Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 42: Local Root Exploit and Configuration Update Announcement

Update default config options for build. New upstream release 5.0.1 . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-f055a0d751 2025-07-19 21:31:40.396395+00:00 -------------------------------------------------------------------------------- Name : screen Product : Fedora 42 Version : 5.0.1 Release : 4.fc42 URL : http://www.gnu.org/software/screen Summary : A screen manager that supports multiple logins on one terminal Description : The screen utility allows you to have multiple logins on just one terminal. Screen is useful for users who telnet into a machine or are connected via a dumb terminal, but want to use more than just one login. Install the screen package if you need a screen manager that can support multiple logins on one terminal. -------------------------------------------------------------------------------- Update Information: Update default config options for build. New upstream release 5.0.1 -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 30 2025 Josef Ridky - 5.0.1-4 - Modify configuration options to reflect changes in version 5.0.1 * Sat Jun 28 2025 Charles R. Anderson - 5.0.1-3 - Add --enable-socket-dir - Resolves: rhbz#2375347 * Wed Jun 25 2025 Josef Ridky - 5.0.1-2 - Unify patch name * Thu May 29 2025 Dick Marinus - 5.0.1-1 - New upstream release 5.0.1 (#2366507) * Tue Feb 11 2025 Zbigniew J\u0119drzejewski-Szmek - 5.0.0-4 - Add sysusers.d config file to allow rpm to create users/groups automatically * Sat Feb 1 2025 Bjrn Esser - 5.0.0-3 - Add explicit BR: libxcrypt-devel -------------------------------------------------------------------------------- References: [ 1 ] Bug #2362065 - [abrt] screen: strncpy(): screen killed by SIGABRT https://bugzilla.redhat.com/show_bug.cgi?id=2362065 [ 2 ] Bug #2366507 - screen-5.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2366507 [ 3 ] Bug #2367169 - Backport to F42: Add sysusers.d config file to allow rpm to create users/groups automatically https://bugzilla.redhat.com/show_bug.cgi?id=2367169 [ 4 ] Bug #2368500 - CVE-2025-46803 screen: Screen by Default Creates World Writable PTYs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2368500 [ 5 ] Bug #2368501 - CVE-2025-46803 screen: Screen by Default Creates World Writable PTYs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2368501 [ 6 ] Bug #2368503 - CVE-2025-46802 screen: TTY Hijacking while Attaching to a Multiuser Session [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2368503 [ 7 ] Bug #2368504 - CVE-2025-46802 screen: TTY Hijacking while Attaching to a Multiuser Session [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2368504 [ 8 ] Bug #2374606 - CVE-2025-23395 screen: Local Root Exploit via `logfile_reopen()` [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2374606 [ 9 ] Bug #2375347 - screen changed location of sockets--now in $HOME/.screen rather than /run/screen https://bugzilla.redhat.com/show_bug.cgi?id=2375347 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f055a0d751' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 42 release tackles security vulnerabilities and settings adjustments in the screen tool. Prompt upgrade advised.. Fedora 42, screen utility, system security fixes, softwareupdate. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jul 19, 2025 Important Fedora
89

