Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-28999 http://linux.oracle.com/errata/ELSA-2026-28999.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: postgresql-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.x86_64.rpm postgresql-contrib-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.x86_64.rpm postgresql-docs-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.x86_64.rpm postgresql-plperl-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.x86_64.rpm postgresql-plpython3-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.x86_64.rpm postgresql-pltcl-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.x86_64.rpm postgresql-server-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.x86_64.rpm postgresql-server-devel-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.x86_64.rpm postgresql-static-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.x86_64.rpm postgresql-test-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.x86_64.rpm postgresql-test-rpm-macros-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.noarch.rpm postgresql-upgrade-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.x86_64.rpm postgresql-upgrade-devel-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.x86_64.rpm aarch64: postgresql-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.aarch64.rpm postgresql-contrib-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.aarch64.rpm postgresql-docs-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.aarch64.rpm postgresql-plperl-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.aarch64.rpm postgresql-plpython3-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.aarch64.rpm postgresql-pltcl-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.aarch64.rpm postgresql-server-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.aarch64.rpm postgresql-server-devel-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.aarch64.rpm postgresql-static-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.aarch64.rpm postgresql-test-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.aarch64.rpm postgresql-test-rpm-macros-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.noarch.rpm postgresql-upgrade-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.aarch64.rpm postgresql-upgrade-devel-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/postgresql-12.22-6.0.1.module+el8.10.0+90932+f6d78e3c.src.rpm Related CVEs: CVE-2026-6473 CVE-2026-6478 Description of changes: [12.22-6.0.1] - Add backport of CVE-2025-8714 [Orabug: 38667546] [12.22-6] - Fix CVE-2026-2004 CVE-2026-2005 CVE-2026-2006 [12.22-5] - Fix previous Backport [12.22-4] - Backport CVE-2025-8715 [12.22-3] - Fix backport for CVE-2025-1094 [12.22-2] - Backport fix for CVE-2025-1094 [12.22-1] - Update to 12.22 - Fixes: CVE-2024-10976 CVE-2024-10978 [12.20-1] - Update to 12.20 - Fix CVE-2024-7348 [12.18-1] - Update to 12.18 - Fix CVE-2024-0985 [12.17-1] - Update to version 12.17 Fix: CVE-2023-5868, CVE-2023-5869, CVE-2023-5870 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-25113 http://linux.oracle.com/errata/ELSA-2026-25113.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: aspnetcore-runtime-9.0-9.0.17-1.0.1.el8_10.x86_64.rpm aspnetcore-runtime-dbg-9.0-9.0.17-1.0.1.el8_10.x86_64.rpm aspnetcore-targeting-pack-9.0-9.0.17-1.0.1.el8_10.x86_64.rpm dotnet-apphost-pack-9.0-9.0.17-1.0.1.el8_10.x86_64.rpm dotnet-hostfxr-9.0-9.0.17-1.0.1.el8_10.x86_64.rpm dotnet-runtime-9.0-9.0.17-1.0.1.el8_10.x86_64.rpm dotnet-runtime-dbg-9.0-9.0.17-1.0.1.el8_10.x86_64.rpm dotnet-sdk-9.0-9.0.118-1.0.1.el8_10.x86_64.rpm dotnet-sdk-9.0-source-built-artifacts-9.0.118-1.0.1.el8_10.x86_64.rpm dotnet-sdk-aot-9.0-9.0.118-1.0.1.el8_10.x86_64.rpm dotnet-sdk-dbg-9.0-9.0.118-1.0.1.el8_10.x86_64.rpm dotnet-targeting-pack-9.0-9.0.17-1.0.1.el8_10.x86_64.rpm dotnet-templates-9.0-9.0.118-1.0.1.el8_10.x86_64.rpm netstandard-targeting-pack-2.1-9.0.118-1.0.1.el8_10.x86_64.rpm aarch64: aspnetcore-runtime-9.0-9.0.17-1.0.1.el8_10.aarch64.rpm aspnetcore-runtime-dbg-9.0-9.0.17-1.0.1.el8_10.aarch64.rpm aspnetcore-targeting-pack-9.0-9.0.17-1.0.1.el8_10.aarch64.rpm dotnet-apphost-pack-9.0-9.0.17-1.0.1.el8_10.aarch64.rpm dotnet-hostfxr-9.0-9.0.17-1.0.1.el8_10.aarch64.rpm dotnet-runtime-9.0-9.0.17-1.0.1.el8_10.aarch64.rpm dotnet-runtime-dbg-9.0-9.0.17-1.0.1.el8_10.aarch64.rpm dotnet-sdk-9.0-9.0.118-1.0.1.el8_10.aarch64.rpm dotnet-sdk-9.0-source-built-artifacts-9.0.118-1.0.1.el8_10.aarch64.rpm dotnet-sdk-aot-9.0-9.0.118-1.0.1.el8_10.aarch64.rpm dotnet-sdk-dbg-9.0-9.0.118-1.0.1.el8_10.aarch64.rpm dotnet-targeting-pack-9.0-9.0.17-1.0.1.el8_10.aarch64.rpm dotnet-templates-9.0-9.0.118-1.0.1.el8_10.aarch64.rpm netstandard-targeting-pack-2.1-9.0.118-1.0.