Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Security update. Publication date: 15 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0210.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-4115 Description: ECDSA signature verification can be made to fail an assertion. Server can provoke a double free in RSA KEX code. Telnet session data is marked with trust sigils after authenticating to a proxy. PuTTY Ed25519 Signature ecc-ssh.c eddsa_verify signature verification. (CVE-2026-4115) References: - https://bugs.mageia.org/show_bug.cgi?id=35585 - https://www.openwall.com/lists/oss-security/2026/05/24/11 - https://lists.tartarus.org/pipermail/putty-announce/2026/000042.html - https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/rsakex-double-free.html - https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/telnet-trust-sigil.html - https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/eddsa-overlarge-s.html - https://www.cve.org/CVERecord?id=CVE-2026-4115 SRPMS: - 9/core/putty-0.84-1.mga9 . Critical security update for Mageia 9 addressing multiple issues in PuTTY due to signature failures and memory errors.. Mageia security update, PuTTY vulnerabilities, ECDSA issues, critical security advisory. . Severity: Critical. LinuxSecurity.com Team
This is an update fixing several security related problems in putty.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-61f53cc218 2026-06-10 01:08:28.182994+00:00 -------------------------------------------------------------------------------- Name : putty Product : Fedora 43 Version : 0.84 Release : 1.fc43 URL : http://www.chiark.greenend.org.uk/~sgtatham/putty/ Summary : SSH, Telnet and Rlogin client Description : Putty is a SSH, Telnet & Rlogin client - this time for Linux. -------------------------------------------------------------------------------- Update Information: This is an update fixing several security related problems in putty. -------------------------------------------------------------------------------- ChangeLog: * Mon May 25 2026 Jaroslav Škarvada - 0.84-1 - New version Resolves: rhbz#2480724 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2480724 - putty-0.84 is available https://bugzilla.redhat.com/show_bug.cgi?id=2480724 [ 2 ] Bug #2481658 - CVE-2026-48850 putty: double free vulnerability in RSA KEX code [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481658 [ 3 ] Bug #2481659 - CVE-2026-48851 putty: TELNET session data is marked with trust sigils after authenticating to a proxy [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481659 [ 4 ] Bug #2481662 - CVE-2026-48852 putty: assertion failure in ECDSA signature verification [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481662 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-61f53cc218' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update addresses security issues in Putty on Fedora 43, ensuring safer remote connections and data integrity.. Putty Update, Fedora Security, SSH Client Upgrade, Putty Security Fix, Fedora Vulnerability. . Severity: Important. LinuxSecurity.com Team
This is an update fixing several security related problems in putty.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-1ab61e6e20 2026-06-10 00:54:41.795258+00:00 -------------------------------------------------------------------------------- Name : putty Product : Fedora 44 Version : 0.84 Release : 1.fc44 URL : http://www.chiark.greenend.org.uk/~sgtatham/putty/ Summary : SSH, Telnet and Rlogin client Description : Putty is a SSH, Telnet & Rlogin client - this time for Linux. -------------------------------------------------------------------------------- Update Information: This is an update fixing several security related problems in putty. -------------------------------------------------------------------------------- ChangeLog: * Mon May 25 2026 Jaroslav Škarvada - 0.84-1 - New version Resolves: rhbz#2480724 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2480724 - putty-0.84 is available https://bugzilla.redhat.com/show_bug.cgi?id=2480724 [ 2 ] Bug #2481658 - CVE-2026-48850 putty: double free vulnerability in RSA KEX code [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481658 [ 3 ] Bug #2481659 - CVE-2026-48851 putty: TELNET session data is marked with trust sigils after authenticating to a proxy [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481659 [ 4 ] Bug #2481662 - CVE-2026-48852 putty: assertion failure in ECDSA signature verification [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481662 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1ab61e6e20' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fixes multiple security issues in Putty, ensuring safer SSH sessions in Fedora 44. Update now!. Putty update Fedora security SSH. . Severity: Important. LinuxSecurity.com Team
An update that solves various issues can now be installed.. openSUSE security update: security update for putty ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20851-1 Rating: important Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves various issues can now be installed. Description: This update for putty fixes the following issues: Changes in putty: - Update to release 0.84 * Fixed a remotely triggerable double-free in RSA key exchange. * Fixed a remotely triggerable crash (assertion failure - program termination) in NIST ECDSA signature verification. * Fixed marking of Telnet and Rlogin session data with a trust sigil after you authenticated to a proxy (possibly allowing a server to spoof a repeat proxy password prompt). * New ability to run a specified command before starting the connection, e.g. to perform wake-on-LAN or a port knock. * Display 'pre-edit text', showing the progress of using multiple keystrokes to compose a single Unicode character. * Improved support for to running the GUI tools on Wayland (fixed startup issues and tuned performance). * Configuring a SSH certificate authority used to fail unless you manually made a config directory, now fixed. * Fixed a spurious "Network error: Socket is not connected" when authenticating to some HTTP proxies. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-281=1 Package List: - openSUSE Leap 16.0: putty-0.84-bp160.1.1 . OpenSUSE security update fixes critical putty issues, enhancing remote access functionality with patch installation instructions.. openSUSE putty security update, important software fixes, remoteaccess vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves various issues can now be installed.. openSUSE security update: security update for putty ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20851-1 Rating: important Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves various issues can now be installed. Description: This update for putty fixes the following issues: Changes in putty: - Update to release 0.84 * Fixed a remotely triggerable double-free in RSA key exchange. * Fixed a remotely triggerable crash (assertion failure - program termination) in NIST ECDSA signature verification. * Fixed marking of Telnet and Rlogin session data with a trust sigil after you authenticated to a proxy (possibly allowing a server to spoof a repeat proxy password prompt). * New ability to run a specified command before starting the connection, e.g. to perform wake-on-LAN or a port knock. * Display 'pre-edit text', showing the progress of using multiple keystrokes to compose a single Unicode character. * Improved support for to running the GUI tools on Wayland (fixed startup issues and tuned performance). * Configuring a SSH certificate authority used to fail unless you manually made a config directory, now fixed. * Fixed a spurious "Network error: Socket is not connected" when authenticating to some HTTP proxies. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-281=1 Package List: - openSUSE Leap 16.0: putty-0.84-bp160.1.1 . Update for openSUSE Leap 16.0 addressing important security flaws in Putty ensuring stable connections.. openSUSE security, putty patch, important update, software stability. . Severity: Important.LinuxSecurity.com Team
A biased ECDSA nonce generation allowed an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. In other words, an adversary may already have enough signature information to compromise a victim's . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3839-1
Putty, a Telnet/SSH client for X, was vulnerable. CVE-2019-17069 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3794-1
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for putty ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0111-1 Rating: important References: Cross-References: CVE-2024-31497 Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for putty fixes the following issues: Update to release 0.81 * Fix CVE-2024-31497: NIST P521 / ecdsa-sha2-nistp521 signatures are no longer generated with biased values of k. The previous bias compromises private keys. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-111=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): putty-0.81-bp155.2.6.1 References: https://www.suse.com/security/cve/CVE-2024-31497.html . This crucial software patch for WinSCP tackles vulnerabilities and guarantees enhanced protection for your system. Update today!. openSUSE Security Update, Putty Advisory, Important Security Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.