Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 43 Insight Critical Denial of Service CVE-2026-0106837085

New upstream snapshot. Fixes CVEs 2025-11494, 2025-11495, 2026-2341, 2026-3441, 2026-3442. Fixes CVEs 2025-69644, 2025-69645, 2025-69646. Fixes FTBFS. Relax BR of itcl/itk/iwidgets.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-0106837085 2026-03-15 00:55:01.242070+00:00 -------------------------------------------------------------------------------- Name : insight Product : Fedora 43 Version : 18.0.50.20260306 Release : 1.fc43 URL : https://www.sourceware.org/insight/ Summary : Graphical debugger based on GDB Description : Insight is a tight graphical user interface to GDB written in Tcl/Tk. It provides a comprehensive interface that enables users to harness most of GDB's power. It's also probably the only up-to-date UI for the latest GDB version. -------------------------------------------------------------------------------- Update Information: New upstream snapshot. Fixes CVEs 2025-11494, 2025-11495, 2026-2341, 2026-3441, 2026-3442. Fixes CVEs 2025-69644, 2025-69645, 2025-69646. Fixes FTBFS. Relax BR of itcl/itk/iwidgets. Patch "libtool_tag" to force C++ language tagging in libtool. -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 6 2026 Patrick Monnerat 18.0.50.20260306-1 - New upstream snapshot. - Fixes CVEs 2025-11494, 2025-11495, 2026-2341, 2026-3441, 2026-3442. https://bugzilla.redhat.com/show_bug.cgi?id=2402843 https://bugzilla.redhat.com/show_bug.cgi?id=2402846 https://bugzilla.redhat.com/show_bug.cgi?id=2438918 https://bugzilla.redhat.com/show_bug.cgi?id=2443834 - Fixes CVEs 2025-69644, 2025-69645, 2025-69646. https://bugzilla.redhat.com/show_bug.cgi?id=2445281 https://bugzilla.redhat.com/show_bug.cgi?id=2445284 https://bugzilla.redhat.com/show_bug.cgi?id=2446276 - Fixes FTBFS. https://bugzilla.redhat.com/show_bug.cgi?id=2434680 - Relax BR of itcl/itk/iwidgets. - Patch"libtool_tag" to force C++ language tagging in libtool. -------------------------------------------------------------------------------- References: [ 1 ] Bug #2402843 - CVE-2025-11495 insight: GNU Binutils Linker heap-based overflow [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2402843 [ 2 ] Bug #2402846 - CVE-2025-11494 insight: GNU Binutils Linker out-of-bounds read [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2402846 [ 3 ] Bug #2434680 - insight: FTBFS in Fedora rawhide/f44 https://bugzilla.redhat.com/show_bug.cgi?id=2434680 [ 4 ] Bug #2438918 - CVE-2026-2341 insight: libiberty: Application crash via crafted C++ symbol demangling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2438918 [ 5 ] Bug #2443834 - CVE-2026-3441 CVE-2026-3442 insight: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2443834 [ 6 ] Bug #2445276 - CVE-2025-69646 insight: Binutils: Denial of Service via malformed DWARF debug_rnglists data [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2445276 [ 7 ] Bug #2445281 - CVE-2025-69644 insight: Binutils: Denial of Service via crafted binary with malformed DWARF debug information [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2445281 [ 8 ] Bug #2445284 - CVE-2025-69645 insight: Binutils objdump: Denial of Service via crafted DWARF debug information [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2445284 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-0106837085' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fedora 43 Insight release fixes multiple critical issues including DDoS risks. Update to enhance stability and security.. Fedora update, Insight application, critical security issues, software patch, denial of service. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 15, 2026 Critical Fedora
202

