Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 16 articles for you...
100

SUSE 16.0 libtpms Moderate Update CVE-2025-49133 CVE-2026-21444

An update that solves two vulnerabilities can now be installed.. # Security update for libtpms Announcement ID: SUSE-SU-2026:21571-1 Release Date: 2026-05-06T18:16:54Z Rating: moderate References: * bsc#1244528 * bsc#1260439 Cross-References: * CVE-2025-49133 * CVE-2026-21444 CVSS scores: * CVE-2025-49133 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2025-49133 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2025-49133 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21444 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-21444 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-21444 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for libtpms fixes the following issues: * CVE-2025-49133: Fixed potential out of bounds (OOB) read vulnerability (bsc#1244528). * CVE-2026-21444: Fixed remote data confidentiality compromise via incorrect Initialization Vector (IV) handling (bsc#1260439). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-714=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-714=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libtpms0-0.10.0-160000.5.1 * libtpms-debugsource-0.10.0-160000.5.1 * libtpms0-debuginfo-0.10.0-160000.5.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libtpms0-0.10.0-160000.5.1 *libtpms-debugsource-0.10.0-160000.5.1 * libtpms0-debuginfo-0.10.0-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49133.html * https://www.suse.com/security/cve/CVE-2026-21444.html * https://bugzilla.suse.com/show_bug.cgi?id=1244528 * https://bugzilla.suse.com/show_bug.cgi?id=1260439 . An SUSE update fixing libtpms vulnerabilities includes instructions for safe installation. Stay secure with the patch!. libtpms update,SUSE security,moderate vulnerabilities,SUSE Linux patch. . LinuxSecurity.com Team

Calendar 2 May 11, 2026 SuSE
197

Debian 10: DLA-3539-1 Urgent: qt4-x11 Memory Handling Vulnerabilities

Several vulnerabilities have been found in qt4-x11, a graphical windowing toolkit. CVE-2021-3481 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3539-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Roberto C. Sánchez August 22, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : qt4-x11 Version : 4:4.8.7+dfsg-18+deb10u2 CVE ID : CVE-2021-3481 CVE-2021-45930 CVE-2023-32573 CVE-2023-32763 CVE-2023-34410 CVE-2023-37369 CVE-2023-38197 Several vulnerabilities have been found in qt4-x11, a graphical windowing toolkit. CVE-2021-3481 While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an unauthorized memory access. The highest threat from this vulnerability is to data confidentiality and the application availability. CVE-2021-45930 An out-of-bounds write in QtPrivate::QCommonArrayOps ::growAppend (called from QPainterPath::addPath and QPathClipper::intersect). CVE-2023-32573 Uninitialized variable usage in m_unitsPerEm. CVE-2023-32763 An application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length. CVE-2023-34410 Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate. CVE-2023-37369 There can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length. CVE-2023-38197 There are infinite loops in recursive entity expansion. For Debian 10 buster, these problems have been fixed in version 4:4.8.7+dfsg-18+deb10u2. We recommend that you upgrade your qt4-x11 packages. For the detailed securitystatus of qt4-x11 please refer to its security tracker page at: Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Notice DLA-3540-1 highlights multiple vulnerabilities in libjpeg-turbo, urging users to upgrade for enhanced security.. qt4-x11 security, memory access issue, application stability, Debian LTS, security update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 22, 2023 Critical Debian LTS
197

Debian 10 DLA-3455-1 Critical: golang-go.crypto Message Forgery

Several security vulnerabilities have been discovered in golang-go.crypto, the supplementary Go cryptography libraries. CVE-2019-11840 . -------------------------------------------------------------------------Debian LTS Advisory DLA-3455-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany June 16, 2023 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : golang-go.crypto Version : 1:0.0~git20181203.505ab14-1+deb10u1 CVE ID : CVE-2019-11840 CVE-2019-11841 CVE-2020-9283 Debian Bug : 952462 Several security vulnerabilities have been discovered in golang-go.crypto, the supplementary Go cryptography libraries. CVE-2019-11840 An issue was discovered in supplementary Go cryptography libraries, aka golang-googlecode-go-crypto. If more than 256 GiB of keystream is generated, or if the counter otherwise grows greater than 32 bits, the amd64 implementation will first generate incorrect output, and then cycle back to previously generated keystream. Repeated keystream bytes can lead to loss of confidentiality in encryption applications, or to predictability in CSPRNG applications. CVE-2019-11841 A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries. The "Hash" Armor Header specifies the message digest algorithm(s) used for the signature. Since the library skips Armor Header parsing in general, an attacker can not only embed arbitrary Armor Headers, but also prepend arbitrary text to cleartext messages without invalidating the signatures. CVE-2020-9283 golang.org/x/crypto allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client. Thefollowing Go packages have been rebuilt in order to fix the aforementioned issues. rclone: 1.45-3+deb10u1 obfs4proxy: 0.0.7-4+deb10u1 gobuster: 2.0.1-1+deb10u1 restic: 0.9.4+ds-2+deb10u1 gopass: 1.2.0-2+deb10u1 aptly: 1.3.0+ds1-2.2~deb10u2: dnscrypt-proxy: 2.0.19+ds1-2+deb10u1 g10k: 0.5.7-1+deb10u1 hub: 2.7.0~ds1-1+deb10u1 acmetool: 0.0.62-3+deb10u1 syncthing: 1.0.0~ds1-1+deb10u1 packer: 1.3.4+dfsg-4+deb10u1 etcd: 3.2.26+dfsg-3+deb10u1 notary: 0.6.1~ds1-3+deb10u1 For Debian 10 buster, these problems have been fixed in version 1:0.0~git20181203.505ab14-1+deb10u1. We recommend that you upgrade your golang-go.crypto packages. For the detailed security status of golang-go.crypto please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/golang-go.crypto Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The recent update for golang-go.crypto addresses a variety of critical vulnerabilities including risks associated with message integrity and safeguarding sensitive information.. Debian LTS,golang-go.crypto,security update,crypto libraries,message forgery. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 16, 2023 Critical Debian LTS
203

