Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Update sequoia-openpgp to version 2.3.0. This includes three security relevant fixes (assigned CVE-2026-42783, CVE-2026-42784, and CVE-not-assigned-yet), see "Notable fixes" in the release notes: https://gitlab.com/sequoia-pgp/sequoia/-/raw/openpgp/v2.3.0/openpgp/NEWS This update includes rebuilds of all affected applications to pick up the fixes. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5619c60e85 2026-05-15 02:33:10.357479+00:00 -------------------------------------------------------------------------------- Name : rust-sequoia-sqv Product : Fedora 44 Version : 1.3.0 Release : 6.fc44 URL : https://crates.io/crates/sequoia-sqv Summary : Simple OpenPGP signature verification program Description : A simple OpenPGP signature verification program. -------------------------------------------------------------------------------- Update Information: Update sequoia-openpgp to version 2.3.0. This includes three security relevant fixes (assigned CVE-2026-42783, CVE-2026-42784, and CVE-not-assigned-yet), see "Notable fixes" in the release notes: https://gitlab.com/sequoia-pgp/sequoia/-/raw/openpgp/v2.3.0/openpgp/NEWS This update includes rebuilds of all affected applications to pick up the fixes for these issues. -------------------------------------------------------------------------------- ChangeLog: * Mon May 11 2026 Fabio Valentini - 1.3.0-6 - Rebuild for sequoia-openpgp v2.3.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2469048 - rust-sequoia-openpgp-2.3.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2469048 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5619c60e85' at the command line. For more information, refer to the dnf documentationavailable at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for python-cryptography ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20506-1 Rating: important References: * bsc#1258074 * bsc#1260876 Cross-References: * CVE-2026-26007 * CVE-2026-34073 CVSS scores: * CVE-2026-26007 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-26007 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34073 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34073 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for python-cryptography fixes the following issues: - CVE-2026-34073: Fixed X.509 bypass of name constraints on wildcard SANs with matching peer names. (bsc#1260876) - CVE-2026-26007: missing validation can lead to security issues for signature verification (ECDSA) and shared key negotiation (ECDH) (bsc#1258074). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-522=1 Package List: - openSUSE Leap 16.0: python313-cryptography-44.0.3-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-26007.html * https://www.suse.com/security/cve/CVE-2026-34073.html . Update for python-cryptography solves two important issues on openSUSE with recommended patching instructions detail.. openSUSE python cryptography update important. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for python-cryptography Announcement ID: SUSE-SU-2026:21021-1 Release Date: 2026-04-10T11:23:42Z Rating: important References: * bsc#1258074 * bsc#1260876 Cross-References: * CVE-2026-26007 * CVE-2026-34073 CVSS scores: * CVE-2026-26007 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-26007 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-26007 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-26007 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-34073 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34073 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34073 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34073 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-cryptography fixes the following issues: * CVE-2026-34073: Fixed X.509 bypass of name constraints on wildcard SANs with matching peer names. (bsc#1260876) * CVE-2026-26007: missing validation can lead to security issues for signature verification (ECDSA) and shared key negotiation (ECDH) (bsc#1258074). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-522=1 ## PackageList: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * python313-cryptography-debuginfo-44.0.3-160000.3.1 * python313-cryptography-44.0.3-160000.3.1 * python-cryptography-debugsource-44.0.3-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-26007.html * https://www.suse.com/security/cve/CVE-2026-34073.html * https://bugzilla.suse.com/show_bug.cgi?id=1258074 * https://bugzilla.suse.com/show_bug.cgi?id=1260876 . This advisory provides critical updates for python-cryptography, fixing issues to enhance security on SUSE systems.. python cryptography security patch. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for python-cryptography Announcement ID: SUSE-SU-2026:20655-1 Release Date: 2026-03-05T14:20:42Z Rating: moderate References: * bsc#1258074 Cross-References: * CVE-2026-26007 CVSS scores: * CVE-2026-26007 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-26007 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-26007 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-26007 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for python-cryptography fixes the following issues: * CVE-2026-26007: missing validation can lead to security issues for signature verification (ECDSA) and shared key negotiation (ECDH) (bsc#1258074). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-427=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * python311-cryptography-42.0.4-slfo.1.1_3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-26007.html * https://bugzilla.suse.com/show_bug.cgi?id=1258074 . Resolving a moderate issue in python-cryptography, SUSE updates enhance signature verification security with CVE-2026-26007.. python-cryptography update SUSE application security. . LinuxSecurity.com Team
