Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
219

Rocky Linux 10 udisks2 Important Backup Authorization Flaws RLSA-2026-3476

Important: udisks2 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:3476", "synopsis": "Important: udisks2 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for udisks2.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The Udisks project provides a daemon, tools, and libraries to access and manipulate disks, storage devices, and technologies.\n\nSecurity Fix(es):\n\n* udisks: Missing Authorization Check Allows Unprivileged Users to Back Up LUKS Headers via udisks D-Bus API (CVE-2026-26104)\n\n* udisks: Missing Authorization Check Allows Unprivileged Users to Restore LUKS Headers via udisks D-Bus API (CVE-2026-26103)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2433719", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2433719", "description": ""}, {"ticket": "2433717", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2433717", "description": ""}], "cves": [{"name": "CVE-2026-26103", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-26103", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H", "cvss3BaseScore": "7.1", "cwe": "CWE-862"}, {"name": "CVE-2026-26104", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-26104", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "5.5", "cwe": "CWE-862"}], "references": [], "publishedAt": "2026-03-05T09:12:24.748134Z", "rpms": {"Rocky Linux 10": {"nvras": ["udisks2-lvm2-debuginfo-0:2.10.90-6.el10_1.1.x86_64.rpm","udisks2-lsm-0:2.10.90-6.el10_1.1.s390x.rpm", "udisks2-iscsi-0:2.10.90-6.el10_1.1.ppc64le.rpm", "udisks2-lvm2-debuginfo-0:2.10.90-6.el10_1.1.aarch64.rpm", "udisks2-0:2.10.90-6.el10_1.1.s390x.rpm", "libudisks2-debuginfo-0:2.10.90-6.el10_1.1.s390x.rpm", "libudisks2-devel-0:2.10.90-6.el10_1.1.ppc64le.rpm", "libudisks2-devel-0:2.10.90-6.el10_1.1.aarch64.rpm", "udisks2-debuginfo-0:2.10.90-6.el10_1.1.ppc64le.rpm", "libudisks2-devel-0:2.10.90-6.el10_1.1.s390x.rpm", "udisks2-lvm2-debuginfo-0:2.10.90-6.el10_1.1.ppc64le.rpm", "udisks2-debugsource-0:2.10.90-6.el10_1.1.s390x.rpm", "udisks2-iscsi-debuginfo-0:2.10.90-6.el10_1.1.aarch64.rpm", "udisks2-lsm-0:2.10.90-6.el10_1.1.ppc64le.rpm", "udisks2-0:2.10.90-6.el10_1.1.x86_64.rpm", "udisks2-debuginfo-0:2.10.90-6.el10_1.1.x86_64.rpm", "udisks2-0:2.10.90-6.el10_1.1.ppc64le.rpm", "udisks2-lsm-debuginfo-0:2.10.90-6.el10_1.1.s390x.rpm", "udisks2-iscsi-0:2.10.90-6.el10_1.1.x86_64.rpm", "udisks2-lsm-0:2.10.90-6.el10_1.1.x86_64.rpm", "udisks2-debugsource-0:2.10.90-6.el10_1.1.x86_64.rpm", "libudisks2-debuginfo-0:2.10.90-6.el10_1.1.x86_64.rpm", "udisks2-iscsi-debuginfo-0:2.10.90-6.el10_1.1.x86_64.rpm", "udisks2-lvm2-debuginfo-0:2.10.90-6.el10_1.1.s390x.rpm", "libudisks2-0:2.10.90-6.el10_1.1.ppc64le.rpm", "udisks2-debuginfo-0:2.10.90-6.el10_1.1.s390x.rpm", "libudisks2-devel-0:2.10.90-6.el10_1.1.x86_64.rpm", "udisks2-iscsi-0:2.10.90-6.el10_1.1.aarch64.rpm", "udisks2-0:2.10.90-6.el10_1.1.src.rpm", "udisks2-iscsi-0:2.10.90-6.el10_1.1.s390x.rpm", "udisks2-lvm2-0:2.10.90-6.el10_1.1.aarch64.rpm", "libudisks2-0:2.10.90-6.el10_1.1.aarch64.rpm", "udisks2-lsm-debuginfo-0:2.10.90-6.el10_1.1.aarch64.rpm", "libudisks2-debuginfo-0:2.10.90-6.el10_1.1.ppc64le.rpm", "udisks2-lvm2-0:2.10.90-6.el10_1.1.x86_64.rpm", "udisks2-lsm-debuginfo-0:2.10.90-6.el10_1.1.x86_64.rpm", "udisks2-lsm-0:2.10.90-6.el10_1.1.aarch64.rpm", "libudisks2-0:2.10.90-6.el10_1.1.s390x.rpm", "udisks2-lvm2-0:2.10.90-6.el10_1.1.s390x.rpm", "udisks2-iscsi-debuginfo-0:2.10.90-6.el10_1.1.s390x.rpm","udisks2-iscsi-debuginfo-0:2.10.90-6.el10_1.1.ppc64le.rpm", "libudisks2-debuginfo-0:2.10.90-6.el10_1.1.aarch64.rpm", "udisks2-lvm2-0:2.10.90-6.el10_1.1.ppc64le.rpm", "udisks2-0:2.10.90-6.el10_1.1.aarch64.rpm", "udisks2-lsm-debuginfo-0:2.10.90-6.el10_1.1.ppc64le.rpm", "libudisks2-0:2.10.90-6.el10_1.1.x86_64.rpm", "udisks2-debuginfo-0:2.10.90-6.el10_1.1.aarch64.rpm", "udisks2-debugsource-0:2.10.90-6.el10_1.1.ppc64le.rpm", "udisks2-debugsource-0:2.10.90-6.el10_1.1.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A security update has been released for udisks2 on Rocky Linux, fixing important authorization issues.. udisks2 security, Rocky Linux update, authorization check, security bug, disk management. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 05, 2026 Important Rocky Linux
89

