Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
219

Rocky Linux 8 RLSA-2026-13834 OpenSSH Vulnerability Announcement

Important: dovecot security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:13830", "synopsis": "Important: dovecot security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dovecot.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages. \n\nSecurity Fix(es):\n\n* dovecot: ManageSieve: Denial of Service via crafted SASL initial response in AUTHENTICATE command (CVE-2025-59032)\n\n* dovecot: denial of service via crafted message before authentication (CVE-2026-27858)\n\n* dovecot: denial of service via specially crafted NOOP command (CVE-2026-27857)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2452172", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2452172", "description": ""}, {"ticket": "2452175", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2452175", "description": ""}, {"ticket": "2452179", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2452179", "description": ""}], "cves": [{"name": "CVE-2025-59032", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59032", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-229"}, {"name": "CVE-2026-27857", "sourceBy": "MITRE", "sourceLink":"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27857", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-770"}, {"name": "CVE-2026-27858", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27858", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-770"}], "references": [], "publishedAt": "2026-05-07T06:00:59.922786Z", "rpms": {"Rocky Linux 8": {"nvras": ["dovecot-1:2.3.16-7.el8_10.aarch64.rpm", "dovecot-1:2.3.16-7.el8_10.i686.rpm", "dovecot-1:2.3.16-7.el8_10.src.rpm", "dovecot-1:2.3.16-7.el8_10.x86_64.rpm", "dovecot-debuginfo-1:2.3.16-7.el8_10.aarch64.rpm", "dovecot-debuginfo-1:2.3.16-7.el8_10.i686.rpm", "dovecot-debuginfo-1:2.3.16-7.el8_10.x86_64.rpm", "dovecot-debugsource-1:2.3.16-7.el8_10.aarch64.rpm", "dovecot-debugsource-1:2.3.16-7.el8_10.i686.rpm", "dovecot-debugsource-1:2.3.16-7.el8_10.x86_64.rpm", "dovecot-devel-1:2.3.16-7.el8_10.aarch64.rpm", "dovecot-devel-1:2.3.16-7.el8_10.i686.rpm", "dovecot-devel-1:2.3.16-7.el8_10.x86_64.rpm", "dovecot-mysql-1:2.3.16-7.el8_10.aarch64.rpm", "dovecot-mysql-1:2.3.16-7.el8_10.x86_64.rpm", "dovecot-mysql-debuginfo-1:2.3.16-7.el8_10.aarch64.rpm", "dovecot-mysql-debuginfo-1:2.3.16-7.el8_10.x86_64.rpm", "dovecot-pgsql-1:2.3.16-7.el8_10.aarch64.rpm", "dovecot-pgsql-1:2.3.16-7.el8_10.x86_64.rpm", "dovecot-pgsql-debuginfo-1:2.3.16-7.el8_10.aarch64.rpm", "dovecot-pgsql-debuginfo-1:2.3.16-7.el8_10.x86_64.rpm", "dovecot-pigeonhole-1:2.3.16-7.el8_10.aarch64.rpm", "dovecot-pigeonhole-1:2.3.16-7.el8_10.x86_64.rpm", "dovecot-pigeonhole-debuginfo-1:2.3.16-7.el8_10.aarch64.rpm", "dovecot-pigeonhole-debuginfo-1:2.3.16-7.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Stay updated with the important Dovecot security update for Rocky Linux 8 addressing multiple denial of service risks.. Dovecot, Rocky Linux 8, security update, denial of service, important issue. . Severity: Important. LinuxSecurity.comTeam

Calendar 2 May 07, 2026 Important Rocky Linux
197

Debian 10 Buster: DLA-3499-1 Moderate: Open Redirect Threat Details

Open Redirect vulnerabilities were found in libapache2-mod-auth-openidc, OpenID Connect Relying Party implementation for Apache, which could lead to information disclosure via phishing attacks. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3499-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin July 19, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : libapache2-mod-auth-openidc Version : 2.3.10.2-1+deb10u3 CVE ID : CVE-2021-39191 CVE-2022-23527 Debian Bug : 993648 1026444 Open Redirect vulnerabilities were found in libapache2-mod-auth-openidc, OpenID Connect Relying Party implementation for Apache, which could lead to information disclosure via phishing attacks. CVE-2021-39191 The 3rd-party init SSO functionality of mod_auth_openidc was reported to be vulnerable to an open redirect attack by supplying a crafted URL in the target_link_uri parameter. CVE-2022-23527 When providing a logout parameter to the redirect URI, mod_auth_openidc failed to properly check for URLs starting with "/\t", leading to an open redirect. For Debian 10 buster, these problems have been fixed in version 2.3.10.2-1+deb10u3. We recommend that you upgrade your libapache2-mod-auth-openidc packages. For the detailed security status of libapache2-mod-auth-openidc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libapache2-mod-auth-openidc Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Mitigate Open Redirect vulnerabilities in libapache2-mod-auth-openidc to enhance cybersecurity and combat phishing threats.. Open Redirect, libapache2-mod-auth-openidc, Debian Advisory, PhishingProtection. . LinuxSecurity.com Team

Calendar 2 Jul 18, 2023 Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here