Moderate: delve security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:3842", "synopsis": "Moderate: delve security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for delve.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Delve is a debugger for the Go programming language. The goal of the project is to provide a simple, full featured debugging tool for Go. Delve should be easy to invoke and easy to use. Chances are if you're using a debugger, things aren't going your way. With that in mind, Delve should stay out of your way as much as possible.\n\nSecurity Fix(es):\n\n* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2437111", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", "description": ""}], "cves": [{"name": "CVE-2025-68121", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-68121", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "cvss3BaseScore": "7.4", "cwe": null}], "references": [], "publishedAt": "2026-03-06T12:03:43.669647Z", "rpms": {"Rocky Linux 9": {"nvras": ["delve-0:1.25.2-2.el9_7.aarch64.rpm", "delve-0:1.25.2-2.el9_7.ppc64le.rpm", "delve-0:1.25.2-2.el9_7.src.rpm", "delve-0:1.25.2-2.el9_7.x86_64.rpm", "delve-debuginfo-0:1.25.2-2.el9_7.aarch64.rpm", "delve-debuginfo-0:1.25.2-2.el9_7.ppc64le.rpm", "delve-debuginfo-0:1.25.2-2.el9_7.x86_64.rpm", "delve-debugsource-0:1.25.2-2.el9_7.aarch64.rpm", "delve-debugsource-0:1.25.2-2.el9_7.ppc64le.rpm", "delve-debugsource-0:1.25.2-2.el9_7.x86_64.rpm"]}},"rebootSuggested": false, "buildReferences": []}. Rocky Linux Delve gets a moderate security update addressing critical session resumption issues for enhanced protection.. Moderate Security Update, Rocky Linux Delve, Go Debugger Security, CVSS Score 7.4. . LinuxSecurity.com Team
Updated jhead package fixes security vulnerabilities: jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c (CVE-2020-6624). . MGASA-2021-0328 - Updated jhead packages fix security vulnerabilities Publication date: 10 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0328.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2020-6624, CVE-2020-6625, CVE-2021-3496 Updated jhead package fixes security vulnerabilities: jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c (CVE-2020-6624). jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c (CVE-2020-6625). A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file (CVE-2021-3496). References: - https://bugs.mageia.org/show_bug.cgi?id=29053 - - - https://www.cve.org/CVERecord?id=CVE-2020-6624 - https://www.cve.org/CVERecord?id=CVE-2020-6625 - https://www.cve.org/CVERecord?id=CVE-2021-3496 SRPMS: - 8/core/jhead-3.06.0.1-1.mga8 - 7/core/jhead-3.06.0.1-1.mga7 . Ubuntu has released an update for the libxyz library to address urgent security flaws such as heap overflows and improper input validations.. jhead security update,mageia package fixes,buffer overflow issues. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.