Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 408 articles for you...
100

SUSE Linux Micro: 2025:20030-1 critical: mozilla-nss TLS attack

* bsc#1214980 * bsc#1216198 * bsc#1222804 * bsc#1222807 * bsc#1222811 . # Security update for mozilla-nss Announcement ID: SUSE-SU-2025:20030-1 Release Date: 2025-02-03T08:51:45Z Rating: critical References: * bsc#1214980 * bsc#1216198 * bsc#1222804 * bsc#1222807 * bsc#1222811 * bsc#1222813 * bsc#1222814 * bsc#1222821 * bsc#1222822 * bsc#1222826 * bsc#1222828 * bsc#1222830 * bsc#1222833 * bsc#1222834 * bsc#1223724 * bsc#1224113 * bsc#1224115 * bsc#1224116 * bsc#1224118 * bsc#1227918 * jsc#PED-6358 Cross-References: * CVE-2023-5388 CVSS scores: * CVE-2023-5388 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2023-5388 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability, contains one feature and has 19 fixes can now be installed. ## Description: This update for mozilla-nss fixes the following issues: * update to NSS 3.101.2 * ChaChaXor to return after the function * update to NSS 3.101.1 * missing sqlite header. * GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME. * update to NSS 3.101 * add diagnostic assertions for SFTKObject refcount. * freeing the slot in DeleteCertAndKey if authentication failed * fix formatting issues. * Add Firmaprofesional CA Root-A Web to NSS. * remove invalid acvp fuzz test vectors. * pad short P-384 and P-521 signatures gtests. * remove unused FreeBL ECC code. * pad short P-384 and P-521 signatures. * be less strict about ECDSA private key length. * Integrate HACL* P-521. * Integrate HACL* P-384. * memory leak in create_objects_from_handles. * ensure all input is consumed in a few places in mozilla::pkix * SMIME/CMS and PKCS #12 do not integrate with modern NSS policy * clean up escape handling * Use lib::pkix as default validator instead of the old-one * Need to add high level support for PQ signing. * Certificate Compression: changing theallocation/freeing of buffer + Improving the documentation * SMIME/CMS and PKCS #12 do not integrate with modern NSS policy * Allow for non-full length ecdsa signature when using softoken * Modification of .taskcluster.yml due to mozlint indent defects * Implement support for PBMAC1 in PKCS#12 * disable VLA warnings for fuzz builds. * remove redundant AllocItem implementation. * add PK11_ReadDistrustAfterAttribute. * Clang-formatting of SEC_GetMgfTypeByOidTag update * Set SEC_ERROR_LIBRARY_FAILURE on self-test failure * sftk_getParameters(): Fix fallback to default variable after error with configfile. * Switch to the mozillareleases/image_builder image * update to NSS 3.100 * merge pk11_kyberSlotList into pk11_ecSlotList for faster Xyber operations. * remove ckcapi. * avoid a potential PK11GenericObject memory leak. * Remove incomplete ESDH code. * Decrypt RSA OAEP encrypted messages. * Fix certutil CRLDP URI code. * Don't set CKA_DERIVE for CKK_EC_EDWARDS private keys. * Add ability to encrypt and decrypt CMS messages using ECDH. * Correct Templates for key agreement in smime/cmsasn.c. * Moving the decodedCert allocation to NSS. * Allow developers to speed up repeated local execution of NSS tests that depend on certificates. * update to NSS 3.99 * Removing check for message len in ed25519 * add ed25519 to SECU_ecName2params. * add EdDSA wycheproof tests. * nss/lib layer code for EDDSA. * Adding EdDSA implementation. * Exporting Certificate Compression types * Updating ACVP docker to rust 1.74 * Updating HACL* to 0f136f28935822579c244f287e1d2a1908a7e552 * Add NSS_CMSRecipient_IsSupported. * update to NSS 3.98 * CVE-2023-5388: Timing attack against