Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":14.29,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":4,"type":"x","order":2,"pct":57.14,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":28.57,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 9,991 articles for you...
89

Fedora 44 libwebsockets High Risk DoS Patch 2026-9921e0e415

Fedora 44 has released libwebsockets version 4.5.8, a lightweight C library for Websockets, which includes important updates and fixes for recent vulnerabilities.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9921e0e415 2026-07-27 00:54:18.641550+00:00 -------------------------------------------------------------------------------- Name : libwebsockets Product : Fedora 44 Version : 4.5.8 Release : 1.fc44 URL : http://libwebsockets.org Summary : Lightweight C library for Websockets Description : This is the libwebsockets C library for lightweight websocket clients and servers. -------------------------------------------------------------------------------- Update Information: Update to 4.5.8 -------------------------------------------------------------------------------- ChangeLog: * Sat Jul 18 2026 Peter Robinson - 4.5.8-1 - Update to 4.5.8 * Thu Jul 16 2026 Fedora Release Engineering - 4.5.7-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild * Fri Jun 12 2026 Yaakov Selkowitz - 4.5.7-3 - Rebuilt for openssl 4.0 * Thu Apr 30 2026 Dmitry Belyavskiy - 4.5.7-2 - Migrated to OpenSSL 4.0: use ASN1_STRING accessors instead of direct struct access * Wed Mar 18 2026 Peter Robinson - 4.5.7-1 - Update to 4.5.7 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452084 - libwebsockets-4.5.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=2452084 [ 2 ] Bug #2487519 - CVE-2026-10650 libwebsockets: libwebsockets: Denial of Service via SSH Protocol Handler resource consumption [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2487519 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9921e0e415' at the command line. Formore information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fedora's critical libwebsockets update addresses a denial of service threat in version 4.5.8, enhancing system security.. libwebsockets update,Fedora security,websocket library. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 26, 2026 Critical Fedora
202

openSUSE Java-17-OpenJDK Important Denial of Service Fix 2026-21440-1

openSUSE has released a security update for java-17-openjdk addressing nine vulnerabilities and includes bug fixes, with installation methods recommended through YaST online_update or zypper patch.. openSUSE security update: security update for java-17-openjdk ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21440-1 Rating: important References: * bsc#1264994 * bsc#1272223 * bsc#1272224 * bsc#1272225 * bsc#1272227 * bsc#1272228 * bsc#1272235 * bsc#1272236 * bsc#1272237 Cross-References: * CVE-2026-41254 * CVE-2026-46917 * CVE-2026-46968 * CVE-2026-47010 * CVE-2026-47021 * CVE-2026-47027 * CVE-2026-47059 * CVE-2026-47063 * CVE-2026-60147 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46917 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47063 ( SUSE ): 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-47063 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-60147 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 9 vulnerabilities and has 9 bug fixes can now be installed. Description: This update for java-17-openjdk fixes the following issues - Upgrade to upstream tag jdk-17.0.20+8 (July 2026 CPU) - CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994). - CVE-2026-46917: partial denial of service via TLS (bsc#1272223). - CVE-2026-46968: unauthorized creation, deletion or modification access to critical data (bsc#1272224). - CVE-2026-47010: unauthorized update, insert or delete access (bsc#1272225). - CVE-2026-47021: partial denial of service via multiple network protocols (bsc#1272227). - CVE-2026-47027: partial denial of service via multiple network protocols (bsc#1272228). - CVE-2026-47059: partial denial of service via multiple network protocols (bsc#1272235). - CVE-2026-47063: unauthorized creation, deletion or modification access to critical data (bsc#1272236). - CVE-2026-60147: unauthorized update, insert or delete access (bsc#1272237). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1344=1 Package List: - openSUSE Leap 16.0: java-17-openjdk-17.0.20.0-160000.1.1 java-17-openjdk-demo-17.0.20.0-160000.1.1 java-17-openjdk-devel-17.0.20.0-160000.1.1 java-17-openjdk-headless-17.0.20.0-160000.1.1 java-17-openjdk-javadoc-17.0.20.0-160000.1.1 java-17-openjdk-jmods-17.0.20.0-160000.1.1 java-17-openjdk-src-17.0.20.0-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://www.suse.com/security/cve/CVE-2026-46917.html * https://www.suse.com/security/cve/CVE-2026-46968.html * https://www.suse.com/security/cve/CVE-2026-47010.html * https://www.suse.com/security/cve/CVE-2026-47021.html * https://www.suse.com/security/cve/CVE-2026-47027.html * https://www.suse.com/security/cve/CVE-2026-47059.html * https://www.suse.com/security/cve/CVE-2026-47063.html * https://www.suse.com/security/cve/CVE-2026-60147.html . An important openSUSE advisory fixes 9 vulnerabilities in java-17-openjdk with critical updates and patch instructions.. openSUSE security update, java 17 vulnerabilities, software patching. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 26, 2026 Important OpenSUSE
202

