Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
217

Oracle Linux 10 cockpit Critical Remote Code Execution VULN ELSA-2026-7383

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-7383 http://linux.oracle.com/errata/ELSA-2026-7383.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: cockpit-344-3.0.1.el10_1.x86_64.rpm cockpit-bridge-344-3.0.1.el10_1.noarch.rpm cockpit-doc-344-3.0.1.el10_1.noarch.rpm cockpit-packagekit-344-3.0.1.el10_1.noarch.rpm cockpit-storaged-344-3.0.1.el10_1.noarch.rpm cockpit-system-344-3.0.1.el10_1.noarch.rpm cockpit-ws-344-3.0.1.el10_1.x86_64.rpm cockpit-ws-selinux-344-3.0.1.el10_1.x86_64.rpm aarch64: cockpit-344-3.0.1.el10_1.aarch64.rpm cockpit-bridge-344-3.0.1.el10_1.noarch.rpm cockpit-doc-344-3.0.1.el10_1.noarch.rpm cockpit-packagekit-344-3.0.1.el10_1.noarch.rpm cockpit-storaged-344-3.0.1.el10_1.noarch.rpm cockpit-system-344-3.0.1.el10_1.noarch.rpm cockpit-ws-344-3.0.1.el10_1.aarch64.rpm cockpit-ws-selinux-344-3.0.1.el10_1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/cockpit-344-3.0.1.el10_1.src.rpm Related CVEs: CVE-2026-4631 Description of changes: [344-3.0.1] - Storage: Enable btrfs support [Orabug: 37464632] - Replaced upstream urls in documentation with oracle links [Orabug: 36528753] - Drop subscription-manager-cockpit requirement for ol [Orabug: 34681110] - Remove duplicate reference to server in cockpit [Orabug: 34030494] - Update documentation links [Orabug: 30271413], [Orabug: 32013095], [Orabug: 32795691], [Orabug: 34398512], [Orabug: 34742876], [Orabug: 37253273] - Update spec file for new release [344-3] - correctly apply CVE patches (CVE-2026-4631) * Wed Mar 25 2026 Jelle van der Waa

Calendar 2 Apr 15, 2026 Critical Oracle
197

Debian 11: PgBouncer Moderate SQL Injection Risk DLA-4422-1 CVE-2025-12819

PgBouncer is a lightweight connection pooler for PostgreSQL. CVE-2025-12819 Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4422-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Andreas Henriksson December 27, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : pgbouncer Version : 1.15.0-1+deb11u2 CVE ID : CVE-2025-12819 Debian Bug : PgBouncer is a lightweight connection pooler for PostgreSQL. CVE-2025-12819 Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage. For Debian 11 bullseye, this problem has been fixed in version 1.15.0-1+deb11u2. We recommend that you upgrade your pgbouncer packages. For the detailed security status of pgbouncer please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/pgbouncer Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . CVE-2025-12819 details a moderate risk SQL injection flaw in PgBouncer on Debian. Upgrade recommended to mitigate risk.. PgBouncer Security, Debian Security Update, SQL Injection Risk, Vulnerability Patch, PgBouncer CVE. . LinuxSecurity.com Team

