Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
89

Fedora 44 curl Security Advisory 2026-f13d888b0f Multiple CVEs Listed

Fix bad reuse of HTTP Negotiate connection (CVE-2026-1965) Fix token leak with redirect and netrc (CVE-2026-3783) Fix wrong proxy connection reuse with credentials (CVE-2026-3784) Fix use after free in SMB connection reuse (CVE-2026-3805) Fix Could not find digest algorithm UNDEF (NID 0). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-f13d888b0f 2026-04-25 01:21:36.172613+00:00 -------------------------------------------------------------------------------- Name : curl Product : Fedora 44 Version : 8.18.0 Release : 6.fc44 URL : https://curl.se/ Summary : A utility for getting files from remote servers (FTP, HTTP, and others) Description : curl is a command line tool for transferring data with URL syntax, supporting FTP, FTPS, HTTP, HTTPS, SCP, SFTP, TFTP, TELNET, DICT, LDAP, LDAPS, FILE, IMAP, SMTP, POP3 and RTSP. curl supports SSL certificates, HTTP POST, HTTP PUT, FTP uploading, HTTP form based upload, proxies, cookies, user+password authentication (Basic, Digest, NTLM, Negotiate, kerberos...), file transfer resume, proxy tunneling and a busload of other useful tricks. -------------------------------------------------------------------------------- Update Information: Fix bad reuse of HTTP Negotiate connection (CVE-2026-1965) Fix token leak with redirect and netrc (CVE-2026-3783) Fix wrong proxy connection reuse with credentials (CVE-2026-3784) Fix use after free in SMB connection reuse (CVE-2026-3805) Fix Could not find digest algorithm UNDEF (NID 0) -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 10 2026 Jan Macku - 8.18.0-6 - Fix bad reuse of HTTP Negotiate connection (CVE-2026-1965) - Fix token leak with redirect and netrc (CVE-2026-3783) - Fix wrong proxy connection reuse with credentials (CVE-2026-3784) - Fix use after free in SMB connection reuse (CVE-2026-3805) * Mon Mar 30 2026 Jan Macku -8.18.0-5 - Fix `Could not find digest algorithm UNDEF (NID 0)` (#2438170) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2438170 - OBJ_find_sigid_algs() returns NID_undef for ML-DSA certificate https://bugzilla.redhat.com/show_bug.cgi?id=2438170 [ 2 ] Bug #2457259 - CVE-2026-3805 curl: curl: Arbitrary code execution or Denial of Service via use-after-free in SMB request handling [fedora-44] https://bugzilla.redhat.com/show_bug.cgi?id=2457259 [ 3 ] Bug #2457261 - CVE-2026-1965 curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication [fedora-44] https://bugzilla.redhat.com/show_bug.cgi?id=2457261 [ 4 ] Bug #2457262 - CVE-2026-3784 curl: curl: Unauthorized access due to improper HTTP proxy connection reuse [fedora-44] https://bugzilla.redhat.com/show_bug.cgi?id=2457262 [ 5 ] Bug #2457263 - CVE-2026-3783 curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect [fedora-44] https://bugzilla.redhat.com/show_bug.cgi?id=2457263 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-f13d888b0f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ ListGuidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . This security advisory highlights potential risks in Fedora 44's curl, including major authentication and connection issues. Immediate action recommended.. Fedora curl update security issues information denial of service. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 25, 2026 Important Fedora
100

