Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 15 articles for you...
89

Fedora 42: nginx Important Compatibility Update 2026-8b992398d3

cleanups and fixes remove RHEL 7 compatibility add RHEL 9 compatibility and EOL comments restore RHEL 8 compatibility. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-8b992398d3 2026-01-11 00:54:21.425399+00:00 -------------------------------------------------------------------------------- Name : nginx Product : Fedora 42 Version : 1.28.1 Release : 3.fc42 URL : https://nginx.org Summary : A high performance web server and reverse proxy server Description : Nginx is a web server and a reverse proxy server for HTTP, SMTP, POP3 and IMAP protocols, with a strong focus on high concurrency, performance and low memory usage. -------------------------------------------------------------------------------- Update Information: cleanups and fixes remove RHEL 7 compatibility add RHEL 9 compatibility and EOL comments restore RHEL 8 compatibility -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 2 2026 Felix Kaechele - 2:1.28.1-3 - cleanups and fixes - remove RHEL 7 compatibility - add RHEL 9 compatibility and EOL comments - restore RHEL 8 compatibility * Sat Dec 27 2025 Aleksei Bavshin - 2:1.28.1-2 - Fix crash in stream SSL configuration (rhbz#2421955) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-8b992398d3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announcemailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Nginx update for Fedora 42 enhances compatibility and performance with RHEL support.. nginx fedora update compatibility performance. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 11, 2026 Important Fedora
89

Fedora 39: 2024-ff98facbc6 critical: rust-rustls-native-certs DoS

Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ff98facbc6 2024-10-19 01:18:49.824560 -------------------------------------------------------------------------------- Name : rust-rustls-native-certs Product : Fedora 39 Version : 0.8.0 Release : 1.fc39 URL : https://crates.io/crates/rustls-native-certs Summary : Allows rustls to use the platform native certificate store Description : Rustls-native-certs allows rustls to use the platform native certificate store. -------------------------------------------------------------------------------- Update Information: Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3. Update the tower crate to version 0.5.1 and add a compat package for version 0.4. Update the tower-http crate to version 0.6.1 and add a compat package for version 0.5. -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 8 2024 Fabio Valentini - 0.8.0-1 - Update to version 0.8.0; Fixes RHBZ#2306094 * Sat Jul 20 2024 Fedora Release Engineering - 0.7.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2316020 - CVE-2024-47609 rust-tonic: Remotely exploitable DoS in Tonic `

Calendar%202 Oct 19, 2024 Critical Fedora
89

Fedora 41: FEDORA-2024-2096f5d14c moderate: rust-nu-protocol improvements

Update rust-brotli-decompressor to 4.0.1, rust-brotli to 7.0.0, and rust-async- compression to 0.4.13. Patch dependent packages as needed to avoid compat packages. Drop i686 support in rust-libcramjam and python-cramjam.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2096f5d14c 2024-10-12 00:17:42.525118 -------------------------------------------------------------------------------- Name : rust-nu-protocol Product : Fedora 41 Version : 0.96.1 Release : 3.fc41 URL : Summary : Nushell's internal protocols, including its abstract syntax tree Description : Nushell's internal protocols, including its abstract syntax tree. -------------------------------------------------------------------------------- Update Information: Update rust-brotli-decompressor to 4.0.1, rust-brotli to 7.0.0, and rust-async- compression to 0.4.13. Patch dependent packages as needed to avoid compat packages. Drop i686 support in rust-libcramjam and python-cramjam. -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 2 2024 Benjamin A. Beasley - 0.96.1-3 - Update rust-brotli to 7.0 * Mon Sep 30 2024 Benjamin A. Beasley - 0.96.1-2 - Update brotli from 5.0 to 6.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2272914 - rust-brotli-6.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2272914 [ 2 ] Bug #2272915 - rust-brotli-decompressor-4.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2272915 [ 3 ] Bug #2273733 - rust-async-compression-0.4.12 is available https://bugzilla.redhat.com/show_bug.cgi?id=2273733 [ 4 ] Bug #2316061 - rust-brotli-7.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2316061 [ 5 ] Bug #2316120 - rust-async-compression-0.4.13 is available https://bugzilla.redhat.com/show_bug.cgi?id=2316120 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2096f5d14c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Enhance rust-nu-protocol in Fedora 41 to boost compatibility and efficiency. Essential updates incorporated in the announcement.. Fedora 41, rust-nu-protocol, software update, rust-brotli. . LinuxSecurity.com Team

Calendar%202 Oct 12, 2024 Fedora
172

Ubuntu 23.10 USN-6568-1 Moderate: ClamAV Compatibility Issue

ClamAV was updated to remain compatible with signature database downloads.. ========================================================================== Ubuntu Security Notice USN-6568-1 January 08, 2024 clamav update ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: ClamAV was updated to remain compatible with signature database downloads. Software Description: - clamav: Anti-virus utility for Unix Details: The ClamAV package was updated to a new upstream version to remain compatible with signature database downloads. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: clamav 1.0.4+dfsg-0ubuntu0.23.10.1 Ubuntu 23.04: clamav 0.103.11+dfsg-0ubuntu0.23.04.1 Ubuntu 22.04 LTS: clamav 0.103.11+dfsg-0ubuntu0.22.04.1 Ubuntu 20.04 LTS: clamav 0.103.11+dfsg-0ubuntu0.20.04.1 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6568-1 https://bugs.launchpad.net/ubuntu/+source/clamav/+bug/2046581 Package Information: https://launchpad.net/ubuntu/+source/clamav/1.0.4+dfsg-0ubuntu0.23.10.1 https://launchpad.net/ubuntu/+source/clamav/0.103.11+dfsg-0ubuntu0.23.04.1 https://launchpad.net/ubuntu/+source/clamav/0.103.11+dfsg-0ubuntu0.22.04.1 https://launchpad.net/ubuntu/+source/clamav/0.103.11+dfsg-0ubuntu0.20.04.1 . ClamAV was updated for compatibility with signature database downloads affecting multiple Ubuntu versions.. ClamAV Update, Ubuntu Security, Signature Database Compatibility. . LinuxSecurity.com Team

Calendar%202 Jan 08, 2024 Ubuntu
89

Fedora 35: SeaMonkey 2.53.12 Update Advisory for Browser Compatibility

Update to 2.53.12 For compatibility with modern sites the default version of Firefox for the User-Agent string has now been set to 78.0 . The value can be changed in Preferences--> Advanced--> HTTP Networking . Note that besides the ordinary builds for the current Fedora and EPEL branches, there is an additional distro-independed build available at https://buc.fedorapeople.org/seamonkey/ . So. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-7c0f2c2d67 2022-05-09 01:35:33.152653 --------------------------------------------------------------------------------Name : seamonkey Product : Fedora 35 Version : 2.53.12 Release : 1.fc35 URL : https://www.seamonkey-project.org/ Summary : Web browser, e-mail, news, IRC client, HTML editor Description : SeaMonkey is an all-in-one Internet application suite (previously made popular by Netscape and Mozilla). It includes an Internet browser, advanced e-mail, newsgroup and feed client, a calendar, IRC client, HTML editor and a tool to inspect the DOM for web pages. It is derived from the application formerly known as Mozilla Application Suite. --------------------------------------------------------------------------------Update Information: Update to 2.53.12 For compatibility with modern sites the default version of Firefox for the User-Agent string has now been set to 78.0 . The value can be changed in Preferences--> Advanced--> HTTP Networking . Note that besides the ordinary builds for the current Fedora and EPEL branches, there is an additional distro-independed build available at https://buc.fedorapeople.org/seamonkey/ . So if you have friends who use other Linux distro, but that distro does not provide SeaMonkey yet, you can recommend it for them. --------------------------------------------------------------------------------ChangeLog: * Tue May 3 2022 Dmitry Butskoy 2.53.12-1 - update to2.53.12 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-7c0f2c2d67' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . The latest release of SeaMonkey 2.53.12 enhances engagement with contemporary web pages on Fedora systems.. SeaMonkey Update, Fedora 35, Internet Application, Browser Compatibility, DNF Upgrade. . LinuxSecurity.com Team

Calendar%202 May 08, 2022 Fedora
89

Fedora 36: FEDORA-2022-609c83fc75 Moderate: SeaMonkey User-Agent Change

Update to 2.53.11 Default version of Firefox for the User-Agent string has now been changed to 68.0 . This should provide better compatibility with modern sites. The value can be changed in Preferences--> Advanced--> HTTP Networking . Besides that, an alternate site-specific override machanism is now activated. (The idea comes from Waterfox-Classic project). The file ua-update.json in the. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-609c83fc75 2022-03-26 14:56:28.650081 --------------------------------------------------------------------------------Name : seamonkey Product : Fedora 36 Version : 2.53.11 Release : 1.fc36 URL : https://www.seamonkey-project.org/ Summary : Web browser, e-mail, news, IRC client, HTML editor Description : SeaMonkey is an all-in-one Internet application suite (previously made popular by Netscape and Mozilla). It includes an Internet browser, advanced e-mail, newsgroup and feed client, a calendar, IRC client, HTML editor and a tool to inspect the DOM for web pages. It is derived from the application formerly known as Mozilla Application Suite. --------------------------------------------------------------------------------Update Information: Update to 2.53.11 Default version of Firefox for the User-Agent string has now been changed to 68.0 . This should provide better compatibility with modern sites. The value can be changed in Preferences--> Advanced--> HTTP Networking . Besides that, an alternate site-specific override machanism is now activated. (The idea comes from Waterfox-Classic project). The file ua-update.json in the application dir is now additionally used for a list of overrides. You can copy it into your profile and edit if needed (be careful with format.) The "general.useragent.override.*" way continues to work and takes precedence. The new mechanism can be toggled by "general.useragent.updates.enabled" prefs(in about:config). --------------------------------------------------------------------------------ChangeLog: * Wed Feb 23 2022 Dmitry Butskoy 2.53.11-1 - update to 2.53.11 - use ua-update.json mechanism for site-specific user-agent overrides - fix some minor issues --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-609c83fc75' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Keep abreast of Fedora's SeaMonkey upgrade to version 2.53.11, which improves support for contemporary web experiences.. Fedora Update, SeaMonkey, User-Agent Mechanism, Internet Suite. . LinuxSecurity.com Team

Calendar%202 Mar 26, 2022 Fedora
89

Fedora 35: 2021-8808996450 Moderate: Seamonkey Compatibility Improvements

Update to 2.53.10.1 Backport fixes to improve compatibility of some sites. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-8808996450 2021-12-26 01:23:55.864059 --------------------------------------------------------------------------------Name : seamonkey Product : Fedora 35 Version : 2.53.10.1 Release : 1.fc35 URL : https://www.seamonkey-project.org/ Summary : Web browser, e-mail, news, IRC client, HTML editor Description : SeaMonkey is an all-in-one Internet application suite (previously made popular by Netscape and Mozilla). It includes an Internet browser, advanced e-mail, newsgroup and feed client, a calendar, IRC client, HTML editor and a tool to inspect the DOM for web pages. It is derived from the application formerly known as Mozilla Application Suite. --------------------------------------------------------------------------------Update Information: Update to 2.53.10.1 Backport fixes to improve compatibility of some sites --------------------------------------------------------------------------------ChangeLog: * Wed Dec 15 2021 Dmitry Butskoy 2.53.10.1-1 - update to 2.53.10.1 - backport new regexp stuff (derived from Waterfox-Classic) - backport fixes for mozbz 1434478, 1449641, 1460295 - fix possible postMessage race conditions --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-8808996450' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . The recent release of Seamonkey 2.53.10.1 improves support for various online platforms within Fedora 35.. Seamonkey Compatibility Update, Fedora 35 Seamonkey, Software Updates for Fedora. . LinuxSecurity.com Team

Calendar%202 Dec 25, 2021 Fedora
89

Fedora 35: 2021-571e3ed33c Moderate RUSTSEC Fix for tiny_http

- Update the tiny_http crate to version 0.8.2. - Introduce a compat package for tiny_http versions 0.6.x. Both versions contain a fix for RUSTSEC-2020-0031 / CVE-2020-35884, and the only dependent application (drg) has been rebuilt against the version containing the fix.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-571e3ed33c 2021-12-13 01:03:28.685557 --------------------------------------------------------------------------------Name : rust-tiny_http Product : Fedora 35 Version : 0.8.2 Release : 1.fc35 URL : Summary : Low level HTTP server library Description : Low level HTTP server library. --------------------------------------------------------------------------------Update Information: - Update the tiny_http crate to version 0.8.2. - Introduce a compat package for tiny_http versions 0.6.x. Both versions contain a fix for RUSTSEC-2020-0031 / CVE-2020-35884, and the only dependent application (drg) has been rebuilt against the version containing the fix. --------------------------------------------------------------------------------ChangeLog: * Sat Dec 4 2021 Fabio Valentini 0.8.2-1 - Update to version 0.8.2 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-571e3ed33c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Upgrade to rust-tiny_http 0.8.3 addresses RUSTSEC-2020-0050. Compatibility layer added for version 0.7.x.. rust-tiny_http,Fedora,update,compatibility,RUSTSEC. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 12, 2021 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200