Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 80 articles for you...
100

SUSE glib-networking Moderate Infinite Loop Issue Vuln 2026-22102-1

An update that solves one vulnerability can now be installed.. # Security update for glib-networking Announcement ID: SUSE-SU-2026:22102-1 Release Date: 2026-06-12T09:03:23Z Rating: moderate References: * bsc#1267979 Cross-References: * CVE-2026-10028 CVSS scores: * CVE-2026-10028 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-10028 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-10028 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for glib-networking fixes the following issue * CVE-2026-10028: two certificates which are each signed by the other can lead to an infinite loop (bsc#1267979). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-753=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * glib-networking-2.76.0-4.1 * glib-networking-debuginfo-2.76.0-4.1 * glib-networking-debugsource-2.76.0-4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10028.html * https://bugzilla.suse.com/show_bug.cgi?id=1267979 . An update for glib-networking addresses a moderate security issue related to certificates causing an infinite loop. Stay secure!. SUSE Linux Micro 6.0, glib-networking, security update, CVE-2026-10028. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 16, 2026 moderate SuSE
202

openSUSE Leap 15.4 NetworkManager Moderate Cert Vulnerability CVE-2025-9615

An update that solves one vulnerability can now be installed.. # Security update for NetworkManager Announcement ID: SUSE-SU-2026:1821-1 Release Date: 2026-05-12T08:00:19Z Rating: moderate References: * bsc#1257359 Cross-References: * CVE-2025-9615 CVSS scores: * CVE-2025-9615 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-9615 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for NetworkManager fixes the following issue: * CVE-2025-9615: Fixed non-admin user using others' certificates (bsc#1257359). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1821=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libnm0-debuginfo-1.32.12-150400.3.3.1 * NetworkManager-1.32.12-150400.3.3.1 * typelib-1_0-NM-1_0-1.32.12-150400.3.3.1 * libnm0-1.32.12-150400.3.3.1 * NetworkManager-debugsource-1.32.12-150400.3.3.1 * NetworkManager-debuginfo-1.32.12-150400.3.3.1 * NetworkManager-devel-1.32.12-150400.3.3.1 * openSUSE Leap 15.4 (noarch) * NetworkManager-branding-upstream-1.32.12-150400.3.3.1 * NetworkManager-lang-1.32.12-150400.3.3.1 * openSUSE Leap 15.4 (x86_64) * NetworkManager-devel-32bit-1.32.12-150400.3.3.1 * libnm0-32bit-1.32.12-150400.3.3.1 * libnm0-32bit-debuginfo-1.32.12-150400.3.3.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libnm0-64bit-1.32.12-150400.3.3.1 * libnm0-64bit-debuginfo-1.32.12-150400.3.3.1 * NetworkManager-devel-64bit-1.32.12-150400.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-9615.html * https://bugzilla.suse.com/show_bug.cgi?id=1257359 . This update addresses amoderate threat in NetworkManager affecting openSUSE Leap 15.4, resolving a user privilege issue.. openSUSE NetworkManager update, security patch, certificate vulnerability, moderate risk advisory. . LinuxSecurity.com Team

Calendar%202 May 13, 2026 OpenSUSE
100

SUSE NetworkManager Moderate CVE-2025-9615 Advisory 2026-21121-1

An update that solves one vulnerability can now be installed.. # Security update for NetworkManager Announcement ID: SUSE-SU-2026:21121-1 Release Date: 2026-04-10T12:43:49Z Rating: moderate References: * bsc#1257359 Cross-References: * CVE-2025-9615 CVSS scores: * CVE-2025-9615 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-9615 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for NetworkManager fixes the following issues: * CVE-2025-9615: Fixed non-admin user using others' certificates (bsc#1257359). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-662=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * NetworkManager-cloud-setup-debuginfo-1.42.6-8.1 * NetworkManager-1.42.6-8.1 * NetworkManager-bluetooth-1.42.6-8.1 * NetworkManager-cloud-setup-1.42.6-8.1 * libnm0-1.42.6-8.1 * typelib-1_0-NM-1_0-1.42.6-8.1 * NetworkManager-debuginfo-1.42.6-8.1 * NetworkManager-wwan-1.42.6-8.1 * NetworkManager-wwan-debuginfo-1.42.6-8.1 * NetworkManager-tui-debuginfo-1.42.6-8.1 * NetworkManager-pppoe-1.42.6-8.1 * NetworkManager-tui-1.42.6-8.1 * libnm0-debuginfo-1.42.6-8.1 * NetworkManager-bluetooth-debuginfo-1.42.6-8.1 * NetworkManager-debugsource-1.42.6-8.1 * NetworkManager-pppoe-debuginfo-1.42.6-8.1 ## References: * https://www.suse.com/security/cve/CVE-2025-9615.html * https://bugzilla.suse.com/show_bug.cgi?id=1257359 . Update for SUSE NetworkManager resolves a moderate issue related to non-admin users accessing certificates. Install now.. NetworkManager update,SUSE Linux vulnerability,moderatesecurity issue,certificate access problem. . LinuxSecurity.com Team

