Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Fedora 44 has released an update for .NET 10.0, improving the SDK and runtime while addressing multiple security vulnerabilities, enhancing performance for cross-platform application development.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-f738966fc9 2026-07-25 00:54:36.250213+00:00 -------------------------------------------------------------------------------- Name : dotnet10.0 Product : Fedora 44 Version : 10.0.110 Release : 1.fc44 URL : https://github.com/dotnet/ Summary : .NET 10.0 Runtime and SDK Description : .NET is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything. -------------------------------------------------------------------------------- Update Information: Update to .NET SDK 10.0.110 and Runtime 10.0.10 Fixes: CVE-2026-47300,CVE-2026-47302,CVE-2026-47303,CVE-2026-47304,CVE-2026- 50524,CVE-2026-50525,CVE-2026-50526,CVE-2026-50527,CVE-2026-50528,CVE-2026- 50646,CVE-2026-50648,CVE-2026-50649,CVE-2026-50650,CVE-2026-50651,CVE-2026- 50659,CVE-2026-56158,CVE-2026-57108 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.10/10.0.110.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.10/10.0.10.md -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 14 2026 Omair Majid - 10.0.110-1 - Update to .NET SDK 10.0.110 and Runtime 10.0.10 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2026-f738966fc9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fedora has released an update for Netatalk version 4.5.1, introducing security fixes and improvements to the Apple Filing Protocol file server software and its utilities.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d085110cf3 2026-07-25 00:54:36.250211+00:00 -------------------------------------------------------------------------------- Name : netatalk Product : Fedora 44 Version : 4.5.1 Release : 1.fc44 URL : http://netatalk.sourceforge.net Summary : Open Source Apple Filing Protocol(AFP) File Server Description : Netatalk is a freely-available Open Source AFP file server. A *NIX/*BSD system running Netatalk is capable of serving many Macintosh clients simultaneously as an AppleShare file server (AFP). In addition to the AFP file server daemon, the following utility programs are also included: * ad - AppleDouble file utility suite * afpldaptest - validate Netatalk LDAP parameters * afppasswd - RandNum UAM password management * afpstats - inquire AFP server usage stats * asip-status - inquire AFP server capabilities * dbd - CNID database maintenance -------------------------------------------------------------------------------- Update Information: 4.5.1 Release -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 16 2026 Andrew Bauer - 5:4.5.1-1 - 4.5.1 release * Thu Jul 16 2026 Fedora Release Engineering - 5:4.4.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild * Fri Jun 12 2026 Yaakov Selkowitz - 5:4.4.3-2 - Rebuilt for openssl 4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2480442 - CVE-2026-44071 netatalk: Netatalk: Denial of Service due to missing buffer overflow detection [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480442 [ 2 ] Bug #2480443 - CVE-2026-44074netatalk: Netatalk: Service disruption due to incorrect error handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480443 [ 3 ] Bug #2480445 - CVE-2026-7837 netatalk: Netatalk: Limited data modification due to TOCTOU condition [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480445 [ 4 ] Bug #2480448 - CVE-2026-44075 netatalk: Netatalk: Minor service disruption via crafted DSI session options [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480448 [ 5 ] Bug #2480460 - CVE-2026-44059 netatalk: Netatalk: Privilege bypass due to non-reentrant privilege toggle [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480460 [ 6 ] Bug #2480463 - CVE-2026-7836 netatalk: Netatalk: Integrity impact due to hextoint macro uppercase bug [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480463 [ 7 ] Bug #2480464 - CVE-2026-44061 netatalk: Netatalk: Information disclosure via DES-ECB authentication timing side channel [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480464 [ 8 ] Bug #2480466 - CVE-2026-44069 netatalk: Netatalk: Integer underflow vulnerability in volxlate function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480466 [ 9 ] Bug #2480469 - CVE-2026-44073 netatalk: Netatalk: Security bypass due to ignored seteuid failure in authentication modules [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480469 [ 10 ] Bug #2480475 - CVE-2026-44072 netatalk: Netatalk: Low impact to integrity and availability via unintended command execution after failed directory change [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480475 [ 11 ] Bug #2480477 - CVE-2026-44067 netatalk: Netatalk: Information disclosure or denial of service via heap over-read [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480477 [ 12 ] Bug #2480482 - CVE-2026-44056 netatalk: Netatalk: Denial of Service via stack buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480482 [ 13 ] Bug #2480492 - CVE-2026-44070 netatalk: Netatalk: Denial of Service via unbounded realloc in charset conversion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480492 [ 14 ] Bug #2480495 - CVE-2026-44053 netatalk: Netatalk: Data compromise due to weak cryptography [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480495 [ 15 ] Bug #2480500 - CVE-2026-7835 netatalk: Netatalk: Denial of Service via format string argument mismatch [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480500 [ 16 ] Bug #2480504 - CVE-2026-44063 netatalk: Netatalk: Information disclosure and data modification via LDAP filter injection [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480504 [ 17 ] Bug #2480630 - CVE-2026-44065 netatalk: off-by-two in papd lp_write() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480630 [ 18 ] Bug #2480632 - CVE-2026-44058 netatalk: authentication bypass via admin auth user [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2480632 [ 19 ] Bug #2483525 - netatalk-4.5.