RSA decryption in TLS * Certificate Compression: enabling the check that the compression was advertised * Move Windows workers to nss-1/b-win2022-alpha * Remove Email trust bit from OISTE WISeKey Global Root GC CA * Replace `distutils.spawn.find_executable` with`shutil.which` within `mach` in `nss` * Certificate Compression: Updating nss_bogo_shim to support Certificate compression * TLS Certificate Compression (RFC 8879) Implementation * Add valgrind annotations to freebl kyber operations for constant-time execution tests * Set nssckbi version number to 2.66 * Add Telekom Security roots * Add D-Trust 2022 S/MIME roots * Remove expired Security Communication RootCA1 root * move keys to a slot that supports concatenation in PK11_ConcatSymKeys * remove unmaintained tls-interop tests * bogo: add support for the -ipv6 and -shim-id shim flags * bogo: add support for the -curves shim flag and update Kyber expectations * bogo: adjust expectation for a key usage bit test * mozpkix: add option to ignore invalid subject alternative names * Fix selfserv not stripping `publicname:` from -X value * take ownership of ecckilla shims * add valgrind annotations to freebl/ec.c * PR_INADDR_ANY needs PR_htonl before assignment to inet.ip * Update zlib to 1.3.1 * update to NSS 3.97 * make Xyber768d00 opt-in by policy * add libssl support for xyber768d00 * add PK11_ConcatSymKeys * add Kyber and a PKCS#11 KEM interface to softoken * add a FreeBL API for Kyber * part 2: vendor github.com/pq-crystals/kyber/commit/e0d1c6ff * part 1: add a script for vendoring kyber from pq-crystals repo * Removing the calls to RSA Blind from loader.* * fix worker type for level3 mac tasks * RSA Blind implementation * Remove DSA selftests * read KWP testvectors from JSON * Backed out changeset dcb174139e4f * Fix CKM_PBE_SHA1_DES2_EDE_CBC derivation * Wrap CC shell commands in gyp expansions * update to NSS 3.96.1 * Use pypi dependencies for MacOS worker in ./build_gyp.sh * p7sign: add -a hash and -u certusage (also p7verify cleanups) * add a defensive check for large ssl_DefSend return values * Add dependency to the taskcluster script for Darwin * Upgrade version of the MacOS worker for the CI * update to NSS3.95 * Bump builtins version number. * Remove Email trust bit from Autoridad de Certificacion Firmaprofesional CIF A62634068 root cert. * Remove 4 DigiCert (Symantec/Verisign) Root Certificates * Remove 3 TrustCor Root Certificates from NSS. * Remove Camerfirma root certificates from NSS. * Remove old Autoridad de Certificacion Firmaprofesional Certificate. * Add four Commscope root certificates to NSS. * Add TrustAsia Global Root CA G3 and G4 root certificates. * Include P-384 and P-521 Scalar Validation from HACL* * Include P-256 Scalar Validation from HACL*. * After the HACL 256 ECC patch, NSS incorrectly encodes 256 ECC without DER wrapping at the softoken level * Add means to provide library parameters to C_Initialize * clang format * add OSXSAVE and XCR0 tests to AVX2 detection. * Typo in ssl3_AppendHandshakeNumber * Introducing input check of ssl3_AppendHandshakeNumber * Fix Invalid casts in instance.c * update to NSS 3.94 * Updated code and commit ID for HACL* * update ACVP fuzzed test vector: refuzzed with current NSS * Softoken C_ calls should use system FIPS setting to select NSC_ or FC_ variants * NSS needs a database tool that can dump the low level representation of the database * declare string literals using char in pkixnames_tests.cpp * avoid implicit conversion for ByteString * update rust version for acvp docker * Moving the init function of the mpi_ints before clean-up in ec.c * P-256 ECDH and