Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-38878 http://linux.oracle.com/errata/ELSA-2026-38878.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: podman-5.8.2-5.0.1.el9_8.x86_64.rpm podman-docker-5.8.2-5.0.1.el9_8.noarch.rpm podman-plugins-5.8.2-5.0.1.el9_8.x86_64.rpm podman-remote-5.8.2-5.0.1.el9_8.x86_64.rpm podman-tests-5.8.2-5.0.1.el9_8.x86_64.rpm aarch64: podman-5.8.2-5.0.1.el9_8.aarch64.rpm podman-docker-5.8.2-5.0.1.el9_8.noarch.rpm podman-plugins-5.8.2-5.0.1.el9_8.aarch64.rpm podman-remote-5.8.2-5.0.1.el9_8.aarch64.rpm podman-tests-5.8.2-5.0.1.el9_8.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/podman-5.8.2-5.0.1.el9_8.src.rpm Related CVEs: CVE-2026-39822 Description of changes: [5.8.2-5.0.1] - Rework CNI/Netavark detection logic [JIRA: EVG-3769] - Rebuild on new golang to support experimental GODEBUG fipsnoenforceems - Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404] [6:5.8.2-5] - rebuild for CVE-2026-39822 - Resolves: RHEL-193646 _______________________________________________ El-errata mailing list
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for flannel ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0239-1 Rating: important References: #1265780 #1266620 Cross-References: CVE-2026-33814 CVE-2026-39821 CVSS scores: CVE-2026-33814 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2026-39821 (SUSE): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for flannel fixes the following issues: - Update to version 0.28.7: * prepare for release v0.28.7 (#2485) * fix: use install-conf in chart (#2484) * fix: use semver tag type in Docker meta to support release events (#2483) * build(deps): bump github/codeql-action/upload-sarif (#2480) * build(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 (#2473), fix for CVE-2026-33814 (boo#1265780) and CVE-2026-39821 (boo#1266620) * build(deps): bump docker/build-push-action from 7.2.0 to 7.3.0 (#2479) * build(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 (#2478) * build(deps): bump docker/metadata-action from 6.1.0 to 6.2.0 (#2476) * build(deps): bump the tencent group with 2 updates (#2475) * build(deps): bump the etcd group with 4 updates (#2474) * fix: skip invalid CIDRs in subnet file readers (#2454) * subnet/etcd: recover subnet watch from compaction (#2471) * Bump the tencent group across 1 directory with 2 updates (#2461) * Bump actions/attest-build-provenance from 4.1.0 to 4.1.1 (#2467) * Bump actions/setup-go from 6.4.0 to 6.5.0 (#2468) * feat: new install_conf cmd to install flannel'sconfig file (#2466) * Bump the other-go-modules group with 2 updates (#2464) * Bump actions/checkout from 6.0.2 to 7.0.0 (#2465) * Bump github/codeql-action from 4.36.0 to 4.36.2 (#2463) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-239=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): flannel-0.28.7-bp157.2.12.1 - openSUSE Backports SLE-15-SP7 (noarch): flannel-k8s-yaml-0.28.7-bp157.2.12.1 References: https://www.suse.com/security/cve/CVE-2026-33814.html https://www.suse.com/security/cve/CVE-2026-39821.html https://bugzilla.suse.com/1265780 https://bugzilla.suse.com/1266620 . An important update to openSUSE flannel addresses critical issues to enhance security. Learn about the flaws and fixes.. openSUSE flannel security update, crucial patches, security advisory highlights. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-33445 http://linux.oracle.com/errata/ELSA-2026-33445.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: thunderbird-140.12.0-1.0.1.el8_10.x86_64.rpm aarch64: thunderbird-140.12.0-1.0.