Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
172

Ubuntu Evolution Data Server Key File Deletion Vulnerability USN-8055-2

Evolution Data Server could be made to remove files.. ========================================================================== Ubuntu Security Notice USN-8055-2 June 01, 2026 evolution-data-server vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Evolution Data Server could be made to remove files. Software Description: - evolution-data-server: Evolution suite data server Details: USN-8055-1 fixed a vulnerability in Evolution Data Server. This update provides the corresponding update for Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. Original advisory details: It was discovered that Evolution Data Server incorrectly handled removing local cache files. An attacker could possibly use this issue to cause Evolution Data Server to remove arbitrary files. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS evolution-data-server 3.36.5-0ubuntu1+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS evolution-data-server 3.28.5-0ubuntu0.18.04.3+esm1 Available with Ubuntu Pro After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8055-2 https://ubuntu.com/security/notices/USN-8055-1 CVE-2026-2604 . The Ubuntu 8055-2 advisory details an important vulnerability in Evolution Data Server that could allow file removal.. Ubuntu Security, Evolution Data Server, file handling, security update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 01, 2026 Important Ubuntu
172

Ubuntu 20.04 LTS Evolution Data Server Critical File Removal CVE-2026-2604

Evolution Data Server could be made to remove files.. ========================================================================== Ubuntu Security Notice USN-8055-2 June 01, 2026 evolution-data-server vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Evolution Data Server could be made to remove files. Software Description: - evolution-data-server: Evolution suite data server Details: USN-8055-1 fixed a vulnerability in Evolution Data Server. This update provides the corresponding update for Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. Original advisory details: It was discovered that Evolution Data Server incorrectly handled removing local cache files. An attacker could possibly use this issue to cause Evolution Data Server to remove arbitrary files. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS evolution-data-server 3.36.5-0ubuntu1+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS evolution-data-server 3.28.5-0ubuntu0.18.04.3+esm1 Available with Ubuntu Pro After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8055-2 https://ubuntu.com/security/notices/USN-8055-1 CVE-2026-2604 . Ubuntu's Evolution Data Server has a critical file removal flaw. Update your system to ensure security and prevent attacks.. Ubuntu security, Evolution Data Server, file removal flaw, critical updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 01, 2026 Critical Ubuntu
172

