Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 2 articles for you...
197

Debian 11: Samba Critical Info Disclosure CVE-2025-9640 DLA-4384-1

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4384-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Paride Legovini November 26, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : samba Version : 2:4.13.13+dfsg-1~deb11u7 CVE ID : CVE-2025-9640 A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability. For Debian 11 bullseye, this problem has been fixed in version 2:4.13.13+dfsg-1~deb11u7. We recommend that you upgrade your samba packages. For the detailed security status of samba please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/samba Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A flaw in Samba allows unauthorized access to data due to uninitialized memory, posing critical risks.. Debian Samba Security, Information Disclosure Bug, Samba System Update, Debian Vulnerability Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 26, 2025 Critical Debian LTS
202

Important Proxy Authentication Issue in openSUSE Leap 15.4 Advisory

An update that solves one vulnerability can now be installed.. # Security update for squid Announcement ID: SUSE-SU-2025:3902-1 Release Date: 2025-10-31T17:08:05Z Rating: important References: * bsc#1252281 Cross-References: * CVE-2025-62168 CVSS scores: * CVE-2025-62168 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2025-62168 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2025-62168 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2025-62168 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Proxy 4.3 LTS * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Retail Branch Server 4.3 LTS * SUSE Manager Server 4.3 * SUSE Manager Server 4.3 LTS An update that solves one vulnerability can now be installed. ## Description: This update for squid fixes the following issues: * CVE-2025-62168: Fixed proxy auth data visible to scripts (bsc#1252281). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-3902=1 * SUSELinux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-3902=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-3902=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-3902=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-3902=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-3902=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-3902=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-3902=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-3902=1 * SUSE Manager Proxy 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-LTS-2025-3902=1 * SUSE Manager Retail Branch Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-LTS-2025-3902=1 * SUSE Manager Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-LTS-2025-3902=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Linux Enterprise High Performance ComputingESPOS 15 SP5 (aarch64 x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Manager Proxy 4.3 LTS (x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Manager Retail Branch Server 4.3 LTS (x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 * SUSE Manager Server 4.3 LTS (ppc64le s390x x86_64) * squid-5.7-150400.3.38.2 * squid-debugsource-5.7-150400.3.38.2 * squid-debuginfo-5.7-150400.3.38.2 ## References: * https://www.suse.com/security/cve/CVE-2025-62168.html * https://bugzilla.suse.com/show_bug.cgi?id=1252281 . SUSE addresses an important squid vulnerability in openSUSE and offers guidance on how to apply updates.. openSUSE Security Fix, Squid Vulnerability Patch, SUSE Update Important. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 31, 2025 Important OpenSUSE
100

SUSE 15-SP6/15-SP7: 2025:02080-1 important: pam-config update

* bsc#1243226 Cross-References: * CVE-2025-6018 . # Security update for pam-config Announcement ID: SUSE-SU-2025:02080-1 Release Date: 2025-06-24T10:26:31Z Rating: important References: * bsc#1243226 Cross-References: * CVE-2025-6018 CVSS scores: * CVE-2025-6018 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-6018 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for pam-config fixes the following issues: * CVE-2025-6018: Stop adding pam_env in AUTH stack, and be sure to put this module at the really end of the SESSION stack (bsc#1243226). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-2080=1 openSUSE-SLE-15.6-2025-2080=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-2080=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-2080=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * pam-config-1.1-150600.16.8.1 * pam-config-debugsource-1.1-150600.16.8.1 * pam-config-debuginfo-1.1-150600.16.8.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * pam-config-1.1-150600.16.8.1 *pam-config-debugsource-1.1-150600.16.8.1 * pam-config-debuginfo-1.1-150600.16.8.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * pam-config-1.1-150600.16.8.1 * pam-config-debugsource-1.1-150600.16.8.1 * pam-config-debuginfo-1.1-150600.16.8.1 ## References: * https://www.suse.com/security/cve/CVE-2025-6018.html * https://bugzilla.suse.com/show_bug.cgi?id=1243226 . Urgent enhancement for pam-config tackling CVE-2025-6018 to bolster system stability and safeguarding in SUSE configurations.. SUSE Linux,pam-config update,system security threat,package management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 24, 2025 Important SuSE
89

