Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 3 vulnerabilities can now be installed.. # rclone-1.74.4-1.1 on GA media Announcement ID: openSUSE-SU-2026:11241-1 Rating: moderate Cross-References: * CVE-2026-54572 * CVE-2026-59732 * CVE-2026-59733 Affected Products: * openSUSE Tumbleweed An update that solves 3 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the rclone-1.74.4-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * rclone 1.74.4-1.1 * rclone-bash-completion 1.74.4-1.1 * rclone-zsh-completion 1.74.4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54572.html * https://www.suse.com/security/cve/CVE-2026-59732.html * https://www.suse.com/security/cve/CVE-2026-59733.html . An update for openSUSE fixes moderate issues in rclone affecting system security, enhancing overall protection and stability.. openSUSE updates,rclone security fixes,moderate vulnerability threats. . Severity: moderate. LinuxSecurity.com Team
Update to 1.74.3. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-e1d1b349cd 2026-07-02 01:07:29.331996+00:00 -------------------------------------------------------------------------------- Name : rclone Product : Fedora 43 Version : 1.74.3 Release : 1.fc43 URL : https://github.com/rclone/rclone Summary : Rsync for cloud storage Description : "rsync for cloud storage" - Google Drive, S3, Dropbox, Backblaze B2, One Drive, Swift, Hubic, Wasabi, Google Cloud Storage, Azure Blob, Azure Files, Yandex Files. -------------------------------------------------------------------------------- Update Information: Update to 1.74.3 -------------------------------------------------------------------------------- ChangeLog: * Sat Jun 6 2026 Packit - 1.74.3-1 - Update to 1.74.3 upstream release - Resolves: rhbz#2485621 * Sat May 23 2026 Packit - 1.74.2-1 - Update to 1.74.2 upstream release - Resolves: rhbz#2468412 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2486295 - CVE-2026-45287 rclone: OpenTelemetry-Go: Denial of Service due to file descriptor leak [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486295 [ 2 ] Bug #2489905 - CVE-2026-39828 rclone: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489905 [ 3 ] Bug #2490091 - CVE-2026-39829 rclone: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490091 [ 4 ] Bug #2490402 - CVE-2026-39830 rclone: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490402 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e1d1b349cd' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 1.74.3. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6145ae14ca 2026-07-02 01:05:29.983954+00:00 -------------------------------------------------------------------------------- Name : rclone Product : Fedora 44 Version : 1.74.3 Release : 1.fc44 URL : https://github.com/rclone/rclone Summary : Rsync for cloud storage Description : "rsync for cloud storage" - Google Drive, S3, Dropbox, Backblaze B2, One Drive, Swift, Hubic, Wasabi, Google Cloud Storage, Azure Blob, Azure Files, Yandex Files. -------------------------------------------------------------------------------- Update Information: Update to 1.74.3 -------------------------------------------------------------------------------- ChangeLog: * Sat Jun 6 2026 Packit - 1.74.3-1 - Update to 1.74.3 upstream release - Resolves: rhbz#2485621 * Sat May 23 2026 Packit - 1.74.2-1 - Update to 1.74.2 upstream release - Resolves: rhbz#2468412 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2486295 - CVE-2026-45287 rclone: OpenTelemetry-Go: Denial of Service due to file descriptor leak [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486295 [ 2 ] Bug #2489905 - CVE-2026-39828 rclone: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489905 [ 3 ] Bug #2490091 - CVE-2026-39829 rclone: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490091 [ 4 ] Bug #2490402 - CVE-2026-39830 rclone: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490402 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6145ae14ca' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that fixes 27 vulnerabilities is now available.. openSUSE Security Update: Security update for rclone ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0199-1 Rating: critical References: #1266210 #1267869 Cross-References: CVE-2026-25680 