Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 528
Alerts This Week
Warning Icon 1 528

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 53 articles for you...
197

Debian 11: DLA-4232-1 important: freeradius denial of service

Several security vulnerabilities have been discovered in freeradius, a highly configurable RADIUS server. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4232-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Abhijith PA June 26, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : freeradius Version : 3.0.21+dfsg-2.2+deb11u2 CVE ID : CVE-2022-41859 CVE-2022-41860 CVE-2022-41861 Several security vulnerabilities have been discovered in freeradius, a highly configurable RADIUS server. CVE-2022-41859 The EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack. CVE-2022-41860 When an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries. This lookup will fail, but the SIM code will not check for that failure. Instead, it will dereference a NULL pointer, and cause the server to crash. CVE-2022-41861 A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server to crash. This crash is not exploitable by end users. Only systems which are in the RADIUS circle of trust can send these malformed attributes to a server. For Debian 11 bullseye, these problems have been fixed in version 3.0.21+dfsg-2.2+deb11u2. We recommend that you upgrade your freeradius packages. For the detailed security status of freeradius please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/freeradius Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS .Issues in freeradius security necessitate an immediate upgrade to safeguard networks and avert possible downtime.. freeradius security, Debian LTS update, RADIUS server vulnerabilities, security measures. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 26, 2025 Important Debian LTS
172

Ubuntu 24.04 LTS USN-7055-1 high: freeradius authentication bypass

A system authentication measure could be bypassed.. ========================================================================== Ubuntu Security Notice USN-7055-1 October 03, 2024 freeradius vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: A system authentication measure could be bypassed. Software Description: - freeradius: high-performance and highly configurable RADIUS server Details: Goldberg, Miro Haller, Nadia Heninger, Mike Milano, Dan Shumow, Marc Stevens, and Adam Suhl discovered that FreeRADIUS incorrectly authenticated certain responses. An attacker able to intercept communications between a RADIUS client and server could possibly use this issue to forge responses, bypass authentication, and access network devices and services. This update introduces new configuration options called "limit_proxy_state" and "require_message_authenticator" that default to "auto" but should be set to "yes" once all RADIUS devices have been upgraded on a network. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS freeradius 3.2.5+dfsg-3~ubuntu24.04.1 Ubuntu 22.04 LTS freeradius 3.0.26~dfsg~git20220223.1.00ed0241fa-0ubuntu3.3 Ubuntu 20.04 LTS freeradius 3.0.20+dfsg-3ubuntu0.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7055-1 CVE-2024-3596 Package Information: https://launchpad.net/ubuntu/+source/freeradius/3.0.26~dfsg~git20220223.1.00ed0241fa-0ubuntu3.3 https://launchpad.net/ubuntu/+source/freeradius/3.0.20+dfsg-3ubuntu0.4 . The Ubuntu Security Alert USN-7056-1 has disclosed a critical vulnerability in OpenSSH that enables remoteaccess without proper authentication.. FreeRADIUS Security, Ubuntu Security Update, RADIUS Authentication, System Security Fix. . LinuxSecurity.com Team

Calendar%202 Oct 03, 2024 Ubuntu
217

Oracle7: ELSA-2024-4911 Important: freeradius CVE-2024-3596 Fix

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-4911 http://linux.oracle.com/errata/ELSA-2024-4911.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: freeradius-3.0.13-15.0.1.el7.aarch64.rpm freeradius-devel-3.0.13-15.0.1.el7.aarch64.rpm freeradius-doc-3.0.13-15.0.1.el7.aarch64.rpm freeradius-krb5-3.0.13-15.0.1.el7.aarch64.rpm freeradius-ldap-3.0.13-15.0.1.el7.aarch64.rpm freeradius-mysql-3.0.13-15.0.1.el7.aarch64.rpm freeradius-perl-3.0.13-15.0.1.el7.aarch64.rpm freeradius-postgresql-3.0.13-15.0.1.el7.aarch64.rpm freeradius-python-3.0.13-15.0.1.el7.aarch64.rpm freeradius-sqlite-3.0.13-15.0.1.el7.aarch64.rpm freeradius-unixODBC-3.0.13-15.0.1.el7.aarch64.rpm freeradius-utils-3.0.13-15.0.1.el7.aarch64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates//freeradius-3.0.13-15.0.1.el7.src.rpm Related CVEs: CVE-2024-3596 Description of changes: [3.0.13-15.0.1] - Fixes CVE-2024-3596 security issue [Orabug: 36904288] _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . The latest Oracle Linux Security Advisory ELSA-2024-4912 focuses on CVE-2024-3597 and provides crucial updates for the httpd packages on arm64 architecture.. Oracle Linux, freeradius, aarch64 updates, security advisory, software patching. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 01, 2024 Important Oracle
217

