Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 57 articles for you...
87

Debian Samba Critical Access Bypass Remote Code Exec Advisory DSA-6297-1

Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix, which might result in bypass of access checks, overwrite of files in unintended situations using the WORM vfs module, installing CA certificates over http without verification when auto-enrollment GPO is enabled, denial of service or remote code. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6297-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso May 26, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : samba CVE ID : CVE-2026-1933 CVE-2026-2340 CVE-2026-3012 CVE-2026-3238 CVE-2026-4408 CVE-2026-4480 Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix, which might result in bypass of access checks, overwrite of files in unintended situations using the WORM vfs module, installing CA certificates over http without verification when auto-enrollment GPO is enabled, denial of service or remote code execution. For the oldstable distribution (bookworm), these problems have been fixed in version 2:4.17.12+dfsg-0+deb12u4. For the stable distribution (trixie), these problems have been fixed in version 2:4.22.8+dfsg-0+deb13u2. We recommend that you upgrade your samba packages. For the detailed security status of samba please refer to its security tracker page at: https://security-tracker.debian.org/tracker/samba Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Several vulnerabilities in Samba may allow access bypass, remote code execution, and more on Debian systems. Urgent updates advised.. Debian Security Advisory,Samba Vulnerability, Remote Code Execution, Denial of Service, Access Bypass. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 26, 2026 Critical Debian
100

SUSE: MozillaFirefox Critical Vulnerability Resolution 2025:4199-1

* bsc#1253188 Cross-References: * CVE-2025-11708 * CVE-2025-11709 . # Security update for MozillaFirefox Announcement ID: SUSE-SU-2025:4174-1 Release Date: 2025-11-24T02:51:13Z Rating: important References: * bsc#1253188 Cross-References: * CVE-2025-11708 * CVE-2025-11709 * CVE-2025-11710 * CVE-2025-11711 * CVE-2025-11712 * CVE-2025-11713 * CVE-2025-11714 * CVE-2025-11715 * CVE-2025-13012 * CVE-2025-13013 * CVE-2025-13014 * CVE-2025-13015 * CVE-2025-13016 * CVE-2025-13017 * CVE-2025-13018 * CVE-2025-13019 * CVE-2025-13020 CVSS scores: * CVE-2025-11708 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-11709 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-11710 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-11711 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-11712 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-11713 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-11714 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-11715 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-13012 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-13012 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-13013 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-13013 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-13014 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-13014 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-13015 ( SUSE ): 3.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2025-13015 ( NVD ): 3.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2025-13016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-13016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-13017 ( SUSE ): 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-13017 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-13018 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-13018 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-13019 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-13019 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-13020 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-13020 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 17 vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issues: * Update to Firefox Extended Support Release 140.5.0 ESR (bsc#1253188) * CVE-2025-13012: Race condition in the Graphics component. * CVE-2025-13016: Incorrect boundary conditions in the JavaScript: WebAssembly component. * CVE-2025-13017: Same-origin policy bypass in the DOM: Notifications component. * CVE-2025-13018: Mitigation bypass in the DOM: Security component. * CVE-2025-13019: Same-origin policy bypass in the DOM: Workers component. * CVE-2025-13013: Mitigation bypass in the DOM: Core & HTML component. * CVE-2025-13020: Use-after-free in the WebRTC: Audio/Video component. * CVE-2025-13014: Use-after-free in the Audio/Video component. * CVE-2025-13015: Spoofing issue in Firefox. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patchSUSE-SLE-SERVER-12-SP5-LTSS-2025-4174=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-4174=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-140.5.0-112.289.1 * MozillaFirefox-debugsource-140.5.0-112.289.1 * MozillaFirefox-translations-common-140.5.0-112.289.1 * MozillaFirefox-debuginfo-140.5.0-112.289.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * MozillaFirefox-devel-140.5.0-112.289.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * MozillaFirefox-140.5.0-112.289.1 * MozillaFirefox-debugsource-140.5.0-112.289.1 * MozillaFirefox-translations-common-140.5.0-112.289.1 * MozillaFirefox-debuginfo-140.5.0-112.289.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * MozillaFirefox-devel-140.5.0-112.289.1 ## References: * https://www.suse.com/security/cve/CVE-2025-11708.html * https://www.suse.com/security/cve/CVE-2025-11709.html * https://www.suse.com/security/cve/CVE-2025-11710.html * https://www.suse.com/security/cve/CVE-2025-11711.html * https://www.suse.com/security/cve/CVE-2025-11712.html * https://www.suse.com/security/cve/CVE-2025-11713.html * https://www.suse.com/security/cve/CVE-2025-11714.html * https://www.suse.com/security/cve/CVE-2025-11715.html * https://www.suse.com/security/cve/CVE-2025-13012.html * https://www.suse.com/security/cve/CVE-2025-13013.html * https://www.suse.com/security/cve/CVE-2025-13014.html * https://www.suse.com/security/cve/CVE-2025-13015.html * https://www.suse.com/security/cve/CVE-2025-13016.html * https://www.suse.com/security/cve/CVE-2025-13017.html * https://www.suse.com/security/cve/CVE-2025-13018.html * https://www.suse.com/security/cve/CVE-2025-13019.html * https://www.suse.com/security/cve/CVE-2025-13020.html * https://bugzilla.suse.com/show_bug.cgi?id=1253188 . SUSE updatesMozillaFirefox to fix important issues including access-bypass and use-after-free vulnerabilities.. SUSE Linux MozillaFirefox security issues access-bypass patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 24, 2025 Important SuSE
89

Fedora 41 Addresses Critical Denial-of-Service Vulnerabilities in Firebird

4.0.6.3221. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-2d3009f39f 2025-10-04 01:05:50.911056+00:00 -------------------------------------------------------------------------------- Name : firebird Product : Fedora 41 Version : 4.0.6.3221 Release : 1.fc41 URL : http://www.firebirdsql.org/ Summary : SQL relational database management system Description : Firebird is a relational database offering many ANSI SQL standard features that runs on Linux, Windows, and a variety of Unix platforms. Firebird offers excellent concurrency, high performance, and powerful language support for stored procedures and triggers. It has been used in production systems, under a variety of names, since 1981. -------------------------------------------------------------------------------- Update Information: 4.0.6.3221 -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 25 2025 Gwyn Ciesla - 4.0.6.3221-1 - 4.0.6.3221 * Wed Jul 23 2025 Fedora Release Engineering - 4.0.4.3010-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Tue Feb 11 2025 Zbigniew J\u0119drzejewski-Szmek - 4.0.4.3010-7 - Add sysusers.d config file to allow rpm to create users/groups automatically * Thu Jan 16 2025 Fedora Release Engineering - 4.0.4.3010-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Wed Aug 7 2024 Miroslav Such - 4.0.4.3010-5 - convert license to SPDX -------------------------------------------------------------------------------- References: [ 1 ] Bug #2283213 - The directory /usr/share/doc/firebird is not in the RPM database. https://bugzilla.redhat.com/show_bug.cgi?id=2283213 [ 2 ] Bug #2388812 - CVE-2025-54989 firebird: Firebird Denial-of-Service Vulnerability [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2388812 [ 3 ] Bug #2388813 - CVE-2025-24975 firebird: Firebird Access Bypass [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2388813 [ 4 ] Bug #2388814 - CVE-2025-54989 firebird: Firebird Denial-of-Service Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2388814 [ 5 ] Bug #2388815 - CVE-2025-24975 firebird: Firebird Access Bypass [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2388815 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-2d3009f39f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical updates for Firebird on Fedora 41 to address important denial-of-service and access issues.. Firebird Update, Fedora 41 Security, SQL Database Management, Denial of Service, Access Bypass. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 04, 2025 Important Fedora
89

Fedora 43: Firebird Vulnerabilities in Denial of Service and Access Bypass

4.0.6.3221. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-10462d0b3e 2025-10-04 00:15:28.826324+00:00 -------------------------------------------------------------------------------- Name : firebird Product : Fedora 43 Version : 4.0.6.3221 Release : 1.fc43 URL : http://www.firebirdsql.org/ Summary : SQL relational database management system Description : Firebird is a relational database offering many ANSI SQL standard features that runs on Linux, Windows, and a variety of Unix platforms. Firebird offers excellent concurrency, high performance, and powerful language support for stored procedures and triggers. It has been used in production systems, under a variety of names, since 1981. -------------------------------------------------------------------------------- Update Information: 4.0.6.3221 -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 25 2025 Gwyn Ciesla - 4.0.6.3221-1 - 4.0.6.3221 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2283213 - The directory /usr/share/doc/firebird is not in the RPM database. https://bugzilla.redhat.com/show_bug.cgi?id=2283213 [ 2 ] Bug #2388812 - CVE-2025-54989 firebird: Firebird Denial-of-Service Vulnerability [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2388812 [ 3 ] Bug #2388813 - CVE-2025-24975 firebird: Firebird Access Bypass [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2388813 [ 4 ] Bug #2388814 - CVE-2025-54989 firebird: Firebird Denial-of-Service Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2388814 [ 5 ] Bug #2388815 - CVE-2025-24975 firebird: Firebird Access Bypass [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2388815 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-10462d0b3e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Latest Fedora advisory on firebird addressing critical DoS and access bypass issues. Update recommended for users.. firebird SQL database, Fedora 43 update, security advisory, Denial of Service, access bypass. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 04, 2025 Critical Fedora
89

Fedora 42: Firebird Important Denial of Service Advisory 2025-d24499a627

4.0.6.3221. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-d24499a627 2025-09-27 01:11:01.200149+00:00 -------------------------------------------------------------------------------- Name : firebird Product : Fedora 42 Version : 4.0.6.3221 Release : 1.fc42 URL : http://www.firebirdsql.org/ Summary : SQL relational database management system Description : Firebird is a relational database offering many ANSI SQL standard features that runs on Linux, Windows, and a variety of Unix platforms. Firebird offers excellent concurrency, high performance, and powerful language support for stored procedures and triggers. It has been used in production systems, under a variety of names, since 1981. -------------------------------------------------------------------------------- Update Information: 4.0.6.3221 -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 25 2025 Gwyn Ciesla - 4.0.6.3221-1 - 4.0.6.3221 * Wed Jul 23 2025 Fedora Release Engineering - 4.0.4.3010-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Tue Feb 11 2025 Zbigniew J\u0119drzejewski-Szmek - 4.0.4.3010-7 - Add sysusers.d config file to allow rpm to create users/groups automatically -------------------------------------------------------------------------------- References: [ 1 ] Bug #2283213 - The directory /usr/share/doc/firebird is not in the RPM database. https://bugzilla.redhat.com/show_bug.cgi?id=2283213 [ 2 ] Bug #2388812 - CVE-2025-54989 firebird: Firebird Denial-of-Service Vulnerability [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2388812 [ 3 ] Bug #2388813 - CVE-2025-24975 firebird: Firebird Access Bypass [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2388813 [ 4 ] Bug #2388814 - CVE-2025-54989 firebird: Firebird Denial-of-Service Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2388814 [ 5 ] Bug #2388815 - CVE-2025-24975 firebird: Firebird Access Bypass [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2388815 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-d24499a627' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical update for Firebird on Fedora fixes Denial-of-Service and Access Bypass. Act promptly with this advisory.. Firebird Update, Fedora 42 Advisory, SQL Database Security, Denial of Service Fix, Access Bypass Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 27, 2025 Important Fedora
198