Fedora 41: restic 0.18.1 Advisory - Urgent Security Concerns Identified

Update to 0.18.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-f618726d01 2025-12-03 01:35:38.231695+00:00 -------------------------------------------------------------------------------- Name : restic Product : Fedora 41 Version : 0.18.1 Release : 1.fc41 URL : https://github.com/restic/restic Summary : Fast, secure, efficient backup program Description : Fast, secure, efficient backup program. restic supports the following backends for storing backups natively: * Local directory * sftp server (via SSH) * HTTP REST server (protocol, rest-server) * Amazon S3 (either from Amazon or using the Minio server) * OpenStack Swift * BackBlaze B2 * Microsoft Azure Blob Storage * Google Cloud Storage * And many other services via the rclone Backend -------------------------------------------------------------------------------- Update Information: Update to 0.18.1 -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 24 2025 Mikel Olasagasti Uranga - 0.18.1-1 - Update to 0.18.1 - Closes rhbz#2397204 rhbz2416773 * Fri Oct 10 2025 Alejandro Sez - 0.18.0-5 - rebuild * Fri Aug 15 2025 Maxwell G - 0.18.0-4 - Rebuild for golang-1.25.0 * Fri Jul 25 2025 Fedora Release Engineering - 0.18.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2398617 - CVE-2025-47910 restic: CrossOriginProtection bypass in net/http [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2398617 [ 2 ] Bug #2399283 - CVE-2025-47906 restic: Unexpected paths returned from LookPath in os/exec [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2399283 [ 3 ] Bug #2407817 - CVE-2025-58189 restic: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2407817 [ 4 ] Bug #2408622 - CVE-2025-61725 restic: Excessive CPU consumption in ParseAddress in net/mail [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2408622 [ 5 ] Bug #2409283 - CVE-2025-61723 restic: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2409283 [ 6 ] Bug #2410232 - CVE-2025-58185 restic: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2410232 [ 7 ] Bug #2411147 - CVE-2025-58188 restic: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2411147 [ 8 ] Bug #2412580 - CVE-2025-58183 restic: Unbounded allocation when parsing GNU sparse map [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2412580 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f618726d01' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Stay informed about critical updates for restic on Fedora 41 to enhance security and performance. Read more!. restic Fedora update security backup program. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 03, 2025 Important Fedora
203

Mageia 9: MGASA-2024-0376 moderate: golang stack exhaustion issues

Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stack exhaustion. CVE-2024-34155 Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion CVE-2024-34156 . MGASA-2024-0376 - Updated golang packages fix security vulnerabilities Publication date: 27 Nov 2024 URL: https://advisories.mageia.org/MGASA-2024-0376.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-34155, CVE-2024-34156, CVE-2024-34158 Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stack exhaustion. CVE-2024-34155 Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion CVE-2024-34156 Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.CVE-2024-34158 References: - https://bugs.mageia.org/show_bug.cgi?id=33526 - https://www.openwall.com/lists/oss-security/2024/09/05/1 - https://www.cve.org/CVERecord?id=CVE-2024-34155 - https://www.cve.org/CVERecord?id=CVE-2024-34156 - https://www.cve.org/CVERecord?id=CVE-2024-34158 SRPMS: - 9/core/golang-1.22.9-1.mga9 . Discover MGASA-2024-0376, which highlights Go language improvements tackling panic issues in nested literals, enhancing security, efficiency, and reliability for developers. Mageia Security Advisory, Golang Update, Stack Exhaustion Fix. . LinuxSecurity.com Team

Calendar 2 Nov 27, 2024 Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here