CVE-2026-25681 CVE-2026-27136 CVE-2026-27145 CVE-2026-33809 CVE-2026-39821 CVE-2026-39824 CVE-2026-39827 CVE-2026-39828 CVE-2026-39829 CVE-2026-39830 CVE-2026-39831 CVE-2026-39832 CVE-2026-39833 CVE-2026-39834 CVE-2026-39835 CVE-2026-42500 CVE-2026-42502 CVE-2026-42504 CVE-2026-42506 CVE-2026-42507 CVE-2026-42508 CVE-2026-44740 CVE-2026-46595 CVE-2026-46597 CVE-2026-46598 CVE-2026-49980 CVSS scores: CVE-2026-25680 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-25681 (SUSE): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N CVE-2026-27136 (SUSE): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N CVE-2026-27145 (SUSE): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVE-2026-39821 (SUSE): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-39827 (SUSE): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-39828 (SUSE): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-39829 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-39830 (SUSE): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-39831 (SUSE): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-39832 (SUSE): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N CVE-2026-39833 (SUSE): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-39834 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-39835 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-42502 (SUSE): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N CVE-2026-42504 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-42506 (SUSE): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N CVE-2026-42507 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVE-2026-42508 (SUSE): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-44740 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-46595 (SUSE): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-46597 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-46598 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes 27 vulnerabilities is now available. Description: This update for rclone fixes the following issues: - Update to version 1.74.3: (boo#1267869) - Bug Fixes - rc - Fix unauthenticated command execution via --rc-serve inline remotes CVE-2026-49980 (Nick Craig-Wood) - Stop global.* connection string options changing config CVE-2026-49980 (Nick Craig-Wood) - build: Fix multiple CVEs byupgrading to go1.26.4 (Nick Craig-Wood) - CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader - CVE-2026-42507: net/textproto: arbitrary input are included in errors without any escaping - CVE-2026-27145: crypto/x509: split candidate hostname only once - log: Fix wrong source file:line in JSON logs from release builds (Nick Craig-Wood) - mount2: Fix empty directory listings on re-read (Janne Beate Bakeng) - serve s3: Fix multipart ListParts pagination returning wrong part numbers (Nick Craig-Wood) - serve sftp - Fix file corruption when a client resumes an upload (Nick Craig-Wood) - Fix truncate request being silently ignored (Nick Craig-Wood) - Local - Fix getXattr returning empty map instead of nil (Leon Brocard) - Drime - Fix server-side copy and move failing with Cloudflare 520 error (Nick Craig-Wood) - Fix files being uploaded to the wrong directory (Nick Craig-Wood) - Remove duplicate upload_cutoff config option (Nick Craig-Wood) - Fix directory rename leaving the renamed folder empty in VFS (Nick Craig-Wood) - Drive - Fix server-side move failing on shared drives with duplicate dirs (Nick Craig-Wood) - Iclouddrive - Fix ADP/PCS cookie acquisition for iCloud Drive (Yakov Till) - Fix "Index has invalid data" error listing iCloud Photos (Nick Craig-Wood) - Update to version 1.74.2: (boo#1266210) - Bug Fixes - build - Update golang.org/x/net to v0.55.0 to address: - CVE-2026-42506: html: incorrect handling of namespaced elements in foreign content - CVE-2026-39821: idna: failure to reject ASCII-only Punycode-encoded labels - CVE-2026-42502: html: incorrect handling of HTML elements in foreign content - CVE-2026-25680: html: denial of service when parsing arbitrary HTML -CVE-2026-25681: html: incorrect handling of character references in DOCTYPE nodes - CVE-2026-27136: html: duplicate attributes can cause XSS - Update golang.org/x/crypto to v0.52.0 to address: - CVE-2026-46598: ssh/agent: pathological inputs can lead to