Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 3 articles for you...
172

Ubuntu 22.04 Tar-FS Important Security Flaws USN-8367-1

Several security issues were fixed in tar-fs.. ========================================================================== Ubuntu Security Notice USN-8367-1 June 02, 2026 node-tar-fs vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in tar-fs. Software Description: - node-tar-fs: File system bindings for tar-stream Details: It was discovered that tar-fs did not properly limit paths when extracting crafted tar files. An attacker could possibly use this issue to write or overwrite files outside the intended extraction directory. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-12905) It was discovered that tar-fs did not properly validate extraction paths for certain crafted tar archives. An attacker could possibly use this issue to write files outside the intended extraction directory. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-48387) It was discovered that tar-fs had a symlink validation bypass when extracting crafted tar files. An attacker could possibly use this issue to write files outside the intended extraction directory. (CVE-2025-59343) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 node-tar-fs 3.0.9+~cs2.0.4-1+deb13u1build0.25.10.1 Ubuntu 24.04 LTS node-tar-fs 2.1.1-6ubuntu0.24.04.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS node-tar-fs 2.1.1-6ubuntu0.22.04.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8367-1 CVE-2024-12905, CVE-2025-48387, CVE-2025-59343 Package Information: https://launchpad.net/ubuntu/+source/node-tar-fs/3.0.9+~cs2.0.4-1+deb13u1build0.25.10.1 . Multiple critical issues in tar-fs affecting Ubuntu 22.04 and 24.04 require immediate updates to ensure system security.. tar-fs vulnerabilities, Ubuntu 22.04 security, file extraction risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 02, 2026 Important Ubuntu
172

Ubuntu 24.04 NLTK Critical File Extraction Threat 2026-8214-1

NLTK could be made to crash or run programs as your login if it opened a specially crafted zip file.. ========================================================================== Ubuntu Security Notice USN-8214-1 April 28, 2026 nltk vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: NLTK could be made to crash or run programs as your login if it opened a specially crafted zip file. Software Description: - nltk: Natural Language Toolkit Details: It was discovered that NLTK incorrectly handled file extraction when opening a maliciously crafted zip file. An attacker could possibly use this issue to create or overwrite files on the system and execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python3-nltk 3.8.1-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS python3-nltk 3.7-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS python3-nltk 3.4.5-2ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS python-nltk 3.2.5-1ubuntu0.1+esm3 Available with Ubuntu Pro python3-nltk 3.2.5-1ubuntu0.1+esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS python-nltk 3.1-1ubuntu0.1+esm3 Available with Ubuntu Pro python3-nltk 3.1-1ubuntu0.1+esm3 Available with Ubuntu Pro Ubuntu 14.04 LTS python-nltk 2.0~b9-0ubuntu4.1~esm5 Available withUbuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8214-1 CVE-2025-14009 . NLTK's latest update addresses a critical flaw that could allow file crashes or unauthorized program execution. Get the fix now!. NLTK security flaw, Ubuntu update, critical vulnerability, file extraction issue, code execution threat. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 28, 2026 Critical Ubuntu
100

SUSE Python-Requests Moderate Predicable Filename Issue 2026-1218-1

An update that solves one vulnerability can now be installed.. # Security update for python-requests Announcement ID: SUSE-SU-2026:1218-1 Release Date: 2026-04-08T14:39:50Z Rating: moderate References: * bsc#1260589 Cross-References: * CVE-2026-25645 CVSS scores: * CVE-2026-25645 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-25645 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-25645 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N * CVE-2026-25645 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python-requests fixes the following issues: * CVE-2026-25645: `extract_zipped_paths()` uses predictable filenames when extracting files from zip archives and reuses target files that already exist without validation (bsc#1260589). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_updateor "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2026-1218=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-1218=1 ## Package List: * Public Cloud Module 12 (noarch) * python3-requests-2.24.0-8.26.1 * python-requests-2.24.0-8.26.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * python-requests-2.24.0-8.26.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25645.html * https://bugzilla.suse.com/show_bug.cgi?id=1260589 . An update for python-requests on SUSE fixes a moderate issue with predictable filenames in zip extraction.. SUSE Security Advisory, python-requests Update, zip Extraction Security, Linux Patch Management. . LinuxSecurity.com Team

Calendar%202 Apr 08, 2026 SuSE
202

openSUSE Leap 16.0 Python-Pip Low Risk Archive Extraction CVE-2026-1703

An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for python-pip ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20202-1 Rating: low References: * bsc#1257599 Cross-References: * CVE-2026-1703 CVSS scores: * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for python-pip fixes the following issues: - CVE-2026-1703: files may be extracted outside the installation directory when installing and extracting maliciously crafted wheel archives (bsc#1257599). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-256=1 Package List: - openSUSE Leap 16.0: python313-pip-25.0.1-160000.3.1 python313-pip-wheel-25.0.1-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-1703.html . Update for openSUSE resolves a bug and a low-severity vulnerability in python-pip related to archive extraction.. python-pip security low severity openSUSE update. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Feb 14, 2026 Low OpenSUSE
172

