Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
202

openSUSE Leap 15.6 govulncheck-vulndb Moderate Update Advisory 2026-0292-1

An update that contains one feature can now be installed.. # Security update for govulncheck-vulndb Announcement ID: SUSE-SU-2026:0292-1 Release Date: 2026-01-26T11:11:53Z Rating: moderate References: * jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 An update that contains one feature can now be installed. ## Description: This update for govulncheck-vulndb fixes the following issues: Update to version 0.0.20260123T022811 2026-01-23T02:28:11Z (jsc#PED-11136). Go CVE Numbering Authority IDs added or updated with aliases: * GO-2025-3764 CVE-2024-44905 GHSA-6xp3-p59p-q4fj * GO-2025-4188 CVE-2025-65637 GHSA-4f99-4q7p-p3gh * GO-2025-4252 CVE-2025-68383 GHSA-2mj3-6grc-px38 * GO-2025-4253 CVE-2025-68388 GHSA-fj69-23m4-ccvv * GO-2026-4310 CVE-2026-22689 GHSA-524m-q5m7-79mm * GO-2026-4311 CVE-2026-22772 GHSA-59jp-pj84-45mr * GO-2026-4312 CVE-2026-22771 GHSA-xrwg-mqj6-6m22 * GO-2026-4313 CVE-2026-22786 GHSA-3558-j79f-vvm6 * GO-2026-4314 CVE-2026-22868 GHSA-mq3p-rrmp-79jg * GO-2026-4315 CVE-2026-22862 GHSA-mr7q-c9w9-wh4h * GO-2026-4316 GHSA-mqqf-5wvp-8fh8 * GO-2026-4317 CVE-2017-18892 GHSA-wj5w-qghh-gvqp * GO-2026-4318 CVE-2025-66292 GHSA-vh2x-fw87-4fxq * GO-2026-4319 CVE-2026-23511 GHSA-pvm5-9frx-264r * GO-2026-4320 CVE-2026-23520 GHSA-gjqq-6r35-w3r8 * GO-2026-4321 CVE-2025-68671 GHSA-f2ph-gc9m-q55f * GO-2026-4322 CVE-2026-22045 GHSA-cwjm-3f7h-9hwq ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-292=1 ## Package List: * openSUSE Leap 15.6 (noarch) * govulncheck-vulndb-0.0.20260123T022811-150000.1.140.1 ## References: * https://jira.suse.com/browse/PED-11136 . An openSUSE update for govulncheck-vulndb addresses moderate severity issues with installation instructions.. openSUSE, govulncheck-vulndb, update,moderate severity, security patch. . LinuxSecurity.com Team

Calendar 2 Jan 26, 2026 OpenSUSE
202

openSUSE Tumbleweed: 2025:14856-1 moderate: go1.24 update

An update that solves one vulnerability can now be installed.. # go1.24-1.24.1-1.1 on GA media Announcement ID: openSUSE-SU-2025:14856-1 Rating: moderate Cross-References: * CVE-2025-22870 CVSS scores: * CVE-2025-22870 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2025-22870 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the go1.24-1.24.1-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * go1.24 1.24.1-1.1 * go1.24-doc 1.24.1-1.1 * go1.24-libstd 1.24.1-1.1 * go1.24-race 1.24.1-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22870.html . The latest openSUSE upgrade for go1.24-1.24.1-1.1 resolves a medium-level security vulnerability. Advisory details are included.. OpenSUSE Updates, Security Patch, Go Application Update, Security Advisory. . LinuxSecurity.com Team

Calendar 2 Mar 07, 2025 OpenSUSE
202

openSUSE Tumbleweed: 2025:14746-1 moderate: go1.23 security patch

An update that solves one vulnerability can now be installed.. # go1.23-1.23.6-1.1 on GA media Announcement ID: openSUSE-SU-2025:14746-1 Rating: moderate Cross-References: * CVE-2025-22866 CVSS scores: * CVE-2025-22866 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-22866 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the go1.23-1.23.6-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * go1.23 1.23.6-1.1 * go1.23-doc 1.23.6-1.1 * go1.23-libstd 1.23.6-1.1 * go1.23-race 1.23.6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22866.html . A recent notice regarding openSUSE Tumbleweed highlights a security vulnerability in the go1.24 software, bolstering overall system safety.. openSUSE Tumbleweed, security update, go1.23 advisory, system package security. . LinuxSecurity.com Team

Calendar 2 Feb 09, 2025 OpenSUSE
202

openSUSE: 2025:14735-1 moderate: go application security advisory

An update that solves 2 vulnerabilities can now be installed.. # go1.24-1.24rc3-1.1 on GA media Announcement ID: openSUSE-SU-2025:14735-1 Rating: moderate Cross-References: * CVE-2025-22866 * CVE-2025-22867 CVSS scores: * CVE-2025-22866 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-22866 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-22867 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the go1.24-1.24rc3-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * go1.24 1.24rc3-1.1 * go1.24-doc 1.24rc3-1.1 * go1.24-libstd 1.24rc3-1.1 * go1.24-race 1.24rc3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22866.html * https://www.suse.com/security/cve/CVE-2025-22867.html . An essential notice for openSUSE addresses moderate vulnerabilities present in the go1.24-1.24rc3-1.1 package, with comprehensive information provided.. openSUSE advisory, go application update, moderate security issues, security advisory, security update. . LinuxSecurity.com Team