SUSE Linux Micro 6.1 curl Important Security Issue 2026-20668-1

An update that solves four vulnerabilities can now be installed.. # Security update for curl Announcement ID: SUSE-SU-2026:20668-1 Release Date: 2026-03-12T10:27:47Z Rating: important References: * bsc#1259362 * bsc#1259363 * bsc#1259364 * bsc#1259365 Cross-References: * CVE-2026-1965 * CVE-2026-3783 * CVE-2026-3784 * CVE-2026-3805 CVSS scores: * CVE-2026-1965 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2026-1965 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-1965 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3783 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-3783 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-3783 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-3784 ( SUSE ): 1.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-3784 ( SUSE ): 4.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N * CVE-2026-3784 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-3805 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-3805 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-3805 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues: * CVE-2026-1965: bad reuse of HTTP Negotiate connection (bsc#1259362). * CVE-2026-3783: token leak with redirect and netrc (bsc#1259363). * CVE-2026-3784: wrong proxy connection reuse with credentials (bsc#1259364). * CVE-2026-3805: use after free in SMB connection reuse (bsc#1259365). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-440=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * curl-debuginfo-8.14.1-slfo.1.1_6.1 * curl-debugsource-8.14.1-slfo.1.1_6.1 * libcurl4-8.14.1-slfo.1.1_6.1 * curl-8.14.1-slfo.1.1_6.1 * libcurl4-debuginfo-8.14.1-slfo.1.1_6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1965.html * https://www.suse.com/security/cve/CVE-2026-3783.html * https://www.suse.com/security/cve/CVE-2026-3784.html * https://www.suse.com/security/cve/CVE-2026-3805.html * https://bugzilla.suse.com/show_bug.cgi?id=1259362 * https://bugzilla.suse.com/show_bug.cgi?id=1259363 * https://bugzilla.suse.com/show_bug.cgi?id=1259364 * https://bugzilla.suse.com/show_bug.cgi?id=1259365 . Four significant issues solved in curl security update for SUSE Micro. Ensure systems are secured against these vulnerabilities.. curl security update,suse linux micro,important security advisory,CVE-2026-1965. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 18, 2026 Important SuSE
100

SUSE 12 SP5 Curl Crucial Security Concerns Resolved Issue 2026-0921-1

An update that solves three vulnerabilities can now be installed.. # Security update for curl Announcement ID: SUSE-SU-2026:0921-1 Release Date: 2026-03-18T08:52:08Z Rating: important References: * bsc#1259362 * bsc#1259363 * bsc#1259364 Cross-References: * CVE-2026-1965 * CVE-2026-3783 * CVE-2026-3784 CVSS scores: * CVE-2026-1965 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2026-1965 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-1965 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3783 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-3783 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-3783 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-3784 ( SUSE ): 1.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-3784 ( SUSE ): 4.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N * CVE-2026-3784 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues: * CVE-2026-1965: bad reuse of HTTP Negotiate connection (bsc#1259362). * CVE-2026-3783: token leak with redirect and netrc (bsc#1259363). * CVE-2026-3784: wrong proxy connection reuse with credentials (bsc#1259364). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -tpatch SUSE-SLE-SERVER-12-SP5-LTSS-2026-921=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-921=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * curl-debugsource-8.0.1-11.120.1 * curl-debuginfo-8.0.1-11.120.1 * libcurl-devel-8.0.1-11.120.1 * libcurl4-8.0.1-11.120.1 * curl-8.0.1-11.120.1 * libcurl4-debuginfo-8.0.1-11.120.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libcurl4-32bit-8.0.1-11.120.1 * libcurl4-debuginfo-32bit-8.0.1-11.120.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libcurl4-debuginfo-32bit-8.0.1-11.120.1 * curl-debugsource-8.0.1-11.120.1 * libcurl4-32bit-8.0.1-11.120.1 * curl-debuginfo-8.0.1-11.120.1 * libcurl-devel-8.0.1-11.120.1 * libcurl4-8.0.1-11.120.1 * curl-8.0.1-11.120.1 * libcurl4-debuginfo-8.0.1-11.120.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1965.html * https://www.suse.com/security/cve/CVE-2026-3783.html * https://www.suse.com/security/cve/CVE-2026-3784.html * https://bugzilla.suse.com/show_bug.cgi?id=1259362 * https://bugzilla.suse.com/show_bug.cgi?id=1259363 * https://bugzilla.suse.com/show_bug.cgi?id=1259364 . An important update for SUSE Linux curl addresses three significant issues, enhancing system security against exploits.. SUSE Linux,curl update,security patch,important updates,curl vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 18, 2026 Important SuSE
202

