Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # Security update for python-urllib3 Announcement ID: SUSE-SU-2026:2486-1 Release Date: 2026-06-22T12:07:44Z Rating: important References: * bsc#1265267 Cross-References: * CVE-2026-44431 CVSS scores: * CVE-2026-44431 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44431 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44431 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44431 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python-urllib3 fixesthe following issue * CVE-2026-44431: sensitive information disclosure due to sensitive headers being forwarded across origins in proxied low-level redirects (bsc#1265267). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2486=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2486=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2486=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-2486=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2486=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2486=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2486=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2486=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2486=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2486=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2486=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2486=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2486=1 ## Package List: * Python 3 Module 15-SP7 (noarch) *python311-urllib3-2.0.7-150400.7.30.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * python311-urllib3-2.0.7-150400.7.30.1 * openSUSE Leap 15.4 (noarch) * python311-urllib3-2.0.7-150400.7.30.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python311-urllib3-2.0.7-150400.7.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python311-urllib3-2.0.7-150400.7.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python311-urllib3-2.0.7-150400.7.30.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python311-urllib3-2.0.7-150400.7.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python311-urllib3-2.0.7-150400.7.30.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python311-urllib3-2.0.7-150400.7.30.1 * Public Cloud Module 15-SP4 (noarch) * python311-urllib3-2.0.7-150400.7.30.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python311-urllib3-2.0.7-150400.7.30.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python311-urllib3-2.0.7-150400.7.30.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python311-urllib3-2.0.7-150400.7.30.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44431.html * https://bugzilla.suse.com/show_bug.cgi?id=1265267 . A critical patch for python-urllib3 addresses sensitive data exposure in openSUSE, improving overall system security.. openSUSE security, python urllib3 patch, sensitive information disclosure, software update, Linux vulnerability. . Severity: Important. LinuxSecurity.com Team
Fix access/use of uninitialized memory in stb_image. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-f45664a58a 2026-04-25 01:21:36.172470+00:00 -------------------------------------------------------------------------------- Name : stb Product : Fedora 44 Version : 0^20260313git904aa67 Release : 2.fc44 URL : https://github.com/nothings/stb Summary : Single-file public domain libraries for C/C++ Description : Single-file public domain libraries for C/C++. -------------------------------------------------------------------------------- Update Information: Fix access/use of uninitialized memory in stb_image -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 8 2026 Benjamin A. Beasley - 0^20260313git904aa67-2 - Fix access/use of uninitialized memory in stb_image - This was undefined behavior, and could leak security-relevant information from other data structures. See https://github.com/nothings/stb/issues/1929. -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-f45664a58a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
patchlevel 1202 Security fix for CVE-2025-29768. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-7b21a14892 2025-03-16 02:26:46.309007+00:00 -------------------------------------------------------------------------------- Name : vim Product : Fedora 41 Version : 9.1.1202 Release : 1.fc41 URL : http://www.vim.org/ Summary : The VIM editor Description : VIM (VIsual editor iMproved) is an updated and improved version of the vi editor. Vi was the first real screen-based editor for UNIX, and is still very popular. VIM improves on vi by adding new features: multiple windows, multi-level undo, block highlighting and more. -------------------------------------------------------------------------------- Update Information: patchlevel 1202 Security fix for CVE-2025-29768 -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 14 2025 Zdenek Dohnal - 2:9.1.1202-1 - patchlevel 1202 * Fri Mar 7 2025 Zdenek Dohnal - 2:9.1.1179-1 - patchlevel 1179 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2352418 - CVE-2025-29768 vim: Vim vulnerable to potential data loss with zip.vim and special crafted zip files https://bugzilla.redhat.com/show_bug.cgi?id=2352418 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7b21a14892' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Qt 6.7.1 bugfix update.