Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Fedora 43 has released kernel version 7.1.4-104, addressing security issues and containing updates. Users can upgrade using the dnf command line tool.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6503a6a639 2026-07-23 01:01:59.493964+00:00 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 43 Version : 7.1.4 Release : 104.fc43 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 7.1.4-104/204 stable kennel updates contain a couple of security fixes for issues with exploits in the wild. -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 22 2026 Justin M. Forbes [7.1.4-4] - net/packet: avoid fanout hook re-registration after unregister (David Lee) * Wed Jul 22 2026 Justin M. Forbes [7.1.4-3] - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (Jamal Hadi Salim) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6503a6a639' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Oracle Linux 8 has updated GLib packages addressing multiple CVEs, including CVE-2026-58016. RPMs for x86_64 and aarch64 architectures are available on the Unbreakable Linux Network.. Oracle Linux Security Advisory ELSA-2026-42090 http://linux.oracle.com/errata/ELSA-2026-42090.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: glib2-2.56.4-170.el8_10.i686.rpm glib2-2.56.4-170.el8_10.x86_64.rpm glib2-devel-2.56.4-170.el8_10.i686.rpm glib2-devel-2.56.4-170.el8_10.x86_64.rpm glib2-doc-2.56.4-170.el8_10.noarch.rpm glib2-fam-2.56.4-170.el8_10.x86_64.rpm glib2-static-2.56.4-170.el8_10.i686.rpm glib2-static-2.56.4-170.el8_10.x86_64.rpm glib2-tests-2.56.4-170.el8_10.x86_64.rpm aarch64: glib2-2.56.4-170.el8_10.aarch64.rpm glib2-devel-2.56.4-170.el8_10.aarch64.rpm glib2-doc-2.56.4-170.el8_10.noarch.rpm glib2-fam-2.56.4-170.el8_10.aarch64.rpm glib2-static-2.56.4-170.el8_10.aarch64.rpm glib2-tests-2.56.4-170.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/glib2-2.56.4-170.el8_10.src.rpm Related CVEs: CVE-2026-58016 Description of changes: [2.56.4-170] - Add patch for CVE-2026-58016 - Resolves: RHEL-190622 [2.68.4-169] - Add patch for CVE-2025-14087 and CVE-2025-14512 [2.56.4-168] - Add patch for CVE-2025-13601 - Fix GUnixMount issues - Enable testsuite during RPM check phase [2.56.4-167] - gdbusconnection: Prevent sending a serial of zero on overflow - Resolves: RHEL-114086 _______________________________________________ El-errata mailing list
An update that fixes 8 vulnerabilities is now available.. openSUSE Security Update: Security update for libkrun ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0255-1 Rating: important References: #1270198 #1270429 #1270470 #1270582 #1270683 #1270721 #1270831 #1270877 Cross-References: CVE-2025-24898 CVE-2026-41676 CVE-2026-41677 CVE-2026-41678 CVE-2026-41681 CVE-2026-41898 CVE-2026-42327 CVE-2026-44662 CVSS scores: CVE-2025-24898 (SUSE): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVE-2026-41676 (SUSE): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N CVE-2026-41677 (SUSE): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U CVE-2026-41678 (SUSE): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-41681 (SUSE): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-41898 (SUSE): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N CVE-2026-42327 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2026-44662 (SUSE): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes 8 vulnerabilities is now available. Description: This update for libkrun fixes the following issues: Update vendored openssl crate to version 0.10.81 to deal with: CVE-2026-41676 (boo#1270198), CVE-2025-24898 (boo#1270429), CVE-2026-41677 (boo#1270582), CVE-2026-42327 (boo#1270470),CVE-2026-41678 (boo#1270683), CVE-2026-41898 (boo#1270831), CVE-2026-41681 (boo#1270721), CVE-2026-44662 (boo#1270877). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-255=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 x86_64): libkrun-devel-1.4.10-bp157.2.3.1 libkrun1-1.4.10-bp157.2.3.1 - openSUSE Backports SLE-15-SP7 (x86_64): libkrun-sev-devel-1.4.10-bp157.2.3.1 libkrun-sev1-1.4.10-bp157.2.3.1 References: https://www.suse.com/security/cve/CVE-2025-24898.html https://www.suse.com/security/cve/CVE-2026-41676.html https://www.suse.com/security/cve/CVE-2026-41677.html https://www.suse.com/security/cve/CVE-2026-41678.html https://www.suse.com/security/cve/CVE-2026-41681.html https://www.suse.com/security/cve/CVE-2026-41898.html https://www.suse.com/security/cve/CVE-2026-42327.html https://www.suse.com/security/cve/CVE-2026-44662.html https://bugzilla.suse.com/1270198 https://bugzilla.suse.com/1270429 https://bugzilla.suse.com/1270470 https://bugzilla.suse.com/1270582 https://bugzilla.suse.com/1270683 https://bugzilla.suse.com/1270721 https://bugzilla.suse.com/1270831 https://bugzilla.suse.com/1270877 . Resolve 8 important vulnerabilities in libkrun with the latest openSUSE update, ensuring system integrity and security.. libkrun vulnerabilities, openSUSE update, security threats. . Severity: Important. LinuxSecurity.com Team
An update that solves 2 vulnerabilities and has one bug fix can now be installed.. openSUSE security update: security update for opam ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21380-1 Rating: important References: * bsc#1262281 Cross-References: * CVE-2026-41082 * CVE-2026-57825 CVSS scores: * CVE-2026-41082 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-41082 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has one bug fix can now be installed. Description: This update for opam fixes the following issues: Changes in opam: - Update to version 2.5.2 (CVE-2026-57825) see included CHANGES file for details - Update to version 2.5.1 (CVE-2026-41082 bsc#1262281) see included CHANGES file for details - Update to version 2.5.0 see included CHANGES file for details Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-431=1 Package List: - openSUSE Leap 16.0: opam-2.5.2-bp160.1.1 opam-devel-2.5.2-bp160.1.1 opam-installer-2.5.2-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2026-41082.html * https://www.suse.com/security/cve/CVE-2026-57825.html . Install the latest openSUSE security update to address critical issues in opam and patch important vulnerabilities today.. openSUSE security, opam update, security patch, important issues, security advisories. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-21754 http://linux.oracle.com/errata/ELSA-2026-21754.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: aspnetcore-runtime-9.0-9.0.17-1.0.1.el10_2.x86_64.rpm aspnetcore-runtime-dbg-9.0-9.0.17-1.0.1.el10_2.x86_64.rpm aspnetcore-targeting-pack-9.0-9.0.17-1.0.1.el10_2.x86_64.rpm dotnet-apphost-pack-9.0-9.0.17-1.0.1.el10_2.x86_64.rpm dotnet-hostfxr-9.0-9.0.17-1.0.1.el10_2.x86_64.rpm dotnet-runtime-9.0-9.0.17-1.0.1.el10_2.x86_64.rpm dotnet-runtime-dbg-9.0-9.0.17-1.0.1.el10_2.x86_64.rpm dotnet-sdk-9.0-9.0.118-1.0.1.el10_2.x86_64.rpm dotnet-sdk-9.0-source-built-artifacts-9.0.118-1.0.1.el10_2.x86_64.rpm dotnet-sdk-aot-9.0-9.0.118-1.0.1.el10_2.x86_64.rpm dotnet-sdk-dbg-9.0-9.0.118-1.0.1.el10_2.x86_64.rpm dotnet-targeting-pack-9.0-9.0.17-1.0.1.el10_2.x86_64.rpm dotnet-templates-9.0-9.0.118-1.0.1.el10_2.x86_64.rpm netstandard-targeting-pack-2.1-9.0.118-1.0.1.el10_2.x86_64.rpm aarch64: aspnetcore-runtime-9.0-9.0.17-1.0.1.el10_2.aarch64.rpm aspnetcore-runtime-dbg-9.0-9.0.17-1.0.1.el10_2.aarch64.rpm aspnetcore-targeting-pack-9.0-9.0.17-1.0.1.el10_2.aarch64.rpm dotnet-apphost-pack-9.0-9.0.17-1.0.1.el10_2.aarch64.rpm dotnet-hostfxr-9.0-9.0.17-1.0.1.el10_2.aarch64.rpm dotnet-runtime-9.0-9.0.17-1.0.1.el10_2.aarch64.rpm dotnet-runtime-dbg-9.0-9.0.17-1.0.1.el10_2.aarch64.rpm dotnet-sdk-9.0-9.0.118-1.0.1.el10_2.aarch64.rpm dotnet-sdk-9.0-source-built-artifacts-9.0.118-1.0.1.el10_2.aarch64.rpm dotnet-sdk-aot-9.0-9.0.118-1.0.1.el10_2.aarch64.rpm dotnet-sdk-dbg-9.0-9.0.118-1.0.1.el10_2.aarch64.rpm dotnet-targeting-pack-9.0-9.0.17-1.0.1.el10_2.aarch64.rpm dotnet-templates-9.0-9.0.118-1.0.1.el10_2.aarch64.rpm netstandard-targeting-pack-2.1-9.0.118-1.0.1.el10_2.