Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # Security update for uriparser Announcement ID: SUSE-SU-2026:22084-1 Release Date: 2026-06-05T13:44:18Z Rating: moderate References: * bsc#1255000 Cross-References: * CVE-2025-67899 CVSS scores: * CVE-2025-67899 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-67899 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-67899 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for uriparser fixes the following issue: * CVE-2025-67899: unbounded recursion and stack consumption (bsc#1255000). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-895=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-895=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * uriparser-doc-0.9.8-160000.4.1 * uriparser-debuginfo-0.9.8-160000.4.1 * uriparser-devel-0.9.8-160000.4.1 * liburiparser1-debuginfo-0.9.8-160000.4.1 * liburiparser1-0.9.8-160000.4.1 * uriparser-0.9.8-160000.4.1 * uriparser-debugsource-0.9.8-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * uriparser-doc-0.9.8-160000.4.1 * uriparser-debuginfo-0.9.8-160000.4.1 * uriparser-devel-0.9.8-160000.4.1 * liburiparser1-debuginfo-0.9.8-160000.4.1 * liburiparser1-0.9.8-160000.4.1 * uriparser-0.9.8-160000.4.1 * uriparser-debugsource-0.9.8-160000.4.1 ## References: *https://www.suse.com/security/cve/CVE-2025-67899.html * https://bugzilla.suse.com/show_bug.cgi?id=1255000 . SUSE Security Update resolves moderate security issue in uriparser. Recommended updates for affected systems.. SUSE security update, uriparser patch, moderate security issue, unbounded recursion, Linux Server. . Severity: moderate. LinuxSecurity.com Team
uriparser could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8409-1 June 09, 2026 uriparser vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: uriparser could be made to crash if it received specially crafted input. Software Description: - uriparser: Strictly RFC 3986 compliant URI parsing library Details: It was discovered that uriparser incorrectly handled certain URI strings. An attacker could possibly use this issue to cause uriparser to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS liburiparser1 0.9.7+dfsg-2ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 22.04 LTS liburiparser1 0.9.6+dfsg-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 20.04 LTS liburiparser1 0.9.3-2ubuntu0.1~esm4 Available with Ubuntu Pro Ubuntu 18.04 LTS liburiparser1 0.8.4-1+deb9u2ubuntu0.1+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS liburiparser1 0.8.4-1ubuntu0.16.04.1~esm5 Available with Ubuntu Pro Ubuntu 14.04 LTS liburiparser1 0.7.5-1ubuntu2+esm5 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8409-1 CVE-2025-67899 . Emergency update for Ubuntu addressing a critical uriparser issue that could cause crashing and denial ofservice.. Ubuntu Security, Denial of Service, uriparser Issue, System Update, RFC Compliance. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for uriparser ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20910-1 Rating: moderate References: * bsc#1255000 Cross-References: * CVE-2025-67899 CVSS scores: * CVE-2025-67899 ( SUSE ): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-67899 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for uriparser fixes the following issue: - CVE-2025-67899: unbounded recursion and stack consumption (bsc#1255000). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-895=1 Package List: - openSUSE Leap 16.0: liburiparser1-0.9.8-160000.4.1 uriparser-0.9.8-160000.4.1 uriparser-devel-0.9.8-160000.4.1 uriparser-doc-0.9.8-160000.4.1 References: * https://www.suse.com/security/cve/CVE-2025-67899.html . Update available for openSUSE addressing moderate security issue in uriparser related to stack consumption.. openSUSE, uriparser, unbounded recursion, security update. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for uriparser ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20910-1 Rating: moderate References: * bsc#1255000 Cross-References: * CVE-2025-67899 CVSS scores: * CVE-2025-67899 ( SUSE ): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-67899 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for uriparser fixes the following issue: - CVE-2025-67899: unbounded recursion and stack consumption (bsc#1255000). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-895=1 Package List: - openSUSE Leap 16.0: liburiparser1-0.9.8-160000.4.1 uriparser-0.9.8-160000.4.1 uriparser-devel-0.9.8-160000.4.1 uriparser-doc-0.9.8-160000.4.1 References: * https://www.suse.com/security/cve/CVE-2025-67899.html . Update for openSUSE fixes unbounded recursion in uriparser, providing a moderate severity patch along with a bug fix.. openSUSE update, uriparser security, unbounded recursion fix, security patch, Linux vulnerabilities. . Severity: moderate. LinuxSecurity.com Team
