Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in PipeWire.. ========================================================================== Ubuntu Security Notice USN-8535-1 July 13, 2026 pipewire vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in PipeWire. Software Description: - pipewire: Low-latency, graph-based processing engine Details: It was discovered that PipeWire accepted unbounded Content-Length values in its RAOP module. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 24.04 LTS. (CVE-2026-14324) It was discovered that PipeWire performed multiple unbounded stack allocations in its PulseAudio protocol server. A local attacker could possibly use this issue to cause a denial of service. (CVE-2026-14330) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libpipewire-0.3-modules 1.6.2-1ubuntu1.1 libpipewire-0.3-modules-extra 1.6.2-1ubuntu1.1 libpipewire-0.3-modules-x11 1.6.2-1ubuntu1.1 libspa-0.2-modules 1.6.2-1ubuntu1.1 libspa-0.2-modules-extra 1.6.2-1ubuntu1.1 pipewire 1.6.2-1ubuntu1.1 pipewire-bin 1.6.2-1ubuntu1.1 pipewire-pulse 1.6.2-1ubuntu1.1 Ubuntu 24.04 LTS libpipewire-0.3-modules 1.0.5-1ubuntu3.3 libpipewire-0.3-modules-x11 1.0.5-1ubuntu3.3 libspa-0.2-modules 1.0.5-1ubuntu3.3 pipewire 1.0.5-1ubuntu3.3 pipewire-bin 1.0.5-1ubuntu3.3 pipewire-pulse 1.0.5-1ubuntu3.3 Ubuntu 22.04 LTS libpipewire-0.3-modules 0.3.48-1ubuntu3.2 libspa-0.2-modules 0.3.48-1ubuntu3.2 pipewire 0.3.48-1ubuntu3.2 pipewire-bin 0.3.48-1ubuntu3.2 pipewire-pulse 0.3.48-1ubuntu3.2 After a standard system update you need to restart pipewire to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8535-1 CVE-2026-14324, CVE-2026-14330 Package Information: https://launchpad.net/ubuntu/+source/pipewire/1.6.2-1ubuntu1.1 https://launchpad.net/ubuntu/+source/pipewire/1.0.5-1ubuntu3.3 https://launchpad.net/ubuntu/+source/pipewire/0.3.48-1ubuntu3.2 . Discover several security issues fixed in PipeWire affecting Ubuntu 22.04-26.04, including critical denial of service risks.. PipeWire Ubuntu Security Issues Denial of Service CVE-2026-14324. . Severity: Critical. LinuxSecurity.com Team
Frameworks 6.25.0 + KDE Plasma 6.6.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fe3d8d4767 2026-04-16 23:40:54.273526+00:00 -------------------------------------------------------------------------------- Name : kpipewire Product : Fedora 44 Version : 6.6.4 Release : 1.fc44 URL : https://invent.kde.org/plasma/kpipewire Summary : Set of convenient classes to use PipeWire in Qt projects Description : It is developed in C++ and it's main use target is QML components. As it's what's been useful, this framework focuses on graphical PipeWire features. If it was necessary, these could be included. At the moment we offer two main components: - KPipeWire: offers the main components to connect to and render PipeWire into your app. - KPipeWireRecord: using FFmpeg, helps to record a PipeWire video stream into a file. -------------------------------------------------------------------------------- Update Information: Frameworks 6.25.0 + KDE Plasma 6.6.4 -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 10 2026 Steve Cossette - 6.6.4-1 - 6.6.