Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 28 articles for you...
217

Oracle Linux 10 Flatpak Important Security Advisory ELSA-2026-21757

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-21757 http://linux.oracle.com/errata/ELSA-2026-21757.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: flatpak-1.16.0-9.el10_2.1.x86_64.rpm flatpak-devel-1.16.0-9.el10_2.1.x86_64.rpm flatpak-libs-1.16.0-9.el10_2.1.x86_64.rpm flatpak-selinux-1.16.0-9.el10_2.1.noarch.rpm flatpak-session-helper-1.16.0-9.el10_2.1.x86_64.rpm aarch64: flatpak-1.16.0-9.el10_2.1.aarch64.rpm flatpak-devel-1.16.0-9.el10_2.1.aarch64.rpm flatpak-libs-1.16.0-9.el10_2.1.aarch64.rpm flatpak-selinux-1.16.0-9.el10_2.1.noarch.rpm flatpak-session-helper-1.16.0-9.el10_2.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/flatpak-1.16.0-9.el10_2.1.src.rpm Related CVEs: CVE-2026-34078 CVE-2026-34079 Description of changes: [1.16.0-9.1] - Fix arbitrary code execution via crafted symlinks in sandbox-expose options Resolves: RHEL-165630 - Fix arbitrary file deletion on host via improper cache file path validation Resolves: RHEL-170157 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 10 security advisory addresses important flatpak updates fixing code execution and file deletion issues.. Oracle Linux Security, flatpak update, code execution fix, Linux package management, security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 17, 2026 Important Oracle
202

openSUSE xdg-desktop-portal Moderate File Deletion Vuln 2026-2712-1

An update that solves one vulnerability can now be installed.. # Security update for xdg-desktop-portal Announcement ID: SUSE-SU-2026:2712-1 Release Date: 2026-06-30T12:01:01Z Rating: moderate References: * bsc#1262045 Cross-References: * CVE-2026-40354 CVSS scores: * CVE-2026-40354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-40354 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40354 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for xdg-desktop-portal fixes the following issue: * CVE-2026-40354: File deletion via symlink attack (bsc#1262045). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2712=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2712=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * xdg-desktop-portal-debugsource-1.18.2-150600.4.6.1 * xdg-desktop-portal-1.18.2-150600.4.6.1 * xdg-desktop-portal-debuginfo-1.18.2-150600.4.6.1 * xdg-desktop-portal-devel-1.18.2-150600.4.6.1 * openSUSE Leap 15.6 (noarch) * xdg-desktop-portal-lang-1.18.2-150600.4.6.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * xdg-desktop-portal-debugsource-1.18.2-150600.4.6.1 * xdg-desktop-portal-1.18.2-150600.4.6.1 * xdg-desktop-portal-debuginfo-1.18.2-150600.4.6.1 *xdg-desktop-portal-devel-1.18.2-150600.4.6.1 * Desktop Applications Module 15-SP7 (noarch) * xdg-desktop-portal-lang-1.18.2-150600.4.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40354.html * https://bugzilla.suse.com/show_bug.cgi?id=1262045 . Update resolves moderate risk posed by CVE-2026-40354 affecting xdg-desktop-portal in openSUSE.. xdg-desktop-portal security update, openSUSE CVE-2026-40354, patch xdg-desktop-portal, file deletion vulnerability, moderate severity patch. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 moderate OpenSUSE
100

