OS: Suse
A security update for google-guest-agent addresses two vulnerabilities in SUSE Linux Micro 6.0, facilitating potential privilege escalation and an infinite loop due to improper input handling. |
A security update for helm addresses three vulnerabilities, including privilege escalation and credential exfiltration issues, with a critical CVSS score of 9.1 for one flaw. |
SUSE released an important security update for wget addressing five vulnerabilities, including potential server-side request forgery and heap buffer overflows, applicable to SUSE Linux Micro 6.0. |
SUSE released a critical update for multipath-tools, addressing significant security issues and numerous bug fixes. The update enhances system stability and compatibility with various hardware configurations. |
Exploit-DB.com
OS: Gentoo
A vulnerability in DTrace's dtprobed allows arbitrary file creation through crafted USDT provider names, posing a risk of running malicious code. Users should upgrade to version 2.0.6. |
Gentoo Linux has issued a security advisory regarding multiple vulnerabilities in FUSE, including a severe issue that may allow code execution; users should upgrade to version 3.18.1 or later. |
A high-severity vulnerability in Commons-BeanUtils allows for arbitrary code execution. Users must upgrade to version 1.11.0 or later, as no workaround exists. |
Gentoo Linux has issued a high-severity advisory for multiple vulnerabilities in Asterisk, which may allow for arbitrary code execution, urging users to upgrade to version 18.26.3. |
NIST Vulnerability Database
CVEMAP.ORG: Vulnerabilities & Exposures
OS: Debian
Debian announced security updates for OpenJDK 25 to address multiple vulnerabilities, including issues with certificate validation and denial of service, recommending users upgrade their packages. |
Debian addressed vulnerabilities in postfix, a mail transport agent, potentially causing denial of service or policy bypass. Users are advised to upgrade to version 3.10.13-0+deb13u1. |
Multiple vulnerabilities in the Caddy web server can lead to unauthorized access and other security issues; users are urged to upgrade to version 2.6.2-12+deb13u1 for protection. |
Debian has released an advisory regarding vulnerabilities in libyaml-syck-perl, advising users to upgrade to version 1.34-2+deb13u3 to mitigate potential denial of service and code execution risks. |
OS: Scientific
python: TLS handshake bypass (CVE-2023-40217) --- This content is derived from https://access.redhat.com/errata/RHSA-2023:6885 SL7 srpm python-0:2.7.5-94.el7_9.src x86_64 python-0:2.7.5-94.el7_9.x86_64 i386 python-libs-0:2.7.5-94.el7_9.i686 - Scientific Linux Development Team |
plexus-archiver: Arbitrary File Creation in AbstractUnArchiver (CVE-2023-37460) --- This content is derived from https://access.redhat.com/errata/RHSA-2023:6886 SL7 srpm plexus-archiver-0:2.4.2-6.el7_9.src noarch plexus-archiver-0:2.4.2-6.el7_9.noarch - Scientific Linux Development Team |
bind: stack exhaustion in control channel code may lead to DoS (CVE-2023-3341) --- This content is derived from https://access.redhat.com/errata/RHSA-2023:5691 SL7 srpm bind-32:9.11.4-26.P2.el7_9.15.src i386 bind-export-libs-32:9.11.4-26.P2.el7_9.15.i686 x86_64 bind-export-libs-32:9.11.4-26.P2.el7_9.15.x86_64 noarch bind-license-32:9.11.4-26.P2.el7_9.15.noarch - Scie [More...] |
