Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 499
Alerts This Week
Warning Icon 1 499

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 5 articles for you...
197

Debian 11: DLA-4226-1 critical: dns-root-data DNSSEC trust anchor

The dns-root-data package contains DNS root zone data as published by IANA to be used as initial source by DNS software. This release adds the DNSKEY record for the KSK-2024 trust anchor. This new key is planned for use starting October 2026, and the previous one (KSK-2017) . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4226-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sylvain Beucler June 23, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : dns-root-data Version : 2024071801~deb11u1 Debian Bug : #1076995 The dns-root-data package contains DNS root zone data as published by IANA to be used as initial source by DNS software. This release adds the DNSKEY record for the KSK-2024 trust anchor. This new key is planned for use starting October 2026, and the previous one (KSK-2017) should be revoked January 2027, leaving time to propagate the new trust anchor, or roll to it sooner in case of emergency. For Debian 11 bullseye, this problem has been fixed in version 2024071801~deb11u1. We recommend that you upgrade your dns-root-data packages. For the detailed security status of dns-root-data please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/dns-root-data Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance DNS security on Debian 11 by adding the KSK-2024 DNSSEC trust anchor. Follow simple steps to update configuration and validate the integration. dns-root-data security update, DNSSEC Debian advisory, KSK-2024 trust anchor. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 23, 2025 Critical Debian LTS
197

Debian 11 DLA-3859-1 Critical: Systemd DNSSEC Issues and Fixes

Multiple vulnerabilities have been fixed in systemd, the default init system in Debian, when using systemd-resolved with DNSSEC. CVE-2023-7008 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3859-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk September 02, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : systemd Version : 247.3-7+deb11u6 CVE ID : CVE-2023-7008 CVE-2023-50387 CVE-2023-50868 Debian Bug : 1059278 Multiple vulnerabilities have been fixed in systemd, the default init system in Debian, when using systemd-resolved with DNSSEC. CVE-2023-7008 Don't accept records of DNSSEC-signed domains when they have no signature. CVE-2023-50387 DNSSEC denial of service (CPU consumption) CVE-2023-50868 DNSSEC denial of service (CPU consumption) For Debian 11 bullseye, these problems have been fixed in version 247.3-7+deb11u6. We recommend that you upgrade your systemd packages. For the detailed security status of systemd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/systemd Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . To improve the security of your DNSSEC on Debian, be sure to upgrade systemd. Refer to advisory DLA-3859-1 for detailed info on vulnerabilities fixed and patch steps.. Debian Security,Systemd Issues,DNSSEC Threats. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 02, 2024 Critical Debian LTS
197

Debian 10 DLA-3795-1 Critical Advisory: Knot-Resolver Security Issues

Several security vulnerabilities have been discovered in knot-resolver, a caching, DNSSEC-validating DNS resolver which may allow remote attackers to bypass DNSSEC validation or cause a denial-of-service. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3795-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany April 26, 2024 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : knot-resolver Version : 3.2.1-3+deb10u2 CVE ID : CVE-2019-10190 CVE-2019-10191 CVE-2019-19331 CVE-2020-12667 Debian Bug : 932048 946181 961076 Several security vulnerabilities have been discovered in knot-resolver, a caching, DNSSEC-validating DNS resolver which may allow remote attackers to bypass DNSSEC validation or cause a denial-of-service. For Debian 10 buster, these problems have been fixed in version 3.2.1-3+deb10u2. We recommend that you upgrade your knot-resolver packages. For the detailed security status of knot-resolver please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/knot-resolver Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3795-2 concerns vulnerabilities in knot-resolver. It is advised to perform an upgrade to reduce potential threats.. knot resolver security,debian lts advisory,dnssec flaws,remote attack mitigation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 26, 2024 Critical Debian LTS
87

