OS: OpenSuse
A security update for python311 addresses a vulnerability affecting multiple SUSE products. Users are encouraged to apply the patch using recommended installation methods. |
SUSE released a security update for openssl-3-livepatches addressing two vulnerabilities related to a DoS attack, affecting several SUSE products with installation instructions provided. |
SUSE has released a security update for podman addressing two vulnerabilities that could modify host filesystem and leak environment variables, impacting various SUSE Linux products. |
SUSE released an important security update for python311 addressing two vulnerabilities, with various package options available for multiple SUSE products and recommended installation methods provided. |
OS: Scientific
python: TLS handshake bypass (CVE-2023-40217) --- This content is derived from https://access.redhat.com/errata/RHSA-2023:6885 SL7 srpm python-0:2.7.5-94.el7_9.src x86_64 python-0:2.7.5-94.el7_9.x86_64 i386 python-libs-0:2.7.5-94.el7_9.i686 - Scientific Linux Development Team |
plexus-archiver: Arbitrary File Creation in AbstractUnArchiver (CVE-2023-37460) --- This content is derived from https://access.redhat.com/errata/RHSA-2023:6886 SL7 srpm plexus-archiver-0:2.4.2-6.el7_9.src noarch plexus-archiver-0:2.4.2-6.el7_9.noarch - Scientific Linux Development Team |
bind: stack exhaustion in control channel code may lead to DoS (CVE-2023-3341) --- This content is derived from https://access.redhat.com/errata/RHSA-2023:5691 SL7 srpm bind-32:9.11.4-26.P2.el7_9.15.src i386 bind-export-libs-32:9.11.4-26.P2.el7_9.15.i686 x86_64 bind-export-libs-32:9.11.4-26.P2.el7_9.15.x86_64 noarch bind-license-32:9.11.4-26.P2.el7_9.15.noarch - Scie [More...] |
libssh2: use-of-uninitialized-value in _libssh2_transport_read (CVE-2020-22218) --- This content is derived from https://sso.redhat.com/auth/realms/redhat-external/protocol/saml?SAMLRequest=fZJBT8MwDIX%2FSm85ZWk7yrZonVQxIU0ChDbgwAVlqccipUmJXTb49aQbg3Hh6jy%2F79nOFFVjW1l1tHVLeOsAKakQIZDx7so77BoIKwjvRsPj8qZkW6IWpRBKa0AcBKi3igbaN6L2O2e9qlH0nmJjnLLmE1hSEQWz7giOfsa9fhsuXA37kmUsmUdu1PfQXwSiP%2FdXMaMIoGyD4ljmsCcIESPa4Mlrbw9olizmJXvJ9WgMWmV8qMcTfpGNUq7WxZCvVTEe5dmoUJebKEXsYhAk5ahkeZoXPL3g6eQhHcqikGn2zJInCHhIlg9Sluwb61D2oJJ1wUmv0KB0qgGUpOWqur2RUSjVaY3nLe3%2FPac52Gzaq%2BUhXZh1zmwM1PxnxVNx%2Fjw9HvEu2i3m994a%2FZFU1vrdVVwXQckodPEO1z40iv4P0FdMzTcHqWz7wZHAEROzI%2FPvX5l9AQ%3D%3D&RelayState=https%3A%2F%2Faccess.redhat.com%2Ferrata%2FRHSA-2&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=BrJPc%2FvdbvszAnFEmxMHTWhWO5IJXnU8CNik001PBsM04yezeCS%2B0pETxgMIupFPsrxTbmD1oepOHhERcPL4Byk1qKkm6TtFvfXm74lB8Pui6rdjg%2B8IwVmrenuF4Ph3LD4ZnDeuNW3YO4dDbN5Q4%2F89FIjEkeGKeLLar10vtkiy8GweKEe8cuja3717pxNrVTOi8ckfBHwomdUD8Xw1IE6M1qHI4u6pOMtxqpKQPu%2FZzsAgrME854P7NQqtGaZRI3eqZlBRVyG2FYrR7KFC6QtA%2FdVCYBxBWG4JdxZhXmbM%2Fc%2Bn%2B04WEKPpbhH12qa7URkjktnYMsJNcVF7rtYtn1D6gCyPnuXrwe7qcV0MgnrfuqmW4FoGsGrjhFdp7Eebe40wh78VaLxxAxO9hR%2BrYRDgNjvtewICpUbzYQUm6jzVk3i%2FYjt5Pmr9HesI1zvaI80Jmpgud1snf1z7VWoIqnAXwIZyLlo%2BxyFZs4qDUBgFr9tqrgbnGjBgTzdyJTItq7yFMVJDCt6dy5LjnMgKSMd%2BjjsoDBjssytWMM4ulzlyQHtn4IdVgCe4q4jgLQrHXf4ZucbUIA6q%2Fxgg7favSO%2FZaivTQq%2BoaQQKJ1NXxPiMXw6j354mdaEtz8jK549xaCEZi2OiF3l8Qrzc%2B7JikRXQ8wlX1gh8SbiNHfo6ZcE%3D 023:5615 SL7 srpm libssh2-0:1.8.0-4.el7_9.1.src i386 libssh2-0:1.8.0-4.el7_9.1.i686 x86_64 libssh2-0:1.8.0-4.el7_9.1.x86_64 noarch libssh2-docs-0:1.8.0- 4.el7_9.1.noarch - Scientific Linux Development Team |
OS: Rocky
A security update for java-21-openjdk on Rocky Linux 8 addresses vulnerabilities improving resource resolving, HTTP connections, and TLS servers, with multiple CVEs cited for their impacts. |
A security update for gstreamer1-plugins-good addresses vulnerabilities affecting Rocky Linux 8, including memory growth and potential out-of-bounds errors, enhancing system protection. |