Mageia: 2022-0345 Moderate: Tcpreplay Memory Leak and Overflow

tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c. (CVE-2022-27939) tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c. (CVE-2022-27940) . MGASA-2022-0345 - Updated tcpreplay packages fix security vulnerability Publication date: 26 Sep 2022 URL: https://advisories.mageia.org/MGASA-2022-0345.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-27939, CVE-2022-27940, CVE-2022-27941, CVE-2022-27942, CVE-2022-28487, CVE-2022-37047, CVE-2022-37048, CVE-2022-37049 tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c. (CVE-2022-27939) tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c. (CVE-2022-27940) tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c. (CVE-2022-27941) tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c. (CVE-2022-27942) Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() function. The highest threat from this vulnerability is to data confidentiality. (CVE-2022-28487) The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713. (CVE-2022-37047) The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at common/get.c:344. (CVE-2022-37048) The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. (CVE-2022-37049) References: - https://bugs.mageia.org/show_bug.cgi?id=30822 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/5B75AFRJUGOYHCFG2ZV2JKSUPA6MSCT5/ - https://www.cve.org/CVERecord?id=CVE-2022-27939 - https://www.cve.org/CVERecord?id=CVE-2022-27940 - https://www.cve.org/CVERecord?id=CVE-2022-27941 -https://www.cve.org/CVERecord?id=CVE-2022-27942 - https://www.cve.org/CVERecord?id=CVE-2022-28487 - https://www.cve.org/CVERecord?id=CVE-2022-37047 - https://www.cve.org/CVERecord?id=CVE-2022-37048 - https://www.cve.org/CVERecord?id=CVE-2022-37049 SRPMS: - 8/core/tcpreplay-4.4.2-1.mga8 . The recent tcpreplay patch addresses crucial vulnerabilities in Ubuntu, bolstering data security.. tcpreplay Update, Buffer Overread, Security Advisory, Mageia, Memory Leak. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 26, 2022 Important Mageia
197

Debian: DLA-2895-1 Critical: Multiple Out-Of-Bounds Errors in qt4-x11

Multiple out-of-bounds error were discovered in qt4-x11. The highest threat from CVE-2021-3481 (at least) is to data confidentiality the application availability. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2895-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta January 24, 2022 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : qt4-x11 Version : 4:4.8.7+dfsg-11+deb9u3 CVE ID : CVE-2021-3481 CVE-2021-45930 Debian Bug : 986798 1002991 Multiple out-of-bounds error were discovered in qt4-x11. The highest threat from CVE-2021-3481 (at least) is to data confidentiality the application availability. For Debian 9 stretch, these problems have been fixed in version 4:4.8.7+dfsg-11+deb9u3. We recommend that you upgrade your qt4-x11 packages. For the detailed security status of qt4-x11 please refer to its security tracker page at: Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2900-1 resolves memory corruption vulnerabilities in gcc-11, bolstering system integrity.. Debian LTS, qt4-x11, out-of-bounds errors, data confidentiality. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 24, 2022 Critical Debian LTS
197