SUSE xdg-desktop-portal Moderate File Deletion Attack Vuln 2026-2712-1

An update that solves one vulnerability can now be installed.. # Security update for xdg-desktop-portal Announcement ID: SUSE-SU-2026:2712-1 Release Date: 2026-06-30T12:01:01Z Rating: moderate References: * bsc#1262045 Cross-References: * CVE-2026-40354 CVSS scores: * CVE-2026-40354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-40354 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40354 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for xdg-desktop-portal fixes the following issue: * CVE-2026-40354: File deletion via symlink attack (bsc#1262045). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2712=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2712=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * xdg-desktop-portal-debugsource-1.18.2-150600.4.6.1 * xdg-desktop-portal-1.18.2-150600.4.6.1 * xdg-desktop-portal-debuginfo-1.18.2-150600.4.6.1 * xdg-desktop-portal-devel-1.18.2-150600.4.6.1 * openSUSE Leap 15.6 (noarch) * xdg-desktop-portal-lang-1.18.2-150600.4.6.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * xdg-desktop-portal-debugsource-1.18.2-150600.4.6.1 * xdg-desktop-portal-1.18.2-150600.4.6.1 * xdg-desktop-portal-debuginfo-1.18.2-150600.4.6.1 *xdg-desktop-portal-devel-1.18.2-150600.4.6.1 * Desktop Applications Module 15-SP7 (noarch) * xdg-desktop-portal-lang-1.18.2-150600.4.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40354.html * https://bugzilla.suse.com/show_bug.cgi?id=1262045 . Update for xdg-desktop-portal addresses moderate risk of file deletion via symlink attack in SUSE Linux.. SUSE Linux Security Patch XDG Desktop Portal Update. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 moderate SuSE
172

Ubuntu Robocode Critical Security Issues 2019-10648 CVE-2019-10648

Several security issues were fixed in Robocode.. ========================================================================== Ubuntu Security Notice USN-8385-1 June 04, 2026 robocode vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Robocode. Software Description: - robocode: An engaging and educational programming game Details: It was discovered that Robocode could be tricked into making network requests to attacker-controlled systems. An attacker could possibly use this issue to cause external service interaction, resulting in information disclosure. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-10648) Lim Sim Yee discovered that Robocode did not properly validate file paths in the CacheCleaner component. An attacker could possibly use this issue to delete arbitrary files. (CVE-2025-14306) Lim Sim Yee discovered that Robocode did not securely create temporary files in the AutoExtract component. An attacker could possibly use this issue to manipulate temporary files, resulting in arbitrary code execution. (CVE-2025-14307) Lim Sim Yee discovered that Robocode did not properly validate data lengths in the Buffer class. An attacker could possibly use this issue to trigger an integer overflow, resulting in arbitrary code execution. (CVE-2025-14308) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS robocode 1.9.3.9-4ubuntu0.26.04.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS robocode 1.9.3.9-3ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS robocode 1.9.3.9-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS robocode 1.9.3.7-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS robocode 1.9.3.1-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS robocode 1.9.2.5-2ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8385-1 CVE-2019-10648, CVE-2025-14306, CVE-2025-14307, CVE-2025-14308 . Several vulnerabilities in Robocode could lead to external service interactions, file deletion, or arbitrary code execution.. Ubuntu Security, Robocode Vulnerabilities, Critical Ubuntu Advisory, Security Fixes, Information Disclosure. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 05, 2026 Critical Ubuntu
217

Oracle Linux 8 Flatpak Critical Code Execution File Removal ELSA-2026-21756

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-21756 http://linux.oracle.com/errata/ELSA-2026-21756.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: flatpak-1.12.9-4.el8_10.i686.rpm flatpak-1.12.9-4.el8_10.x86_64.rpm flatpak-devel-1.12.9-4.el8_10.i686.rpm flatpak-devel-1.12.9-4.el8_10.x86_64.rpm flatpak-libs-1.12.9-4.el8_10.i686.rpm flatpak-libs-1.12.9-4.el8_10.x86_64.rpm flatpak-selinux-1.12.9-4.el8_10.noarch.rpm flatpak-session-helper-1.12.9-4.el8_10.i686.rpm flatpak-session-helper-1.12.9-4.el8_10.x86_64.rpm aarch64: flatpak-1.12.9-4.el8_10.aarch64.rpm flatpak-devel-1.12.9-4.el8_10.aarch64.rpm flatpak-libs-1.12.9-4.el8_10.aarch64.rpm flatpak-selinux-1.12.9-4.el8_10.noarch.rpm flatpak-session-helper-1.12.9-4.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/flatpak-1.12.9-4.el8_10.src.rpm Related CVEs: CVE-2026-34078 CVE-2026-34079 Description of changes: [1.12.9-4] - Fix arbitrary code execution via crafted symlinks in sandbox-expose options Resolves: RHEL-165633 - Fix arbitrary file deletion on host via improper cache file path validation Resolves: RHEL-170160 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 8 updates for flatpak address code execution & file deletion issues. Download now for enhanced security!. Oracle Linux 8, flatpak updates, security advisory, code execution. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 29, 2026 Important Oracle
202

