Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 247 articles for you...
89

Fedora 43 python-asyncssh Critical Unauthorized Access Fix 2026-574496d9ae

import asyncssh 2.23.1 Fix CVE-2026-54590: Unauthorized file modification via authorized-keys directory escape Fix CVE-2026-54591: Arbitrary file write via path traversal in SCP client. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-574496d9ae 2026-07-20 01:10:43.961032+00:00 -------------------------------------------------------------------------------- Name : python-asyncssh Product : Fedora 43 Version : 2.23.1 Release : 1.fc43 URL : https://github.com/ronf/asyncssh Summary : Asynchronous SSH for Python Description : Python 3 library for asynchronous client and server-side SSH communication. It uses the Python asyncio module and implements many SSH protocol features such as the various channels, SFTP, SCP, forwarding, session multiplexing over a connection and more. -------------------------------------------------------------------------------- Update Information: import asyncssh 2.23.1 Fix CVE-2026-54590: Unauthorized file modification via authorized-keys directory escape Fix CVE-2026-54591: Arbitrary file write via path traversal in SCP client -------------------------------------------------------------------------------- ChangeLog: * Sat Jul 11 2026 Georg Sauthoff - 2.23.1-1 - import asyncssh 2.23.1 - fix CVE-2026-54590: Unauthorized file modification via authorized-keys directory escape (fixes fedora#2498421, fixes fedora#2498423) - fix CVE-2026-54591: Arbitrary file write via path traversal in SCP client (fixes fedora#2498488) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2498421 - CVE-2026-54590 python-asyncssh: AsyncSSH: Unauthorized file modification via authorized-keys directory escape [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2498421 [ 2 ] Bug #2498423 - CVE-2026-54590 python-asyncssh: AsyncSSH: Unauthorized file modification via authorized-keys directoryescape [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2498423 [ 3 ] Bug #2498488 - CVE-2026-54591 python-asyncssh: AsyncSSH: Arbitrary file write via path traversal in SCP client [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2498488 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-574496d9ae' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Critical update for Fedora Python-AsyncSSH addresses unauthorized file modifications and path traversal risks.. Fedora Python-AsyncSSH Critical Update Unauthorized Access. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 19, 2026 Critical Fedora
172

Ubuntu Tomcat Important Security Flaws CVE-2026-43515 CVE-2026-50229

Several security issues were fixed in Tomcat.. ========================================================================== Ubuntu Security Notice USN-8551-1 July 15, 2026 tomcat8 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Tomcat. Software Description: - tomcat8: Servlet and JSP engine Details: It was discovered that Tomcat incorrectly handled authorization when multiple method constraints defined the same HTTP method. A remote attacker could possibly use this issue to bypass authorization restrictions. (CVE-2026-43515) It was discovered that the Tomcat number guess example application did not properly sanitize user-supplied input. An attacker could possibly use this issue to inject malicious scripts, resulting in cross-site scripting. (CVE-2026-50229) It was discovered that Tomcat incorrectly evaluated rewrite valve conditions in certain configurations. An attacker could possibly use this issue to bypass rewrite rules, resulting in unauthorized access. (CVE-2026-53404) It was discovered that Tomcat incorrectly omitted certain authorization information when logging the effective web.xml configuration. An attacker could possibly use this issue to hide authorization constraints, resulting in reduced auditability. (CVE-2026-55276) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS libtomcat8-embed-java 8.5.39-1ubuntu1~18.04.3+esm6 Available with Ubuntu Pro libtomcat8-java 8.5.39-1ubuntu1~18.04.3+esm6 Available with Ubuntu Pro tomcat8-examples 8.5.39-1ubuntu1~18.04.3+esm6 Available with Ubuntu Pro Ubuntu 16.04 LTS libtomcat8-java 8.0.32-1ubuntu1.13+esm2 Available with Ubuntu Pro tomcat8-examples 8.0.32-1ubuntu1.13+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8551-1 CVE-2026-43515, CVE-2026-50229, CVE-2026-53404, CVE-2026-55276 . Several security issues in Tomcat on Ubuntu could be exploited, necessitating prompt updates to prevent unauthorized access and script injections.. Tomcat security, Ubuntu patch, Tomcat vulnerabilities, web application security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 15, 2026 Important Ubuntu
89

