Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
89

Fedora 40 iwd 2.16 Critical Update for Access Point Issues

iwd 2.16: Fix issue with uninitialized variable and DPP encrypt. Fix issue with Access Point mode and ATTR_MAC validation. Fix issue with Access Point mode and frequency attributes. Fix issue with P2P and handling client info description.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-3fa713f2e0 2024-03-23 00:20:56.399522 -------------------------------------------------------------------------------- Name : iwd Product : Fedora 40 Version : 2.16 Release : 1.fc40 URL : https://archive.kernel.org/oldwiki/iwd.wiki.kernel.org/ Summary : Wireless daemon for Linux Description : The daemon and utilities for controlling and configuring the Wi-Fi network hardware. -------------------------------------------------------------------------------- Update Information: iwd 2.16: Fix issue with uninitialized variable and DPP encrypt. Fix issue with Access Point mode and ATTR_MAC validation. Fix issue with Access Point mode and frequency attributes. Fix issue with P2P and handling client info description. Fix issue with P2P and handling parsing of service info. Fix issue with netconfig and handling domain list. Add support for forcing a default ECC group. -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 7 2024 Peter Robinson - 2.16-1 - Update to 2.16 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2263573 - iwd-2.15 is available https://bugzilla.redhat.com/show_bug.cgi?id=2263573 [ 2 ] Bug #2264597 - TRIAGE CVE-2023-52161 iwd: potential authorization bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2264597 [ 3 ] Bug #2267652 - iwd-2.16 is available https://bugzilla.redhat.com/show_bug.cgi?id=2267652 [ 4 ] Bug #2267710 - CVE-2024-28084 iwd: denial of service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2267710 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-3fa713f2e0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The iwd 2.16 upgrade resolves multiple concerns, improving both security and performance for users on Fedora. Discover additional details.. iwd Update, Wireless Daemon Fixes, Fedora Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 23, 2024 Critical Fedora
87

Debian: DSA-5631-1 Critical: iwd Access Point Security Flaw

It was discovered that iwd, the iNet Wireless Daemon, does not properly handle messages in the 4-way handshake used when connecting to a protected WiFi network for the first time. An attacker can take advantage of this flaw to gain unauthorized access to a protected WiFi . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5631-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso February 25, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : iwd CVE ID : CVE-2023-52161 Debian Bug : 1064062 It was discovered that iwd, the iNet Wireless Daemon, does not properly handle messages in the 4-way handshake used when connecting to a protected WiFi network for the first time. An attacker can take advantage of this flaw to gain unauthorized access to a protected WiFi network if iwd is operating in Access Point (AP) mode. For the oldstable distribution (bullseye), this problem has been fixed in version 1.14-3+deb11u1. For the stable distribution (bookworm), this problem has been fixed in version 2.3-1+deb12u1. We recommend that you upgrade your iwd packages. For the detailed security status of iwd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/iwd Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-5632-1 concerning iwd details a weakness in WiFi handshake processes.. iwd Security Update, Debian Access Point, Wireless Daemon, Security Issues, iNet Wireless. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 25, 2024 Critical Debian
172

