Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 4 articles for you...
217

Oracle Linux 10: python-requests Moderate Credential Leak ELSA-2025-13604

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-13604 http://linux.oracle.com/errata/ELSA-2025-13604.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: python3-requests-2.32.4-1.el10_0.noarch.rpm aarch64: python3-requests-2.32.4-1.el10_0.noarch.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/python-requests-2.32.4-1.el10_0.src.rpm Related CVEs: CVE-2024-47081 Description of changes: [2.32.4-1] - Update to 2.32.4 - Security fix for CVE-2024-47081: .netrc credentials leak via malicious URLs Resolves: RHEL-105460 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Cautionary security notice for Oracle Linux 10 concerning python-requests, mitigating risk of credential exposure. Prompt update recommended.. Oracle Linux, python-requests, security advisory, update. . LinuxSecurity.com Team

Calendar%202 Aug 12, 2025 Oracle
89

Fedora 41: Critical Security Issue in mingw-python-requests Announced

Update to 2.32.4. Fixes CVE-2024-47081.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-47916db6c7 2025-07-14 02:33:25.946188+00:00 -------------------------------------------------------------------------------- Name : mingw-python-requests Product : Fedora 41 Version : 2.32.4 Release : 1.fc41 URL : https://requests.readthedocs.io/en/latest/ Summary : MinGW Windows Python requests library Description : MinGW Windows Python requests. -------------------------------------------------------------------------------- Update Information: Update to 2.32.4. Fixes CVE-2024-47081. -------------------------------------------------------------------------------- ChangeLog: * Sat Jul 5 2025 Sandro Mani - 2.32.4-1 - Update to 2.32.4 * Fri Jan 17 2025 Fedora Release Engineering - 2.32.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2375883 - CVE-2024-47081 mingw-python-requests: Requests vulnerable to .netrc credentials leak via malicious URLs [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2375883 [ 2 ] Bug #2375885 - CVE-2024-47081 mingw-python-requests: Requests vulnerable to .netrc credentials leak via malicious URLs [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2375885 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-47916db6c7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Update mingw-python-requests to version 2.32.4 to resolve a severe credentials exposure vulnerability. Prompt attention is advised.. Fedora 41, mingw-python-requests, security patch, credentials leak. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 14, 2025 Critical Fedora
89

Fedora 42: Critical Advisory on python-requests .netrc Credentials Leak

Update to 2.32.4 Security fix for CVE-2024-47081: .netrc credentials leak via malicious URLs . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-87207b946a 2025-07-12 01:44:29.847191+00:00 -------------------------------------------------------------------------------- Name : python-requests Product : Fedora 42 Version : 2.32.4 Release : 1.fc42 URL : https://pypi.org/project/requests Summary : HTTP library, written in Python, for human beings Description : Most existing Python modules for sending HTTP requests are extremely verbose and cumbersome. Python\u2019s built-in urllib2 module provides most of the HTTP capabilities you should need, but the API is thoroughly broken. This library is designed to make HTTP requests easy for developers. -------------------------------------------------------------------------------- Update Information: Update to 2.32.4 Security fix for CVE-2024-47081: .netrc credentials leak via malicious URLs -------------------------------------------------------------------------------- ChangeLog: * Mon Jul 7 2025 Miro Hron\u010dok - 2.32.4-1 - Update to 2.32.4 - Security fix for CVE-2024-47081: .netrc credentials leak via malicious URLs * Wed Jun 4 2025 Python Maint - 2.32.3-14 - Rebuilt for Python 3.14 * Tue Jun 3 2025 Python Maint - 2.32.3-13 - Bootstrap for Python 3.14 * Tue Apr 15 2025 Benjamin A. Beasley - 2.32.3-5 - Backport test-cert. fixes for urllib3 2.4.0 compatibility -------------------------------------------------------------------------------- References: [ 1 ] Bug #2371255 - python-requests-2.32.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2371255 [ 2 ] Bug #2375886 - CVE-2024-47081 python-requests: Requests vulnerable to .netrc credentials leak via malicious URLs [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2375886 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-87207b946a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Urgent security notice regarding python-requests in Fedora 42 updates concerning .netrc credential exposure flaw.. Fedora 42, python-requests, security fix, .netrc leak, cybersecurity. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 12, 2025 Critical Fedora
89

