Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 2 vulnerabilities and has 3 bug fixes can now be installed.. openSUSE security update: security update for grafana ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21366-1 Rating: important References: * bsc#1271327 * bsc#1271331 * bsc#1271557 Cross-References: * CVE-2026-33382 * CVE-2026-8595 CVSS scores: * CVE-2026-33382 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-8595 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 3 bug fixes can now be installed. Description: This update for grafana fixes the following issues: Changes in grafana: - CVE-2026-33382: Limit the size of the request body before processing it at several Grafana API endpoints (bsc#1271331) - CVE-2026-8595: Fix stored XSS in the table panel (bsc#1271557) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-426=1 Package List: - openSUSE Leap 16.0: grafana-12.4.5-bp160.2.1 References: * https://www.suse.com/security/cve/CVE-2026-33382.html * https://www.suse.com/security/cve/CVE-2026-8595.html . Update for openSUSE fixes 2 issues including XSS and request size limit in Grafana crucial for securing your application.. openSUSE grafana update important issues security patch. . Severity: Important. LinuxSecurity.com Team
Release 1.6.17 Enigma: Support automatic public key lookup (import) using HKP v1 protocol (#5314) Enigma: Kolab WOAT Support (#8626) Security: Fix an infinite loop in TNEF (winmail.dat) decoder (#10193). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-c3351f4ae4 2026-07-16 01:28:35.510729+00:00 -------------------------------------------------------------------------------- Name : roundcubemail Product : Fedora 43 Version : 1.6.17 Release : 1.fc43 URL : http://www.roundcube.net Summary : Round Cube Webmail is a browser-based multilingual IMAP client Description : RoundCube Webmail is a browser-based multilingual IMAP client with an application-like user interface. It provides full functionality you expect from an e-mail client, including MIME support, address book, folder manipulation, message searching and spell checking. RoundCube Webmail is written in PHP and requires a database: MySQL, PostgreSQL and SQLite are known to work. The user interface is fully skinnable using XHTML and CSS 2. -------------------------------------------------------------------------------- Update Information: Release 1.6.17 Enigma: Support automatic public key lookup (import) using HKP v1 protocol (#5314) Enigma: Kolab WOAT Support (#8626) Security: Fix an infinite loop in TNEF (winmail.dat) decoder (#10193) Security: Fix various vulnerabilities in the password plugin using session- injected username Security: Fix stored XSS via unescaped attachment MIME type on the attachment- validation warning page [CVE-2026-54432] Security: Fix SSRF bypass via specific local address URLs - two new cases Security: Fix zero-click stored XSS in plain-text rendering [CVE-2026-54433] Security: Fix DoS via crafted compressed-RTF size in the TNEF (winmail.dat) file -------------------------------------------------------------------------------- ChangeLog: * Mon Jul 6 2026 Remi Collet - 1.6.17-1 -update to 1.6.17 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2500063 - CVE-2026-54433 roundcubemail: Roundcube Webmail: Arbitrary code execution via zero-click cross-site scripting [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500063 [ 2 ] Bug #2500065 - CVE-2026-62642 roundcubemail: Roundcube Webmail: Denial of Service via infinite loop in TNEF decoder [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500065 [ 3 ] Bug #2500067 - CVE-2026-62644 roundcubemail: Roundcube Webmail: Account takeover via username spoofing in password plugin [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500067 [ 4 ] Bug #2500068 - CVE-2026-54432 roundcubemail: Roundcube Webmail: Stored Cross-Site Scripting via unescaped attachment MIME type [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500068 [ 5 ] Bug #2500071 - CVE-2026-62641 roundcubemail: Roundcube Webmail: Denial of Service via crafted TNEF compressed-RTF size [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500071 [ 6 ] Bug #2500072 - CVE-2026-62643 roundcubemail: Roundcube Webmail: Server-Side Request Forgery via insufficient CSS sanitization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500072 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-c3351f4ae4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list--
MGASA-2026-0075 - Updated ruby-rack packages fix security vulnerabilities. MGASA-2026-0075 - Updated ruby-rack packages fix security vulnerabilities Publication date: 31 Mar 2026 URL: https://advisories.mageia.org/MGASA-2026-0075.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-22860, CVE-2026-25500 Description: Rack has a Directory Traversal via Rack:Directory. (CVE-2026-22860) Rack's Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href. (CVE-2026-25500) References: - https://bugs.mageia.org/show_bug.cgi?id=35285 - https://lists.debian.org/debian-security-announce/2026/msg00089.html - https://www.cve.org/CVERecord?id=CVE-2026-22860 - https://www.cve.org/CVERecord?id=CVE-2026-25500 SRPMS: - 9/core/ruby-rack-2.2.22-1.mga9 . Updated ruby-rack packages for Mageia fix critical security flaws, including directory traversal and stored XSS issues.. Mageia Ruby Rack Security Patch 2026. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for grafana ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2715-1 Rating: moderate References: #1174583 Cross-References: CVE-2020-11110 Affected Products: SUSE Enterprise Storage 5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for grafana fixes the following issues: - CVE-2020-11110: Fixed a stored XSS in dashboard snapshot original dashboard link (bsc#1174583). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Enterprise Storage 5: zypper in -t patch SUSE-Storage-5-2020-2715=1 Package List: - SUSE Enterprise Storage 5 (aarch64 x86_64): grafana-4.6.5-3.13.1 grafana-debuginfo-4.6.5-3.13.1 grafana-debugsource-4.6.5-3.13.1 References: https://www.suse.com/security/cve/CVE-2020-11110.html https://bugzilla.suse.com/1174583 _______________________________________________ sle-security-updates mailing list
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for nextcloud ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:3999-1 Rating: moderate References: #1114817 Cross-References: CVE-2018-3780 Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for nextcloud fixes security issues and bugs. Security issues fixed: - CVE-2018-3780: Stored XSS in autocomplete suggestions for file comments (boo#1114817) This update also contains all bug fixes and improvements in the 13.0.8 version, including: - Password expiration time changed from 12h to 7d - Bug fixes to the OAuth brute force protection - Various other bug fixes and improvements Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Package Hub for SUSE Linux Enterprise 12: zypper in -t patch openSUSE-2018-1487=1 Package List: - SUSE Package Hub for SUSE Linux Enterprise 12 (noarch): nextcloud-13.0.8-8.1 References: https://www.suse.com/security/cve/CVE-2018-3780.html https://bugzilla.suse.com/1114817 -- . openSUSE releases a patch addressing a medium-level security flaw in Nextcloud: an instance of stored XSS found in autocomplete features.. openSUSE Security Update, Nextcloud Vulnerability Fix, XSS Protection. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.