Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves six vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:21887-1 Release Date: 2026-06-01T09:26:24Z Rating: important References: * bsc#1259798 * bsc#1260563 * bsc#1260908 * bsc#1264096 * bsc#1265224 * bsc#1265384 Cross-References: * CVE-2025-54518 * CVE-2026-23243 * CVE-2026-23274 * CVE-2026-23317 * CVE-2026-46300 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23243 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23274 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23317 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23317 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23317 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 (SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-30.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-23243: RDMA/umad: Reject negative data_len in ib_umad_write (bsc#1259798). * CVE-2026-23274: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels (bsc#1260908). * CVE-2026-23317: drm/vmwgfx: Return the correct value in vmw_translate_ptr functions (bsc#1260563). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-455=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-30-default-18-1.2 * kernel-livepatch-6_4_0-30-default-debuginfo-18-1.2 * kernel-livepatch-MICRO-6-0_Update_8-debugsource-18-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-23243.html * https://www.suse.com/security/cve/CVE-2026-23274.html * https://www.suse.com/security/cve/CVE-2026-23317.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1259798 * https://bugzilla.suse.com/show_bug.cgi?id=1260563 *https://bugzilla.suse.com/show_bug.cgi?id=1260908 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 . Critical kernel update for SUSE Linux Enterprise Micro fixes six important vulnerabilities for enhanced security.. SUSE Linux Micro Kernel Update Security Issues Root Exploit. . Severity: Important. LinuxSecurity.com Team
New haveged packages are available for Slackware 15.0 and -current to fix a security issue.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] haveged (SSA:2026-139-01) New haveged packages are available for Slackware 15.0 and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/haveged-1.9.21-i586-1_slack15.0.txz: Upgraded. This update fixes a security issue: Missing exit out of permission check could lead to root exploit. For more information, see: https://www.cve.org/CVERecord?id=CVE-2026-41054 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://slackware.com for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/haveged-1.9.21-i586-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/haveged-1.9.21-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/a/haveged-1.9.21-i686-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/a/haveged-1.9.21-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: 52b3d83fd7bb87f72c70ea684fda742a haveged-1.9.21-i586-1_slack15.0.txz Slackware x86_64 15.0 package: e194704a599fa910d1ae1302161399a0 haveged-1.9.21-x86_64-1_slack15.0.txz Slackware -current package: 728cdda335ad68b7bdeca62356433d73 a/haveged-1.9.21-i686-1.txz Slackware x86_64 -current package: 1a38ed250a1b4a8105ba15dbfdd7d58e a/haveged-1.9.21-x86_64-1.txz Installation instructions: +------------------------+ Upgradethe package as root: # upgradepkg haveged-1.9.21-i586-1_slack15.0.txz Then, restart the daemon: # sh /etc/rc.d/rc.haveged restart +-----+ . Upgrade haveged packages on Slackware 15.0 to fix a critical security issue leading to a root exploit.. haveged package update, Slackware 15.0 security, root exploit fix. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for haveged Announcement ID: SUSE-SU-2026:2008-1 Release Date: 2026-05-19T11:55:08Z Rating: important References: * bsc#1264086 Cross-References: * CVE-2026-41054 CVSS scores: * CVE-2026-41054 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for haveged fixes the following issue * CVE-2026-41054: missing exit out of permission check could lead to root exploit (bsc#1264086). Changes for haveged: * Improvements on the linux kernel random subsystem have made move forward to socket communication within private network * Fix "stop" of service, the daemon in foreground actually see daemon(7) for the rationale. Only "simple" (default) and the help of udev, as starting services while starved of entropy * Add ppc64le support * update to 1.8 * Correct additional run-time test aligment problems on mips. * haveged 1.7a * Correct VPATH issues and modify check target tosupport parallel builds and changes in automake 1.13 test harness. * Remove