Fedora 44 python-jupyter-server High CVE Fixes 2026-dd1d19e58b

New version fixing high-severity CVE. New version of jupyter-server fixing various security vulnerabilities.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-dd1d19e58b 2026-07-05 01:07:02.694197+00:00 -------------------------------------------------------------------------------- Name : python-jupyter-server Product : Fedora 44 Version : 2.20.0 Release : 1.fc44 URL : https://jupyter-server.readthedocs.io Summary : The backend for Jupyter web applications Description : The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. -------------------------------------------------------------------------------- Update Information: New version fixing high-severity CVE. New version of jupyter-server fixing various security vulnerabilities. -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 19 2026 Lumir Balhar - 2.20.0-1 - Update to 2.20.0 (rhbz#2489836) * Thu Jun 4 2026 Python Maint - 2.19.0-2 - Rebuilt for Python 3.15 * Mon Jun 1 2026 Lumir Balhar - 2.19.0-1 - Update to 2.19.0 (rhbz#2483209) * Mon May 11 2026 Lumir Balhar - 2.18.2-1 - Update to 2.18.2 (rhbz#2466683) * Tue May 5 2026 Lumir Balhar - 2.18.0-1 - Update to 2.18.0 (rhbz#2465646) * Tue Apr 14 2026 Tomáš Hrnčiar - 2.17.0-5 - Raise pytest upper bound to allow pytest 9 * Fri Mar 20 2026 Lumir Balhar - 2.17.0-4 - Ignore deprecation warnings from ptyprocess:pty to fix build with Python 3.15 alpha 7 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2484708 - CVE-2026-35397 python-jupyter-server: Jupyter Server: Unauthorized File Access via Path Traversal Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2484708 [ 2 ] Bug #2484713 - CVE-2026-40934 python-jupyter-server: Jupyter Server:Authentication bypass due to unrotated cookie secret [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2484713 [ 3 ] Bug #2485374 - CVE-2026-6657 python-jupyter-server: jupyter-server: Arbitrary code execution due to CORS origin validation bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2485374 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-dd1d19e58b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fixes high-severity security issue in Jupyter Server with improved vulnerabilities.. Jupyter Server Security Update, Fedora High Severity Vulnerabilities, Python Jupyter Server Fix. . Severity: high. LinuxSecurity.com Team

Calendar%202 Jul 04, 2026 high Fedora
89

Fedora 43 python-jupyter-server Critical Path Traversal DoS 2026-9536c7cb79

New version of jupyter-server fixing various security vulnerabilities.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9536c7cb79 2026-06-27 00:54:50.049657+00:00 -------------------------------------------------------------------------------- Name : python-jupyter-server Product : Fedora 43 Version : 2.19.0 Release : 2.fc43 URL : https://jupyter-server.readthedocs.io Summary : The backend for Jupyter web applications Description : The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. -------------------------------------------------------------------------------- Update Information: New version of jupyter-server fixing various security vulnerabilities. -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 4 2026 Python Maint - 2.19.0-2 - Rebuilt for Python 3.15 * Mon Jun 1 2026 Lumir Balhar - 2.19.0-1 - Update to 2.19.0 (rhbz#2483209) * Mon May 11 2026 Lumir Balhar - 2.18.2-1 - Update to 2.18.2 (rhbz#2466683) * Tue May 5 2026 Lumir Balhar - 2.18.0-1 - Update to 2.18.0 (rhbz#2465646) * Tue Apr 14 2026 Tomáš Hrnčiar - 2.17.0-5 - Raise pytest upper bound to allow pytest 9 * Fri Mar 20 2026 Lumir Balhar - 2.17.0-4 - Ignore deprecation warnings from ptyprocess:pty to fix build with Python 3.15 alpha 7 * Sat Jan 17 2026 Fedora Release Engineering - 2.17.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2484708 - CVE-2026-35397 python-jupyter-server: Jupyter Server: Unauthorized File Access via Path Traversal Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2484708 [ 2 ] Bug #2484713 - CVE-2026-40934 python-jupyter-server: Jupyter Server: Authentication bypass due tounrotated cookie secret [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2484713 [ 3 ] Bug #2485374 - CVE-2026-6657 python-jupyter-server: jupyter-server: Arbitrary code execution due to CORS origin validation bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2485374 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9536c7cb79' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update for python-jupyter-server in Fedora 43 addresses critical security flaws for enhanced safety.. python jupyter server, Fedora 43, security update, fix vulnerabilities, software patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 26, 2026 Important Fedora
89

