Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 82 articles for you...
203

Mageia 10 9 perl-String-Util Critical Regex DoS CVE-2026-14895

Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0272.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-14895 Description: The updated package fixes a security vulnerability: String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. (CVE-2026-14895) References: - https://bugs.mageia.org/show_bug.cgi?id=35858 - https://www.openwall.com/lists/oss-security/2026/07/07/18 - https://www.cve.org/CVERecord?id=CVE-2026-14895 SRPMS: - 10/core/perl-String-Util-1.350.0-2.1.mga10 - 9/core/perl-String-Util-1.340.0-1.1.mga9 . This update addresses a critical denial of service flaw in Perl String::Util affecting Mageia 10 and 9. Discover more.. Mageia, Perl, Denial of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 19, 2026 Critical Mageia
89

Fedora 44 Nextcloud Critical Denial Service Issues Advisory 2026-ee50c21f92

33.0.6 Release. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-ee50c21f92 2026-07-05 01:07:02.694223+00:00 -------------------------------------------------------------------------------- Name : nextcloud Product : Fedora 44 Version : 33.0.6 Release : 1.fc44 URL : http://nextcloud.com Summary : Private file sync and share server Description : NextCloud gives you universal access to your files through a web interface or WebDAV. It also provides a platform to easily view & sync your contacts, calendars and bookmarks across all your devices and enables basic editing right on the web. NextCloud is extendable via a simple but powerful API for applications and plugins. -------------------------------------------------------------------------------- Update Information: 33.0.6 Release -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 26 2026 Andrew Bauer - 33.0.6-1 - 33.0.6 release * Tue Jun 9 2026 Brian J. Murrell - 33.0.5-2 - Dynamically determine which .map file to update the occ upgrade command in -------------------------------------------------------------------------------- References: [ 1 ] Bug #2486357 - nextcloud-34.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2486357 [ 2 ] Bug #2486491 - CVE-2026-41150 nextcloud: Mermaid: Denial of Service via specially crafted gantt charts [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486491 [ 3 ] Bug #2486496 - CVE-2026-41150 nextcloud: Mermaid: Denial of Service via specially crafted gantt charts [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486496 [ 4 ] Bug #2487344 - .map file update is fragile https://bugzilla.redhat.com/show_bug.cgi?id=2487344 [ 5 ] Bug #2487477 - CVE-2026-8723 nextcloud: qs: Denial of Service due to improper handling of null/undefined array elements [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2487477 [ 6 ] Bug #2487498 - CVE-2026-8723 nextcloud: qs: Denial of Service due to improper handling of null/undefined array elements [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2487498 [ 7 ] Bug #2488103 - CVE-2026-44495 nextcloud: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488103 [ 8 ] Bug #2488116 - CVE-2026-44489 nextcloud: Axios: Information disclosure via Prototype Pollution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488116 [ 9 ] Bug #2488118 - CVE-2026-44495 nextcloud: Axios: Information disclosure due to prototype pollution vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488118 [ 10 ] Bug #2488119 - CVE-2026-44489 nextcloud: Axios: Information disclosure via Prototype Pollution [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488119 [ 11 ] Bug #2488129 - CVE-2026-44490 nextcloud: Axios: Information disclosure and denial of service due to prototype pollution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488129 [ 12 ] Bug #2488137 - CVE-2026-44490 nextcloud: Axios: Information disclosure and denial of service due to prototype pollution [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488137 [ 13 ] Bug #2488146 - CVE-2026-44488 nextcloud: Axios: Denial of Service due to unenforced request and response size limits [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488146 [ 14 ] Bug #2488154 - CVE-2026-44488 nextcloud: Axios: Denial of Service due to unenforced request and response size limits [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488154 [ 15 ] Bug #2488159 - CVE-2026-44487 nextcloud: Axios: Information disclosure of proxy credentials via redirect flows [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488159 [ 16 ] Bug #2488171 - CVE-2026-44487nextcloud: Axios: Information disclosure of proxy credentials via redirect flows [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488171 [ 17 ] Bug #2488186 - CVE-2026-44494 nextcloud: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488186 [ 18 ] Bug #2488188 - CVE-2026-44494 nextcloud: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488188 [ 19 ] Bug #2488192 - CVE-2026-44486 nextcloud: Axios: Information disclosure of proxy credentials via HTTP redirects [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488192 [ 20 ] Bug #2488196 - CVE-2026-44486 nextcloud: Axios: Information disclosure of proxy credentials via HTTP redirects [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488196 [ 21 ] Bug #2488202 - CVE-2026-44496 nextcloud: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488202 [ 22 ] Bug #2488207 - CVE-2026-44496 nextcloud: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488207 [ 23 ] Bug #2488219 - CVE-2026-44492 nextcloud: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488219 [ 24 ] Bug #2488224 - CVE-2026-44492 nextcloud: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488224 [ 25 ] Bug #2488275 - CVE-2026-48998 nextcloud: guzzlehttp/psr7: Information disclosure via improper Host header validation [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488275 [ 26 ] Bug #2488278 - CVE-2026-48998 nextcloud: guzzlehttp/psr7: Information disclosure via improper Host headervalidation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2488278 [ 27 ] Bug #2489107 - CVE-2026-49214 nextcloud: `guzzlehttp/psr7`: Request Smuggling and Cache Poisoning via HTTP Header Injection [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489107 [ 28 ] Bug #2489108 - CVE-2026-49214 nextcloud: `guzzlehttp/psr7`: Request Smuggling and Cache Poisoning via HTTP Header Injection [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489108 [ 29 ] Bug #2489147 - CVE-2026-41148 nextcloud: Mermaid: CSS injection vulnerability allows page defacement and information disclosure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489147 [ 30 ] Bug #2489154 - CVE-2026-41148 nextcloud: Mermaid: CSS injection vulnerability allows page defacement and information disclosure [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489154 [ 31 ] Bug #2489164 - CVE-2026-54133 nextcloud: jmespath.php has CompilerRuntime code injection via unescaped function names [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489164 [ 32 ] Bug #2489165 - CVE-2026-54133 nextcloud: jmespath.php has CompilerRuntime code injection via unescaped function names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489165 [ 33 ] Bug #2489259 - CVE-2026-41149 nextcloud: Mermaid: HTML injection via classDef directive in state diagrams [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489259 [ 34 ] Bug #2489262 - CVE-2026-41149 nextcloud: Mermaid: HTML injection via classDef directive in state diagrams [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489262 [ 35 ] Bug #2491652 - CVE-2026-42040 nextcloud: Axios: Incorrect null byte handling can lead to data integrity issues [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491652 [ 36 ] Bug #2491660 - CVE-2026-42040 nextcloud: Axios: Incorrect null byte handling can lead to data integrity issues [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491660 [ 37 ] Bug #2491781 - CVE-2026-55766 nextcloud: guzzlehttp/psr7: Information disclosure due to improper handling of CR/LF characters in HTTP start-line fields [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491781 [ 38 ] Bug #2491785 - CVE-2026-55766 nextcloud: guzzlehttp/psr7: Information disclosure due to improper handling of CR/LF characters in HTTP start-line fields [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491785 [ 39 ] Bug #2491789 - CVE-2026-55568 nextcloud: Guzzle: Information disclosure via cleartext proxy communication [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491789 [ 40 ] Bug #2491790 - CVE-2026-55767 nextcloud: Guzzle: Cookie injection and session fixation due to improper domain validation [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491790 [ 41 ] Bug #2491791 - CVE-2026-55568 nextcloud: Guzzle: Information disclosure via cleartext proxy communication [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491791 [ 42 ] Bug #2491792 - CVE-2026-55767 nextcloud: Guzzle: Cookie injection and session fixation due to improper domain validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491792 [ 43 ] Bug #2492891 - CVE-2026-42264 nextcloud: Axios: Prototype pollution allows information disclosure and request manipulation [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2492891 [ 44 ] Bug #2492905 - CVE-2026-42264 nextcloud: Axios: Prototype pollution allows information disclosure and request manipulation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2492905 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ee50c21f92' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Nextcloud 33.0.6 on Fedora 44 addresses critical Denial of Service vulnerabilities requiring immediate attention for users.. Nextcloud Denial Service Fedora Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 04, 2026 Critical Fedora
172