ECDSA from HACL* * Add ACVP test vectors to the repository * Stop relying on std::basic_string * Transpose the PPC_ABI check from Makefile to gyp * Update to NSS 3.93: * Update zlib in NSS to 1.3. * softoken: iterate hashUpdate calls for long inputs. * regenerate NameConstraints test certificates (bsc#1214980). * update to NSS 3.92 * Set nssckbi version number to 2.62 * Add 4 Atos TrustedRoot Root CA certificates to NSS * Add 4 SSL.com Root CA certificates * Add Sectigo E46 and R46 Root CA certificates * Add LAWtrust Root CA2 (4096) * Remove E-Tugra Certification Authority root * Remove Camerfirma Chambers of Commerce Root. * Remove Hongkong Post Root CA 1 * Remove E-Tugra Global Root CA ECC v3 and RSA v3 * Avoid redefining BYTE_ORDER on hppa Linux * update to NSS 3.91 * Implementation of the HW support check for ADX instruction * Removing the support of Curve25519 * Fix comment about the addition of ticketSupportsEarlyData * Adding args to enable-legacy-db build * dbtests.sh failure in "certutil dump keys with explicit default trust flags" * Initialize flags in slot structures * Improve the length check of RSA input to avoid heap overflow * Followup Fixes * avoid processing unexpected inputs by checking for m_exptmod base sign * add a limit check on order_k to avoid infinite loop * Update HACL* to commit 5f6051d2 * add SHA3 to cryptohi and softoken * HACL SHA3 * Disabling ASM C25519 for A but X86_64 * update to NSS 3.90.3 * GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME. * clean up escape handling. * remove redundant AllocItem implementation. * Disable ASM support for Curve25519. * Disable ASM support for Curve25519 for all but X86_64. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-59=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libfreebl3-debuginfo-3.101.2-1.1 * mozilla-nss-tools-debuginfo-3.101.2-1.1 * mozilla-nss-debugsource-3.101.2-1.1 * mozilla-nss-certs-debuginfo-3.101.2-1.1 * mozilla-nss-3.101.2-1.1 * libsoftokn3-3.101.2-1.1 * mozilla-nss-tools-3.101.2-1.1 * libfreebl3-3.101.2-1.1 * libsoftokn3-debuginfo-3.101.2-1.1 * mozilla-nss-debuginfo-3.101.2-1.1 * mozilla-nss-certs-3.101.2-1.1 ## References: *https://www.suse.com/security/cve/CVE-2023-5388.html * https://bugzilla.suse.com/show_bug.cgi?id=1214980 * https://bugzilla.suse.com/show_bug.cgi?id=1216198 * https://bugzilla.suse.com/show_bug.cgi?id=1222804 * https://bugzilla.suse.com/show_bug.cgi?id=1222807 * https://bugzilla.suse.com/show_bug.cgi?id=1222811 * https://bugzilla.suse.com/show_bug.cgi?id=1222813 * https://bugzilla.suse.com/show_bug.cgi?id=1222814 * https://bugzilla.suse.com/show_bug.cgi?id=1222821 * https://bugzilla.suse.com/show_bug.cgi?id=1222822 * https://bugzilla.suse.com/show_bug.cgi?id=1222826 * https://bugzilla.suse.com/show_bug.cgi?id=1222828 * https://bugzilla.suse.com/show_bug.cgi?id=1222830 * https://bugzilla.suse.com/show_bug.cgi?id=1222833 * https://bugzilla.suse.com/show_bug.cgi?id=1222834 * https://bugzilla.suse.com/show_bug.cgi?id=1223724 * https://bugzilla.suse.com/show_bug.cgi?id=1224113 * https://bugzilla.suse.com/show_bug.cgi?id=1224115 * https://bugzilla.suse.com/show_bug.cgi?id=1224116 * https://bugzilla.suse.com/show_bug.cgi?id=1224118 * https://bugzilla.suse.com/show_bug.cgi?id=1227918 * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-6358&page_caps=&user_role= . A major security vulnerability in Mozilla NSS for SUSE Linux Micro requires urgent updates to prevent potential data breaches and MITM attacks. SUSE Linux Micro, Mozilla NSS, Critical Security Advisory, TLS Attack. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 04, 2025 Critical SuSE
100