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/dotnet9.0-9.0.118-1.0.1.el8_10.src.rpm Related CVEs: CVE-2026-45491 CVE-2026-45591 Description ofchanges: [9.0.118-1.0.1] - Add support for Oracle Linux [9.0.118-1] - Update to .NET SDK 9.0.118 and Runtime 9.0.17 - Resolves: RHEL-181550 [9.0.116-2] - Update to .NET SDK 9.0.116 and Runtime 9.0.15 - Resolves: RHEL-163389 [9.0.115-2] - Update to .NET SDK 9.0.115 and Runtime 9.0.14 - Resolves: RHEL-152941 [9.0.114-2] - Update to .NET SDK 9.0.114 and Runtime 9.0.13 - Resolves: RHEL-144969 [9.0.113-2] - Update to .NET SDK 9.0.113 and Runtime 9.0.12 - Resolves: RHEL-138644 [9.0.112-2] - Update to .NET SDK 9.0.112 and Runtime 9.0.11 - Resolves: RHEL-125742 [9.0.111-2] - Update to .NET SDK 9.0.111 and Runtime 9.0.10 - Resolves: RHEL-116856 [9.0.110-2] - Update to .NET SDK 9.0.110 and Runtime 9.0.9 - Resolves: RHEL-112264 [9.0.109-2] - Update to .NET SDK 9.0.109 and Runtime 9.0.8 - Resolves: RHEL-106726 _______________________________________________ El-errata mailing list
An update that solves two vulnerabilities can now be installed.. # Security update for openssh Announcement ID: SUSE-SU-2026:1876-1 Release Date: 2026-05-15T22:06:52Z Rating: important References: * bsc#1261427 * bsc#1261430 Cross-References: * CVE-2026-35385 * CVE-2026-35414 CVSS scores: * CVE-2026-35385 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-35385 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-35385 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-35385 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-35414 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-35414 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-35414 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-35414 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for openssh fixes the following issues * CVE-2026-35385: a file downloaded by scp may be installed setuid or setgid (bsc#1261427). * CVE-2026-35414: mishandling of authorized_keys principals option (bsc#1261430). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1876=1 * SUSELinux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1876=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-1876=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1876=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1876=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * openssh-common-9.6p1-150600.6.37.1 * openssh-askpass-gnome-debuginfo-9.6p1-150600.6.37.1 * openssh-clients-9.6p1-150600.6.37.1 * openssh-common-debuginfo-9.6p1-150600.6.37.1 * openssh-debuginfo-9.6p1-150600.6.37.1 * openssh-debugsource-9.6p1-150600.6.37.1 * openssh-helpers-debuginfo-9.6p1-150600.6.37.1 * openssh-cavs-9.6p1-150600.6.37.1 * openssh-server-9.6p1-150600.6.37.1 * openssh-askpass-gnome-9.6p1-150600.6.37.1 * openssh-server-config-disallow-rootlogin-9.6p1-150600.6.37.1 * openssh-cavs-debuginfo-9.6p1-150600.6.37.1 * openssh-9.6p1-150600.6.37.1 * openssh-clients-debuginfo-9.6p1-150600.6.37.1 * openssh-server-debuginfo-9.6p1-150600.6.37.1 * openssh-helpers-9.6p1-150600.6.37.1 * openssh-askpass-gnome-debugsource-9.6p1-150600.6.37.1 * openssh-fips-9.6p1-150600.6.37.