Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 499
Alerts This Week
Warning Icon 1 499

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 31 articles for you...
172

Ubuntu 16.04 ESM USN-5500-1 Critical: Kernel Security Issues Resolved

Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-5500-1 July 01, 2022 linux, linux-aws vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems Details: Eric Biederman discovered that the cgroup process migration implementation in the Linux kernel did not perform permission checks correctly in some situations. A local attacker could possibly use this to gain administrative privileges. (CVE-2021-4197) Lin Ma discovered that the NFC Controller Interface (NCI) implementation in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-4202) It was discovered that the PF_KEYv2 implementation in the Linux kernel did not properly initialize kernel memory in some situations. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2022-1353) It was discovered that the virtual graphics memory manager implementation in the Linux kernel was subject to a race condition, potentially leading to an information leak. (CVE-2022-1419) Minh Yuan discovered that the floppy disk driver in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-1652) It was discovered that the Atheros ath9k wireless device driver in the Linux kernel did not properly handle some error conditions, leading to a use-after-free vulnerability. A local attacker could usethis to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1679) It was discovered that the Marvell NFC device driver implementation in the Linux kernel did not properly perform memory cleanup operations in some situations, leading to a use-after-free vulnerability. A local attacker could possibly use this to cause a denial of service (system) or execute arbitrary code. (CVE-2022-1734) 赵子轩 discovered that the 802.2 LLC type 2 driver in the Linux kernel did not properly perform reference counting in some error conditions. A local attacker could use this to cause a denial of service. (CVE-2022-28356) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: linux-image-4.4.0-1145-aws 4.4.0-1145.160 linux-image-4.4.0-229-generic 4.4.0-229.263 linux-image-4.4.0-229-lowlatency 4.4.0-229.263 linux-image-aws 4.4.0.1145.149 linux-image-generic 4.4.0.229.235 linux-image-lowlatency 4.4.0.229.235 linux-image-virtual 4.4.0.229.235 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-5500-1 CVE-2021-4197, CVE-2021-4202, CVE-2022-1353, CVE-2022-1419, CVE-2022-1652, CVE-2022-1679, CVE-2022-1734, CVE-2022-28356 . Numerous security patches for the Linux kernel on Ubuntu 16.04 ESM have been addressed, tackling issues related to denial of service and potential information disclosures..Linux Kernel, Ubuntu Update, Security Patches, Denial of Service, Information Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 01, 2022 Critical Ubuntu
172

Ubuntu 20.04 LTS: 0085-1 Critical: Local Attack Risks in Kernel

Several security issues were fixed in the kernel.. Linux kernel vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary Several security issues were fixed in the kernel. Software Description - linux - Linux kernel - linux-aws - Linux kernel for Amazon Web Services (AWS) systems - linux-azure - Linux kernel for Microsoft Azure Cloud systems - linux-gcp - Linux kernel for Google Cloud Platform (GCP) systems - linux-gke - Linux kernel for Google Container Engine (GKE) systems - linux-gkeop - Linux kernel for Google Container Engine (GKE) systems - linux-ibm - Linux kernel for IBM cloud systems - linux-oem - Linux kernel for OEM systems Details Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the Linux kernel did not properly restrict access to the cgroups v1 release_agent feature. A local attacker could use this to gain administrative privileges. (CVE-2022-0492) Nick Gregory discovered that the Linux kernel incorrectly handled network offload functionality. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2022-25636) Update instructions The problem can be corrected by updating your kernel livepatch to the following versions: Ubuntu 20.04 LTS aws - 85.1 azure - 85.1 gcp - 85.1 generic - 85.1 gke - 85.1 gkeop - 85.1 ibm - 85.1 lowlatency - 85.1 Ubuntu 18.04 LTS aws - 85.1 azure - 85.1 generic - 85.1 generic - 85.2 gke - 85.1 gkeop - 85.1 ibm - 85.1 lowlatency - 85.1 lowlatency - 85.2 oem - 85.1 Ubuntu 16.04 ESM aws - 85.1 azure - 85.1 generic - 85.1 lowlatency - 85.1 Ubuntu 14.04 ESM generic - 85.1 lowlatency - 85.1 Support Information Kernels older than the levels listed below do not receive livepatch updates. If you are running a kernel version earlier than the one listed below, please upgradeyour kernel as soon as possible. Ubuntu 20.04 LTS linux-aws - 5.4.0-1009 linux-azure - 5.4.0-1010 linux-gcp - 5.4.0-1009 linux-gke - 5.4.0-1033 linux-gkeop - 5.4.0-1009 linux-ibm - 5.4.0-1009 linux-oem - 5.4.0-26 linux - 5.4.0-26 Ubuntu 18.04 LTS linux-aws - 4.15.0-1054 linux-azure-4.15 - 4.15.0-1115 linux-azure-5.4 - 5.4.0-1069 linux-gke-4.15 - 4.15.0-1076 linux-gke-5.4 - 5.4.0-1009 linux-gkeop-5.4 - 5.4.0-1007 linux-hwe-5.4 - 5.4.0-26 linux-ibm-5.4 - 5.4.0-1009 linux-oem - 4.15.0-1063 linux - 4.15.0-69 Ubuntu 16.04 ESM linux-aws - 4.4.0-1098 linux-azure - 4.15.0-1063 linux-hwe - 4.15.0-69 linux - 4.4.0-168 Ubuntu 14.04 ESM linux-lts-xenial - 4.4.0-168 References - CVE-2022-0492 - CVE-2022-25636 . Various vulnerabilities within the Ubuntu Linux kernel might enable malicious actors to escalate their privileges or trigger service disruptions.. Kernel Security Issues, Ubuntu Patch Management, Local Attack Prevention. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 23, 2022 Critical Ubuntu
172