SUSE Linux Micro: 2025:20130-1 critical: pam_pkcs11 authentication issue

* bsc#1236314 Cross-References: * CVE-2025-24531 . # Security update for pam_pkcs11 Announcement ID: SUSE-SU-2025:20130-1 Release Date: 2025-02-26T13:23:33Z Rating: critical References: * bsc#1236314 Cross-References: * CVE-2025-24531 CVSS scores: * CVE-2025-24531 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-24531 ( SUSE ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for pam_pkcs11 fixes the following issues: * CVE-2025-24531: Fixed regression in version 0.6.12 returning PAM_IGNORE in many situations with possible authentication bypass (bsc#1236314). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-219=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * pam_pkcs11-debugsource-0.6.12-2.1 * pam_pkcs11-0.6.12-2.1 * pam_pkcs11-debuginfo-0.6.12-2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-24531.html * https://bugzilla.suse.com/show_bug.cgi?id=1236314 . Keep informed about the recent security patch for SUSE Linux Micro concerning pam_pkcs11, which resolves specific authentication problems.. SUSE Linux Security Update, pam_pkcs11 Critical Issue, Authentication Bypass Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 04, 2025 Critical SuSE
100

SUSE Micro 6.0: 2025:20160-1 important: openssh DoS & MitM Fixes

* bsc#1186673 * bsc#1213004 * bsc#1213008 * bsc#1221063 * bsc#1221928 . # Security update for openssh Announcement ID: SUSE-SU-2025:20160-1 Release Date: 2025-03-25T09:02:43Z Rating: important References: * bsc#1186673 * bsc#1213004 * bsc#1213008 * bsc#1221063 * bsc#1221928 * bsc#1222840 * bsc#1225904 * bsc#1227456 * bsc#1229010 * bsc#1229072 * bsc#1229449 * bsc#1236826 * bsc#1237040 * bsc#1237041 Cross-References: * CVE-2025-26465 * CVE-2025-26466 CVSS scores: * CVE-2025-26465 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-26465 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-26465 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-26466 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-26466 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-26466 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-26466 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities and has 12 fixes can now be installed. ## Description: This update for openssh fixes the following issues: * CVE-2025-26465: Fixed MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client (bsc#1237040). * CVE-2025-26466: Fixed DoS attack against OpenSSH's client and server (bsc#1237041). Other bugfixes: * Fix ssh client segfault with GSSAPIKeyExchange=yes in ssh_kex2 due to gssapi proposal not being correctly initialized (bsc#1236826). * Add #include in some files added by the ldap patch to fix build with gcc14 (bsc#1225904). * Added missing struct initializer, added missing parameter (bsc#1222840). * Remove OPENSSL_HAVE_EVPGCM-ifdef, which is no longer supported by upstream (bsc#1221928). * Use %config(noreplace) for sshd_config. In any case, it's recommended to drop a file in sshd_config.dinstead of editing sshd_config (bsc#1221063). * Add a patch to fix a regression introduced in 9.6 that makes X11 forwarding very slow (bsc#1229449). * Drop keycat binary that is not supported, except of the code that is used by other SELinux patches (bsc#1229072). * Fix RFC4256 implementation that keyboard-interactive authentication method can send instructions and sshd shows them to users (bsc#1229010). * Add attempts to mitigate instances of secrets lingering in memory after a session exits (bsc#1186673, bsc#1213004, bsc#1213008). * Remove empty line at the end of sshd-sle.pamd (bsc#1227456) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-259=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * openssh-clients-9.6p1-3.1 * openssh-debugsource-9.6p1-3.1 * openssh-server-config-rootlogin-9.6p1-3.1 * openssh-server-9.6p1-3.1 * openssh-common-9.6p1-3.1 * openssh-debuginfo-9.6p1-3.1 * openssh-clients-debuginfo-9.6p1-3.1 * openssh-server-debuginfo-9.6p1-3.1 * openssh-fips-9.6p1-3.1 * openssh-common-debuginfo-9.6p1-3.1 * openssh-9.6p1-3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-26465.html * https://www.suse.com/security/cve/CVE-2025-26466.html * https://bugzilla.suse.com/show_bug.cgi?id=1186673 * https://bugzilla.suse.com/show_bug.cgi?id=1213004 * https://bugzilla.suse.com/show_bug.cgi?id=1213008 * https://bugzilla.suse.com/show_bug.cgi?id=1221063 * https://bugzilla.suse.com/show_bug.cgi?id=1221928 * https://bugzilla.suse.com/show_bug.cgi?id=1222840 * https://bugzilla.suse.com/show_bug.cgi?id=1225904 * https://bugzilla.suse.com/show_bug.cgi?id=1227456 * https://bugzilla.suse.com/show_bug.cgi?id=1229010 * https://bugzilla.suse.com/show_bug.cgi?id=1229072 *https://bugzilla.suse.com/show_bug.cgi?id=1229449 * https://bugzilla.suse.com/show_bug.cgi?id=1236826 * https://bugzilla.suse.com/show_bug.cgi?id=1237040 * https://bugzilla.suse.com/show_bug.cgi?id=1237041 . This SUSE advisory details important openssh fixes addressing DoS and MitM attacks. Immediate action is essential.. openssh vulnerabilities, SUSE patches, critical security updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 04, 2025 Important SuSE
100