Ubuntu 26.04 Google Guest Agent Important Denial Service Issues USN-8447-3

Several security issues were fixed in Google Guest Agent.. ========================================================================== Ubuntu Security Notice USN-8447-3 June 22, 2026 google-guest-agent vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Google Guest Agent. Software Description: - google-guest-agent: Google Compute Engine Guest Agent Details: USN-8447-1 fixed vulnerabilities in Go Cryptography. This update provides the corresponding updates for Go Cryptography code embedded in Google Guest Agent. Original advisory details: It was discovered that Go Cryptography did not properly handle SSH global request responses. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-39830) It was discovered that Go Cryptography did not properly verify user presence when using FIDO/U2F security keys. An attacker could possibly use this issue to bypass user presence verification for hardware security keys. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-39831) It was discovered that Go Cryptography did not properly serialize SSH agent key constraint extensions. An attacker could possibly use this issue to bypass intended key usage restrictions. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-39832) It was discovered that Go Cryptography did not properly enforce the confirm-before-use constraint in the SSH agent keyring. An attacker could possibly use this issue to use SSH keys without the required user confirmation. (CVE-2026-39833) It was discovered that Go Cryptography had an integer overflow when handling large SSH channel writes. A remoteattacker could possibly use this issue to cause a denial of service. (CVE-2026-39834) It was discovered that Go Cryptography did not properly check certificate authority key revocation. An attacker could possibly use this issue to bypass certificate authority revocation checks. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42508) It was discovered that Go Cryptography did not properly enforce the source- address critical option for all SSH server callback types. An attacker could possibly use this issue to bypass source address authorization restrictions. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-46595) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS google-guest-agent 20250506.01-0ubuntu2.1 Ubuntu 25.10 google-guest-agent 20250506.01-0ubuntu1.2 Ubuntu 24.04 LTS google-guest-agent 20250116.00-0ubuntu1~24.04.4 Ubuntu 22.04 LTS google-guest-agent 20250116.00-0ubuntu1~22.04.3 Ubuntu 20.04 LTS google-guest-agent 20250116.00-0ubuntu1~20.04.0+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS google-guest-agent 20241011.01-0ubuntu1~18.04.0+esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS google-guest-agent 20240716.00-0ubuntu1~16.04.0+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8447-3 https://ubuntu.com/security/notices/USN-8447-2 https://ubuntu.com/security/notices/USN-8447-1 CVE-2026-39830, CVE-2026-39831, CVE-2026-39834, CVE-2026-46595 Package Information: https://launchpad.net/ubuntu/+source/google-guest-agent/20250506.01-0ubuntu2.1 https://launchpad.net/ubuntu/+source/google-guest-agent/20250506.01-0ubuntu1.2 https://launchpad.net/ubuntu/+source/google-guest-agent/20250116.00-0ubuntu1~24.04.4 https://launchpad.net/ubuntu/+source/google-guest-agent/20250116.00-0ubuntu1~22.04.3 . Explore the critical updates for Google Guest Agent on Ubuntu addressing several security issues and their impacts.. Google Guest Agent vulnerabilities, Ubuntu security updates, SSH issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 22, 2026 Important Ubuntu
172

Ubuntu 25.10 24.04 LTS Kea DHCP Important Denial of Service USN-8403-1

Kea DHCP could be made to crash if it received specially crafted messages.. ========================================================================== Ubuntu Security Notice USN-8403-1 June 08, 2026 isc-kea vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS Summary: Kea DHCP could be made to crash if it received specially crafted messages. Software Description: - isc-kea: Standards-based DHCP server Details: Ali Norouzi discovered that Kea DHCP did not properly handle maliciously crafted messages over configured API sockets and HA listeners. A remote attacker could possibly use this issue to cause Kea DHCP to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 kea-admin 2.6.3-2ubuntu0.1 kea-common 2.6.3-2ubuntu0.1 kea-dhcp-ddns-server 2.6.3-2ubuntu0.1 kea-dhcp4-server 2.6.3-2ubuntu0.1 kea-dhcp6-server 2.6.3-2ubuntu0.1 Ubuntu 24.04 LTS kea-admin 2.4.1-3ubuntu0.2 kea-common 2.4.1-3ubuntu0.2 kea-dhcp-ddns-server 2.4.1-3ubuntu0.2 kea-dhcp4-server 2.4.1-3ubuntu0.2 kea-dhcp6-server 2.4.1-3ubuntu0.2 After a standard system update you may need to restart Kea DHCP server instances to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8403-1 CVE-2026-3608 Package Information: https://launchpad.net/ubuntu/+source/isc-kea/2.6.3-2ubuntu0.1 https://launchpad.net/ubuntu/+source/isc-kea/2.4.1-3ubuntu0.2 . Kea DHCP has a significant issue where crafted messages can cause crashes, impacting service availability. Update recommended.. Kea DHCP Denial of Service, Ubuntu Security Notice, isc-kea vulnerability, Update Required, SoftwareIssue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 08, 2026 Important Ubuntu
99