Fedora 43 Goose Critical DNS Rebinding Threat Fix 2026-08bb036c3e

Update goose to 1.36.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-08bb036c3e 2026-06-25 16:24:07.917328+00:00 -------------------------------------------------------------------------------- Name : goose Product : Fedora 43 Version : 1.36.0 Release : 1.fc43 URL : https://github.com/block/goose Summary : Extensible AI agent client Description : Goose is your on-machine AI agent, capable of automating complex development tasks from start to finish. More than just code suggestions, goose can build entire projects from scratch, write and execute code, debug failures, orchestrate workflows, and interact with external APIs - autonomously. Whether you're prototyping an idea, refining existing code, or managing intricate engineering pipelines, goose adapts to your workflow and executes tasks with precision. Designed for maximum flexibility, goose works with any LLM and supports multi-model configuration to optimize performance and cost, seamlessly integrates with MCP servers, and is available as both a desktop app as well as CLI - making it the ultimate AI assistant for developers who want to move faster and focus on innovation. -------------------------------------------------------------------------------- Update Information: Update goose to 1.36.0 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 17 2026 Sam Doran - 1.36.0-1 - Update goose to 1.36.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2477786 - CVE-2026-42559 goose: rmcp: Unauthorized access to MCP server via DNS rebinding vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2477786 [ 2 ] Bug #2477787 - CVE-2026-42559 goose: rmcp: Unauthorized access to MCP server via DNS rebinding vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2477787 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-08bb036c3e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Address critical update for Goose on Fedora 43 to fix a serious DNS rebinding issue impacting server access.. Fedora updates, Goose software, AI automation, DNS rebinding, critical vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 25, 2026 Critical Fedora
89

Fedora 44 Goose Important Unauthorized Access Vulnerability 2026-00021c7c91

Update goose to 1.36.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-00021c7c91 2026-06-25 16:08:03.982873+00:00 -------------------------------------------------------------------------------- Name : goose Product : Fedora 44 Version : 1.36.0 Release : 1.fc44 URL : https://github.com/block/goose Summary : Extensible AI agent client Description : Goose is your on-machine AI agent, capable of automating complex development tasks from start to finish. More than just code suggestions, goose can build entire projects from scratch, write and execute code, debug failures, orchestrate workflows, and interact with external APIs - autonomously. Whether you're prototyping an idea, refining existing code, or managing intricate engineering pipelines, goose adapts to your workflow and executes tasks with precision. Designed for maximum flexibility, goose works with any LLM and supports multi-model configuration to optimize performance and cost, seamlessly integrates with MCP servers, and is available as both a desktop app as well as CLI - making it the ultimate AI assistant for developers who want to move faster and focus on innovation. -------------------------------------------------------------------------------- Update Information: Update goose to 1.36.0 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 17 2026 Sam Doran - 1.36.0-1 - Update goose to 1.36.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2477786 - CVE-2026-42559 goose: rmcp: Unauthorized access to MCP server via DNS rebinding vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2477786 [ 2 ] Bug #2477787 - CVE-2026-42559 goose: rmcp: Unauthorized access to MCP server via DNS rebinding vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2477787 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-00021c7c91' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Goose 1.36.0 update for Fedora improves AI automation for developers. Critical patch fixes unauthorized access risk.. Fedora Update Goose AI Agent, Security Fix Goosel, Unauthorized Access Vulnerability, Fedora 44 Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 25, 2026 Important Fedora
100

