Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 3 articles for you...
202

openSUSE Leap 16.0 openSUSE-SU-2026-20529-2 Botan Severe TLS Vulnerability

An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for botan ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20528-1 Rating: critical References: * bsc#1261880 Cross-References: * CVE-2026-34582 CVSS scores: * CVE-2026-34582 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for Botan fixes the following issues: - CVE-2026-34582: Fixed a client authentication bypass in TLS 1.3 implementation (bsc#1261880) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-551=1 Package List: - openSUSE Leap 16.0: Botan-3.7.1-160000.3.1 Botan-doc-3.7.1-160000.3.1 libbotan-3-7-3.7.1-160000.3.1 libbotan-devel-3.7.1-160000.3.1 python3-botan-3.7.1-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-34582.html . This update addresses a critical bug in Botan, resolving a TLS 1.3 client auth bypass issue. Upgrade now for security.. openSUSE, Botan, TLS security, critical updates, client authentication. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 21, 2026 Critical OpenSUSE
202

openSUSE Backports 15-SP7 Botan Important TLS Bypass Vuln 2026-0142-1

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for Botan ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0142-1 Rating: important References: #1261880 Cross-References: CVE-2026-34582 CVSS scores: CVE-2026-34582 (SUSE): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for Botan fixes the following issues: - CVE-2026-34582: client authentication bypass in TLS 1.3 implementation (boo#1261880) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-142=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): Botan-3.5.0-bp157.2.3.1 libbotan-3-5-3.5.0-bp157.2.3.1 libbotan-devel-3.5.0-bp157.2.3.1 python3-botan-3.5.0-bp157.2.3.1 - openSUSE Backports SLE-15-SP7 (aarch64_ilp32): libbotan-3-5-64bit-3.5.0-bp157.2.3.1 libbotan-devel-64bit-3.5.0-bp157.2.3.1 - openSUSE Backports SLE-15-SP7 (x86_64): libbotan-3-5-32bit-3.5.0-bp157.2.3.1 libbotan-devel-32bit-3.5.0-bp157.2.3.1 - openSUSE Backports SLE-15-SP7 (noarch): Botan-doc-3.5.0-bp157.2.3.1 References: https://www.suse.com/security/cve/CVE-2026-34582.html https://bugzilla.suse.com/1261880 . Important update for openSUSE addresses TLS authentication bypass issue in Botan. Apply patch promptly for security.. openSUSE update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 20, 2026 Important OpenSUSE
202

openSUSE Tumbleweed Botan Moderate Update for 2026-10540-1 Released

An update that solves 2 vulnerabilities can now be installed.. # Botan-3.11.1-1.1 on GA media Announcement ID: openSUSE-SU-2026:10540-1 Rating: moderate Cross-References: * CVE-2026-35580 * CVE-2026-35582 Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the Botan-3.11.1-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * Botan 3.11.1-1.1 * Botan-doc 3.11.1-1.1 * libbotan-3-11 3.11.1-1.1 * libbotan-devel 3.11.1-1.1 * python3-botan 3.11.1-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-35580.html * https://www.suse.com/security/cve/CVE-2026-35582.html . An update for openSUSE Tumbleweed reduces risk by addressing moderate issues in Botan package.. openSUSE Tumbleweed Botan security patch package update. . LinuxSecurity.com Team

Calendar%202 Apr 15, 2026 OpenSUSE
172

Ubuntu 24.10 USN-7586-1 critical: botan denial of service

Several security issues were fixed in Botan.. ========================================================================== Ubuntu Security Notice USN-7586-1 June 23, 2025 botan vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Botan. Software Description: - botan: C++ cryptography library Details: It was discovered that Botan could have compiler dependent operations induced under certain circumstances. An attacker could possibly use this issue to cause undefined behavior. (CVE-2024-50382, CVE-2024-50383) Bing Shi discovered that Botan did not limit the size of certain inputs when checking primality and name constraints. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-34702, CVE-2024-34703) It was discovered that Botan did not correctly handle conflicting name constraints. An attacker could possibly use this issue to bypass authentication. (CVE-2024-39312) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 botan 2.19.3+dfsg-1ubuntu2.1 libbotan-2-19 2.19.3+dfsg-1ubuntu2.1 libbotan-2-dev 2.19.3+dfsg-1ubuntu2.1 python3-botan 2.19.3+dfsg-1ubuntu2.1 Ubuntu 24.04 LTS botan 2.19.3+dfsg-1ubuntu2+esm1 Available with Ubuntu Pro libbotan-2-19 2.19.3+dfsg-1ubuntu2+esm1 Available with Ubuntu Pro libbotan-2-dev 2.19.3+dfsg-1ubuntu2+esm1 Available with Ubuntu Pro python3-botan 2.19.3+dfsg-1ubuntu2+esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS botan 2.19.1+dfsg-2ubuntu1+esm1 Available with Ubuntu Pro libbotan-2-19 2.19.1+dfsg-2ubuntu1+esm1 Available with Ubuntu Pro libbotan-2-dev 2.19.1+dfsg-2ubuntu1+esm1 Available with Ubuntu Pro python3-botan 2.19.1+dfsg-2ubuntu1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7586-1 CVE-2024-34702, CVE-2024-34703, CVE-2024-39312, CVE-2024-50382, CVE-2024-50383 Package Information: https://launchpad.net/ubuntu/+source/botan/2.19.3+dfsg-1ubuntu2.1 . Several security updates in Botan for Ubuntu versions 22.04 through 24.10 target denial of service vulnerabilities and additional concerns.. Ubuntu Botan Security Fixes, Botan Denial of Service, C++ Cryptography Library. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 23, 2025 Critical Ubuntu
203