Oracle Linux 7 ELSA-2024-4911: Critical Freeradius Fix CVE-2024-3596

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-4911 http://linux.oracle.com/errata/ELSA-2024-4911.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: freeradius-3.0.13-15.0.1.el7.x86_64.rpm freeradius-devel-3.0.13-15.0.1.el7.i686.rpm freeradius-devel-3.0.13-15.0.1.el7.x86_64.rpm freeradius-doc-3.0.13-15.0.1.el7.x86_64.rpm freeradius-krb5-3.0.13-15.0.1.el7.x86_64.rpm freeradius-ldap-3.0.13-15.0.1.el7.x86_64.rpm freeradius-mysql-3.0.13-15.0.1.el7.x86_64.rpm freeradius-perl-3.0.13-15.0.1.el7.x86_64.rpm freeradius-postgresql-3.0.13-15.0.1.el7.x86_64.rpm freeradius-python-3.0.13-15.0.1.el7.x86_64.rpm freeradius-sqlite-3.0.13-15.0.1.el7.x86_64.rpm freeradius-unixODBC-3.0.13-15.0.1.el7.x86_64.rpm freeradius-utils-3.0.13-15.0.1.el7.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates//freeradius-3.0.13-15.0.1.el7.src.rpm Related CVEs: CVE-2024-3596 Description of changes: [3.0.13-15.0.1] - Fixes CVE-2024-3596 security issue [Orabug: 36904288] _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Critical security advisory for Oracle Linux 7's freeradius updates addressing CVE-2024-3596. Download essential patches now.. Oracle Linux 7, freeradius update, security advisory, security fix, software security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 01, 2024 Critical Oracle
217

Oracle Linux 9 ELSA-2024-4935 Critical Freeradius Update

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-4935 http://linux.oracle.com/errata/ELSA-2024-4935.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: freeradius-3.0.21-40.el9_4.x86_64.rpm freeradius-devel-3.0.21-40.el9_4.x86_64.rpm freeradius-doc-3.0.21-40.el9_4.x86_64.rpm freeradius-krb5-3.0.21-40.el9_4.x86_64.rpm freeradius-ldap-3.0.21-40.el9_4.x86_64.rpm freeradius-utils-3.0.21-40.el9_4.x86_64.rpm python3-freeradius-3.0.21-40.el9_4.x86_64.rpm freeradius-mysql-3.0.21-40.el9_4.x86_64.rpm freeradius-perl-3.0.21-40.el9_4.x86_64.rpm freeradius-postgresql-3.0.21-40.el9_4.x86_64.rpm freeradius-rest-3.0.21-40.el9_4.x86_64.rpm freeradius-sqlite-3.0.21-40.el9_4.x86_64.rpm freeradius-unixODBC-3.0.21-40.el9_4.x86_64.rpm aarch64: freeradius-3.0.21-40.el9_4.aarch64.rpm freeradius-devel-3.0.21-40.el9_4.aarch64.rpm freeradius-doc-3.0.21-40.el9_4.aarch64.rpm freeradius-krb5-3.0.21-40.el9_4.aarch64.rpm freeradius-ldap-3.0.21-40.el9_4.aarch64.rpm freeradius-utils-3.0.21-40.el9_4.aarch64.rpm python3-freeradius-3.0.21-40.el9_4.aarch64.rpm freeradius-mysql-3.0.21-40.el9_4.aarch64.rpm freeradius-perl-3.0.21-40.el9_4.aarch64.rpm freeradius-postgresql-3.0.21-40.el9_4.aarch64.rpm freeradius-rest-3.0.21-40.el9_4.aarch64.rpm freeradius-sqlite-3.0.21-40.el9_4.aarch64.rpm freeradius-unixODBC-3.0.21-40.el9_4.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//freeradius-3.0.21-40.el9_4.src.rpm Related CVEs: CVE-2024-3596 Description of changes: [3.0.21-40] - Backport fixes for BlastRADIUS CVE Resolves: RHEL-46566 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 9 has released a set of security advisories for freeradius, addressing critical vulnerabilities and incorporating essential updates to bolster security measures.. Oracle Linux, FreeradiusUpdate, Security Advisory, Important Fixes, Linux Networking. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 01, 2024 Critical Oracle
217