client panic - CVE-2026-46597: ssh: byte arithmetic causes underflow and panic - CVE-2026-39828: ssh: bypass of certificate restrictions - CVE-2026-39835: ssh: server panic during CheckHostKey/Authenticate - CVE-2026-39833: ssh/agent: key constraints not enforced - CVE-2026-39832: ssh/agent: agent constraints dropped when forwarding keys - CVE-2026-39827: ssh: memory leak when rejecting channels can lead to DoS - CVE-2026-39830: ssh: client can cause server deadlock on unexpected responses - CVE-2026-39829: ssh: pathological RSA/DSA parameters may cause DoS - CVE-2026-39831: ssh: bypass of FIDO/U2F security keys physical interaction - CVE-2026-39834: ssh: infinite loop on large channel writes - CVE-2026-42508: ssh/knownhosts: auth bypass via unenforced @revoked status - CVE-2026-46595: ssh: VerifiedPublicKeyCallback permissions skip enforcement - update golang.org/x/image to v0.41.0 to address: - CVE-2026-42500: bmp: panic when reading out of bound palette index - CVE-2026-33809: tiff: excessive resource consumption in PackBits decompression - Update golang.org/x/sys to version v0.45.0 to address: - CVE-2026-39824: windows: integer overflow in NewNTUnicodeString - Update github.com/go-git/go-billy/v5 to 5.9.0 to fix CVE-2026-44740 - bisync: Fix --conflict-loser pathname with --conflict-resolve newer (nielash) - gui: Update embedded release to 1.1.8 (Nick Craig-Wood) - lib/http: Replace deprecated h2c.NewHandler with http.Server.Protocols (Nick Craig-Wood) -rc: Remove duplicate metrics_addr option registration (Nick Craig-Wood) - vfs/vfscache: Fix silent write failure when mounting with remote:. (Lucky945H) - doc fixes (FTCHD, Iizuki, Leon Brocard, Nick Craig-Wood) - Drime - Fix file doesn't exists error when trying to delete (John Volk) - Fix 500 errors when listing shared folders (Alvinwylim) - Jottacloud - Support whitelabel service Phonero Sky (Tore Anderson) - Protondrive - Fix corrupted on transfer: sha1 hashes differ (William Tange) - S3 - Add new MEGA S4 endpoints on megas4.com including Asia-Pacific region (Nick Craig-Wood) - WebDAV - Honour auth_redirect on listAll PROPFIND (Sai Asish Y) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-199=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): rclone-1.74.3-bp157.2.9.1 - openSUSE Backports SLE-15-SP7 (noarch): rclone-bash-completion-1.74.3-bp157.2.9.1 rclone-zsh-completion-1.74.3-bp157.2.9.1 References: https://www.suse.com/security/cve/CVE-2026-25680.html https://www.suse.com/security/cve/CVE-2026-25681.html https://www.suse.com/security/cve/CVE-2026-27136.html https://www.suse.com/security/cve/CVE-2026-27145.html https://www.suse.com/security/cve/CVE-2026-33809.html https://www.suse.com/security/cve/CVE-2026-39821.html https://www.suse.com/security/cve/CVE-2026-39824.html https://www.suse.com/security/cve/CVE-2026-39827.html https://www.suse.com/security/cve/CVE-2026-39828.html https://www.suse.com/security/cve/CVE-2026-39829.html https://www.suse.com/security/cve/CVE-2026-39830.html https://www.suse.com/security/cve/CVE-2026-39831.html https://www.suse.com/security/cve/CVE-2026-39832.html https://www.suse.com/security/cve/CVE-2026-39833.html https://www.suse.com/security/cve/CVE-2026-39834.html https://www.suse.com/security/cve/CVE-2026-39835.html https://www.suse.com/security/cve/CVE-2026-42500.html https://www.suse.com/security/cve/CVE-2026-42502.html https://www.suse.com/security/cve/CVE-2026-42504.html https://www.suse.com/security/cve/CVE-2026-42506.html https://www.suse.com/security/cve/CVE-2026-42507.html https://www.suse.com/security/cve/CVE-2026-42508.html https://www.suse.com/security/cve/CVE-2026-44740.html https://www.suse.com/security/cve/CVE-2026-46595.html https://www.suse.com/security/cve/CVE-2026-46597.html https://www.suse.com/security/cve/CVE-2026-46598.html https://www.suse.com/security/cve/CVE-2026-49980.html https://bugzilla.suse.com/1266210 https://bugzilla.suse.com/1267869 . Critical openSUSE update for rclone addresses 27 high-risk issues with potential exploits, enhancing system security.. openSUSE security, rclone update, critical vulnerabilities, Linux administration. . Severity: Critical. LinuxSecurity.com Team
