Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Update to 143.0.7499.192 [rhbz#2427842] * High CVE-2026-0628: Insufficient policy enforcement in WebView tag. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-77e3579a49 2026-01-21 01:10:49.670808+00:00 -------------------------------------------------------------------------------- Name : cef Product : Fedora 43 Version : 143.0.13^chromium143.0.7499.192 Release : 1.fc43 URL : https://bitbucket.org/chromiumembedded/cef Summary : Chromium Embedded Framework Description : CEF is an embeddable build of Chromium, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 143.0.7499.192 [rhbz#2427842] * High CVE-2026-0628: Insufficient policy enforcement in WebView tag -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 9 2026 Than Ngo - 143.0.13^chromium143.0.7499.192-1 - Update to 143.0.7499.192 [rhbz#2427842] - * High CVE-2026-0628: Insufficient policy enforcement in WebView tag - Fix rhbz#2425338, Enable control flow integrity support for x86_64/aarch64 - Enable build for epel10.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2427842 - cef-143.0.14 is available https://bugzilla.redhat.com/show_bug.cgi?id=2427842 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-77e3579a49' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 138.0.7204.49 CVE-2025-6555: Use after free in Animation CVE-2025-6556: Insufficient policy enforcement in Loader CVE-2025-6557: Insufficient data validation in DevTools. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e4b1668bdd 2025-06-28 01:45:12.871378+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 41 Version : 138.0.7204.49 Release : 1.fc41 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 138.0.7204.49 CVE-2025-6555: Use after free in Animation CVE-2025-6556: Insufficient policy enforcement in Loader CVE-2025-6557: Insufficient data validation in DevTools -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 24 2025 Than Ngo - 138.0.7204.49-1 - Update to 138.0.7204.49 * CVE-2025-6555: Use after free in Animation * CVE-2025-6556: Insufficient policy enforcement in Loader * CVE-2025-6557: Insufficient data validation in DevTools -------------------------------------------------------------------------------- References: [ 1 ] Bug #2374686 - CVE-2025-6555 chromium: Chromium use after free vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2374686 [ 2 ] Bug #2374687 - CVE-2025-6557 chromium: Chromium data validation vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2374687 [ 3 ] Bug #2374688 - CVE-2025-6556 chromium: Chromium policy enforcement vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2374688 [ 4 ] Bug #2374689 - CVE-2025-6555 chromium: Chromium use after freevulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2374689 [ 5 ] Bug #2374690 - CVE-2025-6556 chromium: Chromium policy enforcement vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2374690 [ 6 ] Bug #2374691 - CVE-2025-6557 chromium: Chromium data validation vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2374691 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e4b1668bdd' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 136.0.7103.113 CVE-2025-4664: Insufficient policy enforcement in Loader CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-bd02634055 2025-05-18 01:36:15.366010+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 41 Version : 136.0.7103.113 Release : 1.fc41 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 136.0.7103.113 CVE-2025-4664: Insufficient policy enforcement in Loader CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo -------------------------------------------------------------------------------- ChangeLog: * Wed May 14 2025 Than Ngo - 136.0.7103.113-1 - Update to 136.0.7103.113 * CVE-2025-4664: Insufficient policy enforcement in Loader * CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-bd02634055' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Update to 136.0.7103.113 CVE-2025-4664: Insufficient policy enforcement in Loader CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-9b9b36bc72 2025-05-18 01:09:04.765993+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 42 Version : 136.0.7103.113 Release : 1.fc42 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 136.0.7103.113 CVE-2025-4664: Insufficient policy enforcement in Loader CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo -------------------------------------------------------------------------------- ChangeLog: * Wed May 14 2025 Than Ngo - 136.0.7103.113-1 - Update to 136.0.7103.113 * CVE-2025-4664: Insufficient policy enforcement in Loader * CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-9b9b36bc72' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Gatekeeper Operator v0.2 security fixes and enhancements Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: Gatekeeper Operator v0.2 security fixes and enhancements Advisory ID: RHSA-2023:4475-01 Product: Red Hat ACM Advisory URL: https://access.redhat.com/errata/RHSA-2023:4475 Issue date: 2023-08-03 CVE Names: CVE-2020-24736 CVE-2022-36227 CVE-2023-1667 CVE-2023-2283 CVE-2023-3089 CVE-2023-26604 CVE-2023-27535 ===================================================================== 1. Summary: Gatekeeper Operator v0.2 security fixes and enhancements Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section. 2. Description: Gatekeeper Operator v0.2 Gatekeeper is an open source project that applies the OPA Constraint Framework to enforce policies on your Kubernetes clusters. This advisory contains the container images for Gatekeeper that include bug fixes and container upgrades. Note: Gatekeeper support from the Red Hat support team is limited cases where it is integrated and used with Red Hat Advanced Cluster Management for Kubernetes. For support options for any other use, see the Gatekeeper open source project website at: https://open-policy-agent.github.io/gatekeeper/website/docs/howto/. Security fix(es): * CVE-2023-3089 openshift: OCP & FIPS mode 3. Solution: IMPORTANT: This release removes `PodSecurityPolicy` resource references, a deprecated Kubernetesconstruct, from the operator. Gatekeeper constraints based on the resource may no longer work. The Gatekeeper operator that is installed by the Gatekeeper operator policy has `installPlanApproval` set to `Automatic`. This setting means the operator is upgraded automatically when there is a new version of the operator. No further action is required for upgrade. If you changed the setting to `Manual`, then you must view each cluster to manually approve the upgrade to the operator. 4. Bugs fixed (https://bugzilla.redhat.com/): 2212085 - CVE-2023-3089 openshift: OCP & FIPS mode 5. References: https://access.redhat.com/security/cve/CVE-2020-24736 https://access.redhat.com/security/cve/CVE-2022-36227 https://access.redhat.com/security/cve/CVE-2023-1667 https://access.redhat.com/security/cve/CVE-2023-2283 https://access.redhat.com/security/cve/CVE-2023-3089 https://access.redhat.com/security/cve/CVE-2023-26604 https://access.redhat.com/security/cve/CVE-2023-27535 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2023-001 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJkzAz/AAoJENzjgjWX9erEndsP/ifzKa5y3lM6GfDXmENg56du KQliejD5fDaVz+FJOcvzbqrSdjPV5yLsyM0G3CEWxYUvV0CXNnefkF9/cDzyXT4D kcGjGlJaM1SFg7eLI9T9rz5CLVwQi7Va/fBIxLhmDlW3gc7M2k2UmuGKHHQUFFuF uSSTMP4M3ygXComOEs2gLJkBA+PXkRRg+p0uS9+40fiPWZKIScjrDsous702uSGu ynITaReQJfegN7Thv6IAuZ7iJxIJKYTjYPOgU3Mj9p1jAR2a7MUWCYdxwmTnfmkV W1flnlAOVZcdRniOiLlj7bN3wnHFvNjyHbeWBCE205abg2EPZvjj9lPNCdkcPLSc OHcfIG+I22GMfkIwHCE+WsCRtpoBvERfn2fC5up+ghmI1nTqX1Bna7wGh9+KnHxk bQZvJxXZx+7S1HO/OUjqDwaTP0vHuFfPjwEzWuVNtbuUxJhhLurUInOSG9FEqxsy m7piV7q/GgXxIJnD/mt3izseINRtrm/2iz6UDipcpGi4TeaoPMhene2vv40k9tGA ezT2pyzsQnJVQesVHtWmNjNYzbpbAcYU5OO4Stt29l51uz1cbA+Rg8q8BM9MjpHT 9ueMyZn47SJaGXZCLToHiJ1JbuDMcsErBH9lBnOsAehEImD2NTDMs01H+PFlFzAX 8nDmKe1nqsDI7ca0SwEC =JlO4 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for ztp-site-generate-container, topology-aware-lifecycle-manager and bare-metal-event-relay is now available for Red Hat OpenShift Container Platform 4.13. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: OpenShift Container Platform 4.13.0 CNF vRAN extras security update Advisory ID: RHSA-2023:2138-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2023:2138 Issue date: 2023-05-18 CVE Names: CVE-2020-16251 CVE-2021-43998 ==================================================================== 1. Summary: An update for ztp-site-generate-container, topology-aware-lifecycle-manager and bare-metal-event-relay is now available for Red Hat OpenShift Container Platform 4.13. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the extra low-latency container images for Red Hat OpenShift Container Platform 4.13. