Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
100

SUSE perl-HTML-Parser Moderate Heap Memory Issue 2026-22189-1

An update that solves one vulnerability can now be installed.. # Security update for perl-HTML-Parser Announcement ID: SUSE-SU-2026:22189-1 Release Date: 2026-06-20T06:49:38Z Rating: moderate References: * bsc#1267606 Cross-References: * CVE-2026-8829 CVSS scores: * CVE-2026-8829 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-8829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for perl-HTML-Parser fixes the following issue * CVE-2026-8829: HTML:Entities versions before 3.84 for Perl read freed heap memory in _decode_entities (bsc#1267606). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-991=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-991=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * perl-HTML-Parser-debugsource-3.830.0-160000.3.1 * perl-HTML-Parser-3.830.0-160000.3.1 * perl-HTML-Parser-debuginfo-3.830.0-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * perl-HTML-Parser-debugsource-3.830.0-160000.3.1 * perl-HTML-Parser-3.830.0-160000.3.1 * perl-HTML-Parser-debuginfo-3.830.0-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8829.html * https://bugzilla.suse.com/show_bug.cgi?id=1267606 . Important update for SUSE addresses moderate risk in perl-HTML-Parser, resolving security concerns effectively.. SUSE update, perl-HTML-Parser, security patch, medium risk, Linux security. . Severity: moderate.LinuxSecurity.com Team

Calendar%202 Jun 23, 2026 moderate SuSE
202

openSUSE Tumbleweed perl-HTML-Parser Moderate CVE-2026-8829 Notice

An update that solves one vulnerability can now be installed.. # perl-HTML-Parser-3.850.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:10957-1 Rating: moderate Cross-References: * CVE-2026-8829 CVSS scores: * CVE-2026-8829 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the perl-HTML-Parser-3.850.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * perl-HTML-Parser 3.850.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8829.html . A moderate-severity advisory for openSUSE Tumbleweed addresses a security issue in perl-HTML-Parser. Update recommended.. openSUSE Tumbleweed, perl-HTML-Parser, CVE-2026-8829, moderate security. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 08, 2026 moderate OpenSUSE
202

openSUSE apptainer Minor HTML Analyzer Concerns Resolution 2026-0580-1

An update that solves two vulnerabilities and has one security fix can now be installed.. # Security update for apptainer Announcement ID: SUSE-SU-2026:0580-1 Release Date: 2026-02-19T11:38:12Z Rating: moderate References: * bsc#1253924 * bsc#1258047 * bsc#1258048 Cross-References: * CVE-2025-47911 * CVE-2025-58190 CVSS scores: * CVE-2025-47911 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-47911 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47911 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47911 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58190 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * HPC Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP7 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for apptainer fixes the following issues: * CVE-2025-58190: Fixed a HTML parser misimplementation of a part of the HTML specification for table related tags. (bsc#1258048). * CVE-2025-47911: Fixed an issue where the HTML parser takes a very long time or even never returns. (bsc#1258047). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-580=1 openSUSE-SLE-15.6-2026-580=1 * HPC Module 15-SP7 zypper in -t patch SUSE-SLE-Module-HPC-15-SP7-2026-580=1 ## Package List: * openSUSE Leap 15.6 (aarch64 x86_64) *apptainer-1.4.5-150600.4.15.1 * apptainer-debuginfo-1.4.5-150600.4.15.1 * openSUSE Leap 15.6 (noarch) * apptainer-leap-1.4.5-150600.4.15.1 * apptainer-sle15_6-1.4.5-150600.4.15.1 * apptainer-sle15_7-1.4.5-150600.4.15.1 * apptainer-sle16-1.4.5-150600.4.15.1 * HPC Module 15-SP7 (aarch64 x86_64) * apptainer-1.4.5-150600.4.15.1 * apptainer-debuginfo-1.4.5-150600.4.15.1 * HPC Module 15-SP7 (noarch) * apptainer-sle15_7-1.4.5-150600.4.15.1 ## References: * https://www.suse.com/security/cve/CVE-2025-47911.html * https://www.suse.com/security/cve/CVE-2025-58190.html * https://bugzilla.suse.com/show_bug.cgi?id=1253924 * https://bugzilla.suse.com/show_bug.cgi?id=1258047 * https://bugzilla.suse.com/show_bug.cgi?id=1258048 . An update for apptainer addresses critical HTML parser issues in openSUSE, improving stability and security.. apptainer security update, openSUSE patch, HTML parser issues, SUSE vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Feb 19, 2026 OpenSUSE
202

openSUSE: go-sendxmpp Important Memory Issues Fix CVE-2025-47911

An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for go-sendxmpp ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0483-1 Rating: important References: #1251461 #1251677 Cross-References: CVE-2025-47911 CVE-2025-58190 CVSS scores: CVE-2025-47911 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVE-2025-58190 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for go-sendxmpp fixes the following issues: Update to 0.15.1: - Added * Add XEP-0359 Origin-ID to messages (requires go-xmpp > = v0.2.18). - Changed * HTTP upload: Ignore timeouts on disco IQs as some components do not reply. Upgrades the embedded golang.org/x/net to 0.46.0 * Fixes: boo#1251461, CVE-2025-47911: various algorithms with quadratic complexity when parsing HTML documents * Fixes: boo#1251677, CVE-2025-58190: excessive memory consumption by 'html.ParseFragment' when processing specially crafted input Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2025-483=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): go-sendxmpp-0.15.1-bp157.2.6.1 References: https://www.suse.com/security/cve/CVE-2025-47911.html https://www.suse.com/security/cve/CVE-2025-58190.html https://bugzilla.suse.com/1251461 https://bugzilla.suse.com/1251677 . Update for go-sendxmpp resolves two important issues improving security and performance in openSUSE Backports.. go-sendxmpp update, openSUSE security, memory issues resolve, important security fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 24, 2025 Important OpenSUSE
197