SUSE java-1_8_0-openjdk Important Partial DoS Vulnern 2026-2624-1

An update that solves seven vulnerabilities and has one security fix can now be installed.. # Security update for java-1_8_0-openjdk Announcement ID: SUSE-SU-2026:2624-1 Release Date: 2026-06-24T14:26:23Z Rating: important References: * bsc#1259118 * bsc#1262490 * bsc#1262494 * bsc#1262495 * bsc#1262496 * bsc#1262497 * bsc#1262500 * bsc#1267355 Cross-References: * CVE-2026-22007 * CVE-2026-22013 * CVE-2026-22016 * CVE-2026-22018 * CVE-2026-22021 * CVE-2026-23865 * CVE-2026-34268 CVSS scores: * CVE-2026-22007 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22007 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22007 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22013 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22013 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22013 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22016 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22018 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22018 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22018 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23865 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-23865 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-23865 ( NVD): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-34268 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34268 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34268 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities and has one security fix can now be installed. ## Description: This update for java-1_8_0-openjdk fixes the following issues Update to version jdk8u492: Security issues: * CVE-2026-22007: APIs in the specified component can lead to an unauthorized read access (bsc#1262490). * CVE-2026-22013: unauthenticated attacker with network access can access to critical data (bsc#1262494). * CVE-2026-22016: APIs in the specified Component can cause unauthorized access to critical data (bsc#1262495). * CVE-2026-22018: unauthenticated attacker with network access can cause a partial denial of service (bsc#1262496). * CVE-2026-22021: APIs in the specified Component can cause a partial denial of service (bsc#1262497). * CVE-2026-23865: Integer overflow in the tt_var_load_item_variation_store function (bsc#1259118). * CVE-2026-34268: unauthenticated attacker with logon can gain unauthorized read access (bsc#1262500). Non security issue: * Errors from update-alternatives when installing java-25-openjdk (bsc#1267355). Changes: * Update to version jdk8u492 (icedtea 3.39.0) * Import of OpenJDK 8 u492 build 09 * JDK-8056039: Hotspot does not compile with clang 3.4 on Linux * JDK-8074840: Resolve disabled warnings for libjli and libjli_static * JDK-8132786: java/security/cert/CertPathValidator/OCSP/ /AIACheck.java fails intermittently * JDK-8153147: Mark java/net/BindException/Test.java as intermittently failing * JDK-8157758: JDK9 does not compile on Linux with GCC 6.1 because left- shifting a negative number has undefined behavior * JDK-8170464: Remove shell script from compiler/c2/cr7005594/Test7005594.java * JDK-8174734: Safepoint sync time did not increase * JDK-8186149: quarantine gc/survivorAlignment/ /TestPromotionFromSurvivorToTenuredAfterMinorGC.java * JDK-8220658: Improve the readability of container information in the error log * JDK-8223145: Replace wildcard address with loopback or local host in tests - part 1 * JDK-8225487: giflib legal file is missing attribution for openbsd- reallocarray.c. * JDK-8237834: com/sun/jndi/ldap/LdapDnsProviderTest.java failing with LDAP response read timeout * JDK-8251189: com/sun/jndi/ldap/LdapDnsProviderTest.java failed due to timeout * JDK-8264524: jdk/internal/platform/docker/ /TestDockerMemoryMetrics.java fails due to swapping not working * JDK-8274893: Update java.desktop classes to use try-with-resources * JDK-8277159: Fix java/nio/file/FileStore/Basic.java test by ignoring /run/user/* mount points * JDK-8284758: [linux] improve print_container_info * JDK-8285836: sun/net/www/http/KeepAliveCache/ /KeepAliveProperty.java failed with "RuntimeException: Failed in server" * JDK-8287011: Improve container information * JDK-8303482: Update LCMS to 2.15 * JDK-8312518: [macos13] setFullScreenWindow() shows black screen on macOS 13 & above * JDK-8313770: jdk/internal/platform/docker/ /TestSystemMetrics.java fails on Ubuntu * JDK-8328999: Update GIFlib to 5.2.2 * JDK-8339271: giflib attribution correction * JDK-8343622: AesDkCrypto.stringToKey should not return null * JDK-8345578: New test