An update that solves 2 vulnerabilities and has 3 bug fixes can now be installed.. openSUSE security update: security update for go1.25 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20214-1 Rating: critical References: * bsc#1244485 * bsc#1256818 * bsc#1257692 Cross-References: * CVE-2025-61732 * CVE-2025-68121 CVSS scores: * CVE-2025-61732 ( SUSE ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-61732 ( SUSE ): 9.4 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-68121 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-68121 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 3 bug fixes can now be installed. Description: This update for go1.25 fixes the following issues: Update to version 1.25.7. Security issues fixed: - CVE-2025-61732: cmd/go: discrepancy between Go and C/C++ comment parsing allows for C code smuggling (bsc#1257692). - CVE-2025-68121: crypto/tls: Config.Clone copies automatically generated session ticket keys, session resumption does not account for the expiration of full certificate chain (bsc#1256818). Other updates and bugfixes: - version update to 1.25.7: * go#75844 cmd/compile: OOM killed on linux/arm64 * go#77323 crypto/x509: single-label excluded DNS name constraints incorrectly match all wildcard SANs * go#77425 crypto/tls: CL 737700 broke session resumption on macOS Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-269=1 Package List: - openSUSE Leap 16.0: go1.25-1.25.7-160000.1.1 go1.25-doc-1.25.7-160000.1.1 go1.25-libstd-1.25.7-160000.1.1 go1.25-race-1.25.7-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2025-61732.html * https://www.suse.com/security/cve/CVE-2025-68121.html . This update for go1.25 addresses critical vulnerabilities and includes essential bug fixes for openSUSE Leap 16.0.. openSUSE security update, go1.25 vulnerabilities, critical security update. . Severity: Critical. LinuxSecurity.com Team
An insufficient session expiration has been reported in Telegram.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202105-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: Telegram: Security bypass Date: May 26, 2021 Bugs: #771684 ID: 202105-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An insufficient session expiration has been reported in Telegram. Background ========= Telegram is a cloud-based mobile and desktop messaging app with a focus on security and speed. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-im/telegram-desktop < 2.4.11 > = 2.4.11 2 net-im/telegram-desktop-bin < 2.4.11 > = 2.4.11 ------------------------------------------------------------------- 2 affected packages Description ========== It was discovered that Telegram failed to invalidate a recently active session. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Telegram users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-im/telegram-desktop-2.4.11" All Telegram binary users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =net-im/telegram-desktop-bin-2.4.11" References ========= [ 1 ] CVE-2021-27351 https://nvd.nist.gov/vuln/detail/CVE-2021-27351 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202105-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.