New p11-kit packages are available for Slackware 15.0 and -current to fix security issues.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] p11-kit (SSA:2026-037-01) New p11-kit packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/p11-kit-0.26.2-i586-1_slack15.0.txz: Upgraded. This update fixes a security issue: rpc: fix NULL dereference via C_DeriveKey with specific NULL parameters. For more information, see: https://www.cve.org/CVERecord?id=CVE-2026-2100 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/p11-kit-0.26.2-i586-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/p11-kit-0.26.2-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/p11-kit-0.26.2-i686-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/p11-kit-0.26.2-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: 97ddf299bf02e49a10b1c77be7aaa726 p11-kit-0.26.2-i586-1_slack15.0.txz Slackware x86_64 15.0 package: ffb232e42537d03547a19ab5cab29ad4 p11-kit-0.26.2-x86_64-1_slack15.0.txz Slackware -current package: 231ea9b5ae31d8a312fe26629726c059 n/p11-kit-0.26.2-i686-1.txz Slackware x86_64 -current package: 5f9c33d6fc1537e98c17ce81549e139d n/p11-kit-0.26.2-x86_64-1.txz Installationinstructions: +------------------------+ Upgrade the package as root: # upgradepkg p11-kit-0.26.2-i586-1_slack15.0.txz +-----+ . New p11-kit packages for Slackware address specific security issues, ensuring protection against relevant threats.. Slackware security, p11-kit package update, RPC issue, Linux security advisory. . Severity: Important. LinuxSecurity.com Team
* bsc#1222584 * bsc#1223849 * bsc#1226492 Cross-References: . # Security update for libvirt Announcement ID: SUSE-SU-2025:20012-1 Release Date: 2025-02-03T08:47:44Z Rating: important References: * bsc#1222584 * bsc#1223849 * bsc#1226492 Cross-References: * CVE-2024-4418 CVSS scores: * CVE-2024-4418 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-4418 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability and has two fixes can now be installed. ## Description: This update for libvirt fixes the following issues: Security issue fixed: * CVE-2024-4418: rpc: ensure temporary GSource is removed from client event loop (bsc#1223849) Non-security issue fixed: * libxl: Fix domxml-to-native conversion (bsc#1222584) * qemu: Fix migration with custom XML (bsc#1226492) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-40=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libvirt-daemon-driver-storage-core-debuginfo-10.0.0-3.1 * libvirt-daemon-driver-qemu-10.0.0-3.1 * libvirt-daemon-10.0.0-3.1 * libvirt-daemon-driver-nwfilter-10.0.0-3.1 * libvirt-daemon-driver-network-10.0.0-3.1 * libvirt-daemon-driver-qemu-debuginfo-10.0.0-3.1 * libvirt-daemon-driver-storage-iscsi-direct-10.0.0-3.1 * libvirt-daemon-lock-10.0.0-3.1 * libvirt-daemon-driver-storage-logical-debuginfo-10.0.0-3.1 * libvirt-daemon-driver-storage-10.0.0-3.1 * libvirt-daemon-driver-storage-disk-10.0.0-3.1 * libvirt-daemon-driver-storage-disk-debuginfo-10.0.0-3.