Fedora 31: FEDORA-2019-4c69fb4cd7 Moderate: Mosquitto Config Crash Fix

1.6.7 Fix potential crash when reloading config. Client library: * Don't use / in autogenerated client ids, to avoid confusing with topics. * Fix mosquitto_max_inflight_messages_set() and mosquitto_int_option(..., MOSQ_OPT_*_MAX, ...) behaviour. * Fix regression on use of. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-4c69fb4cd7 2019-10-04 20:02:51.623142 --------------------------------------------------------------------------------Name : mosquitto Product : Fedora 31 Version : 1.6.7 Release : 1.fc31 URL : https://mosquitto.org/ Summary : An Open Source MQTT v3.1/v3.1.1 Broker Description : Mosquitto is an open source message broker that implements the MQ Telemetry Transport protocol version 3.1 and 3.1.1 MQTT provides a lightweight method of carrying out messaging using a publish/subscribe model. This makes it suitable for "machine to machine" messaging such as with low power sensors or mobile devices such as phones, embedded computers or micro-controllers like the Arduino. --------------------------------------------------------------------------------Update Information: 1.6.7 ===== Broker: * Add workaround for working with libwebsockets 3.2.0. * Fix potential crash when reloading config. Client library: * Don't use / in autogenerated client ids, to avoid confusing with topics. * Fix mosquitto_max_inflight_messages_set() and mosquitto_int_option(..., MOSQ_OPT_*_MAX, ...) behaviour. * Fix regression on use of mosquitto_connect_async() not working. Clients: * mosquitto_sub: Fix -E incorrectly not working unless -d was also specified. * Updated documentation around automatic client ids. 1.6.6 ===== Security: * CVE-2019-11779 * Restrict topic hierarchy to 200 levels to prevent possible stack overflow. Broker: * Restrict topic hierarchy to 200 levels to prevent possible stack overflow. * mosquitto_passwd now returns 1 when attempting to update a user that does notexist. 1.6.5 ===== Broker: * Fix v5 DISCONNECT packets with remaining length == 2 being treated as a protocol error. * Fix support for libwebsockets 3.x. * Fix slow websockets performance when sending large messages. * Fix bridges potentially not connecting on Windows. * Fix clients authorised using `use_identity_as_username` or `use_subject_as_username` being disconnected on SIGHUP. * Improve error messages in some situations when clients disconnect. Reduces the number of "Socket error on client X, disconnecting" messages. * Fix Will for v5 clients not being sent if will delay interval was greater than the session expiry interval. * Fix CRL file not being reloaded on HUP. * Fix repeated "Error in poll" messages on Windows when only websockets listeners are defined. Client library: * Fix reconnect backoff for the situation where connections are dropped rather than refused. * Fix missing locks on `mosq-> state`. Documentation: * Improve details on global/per listener options in the mosquitto.conf man page. * Clarify behaviour when clients exceed the `message_size_limit`. * Improve documentation for `max_inflight_bytes`, `max_inflight_messages`, and `max_queued_messages`. --------------------------------------------------------------------------------References: [ 1 ] Bug #1753846 - CVE-2019-11779 mosquitto: malicious MQTT sends SUBSCRIBE packet leads to stack over flow https://bugzilla.redhat.com/show_bug.cgi?id=1753846 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-4c69fb4cd7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The recent Mosquitto upgrade on Fedora 31 introduces vital updates and enhancements aimed at boosting both performance and reliability.. Fedora Mosquitto Update, MQTT Broker Fixes, Client Library Improvements. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 04, 2019 Important Fedora
87

