Important: krb5 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:16799", "synopsis": "Important: krb5 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for krb5.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Kerberos is a network authentication system, which can improve the security of your network by eliminating the insecure practice of sending passwords over the network in unencrypted form. It allows clients and servers to authenticate to each other with the help of a trusted third party, the Kerberos key distribution center (KDC).\n\nSecurity Fix(es):\n\n* krb5: MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read (CVE-2026-40356)\n\n* krb5: MIT Kerberos 5: Denial of Service via NULL pointer dereference in NegoEx mechanism (CVE-2026-40355)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2463368", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2463368", "description": ""}, {"ticket": "2463370", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2463370", "description": ""}], "cves": [{"name": "CVE-2026-40355", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40355", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-476"}, {"name": "CVE-2026-40356", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40356", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-191"}],"references": [], "publishedAt": "2026-05-14T18:00:46.647307Z", "rpms": {"Rocky Linux 8": {"nvras": ["krb5-devel-0:1.18.2-34.el8_10.x86_64.rpm", "krb5-0:1.18.2-34.el8_10.src.rpm", "krb5-debuginfo-0:1.18.2-34.el8_10.aarch64.rpm", "krb5-debuginfo-0:1.18.2-34.el8_10.i686.rpm", "krb5-debuginfo-0:1.18.2-34.el8_10.x86_64.rpm", "krb5-debugsource-0:1.18.2-34.el8_10.aarch64.rpm", "krb5-debugsource-0:1.18.2-34.el8_10.i686.rpm", "krb5-debugsource-0:1.18.2-34.el8_10.x86_64.rpm", "krb5-devel-0:1.18.2-34.el8_10.aarch64.rpm", "krb5-devel-0:1.18.2-34.el8_10.i686.rpm", "krb5-devel-debuginfo-0:1.18.2-34.el8_10.aarch64.rpm", "krb5-devel-debuginfo-0:1.18.2-34.el8_10.i686.rpm", "krb5-devel-debuginfo-0:1.18.2-34.el8_10.x86_64.rpm", "krb5-libs-0:1.18.2-34.el8_10.aarch64.rpm", "krb5-libs-0:1.18.2-34.el8_10.i686.rpm", "krb5-libs-0:1.18.2-34.el8_10.x86_64.rpm", "krb5-libs-debuginfo-0:1.18.2-34.el8_10.aarch64.rpm", "krb5-libs-debuginfo-0:1.18.2-34.el8_10.i686.rpm", "krb5-libs-debuginfo-0:1.18.2-34.el8_10.x86_64.rpm", "krb5-pkinit-0:1.18.2-34.el8_10.aarch64.rpm", "krb5-pkinit-0:1.18.2-34.el8_10.i686.rpm", "krb5-pkinit-0:1.18.2-34.el8_10.x86_64.rpm", "krb5-pkinit-debuginfo-0:1.18.2-34.el8_10.aarch64.rpm", "krb5-pkinit-debuginfo-0:1.18.2-34.el8_10.i686.rpm", "krb5-pkinit-debuginfo-0:1.18.2-34.el8_10.x86_64.rpm", "krb5-server-0:1.18.2-34.el8_10.aarch64.rpm", "krb5-server-0:1.18.2-34.el8_10.i686.rpm", "krb5-server-0:1.18.2-34.el8_10.x86_64.rpm", "krb5-server-debuginfo-0:1.18.2-34.el8_10.aarch64.rpm", "krb5-server-debuginfo-0:1.18.2-34.el8_10.i686.rpm", "krb5-server-debuginfo-0:1.18.2-34.el8_10.x86_64.rpm", "krb5-server-ldap-0:1.18.2-34.el8_10.aarch64.rpm", "krb5-server-ldap-0:1.18.2-34.el8_10.i686.rpm", "krb5-server-ldap-0:1.18.2-34.el8_10.x86_64.rpm", "krb5-server-ldap-debuginfo-0:1.18.2-34.el8_10.aarch64.rpm", "krb5-server-ldap-debuginfo-0:1.18.2-34.el8_10.i686.rpm", "krb5-server-ldap-debuginfo-0:1.18.2-34.el8_10.x86_64.rpm", "krb5-workstation-0:1.18.2-34.el8_10.aarch64.rpm", "krb5-workstation-0:1.18.2-34.el8_10.x86_64.rpm","krb5-workstation-debuginfo-0:1.18.2-34.el8_10.aarch64.rpm", "krb5-workstation-debuginfo-0:1.18.2-34.el8_10.x86_64.rpm", "libkadm5-0:1.18.2-34.el8_10.aarch64.rpm", "libkadm5-0:1.18.2-34.el8_10.i686.rpm", "libkadm5-0:1.18.2-34.el8_10.x86_64.rpm", "libkadm5-debuginfo-0:1.18.2-34.el8_10.aarch64.rpm", "libkadm5-debuginfo-0:1.18.2-34.el8_10.i686.rpm", "libkadm5-debuginfo-0:1.18.2-34.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Critical krb5 security update for Rocky Linux 8 addressing denial of service issues. Be sure to patch promptly for safety.. Rocky Linux, krb5 security, important update, denial of service, software patch. . Severity: Important. LinuxSecurity.com Team
