Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
A security issue was fixed in MariaDB.. ========================================================================== Ubuntu Security Notice USN-7376-1 March 27, 2025 mariadb vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 Summary: A security issue was fixed in MariaDB. Software Description: - mariadb: MariaDB database Details: A security issue was discovered in MariaDB and this update includes a new upstream MariaDB version to fix the issue. In addition to security fixes, the updated packages contain bug and regression fixes, new features, and possibly incompatible changes. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 mariadb-server 1:11.4.5-0ubuntu0.24.10.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart MariaDB to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7376-1 CVE-2025-21490 Package Information: https://launchpad.net/ubuntu/+source/mariadb/1:11.4.5-0ubuntu0.24.10.1 . Ubuntu's latest advisory updates resolve critical MariaDB security issue. Essential for risk mitigation and system integrity.. security, mariadb, =============================================================. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in MariaDB.. ========================================================================== Ubuntu Security Notice USN-6600-1 January 25, 2024 mariadb, mariadb-10.3, mariadb-10.6 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in MariaDB. Software Description: - mariadb: MariaDB database - mariadb-10.6: MariaDB database - mariadb-10.3: MariaDB database Details: Several security issues were discovered in MariaDB and this update includes new upstream MariaDB versions to fix these issues. MariaDB has been updated to 10.3.39 in Ubuntu 20.04 LTS, 10.6.16 in Ubuntu 22.04 LTS and 10.11.6 in Ubuntu 23.10. CVE-2022-47015 only affected the MariaDB packages in Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: mariadb-server 1:10.11.6-0ubuntu0.23.10.2 Ubuntu 22.04 LTS: mariadb-server 1:10.6.16-0ubuntu0.22.04.1 Ubuntu 20.04 LTS: mariadb-server 1:10.3.39-0ubuntu0.20.04.2 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6600-1 CVE-2022-47015, CVE-2023-22084 Package Information: https://launchpad.net/ubuntu/+source/mariadb/1:10.11.6-0ubuntu0.23.10.2 https://launchpad.net/ubuntu/+source/mariadb-10.6/1:10.6.16-0ubuntu0.22.04.1 https://launchpad.net/ubuntu/+source/mariadb-10.3/1:10.3.39-0ubuntu0.20.04.2 .Critical updates for PostgreSQL address various security flaws in Ubuntu machines. Protect your database immediately.. MariaDB Security, Ubuntu Database, Security Update, Critical Fix. . Severity: Critical. LinuxSecurity.com Team
This is a routine update of the distro-info-data database for Debian LTS users. It includes Ubuntu 24.10, and makes some minor updates to older EoL . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3639-1
Moderate: postgresql:13 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:4527", "synopsis": "Moderate: postgresql:13 security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for module.pgaudit, postgresql, pgaudit, module.pg_repack, module.postgres-decoderbufs, pg_repack, module.postgresql, postgres-decoderbufs.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "PostgreSQL is an advanced object-relational database management system (DBMS).\n\nSecurity Fix(es):\n\n* postgresql: schema_element defeats protective search_path changes (CVE-2023-2454)\n\n* postgresql: row security policies disregard user ID changes after inlining. (CVE-2023-2455)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2207568", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2207568", "description": ""}, {"ticket": "2207569", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2207569", "description": ""}], "cves": [{"name": "CVE-2023-2454", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-2454", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.2", "cwe": "CWE-20"}, {"name": "CVE-2023-2455", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-2455", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N", "cvss3BaseScore": "4.2", "cwe": "CWE-20"}], "references": [], "publishedAt": "2023-10-06T23:10:12.373291Z", "rpms": {"Rocky Linux 8": {"nvras": ["pgaudit-0:1.5.0-1.module+el8.5.0+684+c3892ef9.aarch64.rpm","pgaudit-0:1.5.0-1.module+el8.5.0+684+c3892ef9.src.rpm", "pgaudit-debuginfo-0:1.5.0-1.module+el8.5.0+684+c3892ef9.aarch64.rpm", "pgaudit-debugsource-0:1.5.0-1.module+el8.5.0+684+c3892ef9.aarch64.rpm", "pg_repack-0:1.4.6-3.module+el8.5.0+684+c3892ef9.aarch64.rpm", "pg_repack-0:1.4.6-3.module+el8.5.0+684+c3892ef9.src.rpm", "pg_repack-debuginfo-0:1.4.6-3.module+el8.5.0+684+c3892ef9.aarch64.rpm", "pg_repack-debugsource-0:1.4.6-3.module+el8.5.0+684+c3892ef9.aarch64.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.5.0+684+c3892ef9.aarch64.