Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 513
Alerts This Week
Warning Icon 1 513

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 6 articles for you...
202

openSUSE Shadowsocks Moderate Update CVE-2025-297850 Fix

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for shadowsocks-v2ray-plugin ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0365-1 Rating: moderate References: #1243954 Cross-References: CVE-2025-297850 Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for shadowsocks-v2ray-plugin fixes the following issues: Update version to 5.37.0 * Update v2ray-core to 5.37.0 * Fixed CVE-2025-29785 in dependency ackhandler (bsc#1243954) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2025-365=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): shadowsocks-v2ray-plugin-5.37.0-bp157.2.3.1 - openSUSE Backports SLE-15-SP7 (noarch): golang-github-teddysun-v2ray-plugin-5.37.0-bp157.2.3.1 References: https://www.suse.com/security/cve/CVE-2025-297850.html https://bugzilla.suse.com/1243954 . A moderate security fix for shadowsocks-v2ray-plugin in openSUSE addresses CVE-2025-297850 with updated dependencies.. openSUSE Update, shadowsocks security fix, CVE-2025-297850. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 11, 2026 moderate OpenSUSE
89

Fedora 36: 2022-8b0d8fb7da moderate: Type Confusion in Chromium

Minor update for CVE-2022-1096. Also fixes dependency issues for chrome-remote- desktop and sizing issues where some libraries/binaries were not being stripped.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-8b0d8fb7da 2022-05-07 04:08:14.309241 --------------------------------------------------------------------------------Name : chromium Product : Fedora 36 Version : 99.0.4844.84 Release : 1.fc36 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). --------------------------------------------------------------------------------Update Information: Minor update for CVE-2022-1096. Also fixes dependency issues for chrome-remote-desktop and sizing issues where some libraries/binaries were not being stripped. --------------------------------------------------------------------------------ChangeLog: * Sun Mar 27 2022 Tom Callaway - 99.0.4844.84-1 - update to 99.0.4844.84 - package up libremoting_core.so* for chrome-remote-desktop - strip all the .so files (and binaries) * Sat Mar 19 2022 Tom Callaway - 99.0.4844.74-1 - update to 99.0.4844.74 --------------------------------------------------------------------------------References: [ 1 ] Bug #2068954 - CVE-2022-1096 chromium-browser: Type Confusion in V8 https://bugzilla.redhat.com/show_bug.cgi?id=2068954 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-8b0d8fb7da' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Announcement for Fedora 36 includes fixes for CVE-2022-1096, plus enhancements for enhanced remote desktop functionality. Read more for insights!. Fedora 36, Type Confusion, Chromium Update, Dependency Issues. . LinuxSecurity.com Team

Calendar%202 May 07, 2022 Fedora
89

Fedora 33: 2020-640645e518 Moderate: Guacamole-Server Update Information

Updated SPEC file and rebuilt for new dependencies.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-640645e518 2021-01-04 01:05:53.142327 --------------------------------------------------------------------------------Name : guacamole-server Product : Fedora 33 Version : 1.2.0 Release : 3.fc33 URL : https://guacamole.apache.org/ Summary : Server-side native components that form the Guacamole proxy Description : Guacamole is an HTML5 remote desktop gateway. Guacamole provides access to desktop environments using remote desktop protocols like VNC and RDP. A centralized server acts as a tunnel and proxy, allowing access to multiple desktops through a web browser. No browser plugins are needed, and no client software needs to be installed. The client requires nothing more than a web browser supporting HTML5 and AJAX. The main web application is provided by the "guacamole-client" package. --------------------------------------------------------------------------------Update Information: Updated SPEC file and rebuilt for new dependencies. --------------------------------------------------------------------------------ChangeLog: * Sat Dec 26 2020 Simone Caronni - 1.2.0-3 - Do not ship deprecated sysconfig file. - Trim changelog. --------------------------------------------------------------------------------References: [ 1 ] Bug #1853386 - CVE-2020-9498 guacamole-server: Dangling pointer in RDP static virtual channel handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1853386 [ 2 ] Bug #1853388 - CVE-2020-9498 guacamole-server: Dangling pointer in RDP static virtual channel handling [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1853388 [ 3 ] Bug #1853391 - CVE-2020-9497 guacamole-server: Improper input validation of RDP static virtual channels [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1853391 [ 4 ] Bug#1853393 - CVE-2020-9497 guacamole-server: Improper input validation of RDP static virtual channels [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1853393 [ 5 ] Bug #1878395 - F34FailsToInstall: libguac-client-kubernetes https://bugzilla.redhat.com/show_bug.cgi?id=1878395 [ 6 ] Bug #1899751 - Dependency error installing libguac-client-kubernetes https://bugzilla.redhat.com/show_bug.cgi?id=1899751 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-640645e518' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The Guacamole-server patch addresses vulnerabilities in Fedora 33, introducing updated dependencies. Execute the command dnf upgrade for installation.. Guacamole Update,Fedora 33,Remote Access Security,Server Update. . LinuxSecurity.com Team

