Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 21 articles for you...
89

Fedora 44 perl-HTTP-Daemon Important Remote Code Exec Patch 2026-8982379b5c

Changes: 6.17 2026-05-19 23:11:06Z Fix CVE-2026-8450 (affects 6.15 and earlier): 2-arg open() in send_file() enabled RCE / arbitrary file write / response-body exfiltration when a string argument was derived from attacker-. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-8982379b5c 2026-06-19 00:59:07.048604+00:00 -------------------------------------------------------------------------------- Name : perl-HTTP-Daemon Product : Fedora 44 Version : 6.17 Release : 1.fc44 URL : https://metacpan.org/release/HTTP-Daemon Summary : Simple HTTP server class Description : Instances of the HTTP::Daemon class are HTTP/1.1 servers that listen on a socket for incoming requests. The HTTP::Daemon is a subclass of IO::Socket::IP, so you can perform socket operations directly on it too. -------------------------------------------------------------------------------- Update Information: Changes: 6.17 2026-05-19 23:11:06Z Fix CVE-2026-8450 (affects 6.15 and earlier): 2-arg open() in send_file() enabled RCE / arbitrary file write / response-body exfiltration when a string argument was derived from attacker- influenced input. send_file() now uses 3-arg open() with an explicit ' path', etc.) are no longer interpreted. send_file() now also returns '0E0' (true zero) on a successful zero-byte transfer so callers can distinguish empty file from open failure (undef). See https://www.cve.org/CVERecord?id=CVE-2026-8450 for the advisory. Reported and patched by Stig Palmquist (stigtsp). (Stig Palmquist, Olaf Alders) -------------------------------------------------------------------------------- ChangeLog: * Wed May 20 2026 Michal Josef Špaček - 6.17-1 - 6.17 bump -------------------------------------------------------------------------------- References: [ 1 ] Bug #2480076 - perl-HTTP-Daemon-6.17 is available https://bugzilla.redhat.com/show_bug.cgi?id=2480076 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-8982379b5c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical update for Fedora 44 addressing remote code execution in perl-HTTP-Daemon due to flaws in send_file().. Fedora 44 perl-HTTP-Daemon update, security advisory, remote code execution, file write issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 18, 2026 Critical Fedora
202

openSUSE Leap 16.0 python-PyMuPDF Major Path Traversal Issue CVE-2026-3029

An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for python-pymupdf ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20887-1 Rating: important References: * bsc#1259921 Cross-References: * CVE-2026-3029 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for python-PyMuPDF fixes the following issues: Changes in python-PyMuPDF: - CVE-2026-3029: Fixed path traversal and arbitrary file write via the `embedded_get` function in `_main_.py` (bsc#1259921) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-leap-15=1 Package List: - openSUSE Leap 16.0: python313-PyMuPDF-1.21.1-lp160.5.1 References: * https://www.suse.com/security/cve/CVE-2026-3029.html . Get important fixes for openSUSE Leap 16.0's python-PyMuPDF, addressing CVE-2026-3029 vulnerability with this update.. openSUSE security, python-PyMuPDF, important update, software patch, vulnerability fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 03, 2026 Important OpenSUSE
202

openSUSE Leap 16.0 python-PyMuPDF High Path Traversal CVE-2026-3029

An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for python-pymupdf ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20887-1 Rating: important References: * bsc#1259921 Cross-References: * CVE-2026-3029 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for python-PyMuPDF fixes the following issues: Changes in python-PyMuPDF: - CVE-2026-3029: Fixed path traversal and arbitrary file write via the `embedded_get` function in `_main_.py` (bsc#1259921) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-leap-15=1 Package List: - openSUSE Leap 16.0: python313-PyMuPDF-1.21.1-lp160.5.1 References: * https://www.suse.com/security/cve/CVE-2026-3029.html . This update for openSUSE Leap 16.0 fixes an important security issue in python-PyMuPDF related to path traversal.. openSUSE security update, Python updates, path traversal, file write issue, security patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 03, 2026 Important OpenSUSE
197

