Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 490
Alerts This Week
Warning Icon 1 490

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 41 articles for you...
197

Debian LTS dpkg Severe Directory Access Permissions DoS Concern DLA-4673-1

A vulnerability have been discovered in dpkg, the Debian package manager (dpkg is the low-level tool that actually installs or removes packages). CVE-2025-6297 It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary. Debian LTS Advisory DLA-4673-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Arnaud Rebillout July 08, 2026 https://wiki.debian.org/LTS Package : dpkg Version : 1.20.14 CVE ID : CVE-2025-6297 Debian Bug : 1061404 1065575 1107971 1108192 A vulnerability have been discovered in dpkg, the Debian package manager (dpkg is the low-level tool that actually installs or removes packages). CVE-2025-6297 It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is documented as being a safe operation even on untrusted data. This may result in leaving temporary files behind on cleanup. Given automated and repeated execution of dpkg-deb commands on adversarial .deb packages or with well compressible files, placed inside a directory with permissions not allowing removal by a non-root user, this can end up in a DoS scenario due to causing disk quota exhaustion or disk full conditions. Additionally, this version includes some minor security fixes that didn't receive a CVE number, but were reported on the Debian bug tracker, see the list of Debian bugs above. For Debian 11 bullseye, this problem has been fixed in version 1.20.14. We recommend that you upgrade your dpkg packages. For the detailed security status of dpkg please refer to its security tracker page at: https://security-tracker.debian.org/tracker/dpkg Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Acritical security advisory discussing a DoS threat and inadequate permissions in dpkg for Debian LTS.. Debian LTS security, DoS scenario, dpkg permissions, critical update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 08, 2026 Critical Debian LTS
100

SUSE Linux Enterprise Server 16.0 Dpkg Moderate DoS Vuln 2026-22085-1

An update that solves one vulnerability can now be installed.. # Security update for dpkg Announcement ID: SUSE-SU-2026:22085-1 Release Date: 2026-06-05T13:47:06Z Rating: moderate References: * bsc#1259385 Cross-References: * CVE-2026-2219 CVSS scores: * CVE-2026-2219 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-2219 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-2219 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for dpkg fixes the following issue: * CVE-2026-2219: dpkg-deb: malformed .deb archives can cause a denial of service (bsc#1259385). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-894=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-894=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * dpkg-debugsource-1.22.21-160000.3.1 * update-alternatives-debuginfo-1.22.21-160000.3.1 * update-alternatives-1.22.21-160000.3.1 * dpkg-debuginfo-1.22.21-160000.3.1 * dpkg-devel-1.22.21-160000.3.1 * update-alternatives-debugsource-1.22.21-160000.3.1 * dpkg-1.22.21-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * dpkg-lang-1.22.21-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dpkg-debugsource-1.22.21-160000.3.1 * update-alternatives-debuginfo-1.22.21-160000.3.1 * update-alternatives-1.22.21-160000.3.1 * dpkg-debuginfo-1.22.21-160000.3.1 *dpkg-devel-1.22.21-160000.3.1 * update-alternatives-debugsource-1.22.21-160000.3.1 * dpkg-1.22.21-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * dpkg-lang-1.22.21-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2219.html * https://bugzilla.suse.com/show_bug.cgi?id=1259385 . Security update for dpkg in SUSE addresses moderate vulnerability causing denial of service. Installation recommendations provided.. SUSE Linux, dpkg security, update management, security patch, Linux vulnerabilities. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 15, 2026 moderate SuSE
100

SUSE Linux Micro 6.2 dpkg Moderate Denial of Service Fix 2026-22046-1

An update that solves one vulnerability can now be installed.. # Security update for dpkg Announcement ID: SUSE-SU-2026:22046-1 Release Date: 2026-06-05T13:44:58Z Rating: moderate References: * bsc#1259385 Cross-References: * CVE-2026-2219 CVSS scores: * CVE-2026-2219 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-2219 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-2219 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for dpkg fixes the following issue: * CVE-2026-2219: dpkg-deb: malformed .deb archives can cause a denial of service (bsc#1259385). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-894=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * update-alternatives-debugsource-1.22.21-160000.3.1 * update-alternatives-1.22.21-160000.3.1 * update-alternatives-debuginfo-1.22.21-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2219.html * https://bugzilla.suse.com/show_bug.cgi?id=1259385 . A security update for SUSE Linux Micro 6.2 addressing moderate issues in dpkg to prevent denial of service attacks.. SUSE Linux Micro 6.2, dpkg update, moderate security fix. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 09, 2026 moderate SuSE
202