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-10.0.0-3.1 * libvirt-daemon-driver-storage-core-10.0.0-3.1 *libvirt-daemon-driver-storage-scsi-10.0.0-3.1 * libvirt-daemon-driver-nwfilter-debuginfo-10.0.0-3.1 * libvirt-daemon-driver-secret-debuginfo-10.0.0-3.1 * libvirt-daemon-plugin-lockd-debuginfo-10.0.0-3.1 * libvirt-daemon-log-debuginfo-10.0.0-3.1 * libvirt-daemon-proxy-debuginfo-10.0.0-3.1 * libvirt-debugsource-10.0.0-3.1 * libvirt-daemon-log-10.0.0-3.1 * libvirt-libs-10.0.0-3.1 * libvirt-daemon-driver-storage-mpath-debuginfo-10.0.0-3.1 * libvirt-daemon-common-debuginfo-10.0.0-3.1 * libvirt-daemon-driver-nodedev-debuginfo-10.0.0-3.1 * libvirt-daemon-driver-storage-iscsi-10.0.0-3.1 * libvirt-daemon-hooks-10.0.0-3.1 * libvirt-daemon-driver-storage-scsi-debuginfo-10.0.0-3.1 * libvirt-daemon-driver-storage-mpath-10.0.0-3.1 * libvirt-daemon-proxy-10.0.0-3.1 * libvirt-daemon-driver-nodedev-10.0.0-3.1 * libvirt-nss-debuginfo-10.0.0-3.1 * libvirt-client-qemu-10.0.0-3.1 * libvirt-libs-debuginfo-10.0.0-3.1 * libvirt-client-debuginfo-10.0.0-3.1 * libvirt-daemon-driver-secret-10.0.0-3.1 * libvirt-daemon-plugin-lockd-10.0.0-3.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-10.0.0-3.1 * libvirt-daemon-driver-storage-logical-10.0.0-3.1 * libvirt-nss-10.0.0-3.1 * libvirt-daemon-qemu-10.0.0-3.1 * libvirt-daemon-common-10.0.0-3.1 * libvirt-client-10.0.0-3.1 * libvirt-daemon-driver-network-debuginfo-10.0.0-3.1 * libvirt-daemon-lock-debuginfo-10.0.0-3.1 * libvirt-daemon-debuginfo-10.0.0-3.1 * libvirt-daemon-config-network-10.0.0-3.1 * SUSE Linux Micro 6.0 (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-10.0.0-3.1 * libvirt-daemon-driver-storage-rbd-debuginfo-10.0.0-3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-4418.html * https://bugzilla.suse.com/show_bug.cgi?id=1222584 * https://bugzilla.suse.com/show_bug.cgi?id=1223849 * https://bugzilla.suse.com/show_bug.cgi?id=1226492 . SUSE Security Advisory: libvirt resolves a significant RPC vulnerability andcorrects several defects. Ensure you update immediately!. SUSE Security Update, libvirt security, important security patch, rpc issue fix, CVE-2024-4418. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.. SUSE Security Update: Security update for cryptctl ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1865-1 Rating: important References: #1041963 Cross-References: CVE-2017-9270 Affected Products: SUSE Linux Enterprise Server for SAP 12-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for cryptctl fixes an issue that could have allowed a malicious administrator to craft RPC requests to overwrite files outside of key database. (bsc#1041963 / CVE-2017-9270) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2017-1158=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): cryptctl-1.2.6-5.3.11 cryptctl-debuginfo-1.2.6-5.3.11 cryptctl-debugsource-1.2.6-5.3.11 References: https://www.suse.com/security/cve/CVE-2017-9270.html https://bugzilla.suse.com/1041963 . SUSE has released a crucial security update for cryptctl, targeting issues with RPC communication on SUSE Linux Enterprise systems.. cryptctl Software Update, SUSE Security Patch, RPC Threat Fix. . Severity: Important. LinuxSecurity.com Team
Moderate: openchange security, bug fix and . Date: Mon, 4 Mar 2013 13:09:40 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Moderate: openchange on SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Moderate: openchange security, bug fix and enhancement update Issue Date: 2013-02-21 CVE Numbers: CVE-2012-1182 -- A flaw was found in the Samba suite's Perl-based DCE/RPC IDL (PIDL) compiler. As OpenChange uses code generated by PIDL, this could have resulted in buffer overflows in the way OpenChange handles RPC calls. With this update, the code has been generated with an updated version of PIDL to correct this issue. (CVE-2012-1182) The openchange packages have been upgraded to upstream version 1.0, which provides a number of bug fixes and