Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
100

SUSE: kernel-livepatch Important Fix for Multiple Issues 2025:20687-1

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351 . # Security update for kernel-livepatch-MICRO-6-0-RT_Update_6 Announcement ID: SUSE-SU-2025:20687-1 Release Date: 2025-08-29T13:42:59Z Rating: important References: * bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351 Cross-References: * CVE-2025-38079 * CVE-2025-38083 * CVE-2025-38494 * CVE-2025-38495 CVSS scores: * CVE-2025-38079 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38079 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38083 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38494 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38494 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38495 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38495 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_6 fixes the following issues: * CVE-2025-38079: crypto: algif_hash - fix double free in hash_accept (bsc#1245218) * CVE-2025-38083: net_sched: prio: fix a race in prio_tune() (bsc#1245350) * CVE-2025-38494: HID: core: do not bypass hid_hw_raw_request (bsc#1247350) * CVE-2025-38495: HID: core: ensure the allocated report buffer can contain the reserved report ID (bsc#1247351) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-88=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-28-rt-debuginfo-4-3.1 *kernel-livepatch-MICRO-6-0-RT_Update_6-debugsource-4-3.1 * kernel-livepatch-6_4_0-28-rt-4-3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-38079.html * https://www.suse.com/security/cve/CVE-2025-38083.html * https://www.suse.com/security/cve/CVE-2025-38494.html * https://www.suse.com/security/cve/CVE-2025-38495.html * https://bugzilla.suse.com/show_bug.cgi?id=1245218 * https://bugzilla.suse.com/show_bug.cgi?id=1245350 * https://bugzilla.suse.com/show_bug.cgi?id=1247350 * https://bugzilla.suse.com/show_bug.cgi?id=1247351 . Kernel livepatch security patch addressing various vulnerabilities. Necessary update for SUSE Linux Micro 6.1 to mitigate potential threats.. SUSE Linux Micro,kernel-livepatch,security update,advisory,risk assessment. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 10, 2025 Important SuSE
217

Oracle Linux 8 socat Moderate Vulnerability Advisory ELSA-2025-11042

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-11042 http://linux.oracle.com/errata/ELSA-2025-11042.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: socat-1.7.4.1-2.el8_10.x86_64.rpm aarch64: socat-1.7.4.1-2.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/socat-1.7.4.1-2.el8_10.src.rpm Related CVEs: CVE-2024-54661 Description of changes: [1.7.4.1-2] - add fix for CVE-2024-54661 Resolves: RHEL-70095 - switch to autopatch, remove unused patches _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle's security advisory ELSA-2025-11042 highlights a moderate vulnerability in socat that could affect system security. Users should apply the recommended fixes swiftly to mitigate risks.. Oracle Linux 8,socat advisory,security update,Moderate risk,CVE-2024-54661. . LinuxSecurity.com Team

