Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 17 articles for you...
89

Fedora 42: freeipa Important Host Escalation Fix CVE-2025-7493

CVE-2025-7493: host to admin escalation prevention: https://www.freeipa.org/release-notes/4-12-5.html Update FreeIPA to latest fixes from ipa-4-12 branch. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e41ba62ff1 2025-10-03 00:52:22.552541+00:00 -------------------------------------------------------------------------------- Name : freeipa Product : Fedora 42 Version : 4.12.5 Release : 2.fc42 URL : http://www.freeipa.org/ Summary : The Identity, Policy and Audit system Description : IPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts). -------------------------------------------------------------------------------- Update Information: CVE-2025-7493: host to admin escalation prevention: https://www.freeipa.org/release-notes/4-12-5.html Update FreeIPA to latest fixes from ipa-4-12 branch -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 30 2025 Alexander Bokovoy - 4.12.5-2 - Update minor version metadata to alow IPA data upgrade * Tue Sep 30 2025 Alexander Bokovoy - 4.12.5-1 - CVE-2025-7493: host to admin escalation prevention * Tue Sep 23 2025 Alexander Bokovoy - 4.12.2-15 - Update fixes from ipa-4-12 branch -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e41ba62ff1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the FedoraProject GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Update FreeIPA on Fedora 42 fixes CVE-2025-7493 for host to admin escalation prevention issues.. FreeIPA update,Fedora security,escalation prevention,CVE-2025-7493. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 03, 2025 Important Fedora
172

Ubuntu 14.04 LTS: USN-7064-2 moderate: nano privilege escalation

nano could be made to give users administrator privileges.. ========================================================================== Ubuntu Security Notice USN-7064-2 October 29, 2024 nano vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: nano could be made to give users administrator privileges. Software Description: - nano: small, friendly text editor inspired by Pico Details: USN-7064-1 fixed a vulnerability in nano. This update provides the corresponding update for Ubuntu 14.04 LTS. Original advisory details: It was discovered that nano allowed a possible privilege escalation through an insecure temporary file. If nano was killed while editing, the permissions granted to the emergency save file could be used by an attacker to escalate privileges using a malicious symlink. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS nano 2.2.6-1ubuntu1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7064-2 https://ubuntu.com/security/notices/USN-7064-1 CVE-2024-5742 . The Ubuntu Security Notice USN-7064-2 addresses a security flaw in nano that could allow for privilege escalation. For further information, click here.. Ubuntu Security, nano Update, Privilege Escalation, Security Notice, System Update. . LinuxSecurity.com Team

Calendar%202 Oct 29, 2024 Ubuntu
172

Ubuntu 22.04 LTS USN-6089-1 Moderate: linux-oem-6.0 Admin Access

The system could be made to crash or run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-6089-1 May 18, 2023 linux-oem-6.0 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: The system could be made to crash or run programs as an administrator. Software Description: - linux-oem-6.0: Linux kernel for OEM systems Details: It was discovered that the Intel i915 graphics driver in the Linux kernel did not perform a GPU TLB flush in some situations. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: linux-image-6.0.0-1016-oem 6.0.0-1016.16 linux-image-oem-22.04b 6.0.0.1016.16 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-6089-1 CVE-2022-4139 Package Information: https://launchpad.net/ubuntu/+source/linux-oem-6.0/6.0.0-1016.16 . Ubuntu 22.04 LTS patch necessary for linux-oem-6.0 flaw impacting system integrity and permission levels.. Linux Kernel Vulnerability, Ubuntu Security Update, Admin Access Exploit. . LinuxSecurity.com Team

Calendar%202 May 18, 2023 Ubuntu
172

Ubuntu 18.04 LTS USN-6052-1 Moderate: Kernel Privilege Escalation

The system could be made to run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-6052-1 May 01, 2023 linux-ibm-5.4, linux-snapdragon vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: The system could be made to run programs as an administrator. Software Description: - linux-ibm-5.4: Linux kernel for IBM cloud systems - linux-snapdragon: Linux kernel for Qualcomm Snapdragon processors Details: It was discovered that the Traffic-Control Index (TCINDEX) implementation in the Linux kernel did not properly perform filter deactivation in some situations. A local attacker could possibly use this to gain elevated privileges. Please note that with the fix for this CVE, kernel support for the TCINDEX classifier has been removed. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: linux-image-4.15.0-1149-snapdragon 4.15.0-1149.159 linux-image-5.4.0-1048-ibm 5.4.0-1048.53~18.04.1 linux-image-ibm 5.4.0.1048.59 linux-image-snapdragon 4.15.0.1149.148 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-6052-1 CVE-2023-1829 Package Information: https://launchpad.net/ubuntu/+source/linux-ibm-5.4/5.4.0-1048.53~18.04.1 https://launchpad.net/ubuntu/+source/linux-snapdragon/4.15.0-1149.159 . The latest security update from Ubuntu addresses a critical kernel flaw that could allow unauthorized execution of administrative programs. Users are urged to upgrade.. Kernel Privilege Escalation, Ubuntu 18.04 LTS, Administrative Privileges. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 01, 2023 Important Ubuntu
203

