Explore top 10 tips to secure your open-source projects now. Read More
×
Update to 3.6.6. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-10443c65e3 2026-04-18 01:08:05.671392+00:00 -------------------------------------------------------------------------------- Name : mbedtls Product : Fedora 42 Version : 3.6.6 Release : 1.fc42 URL : https://www.trustedfirmware.org/projects/mbed-tls Summary : Light-weight cryptographic and SSL/TLS library Description : Mbed TLS is a light-weight open source cryptographic and SSL/TLS library written in C. Mbed TLS makes it easy for developers to include cryptographic and SSL/TLS capabilities in their (embedded) applications with as little hassle as possible. -------------------------------------------------------------------------------- Update Information: Update to 3.6.6 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 2 2026 Peter Robinson - 3.6.6-1 - Update to 3.6.6 * Fri Jan 16 2026 Fedora Release Engineering - 3.6.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2340826 - mbedtls: FTBFS in Fedora rawhide/f42 https://bugzilla.redhat.com/show_bug.cgi?id=2340826 [ 2 ] Bug #2454030 - CVE-2026-25833 mbedtls: buffer underflow in x509_inet_pton_ipv6() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454030 [ 3 ] Bug #2454045 - CVE-2026-34874 mbedtls: NULL pointer dereference when setting a distinguished name [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454045 [ 4 ] Bug #2454085 - CVE-2026-34871 mbedtls: entropy on Linux can fall back to /dev/urandom [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454085 [ 5 ] Bug #2454116 - CVE-2026-25835 mbedtls: PSA random generator cloning [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454116 [ 6 ] Bug #2454193 - CVE-2026-34873 mbedtls: Mbed TLS: Client impersonation during TLS 1.3 session resumption [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454193 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-10443c65e3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Important: opentelemetry-collector security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:4177", "synopsis": "Important: opentelemetry-collector security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for opentelemetry-collector.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Collector with the supported components for a Rocky Enterprise Software Foundation build of OpenTelemetry\n\nSecurity Fix(es):\n\n* golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)\n\n* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2434432", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", "description": ""}, {"ticket": "2437111", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", "description": ""}], "cves": [{"name": "CVE-2025-61726", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61726", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-770"}, {"name": "CVE-2025-68121", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-68121", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "cvss3BaseScore": "7.4", "cwe": null}], "references": [], "publishedAt": "2026-03-11T12:05:01.163508Z", "rpms": {"Rocky Linux 9": {"nvras": ["opentelemetry-collector-0:0.144.0-1.el9.aarch64.rpm", "opentelemetry-collector-0:0.144.0-1.el9.ppc64le.rpm", "opentelemetry-collector-0:0.144.0-1.el9.s390x.rpm","opentelemetry-collector-0:0.144.0-1.el9.src.rpm", "opentelemetry-collector-0:0.144.0-1.el9.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important opentelemetry-collector security update is available for Rocky Linux 9 to address critical issues.. opentelemetry-collector update, Rocky Linux security fix, important security advisory. . Severity: Important. LinuxSecurity.com Team
Important: git-lfs security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:3985", "synopsis": "Important: git-lfs security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for git-lfs.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.