Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
219

Mountain OS 4 Java 8.3 Key Outage PQRW-9870-5431 Update Now

Important: .NET 8.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:4454", "synopsis": "Important: .NET 8.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dotnet8.0.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.125 and .NET Runtime 8.0.25.Security Fix(es):\n\n* asp.net: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-26130)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2446134", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2446134", "description": ""}], "cves": [{"name": "CVE-2026-26130", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-26130", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-770"}], "references": [], "publishedAt": "2026-03-13T12:03:59.563415Z", "rpms": {"Rocky Linux 9": {"nvras": ["aspnetcore-runtime-8.0-0:8.0.25-1.el9_7.aarch64.rpm", "aspnetcore-runtime-8.0-0:8.0.25-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-8.0-0:8.0.25-1.el9_7.s390x.rpm", "aspnetcore-runtime-8.0-0:8.0.25-1.el9_7.x86_64.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.25-1.el9_7.aarch64.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.25-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.25-1.el9_7.s390x.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.25-1.el9_7.x86_64.rpm","aspnetcore-targeting-pack-8.0-0:8.0.25-1.el9_7.aarch64.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.25-1.el9_7.ppc64le.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.25-1.el9_7.s390x.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet8.0-0:8.0.125-1.el9_7.src.rpm", "dotnet8.0-debuginfo-0:8.0.125-1.el9_7.aarch64.rpm", "dotnet8.0-debuginfo-0:8.0.125-1.el9_7.ppc64le.rpm", "dotnet8.0-debuginfo-0:8.0.125-1.el9_7.s390x.rpm", "dotnet8.0-debuginfo-0:8.0.125-1.el9_7.x86_64.rpm", "dotnet8.0-debugsource-0:8.0.125-1.el9_7.aarch64.rpm", "dotnet8.0-debugsource-0:8.0.125-1.el9_7.ppc64le.rpm", "dotnet8.0-debugsource-0:8.0.125-1.el9_7.s390x.rpm", "dotnet8.0-debugsource-0:8.0.125-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-8.0-0:8.0.25-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-8.0-0:8.0.25-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-8.0-0:8.0.25-1.el9_7.s390x.rpm", "dotnet-apphost-pack-8.0-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.25-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.25-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.25-1.el9_7.s390x.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet-hostfxr-8.0-0:8.0.25-1.el9_7.aarch64.rpm", "dotnet-hostfxr-8.0-0:8.0.25-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-8.0-0:8.0.25-1.el9_7.s390x.rpm", "dotnet-hostfxr-8.0-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.25-1.el9_7.aarch64.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.25-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.25-1.el9_7.s390x.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet-runtime-8.0-0:8.0.25-1.el9_7.aarch64.rpm", "dotnet-runtime-8.0-0:8.0.25-1.el9_7.ppc64le.rpm", "dotnet-runtime-8.0-0:8.0.25-1.el9_7.s390x.rpm", "dotnet-runtime-8.0-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet-runtime-8.0-debuginfo-0:8.0.25-1.el9_7.aarch64.rpm", "dotnet-runtime-8.0-debuginfo-0:8.0.25-1.el9_7.ppc64le.rpm", "dotnet-runtime-8.0-debuginfo-0:8.0.25-1.el9_7.s390x.rpm","dotnet-runtime-8.0-debuginfo-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet-runtime-dbg-8.0-0:8.0.25-1.el9_7.aarch64.rpm", "dotnet-runtime-dbg-8.0-0:8.0.25-1.el9_7.ppc64le.rpm", "dotnet-runtime-dbg-8.0-0:8.0.25-1.el9_7.s390x.rpm", "dotnet-runtime-dbg-8.0-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet-sdk-8.0-0:8.0.125-1.el9_7.aarch64.rpm", "dotnet-sdk-8.0-0:8.0.125-1.el9_7.ppc64le.rpm", "dotnet-sdk-8.0-0:8.0.125-1.el9_7.s390x.rpm", "dotnet-sdk-8.0-0:8.0.125-1.el9_7.x86_64.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.125-1.el9_7.aarch64.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.125-1.el9_7.ppc64le.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.125-1.el9_7.s390x.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.125-1.el9_7.x86_64.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.125-1.el9_7.aarch64.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.125-1.el9_7.ppc64le.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.125-1.el9_7.s390x.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.125-1.el9_7.x86_64.rpm", "dotnet-sdk-dbg-8.0-0:8.0.125-1.el9_7.aarch64.rpm", "dotnet-sdk-dbg-8.0-0:8.0.125-1.el9_7.ppc64le.rpm", "dotnet-sdk-dbg-8.0-0:8.0.125-1.el9_7.s390x.rpm", "dotnet-sdk-dbg-8.0-0:8.0.125-1.el9_7.x86_64.rpm", "dotnet-targeting-pack-8.0-0:8.0.25-1.el9_7.aarch64.rpm", "dotnet-targeting-pack-8.0-0:8.0.25-1.el9_7.ppc64le.rpm", "dotnet-targeting-pack-8.0-0:8.0.25-1.el9_7.s390x.rpm", "dotnet-targeting-pack-8.0-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet-templates-8.0-0:8.0.125-1.el9_7.aarch64.rpm", "dotnet-templates-8.0-0:8.0.125-1.el9_7.ppc64le.rpm", "dotnet-templates-8.0-0:8.0.125-1.el9_7.s390x.rpm", "dotnet-templates-8.0-0:8.0.125-1.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Critical .NET 8.0 update for Rocky Linux addresses a denial of service threat. Explore the details of this important patch.. Rocky Linux .NET security update, ASP.NET core fix, DoS vulnerability patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 13, 2026 Important Rocky Linux
100

