Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Update to 0.19.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-e6094447f0 2026-06-19 01:08:57.989170+00:00 -------------------------------------------------------------------------------- Name : restic Product : Fedora 43 Version : 0.19.0 Release : 1.fc43 URL : https://github.com/restic/restic Summary : Fast, secure, efficient backup program Description : Fast, secure, efficient backup program. restic supports the following backends for storing backups natively: * Local directory * sftp server (via SSH) * HTTP REST server (protocol, rest-server) * Amazon S3 (either from Amazon or using the Minio server) * OpenStack Swift * BackBlaze B2 * Microsoft Azure Blob Storage * Google Cloud Storage * And many other services via the rclone Backend -------------------------------------------------------------------------------- Update Information: Update to 0.19.0 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 10 2026 Mikel Olasagasti Uranga - 0.19.0-1 - Update to 0.19.0 - Closes rhbz#2487290 * Tue Feb 3 2026 Maxwell G - 0.18.1-3 - Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26 * Sat Jan 17 2026 Fedora Release Engineering - 0.18.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455673 - CVE-2026-34986 restic: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455673 [ 2 ] Bug #2464136 - CVE-2026-41179 restic: Rclone: Unauthenticated local command execution via exposed RC endpoint [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2464136 [ 3 ] Bug #2464140 - CVE-2026-41176 restic: Rclone: Unauthorized access to administrative functions through unauthenticatedRemote Control endpoint. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2464140 [ 4 ] Bug #2486238 - CVE-2026-45287 restic: OpenTelemetry-Go: Denial of Service due to file descriptor leak [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486238 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e6094447f0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 0.19.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-2290b9a9ad 2026-06-19 00:59:07.048638+00:00 -------------------------------------------------------------------------------- Name : restic Product : Fedora 44 Version : 0.19.0 Release : 1.fc44 URL : https://github.com/restic/restic Summary : Fast, secure, efficient backup program Description : Fast, secure, efficient backup program. restic supports the following backends for storing backups natively: * Local directory * sftp server (via SSH) * HTTP REST server (protocol, rest-server) * Amazon S3 (either from Amazon or using the Minio server) * OpenStack Swift * BackBlaze B2 * Microsoft Azure Blob Storage * Google Cloud Storage * And many other services via the rclone Backend -------------------------------------------------------------------------------- Update Information: Update to 0.19.0 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 10 2026 Mikel Olasagasti Uranga - 0.19.0-1 - Update to 0.19.0 - Closes rhbz#2487290 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455673 - CVE-2026-34986 restic: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455673 [ 2 ] Bug #2464136 - CVE-2026-41179 restic: Rclone: Unauthenticated local command execution via exposed RC endpoint [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2464136 [ 3 ] Bug #2464140 - CVE-2026-41176 restic: Rclone: Unauthorized access to administrative functions through unauthenticated Remote Control endpoint. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2464140 [ 4 ] Bug #2486238 - CVE-2026-45287 restic: OpenTelemetry-Go: Denial of Service due to file descriptor leak [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486238 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2290b9a9ad' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability and has three fixes is now available.. openSUSE Security Update: Security update for restic ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0206-1 Rating: important References: #1240262 #1265915 #1266211 #1266795 Cross-References: CVE-2026-33814 CVSS scores: CVE-2026-33814 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that solves one vulnerability and has three fixes is now available. Description: This update for restic fixes the following issues: Update to 0.19.0 (boo#1266795 boo#1266211): For all the details see: https://github.com/restic/restic/releases/tag/v0.19.0 - Fix #2034: Support serving a restic mount of a Windows system via Samba - Fix #4447: Use mode 0700 for repository directories created over SFTP - Fix #4467: Exit with code 3 when some backup source paths do not exist - Fix #4759: Error out when environment variables hold invalid values - Fix #5233: Return exit code 3 when failing to remove snapshots - Fix #5258: Exit with code 130 on SIGINT - Fix #5280: Reject impossible find time bounds immediately - Fix #5280: Make find --pack list blobs for tree packs - Fix #5354: Allow rclone and sftp backends when running in background - Fix #5427: Correctly restore ACL inheritance state on Windows - Fix #5477: Password prompt was sometimes not shown for backup -v - Fix #5487: Mark repository files read-only when using the SFTP backend - Fix #5586: Correctly handle snapshots --group-by with --latest - Fix #5595: Avoid spurious chmod errors on certain file backends - Fix #5683: Prevent backup --stdin-from-command from hanging - Fix #5757: Respect --user and --host inkey passwd - Fix #21820: Correct handling of duplicate index entries - Fix #21820: Correctly handle pack files missing from the index - Chg #5293: Prune small packfiles more aggressively - Chg #5767: Prevent excluding paths explicitly passed to backup - Chg #21791: Update dependencies and require Go 1.25 or newer - Enh #3326: Limit check to