New upstream release fixing various security issues.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-0d8264f449 2026-02-18 00:54:04.864913+00:00 -------------------------------------------------------------------------------- Name : libssh Product : Fedora 42 Version : 0.11.4 Release : 1.fc42 URL : http://www.libssh.org Summary : A library implementing the SSH protocol Description : The ssh library was designed to be used by programmers needing a working SSH implementation by the mean of a library. The complete control of the client is made by the programmer. With libssh, you can remotely execute programs, transfer files, use a secure and transparent tunnel for your remote programs. With its Secure FTP implementation, you can play with remote files easily, without third-party programs others than libcrypto (from openssl). -------------------------------------------------------------------------------- Update Information: New upstream release fixing various security issues. -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 10 2026 Jakub Jelen - 0.11.4-1 - New upstream release fixing following security issues: - CVE-2025-14821: libssh loads configuration files from the C:\etc directory on Windows - CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request() - CVE-2026-0965: Possible Denial of Service when parsing unexpected configuration files - CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input - CVE-2026-0967: Specially crafted patterns could cause DoS - CVE-2026-0968: OOB Read in sftp_parse_longname() -------------------------------------------------------------------------------- References: [ 1 ] Bug #2438452 - libssh-0.12.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2438452 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-0d8264f449' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability can now be installed.. # Security update for curl Announcement ID: SUSE-SU-2026:0494-1 Release Date: 2026-02-13T09:59:35Z Rating: moderate References: * bsc#1219273 Cross-References: * CVE-2023-27534 CVSS scores: * CVE-2023-27534 ( SUSE ): 4.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2023-27534 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-27534 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for curl fixes the following issues: * CVE-2023-27534: Regression fix for SFTP path ~ resolving discrepancy (bsc#1219273) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-494=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-494=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * nghttp2-debuginfo-1.39.2-3.20.1 * libnghttp2-devel-1.39.2-3.20.1 * curl-8.0.1-11.117.1 * curl-debugsource-8.0.1-11.117.1 * nghttp2-debugsource-1.39.2-3.20.1 * curl-debuginfo-8.0.1-11.117.1 * libcurl4-debuginfo-8.0.1-11.117.1 * libnghttp2-14-debuginfo-1.39.2-3.20.1 * libnghttp2-14-1.39.2-3.20.1 * libcurl4-8.0.1-11.117.1 * libcurl-devel-8.0.1-11.117.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390xx86_64) * libcurl4-debuginfo-32bit-8.0.1-11.117.1 * libnghttp2-14-debuginfo-32bit-1.39.2-3.20.1 * libnghttp2-14-32bit-1.39.2-3.20.1 * libcurl4-32bit-8.0.1-11.117.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * nghttp2-debuginfo-1.39.2-3.20.1 * libcurl4-debuginfo-32bit-8.0.1-11.117.1 * curl-8.0.1-11.117.1 * libnghttp2-devel-1.39.2-3.20.1 * libcurl4-32bit-8.0.1-11.117.1 * curl-debugsource-8.0.1-11.117.1 * nghttp2-debugsource-1.39.2-3.20.1 * libnghttp2-14-32bit-1.39.2-3.20.1 * libnghttp2-14-debuginfo-32bit-1.39.2-3.20.1 * curl-debuginfo-8.0.1-11.117.1 * libcurl4-debuginfo-8.0.1-11.117.1 * libnghttp2-14-debuginfo-1.39.2-3.20.1 * libnghttp2-14-1.39.2-3.20.1 * libcurl4-8.0.1-11.117.1 * libcurl-devel-8.0.1-11.117.1 ## References: * https://www.suse.com/security/cve/CVE-2023-27534.html * https://bugzilla.suse.com/show_bug.cgi?id=1219273 . Update for curl resolves SFTP regression issue on SUSE with moderate severity. Ensure systems are patched promptly.. curl update, SUSE security, moderation update. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for erlang Announcement ID: SUSE-SU-2025:0901-1 Release Date: 2025-03-18T09:59:04Z Rating: moderate References: * bsc#1237467 Cross-References: * CVE-2025-26618 CVSS scores: * CVE-2025-26618 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-26618 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-26618 ( NVD ): 7.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for erlang fixes the following issues: * CVE-2025-26618: Fixed SSH SFTP packet size not verified properly in Erlang OTP (bsc#1237467). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-901=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-901=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2025-901=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * erlang-observer-23.3.4.19-150300.3.17.1 * erlang-dialyzer-src-23.3.4.19-150300.3.17.1 * erlang-debuginfo-23.3.4.19-150300.3.17.1 * erlang-et-src-23.3.4.19-150300.3.17.1 * erlang-observer-src-23.3.4.19-150300.3.17.1 * erlang-dialyzer-23.3.4.19-150300.3.17.1 * erlang-23.3.4.19-150300.3.17.1 *erlang-wx-src-23.3.4.19-150300.3.17.1 * erlang-diameter-23.3.4.19-150300.3.17.1 * erlang-debugsource-23.3.4.19-150300.3.17.1 * erlang-src-23.3.4.19-150300.3.17.1 * erlang-reltool-src-23.3.4.19-150300.3.17.1 * erlang-doc-23.3.4.19-150300.3.17.1 * erlang-jinterface-src-23.3.4.19-150300.3.17.1 * erlang-et-23.3.4.19-150300.3.17.1 * erlang-debugger-23.3.4.19-150300.3.17.1 * erlang-reltool-23.3.4.19-150300.3.17.1 * erlang-jinterface-23.3.4.19-150300.3.17.1 * erlang-epmd-23.3.4.19-150300.3.17.1 * erlang-dialyzer-debuginfo-23.3.4.19-150300.3.17.1 * erlang-wx-debuginfo-23.3.4.19-150300.3.17.1 * erlang-wx-23.3.4.19-150300.3.17.1 * erlang-diameter-src-23.3.4.19-150300.3.17.1 * erlang-debugger-src-23.3.4.19-150300.3.17.1 * erlang-epmd-debuginfo-23.3.4.19-150300.3.17.