libssh2: use-of-uninitialized-value in _libssh2_transport_read (CVE-2020-22218) --- This content is derived from https://sso.redhat.com/auth/realms/redhat-external/protocol/saml?SAMLRequest=fZJBT8MwDIX%2FSm85ZWk7yrZonVQxIU0ChDbgwAVlqccipUmJXTb49aQbg3Hh6jy%2F79nOFFVjW1l1tHVLeOsAKakQIZDx7so77BoIKwjvRsPj8qZkW6IWpRBKa0AcBKi3igbaN6L2O2e9qlH0nmJjnLLmE1hSEQWz7giOfsa9fhsuXA37kmUsmUdu1PfQXwSiP%2FdXMaMIoGyD4ljmsCcIESPa4Mlrbw9olizmJXvJ9WgMWmV8qMcTfpGNUq7WxZCvVTEe5dmoUJebKEXsYhAk5ahkeZoXPL3g6eQhHcqikGn2zJInCHhIlg9Sluwb61D2oJJ1wUmv0KB0qgGUpOWqur2RUSjVaY3nLe3%2FPac52Gzaq%2BUhXZh1zmwM1PxnxVNx%2Fjw9HvEu2i3m994a%2FZFU1vrdVVwXQckodPEO1z40iv4P0FdMzTcHqWz7wZHAEROzI%2FPvX5l9AQ%3D%3D&RelayState=https%3A%2F%2Faccess.redhat.com%2Ferrata%2FRHSA-2&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=BrJPc%2FvdbvszAnFEmxMHTWhWO5IJXnU8CNik001PBsM04yezeCS%2B0pETxgMIupFPsrxTbmD1oepOHhERcPL4Byk1qKkm6TtFvfXm74lB8Pui6rdjg%2B8IwVmrenuF4Ph3LD4ZnDeuNW3YO4dDbN5Q4%2F89FIjEkeGKeLLar10vtkiy8GweKEe8cuja3717pxNrVTOi8ckfBHwomdUD8Xw1IE6M1qHI4u6pOMtxqpKQPu%2FZzsAgrME854P7NQqtGaZRI3eqZlBRVyG2FYrR7KFC6QtA%2FdVCYBxBWG4JdxZhXmbM%2Fc%2Bn%2B04WEKPpbhH12qa7URkjktnYMsJNcVF7rtYtn1D6gCyPnuXrwe7qcV0MgnrfuqmW4FoGsGrjhFdp7Eebe40wh78VaLxxAxO9hR%2BrYRDgNjvtewICpUbzYQUm6jzVk3i%2FYjt5Pmr9HesI1zvaI80Jmpgud1snf1z7VWoIqnAXwIZyLlo%2BxyFZs4qDUBgFr9tqrgbnGjBgTzdyJTItq7yFMVJDCt6dy5LjnMgKSMd%2BjjsoDBjssytWMM4ulzlyQHtn4IdVgCe4q4jgLQrHXf4ZucbUIA6q%2Fxgg7favSO%2FZaivTQq%2BoaQQKJ1NXxPiMXw6j354mdaEtz8jK549xaCEZi2OiF3l8Qrzc%2B7JikRXQ8wlX1gh8SbiNHfo6ZcE%3D 023:5615 SL7 srpm libssh2-0:1.8.0-4.el7_9.1.src i386 libssh2-0:1.8.0-4.el7_9.1.i686 x86_64 libssh2-0:1.8.0-4.el7_9.1.x86_64 noarch libssh2-docs-0:1.8.0- 4.el7_9.1.noarch - Scientific Linux Development Team |
OS: Mageia
Updated bind packages for Mageia 10 address multiple security vulnerabilities, including issues with NSEC3 records, DNSSEC validation, and potential cache poisoning, as detailed by the respective CVEs. |
Updated php 8.5 packages in Mageia 10 address several security vulnerabilities, specifically CVE-2026-17544, CVE-2026-9672, CVE-2026-17543, and CVE-2026-7260. |
Mageia 10 has released updates for php 8.4 to address multiple security vulnerabilities, as identified by CVEs CVE-2026-17544, CVE-2026-9672, CVE-2026-17543, and CVE-2026-7260. |
Mageia 10 is affected by CVE-2026-48977, a vulnerability allowing arbitrary memory write through a crafted Ventana BIF file, which could pose security risks. |
OS: Arch
The package python-django before version 5.1.11-1 is vulnerable to content spoofing. |
The package konsole before version 25.04.2-1 is vulnerable to arbitrary code execution. |
The package go before version 1.24.4-1 is vulnerable to multiple issues including certificate verification bypass and information disclosure. |
The package samba before version 4.22.2-1 is vulnerable to access restriction bypass. |
OS: Fedora
Fedora 43 has released ClamAV version 1.4.6, enhancing the anti-virus toolkit with updates for proper error handling and multiple denial of service vulnerabilities. Updates are available via dnf. |
Fedora 43 has released an update for libidn, version 1.44, fixing a security issue identified as CVE-2026-57053, addressing an out-of-bounds read vulnerability. |
Fedora 44 has updated ClamAV to version 1.4.6, enhancing its anti-virus toolkit functionality and addressing multiple security vulnerabilities and errors related to UTF-8 string handling. |
Fedora 44 has released an update for libidn version 1.44, addressing a security flaw (CVE-2026-57053) related to out-of-bounds reads in ToUnicode APIs. |
OS: Redhat
Red Hat released a security update for libvpx in RHEL 8.6, fixing critical vulnerabilities including a heap buffer overflow and a crash related to VP9 encoding. |
Red Hat released a security update for BIND in RHEL 8.2, addressing a critical vulnerability (CVE-2023-3341) that may lead to DoS due to stack exhaustion. |
Red Hat released an important security update for libvpx in Red Hat Enterprise Linux 9, addressing a heap buffer overflow and a crash related to VP9 encoding. |
Red Hat released a security update for libvpx in RHEL 8.2 addressing important vulnerabilities, including a heap buffer overflow and a crash related to VP9 encoding. |
OS: Slackware
New OpenSSH packages for Slackware 15.0 and -current address security issues. Users can download updates and are advised to restart the sshd daemon after installation. |