openSUSE 16.2 wget Security Update for Access Management Vulnerability

An update that solves four vulnerabilities can now be installed.. # Security update for curl Announcement ID: SUSE-SU-2026:0885-1 Release Date: 2026-03-12T14:50:21Z Rating: important References: * bsc#1259362 * bsc#1259363 * bsc#1259364 * bsc#1259365 Cross-References: * CVE-2026-1965 * CVE-2026-3783 * CVE-2026-3784 * CVE-2026-3805 CVSS scores: * CVE-2026-1965 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2026-1965 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-1965 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3783 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-3783 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-3783 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-3784 ( SUSE ): 1.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-3784 ( SUSE ): 4.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N * CVE-2026-3784 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-3805 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-3805 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-3805 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves four vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues: * CVE-2026-1965: bad reuse of HTTP Negotiate connection (bsc#1259362). * CVE-2026-3783: token leak with redirect and netrc (bsc#1259363). * CVE-2026-3784: wrong proxy connection reuse with credentials (bsc#1259364). * CVE-2026-3805: use after free in SMB connection reuse (bsc#1259365). ## PatchInstructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-885=1 openSUSE-SLE-15.6-2026-885=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-885=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-885=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * curl-debuginfo-8.14.1-150600.4.40.1 * curl-8.14.1-150600.4.40.1 * curl-mini-debugsource-8.14.1-150600.4.40.1 * libcurl-mini4-8.14.1-150600.4.40.1 * libcurl-mini4-debuginfo-8.14.1-150600.4.40.1 * curl-debugsource-8.14.1-150600.4.40.1 * libcurl4-debuginfo-8.14.1-150600.4.40.1 * libcurl4-8.14.1-150600.4.40.1 * libcurl-devel-8.14.1-150600.4.40.1 * openSUSE Leap 15.6 (noarch) * curl-zsh-completion-8.14.1-150600.4.40.1 * curl-fish-completion-8.14.1-150600.4.40.1 * libcurl-devel-doc-8.14.1-150600.4.40.1 * openSUSE Leap 15.6 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150600.4.40.1 * libcurl4-32bit-8.14.1-150600.4.40.1 * libcurl-devel-32bit-8.14.1-150600.4.40.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libcurl4-64bit-8.14.1-150600.4.40.1 * libcurl-devel-64bit-8.14.1-150600.4.40.1 * libcurl4-64bit-debuginfo-8.14.1-150600.4.40.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * curl-debuginfo-8.14.1-150600.4.40.1 * curl-8.14.1-150600.4.40.1 * curl-debugsource-8.14.1-150600.4.40.1 * libcurl4-debuginfo-8.14.1-150600.4.40.1 * libcurl4-8.14.1-150600.4.40.1 * libcurl-devel-8.14.1-150600.4.40.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150600.4.40.1 * libcurl4-32bit-8.14.1-150600.4.40.1 * SUSE Linux Enterprise Server for SAP Applications 15SP6 (ppc64le x86_64) * curl-debuginfo-8.14.1-150600.4.40.1 * curl-8.14.1-150600.4.40.1 * curl-debugsource-8.14.1-150600.4.40.1 * libcurl4-debuginfo-8.14.1-150600.4.40.1 * libcurl4-8.14.1-150600.4.40.1 * libcurl-devel-8.14.1-150600.4.40.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150600.4.40.1 * libcurl4-32bit-8.14.1-150600.4.40.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1965.html * https://www.suse.com/security/cve/CVE-2026-3783.html * https://www.suse.com/security/cve/CVE-2026-3784.html * https://www.suse.com/security/cve/CVE-2026-3805.html * https://bugzilla.suse.com/show_bug.cgi?id=1259362 * https://bugzilla.suse.com/show_bug.cgi?id=1259363 * https://bugzilla.suse.com/show_bug.cgi?id=1259364 * https://bugzilla.suse.com/show_bug.cgi?id=1259365 . Resolve important curl vulnerabilities with the latest openSUSE security update for enhanced system protection.. SUSE Linux, curl, security update, patch management, openSUSE. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 12, 2026 Important OpenSUSE
100