Calendar 2 Dec 27, 2025 Debian LTS
202

openSUSE: java-11-openjdk Important Data Access Threat 2025:3996-1

An update that solves two vulnerabilities and has one security fix can now be installed.. # Security update for java-11-openjdk Announcement ID: SUSE-SU-2025:3996-1 Release Date: 2025-11-07T15:49:28Z Rating: important References: * bsc#1246806 * bsc#1252414 * bsc#1252417 Cross-References: * CVE-2025-53057 * CVE-2025-53066 CVSS scores: * CVE-2025-53057 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-53057 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53057 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53066 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-53066 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-53066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Legacy Module 15-SP6 * Legacy Module 15-SP7 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE LinuxEnterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Proxy 4.3 LTS * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Retail Branch Server 4.3 LTS * SUSE Manager Server 4.3 * SUSE Manager Server 4.3 LTS * SUSE Package Hub 15 15-SP6 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for java-11-openjdk fixes the following issues: Upgrade to upstream tag jdk-11.0.29+7 (October 2025 CPU): * CVE-2025-53057: Fixed unauthenticated attacker can achieve unauthorized creation, deletion or modification access to critical data (bsc#1252414). * CVE-2025-53066: Fixed unauthenticated attacker can achive unauthorized access to critical data or complete access (bsc#1252417). Other bug fixes: * Do not embed rebuild counter (bsc#1246806) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Retail Branch Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-LTS-2025-3996=1 * SUSE Manager Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-LTS-2025-3996=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-3996=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-3996=1 * Legacy Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP6-2025-3996=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2025-3996=1 * SUSE Package Hub 15 15-SP6 zypper in -t patchSUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-3996=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-3996=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-3996=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-3996=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-3996=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-3996=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-3996=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-3996=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-3996=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-3996=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-3996=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-3996=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-3996=1 * SUSE Manager Proxy 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-LTS-2025-3996=1 ## Package List: * SUSE Manager Retail Branch Server 4.3 LTS (x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 *java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Manager Server 4.3 LTS (ppc64le s390x x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-src-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-jmods-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * openSUSE Leap 15.6 (noarch) * java-11-openjdk-javadoc-11.0.29.0-150000.3.132.2 * Legacy Module 15-SP6 (aarch64 ppc64le s390x x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) *java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Package Hub 15 15-SP6 (noarch) * java-11-openjdk-javadoc-11.0.29.0-150000.3.132.2 * SUSE Package Hub 15 15-SP7 (noarch) * java-11-openjdk-javadoc-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 *java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 *java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * SUSE Manager Proxy 4.3 LTS (x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 ## References: * https://www.suse.com/security/cve/CVE-2025-53057.html * https://www.suse.com/security/cve/CVE-2025-53066.html * https://bugzilla.suse.com/show_bug.cgi?id=1246806 * https://bugzilla.suse.com/show_bug.cgi?id=1252414 * https://bugzilla.suse.com/show_bug.cgi?id=1252417 . Solve key issues with Java OpenJDK security in openSUSE. Important HTTP access vulnerabilities fixed. Install the update.. openSUSE security update, Java OpenJDK vulnerabilities, important security patch, openSUSE advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 07, 2025 Important OpenSUSE
100

