Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 48 articles for you...
197

Debian 11: DLA-4069-1 Critical: emacs code execution threats

Multiple vulnerabilities were discovered in GNU Emacs, the extensible, customisable, self-documenting, real-time display editor. CVE-2023-28617 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4069-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sean Whitton February 27, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : emacs Version : 1:27.1+1-3.1+deb11u6 CVE ID : CVE-2023-28617 CVE-2024-53920 CVE-2025-1244 Debian Bug : 1033342 1088690 1098255 Multiple vulnerabilities were discovered in GNU Emacs, the extensible, customisable, self-documenting, real-time display editor. CVE-2023-28617 Improper handling of file or directory names containing shell metacharacters in the ob-latex Lisp library could allow the execution of attacker-controlled code. CVE-2024-53920 Several ways to trigger arbitrary code execution were discovered in Emacs's support for editing files in its own dialect of Lisp. These include arbitrary code execution upon opening an otherwise innocent-looking file, with any (or no) file extension, for editing. CVE-2025-1244 Improper handling of custom 'man' URI schemes could allow an attacker to execute arbitrary shell commands by tricking users into visiting a specially crafted website, or an HTTP URL with a redirect. For Debian 11 bullseye, these problems have been fixed in version 1:27.1+1-3.1+deb11u6. We recommend that you upgrade your emacs packages. For the detailed security status of emacs please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/emacs Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The latest Debian LTS SecurityNotification highlights several vulnerabilities in Emacs that could lead to code execution, necessitating prompt updates to enhance system security.. GNU Emacs Security, Debian LTS Advisory, Code Execution Risk, Emacs Vulnerabilities, Security Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 27, 2025 Critical Debian LTS
203

Mageia 9 MGASA-2024-0288 Critical: ORC Buffer Overflow Threat

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments. . MGASA-2024-0288 - Updated orc packages fix security vulnerability Publication date: 10 Sep 2024 URL: https://advisories.mageia.org/MGASA-2024-0288.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-40897 Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments. (CVE-2024-40897) References: - https://bugs.mageia.org/show_bug.cgi?id=33529 - https://ubuntu.com/security/notices/USN-6964-1 - https://www.cve.org/CVERecord?id=CVE-2024-40897 SRPMS: - 9/core/orc-0.4.33-1.1.mga9 . A stack-related buffer overflow issue in ORC poses a risk of unauthorized code execution that may compromise system integrity. Urgent patches are advised.. orc packages,Mageia security,buffer overflow fix,software vulnerability,developer security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 10, 2024 Critical Mageia
197

Debian 10: DLA-3653-1 Critical: libclamunrar Buffer Overflow Execution Risk

A buffer overflow was found in the RAR code used by libclamunrar, which could result in arbitrary code execution when processing malicious RAR archives. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3653-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort November 15, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libclamunrar Version : 0.103.10-0+deb10u1 CVE ID : CVE-2023-40477 A buffer overflow was found in the RAR code used by libclamunrar, which could result in arbitrary code execution when processing malicious RAR archives. For Debian 10 buster, this problem has been fixed in version 0.103.10-0+deb10u1. We recommend that you upgrade your libclamunrar packages. For the detailed security status of libclamunrar please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libclamunrar Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3654-1 highlights a security vulnerability in libxyz, posing a risk of unauthorized data access.. debian 10 libclamunrar update, buffer overflow mitigate, security advisory details. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 15, 2023 Critical Debian LTS
172

Ubuntu 22.10 USN-6153-1 Critical: Jupyter Core Code Execution Risk

Jupyter Core could be made to run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-6153-1 June 12, 2023 jupyter-core vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS (Available with Ubuntu Pro) - Ubuntu 20.04 LTS (Available with Ubuntu Pro) - Ubuntu 18.04 LTS (Available with Ubuntu Pro) Summary: Jupyter Core could be made to run programs as your login if it opened a specially crafted file. Software Description: - jupyter-core: Core common functionality of Jupyter projects (tools) Details: It was discovered that Jupyter Core executed untrusted files in the current working directory. An attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: python3-jupyter-core 4.11.1-1ubuntu0.22.10.1 Ubuntu 22.04 LTS (Available with Ubuntu Pro): python3-jupyter-core 4.9.1-1ubuntu0.1~esm1 Ubuntu 20.04 LTS (Available with Ubuntu Pro): python3-jupyter-core 4.6.3-3ubuntu0.1~esm1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): python-jupyter-core 4.4.0-2ubuntu0.1~esm1 python3-jupyter-core 4.4.0-2ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6153-1 CVE-2022-39286 Package Information: https://launchpad.net/ubuntu/+source/jupyter-core/4.11.1-1ubuntu0.22.10.1 . Investigate the Jupyter Core vulnerability in Ubuntu that affects multiple releases. Ensure to apply the latest patches immediately to protect against potential unauthorized code execution.. Jupyter Core Vulnerability, Ubuntu Software Security, PythonKernel Flaw. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 12, 2023 Critical Ubuntu
172

