Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 39: FEDORA-2023-467632ecbe Moderate: Borgbackup Data Loss Fix

fix for CVE-2023-36811: spoofed archive leads to data loss Please note that starting with borgbackup 1.2.5 all borg repos must use TAM authentication: https://github.com/borgbackup/borg/blob/1.2.6/docs/changes.rst#pre-125-archives- spoofing-vulnerability-cve-2023-36811. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-467632ecbe 2023-09-15 18:36:13.241465 -------------------------------------------------------------------------------- Name : borgbackup Product : Fedora 39 Version : 1.2.6 Release : 1.fc39 URL : https://borgbackup.readthedocs.io/en/stable/ Summary : A deduplicating backup program with compression and authenticated encryption Description : BorgBackup (short: Borg) is a deduplicating backup program. Optionally, it supports compression and authenticated encryption. -------------------------------------------------------------------------------- Update Information: fix for CVE-2023-36811: spoofed archive leads to data loss Please note that starting with borgbackup 1.2.5 all borg repos must use TAM authentication: https://github.com/borgbackup/borg/blob/1.2.6/docs/changes.rst#pre-125-archives- spoofing-vulnerability-cve-2023-36811 -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 5 2023 Felix Schwarz - 1.2.6-1 - update to 1.2.6 to fix CVE-2023-36811 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2236305 - CVE-2023-36811 borgbackup: spoofed archive leads to data loss [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2236305 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-467632ecbe' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Addressing CVE-2023-36811 is essential for borgbackup users utilizing Fedora. Ensure you update immediately to protect your backup systems from potential data compromise.. BorgBackup Update, Fedora Security, Spoofing Issues. . LinuxSecurity.com Team

Calendar%202 Sep 15, 2023 Fedora
89

Fedora 37: FEDORA-2023-34411d8f77 Critical BorgBackup Spoofing Issue

fix for CVE-2023-36811: spoofed archive leads to data loss Please note that starting with borgbackup 1.2.5 all borg repos must use TAM authentication: https://github.com/borgbackup/borg/blob/1.2.6/docs/changes.rst#pre-125-archives- spoofing-vulnerability-cve-2023-36811. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-34411d8f77 2023-09-15 01:34:53.819945 -------------------------------------------------------------------------------- Name : borgbackup Product : Fedora 37 Version : 1.2.6 Release : 1.fc37 URL : https://borgbackup.readthedocs.io/en/stable/ Summary : A deduplicating backup program with compression and authenticated encryption Description : BorgBackup (short: Borg) is a deduplicating backup program. Optionally, it supports compression and authenticated encryption. -------------------------------------------------------------------------------- Update Information: fix for CVE-2023-36811: spoofed archive leads to data loss Please note that starting with borgbackup 1.2.5 all borg repos must use TAM authentication: https://github.com/borgbackup/borg/blob/1.2.6/docs/changes.rst#pre-125-archives- spoofing-vulnerability-cve-2023-36811 -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 5 2023 Felix Schwarz - 1.2.6-1 - update to 1.2.6 to fix CVE-2023-36811 - rely on auto-generated version requirement for msgpack -------------------------------------------------------------------------------- References: [ 1 ] Bug #2236305 - CVE-2023-36811 borgbackup: spoofed archive leads to data loss [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2236305 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-34411d8f77' at the command line. For more information, refer to thednf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 37 releases a fix for borgbackup addressing a serious data loss vulnerability linked to a tampered archive identified by CVE-2023-36811.. BorgBackup Update,Fedora Notification,Critical Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 15, 2023 Critical Fedora
89

Fedora 26 borgbackup Security Update FEDORA-2017-7b0a42338c Moderate

upstream version 1.1.3. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-7b0a42338c 2017-12-10 19:21:01.985527 --------------------------------------------------------------------------------Name : borgbackup Product : Fedora 26 Version : 1.1.3 Release : 1.fc26 URL : https://borgbackup.readthedocs.io/en/stable/ Summary : A deduplicating backup program with compression and authenticated encryption Description : BorgBackup (short: Borg) is a deduplicating backup program. Optionally, it supports compression and authenticated encryption. --------------------------------------------------------------------------------Update Information: upstream version 1.1.3 --------------------------------------------------------------------------------References: [ 1 ] Bug #1517664 - borgbackup 1.1.3 is available (CVE-2017-15914) https://bugzilla.redhat.com/show_bug.cgi?id=1517664 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade borgbackup' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Keep updated on Fedora's crucial borgbackup patch with essential details regarding setup and enhancements.. Fedora Security Update, BorgBackup Update, Backup Software Security. . LinuxSecurity.com Team

Calendar%202 Dec 10, 2017 Fedora
89

Fedora 24: FEDORA-2016-3b51e954fd Critical: BorgBackup Security Fix

upstream version 1.0.9 (BZ#1406277). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-3b51e954fd 2017-01-03 16:38:52.539083 -------------------------------------------------------------------------------- Name : borgbackup Product : Fedora 24 Version : 1.0.9 Release : 1.fc24 URL : https://borgbackup.readthedocs.io/en/stable/ Summary : A deduplicating backup program with compression and authenticated encryption Description : BorgBackup (short: Borg) is a deduplicating backup program. Optionally, it supports compression and authenticated encryption. -------------------------------------------------------------------------------- Update Information: upstream version 1.0.9 (BZ#1406277) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1406277 - borgbackup 1.0.9 is available (includes security fixes) https://bugzilla.redhat.com/show_bug.cgi?id=1406277 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade borgbackup' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest BorgBackup security patch features upstream version 1.0.9 for Fedora 24, improving both backup reliability and efficiency.. BorgBackup Update, Fedora Security Fixes, Backup Encryption Solutions. . Severity: Critical. LinuxSecurity.comTeam

Calendar%202 Jan 03, 2017 Critical Fedora
89

Fedora 25 BorgBackup Security Update - BZ#1406277 Critical Fixes

upstream version 1.0.9 (BZ#1406277). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-6e66f01186 2017-01-03 16:39:10.474753 -------------------------------------------------------------------------------- Name : borgbackup Product : Fedora 25 Version : 1.0.9 Release : 1.fc25 URL : https://borgbackup.readthedocs.io/en/stable/ Summary : A deduplicating backup program with compression and authenticated encryption Description : BorgBackup (short: Borg) is a deduplicating backup program. Optionally, it supports compression and authenticated encryption. -------------------------------------------------------------------------------- Update Information: upstream version 1.0.9 (BZ#1406277) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1406277 - borgbackup 1.0.9 is available (includes security fixes) https://bugzilla.redhat.com/show_bug.cgi?id=1406277 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade borgbackup' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The release of Fedora 25 brings a vital security update for BorgBackup, addressing severe flaws while improving backup systems with advanced encryption features.. BorgBackup Security Update, Fedora Backup Update, Backup Program Enhancements. .Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 03, 2017 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200