SUSE: java-1_8_0-ibm Important Network Access Issues 2025:03262-1

* bsc#1246575 * bsc#1246580 * bsc#1246584 * bsc#1246595 * bsc#1246598 . # Security update for java-1_8_0-ibm Announcement ID: SUSE-SU-2025:03262-1 Release Date: 2025-09-18T06:42:36Z Rating: important References: * bsc#1246575 * bsc#1246580 * bsc#1246584 * bsc#1246595 * bsc#1246598 * bsc#1247754 Cross-References: * CVE-2025-30749 * CVE-2025-30754 * CVE-2025-30761 * CVE-2025-50059 * CVE-2025-50106 CVSS scores: * CVE-2025-30749 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-30749 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2025-30749 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-30754 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-30754 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-30754 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-30761 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-30761 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-50059 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2025-50059 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2025-50106 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-50106 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Legacy Module 15-SP6 * Legacy Module 15-SP7 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves five vulnerabilities and has one security fix can now be installed. ## Description: This update for java-1_8_0-ibm fixes the following issues: Update to Java 8.0 Service Refresh 8 Fix Pack 50. Security issues fixed: * Oracle July 15 2025 CPU (bsc#1247754). * CVE-2025-30749: heap corruption allows unauthenticated attacker with network access to compromise and takeover Java applications that load and run untrusted code (bsc#1246595). * CVE-2025-30754: incomplete handshake allows unauthenticated attacker with network access via TLS to gain unauthorized update, insert, delete and read access to sensitive data (bsc#1246598). * CVE-2025-30761: issue in the Scripting component allows unauthenticated attacker with network access to gain unauthorized creation, deletion or modification access to critical data (bsc#1246580). * CVE-2025-50059: issue in the Networking component allows unauthenticated attacker with network access to gain unauthorized access to critical data (bsc#1246575). * CVE-2025-50106: Glyph out-of-memory access allows unauthenticated attacker with network access to compromise and takeover Java applications that load and run untrusted code (bsc#1246584). Other issues fixed: * Class Libraries: * Oracle Security Fix 8348989: Better Glyph drawing. * Removal of Baltimore root certificate and TWO CAMERFIRMA root CA certificates from CACERTS. * Update timezone information to the latest TZDATA2025B. * Java Virtual Machine: * Assertionfailure at copyforwardscheme.cpp. * JIT Compiler: * GC assert due to an invalid object reference. * SIGILL from JIT compiled method. * Unexpected behaviour with very large arrays. * Security: * Deserialization of a serialized RSAPrivateCrtKey is throwing an exception. * EDDSAsignature fails when doing multiple update. * HTTPS channel binding support. * IBMJCEPlus provider supports post quantum cryptography algorithms ML-KEM (key encapsulation) and ML-DSA (digital signature). * Key certificate management: Extended key usage cannot be set without having key usage extension in certificate request. * MessageDigest.update API does not throw the correct exception. * Oracle Security Fix 8349594: Enhance TLS protocol support. * Problem getting key in PKCS12 keystore on MAC. * TLS support for the EDDSA signature algorithm. * Wrong algorithm name returned for EDDSA keys. * z/OS Extentions: * IBMJCEHybridException with hybrid provider in GCM mode. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-3262=1 * Legacy Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP6-2025-3262=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2025-3262=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-3262=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-3262=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-3262=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-3262=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-3262=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-3262=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-3262=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-3262=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-3262=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-3262=1 ## Package List: * openSUSE Leap 15.6 (nosrc ppc64le s390x x86_64) * java-1_8_0-ibm-1.8.0_sr8.50-150000.3.104.1 * openSUSE Leap 15.6 (x86_64) * java-1_8_0-ibm-alsa-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-plugin-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-32bit-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-devel-32bit-1.8.0_sr8.50-150000.3.104.1 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * java-1_8_0-ibm-src-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-demo-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-devel-1.8.0_sr8.50-150000.3.104.1 * Legacy Module 15-SP6 (nosrc ppc64le s390x x86_64) * java-1_8_0-ibm-1.8.0_sr8.50-150000.3.104.1 * Legacy Module 15-SP6 (ppc64le s390x x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.50-150000.3.104.1 * Legacy Module 15-SP6 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.50-150000.3.104.1 * Legacy Module 15-SP7 (nosrc ppc64le s390x x86_64) * java-1_8_0-ibm-1.8.0_sr8.50-150000.3.104.1 * Legacy Module 15-SP7 (ppc64le s390x x86_64) * java-1_8_0-ibm-src-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-demo-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-devel-1.8.0_sr8.50-150000.3.104.1 * Legacy Module 15-SP7 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.50-150000.3.104.1 *java-1_8_0-ibm-alsa-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (nosrc x86_64) * java-1_8_0-ibm-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-devel-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (nosrc x86_64) * java-1_8_0-ibm-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-devel-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (nosrc x86_64) * java-1_8_0-ibm-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-devel-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (nosrc ppc64le s390x x86_64) * java-1_8_0-ibm-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (ppc64le s390x x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (nosrc ppc64le s390x x86_64) * java-1_8_0-ibm-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (ppc64le s390x x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (nosrc ppc64le s390xx86_64) * java-1_8_0-ibm-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (ppc64le s390x x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (nosrc ppc64le x86_64) * java-1_8_0-ibm-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (nosrc ppc64le x86_64) * java-1_8_0-ibm-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (nosrc ppc64le x86_64) * java-1_8_0-ibm-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.50-150000.3.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.50-150000.3.104.1 * SUSE Enterprise Storage 7.1 (nosrc x86_64) * java-1_8_0-ibm-1.8.0_sr8.50-150000.3.104.1 * SUSE Enterprise Storage 7.1 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.50-150000.3.104.1 * java-1_8_0-ibm-devel-1.8.0_sr8.50-150000.3.104.1 ## References: *https://www.suse.com/security/cve/CVE-2025-30749.html * https://www.suse.com/security/cve/CVE-2025-30754.html * https://www.suse.com/security/cve/CVE-2025-30761.html * https://www.suse.com/security/cve/CVE-2025-50059.html * https://www.suse.com/security/cve/CVE-2025-50106.html * https://bugzilla.suse.com/show_bug.cgi?id=1246575 * https://bugzilla.suse.com/show_bug.cgi?id=1246580 * https://bugzilla.suse.com/show_bug.cgi?id=1246584 * https://bugzilla.suse.com/show_bug.cgi?id=1246595 * https://bugzilla.suse.com/show_bug.cgi?id=1246598 * https://bugzilla.suse.com/show_bug.cgi?id=1247754 . An essential security patch for java-1_8_0-ibm tackles various concerns affecting network security flaws in SUSE.. SUSE Java Patch, Network Access Security, IBM Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 18, 2025 Important SuSE
203

Mageia 7: MGASA-2020-0380 Moderate: Samba Netlogon Protocol Flaw

When Samba is used as a domain controller, an unauthenticated attacker on the network can gain administrator access by exploiting a netlogon protocol flaw (CVE-2020-1472). Note that Samba installations are not vulnerable unless they have the smb.conf . MGASA-2020-0380 - Updated samba packages fix security vulnerability Publication date: 30 Sep 2020 URL: https://advisories.mageia.org/MGASA-2020-0380.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-1472 When Samba is used as a domain controller, an unauthenticated attacker on the network can gain administrator access by exploiting a netlogon protocol flaw (CVE-2020-1472). Note that Samba installations are not vulnerable unless they have the smb.conf lines 'server schannel = no' or 'server schannel = auto'. References: - https://bugs.mageia.org/show_bug.cgi?id=27299 - - - https://ubuntu.com/security/notices/USN-4510-1 - https://www.cve.org/CVERecord?id=CVE-2020-1472 SRPMS: - 7/core/samba-4.10.18-1.mga7 . The Samba security update MGASA-2020-0380 resolves an issue with administrative access stemming from a vulnerability in the netlogon protocol.. samba security, mageia advisory, network vulnerabilities, admin access protocols, netlogon exploitation. . LinuxSecurity.com Team

