Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update that solves 4 vulnerabilities and has 4 bug fixes can now be installed.. openSUSE security update: security update for opensc ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20967-1 Rating: low References: * bsc#1261214 * bsc#1261218 * bsc#1261219 * bsc#1261220 Cross-References: * CVE-2025-49010 * CVE-2025-66037 * CVE-2025-66038 * CVE-2025-66215 CVSS scores: * CVE-2025-49010 ( SUSE ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-49010 ( SUSE ): 1 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-66037 ( SUSE ): 3.9 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-66037 ( SUSE ): 1 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-66038 ( SUSE ): 3.9 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-66038 ( SUSE ): 1 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-66215 ( SUSE ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-66215 ( SUSE ): 1 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 4 vulnerabilities and has 4 bug fixes can now be installed. Description: This update for opensc fixes the following issues: - CVE-2025-49010: stack-buffer-overflow via crafted smart card or USB device responses (bsc#1261214). - CVE-2025-66037: crafted input can cause an out-of-bounds read (bsc#1261218). - CVE-2025-66038: improper compact-TLV length validation can lead to crash or unexpected behavior (bsc#1261219). - CVE-2025-66215: crafted smart card or USB device can cause a stack-buffer-overflow write (bsc#1261220). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap16.0 zypper in -t patch openSUSE-Leap-16.0-932=1 Package List: - openSUSE Leap 16.0: opensc-0.26.1-160000.3.1 opensc-bash-completion-0.26.1-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2025-49010.html * https://www.suse.com/security/cve/CVE-2025-66037.html * https://www.suse.com/security/cve/CVE-2025-66038.html * https://www.suse.com/security/cve/CVE-2025-66215.html . Update addresses low-risk vulnerabilities in OpenSC for openSUSE, enhancing overall system security.. openSUSE update, OpenSC vulnerabilities, security patches. . Severity: Low. LinuxSecurity.com Team
This update fixes updfstab in the presence of multiple USB plug/unplug events.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-128 2005-02-08 ---------------------------------------------------------------------Product : Fedora Core 2 Name : hotplug Version : 2004_04_01 Release : 1.1 Summary : A helper application which loads modules for USB devices. Description : The term "hotplugging" refers to the dynamic reconfiguration performed after a device has been attached to a running system. This package contains the application which is called by the kernel when a USB device is added; hotplug then loads the required modules for that device. ---------------------------------------------------------------------Update Information: This update fixes updfstab in the presence of multiple USB plug/unplug events. ---------------------------------------------------------------------* Mon Feb 07 2005 Bill Nottingham 3:2004_04_01-1.1 - run updfstab from the right place (#119140, others) ---------------------------------------------------------------------This update can be downloaded from: 50788c3ef8386139c5d745fd433707b6 SRPMS/hotplug-2004_04_01-1.1.src.rpm b0268ea71a287081b5516f874f2f0fbb x86_64/hotplug-2004_04_01-1.1.x86_64.rpm 4596b18e9f1307e525743f7ed3d4c8b2 x86_64/debug/hotplug-debuginfo-2004_04_01-1.1.x86_64.rpm 9085b428f15c1f7b3e88f127951f1aa9 i386/hotplug-2004_04_01-1.1.i386.rpm c0774f1ce2b15bbf1620e441b969dfe6 i386/debug/hotplug-debuginfo-2004_04_01-1.1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.