Slackware 15.0 httpd Important DoS Fix for CVE-2026-49975 2026-154-01

New httpd packages are available for Slackware 15.0 and -current to fix a security issue.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] httpd (SSA:2026-154-01) New httpd packages are available for Slackware 15.0 and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/httpd-2.4.67-i586-2_slack15.0.txz: Rebuilt. This update fixes "HTTP/2 Bomb", a resource exhaustion denial-of-service attack against HTTP/2. For more information, see: https://seclists.org/oss-sec/2026/q2/790 https://www.cve.org/CVERecord?id=CVE-2026-49975 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://slackware.com for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/httpd-2.4.67-i586-2_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/httpd-2.4.67-x86_64-2_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/httpd-2.4.67-i686-2.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/httpd-2.4.67-x86_64-2.txz MD5 signatures: +-------------+ Slackware 15.0 package: fe1db72c286841174ff38534c6e6918d httpd-2.4.67-i586-2_slack15.0.txz Slackware x86_64 15.0 package: b14dd1a6d97a842eee7a5ecd7b8f0855 httpd-2.4.67-x86_64-2_slack15.0.txz Slackware -current package: eee9bd40cb210f87590334e724d2bde0 n/httpd-2.4.67-i686-2.txz Slackware x86_64 -current package: 594fcc2edd5ca2f41a3aade3b7d467bb n/httpd-2.4.67-x86_64-2.txz Installationinstructions: +------------------------+ Upgrade the package as root: # upgradepkg httpd-2.4.67-i586-2_slack15.0.txz Then, restart Apache httpd: # /etc/rc.d/rc.httpd stop # /etc/rc.d/rc.httpd start +-----+ . New httpd packages address security issues in Slackware 15.0 and -current ensuring system stability. Updates recommended.. HTTPD Security Update, Slackware Linux, Resource Exhaustion, Denial of Service, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 03, 2026 Important Slackware
219