Ubuntu 20.04 LTS USN-6121-1 Moderate: Nanopb DoS and Code Issues

Several security issues were fixed in Nanopb.. =========================================================================Ubuntu Security Notice USN-6121-1 May 30, 2023 nanopb vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in Nanopb. Software Description: - nanopb: Protocol Buffers with small code size Details: It was discovered that Nanopb incorrectly handled certain decode messages. An attacker could possibly use this cause a denial of service or expose sensitive information. (CVE-2020-26243) It was discovered that Nanopb incorrectly handled certain decode messages. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2021-21401) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS (Available with Ubuntu Pro): nanopb 0.4.1-1ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6121-1 CVE-2020-26243, CVE-2021-21401 . Multiple vulnerabilities in Nanopb resolved via Ubuntu Security Notice USN-6121-1 mitigating code execution and denial-of-service threats.. Nanopb Security, Ubuntu Updates, DoS Protection. . LinuxSecurity.com Team

Calendar%202 May 30, 2023 Ubuntu
87

Debian Bullseye DSA-5367-1 Moderate: Spip Code Execution Risk

It was discovered that SPIP, a website engine for publishing, would allow a malicious user to execute arbitrary code. For the stable distribution (bullseye), this problem has been fixed in . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5367-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Sebastien Delafond March 02, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : spip CVE ID : CVE-2023-27372 It was discovered that SPIP, a website engine for publishing, would allow a malicious user to execute arbitrary code. For the stable distribution (bullseye), this problem has been fixed in version 3.2.11-3+deb11u7. We recommend that you upgrade your spip packages. For the detailed security status of spip please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/spip Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian releases patched version of spip package addressing potential remote code execution vulnerability, reinforcing user safety on the stable platform.. Spip Security Update, Arbitrary Code Execution, Debian Security Advisory, Software Update. . LinuxSecurity.com Team

Calendar%202 Mar 02, 2023 Debian
87

Debian DSA-5356-1 Severe: Sox Denial Of Service Threat Explained

Multiple security issues were discovered in Sox, the Swiss Army knife of sound processing programs, which could result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5356-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff February 20, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : sox CVE ID : CVE-2021-3643 CVE-2021-23159 CVE-2021-23172 CVE-2021-23210 CVE-2021-33844 CVE-2021-40426 CVE-2022-31650 CVE-2022-31651 Debian Bug : 1010374 1012138 1012516 1021133 1021134 1021135 Multiple security issues were discovered in Sox, the Swiss Army knife of sound processing programs, which could result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed. For the stable distribution (bullseye), these problems have been fixed in version 14.4.2+git20190427-2+deb11u1. We recommend that you upgrade your sox packages. For the detailed security status of sox please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/sox Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Various vulnerabilities identified in Sox may lead to denial of service or arbitrary code execution upon processing corrupted audio files. It is advisable to implement updates.. Debian Security,Sox Update,DoS Risk. . LinuxSecurity.com Team

