Explore top 10 tips to secure your open-source projects now. Read More
×Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-8488-1 July 01, 2026 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel Details: It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - Rados block device (RBD) driver; - Compressed RAM block device driver; - Character device driver; - TPM device driver; - Hardware crypto device drivers; - EDAC drivers; - GPU drivers; - Greybus drivers; - HID subsystem; - Microsoft Hyper-V drivers; - Hardware monitoring drivers; - I2C subsystem; - IIO subsystem; - InfiniBand drivers; - Input Device core drivers; - LED subsystem; - Multiple devices driver; - Media drivers; - IBM Advanced System Management driver; - MTD block device drivers; - Network drivers; - Microsoft Azure Network Adapter (MANA) driver; - NTB driver; - NVME drivers; - Device tree and open firmware driver; - PCI subsystem; - Remote Processor subsystem; - SCSI subsystem; - SPI subsystem; - Realtek RTL8723BS SDIO drivers; - SM750 framebuffer staging driver; - Thermal drivers; - USB Gadget drivers; - USB over IP driver; - VFIO drivers; - Framebuffer layer; - 9P distributed file system; - AFS file system; - Ceph distributed file system; - Filesystems infrastructure; - EROFS file system; - Ext4 file system; - F2FS file system; - FUSE (File system in Userspace); - Journaling layer for block devices (JBD2); - NILFS2 file system; - File system notification infrastructure; - NTFS3 file system; - OCFS2 file system; - SMB network file system; - UDF file system; - XFS file system; - Codetag library; - Memory management; - Memory Management; - KVM subsystem; - Tracing infrastructure; - User-space API (UAPI); - io_uring subsystem; - Locking primitives; - Timer subsystem; - Scatterlist API; - Heterogeneous memory management; - KASAN memory debugging framework; - Bluetooth subsystem; - Ethernet bridge; - CAIF protocol; - CAN network layer; - Ceph Core library; - IPv4 networking; - IPv6 networking; - Multipath TCP; - Netfilter; - NFC subsystem; - Packet sockets; - Qualcomm IPC Router (QRTR); - RDS protocol; - RxRPC session sockets; - SMC sockets; - Stream parser; - Landlock security; - SELinux security module; - ALSA framework; - Generic PCM loopback sound driver; - FireWire sound drivers; - Creative Sound Blaster X-Fi driver; - QCOM ASoC drivers; - USB sound devices; - Objtool; (CVE-2026-31532, CVE-2026-31574, CVE-2026-31575, CVE-2026-31576, CVE-2026-31577, CVE-2026-31578, CVE-2026-31579, CVE-2026-31580, CVE-2026-31581, CVE-2026-31582, CVE-2026-31583, CVE-2026-31584, CVE-2026-31585, CVE-2026-31586, CVE-2026-31587, CVE-2026-31588, CVE-2026-31589, CVE-2026-31590, CVE-2026-31591, CVE-2026-31592, CVE-2026-31593, CVE-2026-31594, CVE-2026-31595, CVE-2026-31596, CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31600, CVE-2026-31601, CVE-2026-31602, CVE-2026-31603, CVE-2026-31604, CVE-2026-31605, CVE-2026-31606, CVE-2026-31607, CVE-2026-31608, CVE-2026-31609, CVE-2026-31610, CVE-2026-31611, CVE-2026-31612, CVE-2026-31613, CVE-2026-31614, CVE-2026-31615, CVE-2026-31616, CVE-2026-31617, CVE-2026-31618, CVE-2026-31619, CVE-2026-31620, CVE-2026-31621, CVE-2026-31622,CVE-2026-31623, CVE-2026-31624, CVE-2026-31625, CVE-2026-31626, CVE-2026-31627, CVE-2026-31628, CVE-2026-31629, CVE-2026-31686, CVE-2026-31694, CVE-2026-31696, CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31700, CVE-2026-31701, CVE-2026-31702, CVE-2026-31703, CVE-2026-31704, CVE-2026-31705, CVE-2026-31706, CVE-2026-31707, CVE-2026-31708, CVE-2026-31709, CVE-2026-31710, CVE-2026-31711, CVE-2026-31712, CVE-2026-31713, CVE-2026-31714, CVE-2026-31715, CVE-2026-31716, CVE-2026-31717, CVE-2026-31718, CVE-2026-31719, CVE-2026-43058, CVE-2026-43071, CVE-2026-43072, CVE-2026-43073, CVE-2026-43348