Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
172

Ubuntu 26.04 Tomcat Critical DoS and Authentication Bypass Vuln 8417-1

Several security issues were fixed in Tomcat.. ========================================================================== Ubuntu Security Notice USN-8417-1 June 10, 2026 tomcat9, tomcat10 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Tomcat. Software Description: - tomcat10: Servlet and JSP engine - tomcat9: Servlet and JSP engine Details: It was discovered that Tomcat did not properly limit the size of WebDAV LOCK and PROPFIND request bodies. A remote attacker could use this issue to cause Tomcat to consume excessive memory, resulting in a denial of service. (CVE-2026-41284) It was discovered that Tomcat incorrectly validated HTTP/2 header fields. A remote attacker could use this issue to cause Tomcat to crash or possibly execute arbitrary code. (CVE-2026-41293) It was discovered that Tomcat did not properly clear HTTP authentication headers during WebSocket connection upgrades and redirects. A remote attacker could use this issue to obtain sensitive credentials. (CVE-2026-42498) It was discovered that Tomcat incorrectly handled digest authentication. A remote attacker could possibly use this issue to bypass authentication restrictions. (CVE-2026-43512) It was discovered that Tomcat incorrectly handled case sensitivity in LockOutRealm. A remote attacker could possibly use this issue to bypass account lockout protections and obtain sensitive information. (CVE-2026-43513) It was discovered that Tomcat incorrectly handled authorization when multiple method constraints defined the same HTTP method. A remote attacker could possibly use this issue to bypass authorization restrictions. (CVE-2026-43515) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libtomcat10-embed-java 10.1.40-1ubuntu1.26.04.1 libtomcat10-java 10.1.40-1ubuntu1.26.04.1 libtomcat9-java 9.0.115-1ubuntu0.1 tomcat10 10.1.40-1ubuntu1.26.04.1 Ubuntu 25.10 libtomcat10-embed-java 10.1.40-1ubuntu1.25.10.1 libtomcat10-java 10.1.40-1ubuntu1.25.10.1 libtomcat9-java 9.0.95-1ubuntu1.1 tomcat10 10.1.40-1ubuntu1.25.10.1 Ubuntu 24.04 LTS libtomcat10-embed-java 10.1.16-1ubuntu0.1~esm4 Available with Ubuntu Pro libtomcat10-java 10.1.16-1ubuntu0.1~esm4 Available with Ubuntu Pro libtomcat9-java 9.0.70-2ubuntu0.1+esm3 Available with Ubuntu Pro tomcat10 10.1.16-1ubuntu0.1~esm4 Available with Ubuntu Pro Ubuntu 22.04 LTS libtomcat9-embed-java 9.0.58-1ubuntu0.2+esm4 Available with Ubuntu Pro libtomcat9-java 9.0.58-1ubuntu0.2+esm4 Available with Ubuntu Pro tomcat9 9.0.58-1ubuntu0.2+esm4 Available with Ubuntu Pro Ubuntu 20.04 LTS libtomcat9-embed-java 9.0.31-1ubuntu0.9+esm3 Available with Ubuntu Pro libtomcat9-java 9.0.31-1ubuntu0.9+esm3 Available with Ubuntu Pro tomcat9 9.0.31-1ubuntu0.9+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS libtomcat9-embed-java 9.0.16-3ubuntu0.18.04.2+esm8 Available with Ubuntu Pro libtomcat9-java 9.0.16-3ubuntu0.18.04.2+esm8 Available with Ubuntu Pro tomcat9 9.0.16-3ubuntu0.18.04.2+esm8 Available with Ubuntu Pro After a standard system update you need to restart Tomcat to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8417-1 CVE-2026-41284, CVE-2026-41293, CVE-2026-42498, CVE-2026-43512, CVE-2026-43513, CVE-2026-43515 Package Information: https://launchpad.net/ubuntu/+source/tomcat10/10.1.40-1ubuntu1.26.04.1 https://launchpad.net/ubuntu/+source/tomcat9/9.0.115-1ubuntu0.1 https://launchpad.net/ubuntu/+source/tomcat10/10.1.40-1ubuntu1.25.10.1 https://launchpad.net/ubuntu/+source/tomcat9/9.0.95-1ubuntu1.1 . Address multiple security concerns with Tomcat in Ubuntu 20.04 to 26.04 for safer usage. Update as advised.. Ubuntu Tomcat security issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 10, 2026 Critical Ubuntu
87

