Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 15 articles for you...
202

openSUSE Leap 16.0 Ansible-Core Important Code Execution Risk 2026-21097-1

An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for ansible-core ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21097-1 Rating: important References: * bsc#1267822 Cross-References: * CVE-2026-11332 CVSS scores: * CVE-2026-11332 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for ansible-core fixes the following issue - CVE-2026-11332: argument injection in ansible-galaxy role install leads to arbitrary code execution (bsc#1267822). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-962=1 Package List: - openSUSE Leap 16.0: ansible-core-2.18.3-160000.3.1 ansible-test-2.18.3-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-11332.html . openSUSE updates ansible-core for an important security issue with arbitrary code execution risk. Install recommended fixes.. openSUSE security, ansible-core update, code execution risk, security patch, system vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 Important OpenSUSE
100

SUSE Ansible-Core Important Arbitrary Code Exec Vulnerability 2026-22171-1

An update that solves one vulnerability can now be installed.. # Security update for ansible-core Announcement ID: SUSE-SU-2026:22171-1 Release Date: 2026-06-19T06:39:42Z Rating: important References: * bsc#1267822 Cross-References: * CVE-2026-11332 CVSS scores: * CVE-2026-11332 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11332 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for ansible-core fixes the following issue * CVE-2026-11332: argument injection in ansible-galaxy role install leads to arbitrary code execution (bsc#1267822). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-962=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-962=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * ansible-core-2.18.3-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * ansible-core-2.18.3-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11332.html * https://bugzilla.suse.com/show_bug.cgi?id=1267822 . SUSE updates ansible-core to fix important issue allowing arbitrary code execution via injected arguments. Act now!. ansible-core security update, SUSE Linux vulnerability, CVE-2026-11332 patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 23, 2026 Important SuSE
89

Fedora 43 Ansible-Core Important Argument Injection Fix CVE-2026-11332

Mitigates CVE-2026-11332 (rhbz#2485397). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-f027f57724 2026-06-20 01:06:42.654493+00:00 -------------------------------------------------------------------------------- Name : ansible-core Product : Fedora 43 Version : 2.18.18~rc1 Release : 1.fc43 URL : https://ansible.com Summary : A radically simple IT automation system Description : Ansible is a radically simple model-driven configuration management, multi-node deployment, and remote task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically. This is the base part of ansible (the engine). -------------------------------------------------------------------------------- Update Information: Mitigates CVE-2026-11332 (rhbz#2485397) -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 11 2026 Maxwell G - 2.18.18~rc1-1 - Update to 2.18.18~rc1. - Mitigates CVE-2026-11332 (rhbz#2485397) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2485397 - CVE-2026-11332 ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2485397 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-f027f57724' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can befound at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Mitigation of argument injection flaw in ansible-core for Fedora 43, addressing CVE-2026-11332.. Fedora 43, ansible-core security, CVE-2026-11332, important security updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 19, 2026 Important Fedora
202