, CVE-2026-43349, CVE-2026-43350, CVE-2026-43491, CVE-2026-43493, CVE-2026-43499, CVE-2026-43501, CVE-2026-45986, CVE-2026-45987, CVE-2026-45988, CVE-2026-45989, CVE-2026-45990, CVE-2026-45991, CVE-2026-45994, CVE-2026-45995, CVE-2026-45996, CVE-2026-45997, CVE-2026-45999, CVE-2026-46001, CVE-2026-46002, CVE-2026-46003, CVE-2026-46004, CVE-2026-46005, CVE-2026-46006, CVE-2026-46007, CVE-2026-46008, CVE-2026-46009, CVE-2026-46010, CVE-2026-46011, CVE-2026-46012, CVE-2026-46013, CVE-2026-46014, CVE-2026-46015, CVE-2026-46016, CVE-2026-46018, CVE-2026-46019, CVE-2026-46020, CVE-2026-46021, CVE-2026-46022, CVE-2026-46023, CVE-2026-46024, CVE-2026-46025, CVE-2026-46026, CVE-2026-46027, CVE-2026-46028, CVE-2026-46029, CVE-2026-46030, CVE-2026-46031, CVE-2026-46032, CVE-2026-46033, CVE-2026-46034, CVE-2026-46035, CVE-2026-46036, CVE-2026-46037, CVE-2026-46038, CVE-2026-46039, CVE-2026-46040, CVE-2026-46041, CVE-2026-46042, CVE-2026-46043, CVE-2026-46044, CVE-2026-46045, CVE-2026-46046, CVE-2026-46047, CVE-2026-46049, CVE-2026-46050, CVE-2026-46051, CVE-2026-46052, CVE-2026-46053, CVE-2026-46054, CVE-2026-46056, CVE-2026-46057, CVE-2026-46058, CVE-2026-46059, CVE-2026-46060, CVE-2026-46061, CVE-2026-46062, CVE-2026-46063, CVE-2026-46064, CVE-2026-46065, CVE-2026-46066, CVE-2026-46067, CVE-2026-46068, CVE-2026-46069, CVE-2026-46070, CVE-2026-46071, CVE-2026-46072, CVE-2026-46073, CVE-2026-46074, CVE-2026-46075, CVE-2026-46076,CVE-2026-46077, CVE-2026-46078, CVE-2026-46079, CVE-2026-46080, CVE-2026-46081, CVE-2026-46082, CVE-2026-46083, CVE-2026-46084, CVE-2026-46085, CVE-2026-46086, CVE-2026-46087, CVE-2026-46088, CVE-2026-46089, CVE-2026-46090, CVE-2026-46091, CVE-2026-46092, CVE-2026-46093, CVE-2026-46094, CVE-2026-46095, CVE-2026-46096, CVE-2026-46097, CVE-2026-46098, CVE-2026-46099, CVE-2026-46100, CVE-2026-46101, CVE-2026-46102, CVE-2026-46103, CVE-2026-46115, CVE-2026-46119, CVE-2026-46135, CVE-2026-46137, CVE-2026-46155, CVE-2026-46185, CVE-2026-46195, CVE-2026-46243, CVE-2026-46244, CVE-2026-46276, CVE-2026-46277, CVE-2026-46278, CVE-2026-46279, CVE-2026-46280, CVE-2026-46281, CVE-2026-46282, CVE-2026-46283, CVE-2026-46284, CVE-2026-46285, CVE-2026-46286, CVE-2026-46287, CVE-2026-46288, CVE-2026-46289, CVE-2026-46316, CVE-2026-46332, CVE-2026-52904, CVE-2026-52905, CVE-2026-52906, CVE-2026-52907, CVE-2026-52933) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS linux-image-7.0.0-27-generic 7.0.0-27.27 linux-image-7.0.0-27-generic-64k 7.0.0-27.27 linux-image-generic 7.0.0-27.27 linux-image-generic-64k 7.0.0-27.27 linux-image-generic-64k-7.0 7.0.0-27.27 linux-image-generic-64k-hwe-26.04 7.0.0-27.27 linux-image-generic-7.0 7.0.0-27.27 linux-image-generic-hwe-26.04 7.0.0-27.27 linux-image-oem-24.04 7.0.0-27.27 linux-image-oem-24.04a 7.0.0-27.27 linux-image-oem-24.04b 7.0.0-27.27 linux-image-oem-24.04c 7.0.0-27.27 linux-image-oem-24.04d 7.0.0-27.27 linux-image-virtual 7.0.0-27.27 linux-image-virtual-7.0 7.0.0-27.27 linux-image-virtual-hwe-26.04 7.0.0-27.27 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third partykernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8488-1 CVE-2025-54505, CVE-2026-31532, CVE-2026-31574, CVE-2026-31575, CVE-2026-31576, CVE-2026-31577, CVE-2026-31578, CVE-2026-31579, CVE-2026-31580, CVE-2026-31581, CVE-2026-31582, CVE-2026-31583, CVE-2026-31584, CVE-2026-31585, CVE-2026-31586, CVE-2026-31587, CVE-2026-31588, CVE-2026-31589, CVE-2026-31590, CVE-2026-31591, CVE-2026-31592, CVE-2026-31593, CVE-2026-31594, CVE-2026-31595, CVE-2026-31596, CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31600, CVE-2026-31601, CVE-2026-31602, CVE-2026-31603, CVE-2026-31604, CVE-2026-31605, CVE-2026-31606, CVE-2026-31607, CVE-2026-31608, CVE-2026-31609, CVE-2026-31610, CVE-2026-31611, CVE-2026-31