Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
89

Fedora 43 xmlstarlet Important XML Entity Issue Fix FEDORA-2026-3c78c99467

Fixes XML external entity vulnerability. For more information, refer to https://src.fedoraproject.org/rpms/xmlstarlet/pull-request/4.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3c78c99467 2026-06-11 01:08:40.189444+00:00 -------------------------------------------------------------------------------- Name : xmlstarlet Product : Fedora 43 Version : 1.6.1 Release : 30.fc43 URL : http://xmlstar.sourceforge.net/ Summary : Command Line XML Toolkit Description : XMLStarlet is a set of command line utilities which can be used to transform, query, validate, and edit XML documents and files using simple set of shell commands in similar way it is done for plain text files using UNIX grep, sed, awk, diff, patch, join, etc commands. -------------------------------------------------------------------------------- Update Information: Fixes XML external entity vulnerability. For more information, refer to https://src.fedoraproject.org/rpms/xmlstarlet/pull-request/4. -------------------------------------------------------------------------------- ChangeLog: * Wed May 27 2026 Vitezslav Crhonek - 1.6.1-30 - Fix XXE (XML External Entity) vulnerability * Sat Jan 17 2026 Fedora Release Engineering - 1.6.1-29 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3c78c99467' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fixes XML external entity threat in xmlstarlet for Fedora 43. Stay updated and secure your systems.. xmlstarlet security, Fedora updates, external entity vulnerability, command line toolkit, software patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 10, 2026 Important Fedora
89

Fedora 44 XMLStarlet Critical XML Entity Issue Vuln 2026-dbf44e0b72

Fixes XML external entity vulnerability. For more information, refer to https://src.fedoraproject.org/rpms/xmlstarlet/pull-request/4.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-dbf44e0b72 2026-06-11 00:54:51.286484+00:00 -------------------------------------------------------------------------------- Name : xmlstarlet Product : Fedora 44 Version : 1.6.1 Release : 30.fc44 URL : http://xmlstar.sourceforge.net/ Summary : Command Line XML Toolkit Description : XMLStarlet is a set of command line utilities which can be used to transform, query, validate, and edit XML documents and files using simple set of shell commands in similar way it is done for plain text files using UNIX grep, sed, awk, diff, patch, join, etc commands. -------------------------------------------------------------------------------- Update Information: Fixes XML external entity vulnerability. For more information, refer to https://src.fedoraproject.org/rpms/xmlstarlet/pull-request/4. -------------------------------------------------------------------------------- ChangeLog: * Wed May 27 2026 Vitezslav Crhonek - 1.6.1-30 - Fix XXE (XML External Entity) vulnerability -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-dbf44e0b72' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. Tounsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fixes XML external entity issue in xmlstarlet for Fedora 44 with update instructions. Learn more about the patch.. xmlstarlet security update, Fedora XML issue, XML external entity fix, xmlstarlet vulnerability patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 10, 2026 Important Fedora
100

SUSE Linux Micro 6.0: 2025:20116-1 important: libxml2 XML threat

* bsc#1234812 Cross-References: * CVE-2024-40896 . # Security update for libxml2 Announcement ID: SUSE-SU-2025:20116-1 Release Date: 2025-02-03T09:20:59Z Rating: important References: * bsc#1234812 Cross-References: * CVE-2024-40896 CVSS scores: * CVE-2024-40896 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2024-40896 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2024-40896 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for libxml2 fixes the following issues: * CVE-2024-40896: Fixed XML external entity vulnerability (bsc#1234812) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-188=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libxml2-2-2.11.6-4.1 * libxml2-tools-debuginfo-2.11.6-4.1 * libxml2-debugsource-2.11.6-4.1 * libxml2-tools-2.11.6-4.1 * libxml2-2-debuginfo-2.11.6-4.1 ## References: * https://www.suse.com/security/cve/CVE-2024-40896.html * https://bugzilla.suse.com/show_bug.cgi?id=1234812 . Important revision for libxml2 fixes a vulnerability related to XML external entities in SUSE Linux Micro, boosting overall system security.. SUSE Linux Micro, libxml2 security fix, important security update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 04, 2025 Important SuSE
100

