Collected every two hours from specialised publications — each link leads to the original article.
Here's excellent news for sysadmins. You can now use a physical security key as hardware-based two-factor authentication to securely log into a remote system v…
An integer overflow in OpenSSH might allow an attacker to execute arbitrary code.
An update for openssh is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. …
A change introduced in openssl 1.1.1d (which got released as DSA 4539-1) requires sandboxing features which are not available in Linux kernels before 3.19, res…
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
CVE-2026-59996: Fix remote glob result of ".." causing files to be placed in unintended parent directories when scp performs remote-to-remote copy via the loca…
CVE-2026-59996: Fix remote glob result of ".." causing files to be placed in unintended parent directories when scp performs remote-to-remote copy via the loca…
An update that solves two vulnerabilities and has one fix can now be installed.
An update that solves two vulnerabilities and has one fix can now be installed.
An update that solves two vulnerabilities and has one security fix can now be installed.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
An update that solves four vulnerabilities and has one security fix can now be installed.
An update that solves three vulnerabilities and has one security fix can now be installed.
Important: dovecot security update
CVE-2026-35385: Fix privilege escalation via scp legacy protocol when not in preserving file mode CVE-2026-35388: Add connection multiplexing confirmation for …
CVE-2026-35385: Fix privilege escalation via scp legacy protocol when not in preserving file mode CVE-2026-35388: Add connection multiplexing confirmation for …
CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex
CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex
CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex
Added fixes for CVE-2025-61985 and CVE-2025-61984
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: