Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 8 articles for you...
89

Fedora 40: 2024-43ea98691e Critical: Flatpak 1.15.8 Security Fix

Update to 1.15.8 Fixes CVE-2024-32462. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-43ea98691e 2024-04-21 01:07:27.497020 -------------------------------------------------------------------------------- Name : flatpak Product : Fedora 40 Version : 1.15.8 Release : 1.fc40 URL : https://flatpak.org/ Summary : Application deployment framework for desktop apps Description : flatpak is a system for building, distributing and running sandboxed desktop applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for more information. -------------------------------------------------------------------------------- Update Information: Update to 1.15.8 Fixes CVE-2024-32462 -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 19 2024 David King - 1.15.8-1 - Update to 1.15.8 (#2275983) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2271979 https://bugzilla.redhat.com/show_bug.cgi?id=2271979 [ 2 ] Bug #2275983 https://bugzilla.redhat.com/show_bug.cgi?id=2275983 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-43ea98691e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 40's flatpak enhancement to version 1.15.8 resolves urgent security vulnerability CVE-2024-32462, boosting app protection.. Fedora Security, Flatpak Update, Application Framework, CVE Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 21, 2024 Critical Fedora
89

Fedora 34: 2022-8c64cb0992 Moderate: Flatpak Regression Fix

This is a regression fix update, reverting non-backwards-compatible behaviour changes in the solution previously chosen for [CVE-2022-21682](https://github.com/ m/flatpak/flatpak/security/advisories/GHSA-8ch7-5j3h-g4fx) ---- Update to 1.10.6 Fixes these two security issues: * CVE-2021-43860 or *. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-8c64cb0992 2022-02-03 01:12:09.331919 --------------------------------------------------------------------------------Name : flatpak Product : Fedora 34 Version : 1.10.7 Release : 1.fc34 URL : https://flatpak.org/ Summary : Application deployment framework for desktop apps Description : flatpak is a system for building, distributing and running sandboxed desktop applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for more information. --------------------------------------------------------------------------------Update Information: This is a regression fix update, reverting non-backwards-compatible behaviour changes in the solution previously chosen for [CVE-2022-21682](https://github.com/ m/flatpak/flatpak/security/advisories/GHSA-8ch7-5j3h-g4fx) ---- Update to 1.10.6 Fixes these two security issues: * CVE-2021-43860 or * CVE-2022-21682 or Full release notes: --------------------------------------------------------------------------------ChangeLog: * Tue Jan 18 2022 Debarshi Ray - 1.10.7-1 - Update to 1.10.7 * Fri Jan 14 2022 Debarshi Ray - 1.10.6-1 - Update to 1.10.6 --------------------------------------------------------------------------------References: [ 1 ] Bug #1969591 - flatpak-builder-1.2.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1969591 [ 2 ] Bug #2041593 - CVE-2022-21682 flatpak: flatpak-builder --mirror-screenshots-url can access files outside the build directory [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2041593 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-8c64cb0992' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . This release of Fedora 34 focuses on enhancing security measures and reinstating previous compatible functionalities within flatpak.. Fedora Update, Flatpak Security Fix, Application Framework, Linux Security. . LinuxSecurity.com Team

Calendar 2 Feb 02, 2022 Fedora
89

Fedora 35: FEDORA-2022-7e328bd66c Moderate: Flatpak Application Update

This is a regression fix update, reverting non-backwards-compatible behaviour changes in the solution previously chosen for [CVE-2022-21682](https://github.com/ m/flatpak/flatpak/security/advisories/GHSA-8ch7-5j3h-g4fx). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-7e328bd66c 2022-01-26 18:39:49.375589 --------------------------------------------------------------------------------Name : flatpak Product : Fedora 35 Version : 1.12.4 Release : 1.fc35 URL : https://flatpak.org/ Summary : Application deployment framework for desktop apps Description : flatpak is a system for building, distributing and running sandboxed desktop applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for more information. --------------------------------------------------------------------------------Update Information: This is a regression fix update, reverting non-backwards-compatible behaviour changes in the solution previously chosen for [CVE-2022-21682](https://github.com/ m/flatpak/flatpak/security/advisories/GHSA-8ch7-5j3h-g4fx) --------------------------------------------------------------------------------ChangeLog: * Tue Jan 18 2022 Debarshi Ray - 1.12.4-1 - Update to 1.12.4 (#2042071) --------------------------------------------------------------------------------References: [ 1 ] Bug #1969591 - flatpak-builder-1.2.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1969591 [ 2 ] Bug #2041593 - CVE-2022-21682 flatpak: flatpak-builder --mirror-screenshots-url can access files outside the build directory [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2041593 [ 3 ] Bug #2042071 - flatpak-1.12.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2042071 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade--advisory FEDORA-2022-7e328bd66c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora 35 receives a Flatpak update that restores previous enhancements, resolving compatibility issues for user experience.. Flatpak Update, Fedora 35 Security, Regression Issues. . LinuxSecurity.com Team

