Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 12 articles for you...
203

Mageia 10 Neovim Update Notification for Version 2026-0050 Released

Security update. Publication date: 15 Jul 2026 URL: https://advisories.mageia.org/MGAA-2026-0050.html Type: bugfix Affected Mageia releases: 10 Description: neovim erred when started, because of a missing dependency on lua5.1-lpeg. This update fixes the issue. References: - https://bugs.mageia.org/show_bug.cgi?id=35817 SRPMS: - 10/core/neovim-0.11.5-1.1.mga10 . A security update for Mageia affecting neovim due to a missing dependency is addressed in this advisory.. neovim security update, Mageia bugfix advisory, software dependency issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 15, 2026 Important Mageia
203

Mageia Slurm Important Dependency Fix Advisory 2026-0037

Security update. Publication date: 04 Jul 2026 URL: https://advisories.mageia.org/MGAA-2026-0037.html Type: bugfix Affected Mageia releases: 10 Description: Updated slurm packages fix errors in opening dependency modules References: - https://bugs.mageia.org/show_bug.cgi?id=35765 SRPMS: - 10/core/slurm-25.11.6-2.mga10 . Update for Mageia slurm resolves issues in dependency modules, enhancing system stability and fixing bugs.. Mageia security advisory, slurm bugfix, dependency module update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 04, 2026 Important Mageia
100

SUSE Enterprise Micro 5.2 Cockpit-Podman Important Patch CVE-2025-13465

An update that solves one vulnerability can now be installed.. # Security update for cockpit-podman Announcement ID: SUSE-SU-2026:0379-1 Release Date: 2026-02-04T07:38:29Z Rating: important References: * bsc#1257324 Cross-References: * CVE-2025-13465 CVSS scores: * CVE-2025-13465 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-13465 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2025-13465 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves one vulnerability can now be installed. ## Description: This update for cockpit-podman fixes the following issues: * CVE-2025-13465: Update the lodash dependencie to avoid prototype pollution. (bsc#1257324) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-379=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-379=1 ## Package List: * SUSE Linux Enterprise Micro 5.2 (noarch) * cockpit-podman-33-150300.6.6.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (noarch) * cockpit-podman-33-150300.6.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-13465.html * https://bugzilla.suse.com/show_bug.cgi?id=1257324 . Update for cockpit-podman resolves important issue with lodash dependency, improving security for SUSE Micro systems.. cockpit podman security patch SUSE important. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 04, 2026 Important SuSE
89

Fedora 41: FEDORA-2025-c53905e83d critical: rust-kbs-types update

This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-c53905e83d 2025-06-14 01:51:14.531329+00:00 -------------------------------------------------------------------------------- Name : rust-kbs-types Product : Fedora 41 Version : 0.11.0 Release : 1.fc41 URL : https://crates.io/crates/kbs-types Summary : Rust (de)serializable types for KBS Description : Rust (de)serializable types for KBS. -------------------------------------------------------------------------------- Update Information: This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574 -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 2 2025 Sergio Lopez - 0.11.0-1 - Update to version 0.11.0 * Wed May 28 2025 Sergio Lopez - 0.10.0-1 - Update to version 0.10.0 * Sun Jan 19 2025 Fedora Release Engineering - 0.8.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-c53905e83d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code ofConduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . The recent Fedora upgrade improves rust-kbs-types by resolving the crossbeam-channel issue and mitigating CVE-2025-4574.. Fedora security advisory, rust-kbs-types update, crossbeam-channel fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 14, 2025 Critical Fedora
100