612, CVE-2026-31613, CVE-2026-31614, CVE-2026-31615, CVE-2026-31616, CVE-2026-31617, CVE-2026-31618, CVE-2026-31619, CVE-2026-31620, CVE-2026-31621, CVE-2026-31622, CVE-2026-31623, CVE-2026-31624, CVE-2026-31625, CVE-2026-31626, CVE-2026-31627, CVE-2026-31628, CVE-2026-31629, CVE-2026-31686, CVE-2026-31694, CVE-2026-31696, CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31700, CVE-2026-31701, CVE-2026-31702, CVE-2026-31703, CVE-2026-31704, CVE-2026-31705, CVE-2026-31706, CVE-2026-31707, CVE-2026-31708, CVE-2026-31709, CVE-2026-31710, CVE-2026-31711, CVE-2026-31712, CVE-2026-31713, CVE-2026-31714, CVE-2026-31715, CVE-2026-31716, CVE-2026-31717, CVE-2026-31718, CVE-2026-31719, CVE-2026-43058, CVE-2026-43071, CVE-2026-43072, CVE-2026-43073, CVE-2026-43348, CVE-2026-43349, CVE-2026-43350, CVE-2026-43491, CVE-2026-43493, CVE-2026-43499, CVE-2026-43501, CVE-2026-45986, CVE-2026-45987, CVE-2026-45988, CVE-2026-45989, CVE-2026-45990, CVE-2026-45991, CVE-2026-45994, CVE-2026-45995, CVE-2026-45996, CVE-2026-45997,CVE-2026-45999, CVE-2026-46001, CVE-2026-46002, CVE-2026-46003, CVE-2026-46004, CVE-2026-46005, CVE-2026-46006, CVE-2026-46007, CVE-2026-46008, CVE-2026-46009, CVE-2026-46010, CVE-2026-46011, CVE-2026-46012, CVE-2026-46013, CVE-2026-46014, CVE-2026-46015, CVE-2026-46016, CVE-2026-46018, CVE-2026-46019, CVE-2026-46020, CVE-2026-46021, CVE-2026-46022, CVE-2026-46023, CVE-2026-46024, CVE-2026-46025, CVE-2026-46026, CVE-2026-46027, CVE-2026-46028, CVE-2026-46029, CVE-2026-46030, CVE-2026-46031, CVE-2026-46032, CVE-2026-46033, CVE-2026-46034, CVE-2026-46035, CVE-2026-46036, CVE-2026-46037, CVE-2026-46038, CVE-2026-46039, CVE-2026-46040, CVE-2026-46041, CVE-2026-46042, CVE-2026-46043, CVE-2026-46044, CVE-2026-46045, CVE-2026-46046, CVE-2026-46047, CVE-2026-46049, CVE-2026-46050, CVE-2026-46051, CVE-2026-46052, CVE-2026-46053, CVE-2026-46054, CVE-2026-46056, CVE-2026-46057, CVE-2026-46058, CVE-2026-46059, CVE-2026-46060, CVE-2026-46061, CVE-2026-46062, CVE-2026-46063, CVE-2026-46064, CVE-2026-46065, CVE-2026-46066, CVE-2026-46067, CVE-2026-46068, CVE-2026-46069, CVE-2026-46070, CVE-2026-46071, CVE-2026-46072, CVE-2026-46073, CVE-2026-46074, CVE-2026-46075, CVE-2026-46076, CVE-2026-46077, CVE-2026-46078, CVE-2026-46079, CVE-2026-46080, CVE-2026-46081, CVE-2026-46082, CVE-2026-46083, CVE-2026-46084, CVE-2026-46085, CVE-2026-46086, CVE-2026-46087, CVE-2026-46088, CVE-2026-46089, CVE-2026-46090, CVE-2026-46091, CVE-2026-46092, CVE-2026-46093, CVE-2026-46094, CVE-2026-46095, CVE-2026-46096, CVE-2026-46097, CVE-2026-46098, CVE-2026-46099, CVE-2026-46100, CVE-2026-46101, CVE-2026-46102, CVE-2026-46103, CVE-2026-46115, CVE-2026-46119, CVE-2026-46135, CVE-2026-46137, CVE-2026-46155, CVE-2026-46185, CVE-2026-46195, CVE-2026-46243, CVE-2026-46244, CVE-2026-46276, CVE-2026-46277, CVE-2026-46278, CVE-2026-46279, CVE-2026-46280, CVE-2026-46281, CVE-2026-46282, CVE-2026-46283, CVE-2026-46284, CVE-2026-46285, CVE-2026-46286, CVE-2026-46287, CVE-2026-46288, CVE-2026-46289,CVE-2026-46316, CVE-2026-46332, CVE-2026-52904, CVE-2026-52905, CVE-2026-52906, CVE-2026-52907, CVE-2026-52933 Package Information: https://launchpad.net/ubuntu/+source/linux/7.0.0-27.27 . Critical security advisory for Ubuntu fixing multiple issues in the Linux kernel, impacting local system access and data security.. Ubuntu Linux Kernel Updates, System Security Fixes, Local Access Vulnerabilities, Kernel Security Advisories. . Severity: Critical. LinuxSecurity.com Team
