Explore top 10 tips to secure your open-source projects now. Read More
×An update that solves six vulnerabilities can now be installed.. # Security update for curl Announcement ID: SUSE-SU-2026:2703-1 Release Date: 2026-06-30T10:27:51Z Rating: moderate References: * bsc#1262631 * bsc#1262632 * bsc#1262633 * bsc#1262635 * bsc#1262636 * bsc#1262638 Cross-References: * CVE-2026-4873 * CVE-2026-5545 * CVE-2026-5773 * CVE-2026-6253 * CVE-2026-6276 * CVE-2026-6429 CVSS scores: * CVE-2026-4873 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-4873 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-4873 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-5545 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-5545 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-5545 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-5545 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-5773 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-5773 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-5773 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-5773 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-6253 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-6253 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-6253 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6276 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-6276 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-6276 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6276 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6429 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-6429 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-6429 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues * CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). * CVE-2026-5545: wrong reuse of HTTP Negotiate connection (bsc#1262632). * CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). * CVE-2026-6253: proxy credentials leak over redirect-to proxy (bsc#1262635). * CVE-2026-6276: stale custom cookie host causes cookie leak (bsc#1262636). * CVE-2026-6429: netrc credential leak with reused proxy connection (bsc#1262638). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2703=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * curl-debugsource-8.0.1-11.123.1 * libcurl4-8.0.1-11.123.1 * libcurl4-debuginfo-32bit-8.0.1-11.123.1 * libcurl4-32bit-8.0.1-11.123.1 * curl-debuginfo-8.0.1-11.123.1 * curl-8.0.1-11.123.1 * libcurl4-debuginfo-8.0.1-11.123.1 * libcurl-devel-8.0.1-11.123.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4873.html * https://www.suse.com/security/cve/CVE-2026-5545.html * https://www.suse.com/security/cve/CVE-2026-5773.html * https://www.suse.com/security/cve/CVE-2026-6253.html * https://www.suse.com/security/cve/CVE-2026-6276.html *https://www.suse.com/security/cve/CVE-2026-6429.html * https://bugzilla.suse.com/show_bug.cgi?id=1262631 * https://bugzilla.suse.com/show_bug.cgi?id=1262632 * https://bugzilla.suse.com/show_bug.cgi?id=1262633 * https://bugzilla.suse.com/show_bug.cgi?id=1262635 * https://bugzilla.suse.com/show_bug.cgi?id=1262636 * https://bugzilla.suse.com/show_bug.cgi?id=1262638 . Install the latest SUSE security update for curl addressing six vulnerabilities and enhancing system security.. SUSE curl security update, curl vulnerabilities fix, SUSE patch instructions. . Severity: moderate. LinuxSecurity.com Team
Backport upstream fixes for CVE-2026-54387 and CVE-2026-54388.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-efbe094630 2026-06-27 01:10:00.374896+00:00 -------------------------------------------------------------------------------- Name : tinyproxy Product : Fedora 44 Version : 1.11.2 Release : 8.fc44 URL : https://tinyproxy.github.io/ Summary : A small, efficient HTTP/SSL proxy daemon Description : tinyproxy is a small, efficient HTTP/SSL proxy daemon that is very useful in a small network setting, where a larger proxy like Squid would either be too resource intensive, or a security risk. -------------------------------------------------------------------------------- Update Information: Backport upstream fixes for CVE-2026-54387 and CVE-2026-54388. -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 18 2026 Carl George - 1.11.2-8 - Backport upstream CVE fixes - Fixes CVE-2026-54387 - Fixes CVE-2026-54388 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2490299 - CVE-2026-54387 tinyproxy: HTTP Request Smuggling via CL/TE desynchronization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490299 [ 2 ] Bug #2490301 - CVE-2026-54388 tinyproxy: HTTP Request Smuggling via duplicate Content-Length headers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490301 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-efbe094630' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the FedoraProject can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Important: squid:4 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:19107", "synopsis": "Important: squid:4 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for module.libecap, libecap, module.squid, squid.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Squid is a high-performance proxy caching server for web clients, supporting FTP, and HTTP data objects.