Explore top 10 tips to secure your open-source projects now. Read More
×An update that can now be installed.. # Security update for cosign Announcement ID: SUSE-SU-2026:1486-1 Release Date: 2026-04-20T15:51:24Z Rating: important References: Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for cosign rebuilds it against the current go 1.25 security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1486=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1486=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1486=1 * SUSE Linux EnterpriseServer 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1486=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1486=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1486=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1486=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-1486=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1486=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1486=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-1486=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1486=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * cosign-3.0.5-150400.3.39.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * cosign-3.0.5-150400.3.39.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * cosign-3.0.5-150400.3.39.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.0.5-150400.3.39.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.0.5-150400.3.39.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * cosign-debuginfo-3.0.5-150400.3.39.1 * cosign-3.0.5-150400.3.39.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * cosign-3.0.5-150400.3.39.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * cosign-3.0.5-150400.3.39.1 * SUSE Linux Enterprise Server for SAP Applications15 SP6 (ppc64le x86_64) * cosign-debuginfo-3.0.5-150400.3.39.1 * cosign-3.0.5-150400.3.39.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * cosign-debuginfo-3.0.5-150400.3.39.1 * cosign-3.0.5-150400.3.39.1 * openSUSE Leap 15.4 (noarch) * cosign-bash-completion-3.0.5-150400.3.39.1 * cosign-zsh-completion-3.0.5-150400.3.39.1 * cosign-fish-completion-3.0.5-150400.3.39.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cosign-debuginfo-3.0.5-150400.3.39.1 * cosign-3.0.5-150400.3.39.1 * Basesystem Module 15-SP7 (noarch) * cosign-bash-completion-3.0.5-150400.3.39.1 * cosign-zsh-completion-3.0.5-150400.3.39.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * cosign-3.0.5-150400.3.39.1 . Important security update for cosign in openSUSE with key patch installation instructions for various systems.. security update, cosign, important update, openSUSE patch. . Severity: Important. LinuxSecurity.com Team
cargo-c could be made to modify permissions on arbitrary directories.. ========================================================================== Ubuntu Security Notice USN-8139-1 April 01, 2026 rust-cargo-c vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 Summary: cargo-c could be made to modify permissions on arbitrary directories. Software Description: - rust-cargo-c: Helper program to build and install c-like libraries Details: It was discovered that tar-rs embedded in cargo-c incorrectly handled symlinks when unpacking a tar archive. If a user or automated system were tricked into processing a specially crafted tar archive, a remote attacker could use this issue to modify permissions of arbitrary directories outside the extraction root, and possibly escalate privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 cargo-c 0.10.11-1ubuntu1.1 librust-cargo-c-dev 0.10.11-1ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8139-1 CVE-2026-33056 Package Information: https://launchpad.net/ubuntu/+source/rust-cargo-c/0.10.11-1ubuntu1.1 . Cargo-c vulnerability on Ubuntu allows permission modifications on directories, posing a risk to system integrity. Update recommended.. cargo-c vulnerability, Ubuntu security, rust-cargo-c, permission escalation, remote access. . Severity: Important. LinuxSecurity.com Team
An update that solves five vulnerabilities and contains three features can now be installed.. # Security update for grafana Announcement ID: SUSE-SU-2025:0545-1 Release Date: 2025-02-14T07:24:23Z Rating: moderate References: * bsc#1212641 * bsc#1219912 * bsc#1231024 * bsc#1234554 * bsc#1236301 * jsc#MSQA-914 * jsc#PED-11591 * jsc#PED-11649 Cross-References: * CVE-2023-3128 * CVE-2023-6152 * CVE-2024-45337 * CVE-2024-6837 * CVE-2024-8118 CVSS scores: * CVE-2023-3128 ( SUSE ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L * CVE-2023-3128 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L * CVE-2023-3128 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6152 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2023-6152 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2023-6152 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2024-45337 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45337 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2024-6837 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-6837 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-8118 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2024-8118 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves five vulnerabilities and contains three features can now be installed. ## Description: This update for grafana fixes the following issues: grafana was updatedfrom version 9.5.18 to 10.4.13 (jsc#PED-11591,jsc#PED-11649): * Security