Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 65 articles for you...
172

Ubuntu 16.04 OpenSSH Critical File Overwrite Risk USN-8514-1 CVE-2026-35385

OpenSSH could be made to overwrite files as the administrator.. ========================================================================== Ubuntu Security Notice USN-8514-1 July 06, 2026 openssh vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: OpenSSH could be made to overwrite files as the administrator. Software Description: - openssh: secure shell (SSH) for secure access to remote machines Details: It was discovered that OpenSSH incorrectly handled file permissions when downloading files as root using the legacy scp protocol without the preserve-mode option. An attacker could use this to install setuid or setgid files on a system, possibly leading to privilege escalation. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS openssh-client 1:7.2p2-4ubuntu2.10+esm8 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8514-1 CVE-2026-35385 . OpenSSH flaw could allow file overwriting by the admin in Ubuntu systems. Must update to avoid privilege escalation risks.. Ubuntu OpenSSH Update, OpenSSH Security Notice, Privilege Escalation Ubuntu. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 06, 2026 Critical Ubuntu
202

openSUSE Leap 15.6 nodejs14 Key Update Alert SUSE-SU-2026-1457-1

An update that solves seven vulnerabilities can now be installed.. # Security update for nodejs20 Announcement ID: SUSE-SU-2026:1363-1 Release Date: 2026-04-15T14:16:21Z Rating: important References: * bsc#1256576 * bsc#1260455 * bsc#1260462 * bsc#1260463 * bsc#1260480 * bsc#1260482 * bsc#1260494 Cross-References: * CVE-2026-21637 * CVE-2026-21710 * CVE-2026-21713 * CVE-2026-21714 * CVE-2026-21715 * CVE-2026-21716 * CVE-2026-21717 CVSS scores: * CVE-2026-21637 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-21637 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-21637 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21637 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21710 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-21710 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21710 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21713 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-21713 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-21713 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-21714 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-21714 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21714 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-21715 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-21715 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-21715 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-21716 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-21716 ( SUSE ): 4.4CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-21716 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-21717 ( SUSE ): 7.2 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-21717 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-21717 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves seven vulnerabilities can now be installed. ## Description: This update for nodejs20 fixes the following issues: Update to version 20.20.2. * CVE-2026-21717: trivially predictable hash collisions due to flaw in V8's string hashing mechanism allows for performance degradation via a crafted request (bsc#1260494). * CVE-2026-21716: incomplete fix for CVE-2024-36137 allows promise-based FileHandle methods to be used to modify file permissions and ownership on already-open file descriptors (bsc#1260462). * CVE-2026-21715: flaw in the Permission Model filesystem enforcement allows for file existence disclosure and filesystem path enumeration via `fs.realpathSync.native()` (bsc#1260482). * CVE-2026-21714: memory leak in Node.js HTTP/2 server allows for resource exhaustion via `WINDOW_UPDATE` frames sent on stream 0 (bsc#1260480). * CVE-2026-21713: timing side-channel due to flaw in Node.js HMAC verification allows for discovery of HMAC values and potential MAC forgery (bsc#1260463). * CVE-2026-21710: uncaught `TypeError` when handling HTTP requests allows for a process crash via requests with a header named `__proto__` when the application accesses `req.headersDistinct` (bsc#1260455). * CVE-2026-21637: flaw in TLS error handling allows for resource exhaustion and crash when `pskCallback` or `ALPNCallback` are in use (bsc#1256576). ## Patch Instructions: To installthis SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1363=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1363=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1363=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * nodejs20-20.20.2-150600.3.18.1 * nodejs20-debugsource-20.20.2-150600.3.18.1 * npm20-20.20.2-150600.3.18.1 * nodejs20-debuginfo-20.20.2-150600.3.18.1 * nodejs20-devel-20.20.2-150600.3.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * nodejs20-docs-20.20.2-150600.3.18.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * nodejs20-20.20.2-150600.3.18.1 * nodejs20-debugsource-20.20.2-150600.3.18.1 * npm20-20.20.2-150600.3.18.1 * nodejs20-debuginfo-20.20.2-150600.3.18.1 * nodejs20-devel-20.20.2-150600.3.18.1 * corepack20-20.20.2-150600.3.18.1 * openSUSE Leap 15.6 (noarch) * nodejs20-docs-20.20.2-150600.3.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * nodejs20-20.20.2-150600.3.18.1 * nodejs20-debugsource-20.20.2-150600.3.18.1 * npm20-20.20.2-150600.3.18.1 * nodejs20-debuginfo-20.20.2-150600.3.18.1 * nodejs20-devel-20.20.2-150600.3.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * nodejs20-docs-20.20.2-150600.3.18.1 ## References: * https://www.suse.com/security/cve/CVE-2026-21637.html * https://www.suse.com/security/cve/CVE-2026-21710.html * https://www.suse.com/security/cve/CVE-2026-21713.html * https://www.suse.com/security/cve/CVE-2026-21714.html * https://www.suse.com/security/cve/CVE-2026-21715.html * https://www.suse.com/security/cve/CVE-2026-21716.html *https://www.suse.com/security/cve/CVE-2026-21717.html * https://bugzilla.suse.com/show_bug.cgi?id=1256576 * https://bugzilla.suse.com/show_bug.cgi?id=1260455 * https://bugzilla.suse.com/show_bug.cgi?id=1260462 * https://bugzilla.suse.com/show_bug.cgi?id=1260463 * https://bugzilla.suse.com/show_bug.cgi?id=1260480 * https://bugzilla.suse.com/show_bug.cgi?id=1260482 * https://bugzilla.suse.com/show_bug.cgi?id=1260494 . Update for openSUSE addressing seven issues in Node.js. Important patch installation details for improved security.. openSUSE Node.js update security important patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 15, 2026 Important OpenSUSE
89

