Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
89

Fedora 43 bpfman Critical Update CVE-2026-31812 Arbitrary Permissions Issue

Fix CVE-2026-31812: Bump tar-rs to .5.45 - Closes rhbz#2449672. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d62d7fe77e 2026-04-02 01:05:52.796857+00:00 -------------------------------------------------------------------------------- Name : bpfman Product : Fedora 43 Version : 0.5.4 Release : 5.fc43 URL : https://bpfman.io Summary : EBPF Program Manager Description : bpfman operates as an eBPF manager, focusing on simplifying the deployment and administration of eBPF programs. -------------------------------------------------------------------------------- Update Information: Fix CVE-2026-31812: Bump tar-rs to .5.45 - Closes rhbz#2449672 -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 24 2026 Daniel Mellado - 0.5.4-5 - Fix CVE-2026-31812: Bump tar-rs to .5.45 - Closes rhbz#2449672 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2449672 - CVE-2026-33056 bpfman: tar-rs: Arbitrary directory permission modification via crafted tar archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449672 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d62d7fe77e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send anemail to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update on bpfman 0.5.4 to fix CVE-2026-31812 with tar-rs adjustment for Fedora 43. Immediate actions recommended!. Fedora security advisory, bpfman update, CVE-2026-31812 fix, Linux package security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 02, 2026 Critical Fedora
89

Fedora 43 BPFMAN Major Denial of Service Fix for CVE-2026-31812

Fix CVE-2026-31812: Bump quinn-proto to 0.11.14 - Closes rhbz#2446359. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-2fef29d32a 2026-03-20 01:01:53.697472+00:00 -------------------------------------------------------------------------------- Name : bpfman Product : Fedora 43 Version : 0.5.4 Release : 4.fc43 URL : https://bpfman.io Summary : EBPF Program Manager Description : bpfman operates as an eBPF manager, focusing on simplifying the deployment and administration of eBPF programs. -------------------------------------------------------------------------------- Update Information: Fix CVE-2026-31812: Bump quinn-proto to 0.11.14 - Closes rhbz#2446359 -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 11 2026 Daniel Mellado - 0.5.4-4 - Fix CVE-2026-31812: Bump quinn-proto to 0.11.14 - Closes rhbz#2446359 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2446359 - CVE-2026-31812 bpfman: quinn-proto: Denial of Service via crafted QUIC Initial packet [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2446359 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2fef29d32a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribesend an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Resolve CVE-2026-31812 affecting bpfman in Fedora 43 to prevent Denial of Service issues and ensure system security.. Fedora 43 bpfman fix CVE-2026-31812 DoS. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 20, 2026 Important Fedora
89

Fedora 42: bpfman Security Update CVE-2025-0977 Use-After-Free

This update fixes CVE-2025-0977 (RUSTSEC-2025-0004), a use-after-free vulnerability in the Rust openssl crate's ssl::select_next_proto function. The openssl crate has been updated from version 0.10.67 to 0.10.70 in the vendored dependencies.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-0753bddd6c 2025-11-09 03:17:35.195090+00:00 -------------------------------------------------------------------------------- Name : bpfman Product : Fedora 42 Version : 0.5.4 Release : 3.fc42 URL : https://bpfman.io Summary : EBPF Program Manager Description : bpfman operates as an eBPF manager, focusing on simplifying the deployment and administration of eBPF programs. -------------------------------------------------------------------------------- Update Information: This update fixes CVE-2025-0977 (RUSTSEC-2025-0004), a use-after-free vulnerability in the Rust openssl crate's ssl::select_next_proto function. The openssl crate has been updated from version 0.10.67 to 0.10.70 in the vendored dependencies. -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 31 2025 Daniel Mellado - 0.5.4-3 - Fix CVE-2025-0977: Update openssl to 0.10.70 - closes rhbz#2344554 * Wed Jul 23 2025 Fedora Release Engineering - 0.5.4-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Mon Jun 23 2025 Daniel Mellado - 0.5.4-1 - Add patch for Cargo.lock - closes rhbz2370581 * Sat Jun 7 2025 Daniel Mellado - 0.5.6-1 - Update to version 0.5.6 * Thu Jan 16 2025 Fedora Release Engineering - 0.5.4-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Wed Dec 18 2024 Daniel Mellado - 0.5.4-4 - Correct sources vendor file * Wed Dec 18 2024 Daniel Mellado - 0.5.4-3 - Remove forbidden RTLO characters in vendor/idna-5.0tests -------------------------------------------------------------------------------- References: [ 1 ] Bug #2344554 - bpfman: openssl: CVE-2025-0977 / RUSTSEC-2025-0004: ssl::select_next_proto use after free https://bugzilla.redhat.com/show_bug.cgi?id=2344554 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-0753bddd6c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fix for CVE-2025-0977 (use-after-free) in bpfman on Fedora 42, updating openssl crate to enhance security.. CVE-2025-0977,bpfman,Fedora 42,eBPF,openssl crate. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 09, 2025 Important Fedora
89

Fedora 43: bpfman CVE-2025-0977 Use-After-Free Advisory Announcement

This update fixes CVE-2025-0977 (RUSTSEC-2025-0004), a use-after-free vulnerability in the Rust openssl crate's ssl::select_next_proto function. The openssl crate has been updated from version 0.10.67 to 0.10.70 in the vendored dependencies.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e67231423f 2025-11-09 03:05:33.669278+00:00 -------------------------------------------------------------------------------- Name : bpfman Product : Fedora 43 Version : 0.5.4 Release : 3.fc43 URL : https://bpfman.io Summary : EBPF Program Manager Description : bpfman operates as an eBPF manager, focusing on simplifying the deployment and administration of eBPF programs. -------------------------------------------------------------------------------- Update Information: This update fixes CVE-2025-0977 (RUSTSEC-2025-0004), a use-after-free vulnerability in the Rust openssl crate's ssl::select_next_proto function. The openssl crate has been updated from version 0.10.67 to 0.10.70 in the vendored dependencies. -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 31 2025 Daniel Mellado - 0.5.4-3 - Fix CVE-2025-0977: Update openssl to 0.10.70 - closes rhbz#2344554 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2344554 - bpfman: openssl: CVE-2025-0977 / RUSTSEC-2025-0004: ssl::select_next_proto use after free https://bugzilla.redhat.com/show_bug.cgi?id=2344554 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e67231423f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPGkey. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . CVE-2025-0977 fixed in Fedora 43 for bpfman, addressing use-after-free vulnerability in Rust OpenSSL crate.. Fedora Update,bpfman security fix,RUSTSEC-2025-0004,CVE-2025-0977,ebpf management. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 09, 2025 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here