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/dotnet9.0-9.0.118-1.0.1.el10_2.src.rpm Related CVEs: CVE-2026-42899 Description ofchanges: [9.0.118-1.0.1] - Add support for Oracle Linux [9.0.118-1] - Update to .NET SDK 9.0.118 and Runtime 9.0.17 - Resolves: RHEL-181554 [9.0.117-1] - Update to .NET SDK 9.0.117 and Runtime 9.0.16 - Resolves: RHEL-173919 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-19136 http://linux.oracle.com/errata/ELSA-2026-19136.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: grafana-pcp-5.3.0-7.el10_2.x86_64.rpm aarch64: grafana-pcp-5.3.0-7.el10_2.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/grafana-pcp-5.3.0-7.el10_2.src.rpm Related CVEs: CVE-2026-32282 CVE-2026-32283 Description of changes: [5.3.0-7] - Resolves RHEL-183688: CVE-2026-39821 [5.3.0-6] - Resolves RHEL-183688: CVE-2026-39821 [5.3.0-5] - Resolves RHEL-166460: CVE-2026-32282 - Resolves RHEL-167495: CVE-2026-32283 _______________________________________________ El-errata mailing list
An update that fixes 7 vulnerabilities is now available.. openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0254-1 Rating: important References: #1271656 Cross-References: CVE-2026-15899 CVE-2026-15900 CVE-2026-15901 CVE-2026-15902 CVE-2026-15903 CVE-2026-15904 CVE-2026-15905 Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes 7 vulnerabilities is now available. Description: This update for chromium fixes the following issues: - Chromium 150.0.7871.128 (boo#1271656): * CVE-2026-15899: Use after free in CameraCapture * CVE-2026-15900: Use after free in GPU * CVE-2026-15901: Use after free in Network * CVE-2026-15902: Use after free in Cast * CVE-2026-15903: Out of bounds read and write in V8 * CVE-2026-15904: Use after free in Ozone * CVE-2026-15905: Use after free in Aura Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-254=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 ppc64le x86_64): chromedriver-150.0.7871.128-bp157.2.190.1 chromium-150.0.7871.128-bp157.2.190.1 References: https://www.suse.com/security/cve/CVE-2026-15899.html https://www.suse.com/security/cve/CVE-2026-15900.html https://www.suse.com/security/cve/CVE-2026-15901.html https://www.suse.com/security/cve/CVE-2026-15902.html https://www.suse.com/security/cve/CVE-2026-15903.html https://www.suse.com/security/cve/CVE-2026-15904.html https://www.suse.com/security/cve/CVE-2026-15905.html https://bugzilla.suse.com/1271656 . Critical update for openSUSE fixing seven issues in Chromium. Important patches available for vulnerabilities.. openSUSE Security, Chromium Update, Important Security Advisory, Vulnerability Fixes. . Severity: Important. LinuxSecurity.com Team
An update that solves 4 vulnerabilities can now be installed.. # perl-DBI-1.651.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:11298-1 Rating: moderate Cross-References: * CVE-2026-15043 * CVE-2026-15392 * CVE-2026-60081 * CVE-2026-60082 CVSS scores: * CVE-2026-15043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-15043 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-15392 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-60081 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-60082 ( SUSE ): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * openSUSE Tumbleweed An update that solves 4 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the perl-DBI-1.651.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * perl-DBI 1.651.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15043.html * https://www.suse.com/security/cve/CVE-2026-15392.html * https://www.suse.com/security/cve/CVE-2026-60081.html * https://www.suse.com/security/cve/CVE-2026-60082.html . This update resolves four moderate issues in perl-DBI for openSUSE Tumbleweed, enhancing system security significantly.. perl DBI security issues updates. . Severity: moderate. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.