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455469 - Configuring WifI network via Network pane appears to not work https://bugzilla.redhat.com/show_bug.cgi?id=2455469 [ 2 ] Bug #2457573 - FE: KDE Frameworks 6.25.0 + Plasma 6.6.4 https://bugzilla.redhat.com/show_bug.cgi?id=2457573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fe3d8d4767' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key.More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-0132 http://linux.oracle.com/errata/ELSA-2025-0132.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: firefox-128.6.0-1.0.1.el7_9.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates//firefox-128.6.0-1.0.1.el7_9.src.rpm Related CVEs: CVE-2025-0237 CVE-2025-0238 CVE-2025-0239 CVE-2025-0240 CVE-2025-0241 CVE-2025-0242 CVE-2025-0243 Description of changes: [128.6.0-1.0.1] - Update to 128.6.0 build1 [Orabug: 37460830][CVE-2025-0237][CVE-2025-0238] [CVE-2025-0239][CVE-2025-0240][CVE-2025-0241][CVE-2025-0242][CVE-2025-0243] - Enable PipeWire camera support for RHEL 10 + backport upstream fixes for PipeWire camera support Fixes: RHEL-64749 _______________________________________________ El-errata mailing list
This update for pipewire fixes the following security issues: Fixed issue where an app which only has permission to access one stream can also access other streams (bsc#1213682).. # Security update for pipewire Announcement ID: SUSE-SU-2023:3256-1 Rating: moderate References: * #1213682 Affected Products: * Desktop Applications Module 15-SP4 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 * SUSE Package Hub 15 15-SP4 An update that has one fix can now be installed. ## Description: This update for pipewire fixes the following security issues: * Fixed issue where an app which only has permission to access one stream can also access other streams (bsc#1213682). Bugfixes: \- Fixed division by 0 and other issues with invalid values (glfo#pipewire/pipewire#2953) \- Fixed an overflow resulting in choppy sound in some cases (glfo#pipewire/pipewire#2680) ## Patch Instructions: To install this SUSE Moderate update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2023-3256=1 openSUSE-SLE-15.4-2023-3256=1 * Desktop Applications Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP4-2023-3256=1 * SUSE Package Hub 15 15-SP4 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2023-3256=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libpipewire-0_3-0-0.3.49-150400.3.3.1 * pipewire-0.3.49-150400.3.3.1 * pipewire-modules-0_3-0.3.49-150400.3.3.1 *pipewire-libjack-0_3-debuginfo-0.3.49-150400.3.3.1 * pipewire-alsa-debuginfo-0.3.49-150400.3.3.1 * pipewire-pulseaudio-debuginfo-0.3.49-150400.3.3.1 * pipewire-spa-plugins-0_2-debuginfo-0.3.49-150400.3.3.1 * pipewire-spa-plugins-0_2-0.3.49-150400.3.3.1 * pipewire-doc-0.3.49-150400.3.3.1 * pipewire-spa-tools-0.3.49-150400.3.3.1 * libpipewire-0_3-0-debuginfo-0.3.49-150400.3.3.1 * pipewire-alsa-0.3.49-150400.3.3.1 * pipewire-modules-0_3-debuginfo-0.3.49-150400.3.3.1 * pipewire-devel-0.3.49-150400.3.3.1 * pipewire-tools-0.3.49-150400.3.3.1 * pipewire-pulseaudio-0.3.49-150400.3.3.1 * gstreamer-plugin-pipewire-debuginfo-0.3.49-150400.3.3.1 * pipewire-debugsource-0.3.49-150400.3.3.1 * gstreamer-plugin-pipewire-0.3.49-150400.3.3.1 * pipewire-libjack-0_3-0.3.49-150400.3.3.1 * pipewire-spa-tools-debuginfo-0.3.49-150400.3.3.1 * pipewire-debuginfo-0.3.49-150400.3.3.1 * pipewire-libjack-0_3-devel-0.3.49-150400.3.3.1 * pipewire-tools-debuginfo-0.3.49-150400.3.3.1 * openSUSE Leap 15.4 (x86_64) * pipewire-modules-0_3-32bit-debuginfo-0.3.49-150400.3.3.1 * libpipewire-0_3-0-32bit-debuginfo-0.3.49-150400.3.3.1 * pipewire-modules-0_3-32bit-0.3.49-150400.3.3.1 * pipewire-libjack-0_3-32bit-0.3.49-150400.3.3.1 * pipewire-spa-plugins-0_2-32bit-debuginfo-0.3.49-150400.3.3.1 * pipewire-alsa-32bit-debuginfo-0.3.49-150400.3.3.1 * pipewire-libjack-0_3-32bit-debuginfo-0.3.49-150400.3.3.1 * pipewire-spa-plugins-0_2-32bit-0.3.49-150400.3.3.1 * libpipewire-0_3-0-32bit-0.3.49-150400.3.3.1 * pipewire-alsa-32bit-0.3.49-150400.3.3.1 * openSUSE Leap 15.4 (noarch) * pipewire-lang-0.3.49-150400.3.3.1 * openSUSE Leap 15.4 (aarch64_ilp32) * pipewire-spa-plugins-0_2-64bit-0.3.49-150400.3.3.1 * pipewire-libjack-0_3-64bit-0.3.49-150400.3.3.1 * pipewire-modules-0_3-64bit-0.3.49-150400.3.3.1 * pipewire-libjack-0_3-64bit-debuginfo-0.3.49-150400.3.3.1 *pipewire-spa-plugins-0_2-64bit-debuginfo-0.3.49-150400.3.3.1 * pipewire-alsa-64bit-debuginfo-0.3.49-150400.3.3.1 * libpipewire-0_3-0-64bit-debuginfo-0.3.49-150400.3.3.1 * pipewire-alsa-64bit-0.3.49-150400.3.3.1 * libpipewire-0_3-0-64bit-0.3.49-150400.3.3.1 * pipewire-modules-0_3-64bit-debuginfo-0.3.49-150400.3.3.1 * Desktop Applications Module 15-SP4 (aarch64 ppc64le s390x x86_64) * pipewire-debugsource-0.3.49-150400.3.3.1 * pipewire-spa-plugins-0_2-debuginfo-0.3.49-150400.3.3.1 * pipewire-modules-0_3-debuginfo-0.3.49-150400.3.3.1 * gstreamer-plugin-pipewire-0.3.49-150400.3.3.1 * pipewire-spa-tools-debuginfo-0.3.49-150400.3.3.1 * pipewire-spa-plugins-0_2-0.3.49-150400.3.3.1 * pipewire-debuginfo-0.3.49-150400.3.3.1 * pipewire-0.3.49-150400.3.3.1 * libpipewire-0_3-0-debuginfo-0.3.49-150400.3.3.1 * libpipewire-0_3-0-0.3.49-150400.3.3.1 * pipewire-modules-0_3-0.3.49-150400.3.3.1 * pipewire-tools-0.3.49-150400.3.3.1 * pipewire-spa-tools-0.3.49-150400.3.3.1 * gstreamer-plugin-pipewire-debuginfo-0.3.49-150400.3.3.1 * pipewire-tools-debuginfo-0.3.49-150400.3.3.1 * Desktop Applications Module 15-SP4 (noarch) * pipewire-lang-0.3.49-150400.3.3.1 * SUSE Package Hub 15 15-SP4 (aarch64 ppc64le s390x x86_64) * pipewire-debugsource-0.3.49-150400.3.3.1 * pipewire-alsa-0.3.49-150400.3.3.1 * pipewire-pulseaudio-debuginfo-0.3.49-150400.3.3.1 * pipewire-libjack-0_3-0.3.49-150400.3.3.1 * pipewire-doc-0.3.49-150400.3.3.1 * pipewire-debuginfo-0.3.49-150400.3.3.1 * pipewire-libjack-0_3-devel-0.3.49-150400.3.3.1 * pipewire-pulseaudio-0.3.49-150400.3.3.1 * pipewire-libjack-0_3-debuginfo-0.3.49-150400.3.3.1 * pipewire-alsa-debuginfo-0.3.49-150400.3.3.1 * SUSE Package Hub 15 15-SP4 (noarch) * pipewire-lang-0.3.49-150400.3.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1213682 . The latest pipewire update addresses critical security vulnerabilities, enhancing application accessmanagement while bolstering the system’s overall security framework.. PipeWire Security, Software Update, Access Control Issues. . LinuxSecurity.com Team
