Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Ubuntu 18.04: 2018-5dacdf445d Essential: Kernel Security Patch

xen: various flaws (#1518214) x86: infinite loop due to missing PoD error checking [XSA-246] Missing p2m error checking in PoD code [XSA-247]. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-4bfcd57172 2017-12-10 03:53:15.787480 --------------------------------------------------------------------------------Name : xen Product : Fedora 27 Version : 4.9.1 Release : 2.fc27 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor --------------------------------------------------------------------------------Update Information: xen: various flaws (#1518214) x86: infinite loop due to missing PoD error checking [XSA-246] Missing p2m error checking in PoD code [XSA-247] --------------------------------------------------------------------------------References: [ 1 ] Bug #1513335 - CVE-2017-17044 xsa246 xen: x86: infinite loop due to missing PoD error checking (XSA-246) https://bugzilla.redhat.com/show_bug.cgi?id=1513335 [ 2 ] Bug #1513336 - CVE-2017-17045 xsa247 xen: Missing p2m error checking in PoD code (XSA-247) https://bugzilla.redhat.com/show_bug.cgi?id=1513336 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade xen' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest Fedora 27 update addresses critical security vulnerabilities in Xen, enhancing error validation and delivering vital patches for improved system integrity.. Fedora Security Update,xen Flaws,Error Checking,Virtual Machine Monitor,Update Notification. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 10, 2017 Critical Fedora
172

Ubuntu 15.04 USN-2829-1 Critical: Kernel Denial Of Service

Several security issues were fixed in the kernel.. =========================================================================Ubuntu Security Notice USN-2829-1 December 04, 2015 linux vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 Summary: Several security issues were fixed in the kernel. Software Description: - linux: Linux kernel Details: It was discovered that the SCTP protocol implementation in the Linux kernel performed an incorrect sequence of protocol-initialization steps. A local attacker could use this to cause a denial of service (system crash). (CVE-2015-5283) Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted to garbage collect incompletely instantiated keys. A local unprivileged attacker could use this to cause a denial of service (system crash). (CVE-2015-7872) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: linux-image-3.19.0-39-generic 3.19.0-39.44 linux-image-3.19.0-39-generic-lpae 3.19.0-39.44 linux-image-3.19.0-39-lowlatency 3.19.0-39.44 linux-image-3.19.0-39-powerpc-e500mc 3.19.0-39.44 linux-image-3.19.0-39-powerpc-smp 3.19.0-39.44 linux-image-3.19.0-39-powerpc64-emb 3.19.0-39.44 linux-image-3.19.0-39-powerpc64-smp 3.19.0-39.44 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this aswell. References: CVE-2015-5283, CVE-2015-7872 Package Information: https://launchpad.net/ubuntu/+source/linux/3.19.0-39.44 . The latest Ubuntu security bulletin highlights significant kernel vulnerabilities, prompting users to apply necessary updates to safeguard their systems.. Ubuntu Kernel Updates, Linux Security Advisory, Denial of Service Risks, System Crash Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 04, 2015 Critical Ubuntu
87

Debian DSA-3280-1 Critical: PHP5 Null Byte Checks And DoS Issues

Multiple vulnerabilities have been discovered in PHP: CVE-2015-4025 / CVE-2015-4026 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3280-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff June 07, 2015 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : php5 CVE ID : CVE-2015-2783 CVE-2015-3329 CVE-2015-4021 CVE-2015-4022 CVE-2015-4024 CVE-2015-4025 CVE-2015-4026 Multiple vulnerabilities have been discovered in PHP: CVE-2015-4025 / CVE-2015-4026 Multiple function didn't check for NULL bytes in path names. CVE-2015-4024 Denial of service when processing multipart/form-data requests. CVE-2015-4022 Integer overflow in the ftp_genlist() function may result in denial of service or potentially the execution of arbitrary code. CVE-2015-4021 CVE-2015-3329 CVE-2015-2783 Multiple vulnerabilities in the phar extension may result in denial of service or potentially the execution of arbitrary code when processing malformed archives. For the oldstable distribution (wheezy), these problems have been fixed in version 5.4.41-0+deb7u1. For the stable distribution (jessie), these problems have been fixed in version 5.6.9+dfsg-0+deb8u1. For the testing distribution (stretch), these problems have been fixed in version 5.6.9+dfsg-1. For the unstable distribution (sid), these problems have been fixed in version 5.6.9+dfsg-1. We recommend that you upgrade your php5 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent Debian Security advisory DSA-3280-1 addresses multiple vulnerabilities in PHP,including improper null byte validation and potential denial of service issues.. Debian Security, PHP Update, DoS Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 07, 2015 Critical Debian
89

Fedora 34: 2021-7453 Important Freetype2 Security Patch

Port of freetype2 security fixes. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-5644 2009-05-28 07:03:15 -------------------------------------------------------------------------------- Name : freetype1 Product : Fedora 11 Version : 1.4 Release : 0.8.pre.fc11 URL : https://freetype.org/ Summary : Free TrueType font rendering engine, compatibility version Description : The FreeType engine is a free and portable TrueType font rendering engine, developed to provide TrueType support for a variety of platforms and environments. FreeType is a library which can open and manages font files as well as efficiently load, hint and render individual glyphs. FreeType is not a font server or a complete text-rendering library. This package contains the obsolote version 1.x of FreeType for applications which still need this old version. New applications should use the more advanced FreeType 2.x library packaged as freetype. -------------------------------------------------------------------------------- Update Information: Port of freetype2 security fixes -------------------------------------------------------------------------------- ChangeLog: * Tue May 26 2009 Adam Jackson 1.4-0.8.pre - cve-2006-1861.patch, cve-2007-2754.patch: Port of freetype2 fixes. (#502565) -------------------------------------------------------------------------------- References: [ 1 ] Bug #502565 - CVE-2006-1861 CVE-2007-2754 Multiple freetype1 vulnerabilities [Fedora rawhide] https://bugzilla.redhat.com/show_bug.cgi?id=502565 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update freetype1' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Update bulletin for Fedora 11 freetype1 focusing on addressing severe vulnerabilities in font handling. This patch aims to enhance security and stability.. freetype1 update,Fedora security patch,font rendering vulnerabilities,software update instructions. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 28, 2009 Important Fedora
89

Fedora 10: 2009-5524 Critical: Libwmf Use-After-Free Error

CVE-2009-1364 libwmf: embedded gd use-after-free error. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-5524 2009-05-27 01:31:24 -------------------------------------------------------------------------------- Name : libwmf Product : Fedora 10 Version : 0.2.8.4 Release : 18.1.fc10 URL : https://wvware.sourceforge.net/libwmf.html Summary : Windows MetaFile Library Description : A library for reading and converting Windows MetaFile vector graphics (WMF). -------------------------------------------------------------------------------- Update Information: CVE-2009-1364 libwmf: embedded gd use-after-free error -------------------------------------------------------------------------------- ChangeLog: -------------------------------------------------------------------------------- References: [ 1 ] Bug #496864 - CVE-2009-1364 libwmf: embedded gd use-after-free error https://bugzilla.redhat.com/show_bug.cgi?id=496864 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libwmf' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora 10 has released an update that rectifies CVE-2009-1364, which involves a significant use-after-free vulnerability found in libwmf.. Fedora Update, Libwmf Security, Use-After-Free Error. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 27, 2009 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200