Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Update uv / python-uv-build to 0.11.28, with significant hardening of zip file handling against parser differentials.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-be84487fdd 2026-07-19 05:46:37.002118+00:00 -------------------------------------------------------------------------------- Name : python-uv-build Product : Fedora 44 Version : 0.11.28 Release : 1.fc44 URL : https://pypi.org/project/uv-build Summary : The uv build backend Description : This package is a slimmed down version of uv containing only the build backend. -------------------------------------------------------------------------------- Update Information: Update uv / python-uv-build to 0.11.28, with significant hardening of zip file handling against parser differentials. -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 8 2026 Benjamin A. Beasley - 0.11.28-1 - Update to 0.11.28 (close RHBZ#2497949) * Tue Jul 7 2026 Benjamin A. Beasley - 0.11.27-1 - Update to 0.11.27 (close RHBZ#2497574) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-be84487fdd' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update uv / python-uv-build to 0.11.28, with significant hardening of zip file handling against parser differentials.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-8893ec1aeb 2026-07-19 03:55:06.729034+00:00 -------------------------------------------------------------------------------- Name : rust-astral_async_zip Product : Fedora 43 Version : 0.0.20 Release : 1.fc43 URL : https://crates.io/crates/astral_async_zip Summary : Asynchronous ZIP archive reading/writing crate Description : An asynchronous ZIP archive reading/writing crate. -------------------------------------------------------------------------------- Update Information: Update uv / python-uv-build to 0.11.28, with significant hardening of zip file handling against parser differentials. -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 7 2026 Benjamin A. Beasley - 0.0.20-1 - Update to version 0.0.20; Fixes RHBZ#2497383 * Thu Jun 18 2026 Benjamin A. Beasley - 0.0.18-3 - Exclude examples, tests, and test data from -devel packages * Thu Jun 18 2026 Benjamin A. Beasley - 0.0.18-2 - Exclude rustfmt.toml from the crate -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-8893ec1aeb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability can now be installed.. # Security update for gsasl Announcement ID: SUSE-SU-2026:22313-1 Release Date: 2026-06-22T09:25:40Z Rating: important References: * bsc#1266371 Cross-References: * CVE-2026-48829 CVSS scores: * CVE-2026-48829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for gsasl fixes the following issues: Changes in gsasl: * CVE-2026-48829: DIGEST-MD5: Fix NULL pointer dereference in parser (bsc#1266371) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1016=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1016=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * gsasl-devel-2.2.1-160000.3.1 * gsasl-debugsource-2.2.1-160000.3.1 * gsasl-debuginfo-2.2.1-160000.3.1 * libgsasl18-2.2.1-160000.3.1 * gsasl-2.2.1-160000.3.1 * libgsasl18-debuginfo-2.2.1-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * gsasl-lang-2.2.1-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * gsasl-devel-2.2.1-160000.3.1 * gsasl-debugsource-2.2.1-160000.3.1 * gsasl-debuginfo-2.2.1-160000.3.1 * libgsasl18-2.2.1-160000.3.1 * gsasl-2.2.1-160000.3.1 * libgsasl18-debuginfo-2.2.1-160000.3.1 * SUSE Linux Enterprise Server for SAPapplications 16.0 (noarch) * gsasl-lang-2.2.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48829.html * https://bugzilla.suse.com/show_bug.cgi?id=1266371 . Important update for gsasl addresses a critical null pointer issue. Install recommended patches for SUSE systems.. SUSE gsasl update important patch security. . Severity: Important. LinuxSecurity.com Team