Fedora 38: FEDORA-2023-84ee781688 Moderate: matrix-synapse Security Fix

Update to v1.93.0 (CVE-2023-41335, CVE-2023-42453). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-84ee781688 2023-10-06 01:28:08.203664 -------------------------------------------------------------------------------- Name : matrix-synapse Product : Fedora 38 Version : 1.93.0 Release : 2.fc38 URL : https://github.com/matrix-org/synapse Summary : A Matrix reference homeserver written in Python using Twisted Description : Matrix is an ambitious new ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix from the core development team at matrix.org, written in Python/Twisted. It is intended to showcase the concept of Matrix and let folks see the spec in the context of a coded base and let you run your own homeserver and generally help bootstrap the ecosystem. -------------------------------------------------------------------------------- Update Information: Update to v1.93.0 (CVE-2023-41335, CVE-2023-42453) -------------------------------------------------------------------------------- ChangeLog: * Wed Sep 27 2023 Kai A. Hiller - 1.93.0-2 - Relax pillow requirement * Wed Sep 27 2023 Kai A. Hiller - 1.93.0-1 - Update to v1.93.0 (CVE-2023-41335, CVE-2023-42453) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2242239 - CVE-2023-42453 matrix-synapse: improper validation of receipts allows forged read receipts https://bugzilla.redhat.com/show_bug.cgi?id=2242239 [ 2 ] Bug #2242240 - CVE-2023-41335 matrix-synapse: temporary storage of plaintext passwords during password changes https://bugzilla.redhat.com/show_bug.cgi?id=2242240 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-84ee781688' at thecommand line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest release of matrix-synapse 1.93.0 addresses critical security vulnerabilities, including flaws in receipt validation and exposure of passwords in plaintext.. matrix-synapse update,Fedora security notification,python homeserver,threat management. . LinuxSecurity.com Team

Calendar%202 Oct 06, 2023 Fedora
100

SUSE: 2022:3199-1 Moderate: Yast2-Samba-Provision Credential Leak Fix

An update that solves one vulnerability and has three fixes is now available. . SUSE Security Update: Security update for yast2-samba-provision ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3199-1 Rating: moderate References: #1117597 #1132676 #1140548 #1184897 Cross-References: CVE-2018-17956 CVSS scores: CVE-2018-17956 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Server Applications 15-SP4 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that solves one vulnerability and has three fixes is now available. Description: This update for yast2-samba-provision fixes the following issues: Security issue fixed: - CVE-2018-17956: Fixed a credentials leak (bsc#1117597). Non-Security issues fixed: - Stop packaging docdir, it only contained the license which is now in licensedir. (bsc#1184897) - Catch and show internal python exceptions. (bsc#1140548) - Show a dialog with provision details or errors. (bsc#1132676) - Add metainfo (fate#319035) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-3199=1 - SUSE Linux Enterprise Module for Server Applications 15-SP4: zypper in -t patchSUSE-SLE-Module-Server-Applications-15-SP4-2022-3199=1 Package List: - openSUSE Leap 15.4 (noarch): yast2-samba-provision-1.0.5-150400.9.3.3 - SUSE Linux Enterprise Module for Server Applications 15-SP4 (noarch): yast2-samba-provision-1.0.5-150400.9.3.3 References: https://www.suse.com/security/cve/CVE-2018-17956.html https://bugzilla.suse.com/1117597 https://bugzilla.suse.com/1132676 https://bugzilla.suse.com/1140548 https://bugzilla.suse.com/1184897 . The samba-server-update tackles security vulnerabilities and introduces enhancements. Explore its implications and remedies.. SUSE Linux Update,yast2-samba-provision,credentials leak fix,security patch,moderate severity. . LinuxSecurity.com Team