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/thunderbird-140.12.0-1.0.1.el8_10.src.rpm Related CVEs: CVE-2026-12289 CVE-2026-12290 CVE-2026-12291 CVE-2026-12292 CVE-2026-12294 CVE-2026-12295 CVE-2026-12296 CVE-2026-12297 CVE-2026-12298 CVE-2026-12299 CVE-2026-12302 CVE-2026-12304 CVE-2026-12305 CVE-2026-12306 CVE-2026-12307 CVE-2026-12308 CVE-2026-12309 CVE-2026-12310 CVE-2026-12311 CVE-2026-12312 CVE-2026-12313 CVE-2026-12314 CVE-2026-12315 CVE-2026-12324 CVE-2026-12325 CVE-2026-12327 CVE-2026-12328 CVE-2026-12329 CVE-2026-12330 Description of changes: [140.12.0-1.0.1] - Fix prefs for new nss [Orabug: 37079820] - Add Oracle prefs file [140.12.0] - Add OpenELA debranding [140.12.0-1] - Update to 140.12.0 ESR _______________________________________________ El-errata mailing list
An update that solves eight vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:20863-1 Release Date: 2026-03-24T16:49:35Z Rating: important References: * bsc#1247240 * bsc#1255053 * bsc#1255378 * bsc#1255402 * bsc#1255895 * bsc#1256624 * bsc#1256644 * bsc#1257669 Cross-References: * CVE-2025-38488 * CVE-2025-40258 * CVE-2025-40284 * CVE-2025-40297 * CVE-2025-68284 * CVE-2025-68285 * CVE-2025-68813 * CVE-2025-71085 CVSS scores: * CVE-2025-38488 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38488 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38488 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40258 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40258 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40284 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40284 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40297 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40297 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68284 ( SUSE ): 7.0 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-68284 ( SUSE ): 7.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2025-68285 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-68285 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68813 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-68813 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71085 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N *CVE-2025-71085 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues The following security issues were fixed: * CVE-2025-38488: smb: client: fix use-after-free in crypt_message when using async crypto (bsc#1247240). * CVE-2025-40258: mptcp: fix race condition in mptcp_schedule_work() (bsc#1255053). * CVE-2025-40284: Bluetooth: MGMT: cancel mesh send timer when hdev removed (bsc#1257669). * CVE-2025-40297: net: bridge: fix use-after-free due to MST port state bypass (bsc#1255895). * CVE-2025-68284: libceph: prevent potential out-of-bounds writes in handle_auth_session_key() (bsc#1255378). * CVE-2025-68285: libceph: fix potential use-after-free in have_mon_and_osd_map() (bsc#1255402). * CVE-2025-68813: ipvs: fix ipv4 null-ptr-deref in route error path (bsc#1256644). * CVE-2025-71085: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (bsc#1256624). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-313=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-34-default-6-1.1 * kernel-livepatch-MICRO-6-0_Update_11-debugsource-6-1.1 * kernel-livepatch-6_4_0-34-default-debuginfo-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-38488.html * https://www.suse.com/security/cve/CVE-2025-40258.html * https://www.suse.com/security/cve/CVE-2025-40284.html * https://www.suse.com/security/cve/CVE-2025-40297.html *https://www.suse.com/security/cve/CVE-2025-68284.html * https://www.suse.com/security/cve/CVE-2025-68285.html * https://www.suse.com/security/cve/CVE-2025-68813.html * https://www.suse.com/security/cve/CVE-2025-71085.html * https://bugzilla.suse.com/show_bug.cgi?id=1247240 * https://bugzilla.suse.com/show_bug.cgi?id=1255053 * https://bugzilla.suse.com/show_bug.cgi?id=1255378 * https://bugzilla.suse.com/show_bug.cgi?id=1255402 * https://bugzilla.suse.com/show_bug.cgi?id=1255895 * https://bugzilla.suse.com/show_bug.cgi?id=1256624 * https://bugzilla.suse.com/show_bug.cgi?id=1256644 * https://bugzilla.suse.com/show_bug.cgi?id=1257669 . Install the latest SUSE Linux Micro kernel patch addressing eight essential updates and security issues.. SUSE Linux Micro, Kernel Patch, Security Updates, Risk Management, Important Fixes. . Severity: Important. LinuxSecurity.com Team
* bsc#1241802 Cross-References: * CVE-2025-22872 . # Security update for helm Announcement ID: SUSE-SU-2025:02121-1 Release Date: 2025-06-26T08:34:33Z Rating: important References: * bsc#1241802 Cross-References: * CVE-2025-22872 CVSS scores: * CVE-2025-22872 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L * CVE-2025-22872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L * CVE-2025-22872 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L Affected Products: * Containers Module 15-SP6 * Containers Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP6 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for helm fixes the following issues: Update to version 3.18.3: * build(deps): bump golang.org/x/crypto from 0.38.0 to 0.39.0 6838ebc (dependabot[bot]) * fix: user username password for login 5b9e2f6 (Terry Howe) * Update pkg/registry/transport.go 2782412 (Terry Howe) * Update pkg/registry/transport.go e66cf6a (Terry Howe) * fix: add debug logging to oci transport 191f05c (Terry Howe) Update to version 3.18.2: * fix: legacy docker support broken for login 04cad46 (Terry Howe) * Handle an empty registry config file. bc9f8a2 (Matt Farina) Update to version 3.18.1: * Notes: * This release fixes regressions around template generation and OCI registry interaction in 3.18.0 * There are at least 2 known regressions unaddressed in this release. They are being worked on. * Empty registry configurationfiles. When the file exists but it is empty. * Login to Docker Hub on some domains fails. * Changelog * fix(client): skipnode utilization for PreCopy * fix(client): layers now returns manifest - remove duplicate from descriptors * fix(client): return nil on non-allowed media types * Prevent fetching newReference again as we have in calling method * Prevent failure when resolving version tags in oras memory store * Update pkg/plugin/plugin.go * Update pkg/plugin/plugin.go * Wait for Helm v4 before raising when platformCommand and Command are set * Fix 3.18.0 regression: registry login with scheme * Revert "fix (helm) : toToml` renders int as float [ backport to v3 ]" Update to version 3.18.0 (bsc#1241802, CVE-2025-22872): * Notable Changes * Add support for JSON Schema 2020 * Enabled cpu and memory profiling * Add hook annotation to output hook logs to client on error * Changelog * build(deps): bump the k8s-io group with 7 updates * fix: govulncheck workflow * bump version to v3.18.0 * fix:add proxy support when mTLS configured * docs: Note about http fallback for OCI registries * Bump net package to avoid CVE on dev-v3 * Bump toml * backport #30677to dev3 * build(deps): bump github.com/rubenv/sql-migrate from 1.7.2 to 1.8.0 * Add install test for TakeOwnership flag * Fix --take-ownership * build(deps): bump github.com/rubenv/sql-migrate