Calendar%202 Apr 17, 2026 SuSE
100

SUSE 2026 NetworkManager Moderate Certificate Access Issue 1420-1

An update that solves one vulnerability can now be installed.. # Security update for NetworkManager Announcement ID: SUSE-SU-2026:1420-1 Release Date: 2026-04-16T16:44:58Z Rating: moderate References: * bsc#1257359 Cross-References: * CVE-2025-9615 CVSS scores: * CVE-2025-9615 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-9615 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for NetworkManager fixes the following issues: * CVE-2025-9615: non-admin users are allowed to use certificates from other users (bsc#1257359). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-1420=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-1420=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * NetworkManager-wwan-debuginfo-1.38.2-150400.3.6.1 * libnm0-1.38.2-150400.3.6.1 * libnm0-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-cloud-setup-1.38.2-150400.3.6.1 * NetworkManager-bluetooth-1.38.2-150400.3.6.1 * NetworkManager-pppoe-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-tui-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-tui-1.38.2-150400.3.6.1 * NetworkManager-debugsource-1.38.2-150400.3.6.1 * NetworkManager-1.38.2-150400.3.6.1 * NetworkManager-pppoe-1.38.2-150400.3.6.1 * typelib-1_0-NM-1_0-1.38.2-150400.3.6.1 * NetworkManager-wwan-1.38.2-150400.3.6.1 * NetworkManager-cloud-setup-debuginfo-1.38.2-150400.3.6.1 *NetworkManager-bluetooth-debuginfo-1.38.2-150400.3.6.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * NetworkManager-wwan-debuginfo-1.38.2-150400.3.6.1 * libnm0-1.38.2-150400.3.6.1 * libnm0-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-cloud-setup-1.38.2-150400.3.6.1 * NetworkManager-bluetooth-1.38.2-150400.3.6.1 * NetworkManager-pppoe-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-tui-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-tui-1.38.2-150400.3.6.1 * NetworkManager-debugsource-1.38.2-150400.3.6.1 * NetworkManager-1.38.2-150400.3.6.1 * NetworkManager-pppoe-1.38.2-150400.3.6.1 * typelib-1_0-NM-1_0-1.38.2-150400.3.6.1 * NetworkManager-wwan-1.38.2-150400.3.6.1 * NetworkManager-cloud-setup-debuginfo-1.38.2-150400.3.6.1 * NetworkManager-bluetooth-debuginfo-1.38.2-150400.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-9615.html * https://bugzilla.suse.com/show_bug.cgi?id=1257359 . Security update for SUSE NetworkManager addresses moderate issues with user certificate access. Update recommended now.. SUSE NetworkManager moderate update access control user certificate. . LinuxSecurity.com Team

Calendar%202 Apr 17, 2026 SuSE
203

Mageia 9 Ceph Important Security Update CVE-2024-31884 MGASA-2026-0025

MGASA-2026-0025 - Updated ceph packages fix security vulnerability. MGASA-2026-0025 - Updated ceph packages fix security vulnerability Publication date: 29 Jan 2026 URL: https://advisories.mageia.org/MGASA-2026-0025.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-31884 Description: Updated ceph packages fix a security issue allowing an attacker to make Ceph accept any certificate. References: - https://bugs.mageia.org/show_bug.cgi?id=35051 - https://www.openwall.com/lists/oss-security/2026/01/21/6 - https://www.cve.org/CVERecord?id=CVE-2024-31884 SRPMS: - 9/core/ceph-18.2.7-2.2.mga9 . Updated ceph packages for Mageia 9 fix significant security risk allowing any certificate acceptance by Ceph.. Mageia Security Advisory,Critical Ceph Update,Certificate Acceptance Issue,Security Vulnerability Report. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 29, 2026 Important Mageia
99