Fedora 42: NetworkManager-l2tp Important File Permissions Fix CVE-2025-9615

Updated to 1.52.0 release (CVE-2025-9615) Verify file permissions for private connections to prevent unprivileged user from using other user's certs. Ensure NetworkManager dependency has CVE-2025-9615 update.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-0d1cf2e45b 2026-01-13 01:12:50.637164+00:00 -------------------------------------------------------------------------------- Name : NetworkManager-l2tp Product : Fedora 42 Version : 1.52.0 Release : 1.fc42 URL : https://github.com/nm-l2tp/NetworkManager-l2tp Summary : NetworkManager VPN plugin for L2TP and L2TP/IPsec Description : This package contains software for integrating L2TP and L2TP over IPsec VPN support with the NetworkManager. -------------------------------------------------------------------------------- Update Information: Updated to 1.52.0 release (CVE-2025-9615) Verify file permissions for private connections to prevent unprivileged user from using other user's certs. Ensure NetworkManager dependency has CVE-2025-9615 update. -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 11 2026 Douglas Kosovic - 1.52.0-1 - Updated to 1.52.0 release Verify file permissions for private connections to prevent unprivileged user from using other user's certs (CVE-2025-9615) - Ensure NetworkManager dependency has CVE-2025-9615 update. - Correct sed example in generated README.Fedora and README.EPEL files. * Wed Nov 12 2025 Douglas Kosovic - 1.20.20-5 - Add README.Fedora for Fedora or README.EPEL for EPEL - Use (go-l2tp or xl2tpd) dependency for Fedora 43 to handle upgrades from earlier Fedora versions that had xl2tpd installed. * Tue Aug 26 2025 Douglas Kosovic - 1.20.20-4 - Fix orphaned xl2tpd dependency issue, switch to go-l2tp (rhbz#2390669,rhbz#2390688) * Wed Jul 23 2025 Fedora Release Engineering - 1.20.20-3 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-0d1cf2e45b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . NetworkManager-l2tp updated to 1.52.0 to fix CVE-2025-9615 file permissions issue. Important security advisory for Fedora.. NetworkManager, L2TP, security patch, Fedora updates, CVE-2025-9615. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 13, 2026 Important Fedora
89