Calendar%202 Feb 20, 2023 Debian
98

Red Hat 8.6 RHSA-2023-0594-01 Important: Libksba Integer Overflow

An update for libksba is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: libksba security update Advisory ID: RHSA-2023:0594-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0594 Issue date: 2023-02-06 CVE Names: CVE-2022-47629 ==================================================================== 1. Summary: An update for libksba is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder EUS (v.8.6) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS EUS (v.8.6) - aarch64, ppc64le, s390x, x86_64 3. Description: KSBA (pronounced Kasbah) is a library to make X.509 certificates as well as the CMS easily accessible by other applications. Both specifications are building blocks of S/MIME and TLS. Security Fix(es): * libksba: integer overflow to code executiona (CVE-2022-47629) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2161571 - CVE-2022-47629 libksba:integer overflow to code execution 6. Package List: Red Hat Enterprise Linux BaseOS EUS (v.8.6): Source: libksba-1.3.5-9.el8_6.src.rpm aarch64: libksba-1.3.5-9.el8_6.aarch64.rpm libksba-debuginfo-1.3.5-9.el8_6.aarch64.rpm libksba-debugsource-1.3.5-9.el8_6.aarch64.rpm ppc64le: libksba-1.3.5-9.el8_6.ppc64le.rpm libksba-debuginfo-1.3.5-9.el8_6.ppc64le.rpm libksba-debugsource-1.3.5-9.el8_6.ppc64le.rpm s390x: libksba-1.3.5-9.el8_6.s390x.rpm libksba-debuginfo-1.3.5-9.el8_6.s390x.rpm libksba-debugsource-1.3.5-9.el8_6.s390x.rpm x86_64: libksba-1.3.5-9.el8_6.i686.rpm libksba-1.3.5-9.el8_6.x86_64.rpm libksba-debuginfo-1.3.5-9.el8_6.i686.rpm libksba-debuginfo-1.3.5-9.el8_6.x86_64.rpm libksba-debugsource-1.3.5-9.el8_6.i686.rpm libksba-debugsource-1.3.5-9.el8_6.x86_64.rpm Red Hat CodeReady Linux Builder EUS (v.8.6): aarch64: libksba-debuginfo-1.3.5-9.el8_6.aarch64.rpm libksba-debugsource-1.3.5-9.el8_6.aarch64.rpm libksba-devel-1.3.5-9.el8_6.aarch64.rpm ppc64le: libksba-debuginfo-1.3.5-9.el8_6.ppc64le.rpm libksba-debugsource-1.3.5-9.el8_6.ppc64le.rpm libksba-devel-1.3.5-9.el8_6.ppc64le.rpm s390x: libksba-debuginfo-1.3.5-9.el8_6.s390x.rpm libksba-debugsource-1.3.5-9.el8_6.s390x.rpm libksba-devel-1.3.5-9.el8_6.s390x.rpm x86_64: libksba-debuginfo-1.3.5-9.el8_6.i686.rpm libksba-debuginfo-1.3.5-9.el8_6.x86_64.rpm libksba-debugsource-1.3.5-9.el8_6.i686.rpm libksba-debugsource-1.3.5-9.el8_6.x86_64.rpm libksba-devel-1.3.5-9.el8_6.i686.rpm libksba-devel-1.3.5-9.el8_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-47629 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY+FwatzjgjWX9erEAQjkEQ/+MjgHxmWjyizq0RATTn3EmEFo4zRkuT7/ xMuwNFp0nM/oG0s+PSGHosHEb9qIHvEOVSABWIAV5YsrPDtulL5j2YpdsFcYq9Xf 19X5gY7TUt1yaIDykxxnyWs1fP/8551J8WtwSOPk5hGAcULBd9QmllCjIjernWnj PfKvqvPl3us4fBHwiwO2FFPT8/ddUcKuDXMyHMWwRVyolfLI71lScF/J4/bCNZOh gCE1ujmEnsCDenyWr2Zk6Q+rq+xMVIxlNGI4wXKqAi1izaA1rMjsCdaIBabcMhBL EQxJ04oFlGUvB4obCWPzTdnInBanH64WiNbZWzI8/zMCxRh83Qx2rmMV0+ie455q nTTu2HNFRRMto8MKZSInKkbA3EfBo1S0dNSNnCAtsYm+3pCQry9kzbLssdcbqdSq WRELA5Em8RQqwxg+6+HRvk4D6jKl8rAd37qcDBSbL1XKvhIKk3O3/bgLzgKdopTB L0rFPLv8VAELGyRbnZ9nTZHjHZYOmk07ula+sMsAMualm2hMiKSXFreYNQF8bxwB LStcWvZkO8MAAeoL+SiRHfxV2wuyB50vEchDfdTVUsyPE8ny2nTGya8igVmtN7/h +aYebE+QbI450/eMtvOSUhdblMrO4A9JPYgQD3heMPmIZvkqWmDzFvP2F0VmLPz9 fdY5Xv3Pk5I=xQ5I -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Keep updated regarding the important libksba security patch for Red Hat. Protect against integer overflow vulnerabilities effectively.. libksba Update, Red Hat Security Advisory, Enterprise Linux Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 06, 2023 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200