Debian: DSA-5633-1 Severe Threat: Knot Resolver Denial of Service

It was discovered that malformed DNSSEC records within a DNS zone could result in denial of service against Knot Resolver, a caching, DNSSEC- validating DNS resolver. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5633-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff February 27, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : knot-resolver CVE ID : CVE-2023-46317 CVE-2023-50387 CVE-2023-50868 It was discovered that malformed DNSSEC records within a DNS zone could result in denial of service against Knot Resolver, a caching, DNSSEC- validating DNS resolver. For the stable distribution (bookworm), these problems have been fixed in version 5.6.0-1+deb12u1. We recommend that you upgrade your knot-resolver packages. For the detailed security status of knot-resolver please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/knot-resolver Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-5633-1 addresses a vulnerability in Knot Resolver that may cause DoS due to malformed DNSSEC records, urging users to apply patches. Debian Advisory,DNSSEC Security,Knot Resolver Update,Denial of Service,Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 27, 2024 Critical Debian
202

openSUSE: 2019:0107-1 Important: pdns-recursor DNSSEC Fix - Critical Issue

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for pdns-recursor ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:0107-1 Rating: important References: #1121889 Cross-References: CVE-2019-3807 Affected Products: openSUSE Backports SLE-15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for pdns-recursor fixes the following issues: - CVE-2019-3807: Fixed insufficient validation of DNSSEC signatures (boo#1121889) This update was imported from the openSUSE:Leap:15.0:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15: zypper in -t patch openSUSE-2019-107=1 Package List: - openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64): pdns-recursor-4.1.2-bp150.2.6.1 References: https://www.suse.com/security/cve/CVE-2019-3807.html https://bugzilla.suse.com/1121889 -- . openSUSE Security Update: Security update for pdns-recursor ________________________________________. update, security, fixes, vulnerability, opensuse. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 31, 2019 Important OpenSUSE
197

Debian 8: DLA-1532-1 Critical dnsmasq Key Signing Key Update

dnsmasq, a DNS forwarder and DHCP server, ships the DNS Root Zone Key Signing Key (KSK), used as the DNSSEC trust anchor. ICANN will rollover the KSK in 11 October 2018, and DNS resolvers will need the new key . Package : dnsmasq Version : 2.72-3+deb8u4 Debian Bug : 907887 dnsmasq, a DNS forwarder and DHCP server, ships the DNS Root Zone Key Signing Key (KSK), used as the DNSSEC trust anchor. ICANN will rollover the KSK in 11 October 2018, and DNS resolvers will need the new key (KSK-2017) to continue performing DNSSEC validation. This dnsmasq package update includes the latest key to prevent issues in scenarios where dnsmasq runs with DNSSEC enabled and it is using the trusted anchors file shipped with the package. Please note this is not the default configuration in Debian. For Debian 8 "Jessie", this problem has been fixed in version 2.72-3+deb8u4. We recommend that you upgrade your dnsmasq packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The latest dnsmasq update provides crucial enhancements for DNSSEC validation, incorporating a new Key Signing Key for Debian 8. Users are advised to perform an upgrade.. dnsmasq update,dnssec validation,debian packages,key signing,dhcp server. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 04, 2018 Critical Debian LTS
98

