Explore top 10 tips to secure your open-source projects now. Read More
×Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0272.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-14895 Description: The updated package fixes a security vulnerability: String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. (CVE-2026-14895) References: - https://bugs.mageia.org/show_bug.cgi?id=35858 - https://www.openwall.com/lists/oss-security/2026/07/07/18 - https://www.cve.org/CVERecord?id=CVE-2026-14895 SRPMS: - 10/core/perl-String-Util-1.350.0-2.1.mga10 - 9/core/perl-String-Util-1.340.0-1.1.mga9 . This update addresses a critical denial of service flaw in Perl String::Util affecting Mageia 10 and 9. Discover more.. Mageia, Perl, Denial of Service. . Severity: Critical. LinuxSecurity.com Team
Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0271.html Type: security Affected Mageia releases: 10 CVE: CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244 Description: The updated packages fix security vulnerabilities: PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20213) FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20214) 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20215) InstallShield File Format Processing Resource Exhaustion Vulnerability. (CVE-2026-20216) PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20217) ALZ Archive Processing Denial of Service Vulnerability. (CVE-2026-20243) DMG File Processing Denial of Service Vulnerability. (CVE-2026-20244) References: - https://bugs.mageia.org/show_bug.cgi?id=35841 - https://lists.fedoraproject.org/archives/list/
Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0270.html Type: security Affected Mageia releases: 10 CVE: CVE-2026-48855 Description: The updated packages fix a security vulnerability: SFTP READLINK response leaks absolute backend filesystem path when root is configured. (CVE-2026-48855) References: - https://bugs.mageia.org/show_bug.cgi?id=35839 - https://lists.fedoraproject.org/archives/list/
Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0269.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-14803 Description: The updated package fixes a security vulnerability: Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. (CVE-2026-14803) References: - https://bugs.mageia.org/show_bug.cgi?id=35835 - https://www.openwall.com/lists/oss-security/2026/07/06/2 - https://metacpan.org/release/SRI/Mojolicious-9.47/changes - https://www.cve.org/CVERecord?id=CVE-2026-14803 SRPMS: - 10/core/perl-Mojolicious-9.420.0-1.1.mga10 - 9/core/perl-Mojolicious-9.310.0-1.1.mga9 . Update for Mageia addresses critical memory exhaustion flaw in perl-Mojolicious, improving overall system safety.. Mageia security update, memory exhaustion, perl-Mojolicious, CVE-2026-14803, security advisory. . Severity: Critical. LinuxSecurity.com Team
Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0268.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-58058 Description: The updated packages fix a security vulnerability: Integer Underflow in IPv6 Extension Header Parsing. (CVE-2026-58058) References: - https://bugs.mageia.org/show_bug.cgi?id=35812 - https://lists.fedoraproject.org/archives/list/
Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0267.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-13593 Description: The updated package fixes a security vulnerability: CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. (CVE-2026-13593) References: - https://bugs.mageia.org/show_bug.cgi?id=35781 - https://www.openwall.com/lists/oss-security/2026/06/29/18 - https://lists.opensuse.org/archives/list/
Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0266.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-11625 Description: The updated package fixes a security vulnerability: Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. (CVE-2026-11625) References: - https://bugs.mageia.org/show_bug.cgi?id=35767 - https://www.openwall.com/lists/oss-security/2026/06/26/5 - https://github.com/daoswald/Bytes-Random-Secure/issues/3 - https://www.cve.org/CVERecord?id=CVE-2026-11625 SRPMS: - 10/core/perl-Bytes-Random-Secure-0.290.0-7.1.mga10 - 9/core/perl-Bytes-Random-Secure-0.290.0-6.1.mga9 . The Mageia advisory details a security fix for perl-Bytes-Random-Secure to address CVE-2026-11625, ensuring process state integrity.. Mageia security update, perl-Bytes-Random-Secure fix, process security issue. . Severity: Important. LinuxSecurity.com Team
CVE-2026-59996: Fix remote glob result of ".." causing files to be placed in unintended parent directories when scp performs remote-to-remote copy via the local host CVE-2026-60002: Fix use-after-free in cached hostkey during key re-exchange. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-c9d8542bb3 2026-07-19 05:46:37.002248+00:00 -------------------------------------------------------------------------------- Name : openssh Product : Fedora 44 Version : 10.2p1 Release : 13.fc44 URL : http://www.openssh.com/portable.html Summary : An open source implementation of SSH protocol version 2 Description : SSH (Secure SHell) is a program for logging into and executing commands on a remote machine. SSH is intended to replace rlogin and rsh, and to provide secure encrypted communications between two untrusted hosts over an insecure network. X11 connections and arbitrary TCP/IP ports can also be forwarded over the secure channel. OpenSSH is OpenBSD's version of the last free version of SSH, bringing it up to date in terms of security and features. This package includes the core files necessary for both the OpenSSH client and server. To make this package useful, you should also install openssh-clients, openssh-server, or both. -------------------------------------------------------------------------------- Update Information: CVE-2026-59996: Fix remote glob result of ".." causing files to be placed in unintended parent directories when scp performs remote-to-remote copy via the local host CVE-2026-60002: Fix use-after-free in cached hostkey during key re-exchange -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 17 2026 Zoltan Fridrich - 10.2p1-13 - CVE-2026-59996: Fix remote glob result of ".." causing files to be placed in unintended parent directories when scp performs remote-to-remote copy via the local host Resolves: rhbz#2498027 - CVE-2026-60002: Fix use-after-free in cached hostkey during key re-exchange Resolves: rhbz#2497966 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2497966 - CVE-2026-60002 openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2497966 [ 2 ] Bug #2498027 - CVE-2026-59996 openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2498027 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-c9d8542bb3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.