Debian trixie inetutils Critical Telnetd Authentication Bypass DSA-6144-1

Ron Ben Yizhak discovered that the inetutils implementation of telnetd didn't sanitise the CREDENTIALS_DIRECTORY environment variable before passing it to the login binary. This could be exploited to bypass authentication and login as root. For the stable distribution (trixie), this problem has been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6144-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso February 19, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : inetutils CVE ID : not yet available Ron Ben Yizhak discovered that the inetutils implementation of telnetd didn't sanitise the CREDENTIALS_DIRECTORY environment variable before passing it to the login binary. This could be exploited to bypass authentication and login as root. For the stable distribution (trixie), this problem has been fixed in version 2:2.6-3+deb13u2. We recommend that you upgrade your inetutils packages. For the detailed security status of inetutils please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/inetutils Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . inetutils telnetd flaw allows bypass of authentication, leading to potential root access; fix recommended for Debian trixie.. Debian inetutils security telnetd authentication. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 19, 2026 Critical Debian
197

Debian 11: DLA-4027-1 Critical: Sympa Authentication Bypass Issue

A flaw was found in Sympa’s web interface, a modern mailing list manager. An attacker may bypass authentication by using an arbitrary e-mail address when the generic SSO loging feature was enabled. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4027-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany January 21, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : sympa Version : 6.2.60~dfsg-4+deb11u1 CVE ID : CVE-2024-55919 Debian Bug : 1090188 A flaw was found in Sympa’s web interface, a modern mailing list manager. An attacker may bypass authentication by using an arbitrary e-mail address when the generic SSO loging feature was enabled. For Debian 11 bullseye, this problem has been fixed in version 6.2.60~dfsg-4+deb11u1. We recommend that you upgrade your sympa packages. For the detailed security status of sympa please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/sympa Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-4028-1 addresses a critical vulnerability in the Dovecot email server; users are urged to apply the patch without delay. security advisory, Debian Sympa, authentication bypass, mailing list security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 20, 2025 Critical Debian LTS
100

SUSE 12 SP2: SUSE-SU-2019:1591-1 Important: dbus-1 Local Attack

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for dbus-1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1591-1 Rating: important References: #1137832 Cross-References: CVE-2019-12749 Affected Products: SUSE OpenStack Cloud 7 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP1-LTSS SUSE Linux Enterprise Server 12-LTSS SUSE Enterprise Storage 4 OpenStack Cloud Magnum Orchestration 7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for dbus-1 fixes the following issue: Security issue fixed: - CVE-2019-12749: Fixed an implementation flaw in DBUS_COOKIE_SHA1 which could have allowed local attackers to bypass authentication (bsc#1137832). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2019-1591=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2019-1591=1 - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2019-1591=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2019-1591=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2019-1591=1 - SUSE Linux Enterprise Server12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2019-1591=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2019-1591=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2019-1591=1 - OpenStack Cloud Magnum Orchestration 7: zypper in -t patch SUSE-OpenStack-Cloud-Magnum-Orchestration-7-2019-1591=1 Package List: - SUSE OpenStack Cloud 7 (s390x x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debuginfo-32bit-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-32bit-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 libdbus-1-3-debuginfo-32bit-1.8.22-24.19.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (x86_64): dbus-1-debuginfo-32bit-1.8.22-24.19.1 libdbus-1-3-32bit-1.8.22-24.19.1 libdbus-1-3-debuginfo-32bit-1.8.22-24.19.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debuginfo-32bit-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-32bit-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 libdbus-1-3-debuginfo-32bit-1.8.22-24.19.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (s390x x86_64): dbus-1-debuginfo-32bit-1.8.22-24.19.1 libdbus-1-3-32bit-1.8.22-24.19.1 libdbus-1-3-debuginfo-32bit-1.8.22-24.19.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debuginfo-32bit-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-32bit-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 libdbus-1-3-debuginfo-32bit-1.8.22-24.19.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (s390x x86_64): dbus-1-debuginfo-32bit-1.8.22-24.19.1 libdbus-1-3-32bit-1.8.22-24.19.1 libdbus-1-3-debuginfo-32bit-1.8.22-24.19.1 - SUSE Linux Enterprise Server 12-LTSS (ppc64le s390x x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 - SUSE Linux Enterprise Server 12-LTSS (s390x x86_64): libdbus-1-3-32bit-1.8.22-24.19.1 libdbus-1-3-debuginfo-32bit-1.8.22-24.19.1 - SUSEEnterprise Storage 4 (x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debuginfo-32bit-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-32bit-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 libdbus-1-3-debuginfo-32bit-1.8.22-24.19.1 - OpenStack Cloud Magnum Orchestration 7 (x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 References: https://www.suse.com/security/cve/CVE-2019-12749.html https://bugzilla.suse.com/1137832 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE has released a security update for dbus-1 addressing a significant local vulnerability, identified as CVE-2019-12749.. SUSE Security Update, important fixes, local attack, authentication flaw. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 21, 2019 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200