enhancements over the previous version, including support for the rebased samba4 packages and several API changes. This update also fixes the following bugs: * When the user tried to modify a meeting with one required attendee and himself as the organizer, a segmentation fault occurred in the memcpy() function. Consequently, the evolution-data-server application terminated unexpectedly with a segmentation fault. This bug has been fixed and evolution- data-server no longer crashes in the described scenario. * Prior to this update, OpenChange 1.0 was unable to send messages with a large message body or with extensive attachment. This was caused by minor issues in OpenChange's exchange.idl definitions. This bug has been fixed and OpenChange now sends extensive messages without complications. -- SL6 x86_64 evolution-mapi-0.28.3-12.el6.x86_64.rpm evolution-mapi-debuginfo-0.28.3-12.el6.x86_64.rpm openchange-1.0-4.el6.x86_64.rpm openchange-debuginfo-1.0-4.el6.x86_64.rpm evolution-mapi-devel-0.28.3-12.el6.x86_64.rpm openchange-client-1.0-4.el6.x86_64.rpm openchange-devel-1.0-4.el6.x86_64.rpm openchange-devel-docs-1.0-4.el6.x86_64.rpm i386 evolution-mapi-0.28.3-12.el6.i686.rpm evolution-mapi-debuginfo-0.28.3-12.el6.i686.rpm openchange-1.0-4.el6.i686.rpm openchange-debuginfo-1.0-4.el6.i686.rpm evolution-mapi-devel-0.28.3-12.el6.i686.rpm openchange-client-1.0-4.el6.i686.rpm openchange-devel-1.0-4.el6.i686.rpm openchange-devel-docs-1.0-4.el6.i686.rpm - Scientific Linux Development Team . Security enhancement for Scientific Linux SL6.x regarding OpenChange, addressing moderate vulnerabilities and optimizing performance.. OpenChange, Scientific Linux, RPC Security, Bug Fix, SL6. . LinuxSecurity.com Team
Moderate: libvirt security and bug fix update. Date: Thu, 11 Oct 2012 11:11:56 -0500 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Moderate: libvirt on SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Moderate: libvirt security and bug fix update Issue Date: 2012-10-11 CVE Numbers: CVE-2012-4423 -- The libvirt library is a C API for managing and interacting with the virtualization capabilities of Linux and other operating systems. In addition, libvirt provides tools for remote management of virtualized systems. A flaw was found in libvirtd's RPC call handling. An attacker able to establish a read-only connection to libvirtd could use this flaw to crash libvirtd by sending an RPC message that has an event as the RPC number, or an RPC number that falls into a gap in the RPC dispatch table. (CVE-2012-4423) This update also fixes the following bugs: * When the host_uuid option was present in the libvirtd.conf file, the augeas libvirt lens was unable to parse the file. This bug has been fixed and the augeas libvirt lens now parses libvirtd.conf as expected in the described scenario. * Disk hot plug is a two-part action: the qemuMonitorAddDrive() call is followed by the qemuMonitorAddDevice() call. When the first part succeeded but the second one failed, libvirt failed to roll back the first part and the device remained in use even though the disk hot plug failed. With this update, the rollback for the drive addition is properly performed in the described scenario and disk hot plug now works as expected. * When a virtual machine was started with an image chain using block devices and a block rebase operation was issued, the operation failed on completion in the blockJobAbort() function. This update relabels and configures cgroups for the