SUSE: 2021:0243-1 Moderate: jackson-databind External Entity Fix

An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for jackson-databind ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0243-1 Rating: moderate References: #1177616 #1180391 #1181118 Cross-References: CVE-2020-25649 CVE-2020-35728 CVE-2021-20190 Affected Products: SUSE Linux Enterprise Module for Development Tools 15-SP2 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for jackson-databind fixes the following issues: jackson-databind was updated to 2.10.5.1: * #2589: `DOMDeserializer`: setExpandEntityReferences(false) may not prevent external entity expansion in all cases (CVE-2020-25649, bsc#1177616) * #2787 (partial fix): NPE after add mixin for enum * #2679: 'ObjectMapper.readValue("123", Void.TYPE)' throws "should never occur" Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Development Tools 15-SP2: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP2-2021-243=1 Package List: - SUSE Linux Enterprise Module for Development Tools 15-SP2 (noarch): jackson-databind-2.10.5.1-3.3.2 References: https://www.suse.com/security/cve/CVE-2020-25649.html https://www.suse.com/security/cve/CVE-2020-35728.html https://www.suse.com/security/cve/CVE-2021-20190.html https://bugzilla.suse.com/1177616 https://bugzilla.suse.com/1180391 https://bugzilla.suse.com/1181118 . Resolved vulnerabilities in jackson-databind with SUSE Security Update: SUSE-SU-2021:0244-1, addressing four concerns now implemented.. SUSE Linux,jackson-databind, security update, development tools, external entity fix. . LinuxSecurity.com Team

Calendar%202 Jan 29, 2021 SuSE
202

openSUSE: 2020:1204-1 moderate: perl-XML-Twig Security Fix

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for perl-XML-Twig ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1204-1 Rating: moderate References: #1008644 Cross-References: CVE-2016-9180 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for perl-XML-Twig fixes the following issues: - Security fix [bsc#1008644, CVE-2016-9180] * Setting expand_external_ents to 0 or -1 currently doesn't work as expected; To completely turn off expanding external entities use no_xxe. * Update documentation for XML::Twig to mention problems with expand_external_ents and add information about new no_xxe argument This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2020-1204=1 Package List: - openSUSE Leap 15.2 (noarch): perl-XML-Twig-3.52-lp152.4.3.1 References: https://www.suse.com/security/cve/CVE-2016-9180.html https://bugzilla.suse.com/1008644 -- . The latest openSUSE Security Patch for perl-XML-Twig addresses a vulnerability concerning external entity expansion.. perl XML Twig, security update, openSUSE fix, software patch. . LinuxSecurity.com Team

Calendar%202 Aug 14, 2020 OpenSUSE
200

Scientific Linux SL7: SLSA-2017:2492-1 Moderate: xmlsec1 DoS Risk

It was discovered xmlsec1's use of libxml2 inadvertently enabled external entity expansion (XXE) along with validation. An attacker could craft an XML file that would cause xmlsec1 to try and read local files or HTTP/FTP URLs, leading to information disclosure or denial of service. (CVE-2017-1000061) SL7 x86_64 xmlsec1-1.2.20-7.el7_4.i686.rpm xmlsec1-1.2.20-7.el7_4.x86_64.rpm xm [More...]. Synopsis: Moderate: xmlsec1 security update Advisory ID: SLSA-2017:2492-1 Issue Date: 2017-08-21 CVE Numbers: CVE-2017-1000061 -- Security Fix(es): * It was discovered xmlsec1's use of libxml2 inadvertently enabled external entity expansion (XXE) along with validation. An attacker could craft an XML file that would cause xmlsec1 to try and read local files or HTTP/FTP URLs, leading to information disclosure or denial of service. (CVE-2017-1000061) -- SL7 x86_64 xmlsec1-1.2.20-7.el7_4.i686.rpm xmlsec1-1.2.20-7.el7_4.x86_64.rpm xmlsec1-debuginfo-1.2.20-7.el7_4.i686.rpm xmlsec1-debuginfo-1.2.20-7.el7_4.x86_64.rpm xmlsec1-openssl-1.2.20-7.el7_4.i686.rpm xmlsec1-openssl-1.2.20-7.el7_4.x86_64.rpm xmlsec1-devel-1.2.20-7.el7_4.i686.rpm xmlsec1-devel-1.2.20-7.el7_4.x86_64.rpm xmlsec1-gcrypt-1.2.20-7.el7_4.i686.rpm xmlsec1-gcrypt-1.2.20-7.el7_4.x86_64.rpm xmlsec1-gcrypt-devel-1.2.20-7.el7_4.i686.rpm xmlsec1-gcrypt-devel-1.2.20-7.el7_4.x86_64.rpm xmlsec1-gnutls-1.2.20-7.el7_4.i686.rpm xmlsec1-gnutls-1.2.20-7.el7_4.x86_64.rpm xmlsec1-gnutls-devel-1.2.20-7.el7_4.i686.rpm xmlsec1-gnutls-devel-1.2.20-7.el7_4.x86_64.rpm xmlsec1-nss-1.2.20-7.el7_4.i686.rpm xmlsec1-nss-1.2.20-7.el7_4.x86_64.rpm xmlsec1-nss-devel-1.2.20-7.el7_4.i686.rpm xmlsec1-nss-devel-1.2.20-7.el7_4.x86_64.rpm xmlsec1-openssl-devel-1.2.20-7.el7_4.i686.rpm xmlsec1-openssl-devel-1.2.20-7.el7_4.x86_64.rpm - Scientific Linux Development Team . A recent xmlsec1 update for Scientific Linux mitigates vulnerabilities related to external entity expansion thatcould result in data leakage.. xmlsec1, Scientific Linux, libxml2 security, external entity vulnerability, DoS risk. . LinuxSecurity.com Team