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-bfb8617ba3 2024-05-29 03:35:14.763998 -------------------------------------------------------------------------------- Name : qt6-qtimageformats Product : Fedora 40 Version : 6.7.1 Release : 1.fc40 URL : http://www.qt.io Summary : Qt6 - QtImageFormats component Description : The core Qt Gui library by default supports reading and writing image files of the most common file formats: PNG, JPEG, BMP, GIF and a few more, ref. Reading and Writing Image Files. The Qt Image Formats add-on module provides optional support for other image file formats, including: MNG, TGA, TIFF, WBMP. -------------------------------------------------------------------------------- Update Information: Qt 6.7.1 bugfix update. -------------------------------------------------------------------------------- ChangeLog: * Tue May 21 2024 Jan Grulich - 6.7.1-1 - 6.7.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2282868 - CVE-2024-36048 qt6-qtnetworkauth: qtnetworkauth: badly seeded PRNG may result in guessable values [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2282868 [ 2 ] Bug #2282870 - CVE-2024-36048 qt6-qtnetworkauth: qtnetworkauth: badly seeded PRNG may result in guessable values [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2282870 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-bfb8617ba3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Upstream details at : https://access.redhat.com/errata/RHSA-2020:5009. CentOS Errata and Security Advisory 2020:5009 Moderate Upstream details at : https://access.redhat.com/errata/RHSA-2020:5009 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: cf8845ef810f6cf39ce19f2a986496e8ae2fed2fe5d711309d0e91b72b693e29 python-2.7.5-90.el7.x86_64.rpm f34c8bb09dee906565117017407530b10c48ef7eb3ccb89860689de03b8e4118 python-debug-2.7.5-90.el7.x86_64.rpm 2c05f80ee0d06dcbfa8d83439b41cacb2acbe096d4994aed2e9a4b88d43c309c python-devel-2.7.5-90.el7.x86_64.rpm 82386943e7fd9af89f6c5d8dcb1845c1484cf6a8e11a055c062e3c11deb5110c python-libs-2.7.5-90.el7.i686.rpm 714b86985ff8c757c1d759dc240539eb7226c4445ee4b6ed010da90d5449c6a6 python-libs-2.7.5-90.el7.x86_64.rpm 32249537b076dbba37c943b1b65d1fff2e87bb54365e3b33c003135dd728a178 python-test-2.7.5-90.el7.x86_64.rpm 0b1af8e104a87dcac9e19a39e5868fef98096447b8a8eafc1e3fe57711fabf57 python-tools-2.7.5-90.el7.x86_64.rpm 2a26d447506a770f081b5fb28e25fb0f7666bbfffc7c5f065c200fda418823ea tkinter-2.7.5-90.el7.x86_64.rpm Source: 58aba47251e141d3069910d2ad957ef1defa0913389e350322ccd226536f2d01 python-2.7.5-90.el7.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
**MySQL 8.0.18** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-18.html Security Advisory: https://www.oracle.com/security-alerts/cpuoct2019.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-40ed49f449 2019-12-07 01:29:55.746965 --------------------------------------------------------------------------------Name : community-mysql Product : Fedora 30 Version : 8.0.18 Release : 4.fc30 URL : http://www.mysql.com Summary : MySQL client programs and shared libraries Description : MySQL is a multi-user, multi-threaded SQL database server. MySQL is a client/server implementation consisting of a server daemon (mysqld) and many different client programs and libraries. The base package contains the standard MySQL client programs and generic MySQL files. --------------------------------------------------------------------------------Update Information: **MySQL 8.0.18** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-18.html Security Advisory: https://www.oracle.com/security-alerts/cpuoct2019.html --------------------------------------------------------------------------------ChangeLog: * Fri Nov 15 2019 Michal Schorm - 8.0.18-4 - Typo fixup * Mon Nov 11 2019 Michal Schorm - 8.0.18-3 - Let the devel package require the libzstd-devel * Fri Nov 1 2019 Pete Walter - 8.0.18-2 - Rebuild for ICU 65 * Mon Oct 14 2019 Lars Tangvald - 8.0.18-1 - Update to MySQL 8.0.18 * Mon Aug 19 2019 Michal Schorm - 8.0.17-2 - Use RELRO hardening on all binaries * Wed Jul 31 2019 Lars Tangvald - 8.0.17-1 - Update to MySQL 8.0.17 * Wed Jul 24 2019 Fedora Release Engineering - 8.0.16-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Wed May 1 2019 Michal Schorm - 8.0.16-2 - Remove SysVInit stuff, no longer needed - Clean up the SPECfile * Fri Apr 26 2019 Lars Tangvald - 8.0.16-1 - Update to MySQL8.0.16 - Rediff sharedir patch - Refresh skip list and use new, required format - Remove GCC9 patch now upstream - Upstream: my_safe_process renamed and moved into proper location - Use upstream option to skip router build - OpenSSL 1.1.1 and TLSv1.3 is now supported, enable tests - Update version of bundled Boost - Start requiring mysql-selinux package --------------------------------------------------------------------------------References: [ 1 ] Bug #1772876 - Typo in spec file https://bugzilla.redhat.com/show_bug.cgi?id=1772876 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-40ed49f449' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Upstream details at : https://access.redhat.com/errata/RHSA-2018:1660. CentOS Errata and Security Advisory 2018:1660 Important Upstream details at : https://access.redhat.com/errata/RHSA-2018:1660 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) i386: 16115cc8e7a72d4d5eaa975121021491213b971769bc8fa86944d7511a1e11c3 qemu-guest-agent-0.12.1.2-2.503.el6_9.6.i686.rpm x86_64: 03a6ad9df64c6820ed8f820c169d0bb060909002fb628e8abc395a3e62725011 qemu-guest-agent-0.12.1.2-2.503.el6_9.6.x86_64.rpm 030219d45b9a3cd1d43d99ce3e360c1bcb0877401793b0b7183b13be057a8a0d qemu-img-0.12.1.2-2.503.el6_9.6.x86_64.rpm 95a7320cb381b404a5b576525149f9aa37a6873ec1119807e68a4e63df899fae qemu-kvm-0.12.1.2-2.503.el6_9.6.x86_64.rpm 1dcabfd150ea30ba0ee80b923dc042262c0bc79e21aefca27f2f0b5b6b8ac1e0 qemu-kvm-tools-0.12.1.2-2.503.el6_9.6.x86_64.rpm Source: 02c41c9fb0313b84b6cfe1a987253e5bcf12c55d563900adcb1041ee8253270a qemu-kvm-0.12.1.2-2.503.el6_9.6.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
Get the latest Linux and open source security news straight to your inbox.