Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 4 articles for you...
219

Rocky Linux gmp Low Integer Overflow Security Issue RLSA-2023-6661

Low: gmp security and enhancement update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:6661", "synopsis": "Low: gmp security and enhancement update", "severity": "SEVERITY_LOW", "topic": "An update is available for gmp.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The gmp packages contain GNU MP, a library for arbitrary precision arithmetics, signed integers operations, rational numbers, and floating point numbers. \n\nSecurity Fix(es):\n\n* gmp: Integer overflow and resultant buffer overflow via crafted input (CVE-2021-43618)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Rocky Linux 9.3 Release Notes linked from the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2024904", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2024904", "description": ""}], "cves": [{"name": "CVE-2021-43618", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43618", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.2", "cwe": "CWE-190"}], "references": [], "publishedAt": "2026-06-25T12:03:37.665962Z", "rpms": {"Rocky Linux 9": {"nvras": ["gmp-1:6.2.0-13.el9.aarch64.rpm", "gmp-1:6.2.0-13.el9.i686.rpm", "gmp-1:6.2.0-13.el9.ppc64le.rpm", "gmp-1:6.2.0-13.el9.s390x.rpm", "gmp-1:6.2.0-13.el9.src.rpm", "gmp-1:6.2.0-13.el9.x86_64.rpm", "gmp-c++-1:6.2.0-13.el9.aarch64.rpm", "gmp-c++-1:6.2.0-13.el9.i686.rpm", "gmp-c++-1:6.2.0-13.el9.ppc64le.rpm", "gmp-c++-1:6.2.0-13.el9.s390x.rpm", "gmp-c++-1:6.2.0-13.el9.x86_64.rpm", "gmp-c++-debuginfo-1:6.2.0-13.el9.aarch64.rpm","gmp-c++-debuginfo-1:6.2.0-13.el9.i686.rpm", "gmp-c++-debuginfo-1:6.2.0-13.el9.ppc64le.rpm", "gmp-c++-debuginfo-1:6.2.0-13.el9.s390x.rpm", "gmp-c++-debuginfo-1:6.2.0-13.el9.x86_64.rpm", "gmp-debuginfo-1:6.2.0-13.el9.aarch64.rpm", "gmp-debuginfo-1:6.2.0-13.el9.i686.rpm", "gmp-debuginfo-1:6.2.0-13.el9.ppc64le.rpm", "gmp-debuginfo-1:6.2.0-13.el9.s390x.rpm", "gmp-debuginfo-1:6.2.0-13.el9.x86_64.rpm", "gmp-debugsource-1:6.2.0-13.el9.aarch64.rpm", "gmp-debugsource-1:6.2.0-13.el9.i686.rpm", "gmp-debugsource-1:6.2.0-13.el9.ppc64le.rpm", "gmp-debugsource-1:6.2.0-13.el9.s390x.rpm", "gmp-debugsource-1:6.2.0-13.el9.x86_64.rpm", "gmp-devel-1:6.2.0-13.el9.aarch64.rpm", "gmp-devel-1:6.2.0-13.el9.i686.rpm", "gmp-devel-1:6.2.0-13.el9.ppc64le.rpm", "gmp-devel-1:6.2.0-13.el9.s390x.rpm", "gmp-devel-1:6.2.0-13.el9.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Learn about the gmp security update for Rocky Linux that addresses a potential integer overflow issue and enhancement measures.. Rocky Linux update,gmp security update,buffer overflow issue,integration issues,integer overflow. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Jun 25, 2026 Low Rocky Linux
91

Gentoo: GLSA-202309-13 Normal: GMP Buffer Overflow DoS Threat

A buffer overflow vulnerability has been found in GMP which could result in denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202309-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: GMP: Buffer Overflow Vulnerability Date: September 29, 2023 Bugs: #823804 ID: 202309-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A buffer overflow vulnerability has been found in GMP which could result in denial of service. Background ========== The GNU Multiple Precision Arithmetic Library is a library forarbitrary- precision arithmetic on different types of numbers. Affected packages ================= Package Vulnerable Unaffected ------------ ------------ ------------ dev-libs/gmp < 6.2.1-r2 > = 6.2.1-r2 Description =========== There is an integer overflow leading to a buffer overflow when processing untrusted input via GMP's mpz_inp_raw function. Impact ====== Untrusted input can cause a denial of service via segmentation fault. Workaround ========== Users can ensure no untrusted input is passed into GMP's mpz_inp_raw function. Resolution ========== All GMP users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/gmp-6.2.1-r2" References ========== [ 1 ] CVE-2021-43618 https://nvd.nist.gov/vuln/detail/CVE-2021-43618 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202309-13 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should beaddressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2023 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . GMP Buffer Overflow Threat Addressed in Gentoo GLSA 202309-13 - Learn How to Safeguard Your System. GMP Buffer Overflow,Gentoo Advisory,Security Update,Denial of Service. . LinuxSecurity.com Team