all sysvinit compatibility. * fix powerpc detection * Current version does support ARM, remove the ExcludeArch need network and can use PrivateNetwork=yes * Add online tests based on AIS-31 * Fix install target, move to bin and eliminate script if not daemon, now use sysv and systemd templates * use -F with no arguments in haveged.service * build with -fpie * Use Service type "simple" in systemd unit * fix build on ia64, s390, s390x * fix ppc64 build present in old versions have been fixed in different ways. * run spec cleaner * Link with full RELRO (-Wl,-z,relro,-z,now) * add systemd support * Drop as much capabilitites as possible using libcap-ng * I meant Enhances not Supplements * Implement hack to start by default only in VMs * use O_CLOEXEC on fds * add proper Requires(pre) * add a SUSE standard init script ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2008=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2008=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2008=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2008=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2008=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2008=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2008=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2008=1 * SUSE Linux Enterprise Server for SAP Applications 15SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2008=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2008=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2008=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2008=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2008=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2008=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libhavege2-1.9.14-150400.3.11.1 * haveged-1.9.14-150400.3.11.1 * haveged-devel-1.9.14-150400.3.11.1 * haveged-debuginfo-1.9.14-150400.3.11.1 * haveged-debugsource-1.9.14-150400.3.11.1 * libhavege2-debuginfo-1.9.14-150400.3.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libhavege2-1.9.14-150400.3.11.1 * libhavege2-debuginfo-1.9.14-150400.3.11.1 * haveged-1.9.14-150400.3.11.1 * haveged-devel-1.9.14-150400.3.11.1 * haveged-debuginfo-1.9.14-150400.3.11.1 * haveged-debugsource-1.9.14-150400.3.11.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libhavege2-1.9.14-150400.3.11.1 * libhavege2-debuginfo-1.9.14-150400.3.11.1 * haveged-1.9.14-150400.3.11.1 * haveged-devel-1.9.14-150400.3.11.1 * haveged-debuginfo-1.9.14-150400.3.11.1 * haveged-debugsource-1.9.14-150400.3.11.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libhavege2-1.9.14-150400.3.11.1 * haveged-1.9.14-150400.3.11.1 * haveged-debuginfo-1.9.14-150400.3.11.1 * haveged-debugsource-1.9.14-150400.3.11.1 * libhavege2-debuginfo-1.9.14-150400.3.11.1 * SUSE Linux Enterprise Micro 5.3(aarch64 s390x x86_64) * libhavege2-1.9.14-150400.3.11.1 * haveged-1.9.14-150400.3.11.1 * haveged-debuginfo-1.9.14-150400.3.11.1 * haveged-debugsource-1.9.14-150400.3.11.1 * libhavege2-debuginfo-1.9.14-150400.3.11.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libhavege2-1.9.14-150400.3.11.1 * haveged-1.9.14-150400.3.11.1 * haveged-debuginfo-1.9.14-150400.3.11.1 * haveged-debugsource-1.9.14-150400.3.11.1 * libhavege2-debuginfo-1.9.14-150400.3.11.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libhavege2-1.9.14-150400.3.11.1 * haveged-1.9.14-150400.3.11.1 * haveged-debuginfo-1.9.14-150400.3.11.1 * haveged-debugsource-1.9.14-150400.3.11.1 * libhavege2-debuginfo-1.9.14-150400.3.11.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libhavege2-1.9.14-150400.3.11.1 * haveged-1.9.14-150400.3.11.1 * haveged-debuginfo-1.9.14-150400.3.11.1 * haveged-debugsource-1.9.14-150400.3.11.1 * libhavege2-debuginfo-1.9.14-150400.3.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libhavege2-1.9.14-150400.3.11.1 * haveged-1.9.14-150400.3.11.1 * haveged-devel-1.9.14-150400.3.11.1 * haveged-debuginfo-1.9.14-150400.3.11.1 * haveged-debugsource-1.9.14-150400.3.11.1 * libhavege2-debuginfo-1.9.14-150400.3.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libhavege2-1.9.14-150400.3.11.1 * libhavege2-debuginfo-1.9.14-150400.3.11.1 * haveged-1.9.14-150400.3.11.1 * haveged-devel-1.9.14-150400.3.11.1 * haveged-debuginfo-1.9.14-150400.3.11.1 * haveged-debugsource-1.9.14-150400.3.11.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libhavege2-1.9.14-150400.3.11.1 * libhavege2-debuginfo-1.9.14-150400.3.11.1 * haveged-1.9.14-150400.3.11.1 * haveged-devel-1.9.14-150400.3.11.1 * haveged-debuginfo-1.9.14-150400.3.11.1 *haveged-debugsource-1.9.14-150400.3.