Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 43 php-phpseclib3 Critical Info Disclosure CVE-2026-32935

Update to v3.0.50; contains fix for CVE-2026-32935. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b7d9416ec4 2026-03-30 00:53:25.964738+00:00 -------------------------------------------------------------------------------- Name : php-phpseclib3 Product : Fedora 43 Version : 3.0.50 Release : 1.fc43 URL : https://github.com/phpseclib/phpseclib Summary : PHP Secure Communications Library Description : MIT-licensed pure-PHP implementations of an arbitrary-precision integer arithmetic library, fully PKCS#1 (v2.1) compliant RSA, DES, 3DES, RC4, Rijndael, AES, Blowfish, Twofish, SSH-1, SSH-2, SFTP, and X.509 -------------------------------------------------------------------------------- Update Information: Update to v3.0.50; contains fix for CVE-2026-32935 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 21 2026 Artur Frenszek-Iwicki - 3.0.50-1 - Update to v3.0.50 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2448961 - php-phpseclib3-3.0.50 is available https://bugzilla.redhat.com/show_bug.cgi?id=2448961 [ 2 ] Bug #2449637 - CVE-2026-32935 php-phpseclib3: phpseclib: Information disclosure via padding oracle timing attack when using AES in CBC mode [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2449637 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b7d9416ec4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Critical security advisory for Fedora 43 php-phpseclib3 update fixing CVE-2026-32935 related to information disclosure.. Fedora php-phpseclib3 CVE-2026-32935. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 30, 2026 Critical Fedora
89

Fedora 43 php-phpseclib Update 2.0.52 Vulnerability Disclosure Risk

Update to v2.0.52. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d1feefa819 2026-03-28 00:45:01.878008+00:00 -------------------------------------------------------------------------------- Name : php-phpseclib Product : Fedora 43 Version : 2.0.52 Release : 1.fc43 URL : https://github.com/phpseclib/phpseclib Summary : PHP Secure Communications Library Description : MIT-licensed pure-PHP implementations of an arbitrary-precision integer arithmetic library, fully PKCS#1 (v2.1) compliant RSA, DES, 3DES, RC4, Rijndael, AES, Blowfish, Twofish, SSH-1, SSH-2, SFTP, and X.509 -------------------------------------------------------------------------------- Update Information: Update to v2.0.52 -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 19 2026 Artur Frenszek-Iwicki - 2.0.52-1 - Update to v2.0.52 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2449636 - CVE-2026-32935 php-phpseclib: phpseclib: Information disclosure via padding oracle timing attack when using AES in CBC mode [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2449636 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d1feefa819' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fedora 43 updates php-phpseclib to v2.0.52 addressing AES information disclosure risks via timing attacks.. Fedora security phpseclib updates information disclosure AES. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 28, 2026 Important Fedora
100

SUSE Linux: 2022:2311-1 Important: openssl-1_1 AES OCB Encryption Threat

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for openssl-1_1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2311-1 Rating: important References: #1201099 Cross-References: CVE-2022-2097 CVSS scores: CVE-2022-2097 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: SUSE CaaS Platform 4.0 SUSE Enterprise Storage 6 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server for SAP 15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for openssl-1_1 fixes the following issues: - CVE-2022-2097: Fixed partial missing encryption in AES OCB mode (bsc#1201099). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2022-2311=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2022-2311=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2022-2311=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2022-2311=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patchSUSE-SLE-Product-HPC-15-SP1-ESPOS-2022-2311=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2022-2311=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE Linux Enterprise Server for SAP 15-SP1 (ppc64le x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.36.1 libopenssl1_1-1.1.0i-150100.14.36.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-1.1.0i-150100.14.36.1 openssl-1_1-1.1.0i-150100.14.36.1 openssl-1_1-debuginfo-1.1.0i-150100.14.36.1 openssl-1_1-debugsource-1.1.0i-150100.14.36.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.36.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (aarch64 ppc64le s390x x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.36.1 libopenssl1_1-1.1.0i-150100.14.36.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-1.1.0i-150100.14.36.1 openssl-1_1-1.1.0i-150100.14.36.1 openssl-1_1-debuginfo-1.1.0i-150100.14.36.1 openssl-1_1-debugsource-1.1.0i-150100.14.36.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.36.1 - SUSE Linux Enterprise Server 15-SP1-BCL (x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.36.1 libopenssl-1_1-devel-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.36.1 openssl-1_1-1.1.0i-150100.14.36.1 openssl-1_1-debuginfo-1.1.0i-150100.14.36.1 openssl-1_1-debugsource-1.1.0i-150100.14.36.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (aarch64 x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.36.1 libopenssl1_1-1.1.0i-150100.14.36.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-1.1.0i-150100.14.36.1 openssl-1_1-1.1.0i-150100.14.36.1 openssl-1_1-debuginfo-1.1.0i-150100.14.36.1 openssl-1_1-debugsource-1.1.0i-150100.14.36.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.36.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (aarch64 x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.36.1 libopenssl1_1-1.1.0i-150100.14.36.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-1.1.0i-150100.14.36.1 openssl-1_1-1.1.0i-150100.14.36.1 openssl-1_1-debuginfo-1.1.0i-150100.14.36.1 openssl-1_1-debugsource-1.1.0i-150100.14.36.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.36.1 - SUSE Enterprise Storage 6 (aarch64 x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.36.1 libopenssl1_1-1.1.0i-150100.14.36.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-1.1.0i-150100.14.36.1 openssl-1_1-1.1.0i-150100.14.36.1 openssl-1_1-debuginfo-1.1.0i-150100.14.36.1 openssl-1_1-debugsource-1.1.0i-150100.14.36.1 - SUSE Enterprise Storage 6 (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.36.1 - SUSE CaaS Platform 4.0 (x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.36.1 libopenssl-1_1-devel-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-1.1.0i-150100.14.36.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-1.1.0i-150100.14.36.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.36.1 openssl-1_1-1.1.0i-150100.14.36.1 openssl-1_1-debuginfo-1.1.0i-150100.14.36.1 openssl-1_1-debugsource-1.1.0i-150100.14.36.1 References: https://www.suse.com/security/cve/CVE-2022-2097.html https://bugzilla.suse.com/1201099 . SUSE Security Notification: Crucial patch for openssl-1_1 addressing AES GCM encryption vulnerabilities has been released.. SUSE OpenSSL Security Update, Important Updates SUSE, openssl AES Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jul 06, 2022 Important SuSE
89