Ubuntu 20.04 LTS USN-5302-1: Moderate Kernel Security Issues

Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-5302-1 February 22, 2022 linux-oem-5.14 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-oem-5.14: Linux kernel for OEM systems Details: Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the Linux kernel did not properly restrict access to the cgroups v1 release_agent feature. A local attacker could use this to gain administrative privileges. (CVE-2022-0492) Brendan Dolan-Gavitt discovered that the Marvell WiFi-Ex USB device driver in the Linux kernel did not properly handle some error conditions. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2021-43976) Wenqing Liu discovered that the f2fs file system implementation in the Linux kernel did not properly validate inode types while performing garbage collection. An attacker could use this to construct a malicious f2fs image that, when mounted and operated on, could cause a denial of service (system crash). (CVE-2021-44879) Samuel Page discovered that the Transparent Inter-Process Communication (TIPC) protocol implementation in the Linux kernel contained a stack-based buffer overflow. A remote attacker could use this to cause a denial of service (system crash) for systems that have a TIPC bearer configured. (CVE-2022-0435) Lyu Tao discovered that the NFS implementation in the Linux kernel did not properly handle requests to open a directory on a regular file. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2022-24448) It was discovered that the YAM AX.25 device driver in the Linux kernel did not properly deallocate memory in some error conditions. A local privilegedattacker could use this to cause a denial of service (kernel memory exhaustion). (CVE-2022-24959) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: linux-image-5.14.0-1024-oem 5.14.0-1024.26 linux-image-oem-20.04 5.14.0.1024.22 linux-image-oem-20.04b 5.14.0.1024.22 linux-image-oem-20.04c 5.14.0.1024.22 linux-image-oem-20.04d 5.14.0.1024.22 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-5302-1 CVE-2021-43976, CVE-2021-44879, CVE-2022-0435, CVE-2022-0492, CVE-2022-24448, CVE-2022-24959 Package Information: https://launchpad.net/ubuntu/+source/linux-oem-5.14/5.14.0-1024.26 . Tackling security vulnerabilities in Ubuntu 20.04 LTS that impact the Linux kernel through essential updates for kernel environments.. Linux Kernel Issues, Ubuntu Security Notice, Kernel Updates, Administrative Privileges. . LinuxSecurity.com Team