Gemini OS 10 RLSA-2026-14568 High Vulnerability DoS CVE-2026-31235

Important: fence-agents security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:13917", "synopsis": "Important: fence-agents security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for fence-agents.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. \n\nSecurity Fix(es):\n\n* pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2448553", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448553", "description": ""}], "cves": [{"name": "CVE-2026-30922", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-30922", "cvss3ScoringVector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-835"}], "references": [], "publishedAt": "2026-05-07T12:03:39.445016Z", "rpms": {"Rocky Linux 9": {"nvras": ["fence-agents-0:4.10.0-98.el9_7.13.src.rpm", "fence-agents-aliyun-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-all-0:4.10.0-98.el9_7.13.aarch64.rpm", "fence-agents-all-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-all-0:4.10.0-98.el9_7.13.s390x.rpm", "fence-agents-all-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-amt-ws-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-apc-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-apc-snmp-0:4.10.0-98.el9_7.13.noarch.rpm","fence-agents-aws-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-azure-arm-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-bladecenter-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-brocade-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-cisco-mds-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-cisco-ucs-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-common-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-compute-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-compute-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-debuginfo-0:4.10.0-98.el9_7.13.aarch64.rpm", "fence-agents-debuginfo-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-debuginfo-0:4.10.0-98.el9_7.13.s390x.rpm", "fence-agents-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-debugsource-0:4.10.0-98.el9_7.13.aarch64.rpm", "fence-agents-debugsource-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-debugsource-0:4.10.0-98.el9_7.13.s390x.rpm", "fence-agents-debugsource-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-drac5-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-eaton-snmp-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-emerson-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-eps-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-gce-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-heuristics-ping-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-hpblade-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ibmblade-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ibm-powervs-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ibm-vpc-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ifmib-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ilo2-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ilo-moonshot-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ilo-mp-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ilo-ssh-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-intelmodular-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ipdu-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-ipmilan-0:4.10.0-98.el9_7.13.noarch.rpm","fence-agents-kdump-0:4.10.0-98.el9_7.13.aarch64.rpm", "fence-agents-kdump-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-kdump-0:4.10.0-98.el9_7.13.s390x.rpm", "fence-agents-kdump-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-kdump-debuginfo-0:4.10.0-98.el9_7.13.aarch64.rpm", "fence-agents-kdump-debuginfo-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-kdump-debuginfo-0:4.10.0-98.el9_7.13.s390x.rpm", "fence-agents-kdump-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-kubevirt-0:4.10.0-98.el9_7.13.aarch64.rpm", "fence-agents-kubevirt-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-kubevirt-0:4.10.0-98.el9_7.13.s390x.rpm", "fence-agents-kubevirt-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-kubevirt-debuginfo-0:4.10.0-98.el9_7.13.aarch64.rpm", "fence-agents-kubevirt-debuginfo-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-kubevirt-debuginfo-0:4.10.0-98.el9_7.13.s390x.rpm", "fence-agents-kubevirt-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-lpar-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-mpath-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-nutanix-ahv-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-openstack-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-openstack-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-redfish-0:4.10.0-98.el9_7.13.aarch64.rpm", "fence-agents-redfish-0:4.10.0-98.el9_7.13.ppc64le.rpm", "fence-agents-redfish-0:4.10.0-98.el9_7.13.s390x.rpm", "fence-agents-redfish-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-agents-rhevm-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-rsa-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-rsb-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-sbd-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-scsi-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-virsh-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-vmware-rest-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-vmware-soap-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-wti-0:4.10.0-98.el9_7.13.noarch.rpm", "fence-agents-zvm-0:4.10.0-98.el9_7.13.s390x.rpm","fence-virt-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-cpg-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-cpg-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virt-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-libvirt-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-libvirt-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-multicast-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-multicast-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-serial-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-serial-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-tcp-0:4.10.0-98.el9_7.13.x86_64.rpm", "fence-virtd-tcp-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm", "ha-cloud-support-0:4.10.0-98.el9_7.13.ppc64le.rpm", "ha-cloud-support-0:4.10.0-98.el9_7.13.x86_64.rpm", "ha-cloud-support-debuginfo-0:4.10.0-98.el9_7.13.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Security update for fence-agents on Rocky Linux addressing denial of service risks with CVE-2026-30922. Immediate action required.. Rocky Linux update, fence-agents security, important Linux security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 07, 2026 Important Rocky Linux
219

Rocky Linux 8 RLSA-2026-13902 Important Fix for Resource Agents DoS

Important: resource-agents security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:13902", "synopsis": "Important: resource-agents security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for resource-agents.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The resource-agents packages provide the Pacemaker and RGManager service managers with a set of scripts. These scripts interface with several services to allow operating in a high-availability (HA) environment.\n\nSecurity Fix(es):\n\n* pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2448553", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448553", "description": ""}], "cves": [{"name": "CVE-2026-30922", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-30922", "cvss3ScoringVector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-835"}], "references": [], "publishedAt": "2026-05-07T06:01:03.840543Z", "rpms": {"Rocky Linux 8": {"nvras": ["resource-agents-0:4.9.0-54.el8_10.33.aarch64.rpm", "resource-agents-0:4.9.0-54.el8_10.33.src.rpm", "resource-agents-0:4.9.0-54.el8_10.33.x86_64.rpm", "resource-agents-aliyun-0:4.9.0-54.el8_10.33.x86_64.rpm", "resource-agents-aliyun-debuginfo-0:4.9.0-54.el8_10.33.x86_64.rpm", "resource-agents-debuginfo-0:4.9.0-54.el8_10.33.aarch64.rpm", "resource-agents-debuginfo-0:4.9.0-54.el8_10.33.x86_64.rpm", "resource-agents-debugsource-0:4.9.0-54.el8_10.33.aarch64.rpm","resource-agents-debugsource-0:4.9.0-54.el8_10.33.x86_64.rpm", "resource-agents-gcp-0:4.9.0-54.el8_10.33.x86_64.rpm", "resource-agents-paf-0:4.9.0-54.el8_10.33.aarch64.rpm", "resource-agents-paf-0:4.9.0-54.el8_10.33.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Critical security update for Rocky Linux addressing a denial of service threat in resource-agents. Act now!. Rocky Linux 8 security update denial of service resource-agents. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 07, 2026 Important Rocky Linux
197