Debian 4.0: DSA-1516-1 Critical: Dovecot Privilege Escalation Fix

Prior to this update, the default configuration for Dovecot used by Debian runs the server daemons with group mail privileges. This means that users with write access to their mail directory by other means (for example, through an SSH login) could read mailboxes owned by other users for which they do not have direct write access (CVE-2008-1199). In addition, an internal interpretation conflict in password handling has been addressed proactively, even though it is not known to be exploitable.. - ----------------------------------------------------------------------Debian Security Advisory DSA-1516-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Florian Weimer March 14, 2008 http://www.debian.org/security/faq - ----------------------------------------------------------------------Package : dovecot Vulnerability : privilege escalation Problem type : local Debian-specific: no CVE Id(s) : CVE-2008-1199 CVE-2008-1218 Debian Bug : 469457 Prior to this update, the default configuration for Dovecot used by Debian runs the server daemons with group mail privileges. This means that users with write access to their mail directory by other means (for example, through an SSH login) could read mailboxes owned by other users for which they do not have direct write access (CVE-2008-1199). In addition, an internal interpretation conflict in password handling has been addressed proactively, even though it is not known to be exploitable (CVE-2008-1218). Note that applying this update requires manual action: The configuration setting "mail_extra_groups = mail" has been replaced with "mail_privileged_group = mail". The update will show a configuration file conflict in /etc/dovecot/dovecot.conf. It is recommended that you keep the currently installed configuration file, and change the affected line. For your reference, the sample configuration (without your local changes) will have been writtento /etc/dovecot/dovecot.conf.dpkg-new. If your current configuration uses mail_extra_groups with a value different from "mail", you may have to resort to the mail_access_groups configuration directive. For the stable distribution (etch), these problems have been fixed in version 1.0.rc15-2etch4. For the unstable distribution (sid), these problems have been fixed in version 1.0.13-1. For the old stable distribution (sarge), no updates are provided. We recommend that you consider upgrading to the stable distribution. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - -------------------------------Source archives: Size/MD5 checksum: 1300 8146ccf246ed64e1ac8c0127489ec798 Size/MD5 checksum: 1463069 26f3d2b075856b1b1d180146363819e6 Size/MD5 checksum: 102991 21959fc45cf0f8932fa9eb890791ff39 alpha architecture (DEC Alpha) Size/MD5 checksum: 583482 a0d18885da096140ceb4110d525569d4 Size/MD5 checksum: 1379844 6103bce830848d3f9bb4347f5c9b94f0 Size/MD5 checksum: 621320 48127903af1fe2130cb84c57e5a607ff amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 1222430 1c2e1ffeb6bf745ed88cde01c62d264a Size/MD5 checksum: 536634 4f64ed0cc16510e9c3d709342b3c57ca Size/MD5 checksum: 569588 c17bac715f188f55ae20e5a3c95109b1 arm architecture (ARM) Size/MD5 checksum: 1123030 47eb9fddcc68c2c213afa10c8e3d8747 Size/MD5 checksum: 506134 0f4d939f2cf68f4e5b01140c846e50bc Size/MD5 checksum: 537564 82310ae4e42406429f8ade7cbb81abf0 hppaarchitecture (HP PA RISC) Size/MD5 checksum: 1298818 603d12284115b6349e1d0334263d2af0 Size/MD5 checksum: 562192 413ac964849698428c1b08e9cc9075bc Size/MD5 checksum: 598934 811c32b5c7e2009e5bf2f0ee0ea26859 i386 architecture (Intel ia32) Size/MD5 checksum: 1133484 3bf26ab783ddffed0b3c5ee53225ba20 Size/MD5 checksum: 546528 d53c11fd1c39870bd208d684e70e7551 Size/MD5 checksum: 514280 e85dcbcdd9b85f6e09cdeb4c82b47916 ia64 architecture (Intel ia64) Size/MD5 checksum: 793878 106fe266dd26373615772b4e3636a914 Size/MD5 checksum: 737582 18b15162711b22a704d0ff1ff26e0261 Size/MD5 checksum: 1701788 7535b0a3407f664efa66bcf86966ff85 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 559520 96d7ff1bbd3a38fbdd3bd06b4bc939fb Size/MD5 checksum: 594680 41536feb8048183b78f0d1742278520c Size/MD5 checksum: 1265800 a42823e1253c78709d5d1c18668d9b40 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 1268408 25c8582fea24e3174283066b7c8b6525 Size/MD5 checksum: 594912 264c368593a3fe7a9268aadee2ab1292 Size/MD5 checksum: 558832 d2a20bbfe49d234d0f3c7911c17c9bfb powerpc architecture (PowerPC) Size/MD5 checksum: 569772 e49cc25c54e4fa88217e0fa555de6039 Size/MD5 checksum: 536000 92330b2d1fa2ae8bf6c1b8f05cea3d59 Size/MD5 checksum: 1212096 e2339d417408e14eba21b28684926a5b s390 architecture (IBM S/390) Size/MD5 checksum: 559786 3f7faca1fa56aa29a013068e14e7fada Size/MD5 checksum: 1290186 5b8722445aab8b59ba15beae695e7f77 Size/MD5 checksum: 595498 ad3af123ee9c10dece62ff7cf0e84b35 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 533482 576d0f5a1a733dad01c868095488afcf Size/MD5 checksum: 1108250 1ac8086c83312fec554abd74074cf7b2 Size/MD5 checksum: 501514 27d4aa890df60532d0a33167df7af219 These files will probably be moved into the stable distribution on its next update. ----------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Mitigating privilege escalation in Dovecot on Debian involves adjusting permissions, configuring mail locations, isolating users, and applying ACLs for enhanced security. Dovecot Configuration, Debian Security Update, Privilege Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 14, 2008 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here