Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 2 articles for you...
89

Fedora 41: rust-ammonia 3.3.1 Security Advisory RUSTSEC-2025-0071

Update the ammonia crate to version 3.3.1 and rebuild python-nh3 to apply fixes for RUSTSEC-2025-0071.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-1be5992b52 2025-10-01 15:00:59.894553+00:00 -------------------------------------------------------------------------------- Name : rust-ammonia Product : Fedora 41 Version : 3.3.1 Release : 1.fc41 URL : https://crates.io/crates/ammonia Summary : HTML Sanitization Description : HTML Sanitization. -------------------------------------------------------------------------------- Update Information: Update the ammonia crate to version 3.3.1 and rebuild python-nh3 to apply fixes for RUSTSEC-2025-0071. -------------------------------------------------------------------------------- ChangeLog: * Mon Sep 22 2025 Fabio Valentini - 3.3.1-1 - Update to version 3.3.1 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-1be5992b52' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not replyto spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fixes for HTML sanitization issue in rust-ammonia 3.3.1 released for Fedora 41 addressing RUSTSEC-2025-0071 vulnerability.. rust-ammonia updates, Fedora 41 security, HTML sanitization issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 01, 2025 Important Fedora
89

Fedora: rust-ammonia 4.0.1 Security Update RUSTSEC-2025-0071

Update the ammonia crate to version 4.0.1 and rebuild python-nh3 to apply fixes for RUSTSEC-2025-0071.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-7ec84ba6e9 2025-10-01 14:43:51.750497+00:00 -------------------------------------------------------------------------------- Name : rust-ammonia Product : Fedora 42 Version : 4.0.1 Release : 1.fc42 URL : https://crates.io/crates/ammonia Summary : HTML Sanitization Description : HTML Sanitization. -------------------------------------------------------------------------------- Update Information: Update the ammonia crate to version 4.0.1 and rebuild python-nh3 to apply fixes for RUSTSEC-2025-0071. -------------------------------------------------------------------------------- ChangeLog: * Mon Sep 22 2025 Fabio Valentini - 4.0.1-1 - Update to version 4.0.1 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7ec84ba6e9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not replyto spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Update rust-ammonia to version 4.0.1 for HTML sanitization fixes on Fedora 42. Apply necessary updates today.. Fedora 42,rust-ammonia,HTML Sanitization updates,security advisory. . LinuxSecurity.com Team

Calendar%202 Oct 01, 2025 Fedora
89

Fedora 43: rust-ammonia Update RUSTSEC-2025-0071 HTML Fix

Update the ammonia crate to version 4.1.2 and rebuild python-nh3 to apply fixes for RUSTSEC-2025-0071.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-074aba6ad4 2025-10-01 00:14:58.043372+00:00 -------------------------------------------------------------------------------- Name : rust-ammonia Product : Fedora 43 Version : 4.1.2 Release : 1.fc43 URL : https://crates.io/crates/ammonia Summary : HTML Sanitization Description : HTML Sanitization. -------------------------------------------------------------------------------- Update Information: Update the ammonia crate to version 4.1.2 and rebuild python-nh3 to apply fixes for RUSTSEC-2025-0071. -------------------------------------------------------------------------------- ChangeLog: * Mon Sep 22 2025 Fabio Valentini - 4.1.2-1 - Update to version 4.1.2; Fixes RHBZ#2397219 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2396811 - python-nh3: Please rebuild in Fedora 43 https://bugzilla.redhat.com/show_bug.cgi?id=2396811 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-074aba6ad4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Update ammonia crate to version 4.1.2 for HTML sanitation improvements in Fedora 43.. Fedora security advisory, HTML sanitization, rust-ammonia update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 01, 2025 Important Fedora
203

Mageia: MGASA-2021-0260 moderate: python-bleach xss Issue

It was reported that python-bleach, a whitelist-based HTML-sanitizing library, is prone to a mutation XSS vulnerability in bleach.clean when "svg" or "math" are in the allowed tags, 'p' or "br" are in allowed tags, "style", "title", "noscript", "script", "textarea", "noframes", "iframe", or "xmp" are in allowed tags and 'strip_comments=False' is set (CVE-2021-23980). . MGASA-2021-0260 - Updated python-bleach packages fix a security vulnerability Publication date: 16 Jun 2021 URL: https://advisories.mageia.org/MGASA-2021-0260.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-23980 It was reported that python-bleach, a whitelist-based HTML-sanitizing library, is prone to a mutation XSS vulnerability in bleach.clean when "svg" or "math" are in the allowed tags, 'p' or "br" are in allowed tags, "style", "title", "noscript", "script", "textarea", "noframes", "iframe", or "xmp" are in allowed tags and 'strip_comments=False' is set (CVE-2021-23980). References: - https://bugs.mageia.org/show_bug.cgi?id=28986 - https://lists.debian.org/debian-security-announce/2021/msg00073.html - https://github.com/mozilla/bleach/security/advisories/GHSA-vv2x-vrpj-qqpq - - https://www.cve.org/CVERecord?id=CVE-2021-23980 SRPMS: - 7/core/python-bleach-3.1.4-1.1.mga7 - 8/core/python-bleach-3.3.0-1.mga8 . Recent patches to python-bleach tackle a critical XSS vulnerability impacting permitted tags; vital for safeguarding web applications on Mageia.. Python Bleach Update, HTML Sanitization, Mageia Security. . LinuxSecurity.com Team

