Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 468
Alerts This Week
Warning Icon 1 468

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 36 articles for you...
89

Fedora 42: Drupal7 Important Security Update FEDORA-2025-f8a08bb335

https:// https:// https:// https:// https://. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-f8a08bb335 2025-11-29 17:02:16.261291+00:00 -------------------------------------------------------------------------------- Name : drupal7 Product : Fedora 42 Version : 7.103 Release : 1.fc42 URL : https:// Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. -------------------------------------------------------------------------------- Update Information: https:// https:// https:// https:// https:// https:// https:// -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 19 2025 Shawn Iwinski - 7.103-1 - Update to 7.103 (RHBZ #2253220) - SA-CORE-2024-005 / CVE-2024-55635 - SA-CORE-2024-008 / CVE-2024-55638 * Wed Jul 23 2025 Fedora Release Engineering - 7.98-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2253220 - drupal7-7.103 is available https://bugzilla.redhat.com/show_bug.cgi?id=2253220 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f8a08bb335' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Drupal 7.103 update for Fedora 42 addresses critical issues and enhances security features. Upgrade recommended.. Fedora 42 update, Drupal 7.103 security, Fedora advisory, content management security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 29, 2025 Important Fedora
89

Fedora 43: Crucial Security Update for Drupal 7 on CVE-2024-55635

https:// https:// https:// https:// https://. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-355d5aac01 2025-11-29 16:43:28.332599+00:00 -------------------------------------------------------------------------------- Name : drupal7 Product : Fedora 43 Version : 7.103 Release : 1.fc43 URL : https:// Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. -------------------------------------------------------------------------------- Update Information: https:// https:// https:// https:// https:// https:// https:// -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 19 2025 Shawn Iwinski - 7.103-1 - Update to 7.103 (RHBZ #2253220) - SA-CORE-2024-005 / CVE-2024-55635 - SA-CORE-2024-008 / CVE-2024-55638 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2253220 - drupal7-7.103 is available https://bugzilla.redhat.com/show_bug.cgi?id=2253220 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-355d5aac01' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Critical update for Drupal7 on Fedora 43 addressing security issues including CVE-2024-55635. Install promptly!. Drupal Update, Fedora Security, Content Management, PHP Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 29, 2025 Important Fedora
89

Fedora 41: drupal7 Critical Update SA-CORE-2024-005 CVE-2024-55635

https:// https:// https:// https:// https://. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-d645721ca4 2025-11-29 16:05:06.047940+00:00 -------------------------------------------------------------------------------- Name : drupal7 Product : Fedora 41 Version : 7.103 Release : 1.fc41 URL : https:// Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. -------------------------------------------------------------------------------- Update Information: https:// https:// https:// https:// https:// https:// https:// -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 19 2025 Shawn Iwinski - 7.103-1 - Update to 7.103 (RHBZ #2253220) - SA-CORE-2024-005 / CVE-2024-55635 - SA-CORE-2024-008 / CVE-2024-55638 * Wed Jul 23 2025 Fedora Release Engineering - 7.98-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Thu Jan 16 2025 Fedora Release Engineering - 7.98-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Wed Aug 28 2024 Miroslav Such - 7.98-5 - convert license to SPDX -------------------------------------------------------------------------------- References: [ 1 ] Bug #2253220 - drupal7-7.103 is available https://bugzilla.redhat.com/show_bug.cgi?id=2253220 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-d645721ca4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical Fedora update released for drupal7 addressing core vulnerabilities with strong recommendations for installation.. Fedora security advisory, drupal7 update, software vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 29, 2025 Critical Fedora
172

Ubuntu 14.04 LTS: USN-6981-2 Critical Remote Code Execution Threats

Drupal could be made to crash or run programs if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-6981-2 September 03, 2024 drupal7 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Drupal could be made to crash or run programs if it received specially crafted network traffic. Software Description: - drupal7: fully-featured content management framework Details: USN-6981-1 fixed vulnerabilities in Drupal. This update provides the corresponding updates for Ubuntu 14.04 LTS. Original advisory details: It was discovered that Drupal incorrectly sanitized uploaded filenames. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2020-13671) It was discovered that Drupal incorrectly sanitized archived filenames. A remote attacker could possibly use this issue to overwrite arbitrary files, or execute arbitrary code. (CVE-2020-28948, CVE-2020-28949) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS drupal7 7.26-1ubuntu0.1+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6981-2 https://ubuntu.com/security/notices/USN-6981-1 CVE-2020-13671, CVE-2020-28948, CVE-2020-28949 . Alert Announcement USN-6982-1 addresses critical security weaknesses in Drupal 7 for Ubuntu 14.04 LTS, implementing essential updates to safeguard network transmission issues.. Drupal Security, Remote Code Execution, Update Instructions. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 03, 2024 Critical Ubuntu
89

Fedora 38 Drupal7 2023-F4D22F8A92 Critical: File Download Sanitation

- [7.98]() - [7.97]() - [7.96]() - [SA- CORE-2023-005]() - [7.95]() - [SA-. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-f4d22f8a92 2023-10-04 15:50:14.488586 -------------------------------------------------------------------------------- Name : drupal7 Product : Fedora 38 Version : 7.98 Release : 1.fc38 URL : Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. -------------------------------------------------------------------------------- Update Information: - [7.98]() - [7.97]() - [7.96]() - [SA- CORE-2023-005]() - [7.95]() - [SA- CORE-2023-004]() - [7.94]() - [7.93]() -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 26 2023 Shawn Iwinski - 7.98-1 - Update to 7.98 (RHBZ #2217253) - SA-CORE-2023-004 - SA-CORE-2023-005 (RHBZ #2188106, 2188107, 2188108) * Wed Jul 19 2023 Fedora Release Engineering - 7.92-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2188107 - drupal7: drupal: File download facility doesn't sufficiently sanitize file paths [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2188107 [ 2 ] Bug #2188108 - drupal7: drupal: File download facility doesn't sufficiently sanitize file paths [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=2188108 [ 3 ] Bug #2217253 - drupal7-7.98 is available https://bugzilla.redhat.com/show_bug.cgi?id=2217253 -------------------------------------------------------------------------------- This update can beinstalled with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-f4d22f8a92' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 38 releases drupal7 update addressing vital file validation flaw in version 7.98 to bolster security.. drupal update, fedora security, content management system, file sanitation, open source software. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 04, 2023 Critical Fedora
89

