Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 2 articles for you...
89

Fedora 44 kf6-ki18n Update Advisory 2026-04-16 KDE Frameworks 6.25.0

Frameworks 6.25.0 + KDE Plasma 6.6.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fe3d8d4767 2026-04-16 23:40:54.273526+00:00 -------------------------------------------------------------------------------- Name : kf6-ki18n Product : Fedora 44 Version : 6.25.0 Release : 1.fc44 URL : https://invent.kde.org/frameworks/ki18n Summary : KDE Frameworks 6 Tier 1 addon for localization Description : KDE Frameworks 6 Tier 1 addon for localization. -------------------------------------------------------------------------------- Update Information: Frameworks 6.25.0 + KDE Plasma 6.6.4 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 9 2026 Steve Cossette - 6.25.0-1 - 6.25.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455469 - Configuring WifI network via Network pane appears to not work https://bugzilla.redhat.com/show_bug.cgi?id=2455469 [ 2 ] Bug #2457573 - FE: KDE Frameworks 6.25.0 + Plasma 6.6.4 https://bugzilla.redhat.com/show_bug.cgi?id=2457573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fe3d8d4767' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . KDE Frameworks 6.25.0 update for Fedora 44 addresses localization issues with the latest enhancements.. KDE Frameworks,Fedora 44,software update,localization,Bug tracking. . LinuxSecurity.com Team

Calendar%202 Apr 16, 2026 Fedora
89

Fedora 32: FEDORA-2020-cf8ef2f333 Moderate: Eclipse Remote Services Fix

Updates to the latest upstream release of Eclipse. See the upstream release notes for details: https://eclipseide.org/release/noteworthy/ Also contains security fixes for CVE-2019-17566 and CVE-2019-17638.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-cf8ef2f333 2020-08-31 15:48:37.485399 --------------------------------------------------------------------------------Name : eclipse-remote Product : Fedora 32 Version : 3.0.1 Release : 6.fc32 URL : https://www.eclipse.org/projects/archives.php Summary : Eclipse Remote Services plug-in Description : Remote Services provides an extensible remote services framework. --------------------------------------------------------------------------------Update Information: Updates to the latest upstream release of Eclipse. See the upstream release notes for details: https://eclipseide.org/release/noteworthy/ Also contains security fixes for CVE-2019-17566 and CVE-2019-17638. --------------------------------------------------------------------------------ChangeLog: * Fri Aug 14 2020 Mat Booth - 3.0.1-6 - Update dep on tm-terminal * Mon Jul 27 2020 Fedora Release Engineering - 3.0.1-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Tue Jan 28 2020 Fedora Release Engineering - 3.0.1-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Wed Jul 24 2019 Fedora Release Engineering - 3.0.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1848617 - CVE-2019-17566 batik: SSRF via "xlink:href" https://bugzilla.redhat.com/show_bug.cgi?id=1848617 [ 2 ] Bug #1864680 - CVE-2019-17638 jetty: double release of resource can lead to information disclosure https://bugzilla.redhat.com/show_bug.cgi?id=1864680 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-cf8ef2f333' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora 32 releases upgraded Eclipse Remote Services addressing serious security flaws. Check here for further information.. Eclipse Remote Services Plug-in, Fedora Updates, Security Fixes, Bug Tracking. . LinuxSecurity.com Team