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * openssh-common-9.6p1-150600.6.37.1 * openssh-askpass-gnome-debuginfo-9.6p1-150600.6.37.1 * openssh-clients-9.6p1-150600.6.37.1 * openssh-common-debuginfo-9.6p1-150600.6.37.1 * openssh-debuginfo-9.6p1-150600.6.37.1 * openssh-debugsource-9.6p1-150600.6.37.1 * openssh-helpers-debuginfo-9.6p1-150600.6.37.1 * openssh-server-9.6p1-150600.6.37.1 * openssh-server-config-disallow-rootlogin-9.6p1-150600.6.37.1 * openssh-askpass-gnome-9.6p1-150600.6.37.1 * openssh-clients-debuginfo-9.6p1-150600.6.37.1 * openssh-9.6p1-150600.6.37.1 * openssh-server-debuginfo-9.6p1-150600.6.37.1 * openssh-helpers-9.6p1-150600.6.37.1 * openssh-askpass-gnome-debugsource-9.6p1-150600.6.37.1 * openssh-fips-9.6p1-150600.6.37.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * openssh-common-9.6p1-150600.6.37.1 * openssh-server-config-disallow-rootlogin-9.6p1-150600.6.37.1 * openssh-clients-9.6p1-150600.6.37.1 * openssh-common-debuginfo-9.6p1-150600.6.37.1 * openssh-debuginfo-9.6p1-150600.6.37.1 * openssh-debugsource-9.6p1-150600.6.37.1 * openssh-helpers-debuginfo-9.6p1-150600.6.37.1 * openssh-server-9.6p1-150600.6.37.1 * openssh-9.6p1-150600.6.37.1 * openssh-server-debuginfo-9.6p1-150600.6.37.1 * openssh-clients-debuginfo-9.6p1-150600.6.37.1 * openssh-helpers-9.6p1-150600.6.37.1 * openssh-fips-9.6p1-150600.6.37.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * openssh-askpass-gnome-debuginfo-9.6p1-150600.6.37.1 * openssh-askpass-gnome-9.6p1-150600.6.37.1 * openssh-askpass-gnome-debugsource-9.6p1-150600.6.37.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * openssh-common-9.6p1-150600.6.37.1 * openssh-askpass-gnome-debuginfo-9.6p1-150600.6.37.1 * openssh-clients-9.6p1-150600.6.37.1 * openssh-common-debuginfo-9.6p1-150600.6.37.1 * openssh-debuginfo-9.6p1-150600.6.37.1 * openssh-debugsource-9.6p1-150600.6.37.1 * openssh-helpers-debuginfo-9.6p1-150600.6.37.1 * openssh-server-9.6p1-150600.6.37.1 * openssh-server-config-disallow-rootlogin-9.6p1-150600.6.37.1 * openssh-askpass-gnome-9.6p1-150600.6.37.1 * openssh-9.6p1-150600.6.37.1 * openssh-clients-debuginfo-9.6p1-150600.6.37.1 * openssh-server-debuginfo-9.6p1-150600.6.37.1 * openssh-helpers-9.6p1-150600.6.37.1 * openssh-askpass-gnome-debugsource-9.6p1-150600.6.37.1 * openssh-fips-9.6p1-150600.6.37.1 ## References: * https://www.suse.com/security/cve/CVE-2026-35385.html *https://www.suse.com/security/cve/CVE-2026-35414.html * https://bugzilla.suse.com/show_bug.cgi?id=1261427 * https://bugzilla.suse.com/show_bug.cgi?id=1261430 . A critical update for openssh resolves important issues related to file handling and security settings in SUSE systems.. openssh update, security patch, SUSE advisory, Linux security update. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 34 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:1611-1 Release Date: 2026-04-24T14:06:13Z Rating: important References: * bsc#1258396 * bsc#1259859 Cross-References: * CVE-2026-23191 * CVE-2026-23268 CVSS scores: * CVE-2026-23191 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23191 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23191 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23191 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23268 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23268 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23268 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.133 fixes various securityissues The following security issues were fixed: * CVE-2026-23191: ALSA: aloop: Fix racy access at PCM trigger (bsc#1258396). * CVE-2026-23268: apparmor: fix unprivileged local user can do privileged policy management (bsc#1259859). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-1611=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1612=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-1612=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-1614=1 SUSE-2026-1615=1 SUSE-2026-1616=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-1614=1 SUSE-SLE- Module-Live-Patching-15-SP5-2026-1615=1 SUSE-SLE-Module-Live- Patching-15-SP5-2026-1616=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_261-default-13-2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_46-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-5-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_46-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-5-150400.2.1 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_116-default-13-150500.2.1 * kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-13-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_31-debugsource-8-150500.2.1 *kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-5-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-8-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_34-debugsource-5-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-8-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_29-debugsource-13-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_116-default-13-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_31-debugsource-8-150500.2.1 * kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-13-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-5-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-8-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_34-debugsource-5-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-8-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x) * kernel-livepatch-SLE15-SP5_Update_29-debugsource-13-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23191.html * https://www.suse.com/security/cve/CVE-2026-23268.html * https://bugzilla.suse.com/show_bug.cgi?id=1258396 * https://bugzilla.suse.com/show_bug.cgi?id=1259859 . Install important kernel update for SUSE Linux to fix access issues. Security vulnerabilities addressed to protect integrity.. SUSE Linux, kernel security, important patch, access management, threat mitigation. . Severity: Important. LinuxSecurity.com Team
An update that solves three vulnerabilities can now be installed.. # Security update for erlang26 Announcement ID: SUSE-SU-2026:0023-1 Release Date: 2026-01-05T12:06:33Z Rating: moderate References: * bsc#1249469 * bsc#1249470 * bsc#1249472 Cross-References: * CVE-2025-48038 * CVE-2025-48039 * CVE-2025-48040 CVSS scores: * CVE-2025-48038 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-48038 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-48038 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-48039 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-48039 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-48039 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-48040 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-48040 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-48040 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux EnterpriseServer 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for erlang26 fixes the following issues: * CVE-2025-48040: Excessive resource consumption (bsc#1249472) * CVE-2025-48039: Excessive use of system resources (bsc#1249469) * CVE-2025-48038: Excessive use of system resources (bsc#1249470) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-23=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-23=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-23=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * erlang26-epmd-debuginfo-26.2.1-150300.7.22.1 * erlang26-wx-26.2.1-150300.7.22.1 * erlang26-dialyzer-26.2.1-150300.7.22.1 * erlang26-reltool-26.2.1-150300.7.22.1 * erlang26-observer-src-26.2.1-150300.7.22.1 * erlang26-jinterface-src-26.2.1-150300.7.22.1 * erlang26-debugger-src-26.2.1-150300.7.22.1 * erlang26-epmd-26.2.1-150300.7.22.1 * erlang26-debugger-26.2.1-150300.7.22.1 * erlang26-debugsource-26.2.1-150300.7.22.1 * erlang26-dialyzer-src-26.2.1-150300.7.22.1 * erlang26-observer-26.2.1-150300.7.22.1 * erlang26-dialyzer-debuginfo-26.2.1-150300.7.22.1 * erlang26-debuginfo-26.2.1-150300.7.22.1 * erlang26-reltool-src-26.2.1-150300.7.22.1 * erlang26-wx-debuginfo-26.2.1-150300.7.22.1 * erlang26-et-26.2.1-150300.7.22.1 * erlang26-wx-src-26.2.1-150300.7.22.1 * erlang26-diameter-src-26.2.1-150300.7.22.1 * erlang26-et-src-26.2.1-150300.7.22.1 * erlang26-26.2.1-150300.7.22.1 * erlang26-diameter-26.2.1-150300.7.22.1 * erlang26-jinterface-26.2.1-150300.7.22.1 *erlang26-doc-26.2.1-150300.7.22.1 * erlang26-src-26.2.1-150300.7.22.