Debian 11 calibre DLA-4554-1 Path Traversal and File Write Risks

Multiple vulnerabilities have been discovered in calibre, an e-book manager CVE-2025-64486 calibre does not validate filenames when handling binary assets in FB2 files, allowing an attacker to write arbitrary files on the. Debian LTS Advisory DLA-4554-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Abhijith PA April 29, 2026 https://wiki.debian.org/LTS Package : calibre Version : 5.12.0+dfsg-1+deb11u4 CVE ID : CVE-2025-64486 CVE-2026-25635 CVE-2026-25636 CVE-2026-26064 CVE-2026-26065 Multiple vulnerabilities have been discovered in calibre, an e-book manager CVE-2025-64486 calibre does not validate filenames when handling binary assets in FB2 files, allowing an attacker to write arbitrary files on the filesystem when viewing or converting a malicious FictionBook file. This can be leveraged to achieve arbitrary code execution. CVE-2026-25635 Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. CVE-2026-25636 a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process CVE-2026-26064 a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. CVE-2026-26065 Path Traversal through PDB readers that allow arbitrary file writes with arbitrary extension and arbitrary content anywhere the user has write permissions. Files are written in 'wb' mode, silently overwriting existing files. This can lead to potential code execution and Denial of Service through file corruption. For Debian 11 bullseye, these problems have been fixed in version 5.12.0+dfsg-1+deb11u4. We recommend that you upgrade your calibre packages. For the detailed security status of calibre please refer to its securitytracker page at: https://security-tracker.debian.org/tracker/calibre Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Multiple vulnerabilities in calibre e-book manager could allow file writes and code execution in Debian systems.. calibre security, Debian LTS, file write flaws, path traversal issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 30, 2026 Critical Debian LTS
202

openSUSE Leap 15.6 python-poetry Severe Access Issue SUSE-SU-2026-5679-1

An update that solves one vulnerability can now be installed.. # Security update for python-poetry Announcement ID: SUSE-SU-2026:1220-1 Release Date: 2026-04-08T16:03:10Z Rating: moderate References: * bsc#1261383 Cross-References: * CVE-2026-34591 CVSS scores: * CVE-2026-34591 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34591 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-34591 ( NVD ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.6 An update that solves one vulnerability can now be installed. ## Description: This update for python-poetry fixes the following issue: * CVE-2026-34591: From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, allowing arbitrary file write (bsc#1261383). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1220=1 ## Package List: * openSUSE Leap 15.6 (noarch) * python311-poetry-1.7.1-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34591.html * https://bugzilla.suse.com/show_bug.cgi?id=1261383 . Update for openSUSE addresses moderate file write issue in python-poetry, fixing CVE-2026-34591 efficiently.. python-poetry update, openSUSE security, file write risk, CVE-2026-34591. . LinuxSecurity.com Team

Calendar%202 Apr 09, 2026 OpenSUSE
219

CentOS Stream 9 RLSB-2026-8537 Critical Security Update for Python Files

Important: golang security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:5942", "synopsis": "Important: golang security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for golang.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The golang packages provide the Go programming language compiler.\n\nSecurity Fix(es):\n\n* cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive (CVE-2025-61731)\n\n* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2434433", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2434433", "description": ""}, {"ticket": "2445356", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", "description": ""}], "cves": [{"name": "CVE-2025-61731", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61731", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H", "cvss3BaseScore": "8.6", "cwe": "CWE-88"}, {"name": "CVE-2026-25679", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-25679", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1286"}], "references": [], "publishedAt": "2026-04-07T12:03:55.701474Z", "rpms": {"Rocky Linux 9": {"nvras": ["golang-0:1.25.8-1.el9_7.aarch64.rpm", "golang-0:1.25.8-1.el9_7.ppc64le.rpm", "golang-0:1.25.8-1.el9_7.s390x.rpm", "golang-0:1.25.8-1.el9_7.src.rpm", "golang-0:1.25.8-1.el9_7.x86_64.rpm", "golang-bin-0:1.25.8-1.el9_7.aarch64.rpm","golang-bin-0:1.25.8-1.el9_7.ppc64le.rpm", "golang-bin-0:1.25.8-1.el9_7.s390x.rpm", "golang-bin-0:1.25.8-1.el9_7.x86_64.rpm", "golang-docs-0:1.25.8-1.el9_7.noarch.rpm", "golang-misc-0:1.25.8-1.el9_7.noarch.rpm", "golang-race-0:1.25.8-1.el9_7.aarch64.rpm", "golang-race-0:1.25.8-1.el9_7.ppc64le.rpm", "golang-race-0:1.25.8-1.el9_7.s390x.rpm", "golang-race-0:1.25.8-1.el9_7.x86_64.rpm", "golang-src-0:1.25.8-1.el9_7.noarch.rpm", "golang-tests-0:1.25.8-1.el9_7.noarch.rpm", "go-toolset-0:1.25.8-1.el9_7.aarch64.rpm", "go-toolset-0:1.25.8-1.el9_7.ppc64le.rpm", "go-toolset-0:1.25.8-1.el9_7.s390x.rpm", "go-toolset-0:1.25.8-1.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important golang security update enhances stability and mitigates risk with fixes for significant vulnerabilities. . go programming language update, golang security fix, Rocky Linux advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 07, 2026 Important Rocky Linux
203