SUSE Linux Enterprise ucode-intel Important Escalation Fix 2026-0668-1

An update that solves two vulnerabilities can now be installed.. # Security update for ucode-intel Announcement ID: SUSE-SU-2026:0668-1 Release Date: 2026-02-26T15:21:26Z Rating: important References: * bsc#1229129 * bsc#1258046 Cross-References: * CVE-2024-24853 * CVE-2025-31648 CVSS scores: * CVE-2024-24853 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2024-24853 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H * CVE-2025-31648 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31648 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N * CVE-2025-31648 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31648 ( NVD ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 *SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for ucode-intel fixes the following issues: * Intel CPU Microcode was updated to the 20260210 release (bsc#1258046) * CVE-2024-24853: Updated fix for incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a privileged user to potentially enable escalation of privilege via local access. (bsc#1229129) * CVE-2025-31648: Improper handling of values in the microcode flow for some Intel Processor Family may allow an escalation of privilege. (bsc#1258046) ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-668=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-668=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-668=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-668=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-668=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-668=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-668=1 *SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-668=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-668=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-668=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-668=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-668=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-668=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-668=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-668=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-668=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-668=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-668=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-668=1 ## Package List: * SUSE Linux Enterprise Micro 5.2 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (x86_64) * ucode-intel-20260210-150200.62.1 * openSUSE Leap 15.6 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux EnterpriseMicro 5.4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * ucode-intel-20260210-150200.62.1 * Basesystem Module 15-SP7 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * ucode-intel-20260210-150200.62.1 ## References: * https://www.suse.com/security/cve/CVE-2024-24853.html * https://www.suse.com/security/cve/CVE-2025-31648.html * https://bugzilla.suse.com/show_bug.cgi?id=1229129 * https://bugzilla.suse.com/show_bug.cgi?id=1258046 . Critical update for ucode-intel fixing important vulnerabilities, enhancing system security for SUSE systems. Install now!. SUSE update, ucode-intel, escalation of privilege, security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 26, 2026 Important SuSE
100