Calendar%202 Aug 31, 2020 Fedora
89

Fedora 26: 2018-b79f325c48 Moderate: Bugzilla CSRF Issue

A CSRF vulnerability in Bugzilla's report.cgi would allow a third-party site to extract confidential information from a bug the victim had access to. This security bug has been published as CVE-2018-5123. This updates contains Bugzilla 5.0.4, which fixes the issue.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-b79f325c48 2018-03-06 17:26:39.509141 --------------------------------------------------------------------------------Name : bugzilla Product : Fedora 26 Version : 5.0.4 Release : 1.fc26 URL : https://www.bugzilla.org/ Summary : Bug tracking system Description : Bugzilla is a popular bug tracking system used by multiple open source projects It requires a database engine installed - either MySQL, PostgreSQL or Oracle. Without one of these database engines (local or remote), Bugzilla will not work - see the Release Notes for details. --------------------------------------------------------------------------------Update Information: A CSRF vulnerability in Bugzilla's report.cgi would allow a third-party site to extract confidential information from a bug the victim had access to. This security bug has been published as CVE-2018-5123. This updates contains Bugzilla 5.0.4, which fixes the issue. --------------------------------------------------------------------------------References: [ 1 ] Bug #1438957 - icons are missing on bugzilla's front page https://bugzilla.redhat.com/show_bug.cgi?id=1438957 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bugzilla' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 26 has released a security patch for Bugzilla addressing a CSRF vulnerability that potentially permits unauthorized access to sensitive report information.. Fedora Security Update,Bugzilla CSRF Fix,Bug Tracking System. . LinuxSecurity.com Team

Calendar%202 Mar 06, 2018 Fedora
89

Fedora 22: FEDORA-2016-0123 Important: SQLite Security Patch

Update to latest release. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-9090 2015-10-14 23:00:41.814383 -------------------------------------------------------------------------------- Name : fossil Product : Fedora 21 Version : 1.33 Release : 1.fc21 URL : https://www.fossil-scm.org/home/doc/trunk/www/index.wiki Summary : A distributed SCM with bug tracking and wiki Description : Fossil is a simple, high-reliability, distributed software configuration management with distributed bug tracking, distributed wiki and built-in web interface. -------------------------------------------------------------------------------- Update Information: Update to latest release -------------------------------------------------------------------------------- References: [ 1 ] Bug #1191203 - fossil: version 1.30 is available with CVE-2014-3566 (POODLE) fixed https://bugzilla.redhat.com/show_bug.cgi?id=1191203 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update fossil' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Upgrade the fossil application to its most recent version on Fedora 21 to improve both security features and performance capabilities.. Fossil Software Update, Fedora Distribution, Configuration Management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 15, 2015 Important Fedora
89

Fedora 22 FEDORA-2015-9110 Critical Fossil Security Update

Update to latest release. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-9110 2015-10-14 23:00:48.503821 -------------------------------------------------------------------------------- Name : fossil Product : Fedora 22 Version : 1.33 Release : 1.fc22 URL : https://www.fossil-scm.org/home/doc/trunk/www/index.wiki Summary : A distributed SCM with bug tracking and wiki Description : Fossil is a simple, high-reliability, distributed software configuration management with distributed bug tracking, distributed wiki and built-in web interface. -------------------------------------------------------------------------------- Update Information: Update to latest release -------------------------------------------------------------------------------- References: [ 1 ] Bug #1191203 - fossil: version 1.30 is available with CVE-2014-3566 (POODLE) fixed https://bugzilla.redhat.com/show_bug.cgi?id=1191203 [ 2 ] Bug #1180999 - Non-free code included. https://bugzilla.redhat.com/show_bug.cgi?id=1180999 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update fossil' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . System patch for Fedora 22 addresses vulnerabilities, integrating updated software and fixes to boost reliability and efficiency.. Fossil Scm Update,Fedora Software Management,Security Update Information. . Severity: Critical.LinuxSecurity.com Team