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libhavege2-1.9.14-150400.3.11.1 * libhavege2-debuginfo-1.9.14-150400.3.11.1 * haveged-1.9.14-150400.3.11.1 * haveged-devel-1.9.14-150400.3.11.1 * haveged-debuginfo-1.9.14-150400.3.11.1 * haveged-debugsource-1.9.14-150400.3.11.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libhavege2-1.9.14-150400.3.11.1 * libhavege2-debuginfo-1.9.14-150400.3.11.1 * haveged-1.9.14-150400.3.11.1 * haveged-devel-1.9.14-150400.3.11.1 * haveged-debuginfo-1.9.14-150400.3.11.1 * haveged-debugsource-1.9.14-150400.3.11.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libhavege2-1.9.14-150400.3.11.1 * libhavege2-debuginfo-1.9.14-150400.3.11.1 * haveged-1.9.14-150400.3.11.1 * haveged-devel-1.9.14-150400.3.11.1 * haveged-debuginfo-1.9.14-150400.3.11.1 * haveged-debugsource-1.9.14-150400.3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41054.html * https://bugzilla.suse.com/show_bug.cgi?id=1264086 . Important security advisory for openSUSE addressing root exploit in haveged, CVE-2026-41054. Installation recommended.. openSUSE advisory, security update, haveged root exploit, patch recommendation, CVE-2026-41054. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for haveged Announcement ID: SUSE-SU-2026:2009-1 Release Date: 2026-05-19T11:55:29Z Rating: important References: * bsc#1264086 Cross-References: * CVE-2026-41054 CVSS scores: * CVE-2026-41054 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for haveged fixes the following issue * CVE-2026-41054: missing exit out of permission check could lead to root exploit (bsc#1264086). Changes for haveged: * Improvements on the linux kernel random subsystem have made move forward to socket communication within private network * Fix "stop" of service, the daemon in foreground actually see daemon(7) for the rationale. Only "simple" (default) and the help of udev, as starting services while starved of entropy * Add ppc64le support * update to 1.8 * Correct additional run-time test aligment problems on mips. * haveged 1.7a * Correct VPATH issues and modify check target to support parallel builds and changes in automake 1.13 test harness. * Remove all sysvinit compatibility. * fix powerpc detection * Current version does support ARM, remove the ExcludeArch need network and can use PrivateNetwork=yes * Add online tests based on AIS-31 * Fix install target, move to bin and eliminate script if not daemon, now use sysv and systemd templates * use -F with no arguments in haveged.service * build with -fpie * Use Service type "simple" in systemd unit * fixbuild on ia64, s390, s390x * fix ppc64 build present in old versions have been fixed in different ways. * run spec cleaner * Link with full RELRO (-Wl,-z,relro,-z,now) * add systemd support * Drop as much capabilitites as possible using libcap-ng * I meant Enhances not Supplements * Implement hack to start by default only in VMs * use O_CLOEXEC on fds * add proper Requires(pre) * add a SUSE standard init script ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2009=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2009=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2009=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2009=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * haveged-debugsource-1.9.14-150600.11.6.1 * libhavege2-1.9.14-150600.11.6.1 * libhavege2-debuginfo-1.9.14-150600.11.6.1 * haveged-devel-1.9.14-150600.11.6.1 * haveged-1.9.14-150600.11.6.1 * haveged-debuginfo-1.9.14-150600.11.6.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * haveged-debugsource-1.9.14-150600.11.6.1 * libhavege2-1.9.14-150600.11.6.1 * libhavege2-debuginfo-1.9.14-150600.11.6.1 * haveged-devel-1.9.14-150600.11.6.1 * haveged-1.9.14-150600.11.6.1 * haveged-debuginfo-1.9.14-150600.11.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * haveged-debugsource-1.9.14-150600.11.6.1 * libhavege2-1.9.14-150600.11.6.1 * libhavege2-debuginfo-1.9.14-150600.11.6.1 * haveged-devel-1.9.14-150600.11.6.1 * haveged-1.9.14-150600.11.6.1 * haveged-debuginfo-1.9.14-150600.11.6.1 * SUSELinux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * haveged-debugsource-1.9.14-150600.11.6.1 * libhavege2-1.9.14-150600.11.6.1 * libhavege2-debuginfo-1.9.14-150600.11.6.1 * haveged-devel-1.9.14-150600.11.6.1 * haveged-1.9.14-150600.11.6.1 * haveged-debuginfo-1.9.14-150600.11.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41054.html * https://bugzilla.suse.com/show_bug.cgi?id=1264086 . An important security update for haveged identifies a root exploit risk. Details on patching available.. important update, haveged security, openSUSE patch, root exploit risk. . Severity: Important. LinuxSecurity.com Team