SUSE: 2025:1430-1 critical: python-h11 request smuggling

* bsc#1241872 Cross-References: * CVE-2025-43859 . # Security update for python-h11 Announcement ID: SUSE-SU-2025:1430-1 Release Date: 2025-05-02T08:11:00Z Rating: critical References: * bsc#1241872 Cross-References: * CVE-2025-43859 CVSS scores: * CVE-2025-43859 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-43859 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-43859 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.6 * Python 3 Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for python-h11 fixes the following issues: * CVE-2025-43859: leniency when parsing of line terminators in chunked-coding message bodies can lead to request smuggling. (bsc#1241872) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-1430=1 * openSUSE Leap 15.6 zypper in -tpatch openSUSE-SLE-15.6-2025-1430=1 * Python 3 Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Python3-15-SP6-2025-1430=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-1430=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-1430=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-1430=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-1430=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-1430=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-1430=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-1430=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-1430=1 ## Package List: * openSUSE Leap 15.4 (noarch) * python311-h11-0.14.0-150400.9.6.1 * openSUSE Leap 15.6 (noarch) * python311-h11-0.14.0-150400.9.6.1 * Python 3 Module 15-SP6 (noarch) * python311-h11-0.14.0-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python311-h11-0.14.0-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python311-h11-0.14.0-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python311-h11-0.14.0-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python311-h11-0.14.0-150400.9.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python311-h11-0.14.0-150400.9.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) *python311-h11-0.14.0-150400.9.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python311-h11-0.14.0-150400.9.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python311-h11-0.14.0-150400.9.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-43859.html * https://bugzilla.suse.com/show_bug.cgi?id=1241872 . Important patch for python-h11 on SUSE addresses cache poisoning issues. Protect your environment immediately.. python-h11 vulnerability, SUSE security update, request smuggling, openSUSE patch, Python module security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 02, 2025 Critical SuSE
202

openSUSE Leap 15.4 important: Linux Kernel Critical Patch

An update that solves three vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 32 for SLE 15 SP4) Announcement ID: SUSE-SU-2025:1425-1 Release Date: 2025-05-01T19:39:28Z Rating: important References: * bsc#1233294 * bsc#1235431 * bsc#1240840 Cross-References: * CVE-2024-50205 * CVE-2024-56650 * CVE-2024-8805 CVSS scores: * CVE-2024-50205 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-50205 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2024-50205 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-56650 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56650 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56650 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-8805 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-8805 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-8805 ( NVD ): 8.8 CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves three vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.14.21-150400_24_136 fixes several issues. The following security issues were fixed: * CVE-2024-8805: Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE (bsc#1240840). * CVE-2024-50205: ALSA: firewire-lib: Avoid division by zero in apply_constraint_to_size() (bsc#1233294). * CVE-2024-56650: netfilter: x_tables: fix LED ID check in led_tg_check() (bsc#1235431). ## PatchInstructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-1425=1 SUSE-2025-1427=1 SUSE-2025-1424=1 SUSE-2025-1426=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2025-1426=1 SUSE-SLE- Module-Live-Patching-15-SP4-2025-1425=1 SUSE-SLE-Module-Live- Patching-15-SP4-2025-1427=1 SUSE-SLE-Module-Live-Patching-15-SP4-2025-1424=1 ## Package List: * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_116-default-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_136-default-debuginfo-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_128-default-9-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_31-debugsource-7-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_25-debugsource-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_116-default-debuginfo-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_133-default-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_133-default-debuginfo-7-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_32-debugsource-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_136-default-7-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_29-debugsource-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_128-default-debuginfo-9-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_116-default-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_136-default-debuginfo-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_128-default-9-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_31-debugsource-7-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_25-debugsource-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_116-default-debuginfo-17-150400.2.1 *kernel-livepatch-5_14_21-150400_24_133-default-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_133-default-debuginfo-7-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_32-debugsource-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_136-default-7-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_29-debugsource-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_128-default-debuginfo-9-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-50205.html * https://www.suse.com/security/cve/CVE-2024-56650.html * https://www.suse.com/security/cve/CVE-2024-8805.html * https://bugzilla.suse.com/show_bug.cgi?id=1233294 * https://bugzilla.suse.com/show_bug.cgi?id=1235431 * https://bugzilla.suse.com/show_bug.cgi?id=1240840 . This notification presents an important security patch for the Linux Kernel within Fedora, addressing four significant exploits.. openSUSE Kernel Patch, Linux Kernel Security, SUSE Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 01, 2025 Important OpenSUSE
197

