Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # Security update for python-python-dotenv Announcement ID: SUSE-SU-2026:2724-1 Release Date: 2026-07-01T18:09:54Z Rating: moderate References: * bsc#1262423 Cross-References: * CVE-2026-28684 CVSS scores: * CVE-2026-28684 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28684 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H * CVE-2026-28684 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-python-dotenv fixes the following issue: * CVE-2026-28684: follow symbolic links when rewriting `.env` files (bsc#1262423) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2724=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2724=1 ## Package List: * Python 3 Module 15-SP7 (noarch) * python311-python-dotenv-1.0.0-150400.9.6.1 * openSUSE Leap 15.4 (noarch) * python311-python-dotenv-1.0.0-150400.9.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-28684.html * https://bugzilla.suse.com/show_bug.cgi?id=1262423 . # Security update for python-python-dotenv Announcement ID: SUSE-SU-2026:2724-1 Release Date: 2026-0. update, solves, vulnerability, installed, security, python-python-do. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for python-python-dotenv Announcement ID: SUSE-SU-2026:2724-1 Release Date: 2026-07-01T18:09:54Z Rating: moderate References: * bsc#1262423 Cross-References: * CVE-2026-28684 CVSS scores: * CVE-2026-28684 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28684 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H * CVE-2026-28684 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-python-dotenv fixes the following issue: * CVE-2026-28684: follow symbolic links when rewriting `.env` files (bsc#1262423) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2724=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2724=1 ## Package List: * Python 3 Module 15-SP7 (noarch) * python311-python-dotenv-1.0.0-150400.9.6.1 * openSUSE Leap 15.4 (noarch) * python311-python-dotenv-1.0.0-150400.9.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-28684.html * https://bugzilla.suse.com/show_bug.cgi?id=1262423 . A security update for python-dotenv addresses a critical issue allowing symbolic link rewrites. Install SUSE updates now.. SUSE python update, python-dotenv security, moderate severity patch, CVE-2026-28684, SUSE Linux security. . Severity: moderate. LinuxSecurity.com Team
An update that solves six vulnerabilities and has one security fix can now be installed.. # Security update for rsync Announcement ID: SUSE-SU-2025:0156-1 Release Date: 2025-01-17T11:59:13Z Rating: important References: * bsc#1234100 * bsc#1234101 * bsc#1234102 * bsc#1234103 * bsc#1234104 * bsc#1235475 * bsc#1235895 Cross-References: * CVE-2024-12084 * CVE-2024-12085 * CVE-2024-12086 * CVE-2024-12087 * CVE-2024-12088 * CVE-2024-12747 CVSS scores: * CVE-2024-12084 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-12084 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-12084 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-12085 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-12085 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2024-12085 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-12086 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-12086 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2024-12086 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2024-12087 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-12087 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-12087 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2024-12088 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2024-12088 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2024-12088 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2024-12747 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2024-12747 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2024-12747 ( NVD ): 5.6CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves six vulnerabilities and has one security fix can now be installed. ## Description: This update for rsync fixes the following issues: * CVE-2024-12084: heap buffer overflow in checksum parsing. (bsc#1234100) * CVE-2024-12085: leak of uninitialized stack data on the server leading to possible ASLR bypass. (bsc#1234101) * CVE-2024-12086: leak of a client machine's file contents through the processing of checksum data. (bsc#1234102) * CVE-2024-12087: arbitrary file overwrite possible on clients when symlink syncing is enabled. (bsc#1234103) * CVE-2024-12088: bypass of the --safe-links flag may allow the placement of unsafe symlinks in a client. (bsc#1234104) * CVE-2024-12747: race condition in rsync handling symbolic links (bsc#1235475) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-156=1 openSUSE-SLE-15.6-2025-156=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-156=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * rsync-debuginfo-3.2.7-150600.3.8.1 * rsync-debugsource-3.2.7-150600.3.8.1 * rsync-3.2.7-150600.3.8.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * rsync-debuginfo-3.2.7-150600.3.8.1 * rsync-debugsource-3.2.7-150600.3.8.1 * rsync-3.2.7-150600.3.8.1 ## References: * https://www.suse.com/security/cve/CVE-2024-12084.html * https://www.suse.com/security/cve/CVE-2024-12085.html *https://www.suse.com/security/cve/CVE-2024-12086.html * https://www.suse.com/security/cve/CVE-2024-12087.html * https://www.suse.com/security/cve/CVE-2024-12088.html * https://www.suse.com/security/cve/CVE-2024-12747.html * https://bugzilla.suse.com/show_bug.cgi?id=1234100 * https://bugzilla.suse.com/show_bug.cgi?id=1234101 * https://bugzilla.suse.com/show_bug.cgi?id=1234102 * https://bugzilla.suse.com/show_bug.cgi?id=1234103 * https://bugzilla.suse.com/show_bug.cgi?id=1234104 * https://bugzilla.suse.com/show_bug.cgi?id=1235475 * https://bugzilla.suse.com/show_bug.cgi?id=1235895 . Important patch released for rsync in openSUSE Leap 15.6 tackling multiple security flaws, including five vulnerabilities and an additional security enhancement.. rsync security update, openSUSE advisory, important security fix. . Severity: Important. LinuxSecurity.com Team