Ubuntu 25.10 USN-8055-1 Evolution Data Server Medium File Removal Risk

Evolution Data Server could be made to remove files.. ========================================================================== Ubuntu Security Notice USN-8055-1 February 23, 2026 evolution-data-server vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Evolution Data Server could be made to remove files. Software Description: - evolution-data-server: Evolution suite data server Details: It was discovered that Evolution Data Server incorrectly handled removing local cache files. An attacker could possibly use this issue to cause Evolution Data Server to remove arbitrary files. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 evolution-data-server 3.56.2-3ubuntu0.1 evolution-data-server-common 3.56.2-3ubuntu0.1 libcamel-1.2-64t64 3.56.2-3ubuntu0.1 libebackend-1.2-11t64 3.56.2-3ubuntu0.1 libebook-1.2-21t64 3.56.2-3ubuntu0.1 libebook-contacts-1.2-4t64 3.56.2-3ubuntu0.1 libecal-2.0-3 3.56.2-3ubuntu0.1 libedata-book-1.2-27t64 3.56.2-3ubuntu0.1 libedata-cal-2.0-2t64 3.56.2-3ubuntu0.1 libedataserver-1.2-27t64 3.56.2-3ubuntu0.1 libedataserverui-1.2-4t64 3.56.2-3ubuntu0.1 libedataserverui4-1.0-0t64 3.56.2-3ubuntu0.1 Ubuntu 24.04 LTS evolution-data-server 3.52.3-0ubuntu1.2 evolution-data-server-common 3.52.3-0ubuntu1.2 libcamel-1.2-64t64 3.52.3-0ubuntu1.2 libebackend-1.2-11t64 3.52.3-0ubuntu1.2 libebook-1.2-21t64 3.52.3-0ubuntu1.2 libebook-contacts-1.2-4t64 3.52.3-0ubuntu1.2 libecal-2.0-3 3.52.3-0ubuntu1.2 libedata-book-1.2-27t64 3.52.3-0ubuntu1.2 libedata-cal-2.0-2t64 3.52.3-0ubuntu1.2 libedataserver-1.2-27t64 3.52.3-0ubuntu1.2 libedataserverui-1.2-4t64 3.52.3-0ubuntu1.2 libedataserverui4-1.0-0t64 3.52.3-0ubuntu1.2 Ubuntu 22.04 LTS evolution-data-server 3.44.4-0ubuntu1.2 evolution-data-server-common 3.44.4-0ubuntu1.2 libcamel-1.2-63 3.44.4-0ubuntu1.2 libebackend-1.2-10 3.44.4-0ubuntu1.2 libebook-1.2-20 3.44.4-0ubuntu1.2 libebook-contacts-1.2-3 3.44.4-0ubuntu1.2 libecal-2.0-1 3.44.4-0ubuntu1.2 libedata-book-1.2-26 3.44.4-0ubuntu1.2 libedata-cal-2.0-1 3.44.4-0ubuntu1.2 libedataserver-1.2-26 3.44.4-0ubuntu1.2 libedataserverui-1.2-3 3.44.4-0ubuntu1.2 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8055-1 CVE-2026-2604 Package Information: https://launchpad.net/ubuntu/+source/evolution-data-server/3.56.2-3ubuntu0.1 https://launchpad.net/ubuntu/+source/evolution-data-server/3.52.3-0ubuntu1.2 https://launchpad.net/ubuntu/+source/evolution-data-server/3.44.4-0ubuntu1.2 . Explore the Evolution Data Server issue allowing file removal with this Ubuntu update. Critical security patch needed!. Evolution Data Server, Ubuntu security patch, file access issue. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Feb 23, 2026 Medium Ubuntu
89

Fedora 35: FEDORA-2022-64332f2a7c Moderate: Python-Pillow File Issue

Backport fix for CVE-2022-24303.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-64332f2a7c 2022-04-05 15:42:46.531407 --------------------------------------------------------------------------------Name : python-pillow Product : Fedora 35 Version : 8.3.2 Release : 3.fc35 URL : / Summary : Python image processing library Description : Python image processing library, fork of the Python Imaging Library (PIL) This library provides extensive file format support, an efficient internal representation, and powerful image processing capabilities. There are four subpackages: tk (tk interface), qt (PIL image wrapper for Qt), devel (development) and doc (documentation). --------------------------------------------------------------------------------Update Information: Backport fix for CVE-2022-24303. --------------------------------------------------------------------------------ChangeLog: * Mon Mar 28 2022 Sandro Mani - 8.3.2-3 - Backport patch for CVE-2022-24303 --------------------------------------------------------------------------------References: [ 1 ] Bug #2052683 - CVE-2022-24303 mingw-python-pillow: python-pillow: temporary directory with a space character allows removal of unrelated file after im.show() and related actions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2052683 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-64332f2a7c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Implement patch addressing CVE-2022-24303 in the python-pillow package for Fedora 35 to mitigate potential file deletion vulnerabilities.. python pillow security,Fedora package update,CVE mitigation for python pillow. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 05, 2022 Important Fedora
200