SUSE Linux Micro 6.0: 2025:20013-1 moderate: podman dependency issue

* bsc#1227052 Cross-References: * CVE-2024-1753 * CVE-2024-24786 . # Security update for podman Announcement ID: SUSE-SU-2025:20013-1 Release Date: 2025-02-03T08:48:39Z Rating: moderate References: * bsc#1227052 Cross-References: * CVE-2024-1753 * CVE-2024-24786 * CVE-2024-3727 * CVE-2024-6104 CVSS scores: * CVE-2024-1753 ( SUSE ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2024-1753 ( NVD ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2024-24786 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-24786 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-3727 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2024-3727 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2024-6104 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2024-6104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for podman fixes the following issues: * CVE-2024-6104: Fixed dependency issue with go-retryablehttp: url might write sensitive information to log file (bsc#1227052). * Update to version 4.9.5: * Bump to v4.9.5 * Update release notes for v4.9.5 * fix "concurrent map writes" in network ls compat endpoint * [v4.9] Fix for CVE-2024-3727 * Disable failing bud test * CI Maintenance: Disable machine tests * [CI:DOCS] Allow downgrade of WiX * [CI:DOCS] Force WiX 3.11 * [CI:DOCS] Fix windows installer action * Bump to v4.9.5-dev * Bump to v4.9.4 * Update release notes for v4.9.4 * [v4.9] Bump Buildah to v1.33.7, CVE-2024-1753, CVE-2024-24786 * Add farm command to commands list * Bump to FreeBSD 13.3 (13.2 vanished) * Update health-start-periods docs * Don't update health check status during initialDelaySeconds * image scp: don't require port for ssh URL * Ignore docker's end pointconfig when the final network mode isn't bridge. * Fix running container from docker client with rootful in rootless podman. * [skip-ci] Packit: remove koji and bodhi tasks for v4.9 * Bump to v4.9.4-dev * Remove gitleaks scanning ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-46=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * podman-debuginfo-4.9.5-1.1 * podman-remote-4.9.5-1.1 * podman-remote-debuginfo-4.9.5-1.1 * podman-4.9.5-1.1 * SUSE Linux Micro 6.0 (noarch) * podman-docker-4.9.5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-1753.html * https://www.suse.com/security/cve/CVE-2024-24786.html * https://www.suse.com/security/cve/CVE-2024-3727.html * https://www.suse.com/security/cve/CVE-2024-6104.html * https://bugzilla.suse.com/show_bug.cgi?id=1227052 . Podman receives a notable security enhancement addressing four vulnerabilities, one of which pertains to the exposure of confidential log data.. Podman Security Update, SUSE Linux Update, Dependency Issue. . LinuxSecurity.com Team

Calendar%202 Jun 04, 2025 SuSE
89

Fedora 39: FEDORA-2023-a04cc349e1 Critical: python-aiohttp Update

Security fix for CVE-2023-49081, CVE-2023-49082. Update `python-aiohttp` to 3.9.1. Patch `python-pysqeezebox` and `python-wled` so they do not have an implicit dependency on `python-async-timeout` via `python-aiohttp`. libs/aiohttp/releases/tag/v3.9.0 libs/aiohttp/releases/tag/v3.9.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-a04cc349e1 2024-01-08 01:23:05.713075 -------------------------------------------------------------------------------- Name : python-pysqueezebox Product : Fedora 39 Version : 0.5.5 Release : 11.fc39 URL : https://github.com/rajlaud/pysqueezebox Summary : Python library to control Logitech Media Server Description : Python library to control a Logitech Media Server asynchronously. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-49081, CVE-2023-49082. Update `python-aiohttp` to 3.9.1. Patch `python-pysqeezebox` and `python-wled` so they do not have an implicit dependency on `python-async-timeout` via `python-aiohttp`. libs/aiohttp/releases/tag/v3.9.0 libs/aiohttp/releases/tag/v3.9.1 -------------------------------------------------------------------------------- ChangeLog: * Sat Dec 2 2023 Benjamin A. Beasley - 0.5.5-11 - Add explicit async-timeout dependency -------------------------------------------------------------------------------- References: [ 1 ] Bug #2252236 - TRIAGE CVE-2023-49081 python-aiohttp: aiohttp: HTTP request modification [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2252236 [ 2 ] Bug #2252249 - TRIAGE CVE-2023-49082 python-aiohttp: aiohttp: CRLF injection if user controls the HTTP method using aiohttp client [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2252249 [ 3 ] Bug #2253439 - python-pysqueezebox: Please merge rawhide back to f39 and f38 https://bugzilla.redhat.com/show_bug.cgi?id=2253439 [ 4 ] Bug #2253440 - python-wled: Please merge rawhide back to f39 and f38 https://bugzilla.redhat.com/show_bug.cgi?id=2253440 [ 5 ] Bug #2254945 - deprecation warning: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal https://bugzilla.redhat.com/show_bug.cgi?id=2254945 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-a04cc349e1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Make certain that Fedora 39's security patches are applied by refreshing python-aiohttp along with its related packages to address various CVEs.. python library, logitech media server, security update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 08, 2024 Critical Fedora
100