0.0.32 (2026-06-04) Speed up partial-boundary scanning for CR/LF-dense part data. 0.0.31 (2026-06-04) Speed up multipart header parsing and callback dispatch. Bound header field name size before validating.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-2cfc16a621 2026-06-15 01:10:25.755860+00:00 -------------------------------------------------------------------------------- Name : python-python-multipart Product : Fedora 43 Version : 0.0.32 Release : 1.fc43 URL : https://github.com/Kludex/python-multipart Summary : A streaming multipart parser for Python Description : Python-Multipart is a streaming multipart parser for Python. -------------------------------------------------------------------------------- Update Information: 0.0.32 (2026-06-04) Speed up partial-boundary scanning for CR/LF-dense part data. 0.0.31 (2026-06-04) Speed up multipart header parsing and callback dispatch. Bound header field name size before validating. Validate Content-Length is non-negative in parse_form. Fixes security issues GHSA-v9pg-7xvm-68hf, GHSA-5rvq-cxj2-64vf, GHSA-6jv3-5f52-599m, and GHSA-vffw-93wf-4j4q. 0.0.30 (2026-05-31) Parse application/x-www-form-urlencoded bodies per the WHATWG URL standard, treating only & as a field separator. Ignore RFC 2231/5987 extended parameters (name*, filename*) in parse_options_header, keeping the plain parameter authoritative per RFC 7578 §4.2. -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 5 2026 Packit - 0.0.32-1 - Update to 0.0.32 upstream release - Resolves: rhbz#2484846 * Thu Jun 4 2026 Packit - 0.0.31-1 - Update to 0.0.31 upstream release - Resolves: rhbz#2484715 * Mon Jun 1 2026 Packit - 0.0.30-1 - Update to 0.0.30 upstream release - Resolves: rhbz#2483639 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2483639 - python-python-multipart-0.0.30 isavailable https://bugzilla.redhat.com/show_bug.cgi?id=2483639 [ 2 ] Bug #2484715 - python-python-multipart-0.0.31 is available https://bugzilla.redhat.com/show_bug.cgi?id=2484715 [ 3 ] Bug #2484846 - python-python-multipart-0.0.32 is available https://bugzilla.redhat.com/show_bug.cgi?id=2484846 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2cfc16a621' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 43 update for python-python-multipart addresses security issues and enhances performance for multipart data parsing.. Fedora 43, Python Multipart, Security Update, Performance Improvements. . Severity: Important. LinuxSecurity.com Team
New libxml2 packages are available for Slackware 15.0 and -current to fix security issues.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] libxml2 (SSA:2026-070-02) New libxml2 packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/libxml2-2.11.9-i586-8_slack15.0.txz: Rebuilt. This update fixes security issues: CVE-2026-1757 fix: Memory leak in xmllint Shell - shell.c CVE-2026-0990 fix: Prevent infinite recursion in xmlCatalogListXMLResolve CVE-2026-0992 fix: Exponential behavior when handling parser: Fix infinite loop in xmlCtxtParseContent CVE-2025-10911 libxslt related: Ignore next/prev of documents when traversing XPath CVE-2026-0989 fix: Add RelaxNG include limit Thanks to r1w1s1 for locating the backported patches. For more information, see: https://www.cve.org/CVERecord?id=CVE-2026-1757 https://www.cve.org/CVERecord?id=CVE-2026-0990 https://www.cve.org/CVERecord?id=CVE-2026-0992 https://www.cve.org/CVERecord?id=CVE-2025-10911 https://www.cve.org/CVERecord?id=CVE-2026-0989 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libxml2-2.11.9-i586-8_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/libxml2-2.11.9-x86_64-8_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/libxml2-2.15.2-i686-1.txz Updated package for Slackware x86_64-current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/libxml2-2.15.2-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: 5868328f253dc7040729ef0b057a429c libxml2-2.11.9-i586-8_slack15.0.txz Slackware x86_64 15.0 package: 7969553fbdf9ffdce4bfec2619ff38a6 libxml2-2.11.9-x86_64-8_slack15.0.txz Slackware -current package: a474110a92bac5d51ac8fb62c270b10d l/libxml2-2.15.2-i686-1.txz Slackware x86_64 -current package: 484f22dfed7a7391119bd53bebf8480f l/libxml2-2.15.2-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg libxml2-2.11.9-i586-8_slack15.0.txz +-----+ . New libxml2 packages for Slackware address several security fixes including memory leaks and infinite loop issues.. libxml2 packages Slackware updates security fixes. . Severity: Important. LinuxSecurity.com Team