openSUSE NGINX Important Buffer Overflow DoS Vuln 2026-21439-1

openSUSE has released a security update for nginx addressing three vulnerabilities, including authorization bypass and buffer overflows, along with four bug fixes for openSUSE Leap 16.0.. openSUSE security update: security update for nginx ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21439-1 Rating: important References: * bsc#1265228 * bsc#1267525 * bsc#1268492 * bsc#1268495 Cross-References: * CVE-2026-40460 * CVE-2026-42055 * CVE-2026-48142 CVSS scores: * CVE-2026-40460 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-40460 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42055 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48142 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has 4 bug fixes can now be installed. Description: This update for nginx fixes the following issues - CVE-2026-40460: bypass of authorization and bypass of rate limiting when NGINX is configured to use the HTTP/3 QUIC module (bsc#1265228). - CVE-2026-42055: heap-based buffer overflow in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules (bsc#1268492). - CVE-2026-48142: heap buffer over-read in the ngx_http_charset_module module (bsc#1268495). - HTTP2-BOMB denial of service (bsc#1267525). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1343=1 Package List: - openSUSE Leap 16.0: nginx-1.27.2-160000.6.1 nginx-source-1.27.2-160000.6.1 References: * https://www.suse.com/security/cve/CVE-2026-40460.html * https://www.suse.com/security/cve/CVE-2026-42055.html * https://www.suse.com/security/cve/CVE-2026-48142.html . An important openSUSE advisory addresses nginx vulnerabilities including a denial of service and buffer overflow issues.. openSUSE security update, nginx vulnerability, important patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 26, 2026 Important OpenSUSE
202

openSUSE Java Moderate 9 Vulnerabilities Advisory 2026-11363-1

An update for java-25-openjdk on openSUSE Tumbleweed fixes nine vulnerabilities, improving security posture with moderate ratings assigned to several CVEs. Users should install the updated packages.. # java-25-openjdk-25.0.4.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:11363-1 Rating: moderate Cross-References: * CVE-2026-41254 * CVE-2026-46917 * CVE-2026-46968 * CVE-2026-47010 * CVE-2026-47021 * CVE-2026-47027 * CVE-2026-47059 * CVE-2026-47063 * CVE-2026-60147 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46917 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-47063 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-60147 ( SUSE ): 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 9 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the java-25-openjdk-25.0.4.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * java-25-openjdk 25.0.4.0-1.1 * java-25-openjdk-demo 25.0.4.0-1.1 * java-25-openjdk-devel 25.0.4.0-1.1 * java-25-openjdk-headless 25.0.4.0-1.1 * java-25-openjdk-javadoc 25.0.4.0-1.1 * java-25-openjdk-jmods 25.0.4.0-1.1 * java-25-openjdk-src 25.0.4.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://www.suse.com/security/cve/CVE-2026-46917.html * https://www.suse.com/security/cve/CVE-2026-46968.html * https://www.suse.com/security/cve/CVE-2026-47010.html * https://www.suse.com/security/cve/CVE-2026-47021.html * https://www.suse.com/security/cve/CVE-2026-47027.html * https://www.suse.com/security/cve/CVE-2026-47059.html * https://www.suse.com/security/cve/CVE-2026-47063.html * https://www.suse.com/security/cve/CVE-2026-60147.html . Update available for openSUSE Java package addressing 9 vulnerabilities with moderate severity. Install now for improved security.. openSUSE vulnerabilities, Java update, moderate security threat, openSUSE Java package. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 26, 2026 moderate OpenSUSE
202