snapshots selected by filters - Enh #3572: Support restoring ownership by name on UNIX systems - Enh #3738: Optional GitHub token for self-update API requests - Enh #4278: Support include filters in the rewrite command - Enh #4728: Support zstd compression levels fastest and better - Enh #4868: Include repository ID in the filesystem name used by mount - Enh #5175: Add status counters to copy in verbose text output - Enh #5352: Support excluding cloud-backed files on macOS - Enh #5383: Reduce progress bar refresh rates to decrease energy usage - Enh #5424: Enable Windows filesystem privileges before file access - Enh #5440: Make --host override environment variable RESTIC_HOST - Enh #5448: Support configuring nice and ionice in the Docker image - Enh #5453: Copy multiple snapshots in batches - Enh #5523: Add Open Container Initiative labels to release Docker image - Enh #5531: Reduce Azure storage costs by optimizing uploads - Enh #5562: Rewrite only changed status lines each frame - Enh #5588: Show timezone context in snapshots output - Enh #5610: Reduce check, copy, diff and stats memory usage - Enh #5689: Show more detailed progress for stats - Enh #5713: Significantly speed up index loading - Enh #5718: Stricter and earlier validation of the mount point - refresh disable-selfupdate.patch - Update golang.org/x/net to 0.53.0 (boo#1265915 CVE-2026-33814) - Add fuse recommends as it's needed for mounting restic snapshots and should as such be part of the package. update to 0.18.1: - Fix #5324: Correctly handle backup--stdin-filename with directory paths - Fix #5325: Accept RESTIC_HOST environment variable in forget command - Fix #5342: Ignore "chmod not supported" errors when writing files - Fix #5344: Ignore EOPNOTSUPP errors for extended attributes - Fix #5421: Fix rare crash if directory is removed during backup - Fix #5429: Stop retrying uploads when rest-server runs out of space - Fix #5467: Improve handling of download retries in check command all details at https://github.com/restic/restic/releases/tag/v0.18.1 Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-206=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le x86_64): restic-0.19.0-bp157.2.3.1 - openSUSE Backports SLE-15-SP7 (noarch): restic-bash-completion-0.19.0-bp157.2.3.1 restic-zsh-completion-0.19.0-bp157.2.3.1 References: https://www.suse.com/security/cve/CVE-2026-33814.html https://bugzilla.suse.com/1240262 https://bugzilla.suse.com/1265915 https://bugzilla.suse.com/1266211 https://bugzilla.suse.com/1266795 . An important security update for restic on openSUSE addresses critical issues and includes several fixes.. important update, restic security, openSUSE patch, software fixes, system security. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # restic-0.18.1-3.1 on GA media Announcement ID: openSUSE-SU-2026:10912-1 Rating: moderate Cross-References: * CVE-2026-33814 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the restic-0.18.1-3.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * restic 0.18.1-3.1 * restic-bash-completion 0.18.1-3.1 * restic-zsh-completion 0.18.1-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html . Moderate security advisory for openSUSE Tumbleweed addressing vulnerability in restic-0.18.1-3.1 package.. openSUSE,Tumbleweed,restic,security patch. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # restic-0.18.1-3.1 on GA media Announcement ID: openSUSE-SU-2026:10912-1 Rating: moderate Cross-References: * CVE-2026-33814 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the restic-0.18.1-3.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * restic 0.18.1-3.1 * restic-bash-completion 0.18.1-3.1 * restic-zsh-completion 0.18.1-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html . Security advisory for openSUSE Tumbleweed addresses a moderate risk in restic package, fixing crucial vulnerabilities.. openSUSE Tumbleweed, restic security, moderate vulnerability, Linux updates, open source security. . Severity: moderate. LinuxSecurity.com Team
Update to 0.18.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-65fc438cba 2025-12-03 01:05:22.296763+00:00 -------------------------------------------------------------------------------- Name : restic Product : Fedora 42 Version : 0.18.1 Release : 1.fc42 URL : https://github.com/restic/restic Summary : Fast, secure, efficient backup program Description : Fast, secure, efficient backup program. restic supports the following backends for storing backups natively: * Local directory * sftp server (via SSH) * HTTP REST server (protocol, rest-server) * Amazon S3 (either from Amazon or using the Minio server) * OpenStack Swift * BackBlaze B2 * Microsoft Azure Blob Storage * Google Cloud Storage * And many other services via the rclone Backend -------------------------------------------------------------------------------- Update Information: Update to 0.18.1 -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 24 2025 Mikel Olasagasti Uranga - 0.18.1-1 - Update to 0.18.1 - Closes rhbz#2397204 rhbz2416773 * Fri Oct 10 2025 Alejandro Sez - 0.18.0-5 - rebuild * Fri Aug 15 2025 Maxwell G - 0.18.0-4 - Rebuild for golang-1.25.0 * Fri Jul 25 2025 Fedora Release Engineering - 0.18.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2398882 - CVE-2025-47910 restic: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398882 [ 2 ] Bug #2399561 - CVE-2025-47906 restic: Unexpected paths returned from LookPath in os/exec [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2399561 [ 3 ] Bug #2408090 - CVE-2025-58189 restic: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2408090 [ 4 ] Bug #2408687 - CVE-2025-61725 restic: Excessive CPU consumption in ParseAddress in net/mail [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2408687 [ 5 ] Bug #2409560 - CVE-2025-61723 restic: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2409560 [ 6 ] Bug #2410511 - CVE-2025-58185 restic: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2410511 [ 7 ] Bug #2411409 - CVE-2025-58188 restic: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2411409 [ 8 ] Bug #2412816 - CVE-2025-58183 restic: Unbounded allocation when parsing GNU sparse map [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2412816 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-65fc438cba' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical update for restic on Fedora 42 addressing multiple security issues, improve backup efficiency.. Fedora Security Advisory, Restic Backup Program, Fedora 42 Updates, Restic Security Issues. . Severity: Important. LinuxSecurity.com Team