issues fixed: * CVE-2024-45337: Prevent possible misuse of ServerConfig.PublicKeyCallback by upgrading golang.org/x/crypto (bsc#1234554) * CVE-2023-3128: Fixed authentication bypass using Azure AD OAuth (bsc#1212641) * CVE-2023-6152: Add email verification when updating user email (bsc#1219912) * CVE-2024-6837: Fixed potential data source permission escalation (bsc#1236301) * CVE-2024-8118: Fixed permission on external alerting rule write endpoint (bsc#1231024) * Potential breaking changes in version 10: * In panels using the `extract fields` transformation, where one of the extracted names collides with one of the already existing ields, the extracted field will be renamed. * For the existing backend mode users who have table visualization might see some inconsistencies on their panels. We have updated the table column naming. This will potentially affect field transformations and/or field overrides. To resolve this either: update transformation or field override. * For the existing backend mode users who have Transformations with the `time` field, might see their transformations are not working. Those panels that have broken transformations will fail to render. This is because we changed the field key. To resolve this either: Remove the affected panel and re- create it; Select the `Time` field again; Edit the `time` field as `Time` for transformation in `panel.json` or `dashboard.json` * The following data source permission endpoints have been removed: `GET /datasources/:datasourceId/permissions` `POST /api/datasources/:datasourceId/permissions` `DELETE /datasources/:datasourceId/permissions` `POST /datasources/:datasourceId/enable-permissions` `POST /datasources/:datasourceId/disable-permissions` * Please use the following endpoints instead: `GET /api/access-control/datasources/:uid` for listing data source permissions `POST/api/access-control/datasources/:uid/users/:id`, `POST /api/access-control/datasources/:uid/teams/:id` and `POST /api/access-control/datasources/:uid/buildInRoles/:id` for adding or removing data source permissions * If you are using Terraform Grafana provider to manage data source permissions, you will need to upgrade your provider. * For the existing backend mode users who have table visualization might see some inconsistencies on their panels. We have updated the table column naming. This will potentially affect field transformations and/or field overrides. * The deprecated `/playlists/{uid}/dashboards` API endpoint has been removed. Dashboard information can be retrieved from the `/dashboard/...` APIs. * The `PUT /api/folders/:uid` endpoint no more supports modifying the folder's `UID` * Removed all components for the old panel header design. * Please review changes/breaking-changes-v10-3/ for more details * OAuth role mapping enforcement: This change impacts GitHub, Gitlab, Okta, and Generic OAuth. To avoid overriding manually set roles, enable the skip_org_role_sync option in the Grafana configuration for your OAuth provider before upgrading * Angular has been deprecated * Grafana legacy alerting has been deprecated * API keys are migrating to service accounts * The experimental “dashboard previews” feature is removed * Usernames are now case-insensitive by default * Grafana OAuth integrations do not work anymore with email lookups * The “Alias” field in the CloudWatch data source is removed * Athena data source plugin must be updated to version > =2.9.3 * Redshift data source plugin must be updated to version > =1.8.3 * DoiT International BigQuery plugin no longer supported * Please review changes/breaking-changes-v10-0 for more details * This update brings many new features, enhancements and fixes highlighted at: * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v10-4/ *https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v10-3/ * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v10-2/ * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v10-1/ * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v10-0/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-545=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-545=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * grafana-10.4.13-150200.3.59.1 * grafana-debuginfo-10.4.13-150200.3.59.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * grafana-10.4.13-150200.3.59.1 * grafana-debuginfo-10.4.13-150200.3.59.1 ## References: * https://www.suse.com/security/cve/CVE-2023-3128.html * https://www.suse.com/security/cve/CVE-2023-6152.html * https://www.suse.com/security/cve/CVE-2024-45337.html * https://www.suse.com/security/cve/CVE-2024-6837.html * https://www.suse.com/security/cve/CVE-2024-8118.html * https://bugzilla.suse.com/show_bug.cgi?id=1212641 * https://bugzilla.suse.com/show_bug.cgi?id=1219912 * https://bugzilla.suse.com/show_bug.cgi?id=1231024 * https://bugzilla.suse.com/show_bug.cgi?id=1234554 * https://bugzilla.suse.com/show_bug.cgi?id=1236301 * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FMSQA-914&page_caps=&user_role= * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-11591&page_caps=&user_role= * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-11649&page_caps=&user_role= . This bulletin details the software patch for Grafana on openSUSE, focusing on a number of moderate vulnerabilities.. grafana SecurityUpdate, SUSE Advisory, openSUSE grafana. . LinuxSecurity.com Team