openSUSE Tumbleweed ffmpeg Moderate Vulnerability 2026-11361-1

An update for ffmpeg-7-7.1.4-5.1 in openSUSE Tumbleweed addresses a vulnerability (CVE-2026-12706) rated moderate, allowing for installation to enhance security.. # ffmpeg-7-7.1.4-5.1 on GA media Announcement ID: openSUSE-SU-2026:11361-1 Rating: moderate Cross-References: * CVE-2026-12706 CVSS scores: * CVE-2026-12706 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the ffmpeg-7-7.1.4-5.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * ffmpeg-7 7.1.4-5.1 * ffmpeg-7-libavcodec-devel 7.1.4-5.1 * ffmpeg-7-libavdevice-devel 7.1.4-5.1 * ffmpeg-7-libavfilter-devel 7.1.4-5.1 * ffmpeg-7-libavformat-devel 7.1.4-5.1 * ffmpeg-7-libavutil-devel 7.1.4-5.1 * ffmpeg-7-libpostproc-devel 7.1.4-5.1 * ffmpeg-7-libswresample-devel 7.1.4-5.1 * ffmpeg-7-libswscale-devel 7.1.4-5.1 * libavcodec61 7.1.4-5.1 * libavdevice61 7.1.4-5.1 * libavfilter10 7.1.4-5.1 * libavformat61 7.1.4-5.1 * libavutil59 7.1.4-5.1 * libpostproc58 7.1.4-5.1 * libswresample5 7.1.4-5.1 * libswscale8 7.1.4-5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12706.html . An update is available for openSUSE Tumbleweed addressing a moderate vulnerability in ffmpeg package. Install promptly.. openSUSE Tumbleweed, ffmpeg security fix, moderate vulnerability advisory. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 26, 2026 moderate OpenSUSE
202