Calendar 2 Feb 07, 2025 OpenSUSE
100

SUSE: 2024:2295-1 Important: Go1.22 Denial of Service Advisory

* bsc#1218424 * bsc#1227314 Cross-References: * CVE-2024-24791 . # Security update for go1.22 Announcement ID: SUSE-SU-2024:2295-1 Rating: important References: * bsc#1218424 * bsc#1227314 Cross-References: * CVE-2024-24791 CVSS scores: * CVE-2024-24791 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for go1.22 fixes the following issues: Updated to version 1.22.5 (bsc#1218424): * CVE-2024-24791: Fixed a potential denial of service due to improper handling of HTTP 100-continue headers (bsc#1227314). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-2295=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * go1.22-1.22.5-1.15.1 * go1.22-doc-1.22.5-1.15.1 ## References: * https://www.suse.com/security/cve/CVE-2024-24791.html * https://bugzilla.suse.com/show_bug.cgi?id=1218424 * https://bugzilla.suse.com/show_bug.cgi?id=1227314 . OpenSUSE releases for golang 1.22 tackle severe vulnerabilities. Discover more regarding this crucial advisory release!. SUSE Security Update, go1.22 Denial of Service, Important Security Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jul 03, 2024 Important SuSE
89

Fedora 35 - Update for Node Exporter CVE-2022-27191 Critical Security Issue

Rebuild for CVE-2022-27191. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-3a63897745 2022-04-28 05:50:06.248389 --------------------------------------------------------------------------------Name : golang-github-prometheus-node-exporter Product : Fedora 35 Version : 1.3.1 Release : 7.fc35 URL : https://github.com/prometheus/node_exporter Summary : Exporter for machine metrics Description : Prometheus exporter for hardware and OS metrics exposed by *NIX kernels, written in Go with pluggable metric collectors. --------------------------------------------------------------------------------Update Information: Rebuild for CVE-2022-27191 --------------------------------------------------------------------------------ChangeLog: * Sat Apr 16 2022 Fabio Alessandro Locati 1.3.1-7 - Rebuilt for CVE-2022-27191 --------------------------------------------------------------------------------References: [ 1 ] Bug #2074262 - CVE-2022-27191 golang-x-crypto: golang: crash in a golang.org/x/crypto/ssh server [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2074262 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-3a63897745' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Explore the essential information regarding Fedora 35 pertaining to the node exporter, which tackles significant security vulnerabilities.. Fedora Update, Golang Security, Prometheus Node Exporter. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 28, 2022 Critical Fedora
202

openSUSE Leap 15.2: 2021:0480-1 Moderate: Go1.15 Infinite Loop

An update that solves one vulnerability and has one errata is now available. . openSUSE Security Update: Security update for go1.15 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0480-1 Rating: moderate References: #1175132 #1183333 Cross-References: CVE-2021-27918 CVSS scores: CVE-2021-27918 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for go1.15 fixes the following issues: - go1.15.10 (released 2021-03-11) (bsc#1175132) - go1.15.9 (released 2021-03-10) (bsc#1175132) - CVE-2021-27918: Fixed an infinite loop when using xml.NewTokenDecoder with a custom TokenReader (bsc#1183333). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-480=1 Package List: - openSUSE Leap 15.2 (x86_64): go1.15-1.15.10-lp152.14.1 go1.15-doc-1.15.10-lp152.14.1 go1.15-race-1.15.10-lp152.14.1 References: https://www.suse.com/security/cve/CVE-2021-27918.html https://bugzilla.suse.com/1175132 https://bugzilla.suse.com/1183333 . openSUSE Security Patch for go1.15 addresses several moderate concerns, notably an infinite loop vulnerability.. go application patch, openSUSE security update, moderate issues. . LinuxSecurity.com Team

Calendar 2 Mar 27, 2021 OpenSUSE
203

Mageia: 2019-0310 Critical: Golang Denial Of Service Issue

Updated golang packages fix security vulnerability: Daniel Mandragona discovered that invalid DSA public keys can cause a panic in dsa.Verify(), resulting in denial of service (CVE-2019-17596). . MGASA-2019-0310 - Updated golang packages fix security vulnerability Publication date: 02 Nov 2019 URL: https://advisories.mageia.org/MGASA-2019-0310.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-17596 Updated golang packages fix security vulnerability: Daniel Mandragona discovered that invalid DSA public keys can cause a panic in dsa.Verify(), resulting in denial of service (CVE-2019-17596). References: - https://bugs.mageia.org/show_bug.cgi?id=25616 - https://groups.google.com/forum/#!msg/golang-announce/lVEm7llp0w0/VbafyRkgCgAJ - https://lists.debian.org/debian-security-announce/2019/msg00203.html - https://www.cve.org/CVERecord?id=CVE-2019-17596 SRPMS: - 7/core/golang-1.12.11-1.mga7 . Revised Go libraries tackle service interruption caused by incorrect DSA key usage. Patch issued on November 2, 2019.. Golang Security Update, Mageia Advisory, DSA Key Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 02, 2019 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here