This update for pipewire fixes the following security issues: Fixed issue where an app which only has permission to access one stream can also access other streams (bsc#1213682).. # Security update for pipewire Announcement ID: SUSE-SU-2023:3257-1 Rating: moderate References: * #1213682 Affected Products: * Desktop Applications Module 15-SP5 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Package Hub 15 15-SP5 An update that has one fix can now be installed. ## Description: This update for pipewire fixes the following security issues: * Fixed issue where an app which only has permission to access one stream can also access other streams (bsc#1213682). Bugfixes: \- Fixed division by 0 and other issues with invalid values (glfo#pipewire/pipewire#2953) \- Fixed an overflow resulting in choppy sound in some cases (glfo#pipewire/pipewire#2680) ## Patch Instructions: To install this SUSE Moderate update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2023-3257=1 openSUSE-SLE-15.5-2023-3257=1 * Desktop Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP5-2023-3257=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2023-3257=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * libpipewire-0_3-0-0.3.64-150500.3.3.1 * pipewire-modules-0_3-debuginfo-0.3.64-150500.3.3.1 * pipewire-modules-0_3-0.3.64-150500.3.3.1 * gstreamer-plugin-pipewire-0.3.64-150500.3.3.1 * pipewire-libjack-0_3-0.3.64-150500.3.3.1 *pipewire-libjack-0_3-debuginfo-0.3.64-150500.3.3.1 * pipewire-tools-debuginfo-0.3.64-150500.3.3.1 * pipewire-spa-plugins-0_2-debuginfo-0.3.64-150500.3.3.1 * pipewire-alsa-debuginfo-0.3.64-150500.3.3.1 * pipewire-tools-0.3.64-150500.3.3.1 * pipewire-debuginfo-0.3.64-150500.3.3.1 * pipewire-doc-0.3.64-150500.3.3.1 * pipewire-spa-tools-0.3.64-150500.3.3.1 * pipewire-alsa-0.3.64-150500.3.3.1 * pipewire-spa-tools-debuginfo-0.3.64-150500.3.3.1 * libpipewire-0_3-0-debuginfo-0.3.64-150500.3.3.1 * pipewire-pulseaudio-debuginfo-0.3.64-150500.3.3.1 * pipewire-module-x11-0_3-0.3.64-150500.3.3.1 * pipewire-debugsource-0.3.64-150500.3.3.1 * pipewire-module-x11-0_3-debuginfo-0.3.64-150500.3.3.1 * pipewire-0.3.64-150500.3.3.1 * gstreamer-plugin-pipewire-debuginfo-0.3.64-150500.3.3.1 * pipewire-libjack-0_3-devel-0.3.64-150500.3.3.1 * pipewire-pulseaudio-0.3.64-150500.3.3.1 * pipewire-spa-plugins-0_2-0.3.64-150500.3.3.1 * pipewire-devel-0.3.64-150500.3.3.1 * openSUSE Leap 15.5 (x86_64) * pipewire-libjack-0_3-32bit-0.3.64-150500.3.3.1 * pipewire-alsa-32bit-debuginfo-0.3.64-150500.3.3.1 * pipewire-libjack-0_3-32bit-debuginfo-0.3.64-150500.3.3.1 * libpipewire-0_3-0-32bit-debuginfo-0.3.64-150500.3.3.1 * pipewire-alsa-32bit-0.3.64-150500.3.3.1 * libpipewire-0_3-0-32bit-0.3.64-150500.3.3.1 * pipewire-modules-0_3-32bit-debuginfo-0.3.64-150500.3.3.1 * pipewire-spa-plugins-0_2-32bit-debuginfo-0.3.64-150500.3.3.1 * pipewire-modules-0_3-32bit-0.3.64-150500.3.3.1 * pipewire-spa-plugins-0_2-32bit-0.3.64-150500.3.3.1 * openSUSE Leap 15.5 (noarch) * pipewire-lang-0.3.64-150500.3.3.1 * openSUSE Leap 15.5 (aarch64_ilp32) * pipewire-spa-plugins-0_2-64bit-debuginfo-0.3.64-150500.3.3.1 * libpipewire-0_3-0-64bit-debuginfo-0.3.64-150500.3.3.1 * libpipewire-0_3-0-64bit-0.3.64-150500.3.3.1 * pipewire-alsa-64bit-0.3.64-150500.3.3.1 * pipewire-modules-0_3-64bit-0.3.64-150500.3.3.1 *pipewire-spa-plugins-0_2-64bit-0.3.64-150500.3.3.1 * pipewire-libjack-0_3-64bit-debuginfo-0.3.64-150500.3.3.1 * pipewire-libjack-0_3-64bit-0.3.64-150500.3.3.1 * pipewire-alsa-64bit-debuginfo-0.3.64-150500.3.3.1 * pipewire-modules-0_3-64bit-debuginfo-0.3.64-150500.3.3.1 * Desktop Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * pipewire-debugsource-0.3.64-150500.3.3.1 * pipewire-spa-plugins-0_2-debuginfo-0.3.64-150500.3.3.1 * pipewire-0.3.64-150500.3.3.1 * libpipewire-0_3-0-0.3.64-150500.3.3.1 * gstreamer-plugin-pipewire-debuginfo-0.3.64-150500.3.3.1 * pipewire-spa-tools-debuginfo-0.3.64-150500.3.3.1 * pipewire-tools-0.3.64-150500.3.3.1 * pipewire-modules-0_3-debuginfo-0.3.64-150500.3.3.1 * pipewire-tools-debuginfo-0.3.64-150500.3.3.1 * libpipewire-0_3-0-debuginfo-0.3.64-150500.3.3.1 * pipewire-debuginfo-0.3.64-150500.3.3.1 * pipewire-modules-0_3-0.3.64-150500.3.3.1 * gstreamer-plugin-pipewire-0.3.64-150500.3.3.1 * pipewire-spa-plugins-0_2-0.3.64-150500.3.3.1 * pipewire-spa-tools-0.3.64-150500.3.3.1 * Desktop Applications Module 15-SP5 (noarch) * pipewire-lang-0.3.64-150500.3.3.1 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * pipewire-debugsource-0.3.64-150500.3.3.1 * pipewire-alsa-0.3.64-150500.3.3.1 * pipewire-alsa-debuginfo-0.3.64-150500.3.3.1 * pipewire-libjack-0_3-devel-0.3.64-150500.3.3.1 * pipewire-pulseaudio-0.3.64-150500.3.3.1 * pipewire-debuginfo-0.3.64-150500.3.3.1 * pipewire-doc-0.3.64-150500.3.3.1 * pipewire-libjack-0_3-0.3.64-150500.3.3.1 * pipewire-libjack-0_3-debuginfo-0.3.64-150500.3.3.1 * pipewire-pulseaudio-debuginfo-0.3.64-150500.3.3.1 * SUSE Package Hub 15 15-SP5 (noarch) * pipewire-lang-0.3.64-150500.3.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1213682 . The latest Pipewire patch resolves stream accessibility problems and multiple bugs in openSUSE. Keep your system secure and up-to-date!. openSUSE Updates,Pipewire Security, Stream Access Issues. . LinuxSecurity.com Team
This update for pipewire fixes the following security issues: Fixed issue where an app which only has permission to access one stream can also access other streams (bsc#1213682).. # Security update for pipewire Announcement ID: SUSE-SU-2023:3185-1 Rating: moderate References: * #1213682 Affected Products: * openSUSE Leap 15.4 An update that has one fix can now be installed. ## Description: This update for pipewire fixes the following security issues: * Fixed issue where an app which only has permission to access one stream can also access other streams (bsc#1213682). Bugfixes: \- Fixed division by 0 and other issues with invalid values (glfo#pipewire/pipewire#2953) \- Fixed an overflow resulting in choppy sound in some cases (glfo#pipewire/pipewire#2680) ## Patch Instructions: To install this SUSE Moderate update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3185=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * pipewire-modules-0.3.24-150300.4.6.1 * pipewire-modules-debuginfo-0.3.24-150300.4.6.1 * openSUSE Leap 15.4 (x86_64) * pipewire-modules-32bit-debuginfo-0.3.24-150300.4.6.1 * pipewire-modules-32bit-0.3.24-150300.4.6.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1213682 . The recent security advisory for PipeWire outlines critical issues with stream access controls, urging users to update for enhanced protection against unauthorized access.. openSUSE Pipewire Update, Moderate Security Advisory, App Access Security. . LinuxSecurity.com Team