Oracle Linux 8 ELSA-2024-4936: Important Freeradius Security Fix

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-4936 http://linux.oracle.com/errata/ELSA-2024-4936.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: freeradius-3.0.20-15.module+el8.10.0+90375+641abe33.x86_64.rpm freeradius-devel-3.0.20-15.module+el8.10.0+90375+641abe33.x86_64.rpm freeradius-doc-3.0.20-15.module+el8.10.0+90375+641abe33.x86_64.rpm freeradius-krb5-3.0.20-15.module+el8.10.0+90375+641abe33.x86_64.rpm freeradius-ldap-3.0.20-15.module+el8.10.0+90375+641abe33.x86_64.rpm freeradius-mysql-3.0.20-15.module+el8.10.0+90375+641abe33.x86_64.rpm freeradius-perl-3.0.20-15.module+el8.10.0+90375+641abe33.x86_64.rpm freeradius-postgresql-3.0.20-15.module+el8.10.0+90375+641abe33.x86_64.rpm freeradius-rest-3.0.20-15.module+el8.10.0+90375+641abe33.x86_64.rpm freeradius-sqlite-3.0.20-15.module+el8.10.0+90375+641abe33.x86_64.rpm freeradius-unixODBC-3.0.20-15.module+el8.10.0+90375+641abe33.x86_64.rpm freeradius-utils-3.0.20-15.module+el8.10.0+90375+641abe33.x86_64.rpm python3-freeradius-3.0.20-15.module+el8.10.0+90375+641abe33.x86_64.rpm aarch64: freeradius-3.0.20-15.module+el8.10.0+90375+641abe33.aarch64.rpm freeradius-devel-3.0.20-15.module+el8.10.0+90375+641abe33.aarch64.rpm freeradius-doc-3.0.20-15.module+el8.10.0+90375+641abe33.aarch64.rpm freeradius-krb5-3.0.20-15.module+el8.10.0+90375+641abe33.aarch64.rpm freeradius-ldap-3.0.20-15.module+el8.10.0+90375+641abe33.aarch64.rpm freeradius-mysql-3.0.20-15.module+el8.10.0+90375+641abe33.aarch64.rpm freeradius-perl-3.0.20-15.module+el8.10.0+90375+641abe33.aarch64.rpm freeradius-postgresql-3.0.20-15.module+el8.10.0+90375+641abe33.aarch64.rpm freeradius-rest-3.0.20-15.module+el8.10.0+90375+641abe33.aarch64.rpm freeradius-sqlite-3.0.20-15.module+el8.10.0+90375+641abe33.aarch64.rpm freeradius-unixODBC-3.0.20-15.module+el8.10.0+90375+641abe33.aarch64.rpm freeradius-utils-3.0.20-15.module+el8.10.0+90375+641abe33.aarch64.rpm python3-freeradius-3.0.20-15.module+el8.10.0+90375+641abe33.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//freeradius-3.0.20-15.module+el8.10.0+90375+641abe33.src.rpm Related CVEs: CVE-2024-3596 Description of changes: [3.0.20-15] - Backport BlastRADIUS CVE fix Resolves: RHEL-46572 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Uncover the latest enhancements and patches in Oracle Linux Security Alert ELSA-2024-4936 concerning freeradius and measures to counteract threats.. Oracle Linux, Freeradius Updates, Security Issues, Threat Mitigation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 01, 2024 Important Oracle
219