Scientific Linux: CVE-2009-4492 Moderate: Ruby Memory Corruption and XSS

Moderate: ruby security update. Date: Wed, 29 Jun 2011 14:44:23 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Moderate: ruby on SL5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." MIME-Version: 1.0 Synopsis: Moderate: ruby security update Issue Date: 2011-06-28 CVE Numbers: CVE-2009-4492 CVE-2010-0541 CVE-2011-1004 CVE-2011-1005 CVE-2011-0188 Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to do system management tasks. A flaw was found in the way large amounts of memory were allocated on 64-bit systems when using the BigDecimal class. A context-dependent attacker could use this flaw to cause memory corruption, causing a Ruby application that uses the BigDecimal class to crash or, possibly, execute arbitrary code. This issue did not affect 32-bit systems. (CVE-2011-0188) A race condition flaw was found in the remove system entries method in the FileUtils module. If a local user ran a Ruby script that uses this method, a local attacker could use this flaw to delete arbitrary files and directories accessible to that user via a symbolic link attack. (CVE-2011-1004) It was found that WEBrick (the Ruby HTTP server toolkit) did not filter terminal escape sequences from its log files. A remote attacker could use specially-crafted HTTP requests to inject terminal escape sequences into the WEBrick log files. If a victim viewed the log files with a terminal emulator, it could result in control characters being executed with the privileges of that user. (CVE-2009-4492) A cross-site scripting (XSS) flaw was found in the way WEBrick displayed error pages. A remote attacker could use this flaw to perform a cross-site scripting attack against victims by tricking them into visiting a specially-crafted URL. (CVE-2010-0541) A flaw was found in the method for translating an exception message into a string in the Exception class. A remote attacker could usethis flaw to bypass safe level 4 restrictions, allowing untrusted (tainted) code to modify arbitrary, trusted (untainted) strings, which safe level 4 restrictions would otherwise prevent. (CVE-2011-1005) All Ruby users should upgrade to these updated packages, which contain backported patches to resolve these issues. SL5: i386 ruby-1.8.5-19.el5_6.1.i386.rpm ruby-tcltk-1.8.5-19.el5_6.1.i386.rpm ruby-ri-1.8.5-19.el5_6.1.i386.rpm ruby-rdoc-1.8.5-19.el5_6.1.i386.rpm ruby-mode-1.8.5-19.el5_6.1.i386.rpm ruby-libs-1.8.5-19.el5_6.1.i386.rpm ruby-irb-1.8.5-19.el5_6.1.i386.rpm ruby-docs-1.8.5-19.el5_6.1.i386.rpm ruby-devel-1.8.5-19.el5_6.1.i386.rpm x86_64 ruby-libs-1.8.5-19.el5_6.1.i386.rpm ruby-libs-1.8.5-19.el5_6.1.x86_64.rpm ruby-mode-1.8.5-19.el5_6.1.x86_64.rpm ruby-rdoc-1.8.5-19.el5_6.1.x86_64.rpm ruby-ri-1.8.5-19.el5_6.1.x86_64.rpm ruby-irb-1.8.5-19.el5_6.1.x86_64.rpm ruby-docs-1.8.5-19.el5_6.1.x86_64.rpm ruby-devel-1.8.5-19.el5_6.1.x86_64.rpm ruby-devel-1.8.5-19.el5_6.1.i386.rpm ruby-1.8.5-19.el5_6.1.x86_64.rpm ruby-tcltk-1.8.5-19.el5_6.1.x86_64.rpm - Scientific Linux Development Team . Upgrade your Scientific Linux to the newest Ruby security fixes to address vulnerabilities such as buffer overflows and unauthorized access.. ruby Security Update, Moderate Vulnerability Advisory, Scientific Linux Update, Security Fixes, Memory Corruption Exploit. . LinuxSecurity.com Team

Calendar%202 Jun 29, 2011 Scientific Linux
87

Debian: DSA-2195-1 Critical: PHP 5 Race Condition File Removal

Stephane Chazelas discovered that the cronjob of the PHP 5 package in Debian suffers from a race condition which might be used to remove arbitrary files from a system (CVE-2011-0441). . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2195-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Raphael Geissert March 19, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : php5 Vulnerability : several Problem type : local/remote Debian-specific: yes/no CVE ID : CVE-2011-0441 CVE-2010-3709 CVE-2010-3710 CVE-2010-3870 CVE-2010-4150 Stephane Chazelas discovered that the cronjob of the PHP 5 package in Debian suffers from a race condition which might be used to remove arbitrary files from a system (CVE-2011-0441). When upgrading your php5-common package take special care to _accept_ the changes to the /etc/cron.d/php5 file. Ignoring them would leave the system vulnerable. For the oldstable distribution (lenny), this problem has been fixed in version 5.2.6.dfsg.1-1+lenny10. For the stable distribution (squeeze), this problem has been fixed in version 5.3.3-7+squeeze1. For the unstable distribution (sid), this problem has been fixed in version 5.3.6-1. Additionally, the following vulnerabilities have also been fixed in the oldstable distribution (lenny): CVE-2010-3709 Maksymilian Arciemowicz discovered that the ZipArchive class may dereference a NULL pointer when extracting comments from a zip archive, leading to application crash and possible denial of service. CVE-2010-3710 Stefan Neufeind discovered that the FILTER_VALIDATE_EMAIL filter does not correctly handle long, to be validated, strings. Such crafted strings may lead to denial of service because of high memory consumption and applicationcrash. CVE-2010-3870 It was discovered that PHP does not correctly handle certain UTF-8 sequences and may be used to bypass XSS protections. CVE-2010-4150 Mateusz Kocielski discovered that the imap extension may try to free already freed memory when processing user credentials, leading to application crash and possibly arbitrary code execution. We recommend that you upgrade your php5 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical PHP 5 security alert has been released, revealing a race condition vulnerability that may allow unauthorized file deletion on Debian systems. Upgrade now!. PHP 5 Update, Debian Advisory, Cronjob Security, Race Condition, Upgrade Recommendation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 19, 2011 Critical Debian
172

