Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-dafdad8fd3 2026-06-05 04:25:00.358941+00:00 -------------------------------------------------------------------------------- Name : perl-Crypt-Argon2 Product : Fedora 44 Version : 0.031 Release : 1.fc44 URL : https://metacpan.org/release/Crypt-Argon2 Summary : Perl interface to the Argon2 key derivation functions Description : This module implements the Argon2 key derivation function, which is suitable to convert any password into a cryptographic key. This is most often used to for secure storage of passwords but can also be used to derive a encryption key from a password. It offers variable time and memory costs as well as output size. -------------------------------------------------------------------------------- Update Information: Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463 -------------------------------------------------------------------------------- ChangeLog: * Tue May 26 2026 Charles R. Anderson - 0.031-1 - Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-dafdad8fd3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that fixes three vulnerabilities, contains one feature is now available. . SUSE Security Update: Security update for libreoffice ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3602-1 Rating: important References: #1201868 #1201872 #1203209 SLE-23448 Cross-References: CVE-2022-26305 CVE-2022-26307 CVE-2022-3140 CVSS scores: CVE-2022-26305 (NVD) : 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-26305 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-26307 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-26307 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N CVE-2022-3140 (NVD) : 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L Affected Products: SUSE Linux Enterprise Desktop 12-SP5 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Workstation Extension 12-SP5 ______________________________________________________________________________ An update that fixes three vulnerabilities, contains one feature is now available. Description: This update for libreoffice fixes the following issues: Updated to version 7.3.6.2 (jsc#SLE-23448): - CVE-2022-3140: Fixed macro URL arbitrary script execution (bsc#1203209). - CVE-2022-26305: Fixed execution of untrusted Macros due to improper certificate validation (bsc#1201868). - CVE-2022-26307: Fixed weak Master Keys in password storage (bsc#1201872). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run thecommand listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2022-3602=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-3602=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (noarch): libreoffice-branding-upstream-7.3.6.2-48.28.1 libreoffice-icon-themes-7.3.6.2-48.28.1 libreoffice-l10n-af-7.3.6.2-48.28.1 libreoffice-l10n-ar-7.3.6.2-48.28.1 libreoffice-l10n-bg-7.3.6.2-48.28.1 libreoffice-l10n-ca-7.3.6.2-48.28.1 libreoffice-l10n-cs-7.3.6.2-48.28.1 libreoffice-l10n-da-7.3.6.2-48.28.1 libreoffice-l10n-de-7.3.6.2-48.28.1 libreoffice-l10n-en-7.3.6.2-48.28.1 libreoffice-l10n-es-7.3.6.2-48.28.1 libreoffice-l10n-fi-7.3.6.2-48.28.1 libreoffice-l10n-fr-7.3.6.2-48.28.1 libreoffice-l10n-gu-7.3.6.2-48.28.1 libreoffice-l10n-hi-7.3.6.2-48.28.1 libreoffice-l10n-hr-7.3.6.2-48.28.1 libreoffice-l10n-hu-7.3.6.2-48.28.1 libreoffice-l10n-it-7.3.6.2-48.28.1 libreoffice-l10n-ja-7.3.6.2-48.28.1 libreoffice-l10n-ko-7.3.6.2-48.28.1 libreoffice-l10n-lt-7.3.6.2-48.28.1 libreoffice-l10n-nb-7.3.6.2-48.28.1 libreoffice-l10n-nl-7.3.6.2-48.28.1 libreoffice-l10n-nn-7.3.6.2-48.28.1 libreoffice-l10n-pl-7.3.6.2-48.28.1 libreoffice-l10n-pt_BR-7.3.6.2-48.28.1 libreoffice-l10n-pt_PT-7.3.6.2-48.28.1 libreoffice-l10n-ro-7.3.6.2-48.28.1 libreoffice-l10n-ru-7.3.6.2-48.28.1 libreoffice-l10n-sk-7.3.6.2-48.28.1 libreoffice-l10n-sv-7.3.6.2-48.28.1 libreoffice-l10n-uk-7.3.6.2-48.28.1 libreoffice-l10n-xh-7.3.6.2-48.28.1 libreoffice-l10n-zh_CN-7.3.6.2-48.28.1 libreoffice-l10n-zh_TW-7.3.6.2-48.28.1 libreoffice-l10n-zu-7.3.6.2-48.28.1 - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): libreoffice-7.3.6.2-48.28.1 libreoffice-base-7.3.6.2-48.28.1 libreoffice-base-debuginfo-7.3.6.2-48.28.1 libreoffice-base-drivers-postgresql-7.3.6.2-48.28.1 libreoffice-base-drivers-postgresql-debuginfo-7.3.6.2-48.28.1 libreoffice-calc-7.3.6.2-48.28.1 libreoffice-calc-debuginfo-7.3.6.2-48.28.1 libreoffice-calc-extensions-7.3.6.2-48.28.1 libreoffice-debuginfo-7.3.6.2-48.28.1 libreoffice-debugsource-7.3.6.2-48.28.1 libreoffice-draw-7.3.6.2-48.28.1 libreoffice-draw-debuginfo-7.3.6.2-48.28.1 libreoffice-filters-optional-7.3.6.2-48.28.1 libreoffice-gnome-7.3.6.2-48.28.1 libreoffice-gnome-debuginfo-7.3.6.2-48.28.1 libreoffice-gtk3-7.3.6.2-48.28.1 libreoffice-gtk3-debuginfo-7.3.6.2-48.28.1 libreoffice-impress-7.3.6.2-48.28.1 libreoffice-impress-debuginfo-7.3.6.2-48.28.1 libreoffice-librelogo-7.3.6.2-48.28.1 libreoffice-mailmerge-7.3.6.2-48.28.1 libreoffice-math-7.3.6.2-48.28.1 libreoffice-math-debuginfo-7.3.6.2-48.28.1 libreoffice-officebean-7.3.6.2-48.28.1 libreoffice-officebean-debuginfo-7.3.6.2-48.28.1 libreoffice-pyuno-7.3.6.2-48.28.1 libreoffice-pyuno-debuginfo-7.3.6.2-48.28.1 libreoffice-writer-7.3.6.2-48.28.1 libreoffice-writer-debuginfo-7.3.6.2-48.28.1 libreoffice-writer-extensions-7.3.6.2-48.28.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (x86_64): libreoffice-debuginfo-7.3.6.2-48.28.1 libreoffice-debugsource-7.3.6.2-48.28.1 libreoffice-sdk-7.3.6.2-48.28.1 libreoffice-sdk-debuginfo-7.3.6.2-48.28.1 References: https://www.suse.com/security/cve/CVE-2022-26305.html https://www.suse.com/security/cve/CVE-2022-26307.html https://www.suse.com/security/cve/CVE-2022-3140.html https://bugzilla.suse.com/1201868 https://bugzilla.suse.com/1201872 https://bugzilla.suse.com/1203209 . SUSE has released a security patch for libreoffice addressing critical concerns such as vulnerabilities related to macro execution and the management of password storage..LibreOffice Security, Macro Execution Risk, SUSE Update, Security Issue, Important Update. . Severity: Important. LinuxSecurity.com Team
A flaw was found in Ceph where Ceph stores mgr module passwords in clear text. This issue can be found by searching the mgr logs for Grafana and dashboard with passwords visible. The highest threat from this vulnerability is to confidentiality (CVE-2020-25678). . MGASA-2021-0126 - Updated ceph packages fix security vulnerabilities Publication date: 12 Mar 2021 URL: https://advisories.mageia.org/MGASA-2021-0126.html Type: security Affected Mageia releases: 8 CVE: CVE-2020-25678, CVE-2020-27839 A flaw was found in Ceph where Ceph stores mgr module passwords in clear text. This issue can be found by searching the mgr logs for Grafana and dashboard with passwords visible. The highest threat from this vulnerability is to confidentiality (CVE-2020-25678). A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s localStorage which is potentially vulnerable to attackers via XSS attacks. The highest threat from this vulnerability is to data confidentiality and integrity (CVE-2020-27839). References: - https://bugs.mageia.org/show_bug.cgi?id=28538 - https://lists.fedoraproject.org/archives/list/
fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of the password (CVE-2020-12755). . MGASA-2020-0371 - Updated kio-extras packages fix security vulnerability Publication date: 27 Sep 2020 URL: https://advisories.mageia.org/MGASA-2020-0371.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-12755 fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of the password (CVE-2020-12755). References: - https://bugs.mageia.org/show_bug.cgi?id=27297 - https://kde.org/info/security/advisory-20200510-1.txt - https://www.cve.org/CVERecord?id=CVE-2020-12755 SRPMS: - 7/core/kio-extras-19.04.0-1.1.mga7 . Mageia 2020-0371 has released an update for kio-extras, addressing a vulnerability that could inadvertently save user credentials, thereby improving overall security.. kio-extras Security Update, Mageia Security, KDE Bug Fix. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.