uv 0.9.5 https://github.com/astral-sh/uv/blob/0.9.5/CHANGELOG.md Since uv was built with astral-tokio-tar 0.5.6, this is a security fix for CVE-2025-62518. ruff 0.14.2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-a77c1f005b 2025-11-03 01:05:58.219415+00:00 -------------------------------------------------------------------------------- Name : rust-reqsign-aws-v4 Product : Fedora 42 Version : 2.0.0 Release : 1.fc42 URL : https://crates.io/crates/reqsign-aws-v4 Summary : AWS SigV4 signing implementation for reqsign Description : AWS SigV4 signing implementation for reqsign. -------------------------------------------------------------------------------- Update Information: uv 0.9.5 https://github.com/astral-sh/uv/blob/0.9.5/CHANGELOG.md Since uv was built with astral-tokio-tar 0.5.6, this is a security fix for CVE-2025-62518. ruff 0.14.2 https://github.com/astral-sh/ruff/blob/0.14.2/CHANGELOG.md rust-astral-tokio-tar 0.5.6 Fixed a parser desynchronization vulnerability when reading tar archives that contain mismatched size information in PAX/ustar headers. This vulnerability is being tracked as GHSA-j5gw-2vrg-8fgx and CVE-2025-62518. Initial package for python-uv-build in Fedora 42 Initial packages for a number of new dependencies for ruff and uv Update rust-tikv-jemallocator and rust-tikv-jemalloc-sys to 0.6.1 Update openapi-python-client to 0.26.2 and patch it to allow ruff 0.14 -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 23 2025 Benjamin A. Beasley - 2.0.0-1 - Update to version 2.0.0 * Sat Oct 11 2025 Benjamin A. Beasley - 1.0.0-1 - Initial package (close RHBZ#2400195) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2360699 - ruff-0.14.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2360699 [ 2 ] Bug #2402441 -rust-reqsign-core-2.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2402441 [ 3 ] Bug #2402442 - rust-reqsign-command-execute-tokio-2.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2402442 [ 4 ] Bug #2402443 - rust-reqsign-http-send-reqwest-2.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2402443 [ 5 ] Bug #2402881 - python-uv-build-0.9.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2402881 [ 6 ] Bug #2402923 - uv-0.9.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2402923 [ 7 ] Bug #2405474 - CVE-2025-62518 rust-astral-tokio-tar: astral-tokio-tar Vulnerable to PAX Header Desynchronization [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2405474 [ 8 ] Bug #2405476 - CVE-2025-62518 uv: astral-tokio-tar Vulnerable to PAX Header Desynchronization [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2405476 [ 9 ] Bug #2406135 - ruff-0.14.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2406135 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a77c1f005b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
crosswords 0.3.13. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-e4717532c4 2024-05-25 01:04:07.908862 -------------------------------------------------------------------------------- Name : libipuz Product : Fedora 40 Version : 0.4.6.2 Release : 1.fc40 URL : Summary : Library for parsing .ipuz puzzle files Description : This is a library for parsing .ipuz puzzle files, for crossword puzzles, sudokus, etc. The library only handles crosswords for now. -------------------------------------------------------------------------------- Update Information: crosswords 0.3.13 -------------------------------------------------------------------------------- ChangeLog: * Mon May 20 2024 Davide Cavalca - 0.4.6.2-1 - Update to 0.4.6.2; Fixes: RHBZ#2281417 * Wed Mar 20 2024 Davide Cavalca - 0.4.5-4 - Add rust support in preparation for 0.4.6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2281417 - libipuz-0.4.6.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2281417 [ 2 ] Bug #2281577 - crosswords-0.3.13 is available https://bugzilla.redhat.com/show_bug.cgi?id=2281577 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-e4717532c4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --- See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. ---- enable s390x build (rhbz#1971028). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-37aef44d1e 2022-07-30 01:52:05.591856 --------------------------------------------------------------------------------Name : golang-github-quay-goval-parser Product : Fedora 36 Version : 0.8.6 Release : 5.fc36 URL : https://github.com/quay/goval-parser Summary : OVAL parser written in go Description : OVAL parser written in go. --------------------------------------------------------------------------------Update Information: Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang ---See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. ---- enable s390x build (rhbz#1971028) --------------------------------------------------------------------------------ChangeLog: * Tue Jul 19 2022 Maxwell G 0.8.6-5 - Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-37aef44d1e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.