Calendar%202 Sep 29, 2023 Gentoo
172

Ubuntu 14.04 ESM USN-5672-2 Warning for Moderate GMP Crash Risk

GMP could be made to crash if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-5672-2 March 06, 2023 gmp vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 ESM Summary: GMP could be made to crash if it received specially crafted input. Software Description: - gmp: Multiprecision arithmetic library developers tools Details: USN-5672-1 fixed a vulnerability in GMP. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: It was discovered that GMP did not properly manage memory on 32-bit platforms when processing a specially crafted input. An attacker could possibly use this issue to cause applications using GMP to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM: libgmp-dev 2:5.1.3+dfsg-1ubuntu1+esm1 libgmp10 2:5.1.3+dfsg-1ubuntu1+esm1 libgmpxx4ldbl 2:5.1.3+dfsg-1ubuntu1+esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5672-2 https://ubuntu.com/security/notices/USN-5672-1 CVE-2021-43618 . A vulnerability in GMP may lead to a system failure when processing specially designed input, impacting Ubuntu 14.04 ESM users. Update now for the necessary patch.. GMP Crash, Ubuntu Update, Denial Of Service. . LinuxSecurity.com Team

Calendar%202 Mar 06, 2023 Ubuntu
172

Ubuntu: 5672-1 Critical: GMP Denial Of Service Impacting Multiple Versions

GMP could be made to crash if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-5672-1 October 12, 2022 GMP vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM Summary: GMP could be made to crash if it received specially crafted input. Software Description: - gmp: Multiprecision arithmetic library developers tools Details: It was discovered that GMP did not properly manage memory on 32-bit platforms when processing a specially crafted input. An attacker could possibly use this issue to cause applications using GMP to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libgmp-dev 2:6.2.0+dfsg-4ubuntu0.1 libgmp10 2:6.2.0+dfsg-4ubuntu0.1 libgmpxx4ldbl 2:6.2.0+dfsg-4ubuntu0.1 Ubuntu 18.04 LTS: libgmp-dev 2:6.1.2+dfsg-2ubuntu0.1 libgmp10 2:6.1.2+dfsg-2ubuntu0.1 libgmpxx4ldbl 2:6.1.2+dfsg-2ubuntu0.1 Ubuntu 16.04 ESM: libgmp-dev 2:6.1.0+dfsg-2ubuntu0.1~esm1 libgmp10 2:6.1.0+dfsg-2ubuntu0.1~esm1 libgmpxx4ldbl 2:6.1.0+dfsg-2ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5672-1 CVE-2021-43618 Package Information: https://launchpad.net/ubuntu/+source/gmp/2:6.2.0+dfsg-4ubuntu0.1 https://launchpad.net/ubuntu/+source/gmp/2:6.1.2+dfsg-2ubuntu0.1 . A newly discovered bug in GMP poses risks of system failures on Fedora. Users using affected versions should apply updates promptly.. GMP Denial Of Service, Ubuntu Security Advisory, Update Recommendations, Software Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 12, 2022 Critical Ubuntu
202

