Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Moderate: lynx security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2022:2129", "synopsis": "Moderate: lynx security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for lynx.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Lynx is a text-based Web browser. Lynx does not display any images, but it does support frames, tables, and most other HTML tags.\n\nSecurity Fix(es):\n\n* lynx: Disclosure of HTTP authentication credentials via SNI data (CVE-2021-38165)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Rocky Linux 8.6 Release Notes linked from the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "1994998", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=1994998", "description": ""}], "cves": [{"name": "CVE-2021-38165", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38165", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N", "cvss3BaseScore": "5.3", "cwe": "CWE-522"}], "references": [], "publishedAt": "2026-06-28T00:01:40.098233Z", "rpms": {"Rocky Linux 8": {"nvras": ["lynx-debuginfo-0:2.8.9-4.el8.aarch64.rpm", "lynx-0:2.8.9-4.el8.aarch64.rpm", "lynx-0:2.8.9-4.el8.src.rpm", "lynx-0:2.8.9-4.el8.x86_64.rpm", "lynx-debuginfo-0:2.8.9-4.el8.x86_64.rpm", "lynx-debugsource-0:2.8.9-4.el8.aarch64.rpm", "lynx-debugsource-0:2.8.9-4.el8.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Lynx security update for Rocky Linux addresses moderate risks, including HTTP credential exposure. Read more.. Rocky Linux Lynx Update CredentialExposure Web Browser. . Severity: moderate. LinuxSecurity.com Team
Update to 0.50.18. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a74aa25180 2026-03-09 01:01:24.903121+00:00 -------------------------------------------------------------------------------- Name : k9s Product : Fedora 42 Version : 0.50.18 Release : 1.fc42 URL : https://github.com/derailed/k9s Summary : Kubernetes CLI To Manage Your Clusters In Style Description : Kubernetes CLI To Manage Your Clusters In Style! -------------------------------------------------------------------------------- Update Information: Update to 0.50.18 -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 28 2026 blinxen - 0.50.18-1 - Update to version 0.50.18 (rhbz#2428576) * Fri Jan 16 2026 Fedora Release Engineering - 0.50.16-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2417127 - CVE-2025-65965 k9s: Grype has a credential disclosure vulnerability in Grype JSON output [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2417127 [ 2 ] Bug #2419013 - CVE-2024-25621 k9s: containerd local privilege escalation [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2419013 [ 3 ] Bug #2420597 - CVE-2025-47913 k9s: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2420597 [ 4 ] Bug #2424014 - [Minor Incident] CVE-2025-52881 k9s: container escape and denial of service due to arbitrary write gadgets and procfs write redirects [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2424014 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a74aa25180'at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An issue has been found in librabbitmq, a AMQP client library and tools written in C. The issue is related to credential visibility when . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4096-1
Important: git-lfs security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:0673", "synopsis": "Important: git-lfs security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for git-lfs.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.\n\nSecurity Fix(es):\n\n* git-lfs: Git LFS permits exfiltration of credentials via crafted HTTP URLs (CVE-2024-53263)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2338002", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2338002", "description": ""}], "cves": [{"name": "CVE-2024-53263", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-53263", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2025-02-13T20:35:44.459056Z", "rpms": {"Rocky Linux 9": {"nvras": ["git-lfs-0:3.4.1-4.el9_4.aarch64.rpm", "git-lfs-0:3.4.1-4.el9_4.ppc64le.rpm", "git-lfs-0:3.4.1-4.el9_4.s390x.rpm", "git-lfs-0:3.4.1-4.el9_4.src.rpm", "git-lfs-0:3.4.1-4.el9_4.x86_64.rpm", "git-lfs-debuginfo-0:3.4.1-4.el9_4.aarch64.rpm", "git-lfs-debuginfo-0:3.4.1-4.el9_4.ppc64le.rpm", "git-lfs-debuginfo-0:3.4.1-4.el9_4.s390x.rpm", "git-lfs-debuginfo-0:3.4.1-4.el9_4.x86_64.rpm", "git-lfs-debugsource-0:3.4.1-4.el9_4.aarch64.rpm", "git-lfs-debugsource-0:3.4.1-4.el9_4.ppc64le.rpm", "git-lfs-debugsource-0:3.4.1-4.el9_4.s390x.rpm", "git-lfs-debugsource-0:3.4.1-4.el9_4.x86_64.rpm"]}},"rebootSuggested": false, "buildReferences": []}. Critical update issued for git-lfs on Rocky Linux 9 tackles issues related to credential exposures swiftly.. Git LFS security, Rocky Linux security update, credential protection, security patch, software updates. . Severity: Important. LinuxSecurity.com Team
Multiple vulnerabilities were discovered in git, a fast, scalable and distributed revision control system. CVE-2024-50349 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4031-1
Ansible a configuration management, deployment, and task execution system was affected by multiple vulnerabilities. CVE-2019-10206 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3695-1
Forwarding proxy credentials to the destination server unintentionally (CVE-2023-32681) References: - https://bugs.mageia.org/show_bug.cgi?id=32032 . MGASA-2023-0210 - Updated python-requests packages fix security vulnerability Publication date: 28 Jun 2023 URL: https://advisories.mageia.org/MGASA-2023-0210.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-32681 Forwarding proxy credentials to the destination server unintentionally (CVE-2023-32681) References: - https://bugs.mageia.org/show_bug.cgi?id=32032 - https://lists.debian.org/debian-lts-announce/2023/06/msg00018.html - https://ubuntu.com/security/notices/USN-6155-1 - https://www.cve.org/CVERecord?id=CVE-2023-32681 SRPMS: - 8/core/python-requests-2.25.1-1.2.mga8 . MGASA-2023-0211 addresses a vulnerability in python-urllib3 to remediate severe credential leakage risk on Mageia.. Mageia Security Update, Python Requests Vulnerability, Credential Exposure Fix. . Severity: Critical. LinuxSecurity.com Team
etcd could be made to expose sensitive information over the network.. =========================================================================Ubuntu Security Notice USN-6189-1 June 28, 2023 etcd vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.10 Summary: etcd could be made to expose sensitive information over the network. Software Description: - etcd: highly-available key value store -- client Details: It was discovered that etcd leaked credentials when debugging was enabled. This allowed remote attackers to discover etcd authentication credentials and possibly escalate privileges on systems using etcd. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: etcd-client 3.4.23-4ubuntu0.1 etcd-server 3.4.23-4ubuntu0.1 Ubuntu 22.10: etcd-client 3.3.25+dfsg-7ubuntu0.22.10.2 etcd-server 3.3.25+dfsg-7ubuntu0.22.10.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6189-1 CVE-2021-28235 Package Information: https://launchpad.net/ubuntu/+source/etcd/3.4.23-4ubuntu0.1 https://launchpad.net/ubuntu/+source/etcd/3.3.25+dfsg-7ubuntu0.22.10.2 . Critical advisory concerning etcd security flaw on Ubuntu 23.04 and 22.10 to avert unauthorized credential sharing across networks.. etcd Vulnerability, Ubuntu Security, Credential Exposure. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.