openSUSE MozillaFirefox Security Update - 2026-11358-1 - Moderate Level

An update for MozillaFirefox-153.0-1.1 on openSUSE Tumbleweed fixes 63 vulnerabilities, enhancing security for users with various critical issues addressed.. # MozillaFirefox-153.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:11358-1 Rating: moderate Cross-References: * CVE-2026-16349 * CVE-2026-16350 * CVE-2026-16351 * CVE-2026-16352 * CVE-2026-16353 * CVE-2026-16354 * CVE-2026-16355 * CVE-2026-16356 * CVE-2026-16357 * CVE-2026-16358 * CVE-2026-16359 * CVE-2026-16360 * CVE-2026-16362 * CVE-2026-16363 * CVE-2026-16364 * CVE-2026-16365 * CVE-2026-16366 * CVE-2026-16367 * CVE-2026-16368 * CVE-2026-16369 * CVE-2026-16370 * CVE-2026-16371 * CVE-2026-16372 * CVE-2026-16373 * CVE-2026-16374 * CVE-2026-16375 * CVE-2026-16376 * CVE-2026-16377 * CVE-2026-16378 * CVE-2026-16379 * CVE-2026-16380 * CVE-2026-16381 * CVE-2026-16382 * CVE-2026-16383 * CVE-2026-16384 * CVE-2026-16385 * CVE-2026-16386 * CVE-2026-16387 * CVE-2026-16388 * CVE-2026-16389 * CVE-2026-16390 * CVE-2026-16391 * CVE-2026-16392 * CVE-2026-16393 * CVE-2026-16394 * CVE-2026-16395 * CVE-2026-16396 * CVE-2026-16397 * CVE-2026-16398 * CVE-2026-16399 * CVE-2026-16400 * CVE-2026-16401 * CVE-2026-16402 * CVE-2026-16403 * CVE-2026-16404 * CVE-2026-16405 * CVE-2026-16406 * CVE-2026-16407 * CVE-2026-16408 * CVE-2026-16409 * CVE-2026-16410 * CVE-2026-16411 * CVE-2026-16412 Affected Products: * openSUSE Tumbleweed An update that solves 63 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the MozillaFirefox-153.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * MozillaFirefox 153.0-1.1 * MozillaFirefox-branding-upstream 153.0-1.1 * MozillaFirefox-devel 153.0-1.1 * MozillaFirefox-translations-common 153.0-1.1 * MozillaFirefox-translations-other 153.0-1.1 ## References: *https://www.suse.com/security/cve/CVE-2026-16349.html * https://www.suse.com/security/cve/CVE-2026-16350.html * https://www.suse.com/security/cve/CVE-2026-16351.html * https://www.suse.com/security/cve/CVE-2026-16352.html * https://www.suse.com/security/cve/CVE-2026-16353.html * https://www.suse.com/security/cve/CVE-2026-16354.html * https://www.suse.com/security/cve/CVE-2026-16355.html * https://www.suse.com/security/cve/CVE-2026-16356.html * https://www.suse.com/security/cve/CVE-2026-16357.html * https://www.suse.com/security/cve/CVE-2026-16358.html * https://www.suse.com/security/cve/CVE-2026-16359.html * https://www.suse.com/security/cve/CVE-2026-16360.html * https://www.suse.com/security/cve/CVE-2026-16362.html * https://www.suse.com/security/cve/CVE-2026-16363.html * https://www.suse.com/security/cve/CVE-2026-16364.html * https://www.suse.com/security/cve/CVE-2026-16365.html * https://www.suse.com/security/cve/CVE-2026-16366.html * https://www.suse.com/security/cve/CVE-2026-16367.html * https://www.suse.com/security/cve/CVE-2026-16368.html * https://www.suse.com/security/cve/CVE-2026-16369.html * https://www.suse.com/security/cve/CVE-2026-16370.html * https://www.suse.com/security/cve/CVE-2026-16371.html * https://www.suse.com/security/cve/CVE-2026-16372.html * https://www.suse.com/security/cve/CVE-2026-16373.html * https://www.suse.com/security/cve/CVE-2026-16374.html * https://www.suse.com/security/cve/CVE-2026-16375.html * https://www.suse.com/security/cve/CVE-2026-16376.html * https://www.suse.com/security/cve/CVE-2026-16377.html * https://www.suse.com/security/cve/CVE-2026-16378.html * https://www.suse.com/security/cve/CVE-2026-16379.html * https://www.suse.com/security/cve/CVE-2026-16380.html * https://www.suse.com/security/cve/CVE-2026-16381.html * https://www.suse.com/security/cve/CVE-2026-16382.html * https://www.suse.com/security/cve/CVE-2026-16383.html * https://www.suse.com/security/cve/CVE-2026-16384.html *https://www.suse.com/security/cve/CVE-2026-16385.html * https://www.suse.com/security/cve/CVE-2026-16386.html * https://www.suse.com/security/cve/CVE-2026-16387.html * https://www.suse.com/security/cve/CVE-2026-16388.html * https://www.suse.com/security/cve/CVE-2026-16389.html * https://www.suse.com/security/cve/CVE-2026-16390.html * https://www.suse.com/security/cve/CVE-2026-16391.html * https://www.suse.com/security/cve/CVE-2026-16392.html * https://www.suse.com/security/cve/CVE-2026-16393.html * https://www.suse.com/security/cve/CVE-2026-16394.html * https://www.suse.com/security/cve/CVE-2026-16395.html * https://www.suse.com/security/cve/CVE-2026-16396.html * https://www.suse.com/security/cve/CVE-2026-16397.html * https://www.suse.com/security/cve/CVE-2026-16398.html * https://www.suse.com/security/cve/CVE-2026-16399.html * https://www.suse.com/security/cve/CVE-2026-16400.html * https://www.suse.com/security/cve/CVE-2026-16401.html * https://www.suse.com/security/cve/CVE-2026-16402.html * https://www.suse.com/security/cve/CVE-2026-16403.html * https://www.suse.com/security/cve/CVE-2026-16404.html * https://www.suse.com/security/cve/CVE-2026-16405.html * https://www.suse.com/security/cve/CVE-2026-16406.html * https://www.suse.com/security/cve/CVE-2026-16407.html * https://www.suse.com/security/cve/CVE-2026-16408.html * https://www.suse.com/security/cve/CVE-2026-16409.html * https://www.suse.com/security/cve/CVE-2026-16410.html * https://www.suse.com/security/cve/CVE-2026-16411.html * https://www.suse.com/security/cve/CVE-2026-16412.html . An important security update for openSUSE addresses 63 issues in MozillaFirefox, ensuring better system protection.. openSUSE MozillaFirefox security update, moderate security advisory, Linux application vulnerabilities. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 26, 2026 moderate OpenSUSE
202