openSUSE 15.6: 2025:0601-1 important: brise auth bypass and injection

An update that solves two vulnerabilities can now be installed.. # Security update for brise Announcement ID: SUSE-SU-2025:0601-1 Release Date: 2025-02-20T09:14:15Z Rating: important References: * bsc#1234597 * bsc#1235573 Cross-References: * CVE-2024-45337 * CVE-2025-21613 CVSS scores: * CVE-2024-45337 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45337 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-21613 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-21613 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear * CVE-2025-21613 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for brise fixes the following issues: * CVE-2025-21613: Fixed argument injection via the URL field (bsc#1235573). * CVE-2024-45337: Fixed authorization bypass in golang.org/x/crypto via the ServerConfig.PublicKeyCallback callback (bsc#1234597). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-601=1 SUSE-2025-601=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-601=1 ## Package List: * openSUSE Leap 15.6 (noarch) * rime-schema-soutzoe-20230603+git.5fdd2d6-150600.3.8.1 *rime-schema-emoji-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-bopomofo-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-wugniu-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-luna-pinyin-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-wubi-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-stenotype-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-pinyin-simp-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-terra-pinyin-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-cantonese-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-default-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-quick-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-custom-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-essay-simp-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-essay-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-ipa-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-scj-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-all-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-double-pinyin-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-array-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-combo-pinyin-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-middle-chinese-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-prelude-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-cangjie-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-stroke-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-extra-20230603+git.5fdd2d6-150600.3.8.1 * Desktop Applications Module 15-SP6 (noarch) * rime-schema-soutzoe-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-emoji-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-bopomofo-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-wugniu-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-luna-pinyin-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-wubi-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-stenotype-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-pinyin-simp-20230603+git.5fdd2d6-150600.3.8.1 *rime-schema-terra-pinyin-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-cantonese-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-default-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-quick-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-custom-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-essay-simp-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-essay-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-ipa-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-scj-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-all-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-double-pinyin-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-array-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-combo-pinyin-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-middle-chinese-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-prelude-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-cangjie-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-stroke-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-extra-20230603+git.5fdd2d6-150600.3.8.1 ## References: * https://www.suse.com/security/cve/CVE-2024-45337.html * https://www.suse.com/security/cve/CVE-2025-21613.html * https://bugzilla.suse.com/show_bug.cgi?id=1234597 * https://bugzilla.suse.com/show_bug.cgi?id=1235573 . Critical safety enhancements targeting flaws in brise for openSUSE. Immediate application advised for rectification.. openSUSE Update, Brise Security Fix, Important Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 21, 2025 Important OpenSUSE
100

SUSE: 2025:0601-1 critical: brise argument injection and bypass

* bsc#1234597 * bsc#1235573 Cross-References: * CVE-2024-45337 . # Security update for brise Announcement ID: SUSE-SU-2025:0601-1 Release Date: 2025-02-20T09:14:15Z Rating: important References: * bsc#1234597 * bsc#1235573 Cross-References: * CVE-2024-45337 * CVE-2025-21613 CVSS scores: * CVE-2024-45337 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45337 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-21613 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-21613 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear * CVE-2025-21613 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for brise fixes the following issues: * CVE-2025-21613: Fixed argument injection via the URL field (bsc#1235573). * CVE-2024-45337: Fixed authorization bypass in golang.org/x/crypto via the ServerConfig.PublicKeyCallback callback (bsc#1234597). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-601=1 SUSE-2025-601=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-601=1 ## Package List: * openSUSE Leap 15.6 (noarch) * rime-schema-soutzoe-20230603+git.5fdd2d6-150600.3.8.1 *rime-schema-emoji-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-bopomofo-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-wugniu-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-luna-pinyin-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-wubi-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-stenotype-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-pinyin-simp-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-terra-pinyin-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-cantonese-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-default-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-quick-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-custom-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-essay-simp-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-essay-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-ipa-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-scj-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-all-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-double-pinyin-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-array-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-combo-pinyin-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-middle-chinese-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-prelude-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-cangjie-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-stroke-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-extra-20230603+git.5fdd2d6-150600.3.8.1 * Desktop Applications Module 15-SP6 (noarch) * rime-schema-soutzoe-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-emoji-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-bopomofo-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-wugniu-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-luna-pinyin-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-wubi-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-stenotype-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-pinyin-simp-20230603+git.5fdd2d6-150600.3.8.1 *rime-schema-terra-pinyin-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-cantonese-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-default-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-quick-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-custom-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-essay-simp-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-essay-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-ipa-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-scj-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-all-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-double-pinyin-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-array-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-combo-pinyin-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-middle-chinese-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-prelude-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-cangjie-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-stroke-20230603+git.5fdd2d6-150600.3.8.1 * rime-schema-extra-20230603+git.5fdd2d6-150600.3.8.1 ## References: * https://www.suse.com/security/cve/CVE-2024-45337.html * https://www.suse.com/security/cve/CVE-2025-21613.html * https://bugzilla.suse.com/show_bug.cgi?id=1234597 * https://bugzilla.suse.com/show_bug.cgi?id=1235573 . Vital security upgrade for brise addressing two significant vulnerabilities and improving overall system protection.. brise security,SUSE updates,critical issues,software security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 21, 2025 Important SuSE
100