openSUSE Leap 16.0 dpkg Moderate DoS Vulnerability Fix 2026-20909-1

An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for dpkg ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20909-1 Rating: moderate References: * bsc#1259385 Cross-References: * CVE-2026-2219 CVSS scores: * CVE-2026-2219 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-2219 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for dpkg fixes the following issue: - CVE-2026-2219: dpkg-deb: malformed .deb archives can cause a denial of service (bsc#1259385). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-894=1 Package List: - openSUSE Leap 16.0: dpkg-1.22.21-160000.3.1 dpkg-devel-1.22.21-160000.3.1 dpkg-lang-1.22.21-160000.3.1 update-alternatives-1.22.21-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-2219.html . Install openSUSE's latest security update for dpkg addressing a moderate issue and improving system stability. . openSUSE security, dpkg update, denial of service, moderate security fix. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 08, 2026 moderate OpenSUSE
202

openSUSE dpkg Moderate Denial of Service Fix Advisory 2026-20909-1

An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for dpkg ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20909-1 Rating: moderate References: * bsc#1259385 Cross-References: * CVE-2026-2219 CVSS scores: * CVE-2026-2219 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-2219 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for dpkg fixes the following issue: - CVE-2026-2219: dpkg-deb: malformed .deb archives can cause a denial of service (bsc#1259385). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-894=1 Package List: - openSUSE Leap 16.0: dpkg-1.22.21-160000.3.1 dpkg-devel-1.22.21-160000.3.1 dpkg-lang-1.22.21-160000.3.1 update-alternatives-1.22.21-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-2219.html . This update for openSUSE resolves moderate issues with dpkg, addressing CVE-2026-2219 and improving system stability.. openSUSE patches, dpkg security update, CVE-2026-2219, Linux vulnerabilities, security fixes. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 08, 2026 moderate OpenSUSE
203

Mageia 9 dpkg Critical Denial of Service Advisory MGASA-2026-0144

MGASA-2026-0144 - Updated dpkg packages fix security vulnerabilities. MGASA-2026-0144 - Updated dpkg packages fix security vulnerabilities Publication date: 16 May 2026 URL: https://advisories.mageia.org/MGASA-2026-0144.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-2219 Description: It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU). References: - https://bugs.mageia.org/show_bug.cgi?id=35489 - https://lists.opensuse.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/3QFBK2ZJ4T5BTAWBSDBQLVRZQKJEAJEX/ - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2219 SRPMS: - 9/core/dpkg-1.22.22-1.mga9 . Critical advisory for Mageia 9 addressing dpkg security flaws that may lead to denial of service. Immediate action required.. Mageia security, dpkg update, denial of service, critical vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 16, 2026 Critical Mageia
172

Ubuntu 25.10 dpkg Important Denial of Service Risk USN-8249-1

dpkg could be made to stop responding if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-8249-1 May 07, 2026 dpkg vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS Summary: dpkg could be made to stop responding if it opened a specially crafted file. Software Description: - dpkg: Debian package management system Details: Yashashree Gund discovered that the dpkg dpkg-deb tool incorrectly handled certain zstd-compressed .deb archives. If a user or automated system were tricked into manipulating a specially crafted .deb archive, a remote attacker could possibly use this issue to cause dpkg-deb to stop responding, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 dpkg 1.22.21ubuntu3.2 Ubuntu 24.04 LTS dpkg 1.22.6ubuntu6.6 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8249-1 CVE-2026-2219 Package Information: https://launchpad.net/ubuntu/+source/dpkg/1.22.21ubuntu3.2 https://launchpad.net/ubuntu/+source/dpkg/1.22.6ubuntu6.6 . dpkg exposes Ubuntu to DoS risks through specially crafted files. Update to mitigate this issue.. dpkg vulnerability, Ubuntu security, system update, denial of service, security patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 07, 2026 Important Ubuntu
202

openSUSE Tumbleweed dpkg Moderate Update Threat CVE-2026-2219 2026-10675-1

An update that solves one vulnerability can now be installed.. # dpkg-1.22.22-1.1 on GA media Announcement ID: openSUSE-SU-2026:10675-1 Rating: moderate Cross-References: * CVE-2026-2219 CVSS scores: * CVE-2026-2219 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-2219 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the dpkg-1.22.22-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * dpkg 1.22.22-1.1 * dpkg-devel 1.22.22-1.1 * dpkg-lang 1.22.22-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2219.html . An update for openSUSE Tumbleweed dpkg addresses a moderate security risk. Learn more about the details and installation.. openSUSE updates, dpkg security, moderate threat assessment, Linux package management, software vulnerabilities. . LinuxSecurity.com Team

Calendar%202 May 05, 2026 OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200