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * erlang26-epmd-debuginfo-26.2.1-150300.7.22.1 * erlang26-26.2.1-150300.7.22.1 * erlang26-debuginfo-26.2.1-150300.7.22.1 * erlang26-epmd-26.2.1-150300.7.22.1 * erlang26-debugsource-26.2.1-150300.7.22.1 * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * erlang26-epmd-debuginfo-26.2.1-150300.7.22.1 * erlang26-wx-26.2.1-150300.7.22.1 * erlang26-dialyzer-26.2.1-150300.7.22.1 * erlang26-reltool-26.2.1-150300.7.22.1 * erlang26-observer-src-26.2.1-150300.7.22.1 * erlang26-jinterface-src-26.2.1-150300.7.22.1 * erlang26-debugger-src-26.2.1-150300.7.22.1 * erlang26-epmd-26.2.1-150300.7.22.1 * erlang26-debugger-26.2.1-150300.7.22.1 * erlang26-debugsource-26.2.1-150300.7.22.1 * erlang26-dialyzer-src-26.2.1-150300.7.22.1 * erlang26-observer-26.2.1-150300.7.22.1 * erlang26-dialyzer-debuginfo-26.2.1-150300.7.22.1 * erlang26-debuginfo-26.2.1-150300.7.22.1 * erlang26-reltool-src-26.2.1-150300.7.22.1 * erlang26-wx-debuginfo-26.2.1-150300.7.22.1 * erlang26-et-26.2.1-150300.7.22.1 * erlang26-wx-src-26.2.1-150300.7.22.1 * erlang26-diameter-src-26.2.1-150300.7.22.1 * erlang26-et-src-26.2.1-150300.7.22.1 * erlang26-26.2.1-150300.7.22.1 * erlang26-diameter-26.2.1-150300.7.22.1 * erlang26-jinterface-26.2.1-150300.7.22.1 * erlang26-doc-26.2.1-150300.7.22.1 * erlang26-src-26.2.1-150300.7.22.1 ## References: * https://www.suse.com/security/cve/CVE-2025-48038.html * https://www.suse.com/security/cve/CVE-2025-48039.html * https://www.suse.com/security/cve/CVE-2025-48040.html * https://bugzilla.suse.com/show_bug.cgi?id=1249469 * https://bugzilla.suse.com/show_bug.cgi?id=1249470 * https://bugzilla.suse.com/show_bug.cgi?id=1249472 . Security update for erlang26 addresses three issues to optimize system resource usage on openSUSE platforms.. erlang26 securityupdate, openSUSE resource issue, moderate vulnerability patch. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-10631 http://linux.oracle.com/errata/ELSA-2025-10631.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: gnome-remote-desktop-40.0-11.el9_6.x86_64.rpm aarch64: gnome-remote-desktop-40.0-11.el9_6.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/gnome-remote-desktop-40.0-11.el9_6.src.rpm Related CVEs: CVE-2025-5024 Description of changes: [40.0-11] - Backport connection throttling Resolves: RHEL-92795 _______________________________________________ El-errata mailing list
An update that solves 12 vulnerabilities can now be installed.. # SDL-1.2.15-1.1 on GA media Announcement ID: openSUSE-SU-2025:15205-1 Rating: moderate Cross-References: * CVE-2019-13616 * CVE-2019-7572 * CVE-2019-7573 * CVE-2019-7574 * CVE-2019-7575 * CVE-2019-7577 * CVE-2019-7578 * CVE-2019-7635 * CVE-2019-7636 * CVE-2019-7637 * CVE-2019-7638 * CVE-2021-33657 CVSS scores: * CVE-2019-13616 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2019-7572 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2019-7573 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2019-7574 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2019-7575 ( SUSE ): 5.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2019-7577 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2019-7578 ( SUSE ): 5.1 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2019-7635 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2019-7636 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2019-7637 ( SUSE ): 5.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2019-7638 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2021-33657 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Tumbleweed An update that solves 12 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the SDL-1.2.15-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * SDL 1.2.15-1.1 ## References: * https://www.suse.com/security/cve/CVE-2019-13616.html * https://www.suse.com/security/cve/CVE-2019-7572.html * https://www.suse.com/security/cve/CVE-2019-7573.html * https://www.suse.com/security/cve/CVE-2019-7574.html * https://www.suse.com/security/cve/CVE-2019-7575.html * https://www.suse.com/security/cve/CVE-2019-7577.html *https://www.suse.com/security/cve/CVE-2019-7578.html * https://www.suse.com/security/cve/CVE-2019-7635.html * https://www.suse.com/security/cve/CVE-2019-7636.html * https://www.suse.com/security/cve/CVE-2019-7637.html * https://www.suse.com/security/cve/CVE-2019-7638.html * https://www.suse.com/security/cve/CVE-2021-33657.html . An update for SDL-1.2.15-1.2 addresses several security flaws impacting Fedora Rawhide.. openSUSE, SDL, security issues, software update, threat management. . LinuxSecurity.com Team
