com/show_bug.cgi?id=1270018 * https://bugzilla.suse.com/show_bug.cgi?id=1270021 . A security update for glib2 addresses six issues, including out-of-bounds access exploits impacting SUSE systems.. SUSE update, glib2 security, Linux patch, system vulnerabilities, important update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 27, 2026 Important SuSE
89

Fedora 44 cjson Moderate Out-of-Bounds Access Issues FEDORA-2026-0c3f6c7c67

Update to version 1.7.19. https://github.com/DaveGamble/cJSON/blob/v1.7.19/CHANGELOG.md. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-0c3f6c7c67 2026-07-11 01:06:30.201347+00:00 -------------------------------------------------------------------------------- Name : cjson Product : Fedora 44 Version : 1.7.19 Release : 1.fc44 URL : https://github.com/DaveGamble/cJSON Summary : Ultralightweight JSON parser in ANSI C Description : cJSON aims to be the dumbest possible parser that you can get your job done with. It's a single file of C, and a single header file. -------------------------------------------------------------------------------- Update Information: Update to version 1.7.19. https://github.com/DaveGamble/cJSON/blob/v1.7.19/CHANGELOG.md -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 1 2026 Carl George - 1.7.19-1 - Update to version 1.7.19 rhbz#2394084 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2495843 - CVE-2025-57052 cjson: out-of-bounds access in decode_array_index_from_pointer() in cJSON_Utils.c via crafted JSON pointer strings [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2495843 [ 2 ] Bug #2495846 - CVE-2023-26819 cjson: cJSON rejects a valid text [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2495846 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-0c3f6c7c67' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . The Fedora 44 security advisory discusses cjson update 1.7.19 addressing moderate severity vulnerabilities and their impact.. Fedora cJSON update security advisory out-of-bounds access JSON parser. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 10, 2026 moderate Fedora
89

Fedora 44 Upower Moderate Access Control Fix FEDORA-2026-e5305cffc2

upower 1.91.3: Feature: up-device-battery: Prefer "Standard" over "Fast" charging (!316 (merged), #344 (closed)) Fix: Resolve potential leaks (!327 (merged)) Fix: Potential out-of-bound access (!328 (merged)). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-e5305cffc2 2026-07-09 00:54:37.609376+00:00 -------------------------------------------------------------------------------- Name : upower Product : Fedora 44 Version : 1.91.3 Release : 1.fc44 URL : https://upower.freedesktop.org/ Summary : Power Management Service Description : UPower (formerly DeviceKit-power) provides a daemon, API and command line tools for managing power devices attached to the system. -------------------------------------------------------------------------------- Update Information: upower 1.91.3: Feature: up-device-battery: Prefer "Standard" over "Fast" charging (!316 (merged), #344 (closed)) Fix: Resolve potential leaks (!327 (merged)) Fix: Potential out-of-bound access (!328 (merged)) Fix: Improve access control (!326 (merged)) Fix: Remove unused codes (!329 (merged)) Fix: Fix for Asus Battery Charge Threshold Detection (!330 (merged), #347 (closed)) -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 7 2026 Peter Robinson - 1.91.3-1 - Update to 1.91.3 (fixes rhbz#2496407 rhbz#2414589) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2414589 - Settings > Power > Battery Charging: "Preserve Battery Health" can't be set persistently when BIOS Admin Password (a.k.a Setup Password) is set. https://bugzilla.redhat.com/show_bug.cgi?id=2414589 [ 2 ] Bug #2496407 - upower-1.91.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2496407 -------------------------------------------------------------------------------- This update can be installed with the"dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e5305cffc2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Explore the latest Fedora update for upower 1.91.3 addressing leaks and out-of-bounds access concerns.. Fedora Update, UPower Security, Out-of-Bounds Access, Power Management, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 08, 2026 Important Fedora
100