Rocky Linux 9 has released an important security update for MySQL 8.4, addressing multiple unspecified vulnerabilities, bugs, and enhancements to improve database operations and security. |
An important MySQL update for Rocky Linux 8 addresses multiple security vulnerabilities, bug fixes, and enhancements, along with a detailed Common Vulnerability Scoring System rating for each issue. |
OS: Suse
SUSE released an important security update for container-suseconnect, intended for various SUSE Linux Enterprise products, which can be installed using recommended methods like YaST or zypper. |
A security update for python311 resolves a vulnerability affecting multiple SUSE products, specifically addressing a regression in http.cookies, with installation instructions provided for various systems. |
An important security update for openssl-3-livepatches addresses two vulnerabilities, including a DoS threat against OpenSSL TLS ClientHello, affecting various SUSE products. |
A podman security update addresses two vulnerabilities affecting various SUSE products, allowing exploitation of symlinks and leaking of host environment variables, with patches available through recommended installation methods. |
CVEMAP.ORG: Vulnerabilities & Exposures
NIST Vulnerability Database
OS: Fedora
The Fedora 43 update for Mozilla Firefox to version 154.0 includes enhancements for Wayland session restoration specifically for KDE users, improving overall performance and compliance. |
Fedora has released an update for libgit2 to version 1.9.7, enhancing its C implementation of Git core methods and enabling custom application development with improved API access. |
Fedora 43 has released an update for Domoticz, version 2026.3, which includes critical security fixes for the web server and API, mandating an upgrade for users. |
The Fedora update for RoundCube Webmail version 1.6.18 addresses multiple security vulnerabilities, including SSRF bypass, injection flaws, and ensures better content validation to enhance security. |
OS: Debian LTS
Multiple security vulnerabilities in the Swift package could lead to information disclosure or denial of service, prompting an upgrade to version 2.30.1-0+deb12u2 for Debian 12. |
Debian LTS Advisory DLA-4706-2 addresses a test failure in the ruby-grape package caused by a security fix in ruby-rack, recommending an upgrade for Debian 11 bullseye users. |
Debian's update for the linux-6.12 package addresses numerous vulnerabilities that could lead to privilege escalation, denial of service, and information leaks, urging users to upgrade. |
Debian LTS advisory DLA-4744-1 addresses a vulnerability in calibre that allows malicious files to execute arbitrary Python code, with a recommended upgrade to version 6.13.0+repack-2+deb12u10. |
NIST Vulnerability Database
Exploit-DB.com
OS: Ubuntu
Ubuntu released a security update addressing multiple vulnerabilities in PostgreSQL across various versions, allowing potential arbitrary code execution and sensitive information disclosure by authenticated users. |
An update for nginx in Ubuntu addresses a regression caused by a previous security fix, reverting the change until further investigation on vulnerabilities is completed. |
Ubuntu Security Notice USN-8651-1 warns of a curl vulnerability affecting multiple Ubuntu releases, allowing sensitive information exposure. Users should update their systems to the latest package versions. |
Ubuntu Security Notice USN-8639-1 addresses multiple vulnerabilities in libpng affecting various releases, potentially allowing denial of service or arbitrary code execution. |
OS: Debian
Debian issued an advisory for Designate, revealing two vulnerabilities that may allow tenant zone manipulation, leading to denial of service or DNS hijacking. Users should upgrade packages. |
Debian released a security advisory for firefox-esr addressing multiple vulnerabilities, recommending users upgrade to version 140.14.0esr-1~deb13u1 to mitigate risks including code execution and information disclosure. |