Debian 11 DLA-4072-1 Critical: xorg-server Privilege Escalation Advisory

Jan-Niklas Sohn discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4072-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz March 01, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : xorg-server Version : 2:1.20.11-1+deb11u15 CVE ID : CVE-2025-26594 CVE-2025-26595 CVE-2025-26596 CVE-2025-26597 CVE-2025-26598 CVE-2025-26599 CVE-2025-26600 CVE-2025-26601 Jan-Niklas Sohn discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged. For Debian 11 bullseye, these problems have been fixed in version 2:1.20.11-1+deb11u15. We recommend that you upgrade your xorg-server packages. For the detailed security status of xorg-server please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/xorg-server Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Ubuntu Security Notice USN-1234-1 details vulnerabilities in the kernel which could lead to user impersonation.. Debian Security, Xorg Privilege Escalation, Security Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 28, 2025 Critical Debian LTS
172

Ubuntu 22.04 LTS USN-7288-1 Critical: Linux Kernel Heap Overflow

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7288-1 February 24, 2025 linux, linux-lowlatency vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-lowlatency: Linux low latency kernel Details: Attila Szász discovered that the HFS+ file system implementation in the Linux Kernel contained a heap overflow vulnerability. An attacker could use a specially crafted file system image that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2025-0927) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - x86 architecture; - Block layer subsystem; - ACPI drivers; - GPU drivers; - HID subsystem; - I2C subsystem; - IIO ADC drivers; - IIO subsystem; - InfiniBand drivers; - IOMMU subsystem; - IRQ chip drivers; - Multiple devices driver; - Media drivers; - Network drivers; - STMicroelectronics network drivers; - Parport drivers; - Pin controllers subsystem; - Direct Digital Synthesis drivers; - TCM subsystem; - TTY drivers; - USB Dual Role (OTG-ready) Controller drivers; - USB Serial drivers; - USB Type-C support driver; - USB Type-C Connector System Software Interface driver; - BTRFS file system; - File systems infrastructure; - Network file system (NFS) client; - NILFS2 file system; - NTFS3 file system; - SMB network file system; - User-space API (UAPI); - io_uring subsystem; - BPF subsystem; - Timer substystem drivers; -Tracing infrastructure; - Closures library; - Memory management; - Amateur Radio drivers; - Bluetooth subsystem; - Networking core; - IPv4 networking; - MAC80211 subsystem; - Multipath TCP; - Netfilter; - Network traffic control; - SCTP protocol; - XFRM subsystem; - Key management; - FireWire sound drivers; - HD-audio driver; - QCOM ASoC drivers; - STMicroelectronics SoC drivers; - KVM core; (CVE-2024-50202, CVE-2024-50208, CVE-2024-50265, CVE-2024-41080, CVE-2024-50101, CVE-2024-39497, CVE-2024-50153, CVE-2024-50162, CVE-2024-50150, CVE-2024-50115, CVE-2024-53066, CVE-2024-50279, CVE-2024-50116, CVE-2024-50218, CVE-2024-53104, CVE-2024-50086, CVE-2024-50154, CVE-2024-50244, CVE-2024-50074, CVE-2024-50278, CVE-2024-50262, CVE-2024-50168, CVE-2024-50134, CVE-2024-53063, CVE-2024-50236, CVE-2024-50082, CVE-2024-50234, CVE-2024-50247, CVE-2024-50282, CVE-2024-50267, CVE-2024-40965, CVE-2024-50229, CVE-2024-50110, CVE-2024-35887, CVE-2024-50302, CVE-2024-50036, CVE-2024-50209, CVE-2024-50287, CVE-2024-50245, CVE-2024-50072, CVE-2024-50301, CVE-2024-50201, CVE-2024-53097, CVE-2024-40953, CVE-2024-50085, CVE-2024-50299, CVE-2024-50292, CVE-2024-50269, CVE-2024-50182, CVE-2024-50233, CVE-2024-53088, CVE-2024-50259, CVE-2024-50232, CVE-2024-53055, CVE-2024-50195, CVE-2024-50273, CVE-2024-42291, CVE-2024-50192, CVE-2024-50251, CVE-2024-50193, CVE-2024-50142, CVE-2024-53101, CVE-2024-50205, CVE-2024-26718, CVE-2024-50167, CVE-2024-50010, CVE-2024-50230, CVE-2024-41066, CVE-2024-50194, CVE-2024-50148, CVE-2024-50151, CVE-2024-50127, CVE-2024-50160, CVE-2023-52913, CVE-2024-53052, CVE-2024-50156, CVE-2024-50141, CVE-2024-50103, CVE-2024-50296, CVE-2024-50257, CVE-2024-50199, CVE-2024-50128, CVE-2024-50058, CVE-2024-50099, CVE-2024-50290, CVE-2024-53042, CVE-2024-50295, CVE-2024-50268, CVE-2024-50163, CVE-2024-53058, CVE-2024-50185, CVE-2024-50117, CVE-2024-50237, CVE-2024-50083, CVE-2024-50131, CVE-2024-50196, CVE-2024-42252, CVE-2024-50143,CVE-2024-50171, CVE-2024-50249, CVE-2024-53059, CVE-2024-50198, CVE-2024-53061) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-133-generic 5.15.0-133.144 linux-image-5.15.0-133-generic-64k 5.15.0-133.144 linux-image-5.15.0-133-generic-lpae 5.15.0-133.144 linux-image-5.15.0-133-lowlatency 5.15.0-133.143 linux-image-5.15.0-133-lowlatency-64k 5.15.0-133.143 linux-image-generic 5.15.0.133.132 linux-image-generic-64k 5.15.0.133.132 linux-image-generic-64k-hwe-20.04 5.15.0.133.132 linux-image-generic-hwe-20.04 5.15.0.133.132 linux-image-generic-lpae 5.15.0.133.132 linux-image-generic-lpae-hwe-20.04 5.15.0.133.132 linux-image-lowlatency 5.15.0.133.120 linux-image-lowlatency-64k 5.15.0.133.120 linux-image-lowlatency-64k-hwe-20.04 5.15.0.133.120 linux-image-lowlatency-hwe-20.04 5.15.0.133.120 linux-image-oem-20.04 5.15.0.133.132 linux-image-virtual 5.15.0.133.132 linux-image-virtual-hwe-20.04 5.15.0.133.132 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7288-1 CVE-2023-52913, CVE-2024-26718, CVE-2024-35887, CVE-2024-39497, CVE-2024-40953, CVE-2024-40965, CVE-2024-41066, CVE-2024-41080, CVE-2024-42252, CVE-2024-42291, CVE-2024-50010, CVE-2024-50036, CVE-2024-50058, CVE-2024-50072, CVE-2024-50074, CVE-2024-50082, CVE-2024-50083, CVE-2024-50085,CVE-2024-50086, CVE-2024-50099, CVE-2024-50101, CVE-2024-50103, CVE-2024-50110, CVE-2024-50115, CVE-2024-50116, CVE-2024-50117, CVE-2024-50127, CVE-2024-50128, CVE-2024-50131, CVE-2024-50134, CVE-2024-50141, CVE-2024-50142, CVE-2024-50143, CVE-2024-50148, CVE-2024-50150, CVE-2024-50151, CVE-2024-50153, CVE-2024-50154, CVE-2024-50156, CVE-2024-50160, CVE-2024-50162, CVE-2024-50163, CVE-2024-50167, CVE-2024-50168, CVE-2024-50171, CVE-2024-50182, CVE-2024-50185, CVE-2024-50192, CVE-2024-50193, CVE-2024-50194, CVE-2024-50195, CVE-2024-50196, CVE-2024-50198, CVE-2024-50199, CVE-2024-50201, CVE-2024-50202, CVE-2024-50205, CVE-2024-50208, CVE-2024-50209, CVE-2024-50218, CVE-2024-50229, CVE-2024-50230, CVE-2024-50232, CVE-2024-50233, CVE-2024-50234, CVE-2024-50236, CVE-2024-50237, CVE-2024-50244, CVE-2024-50245, CVE-2024-50247, CVE-2024-50249, CVE-2024-50251, CVE-2024-50257, CVE-2024-50259, CVE-2024-50262, CVE-2024-50265, CVE-2024-50267, CVE-2024-50268, CVE-2024-50269, CVE-2024-50273, CVE-2024-50278, CVE-2024-50279, CVE-2024-50282, CVE-2024-50287, CVE-2024-50290, CVE-2024-50292, CVE-2024-50295, CVE-2024-50296, CVE-2024-50299, CVE-2024-50301, CVE-2024-50302, CVE-2024-53042, CVE-2024-53052, CVE-2024-53055, CVE-2024-53058, CVE-2024-53059, CVE-2024-53061, CVE-2024-53063, CVE-2024-53066, CVE-2024-53088, CVE-2024-53097, CVE-2024-53101, CVE-2024-53104, CVE-2025-0927 Package Information: https://launchpad.net/ubuntu/+source/linux/5.15.0-133.144 https://launchpad.net/ubuntu/+source/linux-lowlatency/5.15.0-133.143 . Numerous enhancements in Linux kernel security for Ubuntu users on February 24, 2025, targeting urgent vulnerabilities.. Ubuntu Kernel Security, Linux Heap Overflow, Ubuntu System Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 24, 2025 Critical Ubuntu
217