SUSE go1.24 Critical Security Update for Execution Risks 2026-20429-1

An update that solves three vulnerabilities and has one fix can now be installed.. # Security update for go1.24 Announcement ID: SUSE-SU-2026:20429-1 Release Date: 2026-02-13T11:53:30Z Rating: critical References: * bsc#1236217 * bsc#1256818 * bsc#1256820 * bsc#1257692 Cross-References: * CVE-2025-61732 * CVE-2025-68119 * CVE-2025-68121 CVSS scores: * CVE-2025-61732 ( SUSE ): 9.4 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-61732 ( SUSE ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-61732 ( NVD ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-68119 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-68119 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-68119 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68121 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-68121 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-68121 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-68121 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves three vulnerabilities and has one fix can now be installed. ## Description: This update for go1.24 fixes the following issues: Update to version 1.24.13. Security issues fixed: * CVE-2025-61732: cmd/go: discrepancy between Go and C/C++ comment parsing allows for C code smuggling (bsc#1257692). * CVE-2025-68121: crypto/tls: Config.Clone copies automatically generated session ticket keys, session resumption does not account for the expiration of full certificate chain (bsc#1256818). * CVE-2025-68119: cmd/go: unexpected code execution when invoking toolchain (bsc1256820). Other updates and bugfixes: * version updateto 1.24.13: * go#77323 crypto/x509: single-label excluded DNS name constraints incorrectly match all wildcard SANs * go#77424 crypto/tls: CL 737700 broke session resumption on macOS ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-270=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-270=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.24-race-1.24.13-160000.1.1 * go1.24-1.24.13-160000.1.1 * go1.24-doc-1.24.13-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * go1.24-libstd-debuginfo-1.24.13-160000.1.1 * go1.24-libstd-1.24.13-160000.1.1 * go1.24-debuginfo-1.24.13-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * go1.24-race-1.24.13-160000.1.1 * go1.24-1.24.13-160000.1.1 * go1.24-doc-1.24.13-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (x86_64) * go1.24-libstd-debuginfo-1.24.13-160000.1.1 * go1.24-libstd-1.24.13-160000.1.1 * go1.24-debuginfo-1.24.13-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-61732.html * https://www.suse.com/security/cve/CVE-2025-68119.html * https://www.suse.com/security/cve/CVE-2025-68121.html * https://bugzilla.suse.com/show_bug.cgi?id=1236217 * https://bugzilla.suse.com/show_bug.cgi?id=1256818 * https://bugzilla.suse.com/show_bug.cgi?id=1256820 * https://bugzilla.suse.com/show_bug.cgi?id=1257692 . Critical update for SUSE fixes three major issues in go1.24 ensuring better security and stability.. SUSE Linux, Security Update, Go Language, Critical Vulnerability, System Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 18, 2026 Critical SuSE
197

Debian 11: DLA-3920-1 high: php7.4 code execution risks

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in execution of arbitrary code, erroneous parsing of invalid URLs or multipart form data, configuration setting bypass, or log pollution. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3920-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin October 14, 2024 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : php7.4 Version : 7.4.33-1+deb11u6 CVE ID : CVE-2022-4900 CVE-2024-5458 CVE-2024-8925 CVE-2024-8927 CVE-2024-9026 Debian Bug : 1072885 Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in execution of arbitrary code, erroneous parsing of invalid URLs or multipart form data, configuration setting bypass, or log pollution. CVE-2022-4900 It was discovered that setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow. CVE-2024-5458 Due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function results in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly. This causes the same problems as CVE-2020-7071, but with IPv6 host parts. CVE-2024-8925 Mihail Kirov discovered an erroneous parsing of multipart form data contained in an HTTP POST request, which could lead to legitimate data not being processed thereby violating data integrity. CVE-2024-8927 It was discovered that the `cgi.force_redirect` configuration setting isbypassable due to environment variable collision. CVE-2024-9026 In PHP-FPM, when configured to catch workers output through catch_workers_output = yes configuration, it may be possible to pollute the final log with up to 4 characters from the FPM_STDIO_CMD_FLUSH macro, or remove up to 4 characters from the logs. For Debian 11 bullseye, these problems have been fixed in version 7.4.33-1+deb11u6. We recommend that you upgrade your php7.4 packages. For the detailed security status of php7.4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/php7.4 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-4874-1 fixes significant vulnerabilities in nginx 1.18, enhancing security measures and performance optimizations.. Debian LTS, php7.4, security advisory, code execution, data integrity. . LinuxSecurity.com Team

