Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
98

Red Hat Enterprise Linux 9.0 RHSA-2023-0004-01 Critical BCEL Update

An update for bcel is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: bcel security update Advisory ID: RHSA-2023:0004-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0004 Issue date: 2023-01-02 CVE Names: CVE-2022-42920 ==================================================================== 1. Summary: An update for bcel is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.9.0) - noarch 3. Description: The Byte Code Engineering Library (Apache Commons BCEL) is intended to give users a convenient way to analyze, create, and manipulate (binary) Java class files (those ending with .class). Security Fix(es): * Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing (CVE-2022-42920) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2142707 - CVE-2022-42920 Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing 6. PackageList: Red Hat Enterprise Linux AppStream EUS (v.9.0): Source: bcel-6.4.1-9.el9_0.src.rpm noarch: bcel-6.4.1-9.el9_0.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-42920 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY7KzMdzjgjWX9erEAQhNnA/6Aj0dFqQToL48z8urkAHu9cjbjtXe8WY4 OtTUIPiNcx/ag0nFZXiJAg9Fpm1zsZ/vtijr+0g1zOwDH+jxsD6Jls0B2hvJ231+ MGpfDLLSbAiGPBi+h6bfS/5B0pVnBPzwIqHDuw88pZ65oTvYrSbesBxQRwSlpoLx KVNaZLcI1un3Tnj0B+g1PTenIoZr4t2ew5a1UBHG6922PfhpjkkGZkEMMGXhS39u IoDnZ86D6EwKgfgkI3DRvWROyllD3Uwn2K2LxWbGa3h6kgpIpLAwsBLs46pnoyYm F0SFZk/dLqWfAlQdBuQf9puG9b/UgF9afz/Sd823QItmV53i0K9969PKJTXd7hKV kup5w8Q+DXPB4QkVkirX/45vw8HynC3f+3v2PtIG4RX4vmavIKa7KH/GyQP+jKfj I42jho3Bof5QH2HYuYOPrsxc1Q9kuyNPy6C8q4kwj42I3T7uWnn1eztodGniv2qN ewOpSbIvQF9qgnpoDGSAydp6AfWq1hXLApWgq3Q3gwp/Bw4CVRF9BNaiGO92Qan8 Jh6jVdoBrLlpQeTeG3KNSA/cuagQzDFOlNPGAlRweoZd8HU1DKtbKVAWiy98WkcZ wX6h+/MheGxofaA5JKNpmF5T8a+6x5fOlLQW9DFxHtNXWPI6TpWp9aC0F2TOgjqt 4lvL+q5bFIM=2oN+ -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Essential security patch for bcel now accessible for Red Hat Enterprise Linux, addressing severe vulnerabilities that require immediate action.. Red Hat,bcel,security advisory,bytecode fix,update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 02, 2023 Important Red Hat
89

Fedora 36: 2022-0e358addb8 Critical Advisory For Bcel Execution Risk

Security fix: CVE-2022-42920 bcel: Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-0e358addb8 2022-12-11 01:39:26.469686 --------------------------------------------------------------------------------Name : bcel Product : Fedora 36 Version : 6.4.1 Release : 10.fc36 URL : https://commons.apache.org/proper/commons-bcel/ Summary : Byte Code Engineering Library Description : The Byte Code Engineering Library (formerly known as JavaClass) is intended to give users a convenient possibility to analyze, create, and manipulate (binary) Java class files (those ending with .class). Classes are represented by objects which contain all the symbolic information of the given class: methods, fields and byte code instructions, in particular. Such objects can be read from an existing file, be transformed by a program (e.g. a class loader at run-time) and dumped to a file again. An even more interesting application is the creation of classes from scratch at run-time. The Byte Code Engineering Library (BCEL) may be also useful if you want to learn about the Java Virtual Machine (JVM) and the format of Java .class files. BCEL is already being used successfully in several projects such as compilers, optimizers, obsfuscators and analysis tools, the most popular probably being the Xalan XSLT processor at Apache. --------------------------------------------------------------------------------Update Information: Security fix: CVE-2022-42920 bcel: Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing --------------------------------------------------------------------------------ChangeLog: * Thu Dec 1 2022 Mikolaj Izdebski - 6.4.1-10 - Fix arbitrary bytecode produced via out-of-bounds writing - Resolves:CVE-2022-42920 --------------------------------------------------------------------------------References: [ 1 ] Bug #2142728 - CVE-2022-42920 bcel: Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing [fedora-36] https://bugzilla.redhat.com/show_bug.cgi?id=2142728 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-0e358addb8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Debian 11 issues security memo for gnome-shell highlighting CVE-2022-45331 concerning buffer overflow vulnerabilities in UI rendering.. Fedora 36 Advisory,Bytecode Engineering Security,Bcel Security Fix,Out-of-Bounds Writing,Arbitrary Code Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 11, 2022 Critical Fedora
89

Fedora 37 CVE-2022-42920 Critical: bcel Out-Of-Bounds Bytecode Risk

Security fix: CVE-2022-42920 bcel: Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-01a56f581c 2022-12-11 01:24:18.453204 --------------------------------------------------------------------------------Name : bcel Product : Fedora 37 Version : 6.5.0 Release : 3.fc37 URL : https://commons.apache.org/proper/commons-bcel/ Summary : Byte Code Engineering Library Description : The Byte Code Engineering Library (formerly known as JavaClass) is intended to give users a convenient possibility to analyze, create, and manipulate (binary) Java class files (those ending with .class). Classes are represented by objects which contain all the symbolic information of the given class: methods, fields and byte code instructions, in particular. Such objects can be read from an existing file, be transformed by a program (e.g. a class loader at run-time) and dumped to a file again. An even more interesting application is the creation of classes from scratch at run-time. The Byte Code Engineering Library (BCEL) may be also useful if you want to learn about the Java Virtual Machine (JVM) and the format of Java .class files. BCEL is already being used successfully in several projects such as compilers, optimizers, obsfuscators and analysis tools, the most popular probably being the Xalan XSLT processor at Apache. --------------------------------------------------------------------------------Update Information: Security fix: CVE-2022-42920 bcel: Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing --------------------------------------------------------------------------------ChangeLog: * Thu Dec 1 2022 Mikolaj Izdebski - 6.5.0-3 - Fix arbitrary bytecode produced via out-of-bounds writing - Resolves:CVE-2022-42920 --------------------------------------------------------------------------------References: [ 1 ] Bug #2143514 - CVE-2022-42920 bcel: Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing [fedora-37] https://bugzilla.redhat.com/show_bug.cgi?id=2143514 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-01a56f581c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Uncover the critical security patch for Fedora regarding bcel that tackles CVE-2022-42921, safeguarding against potential bytecode alteration threats.. Fedora Update, BCEL Security Fix, Bytecode Security, Apache Commons BCEL, Out-of-Bounds Writing. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 11, 2022 Critical Fedora
87

Debian: DSA-2987-2 OpenJDK 7 Update Critical: Bytecode Verifier Issue

The previous security update for OpenJDK 7, DSA-2987-1, introduced a regression due to an overly strict bytecode verifier. As a result, legitimate bytecode which is produced by some non-Java languages would no longer run. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2987-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Florian Weimer August 31, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openjdk-7 The previous security update for OpenJDK 7, DSA-2987-1, introduced a regression due to an overly strict bytecode verifier. As a result, legitimate bytecode which is produced by some non-Java languages would no longer run. For the stable distribution (wheezy), this problem has been fixed in version 7u65-2.5.1-5~deb7u1. We recommend that you upgrade your openjdk-7 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian DSA-3999-1 addresses a critical OpenJDK 11 vulnerability. Immediate update suggested for enhanced security.. OpenJDK Update, Debian Security, Java Bytecode Verifier. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 31, 2014 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200