Calendar%202 Aug 21, 2017 Scientific Linux
197

Debian: DLA-1008-1 Moderate: Libxml2 Heap Over-Read Warning

CVE-2017-7375 Missing validation for external entities in xmlParsePEReference CVE-2017-9047 . Hash: SHA512 Package : libxml2 Version : 2.8.0+dfsg1-7+wheezy8 CVE ID : CVE-2017-7375 CVE-2017-9047 CVE-2017-9048 CVE-2017-9049 CVE-2017-9050 CVE-2017-7375 Missing validation for external entities in xmlParsePEReference CVE-2017-9047 CVE-2017-9048 A buffer overflow was discovered in libxml2 20904-GITv2.9.4-16-g0741801. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. The variable len is assigned strlen(buf). If the content-> type is XML_ELEMENT_CONTENT_ELEMENT, then (i) the content-> prefix is appended to buf (if it actually fits) whereupon (ii) content-> name is written to the buffer. However, the check for whether the content-> name actually fits also uses 'len' rather than the updated buffer length strlen(buf). This allows us to write about "size" many bytes beyond the allocated memory. This vulnerability causes programs that use libxml2, such as PHP, to crash. CVE-2017-9049 CVE-2017-9050 libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for libxml2 Bug 759398. For Debian 7 "Wheezy", these problems have been fixed in version 2.8.0+dfsg1-7+wheezy8. We recommend that you upgrade your libxml2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance libxml2 to address critical vulnerabilities impacting Debian Wheezy. Discover additional insights on enhancements and remedies.. libxml2 Update, Debian Security, BufferOverflow, Heap Over-Read. . LinuxSecurity.com Team

Calendar%202 Jun 30, 2017 Debian LTS
89

Fedora 22: 2016-250042b8a6 Critical: XStream External Entity Issue

Security fix for CVE-2016-3674. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-250042b8a6 2016-04-26 16:44:25.072543 -------------------------------------------------------------------------------- Name : xstream Product : Fedora 22 Version : 1.4.9 Release : 1.fc22 URL : Summary : Java XML serialization library Description : XStream is a simple library to serialize objects to XML and back again. A high level facade is supplied that simplifies common use cases. Custom objects can be serialized without need for specifying mappings. Speed and low memory footprint are a crucial part of the design, making it suitable for large object graphs or systems with high message throughput. No information is duplicated that can be obtained via reflection. This results in XML that is easier to read for humans and more compact than native Java serialization. XStream serializes internal fields, including private and final. Supports non-public and inner classes. Classes are not required to have default constructor. Duplicate references encountered in the object-model will be maintained. Supports circular references. By implementing an interface, XStream can serialize directly to/from any tree structure (not just XML). Strategies can be registered allowing customization of how particular types are represented as XML. When an exception occurs due to malformed XML, detailed diagnostics are provided to help isolate and fix the problem. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-3674 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1321789 - CVE-2016-3674 XStream: enabled processing of external entities https://bugzilla.redhat.com/show_bug.cgi?id=1321789 -------------------------------------------------------------------------------- This update can be installed with the "yum"update program. Use su -c 'yum update xstream' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Essential update for Fedora's xstream tackling CVE-2016-3674 featuring enhanced XML serialization techniques.. xstream security,Fedora updates,security fix,Java XML serialization. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 26, 2016 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200