Ubuntu 8.04 LTS USN-768-1 Critical: Apport File Removal

Stephane Chazelas discovered that Apport did not safely remove files fromits crash report directory. If Apport had been enabled at some point, alocal attacker could remove arbitrary files from the system. [More...]. ==========================================================Ubuntu Security Notice USN-768-1 April 29, 2009 Apport vulnerability CVE-2009-1295 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: apport 0.108.4 Ubuntu 8.10: apport 0.119.2 Ubuntu 9.04: apport 1.0-0ubuntu5.2 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Stephane Chazelas discovered that Apport did not safely remove files from its crash report directory. If Apport had been enabled at some point, a local attacker could remove arbitrary files from the system. Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 776 84645454e08c3f65d8c52dac74f905be Size/MD5: 188833 f61510a9319ad3fd3a7903d63f8e96d9 Architecture independent packages: Size/MD5: 55292 4bc790aa6618eecfa27e5b8222e5766f Size/MD5: 54048 d1ac561fe9a5c980cc4150a9939cb722 Size/MD5: 63690 a6b693e4cd22e222a052c0818e43eb2b Size/MD5: 104590 2a61c23a4fcd822dc148151e8b68c447 Size/MD5: 56970 875f5505b1e258eee1c455cfc270c7f9 Size/MD5: 58658 9f8dc7432955def5e5476d7332ffb725 Updated packages for Ubuntu 8.10: Source archives: Size/MD5: 979 6c0cd091b3970e2761751e54aabed459 Size/MD5: 198567 8a3f6a81452f815b6755da1d024298e9 Architecture independent packages: Size/MD5: 57796dd4bd02f893e04497f418840d437402c Size/MD5: 56518 8ec6f3cdf154cd94fd93e77186beb50e Size/MD5: 67036 651104a20557b07edc065157e2539b79 Size/MD5: 107536 acaa7af80a1df3c4a87df65fbd772860 Size/MD5: 61332 9adc2a89f2ddfa53020a43db0646f713 Size/MD5: 61382 8db396b5045a9f5fd365572223377e57 Updated packages for Ubuntu 9.04: Source archives: Size/MD5: 73978 1036e1541554d50a6b201cf3b9ed2e81 Size/MD5: 1236 a8f08f5b1c8e3970e65cfb705bf72de2 Size/MD5: 217793 f9932601045b109fbc487b8fdca0c9fa Architecture independent packages: Size/MD5: 67744 3504cedc5be46644d0174438b9613aeb Size/MD5: 66374 f799fa04509e8cdcad100a7ca766bd32 Size/MD5: 74134 ea67d398ccf8f7070cbe8a2e2326ba97 Size/MD5: 112574 da9a0460879aee9e8ed7a229a87275db Size/MD5: 74006 490ed42d9d5f209d5d344ffed151eb5e Size/MD5: 71878 17406c34e7d0467609e22410f70864ab . Critical flaw found in Ubuntu's Apport could enable local adversaries to erase any files. Ensure you update for protection.. Apport Vulnerability, Ubuntu Security, File Removal Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 29, 2009 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200