\n\nSecurity Fix(es):\n\n* golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)\n\n* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2434432", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", "description": ""}, {"ticket": "2437111", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", "description": ""}], "cves": [{"name": "CVE-2025-61726", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61726", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-770"}, {"name": "CVE-2025-68121", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-68121", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "cvss3BaseScore": "7.4", "cwe": null}], "references": [], "publishedAt": "2026-03-10T12:01:15.755248Z", "rpms": {"Rocky Linux 8": {"nvras": ["git-lfs-0:3.4.1-8.el8_10.aarch64.rpm", "git-lfs-0:3.4.1-8.el8_10.src.rpm", "git-lfs-0:3.4.1-8.el8_10.x86_64.rpm","git-lfs-debuginfo-0:3.4.1-8.el8_10.aarch64.rpm", "git-lfs-debuginfo-0:3.4.1-8.el8_10.x86_64.rpm", "git-lfs-debugsource-0:3.4.1-8.el8_10.aarch64.rpm", "git-lfs-debugsource-0:3.4.1-8.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important security update for git-lfs on Rocky Linux 8 addressing critical issues related to memory exhaustion and session resumption.. git-lfs security update, Rocky Linux advisory, important security fix. . Severity: Important. LinuxSecurity.com Team
Moderate: delve security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:3842", "synopsis": "Moderate: delve security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for delve.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Delve is a debugger for the Go programming language. The goal of the project is to provide a simple, full featured debugging tool for Go. Delve should be easy to invoke and easy to use. Chances are if you're using a debugger, things aren't going your way. With that in mind, Delve should stay out of your way as much as possible.\n\nSecurity Fix(es):\n\n* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2437111", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", "description": ""}], "cves": [{"name": "CVE-2025-68121", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-68121", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "cvss3BaseScore": "7.4", "cwe": null}], "references": [], "publishedAt": "2026-03-06T12:03:43.669647Z", "rpms": {"Rocky Linux 9": {"nvras": ["delve-0:1.25.2-2.el9_7.aarch64.rpm", "delve-0:1.25.2-2.el9_7.ppc64le.rpm", "delve-0:1.25.2-2.el9_7.src.rpm", "delve-0:1.25.2-2.el9_7.x86_64.rpm", "delve-debuginfo-0:1.25.2-2.el9_7.aarch64.rpm", "delve-debuginfo-0:1.25.2-2.el9_7.ppc64le.rpm", "delve-debuginfo-0:1.25.2-2.el9_7.x86_64.rpm", "delve-debugsource-0:1.25.2-2.el9_7.aarch64.rpm", "delve-debugsource-0:1.25.2-2.el9_7.ppc64le.rpm", "delve-debugsource-0:1.25.2-2.el9_7.x86_64.rpm"]}},"rebootSuggested": false, "buildReferences": []}. Delve security update available for Rocky Linux 9 addresses moderate risks. Enhance your system's defenses with this patch.. Delve security, Rocky Linux updates, security patches, moderate vulnerabilities, blockchain security. . LinuxSecurity.com Team
Important: grafana-pcp security update. {"type":"TYPE_SECURITY","shortCode":"RL","name":"RLSA-2026:3187","synopsis":"Important: grafana-pcp security update","severity":"SEVERITY_IMPORTANT","topic":"An update is available for grafana-pcp.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards.\n\nSecurity Fix(es):\n\n* golang: net\/url: Memory exhaustion in query parameter parsing in net\/url (CVE-2025-61726)\n\n* crypto\/tls: Unexpected session resumption in crypto\/tls (CVE-2025-68121)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","solution":null,"affectedProducts":["Rocky Linux 8"],"fixes":[{"ticket":"2434432","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2434432","description":""},{"ticket":"2437111","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2437111","description":""}],"cves":[{"name":"CVE-2025-61726","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2025-61726","cvss3ScoringVector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H","cvss3BaseScore":"7.5","cwe":"CWE-770"},{"name":"CVE-2025-68121","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2025-68121","cvss3ScoringVector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:N","cvss3BaseScore":"7.4","cwe":null}],"references":[],"publishedAt":"2026-02-26T20:43:11.648035Z","rpms":{"Rocky Linux8":{"nvras":["grafana-pcp-0:5.1.1-12.el8_10.aarch64.rpm","grafana-pcp-0:5.1.1-12.el8_10.src.rpm","grafana-pcp-0:5.1.1-12.el8_10.x86_64.rpm","grafana-pcp-debuginfo-0:5.1.1-12.el8_10.aarch64.rpm","grafana-pcp-debuginfo-0:5.1.1-12.el8_10.x86_64.rpm","grafana-pcp-debugsource-0:5.1.1-12.el8_10.aarch64.rpm","grafana-pcp-debugsource-0:5.1.1-12.el8_10.x86_64.rpm"]}},"rebootSuggested":false,"buildReferences":[]}. Significant security patch available for grafana-pcp in Rocky Linux 8 to fix memory exhaustion and session issues.. grafana-pcp patch, Rocky Linux updates, security fixes. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for nginx Announcement ID: SUSE-SU-2025:03089-1 Release Date: 2025-09-05T10:39:06Z Rating: moderate References: * bsc#1236851 * bsc#1248070 Cross-References: * CVE-2025-23419 * CVE-2025-53859 CVSS scores: * CVE-2025-23419 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-23419 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2025-23419 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-23419 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2025-53859 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-53859 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2025-53859 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-53859 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * openSUSE Leap 15.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for nginx fixes the following issues: * CVE-2025-53859: the server side may leak arbitrary bytes during the NGINX SMTP authentication process (bsc#1248070). * CVE-2025-23419: session resumption can bypass client certificate authentication requirements using TLSv1.3 (bsc#1236851). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_updateor "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-3089=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * nginx-1.19.8-150300.3.18.1 * nginx-debuginfo-1.19.8-150300.3.18.1 * nginx-debugsource-1.19.8-150300.3.18.1 * openSUSE Leap 15.3 (noarch) * vim-plugin-nginx-1.19.8-150300.3.18.1 * nginx-source-1.19.8-150300.3.18.1 ## References: * https://www.suse.com/security/cve/CVE-2025-23419.html * https://www.suse.com/security/cve/CVE-2025-53859.html * https://bugzilla.suse.com/show_bug.cgi?id=1236851 * https://bugzilla.suse.com/show_bug.cgi?id=1248070 . This update addresses security flaws in nginx on openSUSE Leap 15.3, fixing an issue related to session management and preventing inadvertent data leaks.. openSUSE security patch nginx. . LinuxSecurity.com Team
This upload fixes two security issues in the version of nginx shipped in bullseye. CVE-2024-7347 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4091-1
Several security issues were fixed in nginx.. ========================================================================== Ubuntu Security Notice USN-7285-1 February 24, 2025 nginx vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in nginx. Software Description: - nginx: small, powerful, scalable web/proxy server Details: It was discovered that nginx incorrectly handled when multiple server blocks are configured to share the same IP address and port. An attacker could use this issue to use session resumption to bypass client certificate authentication requirements on these servers. This issue only affected Ubuntu 24.10. A buffer overflow and a null pointer deref was fixed in nginx rtmp module (#LP 1977718). This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 nginx 1.26.0-2ubuntu3.2 nginx-common 1.26.0-2ubuntu3.2 nginx-core 1.26.0-2ubuntu3.2 nginx-dev 1.26.0-2ubuntu3.2 nginx-doc 1.26.0-2ubuntu3.2 nginx-extras 1.26.0-2ubuntu3.2 nginx-full 1.26.0-2ubuntu3.2 nginx-light 1.26.0-2ubuntu3.2 Ubuntu 22.04 LTS libnginx-mod-rtmp 1.18.0-6ubuntu14.6 nginx 1.18.0-6ubuntu14.6 nginx-common 1.18.0-6ubuntu14.6 nginx-core 1.18.0-6ubuntu14.6 nginx-doc 1.18.0-6ubuntu14.6 nginx-extras 1.18.0-6ubuntu14.6 nginx-full 1.18.0-6ubuntu14.6 nginx-light 1.18.0-6ubuntu14.6 Ubuntu 20.04 LTS libnginx-mod-rtmp 1.18.0-0ubuntu1.7 nginx 1.18.0-0ubuntu1.7 nginx-common 1.18.0-0ubuntu1.7 nginx-core 1.18.0-0ubuntu1.7 nginx-doc 1.18.0-0ubuntu1.7 nginx-extras 1.18.0-0ubuntu1.7 nginx-full 1.18.0-0ubuntu1.7 nginx-light 1.18.0-0ubuntu1.7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7285-1 CVE-2025-23419, https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1977718 Package Information: https://launchpad.net/ubuntu/+source/nginx/1.26.0-2ubuntu3.2 https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.6 https://launchpad.net/ubuntu/+source/nginx/1.18.0-0ubuntu1.7 . Multiple security issues were fixed in nginx for Ubuntu versions. Follow the guidance for necessary updates.. nginx updates, Ubuntu vulnerabilities, web server patches. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.