Debian announced the fix for two vulnerabilities in the SRT UDP streaming library, which could cause denial of service or encryption bypass, in version 1.5.4-1+deb13u1. |
Debian's security advisory DSA-6449-1 warns of multiple vulnerabilities in Swift that could lead to information disclosure or authorization bypass, urging users to upgrade their software. |
OS: Gentoo
Gentoo Linux announced a high-severity advisory regarding multiple vulnerabilities in acl and attr packages, potentially allowing local privilege escalation, with affected versions requiring upgrades to mitigate risks. |
Gentoo Linux has issued a security advisory for quickjs-ng due to multiple vulnerabilities, particularly one that could allow arbitrary code execution, urging users to upgrade to version 0.12.0 or higher. |
A vulnerability in Emacs allows arbitrary code execution by tricking users into opening malicious files, prompting a recommended upgrade for affected versions to ensure security. |
Gentoo Linux has issued a high-severity security advisory regarding multiple vulnerabilities in libssh2, which could lead to remote code execution; affected users should upgrade to version 1.11.1-r2. |
OS: Redhat
Red Hat released a security update for libvpx in RHEL 8.6, fixing critical vulnerabilities including a heap buffer overflow and a crash related to VP9 encoding. |
Red Hat released a security update for BIND in RHEL 8.2, addressing a critical vulnerability (CVE-2023-3341) that may lead to DoS due to stack exhaustion. |
Red Hat released an important security update for libvpx in Red Hat Enterprise Linux 9, addressing a heap buffer overflow and a crash related to VP9 encoding. |
Red Hat released a security update for libvpx in RHEL 8.2 addressing important vulnerabilities, including a heap buffer overflow and a crash related to VP9 encoding. |
OS: CentOS
Upstream details at : https://access.redhat.com/errata/RHSA-2024:1498 |
Upstream details at : https://access.redhat.com/errata/RHSA-2024:1486 |
Upstream details at : https://access.redhat.com/errata/RHSA-2024:1249 |
Upstream details at : https://access.redhat.com/errata/RHSA-2024:0957 |
OS: Slackware
New mozilla-thunderbird packages have been released for Slackware 15.0 and -current, addressing various security issues and requiring an upgrade by users. |
New Mozilla Firefox packages for Slackware 15.0 and -current address security vulnerabilities, offering significant updates and improvements along with detailed change logs and installation instructions. |
New proftpd packages for Slackware 15.0 and -current address security issues, including a critical use-after-free bug and passive transfer settings. Updated packages are available online. |
Slackware has released updated rsync packages for version 15.0 and -current to address security issues and bugs, with various download links and MD5 signatures provided. |
OS: Mageia
The latest lsp-plugins version 1.2.34 allows compatibility with pipewire and is available for Mageia 10 as a bugfix update. |
Mageia's August 2026 update for versions 10 and 9 fixes translations, supports i686 architecture, and allows downloading backport testing packages, changing repository folders to ix86. |
A bugfix update for Mageia 10 has been released, enhancing compatibility with new versions of gig and linuxsampler. |
An update for Mageia 10 introduces new features and bugfixes from upstream, including related software versions gig, linuxsampler, and gigedit. |
OS: Arch
The package python-django before version 5.1.11-1 is vulnerable to content spoofing. |
The package konsole before version 25.04.2-1 is vulnerable to arbitrary code execution. |
The package go before version 1.24.4-1 is vulnerable to multiple issues including certificate verification bypass and information disclosure. |
The package samba before version 4.22.2-1 is vulnerable to access restriction bypass. |