\n\nSecurity Fix(es):\n\n* squid-cache: Squid vulnerable to information disclosure via authentication credential leakage in error handling (CVE-2025-62168)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2404736", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2404736", "description": ""}], "cves": [{"name": "CVE-2025-62168", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-62168", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N", "cvss3BaseScore": "8.6", "cwe": "CWE-209"}], "references": [], "publishedAt": "2026-01-15T09:11:45.290734Z", "rpms": {"Rocky Linux 8": {"nvras": ["squid-7:4.15-10.module+el8.10.0+1885+e30b7122.3.aarch64.rpm", "squid-7:4.15-10.module+el8.10.0+1985+eaf982f0.6.aarch64.rpm", "squid-7:4.15-10.module+el8.10.0+1881+7e31fb44.1.aarch64.rpm", "squid-7:4.15-10.module+el8.10.0+1758+80ba9f4b.aarch64.rpm", "squid-7:4.15-10.module+el8.10.0+1928+e8441768.5.aarch64.rpm", "squid-7:4.15-10.module+el8.10.0+1928+e8441768.5.src.rpm", "squid-7:4.15-10.module+el8.10.0+1985+eaf982f0.6.src.rpm", "squid-7:4.15-10.module+el8.10.0+1758+80ba9f4b.src.rpm", "squid-7:4.15-10.module+el8.10.0+1881+7e31fb44.1.src.rpm","squid-7:4.15-10.module+el8.10.0+1885+e30b7122.3.src.rpm", "squid-7:4.15-10.module+el8.10.0+1885+e30b7122.3.x86_64.rpm", "squid-7:4.15-10.module+el8.10.0+1985+eaf982f0.6.x86_64.rpm", "squid-7:4.15-10.module+el8.10.0+1758+80ba9f4b.x86_64.rpm", "squid-7:4.15-10.module+el8.10.0+1881+7e31fb44.1.x86_64.rpm", "squid-7:4.15-10.module+el8.10.0+1928+e8441768.5.x86_64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1985+eaf982f0.6.aarch64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1758+80ba9f4b.aarch64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1928+e8441768.5.aarch64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1885+e30b7122.3.aarch64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1881+7e31fb44.1.aarch64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1928+e8441768.5.x86_64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1885+e30b7122.3.x86_64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1985+eaf982f0.6.x86_64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1758+80ba9f4b.x86_64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1881+7e31fb44.1.x86_64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1985+eaf982f0.6.aarch64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1928+e8441768.5.aarch64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1881+7e31fb44.1.aarch64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1885+e30b7122.3.aarch64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1758+80ba9f4b.aarch64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1758+80ba9f4b.x86_64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1885+e30b7122.3.x86_64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1928+e8441768.5.x86_64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1881+7e31fb44.1.x86_64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1985+eaf982f0.6.x86_64.rpm", "libecap-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.aarch64.rpm", "libecap-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.src.rpm", "libecap-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.x86_64.rpm","libecap-debuginfo-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.aarch64.rpm", "libecap-debuginfo-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.x86_64.rpm", "libecap-debugsource-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.aarch64.rpm", "libecap-debugsource-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.x86_64.rpm", "libecap-devel-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.aarch64.rpm", "libecap-devel-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.x86_64.rpm", "squid-7:4.15-10.module+el8.10.0+2080+49064dbd.9.aarch64.rpm", "squid-7:4.15-10.module+el8.10.0+2080+49064dbd.9.src.rpm", "squid-7:4.15-10.module+el8.10.0+2080+49064dbd.9.x86_64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+2080+49064dbd.9.aarch64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+2080+49064dbd.9.x86_64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+2080+49064dbd.9.aarch64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+2080+49064dbd.9.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A crucial update resolves an information leakage flaw in Squid for Rocky Linux 8, ensuring enhanced security and functionality.. Rocky Linux 8, Squid update, information disclosure, security patch. . Severity: Important. LinuxSecurity.com Team
Rebuilt for CVEs. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-582e97b7b4 2026-01-01 01:07:37.402503+00:00 -------------------------------------------------------------------------------- Name : golang-github-googlecloudplatform-cloudsql-proxy Product : Fedora 42 Version : 1.31.2 Release : 9.fc42 URL : https://github.com/GoogleCloudPlatform/cloud-sql-proxy Summary : Cloud SQL proxy client and Go library Description : The Cloud SQL Proxy allows a user with the appropriate permissions to connect to a Second Generation Cloud SQL database without having to deal with IP whitelisting or SSL certificates manually. It works by opening unix/tcp sockets on the local machine and proxying connections to the associated Cloud SQL instances when the sockets are used. -------------------------------------------------------------------------------- Update Information: Rebuilt for CVEs -------------------------------------------------------------------------------- ChangeLog: * Tue Dec 23 2025 W. Michael Petullo - 1.31.2-9 - Rebuilt for CVEs -------------------------------------------------------------------------------- References: [ 1 ] Bug #2398740 - CVE-2025-47910 golang-github-googlecloudplatform-cloudsql-proxy: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398740 [ 2 ] Bug #2399418 - CVE-2025-47906 golang-github-googlecloudplatform-cloudsql-proxy: Unexpected paths returned from LookPath in os/exec [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2399418 [ 3 ] Bug #2407942 - CVE-2025-58189 golang-github-googlecloudplatform-cloudsql-proxy: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2407942 [ 4 ] Bug #2409412 - CVE-2025-61723 golang-github-googlecloudplatform-cloudsql-proxy: Quadratic complexitywhen parsing some invalid inputs in encoding/pem [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2409412 [ 5 ] Bug #2410363 - CVE-2025-58185 golang-github-googlecloudplatform-cloudsql-proxy: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2410363 [ 6 ] Bug #2411263 - CVE-2025-58188 golang-github-googlecloudplatform-cloudsql-proxy: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2411263 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-582e97b7b4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability can now be installed.. # Security update for squid Announcement ID: SUSE-SU-2025:3902-1 Release Date: 2025-10-31T17:08:05Z Rating: important References: * bsc#1252281 Cross-References: * CVE-2025-62168 CVSS scores: * CVE-2025-62168 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2025-62168 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2025-62168 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2025-62168 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Proxy 4.3 LTS * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Retail Branch Server 4.3 LTS * SUSE Manager Server 4.3 * SUSE Manager Server 4.3 LTS An update that solves one vulnerability can now be installed. ## Description: This update for squid fixes the following issues: * CVE-2025-62168: Fixed proxy auth data visible to scripts (bsc#1252281). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-3902=1 * SUSELinux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-3902=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-3902=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-3902=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-3902=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-3902=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-3902=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-3902=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-3902=1 * SUSE Manager Proxy 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-LTS-2025-3902=1 * SUSE Manager Retail Branch Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-LTS-2025-3902=1 * SUSE Manager Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-LTS-2025-3902=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Linux Enterprise High Performance ComputingESPOS 15 SP5 (aarch64 x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Manager Proxy 4.3 LTS (x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Manager Retail Branch Server 4.3 LTS (x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Manager Server 4.3 LTS (ppc64le s390x x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 ## References: * https://www.suse.com/security/cve/CVE-2025-62168.html * https://bugzilla.suse.com/show_bug.cgi?id=1252281 . SUSE addresses an important squid vulnerability in openSUSE and offers guidance on how to apply updates.. openSUSE Security Fix, Squid Vulnerability Patch, SUSE Update Important. . Severity: Important. LinuxSecurity.com Team
Changes with Apache Traffic Server 10.0.6 #12298 - Add a setting to choose the data source of IP address for ACL #12299 - Add max inclusion depth support for esi plugin 10.0.x #12300 - otel build update for GCC 15 #12301 - autest updates for recent curl and nghttp2 versions (#12165). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-512daf16b9 2025-06-27 01:19:29.250963+00:00 -------------------------------------------------------------------------------- Name : trafficserver Product : Fedora 42 Version : 10.0.6 Release : 1.fc42 URL : https://trafficserver.apache.org/ Summary : Fast, scalable and extensible HTTP/1.1 and HTTP/2 caching proxy server Description : Traffic Server is a high-performance building block for cloud services. It's more than just a caching proxy server; it also has support for plugins to build large scale web applications. Key features: Caching - Improve your response time, while reducing server load and bandwidth needs by caching and reusing frequently-requested web pages, images, and web service calls. Proxying - Easily add keep-alive, filter or anonymize content requests, or add load balancing by adding a proxy layer. Fast - Scales well on modern SMP hardware, handling 10s of thousands of requests per second. Extensible - APIs to write your own plug-ins to do anything from modifying HTTP headers to handling ESI requests to writing your own cache algorithm. Proven - Handling over 400TB a day at Yahoo! both as forward and reverse proxies, Apache Traffic Server is battle hardened. -------------------------------------------------------------------------------- Update Information: Changes with Apache Traffic Server 10.0.6 #12298 - Add a setting to choose the data source of IP address for ACL #12299 - Add max inclusion depth support for esi plugin 10.0.x #12300 - otel build update for GCC 15 #12301 - autest updates for recent curland nghttp2 versions (#12165) -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 17 2025 Jered Floyd 10.0.6-1 - Update to upstream 10.0.6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2373880 - CVE-2025-31698 trafficserver: Apache Traffic Server PROXY Protocol ACL Bypass [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373880 [ 2 ] Bug #2373884 - CVE-2025-49763 trafficserver: Traffic Server ESI Inclusion Depth Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373884 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-512daf16b9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
rebuild with new golang to fix CVE-2025-22870 (fedora#2352013). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-2280949271 2025-04-25 01:58:58.477000+00:00 -------------------------------------------------------------------------------- Name : golang-github-openprinting-ipp-usb Product : Fedora 40 Version : 0.9.30 Release : 4.fc40 URL : https://github.com/OpenPrinting/ipp-usb Summary : HTTP reverse proxy, backed by IPP-over-USB connection to device Description : HTTP reverse proxy, backed by IPP-over-USB connection to device. It enables driverless support for USB devices capable of using IPP-over-USB protocol. -------------------------------------------------------------------------------- Update Information: rebuild with new golang to fix CVE-2025-22870 (fedora#2352013) -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 16 2025 Zdenek Dohnal - 0.9.30-4 - rebuild with new golang to fix CVE-2025-22870 (fedora#2352013) * Fri Apr 11 2025 Zdenek Dohnal - 0.9.30-3 - rebuilt with goipp 1.2.0 * Wed Mar 26 2025 Zdenek Dohnal - 0.9.30-2 - update SPEC file with new changes from go2rpm -------------------------------------------------------------------------------- References: [ 1 ] Bug #2351766 - CVE-2025-22870 golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-2280949271' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in denial of service or request smuggling. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5758-1
Get the latest Linux and open source security news straight to your inbox.