Slackware has released updated expat packages for 15.0 and -current to address a security issue involving an out-of-bounds read and infinite loop related to Unicode handling. |
Slackware has released updated wpa_supplicant packages for version 15.0 and -current to address various security vulnerabilities, with installation instructions provided for users. |
Slackware has released new p11-kit packages for versions 15.0 and -current to address a security vulnerability related to decoding nested attributes, detailed in CVE-2026-18938. |
OS: Ubuntu
Ubuntu has patched several vulnerabilities in ImageMagick across various LTS versions, which could allow for arbitrary code execution and denial of service through specific image handling flaws. |
Ubuntu has issued security updates for systemd to address vulnerabilities that could allow local attackers to gain elevated privileges or terminate processes on specific LTS releases. |
Ubuntu 22.04 LTS received kernel updates addressing multiple vulnerabilities, including flaws in NTFS file systems and AMD processor data handling, requiring system reboot and module recompilation. |
Ubuntu's July 31, 2026, security notice details vulnerabilities in the Linux kernel affecting versions 20.04 LTS and 22.04 LTS, requiring updates and reboot after installation. |
NIST Vulnerability Database
OS: Rocky
A security update is available for resource-agents in Rocky Linux 8, addressing a vulnerability leading to Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886). |
A security update for fence-agents on Rocky Linux 8 addresses a Denial of Service vulnerability, with a CVSS base score of 7.5, ensuring safer remote power management. |
A security update for isns-utils in Rocky Linux 8 addresses a denial of service vulnerability (CVE-2026-55995), which requires immediate attention due to its important severity rating. |
A security update for vim in Rocky Linux 10 fixes multiple vulnerabilities, including command injection and arbitrary code execution issues, with related CVE scores indicating their severity. |
OS: Debian LTS
Debian LTS has issued an advisory for php7.4, addressing two vulnerabilities that could lead to denial of service and SQL injection; users are urged to upgrade to the latest version. |
Debian has released a security advisory for PHP 8.2, addressing vulnerabilities that could lead to denial of service and SQL injection. Users are urged to upgrade packages. |
A vulnerability in libgd2 could lead to denial of service or arbitrary code execution when processing malformed GIF files. Updates are available for Debian 11 and 12. |
Debian LTS Advisory DLA-4730-1 addresses multiple vulnerabilities in libyaml-syck-perl, leading to potential denial of service and arbitrary code execution; updates are available for Debian 11 and 12. |
OS: OpenSuse
A security update for erlang26 addresses 22 vulnerabilities affecting products like openSUSE Leap and SUSE Linux Enterprise Server, including risks of DoS and certificate forgery. |
A moderate security update for python3-pip addresses CVE-2026-13346, which enables the installation of files to arbitrary locations due to improper URL handling, affecting multiple SUSE products. |
A security update for python-pip addresses CVE-2026-13346, which involves improper handling of package URLs that could allow arbitrary file installations on affected SUSE products. |
SUSE announces a moderate security update for ImageMagick addressing CVE-2026-64685, a heap buffer overread vulnerability, affecting multiple SUSE and openSUSE products, with installation instructions provided. |
OS: CentOS
Upstream details at : https://access.redhat.com/errata/RHSA-2024:1498 |
Upstream details at : https://access.redhat.com/errata/RHSA-2024:1486 |
Upstream details at : https://access.redhat.com/errata/RHSA-2024:1249 |
Upstream details at : https://access.redhat.com/errata/RHSA-2024:0957 |