from 1.7.1 to 1.7.2 * build(deps): bump golang.org/x/crypto from 0.36.0 to 0.37.0 * build(deps): bump golang.org/x/term from 0.30.0 to 0.31.0 * Testing text bump * Permit more Go version and not only 1.23.8 * Bumps github.com/distribution/distribution/v3 from 3.0.0-rc.3 to 3.0.0 * Unarchiving fix * Fix typo * Report as debug log, the time spent waiting for resources * build(deps): bump github.com/containerd/containerd from 1.7.26 to 1.7.27 * Update pkg/registry/fallback.go * automatic fallback to http * chore(oci):upgrade to ORAS v2 * Updating to 0.37.0 for x/net * build(deps): bump the k8s-io group with 7 updates * build(deps): bump golang.org/x/crypto from 0.35.0 to 0.36.0 * build(deps): bump github.com/opencontainers/image-spec * build(deps): bump github.com/containerd/containerd from 1.7.25 to 1.7.26 * build(deps): bump golang.org/x/crypto from 0.33.0 to 0.35.0 * Fix cherry-pick helm.sh/helm/v4 -> helm.sh/helm/v3 * Add HookOutputFunc and generic yaml unmarshaller * clarify fix error message * fix err check * add short circuit return * Add hook annotations to output pod logs to client on success and fail * chore: use []error instead of []string * Update cmd/helm/profiling.go * chore: update profiling doc in CONTRIBUTING.md * Update CONTRIBUTING guide * Prefer environment variables to CLI flags * Move pprof paths to HELM_PPROF env variable * feat: Add flags to enable CPU and memory profiling * build(deps): bump github.com/distribution/distribution/v3 * build(deps): bump github.com/spf13/cobra from 1.8.1 to 1.9.1 * Moving to SetOut and SetErr for Cobra * build(deps): bump the k8s-io group with 7 updates * build(deps): bump golang.org/x/crypto from 0.32.0 to 0.33.0 * build(deps): bump golang.org/x/term from 0.28.0 to 0.29.0 * build(deps): bump golang.org/x/text from 0.21.0 to 0.22.0 * build(deps): bump github.com/spf13/pflag from 1.0.5 to 1.0.6 * build(deps): bump github.com/cyphar/filepath-securejoin * build(deps): bump github.com/evanphx/json-patch * build(deps): bump the k8s-io group with 7 updates * fix: check group for resource info match * Bump github.com/cyphar/filepath-securejoin from 0.3.6 to 0.4.0 * add test for nullifying nested global value * Ensuring the file paths are clean prior to passing to securejoin * Bump github.com/containerd/containerd from 1.7.24 to 1.7.25 * Bump golang.org/x/crypto from 0.31.0 to 0.32.0 * Bump golang.org/x/term from 0.27.0 to 0.28.0 * bump version to v3.17.0 * Bump github.com/moby/term from 0.5.0 to 0.5.2 * Add test case for removing an entire object * Tests for bugfix: Override subcharts with null values #12879 * feat: Added multi-platform plugin hook support to v3 * This commit fixes the issue where the yaml.Unmarshaller converts all int values into float64, this passes in option to decoder, which enables conversion of int into . * merge null child chart objects ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-2121=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-2121=1 * Containers Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Containers-15-SP6-2025-2121=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2025-2121=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-2121=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-2121=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * helm-3.18.3-150000.1.50.1 * helm-debuginfo-3.18.3-150000.1.50.1 * openSUSE Leap 15.6 (noarch) * helm-fish-completion-3.18.3-150000.1.50.1 * helm-bash-completion-3.18.3-150000.1.50.1 * helm-zsh-completion-3.18.3-150000.1.50.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * helm-3.18.3-150000.1.50.1 * helm-debuginfo-3.18.3-150000.1.50.