Arch Linux: ASA-202505-8 high severity for nodejs-lts-iron DoS and bypass

The package nodejs-lts-iron before version 20.19.2-1 is vulnerable to multiple issues including denial of service and access restriction bypass. . Arch Linux Security Advisory ASA-202505-8 ========================================= Severity: High Date : 2025-05-18 CVE-ID : CVE-2025-23165 CVE-2025-23166 CVE-2025-23167 Package : nodejs-lts-iron Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-2873 Summary ======= The package nodejs-lts-iron before version 20.19.2-1 is vulnerable to multiple issues including denial of service and access restriction bypass. Resolution ========== Upgrade to 20.19.2-1. # pacman -Syu "nodejs-lts-iron> =20.19.2-1" The problems have been fixed upstream in version 20.19.2. Workaround ========== None. Description =========== - CVE-2025-23165 (denial of service) Corrupted pointer in node::fs::ReadFileUtf8(const FunctionCallbackInfo & args) when args[0] is a string. In Node.js, the ReadFileUtf8 internal binding leaks memory due to a corrupted pointer in uv_fs_s.file: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. - CVE-2025-23166 (denial of service) Improper error handling in async cryptographic operations crashes process. The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime. - CVE-2025-23167 (access restriction bypass) A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using \r\n\rX instead of the required \r\n\r\n. This inconsistency enables request smuggling, allowingattackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading llhttp to version 9, which enforces correct header termination. Impact ====== A remote attacker can exploit multiple vulnerabilities in Node.js to cause a denial of service or bypass access restrictions. Improper error handling and memory management flaws may crash the process or lead to unbounded memory usage, while an HTTP parsing inconsistency in Node.js 20.x can enable request smuggling, allowing attackers to evade proxy- based access controls and submit unauthorized requests. References ========== https://nodejs.org/en/blog/vulnerability/may-2025-security-releases https://nodejs.org/en/blog/vulnerability/may-2025-security-releases#corrupted-pointer-in-nodefsreadfileutf8const-functioncallbackinfovalue-args-when-args0-is-a-string-cve-2025-23165---low https://nodejs.org/en/blog/vulnerability/may-2025-security-releases#improper-error-handling-in-async-cryptographic-operations-crashes-process-cve-2025-23166---high https://nodejs.org/en/blog/vulnerability/may-2025-security-releases#improper-http-header-block-termination-in-llhttp-cve-2025-23167---medium https://security.archlinux.org/CVE-2025-23165 https://security.archlinux.org/CVE-2025-23166 https://security.archlinux.org/CVE-2025-23167 . The latest Arch Linux Security Advisory ASA-202505-9 outlines critical vulnerabilities found in the nodejs-lts-iron package, which could potentially result in service interruptions.. nodejs-lts-iron, Arch Linux, security advisory, denial of service, access control. . LinuxSecurity.com Team