Ubuntu 0063-1 Critical Advisory: Kernel DoS Risks and Fixes

Several security issues were fixed in the kernel.. =========================================================================Kernel Live Patch Security Notice 0063-1 February 19, 2020 linux vulnerability ========================================================================= A security issue affects these releases of Ubuntu: | Series | Base kernel | Arch | flavors | |------------------+--------------+----------+------------------| | Ubuntu 18.04 LTS | 4.15.0 | amd64 | aws | | Ubuntu 18.04 LTS | 4.15.0 | amd64 | generic | | Ubuntu 18.04 LTS | 4.15.0 | amd64 | lowlatency | | Ubuntu 18.04 LTS | 4.15.0 | amd64 | oem | | Ubuntu 18.04 LTS | 5.0.0 | amd64 | azure | | Ubuntu 18.04 LTS | 5.0.0 | amd64 | gcp | | Ubuntu 14.04 LTS | 4.4.0 | amd64 | generic | | Ubuntu 14.04 LTS | 4.4.0 | amd64 | lowlatency | | Ubuntu 16.04 LTS | 4.4.0 | amd64 | aws | | Ubuntu 16.04 LTS | 4.4.0 | amd64 | generic | | Ubuntu 16.04 LTS | 4.4.0 | amd64 | lowlatency | | Ubuntu 16.04 LTS | 4.15.0 | amd64 | azure | | Ubuntu 16.04 LTS | 4.15.0 | amd64 | generic | | Ubuntu 16.04 LTS | 4.15.0 | amd64 | lowlatency | Summary: Several security issues were fixed in the kernel. Software Description: - linux: Linux kernel Details: Mitchell Frank discovered that the Wi-Fi implementation in the Linux kernel when used as an access point would send IAPP location updates for stations before client authentication had completed. A physically proximate attacker could use this to cause a denial of service. (CVE-2019-5108) It was discovered that the Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors. A local attacker could use this to expose sensitive information. (CVE-2019-14615) It was discovered that thecrypto subsystem in the Linux kernel did not properly deallocate memory in certain error conditions. A local attacker could use this to cause a denial of service (kernel memory exhaustion). (CVE-2019-19050) It was discovered that the Datagram Congestion Control Protocol (DCCP) implementation in the Linux kernel did not properly deallocate memory in certain error conditions. An attacker could possibly use this to cause a denial of service (kernel memory exhaustion). (CVE-2019-20096) It was discovered that a race condition can lead to a use-after-free while destroying GEM contexts in the i915 driver for the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-7053) Update instructions: The problem can be corrected by updating your livepatches to the following versions: | Kernel | Version | flavors | |--------------------------+----------+--------------------------| | 4.4.0-168.197 | 63.1 | generic, lowlatency | | 4.4.0-168.197~14.04.1 | 63.1 | lowlatency, generic | | 4.4.0-169.198 | 63.1 | generic, lowlatency | | 4.4.0-169.198~14.04.1 | 63.1 | lowlatency, generic | | 4.4.0-170.199 | 63.1 | lowlatency, generic | | 4.4.0-170.199~14.04.1 | 63.1 | lowlatency, generic | | 4.4.0-171.200 | 63.1 | lowlatency, generic | | 4.4.0-171.200~14.04.1 | 63.1 | generic, lowlatency | | 4.4.0-173.203 | 63.1 | generic, lowlatency | | 4.4.0-1098.109 | 63.1 | aws | | 4.4.0-1099.110 | 63.1 | aws | | 4.4.0-1100.111 | 63.1 | aws | | 4.4.0-1101.112 | 63.1 | aws | | 4.15.0-69.78 | 63.1 | generic, lowlatency | | 4.15.0-69.78~16.04.1 | 63.1 | lowlatency, generic | | 4.15.0-70.79 | 63.1 |lowlatency, generic | | 4.15.0-70.79~16.04.1 | 63.1 | generic, lowlatency | | 4.15.0-72.81 | 63.1 | generic, lowlatency | | 4.15.0-72.81~16.04.1 | 63.1 | generic, lowlatency | | 4.15.0-74.83~16.04.1 | 63.1 | lowlatency, generic | | 4.15.0-74.84 | 63.1 | generic, lowlatency | | 4.15.0-76.86 | 63.1 | generic, lowlatency | | 4.15.0-76.86~16.04.1 | 63.1 | lowlatency, generic | | 4.15.0-1054.56 | 63.1 | aws | | 4.15.0-1056.58 | 63.1 | aws | | 4.15.0-1057.59 | 63.1 | aws | | 4.15.0-1058.60 | 63.1 | aws | | 4.15.0-1063.68 | 63.1 | azure | | 4.15.0-1063.72 | 63.1 | oem | | 4.15.0-1064.69 | 63.1 | azure | | 4.15.0-1064.73 | 63.1 | oem | | 4.15.0-1065.75 | 63.1 | oem | | 4.15.0-1066.71 | 63.1 | azure | | 4.15.0-1066.76 | 63.1 | oem | | 4.15.0-1067.72 | 63.1 | azure | | 4.15.0-1067.77 | 63.1 | oem | | 5.0.0-1025.26~18.04.1 | 63.1 | gcp | | 5.0.0-1025.27~18.04.1 | 63.1 | azure | | 5.0.0-1026.27~18.04.1 | 63.1 | gcp | | 5.0.0-1027.29~18.04.1 | 63.1 | azure | | 5.0.0-1028.29~18.04.1 | 63.1 | gcp | | 5.0.0-1028.30~18.04.1 | 63.1 | azure | | 5.0.0-1029.30~18.04.1 | 63.1 | gcp | | 5.0.0-1029.31~18.04.1 | 63.1 | azure | Support Information: Kernels older than the levels listed below do not receive livepatch updates. Please upgrade your kernel as soon aspossible. | Series | Version | Flavors | |------------------+------------------+--------------------------| | Ubuntu 18.04 LTS | 4.15.0-1054 | aws | | Ubuntu 16.04 LTS | 4.4.0-1098 | aws | | Ubuntu 18.04 LTS | 5.0.0-1025 | azure | | Ubuntu 16.04 LTS | 4.15.0-1063 | azure | | Ubuntu 18.04 LTS | 4.15.0-69 | generic lowlatency | | Ubuntu 18.04 LTS | 5.0.0-1025 | gcp | | Ubuntu 16.04 LTS | 4.15.0-69 | generic lowlatency | | Ubuntu 14.04 LTS | 4.4.0-168 | generic lowlatency | | Ubuntu 18.04 LTS | 4.15.0-1063 | oem | | Ubuntu 16.04 LTS | 4.4.0-168 | generic lowlatency | References: CVE-2019-5108, CVE-2019-14615, CVE-2019-19050, CVE-2019-20096, CVE-2020-7053 -- ubuntu-security-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce . Investigate the Ubuntu 0063-1 notice which outlines essential kernel patches addressing serious security vulnerabilities affecting multiple versions.. Kernel Security Update, Ubuntu Release, DoS Issues, Data Exposure Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 19, 2020 Critical Ubuntu
89