SUSE: 2025:0277-1 important: amazon-ssm-agent buffer injection

* bsc#1235575 Cross-References: * CVE-2025-21613 . # Security update for amazon-ssm-agent Announcement ID: SUSE-SU-2025:0277-1 Release Date: 2025-01-28T23:46:33Z Rating: important References: * bsc#1235575 Cross-References: * CVE-2025-21613 CVSS scores: * CVE-2025-21613 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-21613 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear * CVE-2025-21613 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * Public Cloud Module 15-SP3 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for amazon-ssm-agent fixes the following issues: Update to version 3.3.1611.0: * CVE-2025-21613: Fixed argument injection via the URL field in github.com/go- git/go-git/v5 (bsc#1235575) Full changelog: agent/compare/3.1.1260.0...3.3.1611.0 ## Patch Instructions: To install this SUSE update use the SUSE recommended installationmethods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-277=1 * Public Cloud Module 15-SP3 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP3-2025-277=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2025-277=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2025-277=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2025-277=1 ## Package List: * openSUSE Leap 15.6 (aarch64 x86_64) * amazon-ssm-agent-3.3.1611.0-150000.5.20.1 * Public Cloud Module 15-SP3 (aarch64 x86_64) * amazon-ssm-agent-3.3.1611.0-150000.5.20.1 * Public Cloud Module 15-SP4 (aarch64 x86_64) * amazon-ssm-agent-3.3.1611.0-150000.5.20.1 * Public Cloud Module 15-SP5 (aarch64 x86_64) * amazon-ssm-agent-3.3.1611.0-150000.5.20.1 * Public Cloud Module 15-SP6 (aarch64 x86_64) * amazon-ssm-agent-3.3.1611.0-150000.5.20.1 ## References: * https://www.suse.com/security/cve/CVE-2025-21613.html * https://bugzilla.suse.com/show_bug.cgi?id=1235575 . Critical security patch for amazon-ssm-agent (SUSE-SU-2025:0278-1) released featuring essential updates and installation guidelines.. amazon ssm agent, SUSE update, security patch, argument injection, security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 29, 2025 Important SuSE
100

SUSE: 2025:0191-1 important: amazon-ssm-agent fixes argument injection

* bsc#1235575 Cross-References: * CVE-2025-21613 . # Security update for amazon-ssm-agent Announcement ID: SUSE-SU-2025:0191-1 Release Date: 2025-01-20T06:49:22Z Rating: important References: * bsc#1235575 Cross-References: * CVE-2025-21613 CVSS scores: * CVE-2025-21613 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-21613 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear * CVE-2025-21613 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for amazon-ssm-agent fixes the following issues: Update to version 3.3.1611.0: * CVE-2025-21613: Fixed argument injection via the URL field in github.com/go- git/go-git/v5 (bsc#1235575) Full changelog: agent/compare/3.1.1260.0...3.3.1611.0 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2025-191=1 ## Package List: * Public Cloud Module 12 (aarch64 x86_64) * amazon-ssm-agent-3.3.1611.0-4.36.1 ## References: * https://www.suse.com/security/cve/CVE-2025-21613.html * https://bugzilla.suse.com/show_bug.cgi?id=1235575 . Amazon-SSM-Agent security update released addressing important issues including argument injection vulnerabilities.. amazon ssm agent update,suse security advisory,cloud module vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 20, 2025 Important SuSE
89