An update that solves 4 vulnerabilities can now be installed.. # rclone-1.74.3-1.1 on GA media Announcement ID: openSUSE-SU-2026:10975-1 Rating: moderate Cross-References: * CVE-2026-27145 * CVE-2026-42504 * CVE-2026-42507 * CVE-2026-49980 CVSS scores: * CVE-2026-27145 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-27145 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42504 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42504 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42507 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-42507 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 4 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the rclone-1.74.3-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * rclone 1.74.3-1.1 * rclone-bash-completion 1.74.3-1.1 * rclone-zsh-completion 1.74.3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27145.html * https://www.suse.com/security/cve/CVE-2026-42504.html * https://www.suse.com/security/cve/CVE-2026-42507.html * https://www.suse.com/security/cve/CVE-2026-49980.html . rclone on openSUSE Tumbleweed update solves four vulnerabilities, enhancing security with moderate rating.. rclone update, openSUSE vulnerabilities, security advisory, package update, moderate risk. . Severity: moderate. LinuxSecurity.com Team
An update that solves 23 vulnerabilities can now be installed.. # rclone-1.74.2-1.1 on GA media Announcement ID: openSUSE-SU-2026:10856-1 Rating: moderate Cross-References: * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-27136 * CVE-2026-33809 * CVE-2026-39821 * CVE-2026-39824 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42500 * CVE-2026-42502 * CVE-2026-42506 * CVE-2026-42508 * CVE-2026-44740 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N *CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 23 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the rclone-1.74.2-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * rclone 1.74.2-1.1 * rclone-bash-completion 1.74.2-1.1 * rclone-zsh-completion 1.74.2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-33809.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39824.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html *https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42500.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-44740.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html . Update rclone-1.74.2-1.1 on openSUSE fixes 23 security issues. Get details on severity and threats involved.. openSUSE Security Advisory, rclone update, moderate severity security, openSUSE vulnerabilities. . Severity: moderate. LinuxSecurity.com Team
Several security issues were fixed in Rclone.. ========================================================================== Ubuntu Security Notice USN-8299-1 May 25, 2026 rclone vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in Rclone. Software Description: - rclone: rsync for commercial cloud storage Details: It was discovered that Rclone incorrectly handled authorization in the remote control API. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-41176) It was discovered that Rclone incorrectly handled backend instantiation via the remote control API. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 24.04 LTS, Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-41179) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS rclone 1.60.1+dfsg-4ubuntu3.1 Ubuntu 25.10 rclone 1.60.1+dfsg-4ubuntu2.1 Ubuntu 24.04 LTS rclone 1.60.1+dfsg-3ubuntu0.24.04.5 Ubuntu 22.04 LTS rclone 1.53.3-4ubuntu1.22.04.4 Ubuntu 20.04 LTS rclone 1.50.2-2ubuntu0.2+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8299-1 CVE-2026-41176, CVE-2026-41179 Package Information: https://launchpad.net/ubuntu/+source/rclone/1.60.1+dfsg-4ubuntu3.1 https://launchpad.net/ubuntu/+source/rclone/1.60.1+dfsg-4ubuntu2.1 https://launchpad.net/ubuntu/+source/rclone/1.60.1+dfsg-3ubuntu0.24.04.5 https://launchpad.net/ubuntu/+source/rclone/1.53.3-4ubuntu1.22.04.4 .Update your Ubuntu systems for Rclone vulnerabilities identified by CVE-2026-41176 and CVE-2026-41179.. Ubuntu Security Notice Rclone Arbitrary Code Execution Remote Control API. . Severity: Critical. LinuxSecurity.com Team