Fedora 42: krb5 2025-3de9fe91ff critical: message spoofing risk

Disallowing use of the arcfour-hmac(-md5) encryption type for session keys Add support for the PKINIT paChecksum2 sequence, required for Active Directory interoperability on Windows Server 2025 Fix generation of RADIUS Message-Authenticator in FIPS mode. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-3de9fe91ff 2025-06-09 02:34:27.502391+00:00 -------------------------------------------------------------------------------- Name : krb5 Product : Fedora 42 Version : 1.21.3 Release : 6.fc42 URL : https://web.mit.edu/kerberos/www/ Summary : The Kerberos network authentication system Description : Kerberos V5 is a trusted-third-party network authentication system, which can improve your network's security by eliminating the insecure practice of sending passwords over the network in unencrypted form. -------------------------------------------------------------------------------- Update Information: Disallowing use of the arcfour-hmac(-md5) encryption type for session keys Add support for the PKINIT paChecksum2 sequence, required for Active Directory interoperability on Windows Server 2025 Fix generation of RADIUS Message-Authenticator in FIPS mode -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 4 2025 Julien Rische - 1.21.3-6 - Do not block HMAC-MD4/5 in FIPS mode Resolves: rhbz#2370259 - PKINIT: implement paChecksum2 from MS-PKCA v20230920 Resolves: rhbz#2357215 - Disallow RC4 HMAC-MD5 session keys by default (CVE-2025-3576) Resolves: rhbz#2359705 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2357215 - PKINIT: implement paChecksum2 from MS-PKCA v20230920 [fedora] https://bugzilla.redhat.com/show_bug.cgi?id=2357215 [ 2 ] Bug #2359705 - CVE-2025-3576 krb5: Kerberos RC4-HMAC-MD5 Checksum Vulnerability Enabling Message Spoofing via MD5Collisions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2359705 [ 3 ] Bug #2370259 - Do not block HMAC-MD4/5 in FIPS mode [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2370259 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-3de9fe91ff' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 42 brings improvements to krb5, boosting both Kerberos authentication security and its interoperability with Windows Server.. krb5 security update, Fedora security advisory, encryption updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 09, 2025 Critical Fedora
197

Debian LTS 2.4.9.4-0: DLA-4129-1 moderate: mod_auth_openidc security flaw

A vulnerability has been fixed in mod_auth_openidc, an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4129-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Moritz Schlarb April 17, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : libapache2-mod-auth-openidc Version : 2.4.9.4-0+deb11u5 CVE ID : CVE-2025-31492 Debian Bug : 1102413 A vulnerability has been fixed in mod_auth_openidc, an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. The bug in mod_auth_openidc results in disclosure of protected content to unauthenticated users. The conditions for disclosure are the following directives: OIDCProviderAuthRequestMethod POST Require valid-user and there mustn't be any application-level gateway (or load balancer etc) protecting the server. When you request a protected resource, the response includes the HTTP status, the HTTP headers, the intended response (the self-submitting form), *and the protected resource (with no headers)*. The patch fixing this issue has been backported from mod_auth_openidc 2.4.16.11. For Debian 11 bullseye, this problem has been fixed in version 2.4.9.4-0+deb11u5. We recommend that you upgrade your libapache2-mod-auth-openidc packages. For the detailed security status of libapache2-mod-auth-openidc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libapache2-mod-auth-openidc Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questionscan be found at: https://wiki.debian.org/LTS . An essential patch for libapache2-mod-auth-openidc addresses a major security vulnerability concerning data exposure in Debian LTS.. libapache2-mod-auth-openidc, Debian LTS update, security patch, authentication module, content protection. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 17, 2025 Important Debian LTS
197

Debian Buster: DLA-3409-1 Critical: libapache2-mod-auth-openidc Issues

Several vulnerabilities were fixed in libapache2-mod-auth-openidc, an OpenID Connect Relying Party implementation for Apache. CVE-2019-20479 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3409-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk April 30, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libapache2-mod-auth-openidc Version : 2.3.10.2-1+deb10u2 CVE ID : CVE-2019-20479 CVE-2021-32785 CVE-2021-32786 CVE-2021-32791 CVE-2021-32792 CVE-2023-28625 Debian Bug : 991580 991581 991582 991583 1033916 Several vulnerabilities were fixed in libapache2-mod-auth-openidc, an OpenID Connect Relying Party implementation for Apache. CVE-2019-20479 Insufficient validatation of URLs beginning with a slash and backslash. CVE-2021-32785 Crash when using an unencrypted Redis cache. CVE-2021-32786 Open Redirect vulnerability in the logout functionality. CVE-2021-32791 AES GCM encryption in used static IV and AAD. CVE-2021-32792 XSS vulnerability when using OIDCPreservePost. CVE-2023-28625 NULL pointer dereference with OIDCStripCookies. For Debian 10 buster, these problems have been fixed in version 2.3.10.2-1+deb10u2. We recommend that you upgrade your libapache2-mod-auth-openidc packages. For the detailed security status of libapache2-mod-auth-openidc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libapache2-mod-auth-openidc Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3410-1 resolves various vulnerabilities in libapache2-mod-auth-saml. Immediate update advised.. Debian LTS Advisory,libapache2-mod-auth-openidc, OpenID Connect, security update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 30, 2023 Critical Debian LTS
203

