Explore top 10 tips to secure your open-source projects now. Read More
×
Security update. Publication date: 20 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0278.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-11822, CVE-2026-11824 Description: The updated packages fix security vulnerabilities: SQLite before 3.53.2 Memory Corruption in FTS5 Extension. (CVE-2026-11822) SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate. (CVE-2026-11824) References: - https://bugs.mageia.org/show_bug.cgi?id=35740 - https://lists.opensuse.org/archives/list/
Security update. Publication date: 20 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0277.html Type: security Affected Mageia releases: 10, 9 Description: The updated package fixes a security vulnerability: XML external entity vulnerability. References: https://lists.fedoraproject.org/archives/list/
Security update. Publication date: 20 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0276.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-42504, CVE-2026-42507, CVE-2026-27145, CVE-2026-39822, CVE-2026-42505 Description: The updated packages fix security vulnerabilities: mime: quadratic complexity in WordDecoder.DecodeHeader. (CVE-2026-42504) net/textproto: arbitrary input are included in errors without any escaping. (CVE-2026-42507) crypto/x509: split candidate hostname only once. (CVE-2026-27145) os: Root escape via symlink plus trailing slash. (CVE-2026-39822) crypto/tls: Encrypted Client Hello privacy leak. (CVE-2026-42505) References: - https://bugs.mageia.org/show_bug.cgi?id=35624 - https://www.openwall.com/lists/oss-security/2026/06/03/2 - https://www.openwall.com/lists/oss-security/2026/07/08/10 - https://lists.opensuse.org/archives/list/
Security update. Publication date: 20 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0275.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-41054 Description: The updated package fixes a security vulnerability: Privilege escalation via command socket. (CVE-2026-41054) References: - https://bugs.mageia.org/show_bug.cgi?id=35550 - https://www.openwall.com/lists/oss-security/2026/05/19/3 - https://www.cve.org/CVERecord?id=CVE-2026-41054 SRPMS: - 10/core/haveged-1.9.21-2.mga10 - 9/core/haveged-1.9.21-2.mga9 . Mageia security update addresses privilege escalation in haveged package, identified as CVE-2026-41054, for Mageia 9 and 10.. Mageia security update, privilege escalation, haveged patch. . Severity: Important. LinuxSecurity.com Team
Security update. Publication date: 20 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0274.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-14355 Description: The updated php packages fix a security issue: Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD. (CVE-2026-14355) References: - https://bugs.mageia.org/show_bug.cgi?id=35807 - https://www.php.net/ChangeLog-8.php#8.2.32 - https://www.cve.org/CVERecord?id=CVE-2026-14355 SRPMS: - 9/core/php-8.2.32-1.mga9 . Critical php security update addresses memory corruption issue in Mageia 9, protecting against potential exploits.. Mageia security update, php memory corruption, OpenSSL AES-WRAP-PAD, CVE-2026-14355. . Severity: Critical. LinuxSecurity.com Team
Security update. Publication date: 20 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0273.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2025-15661, CVE-2026-7598, CVE-2026-55199, CVE-2026-55200, CVE-2026-58050, CVE-2026-58051 Description: The updated packages fix security vulnerabilities: Heap Buffer Over-read via sftp_symlink() in sftp.c. (CVE-2025-15661) libssh2 userauth.c userauth_password integer overflow. (CVE-2026-7598) Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler. (CVE-2026-55199) Out-of-Bounds Write via Unchecked packet_length in transport.c. (CVE-2026-55200) Integer Overflow in publickey Subsystem Attribute Allocation. (CVE-2026-58050) Free of Uninitialized Pointer in publickey List Cleanup. (CVE-2026-58051) References: - https://bugs.mageia.org/show_bug.cgi?id=35616 - https://lists.fedoraproject.org/archives/list/
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-40894 http://linux.oracle.com/errata/ELSA-2026-40894.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: hplip-3.18.4-14.el8_10.x86_64.rpm hplip-common-3.18.4-14.el8_10.i686.rpm hplip-common-3.18.4-14.el8_10.x86_64.rpm hplip-gui-3.18.4-14.el8_10.x86_64.rpm hplip-libs-3.18.4-14.el8_10.i686.rpm hplip-libs-3.18.4-14.el8_10.x86_64.rpm libsane-hpaio-3.18.4-14.el8_10.i686.rpm libsane-hpaio-3.18.4-14.el8_10.x86_64.rpm aarch64: hplip-3.18.4-14.el8_10.aarch64.rpm hplip-common-3.18.4-14.el8_10.aarch64.rpm hplip-gui-3.18.4-14.el8_10.aarch64.rpm hplip-libs-3.18.4-14.el8_10.aarch64.rpm libsane-hpaio-3.18.4-14.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/hplip-3.18.4-14.el8_10.src.rpm Related CVEs: CVE-2026-14544 Description of changes: [3.18.4-14] - RHEL-192009 CVE-2026-14544 hplip: Incomplete Fix for CVE-2026-8631 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-39179 http://linux.oracle.com/errata/ELSA-2026-39179.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: bpftool-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-abi-stablelists-4.18.0-553.144.1.el8_10.noarch.rpm kernel-core-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-cross-headers-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-debug-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-debug-core-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-debug-devel-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-debug-modules-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-debug-modules-extra-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-devel-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-doc-4.18.0-553.144.1.el8_10.noarch.rpm kernel-headers-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-modules-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-modules-extra-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-tools-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-tools-libs-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-tools-libs-devel-4.18.0-553.144.1.el8_10.x86_64.rpm perf-4.18.0-553.144.1.el8_10.x86_64.rpm python3-perf-4.18.0-553.144.1.el8_10.x86_64.rpm aarch64: bpftool-4.18.0-553.144.1.el8_10.aarch64.rpm kernel-cross-headers-4.18.0-553.144.1.el8_10.aarch64.rpm kernel-headers-4.18.0-553.144.1.el8_10.aarch64.rpm kernel-tools-4.18.0-553.144.1.el8_10.aarch64.rpm kernel-tools-libs-4.18.0-553.144.1.el8_10.aarch64.rpm kernel-tools-libs-devel-4.18.0-553.144.1.el8_10.aarch64.rpm perf-4.18.0-553.144.1.el8_10.aarch64.rpm python3-perf-4.18.0-553.144.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/kernel-4.18.0-553.144.1.el8_10.src.rpm Related CVEs: CVE-2026-46086 CVE-2026-46116 Description of changes: [4.18.0-553.144.1] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK ModuleSigning Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64
Get the latest Linux and open source security news straight to your inbox.