SUSE 2026-0879-1 curl Important Token Leak Security Update

An update that solves four vulnerabilities can now be installed.. # Security update for curl Announcement ID: SUSE-SU-2026:0879-1 Release Date: 2026-03-12T10:04:21Z Rating: important References: * bsc#1259362 * bsc#1259363 * bsc#1259364 * bsc#1259365 Cross-References: * CVE-2026-1965 * CVE-2026-3783 * CVE-2026-3784 * CVE-2026-3805 CVSS scores: * CVE-2026-1965 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2026-1965 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-1965 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3783 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-3783 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-3783 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-3784 ( SUSE ): 1.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-3784 ( SUSE ): 4.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N * CVE-2026-3784 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-3805 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-3805 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-3805 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves four vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues: * CVE-2026-1965: bad reuse of HTTP Negotiate connection (bsc#1259362). * CVE-2026-3783: token leak with redirect and netrc (bsc#1259363). * CVE-2026-3784: wrong proxy connection reuse with credentials (bsc#1259364). * CVE-2026-3805: use after free in SMB connection reuse (bsc#1259365). ## Patch Instructions: To install this SUSE update use the SUSE recommended installationmethods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-879=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-879=1 ## Package List: * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libcurl4-debuginfo-8.14.1-150200.4.103.1 * curl-debugsource-8.14.1-150200.4.103.1 * curl-8.14.1-150200.4.103.1 * curl-debuginfo-8.14.1-150200.4.103.1 * libcurl4-8.14.1-150200.4.103.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libcurl4-debuginfo-8.14.1-150200.4.103.1 * curl-debugsource-8.14.1-150200.4.103.1 * curl-8.14.1-150200.4.103.1 * curl-debuginfo-8.14.1-150200.4.103.1 * libcurl4-8.14.1-150200.4.103.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1965.html * https://www.suse.com/security/cve/CVE-2026-3783.html * https://www.suse.com/security/cve/CVE-2026-3784.html * https://www.suse.com/security/cve/CVE-2026-3805.html * https://bugzilla.suse.com/show_bug.cgi?id=1259362 * https://bugzilla.suse.com/show_bug.cgi?id=1259363 * https://bugzilla.suse.com/show_bug.cgi?id=1259364 * https://bugzilla.suse.com/show_bug.cgi?id=1259365 . This advisory details an important update for SUSE curl, addressing several security issues including token leaks.. SUSE curl security update important patch vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 12, 2026 Important SuSE
203

Mageia 9: curl Important Security Issues OpenSSL Bypass MGASA-2026-0003

MGASA-2026-0003 - Updated curl packages fix security vulnerabilities. MGASA-2026-0003 - Updated curl packages fix security vulnerabilities Publication date: 10 Jan 2026 URL: https://advisories.mageia.org/MGASA-2026-0003.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-13034, CVE-2025-14017, CVE-2025-14524, CVE-2025-14819, CVE-2025-15079, CVE-2025-15224 Description: curl is susceptible to a number of low severity security vulnerabilities: CVE-2025-14524: bearer token leak on cross-protocol redirect CVE-2025-14819: OpenSSL partial chain store policy bypass CVE-2025-15079: libssh knownhosts file vulnerability CVE-2025-15224: libssh key passphrase bypass vulnerability This release fixes these issues. References: - https://bugs.mageia.org/show_bug.cgi?id=34944 - https://curl.se/docs/vuln-7.88.1.html - https://www.cve.org/CVERecord?id=CVE-2025-13034 - https://www.cve.org/CVERecord?id=CVE-2025-14017 - https://www.cve.org/CVERecord?id=CVE-2025-14524 - https://www.cve.org/CVERecord?id=CVE-2025-14819 - https://www.cve.org/CVERecord?id=CVE-2025-15079 - https://www.cve.org/CVERecord?id=CVE-2025-15224 SRPMS: - 9/core/curl-7.88.1-4.9.mga9 . Updated curl packages in Mageia fix multiple important issues, including token leak and OpenSSL bypass vulnerabilities.. Mageia curl vulnerabilities security patch fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 10, 2026 Important Mageia
99