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * erlang-observer-23.3.4.19-150300.3.17.1 * erlang-dialyzer-src-23.3.4.19-150300.3.17.1 * erlang-debuginfo-23.3.4.19-150300.3.17.1 * erlang-et-src-23.3.4.19-150300.3.17.1 * erlang-observer-src-23.3.4.19-150300.3.17.1 * erlang-dialyzer-23.3.4.19-150300.3.17.1 * erlang-23.3.4.19-150300.3.17.1 * erlang-wx-src-23.3.4.19-150300.3.17.1 * erlang-diameter-23.3.4.19-150300.3.17.1 * erlang-debugsource-23.3.4.19-150300.3.17.1 * erlang-src-23.3.4.19-150300.3.17.1 * erlang-reltool-src-23.3.4.19-150300.3.17.1 * erlang-doc-23.3.4.19-150300.3.17.1 * erlang-jinterface-src-23.3.4.19-150300.3.17.1 * erlang-et-23.3.4.19-150300.3.17.1 * erlang-debugger-23.3.4.19-150300.3.17.1 * erlang-reltool-23.3.4.19-150300.3.17.1 * erlang-jinterface-23.3.4.19-150300.3.17.1 * erlang-epmd-23.3.4.19-150300.3.17.1 * erlang-dialyzer-debuginfo-23.3.4.19-150300.3.17.1 * erlang-wx-debuginfo-23.3.4.19-150300.3.17.1 * erlang-wx-23.3.4.19-150300.3.17.1 * erlang-diameter-src-23.3.4.19-150300.3.17.1 * erlang-debugger-src-23.3.4.19-150300.3.17.1 *erlang-epmd-debuginfo-23.3.4.19-150300.3.17.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * erlang-epmd-23.3.4.19-150300.3.17.1 * erlang-23.3.4.19-150300.3.17.1 * erlang-debugsource-23.3.4.19-150300.3.17.1 * erlang-debuginfo-23.3.4.19-150300.3.17.1 * erlang-epmd-debuginfo-23.3.4.19-150300.3.17.1 ## References: * https://www.suse.com/security/cve/CVE-2025-26618.html * https://bugzilla.suse.com/show_bug.cgi?id=1237467 . Recent updates address the SFTP complications observed in Erlang on openSUSE systems. Detailed instructions for applying the patch are provided.. openSUSE Security Update, erlang Patch Instructions, moderate RFC. . Severity: Medium. LinuxSecurity.com Team
curl was affected by a path traversal vulnerability. SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3763-1
The update of proftpd-dfsg released as DLA-2338-1 incorrectly destroyed the memory pool in function sftp_kex_handle in contrib/mod_sftp/kex.c which may cause a segmentation fault and thus prevent sftp connections. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2338-2
Several more boundary checks have been backported to libssh2's src/sftp.c. Furthermore, all boundary checks in src/sftp.c now result in an LIBSSH2_ERROR_BUFFER_TOO_SMALL error code, rather than a . Package : libssh2 Version : 1.4.3-4.1+deb8u5 CVE ID : CVE-2019-3860 Several more boundary checks have been backported to libssh2's src/sftp.c. Furthermore, all boundary checks in src/sftp.c now result in an LIBSSH2_ERROR_BUFFER_TOO_SMALL error code, rather than a LIBSSH2_ERROR_ OUT_OF_BOUNDARY error code. As a side note, it was discovered that libssh2's SFTP implementation from Debian jessie only works well against OpenSSH SFTP servers from Debian wheezy, tests against newer OpenSSH versions (such as available in Debian jessie and beyond) interim-fail with SFTP protocol error "Error opening remote file". Operation might continue after this error, this depends on application implementations. For Debian 8 "Jessie", this problem has been fixed in version 1.4.3-4.1+deb8u5. We recommend that you upgrade your libssh2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail:
The update of proftpd-dfsg issued as DLA-1753-1 caused a regression when using the sftp module. Login to the sftp server was impossible when the SFTPPAMEngine option was turned on (#926719). . Package : proftpd-dfsg Version : 1.3.5e+r1.3.5-2+deb8u1 CVE ID : not available Debian Bug : 923926 926719 The update of proftpd-dfsg issued as DLA-1753-1 caused a regression when using the sftp module. Login to the sftp server was impossible when the SFTPPAMEngine option was turned on (#926719). This update reverts to upstream version 1.3.5 again since even the latest upstream release 1.3.6 is still affected by different sftp related bugs (#927270). All fixes for the memory leaks were backported separately now. For Debian 8 "Jessie", this problem has been fixed in version 1.3.5e+r1.3.5-2+deb8u1. We recommend that you upgrade your proftpd-dfsg packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Notice regarding proftpd-dfsg, a resolution for the sftp regression bug has been implemented on Debian 8. It is advisable to perform an upgrade.. Proftpd Upgrade, Debian Security, SFTP Module Fix. . LinuxSecurity.com Team
Vulnerabilities have been found in the bootpd and ftp programs.. Date Reported: 04 Jan 1999 Affected Packages: netstd Vulnerable: Yes For more information: Fixed in: Source archives: g.tar.gz Intel architecture: Motorola 680x0 architecture: . Critical notice concerning Ubuntu: substantial memory overflow vulnerabilities discovered in tftpd and httpd elements affecting netutils package.. Debian, Buffer Overflows, TFTP Service, SFTP Service. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.