Calendar%202 Jul 16, 2025 Oracle
100

SUSE: 2018:4129-1 Moderate: QEMU DoS And Buffer Overflow Issues

An update that solves 6 vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for qemu ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:4129-1 Rating: moderate References: #1100408 #1106222 #1110910 #1111006 #1111010 #1111013 #1114422 Cross-References: CVE-2018-10839 CVE-2018-15746 CVE-2018-17958 CVE-2018-17962 CVE-2018-17963 CVE-2018-18849 Affected Products: SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Desktop 12-SP3 SUSE CaaS Platform ALL SUSE CaaS Platform 3.0 ______________________________________________________________________________ An update that solves 6 vulnerabilities and has one errata is now available. Description: This update for qemu fixes the following issues: Security issues fixed: - CVE-2018-10839: Fixed NE2000 NIC emulation support that is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS (bsc#1110910). - CVE-2018-15746: Fixed qemu-seccomp.c that might allow local OS guest users to cause a denial of service (guest crash) by leveraging mishandling of the seccomp policy for threads other than the main thread (bsc#1106222). - CVE-2018-17958: Fixed a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used (bsc#1111006). - CVE-2018-17962: Fixed a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used (bsc#1111010). - CVE-2018-17963: Fixed qemu_deliver_packet_iov in net/net.c that accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of serviceor possibly have unspecified other impact. (bsc#1111013) - CVE-2018-18849: Fixed an out of bounds memory access issue that was found in the LSI53C895A SCSI Host Bus Adapter emulation while writing a message in lsi_do_msgin. It could occur during migration if the 'msg_len' field has an invalid value. A user/process could use this flaw to crash the Qemu process resulting in DoS (bsc#1114422). Non-security issues fixed: - Improving disk performance for qemu on xen (bsc#1100408) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP3: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2018-2944=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2018-2944=1 - SUSE CaaS Platform ALL: To install this update, use the SUSE CaaS Platform Velum dashboard. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. - SUSE CaaS Platform 3.0: To install this update, use the SUSE CaaS Platform Velum dashboard. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE Linux Enterprise Server 12-SP3 (aarch64 ppc64le s390x x86_64): qemu-2.9.1-6.22.3 qemu-block-curl-2.9.1-6.22.3 qemu-block-curl-debuginfo-2.9.1-6.22.3 qemu-block-iscsi-2.9.1-6.22.3 qemu-block-iscsi-debuginfo-2.9.1-6.22.3 qemu-block-ssh-2.9.1-6.22.3 qemu-block-ssh-debuginfo-2.9.1-6.22.3 qemu-debugsource-2.9.1-6.22.3 qemu-guest-agent-2.9.1-6.22.3 qemu-guest-agent-debuginfo-2.9.1-6.22.3 qemu-lang-2.9.1-6.22.3 qemu-tools-2.9.1-6.22.3 qemu-tools-debuginfo-2.9.1-6.22.3 - SUSE Linux Enterprise Server 12-SP3(aarch64 x86_64): qemu-block-rbd-2.9.1-6.22.3 qemu-block-rbd-debuginfo-2.9.1-6.22.3 - SUSE Linux Enterprise Server 12-SP3 (s390x x86_64): qemu-kvm-2.9.1-6.22.3 - SUSE Linux Enterprise Server 12-SP3 (aarch64): qemu-arm-2.9.1-6.22.3 qemu-arm-debuginfo-2.9.1-6.22.3 - SUSE Linux Enterprise Server 12-SP3 (ppc64le): qemu-ppc-2.9.1-6.22.3 qemu-ppc-debuginfo-2.9.1-6.22.3 - SUSE Linux Enterprise Server 12-SP3 (noarch): qemu-ipxe-1.0.0+-6.22.3 qemu-seabios-1.10.2-6.22.3 qemu-sgabios-8-6.22.3 qemu-vgabios-1.10.2-6.22.3 - SUSE Linux Enterprise Server 12-SP3 (x86_64): qemu-x86-2.9.1-6.22.3 qemu-x86-debuginfo-2.9.1-6.22.3 - SUSE Linux Enterprise Server 12-SP3 (s390x): qemu-s390-2.9.1-6.22.3 qemu-s390-debuginfo-2.9.1-6.22.3 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): qemu-2.9.1-6.22.3 qemu-block-curl-2.9.1-6.22.3 qemu-block-curl-debuginfo-2.9.1-6.22.3 qemu-debugsource-2.9.1-6.22.3 qemu-kvm-2.9.1-6.22.3 qemu-tools-2.9.1-6.22.3 qemu-tools-debuginfo-2.9.1-6.22.3 qemu-x86-2.9.1-6.22.3 - SUSE Linux Enterprise Desktop 12-SP3 (noarch): qemu-ipxe-1.0.0+-6.22.3 qemu-seabios-1.10.2-6.22.3 qemu-sgabios-8-6.22.3 qemu-vgabios-1.10.2-6.22.3 - SUSE CaaS Platform ALL (x86_64): qemu-debugsource-2.9.1-6.22.3 qemu-guest-agent-2.9.1-6.22.3 qemu-guest-agent-debuginfo-2.9.1-6.22.3 - SUSE CaaS Platform 3.0 (x86_64): qemu-debugsource-2.9.1-6.22.3 qemu-guest-agent-2.9.1-6.22.3 qemu-guest-agent-debuginfo-2.9.1-6.22.3 References: https://www.suse.com/security/cve/CVE-2018-10839.html https://www.suse.com/security/cve/CVE-2018-15746.html https://www.suse.com/security/cve/CVE-2018-17958.html https://www.suse.com/security/cve/CVE-2018-17962.html https://www.suse.com/security/cve/CVE-2018-17963.html https://www.suse.com/security/cve/CVE-2018-18849.html https://bugzilla.suse.com/1100408 https://bugzilla.suse.com/1106222 https://bugzilla.suse.com/1110910 https://bugzilla.suse.com/1111006 https://bugzilla.suse.com/1111010 https://bugzilla.suse.com/1111013 https://bugzilla.suse.com/1114422 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE has released an updated version of QEMU to rectify six vulnerabilities categorized with moderate severity levels, thereby improving both security and overall system stability.. SUSE Update, QEMU Security, Linux Security, Cybersecurity Update, DoS Threat. . LinuxSecurity.com Team

Calendar%202 Dec 14, 2018 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200