Update to uriparser-1.0.1.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-593d463bbf 2026-05-15 22:44:59.632843+00:00 -------------------------------------------------------------------------------- Name : uriparser Product : Fedora 42 Version : 1.0.1 Release : 1.fc42 URL : https://uriparser.github.io/ Summary : URI parsing library - RFC 3986 Description : Uriparser is a strictly RFC 3986 compliant URI parsing library written in C. uriparser is cross-platform, fast, supports Unicode and is licensed under the New BSD license. -------------------------------------------------------------------------------- Update Information: Update to uriparser-1.0.1. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 30 2026 Sandro Mani - 1.0.1-1 - Update to 1.0.1 * Sat Jan 17 2026 Fedora Release Engineering - 1.0.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2463210 - CVE-2026-42371 uriparser: uriparser: Denial of Service via numeric truncation with oversized URIs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2463210 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-593d463bbf' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to uriparser-1.0.1.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-57515ed8b1 2026-05-05 00:53:44.303273+00:00 -------------------------------------------------------------------------------- Name : uriparser Product : Fedora 44 Version : 1.0.1 Release : 1.fc44 URL : https://uriparser.github.io/ Summary : URI parsing library - RFC 3986 Description : Uriparser is a strictly RFC 3986 compliant URI parsing library written in C. uriparser is cross-platform, fast, supports Unicode and is licensed under the New BSD license. -------------------------------------------------------------------------------- Update Information: Update to uriparser-1.0.1. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 30 2026 Sandro Mani - 1.0.1-1 - Update to 1.0.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2463210 - CVE-2026-42371 uriparser: uriparser: Denial of Service via numeric truncation with oversized URIs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2463210 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-57515ed8b1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability can now be installed.. # Security update for uriparser Announcement ID: SUSE-SU-2026:0444-1 Release Date: 2026-02-11T09:59:48Z Rating: moderate References: * bsc#1255000 Cross-References: * CVE-2025-67899 CVSS scores: * CVE-2025-67899 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-67899 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-67899 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for uriparser fixes the following issues: * CVE-2025-67899: large input containing many commas can cause unbounded recursion and stack consumption (bsc#1255000). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-444=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-444=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * uriparser-0.8.5-150000.3.11.1 * uriparser-debuginfo-0.8.5-150000.3.11.1 * uriparser-devel-0.8.5-150000.3.11.1 * liburiparser1-debuginfo-0.8.5-150000.3.11.1 * uriparser-debugsource-0.8.5-150000.3.11.1 * liburiparser1-0.8.5-150000.3.11.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * uriparser-0.8.5-150000.3.11.1 * uriparser-debuginfo-0.8.5-150000.3.11.1 * uriparser-devel-0.8.5-150000.3.11.1 * liburiparser1-debuginfo-0.8.5-150000.3.11.1 * uriparser-debugsource-0.8.5-150000.3.11.1 * liburiparser1-0.8.5-150000.3.11.1 * openSUSE Leap 15.6 (x86_64) * liburiparser1-32bit-debuginfo-0.8.5-150000.3.11.1 * liburiparser1-32bit-0.8.5-150000.3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2025-67899.html * https://bugzilla.suse.com/show_bug.cgi?id=1255000 . Update for uriparser on openSUSE addresses stack consumption issue. Learn how to patch it quickly here.. openSUSE Patch Uriparser Stack Consumption Security Fix. . LinuxSecurity.com Team
Update to uriparser-1.0.0, fixes CVE-2025-67899.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-5c12420f33 2025-12-20 00:52:30.902724+00:00 -------------------------------------------------------------------------------- Name : uriparser Product : Fedora 43 Version : 1.0.0 Release : 1.fc43 URL : https://uriparser.github.io/ Summary : URI parsing library - RFC 3986 Description : Uriparser is a strictly RFC 3986 compliant URI parsing library written in C. uriparser is cross-platform, fast, supports Unicode and is licensed under the New BSD license. -------------------------------------------------------------------------------- Update Information: Update to uriparser-1.0.0, fixes CVE-2025-67899. -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 15 2025 Sandro Mani - 1.0.0-1 - Update to 1.0.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2423026 - CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2423026 [ 2 ] Bug #2423027 - CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2423027 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-5c12420f33' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.