NSS could be made to crash or expose sensitive information if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8481-1 June 29, 2026 nss vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: NSS could be made to crash or expose sensitive information if it received specially crafted input. Software Description: - nss: Network Security Service library Details: Haruto Kimura discovered that NSS had incorrecty handled parsing PKCS#11 URI escape sequences. An attacker could possibly use this issue to cause NSS to crash, resulting in a denial of service, or obtain sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libnss3 2:3.120-1ubuntu2.1 Ubuntu 25.10 libnss3 2:3.114-1ubuntu0.2 Ubuntu 24.04 LTS libnss3 2:3.98-1ubuntu0.2 Ubuntu 22.04 LTS libnss3 2:3.98-0ubuntu0.22.04.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8481-1 CVE-2026-12318 Package Information: https://launchpad.net/ubuntu/+source/nss/2:3.120-1ubuntu2.1 https://launchpad.net/ubuntu/+source/nss/2:3.114-1ubuntu0.2 https://launchpad.net/ubuntu/+source/nss/2:3.98-1ubuntu0.2 https://launchpad.net/ubuntu/+source/nss/2:3.98-0ubuntu0.22.04.4 . NSS on Ubuntu could crash or leak sensitive data with crafted input; updates available to mitigate risks. Read more.. Ubuntu NSS Security Update Denial of Service Sensitive Information. . Severity: Important. LinuxSecurity.com Team
Multiple security vulnerabilities have been discovered in Tomcat 11, a Java based web server, servlet and JSP engine which may result in a denial of service, authentication bypass or the disclosure of sensitive information. Although we are not aware of any problems, new upstream versions may introduce new options, limits or code changes which may or may not affect your existing. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6329-1
An update that solves one vulnerability can now be installed.. # Security update for python-urllib3_1 Announcement ID: SUSE-SU-2026:2067-1 Release Date: 2026-05-26T07:29:10Z Rating: important References: * bsc#1265267 Cross-References: * CVE-2026-44431 CVSS scores: * CVE-2026-44431 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44431 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44431 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44431 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-urllib3_1 fixes the following issue * CVE-2026-44431: sensitive information disclosure due to sensitive headers being forwarded across origins in proxied low-level redirects (bsc#1265267). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2067=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2067=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2067=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patchSUSE-SLE-Product-SLES_SAP-15-SP6-2026-2067=1 ## Package List: * openSUSE Leap 15.6 (noarch) * python311-urllib3_1-1.26.18-150600.3.9.1 * Python 3 Module 15-SP7 (noarch) * python311-urllib3_1-1.26.18-150600.3.9.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python311-urllib3_1-1.26.18-150600.3.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python311-urllib3_1-1.26.18-150600.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44431.html * https://bugzilla.suse.com/show_bug.cgi?id=1265267 . Security update for python-urllib3_1 released to address sensitive data disclosure issue on openSUSE.. python-urllib3 update, information leak risk, SUSE security update. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in Exim.. ========================================================================== Ubuntu Security Notice USN-8228-1 May 04, 2026 exim4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Exim. Software Description: - exim4: Exim is a mail transport agent Details: It was discovered that Exim incorrectly handled parsing malformed JSON in message headers. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-40685) It was discovered that Exim incorrectly handled processing of UTF-8 trailing characters. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-40686) It was discovered that Exim incorrectly handled SPA authenticator input. An authenticated user could possibly use this issue to execute arbitrary code. (CVE-2026-40687) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS exim4 4.99.1-1ubuntu1.1 exim4-base 4.99.1-1ubuntu1.1 eximon4 4.99.1-1ubuntu1.1 Ubuntu 25.10 exim4 4.98.2-1ubuntu2.1 exim4-base 4.98.2-1ubuntu2.1 eximon4 4.98.2-1ubuntu2.1 Ubuntu 24.04 LTS exim4 4.97-4ubuntu4.4 exim4-base 4.97-4ubuntu4.4 eximon4 4.97-4ubuntu4.4 Ubuntu 22.04 LTS exim4 4.95-4ubuntu2.7 exim4-base 4.95-4ubuntu2.7 eximon4 4.95-4ubuntu2.7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8228-1 CVE-2026-40685, CVE-2026-40686,CVE-2026-40687 Package Information: https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.1 https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.1 https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.4 https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.7 . Critical security advisory for Exim on Ubuntu 22.04 LTS, addressing multiple remote code execution issues.. Exim, Ubuntu security, remote code execution. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in Dovecot.. ========================================================================== Ubuntu Security Notice USN-8136-1 March 31, 2026 dovecot vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Dovecot. Software Description: - dovecot: IMAP and POP3 email server Details: It was discovered that Dovecot incorrectly handled invalid base64 SASL data. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 25.10. (CVE-2025-59028) It was discovered that Dovecot script decode2text.sh incorrectly handled zip files. An attacker could possibly use this issue to obtain sensitive information. (CVE-2025-59031) It was discovered that Dovecot incorrectly handled certain AUTHENTICATE requests. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-59032) It was discovered that Dovecot incorrectly handled certain SQL based authentication. An attacker could possibly use this issue to bypass authentication. This issue only affected Ubuntu 25.10. (CVE-2026-24031) It was discovered that Dovecot incorrectly handled certain LDAP based authentication. An attacker could possibly use this issue to bypass restrictions and allow probing of LDAP structure. This issue only affected Ubuntu 25.10. (CVE-2026-27860) It was discovered that Dovecot is vulnerable to replay attack under certain conditions. An attacker could possibly use this issue to bypass authentication. (CVE-2026-27855) It was discovered that Dovecot is vulnerable to a timing attack under certain conditions. An attacker could possibly use this issue to bypass authentication. (CVE-2026-27856) It was discovered that Dovecot incorrectly handled certain IMAP login requests. An attacker could possibly use this issue to cause a denial of service.(CVE-2026-27857) It was discovered that Dovecot incorrectly handled certain specially crafted messages. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-27858) It was discovered that Dovecot incorrectly handled certain specially crafted mail messages. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-27859) It was discovered that Dovecot incorrectly handles file paths. A attacker could possibly use this issue to perform a path traversal and obtain or modify arbitrary files. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-0394) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 dovecot-core 1:2.4.1+dfsg1-5ubuntu4.1 Ubuntu 24.04 LTS dovecot-core 1:2.3.21+dfsg1-2ubuntu6.3 Ubuntu 22.04 LTS dovecot-core 1:2.3.16+dfsg1-3ubuntu2.7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8136-1 CVE-2025-59028, CVE-2025-59031, CVE-2025-59032, CVE-2026-0394, CVE-2026-24031, CVE-2026-27855, CVE-2026-27856, CVE-2026-27857, CVE-2026-27858, CVE-2026-27859, CVE-2026-27860 Package Information: https://launchpad.net/ubuntu/+source/dovecot/1:2.4.1+dfsg1-5ubuntu4.1 https://launchpad.net/ubuntu/+source/dovecot/1:2.3.21+dfsg1-2ubuntu6.3 https://launchpad.net/ubuntu/+source/dovecot/1:2.3.16+dfsg1-3ubuntu2.7 . Dovecot security fixes address several vulnerabilities impacting Ubuntu 25.10 and other releases, affecting user security.. Dovecot Security Issues, Ubuntu Dovecot Updates, Email Server Security. . Severity: Critical. LinuxSecurity.com Team