Security fix for CVE-2023-27320. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-11c9d868ca 2023-03-15 00:16:12.054737 --------------------------------------------------------------------------------Name : sudo Product : Fedora 38 Version : 1.9.13 Release : 1.p2.fc38 URL : Summary : Allows restricted root access for specified users Description : Sudo (superuser do) allows a system administrator to give certain users (or groups of users) the ability to run some (or all) commands as root while logging all commands and arguments. Sudo operates on a per-command basis. It is not a replacement for the shell. Features include: the ability to restrict what commands a user may run on a per-host basis, copious logging of each command (providing a clear audit trail of who did what), a configurable timeout of the sudo command, and the ability to use the same configuration file (sudoers) on many different machines. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2023-27320 --------------------------------------------------------------------------------ChangeLog: * Wed Mar 1 2023 Radovan Sroka - 1.9.13-1.p2 - Rebase to sudo 1.9.13p2 - sudo-1.9.13p2 is available Resolves: rhbz#2169840 - sudo: double free with per-command chroot sudoers rules Resolves: CVE-2023-27320 --------------------------------------------------------------------------------References: [ 1 ] Bug #2174218 - CVE-2023-27320 sudo: double free with per-command chroot sudoers rules https://bugzilla.redhat.com/show_bug.cgi?id=2174218 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-11c9d868ca' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
man-db could be made to overwrite file and directory permissions.. =========================================================================Ubuntu Security Notice USN-5334-1 March 17, 2022 man-db vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: man-db could be made to overwrite file and directory permissions. Software Description: - man-db: on-line manual pager Details: It was discovered that man-db incorrectly handled permission changing operations in its daily cron job, and was therefore affected by a race condition. An attacker could possibly use this issue to escalate privileges and execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: man-db 2.7.5-1ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5334-1 CVE-2015-1336 . Impacts Ubuntu 16.04 ESM: man-db could permit permission overrides and elevated privileges via a race condition.. Ubuntu Security Notice, man-db exploit, permission exploit. . Severity: Important. LinuxSecurity.com Team
update to 2.2.16, CVE-2020-24583, CVE-2020-24584. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-6941c0a65b 2020-09-12 16:36:51.588630 --------------------------------------------------------------------------------Name : python-django Product : Fedora 31 Version : 2.2.16 Release : 1.fc31 URL : http://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. --------------------------------------------------------------------------------Update Information: update to 2.2.16, CVE-2020-24583, CVE-2020-24584 --------------------------------------------------------------------------------ChangeLog: * Thu Sep 3 2020 Matthias Runge - 2.2.16-1 - update to 2.2.16, CVE-2020-24583, CVE-2020-24584 --------------------------------------------------------------------------------References: [ 1 ] Bug #1874492 - CVE-2020-24584 django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+ https://bugzilla.redhat.com/show_bug.cgi?id=1874492 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-6941c0a65b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list
update to 3.0.10, fixes CVE-2020-24583, CVE-2020-24584. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-94407454d7 2020-09-12 16:33:14.830442 --------------------------------------------------------------------------------Name : python-django Product : Fedora 32 Version : 3.0.10 Release : 3.fc32 URL : https://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. --------------------------------------------------------------------------------Update Information: update to 3.0.10, fixes CVE-2020-24583, CVE-2020-24584 --------------------------------------------------------------------------------ChangeLog: * Thu Sep 3 2020 Matthias Runge - 3.0.10-1 - update to 3.0.10, fixes CVE-2020-24583, CVE-2020-24584 (rhbz#1874487, rhbz#1874494) * Wed Jul 29 2020 Fedora Release Engineering - 3.0.7-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Wed Jun 24 2020 Michel Alexandre Salim - 3.0.7-2 - Add BR on setuptools --------------------------------------------------------------------------------References: [ 1 ] Bug #1874485 - CVE-2020-24583 django: incorrect permissions on intermediate-level directories on Python 3.7+ https://bugzilla.redhat.com/show_bug.cgi?id=1874485 [ 2 ] Bug #1874492 - CVE-2020-24584 django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+ https://bugzilla.redhat.com/show_bug.cgi?id=1874492 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-94407454d7' at the command line. For more information, referto the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
A vulnerability was found in the EC2 credentials API of Keystone, the OpenStack identity service: Any user authenticated within a limited scope (trust/oauth/application credential) could create an EC2 credential with an escalated permission, such as obtaining "admin" while . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4679-1
Get the latest Linux and open source security news straight to your inbox.