Red Hat Enterprise Linux 5: RHSA-2012:1122-01 Important: Bind97 DoS

Updated bind97 packages that fix one security issue are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Important: bind97 security update Advisory ID: RHSA-2012:1122-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2012:1122.html Issue date: 2012-07-31 CVE Names: CVE-2012-3817 ==================================================================== 1. Summary: Updated bind97 packages that fix one security issue are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 3. Description: The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly. An uninitialized data structure use flaw was found in BIND when DNSSEC validation was enabled. A remote attacker able to send a large number of queries to a DNSSEC validating BIND resolver could use this flaw to cause it to exit unexpectedly with an assertion failure. (CVE-2012-3817) Users of bind97 are advised to upgrade to these updated packages, which correct this issue. After installing the update, the BIND daemon (named) will be restarted automatically. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your systemhave been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 842897 - CVE-2012-3817 bind: heavy DNSSEC validation load can cause assertion failure 6. Package List: RHEL Desktop Workstation (v. 5 client): Source: i386: bind97-9.7.0-10.P2.el5_8.2.i386.rpm bind97-chroot-9.7.0-10.P2.el5_8.2.i386.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.i386.rpm bind97-devel-9.7.0-10.P2.el5_8.2.i386.rpm bind97-libs-9.7.0-10.P2.el5_8.2.i386.rpm bind97-utils-9.7.0-10.P2.el5_8.2.i386.rpm x86_64: bind97-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-chroot-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.i386.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-devel-9.7.0-10.P2.el5_8.2.i386.rpm bind97-devel-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-libs-9.7.0-10.P2.el5_8.2.i386.rpm bind97-libs-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-utils-9.7.0-10.P2.el5_8.2.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: bind97-9.7.0-10.P2.el5_8.2.i386.rpm bind97-chroot-9.7.0-10.P2.el5_8.2.i386.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.i386.rpm bind97-devel-9.7.0-10.P2.el5_8.2.i386.rpm bind97-libs-9.7.0-10.P2.el5_8.2.i386.rpm bind97-utils-9.7.0-10.P2.el5_8.2.i386.rpm ia64: bind97-9.7.0-10.P2.el5_8.2.ia64.rpm bind97-chroot-9.7.0-10.P2.el5_8.2.ia64.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.ia64.rpm bind97-devel-9.7.0-10.P2.el5_8.2.ia64.rpm bind97-libs-9.7.0-10.P2.el5_8.2.ia64.rpm bind97-utils-9.7.0-10.P2.el5_8.2.ia64.rpm ppc: bind97-9.7.0-10.P2.el5_8.2.ppc.rpm bind97-chroot-9.7.0-10.P2.el5_8.2.ppc.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.ppc.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.ppc64.rpm bind97-devel-9.7.0-10.P2.el5_8.2.ppc.rpm bind97-devel-9.7.0-10.P2.el5_8.2.ppc64.rpm bind97-libs-9.7.0-10.P2.el5_8.2.ppc.rpm bind97-libs-9.7.0-10.P2.el5_8.2.ppc64.rpm bind97-utils-9.7.0-10.P2.el5_8.2.ppc.rpm s390x: bind97-9.7.0-10.P2.el5_8.2.s390x.rpm bind97-chroot-9.7.0-10.P2.el5_8.2.s390x.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.s390.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.s390x.rpm bind97-devel-9.7.0-10.P2.el5_8.2.s390.rpm bind97-devel-9.7.0-10.P2.el5_8.2.s390x.rpm bind97-libs-9.7.0-10.P2.el5_8.2.s390.rpm bind97-libs-9.7.0-10.P2.el5_8.2.s390x.rpm bind97-utils-9.7.0-10.P2.el5_8.2.s390x.rpm x86_64: bind97-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-chroot-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.i386.rpm bind97-debuginfo-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-devel-9.7.0-10.P2.el5_8.2.i386.rpm bind97-devel-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-libs-9.7.0-10.P2.el5_8.2.i386.rpm bind97-libs-9.7.0-10.P2.el5_8.2.x86_64.rpm bind97-utils-9.7.0-10.P2.el5_8.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2012-3817 https://access.redhat.com/security/updates/classification/#important 8. Contact: The RedHat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2012 Red Hat, Inc. . Important notice regarding bind97 regarding a vulnerability within Red Hat Enterprise Linux 5. Immediate upgrade recommended to safeguard against potential threats.. Red Hat Bind97 Security Patch, DNSSEC Update, Linux Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 31, 2012 Important Red Hat
87

Debian: DSA-2518-1 Moderate: OpenSSL Vulnerability Update

Einar Lonn discovered that under certain conditions bind9, a DNS server, may use cached data before initialization. As a result, an attacker can trigger and assertion failure on servers under high query load that do DNSSEC validation. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2517-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Nico Golde July 30, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : bind9 Vulnerability : denial of service Problem type : remote Debian-specific: no CVE ID : CVE-2012-3817 Einar Lonn discovered that under certain conditions bind9, a DNS server, may use cached data before initialization. As a result, an attacker can trigger and assertion failure on servers under high query load that do DNSSEC validation. For the stable distribution (squeeze), this problem has been fixed in version 1:9.7.3.dfsg-1~squeeze6. For the testing distribution (wheezy), this problem will be fixed soon. For the unstable distribution (sid), this problem has been fixed in version 1:9.8.1.dfsg.P1-4.2. We recommend that you upgrade your bind9 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . An important security update for Bind9 has been released, targeting a denial of service vulnerability that arises when cached data is utilized for validation under heavy traffic conditions.. Debian Security Advisory, Bind9 Denial of Service, DNSSEC. . LinuxSecurity.com Team

Calendar%202 Jul 30, 2012 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200