|
|
Log in / Subscribe / Register

Mageia alert MGASA-2026-0227 (sslh)

From:  Mageia Updates <updates-announce@ml.mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2026-0227: Updated sslh packages fix security vulnerabilities
Date:  Tue, 23 Jun 2026 08:05:28 +0200
Message-ID:  <20260623060528.97970A0E3C@duvel.mageia.org>
Archive-link:  Article

MGASA-2026-0227 - Updated sslh packages fix security vulnerabilities Publication date: 23 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0227.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-46806, CVE-2025-46807, CVE-2025-52936 Description: CVE-2025-46806, A Use of Out-of-range Pointer Offset vulnerability in sslh leads to denial of service on some architectures CVE-2025-46807, A Allocation of Resources Without Limits or Throttling vulnerability in sslh allows attackers to easily exhaust the file descriptors in sslh and deny legitimate users service. CVE-2025-52936, Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh References: - https://bugs.mageia.org/show_bug.cgi?id=34345 - https://lists.opensuse.org/archives/list/security-announc... - https://www.openwall.com/lists/oss-security/2025/06/13/1 - https://ubuntu.com/security/notices/USN-8360-1 - https://www.cve.org/CVERecord?id=CVE-2025-46806 - https://www.cve.org/CVERecord?id=CVE-2025-46807 - https://www.cve.org/CVERecord?id=CVE-2025-52936 SRPMS: - 9/core/sslh-2.3.1-1.1.mga9


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds