Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
202

openSUSE Capnproto Moderate HTTP Smuggling Vulnerability 2026-21062-1

An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for capnproto ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21062-1 Rating: moderate References: * bsc#1259638 * bsc#1259639 Cross-References: * CVE-2026-32239 * CVE-2026-32240 CVSS scores: * CVE-2026-32239 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-32239 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-32240 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-32240 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for capnproto fixes the following issues: Update to version 1.4.0. Security issues fixed: - CVE-2026-32239: negative `Content-Length` conversion treated as impossibly large length by KJ-HTTP can lead to HTTP smuggling (bsc#1259638). - CVE-2026-32240: integer overflow when KJ-HTTP `Transfer-Encoding` chunk size is parsed to a value of 2^64 or larger can lead to HTTP smuggling (bsc#1259639). Other updates and bugfixes: - Have `stdcoro` use `::std` namespace. - Disable stack check when HWASan is used. - Fix benign buffer overrun in async `readMessage()`. - Shared library naming changes from `libsomething-%{version}.so` to `libsomething.so.%{version}`. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1083=1 Package List: - openSUSE Leap 16.0: capnproto-1.4.0-160000.1.1 libcapnp-1_4_0-1.4.0-160000.1.1 libcapnp-devel-1.4.0-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-32239.html * https://www.suse.com/security/cve/CVE-2026-32240.html . This update for openSUSE addresses vulnerabilities in capnproto that can lead to HTTP smuggling and includes important bug fixes.. openSUSE security capnproto HTTP issues bug fixes. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 moderate OpenSUSE
100

SUSE Linux Enterprise 15-SP4: SUSE-SU-2022:4479-1 Important Boost Fix

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for capnproto ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:4478-1 Rating: moderate References: #1205968 Cross-References: CVE-2022-46149 CVSS scores: CVE-2022-46149 (NVD) : 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L CVE-2022-46149 (SUSE): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L Affected Products: SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Desktop Applications 15-SP4 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for capnproto fixes the following issues: - CVE-2022-46149: Fixed out of bounds read when handling a list of lists (bsc#1205968). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-4478=1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP4: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP4-2022-4478=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): capnproto-0.9.1-150400.3.4.1 capnproto-debuginfo-0.9.1-150400.3.4.1 capnproto-debugsource-0.9.1-150400.3.4.1 libcapnp-0_9-0.9.1-150400.3.4.1 libcapnp-0_9-debuginfo-0.9.1-150400.3.4.1 libcapnp-devel-0.9.1-150400.3.4.1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP4 (aarch64 ppc64le s390x x86_64): capnproto-debuginfo-0.9.1-150400.3.4.1 capnproto-debugsource-0.9.1-150400.3.4.1 libcapnp-0_9-0.9.1-150400.3.4.1 libcapnp-0_9-debuginfo-0.9.1-150400.3.4.1 References: https://www.suse.com/security/cve/CVE-2022-46149.html https://bugzilla.suse.com/1205968 . Important update released for capnproto on SUSE Linux due to a vulnerability involving out of bounds read. Discover more details within.. SUSE Linux, Capnproto Update, Security Patch, 2022 Update, Linux Enterprise. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 14, 2022 Important SuSE
89

Fedora 37: FEDORA-2022-18023b665f Critical: Capnproto Out Of Bounds

Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-18023b665f 2022-12-03 02:00:54.871650 --------------------------------------------------------------------------------Name : rr Product : Fedora 37 Version : 5.6.0 Release : 2.fc37 URL : https://rr-project.org/ Summary : Tool to record and replay execution of applications Description : rr is a lightweight tool for recording and replaying execution of applications (trees of processes and threads). For more information, please visit https://rr-project.org/ --------------------------------------------------------------------------------Update Information: Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump. --------------------------------------------------------------------------------ChangeLog: * Fri Dec 2 2022 Fabio Valentini - 5.6.0-2 - Rebuild for capnproto 0.9.2 / CVE-2022-46149 --------------------------------------------------------------------------------References: [ 1 ] Bug #2150076 - CVE-2022-46149 capnproto: out of bounds read when handling a list of lists. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2150076 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-18023b665f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Upgrade the capnproto package to version 0.9.2 in Fedora 37 to address the serious CVE-2022-46149 vulnerability and enhance overall security of the software.. Fedora Update, Capnproto Fix, Execution Replay, Software Upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 03, 2022 Critical Fedora
89