Calendar%202 Jan 03, 2021 Fedora
89

Fedora 32: FEDORA-2020-1a0c7a3b53 Important: Xmlrpc Library Update

Update to latest release of PyDev and fix dependency errors. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-1d0635bd71 2020-04-06 00:15:14.746061 --------------------------------------------------------------------------------Name : xmlrpc Product : Fedora 32 Version : 3.1.3 Release : 24.fc32 URL : https://ws.apache.org/xmlrpc/ Summary : Java XML-RPC implementation Description : Apache XML-RPC is a Java implementation of XML-RPC, a popular protocol that uses XML over HTTP to implement remote procedure calls. --------------------------------------------------------------------------------Update Information: Update to latest release of PyDev and fix dependency errors --------------------------------------------------------------------------------ChangeLog: --------------------------------------------------------------------------------References: [ 1 ] Bug #1736737 - swt-chart: FTBFS in Fedora rawhide/f31 https://bugzilla.redhat.com/show_bug.cgi?id=1736737 [ 2 ] Bug #1791766 - CVE-2019-17570 xmlrpc: Deserialization of server-side exception from faultCause in XMLRPC error response [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1791766 [ 3 ] Bug #1793870 - Broken dependency on xmlrpc package from eclipse-pydev https://bugzilla.redhat.com/show_bug.cgi?id=1793870 [ 4 ] Bug #1799307 - eclipse-pydev: FTBFS in Fedora rawhide/f32 https://bugzilla.redhat.com/show_bug.cgi?id=1799307 [ 5 ] Bug #1807580 - eclipse-pydev requires Python 2 to build https://bugzilla.redhat.com/show_bug.cgi?id=1807580 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-1d0635bd71' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Follow these instructions to resolve xmlrpc dependency issues and upgrade on Fedora 32, ensuring your system is up to date before proceeding. xmlrpc Update, Fedora Security, Dependency Management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 05, 2020 Important Fedora
89

Fedora 32: FEDORA-2020-1d0635bd71 moderate: Eclipse-PyDev Dependency Fix

Update to latest release of PyDev and fix dependency errors. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-1d0635bd71 2020-04-06 00:15:14.746061 --------------------------------------------------------------------------------Name : eclipse-pydev Product : Fedora 32 Version : 7.5.0 Release : 1.fc32 URL : https://www.pydev.org/ Summary : Eclipse Python development plug-in Description : The eclipse-pydev package contains Eclipse plugins for Python development. --------------------------------------------------------------------------------Update Information: Update to latest release of PyDev and fix dependency errors --------------------------------------------------------------------------------ChangeLog: * Tue Mar 24 2020 Mat Booth - 1:7.5.0-1 - Update to latest upstream release - Drop mylyn extension - Drop python 2 cython extension support * Tue Jan 28 2020 Fedora Release Engineering - 1:7.4.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Sat Nov 23 2019 Mat Booth - 1:7.4.0-2 - Don't build python 2 extensions for Fedora > = 32 * Wed Nov 20 2019 Mat Booth - 1:7.4.0-1 - Update to latest upstream release * Mon Sep 23 2019 Mat Booth - 1:7.3.0-2 - Ensure c++11 is used when building native part * Mon Sep 9 2019 Mat Booth - 1:7.3.0-1 - Update to latest upstream release * Sun Sep 1 2019 Mat Booth - 1:7.2.1-4 - Temporarily disable cython debugging extension on F32 due to a problem building against python 3.8 * Fri Jun 21 2019 Mat Booth - 1:7.2.1-3 - Fix failure to build against Eclipse 2019-06 * Mon Jun 17 2019 Mat Booth - 1:7.2.1-2 - Rebuild against Lucene 8 * Sat Jun 1 2019 Mat Booth - 1:7.2.1-1 - Update to latest upstream release - Fix missing cython extension for python 2 users --------------------------------------------------------------------------------References: [ 1 ] Bug #1736737 - swt-chart: FTBFS inFedora rawhide/f31 https://bugzilla.redhat.com/show_bug.cgi?id=1736737 [ 2 ] Bug #1791766 - CVE-2019-17570 xmlrpc: Deserialization of server-side exception from faultCause in XMLRPC error response [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1791766 [ 3 ] Bug #1793870 - Broken dependency on xmlrpc package from eclipse-pydev https://bugzilla.redhat.com/show_bug.cgi?id=1793870 [ 4 ] Bug #1799307 - eclipse-pydev: FTBFS in Fedora rawhide/f32 https://bugzilla.redhat.com/show_bug.cgi?id=1799307 [ 5 ] Bug #1807580 - eclipse-pydev requires Python 2 to build https://bugzilla.redhat.com/show_bug.cgi?id=1807580 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-1d0635bd71' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Upgrade PyDev to the most recent version on Fedora 32, resolving any dependency issues and improving overall efficiency.. Fedora 32 Update, Eclipse PyDev Dependency, Software Fixes. . LinuxSecurity.com Team