New rsync packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] rsync (SSA:2025-014-01) New rsync packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/rsync-3.4.0-i586-1_slack15.0.txz: Upgraded. This is a security release, fixing several important security vulnerabilities: Heap Buffer Overflow in Checksum Parsing. Info Leak via uninitialized Stack contents defeats ASLR. Server leaks arbitrary client files. Server can make client write files outside of destination directory using symbolic links. --safe-links Bypass. Symlink race condition. Many thanks to Simon Scannell, Pedro Gallegos, and Jasiel Spelman at Google Cloud Vulnerability Research and Aleksei Gorban (Loqpa) for discovering these vulnerabilities and working with the rsync project to develop and test fixes. For more information, see: https://kb.cert.org/vuls/id/952657 https://www.cve.org/CVERecord?id=CVE-2024-12084 https://www.cve.org/CVERecord?id=CVE-2024-12085 https://www.cve.org/CVERecord?id=CVE-2024-12086 https://www.cve.org/CVERecord?id=CVE-2024-12087 https://www.cve.org/CVERecord?id=CVE-2024-12088 https://www.cve.org/CVERecord?id=CVE-2024-12747 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/rsync-3.4.0-i586-1_slack15.0.txz Updated package for Slackware x86_6415.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/rsync-3.4.0-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/rsync-3.4.0-i686-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/rsync-3.4.0-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: 40333ee010789c1feb5cc75d1f040f93 rsync-3.4.0-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 0724faa590a069821a2acdd2affc6712 rsync-3.4.0-x86_64-1_slack15.0.txz Slackware -current package: 8f2267abf3ea43d45383abc591174e0f n/rsync-3.4.0-i686-1.txz Slackware x86_64 -current package: ced6c802e0ceeb0561e4ee21f66cc8d2 n/rsync-3.4.0-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg rsync-3.4.0-i586-1_slack15.0.txz +-----+ . Updated rsync versions resolve severe heap buffer overflow vulnerabilities and information disclosure issues for Slackware 15.0 and ongoing releases. Please update immediately!. rsync advisory, slackware update, security patch, heap overflow, info leak. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in Git.. =========================================================================Ubuntu Security Notice USN-5686-3 November 21, 2022 git vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 Summary: Several security issues were fixed in Git. Software Description: - git: fast, scalable, distributed revision control system Details: USN-5686-1 fixed vulnerabilities in Git. This update provides the corresponding updates for Ubuntu 22.10. Original advisory details: Cory Snider discovered that Git incorrectly handled certain symbolic links. An attacker could possibly use this issue to cause an unexpected behaviour. (CVE-2022-39253) Kevin Backhouse discovered that Git incorrectly handled certain command strings. An attacker could possibly use this issue to arbitrary code execution. (CVE-2022-39260) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: git 1:2.37.2-1ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5686-3 https://ubuntu.com/security/notices/USN-5686-1 CVE-2022-39253, CVE-2022-39260 Package Information: . Multiple vulnerabilities were addressed in Git for Ubuntu 22.10. Upgrade to safeguard your system from possible risks.. Git Security Issues, Ubuntu Updates, Security Flaws, Software Patches. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in Git.. =========================================================================Ubuntu Security Notice USN-5686-1 October 18, 2022 git vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Git. Software Description: - git: fast, scalable, distributed revision control system Details: Cory Snider discovered that Git incorrectly handled certain symbolic links. An attacker could possibly use this issue to cause an unexpected behaviour. (CVE-2022-39253) Kevin Backhouse discovered that Git incorrectly handled certain command strings. An attacker could possibly use this issue to arbitrary code execution. (CVE-2022-39260) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: git 1:2.34.1-1ubuntu1.5 Ubuntu 20.04 LTS: git 1:2.25.1-1ubuntu3.6 Ubuntu 18.04 LTS: git 1:2.17.1-1ubuntu0.13 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5686-1 CVE-2022-39253, CVE-2022-39260 Package Information: https://launchpad.net/ubuntu/+source/git/1:2.34.1-1ubuntu1.5 . Update Git on Ubuntu 22.04, 20.04, and 18.04 to fix vulnerabilities. Open Terminal, update package list, upgrade Git, verify version, and reboot if needed. Git Security, Ubuntu Update, Critical Issues, Security Advisory. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.