This update for pipewire fixes the following security issues: Fixed issue where an app which only has permission to access one stream can also access other streams (bsc#1213682).. # Security update for pipewire Announcement ID: SUSE-SU-2023:3097-1 Rating: moderate References: * #1213682 Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 * SUSE Package Hub 15 15-SP4 * SUSE Package Hub 15 15-SP5 An update that has one fix can now be installed. ## Description: This update for pipewire fixes the following security issues: * Fixed issue where an app which only has permission to access one stream can also access other streams (bsc#1213682). Bugfixes: \- Fixed division by 0 and other issues with invalid values (glfo#pipewire/pipewire#2953) \- Fixed an overflow resulting in choppy sound in some cases (glfo#pipewire/pipewire#2680) ## Patch Instructions: To install this SUSE Moderate update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3097=1 * SUSE Package Hub 15 15-SP4 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2023-3097=1 * SUSE Package Hub 15 15-SP5 zypper in -t patchSUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2023-3097=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * pipewire-libpulse-0_3-debuginfo-0.3.6-150200.3.9.1 * pipewire-libpulse-0_3-0.3.6-150200.3.9.1 * SUSE Package Hub 15 15-SP4 (aarch64 ppc64le s390x x86_64) * pipewire-libpulse-0_3-debuginfo-0.3.6-150200.3.9.1 * pipewire-debugsource-0.3.6-150200.3.9.1 * pipewire-debuginfo-0.3.6-150200.3.9.1 * pipewire-libpulse-0_3-0.3.6-150200.3.9.1 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * pipewire-libpulse-0_3-debuginfo-0.3.6-150200.3.9.1 * pipewire-debugsource-0.3.6-150200.3.9.1 * pipewire-debuginfo-0.3.6-150200.3.9.1 * pipewire-libpulse-0_3-0.3.6-150200.3.9.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1213682 . A new patch release for PipeWire resolves the stream access problem affecting openSUSE, categorized as moderate severity.. Pipewire Security Update, openSUSE Patch, Moderate Advisory. . LinuxSecurity.com Team
- Update to the latest upstream (Firefox 63) - Updated PipeWire support. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-f716c8f9e6 2018-10-25 22:10:46.745244 --------------------------------------------------------------------------------Name : firefox Product : Fedora 28 Version : 63.0 Release : 2.fc28 URL : https://www.firefox.com/en-US/?redirect_source=mozilla-org Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. --------------------------------------------------------------------------------Update Information: - Update to the latest upstream (Firefox 63) - Updated PipeWire support --------------------------------------------------------------------------------ChangeLog: * Tue Oct 23 2018 Martin Stransky - 63.0-2 - Updated to latest upstream (63.0 build 2) * Thu Oct 18 2018 Martin Stransky - 63.0-1 - Updated to latest upstream (63.0) - Updated PipeWire patch * Tue Oct 9 2018 Martin Stransky - 62.0.3-4 - Added fix for mozbz#1447775 - wrong dropspace sizing. * Tue Oct 9 2018 Martin Stransky - 62.0.3-3 - Added fix for mozbz#1493081 - popups incorrectly placed and sized. * Mon Oct 8 2018 Martin Stransky - 62.0.3-2 - Added pipewire patch (mozbz#1496359) - Added Wayland patches from Firefox 63 - Enable Wayland backed by default on Fedora 30 * Tue Oct 2 2018 Martin Stransky - 62.0.3-1 - Updated to latest upstream (62.0.3) * Wed Sep 26 2018 