Calendar 2 Oct 15, 2024 Debian LTS
100

SUSE: 2024:2900-1 Important: Python-Setuptools Code Execution Threat

* bsc#1228105 Cross-References: * CVE-2024-6345 . # Security update for python-setuptools Announcement ID: SUSE-SU-2024:2900-1 Rating: important References: * bsc#1228105 Cross-References: * CVE-2024-6345 CVSS scores: * CVE-2024-6345 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Containers Module 12 * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python-setuptools fixes the following issues: * CVE-2024-6345: Fixed code execution via download functions in the package_index module (bsc#1228105) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 12 zypper in -t patch SUSE-SLE-Module-Containers-12-2024-2900=1 * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2024-2900=1 * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patchSUSE-SLE-SDK-12-SP5-2024-2900=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2900=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2900=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2900=1 ## Package List: * Containers Module 12 (noarch) * python-setuptools-40.6.2-4.24.1 * Public Cloud Module 12 (noarch) * python-setuptools-40.6.2-4.24.1 * python3-setuptools-40.6.2-4.24.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (noarch) * python3-setuptools-40.6.2-4.24.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch) * python-setuptools-40.6.2-4.24.1 * python3-setuptools-40.6.2-4.24.1 * SUSE Linux Enterprise Server 12 SP5 (noarch) * python-setuptools-40.6.2-4.24.1 * python3-setuptools-40.6.2-4.24.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch) * python-setuptools-40.6.2-4.24.1 * python3-setuptools-40.6.2-4.24.1 ## References: * https://www.suse.com/security/cve/CVE-2024-6345.html * https://bugzilla.suse.com/show_bug.cgi?id=1228105 . Critical patch released for python-setuptools tackles potential code execution vulnerabilities in SUSE Linux versions 12 series.. python-setuptools security updates, SUSE Linux vulnerabilities, software security fixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 14, 2024 Important SuSE
91

Gentoo: GLSA-202009-03 Normal: Chromium, Google Chrome Code Execution

Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202009-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Chromium, Google Chrome: Multiple vulnerabilities Date: September 10, 2020 Bugs: #741312 ID: 202009-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execution of code. Background ========= Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web. Google Chrome is one fast, simple, and secure browser for all your devices. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-client/chromium < 85.0.4183.102 > = 85.0.4183.102 2 www-client/google-chrome < 85.0.4183.102 > = 85.0.4183.102 ------------------------------------------------------------------- 2 affected packages Description ========== Multiple vulnerabilities have been discovered in Chromium and Google Chrome. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Chromium users should upgrade to the latest version: # emerge --sync #emerge --ask --oneshot -v "> =www-client/chromium-85.0.4183.102" All Google Chrome users should upgrade to the latest version: # emerge --sync # emerge -a --oneshot -v "> =www-client/google-chrome-85.0.4183.102" References ========= [ 1 ] CVE-2020-15959 https://nvd.nist.gov/vuln/detail/CVE-2020-15959 [ 2 ] CVE-2020-6573 https://nvd.nist.gov/vuln/detail/CVE-2020-6573 [ 3 ] CVE-2020-6575 https://nvd.nist.gov/vuln/detail/CVE-2020-6575 [ 4 ] CVE-2020-6576 https://nvd.nist.gov/vuln/detail/CVE-2020-6576 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202009-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2020 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Several security flaws found in Chromium and Google Chrome might enable unauthorized code execution. Ensure you update immediately!. Chromium Security, Google Chrome Update, Gentoo Security, Browser Vulnerabilities. . LinuxSecurity.com Team