Fedora 42: 2025-dc6ec0a8e2 important: kea multiple local attack fixes

New version 2.6.3 (rhbz#2368989) Fix for: CVE-2025-32801, CVE-2025-32802, CVE-2025-32803 kea.conf: Remove /tmp/ from socket-name for existing configurations kea.conf: Set pseudo-random password for default config to secure fresh install and allow CA startup without user intervention. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-dc6ec0a8e2 2025-06-19 01:56:35.684103+00:00 -------------------------------------------------------------------------------- Name : kea Product : Fedora 42 Version : 2.6.3 Release : 1.fc42 URL : http://kea.isc.org Summary : DHCPv4, DHCPv6 and DDNS server from ISC Description : DHCP implementation from Internet Systems Consortium, Inc. that features fully functional DHCPv4, DHCPv6 and Dynamic DNS servers. Both DHCP servers fully support server discovery, address assignment, renewal, rebinding and release. The DHCPv6 server supports prefix delegation. Both servers support DNS Update mechanism, using stand-alone DDNS daemon. -------------------------------------------------------------------------------- Update Information: New version 2.6.3 (rhbz#2368989) Fix for: CVE-2025-32801, CVE-2025-32802, CVE-2025-32803 kea.conf: Remove /tmp/ from socket-name for existing configurations kea.conf: Set pseudo-random password for default config to secure fresh install and allow CA startup without user intervention kea.conf: Restrict directory permissions Sync service files with upstream Fix leases ownership when switching from root to kea user (rhbz#2324168) Release Notes: The new default configuration file, kea-ctrl-agent.conf, introduces an authentication setting, "password-file", which restricts access to the REST API. On Fedora, the kea-api-password file is automatically populated with a pseudo- random password to secure new installations. For system upgrades, it is strongly recommended to update any custom configurations to restrict access to the REST API. For more details, includinginformation on CVE fixes and incompatible changes, refer to the upstream release notes: https://downloads.isc.org/isc/kea/2.6.3/Kea-2.6.3-ReleaseNotes.txt -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 9 2025 Martin Osvald - 2.6.3-1 - New version 2.6.3 (rhbz#2368989) - Fix for: CVE-2025-32801, CVE-2025-32802, CVE-2025-32803 - kea.conf: Remove /tmp/ from socket-name for existing configurations - kea.conf: Set pseudo-random password for default config to secure fresh install and allow CA startup without user intervention - kea.conf: Restrict directory permissions - Sync service files with upstream - Fix leases ownership when switching from root to kea user (rhbz#2324168) * Mon Jun 9 2025 Yaakov Selkowitz - 2.6.2-5 - Reconditionalize openssl-devel-engine * Mon Jun 9 2025 Martin Osvald - 2.6.2-4 - kea.spec: remove rhel7 and f40 conditions * Mon Jun 9 2025 Pavol Sloboda - 2.6.2-3 - fix: fixed the BuildRequires of mariadb-devel package the mariadb- connector-c-devel package is available for all RHEL versions from version 8 and above, as version 7 is quite old this condition is not necessary and all packages should use the BuildRequires of mariadb-connector-c- devel instead of mariadb-devel if possible * Mon Jun 2 2025 František Hrdina - 2.6.2-2 - Update location of fmf plans -------------------------------------------------------------------------------- References: [ 1 ] Bug #2324168 - System update from F40 to F41: kea-dhcp unusable https://bugzilla.redhat.com/show_bug.cgi?id=2324168 [ 2 ] Bug #2368989 - kea-2.6.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2368989 [ 3 ] Bug #2369337 - CVE-2025-32803 kea: Insecure file permissions can result in confidential information leakage [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2369337 [ 4 ] Bug #2369379 - CVE-2025-32801 kea: Loading a malicious hook library can lead to local privilege escalation [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2369379 [ 5 ] Bug #2370279 - CVE-2025-32802 kea: Insecure handling of file paths allows multiple local attacks [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2370279 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-dc6ec0a8e2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Essential improvements in kea have been made to fortify settings and tackle various local exploit pathways in Fedora 42.. Fedora 42, kea, DHCP server, security updates, local attacks. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 19, 2025 Important Fedora
172

Ubuntu 24.10 USN: 7284-1 Critical Netty DoS and Info Leak

Several security issues were fixed in Netty.. ========================================================================== Ubuntu Security Notice USN-7284-1 February 24, 2025 netty vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Netty. Software Description: - netty: Java NIO client/server socket framework Details: Jonathan Leitschuh discovered that Netty did not correctly handle file permissions when writing temporary files. An attacker could possibly use this issue to leak sensitive information. (CVE-2022-24823) It was discovered that Netty did not correctly handle limiting the number of fields when decoding a HTTP request. An attacker could possibly use issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-29025) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 libnetty-java 1:4.1.48-10ubuntu0.1 Ubuntu 24.04 LTS libnetty-java 1:4.1.48-9ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS libnetty-java 1:4.1.48-4+deb11u2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS libnetty-java 1:4.1.45-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS libnetty-java 1:4.1.7-4ubuntu0.1+esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS libnetty-java 1:4.0.34-1ubuntu0.1~esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7284-1 CVE-2022-24823, CVE-2024-29025 Package Information: https://launchpad.net/ubuntu/+source/netty/1:4.1.48-10ubuntu0.1 . Ubuntu 24.10 as well as previous LTS editions have addressed critical Netty vulnerabilities. Ensure your installations are current to reduce exposure to potential threats.. Netty Security Update, Ubuntu Patch, Software Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 24, 2025 Critical Ubuntu
99