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * helm-bash-completion-3.18.3-150000.1.50.1 * Containers Module 15-SP6 (aarch64 ppc64le s390x x86_64) * helm-3.18.3-150000.1.50.1 * helm-debuginfo-3.18.3-150000.1.50.1 * Containers Module 15-SP6 (noarch) *helm-zsh-completion-3.18.3-150000.1.50.1 * helm-bash-completion-3.18.3-150000.1.50.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * helm-3.18.3-150000.1.50.1 * helm-debuginfo-3.18.3-150000.1.50.1 * Containers Module 15-SP7 (noarch) * helm-zsh-completion-3.18.3-150000.1.50.1 * helm-bash-completion-3.18.3-150000.1.50.1 * SUSE Package Hub 15 15-SP6 (noarch) * helm-fish-completion-3.18.3-150000.1.50.1 * SUSE Package Hub 15 15-SP7 (noarch) * helm-fish-completion-3.18.3-150000.1.50.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22872.html * https://bugzilla.suse.com/show_bug.cgi?id=1241802 . Essential enhancement for helm tackles significant vulnerabilities to fortify SUSE system defense and preserve data reliability.. SUSE security update, helm patch instructions, critical helm issue. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7516-1 May 16, 2025 linux, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-oracle vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-oracle: Linux kernel for Oracle Cloud systems - linux-azure-5.4: Linux kernel for Microsoft Azure cloud systems - linux-gcp-5.4: Linux kernel for Google Cloud Platform (GCP) systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - PowerPC architecture; - Block layer subsystem; - Drivers core; - Network block device driver; - Character device driver; - GPU drivers; - HID subsystem; - InfiniBand drivers; - Media drivers; - Network drivers; - PPS (Pulse Per Second) driver; - PTP clock framework; - RapidIO drivers; - Real Time Clock drivers; - SCSI subsystem; - SLIMbus drivers; - QCOM SoC drivers; - Trusted Execution Environment drivers; - USB DSL drivers; - USB Device Class drivers; - USB core drivers; - USB Gadget drivers; - USB Host Controller drivers; - Renesas USBHS Controller drivers; - File systems infrastructure; - BTRFS file system; - NILFS2 file system; - UBI file system; - KVM subsystem; - L3 Master device support module; - Process Accounting mechanism; - printk logging mechanism; - Scheduler infrastructure; - Tracing infrastructure; - Memorymanagement; - 802.1Q VLAN protocol; - B.A.T.M.A.N. meshing protocol; - Bluetooth subsystem; - Networking core; - IPv4 networking; - IPv6 networking; - Logical Link layer; - NFC subsystem; - Open vSwitch; - Rose network layer; - Network traffic control; - Wireless networking; - Tomoyo security module; (CVE-2025-21866, CVE-2025-21846, CVE-2025-21971, CVE-2025-21909, CVE-2024-58083, CVE-2025-21811, CVE-2025-21776, CVE-2024-58051, CVE-2025-21917, CVE-2025-21935, CVE-2025-21785, CVE-2021-47191, CVE-2025-21765, CVE-2025-21704, CVE-2025-21647, CVE-2024-58069, CVE-2025-21877, CVE-2025-21948, CVE-2024-58007, CVE-2024-58001, CVE-2025-21871, CVE-2024-58055, CVE-2025-21848, CVE-2025-21925, CVE-2024-58058, CVE-2025-21814, CVE-2025-21905, CVE-2025-21898, CVE-2025-21926, CVE-2025-21760, CVE-2024-57973, CVE-2025-21806, CVE-2024-58071, CVE-2025-21761, CVE-2025-21762, CVE-2024-57986, CVE-2025-21708, CVE-2025-21744, CVE-2024-26996, CVE-2024-50055, CVE-2024-58020, CVE-2025-21858, CVE-2025-21715, CVE-2025-21904, CVE-2025-21920, CVE-2024-56599, CVE-2025-21781, CVE-2025-21764, CVE-2025-21865, CVE-2025-21772, CVE-2024-58072, CVE-2025-21928, CVE-2025-21859, CVE-2025-21721, CVE-2025-21719, CVE-2025-21914, CVE-2025-21753, CVE-2024