Update to 1.59.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9af71a53ce 2026-01-23 01:14:49.116922+00:00 -------------------------------------------------------------------------------- Name : hcloud Product : Fedora 42 Version : 1.59.0 Release : 1.fc42 URL : https://github.com/hetznercloud/cli Summary : A command-line interface for Hetzner Cloud Description : A command-line interface for Hetzner Cloud. -------------------------------------------------------------------------------- Update Information: Update to 1.59.0 -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 14 2026 Mikel Olasagasti Uranga - 1.59.0-1 - Update to 1.59.0 * Wed Jan 14 2026 Fedora Release Engineering - 1.51.0-5 - Unretire package: hcloud on rawhide * Fri Oct 10 2025 Alejandro Sez - 1.51.0-4 - rebuild * Fri Aug 15 2025 Maxwell G - 1.51.0-3 - Rebuild for golang-1.25.0 * Thu Jul 24 2025 Fedora Release Engineering - 1.51.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2384159 - hcloud: go-viper information leak [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2384159 [ 2 ] Bug #2390869 - hcloud: go-viper's mapstructure May Leak Sensitive Information in Logs [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2390869 [ 3 ] Bug #2399717 - CVE-2025-11065 hcloud: Go-viper's mapstructure May Leak Sensitive Information in Logs in github.com/go-viper/mapstructure [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2399717 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9af71a53ce' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Learn about the hcloud 1.59.0 update for Fedora 42 addressing sensitive data leaks through Go-viper's mapstructure.. hcloud update Fedora 42 Go-viper information leak. . LinuxSecurity.com Team
* bsc#1248960 * bsc#1250621 Cross-References: * CVE-2025-11065 . # Security update for alloy Announcement ID: SUSE-SU-2025:21137-1 Release Date: 2025-11-20T17:26:16Z Rating: moderate References: * bsc#1248960 * bsc#1250621 Cross-References: * CVE-2025-11065 * CVE-2025-58058 CVSS scores: * CVE-2025-11065 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-11065 ( SUSE ): 4.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N * CVE-2025-58058 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58058 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58058 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for alloy fixes the following issues: * CVE-2025-58058: Removed dependency on vulnerable github.com/ulikunitz/xz (bsc#1248960). * CVE-2025-11065: Fixed sensitive information leak in logs (bsc#1250621). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-47=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-47=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * alloy-1.11.3-160000.1.1 * alloy-debuginfo-1.11.3-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * alloy-1.11.3-160000.1.1 * alloy-debuginfo-1.11.3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-11065.html * https://www.suse.com/security/cve/CVE-2025-58058.html *https://bugzilla.suse.com/show_bug.cgi?id=1248960 * https://bugzilla.suse.com/show_bug.cgi?id=1250621 . SUSE updates fix moderate vulnerabilities in Alloy including leaks. Install updates to secure system.. SUSE Linux Server Alloy patch information leak update. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.