Slackware 15.0: 2024-080-01 Moderate Python3 Security Update for Zipbomb

New python3 packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] python3 (SSA:2024-080-01) New python3 packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/python3-3.9.19-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: bundled libexpat was updated to 2.6.0. zipfile is now protected from the "quoted-overlap" zipbomb. tempfile.TemporaryDirectory cleanup no longer dereferences symlinks when working around file system permission errors. For more information, see: https://pythoninsider.blogspot.com/2024/03/python-31014-3919-and-3819-is-now.html https://www.cve.org/CVERecord?id=CVE-2023-52425 https://www.cve.org/CVERecord?id=CVE-2024-0450 https://www.cve.org/CVERecord?id=CVE-2023-6597 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 15.0 package: 7081105ba6776152ac3b7106f1d39b18 python3-3.9.19-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 473fbc6c3cf937f8f9839113ade8afa8 python3-3.9.19-x86_64-1_slack15.0.txz Slackware -current package: a59b0adbca9785605159767489cbe6e5 d/python3-3.9.19-i586-1.txz Slackware x86_64 -current package: 3b7c17fff3d5f99e8cfae5880c8a8dbb d/python3-3.9.19-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkgpython3-3.9.19-i586-1_slack15.0.txz +-----+ . Updated python3 modules released for Slackware 15.0 to address vital security vulnerabilities and improve overall reliability.. Slackware Security, Python Update, Package Fixes, System Administration. . LinuxSecurity.com Team

Calendar%202 Mar 20, 2024 Slackware
100

SUSE: 2024:0190-1 important: rear118a file permissions correction

* bsc#1218728 Cross-References: * CVE-2024-23301 . # Security update for rear118a Announcement ID: SUSE-SU-2024:0190-1 Rating: important References: * bsc#1218728 Cross-References: * CVE-2024-23301 CVSS scores: * CVE-2024-23301 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-23301 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise High Availability Extension 12 SP5 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for rear118a fixes the following issues: * CVE-2024-23301: Corrected world-readable permissions for initrd, which could be an issue if it contains sensitive information (bsc#1218728). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-HA-12-SP5-2024-190=1 * SUSE Linux Enterprise High Availability Extension 12 SP5 zypper in -t patch SUSE-SLE-HA-12-SP5-2024-190=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * rear118a-1.18.a-9.3.1 * SUSE Linux Enterprise High Availability Extension 12 SP5 (ppc64le x86_64) * rear118a-1.18.a-9.3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-23301.html * https://bugzilla.suse.com/show_bug.cgi?id=1218728 . Important Fedora security update for linux128c addresses critical permission vulnerabilities, enhancing overall platform integrity.. SUSE Linux, Rear118a Update, File Permission Fix, Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 23, 2024 Important SuSE
89

Fedora 39: FEDORA-2023-4f0bb4ff5e Moderate: ActiveRecord File Permissions

Ruby on Rails security upgrade: - Versions-7-0-7-2-6-1-7-6-have-been-released - incorrect file permissions on encrypted files. Exploit not known.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-4f0bb4ff5e 2023-09-15 18:36:13.240099 -------------------------------------------------------------------------------- Name : rubygem-activerecord Product : Fedora 39 Version : 7.0.7.2 Release : 1.fc39 URL : https://rubyonrails.org/ Summary : Object-relational mapper framework (part of Rails) Description : Implements the ActiveRecord pattern (Fowler, PoEAA) for ORM. It ties database tables and classes together for business objects, like Customer or Subscription, that can find, save, and destroy themselves without resorting to manual SQL. -------------------------------------------------------------------------------- Update Information: Ruby on Rails security upgrade: - Versions-7-0-7-2-6-1-7-6-have-been-released - incorrect file permissions on encrypted files. Exploit not known. -------------------------------------------------------------------------------- ChangeLog: * Mon Aug 28 2023 Pavel Valena - 1:7.0.7.2-1 - Update to activerecord 7.0.7.2. -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-4f0bb4ff5e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an emailto This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 39 release tackles vulnerabilities in ActiveRecord concerning file access rights and includes specifics about the Rails version enhancement.. Ruby On Rails, Fedora 39 Update, ActiveRecord Security, DNF Upgrade, ORM Framework. . LinuxSecurity.com Team

Calendar%202 Sep 15, 2023 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200