Rebuild with sequoia-openpgp v2.1.0 to apply fixes for RUSTSEC-2025-0136 / CVE-2025-67897.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9317b8ea7b 2026-02-04 02:08:26.993090+00:00 -------------------------------------------------------------------------------- Name : rust-sequoia-sqv Product : Fedora 43 Version : 1.3.0 Release : 5.fc43 URL : https://crates.io/crates/sequoia-sqv Summary : Simple OpenPGP signature verification program Description : A simple OpenPGP signature verification program. -------------------------------------------------------------------------------- Update Information: Rebuild with sequoia-openpgp v2.1.0 to apply fixes for RUSTSEC-2025-0136 / CVE-2025-67897. -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 26 2026 Fabio Valentini - 1.3.0-5 - Rebuild for sequoia-openpgp v2.1.0 (RUSTSEC-2025-0136 / CVE-2025-67897) * Sat Jan 17 2026 Fedora Release Engineering - 1.3.0-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9317b8ea7b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
MGASA-2025-0258 - Updated microcode packages fix security vulnerability. MGASA-2025-0258 - Updated microcode packages fix security vulnerability Publication date: 05 Nov 2025 URL: https://advisories.mageia.org/MGASA-2025-0258.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-36347 Description: AMD CPU Microcode Signature Verification Vulnerability. (CVE-2024-36347) References: - https://bugs.mageia.org/show_bug.cgi?id=34706 - https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7033.html - https://www.cve.org/CVERecord?id=CVE-2024-36347 SRPMS: - 9/nonfree/microcode-0.20250812-3.mga9.nonfree . Updated microcode packages in Mageia 9 fix AMD CPU signature verification flaw identified as CVE-2024-36347.. Mageia Microcode AMD Vulnerability CVE-2024-36347 Security Fix. . Severity: Important. LinuxSecurity.com Team
CVE-2024-37890 yarnpkg: denial of service when handling a request with many HTTP headers. CVE-2024-48949 yarnpkg: Missing Validation in Elliptic's EDDSA Signature Verification. CVE-2024-12905 yarnpkg: link following and path traversal via . MGASA-2025-0194 - Updated yarnpkg packages fix security vulnerabilities Publication date: 25 Jun 2025 URL: https://advisories.mageia.org/MGASA-2025-0194.html Type: security Affected Mageia releases: 9 CVE: CVE-2020-7677, CVE-2021-43138, CVE-2022-3517, CVE-2024-37890, CVE-2024-48949, CVE-2022-37599, CVE-2023-26136, CVE-2023-46234, CVE-2024-12905, CVE-2024-4067, CVE-2025-48387 CVE-2024-37890 yarnpkg: denial of service when handling a request with many HTTP headers. CVE-2024-48949 yarnpkg: Missing Validation in Elliptic's EDDSA Signature Verification. CVE-2024-12905 yarnpkg: link following and path traversal via maliciously crafted tar file And other vulnerabilities in the yarn's bundled nodejs components are fixed too, see the references. References: - https://bugs.mageia.org/show_bug.cgi?id=33674 - https://lists.fedoraproject.org/archives/list/
poppler could be made to treat documents with forged signatures as legitimately signed.. ========================================================================== Ubuntu Security Notice USN-7471-1 April 29, 2025 poppler vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: poppler could be made to treat documents with forged signatures as legitimately signed. Software Description: - poppler: PDF rendering library Details: It was discovered that poppler did not properly verify adbe.pkcs7.sha1 signatures in PDF documents. An attacker could possibly use this issue to create documents with forged signatures that are treated as legitimately signed. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 libpoppler147 25.03.0-3ubuntu1 poppler-utils 25.03.0-3ubuntu1 Ubuntu 24.10 libpoppler140 24.08.0-1ubuntu0.3 poppler-utils 24.08.0-1ubuntu0.3 Ubuntu 24.04 LTS libpoppler134 24.02.0-1ubuntu9.4 poppler-utils 24.02.0-1ubuntu9.4 Ubuntu 22.04 LTS libpoppler118 22.02.0-2ubuntu0.8 poppler-utils 22.02.0-2ubuntu0.8 Ubuntu 20.04 LTS libpoppler97 0.86.1-0ubuntu1.7 poppler-utils 0.86.1-0ubuntu1.7 Ubuntu 18.04 LTS libpoppler73 0.62.0-2ubuntu2.14+esm6 Available withUbuntu Pro poppler-utils 0.62.0-2ubuntu2.14+esm6 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7471-1 CVE-2025-43903 Package Information: https://launchpad.net/ubuntu/+source/poppler/25.03.0-3ubuntu1 https://launchpad.net/ubuntu/+source/poppler/24.08.0-1ubuntu0.3 https://launchpad.net/ubuntu/+source/poppler/24.02.0-1ubuntu9.4 https://launchpad.net/ubuntu/+source/poppler/22.02.0-2ubuntu0.8 https://launchpad.net/ubuntu/+source/poppler/0.86.1-0ubuntu1.7 . Enhance your Ubuntu operating environment by ensuring that poppler does not permit the acceptance of falsified document signatures.. poppler security, Ubuntu patch, document verification, PDF security update. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.