Oracle Linux 8 ELSA-2025-1675 critical: bind security patch

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1675 http://linux.oracle.com/errata/ELSA-2025-1675.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: bind-9.11.36-16.el8_10.4.x86_64.rpm bind-chroot-9.11.36-16.el8_10.4.x86_64.rpm bind-devel-9.11.36-16.el8_10.4.i686.rpm bind-devel-9.11.36-16.el8_10.4.x86_64.rpm bind-export-devel-9.11.36-16.el8_10.4.i686.rpm bind-export-devel-9.11.36-16.el8_10.4.x86_64.rpm bind-export-libs-9.11.36-16.el8_10.4.i686.rpm bind-export-libs-9.11.36-16.el8_10.4.x86_64.rpm bind-libs-9.11.36-16.el8_10.4.i686.rpm bind-libs-9.11.36-16.el8_10.4.x86_64.rpm bind-libs-lite-9.11.36-16.el8_10.4.i686.rpm bind-libs-lite-9.11.36-16.el8_10.4.x86_64.rpm bind-license-9.11.36-16.el8_10.4.noarch.rpm bind-lite-devel-9.11.36-16.el8_10.4.i686.rpm bind-lite-devel-9.11.36-16.el8_10.4.x86_64.rpm bind-pkcs11-9.11.36-16.el8_10.4.x86_64.rpm bind-pkcs11-devel-9.11.36-16.el8_10.4.i686.rpm bind-pkcs11-devel-9.11.36-16.el8_10.4.x86_64.rpm bind-pkcs11-libs-9.11.36-16.el8_10.4.i686.rpm bind-pkcs11-libs-9.11.36-16.el8_10.4.x86_64.rpm bind-pkcs11-utils-9.11.36-16.el8_10.4.x86_64.rpm bind-sdb-9.11.36-16.el8_10.4.x86_64.rpm bind-sdb-chroot-9.11.36-16.el8_10.4.x86_64.rpm bind-utils-9.11.36-16.el8_10.4.x86_64.rpm python3-bind-9.11.36-16.el8_10.4.noarch.rpm aarch64: bind-9.11.36-16.el8_10.4.aarch64.rpm bind-chroot-9.11.36-16.el8_10.4.aarch64.rpm bind-devel-9.11.36-16.el8_10.4.aarch64.rpm bind-export-devel-9.11.36-16.el8_10.4.aarch64.rpm bind-export-libs-9.11.36-16.el8_10.4.aarch64.rpm bind-libs-9.11.36-16.el8_10.4.aarch64.rpm bind-libs-lite-9.11.36-16.el8_10.4.aarch64.rpm bind-license-9.11.36-16.el8_10.4.noarch.rpm bind-lite-devel-9.11.36-16.el8_10.4.aarch64.rpm bind-pkcs11-9.11.36-16.el8_10.4.aarch64.rpm bind-pkcs11-devel-9.11.36-16.el8_10.4.aarch64.rpm bind-pkcs11-libs-9.11.36-16.el8_10.4.aarch64.rpm bind-pkcs11-utils-9.11.36-16.el8_10.4.aarch64.rpm bind-sdb-9.11.36-16.el8_10.4.aarch64.rpm bind-sdb-chroot-9.11.36-16.el8_10.4.aarch64.rpm bind-utils-9.11.36-16.el8_10.4.aarch64.rpm python3-bind-9.11.36-16.el8_10.4.noarch.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//bind-9.11.36-16.el8_10.4.src.rpm Related CVEs: CVE-2024-11187 Description ofchanges: [32:9.11.36-16.4] - Change patches applying to use -P parameter [32:9.11.36-16.3] - Limit additional section records CPU processing (CVE-2024-11187) - Correct ANY queries to not have additional data appended _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Advisory ELSA-2025-1675 addresses critical BIND vulnerabilities, detailing patches to mitigate security risks and enhance defenses. Oracle Linux Updates, Bind Security Advisory, ELSA-2025-1675. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 24, 2025 Critical Oracle
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200