Fedora 33: FEDORA-2021-caf9e04ef1 Critical: LibTPMS AES IV Fix

tpm2: CryptSym: fix AES output IV; a CVE has been filed for this issue. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-caf9e04ef1 2021-03-10 00:41:43.224986 --------------------------------------------------------------------------------Name : libtpms Product : Fedora 33 Version : 0.7.7 Release : 0.20210302gitfd5bd3fb1d.fc33 URL : https://github.com/stefanberger/libtpms Summary : Library providing Trusted Platform Module (TPM) functionality Description : A library providing TPM functionality for VMs. Targeted for integration into Qemu. --------------------------------------------------------------------------------Update Information: tpm2: CryptSym: fix AES output IV; a CVE has been filed for this issue --------------------------------------------------------------------------------ChangeLog: * Tue Mar 2 2021 Stefan Breger - 0.7.7-0.20210302gitfd5bd3fb1d - tpm2: CryptSym: fix AES output IV; a CVE has been filed for this issue - tpm2: fixes a suspend/resume problem when public keys are loaded --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-caf9e04ef1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines:https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Essential patch addressing concerns with AES initialization vector in libtpms on Fedora 33; detailed upgrade guidance included.. libtpms, Fedora 33, AES, TPM, update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 09, 2021 Critical Fedora
87

Debian 8 DSA-3566-1 Critical: OpenSSL Memory and AES Flaws

Several vulnerabilities were discovered in OpenSSL, a Secure Socket Layer toolkit. CVE-2016-2105 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3566-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Alessandro Ghedini May 03, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openssl CVE ID : CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 CVE-2016-2109 CVE-2016-2176 Several vulnerabilities were discovered in OpenSSL, a Secure Socket Layer toolkit. CVE-2016-2105 Guido Vranken discovered that an overflow can occur in the function EVP_EncodeUpdate(), used for Base64 encoding, if an attacker can supply a large amount of data. This could lead to a heap corruption. CVE-2016-2106 Guido Vranken discovered that an overflow can occur in the function EVP_EncryptUpdate() if an attacker can supply a large amount of data. This could lead to a heap corruption. CVE-2016-2107 Juraj Somorovsky discovered a padding oracle in the AES CBC cipher implementation based on the AES-NI instruction set. This could allow an attacker to decrypt TLS traffic encrypted with one of the cipher suites based on AES CBC. CVE-2016-2108 David Benjamin from Google discovered that two separate bugs in the ASN.1 encoder, related to handling of negative zero integer values and large universal tags, could lead to an out-of-bounds write. CVE-2016-2109 Brian Carpenter discovered that when ASN.1 data is read from a BIO using functions such as d2i_CMS_bio(), a short invalid encoding can casuse allocation of large amounts of memory potentially consuming excessive resources or exhausting memory. CVE-2016-2176 Guido Vranken discovered that ASN.1 Strings that are over 1024 bytes can cause an overread in applications using theX509_NAME_oneline() function on EBCDIC systems. This could result in arbitrary stack data being returned in the buffer. Additional information about these issues can be found in the OpenSSL security advisory at https://openssl-library.org/news/secadv/20160503.txt For the stable distribution (jessie), these problems have been fixed in version 1.0.1k-3+deb8u5. For the unstable distribution (sid), these problems have been fixed in version 1.0.2h-1. We recommend that you upgrade your openssl packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-3578-2 relates to vulnerabilities in OpenSSL, highlighting problems such as buffer overflow and memory corruption.. OpenSSL, Debian Security, Memory Management, AES Vulnerabilities, Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 03, 2016 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here