Calendar%202 Oct 15, 2015 Critical Fedora
87

Debian DSA-3120-1 Moderate: Mantis SQL Injection And Phishing Risk

Multiple security issues have been found in the Mantis bug tracking system, which may result in phishing, information disclosure, CAPTCHA bypass, SQL injection, cross-site scripting or the execution of arbitrary PHP code. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3120-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff January 06, 2015 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mantis CVE ID : CVE-2014-6316 CVE-2014-7146 CVE-2014-8553 CVE-2014-8554 CVE-2014-8598 CVE-2014-8986 CVE-2014-8988 CVE-2014-9089 CVE-2014-9117 CVE-2014-9269 CVE-2014-9270 CVE-2014-9271 CVE-2014-9272 CVE-2014-9280 CVE-2014-9281 CVE-2014-9388 Multiple security issues have been found in the Mantis bug tracking system, which may result in phishing, information disclosure, CAPTCHA bypass, SQL injection, cross-site scripting or the execution of arbitrary PHP code. For the stable distribution (wheezy), these problems have been fixed in version 1.2.18-1. We recommend that you upgrade your mantis packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Various vulnerabilities detected in Mantis may pose risks for phishing attempts and SQL injection attacks; it is recommended to upgrade Debian installations.. Mantis Security Update, Debian Security Advisory, Bug Tracking System. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 06, 2015 Important Debian
87

Debian: DSA-3030-1 Critical: Mantis SQL Injection Threats Resolved

Multiple SQL injection vulnerabilities have been discovered in the Mantis bug tracking system. For the stable distribution (wheezy), these problems have been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3030-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff September 20, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mantis CVE ID : CVE-2014-1608 CVE-2014-1609 Multiple SQL injection vulnerabilities have been discovered in the Mantis bug tracking system. For the stable distribution (wheezy), these problems have been fixed in version 1.2.11-1.2+deb7u1. We recommend that you upgrade your mantis packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Several vulnerabilities addressed for Mantis; please update your packages to ensure a reliable Debian environment.. Mantis Update, SQL Injection Patch, Debian Security, Software Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 20, 2014 Critical Debian
89

Fedora: 2009-3410 Critical Update for Bugzilla CSRF Vulnerability Fix

fix CVE-2009-1213. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2009-3410 2009-04-07 15:17:56 --------------------------------------------------------------------------------Name : bugzilla Product : Fedora 10 Version : 3.2.3 Release : 1.fc10 URL : https://www.bugzilla.org/ Summary : Bug tracking system Description : Bugzilla is a popular bug tracking system used by multiple open source projects It requires a database engine installed - either MySQL, PostgreSQL or Oracle. Without one of these database engines (local or remote), Bugzilla will not work - see the Release Notes for details. --------------------------------------------------------------------------------ChangeLog: * Mon Apr 6 2009 Itamar Reis Peixoto 3.2.3-1 - fix CVE-2009-1213 * Thu Mar 5 2009 Itamar Reis Peixoto 3.2.2-2 - fix from BZ #474250 Comment #16, from Chris Eveleigh --> - add python BR for contrib subpackage - fix description - change Requires perl-SOAP-Lite to perl(SOAP::Lite) according guidelines * Sun Mar 1 2009 Itamar Reis Peixoto 3.2.2-1 - thanks to Chris Eveleigh - for contributing with patches :-) - Upgrade to upstream 3.2.2 to fix multiple security vulns - Removed old perl_requires exclusions, added new ones for RADIUS, Oracle and sanitycheck.cgi - Added Oracle to supported DBs in description (and moved line breaks) - Include a patch to fix max_allowed_packet warnin when using with mysql * Sat Feb 28 2009 Itamar Reis Peixoto 3.0.8-1 - Upgrade to 3.0.8, fix #466077 #438080 - fix macro in changelog rpmlint warning - fix files-attr-not-set rpmlint warning for doc and contrib sub-packages * Mon Feb 23 2009 Fedora Release Engineering - 3.0.4-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Mon Feb 2 2009 Stepan Kasal - 3.0.4-3 - do not require perl-Email-Simple, it is (no longer) in use - remove several explicit perl-* requires; the automaticdependencies do handle them --------------------------------------------------------------------------------References: [ 1 ] Bug #494398 - CVE-2009-1213 bugzilla: CSRF vulnerability in attachment editing https://bugzilla.redhat.com/show_bug.cgi?id=494398 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update bugzilla' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Important patch for Bugzilla on Fedora addressing CSRF vulnerabilities. Safeguard your systems with this essential update.. Bugzilla Update,Fedora Security,CSRF Patch,Software Management,Fedora Release. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 07, 2009 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200