Mageia 7 MGASA-2020-0298 Critical: Intel Microcode Information Disclosure

Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. (CVE-2020-0543) Cleanup errors in some Intel(R) Processors may allow an authenticated user . MGASA-2020-0298 - Updated microcode packages fix security vulnerability Publication date: 31 Jul 2020 URL: https://advisories.mageia.org/MGASA-2020-0298.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-0543, CVE-2020-0548, CVE-2020-0549 Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. (CVE-2020-0543) Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. (CVE-2020-0548) Cleanup errors in some data cache evictions for some Intel(R) Processorsmay allow an authenticated user to potentially enable information disclosure via local access. (CVE-2020-0549) References: - https://bugs.mageia.org/show_bug.cgi?id=26783 - https://lists.debian.org/debian-security-announce/2020/msg00105.html - https://access.redhat.com/errata/RHSA-2020:2431 - https://ubuntu.com/security/notices/USN-4385-1 - https://ubuntu.com/security/notices/USN-4385-2 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/T5OUM24ZC43G4IDT3JUCIHJTSDXJSK6Y/ - https://www.cve.org/CVERecord?id=CVE-2020-0543 - https://www.cve.org/CVERecord?id=CVE-2020-0548 - https://www.cve.org/CVERecord?id=CVE-2020-0549 SRPMS: - 7/nonfree/microcode-0.20200616-1.mga7.nonfree . Mageia's recent microcode patch targets security vulnerabilities in Intel CPUs, which could potentially expose sensitive data. Find comprehensive update insights below.. Mageia Microcode Update, Intel Processor Security, Information Disclosure Fix, Software Patch, Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 31, 2020 Critical Mageia
98