Calendar 2 Sep 09, 2020 Gentoo
91

Gentoo: GLSA-202005-10 Normal Severity: libmicrodns Code Execution Risk

Multiple vulnerabilities have been found in libmicrodns, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202005-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libmicrodns: Multiple vulnerabilities Date: May 14, 2020 Bugs: #714606 ID: 202005-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in libmicrodns, the worst of which could result in the arbitrary execution of code. Background ========= libmicrodns is an mDNS library, focused on being simple and cross-platform. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-libs/libmicrodns < 0.1.2 > = 0.1.2 Description ========== Multiple vulnerabilities have been discovered in libmicrodns. Please review the CVE identifiers and the upstream advisory referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All libmicrodns users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-libs/libmicrodns-0.1.2" References ========= [ 1 ] CVE-2020-6071 https://nvd.nist.gov/vuln/detail/CVE-2020-6071 [ 2 ] CVE-2020-6072 https://nvd.nist.gov/vuln/detail/CVE-2020-6072 [ 3 ] CVE-2020-6073 https://nvd.nist.gov/vuln/detail/CVE-2020-6073 [ 4 ] CVE-2020-6077 https://nvd.nist.gov/vuln/detail/CVE-2020-6077 [ 5 ] CVE-2020-6078 https://nvd.nist.gov/vuln/detail/CVE-2020-6078 [ 6 ] CVE-2020-6079 https://nvd.nist.gov/vuln/detail/CVE-2020-6079 [ 7 ] CVE-2020-6080 https://nvd.nist.gov/vuln/detail/CVE-2020-6080 [ 8 ] VideoLAN-SB-VLC-309 https://www.videolan.org/security/sb-vlc309.html Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202005-10 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2020 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Numerous security flaws identified in libmicrodns may permit unauthorized code execution. Upgrade is advised.. libmicrodns, security advisory, gentoo linux, execution risk, software updates. . LinuxSecurity.com Team