SUSE Glycin-loaders Moderate Out-of-Bounds Access Threat 2026-22302-1

An update that solves two vulnerabilities can now be installed.. # Security update for glycin-loaders Announcement ID: SUSE-SU-2026:22302-1 Release Date: 2026-06-20T18:27:34Z Rating: moderate References: * bsc#1248035 * bsc#1249010 Cross-References: * CVE-2025-55159 * CVE-2025-58160 CVSS scores: * CVE-2025-55159 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-55159 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2025-55159 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for glycin-loaders fixes the following issues * CVE-2025-55159: slab: incorrect bounds check in get_disjoint_mut function can lead to undefined behavior or potential crash due to out-of-bounds access (bsc#1248035). * CVE-2025-58160: tracing-subscriber: Tracing log pollution (bsc#1249010). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-999=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-999=1 ## PackageList: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64) * typelib-1_0-GlyGtk4_1-1.2.1-160000.3.1 * libglycin-1-0-1.2.1-160000.3.1 * typelib-1_0-Gly_1-1.2.1-160000.3.1 * glycin-loaders-1.2.1-160000.3.1 * libglycin-gtk4-1-0-1.2.1-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * typelib-1_0-GlyGtk4_1-1.2.1-160000.3.1 * libglycin-1-0-1.2.1-160000.3.1 * typelib-1_0-Gly_1-1.2.1-160000.3.1 * glycin-loaders-1.2.1-160000.3.1 * libglycin-gtk4-1-0-1.2.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-55159.html * https://www.suse.com/security/cve/CVE-2025-58160.html * https://bugzilla.suse.com/show_bug.cgi?id=1248035 * https://bugzilla.suse.com/show_bug.cgi?id=1249010 . This update addresses two issues in glycin-loaders affecting SUSE Linux Enterprise Server 16.0. Immediate installation is advised.. Glycin Loaders Patch, SUSE Update, Tracing Pollution Fix. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 01, 2026 moderate SuSE
202

openSUSE Leap 16.0 OpenSSL-3 Significant Heap Overflow Out-of-Bounds

An update that solves 15 vulnerabilities and has 15 bug fixes can now be installed.. openSUSE security update: security update for openssl-3 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21005-1 Rating: important References: * bsc#1259652 * bsc#1266340 * bsc#1266341 * bsc#1266342 * bsc#1266344 * bsc#1266345 * bsc#1266347 * bsc#1266349 * bsc#1266350 * bsc#1266351 * bsc#1266352 * bsc#1266353 * bsc#1266355 * bsc#1266356 * bsc#1266357 Cross-References: * CVE-2026-2673 * CVE-2026-34180 * CVE-2026-34182 * CVE-2026-34183 * CVE-2026-42764 * CVE-2026-42766 * CVE-2026-42767 * CVE-2026-42768 * CVE-2026-42769 * CVE-2026-42770 * CVE-2026-45445 * CVE-2026-45446 * CVE-2026-45447 * CVE-2026-7383 * CVE-2026-9076 CVSS scores: * CVE-2026-2673 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-2673 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34180 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34180 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34182 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34182 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34183 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34183 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42764 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42764 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42766 ( SUSE ): 5.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42766 ( SUSE ): 6.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42767 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( SUSE ): 6CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42768 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N * CVE-2026-42768 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-42769 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42769 ( SUSE ): 7.4 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42770 ( SUSE ): 5 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N * CVE-2026-42770 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-45445 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45445 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-45446 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-45447 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45447 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-7383 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7383 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9076 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-9076 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 15 vulnerabilities and has 15 bug fixes can now be installed. Description: This update for openssl-3 fixes the following issues - CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652). - CVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion (bsc#1266340). - CVE-2026-9076: Out-of-Bounds Read in CMS Password-Based Decryption (bsc#1266341). - CVE-2026-34180: Heap Buffer Over-read in ASN.1Content Parsing (bsc#1266342). - CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344). - CVE-2026-34183: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler (bsc#1266345). - CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347). - CVE-2026-42766: Possible NULL Dereference in Password-Based CMS Decryption (bsc#1266349). - CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). - CVE-2026-42768: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() (bsc#1266351). - CVE-2026-42769: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate (bsc#1266352). - CVE-2026-42770: FFC-DH Peer Validation Uses Attacker-Supplied q (bsc#1266353). - CVE-2026-45445: AES-OCB IV Ignored on EVP_Cipher() Path (bsc#1266355). - CVE-2026-45446: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes (bsc#1266356). - CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266357). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1017=1 Package List: - openSUSE Leap 16.0: libopenssl-3-devel-3.5.0-160000.8.1 libopenssl-3-fips-provider-3.5.0-160000.8.1 libopenssl-3-fips-provider-x86-64-v3-3.5.0-160000.8.1 libopenssl3-3.5.0-160000.8.1 libopenssl3-x86-64-v3-3.5.0-160000.8.1 openssl-3-3.5.0-160000.8.1 openssl-3-doc-3.5.0-160000.8.1 References: * https://www.suse.com/security/cve/CVE-2026-2673.html * https://www.suse.com/security/cve/CVE-2026-34180.html * https://www.suse.com/security/cve/CVE-2026-34182.html * https://www.suse.com/security/cve/CVE-2026-34183.html * https://www.suse.com/security/cve/CVE-2026-42764.html * https://www.suse.com/security/cve/CVE-2026-42766.html *https://www.suse.com/security/cve/CVE-2026-42767.html * https://www.suse.com/security/cve/CVE-2026-42768.html * https://www.suse.com/security/cve/CVE-2026-42769.html * https://www.suse.com/security/cve/CVE-2026-42770.html * https://www.suse.com/security/cve/CVE-2026-45445.html * https://www.suse.com/security/cve/CVE-2026-45446.html * https://www.suse.com/security/cve/CVE-2026-45447.html * https://www.suse.com/security/cve/CVE-2026-7383.html * https://www.suse.com/security/cve/CVE-2026-9076.html . This critical update resolves 15 vulnerabilities in openssl-3 for openSUSE, including heap and out-of-bounds issues.. openSUSE security advisory, openssl vulnerabilities, important security update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 Important OpenSUSE
202