in JDK-8343622 fails with a promoted build * JDK-8347911: Limit the length of inflated text chunks * JDK-8348014: Enhance certificate processing * JDK-8350813: Rendering of bulky sound bank from MIDIsequence can cause OutOfMemoryError * JDK-8353657: [8u] Test tools/launcher/VersionCheck.java fails with debug build * JDK-8360869: jcstress is able to crash jdk8 on aarch64 with jfr on * JDK-8361748: Enforce limits on the size of an XBM image * JDK-8364373: Transform Affine transformations * JDK-8364465: Enhance behavior of some intrinsics * JDK-8364660: ClassVerifier::ends_in_athrow() should be removed * JDK-8369226: GHA: Switch to MacOS 15 * JDK-8369282: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA * JDK-8369575: Enhance crypto algorithm support * JDK-8370529: Enhance Path Factories Redux * JDK-8370615: Improve Kerberos credentialing * JDK-8370986: Enhance Zip file reading * JDK-8370995: Enhance ZipFile usage * JDK-8371830: Enhance certificate chain validation * JDK-8371935: Enhance key generation * JDK-8372660: [8u] ProblemList TestCPUAwareness until 8370492 is addressed * JDK-8373250: Bump update version of OpenJDK: 8u492 * JDK-8373290: Update FreeType to 2.14.1 * JDK-8373476: (tz) Update Timezone Data to 2025c * JDK-8373727: New XBM images parser regression: only the first line of the bitmap array is parsed * JDK-8374899: [8u] Fully handle clang as the toolchain in flags.m4 * JDK-8374917: [8u] C++ flags get passed to C compiles in the HotSpot build * JDK-8374948: [8u] saproc & jsig builds add duplicate linker flags on Darwin/MacOS * JDK-8375063: Update Libpng to 1.6.54 * JDK-8375189: [8u] Problem list CAInterop.java#microsoftrsa2017 * JDK-8376225: [8u] GHA: Apply work-around for missing JNF for MacOSX builds * JDK-8376272: [8u] Windows x86-32 fails to build after JDK-8359501 * JDK-8376338: Test7005594.sh fails when given a memory value with decimals * JDK-8376352: [8u] Build failure on Windows 32-bit after JDK-8362308 * JDK-8377344: [8u] Compilation failure on Windows for Linux-specific platform metric tests * JDK-8377526: Update Libpng to 1.6.55 * JDK-8379035: (tz) Update Timezone Data to 2026a * JDK-8379158: Update FreeType to 2.14.2 * JDK-8379256: Update GIFlib to 6.1.1 * JDK-8380078: Update GIFlib to 6.1.2 * JDK-8380959: Update Libpng to 1.6.56 * JDK-8382047: Update Libpng to 1.6.57 * Bug fixes * JDK-8162545, GH37: Mac build failure ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2624=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2624=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-1_8_0-openjdk-debuginfo-1.8.0.492-27.128.1 * java-1_8_0-openjdk-demo-1.8.0.492-27.128.1 * java-1_8_0-openjdk-headless-1.8.0.492-27.128.1 * java-1_8_0-openjdk-1.8.0.492-27.128.1 * java-1_8_0-openjdk-devel-1.8.0.492-27.128.1 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.492-27.128.1 * java-1_8_0-openjdk-debugsource-1.8.0.492-27.128.1 * java-1_8_0-openjdk-demo-debuginfo-1.8.0.492-27.128.1 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.492-27.128.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * java-1_8_0-openjdk-debuginfo-1.8.0.492-27.128.1 * java-1_8_0-openjdk-demo-1.8.0.492-27.128.1 * java-1_8_0-openjdk-headless-1.8.0.492-27.128.1 * java-1_8_0-openjdk-1.8.0.492-27.128.1 * java-1_8_0-openjdk-devel-1.8.0.492-27.128.1 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.492-27.128.1 * java-1_8_0-openjdk-debugsource-1.8.0.492-27.128.1 * java-1_8_0-openjdk-demo-debuginfo-1.8.0.492-27.128.1 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.492-27.128.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22007.html * https://www.suse.com/security/cve/CVE-2026-22013.html *https://www.suse.com/security/cve/CVE-2026-22016.html * https://www.suse.com/security/cve/CVE-2026-22018.html * https://www.suse.com/security/cve/CVE-2026-22021.html * https://www.suse.com/security/cve/CVE-2026-23865.html * https://www.suse.com/security/cve/CVE-2026-34268.html * https://bugzilla.suse.com/show_bug.cgi?id=1259118 * https://bugzilla.suse.com/show_bug.cgi?id=1262490 * https://bugzilla.suse.com/show_bug.cgi?id=1262494 * https://bugzilla.suse.com/show_bug.cgi?id=1262495 * https://bugzilla.suse.com/show_bug.cgi?id=1262496 * https://bugzilla.suse.com/show_bug.cgi?id=1262497 * https://bugzilla.suse.com/show_bug.cgi?id=1262500 * https://bugzilla.suse.com/show_bug.cgi?id=1267355 . Security update addresses seven issues in java-1_8_0-openjdk on SUSE, critical for system protection.. Java Security Update,SUSE Linux Server,OpenJDK Alert. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 24, 2026 Important SuSE
89