Slackware 15.0: Important curl Security Fix for Token Leak DoS Issue

New curl packages are available for Slackware 15.0 and -current to fix security issues.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] curl (SSA:2026-007-01) New curl packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/curl-8.17.0-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: OpenSSL partial chain store policy bypass. bearer token leak on cross-protocol redirect. No QUIC certificate pinning with GnuTLS. For more information, see: https://curl.se/docs/CVE-2025-14819.html https://curl.se/docs/CVE-2025-14524.html https://curl.se/docs/CVE-2025-13034.html https://www.cve.org/CVERecord?id=CVE-2025-14819 https://www.cve.org/CVERecord?id=CVE-2025-14524 https://www.cve.org/CVERecord?id=CVE-2025-13034 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/curl-8.17.0-i586-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/curl-8.17.0-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/curl-8.18.0-i686-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/curl-8.18.0-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: 34bfec34c4d3bae3dd37c4f235bfd8a5 curl-8.17.0-i586-1_slack15.0.txz Slackware x86_64 15.0 package: f128a9bb3f4ecfa684711f8f9c6690ce curl-8.17.0-x86_64-1_slack15.0.txz Slackware -current package: bc565dd7e48bd30903dd02572905280a n/curl-8.18.0-i686-1.txz Slackware x86_64 -current package: ed5939e5b68c87de36bb4cce2f0a7394 n/curl-8.18.0-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg curl-8.17.0-i586-1_slack15.0.txz +-----+ . Curl packages for Slackware 15.0 and -current are updated to address critical security issues.. curl security fixes, Slackware updates, package vulnerability management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 07, 2026 Important Slackware
98