Calendar%202 Jun 16, 2021 Mageia
87

Debian DSA-4892-1 Critical: Mutation XSS in Python-Bleach

It was reported that python-bleach, a whitelist-based HTML-sanitizing library, is prone to a mutation XSS vulnerability in bleach.clean when 'svg' or 'math' are in the allowed tags, 'p' or 'br' are in allowed tags, 'style', 'title', 'noscript', 'script', 'textarea', 'noframes', . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4892-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso April 18, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : python-bleach CVE ID : CVE-2021-23980 Debian Bug : 986251 It was reported that python-bleach, a whitelist-based HTML-sanitizing library, is prone to a mutation XSS vulnerability in bleach.clean when 'svg' or 'math' are in the allowed tags, 'p' or 'br' are in allowed tags, 'style', 'title', 'noscript', 'script', 'textarea', 'noframes', 'iframe', or 'xmp' are in allowed tags and 'strip_comments=False' is set. For the stable distribution (buster), this problem has been fixed in version 3.1.2-0+deb10u2. We recommend that you upgrade your python-bleach packages. For the detailed security status of python-bleach please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/python-bleach Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-4903-1 highlights a reflected XSS vulnerability in flask-cors's handling of cross-origin requests.. Debian Advisory, XSS Threat, Python Bleach Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 18, 2021 Critical Debian
87

Debian: DSA-4730-1 Critical: Ruby-Sanitize HTML Bypass Vulnerability

Michal Bentkowski discovered that ruby-sanitize, a whitelist-based HTML sanitizer, is prone to a HTML sanitization bypass vulnerability when using the "relaxed" or a custom config allowing certain elements. Content in a or element may not be sanitized correctly even . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4730-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso July 19, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ruby-sanitize CVE ID : CVE-2020-4054 Debian Bug : 963808 Michal Bentkowski discovered that ruby-sanitize, a whitelist-based HTML sanitizer, is prone to a HTML sanitization bypass vulnerability when using the "relaxed" or a custom config allowing certain elements. Content in a or element may not be sanitized correctly even if math and svg are not in the allowlist. For the stable distribution (buster), this problem has been fixed in version 4.6.6-2.1~deb10u1. We recommend that you upgrade your ruby-sanitize packages. For the detailed security status of ruby-sanitize please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ruby-sanitize Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-4731-1 addresses vulnerability in python-requests; updating advised for protection.. ruby-sanitize update, HTML sanitizer flaw, Debian security patches. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 19, 2020 Critical Debian
100

SUSE: 2019:2209-1 Moderate: rubygem-loofah Security Issue

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for rubygem-loofah ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2209-1 Rating: moderate References: #1086598 Cross-References: CVE-2018-8048 Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 7 SUSE Enterprise Storage 4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for rubygem-loofah fixes the following issues: - Security issue fixed: - CVE-2018-8048: Update fix to make Loofah::HTML5::Scrub.force_correct_attribute_escaping! callable from other gems (bsc#1086598). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2019-2209=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2019-2209=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2019-2209=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2019-2209=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): ruby2.1-rubygem-loofah-2.0.2-3.8.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): ruby2.1-rubygem-loofah-2.0.2-3.8.1 - SUSE OpenStack Cloud 7 (aarch64 s390x x86_64): ruby2.1-rubygem-loofah-2.0.2-3.8.1 - SUSE Enterprise Storage 4 (aarch64 x86_64): ruby2.1-rubygem-loofah-2.0.2-3.8.1 References: https://www.suse.com/security/cve/CVE-2018-8048.html https://bugzilla.suse.com/1086598 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE has released a security update for rubygem-loofah to tackle a moderate security vulnerability. Detailed patch instructions can be found here.. rubygem-loofah, SUSE security update, moderate issues, html scrubbing. . LinuxSecurity.com Team

Calendar%202 Aug 23, 2019 SuSE
87

Debian: DSA-4364-1 Moderate: Ruby-Loofah SVG Sanitization Issue

It was discovered that ruby-loofah, a general library for manipulating and transforming HTML/XML documents and fragments, performed insufficient sanitising of SVG elements. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4364-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff January 08, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ruby-loofah CVE ID : CVE-2018-16468 It was discovered that ruby-loofah, a general library for manipulating and transforming HTML/XML documents and fragments, performed insufficient sanitising of SVG elements. For the stable distribution (stretch), this problem has been fixed in version 2.0.3-2+deb9u2. We recommend that you upgrade your ruby-loofah packages. For the detailed security status of ruby-loofah please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ruby-loofah Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - --------------------------------------------------. ruby-loofah, general, library, manipulating, transforming, html/xml. . LinuxSecurity.com Team

Calendar%202 Jan 08, 2019 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200