openSUSE Leap 15.3: 2021:1623-1 Important: libpng Memory Corruption

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for gmp ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1569-1 Rating: moderate References: #1192717 Cross-References: CVE-2021-43618 CVSS scores: CVE-2021-43618 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-43618 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gmp fixes the following issues: - CVE-2021-43618: Fixed buffer overflow via crafted input in mpz/inp_raw.c (bsc#1192717). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-1569=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): gmp-debugsource-6.1.2-lp152.6.6.1 gmp-devel-6.1.2-lp152.6.6.1 libgmp10-6.1.2-lp152.6.6.1 libgmp10-debuginfo-6.1.2-lp152.6.6.1 libgmpxx4-6.1.2-lp152.6.6.1 libgmpxx4-debuginfo-6.1.2-lp152.6.6.1 - openSUSE Leap 15.2 (x86_64): gmp-devel-32bit-6.1.2-lp152.6.6.1 libgmp10-32bit-6.1.2-lp152.6.6.1 libgmp10-32bit-debuginfo-6.1.2-lp152.6.6.1 libgmpxx4-32bit-6.1.2-lp152.6.6.1 libgmpxx4-32bit-debuginfo-6.1.2-lp152.6.6.1 References: https://www.suse.com/security/cve/CVE-2021-43618.html https://bugzilla.suse.com/1192717 . The openSUSE Security Update mitigates a buffer overflow vulnerability in gmp, classified with moderate severity, and includesdetailed patch guidance.. openSUSE Update, gmp Security Patch, Buffer Overflow Fix, Software Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 10, 2021 Important OpenSUSE
100

SUSE: 2021:573-1 Moderate: gmp Buffer Overflow and Security Fix

The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2021:573-1 Container Tags : suse/sle15:15.3 , suse/sle15:15.3.17.8.41 Container Release : 17.8.41 Severity : moderate Type : security References : 1192717 CVE-2021-43618 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:3946-1 Released: Mon Dec 6 14:57:42 2021 Summary: Security update for gmp Type: security Severity: moderate References: 1192717,CVE-2021-43618 This update for gmp fixes the following issues: - CVE-2021-43618: Fixed buffer overflow via crafted input in mpz/inp_raw.c (bsc#1192717). The following package changes have been done: - libgmp10-6.1.2-4.9.1 updated . SUSE Container Maintenance Notification for suse/sle15, encompasses security enhancements and fixes for moderate vulnerabilities.. SUSE Container, Security Update, Buffer Overflow, Package Update. . LinuxSecurity.com Team

Calendar%202 Dec 07, 2021 SuSE
100

SUSE: 2021:569-1 Moderate: gmp Buffer Overflow in suse/sle15

The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2021:569-1 Container Tags : suse/sle15:15.2 , suse/sle15:15.2.9.5.58 Container Release : 9.5.58 Severity : moderate Type : security References : 1192717 CVE-2021-43618 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:3946-1 Released: Mon Dec 6 14:57:42 2021 Summary: Security update for gmp Type: security Severity: moderate References: 1192717,CVE-2021-43618 This update for gmp fixes the following issues: - CVE-2021-43618: Fixed buffer overflow via crafted input in mpz/inp_raw.c (bsc#1192717). The following package changes have been done: - libgmp10-6.1.2-4.9.1 updated . Essential security enhancement for suse/sle15 image resolving issue CVE-2021-43619, incorporating critical updates.. SUSE Container, gmp Update, SUSE Advisory, security patches. . LinuxSecurity.com Team

Calendar%202 Dec 07, 2021 SuSE
202

openSUSE Leap 15.3: 2021:3946-1 Moderate: GMP Buffer Overflow

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for gmp ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:3946-1 Rating: moderate References: #1192717 Cross-References: CVE-2021-43618 CVSS scores: CVE-2021-43618 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-43618 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gmp fixes the following issues: - CVE-2021-43618: Fixed buffer overflow via crafted input in mpz/inp_raw.c (bsc#1192717). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-3946=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): gmp-debugsource-6.1.2-4.9.1 gmp-devel-6.1.2-4.9.1 libgmp10-6.1.2-4.9.1 libgmp10-debuginfo-6.1.2-4.9.1 libgmpxx4-6.1.2-4.9.1 libgmpxx4-debuginfo-6.1.2-4.9.1 - openSUSE Leap 15.3 (x86_64): gmp-devel-32bit-6.1.2-4.9.1 libgmp10-32bit-6.1.2-4.9.1 libgmp10-32bit-debuginfo-6.1.2-4.9.1 libgmpxx4-32bit-6.1.2-4.9.1 libgmpxx4-32bit-debuginfo-6.1.2-4.9.1 References: https://www.suse.com/security/cve/CVE-2021-43618.html https://bugzilla.suse.com/1192717 . Patch released to address buffer overflow issue in GMP for openSUSE Leap 15.3. Discover steps to enhance your system security.. openSUSE Update, GMP Security Fix, Buffer Overflow Fix, Linux Advisory. . LinuxSecurity.com Team

Calendar%202 Dec 06, 2021 OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200