Red Hat OpenShift 4.7.0 Moderate Advisory: Multiple Security Issues

Updated images which include numerous security fixes, bug fixes, and enhancements are now available for Red Hat OpenShift Container Storage 4.7.0 on Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenShift Container Storage 4.7.0 security, bug fix, and enhancement update Advisory ID: RHSA-2021:2041-01 Product: Red Hat OpenShift Container Storage Advisory URL: https://access.redhat.com/errata/RHSA-2021:2041 Issue date: 2021-05-19 CVE Names: CVE-2020-7608 CVE-2020-7774 CVE-2020-8565 CVE-2020-25678 CVE-2020-26160 CVE-2020-26289 CVE-2020-28362 CVE-2021-3114 CVE-2021-3139 CVE-2021-3449 CVE-2021-3450 CVE-2021-3528 CVE-2021-20305 ==================================================================== 1. Summary: Updated images which include numerous security fixes, bug fixes, and enhancements are now available for Red Hat OpenShift Container Storage 4.7.0 on Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Container Storage is software-defined storage integrated with and optimized for the Red Hat OpenShift Container Platform. Red Hat OpenShift Container Storage is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Container Storage provisions a multicloud data management service with an S3 compatible API. Security Fix(es): * nodejs-y18n:prototype pollution vulnerability (CVE-2020-7774) * kubernetes: Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel > = 9 (CVE-2020-8565) * jwt-go: access restriction bypass vulnerability (CVE-2020-26160) * nodejs-date-and-time: ReDoS in parsing via date.compile (CVE-2020-26289) * golang: math/big: panic during recursive division of very large numbers(CVE-2020-28362) * golang: crypto/elliptic: incorrect operations on the P-224 curve (CVE-2021-3114) * NooBaa: noobaa-operator leaking RPC AuthToken into log files (CVE-2021-3528) * nodejs-yargs-parser: prototype pollution vulnerability (CVE-2020-7608) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): This update includes various bug fixes and enhancements. Space precludes documenting all of these changes in this advisory. Users are directed to the Red Hat OpenShift Container Storage Release Notes for information on the most significant of these changes: torage/4.7/html-single/4.7_release_notes/index All Red Hat OpenShift Container Storage users are advised to upgrade to these updated images. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 1803849 - [RFE] Include per volume encryption with Vault integration in RHCS 4.1 1814681 - [RFE] use topologySpreadConstraints to evenly spread OSDs across hosts 1840004 - CVE-2020-7608 nodejs-yargs-parser: prototype pollution vulnerability 1850089 - OBC CRD is outdated and leads to missing columns in get queries 1860594 - Toolbox pod should have toleration for OCS tainted nodes 1861104 - OCS podDisruptionBudget prevents successful OCP upgrades 1861878 - [RFE] use appropriate PDB values for OSD 1866301 - [RHOCS UsabilityStudy][Installation] “Create storage cluster” should be a part of the installation flow or need to be emphasized as a crucial step. 1869406 - must-gather should include historical pod logs 1872730 - [RFE][External mode] Re-configure noobaa to use the updated RGW endpoint from the RHCS cluster 1874367 - "Create Backing Store" page doesn't allow to select already defined k8s secret as target bucket credentials when Google Cloud Storage is selected as a provider 1883371 - CVE-2020-26160 jwt-go: access restriction bypass vulnerability 1886112 - log message flood with Reconciling StorageCluster","Request.Namespace":"openshift-storage","Request.Name":"ocs-storagecluster" 1886416 - Uninstall 4.6: ocs-operator logging regarding noobaa-core PVC needs change 1886638 - CVE-2020-8565 kubernetes: Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel > = 9 1888839 - Create public route for ceph-rgw service 1892622 - [GSS] Noobaa management dashboard reporting High number of issues when the cluster is in healthy state 1893611 - Skip ceph commands collection attempt if must-gather helper pod is not created 1893613 - must-gather tries to collect ceph commands in external mode when storagecluster already deleted 1893619 - OCS must-gather: Inspect errors for cephobjectoreUser and few ceph commandd when storage cluster does not exist 1894412 - [RFE][External] RGW metrics should be made available even if anything else except 9283 is provided as the monitoring-endpoint-port 1896338 - OCS upgrade from 4.6 to 4.7 build failed 1897246 - OCS - ceph historical logs collection 1897635 - CVE-2020-28362 golang: math/big: panic during recursive division of very large numbers1898509 - [Tracker][RHV #1899565] Deployment on RHV/oVirt storage class ovirt-csi-sc failing 1898680 - CVE-2020-7774 nodejs-y18n: prototype pollution vulnerability 1898808 - Rook-Ceph crash collector pod should not run on non-ocs node 1900711 - [RFE] Alerting for Namespace buckets and resources 1900722 - Failed to init upgrade process onnoobaa-core-0 1900749 - Namespace Resource reported as Healthy when target bucket deleted 1900760 - RPC call for Namespace resource creation allows invalid target bucket names 1901134 - OCS - ceph historical logs collection 1902192 - [RFE][External] RGW metrics should be made available even if anything else except 9283 