MGASA-2026-0147 - Updated rclone packages fix security vulnerabilities. MGASA-2026-0147 - Updated rclone packages fix security vulnerabilities Publication date: 18 May 2026 URL: https://advisories.mageia.org/MGASA-2026-0147.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-41179, CVE-2026-41176, CVE-2026-32282, CVE-2026-32289, CVE-2026-33810, CVE-2026-27144, CVE-2026-27143, CVE-2026-32288, CVE-2026-32283, CVE-2026-27140, CVE-2026-32280, CVE-2026-32281, CVE-2026-33186, CVE-2026-27137, CVE-2026-27138, CVE-2026-25679, CVE-2026-27142, CVE-2026-1229, CVE-2026-27141, CVE-2025-68121, CVE-2025-61729, CVE-2025-58181, CVE-2025-30204, CVE-2025-22869, CVE-2025-22870, CVE-2024-45337, CVE-2024-45338, CVE-2024-52522, CVE-2023-45288, CVE-2024-35255, CVE-2023-48795 Description: This update bring new features, bugs and vulnerabilities fixed in rclone and golang components used to build it. References: - https://bugs.mageia.org/show_bug.cgi?id=33808 - https://rclone.org/changelog/#v1-73-5-2026-04-19 - https://rclone.org/changelog/#v1-73-4-2026-04-08 - https://rclone.org/changelog/#v1-73-3-2026-03-23 - https://rclone.org/changelog/#v1-73-2-2026-03-06 - https://rclone.org/changelog/#v1-73-1-2026-02-17 - https://rclone.org/changelog/#v1-73-0-2026-01-30 - https://rclone.org/changelog/#v1-72-1-2025-12-10 - https://rclone.org/changelog/#v1-72-0-2025-11-21 - https://rclone.org/changelog/#v1-71-2-2025-10-20 - https://rclone.org/changelog/#v1-71-1-2025-09-24 - https://rclone.org/changelog/#v1-71-0-2025-08-22 - https://rclone.org/changelog/#v1-70-3-2025-07-09 - https://rclone.org/changelog/#v1-70-2-2025-06-27 - https://rclone.org/changelog/#v1-70-1-2025-06-19 - https://rclone.org/changelog/#v1-70-0-2025-06-17 - https://rclone.org/changelog/#v1-69-3-2025-05-21 - https://rclone.org/changelog/#v1-69-2-2025-05-01 - https://rclone.org/changelog/#v1-69-1-2025-02-14 -https://rclone.org/changelog/#v1-69-0-2025-01-12 - https://rclone.org/changelog/#v1-68-2-2024-11-15 - https://rclone.org/changelog/#v1-68-1-2024-09-24 - https://rclone.org/changelog/#v1-68-0-2024-09-08 - https://rclone.org/changelog/#v1-67-0-2024-06-14 - https://rclone.org/changelog/#v1-66-0-2024-03-10 - https://rclone.org/changelog/#v1-65-2-2024-01-24 - https://rclone.org/changelog/#v1-65-1-2024-01-08 - https://rclone.org/changelog/#v1-65-0-2023-11-26 - https://rclone.org/changelog/#v1-64-2-2023-10-19 - https://rclone.org/changelog/#v1-64-1-2023-10-17 - https://rclone.org/changelog/#v1-64-0-2023-09-11 - https://rclone.org/changelog/#v1-63-1-2023-07-17 - https://rclone.org/changelog/#v1-63-0-2023-06-30 - https://rclone.org/changelog/#v1-62-2-2023-03-16 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41179 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41176 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32282 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32289 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33810 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27144 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27143 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32288 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27140 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33186 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27137 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27138 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27142 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1229 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27141 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121 -https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61729 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-58181 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30204 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22869 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22870 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45337 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45338 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52522 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45288 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35255 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-48795 SRPMS: - 9/core/rclone-1.73.5-1.1.mga9 . Updated rclone packages in Mageia fix critical issues. Ensure your system is secure with this update.. Mageia Rclone Security Update Critical Issues. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.