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2483525 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d085110cf3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update for Mageia 9 patches python-zstandard to support the newer libzstd version 1.5.7, addressing compatibility issues from a previous update that only supported version 1.5.5.. Publication date: 25 Jul 2026 URL: https://advisories.mageia.org/MGAA-2026-0066.html Type: bugfix Affected Mageia releases: 9 Description: The previous update was released with the use of the shared library libzstd1, which is now at version 1.5.7 in Mageia 9. However, python-zstandard supported only version 1.5.5. This update patches python-zstandard to use libzstd version 1.5.7. References: - https://bugs.mageia.org/show_bug.cgi?id=35946 SRPMS: - 9/core/python-zstandard-0.21.0-1.3.mga9 . A security fix for python-zstandard in Mageia 9 ensures compatibility with the latest libzstd version.. python-zstandard update,mageia security patch,libzstd compatibility. . Severity: Important. LinuxSecurity.com Team
An update for suricata packages resolves an issue causing the server not to start in Mageia 9 and 10, correcting the bug in both releases.. Publication date: 25 Jul 2026 URL: https://advisories.mageia.org/MGAA-2026-0065.html Type: bugfix Affected Mageia releases: 10, 9 Description: The suricata server did not start in Mageia 9 and Mageia 10. The updated suricata packages fix the issue. References: - https://bugs.mageia.org/show_bug.cgi?id=35737 SRPMS: - 10/core/suricata-7.0.10-3.2.mga10 - 9/core/suricata-7.0.10-1.2.mga9 . An important security update that fixes the suricata server startup issue in Mageia 9 and 10 releases.. Mageia, Suricata, Security Update, Bugfix, Software Fix. . Severity: bugfix. LinuxSecurity.com Team
Debian Security Advisory DSA-6400-1 addressed two vulnerabilities in Exim that could lead to privilege escalation for local attackers, recommending an upgrade to version 4.98.2-1+deb13u4.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6400-1
Mageia has released updates for versions 10 and 9 addressing multiple security vulnerabilities, identified by several CVEs, to enhance system protection and reliability.. Publication date: 24 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0294.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-63379, CVE-2026-63381, CVE-2026-63382, CVE-2026-63382, CVE-2026-63383, CVE-2026-63384, CVE-2026-63385, CVE-2026-63387, CVE-2026-63388 Description: The updated packages fix some security vulnerabilities. References: - https://bugs.mageia.org/show_bug.cgi?id=35801 - https://www.openwall.com/lists/oss-security/2026/07/01/8 - https://www.cve.org/CVERecord?id=CVE-2026-63379 - https://www.cve.org/CVERecord?id=CVE-2026-63381 - https://www.cve.org/CVERecord?id=CVE-2026-63382 - https://www.cve.org/CVERecord?id=CVE-2026-63382 - https://www.cve.org/CVERecord?id=CVE-2026-63383 - https://www.cve.org/CVERecord?id=CVE-2026-63384 - https://www.cve.org/CVERecord?id=CVE-2026-63385 - https://www.cve.org/CVERecord?id=CVE-2026-63387 - https://www.cve.org/CVERecord?id=CVE-2026-63388 SRPMS: - 10/core/libevent-2.1.13-1.mga10 - 9/core/libevent-2.1.13-1.mga9 . Security update for Mageia addressing multiple vulnerabilities in libevent, critical for system security and integrity.. Mageia libevent update, libevent security issues, Mageia vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Mageia 10 users are advised to update to Transmission 4.1.3 to address a clickjacking vulnerability in the WebUI and RPC response paths, identified as CVE-2026-38978.. Publication date: 24 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0293.html Type: security Affected Mageia releases: 10 CVE: CVE-2026-38978 Description: The updated packages fix a security vulnerability: Transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths. (CVE-2026-38978) References: - https://bugs.mageia.org/show_bug.cgi?id=35638 - https://lists.fedoraproject.org/archives/list/
openSUSE has released a security update for perl-XML-Bare addressing two vulnerabilities that could lead to parsing issues and crashes, applicable to openSUSE Leap 16.0.. openSUSE security update: security update for perl-xml-bare ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21435-1 Rating: moderate References: * bsc#1271637 * bsc#1271640 Cross-References: * CVE-2026-13401 * CVE-2026-57074 CVSS scores: * CVE-2026-13401 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-57074 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for perl-XML-Bare fixes the following issues: Changes in perl-XML-Bare: - CVE-2026-13401: XML:Bare would hang when parsing malformed attributes (bsc#1271640) - CVE-2026-57074: Fixed unbounded character lookahead (bsc#1271637) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-438=1 Package List: - openSUSE Leap 16.0: perl-XML-Bare-0.53-bp160.2.1 References: * https://www.suse.com/security/cve/CVE-2026-13401.html * https://www.suse.com/security/cve/CVE-2026-57074.html . This update for openSUSE addresses moderate vulnerabilities in perl-XML-Bare that can cause significant issues.. opensuse update, perl-XML-Bare, security advisory, moderate severity, bug fixes. . Severity: moderate. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.