Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Update to Samba 4.23.8 – Security fix for CVE-2026-4480, CVE-2026-2340, CVE-2026-3012, CVE-2026-1933, CVE-2026-4408, and CVE-2026-3238

libre v4.8.1 (2026-05-28) fmt/pl: add pl_strip_html() sys/fs: add getpwuid fallback for fs_gethome tls: remove unused include rsa.h ice: check source address of incoming application packets

Backport fix for CVE-2026-48710

33.0.4 Release

This update addresses a number of bugs including these security issues: Fix BOM-shift PV-corruption SIGABRT (CVE-2026-9516) Fix dupkeys_as_arrayref type confusion (CVE-2026-9334)

Backport 0.9.41 / 0.9.44 fixes for possible path traversal issues

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463

Update to version 0.11.2. Resolves CVE-2025-12474 and CVE-2026-1837. Release notes: https://github.com/libjxl/libjxl/releases/tag/v0.11.2

Changes: 6.83 2026-05-12 11:41:48Z – LWP::UserAgent now strips Authorization and Proxy-Authorization headers on cross-origin redirects (a different scheme, host, or port) to prevent credential leakage to the redirect target. Same-origin redirects retain

Automatic update for cockpit-362-1.fc43. Changelog for cockpit * Wed May 20 2026 Packit – 362-1 – Bug fixes and translation updates – Fix arbitrary code execution via specially crafted logs page link

0.094 – fix to prevent invalid characters in all headers, and prevent header smuggling (CVE-2026-7010)

Several security issues were fixed in the Linux kernel.

The system could be compromised under certain conditions.

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-6322-1

https://security-tracker.debian.org/tracker/DSA-6321-1

An update that solves 203 vulnerabilities, contains six features and has 41 security fixes can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves two vulnerabilities and contains one feature can now be installed.

An update that solves five vulnerabilities can now be installed.

How Open Source SIEM Architectures Scale Beyond Single-Server Deployments
HTTP/2 Bomb: Why Linux Infrastructure is Vulnerable to a New Low-Bandwidth DoS Attack

An update that solves 14 vulnerabilities and contains one feature can now be installed.

An update that solves five vulnerabilities and contains two features can now be installed.

An update that solves three vulnerabilities and has 12 fixes can now be installed.

Security update

Security update

The following updated rpms for have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Update to xwayland 24.1.12, security fixes for ZDI-CAN-30136, ZDI-CAN-30159, ZDI-CAN-30160, ZDI-CAN-30161, ZDI-CAN-30163, ZDI-CAN-30164, ZDI-CAN-30165, ZDI-CAN-30168

Version 1.4.5 This release contains vulnerability fixes for the following security advisories: GHSA-h842-vjwg-pxxx – Sudo-elevated arbitrary file deletion via extra.pie- installed-binary metadata in UninstallUsingUnlink GHSA-pm6p-666q-hvj5 – Sudo-elevated root code execution via TOCTOU between self-

Version 1.4.5 This release contains vulnerability fixes for the following security advisories: GHSA-h842-vjwg-pxxx – Sudo-elevated arbitrary file deletion via extra.pie- installed-binary metadata in UninstallUsingUnlink GHSA-pm6p-666q-hvj5 – Sudo-elevated root code execution via TOCTOU between self-

Release 1.6.16 Fix potential too long value in IMAP ID command (#10136) Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog Security: Fix CSS injection bypass in HTML sanitizer via SVG

Patch for CVE-2026-5119

Several security issues were fixed in Exim.

Multiple vulnerabilities were discovered in Ceph, a distributed storage and file system, which may result in privilege escalation, denial of service or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 16.2.15+ds-0+deb12u2.

An update that solves one vulnerability, contains one feature and has seven security fixes can now be installed.

An update that solves three vulnerabilities, contains one feature and has six security fixes can now be installed.

An update that solves 17 vulnerabilities, contains two features and has eight security fixes can now be installed.

An update that solves three vulnerabilities, contains one feature and has six security fixes can now be installed.

An update that solves three vulnerabilities, contains one feature and has six security fixes can now be installed.

An update that solves three vulnerabilities, contains one feature and has six security fixes can now be installed.

An update that solves three vulnerabilities, contains one feature and has six security fixes can now be installed.

An update that solves one vulnerability, contains one feature and has five security fixes can now be installed.

An update that solves one vulnerability, contains one feature and has five security fixes can now be installed.

An update that solves three vulnerabilities, contains five features and has seven security fixes can now be installed.

An update that solves three vulnerabilities, contains one feature and has six security fixes can now be installed.

An update that solves one vulnerability, contains one feature and has five security fixes can now be installed.

An update that solves one vulnerability, contains one feature and has five security fixes can now be installed.

An update that solves one vulnerability, contains one feature and has five security fixes can now be installed.

An update that solves 12 vulnerabilities and contains one feature can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

New net-tools packages are available for Slackware 15.0 and -current to fix a security issue.

New tigervnc packages are available for Slackware 15.0 and -current to fix security issues.

New xorg-server packages are available for Slackware 15.0 and -current to fix security issues.

New proftpd packages are available for Slackware 15.0 and -current to fix a security issue.

New httpd packages are available for Slackware 15.0 and -current to fix a security issue.

A regression was fixed in pip.

GStreamer Base Plugins could be made to crash or run programs if it opened a specially crafted file.

Several security issues were fixed in MySQL.

Several security issues were fixed in nginx.

How to Detect Unauthorized SSH Keys on Linux Systems
Compromised VS Code Extension Puts Linux Development Pipelines at Risk
How to Back Up Proxmox VMs on Linux: A Practical Guide

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Update to 3.26.4, fixes CVE-2026-8631, CVE-2026-8632

4.3.4 / 2026-05-24 Resolve security advisory CVE-2026-48099

Update to xserver 21.1.23, security fixes for: ZDI-CAN-30136, ZDI-CAN-30159, ZDI-CAN-30160, ZDI-CAN-30161, ZDI-CAN-30163, ZDI-CAN-30164, ZDI-CAN-30165, ZDI-CAN-30168

4.3.4 / 2026-05-24 Resolve security advisory CVE-2026-48099

Release 1.7.1 Enigma: Support automatic public key lookup (import) using HKP v1 protocol (#5314) Managesieve: Fix error when a mail message contains duplicate List-Id header (#10186)

Several security issues were fixed in Unbound.

# Security update for xorg-x11-server Announcement ID: SUSE-SU-2026:2221-1 Release Date: 2026-06-02T08:40:04Z Rating: important References:

An update that solves three vulnerabilities and has five security fixes can now be installed.

# Security update for xorg-x11-server Announcement ID: SUSE-SU-2026:2223-1 Release Date: 2026-06-02T08:41:31Z Rating: important References:

# Security update for xorg-x11-server Announcement ID: SUSE-SU-2026:2224-1 Release Date: 2026-06-02T08:41:58Z Rating: important References:

# Security update for xorg-x11-server Announcement ID: SUSE-SU-2026:2225-1 Release Date: 2026-06-02T08:42:21Z Rating: important References:

# Security update for xorg-x11-server Announcement ID: SUSE-SU-2026:2226-1 Release Date: 2026-06-02T08:42:33Z Rating: important References: