Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
89

Fedora 40: FEDORA-2025-4871b31998 critical: xz heap-use-after-free

xz 5.8.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-4871b31998 2025-05-10 01:38:46.492145+00:00 -------------------------------------------------------------------------------- Name : xz Product : Fedora 40 Version : 5.8.1 Release : 2.fc40 URL : https://tukaani.org/xz/ Summary : LZMA compression utilities Description : XZ Utils are an attempt to make LZMA compression easy to use on free (as in freedom) operating systems. This is achieved by providing tools and libraries which are similar to use than the equivalents of the most popular existing compression algorithms. LZMA is a general purpose compression algorithm designed by Igor Pavlov as part of 7-Zip. It provides high compression ratio while keeping the decompression speed fast. -------------------------------------------------------------------------------- Update Information: xz 5.8.1 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 24 2025 Adam Williamson - 1:5.8.1-2 - Rebuild without changes to fix gating problem * Thu Apr 3 2025 Richard W.M. Jones - 1:5.8.1-1 - New upstream version 5.8.1 - Fixes CVE-2025-31115 heap-use-after-free bug in threaded .xz decoder * Wed Mar 26 2025 Jakub Martisko - 1:5.8.0-1 - New upstream version 5.8.0 Resolves: rhbz#2341818 * Sun Jan 19 2025 Fedora Release Engineering - 1:5.6.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Fri Oct 11 2024 Richard W.M. Jones - 1:5.6.3-2 - perl-Compress-Raw-Lzma dep has been removed, rebuild https://src.fedoraproject.org/rpms/perl-Compress-Raw-Lzma/pull-request/3 * Wed Oct 2 2024 Richard W.M. Jones - 1:5.6.3-1 - New upstream version 5.6.3 (RHBZ#2316069) * Thu Aug 8 2024 Lukáš Zaoral - 1:5.6.2-3 - fix licenses and finish SPDX license conversion * Sat Jul 20 2024 Fedora Release Engineering - 1:5.6.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild * Thu Jun20 2024 Richard W.M. Jones - 1:5.6.2-1 - New upstream version 5.6.2 (RHBZ#2283854) - Remove "Jia Tan" pubkey, replace with Lasse Collin's. -------------------------------------------------------------------------------- References: [ 1 ] Bug #2357251 - CVE-2025-31115 xz: XZ has a heap-use-after-free bug in threaded .xz decoder [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2357251 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-4871b31998' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- . The xz 5.8.1 update on Fedora 40 addresses a critical heap-use-after-free vulnerability found in the secure compression tool.. Fedora xz update, compression utilities, Fedora security, LZMA compression. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 10, 2025 Critical Fedora
89

Fedora 42: 2025-7f00e5e744 critical: xz 5.8.1 decoder issue fixed

New upstream version 5.8.1 (with a rebuild to try and fix a gating problem). New upstream version 5.8.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-7f00e5e744 2025-04-26 01:55:23.747817+00:00 -------------------------------------------------------------------------------- Name : xz Product : Fedora 42 Version : 5.8.1 Release : 2.fc42 URL : https://tukaani.org/xz/ Summary : LZMA compression utilities Description : XZ Utils are an attempt to make LZMA compression easy to use on free (as in freedom) operating systems. This is achieved by providing tools and libraries which are similar to use than the equivalents of the most popular existing compression algorithms. LZMA is a general purpose compression algorithm designed by Igor Pavlov as part of 7-Zip. It provides high compression ratio while keeping the decompression speed fast. -------------------------------------------------------------------------------- Update Information: New upstream version 5.8.1 (with a rebuild to try and fix a gating problem). New upstream version 5.8.1 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 24 2025 Adam Williamson - 1:5.8.1-2 - Empty rebuild to try and fix gating issue * Thu Apr 3 2025 Richard W.M. Jones - 1:5.8.1-1 - New upstream version 5.8.1 - Fixes CVE-2025-31115 heap-use-after-free bug in threaded .xz decoder * Wed Mar 26 2025 Jakub Martisko - 1:5.8.0-1 - New upstream version 5.8.0 Resolves: rhbz#2341818 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7f00e5e744' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the FedoraProject GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Delve into the recent Fedora 42 enhancement for xz that introduces vital bug rectifications and improved compression tools, aiming for optimized performance.. Fedora Update, xz Utility, LZMA Compression, Linux Software, Bug Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 26, 2025 Critical Fedora
89

Fedora 42: FEDORA-2025-f050ec7d1b critical: upx heap overflow

5.0.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-f050ec7d1b 2025-04-11 18:19:12.061671+00:00 -------------------------------------------------------------------------------- Name : upx Product : Fedora 42 Version : 5.0.0 Release : 1.fc42 URL : https://github.com/upx/upx Summary : Ultimate Packer for eXecutables Description : UPX is a free, portable, extendable, high-performance executable packer for several different executable formats. It achieves an excellent compression ratio and offers very fast decompression. Your executables suffer no memory overhead or other drawbacks. -------------------------------------------------------------------------------- Update Information: 5.0.0 -------------------------------------------------------------------------------- ChangeLog: * Thu Feb 20 2025 Gwyn Ciesla - 5.0.0-1 - 5.0.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2355649 - CVE-2025-2849 upx: UPX p_lx_elf.cpp un_DT_INIT heap-based overflow [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2355649 [ 2 ] Bug #2355650 - CVE-2025-2849 upx: UPX p_lx_elf.cpp un_DT_INIT heap-based overflow [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2355650 [ 3 ] Bug #2355651 - CVE-2025-2849 upx: UPX p_lx_elf.cpp un_DT_INIT heap-based overflow [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2355651 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f050ec7d1b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project canbe found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . A critical security notice for Fedora 42 concerning a buffer overflow vulnerability in upx version 5.0.0. Prompt action to update is advised.. Fedora 42, upx, heap overflow, package update, security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 11, 2025 Critical Fedora
87

Debian: DSA-5649-1 moderate: xz-utils update for liblzma5 injection risk

Andres Freund discovered that the upstream source tarballs for xz-utils, the XZ-format compression utilities, are compromised and inject malicious code, at build time, into the resulting liblzma5 library. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5649-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso March 29, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : xz-utils CVE ID : CVE-2024-3094 Andres Freund discovered that the upstream source tarballs for xz-utils, the XZ-format compression utilities, are compromised and inject malicious code, at build time, into the resulting liblzma5 library. Right now no Debian stable versions are known to be affected. Compromised packages were part of the Debian testing, unstable and experimental distributions, with versions ranging from 5.5.1alpha-0.1 (uploaded on 2024-02-01), up to and including 5.6.1-1. The package has been reverted to use the upstream 5.4.5 code, which we have versioned 5.6.1+really5.4.5-1. Users running Debian testing and unstable are urged to update the xz-utils packages. For the detailed security status of xz-utils please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/xz-utils Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN-4876-1 concerns a vulnerability in libarchive, affecting the libarchive13 package with unauthorized access.. xz-utils Update, Debian Security, Compression Utility, Malicious Code Injection. . LinuxSecurity.com Team

Calendar%202 Mar 29, 2024 Debian
197

Debian: DLA-2574-1 Important: Libpng Security Update Alert

It was discovered that zstd, a compression utility, was vulnerable to a race condition: it temporarily exposed, during a very short timeframe, a world-readable version of its input even if the original file had restrictive permissions. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2573-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta February 20, 2021 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : libzstd Version : 1.1.2-1+deb9u1 Debian Bug : 981404 982519 It was discovered that zstd, a compression utility, was vulnerable to a race condition: it temporarily exposed, during a very short timeframe, a world-readable version of its input even if the original file had restrictive permissions. For Debian 9 stretch, this problem has been fixed in version 1.1.2-1+deb9u1. We recommend that you upgrade your libzstd packages. For the detailed security status of libzstd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libzstd Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu LTS has published notice USN-4872-1 to fix a synchronization issue in the libjpeg-turbo image processing library's security.. Debian LTS, Libzstd Security Update, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 20, 2021 Important Debian LTS
87

