Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
rebase to v2.4.0 to fix CVE-2026-54369 and CVE-2026-54370 Resolves: CVE-2026-54369 Resolves: CVE-2026-54370. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6b9a652463 2026-07-11 01:06:30.201359+00:00 -------------------------------------------------------------------------------- Name : acl Product : Fedora 44 Version : 2.4.0 Release : 1.fc44 URL : https://savannah.nongnu.org/projects/acl Summary : Access control list utilities Description : This package contains the getfacl and setfacl utilities needed for manipulating access control lists. -------------------------------------------------------------------------------- Update Information: rebase to v2.4.0 to fix CVE-2026-54369 and CVE-2026-54370 Resolves: CVE-2026-54369 Resolves: CVE-2026-54370 -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 9 2026 Lukáš Zaoral - 2.4.0-1 - rebase to v2.4.0 to fix the following CVEs: - CVE-2026-54369 - Symlink traversal privilege escalation via libacl functions - CVE-2026-54370 - TOCTOU Symlink Traversal via getfacl/setfacl -------------------------------------------------------------------------------- References: [ 1 ] Bug #2494173 - CVE-2026-54370 acl: TOCTOU Symlink Traversal via getfacl/setfacl [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494173 [ 2 ] Bug #2494174 - CVE-2026-54369 acl: Symlink traversal privilege escalation via libacl functions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494174 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6b9a652463' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key.More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical Fedora 44 acl update since it fixes symlink privilege escalation issues to enhance system security.. Fedora acl update, privilege escalation, symlink vulnerability. . Severity: Critical. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for crun Announcement ID: SUSE-SU-2026:22395-1 Release Date: 2026-06-24T08:59:37Z Rating: moderate References: * bsc#1268302 Cross-References: * CVE-2026-47766 CVSS scores: * CVE-2026-47766 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for crun fixes the following issue * CVE-2026-47766: crun follows rootfs /dev symlink while creating default devices (bsc#1268302). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-766=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * crun-debuginfo-1.14-3.1 * crun-1.14-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-47766.html * https://bugzilla.suse.com/show_bug.cgi?id=1268302 . This security update addresses one moderate issue in crun related to symlink handling, applicable for SUSE Micro.. SUSE Linux Micro, crun security, moderate update. . Severity: moderate. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-30852 http://linux.oracle.com/errata/ELSA-2026-30852.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: perl-Archive-Tar-2.30-2.el8_10.noarch.rpm aarch64: perl-Archive-Tar-2.30-2.el8_10.noarch.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/perl-Archive-Tar-2.30-2.el8_10.src.rpm Related CVEs: CVE-2026-42496 Description of changes: [2.30-2] - Fix CVE-2026-42496: validate symlink and hardlink targets in secure extract mode - Resolves: RHEL-181654 [2.30-1] - 2.30 bump [2.28-1] - 2.28 bump - Fixes CVE-2018-12015 (directory traversal) (bug #1588761) [2.26-6] - Do not run optional test on RHEL [2.26-5] - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild [2.26-4] - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild [2.26-3] - Perl 5.26 re-rebuild of bootstrapped packages [2.26-2] - Perl 5.26 rebuild [2.26-1] - 2.26 bump [2.24-2] - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild _______________________________________________ El-errata mailing list
upstream update, fixes security-related bugs CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device. The SUID mount follows symlinks when resolving loop backing file paths. On systems where non-root users are permitted to mount loop devices (via 'user' option in fstab), this allows access to. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-840b40ef4c 2026-04-10 00:59:15.834457+00:00 -------------------------------------------------------------------------------- Name : util-linux Product : Fedora 43 Version : 2.41.4 Release : 7.fc43 URL : https://en.wikipedia.org/wiki/Util-linux Summary : Collection of basic system utilities Description : The util-linux package contains a large variety of low-level system utilities that are necessary for a Linux system to function. Among others, util-linux contains the fdisk configuration tool and the login program. -------------------------------------------------------------------------------- Update Information: upstream update, fixes security-related bugs CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device. The SUID mount follows symlinks when resolving loop backing file paths. On systems where non-root users are permitted to mount loop devices (via 'user' option in fstab), this allows access to arbitrary files. CWE-190 - Integer overflow in libblkid parse_dos_extended(). A crafted MBR disk image can cause uint32_t wraparound in EBR chain processing, causing reported partitions to not match the on-disk layout. Tools like udisks may then register a partition at logical sector 0. -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 1 2026 Karel Zak - 2.41.4-7 - upgrade to upstream release v2.41.4 * Mon Jan 12 2026 Karel Zak - 2.41.3-9 - enable BuildRequires for parsers * Mon Jan 12 2026 Karel Zak - 2.41.3-8 - fix built on newgcc (bison based code and libblkid API) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-840b40ef4c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Several security issues were fixed in Filelock.. ========================================================================== Ubuntu Security Notice USN-7999-1 February 02, 2026 python-filelock vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Filelock. Software Description: - python-filelock: A platform-independent file lock for Python Details: It was discovered that Filelock incorrectly handled symlinks in temp files. A local attacker could possibly use this issue to cause lock operations to fail or behave unexpectedly. (CVE-2026-22701) It was discovered that the file locking implementation in the Filelock package contained a race condition. A local attacker could possibly use this to cause a denial of service or corrupt arbitrary user files. (CVE-2025-68146) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python3-filelock 3.13.1-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS python3-filelock 3.6.0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS python3-filelock 3.0.12-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS python-filelock 3.0.4-1ubuntu0.1~esm1 Available with Ubuntu Pro python3-filelock 3.0.4-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7999-1 CVE-2025-68146, CVE-2026-22701 . Several security issues were fixed in Filelock affecting multiple Ubuntu LTS releases.Critical updates are recommended.. python-filelock update, Ubuntu security, file locking issues, Denial of Service, local attacker. . Severity: Important. LinuxSecurity.com Team
Fix CVE-2025-59343.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-4dd58248ff 2025-10-09 01:14:09.802852+00:00 -------------------------------------------------------------------------------- Name : yarnpkg Product : Fedora 41 Version : 1.22.22 Release : 12.fc41 URL : https://github.com/yarnpkg/yarn Summary : Fast, reliable, and secure dependency management. Description : Fast, reliable, and secure dependency management. -------------------------------------------------------------------------------- Update Information: Fix CVE-2025-59343. -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 30 2025 Sandro Mani - 1.22.22-12 - Regenerate bundle, fixes CVE-2025-59343 - Patch out eslint and commitizen devDependencies to reduce dependencies -------------------------------------------------------------------------------- References: [ 1 ] Bug #2397971 - CVE-2025-59343 yarnpkg: tar-fs symlink validation bypass [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2397971 [ 2 ] Bug #2397973 - CVE-2025-59343 yarnpkg: tar-fs symlink validation bypass [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2397973 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-4dd58248ff' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
node-tar-fs versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. . From: Xavier Guimard To:
It was discovered that the symlink validation in node-tar-fs, a Node.js module that provides filesystem-like access to tar files, could be bypassed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6013-1
Get the latest Linux and open source security news straight to your inbox.