Fedora 37: FEDORA-2023-83aeb73043 Moderate: Drupal 7 Security Update

- [7.98]() - [7.97]() - [7.96]() - [SA- CORE-2023-005]() - [7.95]() - [SA-. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-83aeb73043 2023-10-04 15:47:53.759443 -------------------------------------------------------------------------------- Name : drupal7 Product : Fedora 37 Version : 7.98 Release : 1.fc37 URL : Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. -------------------------------------------------------------------------------- Update Information: - [7.98]() - [7.97]() - [7.96]() - [SA- CORE-2023-005]() - [7.95]() - [SA- CORE-2023-004]() - [7.94]() - [7.93]() -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 26 2023 Shawn Iwinski - 7.98-1 - Update to 7.98 (RHBZ #2217253) - SA-CORE-2023-004 - SA-CORE-2023-005 (RHBZ #2188106, 2188107, 2188108) * Wed Jul 19 2023 Fedora Release Engineering - 7.92-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Thu Jan 19 2023 Fedora Release Engineering - 7.92-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2188107 - drupal7: drupal: File download facility doesn't sufficiently sanitize file paths [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2188107 [ 2 ] Bug #2188108 - drupal7: drupal: File download facility doesn't sufficiently sanitize file paths [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=2188108 [ 3 ] Bug #2217253 - drupal7-7.98 is available https://bugzilla.redhat.com/show_bug.cgi?id=2217253 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-83aeb73043' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The recent upgrade of Drupal 7 on Fedora 37 effectively tackles numerous security vulnerabilities in a swift and resourceful manner.. Drupal Update, Security Notification, Fedora Package Management, Content Management System. . LinuxSecurity.com Team

Calendar%202 Oct 04, 2023 Fedora
89

Fedora 35 Drupal7: 2022-bf18450366 Moderate Input Validation Threat

- [7.92]() - [7.91]() - [SA-CORE-2022-012 / CVE-2022-25275]() - [7.90]() - [7.89]() -. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-bf18450366 2022-11-03 15:30:27.308055 --------------------------------------------------------------------------------Name : drupal7 Product : Fedora 35 Version : 7.92 Release : 1.fc35 URL : Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. --------------------------------------------------------------------------------Update Information: - [7.92]() -[7.91]() - [SA-CORE-2022-012 / CVE-2022-25275]() -[7.90]() -[7.89]() -[7.88]() - [SA-CORE-2022-003 / CVE-2022-25271]() -[7.87]() -[7.86]() - [SA-CORE-2022-001 / CVE-2021-41184]() -[SA-CORE-2022-002 / CVE-2021-41182 / CVE-2021-41183 / CVE-2016-7103 / CVE-2010-5312]() -[7.85]() -[7.84]() -[7.83]() --------------------------------------------------------------------------------ChangeLog: * Sat Oct 15 2022 Shawn Iwinski - 7.92-1 - Update to 7.92 - SA-CORE-2022-012 / CVE-2022-25275 - SA-CORE-2022-003 / CVE-2022-25271 (RHBZ #2055472, 2055473) - SA-CORE-2022-001 / CVE-2021-41184 - SA-CORE-2022-002 / CVE-2021-41182 / CVE-2021-41183 * Thu Jul 21 2022 Fedora Release Engineering - 7.82-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Thu Jan 20 2022 Fedora Release Engineering - 7.82-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2055473 - CVE-2022-25271 drupal7: drupal: improper input validation found via drupal core api [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2055473 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-bf18450366' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Keep up to date with the Fedora 36 update on drupal8, which addresses serious security vulnerabilities in input validation protocols.. Fedora Update,Fedora 35,Drupal Security,drupal7 Update,Content Management System. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 03, 2022 Important Fedora
197

Debian 9: DLA-2721-1 Critical: Drupal7 Archive_Tar Security Issue

The Drupal project uses the pear Archive_Tar library, which has released a security update that impacts Drupal. The vulnerability is mitigated by the fact that Drupal core's use of . ------------------------------------------------------------------------- Debian LTS Advisory DLA-2721-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Gunnar Wolf July 26, 2021 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : drupal7 Version : 7.52-2+deb9u16 CVE ID : CVE-2021-32610 The Drupal project uses the pear Archive_Tar library, which has released a security update that impacts Drupal. The vulnerability is mitigated by the fact that Drupal core's use of the Archive_Tar library is not vulnerable, as it does not permit symlinks. Exploitation may be possible if contrib or custom code uses the library to extract tar archives (for example .tar, .tar.gz, .bz2, or .tlz) which come from a potentially untrusted source. For Debian 9 stretch, this problem has been fixed in version 7.52-2+deb9u16. We recommend that you upgrade your drupal7 packages. For the detailed security status of drupal7 please refer to its security tracker page at: Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2722-1 informs about a security update for drupal8, aimed at fixing possible threats.. Debian LTS, Drupal Security, Archive Tar, Security Advisory, Debian Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 26, 2021 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200