Debian 9: DLA-2885-1 Critical Qtsvg Out-Of-Bounds Threat Repair

Multiple out-of-bounds error were discovered in qtsvg-opensource-src. The highest threat from CVE-2021-3481 (at least) is to data confidentiality the application availability. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2885-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta January 17, 2022 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : qtsvg-opensource-src Version : 5.7.1~20161021-2.1+deb9u1 CVE ID : CVE-2021-3481 CVE-2021-45930 Debian Bug : 986798 1002991 Multiple out-of-bounds error were discovered in qtsvg-opensource-src. The highest threat from CVE-2021-3481 (at least) is to data confidentiality the application availability. For Debian 9 stretch, these problems have been fixed in version 5.7.1~20161021-2.1+deb9u1. We recommend that you upgrade your qtsvg-opensource-src packages. For the detailed security status of qtsvg-opensource-src please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/qtsvg-opensource-src Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Explore vulnerabilities and solutions concerning qtsvg-opensource-src in Debian LTS Advisory DLA-2885-1. Find out more today!. Debian LTS Advisory, qtsvg, out-of-bounds errors, security updates, data confidentiality. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 23, 2022 Critical Debian LTS
100

SUSE MicroOS 5.1: 2022:0144-1 Moderate: Cryptsetup Confidentiality Risk

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for cryptsetup ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0144-1 Rating: moderate References: #1194469 Cross-References: CVE-2021-4122 CVSS scores: CVE-2021-4122 (SUSE): 5.9 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N Affected Products: SUSE MicroOS 5.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for cryptsetup fixes the following issues: - CVE-2021-4122: Fixed possible attacks against data confidentiality through LUKS2 online reencryption extension crash recovery (bsc#1194469). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE MicroOS 5.1: zypper in -t patch SUSE-SUSE-MicroOS-5.1-2022-144=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2022-144=1 Package List: - SUSE MicroOS 5.1 (aarch64 s390x x86_64): cryptsetup-2.3.7-150300.3.5.1 cryptsetup-debuginfo-2.3.7-150300.3.5.1 cryptsetup-debugsource-2.3.7-150300.3.5.1 libcryptsetup12-2.3.7-150300.3.5.1 libcryptsetup12-debuginfo-2.3.7-150300.3.5.1 libcryptsetup12-hmac-2.3.7-150300.3.5.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): cryptsetup-2.3.7-150300.3.5.1 cryptsetup-debuginfo-2.3.7-150300.3.5.1 cryptsetup-debugsource-2.3.7-150300.3.5.1 libcryptsetup-devel-2.3.7-150300.3.5.1 libcryptsetup12-2.3.7-150300.3.5.1 libcryptsetup12-debuginfo-2.3.7-150300.3.5.1 libcryptsetup12-hmac-2.3.7-150300.3.5.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (noarch): cryptsetup-lang-2.3.7-150300.3.5.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (x86_64): libcryptsetup12-32bit-2.3.7-150300.3.5.1 libcryptsetup12-32bit-debuginfo-2.3.7-150300.3.5.1 libcryptsetup12-hmac-32bit-2.3.7-150300.3.5.1 References: https://www.suse.com/security/cve/CVE-2021-4122.html https://bugzilla.suse.com/1194469 . Recent cryptsetup update addresses possible threats to data confidentiality. Ensure your systems are fortified by following the latest patch guidelines.. SUSE MicroOS, cryptsetup, Security Update, Linux Patch. . LinuxSecurity.com Team

Calendar 2 Jan 20, 2022 SuSE
202

openSUSE: 2022:0144-1 Moderate: Cryptsetup Data Confidentiality Threat

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for cryptsetup ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:0144-1 Rating: moderate References: #1194469 Cross-References: CVE-2021-4122 CVSS scores: CVE-2021-4122 (SUSE): 5.9 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for cryptsetup fixes the following issues: - CVE-2021-4122: Fixed possible attacks against data confidentiality through LUKS2 online reencryption extension crash recovery (bsc#1194469). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-144=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): cryptsetup-2.3.7-150300.3.5.1 cryptsetup-debuginfo-2.3.7-150300.3.5.1 cryptsetup-debugsource-2.3.7-150300.3.5.1 libcryptsetup-devel-2.3.7-150300.3.5.1 libcryptsetup12-2.3.7-150300.3.5.1 libcryptsetup12-debuginfo-2.3.7-150300.3.5.1 libcryptsetup12-hmac-2.3.7-150300.3.5.1 - openSUSE Leap 15.3 (noarch): cryptsetup-lang-2.3.7-150300.3.5.1 - openSUSE Leap 15.3 (x86_64): libcryptsetup12-32bit-2.3.7-150300.3.5.1 libcryptsetup12-32bit-debuginfo-2.3.7-150300.3.5.1 libcryptsetup12-hmac-32bit-2.3.7-150300.3.5.1 References: https://www.suse.com/security/cve/CVE-2021-4122.html https://bugzilla.suse.com/1194469 . This release addresses a significant vulnerability in Fedora, remedying an oversight in libvirt thatjeopardizes system integrity.. openSUSE Fix,Cryptsetup Update,Data Security Issue. . LinuxSecurity.com Team

Calendar 2 Jan 20, 2022 OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here