Martin Stransky - 62.0.2-3 - Enabled DBus remote for all Gtk+ backends - Removed obsoleted patches * Tue Sep 25 2018 Martin Stransky - 62.0.2-2 - Disable workaround for mozbz#1342344 - GFX glitches when building with -O3/gcc 7.2 * Mon Sep 24 2018 Jan Horak - 62.0.2-1 - Update to 62.0.2 * Mon Sep 17 2018 Martin Stransky - 62.0-3 - Added spellchecker.dictionary_path pref pointer to/usr/share/myspell. Thanks to Peter Oliver (rhbz#1627837) * Tue Sep 4 2018 Martin Stransky - 62.0-2 - Update to 62.0 (Build 2) * Tue Aug 28 2018 Martin Stransky - 62.0-1 - Update to 62.0 * Wed Aug 15 2018 Ondrej Zoder - 61.0.2-3 - Added patches for mozbz#1427700 and mozbz#1463809 * Mon Aug 13 2018 Ondrej Zoder - 61.0.2-2 - Updated symbolic icon * Thu Aug 9 2018 Martin Stransky - 61.0.2-1 - Update to 61.0.2 * Wed Aug 1 2018 Ondrej Zoder - 61.0.1-4 - Fixed rhbz#1610428 * Tue Jul 17 2018 Ondrej Zoder - 61.0.1-3 - Bump release * Fri Jul 13 2018 Fedora Release Engineering - 61.0.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Tue Jul 10 2018 Ondrej Zoder - 61.0.1 - Update to 61.0.1 * Mon Jun 25 2018 Martin Stransky - 61.0-4 - Disabled mozbz#1424422 as it's broken. * Fri Jun 22 2018 Martin Stransky - 61.0-3 - Update to 61.0 Build 3 * Thu Jun 21 2018 Martin Stransky - 61.0-2 - Disabled system hunspell due to rhbz#1593494 * Tue Jun 19 2018 Martin Stransky - 61.0-1 - Updated to 61.0 - Created firefox-wayland subpackage with wayland launcher. * Mon Jun 11 2018 Jan Horak - 60.0.2-1 - Update to 60.0.2 * Mon Jun 4 2018 Martin Stransky - 60.0.1-6 - Fixed mozbz#1466473, rhbz#1585300 - Fix GL detection. - Fixed desktop file names (rhbz#1585369). * Wed May 30 2018 Martin Stransky - 60.0.1-5 - Added workaround for mozbz#1464823 which makes GL layer compositor usable on Wayland. * Tue May 29 2018 Martin Stransky - 60.0.1-4 - Added fix for mozbz#1464808 - Set default D&D action to move on Wayland. * Fri May 25 2018 Martin Stransky - 60.0.1-3 - Added fix for mozbz#1436242 (rhbz#1577277) - Firefox IPC crashes. - Added fix for mozbz#1462640 - Sandbox disables eglGetDisplay() call on Wayland/EGL backend. * Fri May 25 2018 Martin Stransky - 60.0.1-2 - Enable Wayland backend. * Wed May 23 2018 Jan Horak - 60.0.1-1 - Update to 60.0.1 * Wed May 16 2018 Martin Stransky - 60.0-6 - Added patch from rhbz#1498561 -second arch (ppc*) crashes. * Wed May 16 2018 Martin Stransky - 60.0-5 - Disabled jemalloc on second arches. * Thu May 3 2018 Martin Stransky - 60.0-4 - Updated to Firefox 60 build 2 * Thu May 3 2018 Martin Stransky - 60.0-3 - Added patch from mozbz#1375074 - fixes aarch64 baseline JIT crashes * Thu May 3 2018 Martin Stransky - 60.0-2 - Make Wayland backend optional and disable it by default due to WebGL issues. * Wed May 2 2018 Martin Stransky - 60.0-1 - Update to Firefox 60 build 1 - Ship firefox-wayland launch script * Mon Apr 30 2018 Martin Stransky - 60.0-0.5 - Build with Wayland backend enabled. * Mon Apr 30 2018 Martin Stransky - 60.0-0.4 - Added patches for correct popups position at CSD mode (mozilla-1457691). * Fri Apr 27 2018 Martin Stransky - 60.0-0.2 - Update to 60.0 Beta 16 * Tue Apr 24 2018 Martin Stransky - 60.0-0.1 - Update to 60.0 Beta 15 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-f716c8f9e6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.