openSUSE 15.3: Kernel Important Security Fix 2025:4172-1

An update that solves three vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 60 for SUSE Linux Enterprise 15 SP3) Announcement ID: SUSE-SU-2025:4172-1 Release Date: 2025-11-23T20:05:00Z Rating: important References: * bsc#1250295 * bsc#1251228 * bsc#1251983 Cross-References: * CVE-2022-50388 * CVE-2022-50432 * CVE-2023-53673 CVSS scores: * CVE-2022-50388 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2022-50388 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-50432 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2022-50432 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-53673 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2023-53673 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise Live Patching 15-SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves three vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 5.3.18-150300.59.215 fixes various security issues The following security issues were fixed: * CVE-2022-50388: nvme: fix multipath crash caused by flush request when blktrace is enabled (bsc#1250295). * CVE-2022-50432: kernfs: fix use-after-free in __kernfs_remove (bsc#1251228). * CVE-2023-53673: Bluetooth: hci_event: call disconnect callback before deleting conn (bsc#1251983). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap15.3 zypper in -t patch SUSE-2025-4172=1 * SUSE Linux Enterprise Live Patching 15-SP3 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2025-4172=1 ## Package List: * openSUSE Leap 15.3 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP3_Update_60-debugsource-6-150300.2.1 * kernel-livepatch-5_3_18-150300_59_215-default-debuginfo-6-150300.2.1 * kernel-livepatch-5_3_18-150300_59_215-default-6-150300.2.1 * openSUSE Leap 15.3 (x86_64) * kernel-livepatch-5_3_18-150300_59_215-preempt-6-150300.2.1 * kernel-livepatch-5_3_18-150300_59_215-preempt-debuginfo-6-150300.2.1 * SUSE Linux Enterprise Live Patching 15-SP3 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP3_Update_60-debugsource-6-150300.2.1 * kernel-livepatch-5_3_18-150300_59_215-default-debuginfo-6-150300.2.1 * kernel-livepatch-5_3_18-150300_59_215-default-6-150300.2.1 ## References: * https://www.suse.com/security/cve/CVE-2022-50388.html * https://www.suse.com/security/cve/CVE-2022-50432.html * https://www.suse.com/security/cve/CVE-2023-53673.html * https://bugzilla.suse.com/show_bug.cgi?id=1250295 * https://bugzilla.suse.com/show_bug.cgi?id=1251228 * https://bugzilla.suse.com/show_bug.cgi?id=1251983 . Update patch for openSUSE 15.3 addressing crucial kernel issues to enhance system stability and security.. openSUSE kernel patch important update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 24, 2025 Important OpenSUSE
197

Debian 11: pgagent Important Local Attack CVE-2025-0218 DLA-4338-1

When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, an insufficiently seeded random number generator is used when generating the directory name, leading to the possibility for a local attacker to pre-create . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4338-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Andreas Henriksson October 18, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : pgagent Version : 4.0.0-8+deb11u1 CVE ID : CVE-2025-0218 Debian Bug : 1092677 When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, an insufficiently seeded random number generator is used when generating the directory name, leading to the possibility for a local attacker to pre-create the directory and thus prevent pgAgent from executing jobs, disrupting scheduled tasks. For Debian 11 bullseye, this problem has been fixed in version 4.0.0-8+deb11u1. We recommend that you upgrade your pgagent packages. For the detailed security status of pgagent please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/pgagent Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade pgAgent for Debian to fix a potential attack vector causing disruption of scheduled tasks.. Debian LTS, pgAgent, security update, CVE-2025-0218, local attack. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 18, 2025 Important Debian LTS
100

SUSE: pam-config Important Security Update for CVE-2025-6018

* bsc#1243226 Cross-References: * CVE-2025-6018 . # Security update for pam-config Announcement ID: SUSE-SU-2025:20533-1 Release Date: 2025-07-28T14:36:18Z Rating: important References: * bsc#1243226 Cross-References: * CVE-2025-6018 CVSS scores: * CVE-2025-6018 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-6018 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-6018 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for pam-config fixes the following issues: * CVE-2025-6018: Stop adding pam_env in AUTH stack, and be sure to put this module at the really end of the SESSION stack. (bsc#1243226) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-192=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * pam-config-2.11+git.20240906-slfo.1.1_2.1 * pam-config-debugsource-2.11+git.20240906-slfo.1.1_2.1 * pam-config-debuginfo-2.11+git.20240906-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-6018.html * https://bugzilla.suse.com/show_bug.cgi?id=1243226 . SUSE pam-config has been updated to fix the CVE-2025-6018 security vulnerability that could let unauthorized users gain elevated privileges. Update now.. SUSE Security Update, pam-config Patch, CVE-2025-6018, SUSE Linux Micro, security issue resolution. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 05, 2025 Important SuSE
203

Mageia 9: MGASA-2025-0058 Critical Issue in Subversion Filename Validation

Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository. (CVE-2024-46901) . MGASA-2025-0058 - Updated subversion packages fix security vulnerability Publication date: 12 Feb 2025 URL: https://advisories.mageia.org/MGASA-2025-0058.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-46901 Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository. (CVE-2024-46901) References: - https://bugs.mageia.org/show_bug.cgi?id=33838 - https://www.openwall.com/lists/oss-security/2024/12/09/1 - https://www.cve.org/CVERecord?id=CVE-2024-46901 SRPMS: - 9/core/subversion-1.14.2-2.1.mga9 . Mageia has released a security advisory addressing Subversion vulnerabilities related to filename validation to help mitigate risks from malformed inputs affecting repositories. subversion, Mageia, security update, filename validation, commit access. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 12, 2025 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here