Mageia: 2022-0466 Critical Advisory: CouchDB Admin Access Risk

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations. (CVE-2022-24706) . MGASA-2022-0466 - Updated couchdb packages fix security vulnerability Publication date: 17 Dec 2022 URL: https://advisories.mageia.org/MGASA-2022-0466.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-24706 In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations. (CVE-2022-24706) References: - https://bugs.mageia.org/show_bug.cgi?id=30342 - https://www.openwall.com/lists/oss-security/2022/04/26/1 - https://www.cve.org/CVERecord?id=CVE-2022-24706 SRPMS: - 8/core/couchdb-3.2.2-1.mga8 . A patch has been issued for CouchDB to fix a significant vulnerability that permitted unauthorized administrative entry prior to version 3.2.2.. CouchDB Security Update, Mageia 2022-0466, Apache CouchDB Issues, Admin Access Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 17, 2022 Critical Mageia
203

Mageia 8 MGASA-2022-0408 Moderate: ntfs-3g Crash and Admin Threat

NTFS-3G could be made to crash or run programs as an administrator if it mounted a specially crafted disk. (CVE-2022-40284) References: - https://bugs.mageia.org/show_bug.cgi?id=31056 . MGASA-2022-0408 - Updated ntfs-3g packages fix security vulnerability Publication date: 04 Nov 2022 URL: https://advisories.mageia.org/MGASA-2022-0408.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-40284 NTFS-3G could be made to crash or run programs as an administrator if it mounted a specially crafted disk. (CVE-2022-40284) References: - https://bugs.mageia.org/show_bug.cgi?id=31056 - https://www.openwall.com/lists/oss-security/2022/10/31/2 - https://github.com/tuxera/ntfs-3g/releases/tag/2022.10.3 - https://ubuntu.com/security/notices/USN-5711-1 - https://www.cve.org/CVERecord?id=CVE-2022-40284 SRPMS: - 8/core/ntfs-3g-2021.8.22-1.2.mga8 . The ntfs-3g filesystem driver received important updates on 04 Nov 2022 to address vulnerabilities that could lead to crashes or unauthorized access, improving system security. ntfs-3g security update, mageia advisory, crash risk, admin access risk. . LinuxSecurity.com Team

Calendar%202 Nov 04, 2022 Mageia
202

openSUSE: 2021:1452-1 Important Mailman CSRF Issues - Auth Attack Fix

An update that solves two vulnerabilities and has one errata is now available. . openSUSE Security Update: Security update for mailman ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1452-1 Rating: important References: #1047218 #1191959 #1191960 Cross-References: CVE-2021-42096 CVE-2021-42097 CVSS scores: CVE-2021-42096 (SUSE): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2021-42097 (SUSE): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: This update for mailman fixes the following issues: Update to 2.1.35 to fix 2 security issues: - A potential for for a list member to carry out an off-line brute force attack to obtain the list admin password has been reported by Andre Protas, Richard Cloke and Andy Nuttall of Apple. This is fixed. CVE-2021-42096 (boo#1191959, LP:#1947639) - A CSRF attack via the user options page could allow takeover of a users account. This is fixed. CVE-2021-42097 (boo#1191960, LP:#1947640) - make package build reproducible (boo#1047218) This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2021-1452=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64): mailman-2.1.35-bp152.7.6.1 References: https://www.suse.com/security/cve/CVE-2021-42096.html https://www.suse.com/security/cve/CVE-2021-42097.html https://bugzilla.suse.com/1047218 https://bugzilla.suse.com/1191959 https://bugzilla.suse.com/1191960 . A crucial openSUSE security patch addresses two flaws in Mailman that impact user accounts and administrative permissions.. Mailman Security Fixes, openSUSE Updates, CSRF Vulnerability Solutions. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 05, 2021 Important OpenSUSE
87

Debian: DSA-4612-1 critical: prosody modules admin access issue

It was discovered that the LDAP authentication modules for the Prosody Jabber/XMPP server incorrectly validated the XMPP address when checking whether a user has admin access. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4612-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff January 31, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : prosody-modules CVE ID : CVE-2020-8086 It was discovered that the LDAP authentication modules for the Prosody Jabber/XMPP server incorrectly validated the XMPP address when checking whether a user has admin access. For the oldstable distribution (stretch), this problem has been fixed in version 0.0~hg20170123.3ed504b944e5+dfsg-1+deb9u1. For the stable distribution (buster), this problem has been fixed in version 0.0~hg20190203.b54e98d5c4a1+dfsg-1+deb10u1. We recommend that you upgrade your prosody-modules packages. For the detailed security status of prosody-modules please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/prosody-modules Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance prosody-modules to address LDAP user authentication issues in Debian systems. Explore information on security advisories and available downloads.. Debian Security, Prosody Modules, Admin Access, LDAP Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 31, 2020 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200