openSUSE Leap 15.4 xdg-desktop-portal Moderate File Deletion CVE-2026-40354

An update that solves one vulnerability can now be installed.. # Security update for xdg-desktop-portal Announcement ID: SUSE-SU-2026:2105-1 Release Date: 2026-05-28T16:04:00Z Rating: moderate References: * bsc#1262045 Cross-References: * CVE-2026-40354 CVSS scores: * CVE-2026-40354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-40354 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40354 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for xdg-desktop-portal fixes the following issue: * CVE-2026-40354: File deletion via symlink attack (bsc#1262045). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2105=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * xdg-desktop-portal-1.10.1-150400.3.11.1 * xdg-desktop-portal-debugsource-1.10.1-150400.3.11.1 * xdg-desktop-portal-debuginfo-1.10.1-150400.3.11.1 * xdg-desktop-portal-devel-1.10.1-150400.3.11.1 * openSUSE Leap 15.4 (noarch) * xdg-desktop-portal-lang-1.10.1-150400.3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40354.html * https://bugzilla.suse.com/show_bug.cgi?id=1262045 . Critical security update for xdg-desktop-portal addresses file deletion risk through symlink attacks in openSUSE Leap 15.4.. xdg desktop portal, openSUSE Leap, file deletion, symlink attack, security update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 29, 2026 Important OpenSUSE
100

OpenSUSE Leap 15.4 Security Update for XDG Desktop Portal 2026-2105-1

An update that solves one vulnerability can now be installed.. # Security update for xdg-desktop-portal Announcement ID: SUSE-SU-2026:2105-1 Release Date: 2026-05-28T16:04:00Z Rating: moderate References: * bsc#1262045 Cross-References: * CVE-2026-40354 CVSS scores: * CVE-2026-40354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-40354 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40354 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for xdg-desktop-portal fixes the following issue: * CVE-2026-40354: File deletion via symlink attack (bsc#1262045). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2105=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * xdg-desktop-portal-1.10.1-150400.3.11.1 * xdg-desktop-portal-debugsource-1.10.1-150400.3.11.1 * xdg-desktop-portal-debuginfo-1.10.1-150400.3.11.1 * xdg-desktop-portal-devel-1.10.1-150400.3.11.1 * openSUSE Leap 15.4 (noarch) * xdg-desktop-portal-lang-1.10.1-150400.3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40354.html * https://bugzilla.suse.com/show_bug.cgi?id=1262045 . SUSE update addresses moderate file deletion risk in xdg-desktop-portal, enhancing system security against symlink attacks.. openSUSE updates, xdg-desktop-portal security, moderate risk patches, symlink vulnerability. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 May 29, 2026 moderate SuSE
172

Ubuntu 25.10 Advisory USN-8287-1 XDG Desktop Portal Important Deletion Risk

XDG Desktop Portal could be made to delete files.. ========================================================================== Ubuntu Security Notice USN-8287-1 May 20, 2026 xdg-desktop-portal vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS Summary: XDG Desktop Portal could be made to delete files. Software Description: - xdg-desktop-portal: A portal frontend service for Flatpak and other desktop containment frameworks Details: It was discovered that XDG Desktop Portal incorrectly handled trashing files. A local attacker could possibly use this issue to delete arbitrary files on the host file system via a symlink attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 xdg-desktop-portal 1.20.3+ds-1ubuntu1.1 xdg-desktop-portal-dev 1.20.3+ds-1ubuntu1.1 Ubuntu 24.04 LTS xdg-desktop-portal 1.18.4-1ubuntu2.24.04.2 xdg-desktop-portal-dev 1.18.4-1ubuntu2.24.04.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8287-1 CVE-2026-40354 Package Information: https://launchpad.net/ubuntu/+source/xdg-desktop-portal/1.20.3+ds-1ubuntu1.1 https://launchpad.net/ubuntu/+source/xdg-desktop-portal/1.18.4-1ubuntu2.24.04.2 . XDG Desktop Portal flaw allows local attackers to delete files via symlink attacks in Ubuntu. Critical updates are advised.. Ubuntu, XDG Desktop Portal, local attack, important security, file deletion. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 21, 2026 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200