Red Hat Enterprise Linux 6 RHSA-2019:1726-01 Important Auth Bypass Issue

An update for dbus is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: dbus security update Advisory ID: RHSA-2019:1726-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:1726 Issue date: 2019-07-10 CVE Names: CVE-2019-12749 ==================================================================== 1. Summary: An update for dbus is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, noarch, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - noarch, x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - noarch Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - noarch 3. Description: D-Bus is a system for sending messages between applications. It is used both for the system-wide message bus service, and as a per-user-login-session messaging facility. Security Fix(es): * dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass (CVE-2019-12749) For more details about the security issue(s), including the impact, a CVSS score,acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all running instances of dbus-daemon and all running applications using the libdbus library must be restarted, or the system rebooted. 5. Bugs fixed (https://bugzilla.redhat.com/): 1719344 - CVE-2019-12749 dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: dbus-1.2.24-11.el6_10.src.rpm i386: dbus-1.2.24-11.el6_10.i686.rpm dbus-debuginfo-1.2.24-11.el6_10.i686.rpm dbus-libs-1.2.24-11.el6_10.i686.rpm dbus-x11-1.2.24-11.el6_10.i686.rpm x86_64: dbus-1.2.24-11.el6_10.x86_64.rpm dbus-debuginfo-1.2.24-11.el6_10.i686.rpm dbus-debuginfo-1.2.24-11.el6_10.x86_64.rpm dbus-libs-1.2.24-11.el6_10.i686.rpm dbus-libs-1.2.24-11.el6_10.x86_64.rpm dbus-x11-1.2.24-11.el6_10.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): i386: dbus-debuginfo-1.2.24-11.el6_10.i686.rpm dbus-devel-1.2.24-11.el6_10.i686.rpm noarch: dbus-doc-1.2.24-11.el6_10.noarch.rpm x86_64: dbus-debuginfo-1.2.24-11.el6_10.i686.rpm dbus-debuginfo-1.2.24-11.el6_10.x86_64.rpm dbus-devel-1.2.24-11.el6_10.i686.rpm dbus-devel-1.2.24-11.el6_10.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: dbus-1.2.24-11.el6_10.src.rpm x86_64: dbus-1.2.24-11.el6_10.x86_64.rpm dbus-debuginfo-1.2.24-11.el6_10.i686.rpm dbus-debuginfo-1.2.24-11.el6_10.x86_64.rpm dbus-libs-1.2.24-11.el6_10.i686.rpm dbus-libs-1.2.24-11.el6_10.x86_64.rpm dbus-x11-1.2.24-11.el6_10.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): noarch: dbus-doc-1.2.24-11.el6_10.noarch.rpm x86_64: dbus-debuginfo-1.2.24-11.el6_10.i686.rpm dbus-debuginfo-1.2.24-11.el6_10.x86_64.rpm dbus-devel-1.2.24-11.el6_10.i686.rpm dbus-devel-1.2.24-11.el6_10.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: dbus-1.2.24-11.el6_10.src.rpm i386: dbus-1.2.24-11.el6_10.i686.rpm dbus-debuginfo-1.2.24-11.el6_10.i686.rpm dbus-devel-1.2.24-11.el6_10.i686.rpm dbus-libs-1.2.24-11.el6_10.i686.rpm dbus-x11-1.2.24-11.el6_10.i686.rpm ppc64: dbus-1.2.24-11.el6_10.ppc64.rpm dbus-debuginfo-1.2.24-11.el6_10.ppc.rpm dbus-debuginfo-1.2.24-11.el6_10.ppc64.rpm dbus-devel-1.2.24-11.el6_10.ppc.rpm dbus-devel-1.2.24-11.el6_10.ppc64.rpm dbus-libs-1.2.24-11.el6_10.ppc.rpm dbus-libs-1.2.24-11.el6_10.ppc64.rpm dbus-x11-1.2.24-11.el6_10.ppc64.rpm s390x: dbus-1.2.24-11.el6_10.s390x.rpm dbus-debuginfo-1.2.24-11.el6_10.s390.rpm dbus-debuginfo-1.2.24-11.el6_10.s390x.rpm dbus-devel-1.2.24-11.el6_10.s390.rpm dbus-devel-1.2.24-11.el6_10.s390x.rpm dbus-libs-1.2.24-11.el6_10.s390.rpm dbus-libs-1.2.24-11.el6_10.s390x.rpm dbus-x11-1.2.24-11.el6_10.s390x.rpm x86_64: dbus-1.2.24-11.el6_10.x86_64.rpm dbus-debuginfo-1.2.24-11.el6_10.i686.rpm dbus-debuginfo-1.2.24-11.el6_10.x86_64.rpm dbus-devel-1.2.24-11.el6_10.i686.rpm dbus-devel-1.2.24-11.el6_10.x86_64.rpm dbus-libs-1.2.24-11.el6_10.i686.rpm dbus-libs-1.2.24-11.el6_10.x86_64.rpm dbus-x11-1.2.24-11.el6_10.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): noarch: dbus-doc-1.2.24-11.el6_10.noarch.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: dbus-1.2.24-11.el6_10.src.rpm i386: dbus-1.2.24-11.el6_10.i686.rpm dbus-debuginfo-1.2.24-11.el6_10.i686.rpm dbus-devel-1.2.24-11.el6_10.i686.rpm dbus-libs-1.2.24-11.el6_10.i686.rpm dbus-x11-1.2.24-11.el6_10.i686.rpm x86_64: dbus-1.2.24-11.el6_10.x86_64.rpm dbus-debuginfo-1.2.24-11.el6_10.i686.rpm dbus-debuginfo-1.2.24-11.el6_10.x86_64.rpm dbus-devel-1.2.24-11.el6_10.i686.rpm dbus-devel-1.2.24-11.el6_10.x86_64.rpm dbus-libs-1.2.24-11.el6_10.i686.rpm dbus-libs-1.2.24-11.el6_10.x86_64.rpm dbus-x11-1.2.24-11.el6_10.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): noarch: dbus-doc-1.2.24-11.el6_10.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature areavailable from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-12749 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXSXIvdzjgjWX9erEAQiCAhAApFcAnV9W/HdPX1OfD/D2Wp4FLIjFBmjI HIGnMlAlfzNmaoVR3JdE2o3tSZYh1mEDUJzwhGKTfPAZhoQfsY+zqKDFm1khUF9C m9+miR4YRYthwKBY2cILrHImza64BhrANJCA4PqhV//GlTEOkxk/4G7orFRyY+tJ X5HSDGXiMKbW77y5179QisvlVU261F4hQ4TXvgwHvCtQXHW8k56rmmRvI+pW8Ks2 ISY0XnfB3d5MbcsB7jFaEfzNmNf5Iw8EjugxQCq+onLSFSauLNS/JfwD+xUry2hj J6Uar2o/lOpmZl6LPVXJ/8hMfmY6e1K+PTEhSXjUKm/2wTC4q6USVfe19fpUvdvq MFDtjHvHYHWJ1G0J+G8pk5Wq5fj6JkRtRv6yVZobgEWVXxP2TheW1zgZe9PknptD SsfaijfwdTeibSJHV9D0pBqC8R5Mu/0Sq2vN016LoQzoe9p7cyoW5hBtDdiTyBbw KIWr7X1fkU0wiTcrV5I/49rofdkmxyjq7oq9NNqtfGoBGgy7uxXLFFbYxNRQhnBL 7zRDEKNV9zqMsCTAzDFP3A98zOrUkJQWDAM6qImtmmWVF4IW4poWO2jkunhQwJ3B WAxAYPjkdobULeT9Xamz9QyueZjlFiGsHCmHGJWLmKtblnmgGmuaRrY4xa34yUGY PMVFOAtrvjc=4jTC -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical dbus security patch for Red Hat Enterprise Linux 6 resolving authentication vulnerabilities, urgent measures required. dbus Update, Red Hat Security, Authentication Bypass. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 10, 2019 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200