Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 13 articles for you...
202

openSUSE: 2023:0369-1 Important: Connman Network Management Fix

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for connman ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0369-1 Rating: important References: #1210395 Cross-References: CVE-2023-28488 CVSS scores: CVE-2023-28488 (NVD) : 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for connman fixes the following issues: Update to 1.42 * Fix issue with iwd and signal strength calculation. * Fix issue with iwd and handling service removal. * Fix issue with iwd and handling new connections. * Fix issue with handling default online check URL. * Fix issue with handling nameservers refresh. * Fix issue with handling proxy from DHCP lease. (boo#1210395 CVE-2023-28488) * Fix issue with handling multiple proxies from PAC. * Fix issue with handling manual time update changes. * Fix issue with handling invalid gateway routes. * Fix issue with handling hidden WiFi agent requests. * Fix issue with handling WiFi SAE authentication failure. * Fix issue with handling DNS Proxy and TCP server replies. * Add support for regulatory domain following timezone. * Add support for localtime configuration option. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2023-369=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): connman-1.42-bp155.4.3.1 connman-client-1.42-bp155.4.3.1 connman-devel-1.42-bp155.4.3.1 connman-doc-1.42-bp155.4.3.1 connman-nmcompat-1.42-bp155.4.3.1 connman-plugin-iospm-1.42-bp155.4.3.1 connman-plugin-l2tp-1.42-bp155.4.3.1 connman-plugin-openvpn-1.42-bp155.4.3.1 connman-plugin-polkit-1.42-bp155.4.3.1 connman-plugin-pptp-1.42-bp155.4.3.1 connman-plugin-wireguard-1.42-bp155.4.3.1 connman-test-1.42-bp155.4.3.1 - openSUSE Backports SLE-15-SP5 (aarch64 ppc64le s390x x86_64): connman-plugin-vpnc-1.42-bp155.4.3.1 - openSUSE Backports SLE-15-SP5 (aarch64 i586 s390x x86_64): connman-plugin-hh2serial-gps-1.42-bp155.4.3.1 connman-plugin-tist-1.42-bp155.4.3.1 References: https://www.suse.com/security/cve/CVE-2023-28488.html https://bugzilla.suse.com/1210395 . This patch targets a significant flaw within connman on openSUSE, successfully rectifying security vulnerabilities and fortifying protection.. openSUSE Update, Connman Security, Important Fix, SLE-15-SP5, Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 14, 2023 Important OpenSUSE
91

Gentoo: 202310-21 High: ConnMan Remote Code Execution Advisory

Multiple vulnerabilities have been discovered in ConnMan, the worst of which can lead to remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202310-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: ConnMan: Multiple Vulnerabilities Date: October 31, 2023 Bugs: #832028, #863425 ID: 202310-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in ConnMan, the worst of which can lead to remote code execution. Background ========== ConnMan provides a daemon for managing Internet connections. Affected packages ================= Package Vulnerable Unaffected ---------------- ------------------ ------------------- net-misc/connman < 1.42_pre20220801 > = 1.42_pre20220801 Description =========== Multiple vulnerabilities have been discovered in ConnMan. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All ConnMan users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-misc/connman-1.42_pre20220801" References ========== [ 1 ] CVE-2022-23096 https://nvd.nist.gov/vuln/detail/CVE-2022-23096 [ 2 ] CVE-2022-23097 https://nvd.nist.gov/vuln/detail/CVE-2022-23097 [ 3 ] CVE-2022-23098 https://nvd.nist.gov/vuln/detail/CVE-2022-23098 [ 4 ] CVE-2022-32292 https://nvd.nist.gov/vuln/detail/CVE-2022-32292 [ 5 ] CVE-2022-32293 https://nvd.nist.gov/vuln/detail/CVE-2022-32293 Availability ============ This GLSA and any updates to it are availablefor viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202310-21 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2023 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . The flaws in ConnMan could enable remote code execution. Upgrade to version 1.42 or above for security.. ConnMan Security,Gentoo Advisory,Remote Code Execution,Software Update,High Severity Issues. . LinuxSecurity.com Team