Fedora 39: FEDORA-2024-52c23ef1ec Moderate: PHP Buffer Fix and Updates

PHP version 8.2.20 (06 Jun 2024) CGI: Fixed buffer limit on Windows, replacing read call usage by _read. (David Carlier) Fixed bug GHSA-3qgc-jrrr-25jv (Bypass of CVE-2012-1823, Argument Injection in. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-52c23ef1ec 2024-06-13 03:03:09.807841 -------------------------------------------------------------------------------- Name : php Product : Fedora 39 Version : 8.2.20 Release : 1.fc39 URL : http://www.php.net/ Summary : PHP scripting language for creating dynamic web sites Description : PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts. -------------------------------------------------------------------------------- Update Information: PHP version 8.2.20 (06 Jun 2024) CGI: Fixed buffer limit on Windows, replacing read call usage by _read. (David Carlier) Fixed bug GHSA-3qgc-jrrr-25jv (Bypass of CVE-2012-1823, Argument Injection in PHP-CGI). (CVE-2024-4577) (nielsdos) CLI: Fixed bug GH-14189 (PHP Interactive shell input state incorrectly handles quoted heredoc literals.). (nielsdos) Core: Fixed bug GH-13970 (Incorrect validation of #[Attribute] flags type for non- compile-time expressions). (ilutov) Fixed bug GH-14140 (Floating point bug in range operation on Apple Silicon hardware). (Derick, Saki) DOM: Fix crashes when entity declaration is removed while still having entity references. (nielsdos) Fix references not handled correctly in C14N. (nielsdos) Fix crash when calling childNodes next() when iterator is exhausted. (nielsdos) Fix crash in ParentNode::append() when dealing with afragment containing text nodes. (nielsdos) FFI: Fixed bug GH-14215 (Cannot use FFI::load on CRLF header file with apache2handler). (nielsdos) Filter: Fixed bug GHSA-w8qr-v226-r27w (Filter bypass in filter_var FILTER_VALIDATE_URL). (CVE-2024-5458) (nielsdos) FPM: Fix bug GH-14175 (Show decimal number instead of scientific notation in systemd status). (Benjamin Cremer) Hash: ext/hash: Swap the checking order of __has_builtin and __GNUC__ (Saki Takamachi) Intl: Fixed build regression on systems without C++17 compilers. (Calvin Buckley, Peter Kokot) Ini: Fixed bug GH-14100 (Corrected spelling mistake in php.ini files). (Marcus Xavier) MySQLnd: Fix bug GH-14255 (mysqli_fetch_assoc reports error from nested query). (Kamil Tekiela) Opcache: Fixed bug GH-14109 (Fix accidental persisting of internal class constant in shm). (ilutov) OpenSSL: The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request: https://github.com/openssl/openssl/pull/13817 (rsa_pkcs1_implicit_rejection). These changes are part of OpenSSL 3.2 and have also been backported to stable versions of various Linux distributions, as well as to the PHP builds provided for Windows since the previous release. All distributors and builders should ensure that this version is used to prevent PHP from being vulnerable. (CVE-2024-2408) Standard: Fixed bug GHSA-9fcc-425m-g385 (Bypass of CVE-2024-1874). (CVE-2024-5585) (nielsdos) XML: Fixed bug GH-14124 (Segmentation fault with XML extension under certain memory limit). (nielsdos) XMLReader: Fixed bug GH-14183 (XMLReader::open() can't be overridden). (nielsdos) -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 4 2024 Remi Collet - 8.2.20-1 - Update to 8.2.20 -http://www.php.net/releases/8_2_20.php -------------------------------------------------------------------------------- References: [ 1 ] Bug #2291252 - CVE-2024-5458 php: Filter bypass in filter_var (FILTER_VALIDATE_URL) https://bugzilla.redhat.com/show_bug.cgi?id=2291252 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-52c23ef1ec' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . PHP 8.2.20 has launched revisions focused on optimizing memory thresholds, rectifying security flaws, and enhancing functionalities for Fedora 39.. PHP Updates, Fedora Security, Buffer Limit Fix, Argument Injection, Web Development. . LinuxSecurity.com Team

Calendar%202 Jun 13, 2024 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200