ceph 16.2.12 GA Security fix for CVE-2022-3650. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-d6b219d19a 2023-04-23 01:22:28.937428 --------------------------------------------------------------------------------Name : ceph Product : Fedora 36 Version : 16.2.12 Release : 1.fc36 URL : Summary : User space components of the Ceph file system Description : Ceph is a massively scalable, open-source, distributed storage system that runs on commodity hardware and delivers object, block and file system storage. --------------------------------------------------------------------------------Update Information: ceph 16.2.12 GA Security fix for CVE-2022-3650 --------------------------------------------------------------------------------ChangeLog: * Thu Apr 13 2023 Kaleb S. KEITHLEY - 2:16.2.12-1 - 16.2.12 GA --------------------------------------------------------------------------------References: [ 1 ] Bug #2137599 - CVE-2022-3650 ceph: ceph-crash.service allows local ceph user to root exploit [fedora-36] https://bugzilla.redhat.com/show_bug.cgi?id=2137599 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-d6b219d19a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for tomcat ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:1790-1 Rating: important References: #1172405 Cross-References: CVE-2020-8022 Affected Products: SUSE Linux Enterprise Module for Web Scripting 15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for tomcat fixes the following issues: - CVE-2020-8022: Fixed a local root exploit due to improper permissions (bsc#1172405) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Web Scripting 15-SP1: zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP1-2020-1790=1 Package List: - SUSE Linux Enterprise Module for Web Scripting 15-SP1 (noarch): tomcat-9.0.35-4.35.1 tomcat-admin-webapps-9.0.35-4.35.1 tomcat-el-3_0-api-9.0.35-4.35.1 tomcat-jsp-2_3-api-9.0.35-4.35.1 tomcat-lib-9.0.35-4.35.1 tomcat-servlet-4_0-api-9.0.35-4.35.1 tomcat-webapps-9.0.35-4.35.1 References: https://www.suse.com/security/cve/CVE-2020-8022.html https://bugzilla.suse.com/1172405 _______________________________________________ sle-security-updates mailing list
Joris van Rantwijk discovered that the Xen host did not correctly validate the contents of a Xen guests's grug.conf file. Xen guest root users could exploit this to run arbitrary commands on the host when the guest system was rebooted. . =========================================================== Ubuntu Security Notice USN-527-1 October 05, 2007 xen-3.0 vulnerability CVE-2007-4993 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 7.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 7.04: xen-utils-3.0 3.0.3-0ubuntu10.1 In general, a standard system upgrade is sufficient to affect the necessary changes. Details follow: Joris van Rantwijk discovered that the Xen host did not correctly validate the contents of a Xen guests's grug.conf file. Xen guest root users could exploit this to run arbitrary commands on the host when the guest system was rebooted. Updated packages for Ubuntu 7.04: Source archives: Size/MD5: 43307 2f531fea82cc88494f81bbdd050ef824 Size/MD5: 1023 3336b4ce7f13d381400bb6d0a80cd0b7 Size/MD5: 5465571 98ac5465ff111a3ff76a985bf755c6a5 Architecture independent packages: Size/MD5: 533754 b65c9495bcfa717ed1a5b8c46f999402 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 70804 ffc9f9d0ab7f8df7df2e0ffd8f08285c Size/MD5: 73492 dd35493b60f4792e345abda43d20aa8b Size/MD5: 420742 a1638f0e7cbbf5685b041abc158dfa8a Size/MD5: 271940 66492dd5d6a4c52fc97114d2bb983ffa Size/MD5: 317284 88a2027bff8d08983d0d8771859e68fd Size/MD5: 283572 8e9197196e594faf891ce535014b6c71 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 708000295889477fb1b8c83edb7cfe2b6872a Size/MD5: 69486 b24236890f2ba901e4852188a72ebb22 Size/MD5: 416932 81e667521fe88fe02db3355b42bf5e5b Size/MD5: 269408 1c2d69bafb3ca2d540dc13105ac40e10 Size/MD5: 251070 facaee8d4581cdbfe7682b30e87e8065 Size/MD5: 298840 6a863568a47389b1d2990c97bdcb2620 Size/MD5: 272848 90980654788696fad35a613fcc562a88 . An urgent alert has been issued concerning the xen-3.0 security flaw, which presents an opportunity for guest root accounts to compromise the integrity of the host machine on Ubuntu platforms.. Xen Vulnerability, Ubuntu Security, Host Exploitation, Security Patch. . Severity: Critical. LinuxSecurity.com Team
Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1011-1
Get the latest Linux and open source security news straight to your inbox.