Calendar%202 Sep 08, 2022 SuSE
197

Debian 9 Stretch: DLA-2873-1 Critical: Aria2 HTTP Credentials Leak

In the download utility aria2, --log was leaking HTTP user credentials in local log file. For Debian 9 stretch, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2873-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk December 31, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : aria2 Version : 1.30.0-2+deb9u1 CVE ID : CVE-2019-3500 Debian Bug : 918058 In the download utility aria2, --log was leaking HTTP user credentials in local log file. For Debian 9 stretch, this problem has been fixed in version 1.30.0-2+deb9u1. We recommend that you upgrade your aria2 packages. For the detailed security status of aria2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/aria2 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2874-1 tackles a vulnerability in curl that exposes sensitive data in system files efficiently.. aria2 Security Update, Debian LTS Advisory, HTTP Credentials Leak, Debian Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 30, 2021 Critical Debian LTS
89

Fedora 34: FEDORA-2021-f59bda7d94 moderate: Lynx HTTP Auth Issue

- fix disclosure of HTTP auth credentials via SNI data (CVE-2021-38165). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-f59bda7d94 2021-09-08 15:05:54.167624 --------------------------------------------------------------------------------Name : lynx Product : Fedora 34 Version : 2.8.9 Release : 13.fc34 URL : http://lynx.browser.org/ Summary : A text-based Web browser Description : Lynx is a text-based Web browser. Lynx does not display any images, but it does support frames, tables, and most other HTML tags. One advantage Lynx has over graphical browsers is speed; Lynx starts and exits quickly and swiftly displays web pages. --------------------------------------------------------------------------------Update Information: - fix disclosure of HTTP auth credentials via SNI data (CVE-2021-38165) --------------------------------------------------------------------------------ChangeLog: * Tue Aug 31 2021 Kamil Dudka - 2.8.9-13 - fix disclosure of HTTP auth credentials via SNI data (CVE-2021-38165) * Thu Jul 22 2021 Fedora Release Engineering - 2.8.9-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1994998 - CVE-2021-38165 lynx: Disclosure of HTTP authentication credentials via SNI data https://bugzilla.redhat.com/show_bug.cgi?id=1994998 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-f59bda7d94' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Resolution for leakage of HTTP auth credentials in Lynx on Fedora caused by SNI exposure.. HTTP Auth Credentials, Lynx Security Fix, Fedora Updates, SNI Data Issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 08, 2021 Important Fedora
203

Mageia 8: 2021-0384 Critical: Curl Connection Issues Resolved

Wrong content via metalink not discarded (CVE-2021-22922). Metalink download sends credentials (CVE-2021-22923). Bad connection reuse due to flawed path name checks (CVE-2021-22924). . MGASA-2021-0384 - Updated curl packages fix security vulnerabilities Publication date: 27 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0384.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-22922, CVE-2021-22923, CVE-2021-22924, CVE-2021-22925 Wrong content via metalink not discarded (CVE-2021-22922). Metalink download sends credentials (CVE-2021-22923). Bad connection reuse due to flawed path name checks (CVE-2021-22924). TELNET stack contents disclosure again (CVE-2021-22925). References: - https://bugs.mageia.org/show_bug.cgi?id=29278 - https://curl.se/docs/CVE-2021-22922.html - https://curl.se/docs/CVE-2021-22923.html - https://curl.se/docs/CVE-2021-22924.html - https://curl.se/docs/CVE-2021-22925.html - https://lists.suse.com/pipermail/sle-security-updates/2021-July/009187.html - https://www.cve.org/CVERecord?id=CVE-2021-22922 - https://www.cve.org/CVERecord?id=CVE-2021-22923 - https://www.cve.org/CVERecord?id=CVE-2021-22924 - https://www.cve.org/CVERecord?id=CVE-2021-22925 SRPMS: - 8/core/curl-7.74.0-1.3.mga8 . New curl updates for Mageia address multiple significant security vulnerabilities, enhancing overall system security and operational efficiency.. curl Security Update, Mageia 8, Security Advisory, Connection Issues, Credential Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 27, 2021 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200