Calendar 2 May 14, 2020 Gentoo
87

Debian 4.0 DSA-1607-1 Severe: Iceweasel Remote Code Threat

Devon Hubbard, Jesse Ruderman and Martijn Wargers discovered crashes in the layout engine, which might allow the execution of arbitrary code.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1607-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff July 11, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : iceweasel Vulnerability : several Problem-Type : remote Debian-specific: no CVE ID : CVE-2008-2798 CVE-2008-2799 CVE-2008-2800 CVE-2008-2801 CVE-2008-2802 CVE-2008-2803 CVE-2008-2805 CVE-2008-2807 CVE-2008-2808 CVE-2008-2809 CVE-2008-2811 Several remote vulnerabilities have been discovered in the Iceweasel webbrowser, an unbranded version of the Firefox browser. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-2798 Devon Hubbard, Jesse Ruderman and Martijn Wargers discovered crashes in the layout engine, which might allow the execution of arbitrary code. CVE-2008-2799 Igor Bukanov, Jesse Ruderman and Gary Kwong discovered crashes in the Javascript engine, which might allow the execution of arbitrary code. CVE-2008-2800 "moz_bug_r_a4" discovered several cross-site scripting vulnerabilities. CVE-2008-2801 Collin Jackson and Adam Barth discovered that Javascript code could be executed in the context or signed JAR archives. CVE-2008-2802 "moz_bug_r_a4" discovered that XUL documements can escalate privileges by accessing the pre-compiled "fastload" file. CVE-2008-2803 "moz_bug_r_a4" discovered that missing input sanitising in the mozIJSSubScriptLoader.loadSubScript() function could lead to the execution of arbitrary code. Iceweasel itself is not affected, but some addons are. CVE-2008-2805 Claudio Santambrogio discoveredthat missing access validation in DOM parsing allows malicious web sites to force the browser to upload local files to the server, which could lead to information disclosure. CVE-2008-2807 Daniel Glazman discovered that a programming error in the code for parsing .properties files could lead to memory content being exposed to addons, which could lead to information disclosure. CVE-2008-2808 Masahiro Yamada discovered that file URLS in directory listings were insufficiently escaped. CVE-2008-2809 John G. Myers, Frank Benkstein and Nils Toedtmann discovered that alternate names on self-signed certificates were handled insufficiently, which could lead to spoofings secure connections. CVE-2008-2811 Greg McManus discovered discovered a crash in the block reflow code, which might allow the execution of arbitrary code. For the stable distribution (etch), these problems have been fixed in version 2.0.0.15-0etch1. Iceweasel from the unstable distribution (sid) links dynamically against the xulrunner library. We recommend that you upgrade your iceweasel package. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - -------------------------------Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 47244449 4fb7fdf128d5c8ce5e880510e58f5cfa Size/MD5 checksum: 1289 f29a9bb4fd9f71d203de489050e1f5f5 Size/MD5 checksum: 186551355acbaea7631bbfa0a1013902a7c82a Architecture independent packages: Size/MD5 checksum: 55052 f166a298b2e71f4e478c01dc99e9601f Size/MD5 checksum: 239592 281c8418a4d86ab976acf4fd65033606 Size/MD5 checksum: 54520 283777c2a1be7e90d85e7f900c085f40 Size/MD5 checksum: 54262 06e72fcbbe44c5d4125137786dfb8011 Size/MD5 checksum: 54260 cb6f4ccf969394a3f5b650fb0f8de834 Size/MD5 checksum: 54376 fe9ef4ef5de1b277d8a532aeaaaf5581 Size/MD5 checksum: 54412 2728ff70a7e5051d7dc5bb424ca17a79 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 50156300 9ab61c77c9b1bb6af19448d2300b3277 Size/MD5 checksum: 87772 a3c3f310edeba4b18dfbb8880c8d76f9 Size/MD5 checksum: 10202026 6017a343bcee74e5922218b25b00a9d9 hppa architecture (HP PA RISC) Size/MD5 checksum: 50526254 29a44a85fd87708cc9c1f8a4bb10f346 Size/MD5 checksum: 11108034 8e9c155e5a4128bed37260c0ad7a0c1b Size/MD5 checksum: 89312 1a2507f73581e80103806bda8c673abd i386 architecture (Intel ia32) Size/MD5 checksum: 49553216 2f70c9f1fb5306d9f937613b3cc84cda Size/MD5 checksum: 81902 34948a1ed1b8558e0804860914cd0c72 Size/MD5 checksum: 9117184 f77fc0ad893338c987f206101facd9f0 ia64 architecture (Intel ia64) Size/MD5 checksum: 14150826 de782a5715826236aacf2311f43ef949 Size/MD5 checksum: 50499040 fe8b0f690dd078d0997b27ba36a0e510 Size/MD5 checksum: 100112 ab756247dd84e77695ff6b4dfab96cd3 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 11058248 30d13ac857eddbbeeb6d19fc2a4f9b75 Size/MD5 checksum: 83040 07fc599646c9d80e43fe84e4509d34b7 Size/MD5 checksum: 53950398 74967273393c4b168c101eae383577ff mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 52499994 9c02fbe217402e9c00ef01fa103dc43d Size/MD5 checksum: 10759554 cd00c8429e986dc2399c60cd8c131b2a Size/MD5 checksum: 83054 66561cb487daf2a9df80c8c1722fcce1 powerpc architecture(PowerPC) Size/MD5 checksum: 9935232 0d405869b71246057614dc440c2c685c Size/MD5 checksum: 83630 46e7175e4b0e1bf27a5254c7bc332eaa Size/MD5 checksum: 51949586 589452bc8022d7947522d4e596f6388a s390 architecture (IBM S/390) Size/MD5 checksum: 88034 a29c5e9842d6704818cce57a3cb53d1e Size/MD5 checksum: 50828486 9f956f6e6a3a40ea666dc3b9bb4888db Size/MD5 checksum: 10359442 86e9bac75060c34d0c42826e38b0e6ae sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 81748 6fc2cc53b1d64b48b24ab8b81c9027a4 Size/MD5 checksum: 49164610 e334feea6dd3c72cc2a49af2b3e25e33 Size/MD5 checksum: 9138482 2a301be276e18b5605454682b37ddefd These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance your Firefox ESR on Debian to address potential vulnerabilities and boost online safety measures.. Iceweasel Update, Browser Threats, Debian Security Advisory, Code Execution, Remote Attacks. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 11, 2008 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here