Calendar%202 May 20, 2025 ArchLinux
198

ArchLinux: 202505-1 High: screen access bypass and privilege escalation

The package screen before version 5.0.0-3 is vulnerable to multiple issues including access restriction bypass, denial of service and privilege escalation. . Arch Linux Security Advisory ASA-202505-1 ========================================= Severity: High Date : 2025-05-13 CVE-ID : CVE-2025-23395 CVE-2025-46802 CVE-2025-46803 CVE-2025-46804 CVE-2025-46805 Package : screen Type : multiple issues Remote : No Link : https://security.archlinux.org/AVG-2862 Summary ======= The package screen before version 5.0.0-3 is vulnerable to multiple issues including access restriction bypass, denial of service and privilege escalation. Resolution ========== Upgrade to 5.0.0-3. # pacman -Syu "screen> =5.0.0-3" The problems have been fixed upstream but no release is available yet. Workaround ========== None. Description =========== - CVE-2025-23395 (privilege escalation) This issue affects Screen 5.0.0 when it runs with setuid-root privileges. The function logfile_reopen() does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with root ownership, the invoking user’s (real) group ownership and file mode 0644. All data written to the Screen PTY will be logged into this file. Also already existing files can be abused for logging in this manner: the data will be appended to the file in question, but the file mode and ownership will be left unchanged. Screen correctly drops privileges when it initially opens the logfile. The privilege escalation becomes possible as soon as Screen believes it is necessary to reopen the logfile. Screen checks this by calling stolen_logfile() before writing to the file. The call to logfile_reopen() happens when the link count of the originally opened logfile drops to zero, or if it unexpectedly changes in size. This condition can be triggered at will on the end of the unprivileged user. - CVE-2025-46802 (access restrictionbypass) This issue is found in the Attach() function when the multiattach flag is set (i.e. Screen attempts to attach to a multi-user session). The function performs a chmod() of the current TTY to mode 0666. The path to the current TTY is stored in the attach_tty string. The issue with this temporary TTY mode change is that it introduces a race condition allowing any other user in the system to open the caller’s TTY for reading and writing for a short period of time. - CVE-2025-46803 (access restriction bypass) In Screen version 5.0.0 the default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone to write to any Screen PTYs in the system. - CVE-2025-46804 (privilege escalation) This is a minor information leak when running Screen with setuid-root privileges that is found in older Screen versions, as well as in version 5.0.0. The code in screen.c starting at line 849 inspects the resulting SocketPath with root privileges, and provides error messages that allow unprivileged users to deduce information about the path that would otherwise not be available. An easy way to achieve this is by using the SCREENDIR environment variable. - CVE-2025-46805 (denial of service) In socket.c lines 646 and 882 time-of-check/time-of-use (TOCTOU) race conditions exist with regards to sending signals to user supplied PIDs in setuid-root context. The CheckPid() function drops privileges to the real user ID and tests whether the kernel allows to send a signal to the target PID using these credentials. The actual signal is sent later via Kill(), potentially using full root privileges. By this time, the PID that was previously checked could have been replaced by a different, privileged process. It might also be possible to trick the (privileged) Screen daemon process into sending signals to itself, since a process is always allowed to send signals to itself. Currently this should only allow to send SIGCONT and SIGHUPsignals, thus the impact is likely only in the area of a local denial of service or a minor integrity violation. Impact ====== A local unprivileged user is able to escalate privileges on the affected host. References ========== https://www.openwall.com/lists/oss-security/2025/05/12/1 https://security.opensuse.org/2025/05/12/screen-security-issues.html https://cgit.git.savannah.gnu.org/cgit/screen.git/commit/?id=e894caeffccdb62f9c644989a936dc7ec83cc747 https://cgit.git.savannah.gnu.org/cgit/screen.git/commit/?id=049b26b22e197ba3be9c46e5c193032e01a4724a https://cgit.git.savannah.gnu.org/cgit/screen.git/commit/?id=e0eef5aac453fa98a2664416a56c50ad1d00cb30 https://cgit.git.savannah.gnu.org/cgit/screen.git/commit/?id=161f85b98b7e1d5e4893aeed20f4cdb5e3dfaaa4 https://security.archlinux.org/CVE-2025-23395 https://security.archlinux.org/CVE-2025-46802 https://security.archlinux.org/CVE-2025-46803 https://security.archlinux.org/CVE-2025-46804 https://security.archlinux.org/CVE-2025-46805 . Debian Security Alert: Critical vulnerabilities detected in the wget software facilitating unauthorized access, service interruption, and escalation of privileges.. ArchLinux,screen,security advisory,access bypass,privilege escalation. . LinuxSecurity.com Team

Calendar%202 May 13, 2025 ArchLinux
172

Ubuntu 22.04 LTS: USN-5697-1 High: Barbican Data Exposure Risk

Barbican could be made to expose sensitive information over the network.. =========================================================================Ubuntu Security Notice USN-5697-1 October 25, 2022 barbican vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Barbican could be made to expose sensitive information over the network. Software Description: - barbican: OpenStack Key Management Service - API Server Details: Douglas Mendizabal discovered that Barbican incorrectly handled certain query strings. A remote attacker could possibly use this issue to bypass the access policy. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: python3-barbican 2:14.0.0-0ubuntu1.1 Ubuntu 20.04 LTS: python3-barbican 1:10.1.0-0ubuntu2.2 Ubuntu 18.04 LTS: python-barbican 1:6.0.1-0ubuntu1.2 In general, a standard system update will make all the necessary changes. References: CVE-2022-3100 Package Information: https://launchpad.net/ubuntu/+source/barbican/2:14.0.0-0ubuntu1.1 https://launchpad.net/ubuntu/+source/barbican/1:10.1.0-0ubuntu2.2 https://launchpad.net/ubuntu/+source/barbican/1:6.0.1-0ubuntu1.2 . A recent flaw in Barbican could lead to unauthorized access to confidential information. To safeguard your systems, ensure your Ubuntu installations are up to date.. Barbican Vulnerability, Access Policy Bypass, Ubuntu Security Notice. . LinuxSecurity.com Team

Calendar%202 Oct 25, 2022 Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200