Calendar%202 Oct 31, 2023 Gentoo
87

Debian 11 DSA-5416-1 Critical: Connman Buffer Overflow Advisory

It was discovered that there was a potential buffer overflow and denial of service vulnerabilty in the gdhcp client implementation of connman, a command-line network manager designed for use on embedded devices. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5416-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Aron Xu May 31, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : connman CVE ID : CVE-2023-28488 Debian Bug : 1034393 It was discovered that there was a potential buffer overflow and denial of service vulnerabilty in the gdhcp client implementation of connman, a command-line network manager designed for use on embedded devices. For the stable distribution (bullseye), this problem has been fixed in version 1.36-2.2+deb11u2. We recommend that you upgrade your connman packages. For the detailed security status of connman please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/connman Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Unveil the insights of the Debian Security Advisory DSA-5420-1 concerning critical vulnerabilities in libxml2, which pose risks of memory corruption and potential remote code execution.. connman security advisory,debian dsa,buffer overflow fix,embedded device security,denial of service patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 30, 2023 Critical Debian
197

Debian LTS DLA-3397-1: Fix for Connman Denial of Service Vulnerability

It was discovered that there was a potential denial of service vulnerabilty in connman, a command-line network manager designed for use on embedded devices. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3397-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Chris Lamb April 21, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : connman Version : 1.36-2.1~deb10u4 CVE ID : CVE-2023-28488 Debian Bug : 1034393 It was discovered that there was a potential denial of service vulnerabilty in connman, a command-line network manager designed for use on embedded devices. Network-adjacent attackers operating a crafted DHCP server could have caused a stack-based buffer overflow, resulting in a denial of service through terminating the connman process. For Debian 10 buster, this problem has been fixed in version 1.36-2.1~deb10u4. We recommend that you upgrade your connman packages. For the detailed security status of connman please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/connman Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Uncover the vital connman security patch in Debian LTS Advisory DLA-3397-2 that resolves a denial of service vulnerability.. Debian LTS, connman update, security patch, denial of service, embedded devices. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 21, 2023 Critical Debian LTS
197

Debian Buster DLA-3144-1 High Severity: ConnMan DoS Advisory

Several vulnerabilities were discovered in ConnMan, a network manager for embedded devices, which could result in denial of service or the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3144-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort October 10, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : connman Version : 1.36-2.1~deb10u4 CVE ID : CVE-2022-23096 CVE-2022-23097 CVE-2022-23098 CVE-2022-32293 Debian Bug : 1004935 1016976 Several vulnerabilities were discovered in ConnMan, a network manager for embedded devices, which could result in denial of service or the execution of arbitrary code. This update also fixes an issue with reference counting in the CVE-2022-32293 fix introduced in DLA-3105-1. For Debian 10 buster, these problems have been fixed in version 1.36-2.1~deb10u4. We recommend that you upgrade your connman packages. For the detailed security status of connman please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/connman Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Multiple security flaws identified in ConnMan could result in service disruptions or potential execution of arbitrary code. Upgrade is advised.. ConnMan Security, Debian LTS, Denial Of Service, Network Manager. . LinuxSecurity.com Team

Calendar%202 Oct 10, 2022 Debian LTS
202

openSUSE: 2022:10134-1 Critical: Connman Heap Overflow and OOB Write

An update that fixes two vulnerabilities is now available. . openSUSE Security Update: Security update for connman ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10134-1 Rating: critical References: #1200189 #1200190 Cross-References: CVE-2022-32292 CVE-2022-32293 CVSS scores: CVE-2022-32292 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-32293 (NVD) : 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for connman fixes the following issues: - CVE-2022-32292: Add refcounting to wispr portal detection to avoid heap overflow (boo#1200190) - CVE-2022-32292: Fix OOB write in received_data (boo#1200189) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2022-10134=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): connman-1.41-bp153.2.6.1 connman-client-1.41-bp153.2.6.1 connman-devel-1.41-bp153.2.6.1 connman-doc-1.41-bp153.2.6.1 connman-nmcompat-1.41-bp153.2.6.1 connman-plugin-iospm-1.41-bp153.2.6.1 connman-plugin-l2tp-1.41-bp153.2.6.1 connman-plugin-openvpn-1.41-bp153.2.6.1 connman-plugin-polkit-1.41-bp153.2.6.1 connman-plugin-pptp-1.41-bp153.2.6.1 connman-plugin-wireguard-1.41-bp153.2.6.1 connman-test-1.41-bp153.2.6.1 - openSUSE Backports SLE-15-SP3 (aarch64 ppc64le s390x x86_64): connman-plugin-vpnc-1.41-bp153.2.6.1 - openSUSE BackportsSLE-15-SP3 (aarch64 i586 s390x x86_64): connman-plugin-hh2serial-gps-1.41-bp153.2.6.1 connman-plugin-tist-1.41-bp153.2.6.1 References: https://www.suse.com/security/cve/CVE-2022-32292.html https://www.suse.com/security/cve/CVE-2022-32293.html https://bugzilla.suse.com/1200189 https://bugzilla.suse.com/1200190 . OpenSUSE has issued a crucial security alert concerning connman, highlighting serious vulnerabilities such as heap overflow and out-of-bounds write operations.. connman security update, openSUSE critical advisory, software patch connman. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 30, 2022 Critical OpenSUSE
87

Debian DSA-5231-1 Critical: Connman Denial Of Service Issues

Several vulnerabilities were discovered in ConnMan, a network manager for embedded devices, which could result in denial of service or the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5231-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso September 17, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : connman CVE ID : CVE-2022-23096 CVE-2022-23097 CVE-2022-23098 CVE-2022-32292 CVE-2022-32293 Debian Bug : 1004935 1016976 Several vulnerabilities were discovered in ConnMan, a network manager for embedded devices, which could result in denial of service or the execution of arbitrary code. For the stable distribution (bullseye), these problems have been fixed in version 1.36-2.2+deb11u1. We recommend that you upgrade your connman packages. For the detailed security status of connman please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/connman Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Bulletin DSA-5232-2 outlines security flaws in NetworkManager impacting various connected systems. Immediate patching advised.. connman security, debian advisory, embedded device vulnerabilities, network manager update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 17, 2022 Critical Debian
197

Debian 10 Buster DLA-3105-1 Alert: Connman Buffer Overflow and Code Exploit

It was discovered that there were two issues in connman, a daemon for managing internet connections within embedded devices: * CVE-2022-32292: Prevent an issue where remote attackers able to . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3105-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Chris Lamb September 13, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : connman Version : 1.36-2.1~deb10u3 CVE IDs : CVE-2022-32292 CVE-2022-32293 Debian Bug : #1016976 It was discovered that there were two issues in connman, a daemon for managing internet connections within embedded devices: * CVE-2022-32292: Prevent an issue where remote attackers able to send HTTP requests to the gweb component were able to exploit a heap-based buffer overflow in the received_data function to execute code. * CVE-2022-32293: Prevent a man-in-the-middle attack against a WISPR HTTP query which could be used to trigger a use-after-free in WISPR handling, leading to crashes or even code execution. For Debian 10 buster, these problems have been fixed in version 1.36-2.1~deb10u3. We recommend that you upgrade your connman packages. For the detailed security status of connman please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/connman Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Debian LTS Advisory DLA-3105-2 tackles several severe vulnerabilities in connman to enhance the security framework of embedded systems.. connman security update, Debian advisories, critical buffer overflow, embedded device security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 13, 2022 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200