Explore top 10 tips to secure your open-source projects now. Read More
×An update that solves one vulnerability can now be installed.. # Security update for xdg-desktop-portal Announcement ID: SUSE-SU-2026:2712-1 Release Date: 2026-06-30T12:01:01Z Rating: moderate References: * bsc#1262045 Cross-References: * CVE-2026-40354 CVSS scores: * CVE-2026-40354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-40354 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40354 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for xdg-desktop-portal fixes the following issue: * CVE-2026-40354: File deletion via symlink attack (bsc#1262045). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2712=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2712=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * xdg-desktop-portal-debugsource-1.18.2-150600.4.6.1 * xdg-desktop-portal-1.18.2-150600.4.6.1 * xdg-desktop-portal-debuginfo-1.18.2-150600.4.6.1 * xdg-desktop-portal-devel-1.18.2-150600.4.6.1 * openSUSE Leap 15.6 (noarch) * xdg-desktop-portal-lang-1.18.2-150600.4.6.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * xdg-desktop-portal-debugsource-1.18.2-150600.4.6.1 * xdg-desktop-portal-1.18.2-150600.4.6.1 * xdg-desktop-portal-debuginfo-1.18.2-150600.4.6.1 *xdg-desktop-portal-devel-1.18.2-150600.4.6.1 * Desktop Applications Module 15-SP7 (noarch) * xdg-desktop-portal-lang-1.18.2-150600.4.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40354.html * https://bugzilla.suse.com/show_bug.cgi?id=1262045 . Update for xdg-desktop-portal addresses moderate risk of file deletion via symlink attack in SUSE Linux.. SUSE Linux Security Patch XDG Desktop Portal Update. . Severity: moderate. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for libheif Announcement ID: SUSE-SU-2026:2681-1 Release Date: 2026-06-29T13:27:52Z Rating: moderate References: * bsc#1261658 * bsc#1265878 Cross-References: * CVE-2026-32282 * CVE-2026-32814 CVSS scores: * CVE-2026-32282 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-32282 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-32282 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-32814 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-32814 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-32814 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.4 An update that solves two vulnerabilities can now be installed. ## Description: This update for libheif fixes the following issues * CVE-2026-32282: os: Root.Chmod can follow symlinks out of the root on Linux (bsc#1261658). * CVE-2026-32814: Uninitialized Heap Memory Information Leak via Failed Grid Tiles (bsc#1265878). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2681=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libheif-devel-1.12.0-150400.3.20.1 * libheif-debugsource-1.12.0-150400.3.20.1 * gdk-pixbuf-loader-libheif-debuginfo-1.12.0-150400.3.20.1 * libheif1-debuginfo-1.12.0-150400.3.20.1 * gdk-pixbuf-loader-libheif-1.12.0-150400.3.20.1 * libheif1-1.12.0-150400.3.20.1 * openSUSE Leap 15.4 (x86_64) * libheif1-32bit-debuginfo-1.12.0-150400.3.20.1 * libheif1-32bit-1.12.0-150400.3.20.1 * openSUSE Leap 15.4 (aarch64_ilp32) *libheif1-64bit-debuginfo-1.12.0-150400.3.20.1 * libheif1-64bit-1.12.0-150400.3.20.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32282.html * https://www.suse.com/security/cve/CVE-2026-32814.html * https://bugzilla.suse.com/show_bug.cgi?id=1261658 * https://bugzilla.suse.com/show_bug.cgi?id=1265878 . Update for libheif fixes two vulnerabilities including root symlink privilege escalation and a memory leak issue.. SUSE libheif vulnerabilities update information leak root symlink. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for xdg-desktop-portal Announcement ID: SUSE-SU-2026:2105-1 Release Date: 2026-05-28T16:04:00Z Rating: moderate References: * bsc#1262045 Cross-References: * CVE-2026-40354 CVSS scores: * CVE-2026-40354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-40354 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40354 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for xdg-desktop-portal fixes the following issue: * CVE-2026-40354: File deletion via symlink attack (bsc#1262045). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2105=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * xdg-desktop-portal-1.10.1-150400.3.11.1 * xdg-desktop-portal-debugsource-1.10.1-150400.3.11.1 * xdg-desktop-portal-debuginfo-1.10.1-150400.3.11.1 * xdg-desktop-portal-devel-1.10.1-150400.3.11.1 * openSUSE Leap 15.4 (noarch) * xdg-desktop-portal-lang-1.10.1-150400.3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40354.html * https://bugzilla.suse.com/show_bug.cgi?id=1262045 . Critical security update for xdg-desktop-portal addresses file deletion risk through symlink attacks in openSUSE Leap 15.4.. xdg desktop portal, openSUSE Leap, file deletion, symlink attack, security update. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for xdg-desktop-portal Announcement ID: SUSE-SU-2026:2105-1 Release Date: 2026-05-28T16:04:00Z Rating: moderate References: * bsc#1262045 Cross-References: * CVE-2026-40354 CVSS scores: * CVE-2026-40354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-40354 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40354 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for xdg-desktop-portal fixes the following issue: * CVE-2026-40354: File deletion via symlink attack (bsc#1262045). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2105=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * xdg-desktop-portal-1.10.1-150400.3.11.1 * xdg-desktop-portal-debugsource-1.10.1-150400.3.11.1 * xdg-desktop-portal-debuginfo-1.10.1-150400.3.11.1 * xdg-desktop-portal-devel-1.10.1-150400.3.11.1 * openSUSE Leap 15.4 (noarch) * xdg-desktop-portal-lang-1.10.1-150400.3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40354.html * https://bugzilla.suse.com/show_bug.cgi?id=1262045 . SUSE update addresses moderate file deletion risk in xdg-desktop-portal, enhancing system security against symlink attacks.. openSUSE updates, xdg-desktop-portal security, moderate risk patches, symlink vulnerability. . Severity: moderate. LinuxSecurity.com Team
upstream update, fixes security-related bugs CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device. The SUID mount follows symlinks when resolving loop backing file paths. On systems where non- root users are permitted to mount loop devices (via 'user' option in fstab), this allows access to arbitrary files.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-67cf3d6cca 2026-04-25 01:21:36.171645+00:00 -------------------------------------------------------------------------------- Name : util-linux Product : Fedora 44 Version : 2.41.4 Release : 7.fc44 URL : https://en.wikipedia.org/wiki/Util-linux Summary : Collection of basic system utilities Description : The util-linux package contains a large variety of low-level system utilities that are necessary for a Linux system to function. Among others, util-linux contains the fdisk configuration tool and the login program. -------------------------------------------------------------------------------- Update Information: upstream update, fixes security-related bugs CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device. The SUID mount follows symlinks when resolving loop backing file paths. On systems where non- root users are permitted to mount loop devices (via 'user' option in fstab), this allows access to arbitrary files. CWE-190 - Integer overflow in libblkid parse_dos_extended(). A crafted MBR disk image can cause uint32_t wraparound in EBR chain processing, causing reported partitions to not match the on-disk layout. Tools like udisks may then register a partition at logical sector 0. -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 1 2026 Karel Zak - 2.41.4-7 - upgrade to upstream release v2.41.4 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su-c 'dnf upgrade --advisory FEDORA-2026-67cf3d6cca' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability can now be installed.. # Security update for crun Announcement ID: SUSE-SU-2026:20452-1 Release Date: 2026-02-17T08:53:07Z Rating: important References: * bsc#1237421 Cross-References: * CVE-2025-24965 CVSS scores: * CVE-2025-24965 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2025-24965 ( SUSE ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2025-24965 ( NVD ): 8.5 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for crun fixes the following issues: * CVE-2025-24965: .krun_config.json symlink attack creates or overwrites file on the host (bsc#1237421). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-588=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * crun-1.14-2.1 * crun-debuginfo-1.14-2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-24965.html * https://bugzilla.suse.com/show_bug.cgi?id=1237421 . Critical SUSE update for crun fixes symlink attack vulnerability, ensuring essential patch management.. SUSE Security, crun Update, Symlink Protection, Vulnerability Management. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in Open VM Tools.. ========================================================================== Ubuntu Security Notice USN-7714-1 August 24, 2025 open-vm-tools vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Open VM Tools. Software Description: - open-vm-tools: Open VMware Tools for virtual machines hosted on VMware Details: Matthias Gerstner discovered that Open VM Tools incorrectly handled file descriptors when dropping privileges. A local attacker could possibly use this issue to hijack /dev/uinput and simulate user inputs. (CVE-2023-34059) Dolev Farhi discovered that Open VM Tools incorrectly handled certain file permissions. A local attacker could possibly use this issue to setup a symlink attack and override files without authorization. (CVE-2014-4199) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS open-vm-tools 2:9.4.0-1280544-5ubuntu6.4+esm1 Available with Ubuntu Pro open-vm-tools-desktop 2:9.4.0-1280544-5ubuntu6.4+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7714-1 CVE-2014-4199, CVE-2023-34059 . The vulnerabilities in Open VM Tools on Ubuntu 14.04 LTS have been patched. Ensure you update your system to safeguard against potential local exploitation.. Ubuntu Security, Open VM Tools, Ubuntu Pro. . Severity: Critical. LinuxSecurity.com Team
* bsc#1217783 * bsc#1217826 * bsc#1222121 * bsc#1230551 * bsc#1230552 . # Security update for pcp Announcement ID: SUSE-SU-2025:20235-1 Release Date: 2025-03-07T16:42:41Z Rating: moderate References: * bsc#1217783 * bsc#1217826 * bsc#1222121 * bsc#1230551 * bsc#1230552 Cross-References: * CVE-2023-6917 * CVE-2024-3019 * CVE-2024-45769 * CVE-2024-45770 CVSS scores: * CVE-2023-6917 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6917 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2023-6917 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-3019 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45769 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-45769 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45769 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45770 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2024-45770 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2024-45770 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities and has one fix can now be installed. ## Description: This update for pcp fixes the following issues: * CVE-2024-45769: Fixed `pmcd` heap corruption through metric pmstore operations (bsc#1230551). * CVE-2024-45770: Fixed `pmpost` symlink attack allowing escalating `pcp` to `root` user (bsc#1230552). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-33=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) *libpcp_import1-6.2.0-slfo.1.1_3.1 * libpcp3-debuginfo-6.2.0-slfo.1.1_3.1 * pcp-debugsource-6.2.0-slfo.1.1_3.1 * libpcp_import1-debuginfo-6.2.0-slfo.1.1_3.1 * libpcp3-6.2.0-slfo.1.1_3.1 * SUSE Linux Micro 6.1 (noarch) * pcp-conf-6.2.0-slfo.1.1_3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-6917.html * https://www.suse.com/security/cve/CVE-2024-3019.html * https://www.suse.com/security/cve/CVE-2024-45769.html * https://www.suse.com/security/cve/CVE-2024-45770.html * https://bugzilla.suse.com/show_bug.cgi?id=1217783 * https://bugzilla.suse.com/show_bug.cgi?id=1217826 * https://bugzilla.suse.com/show_bug.cgi?id=1222121 * https://bugzilla.suse.com/show_bug.cgi?id=1230551 * https://bugzilla.suse.com/show_bug.cgi?id=1230552 . The new patch for SUSE Linux Micro 6.1 mitigates moderate security vulnerabilities in pcp, correcting heap corruption and symbolic link problems.. SUSE Linux, pcp update, moderate threats, heap corruption, Linux Micro. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.