Calendar%202 Feb 22, 2022 Ubuntu
172

Ubuntu 18.04 LTS USN-4484-1 Critical: linux-hwe Denial of Service

The system could be made to crash or run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-4484-1 September 02, 2020 linux-hwe, linux-aws-5.3, linux-gke-5.3, linux-raspi2-5.3 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: The system could be made to crash or run programs as an administrator. Software Description: - linux-aws-5.3: Linux kernel for Amazon Web Services (AWS) systems - linux-gke-5.3: Linux kernel for Google Container Engine (GKE) systems - linux-hwe: Linux hardware enablement (HWE) kernel - linux-raspi2-5.3: Linux kernel for Raspberry Pi (V8) systems Details: It was discovered that the cgroup v2 subsystem in the Linux kernel did not properly perform reference counting in some situations, leading to a NULL pointer dereference. A local attacker could use this to cause a denial of service or possibly gain administrative privileges. (CVE-2020-14356) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: linux-image-5.3.0-1032-raspi2 5.3.0-1032.34 linux-image-5.3.0-1034-aws 5.3.0-1034.36 linux-image-5.3.0-1034-gke 5.3.0-1034.36 linux-image-5.3.0-66-generic 5.3.0-66.60 linux-image-5.3.0-66-lowlatency 5.3.0-66.60 linux-image-aws 5.3.0.1034.33 linux-image-gke-5.3 5.3.0.1034.19 linux-image-gkeop-5.3 5.3.0.66.123 linux-image-raspi2-hwe-18.04 5.3.0.1032.22 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g.linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4484-1 CVE-2020-14356 Package Information: https://launchpad.net/ubuntu/+source/linux-aws-5.3/5.3.0-1034.36 https://launchpad.net/ubuntu/+source/linux-gke-5.3/5.3.0-1034.36 https://launchpad.net/ubuntu/+source/linux-hwe/5.3.0-66.60 https://launchpad.net/ubuntu/+source/linux-raspi2-5.3/5.3.0-1032.34 . Significant vulnerability identified in Ubuntu's Linux kernel; addresses risks for service interruption and unauthorized privilege elevation.. Linux Kernel, Ubuntu Security, Denial of Service, Privilege Escalation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 02, 2020 Critical Ubuntu
203

Mageia: 2020-0156 Moderate: Kernel Use After Free and Info Disclosure

This update is based on upstream 5.5.14 and fixes atleast the following security vulnerabilities: In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include/trace/events/lock.h) . MGASA-2020-0156 - Updated kernel packages fix security vulnerabilities Publication date: 02 Apr 2020 URL: https://advisories.mageia.org/MGASA-2020-0156.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-19769, CVE-2020-8835 This update is based on upstream 5.5.14 and fixes atleast the following security vulnerabilities: In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include/trace/events/lock.h) (CVE-2019-19769). Manfred Paul discovered that the bpf verifier in the Linux kernel did not properly calculate register bounds for certain operations. A local attacker could use this to expose sensitive information (kernel memory) or gain administrative privileges (CVE-2020-8835). Security fixes and hardenings to the mac00211 layer to prevent leaking keys and frames. Other notable changes in this update: - WireGuard kernel module has been updated to v1.0.20200330 and the tools to v1.0.20200319. - exfat-utils has been rebuilt in core (was previously in tainted) as we now also ship the official upstream exfat driver. For other upstream fixes in this update, see the referenced changelogs. References: - https://bugs.mageia.org/show_bug.cgi?id=26420 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.10 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.11 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.12 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.13 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.14 - https://www.cve.org/CVERecord?id=CVE-2019-19769 - https://www.cve.org/CVERecord?id=CVE-2020-8835 SRPMS: - 7/core/kernel-5.5.14-1.mga7 - 7/core/kmod-virtualbox-6.0.18-8.mga7 - 7/core/kmod-xtables-addons-3.8-8.mga7 -7/core/wireguard-tools-1.0.20200319-1.mga7 - 7/core/exfat-utils-1.3.0-2.mga7 . Mageia 2021-0167 enhances kernel components to address security issues, such as buffer overflow and privilege escalation.. kernel Security Update, Mageia 2020-0156, security fixes, Linux kernel issues, administrative privileges. . LinuxSecurity.com Team

Calendar%202 Apr 02, 2020 Mageia
172

Ubuntu 4313-1: Moderate Risk Kernel Issue Exposing Data

The system could be made to expose sensitive information or run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-4313-1 March 30, 2020 linux, linux-aws, linux-azure, linux-azure-5.3, linux-gcp, linux-gcp-5.3, linux-gke-5.3, linux-hwe, linux-kvm, linux-oracle, linux-oracle-5.3, linux-raspi2, linux-raspi2-5.3 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.10 - Ubuntu 18.04 LTS Summary: The system could be made to expose sensitive information or run programs as an administrator. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-azure: Linux kernel for Microsoft Azure Cloud systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-kvm: Linux kernel for cloud environments - linux-oracle: Linux kernel for Oracle Cloud systems - linux-raspi2: Linux kernel for Raspberry Pi 2 - linux-azure-5.3: Linux kernel for Microsoft Azure Cloud systems - linux-gcp-5.3: Linux kernel for Google Cloud Platform (GCP) systems - linux-gke-5.3: Linux kernel for Google Container Engine (GKE) systems - linux-hwe: Linux hardware enablement (HWE) kernel - linux-oracle-5.3: Linux kernel buildinfo for version 5.3.0 on 64 bit x86 SMP - linux-raspi2-5.3: Linux kernel for Raspberry Pi 2 Details: Manfred Paul discovered that the bpf verifier in the Linux kernel did not properly calculate register bounds for certain operations. A local attacker could use this to expose sensitive information (kernel memory) or gain administrative privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10: linux-image-5.3.0-1013-oracle 5.3.0-1013.14 linux-image-5.3.0-1014-kvm 5.3.0-1014.15 linux-image-5.3.0-1015-aws 5.3.0-1015.16 linux-image-5.3.0-1016-gcp 5.3.0-1016.17 linux-image-5.3.0-1018-azure 5.3.0-1018.19 linux-image-5.3.0-1021-raspi2 5.3.0-1021.23 linux-image-5.3.0-45-generic 5.3.0-45.37 linux-image-5.3.0-45-generic-lpae 5.3.0-45.37 linux-image-5.3.0-45-lowlatency 5.3.0-45.37 linux-image-5.3.0-45-snapdragon 5.3.0-45.37 linux-image-aws 5.3.0.1015.17 linux-image-azure 5.3.0.1018.37 linux-image-gcp 5.3.0.1016.17 linux-image-generic 5.3.0.45.38 linux-image-generic-lpae 5.3.0.45.38 linux-image-gke 5.3.0.1016.17 linux-image-kvm 5.3.0.1014.16 linux-image-lowlatency 5.3.0.45.38 linux-image-oracle 5.3.0.1013.14 linux-image-raspi2 5.3.0.1021.18 linux-image-snapdragon 5.3.0.45.38 linux-image-virtual 5.3.0.45.38 Ubuntu 18.04 LTS: linux-image-5.3.0-1013-oracle 5.3.0-1013.14~18.04.1 linux-image-5.3.0-1016-gcp 5.3.0-1016.17~18.04.1 linux-image-5.3.0-1016-gke 5.3.0-1016.17~18.04.1 linux-image-5.3.0-1018-azure 5.3.0-1018.19~18.04.1 linux-image-5.3.0-1021-raspi2 5.3.0-1021.23~18.04.1 linux-image-5.3.0-45-generic 5.3.0-45.37~18.04.1 linux-image-5.3.0-45-generic-lpae 5.3.0-45.37~18.04.1 linux-image-5.3.0-45-lowlatency 5.3.0-45.37~18.04.1 linux-image-azure-edge 5.3.0.1018.18 linux-image-gcp-edge 5.3.0.1016.15 linux-image-generic-hwe-18.04 5.3.0.45.101 linux-image-generic-lpae-hwe-18.04 5.3.0.45.101 linux-image-gke-5.3 5.3.0.1016.6 linux-image-lowlatency-hwe-18.04 5.3.0.45.101 linux-image-oracle-edge 5.3.0.1013.12 linux-image-raspi2-hwe-18.04 5.3.0.1021.10 linux-image-snapdragon-hwe-18.04 5.3.0.45.101 linux-image-virtual-hwe-18.04 5.3.0.45.101 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompileand reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4313-1 CVE-2020-8835 Package Information: https://launchpad.net/ubuntu/+source/linux/5.3.0-45.37 https://launchpad.net/ubuntu/+source/linux-aws/5.3.0-1015.16 https://launchpad.net/ubuntu/+source/linux-azure/5.3.0-1018.19 https://launchpad.net/ubuntu/+source/linux-gcp/5.3.0-1016.17 https://launchpad.net/ubuntu/+source/linux-kvm/5.3.0-1014.15 https://launchpad.net/ubuntu/+source/linux-oracle/5.3.0-1013.14 https://launchpad.net/ubuntu/+source/linux-raspi2/5.3.0-1021.23 https://launchpad.net/ubuntu/+source/linux-azure-5.3/5.3.0-1018.19~18.04.1 https://launchpad.net/ubuntu/+source/linux-gcp-5.3/5.3.0-1016.17~18.04.1 https://launchpad.net/ubuntu/+source/linux-gke-5.3/5.3.0-1016.17~18.04.1 https://launchpad.net/ubuntu/+source/linux-hwe/5.3.0-45.37~18.04.1 https://launchpad.net/ubuntu/+source/linux-oracle-5.3/5.3.0-1013.14~18.04.1 https://launchpad.net/ubuntu/+source/linux-raspi2-5.3/5.3.0-1021.23~18.04.1 . A vulnerability in the Linux kernel on Ubuntu may lead to unauthorized access or data leaks; patches have been released.. Ubuntu Kernel Issue, Security Update, Linux Vulnerability, System Admin Rights. . LinuxSecurity.com Team

Calendar%202 Mar 30, 2020 Ubuntu
200

SciLinux: SLSA-2019-2145-1 Moderate: gvfs Incorrect Authorization Issue

gvfs: Incorrect authorization in admin backend allows privileged users to read and modify arbitrary files without prompting for password (CVE-2019-3827) SL7 x86_64 gvfs-1.36.2-3.el7.i686.rpm gvfs-smb-1.36.2-3.el7.x86_64.rpm gvfs-afp-1.36.2-3.el7.x86_64.rpm gvfs-mtp-1.36.2-3.el7.x86_64.rpm gvfs-devel-1.36.2-3.el7.x86_64.rpm gvfs-client-1.36.2-3.el7.x86_64.rpm gvfs [More...]. Synopsis: Moderate: gvfs security and bug fix update Advisory ID: SLSA-2019:2145-1 Issue Date: 2019-08-06 CVE Numbers: CVE-2019-3827 -- Security Fix(es): * gvfs: Incorrect authorization in admin backend allows privileged usersto read and modify arbitrary files without prompting for password (CVE-2019-3827) -- SL7 x86_64 gvfs-1.36.2-3.el7.i686.rpm gvfs-smb-1.36.2-3.el7.x86_64.rpm gvfs-afp-1.36.2-3.el7.x86_64.rpm gvfs-mtp-1.36.2-3.el7.x86_64.rpm gvfs-devel-1.36.2-3.el7.x86_64.rpm gvfs-client-1.36.2-3.el7.x86_64.rpm gvfs-gphoto2-1.36.2-3.el7.x86_64.rpm gvfs-1.36.2-3.el7.x86_64.rpm gvfs-devel-1.36.2-3.el7.i686.rpm gvfs-client-1.36.2-3.el7.i686.rpm gvfs-afc-1.36.2-3.el7.x86_64.rpm gvfs-goa-1.36.2-3.el7.x86_64.rpm gvfs-fuse-1.36.2-3.el7.x86_64.rpm gvfs-archive-1.36.2-3.el7.x86_64.rpm gvfs-tests-1.36.2-3.el7.x86_64.rpm gvfs-debuginfo-1.36.2-3.el7.i686.rpm gvfs-debuginfo-1.36.2-3.el7.x86_64.rpm - Scientific Linux Development Team . Key gvfs security patch release for SL7.x correcting access control vulnerabilities permitting unauthorized file interactions.. gvfs, security fix, authorization issues, SL7, privileged access. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 26, 2019 Important Scientific Linux
172

Ubuntu 12.04 ESM USN-3861-2 Critical: PolicyKit Access Control Issue

PolicyKit could allow unintended access.. =========================================================================Ubuntu Security Notice USN-3861-2 January 16, 2019 policykit-1 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: PolicyKit could allow unintended access. Software Description: - policykit-1: framework for managing administrative policies and privileges Details: USN-3861-1 fixed a vulnerability in PolicyKit. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that PolicyKit incorrectly handled certain large user UIDs. A local attacker with a large UID could possibly use this issue to perform privileged actions. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: libpolkit-backend-1-0 0.104-1ubuntu1.4 policykit-1 0.104-1ubuntu1.4 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3861-1 CVE-2018-19788 . Ubuntu Security Notice USN-3862-1 addresses a vulnerability within the AppArmor service that enables unauthorized actions by local users.. PolicyKit Flaw, Ubuntu Security Update, Local Access Attack. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 16, 2019 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200