Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
172

Ubuntu 22.04 LTS: USN-7892-1 H2O Critical Denial of Service CVE-2023-44487

H2O could be made to crash if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-7892-1 November 26, 2025 h2o vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: H2O could be made to crash if it received specially crafted network traffic. Software Description: - h2o: the optimized HTTP/1, HTTP/2 server Details: It was discovered that H2O exhibited poor server resource management in its HTTP/2 protocol. An attacker could possibly use this issue to cause H2O to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS h2o 2.2.5+dfsg2-6.1ubuntu2+esm1 Available with Ubuntu Pro libh2o0.13 2.2.5+dfsg2-6.1ubuntu2+esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS h2o 2.2.5+dfsg2-3ubuntu0.1~esm1 Available with Ubuntu Pro libh2o0.13 2.2.5+dfsg2-3ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7892-1 CVE-2023-44487 . H2O crash issue in Ubuntu releases identified, requiring immediate patches for critical denial of service vulnerabilities.. H2O Security, Ubuntu 22.04, Denial of Service, H2O HTTP Server, Ubuntu LTS Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 26, 2025 Critical Ubuntu
197

Debian Buster: DLA-3638-1 Moderate: h2o HTTP/2 Server Disruption

A vulnerability has been identified in h2o, a high-performance web server with support for HTTP/2. A security vulnerability CVE-2023-44487 was discovered that could potentially . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3638-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Anton Gladky October 29, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : h2o Version : 2.2.5+dfsg2-2+deb10u2 CVE ID : CVE-2023-44487 Debian Bug : 1054232 A vulnerability has been identified in h2o, a high-performance web server with support for HTTP/2. A security vulnerability CVE-2023-44487 was discovered that could potentially be exploited to disrupt server operation. The vulnerability in the h2o HTTP/2 server was related to the handling of certain types of HTTP/2 requests. In certain scenarios, an attacker could send a series of malicious requests, causing the server to process them rapidly and exhaust system resources. The applied upstream patch changes the ABI. Therefore, if your application is built against any shared libraries of h2o, you need to rebuild it. No Debian package is affected. For Debian 10 buster, this problem has been fixed in version 2.2.5+dfsg2-2+deb10u2. We recommend that you upgrade your h2o packages. For the detailed security status of h2o please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/h2o Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . DLA-3638-1 addresses key security issues in h2o on Debian systems, highlighting risks of denial of service and data leaks. Users must upgrade h2o packages. H2o Security, Debian Updates, HTTP/2 Issues, Server Threats. . LinuxSecurity.com Team

Calendar%202 Oct 31, 2023 Debian LTS
87

Debian: DSA-4508-1 H2O Security Update for Denial Of Service

Three vulnerabilities were discovered in the HTTP/2 code of the H2O HTTP server, which could result in denial of service. For the stable distribution (buster), these problems have been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4508-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff August 24, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : h2o CVE ID : CVE-2019-9512 CVE-2019-9514 CVE-2019-9515 Three vulnerabilities were discovered in the HTTP/2 code of the H2O HTTP server, which could result in denial of service. For the stable distribution (buster), these problems have been fixed in version 2.2.5+dfsg2-2+deb10u1. We recommend that you upgrade your h2o packages. For the detailed security status of h2o please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/h2o Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Updated patches for three security weaknesses in the H2O web server have been implemented to guard against potential denial of service attacks in the stable release of Debian.. H2O HTTP Server, Debian Security, Denial Of Service, Vulnerability Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 24, 2019 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200