Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gun ver. 2.4.1 and its dependencies New erlang-gun. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-2aa86d411f 2026-06-21 01:09:26.438203+00:00 -------------------------------------------------------------------------------- Name : erlang-cowboy Product : Fedora 43 Version : 2.16.1 Release : 1.fc43 URL : https://github.com/ninenines/cowboy Summary : Small, fast, modular HTTP server written in Erlang Description : Small, fast, modular HTTP server written in Erlang. -------------------------------------------------------------------------------- Update Information: Gun ver. 2.4.1 and its dependencies New erlang-gun -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 12 2026 Peter Lemenkov - 2.16.1-1 - Cowboy ver. 2.16.1 * Wed Jun 10 2026 Peter Lemenkov - 2.16.0-1 - Cowboy ver. 2.16.0 * Fri Jan 16 2026 Fedora Release Engineering - 2.12.0-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2486315 - erlang-cowlib-2.17.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2486315 [ 2 ] Bug #2486350 - erlang-gun-2.4.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2486350 [ 3 ] Bug #2486422 - CVE-2026-43972 erlang-gun: Gun: Cross-origin cookie injection leading to session fixation and account takeover. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486422 [ 4 ] Bug #2486423 - CVE-2026-43974 erlang-gun: gun: Denial of Service via unsolicited 101 Switching Protocols response [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486423 [ 5 ] Bug #2486424 - CVE-2026-43973 erlang-gun: gun: Denial of Service via unbounded HTTP/1.1 response buffering [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486424 [ 6 ]Bug #2487823 - erlang-cowboy-2.16.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2487823 [ 7 ] Bug #2487824 - erlang-cowlib-2.17.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2487824 [ 8 ] Bug #2487833 - erlang-gun-2.4.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2487833 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2aa86d411f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Gun ver. 2.4.1 and its dependencies New erlang-gun. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-c17ea7a74d 2026-06-21 00:58:50.478354+00:00 -------------------------------------------------------------------------------- Name : erlang-cowboy Product : Fedora 44 Version : 2.16.1 Release : 1.fc44 URL : https://github.com/ninenines/cowboy Summary : Small, fast, modular HTTP server written in Erlang Description : Small, fast, modular HTTP server written in Erlang. -------------------------------------------------------------------------------- Update Information: Gun ver. 2.4.1 and its dependencies New erlang-gun -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 12 2026 Peter Lemenkov - 2.16.1-1 - Cowboy ver. 2.16.1 * Wed Jun 10 2026 Peter Lemenkov - 2.16.0-1 - Cowboy ver. 2.16.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2486315 - erlang-cowlib-2.17.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2486315 [ 2 ] Bug #2486350 - erlang-gun-2.4.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2486350 [ 3 ] Bug #2486422 - CVE-2026-43972 erlang-gun: Gun: Cross-origin cookie injection leading to session fixation and account takeover. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486422 [ 4 ] Bug #2486423 - CVE-2026-43974 erlang-gun: gun: Denial of Service via unsolicited 101 Switching Protocols response [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486423 [ 5 ] Bug #2486424 - CVE-2026-43973 erlang-gun: gun: Denial of Service via unbounded HTTP/1.1 response buffering [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486424 [ 6 ] Bug #2487823 - erlang-cowboy-2.16.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2487823 [ 7 ] Bug#2487824 - erlang-cowlib-2.17.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2487824 [ 8 ] Bug #2487833 - erlang-gun-2.4.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2487833 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-c17ea7a74d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST Fixes CVE-2026-6907: Potential exposure of private data due to incorrect. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9b7a6474a1 2026-05-21 00:54:04.884708+00:00 -------------------------------------------------------------------------------- Name : python-django5 Product : Fedora 44 Version : 5.2.14 Release : 1.fc44 URL : https://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST Fixes CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware Fixes CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation Fixes CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin Fixes CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable Fixes CVE-2026-33033: Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload Fixes CVE-2026-33034: Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass Fixes CVE-2026-25674: Potential incorrect permissions on newly created file system objects -------------------------------------------------------------------------------- ChangeLog: * Tue May 12 2026 Michel Lind - 5.2.14-1 - Update to version 5.2.14; Resolves RHBZ#2444117 - Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass - Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST - Fixes CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware - Fixes CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation - Fixes CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin - Fixes CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable - Fixes CVE-2026-33033: Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload - Fixes CVE-2026-33034: Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass - Fixes CVE-2026-25674: Potential incorrect permissions on newly created file system objects -------------------------------------------------------------------------------- References: [ 1 ] Bug #2444117 - python-django5-5.2.14 is available https://bugzilla.redhat.com/show_bug.cgi?id=2444117 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9b7a6474a1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST Fixes CVE-2026-6907: Potential exposure of private data due to incorrect. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-de6e24ae07 2026-05-21 00:54:04.884700+00:00 -------------------------------------------------------------------------------- Name : python-django6 Product : Fedora 44 Version : 6.0.5 Release : 1.fc44 URL : https://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST Fixes CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware Fixes CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation Fixes CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin Fixes CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable Fixes CVE-2026-33033: Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload Fixes CVE-2026-33034: Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass Fixes CVE-2026-25674: Potential incorrect permissions on newly created file system objects -------------------------------------------------------------------------------- ChangeLog: * Tue May 12 2026 Michel Lind - 6.0.5-1 - Update to version 6.0.5; Resolves RHBZ#2444118 - Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass - Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST - Fixes CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware - Fixes CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation - Fixes CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin - Fixes CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable - Fixes CVE-2026-33033: Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload - Fixes CVE-2026-33034: Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass - Fixes CVE-2026-25674: Potential incorrect permissions on newly created file system objects -------------------------------------------------------------------------------- References: [ 1 ] Bug #2444118 - python-django6-6.0.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2444118 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-de6e24ae07' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST Fixes CVE-2026-6907: Potential exposure of private data due to incorrect. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b9548393aa 2026-05-14 04:02:29.141273+00:00 -------------------------------------------------------------------------------- Name : python-django5 Product : Fedora 42 Version : 5.2.14 Release : 1.fc42 URL : https://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST Fixes CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware Fixes CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation Fixes CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin Fixes CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable Fixes CVE-2026-33033: Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload Fixes CVE-2026-33034: Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass Fixes CVE-2026-25674: Potential incorrect permissions on newly created file system objects -------------------------------------------------------------------------------- ChangeLog: * Tue May 12 2026 Michel Lind - 5.2.14-1 - Update to version 5.2.14; Resolves RHBZ#2444117 - Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass - Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST - Fixes CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware - Fixes CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation - Fixes CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin - Fixes CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable - Fixes CVE-2026-33033: Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload - Fixes CVE-2026-33034: Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass - Fixes CVE-2026-25674: Potential incorrect permissions on newly created file system objects -------------------------------------------------------------------------------- References: [ 1 ] Bug #2444117 - python-django5-5.2.14 is available https://bugzilla.redhat.com/show_bug.cgi?id=2444117 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b9548393aa' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed.. openSUSE security update: security update for python-django ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20704-1 Rating: moderate References: * bsc#1264152 * bsc#1264153 * bsc#1264154 Cross-References: * CVE-2026-35192 * CVE-2026-5766 * CVE-2026-6907 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed. Description: This update for python-Django fixes the following issues: Changes in python-Django: - CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass (bsc#1264153) - CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST (bsc#1264154) - CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware (bsc#1264152) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-234=1 Package List: - openSUSE Leap 16.0: python313-Django-5.2.4-bp160.8.1 References: * https://www.suse.com/security/cve/CVE-2026-35192.html * https://www.suse.com/security/cve/CVE-2026-5766.html * https://www.suse.com/security/cve/CVE-2026-6907.html . Update for python-Django on openSUSE fixes three issues affecting system security and overall reliability.. openSUSE python-Django security update moderate bug fixes. . LinuxSecurity.com Team
* bsc#1242894 * bsc#1242899 Cross-References: * CVE-2025-32441 . # Security update for rubygem-rack Announcement ID: SUSE-SU-2025:01586-2 Release Date: 2025-06-03T09:17:07Z Rating: important References: * bsc#1242894 * bsc#1242899 Cross-References: * CVE-2025-32441 * CVE-2025-46727 CVSS scores: * CVE-2025-32441 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-32441 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2025-32441 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2025-46727 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-46727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-46727 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for rubygem-rack fixes the following issues: * CVE-2025-46727: possible memory exhaustion due to unbounded parameter parsing in Rack::QueryParser (bsc#1242894). * CVE-2025-32441: deleted sessions can be restored and occupied by unauthenticated users when the Rack::Session::Pool middleware is being used (bsc#1242899). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2025-1586=1 ## Package List: * SUSE Linux Enterprise High Availability Extension 15 SP7 (aarch64 ppc64le s390x x86_64) * ruby2.5-rubygem-rack-2.0.8-150000.3.31.1 ## References: * https://www.suse.com/security/cve/CVE-2025-32441.html *https://www.suse.com/security/cve/CVE-2025-46727.html * https://bugzilla.suse.com/show_bug.cgi?id=1242894 * https://bugzilla.suse.com/show_bug.cgi?id=1242899 . SUSE's latest release tackles Rack complications, resolving memory depletion and enhancing session restoration. Discover further details within.. rubygem-rack, update instructions, security issues. . Severity: Important. LinuxSecurity.com Team
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, CSP bypass or session fixation. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3121-1
Get the latest Linux and open source security news straight to your inbox.