Fedora 43 SingularityCE Important Denial Of Service Fix 2026-5358fb95a0

Upgrade to 4.4.2 upstream version.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5358fb95a0 2026-06-19 01:08:57.989167+00:00 -------------------------------------------------------------------------------- Name : singularity-ce Product : Fedora 43 Version : 4.4.2 Release : 1.fc43 URL : https://www.sylabs.io/singularity/ Summary : Application and environment virtualization Description : SingularityCE is the Community Edition of Singularity, an open source container platform designed to be simple, fast, and secure. -------------------------------------------------------------------------------- Update Information: Upgrade to 4.4.2 upstream version. -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 10 2026 David Trudgian - 4.4.2-1 - Upgrade to 4.4.2 upstream version. - Fix rhbz#2453093 - Fix rhbz#2458933 - Fix rhbz#2455674 - Fix rhbz#2456379 - Fix CVE-2026-47215 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2453093 - CVE-2026-33748 singularity-ce: BuildKit: Unauthorized file access via Git URL fragment subdir components [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453093 [ 2 ] Bug #2455674 - CVE-2026-34986 singularity-ce: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455674 [ 3 ] Bug #2456379 - CVE-2026-39395 singularity-ce: Cosign: Incorrect attestation verification due to malformed payloads or mismatched predicate types [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2456379 [ 4 ] Bug #2458933 - CVE-2026-39984 singularity-ce: improper certificate validation in verifier [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2458933 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5358fb95a0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Upgrade to SingularityCE 4.4.2 for enhanced security on Fedora. This advisory fixes multiple security issues.. Fedora security advisory, Singularity update, application virtualization security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 18, 2026 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200