Debian 11: DLA-3878-1 Critical: libxml2 XSS and Parsing Vulnerability

Two vulnerabilities have been fixed in the XML library libxml2. CVE-2016-3709 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3878-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk September 05, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libxml2 Version : 2.9.10+dfsg-6.7+deb11u5 CVE ID : CVE-2016-3709 CVE-2022-2309 Debian Bug : 1039991 Two vulnerabilities have been fixed in the XML library libxml2. CVE-2016-3709 HTML 4 parser cross-site scripting CVE-2022-2309 Parser NULL pointer dereference For Debian 11 bullseye, these problems have been fixed in version 2.9.10+dfsg-6.7+deb11u5. We recommend that you upgrade your libxml2 packages. For the detailed security status of libxml2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libxml2 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3878-1 fixes libxml2 vulnerabilities, including cross-site scripting and NULL pointer issues. libxml2 Updates, Debian Security, XML Library Advisory, Cross-Site Scripting, NULL Pointer Fix. . LinuxSecurity.com Team

Calendar%202 Sep 05, 2024 Debian LTS
89

Fedora: 2024-129d8ca6fc High: Jericho HTML Type Confusion Fix

Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-129d8ca6fc 2024-03-07 22:24:39.963937 -------------------------------------------------------------------------------- Name : jericho-html Product : Fedora 40 Version : 3.3 Release : 30.fc40 URL : https://sourceforge.net/projects/jerichohtml/ Summary : Java library allowing analysis and manipulation of parts of an HTML document Description : Jericho HTML Parser is a java library allowing analysis and manipulation of parts of an HTML document, including server-side tags, while reproducing verbatim any unrecognized or invalid HTML. It also provides high-level HTML form manipulation functions. It is an open source library released under both the Eclipse Public License (EPL) and GNU Lesser General Public License (LGPL). You are therefore free to use it in commercial applications subject to the terms detailed in either one of these license documents. -------------------------------------------------------------------------------- Update Information: Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires Automatic update for lucene-9.9.2-1.fc40. bump java source/target to 1.8, fixes 2266639 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 2 2024 Jiri Vanek - 3.3-30 - Rebuilt for java-21-openjdk as system jdk -------------------------------------------------------------------------------- References: [ 1 ] Bug #2123726 - consoleImageViewer crashes at start https://bugzilla.redhat.com/show_bug.cgi?id=2123726 [ 2 ] Bug #2261062 -directory-maven-plugin: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261062 [ 3 ] Bug #2266639 - directory-maven-plugin fails to build with java-21-openjdk https://bugzilla.redhat.com/show_bug.cgi?id=2266639 [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266934 [ 5 ] Bug #2266937 - CVE-2024-1939 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266937 [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta https://bugzilla.redhat.com/show_bug.cgi?id=2267486 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest release features crucial security enhancements for jericho-html addressing type inconsistency problems highlighted in CVE-2024-1938 as well as CVE-2024-1939.. Jericho HTML Security Fix, Fedora Security Update, Type Confusion Vulnerability. . LinuxSecurity.comTeam

Calendar%202 Mar 07, 2024 Fedora
87

Debian: DSA-5472-1 Critical: libxmlparser-java Buffer Overflow Issue

A security vulnerability has been discovered in libhtmlcleaner-java, a Java HTML parser library. An attacker was able to cause a denial of service (StackOverflowError) if the parser runs on user supplied input with deeply nested HTML elements. This update introduces a new nesting depth limit which . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5471-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Markus Koschany August 07, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libhtmlcleaner-java CVE ID : CVE-2023-34624 A security vulnerability has been discovered in libhtmlcleaner-java, a Java HTML parser library. An attacker was able to cause a denial of service (StackOverflowError) if the parser runs on user supplied input with deeply nested HTML elements. This update introduces a new nesting depth limit which can be overridden in cleaner properties. For the oldstable distribution (bullseye), this problem has been fixed in version 2.24-1+deb11u1. For the stable distribution (bookworm), this problem has been fixed in version 2.26-1+deb12u1. We recommend that you upgrade your libhtmlcleaner-java packages. For the detailed security status of libhtmlcleaner-java please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libhtmlcleaner-java Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance libhtmlcleaner-java to address denial of service vulnerabilities stemming from excessively nested HTML content. Implement necessary patches for improved stability.. libhtmlcleaner-java, Denial Of Service, Java HTMLParser. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 07, 2023 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200