Mageia 8 MGASA-2022-0445 Moderate: Botan OCSP Certificate Validation Issue

Fixed validation of embedded certificates was when checking OCSP responses (CVE-2022-43705) References: - https://bugs.mageia.org/show_bug.cgi?id=31176 . MGASA-2022-0445 - Updated botan packages fix security vulnerability Publication date: 27 Nov 2022 URL: https://advisories.mageia.org/MGASA-2022-0445.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-43705 Fixed validation of embedded certificates was when checking OCSP responses (CVE-2022-43705) References: - https://bugs.mageia.org/show_bug.cgi?id=31176 - https://www.suse.com/security/cve/CVE-2022-43705.html - https://www.cve.org/CVERecord?id=CVE-2022-43705 SRPMS: - 8/core/botan2-2.17.3-2.2.mga8 . MGASA-2022-0446 relates to an exposure in the libxml library regarding XML document parsing for Mageia 8.. Botan Security, Mageia Advisory, Certificate Validation Fix, OCSP Response Validation, Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 27, 2022 Important Mageia
202

openSUSE: 2021:0794-1 Important: Botan Encoding Security Issue

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for Botan ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0794-1 Rating: important References: #1182670 Cross-References: CVE-2021-24115 CVSS scores: CVE-2021-24115 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-24115 (SUSE): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for Botan fixes the following issues: - CVE-2021-24115 In Botan before 2.17.3, or this backport, constant-time computations are not used for certain decoding and encoding operations (boo#1182670) This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2021-794=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64): Botan-2.10.0-bp152.4.6.1 libbotan-2-10-2.10.0-bp152.4.6.1 libbotan-devel-2.10.0-bp152.4.6.1 python3-botan-2.10.0-bp152.4.6.1 - openSUSE Backports SLE-15-SP2 (aarch64_ilp32): libbotan-2-10-64bit-2.10.0-bp152.4.6.1 libbotan-devel-64bit-2.10.0-bp152.4.6.1 - openSUSE Backports SLE-15-SP2 (noarch): Botan-doc-2.10.0-bp152.4.6.1 References: https://www.suse.com/security/cve/CVE-2021-24115.html https://bugzilla.suse.com/1182670 . Updates for Botan in openSUSE: 2021:0794-2 critical patch resolving CVE-2021-24115vulnerabilities.. openSUSE Security Update,Botan Vulnerability,Critical Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 25, 2021 Important OpenSUSE
87

Debian DSA-3939-1: Important Botan DoS Vulnerability and Solution

Aleksandar Nikolic discovered that an error in the x509 parser of the Botan crypto library could result in an out-of-bounds memory read, resulting in denial of service or an information leak if processing a malformed certificate. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3939-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff August 12, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : botan1.10 CVE ID : CVE-2017-2801 Aleksandar Nikolic discovered that an error in the x509 parser of the Botan crypto library could result in an out-of-bounds memory read, resulting in denial of service or an information leak if processing a malformed certificate. For the oldstable distribution (jessie), this problem has been fixed in version 1.10.8-2+deb8u2. For the stable distribution (stretch), this problem has been fixed prior to the initial release. We recommend that you upgrade your botan1.10 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A significant patch for the Botan encryption library on Debian addresses a memory flaw that can trigger service interruptions and data leaks.. botan security update, debian botan issues, crypto library patches. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 12, 2017 Important Debian
91

Gentoo GLSA-201701-23 Normal: Botan Multiple Issues Affecting ECDSA Keys

Multiple vulnerabilities have been found in Botan, the worst of which might allow remote attackers to obtain ECDSA secret keys.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201701-23 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Botan: Multiple vulnerabilities Date: January 11, 2017 Bugs: #581324 ID: 201701-23 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Botan, the worst of which might allow remote attackers to obtain ECDSA secret keys. Background ========= Botan (Japanese for peony) is a cryptography library written in C++11. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/botan < 1.10.13 > = 1.10.13 Description ========== Multiple vulnerabilities have been discovered in Botan. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker might obtain ECDSA secret keys via a timing side-channel attack or could possibly bypass TLS policy. Workaround ========= There is no known workaround at this time. Resolution ========= All Botan users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/botan-1.10.13" References ========= [ 1 ] CVE-2016-2849 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2849 [ 2 ] CVE-2016-2850 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2850 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo SecurityWebsite: https://security.gentoo.org/glsa/201701-23 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2017 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Numerous security flaws in Botan could enable distant adversaries to access ECDSA private keys. It is advised to proceed with an update for enhanced protection.. Botan Vulnerabilities,Gentoo Security Update,Remote Attacker Access. . LinuxSecurity.com Team

Calendar%202 Jan 11, 2017 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200