Ubuntu 7349-1: RAR Security Advisory Updates

Several security issues were fixed in RAR.. ========================================================================== Ubuntu Security Notice USN-7349-1 March 12, 2025 rar vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in RAR. Software Description: - rar: Archiver for .rar files Details: It was discovered that RAR incorrectly handled certain paths. If a user or automated system were tricked into extracting a specially crafted RAR archive, a remote attacker could possibly use this issue to write arbitrary files outside of the targeted directory. (CVE-2022-30333) It was discovered that RAR incorrectly handled certain recovery volumes. If a user or automated system were tricked into extracting a specially crafted RAR archive, a remote attacker could possibly use this issue to execute arbitrary code. (CVE-2023-40477) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS rar 2:6.23-1~22.04.1 Ubuntu 20.04 LTS rar 2:6.23-1~20.04.1 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7349-1 CVE-2022-30333, CVE-2023-40477 Package Information: https://launchpad.net/ubuntu/+source/rar/2:6.23-1~22.04.1 https://launchpad.net/ubuntu/+source/rar/2:6.23-1~20.04.1 . Multiple security issues in RAR addressed in Ubuntu Security Notice USN-7349-1 for versions 20.04 and 22.04 LTS.. security, =========================================================. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 12, 2025 Important Ubuntu
89

Fedora 34 GSettings Update: 2021-303f6623fa Moderate Threat Details

GNOME 40.rc. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-303f6623fa 2021-03-20 00:16:30.596999 --------------------------------------------------------------------------------Name : gsettings-desktop-schemas Product : Fedora 34 Version : 40~rc Release : 1.fc34 URL : Summary : A collection of GSettings schemas Description : gsettings-desktop-schemas contains a collection of GSettings schemas for settings shared by various components of a desktop. --------------------------------------------------------------------------------Update Information: GNOME 40.rc --------------------------------------------------------------------------------ChangeLog: * Mon Mar 15 2021 Kalev Lember - 40~rc-1 - Update to 40.rc --------------------------------------------------------------------------------References: [ 1 ] Bug #1925640 - CVE-2020-36241 gnome-autoar: directory traversal via a malicious archive that contains a file whose parent is a symbolic link which points outside of the destination directory https://bugzilla.redhat.com/show_bug.cgi?id=1925640 [ 2 ] Bug #1940026 - CVE-2021-28650 gnome-autoar: directory traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations https://bugzilla.redhat.com/show_bug.cgi?id=1940026 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-303f6623fa' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora 34 has released an important update to its gsettings-desktop-schemas package, correcting critical bugs in the GNOME 40 Release Candidate and improving stability. Fedora Update, GSettings, GNOME Update, Desktop Schemas, System Updates. . LinuxSecurity.com Team

Calendar%202 Mar 19, 2021 Fedora
172

Ubuntu 20.04 LTS: 4461-1 Critical: Ark File Extraction Risk

Ark could be made to write files as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-4461-1 August 18, 2020 ark vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Ark could be made to write files as your login if it opened a specially crafted file. Software Description: - ark: archive utility Details: Dominik Penner discovered that Ark did not properly sanitize zip archive files before performing extraction. An attacker could use this to construct a malicious zip archive that, when opened, would create files outside the extraction directory. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: ark 4:19.12.3-0ubuntu1.1 Ubuntu 18.04 LTS: ark 4:17.12.3-0ubuntu1.1 After a standard system update you need to restart Ark to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4461-1 CVE-2020-16116 Package Information: https://launchpad.net/ubuntu/+source/ark/4:19.12.3-0ubuntu1.1 https://launchpad.net/ubuntu/+source/ark/4:17.12.3-0ubuntu1.1 . A serious vulnerability in the Ark application on Ubuntu could allow unauthorized file changes during user login, creating major security risks. Apply updates promptly to protect your systems. Ark Security, Ubuntu Threats, File Extraction Issues, Archive Utility Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 18, 2020 Critical Ubuntu
203

Mageia 6: MGASA-2018-0361 Critical: Libarchive Out-Of-Bounds Read Threat

The updated packages fix security vulnerabilities: An out-of-bounds read flaw exists in parse_file_info in archive_read_support_format_iso9660.c in libarchive 3.3.2 when extracting a specially crafted iso9660 iso file, related to . MGASA-2018-0361 - Updated libarchive packages fix security vulnerabilities Publication date: 31 Aug 2018 URL: https://advisories.mageia.org/MGASA-2018-0361.html Type: security Affected Mageia releases: 6 CVE: CVE-2017-14501, CVE-2017-14503 The updated packages fix security vulnerabilities: An out-of-bounds read flaw exists in parse_file_info in archive_read_support_format_iso9660.c in libarchive 3.3.2 when extracting a specially crafted iso9660 iso file, related to archive_read_format_iso9660_read_header (CVE-2017-14501). libarchive 3.3.2 suffers from an out-of-bounds read within lha_read_data_none() in archive_read_support_format_lha.c when extracting a specially crafted lha archive, related to lha_crc16 (CVE-2017-14503). References: - https://bugs.mageia.org/show_bug.cgi?id=23437 - https://ubuntu.com/security/notices/USN-3736-1 - https://www.cve.org/CVERecord?id=CVE-2017-14501 - https://www.cve.org/CVERecord?id=CVE-2017-14503 SRPMS: - 6/core/libarchive-3.3.1-1.2.mga6 . MGASA-2018-0361 - Updated libarchive packages fix security vulnerabilities Publication date: 31 Aug . updated, packages, security, vulnerabilities, out-of-bounds, exists, parse_file_i. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 31, 2018 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200