Update to 0.18.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-416c3b48b3 2025-12-03 00:52:00.122550+00:00 -------------------------------------------------------------------------------- Name : restic Product : Fedora 43 Version : 0.18.1 Release : 1.fc43 URL : https://github.com/restic/restic Summary : Fast, secure, efficient backup program Description : Fast, secure, efficient backup program. restic supports the following backends for storing backups natively: * Local directory * sftp server (via SSH) * HTTP REST server (protocol, rest-server) * Amazon S3 (either from Amazon or using the Minio server) * OpenStack Swift * BackBlaze B2 * Microsoft Azure Blob Storage * Google Cloud Storage * And many other services via the rclone Backend -------------------------------------------------------------------------------- Update Information: Update to 0.18.1 -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 24 2025 Mikel Olasagasti Uranga - 0.18.1-1 - Update to 0.18.1 - Closes rhbz#2397204 rhbz2416773 * Fri Oct 10 2025 Alejandro Sez - 0.18.0-5 - rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2408344 - CVE-2025-58189 restic: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408344 [ 2 ] Bug #2408743 - CVE-2025-61725 restic: Excessive CPU consumption in ParseAddress in net/mail [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408743 [ 3 ] Bug #2409817 - CVE-2025-61723 restic: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409817 [ 4 ] Bug #2410767 - CVE-2025-58185 restic: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410767 [ 5 ] Bug #2411663 - CVE-2025-58188 restic: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411663 [ 6 ] Bug #2412599 - CVE-2025-58183 restic: Unbounded allocation when parsing GNU sparse map [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2412599 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-416c3b48b3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update available for restic 0.18.1 in Fedora 43 correcting multiple important security issues related to CPU use and memory exhaustion.. restic update,Fedora 43,security threats,CPU consumption,backup program. . Severity: Important. LinuxSecurity.com Team
An update that contains security fixes can now be installed. . openSUSE Security Update: Security update for restic ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0110-1 Rating: moderate References: Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for restic fixes the following issues: Update to 0.18.0 - Sec #5291: Mitigate attack on content-defined chunking algorithm - Fix #1843: Correctly restore long filepaths' timestamp on old Windows - Fix #2165: Ignore disappeared backup source files - Fix #5153: Include root tree when searching using find --tree - Fix #5169: Prevent Windows VSS event log 8194 warnings for backup with fs snapshot - Fix #5212: Fix duplicate data handling in prune --max-unused - Fix #5249: Fix creation of oversized index by repair index --read-all-packs - Fix #5259: Fix rare crash in command output - Chg #4938: Update dependencies and require Go 1.23 or newer - Chg #5162: Promote feature flags - Enh #1378: Add JSON support to check command - Enh #2511: Support generating shell completions to stdout - Enh #3697: Allow excluding online-only cloud files (e.g. OneDrive) - Enh #4179: Add sort option to ls command - Enh #4433: Change default sort order for find output - Enh #4521: Add support for Microsoft Blob Storage access tiers - Enh #4942: Add snapshot summary statistics to rewritten snapshots - Enh #4948: Format exit errors as JSON when requested - Enh #4983: Add SLSA provenance to GHCR container images - Enh #5054: Enable compression for ZIP archives in dump command - Enh #5081: Add retry mechanism for loading repository config - Enh #5089: Allow including/excluding extended file attributes during restore - Enh#5092: Show count of deleted files and directories during restore - Enh #5109: Make small pack size configurable for prune - Enh #5119: Add start and end timestamps to backup JSON output - Enh #5131: Add DragonFlyBSD support - Enh #5137: Make tag command print which snapshots were modified - Enh #5141: Provide clear error message if AZURE_ACCOUNT_NAME is not set - Enh #5173: Add experimental S3 cold storage support - Enh #5174: Add xattr support for NetBSD 10+ - Enh #5251: Improve retry handling for flaky rclone backends - Enh #52897: Make recover automatically rebuild index when needed Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-110=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64): restic-0.18.0-bp156.2.6.1 - openSUSE Backports SLE-15-SP6 (noarch): restic-bash-completion-0.18.0-bp156.2.6.1 restic-zsh-completion-0.18.0-bp156.2.6.1 References: . Restic update for openSUSE addresses issues including a content-defined chunking attack mitigation and enhances file handling.. security, update, fixes, installed, opensuse. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.