Fedora 26: Hostapd Security Advisory with KRACK Patches Applied

Latest hostapd release with KRACK patches applied.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-45044b6b33 2017-11-15 19:03:16.426489 --------------------------------------------------------------------------------Name : hostapd Product : Fedora 26 Version : 2.6 Release : 6.fc26 URL : http://w1.fi/hostapd/ Summary : IEEE 802.11 AP, IEEE 802.1X/WPA/WPA2/EAP/RADIUS Authenticator Description : hostapd is a user space daemon for access point and authentication servers. It implements IEEE 802.11 access point management, IEEE 802.1X/WPA/WPA2/EAP Authenticators and RADIUS authentication server. hostapd is designed to be a "daemon" program that runs in the back-ground and acts as the backend component controlling authentication. hostapd supports separate frontend programs and an example text-based frontend, hostapd_cli, is included with hostapd. --------------------------------------------------------------------------------Update Information: Latest hostapd release with KRACK patches applied. --------------------------------------------------------------------------------References: [ 1 ] Bug #1503874 - KRACK affects hostapd https://bugzilla.redhat.com/show_bug.cgi?id=1503874 [ 2 ] Bug #1502588 - CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 hostapd: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1502588 [ 3 ] Bug #1468942 - attempting to create Access Point overrides modprobe for wifi and crashes https://bugzilla.redhat.com/show_bug.cgi?id=1468942 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade hostapd' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Tackling essential hostapd improvements alongside KRACK updates within Fedora 26 to bolster security and reliability.. hostapd, KRACK Patches, Fedora 26 Security Update, Access Point, Network Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 15, 2017 Critical Fedora
87