SUSE: 2023:1145-1 Critical: Bci/NodeJS Vulnerability Patch

The container bci/python was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3357-1 Container Tags : bci/python:3 , bci/python:3-14.2 , bci/python:3.6 , bci/python:3.6-14.2 Container Release : 14.2 Severity : important Type : security References : 1215533 1215713 CVE-2023-35945 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3994-1 Released: Fri Oct 6 13:44:15 2023 Summary: Recommended update for git Type: recommended Severity: moderate References: 1215533 This update for git fixes the following issues: - Downgrade openssh dependency to recommends (bsc#1215533) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3997-1 Released: Fri Oct 6 14:13:56 2023 Summary: Security update for nghttp2 Type: security Severity: important References: 1215713,CVE-2023-35945 This update for nghttp2 fixes the following issues: - CVE-2023-35945: Fixed memory leak when PUSH_PROMISE or HEADERS frame cannot be sent (bsc#1215713). The following package changes have been done: - libnghttp2-14-1.40.0-150200.9.1 updated - git-core-2.35.3-150300.10.30.1 updated - libcbor0-0.5.0-150100.4.6.1 removed - libedit0-3.1.snap20150325-2.12 removed - libfido2-1-1.13.0-150400.5.6.1 removed - libhidapi-hidraw0-0.10.1-150300.3.2.1 removed - libudev1-249.16-150400.8.33.1 removed - openssh-clients-8.4p1-150300.3.22.1 removed - openssh-common-8.4p1-150300.3.22.1 removed - openssh-fips-8.4p1-150300.3.22.1 removed . Crucial SUSE enhancement for bci/python and nghttp2, resolving a memory leak and openssh dependency concerns.. SUSE Container Update,Bci/Python Security, Nghttp2 Fixes, Openssh Dependency. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 10, 2023 Important SuSE
89

Fedora 36: Blender Critical Fix For CVE-2022-28041 Severity: Critical

Security fix for CVE-2022-28041 affecting `usd` via its dependency on the header-only `stb_image` library. ----- Do not package `pxrConfig.cmake` with `usd`, since it is not usable with a monolithic library build. - Move bundled library virtual `Provides` from `usd` to `usd-libs` - Do not use `jemalloc` in `usd`. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-c87bba6546 2022-05-07 04:08:14.310830 --------------------------------------------------------------------------------Name : blender Product : Fedora 36 Version : 3.1.2 Release : 3.fc36 URL : Summary : 3D modeling, animation, rendering and post-production Description : Blender is the essential software solution you need for 3D, from modeling, animation, rendering and post-production to interactive creation and playback. Professionals and novices can easily and inexpensively publish stand-alone, secure, multi-platform content to the web, CD-ROMs, and other media. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2022-28041 affecting `usd` via its dependency on the header-only `stb_image` library. ----- Do not package `pxrConfig.cmake` with `usd`, since it is not usable with a monolithic library build. - Move bundled library virtual `Provides` from `usd` to `usd-libs` - Do not use `jemalloc` in `usd` --------------------------------------------------------------------------------ChangeLog: * Sun Apr 10 2022 Benjamin A. Beasley 1:3.1.2-3 - BR usd-devel instead of cmake(pxr) * Fri Apr 1 2022 Fedora Release Monitoring 1:3.1.2-1 - Update to 3.1.2 (#2070344) * Fri Apr 1 2022 Fedora Release Monitoring 1:3.1.1-1 - Update to 3.1.1 (#2070344) --------------------------------------------------------------------------------References: [ 1 ] Bug #2055414 - usd-devel is missing pxrTargets.cmake https://bugzilla.redhat.com/show_bug.cgi?id=2055414 [ 2 ] Bug #2077054 - Rebuild usd with updated stb_image-{devel,static} for CVE-2022-28041 https://bugzilla.redhat.com/show_bug.cgi?id=2077054 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-c87bba6546' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Important update for Blender in Fedora 36 released to resolve CVE-2022-28041, which impacts usd and stb_image components.. Blender Security,Fedora Updates,CVE-2022-28041,USD Dependency Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 07, 2022 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200