backing files and the rebase operation now succeeds. After installing the updated packages, libvirtd will be restarted automatically. -- SL6 x86_64 libvirt-0.9.10-21.el6_3.5.x86_64.rpm libvirt-client-0.9.10-21.el6_3.5.i686.rpm libvirt-client-0.9.10-21.el6_3.5.x86_64.rpm libvirt-python-0.9.10-21.el6_3.5.x86_64.rpm libvirt-devel-0.9.10-21.el6_3.5.i686.rpm libvirt-devel-0.9.10-21.el6_3.5.x86_64.rpm libvirt-lock-sanlock-0.9.10-21.el6_3.5.x86_64.rpm i386 libvirt-0.9.10-21.el6_3.5.i686.rpm libvirt-client-0.9.10-21.el6_3.5.i686.rpm libvirt-python-0.9.10-21.el6_3.5.i686.rpm libvirt-devel-0.9.10-21.el6_3.5.i686.rpm - Scientific Linux Development Team . A recent libvirt upgrade for Scientific Linux resolves an RPC vulnerability among various issues. Discover more information here.. libvirt Update, Scientific Linux Security, Moderate Security Advisory. . LinuxSecurity.com Team
Updated libvirt packages that fix one security issue and two bugs are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libvirt security and bug fix update Advisory ID: RHSA-2012:1202-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2012:1202.html Issue date: 2012-08-23 CVE Names: CVE-2012-3445 ==================================================================== 1. Summary: Updated libvirt packages that fix one security issue and two bugs are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - x86_64 3. Description: The libvirt library is a C API for managing and interacting with the virtualization capabilities of Linux and other operating systems. In addition, libvirt provides tools for remote management of virtualized systems. A flaw was found in libvirtd's RPC call handling. An attacker able to establish a read-only connection to libvirtd could trigger this flaw with a specially-crafted RPC command that has the number of parameters set to 0, causing libvirtd to accessinvalid memory and crash. (CVE-2012-3445) This update also fixes the following bugs: * Previously, repeatedly migrating a guest between two machines while using the tunnelled migration could cause the libvirt daemon to lock up unexpectedly. The bug in the code for locking remote drivers has been fixed and repeated tunnelled migrations of domains now work as expected. (BZ#847946) * Previously, when certain system locales were used by the system, libvirt could issue incorrect commands to the hypervisor. This bug has been fixed and the libvirt library and daemon are no longer affected by the choice of the user locale. (BZ#847959) All users of libvirt are advised to upgrade to these updated packages, which contain backported patches to correct these issues. After installing the updated packages, libvirtd will be restarted automatically. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 844734 - CVE-2012-3445 libvirt: crash in virTypedParameterArrayClear 847946 - libvirtd may hang during tunneled migration 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: i386: libvirt-0.9.10-21.el6_3.4.i686.rpm libvirt-client-0.9.10-21.el6_3.4.i686.rpm libvirt-debuginfo-0.9.10-21.el6_3.4.i686.rpm libvirt-python-0.9.10-21.el6_3.4.i686.rpm x86_64: libvirt-0.9.10-21.el6_3.4.x86_64.rpm libvirt-client-0.9.10-21.el6_3.4.i686.rpm libvirt-client-0.9.10-21.el6_3.4.x86_64.rpm libvirt-debuginfo-0.9.10-21.el6_3.4.i686.rpm libvirt-debuginfo-0.9.10-21.el6_3.4.x86_64.rpm libvirt-python-0.9.10-21.el6_3.4.