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.5.0+684+c3892ef9.src.rpm", "postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.5.0+684+c3892ef9.aarch64.rpm", "postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.5.0+684+c3892ef9.aarch64.rpm", "postgresql-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-0:13.11-1.module+el8.8.0+1443+0e26d3b2.src.rpm", "postgresql-contrib-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-contrib-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-debugsource-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-docs-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-docs-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-plperl-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-plperl-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-plpython3-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-plpython3-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-pltcl-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-pltcl-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-server-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-server-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm","postgresql-server-devel-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-server-devel-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-static-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-test-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-test-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-test-rpm-macros-0:13.11-1.module+el8.8.0+1443+0e26d3b2.noarch.rpm", "postgresql-upgrade-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-upgrade-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-upgrade-devel-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "postgresql-upgrade-devel-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.aarch64.rpm", "pgaudit-0:1.5.0-1.module+el8.5.0+684+c3892ef9.x86_64.rpm", "pgaudit-debuginfo-0:1.5.0-1.module+el8.5.0+684+c3892ef9.x86_64.rpm", "pgaudit-debugsource-0:1.5.0-1.module+el8.5.0+684+c3892ef9.x86_64.rpm", "pg_repack-0:1.4.6-3.module+el8.5.0+684+c3892ef9.x86_64.rpm", "pg_repack-debuginfo-0:1.4.6-3.module+el8.5.0+684+c3892ef9.x86_64.rpm", "pg_repack-debugsource-0:1.4.6-3.module+el8.5.0+684+c3892ef9.x86_64.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.5.0+684+c3892ef9.x86_64.rpm", "postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.5.0+684+c3892ef9.x86_64.rpm", "postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.5.0+684+c3892ef9.x86_64.rpm", "postgresql-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-contrib-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-contrib-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-debugsource-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-docs-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-docs-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-plperl-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm","postgresql-plperl-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-plpython3-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-plpython3-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-pltcl-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-pltcl-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-server-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-server-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-server-devel-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-server-devel-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-static-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-test-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-test-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-upgrade-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-upgrade-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-upgrade-devel-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm", "postgresql-upgrade-devel-debuginfo-0:13.11-1.module+el8.8.0+1443+0e26d3b2.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Crucial PostgreSQL 13 upgrade for Rocky Linux resolves various concerns, boosting database protection and reliability.. PostgreSQL Security, Rocky Linux Update, Database Management, Cybersecurity Patching. . LinuxSecurity.com Team
**MySQL 8.0.33** Changelog: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-33.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-af03a123b5 2023-05-10 01:40:09.608448 --------------------------------------------------------------------------------Name : community-mysql Product : Fedora 37 Version : 8.0.33 Release : 2.fc37 URL : http://www.mysql.com Summary : MySQL client programs and shared libraries Description : MySQL is a multi-user, multi-threaded SQL database server. MySQL is a client/server implementation consisting of a server daemon (mysqld) and many different client programs and libraries. The base package contains the standard MySQL client programs and generic MySQL files. --------------------------------------------------------------------------------Update Information: **MySQL 8.0.33** Changelog: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-33.html --------------------------------------------------------------------------------ChangeLog: * Wed Apr 12 2023 Lars Tangvald - 8.0.33-1 - Update to MySQL 8.0.33 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-af03a123b5' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This is a routine update of the distro-info-data database for Debian LTS users. It includes the expected release date for Debian 12, adds Debian 14, . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3411-1
Several bugs were discovered in PostgreSQL, a relational database server system. This new LTS minor version update fixes over 25 bugs that were reported in the last several months. The complete and detailed list of issues could be found at: https://https://www.postgresql.org/docs/release/ . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-3189-1
This is a routine update of the distro-info-data database for Debian LTS users. It includes a correction to some historical data, and adds Ubuntu 23.04, Lunar Lobster. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3171-1
Get the latest Linux and open source security news straight to your inbox.