Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
198

Arch Linux Vivaldi 3.5.2115.87-1 High: Remote Code Execution Risk

The package vivaldi before version 3.5.2115.87-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution and insufficient validation. . Arch Linux Security Advisory ASA-202101-20 ========================================= Severity: High Date : 2021-01-12 CVE-ID : CVE-2020-15995 CVE-2020-16043 CVE-2021-21106 CVE-2021-21107 CVE-2021-21108 CVE-2021-21109 CVE-2021-21110 CVE-2021-21111 CVE-2021-21112 CVE-2021-21113 CVE-2021-21114 CVE-2021-21115 CVE-2021-21116 Package : vivaldi Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1424 Summary ====== The package vivaldi before version 3.5.2115.87-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution and insufficient validation. Resolution ========= Upgrade to 3.5.2115.87-1. # pacman -Syu "vivaldi> =3.5.2115.87-1" The problems have been fixed upstream in version 3.5.2115.87. Workaround ========= None. Description ========== - CVE-2020-15995 (arbitrary code execution) An out of bounds write security issue has been found in the V8 component of the Chromium browser before version 87.0.4280.141. - CVE-2020-16043 (insufficient validation) An insufficient data validation security issue has been found in the networking component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21106 (arbitrary code execution) A use after free security issue has been found in the autofill component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21107 (arbitrary code execution) A use after free security issue has been found in the drag and drop component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21108 (arbitrary code execution) A use after free security issue has been found in the media component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21109 (arbitrary code execution) A use after free security issue has been found in the payments component of theChromium browser before version 87.0.4280.141. - CVE-2021-21110 (arbitrary code execution) A use after free security issue has been found in the safe browsing component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21111 (access restriction bypass) An insufficient policy enforcement security issue has been found in the WebUI component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21112 (arbitrary code execution) A use after free security issue has been found in the Blink component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21113 (arbitrary code execution) A heap buffer overflow security issue has been found in the Skia component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21114 (arbitrary code execution) A use after free security issue has been found in the audio component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21115 (arbitrary code execution) A use after free security issue has been found in the safe browsing component of the Chromium browser before version 87.0.4280.141. - CVE-2021-21116 (arbitrary code execution) A heap buffer overflow security issue has been found in the audio component of the Chromium browser before version 87.0.4280.141. Impact ===== A remote attacker might be able to bypass security restrictions and execute arbitrarycode. References ========= https://vivaldi.com/blog/desktop/minor-update-for-vivaldi-desktop-browser-3-5/ https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop.html https://security.archlinux.org/CVE-2020-15995 https://security.archlinux.org/CVE-2020-16043 https://security.archlinux.org/CVE-2021-21106 https://security.archlinux.org/CVE-2021-21107 https://security.archlinux.org/CVE-2021-21108 https://security.archlinux.org/CVE-2021-21109 https://security.archlinux.org/CVE-2021-21110 https://security.archlinux.org/CVE-2021-21111 https://security.archlinux.org/CVE-2021-21112 https://security.archlinux.org/CVE-2021-21113 https://security.archlinux.org/CVE-2021-21114 https://security.archlinux.org/CVE-2021-21115 https://security.archlinux.org/CVE-2021-21116 . Arch Linux Security Advisory ASA-202101-20 ========================================= Severity: High . package, vivaldi, version, vulnerable. . LinuxSecurity.com Team

Calendar%202 Jan 15, 2021 ArchLinux
198

Arch Linux: 202301-47 Medium: Linux-LTS Package Privilege Escalation

The package linux-lts before version 4.4.44-1 is vulnerable to privilege escalation. . Arch Linux Security Advisory ASA-201701-35 ========================================= Severity: Medium Date : 2017-01-27 CVE-ID : CVE-2017-2583 Package : linux-lts Type : privilege escalation Remote : No Link : https://security.archlinux.org/AVG-150 Summary ====== The package linux-lts before version 4.4.44-1 is vulnerable to privilege escalation. Resolution ========= Upgrade to 4.4.44-1. # pacman -Syu "linux-lts> =4.4.44-1" The problem has been fixed upstream in version 4.4.44. Workaround ========= None. Description ========== The Linux kernel > 3.6-rc1, when built with Kernel-based Virtual Machine (CONFIG_KVM) support, is vulnerable to an incorrect segment selector (SS) value error. It could occur loading values into SS register in long mode. A user/process inside a guest host could use this flaw to crash the guest, resulting in denial of service, or potentially escalate their privileges inside the guest system on an AMD processor. Impact ===== A local attacker in a guest host is able to crash the system or escalate privileges inside the guest on an AMD processor. References ========= https://seclists.org/oss-sec/2017/q1/137 https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/ https://security.archlinux.org/CVE-2017-2583 . The Linux-lts earlier than version 4.4.44-1 on Arch Linux possesses a risk for privilege escalation. An update is essential.. Arch Linux, Privilege Escalation, Linux-LTS Advisory. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Jan 27, 2017 Medium ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200