Calendar%202 Apr 05, 2020 Fedora
202

openSUSE: 2019:0185-1 Moderate: rmt-server Security Update

An update that solves three vulnerabilities and has 6 fixes is now available.. openSUSE Security Update: Security update for rmt-server ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:0185-1 Rating: moderate References: #1102046 #1102193 #1109307 #1113760 #1113969 #1114831 #1117106 #1118579 #1118584 Cross-References: CVE-2018-14404 CVE-2018-16468 CVE-2018-16470 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that solves three vulnerabilities and has 6 fixes is now available. Description: This update for rmt-server to version 1.1.1 fixes the following issues: The following issues have been fixed: - Fixed migration problems which caused some extensions / modules to be dropped (bsc#1118584, bsc#1118579) - Fixed listing of mirrored products (bsc#1102193) - Include online migration paths into offline migration (bsc#1117106) - Sync products that do not have a base product (bsc#1109307) - Fixed SLP auto discovery for RMT (bsc#1113760) Update dependencies for security fixes: - CVE-2018-16468: Update loofah to 2.2.3 (bsc#1113969) - CVE-2018-16470: Update rack to 2.0.6 (bsc#1114831) - CVE-2018-14404: Update nokogiri to 1.8.5 (bsc#1102046) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-185=1 Package List: - openSUSE Leap 15.0 (x86_64): rmt-server-1.1.1-lp150.2.12.1 rmt-server-debuginfo-1.1.1-lp150.2.12.1 rmt-server-pubcloud-1.1.1-lp150.2.12.1 References: https://www.suse.com/security/cve/CVE-2018-14404.html https://www.suse.com/security/cve/CVE-2018-16468.html https://www.suse.com/security/cve/CVE-2018-16470.html https://bugzilla.suse.com/1102046 https://bugzilla.suse.com/1102193 https://bugzilla.suse.com/1109307 https://bugzilla.suse.com/1113760 https://bugzilla.suse.com/1113969 https://bugzilla.suse.com/1114831 https://bugzilla.suse.com/1117106 https://bugzilla.suse.com/1118579 https://bugzilla.suse.com/1118584 -- . openSUSE Security Update: Security update for rmt-server ___________________________________________. update, solves, three, vulnerabilities, fixes, opensuse, security. . LinuxSecurity.com Team

Calendar%202 Feb 14, 2019 OpenSUSE
89

Fedora 29: 2018-1959097dfc Critical: Texlive Buffer Overflow

Update pretty much everything in texlive. Apply upstream fix for CVE-2018-17407. Resolve (hopefully) all dependency issues.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-1959097dfc 2018-10-09 00:04:24.598855 --------------------------------------------------------------------------------Name : texlive Product : Fedora 29 Version : 2018 Release : 20.fc29 URL : https://tug.org/texlive/ Summary : TeX formatting system Description : The TeX Live software distribution offers a complete TeX system for a variety of Unix, Macintosh, Windows and other platforms. It encompasses programs for editing, typesetting, previewing and printing of TeX documents in many different languages, and a large collection of TeX macros and font libraries. The distribution includes extensive general documentation about TeX, as well as the documentation for the included software packages. --------------------------------------------------------------------------------Update Information: Update pretty much everything in texlive. Apply upstream fix for CVE-2018-17407. Resolve (hopefully) all dependency issues. --------------------------------------------------------------------------------References: [ 1 ] Bug #1632803 - CVE-2018-17407 texlive: Buffer overflow in t1_check_unusual_charstring function in writet1.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1632803 [ 2 ] Bug #1599508 - texlive update still has issues with failed dependencies https://bugzilla.redhat.com/show_bug.cgi?id=1599508 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-1959097dfc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the FedoraProject GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Perform a comprehensive texlive upgrade for Fedora 29 that resolves buffer overflow vulnerabilities and dependency challenges, including essential security patches.. texlive update, Fedora security, buffer overflow fix, software update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 09, 2018 Critical Fedora
197

Debian 8 DLA-1434-1: Linux-Base Update Critical For Dependencies

The linux-base package has been updated to support the package of Linux 4.9 that was recently added to Debian 8. This resolves a dependency that was not satisfiable by the jessie and jessie-security suites. . Package : linux-base Version : 4.5~deb8u1 Debian Bug : 702482 761614 The linux-base package has been updated to support the package of Linux 4.9 that was recently added to Debian 8. This resolves a dependency that was not satisfiable by the jessie and jessie-security suites. This update also fixes a bug in version ordering in the linux-version command, corrects the package name printed by the perf command when linux-perf-4.9 is needed, and adds bash-completion support for the perf command. For Debian 8 "Jessie", the new version is 4.5~deb8u1. We recommend that you upgrade your linux-base packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- Ben Hutchings - Debian developer, member of kernel, installer and LTS teams . The new version of the linux-base package is now compatible with Linux kernel 4.9, addressing critical dependencies in Debian 8.. Debian Linux Base Update, Linux Support Package, Dependency Resolution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 20, 2018 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200