Debian Security Update DSA-3999-1: Serious WPA Authentication Issue

Mathy Vanhoef of the imec-DistriNet research group of KU Leuven discovered multiple vulnerabilities in the WPA protocol, used for authentication in wireless networks. Those vulnerabilities applies to both the access point (implemented in hostapd) and the station (implemented in wpa_supplicant). . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3999-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Yves-Alexis Perez October 16, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : wpa CVE ID : CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 Mathy Vanhoef of the imec-DistriNet research group of KU Leuven discovered multiple vulnerabilities in the WPA protocol, used for authentication in wireless networks. Those vulnerabilities applies to both the access point (implemented in hostapd) and the station (implemented in wpa_supplicant). An attacker exploiting the vulnerabilities could force the vulnerable system to reuse cryptographic session keys, enabling a range of cryptographic attacks against the ciphers used in WPA1 and WPA2. More information can be found in the researchers's paper, Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2. CVE-2017-13077: reinstallation of the pairwise key in the Four-way handshake CVE-2017-13078: reinstallation of the group key in the Four-way handshake CVE-2017-13079: reinstallation of the integrity group key in the Four-way handshake CVE-2017-13080: reinstallation of the group key in the Group Key handshake CVE-2017-13081: reinstallation of the integrity group key in the Group Key handshake CVE-2017-13082: accepting a retransmitted Fast BSS Transition Reassociation Request and reinstalling thepairwise key while processing it CVE-2017-13086: reinstallation of the Tunneled Direct-Link Setup (TDLS) PeerKey (TPK) key in the TDLS handshake CVE-2017-13087: reinstallation of the group key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame CVE-2017-13088: reinstallation of the integrity group key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame For the oldstable distribution (jessie), these problems have been fixed in version 2.3-1+deb8u5. For the stable distribution (stretch), these problems have been fixed in version 2:2.4-1+deb9u1. For the testing distribution (buster), these problems have been fixed in version 2:2.4-1.1. For the unstable distribution (sid), these problems have been fixed in version 2:2.4-1.1. We recommend that you upgrade your wpa packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Uncover various weaknesses in the WPA protocol impacting Wi-Fi security and enhance your networks.. WPA Protocol Vulnerabilities, Debian Security Update, Cryptographic Attack, Wireless Network Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 16, 2017 Critical Debian
89

Fedora 20: 2015-8386 Critical Issue: Integer Underflow in hostapd

Security update for integer underflow in AP mode WMM Action frame processing.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-8386 2015-05-17 02:54:01 -------------------------------------------------------------------------------- Name : hostapd Product : Fedora 20 Version : 2.4 Release : 2.fc20 URL : http://w1.fi/hostapd/ Summary : IEEE 802.11 AP, IEEE 802.1X/WPA/WPA2/EAP/RADIUS Authenticator Description : hostapd is a user space daemon for access point and authentication servers. It implements IEEE 802.11 access point management, IEEE 802.1X/WPA/WPA2/EAP Authenticators and RADIUS authentication server. hostapd is designed to be a "daemon" program that runs in the back-ground and acts as the backend component controlling authentication. hostapd supports separate frontend programs and an example text-based frontend, hostapd_cli, is included with hostapd. -------------------------------------------------------------------------------- Update Information: Security update for integer underflow in AP mode WMM Action frame processing. -------------------------------------------------------------------------------- ChangeLog: * Fri May 15 2015 John W. Linville - 2.4-2 - apply fix for underflow in WMM action frame parser * Tue Apr 21 2015 John W. Linville - 2.4-1 - Update to version 2.4 from upstream - Enable support for IEEE802.11r and IEEE802.11ac * Wed Feb 4 2015 John W. Linville - 2.3-4 - Use BSD instead of %doc for file containing license information * Sun Nov 2 2014 poma - 2.3-3 - Further simplify hostapd.conf installation - Rebase "EAP-TLS server" patch to 2.3 * Tue Oct 28 2014 John W. Linville - 2.3-2 - Remove version info from /usr/share/doc/hostapd/hostapd.conf * Thu Oct 23 2014 John W. Linville - 2.3-1 - Update to version 2.3 from upstream * Sat Aug 16 2014 Fedora Release Engineering - 2.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild * Sat Jun 7 2014Fedora Release Engineering - 2.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Thu Jun 5 2014 John W. Linville - 2.2-1 - Update to version 2.2 from upstream * Sat Feb 22 2014 Simone Caronni - 2.1-2 - Re-enable drivers (#1068849). * Fri Feb 14 2014 John W. Linville - 2.1-1 - Update to version 2.1 from upstream - Remove obsolete patch for libnl build documentation * Mon Feb 3 2014 Simone Caronni - 2.0-6 - Add libnl build documentation and switch libnl-devel to libnl3-devel build dependency (#1041471). * Fri Nov 22 2013 John W. Linville - 2.0-5 - Enable CONFIG_FULL_DYNAMIC_VLAN build option -------------------------------------------------------------------------------- References: [ 1 ] Bug #1221178 - wpa_supplicant and hostapd: integer underflow in AP mode WMM Action frame processing https://bugzilla.redhat.com/show_bug.cgi?id=1221178 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update hostapd' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Important hostapd patch to address integer overflow flaw in Fedora 20, improving safety for wireless network administration.. Hostapd Update, Fedora Security, Integer Underflow Fix, AP Management. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 27, 2015 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here