Important: libpng security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:4728", "synopsis": "Important: libpng security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for libpng.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files.\n\nSecurity Fix(es):\n\n* libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API (CVE-2026-22801)\n\n* libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read (CVE-2026-22695)\n\n* libpng: LIBPNG has a heap buffer overflow in png_set_quantize (CVE-2026-25646)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2428824", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2428824", "description": ""}, {"ticket": "2428825", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2428825", "description": ""}, {"ticket": "2438542", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2438542", "description": ""}], "cves": [{"name": "CVE-2026-22695", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-22695", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H", "cvss3BaseScore": "6.1", "cwe": "CWE-125"}, {"name": "CVE-2026-22801", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-22801", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H", "cvss3BaseScore":"6.6", "cwe": "CWE-125"}, {"name": "CVE-2026-25646", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-25646", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H", "cvss3BaseScore": "7.0", "cwe": "CWE-125"}], "references": [], "publishedAt": "2026-03-18T12:00:48.679196Z", "rpms": {"Rocky Linux 8": {"nvras": ["libpng-2:1.6.34-10.el8_10.aarch64.rpm", "libpng-2:1.6.34-10.el8_10.i686.rpm", "libpng-2:1.6.34-10.el8_10.src.rpm", "libpng-2:1.6.34-10.el8_10.x86_64.rpm", "libpng-debuginfo-2:1.6.34-10.el8_10.aarch64.rpm", "libpng-debuginfo-2:1.6.34-10.el8_10.i686.rpm", "libpng-debuginfo-2:1.6.34-10.el8_10.x86_64.rpm", "libpng-debugsource-2:1.6.34-10.el8_10.aarch64.rpm", "libpng-debugsource-2:1.6.34-10.el8_10.i686.rpm", "libpng-debugsource-2:1.6.34-10.el8_10.x86_64.rpm", "libpng-devel-2:1.6.34-10.el8_10.aarch64.rpm", "libpng-devel-2:1.6.34-10.el8_10.i686.rpm", "libpng-devel-2:1.6.34-10.el8_10.x86_64.rpm", "libpng-devel-debuginfo-2:1.6.34-10.el8_10.aarch64.rpm", "libpng-devel-debuginfo-2:1.6.34-10.el8_10.i686.rpm", "libpng-devel-debuginfo-2:1.6.34-10.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Libpng security update released for Rocky Linux 8 addressing critical issues including denial of service and information leakage.. libpng security,cve update,rocky linux advisory. . Severity: Important. LinuxSecurity.com Team
Important: mingw-libpng security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:4306", "synopsis": "Important: mingw-libpng security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for mingw-libpng.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "MinGW Windows Libpng library.\n\nSecurity Fix(es):\n\n* libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API (CVE-2026-22801)\n\n* libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read (CVE-2026-22695)\n\n* libpng: LIBPNG has a heap buffer overflow in png_set_quantize (CVE-2026-25646)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2428824", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2428824", "description": ""}, {"ticket": "2428825", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2428825", "description": ""}, {"ticket": "2438542", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2438542", "description": ""}], "cves": [{"name": "CVE-2026-22695", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-22695", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H", "cvss3BaseScore": "6.1", "cwe": "CWE-125"}, {"name": "CVE-2026-22801", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-22801", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H", "cvss3BaseScore": "6.6", "cwe": "CWE-125"}, {"name": "CVE-2026-25646", "sourceBy": "MITRE", "sourceLink":"https://www.cve.org/CVERecord?id=CVE-2026-25646", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H", "cvss3BaseScore": "7.0", "cwe": "CWE-125"}], "references": [], "publishedAt": "2026-03-12T12:01:58.355924Z", "rpms": {"Rocky Linux 8": {"nvras": ["mingw32-libpng-0:1.6.34-2.el8_10.noarch.rpm", "mingw32-libpng-debuginfo-0:1.6.34-2.el8_10.noarch.rpm", "mingw32-libpng-static-0:1.6.34-2.el8_10.noarch.rpm", "mingw64-libpng-0:1.6.34-2.el8_10.noarch.rpm", "mingw64-libpng-debuginfo-0:1.6.34-2.el8_10.noarch.rpm", "mingw64-libpng-static-0:1.6.34-2.el8_10.noarch.rpm", "mingw-libpng-0:1.6.34-2.el8_10.src.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Explore the important security update for mingw-libpng on Rocky Linux addressing critical issues. Stay secure!. mingw-libpng security update, Rocky Linux security alerts, denial of service, information disclosure. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.