openSUSE MozillaThunderbird Moderate Security Fix 2026-11359-1

An update for MozillaThunderbird on openSUSE Tumbleweed fixes 33 vulnerabilities, enhancing security for users. The update includes multiple related packages and has a moderate severity rating.. # MozillaThunderbird-140.13.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:11359-1 Rating: moderate Cross-References: * CVE-2026-14899 * CVE-2026-15718 * CVE-2026-15719 * CVE-2026-16349 * CVE-2026-16350 * CVE-2026-16351 * CVE-2026-16352 * CVE-2026-16353 * CVE-2026-16354 * CVE-2026-16355 * CVE-2026-16356 * CVE-2026-16357 * CVE-2026-16358 * CVE-2026-16359 * CVE-2026-16360 * CVE-2026-16361 * CVE-2026-16362 * CVE-2026-16363 * CVE-2026-16368 * CVE-2026-16369 * CVE-2026-16371 * CVE-2026-16374 * CVE-2026-16375 * CVE-2026-16377 * CVE-2026-16379 * CVE-2026-16381 * CVE-2026-16383 * CVE-2026-16387 * CVE-2026-16390 * CVE-2026-16391 * CVE-2026-16396 * CVE-2026-16405 * CVE-2026-16412 Affected Products: * openSUSE Tumbleweed An update that solves 33 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the MozillaThunderbird-140.13.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * MozillaThunderbird 140.13.0-1.1 * MozillaThunderbird-openpgp-librnp 140.13.0-1.1 * MozillaThunderbird-translations-common 140.13.0-1.1 * MozillaThunderbird-translations-other 140.13.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14899.html * https://www.suse.com/security/cve/CVE-2026-15718.html * https://www.suse.com/security/cve/CVE-2026-15719.html * https://www.suse.com/security/cve/CVE-2026-16349.html * https://www.suse.com/security/cve/CVE-2026-16350.html * https://www.suse.com/security/cve/CVE-2026-16351.html * https://www.suse.com/security/cve/CVE-2026-16352.html * https://www.suse.com/security/cve/CVE-2026-16353.html * https://www.suse.com/security/cve/CVE-2026-16354.html *https://www.suse.com/security/cve/CVE-2026-16355.html * https://www.suse.com/security/cve/CVE-2026-16356.html * https://www.suse.com/security/cve/CVE-2026-16357.html * https://www.suse.com/security/cve/CVE-2026-16358.html * https://www.suse.com/security/cve/CVE-2026-16359.html * https://www.suse.com/security/cve/CVE-2026-16360.html * https://www.suse.com/security/cve/CVE-2026-16361.html * https://www.suse.com/security/cve/CVE-2026-16362.html * https://www.suse.com/security/cve/CVE-2026-16363.html * https://www.suse.com/security/cve/CVE-2026-16368.html * https://www.suse.com/security/cve/CVE-2026-16369.html * https://www.suse.com/security/cve/CVE-2026-16371.html * https://www.suse.com/security/cve/CVE-2026-16374.html * https://www.suse.com/security/cve/CVE-2026-16375.html * https://www.suse.com/security/cve/CVE-2026-16377.html * https://www.suse.com/security/cve/CVE-2026-16379.html * https://www.suse.com/security/cve/CVE-2026-16381.html * https://www.suse.com/security/cve/CVE-2026-16383.html * https://www.suse.com/security/cve/CVE-2026-16387.html * https://www.suse.com/security/cve/CVE-2026-16390.html * https://www.suse.com/security/cve/CVE-2026-16391.html * https://www.suse.com/security/cve/CVE-2026-16396.html * https://www.suse.com/security/cve/CVE-2026-16405.html * https://www.suse.com/security/cve/CVE-2026-16412.html . MozillaThunderbird 140.13.0-1.1 update resolves 33 vulnerabilities in openSUSE Tumbleweed for better security.. Mozilla Thunderbird, openSUSE, software update, email security, vulnerabilities fix. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 26, 2026 moderate OpenSUSE
202

openSUSE Tumbleweed Moderate Python313-Urwid Security Issue CVE-2026-9323

An update for the python313-urwid package on openSUSE Tumbleweed addresses a moderate security vulnerability, CVE-2026-9323, enhancing system protection.. # python313-urwid-4.0.5-1.1 on GA media Announcement ID: openSUSE-SU-2026:11356-1 Rating: moderate Cross-References: * CVE-2026-9323 CVSS scores: * CVE-2026-9323 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the python313-urwid-4.0.5-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * python313-urwid 4.0.5-1.1 * python314-urwid 4.0.5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9323.html . An update is available for openSUSE Tumbleweed that addresses the moderate risk vulnerability in python313-urwid.. openSUSE update, python313-urwid security, moderate vulnerability fix, CVE-2026-9323, Linux security advisory. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 26, 2026 moderate OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":14.29,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":4,"type":"x","order":2,"pct":57.14,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":28.57,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200