Debian 11 linux-6.1 Major Privilege Escalation Denial of Service DLA-4561-1

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For Debian 11 bullseye, these problems have been fixed in version 6.1.170-1~deb11u1.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4561-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Ben Hutchings May 02, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : linux-6.1 Version : 6.1.170-1~deb11u1 CVE ID : CVE-2023-53228 CVE-2023-53510 CVE-2023-53545 CVE-2024-47736 CVE-2024-47809 CVE-2024-49998 CVE-2024-50298 CVE-2024-56719 CVE-2025-21676 CVE-2025-21682 CVE-2025-37945 CVE-2025-37980 CVE-2025-38105 CVE-2025-38162 CVE-2025-38192 CVE-2025-38250 CVE-2025-38303 CVE-2025-38436 CVE-2025-38626 CVE-2025-38659 CVE-2025-38704 CVE-2025-39748 CVE-2025-39764 CVE-2025-39863 CVE-2025-40005 CVE-2025-40016 CVE-2025-40135 CVE-2025-40219 CVE-2025-40242 CVE-2025-40261 CVE-2025-40358 CVE-2025-68206 CVE-2025-68239 CVE-2025-68265 CVE-2025-71067 CVE-2025-71161 CVE-2025-71221 CVE-2025-71265 CVE-2025-71266 CVE-2025-71267 CVE-2025-71269 CVE-2026-23100 CVE-2026-23113 CVE-2026-23141 CVE-2026-23154 CVE-2026-23157 CVE-2026-23204 CVE-2026-23227 CVE-2026-23231 CVE-2026-23242 CVE-2026-23243 CVE-2026-23245 CVE-2026-23253 CVE-2026-23270 CVE-2026-23271 CVE-2026-23273 CVE-2026-23274 CVE-2026-23277 CVE-2026-23279 CVE-2026-23281 CVE-2026-23284 CVE-2026-23286 CVE-2026-23287 CVE-2026-23289 CVE-2026-23290 CVE-2026-23291 CVE-2026-23292 CVE-2026-23293 CVE-2026-23296 CVE-2026-23298CVE-2026-23300 CVE-2026-23303 CVE-2026-23304 CVE-2026-23306 CVE-2026-23307 CVE-2026-23312 CVE-2026-23315 CVE-2026-23317 CVE-2026-23318 CVE-2026-23319 CVE-2026-23321 CVE-2026-23324 CVE-2026-23335 CVE-2026-23336 CVE-2026-23339 CVE-2026-23340 CVE-2026-23343 CVE-2026-23351 CVE-2026-23352 CVE-2026-23356 CVE-2026-23357 CVE-2026-23359 CVE-2026-23362 CVE-2026-23364 CVE-2026-23365 CVE-2026-23367 CVE-2026-23368 CVE-2026-23370 CVE-2026-23372 CVE-2026-23378 CVE-2026-23379 CVE-2026-23381 CVE-2026-23382 CVE-2026-23388 CVE-2026-23391 CVE-2026-23392 CVE-2026-23395 CVE-2026-23396 CVE-2026-23397 CVE-2026-23398 CVE-2026-23401 CVE-2026-23414 CVE-2026-23420 CVE-2026-23422 CVE-2026-23426 CVE-2026-23428 CVE-2026-23434 CVE-2026-23438 CVE-2026-23439 CVE-2026-23446 CVE-2026-23449 CVE-2026-23450 CVE-2026-23452 CVE-2026-23454 CVE-2026-23455 CVE-2026-23456 CVE-2026-23457 CVE-2026-23458 CVE-2026-23460 CVE-2026-23462 CVE-2026-23463 CVE-2026-23474 CVE-2026-23475 CVE-2026-31389 CVE-2026-31391 CVE-2026-31392 CVE-2026-31393 CVE-2026-31396 CVE-2026-31399 CVE-2026-31400 CVE-2026-31402 CVE-2026-31403 CVE-2026-31405 CVE-2026-31408 CVE-2026-31409 CVE-2026-31411 CVE-2026-31412 CVE-2026-31414 CVE-2026-31415 CVE-2026-31416 CVE-2026-31417 CVE-2026-31418 CVE-2026-31421 CVE-2026-31422 CVE-2026-31423 CVE-2026-31424 CVE-2026-31425 CVE-2026-31426 