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v.6): Source: i386: libvirt-debuginfo-0.9.10-21.el6_3.4.i686.rpm libvirt-devel-0.9.10-21.el6_3.4.i686.rpm x86_64: libvirt-debuginfo-0.9.10-21.el6_3.4.i686.rpm libvirt-debuginfo-0.9.10-21.el6_3.4.x86_64.rpm libvirt-devel-0.9.10-21.el6_3.4.i686.rpm libvirt-devel-0.9.10-21.el6_3.4.x86_64.rpm libvirt-lock-sanlock-0.9.10-21.el6_3.4.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: x86_64: libvirt-0.9.10-21.el6_3.4.x86_64.rpm libvirt-client-0.9.10-21.el6_3.4.i686.rpm libvirt-client-0.9.10-21.el6_3.4.x86_64.rpm libvirt-debuginfo-0.9.10-21.el6_3.4.i686.rpm libvirt-debuginfo-0.9.10-21.el6_3.4.x86_64.rpm libvirt-python-0.9.10-21.el6_3.4.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: x86_64: libvirt-debuginfo-0.9.10-21.el6_3.4.i686.rpm libvirt-debuginfo-0.9.10-21.el6_3.4.x86_64.rpm libvirt-devel-0.9.10-21.el6_3.4.i686.rpm libvirt-devel-0.9.10-21.el6_3.4.x86_64.rpm libvirt-lock-sanlock-0.9.10-21.el6_3.4.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: i386: libvirt-0.9.10-21.el6_3.4.i686.rpm libvirt-client-0.9.10-21.el6_3.4.i686.rpm libvirt-debuginfo-0.9.10-21.el6_3.4.i686.rpm libvirt-devel-0.9.10-21.el6_3.4.i686.rpm libvirt-python-0.9.10-21.el6_3.4.i686.rpm ppc64: libvirt-0.9.10-21.el6_3.4.ppc64.rpm libvirt-client-0.9.10-21.el6_3.4.ppc.rpm libvirt-client-0.9.10-21.el6_3.4.ppc64.rpm libvirt-debuginfo-0.9.10-21.el6_3.4.ppc.rpm libvirt-debuginfo-0.9.10-21.el6_3.4.ppc64.rpm libvirt-devel-0.9.10-21.el6_3.4.ppc.rpm libvirt-devel-0.9.10-21.el6_3.4.ppc64.rpm libvirt-python-0.9.10-21.el6_3.4.ppc64.rpm s390x: libvirt-0.9.10-21.el6_3.4.s390x.rpm libvirt-client-0.9.10-21.el6_3.4.s390.rpm libvirt-client-0.9.10-21.el6_3.4.s390x.rpm libvirt-debuginfo-0.9.10-21.el6_3.4.s390.rpm libvirt-debuginfo-0.9.10-21.el6_3.4.s390x.rpm libvirt-devel-0.9.10-21.el6_3.4.s390.rpm libvirt-devel-0.9.10-21.el6_3.4.s390x.rpm libvirt-python-0.9.10-21.el6_3.4.s390x.rpm x86_64: libvirt-0.9.10-21.el6_3.4.x86_64.rpm libvirt-client-0.9.10-21.el6_3.4.i686.rpm libvirt-client-0.9.10-21.el6_3.4.x86_64.rpm libvirt-debuginfo-0.9.10-21.el6_3.4.i686.rpm libvirt-debuginfo-0.9.10-21.el6_3.4.x86_64.rpm libvirt-devel-0.9.10-21.el6_3.4.i686.rpm libvirt-devel-0.9.10-21.el6_3.4.x86_64.rpm libvirt-python-0.9.10-21.el6_3.4.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): Source: x86_64: libvirt-debuginfo-0.9.10-21.el6_3.4.x86_64.rpm libvirt-lock-sanlock-0.9.10-21.el6_3.4.x86_64.rpm Red Hat Enterprise Linux Workstation (v.6): Source: i386: libvirt-0.9.10-21.el6_3.4.i686.rpm libvirt-client-0.9.10-21.el6_3.4.i686.rpm libvirt-debuginfo-0.9.10-21.el6_3.4.i686.rpm libvirt-devel-0.9.10-21.el6_3.4.i686.rpm libvirt-python-0.9.10-21.el6_3.4.i686.rpm x86_64: libvirt-0.9.10-21.el6_3.4.x86_64.rpm libvirt-client-0.9.10-21.el6_3.4.i686.rpm libvirt-client-0.9.10-21.el6_3.4.x86_64.rpm libvirt-debuginfo-0.9.10-21.el6_3.4.i686.rpm libvirt-debuginfo-0.9.10-21.el6_3.4.x86_64.rpm libvirt-devel-0.9.10-21.el6_3.4.i686.rpm libvirt-devel-0.9.10-21.el6_3.4.x86_64.rpm libvirt-python-0.9.10-21.el6_3.4.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: x86_64: libvirt-debuginfo-0.9.10-21.el6_3.4.x86_64.rpm libvirt-lock-sanlock-0.9.10-21.el6_3.4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2012-3445 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2012 Red Hat, Inc. . Recent libvirt patch for Red Hat resolves vulnerabilities and improves system stability. Discover additional methods for safeguarding your environment.. libvirt update, red hat advisory, moderate security fix, rpc flaw, bug correction. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.