openSUSE Leap 16.0 Severe Fixes for Mapserver Vulnerabilities 2026-20857-1

An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for mapserver ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20857-1 Rating: important References: * bsc#1260869 * bsc#1266663 Cross-References: * CVE-2026-33721 * CVE-2026-45104 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for mapserver fixes the following issues: Changes in mapserver: - Update to releasee 8.6.3 * SLD parser: fix out of bounds access on SLD with only a Rule with a ElseFilter but without a symbolizer [CVE-2026-33721, boo#1260869] [CVE-2026-45104, boo#1266663] Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-287=1 Package List: - openSUSE Leap 16.0: libjavamapscript-8.6.3-bp160.1.1 libmapserver2-8.6.3-bp160.1.1 mapserver-8.6.3-bp160.1.1 mapserver-devel-8.6.3-bp160.1.1 perl-mapscript-8.6.3-bp160.1.1 php-mapscriptng-8.6.3-bp160.1.1 python313-mapserver-8.6.3-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2026-33721.html * https://www.suse.com/security/cve/CVE-2026-45104.html . Update for openSUSE Leap 16.0 mapserver addresses critical bugs and security issues requiring immediate attention.. openSUSE mapserver update security vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 02, 2026 Important OpenSUSE
202

openSUSE Leap 16.0 Mesa Moderate Out-Of-Bounds Access Vuln 2026-20688-1

An update that solves one vulnerability and has 2 bug fixes can now be installed.. openSUSE security update: security update for mesa ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20688-1 Rating: moderate References: * bsc#1261911 * bsc#1261998 Cross-References: * CVE-2026-40393 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has 2 bug fixes can now be installed. Description: This update for Mesa fixes the following issue: - CVE-2026-40393: out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party (bsc#1261998). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-707=1 Package List: - openSUSE Leap 16.0: Mesa-24.3.3-160000.3.1 Mesa-KHR-devel-24.3.3-160000.3.1 Mesa-devel-24.3.3-160000.3.1 Mesa-dri-24.3.3-160000.3.1 Mesa-dri-devel-24.3.3-160000.3.1 Mesa-dri-nouveau-24.3.3-160000.3.1 Mesa-dri-vc4-24.3.3-160000.3.1 Mesa-gallium-24.3.3-160000.3.1 Mesa-libEGL-devel-24.3.3-160000.3.1 Mesa-libEGL1-24.3.3-160000.3.1 Mesa-libGL-devel-24.3.3-160000.3.1 Mesa-libGL1-24.3.3-160000.3.1 Mesa-libGLESv1_CM-devel-24.3.3-160000.3.1 Mesa-libGLESv2-devel-24.3.3-160000.3.1 Mesa-libGLESv3-devel-24.3.3-160000.3.1 Mesa-libOpenCL-24.3.3-160000.3.1 Mesa-libRusticlOpenCL-24.3.3-160000.3.1 Mesa-libd3d-24.3.3-160000.3.1 Mesa-libd3d-devel-24.3.3-160000.3.1 Mesa-libglapi-devel-24.3.3-160000.3.1 Mesa-libglapi0-24.3.3-160000.3.1 Mesa-libva-24.3.3-160000.3.1 Mesa-vulkan-device-select-24.3.3-160000.3.1 Mesa-vulkan-overlay-24.3.3-160000.3.1 libOSMesa-devel-24.3.3-160000.3.1 libOSMesa8-24.3.3-160000.3.1 libgbm-devel-24.3.3-160000.3.1 libgbm1-24.3.3-160000.3.1 libvdpau_d3d12-24.3.3-160000.3.1 libvdpau_nouveau-24.3.3-160000.3.1 libvdpau_r600-24.3.3-160000.3.1 