An update that solves six vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 32 for SLE 15 SP4) Announcement ID: SUSE-SU-2025:02111-1 Release Date: 2025-06-25T16:03:47Z Rating: important References: * bsc#1232908 * bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062 * bsc#1235231 Cross-References: * CVE-2024-50125 * CVE-2024-50127 * CVE-2024-50279 * CVE-2024-50301 * CVE-2024-56601 * CVE-2024-56605 CVSS scores: * CVE-2024-50125 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-50125 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50125 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50125 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50127 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-50127 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50127 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50127 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50279 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2024-50279 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-50301 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-50301 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-56601 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56601 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56601 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56601 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56605 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56605 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56605 ( NVD ): 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56605 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves six vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.14.21-150400_24_136 fixes several issues. The following security issues were fixed: * CVE-2024-56601: net: inet: do not leave a dangling sk pointer in inet_create() (bsc#1235231). * CVE-2024-50279: dm cache: fix out-of-bounds access to the dirty bitset when resizing (bsc#1233708). * CVE-2024-50301: security/keys: fix slab-out-of-bounds in key_task_permission (bsc#1233680). * CVE-2024-50127: net: sched: fix use-after-free in taprio_change() (bsc#1232908). * CVE-2024-56605: Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create() (bsc#1235062). * CVE-2024-50125: Bluetooth: SCO: Fix UAF on sco_sock_timeout (bsc#1232929). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-2111=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2025-2111=1 ## Package List: * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_136-default-debuginfo-10-150400.2.1 * kernel-livepatch-5_14_21-150400_24_136-default-10-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_32-debugsource-10-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_136-default-debuginfo-10-150400.2.1 * kernel-livepatch-5_14_21-150400_24_136-default-10-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_32-debugsource-10-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-50125.html * https://www.suse.com/security/cve/CVE-2024-50127.html * https://www.suse.com/security/cve/CVE-2024-50279.html * https://www.suse.com/security/cve/CVE-2024-50301.html * https://www.suse.com/security/cve/CVE-2024-56601.html * https://www.suse.com/security/cve/CVE-2024-56605.html * https://bugzilla.suse.com/show_bug.cgi?id=1232908 * https://bugzilla.suse.com/show_bug.cgi?id=1232929 * https://bugzilla.suse.com/show_bug.cgi?id=1233680 * https://bugzilla.suse.com/show_bug.cgi?id=1233708 * https://bugzilla.suse.com/show_bug.cgi?id=1235062 * https://bugzilla.suse.com/show_bug.cgi?id=1235231 . Important security patch for the Fedora kernel to mitigate several risks, vital for maintaining system safety.. openSUSE Kernel Patch, Linux Kernel Security, System Threat Management, Suse Updates. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.