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2023:1326 All OpenShift Container Platform users are advised to upgrade to these updated packages and images. Security Fix(es): * vault: GCP Auth Method Allows Authentication Bypass (CVE-2020-16251) * vault: incorrect policy enforcement (CVE-2021-43998) 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. Fordetails on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2028193 - CVE-2021-43998 vault: incorrect policy enforcement 2167340 - CVE-2020-16251 vault: GCP Auth Method Allows Authentication Bypass 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): OCPBUGS-10819 - TALM SNO Backup Fails on Managed Cluster Running CoreOS 9.2 OCPBUGS-11890 - TALM keeps spinning with the hub template error when unsupported hub template function is being used in the second policy OCPBUGS-2336 - dataset_comparison should be G.8275.x in ptpconfig source crsOCPBUGS-3005 - step_threshold should be changed from 0.0 to 2.0 in in ptpconfig source crsOCPBUGS-3047 - TALM spent 42 minutes precaching when there was no precaching work to be done. OCPBUGS-3092 - TALM precaching pulls more content than needed OCPBUGS-3210 - TALM attempting to approve PAO installplan for 4.11 operator upgrade OCPBUGS-3885 - After CGU timed out it got stuck in a loop and kept adding duplicates to status field OCPBUGS-3954 - Precaching status missing for temporarily unavailable clusters OCPBUGS-4197 - CGU pod goes to CrashLoopBackOff when incorrect channel is provided for OCP precaching OCPBUGS-4200 - Segfault from TALM after CGU timeout OCPBUGS-4246 - Precaching spec error due to invalid policy combination reported as precaching/backup failures on spokes OCPBUGS-4329 - Cannot install LVMO through gitops ZTP OCPBUGS-4406 - ptp configs should match reference configs OCPBUGS-4704 - TALM - precache does not begin if catalogsource config policy is Compliant OCPBUGS-4821 - TALM getImageForVersionFromUpdateGraph func making insecure external calls OCPBUGS-5797 - TALM backup CGU only indicates status of one cluster when two clusters are being backed up OCPBUGS-6612 - Default backup timeout too short for large scale upgrade OCPBUGS-6769 - TALM 4.11 pre-cache fails on 4.10 cluster OCPBUGS-6944 - TALM backup - recovery script fails due to unable to find running container eventhough it is running OCPBUGS-7217 - TALM cli state is not correct when cgu is enabled after backup OCPBUGS-7464 - Unable to deploy 4.11 spoke using ZTP 4.13 due to new spec added to performanceprofile OCPBUGS-7933 - Image Precaching Fails Due To Missing check_space Script OCPBUGS-7948 - 4.13 bmer build does not include 4.13 sidecar changes OCPBUGS-8006 - TALM applies a 5 minute reconciliation loop to monitor cluster readiness and start policy application OCPBUGS-8032 - TALM Fails to Report Low Disk Space during Image Precaching OCPBUGS-8414 - BMER - operator upgrade from 4.12 to 4.13 does not work - subs stays at AtLatestKnown and no installplan is created OCPBUGS-8525 - TALM may miss MCP reconcile after change to PerformanceProfile or operator upgrade OCPBUGS-9428 - ignition reports warning at $.systemd.units.22.contents, line 1 col 363575: unit "container-mount-namespace.service" is enabled, but has no install section so enable does nothing OCPBUGS-9943 - Remove duplicated field macAddress from Siteconfigs 6. References: https://access.redhat.com/security/cve/CVE-2020-16251 https://access.redhat.com/security/cve/CVE-2021-43998 https://access.redhat.com/security/updates/classification/#moderate 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZGW9UdzjgjWX9erEAQi5/A/+KKaHyRl+23u8Wj3rxjrnEcz9KPFU+ZUc UUW1MvuqmFqCX+0Sb98agk5faDIQfhAPuE4ShcwduR8w39ftxFAQWEaDfBqZBuul 1Nptw0Ammrh0btDaQnjXF5vLTcF1sv5GWtkICpoTXg6qcVnIsibw9f1G/hBidiG2 u35ThWipKMp0N9DMDTSBr8Fy0Mffw5+ny05QU18DegHRVFupt1XF8SnW4lh/UlhD LiR9iJ2K1xnfvDr+BdMhFWiqH7xZzZHMX0s2FEcBvUMW6/DYYLzaiUSFbh6TYiIK 5fwCXQKXLlls0+oUbBquoYG64beXOMxSgYEiI4B+bFblqfzTN4ev+vJOqCfjt7ye BG1B7350xgMhHxBV8stMoY5mQMLoYjZHzBvQ9KU672ze0gLlIspTLjzlN2fhUr3/ bfiVsX8T9pJJOszDmbyrRXaFHbgEtR1SYJVMC/0G49koPrSX6JwasGHq/b5yMSIH v+cLWsQ7YTRdC7zUc54j2ILP75VeLxxm4Rxm4pWTHvUo0h48GFn92AYWbW4Vt9Yn 6ZVcEuNSJK1iVd67L9P9Y+hX3nlrt/PBkbMYO0IcTFhCf97Xo76O84iqovuRHGRX rst63r8Zjx0GfT2OA8ewcxBMf5hCs3zBO8Psr6Wx8oMccd6brME9RdzqgNpo9pEW TXwdOxzzbkI=59Dl -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Two security issues were found in PostgreSQL, which may result in privilege escalation or incorrect policy enforcement. For Debian 10 buster, these problems have been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3422-1
Two security issues were found in PostgreSQL, which may result in privilege escalation or incorrect policy enforcement. For the stable distribution (bullseye), these problems have been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5401-1
Get the latest Linux and open source security news straight to your inbox.