Open Source Development

Power Open Source Development

Explore the open source tools and capabilities for building and deploying modern applications on IBM Power platforms including AIX, IBM i, and Linux.


#Power


#Power


#Servers
#Opensource
 View Only
  • 1.  Multiple security vulnerability fix

    Posted 5 days ago

    Hello,
    Our security department has issued several security alerts for the following products:
    a.) vim < 9.2.1090
    b.) PCRE (Perl Compatible Regular Expressions) 2 < 10.48 (CVE-2026-86145, CVE-2026-89156, CVE-2026-89157, CVE-2026-89158, CVE-2026-89160,
    CVE-2026-89161, CVE-2026-89162 )
    c.)  binutils < 2.47 (CVE-2026-90801, CVE-2026-90802, CVE-2026-90803, CVE-2026-90804, CVE-2026-90828,
    CVE-2026-90829, CVE-2026-90830, CVE-2026-90831, CVE-2026-91779, CVE-2026-91780)
    d.) libxml (CVE-2026-76781)
    e.) NGINX Open Source < 1.31.6 (CVE-2026-90439 )

    Will updates be made available for these products soon?
    Regards



    ------------------------------
    Stefan Martin
    ------------------------------


  • 2.  RE: Multiple security vulnerability fix

    Posted 3 days ago

    good morning,

    we got the next security warning for sudo with CVE-2026-96512. Will there be a new version?



    ------------------------------
    Stefan Martin
    ------------------------------



  • 3.  RE: Multiple security vulnerability fix

    Posted 14 hours ago

    Hi Stefan!

    As far as I know there is not yet an official fix for CVE-2026-96512.

    It also only affects sudo privileges which assign notbefore and/or notafter timestamps.  In my experience not very common ;)  It is also very easy to check.

    If it is used it can also be mitigated by ensuring the assigned timestamps are ending in the letter "Z" so the interpretation of the timestamp can not be influenced by the user.

    See https://access.redhat.com/security/cve/cve-2026-96512 for details.

    Hope that helps,

      Alexander



    ------------------------------
    Alexander Reichle-Schmehl
    ------------------------------