Calendar 2 Jan 26, 2022 Fedora
87

Debian DSA-5049-1 Moderate: Flatpak Permissions Issues Explored

Several vulnerabilities were discovered in Flatpak, an application deployment framework for desktop apps. CVE-2021-43860 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5049-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Sebastien Delafond January 20, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : flatpak CVE ID : CVE-2021-43860 CVE-2022-21682 Several vulnerabilities were discovered in Flatpak, an application deployment framework for desktop apps. CVE-2021-43860 Ryan Gonzalez discovered that Flatpak didn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime. Malicious apps could therefore grant themselves permissions without the consent of the user. CVE-2022-21682 Flatpak didn't always prevent a malicious flatpak-builder user from writing to the local filesystem. For the stable distribution (bullseye), these problems have been fixed in version 1.10.7-0+deb11u1. Please note that flatpak-builder also needed an update for compatibility, and is now at version 1.0.12-1+deb11u1 in bullseye. We recommend that you upgrade your flatpak and flatpak-builder packages. For the detailed security status of flatpak please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/flatpak Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Multiple security issues in Flatpak have been resolved in the Debian Security Advisory DSA-5049-1, along with suggested upgrade actions.. Debian Flatpak Security Update, Security Advisory DSA-5049-1, FlatpakPermissions, Application Deployment Framework. . LinuxSecurity.com Team

Calendar 2 Jan 20, 2022 Debian
172

Ubuntu 20.04 LTS USN-4951-1: Critical Flatpak Access Risk Advisory

A Flatpak application could access files that it would not normally be permitted to access.. =========================================================================Ubuntu Security Notice USN-4951-1 May 12, 2021 flatpak vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: A Flatpak application could access files that it would not normally be permitted to access. Software Description: - flatpak: Application deployment framework for desktop apps Details: Anton Lydike discovered that Flatpak did not properly handle special tokens in desktop files. An attacker could use this to specially craft a Flatpak application that could escape sandbox confinement. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: flatpak 1.8.2-1ubuntu0.2 libflatpak0 1.8.2-1ubuntu0.2 Ubuntu 20.04 LTS: flatpak 1.6.5-0ubuntu0.3 libflatpak0 1.6.5-0ubuntu0.3 Ubuntu 18.04 LTS: flatpak 1.0.9-0ubuntu0.3 libflatpak0 1.0.9-0ubuntu0.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4951-1 CVE-2021-21381 Package Information: https://launchpad.net/ubuntu/+source/flatpak/1.8.2-1ubuntu0.2 https://launchpad.net/ubuntu/+source/flatpak/1.6.5-0ubuntu0.3 https://launchpad.net/ubuntu/+source/flatpak/1.0.9-0ubuntu0.3 . Security Alert USN-5002-2 addresses a Snap vulnerability permitting unauthorized data exposure on Linux distributions.. Flatpak Issue, Ubuntu Security, Application Access Risk, Update Instructions. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 12, 2021 Critical Ubuntu
87

Debian Buster DSA-4868-1 Critical: Flatpak Sandbox Bypass Issue

Anton Lydike discovered that sandbox restrictions in Flatpak, an application deployment framework for desktop apps, could by bypassed via a malicious .desktop file. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4868-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff March 12, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : flatpak CVE ID : CVE-2021-21381 Anton Lydike discovered that sandbox restrictions in Flatpak, an application deployment framework for desktop apps, could by bypassed via a malicious .desktop file. For the stable distribution (buster), this problem has been fixed in version 1.2.5-0+deb10u4. We recommend that you upgrade your flatpak packages. For the detailed security status of flatpak please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/flatpak Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ensure your flatpak applications are updated to address the sandbox evasion flaw disclosed by Anton Lydike in DSA-4868-1.. Flatpak Security Update, Debian Advice, Sandbox Bypass Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 12, 2021 Critical Debian
89

Fedora 33: 2021-f970ea9d79 Critical: Flatpak Sandbox Escape

This updates flatpak from 1.8 to new 1.10 stable series. The major new feature in this series compared to 1.8 is the support for the new repo format which should make updates faster and download less data. For details what's new in 1.10, see https://github.com/flatpak/flatpak/releases/tag/1.10.0 This also includes a security update that fixes a sandbox escape where a malicious. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-f970ea9d79 2021-01-16 01:32:44.205275 --------------------------------------------------------------------------------Name : flatpak Product : Fedora 33 Version : 1.10.0 Release : 1.fc33 URL : https://flatpak.org/ Summary : Application deployment framework for desktop apps Description : flatpak is a system for building, distributing and running sandboxed desktop applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for more information. --------------------------------------------------------------------------------Update Information: This updates flatpak from 1.8 to new 1.10 stable series. The major new feature in this series compared to 1.8 is the support for the new repo format which should make updates faster and download less data. For details what's new in 1.10, see https://github.com/flatpak/flatpak/releases/tag/1.10.0 This also includes a security update that fixes a sandbox escape where a malicious application can execute code outside the sandbox by controlling the environment of the "flatpak run" command when spawning a sub-sandbox. See the advisory for details: https://github.com/flatpak/flatpak/security/advisories/GHSA-4ppf-fxf6-vxg2 --------------------------------------------------------------------------------ChangeLog: * Thu Jan 14 2021 Kalev Lember - 1.10.0-1 - Update to 1.10.0 - Use "Fedora Flatpaks" as the visible repo name --------------------------------------------------------------------------------Thisupdate can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-f970ea9d79' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The notable enhancement in Flatpak 1.10 for Fedora 33 boosts efficiency and resolves a sandbox breach vulnerability.. Flatpak Sandbox Escape, Fedora 33 Update, Application Deployment, Linux Flatpak. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 15, 2021 Critical Fedora
89

Fedora 32: FEDORA-2020-6b8868fad9 Critical: php-horde-horde Security Fix

**horde 5.2.22** * [jan] SECURITY: Protect image processing service from rendering active SVG content within the browser. * [jan] SECURITY: Fix XSS vulnerabilities in administration interface. * [jan] Support Redis Sentinel configuration (Michael Menge , Request #14998). * [jan] Use file hashing for detecting outdated configuration files.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-6b8868fad9 2020-05-01 00:35:06.353146 --------------------------------------------------------------------------------Name : php-horde-horde Product : Fedora 32 Version : 5.2.22 Release : 1.fc32 URL : https://www.horde.org/apps/horde Summary : Horde Application Framework Description : The Horde Application Framework is a flexible, modular, general-purpose web application framework written in PHP. It provides an extensive array of components that are targeted at the common problems and tasks involved in developing modern web applications. It is the basis for a large number of production-level web applications, notably the Horde Groupware suites. For more information on Horde or the Horde Groupware suites, visit https://www.horde.org/ --------------------------------------------------------------------------------Update Information: **horde 5.2.22** * [jan] SECURITY: Protect image processing service from rendering active SVG content within the browser. * [jan] SECURITY: Fix XSS vulnerabilities in administration interface. * [jan] Support Redis Sentinel configuration (Michael Menge , Request #14998). * [jan] Use file hashing for detecting outdated configuration files. --------------------------------------------------------------------------------ChangeLog: * Tue Apr 21 2020 Remi Collet - 5.2.22-1 - update to 5.2.22 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2020-6b8868fad9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The php-horde-horde update addresses several vulnerabilities related to XSS and improves the security measures for handling images.. php Horde, Fedora Update, XSS Issues, Active SVG, Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 30, 2020 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here