Calendar 2 Sep 30, 2020 Mageia
202

openSUSE 15.1: 2020:0357-1 Moderate: Salt User Escalation and API Issues

An update that solves two vulnerabilities and has 7 fixes is now available.. openSUSE Security Update: Security update for salt ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0357-1 Rating: moderate References: #1135656 #1153611 #1157465 #1158940 #1159118 #1160931 #1162327 #1162504 #1165425 Cross-References: CVE-2019-17361 CVE-2019-18897 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that solves two vulnerabilities and has 7 fixes is now available. Description: This update for salt fixes the following issues: - Avoid possible user escalation upgrading salt-master (bsc#1157465) (CVE-2019-18897) - Fix unit tests failures in test_batch_async tests - Batch Async: Handle exceptions, properly unregister and close instances after running async batching to avoid CPU starvation of the MWorkers (bsc#1162327) - RHEL/CentOS 8 uses platform-python instead of python3 - New configuration option for selection of grains in the minion start event. - Fix 'os_family' grain for Astra Linux Common Edition - Fix for salt-api NET API where unauthenticated attacker could run arbitrary code (CVE-2019-17361) (bsc#1162504) - Adds disabled parameter to mod_repo in aptpkg module Move token with atomic operation Bad API token files get deleted (bsc#1160931) - Support for Btrfs and XFS in parted and mkfs added - Adds list_downloaded for apt Module to enable pre-downloading support Adds virt.(pool|network)_get_xml functions - Various libvirt updates: * Add virt.pool_capabilities function * virt.pool_running improvements * Add virt.pool_deleted state * virt.network_define allow adding IP configuration - virt: adding kernel boot parameters to libvirt xml - Fix to scheduler when data['run'] does not exist (bsc#1159118) - Fixvirt states to not fail on VMs already stopped - Fix applying of attributes for returner rawfile_json (bsc#1158940) - xfs: do not fail if type is not present (bsc#1153611) - Fix errors when running virt.get_hypervisor function - Align virt.full_info fixes with upstream Salt - Fix for log checking in x509 test - Read repo info without using interpolation (bsc#1135656) - Limiting M2Crypto to > = SLE15 - Replacing pycrypto with M2Crypto (bsc#1165425) This update was imported from the SUSE:SLE-15-SP1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-357=1 Package List: - openSUSE Leap 15.1 (x86_64): python2-salt-2019.2.0-lp151.5.12.1 python3-salt-2019.2.0-lp151.5.12.1 salt-2019.2.0-lp151.5.12.1 salt-api-2019.2.0-lp151.5.12.1 salt-cloud-2019.2.0-lp151.5.12.1 salt-doc-2019.2.0-lp151.5.12.1 salt-master-2019.2.0-lp151.5.12.1 salt-minion-2019.2.0-lp151.5.12.1 salt-proxy-2019.2.0-lp151.5.12.1 salt-ssh-2019.2.0-lp151.5.12.1 salt-standalone-formulas-configuration-2019.2.0-lp151.5.12.1 salt-syndic-2019.2.0-lp151.5.12.1 - openSUSE Leap 15.1 (noarch): salt-bash-completion-2019.2.0-lp151.5.12.1 salt-fish-completion-2019.2.0-lp151.5.12.1 salt-zsh-completion-2019.2.0-lp151.5.12.1 References: https://www.suse.com/security/cve/CVE-2019-17361.html https://www.suse.com/security/cve/CVE-2019-18897.html https://bugzilla.suse.com/1135656 https://bugzilla.suse.com/1153611 https://bugzilla.suse.com/1157465 https://bugzilla.suse.com/1158940 https://bugzilla.suse.com/1159118 https://bugzilla.suse.com/1160931 https://bugzilla.suse.com/1162327 https://bugzilla.suse.com/1162504 https://bugzilla.suse.com/1165425 -- .The latest openSUSE release tackles a duo of significant vulnerabilities and delivers 7 essential enhancements across various system components.. openSUSE security update,salt issues,moderate security patch,openSUSE vulnerabilities. . LinuxSecurity.com Team

Calendar 2 Mar 18, 2020 OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here