CVE-2026-31427 CVE-2026-31428 CVE-2026-31431 CVE-2026-31433 CVE-2026-31434 CVE-2026-31441 CVE-2026-31446 CVE-2026-31447 CVE-2026-31448 CVE-2026-31450 CVE-2026-31452 CVE-2026-31453 CVE-2026-31454 CVE-2026-31455 CVE-2026-31464 CVE-2026-31466 CVE-2026-31467CVE-2026-31469 CVE-2026-31473 CVE-2026-31476 CVE-2026-31477 CVE-2026-31478 CVE-2026-31480 CVE-2026-31483 CVE-2026-31485 CVE-2026-31492 CVE-2026-31494 CVE-2026-31495 CVE-2026-31496 CVE-2026-31497 CVE-2026-31498 CVE-2026-31503 CVE-2026-31504 CVE-2026-31507 CVE-2026-31508 CVE-2026-31509 CVE-2026-31510 CVE-2026-31512 CVE-2026-31515 CVE-2026-31518 CVE-2026-31519 CVE-2026-31520 CVE-2026-31521 CVE-2026-31522 CVE-2026-31523 CVE-2026-31524 CVE-2026-31533 CVE-2026-31540 CVE-2026-31545 CVE-2026-31546 CVE-2026-31548 CVE-2026-31549 CVE-2026-31550 CVE-2026-31551 CVE-2026-31552 CVE-2026-31555 CVE-2026-31563 CVE-2026-31565 CVE-2026-31566 CVE-2026-31570 CVE-2026-31628 CVE-2026-31634 CVE-2026-31649 CVE-2026-31651 CVE-2026-31656 CVE-2026-31657 CVE-2026-31658 CVE-2026-31659 CVE-2026-31660 CVE-2026-31661 CVE-2026-31662 CVE-2026-31664 CVE-2026-31665 CVE-2026-31667 CVE-2026-31668 CVE-2026-31669 CVE-2026-31670 CVE-2026-31671 CVE-2026-31672 CVE-2026-31674 CVE-2026-31678 CVE-2026-31679 CVE-2026-31680 CVE-2026-31682 CVE-2026-31683 CVE-2026-31689 CVE-2026-31695 CVE-2026-31720 CVE-2026-31721 CVE-2026-31726 CVE-2026-31728 CVE-2026-31737 CVE-2026-31738 CVE-2026-31747 CVE-2026-31748 CVE-2026-31749 CVE-2026-31751 CVE-2026-31752 CVE-2026-31754 CVE-2026-31755 CVE-2026-31756 CVE-2026-31758 CVE-2026-31759 CVE-2026-31761 CVE-2026-31762 CVE-2026-31763 CVE-2026-31768 CVE-2026-31770 CVE-2026-31773 CVE-2026-31776 CVE-2026-31778 CVE-2026-31779 CVE-2026-31780 CVE-2026-31781 CVE-2026-31786 CVE-2026-31787 CVE-2026-31788 CVE-2026-43011 CVE-2026-43013 CVE-2026-43014 CVE-2026-43015 CVE-2026-43017 CVE-2026-43018 CVE-2026-43020 CVE-2026-43023 CVE-2026-43024 CVE-2026-43025 CVE-2026-43026 CVE-2026-43027 CVE-2026-43028 CVE-2026-43030 CVE-2026-43032 CVE-2026-43033 CVE-2026-43035 CVE-2026-43037 CVE-2026-43038 CVE-2026-43040 CVE-2026-43041 CVE-2026-43043 CVE-2026-43046 CVE-2026-43047 CVE-2026-43050 CVE-2026-43051 CVE-2026-43054 CVE-2026-43057 Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For Debian 11 bullseye, these problems have been fixed in version 6.1.170-1~deb11u1. We recommend that you upgrade your linux-6.1 packages. For the detailed security status of linux-6.1 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/linux-6.1 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade your Debian 11 system to address critical vulnerabilities in the Linux kernel leading to potential exploit risks.. Debian upgrade Linux kernel security privilege escalation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 02, 2026 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200