-58009, CVE-2024-57981, CVE-2024-58063, CVE-2024-58052, CVE-2025-21722, CVE-2024-57977, CVE-2025-21736, CVE-2025-21922, CVE-2024-26982, CVE-2025-21718, CVE-2025-21916, CVE-2025-21749, CVE-2025-21787, CVE-2024-58085, CVE-2024-58010, CVE-2024-57979, CVE-2024-57980, CVE-2025-21782, CVE-2025-21791, CVE-2025-21728, CVE-2023-52741, CVE-2025-21934, CVE-2024-58002, CVE-2025-21735, CVE-2025-21910, CVE-2025-21823, CVE-2024-58090, CVE-2025-21862, CVE-2025-21731, CVE-2025-21835, CVE-2024-58017, CVE-2024-58014, CVE-2025-21763) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.4.0-1144-oracle 5.4.0-1144.154 linux-image-5.4.0-1149-gcp 5.4.0-1149.158 linux-image-5.4.0-216-generic 5.4.0-216.236 linux-image-5.4.0-216-generic-lpae 5.4.0-216.236 linux-image-5.4.0-216-lowlatency 5.4.0-216.236 linux-image-gcp-lts-20.04 5.4.0.1149.151 linux-image-generic 5.4.0.216.208 linux-image-generic-lpae 5.4.0.216.208 linux-image-lowlatency 5.4.0.216.208 linux-image-oem 5.4.0.216.208 linux-image-oem-osp1 5.4.0.216.208 linux-image-oracle-lts-20.04 5.4.0.1144.138 linux-image-virtual 5.4.0.216.208 Ubuntu 18.04 LTS linux-image-5.4.0-1149-gcp 5.4.0-1149.158~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-1151-azure 5.4.0-1151.158~18.04.1 Available with Ubuntu Pro linux-image-azure 5.4.0.1151.158~18.04.1 Available with Ubuntu Pro linux-image-gcp 5.4.0.1149.158~18.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7516-1 CVE-2021-47191, CVE-2023-52741, CVE-2024-26982, CVE-2024-26996, CVE-2024-50055, CVE-2024-56599, CVE-2024-57973, CVE-2024-57977, CVE-2024-57979, CVE-2024-57980, CVE-2024-57981, CVE-2024-57986, CVE-2024-58001, CVE-2024-58002, CVE-2024-58007, CVE-2024-58009, CVE-2024-58010, CVE-2024-58014, CVE-2024-58017, CVE-2024-58020, CVE-2024-58051, CVE-2024-58052,CVE-2024-58055, CVE-2024-58058, CVE-2024-58063, CVE-2024-58069, CVE-2024-58071, CVE-2024-58072, CVE-2024-58083, CVE-2024-58085, CVE-2024-58090, CVE-2025-21647, CVE-2025-21704, CVE-2025-21708, CVE-2025-21715, CVE-2025-21718, CVE-2025-21719, CVE-2025-21721, CVE-2025-21722, CVE-2025-21728, CVE-2025-21731, CVE-2025-21735, CVE-2025-21736, CVE-2025-21744, CVE-2025-21749, CVE-2025-21753, CVE-2025-21760, CVE-2025-21761, CVE-2025-21762, CVE-2025-21763, CVE-2025-21764, CVE-2025-21765, CVE-2025-21772, CVE-2025-21776, CVE-2025-21781, CVE-2025-21782, CVE-2025-21785, CVE-2025-21787, CVE-2025-21791, CVE-2025-21806, CVE-2025-21811, CVE-2025-21814, CVE-2025-21823, CVE-2025-21835, CVE-2025-21846, CVE-2025-21848, CVE-2025-21858, CVE-2025-21859, CVE-2025-21862, CVE-2025-21865, CVE-2025-21866, CVE-2025-21871, CVE-2025-21877, CVE-2025-21898, CVE-2025-21904, CVE-2025-21905, CVE-2025-21909, CVE-2025-21910, CVE-2025-21914, CVE-2025-21916, CVE-2025-21917, CVE-2025-21920, CVE-2025-21922, CVE-2025-21925, CVE-2025-21926, CVE-2025-21928, CVE-2025-21934, CVE-2025-21935, CVE-2025-21948, CVE-2025-21971 Package Information: https://launchpad.net/ubuntu/+source/linux/5.4.0-216.236 https://launchpad.net/ubuntu/+source/linux-gcp/5.4.0-1149.158 https://launchpad.net/ubuntu/+source/linux-oracle/5.4.0-1144.154 . A range of vulnerabilities fixed in the recent Ubuntu Linux kernel release to bolster system defenses.. Ubuntu Kernel, Linux Security, System Update, Software Patch, Security Management. . Severity: Critical. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 2 for SLE 15 SP6) Announcement ID: SUSE-SU-2025:0669-1 Release Date: 2025-02-24T09:03:58Z Rating: important References: * bsc#1227371 * bsc#1236783 Cross-References: * CVE-2024-36974 * CVE-2024-53104 CVSS scores: * CVE-2024-36974 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53104 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 6.4.0-150600_23_14 fixes several issues. The following security issues were fixed: * CVE-2024-36974: net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP (bsc#1227371). * CVE-2024-53104: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format (bsc#1236783). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-669=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-669=1 ## Package List: * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_14-default-debuginfo-9-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_2-debugsource-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_14-default-9-150600.2.1 * SUSE Linux Enterprise Live Patching 15-SP6(ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_14-default-debuginfo-9-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_2-debugsource-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_14-default-9-150600.2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-36974.html * https://www.suse.com/security/cve/CVE-2024-53104.html * https://bugzilla.suse.com/show_bug.cgi?id=1227371 * https://bugzilla.suse.com/show_bug.cgi?id=1236783 . Crucial Linux Kernel security patch addresses pair of flaws in openSUSE and SLE 15 SP6. Prompt response recommended.. Linux Kernel Security Patch, openSUSE Update, Critical Security Advisory. . Severity: Critical. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-20018 http://linux.oracle.com/errata/ELSA-2025-20018.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: aarch64: bpftool-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-container-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-container-debug-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-core-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-debug-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-debug-core-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-debug-devel-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-debug-modules-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-debug-modules-extra-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-devel-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-doc-5.15.0-304.171.4.el9uek.noarch.rpm kernel-uek-modules-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-modules-extra-5.15.0-304.171.4.el9uek.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//kernel-uek-5.15.0-304.171.4.el9uek.src.rpm Related CVEs: CVE-2024-46770 CVE-2024-53060 CVE-2024-53070 CVE-2024-53097 CVE-2024-53206 CVE-2024-53226 Description of changes: [5.15.0-304.171.4.el9uek] - Revert "unicode: Don't special case ignorable code points" (Linus Torvalds) - Revert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K" (Aurelien Jarno) - tcp: Fix use-after-free of nreq in reqsk_timer_handler(). (Kuniyuki Iwashima) - lib/buildid: Fix build ID parsing logic (Jiri Olsa) - powerpc/vdso: Flag VDSO64 entry points as functions (Christophe Leroy) - mm: krealloc: Fix MTE false alarm in __do_krealloc (Qun-Wei Lin) - Revert "ALSA: hda/conexant: Mute speakers at suspend / shutdown" (JarosÅaw Janik) - usb: dwc3: fix fault at system suspend if device was already runtime suspended (Roger Quadros) - ACPI: PRM: Clean up guid type in struct prm_handler_info (DanCarpenter) - RDMA/hns: Fix NULL pointer derefernce in hns_roce_map_mr_sg() (Junxian Huang) - mm: revert "mm: shmem: fix data-race in shmem_getattr()" (Andrew Morton) - ACPI: CPPC: Fix _CPC register setting issue (Lifeng Zheng) - scsi: qla2xxx: Fix abort in bsg timeout (Quinn Tran) - drm/amdgpu: prevent