Fedora 37: FEDORA-2022-18023b665f Moderate: Capnproto Issue

Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-18023b665f 2022-12-03 02:00:54.871650 --------------------------------------------------------------------------------Name : librime Product : Fedora 37 Version : 1.7.3 Release : 3.fc37 URL : https://rime.im/ Summary : Rime Input Method Engine Library Description : Rime Input Method Engine Library Support for shape-based and phonetic-based input methods, including those for Chinese dialects. A selected dictionary in Traditional Chinese, powered by opencc for Simplified Chinese output. --------------------------------------------------------------------------------Update Information: Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump. --------------------------------------------------------------------------------ChangeLog: * Fri Dec 2 2022 Fabio Valentini - 1.7.3-3 - Rebuild for capnproto 0.9.2 / CVE-2022-46149 --------------------------------------------------------------------------------References: [ 1 ] Bug #2150076 - CVE-2022-46149 capnproto: out of bounds read when handling a list of lists. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2150076 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-18023b665f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . # Notification for Fedora 37 regarding an out of bounds access vulnerability in capnproto. Learn more about recompiling affected packages for resolution.. Fedora Update,librime,capnproto Patch,Security Update. . LinuxSecurity.com Team

Calendar%202 Dec 03, 2022 Fedora
89

Fedora 36 FEDORA-2022-5d37367673 Critical Capnproto Security Fix

Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-5d37367673 2022-12-03 01:41:59.480594 --------------------------------------------------------------------------------Name : rr Product : Fedora 36 Version : 5.6.0 Release : 2.fc36 URL : https://rr-project.org/ Summary : Tool to record and replay execution of applications Description : rr is a lightweight tool for recording and replaying execution of applications (trees of processes and threads). For more information, please visit https://rr-project.org/ --------------------------------------------------------------------------------Update Information: Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump. --------------------------------------------------------------------------------ChangeLog: * Fri Dec 2 2022 Fabio Valentini - 5.6.0-2 - Rebuild for capnproto 0.9.2 / CVE-2022-46149 --------------------------------------------------------------------------------References: [ 1 ] Bug #2150076 - CVE-2022-46149 capnproto: out of bounds read when handling a list of lists. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2150076 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-5d37367673' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Upgrade capnproto to mitigate an out-of-bounds read vulnerability identified in Fedora 36 under the security advisory reference CVE-2022-46149.. Capnproto Update,Fedora Security Advisory,Application Rebuild,Software Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 03, 2022 Critical Fedora
89

Fedora 36 FEDORA-2022-5d37367673 Critical: Fastnetmon Capnproto Update

Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-5d37367673 2022-12-03 01:41:59.480594 --------------------------------------------------------------------------------Name : fastnetmon Product : Fedora 36 Version : 1.2.1 Release : 2.20220528git420e7b8.fc36 URL : https://fastnetmon.com Summary : DDoS detection tool with sFlow, Netflow, IPFIX and port mirror support Description : DDoS detection tool with sFlow, Netflow, IPFIX and port mirror support. --------------------------------------------------------------------------------Update Information: Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump. --------------------------------------------------------------------------------ChangeLog: * Fri Dec 2 2022 Fabio Valentini - 1.2.1-2.20220528git420e7b8 - Rebuild for capnproto 0.9.2 / CVE-2022-46149 --------------------------------------------------------------------------------References: [ 1 ] Bug #2150076 - CVE-2022-46149 capnproto: out of bounds read when handling a list of lists. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2150076 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-5d37367673' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Update capnproto to version 0.9.2 to address security vulnerability (CVE-2022-46149) affecting fastnetmon on Fedora 36. Act promptly.. capnproto update,Fedora fastnetmon,DDoS detection tool. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 03, 2022 Critical Fedora
89

Fedora 36: FEDORA-2022-5d37367673 Critical Update for Capnproto

Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-5d37367673 2022-12-03 01:41:59.480594 --------------------------------------------------------------------------------Name : librime Product : Fedora 36 Version : 1.7.3 Release : 2.fc36 URL : https://rime.im/ Summary : Rime Input Method Engine Library Description : Rime Input Method Engine Library Support for shape-based and phonetic-based input methods, including those for Chinese dialects. A selected dictionary in Traditional Chinese, powered by opencc for Simplified Chinese output. --------------------------------------------------------------------------------Update Information: Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump. --------------------------------------------------------------------------------ChangeLog: * Fri Dec 2 2022 Fabio Valentini - 1.7.3-2 - Rebuild for capnproto 0.9.2 / CVE-2022-46149 --------------------------------------------------------------------------------References: [ 1 ] Bug #2150076 - CVE-2022-46149 capnproto: out of bounds read when handling a list of lists. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2150076 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-5d37367673' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Update capnproto to version 0.9.2 on Fedora 36 to fix a critical out-of-bounds read vulnerability by following the terminal commands provided. Fedora 36 Update, Capnproto Security, Out of Bounds Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 03, 2022 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200