Rocky Linux 9 RLSA-2024:4935 Important Freeradius Forgery Attack

Important: freeradius security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:4935", "synopsis": "Important: freeradius security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for freeradius.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "FreeRADIUS is a high-performance and highly configurable free Remote Authentication Dial In User Service (RADIUS) server, designed to allow centralized authentication and authorization for a network.\n\nSecurity Fix(es):\n\n* freeradius: forgery attack (CVE-2024-3596)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2263240", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2263240", "description": ""}], "cves": [{"name": "CVE-2024-3596", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-3596", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-08-01T01:29:16.922240Z", "rpms": {"Rocky Linux 9": {"nvras": ["freeradius-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-0:3.0.21-40.el9_4.src.rpm", "freeradius-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-debugsource-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-debugsource-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-debugsource-0:3.0.21-40.el9_4.s390x.rpm","freeradius-debugsource-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-devel-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-devel-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-devel-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-devel-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-doc-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-doc-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-doc-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-doc-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-krb5-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-krb5-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-krb5-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-krb5-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-krb5-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-krb5-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-krb5-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-krb5-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-ldap-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-ldap-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-ldap-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-ldap-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-ldap-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-ldap-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-ldap-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-ldap-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-mysql-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-mysql-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-mysql-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-mysql-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-mysql-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-mysql-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-mysql-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-mysql-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-perl-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-perl-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-perl-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-perl-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-perl-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-perl-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm","freeradius-perl-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-perl-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-postgresql-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-postgresql-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-postgresql-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-postgresql-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-postgresql-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-postgresql-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-postgresql-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-postgresql-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-rest-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-rest-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-rest-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-rest-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-rest-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-rest-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-rest-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-rest-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-sqlite-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-sqlite-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-sqlite-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-sqlite-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-sqlite-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-sqlite-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-sqlite-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-sqlite-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-unixODBC-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-unixODBC-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-unixODBC-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-unixODBC-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-unixODBC-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-unixODBC-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-unixODBC-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-unixODBC-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-utils-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-utils-0:3.0.21-40.el9_4.ppc64le.rpm","freeradius-utils-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-utils-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-utils-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-utils-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-utils-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-utils-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "python3-freeradius-0:3.0.21-40.el9_4.aarch64.rpm", "python3-freeradius-0:3.0.21-40.el9_4.ppc64le.rpm", "python3-freeradius-0:3.0.21-40.el9_4.s390x.rpm", "python3-freeradius-0:3.0.21-40.el9_4.x86_64.rpm", "python3-freeradius-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "python3-freeradius-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "python3-freeradius-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "python3-freeradius-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Urgent update released for FreeRADIUS on Rocky Linux 9, fixing a vulnerability linked to a forgery exploit identified as CVE-2024-3596.. freeradius security, rocky linux update, authentication service, network security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 01, 2024 Important Rocky Linux
219

Rocky Linux 8 RLSA-2024:4936 Important: Freeradius Forgery Attack

Important: freeradius:3.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:4936", "synopsis": "Important: freeradius:3.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for freeradius, module.freeradius.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "FreeRADIUS is a high-performance and highly configurable free Remote Authentication Dial In User Service (RADIUS) server, designed to allow centralized authentication and authorization for a network.\n\nSecurity Fix(es):\n\n* freeradius: forgery attack (CVE-2024-3596)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2263240", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2263240", "description": ""}], "cves": [{"name": "CVE-2024-3596", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-3596", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-08-01T01:28:22.605677Z", "rpms": {"Rocky Linux 8": {"nvras": ["freeradius-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-0:3.0.20-15.module+el8.10.0+1841+f214069a.src.rpm", "freeradius-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-debugsource-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-debugsource-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-devel-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm","freeradius-devel-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-doc-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-doc-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-krb5-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-krb5-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-krb5-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-krb5-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-ldap-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-ldap-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-ldap-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-ldap-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-mysql-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-mysql-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-mysql-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-mysql-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-perl-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-perl-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-perl-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-perl-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-postgresql-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-postgresql-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-postgresql-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-postgresql-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-rest-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-rest-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-rest-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm","freeradius-rest-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-sqlite-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-sqlite-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-sqlite-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-sqlite-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-unixODBC-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-unixODBC-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-unixODBC-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-unixODBC-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-utils-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-utils-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-utils-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-utils-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "python3-freeradius-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "python3-freeradius-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "python3-freeradius-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "python3-freeradius-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. An update for FreeRADIUS on Rocky Linux 8 has been released to patch vulnerabilities related to forgery attacks, enhancing system security and integrity. freeradius update, important security fix, Rocky Linux advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 01, 2024 Important Rocky Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200