NULL pointer dereference if ATIF is not supported (Antonio Quartulli) - RDMA/bnxt_re: Check cqe flags to know imm_data vs inv_irkey (Kashyap Desai) - vhost_scsi: log write descriptors (Dongli Zhang) [Orabug: 37393531] - vhost-scsi: protect vq-> log_base with vq-> mutex (Dongli Zhang) [Orabug: 37393531] [5.15.0-304.171.3.el9uek] - build: populate modules_thick.builtin for dirs containing only modules (Nick Alcock) [Orabug: 37381702] - mtd: fix use-after-free in mtd release (Alexander Usyskin) [Orabug: 37371929] - mtd: Clean refcounting with MTD_PARTITIONED_MASTER (Miquel Raynal) [Orabug: 37371929] - mtd: call external _get and _put in right order (Alexander Usyskin) [Orabug: 37371929] - nvmem: core: Check input parameter for NULL in nvmem_unregister() (Andy Shevchenko) [Orabug: 37371929] - Revert "ocfs2: fix the la space leak when unmounting an ocfs2 volume" (Sherry Yang) [Orabug: 37364544] - x86/pkeys: Ensure updated PKRU value is XRSTOR'd (Aruna Ramakrishna) [Orabug: 37361290] - x86/pkeys: Change caller of update_pkru_in_sigframe() (Aruna Ramakrishna) [Orabug: 37361290] - cgroup: cgroup-v1: do not exclude cgrp_dfl_root (Vishal Verma) [Orabug: 37347419] - mm/memcontrol: Fix memcg stat calculation (Aruna Ramakrishna) [Orabug: 37306542] [5.15.0-304.171.2.el9uek] - uek-rpm: Add mstflint_access module to the core list (Thomas Tai) [Orabug: 37345530] - uek-rpm/ol8/config-aarch64-emb3: Enable CONFIG_ARM_SDE_INTERFACE (Thomas Tai) [Orabug: 37345530] - sunrpc: fix a NULL deref in svc_process() when -> sv_stats doesn't exist (Calum Mackay) [Orabug: 37329531] - Partial revert "rds: Add inc/frag cache statistics" (Hans Westgaard Ry) [Orabug: 37232315] [5.15.0-304.171.1.el9uek] - kpcimgr: assign CPUto handle PCIE transactions during kexec (Joe Dobosenski) [Orabug: 37295980] - kexec: update start address for LPI table data (Joe Dobosenski) [Orabug: 37295980] - kpcimgr: fix flush_icache_range arguments (Joe Dobosenski) [Orabug: 37295980] - embedded2: Enable CONFIG_SQUASHFS_ZSTD to support zstd compression (Joe Dobosenski) [Orabug: 37295980] - embedded2: Support booting an encrypted root filesystem (Joe Dobosenski) [Orabug: 37295980] - Update embedded2 config for UEK7 (Joe Dobosenski) [Orabug: 37295980] - Pensando: kernel config changes for kdump (Rob Gardner) [Orabug: 34091165] [Orabug: 37295980] - arm64: Reserve elfcorehdr before scanning reserved memory from device tree (Joe Dobosenski) [Orabug: 37295980] - arm64: kexec: add support for kexec with spin-table (Henry Willard) [Orabug: 32549965] [Orabug: 37295980] - drivers/soc/pensando/cap_mem.c: Support DM region mapping. (David Clear) [Orabug: 37295980] - drivers/edac: elba: Support multiple DDR bypass ranges. (David Clear) [Orabug: 37295980] - mmc: sdhci-cadence: Enable host driver defined bounce buffer (Brad Larson) [Orabug: 37295980] - Fix NULL pointer dereference in cn_filter() (Anjali Kulkarni) [Orabug: 37280567] - selftests: connector: Fix input argument error paths to skip (Shuah Khan) [Orabug: 37280567] - connector/cn_proc: Selftest for proc connector (Anjali Kulkarni) [Orabug: 37280567] - connector/cn_proc: Allow non-root users access (Anjali Kulkarni) [Orabug: 37280567] - connector/cn_proc: Performance improvements (Anjali Kulkarni) [Orabug: 37280567] - connector/cn_proc: Add filtering to fix some bugs (Anjali Kulkarni) [Orabug: 37280567] - netlink: Add new netlink_release function (Anjali Kulkarni) [Orabug: 37280567] - ice: Add netif_device_attach/detach into PF reset flow (Dawid Osuchowski) [Orabug: 37214589] {CVE-2024-46770} _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.