libvdpau_radeonsi-24.3.3-160000.3.1 libvdpau_virtio_gpu-24.3.3-160000.3.1 libvulkan_broadcom-24.3.3-160000.3.1 libvulkan_freedreno-24.3.3-160000.3.1 libvulkan_intel-24.3.3-160000.3.1 libvulkan_lvp-24.3.3-160000.3.1 libvulkan_radeon-24.3.3-160000.3.1 libxatracker-devel-1.0.0-160000.3.1 libxatracker2-1.0.0-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-40393.html . An installation note regarding openSUSE security update addressing moderate issues in Mesa software with critical bug fixes.. openSUSE security patch Mesa vulnerability update. . LinuxSecurity.com Team

Calendar%202 May 08, 2026 OpenSUSE
100

SUSE Linux Micro 6.1 Mesa Moderate Out-of-Bounds Access Vuln 2026-21292-1

An update that solves one vulnerability can now be installed.. # Security update for Mesa Announcement ID: SUSE-SU-2026:21292-1 Release Date: 2026-04-23T12:57:06Z Rating: moderate References: * bsc#1261998 Cross-References: * CVE-2026-40393 CVSS scores: * CVE-2026-40393 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-40393 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40393 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for Mesa fixes the following issue: * CVE-2026-40393: out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party (bsc#1261998). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-504=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * Mesa-23.3.4-slfo.1.1_3.1 * Mesa-libEGL1-23.3.4-slfo.1.1_3.1 * Mesa-drivers-debugsource-23.3.4-slfo.1.1_3.1 * Mesa-libGL1-debuginfo-23.3.4-slfo.1.1_3.1 * libgbm1-debuginfo-23.3.4-slfo.1.1_3.1 * Mesa-libglapi0-23.3.4-slfo.1.1_3.1 * Mesa-libGL1-23.3.4-slfo.1.1_3.1 * Mesa-dri-debuginfo-23.3.4-slfo.1.1_3.1 * Mesa-debugsource-23.3.4-slfo.1.1_3.1 * Mesa-libEGL1-debuginfo-23.3.4-slfo.1.1_3.1 * libgbm1-23.3.4-slfo.1.1_3.1 * Mesa-libglapi0-debuginfo-23.3.4-slfo.1.1_3.1 * Mesa-dri-23.3.4-slfo.1.1_3.1 * SUSE Linux Micro 6.1 (aarch64 ppc64le x86_64) * Mesa-gallium-debuginfo-23.3.4-slfo.1.1_3.1 * Mesa-gallium-23.3.4-slfo.1.1_3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40393.html * https://bugzilla.suse.com/show_bug.cgi?id=1261998 . SUSEupdates Mesa to address an out-of-bounds access issue with moderate severity. Apply the security patch promptly.. SUSE Linux Micro Mesa Security Moderate Patch. . LinuxSecurity.com Team

Calendar%202 Apr 27, 2026 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Are host-based firewalls still worth using?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/158-are-host-based-firewalls-still-worth-using?task=poll.vote&format=json
158
radio
0
[{"id":510,"title":"Yes \u2014 every server needs one.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":511,"title":"No \u2014 perimeter and cloud security are enough.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":512,"title":"Only Internet-facing systems really benefit.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":513,"title":"iptables.conf is my security policy.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200