Slackware 15.0: 2025-148-01 High: curl Certificate Check Issue

New curl packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] curl (SSA:2025-148-01) New curl packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/curl-8.14.0-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: No QUIC certificate pinning with wolfSSL. QUIC certificate check skip with wolfSSL. Please note that curl can be built to use one out of twelve different TLS libraries. The selection is done both at build-time and also optionally at runtime. This vulnerability only affects curl made to use this specific TLS (wolfSSL) backend. For more information, see: https://curl.se/docs/CVE-2025-5025.html https://curl.se/docs/CVE-2025-4947.html https://www.cve.org/CVERecord?id=CVE-2025-5025 https://www.cve.org/CVERecord?id=CVE-2025-4947 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/curl-8.14.0-i586-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/curl-8.14.0-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/curl-8.14.0-i686-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/curl-8.14.0-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: b5f5d5311fede2732ce956c7c8ff37b2 curl-8.14.0-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 49ce3e5df9e6d9f6e8e2c313de7bf0e5 curl-8.14.0-x86_64-1_slack15.0.txz Slackware -current package: 18272e8babf1d31f59f68d051494decf n/curl-8.14.0-i686-1.txz Slackware x86_64 -current package: 2409be9d130145d6da089cd0e0a86be8 n/curl-8.14.0-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg curl-8.14.0-i586-1_slack15.0.txz +-----+ . Updated curl versions have now been released for Slackware to address vulnerabilities linked to certificate management, enhancing overall security.. Curl Security Fix, Slackware Packages, TLS Library Update, Open Source Advisory. . LinuxSecurity.com Team

Calendar%202 May 28, 2025 Slackware
203

Mageia 9 MGASA-2025-0069 moderate: python-cryptography NULL pointer attack

Cryptography vulnerable to NULL-dereference when loading PKCS7 certificates. (CVE-2023-49083) Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659. (CVE-2023-50782) Cryptography NULL pointer deference with . MGASA-2025-0069 - Updated python-cryptography & openssl packages fix security vulnerabilities Publication date: 17 Feb 2025 URL: https://advisories.mageia.org/MGASA-2025-0069.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-49083, CVE-2023-50782, CVE-2024-26130 Cryptography vulnerable to NULL-dereference when loading PKCS7 certificates. (CVE-2023-49083) Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659. (CVE-2023-50782) Cryptography NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override. (CVE-2024-26130) References: - https://bugs.mageia.org/show_bug.cgi?id=32584 - https://www.openwall.com/lists/oss-security/2023/11/29/2 - https://ubuntu.com/security/notices/USN-6673-1 - https://ubuntu.com/security/notices/USN-6673-3 - https://www.cve.org/CVERecord?id=CVE-2023-49083 - https://www.cve.org/CVERecord?id=CVE-2023-50782 - https://www.cve.org/CVERecord?id=CVE-2024-26130 SRPMS: - 9/core/openssl-3.0.15-1.3.mga9 - 9/core/python-cryptography-39.0.1-1.1.mga9 . Revamped python-cryptography and openssl libraries rectify significant security threats in Mageia.. Mageia Security, Python Cryptography, OpenSSL Update, NULL Dereference, Timing Attack. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 17, 2025 Important Mageia
203

Mageia 9: MGASA-2024-0359 critical: qBittorrent SSL validation flaw

qBittorrent, on all platforms, did not verify any SSL certificates in its DownloadManager class from 2010 until October 2024. If it failed to verify a cert, it simply logged an error and proceeded. References: . MGASA-2024-0359 - Updated qbittorrent packages fix security vulnerabilities Publication date: 12 Nov 2024 URL: https://advisories.mageia.org/MGASA-2024-0359.html Type: security Affected Mageia releases: 9 qBittorrent, on all platforms, did not verify any SSL certificates in its DownloadManager class from 2010 until October 2024. If it failed to verify a cert, it simply logged an error and proceeded. References: - https://bugs.mageia.org/show_bug.cgi?id=33712 - https://www.openwall.com/lists/oss-security/2024/10/30/4 - https://www.openwall.com/lists/oss-security/2024/10/31/3 SRPMS: - 9/core/qbittorrent-4.6.7-1.mga9 . The latest Mageia advisory points out vulnerabilities related to SSL certificates in qBittorrent which compromise security; fixes can be found in the updates.. qBittorrent Security, Mageia Advisory, SSL Fixes, Certificate Issues Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 12, 2024 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200