Mageia 9: wget2 Important Path Traversal Fix MGASA-2026-0002 CVE-2025-69194

MGASA-2026-0002 - Updated wget2 packages fix security vulnerability. MGASA-2026-0002 - Updated wget2 packages fix security vulnerability Publication date: 10 Jan 2026 URL: https://advisories.mageia.org/MGASA-2026-0002.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-69194 Description: Arbitrary File Write via Metalink Path Traversal in GNU Wget2. (CVE-2025-69194) References: - https://bugs.mageia.org/show_bug.cgi?id=34947 - https://www.openwall.com/lists/oss-security/2026/01/07/1 - https://www.cve.org/CVERecord?id=CVE-2025-69194 SRPMS: - 9/core/wget2-2.0.1-1.1.mga9 . Updated wget2 packages for Mageia fix critical path traversal security issue, affecting releases 9 and fix details.. wget2 security update, Mageia security advisory, file write vulnerability, path traversal exploit. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 10, 2026 Important Mageia
89

Fedora 43: wget2 Critical Memory Corruption and File Write Issues 2026:01

New version 2.2.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-de1a91fe79 2026-01-08 01:26:39.511506+00:00 -------------------------------------------------------------------------------- Name : wget2 Product : Fedora 43 Version : 2.2.1 Release : 1.fc43 URL : https://gitlab.com/gnuwget/wget2 Summary : An advanced file and recursive website downloader Description : GNU Wget2 is the successor of GNU Wget, a file and recursive website downloader. Designed and written from scratch it wraps around libwget, that provides the basic functions needed by a web client. Wget2 works multi-threaded and uses many features to allow fast operation. In many cases Wget2 downloads much faster than Wget1.x due to HTTP2, HTTP compression, parallel connections and use of If-Modified-Since HTTP header. -------------------------------------------------------------------------------- Update Information: New version 2.2.1 -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 1 2026 LuK1337 - 2.2.1-1 - New version 2.2.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2425777 - CVE-2025-69195 wget2: GNU Wget2: Memory corruption and crash via filename sanitization logic with attacker-controlled URLs [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2425777 [ 2 ] Bug #2425778 - CVE-2025-69195 wget2: GNU Wget2: Memory corruption and crash via filename sanitization logic with attacker-controlled URLs [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2425778 [ 3 ] Bug #2425782 - CVE-2025-69194 wget2: Arbitrary File Write via Metalink Path Traversal in GNU Wget2 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2425782 [ 4 ] Bug #2425783 - CVE-2025-69194 wget2: Arbitrary File Write via Metalink Path Traversal in GNU Wget2 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2425783 [ 5 ] Bug #2426325 - wget2-2.2.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2426325 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-de1a91fe79' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Explore critical updates for Fedora 43 wget2 version 2.2.1 addressing memory corruption and file write issues.. Fedora 43,Wget2 Update,Security Advisory,Memory Corruption,File Write. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 08, 2026 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200