Debian: DSA-4850-1 Critical: World-Readable Permissions in Libzstd

It was discovered that zstd, a compression utility, temporarily exposed a world-readable version of its input even if the original file had restrictive permissions. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4850-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Sebastien Delafond February 10, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libzstd Debian Bug : 981404 It was discovered that zstd, a compression utility, temporarily exposed a world-readable version of its input even if the original file had restrictive permissions. For the stable distribution (buster), this problem has been fixed in version 1.3.8+dfsg-3+deb10u1. We recommend that you upgrade your libzstd packages. For the detailed security status of libzstd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libzstd Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Notice DSA-4851-1 for libxcrypt resolves insecure, universal access permissions flaw. Upgrade is advised.. libzstd permissions exposure, debian security advisory, compression utility issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 10, 2021 Critical Debian
91

Gentoo: GLSA-202007-42 Normal: LHa Buffer Overflow Denial of Service

LHa has a buffer overflow in its compression utility with unspecified impact.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202007-42 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: LHa: Buffer overflow Date: July 27, 2020 Bugs: #572418 ID: 202007-42 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= LHa has a buffer overflow in its compression utility with unspecified impact. Background ========= LHa is a console-based program for packing and unpacking LHarc archives. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-arch/lha < 114i_p20201004 > = 114i_p20201004 Description ========== A buffer overflow in LHa's compression code was discovered which can be triggered by a crafted input file. Impact ===== A remote attacker could send a specially crafted file possibly resulting in a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All LHa users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-arch/lha-114i_p20201004" References ========= [ 1 ] CVE-2016-1925 https://nvd.nist.gov/vuln/detail/CVE-2016-1925 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202007-42 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Anysecurity concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2020 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Adviso. buffer, overflow, compression, utility, unspecified, impact. . LinuxSecurity.com Team

Calendar%202 Jul 26, 2020 Gentoo
89

Fedora 32 pxz Security Advisory: Race Condition and Performance Update

- Update to GIT 20200421 - Added patch against race condition in setting permissions on output file (#1182024) - Added patch to revert environment redirect allowing `export XZ_OPT="-9"` or similar. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-8b89d5b9eb 2020-05-01 04:04:10.484407 --------------------------------------------------------------------------------Name : pxz Product : Fedora 32 Version : 4.999.9 Release : 19.beta.20200421git.fc32 URL : https://jnovy.fedorapeople.org/pxz/ Summary : Parallel LZMA compressor using XZ Description : Parallel XZ is a compression utility that takes advantage of running XZ compression simultaneously on different parts of an input file on multiple cores and processors. This significantly speeds up compression time. --------------------------------------------------------------------------------Update Information: - Update to GIT 20200421 - Added patch against race condition in setting permissions on output file (#1182024) - Added patch to revert environment redirect allowing `export XZ_OPT="-9"` or similar --------------------------------------------------------------------------------ChangeLog: * Tue Apr 21 2020 Robert Scheck 4.999.9-19.beta.20200421git - Update to GIT 20200421 - Added patch against race condition in setting permissions on output file (#1182024) - Added patch to revert environment redirect allowing 'export XZ_OPT="-9"' or similar --------------------------------------------------------------------------------References: [ 1 ] Bug #1182024 - CVE-2015-1200 pxz: race condition in setting permissions on output file https://bugzilla.redhat.com/show_bug.cgi?id=1182024 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-8b89d5b9eb' at the command line. For more information, refer tothe dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Elevate pxz in Fedora 32 to address concurrency issues and boost functionality for improved efficacy.. Fedora 32, pxz update, race condition fix, compression utility. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 01, 2020 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200