is provided as the monitoring-endpoint-port 1902685 - Too strict Content-Length header check refuses valid upload requests 1902711 - Tracker for Bug #1903078 Deleting VolumeSnapshotClass makes VolumeSnapshot not Ready 1903973 - [Azure][ROKS] Set SSD tuning (tuneFastDeviceClass) as default for OSD devices in Azure/ROKS platform 1903975 - Add "ceph df detail" for ocs must-gather to enable support to debug compression 1904302 - [GSS] ceph_daemon label includes references to a replaced OSD that cause a prometheus ruleset to fail 1904929 - [GSS][RFE]Reduce debug level for logs of Nooba Endpoint pod 1907318 - Unable to deploy & upgrade to ocs 4.7 - missing postgres image reference 1908414 - [GSS][VMWare][ROKS] rgw pods are not showing up in OCS 4.5 - due to pg_limit issue 1908678 - ocs-osd-removal job failed with "Invalid value" error when using multiple ids 1909268 - OCS 4.7 UI install -All OCS operator pods respin after storagecluster creation 1909488 - [NooBaa CLI] CLI status command looks for wrong DB PV name 1909745 - pv-pool backing store name restriction should be at 43 characters1910705 - OBCs are stuck in a Pending state 1911131 - Bucket stats in the NB dashboard are incorrect 1911266 - Backingstore phase is ready, modecode is INITIALIZING 1911627 - CVE-2020-26289 nodejs-date-and-time: ReDoS in parsing via date.compile 1911789 - Data deduplication does not work properly 1912421 - [RFE] noobaa cli allow the creation of BackingStores with already existing secrets 1912894 - OCS storagecluster is Progressing state and some noobaa pods missing with latest 4.7 build -4.7.0-223.ci and storagecluster reflected as 4.8.0 instead of 4.7.0 1913149 - make must-gather backward compatibility for version = 3zones 1939617 - [Arbiter] Mons cannot be failed over in stretch mode 1940440 - noobaa migration pod is deleted on failure and logs are not available for inspection 1940476 - Backingstore deletion hangs 1940957 - Deletion of Rejected NamespaceStore is stuck even when target bucket and bucketclass are deleted 1941647 - OCS deployment fails when no backend path is specified for cluster wide encryption using KMS 1941977 - rook-ceph-osd-X gets stuck in initcontainer expand-encrypted-bluefs 1942344 - No permissions in /etc/passwd leads to fail noobaa-operaor 1942350 - No permissions in /etc/passwd leads to fail noobaa-operaor 1942519 - MCG should not use KMS to store encryption keys if cluster wide encryption is not enabled using KMS 1943275 - OSD pods re-spun after "add capacity" on cluster with KMS 1943596 - [Tracker for BZ #1944611][Arbiter] When Performed zone(zone=a) Power off and Power On, 3 mon pod(zone=b,c) goes in CLBO after node Power off and 2 Osd(zone=a) goes in CLBO after node Power on 1944980 - Noobaa deployment fails when no KMS backend path is provided during storagecluster creation 1946592 - [Arbiter] When both the rgw pod hosting nodes are down, the rgw service is unavailable 1946837 - OCS 4.7 Arbiter Mode Cluster becomes stuck when entire zone is shutdown 1955328 - Upgrade of noobaa DB failed when upgrading OCS 4.6 to 4.7 1955601 - CVE-2021-3528 NooBaa: noobaa-operator leaking RPC AuthToken into log files 1957187 - Update to RHCS 4.2z1 Ceph container image at OCS 4.7.0 1957639 - Noobaa migrate job is failing when upgrading OCS 4.6.4 to 4.7 on FIPS environment 5.References: https://access.redhat.com/security/cve/CVE-2020-7608 https://access.redhat.com/security/cve/CVE-2020-7774 https://access.redhat.com/security/cve/CVE-2020-8565 https://access.redhat.com/security/cve/CVE-2020-25678 https://access.redhat.com/security/cve/CVE-2020-26160 https://access.redhat.com/security/cve/CVE-2020-26289 https://access.redhat.com/security/cve/CVE-2020-28362 https://access.redhat.com/security/cve/CVE-2021-3114 https://access.redhat.com/security/cve/CVE-2021-3139 https://access.redhat.com/security/cve/CVE-2021-3449 https://access.redhat.com/security/cve/CVE-2021-3450 https://access.redhat.com/security/cve/CVE-2021-3528 https://access.redhat.com/security/cve/CVE-2021-20305 https://access.redhat.com/security/updates/classification/#moderate 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYKTXntzjgjWX9erEAQhWpRAApeS59vyJLmaSJLski/0+eXbsKF6T3p2J FTz7NRK3Jlvw1LAwiKRuliKY9/dGb+n59hBXZMte80mBp3eBtCUNlp3NuK7iLGRk glAZjVAR1qoaqY6989GF/Limxbv5DOzmZbFGUI2cAJxX2MEkkNk++lrn1Gg7MlF+ M5xjJ5qwORTxbpSgkLLIxNnCL05/pSSmQi1u4kesNXUGa1l7XKJZafVkkAWJj5/D RA2kKF/p59jl1irJPRAHfIeCpn2IpjgvNkv5d2nTp26yhuBnVprI2dDiirOAaMcY GMCmBf8fFkA+kYRW/ad9WvOrhgGNH2vIXwKTkwwNY41W8HNj2HhVfZ41yz67UYv+ Gia+r8/5MJhzJZeWnzcdSKB0w6U9CfE02c2cxjLubDepEOGisoCD9wlm/Zx/TQqp bXvrQQ9rw5tMX1vwHMu8UCdcb2MErj0nW7cmd9nHv8efWCDrRDEmqC7DcHmT4JHl eTa+YS820EGg8DDDZVqUz4Kwxua4u4YvtL64NvH3tnKrF9wyaXLz1FLQquCOpMFc S8TBoIIm9seWLjDKy11FOmAnciBkHPoxS2YzmZWpbE5GWLw5R2/HWsFX1ZYk38tA sMYul3HVTx5UChweURmthpnX9mwUK7oXYRNPMG14VV5718v85Mfw3GRcIM2ovDXF k8d8Crjhc88=wRRT -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://listman.redhat.com/mailman/listinfo/rhsa-announce . New updates featuring security enhancements and bug corrections released for Red Hat OpenShift Container Storage 4.7.0 on RHEL 8.. Red Hat OpenShift, Container Storage, Security Fixes. .Severity: Important. LinuxSecurity.com Team

Calendar%202 May 19, 2021 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200