Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 494
Alerts This Week
Warning Icon 1 494

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 11 articles for you...
89

Fedora 43 FreeIPA Critical Samba RCE CVEs 2026-FC81581A79

Update to Samba 4.23.8 - Security fix for CVE-2026-4480, CVE-2026-2340, CVE-2026-3012, CVE-2026-1933, CVE-2026-4408, and CVE-2026-3238. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fc81581a79 2026-06-05 04:07:33.980053+00:00 -------------------------------------------------------------------------------- Name : freeipa Product : Fedora 43 Version : 4.13.1 Release : 7.fc43 URL : http://www.freeipa.org/ Summary : The Identity, Policy and Audit system Description : IPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts). -------------------------------------------------------------------------------- Update Information: Update to Samba 4.23.8 - Security fix for CVE-2026-4480, CVE-2026-2340, CVE-2026-3012, CVE-2026-1933, CVE-2026-4408, and CVE-2026-3238 -------------------------------------------------------------------------------- ChangeLog: * Fri May 29 2026 Alexander Bokovoy - 4.13.1-7 - Rebuild against Samba 4.23.8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2481447 - CVE-2026-4480 samba: Samba: Remote Code Execution in printing subsystem via unescaped job description [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481447 [ 2 ] Bug #2481857 - CVE-2026-3012 samba: group policy certificate enrollment uses http:// without validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481857 [ 3 ] Bug #2481875 - CVE-2026-2340 samba: vfs_worm does not block directory modification [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481875 [ 4 ] Bug #2481876- CVE-2026-1933 samba: Missing access check on reparse point operations [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481876 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fc81581a79' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Samba 4.23.8 update includes critical security fixes for multiple CVEs in Fedora 43 related to remote code execution. . Fedora Samba Update, Remote Code Execution CVEs, Security Advisory 2026, Fedora FreeIPA, Samba Version 4.23.8. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 05, 2026 Critical Fedora
219

Rocky Linux 8 IdM Critical Denial of Service Security Alert RLSA-2025-21140

Important: idm:DL1 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:21140", "synopsis": "Important: idm:DL1 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for ipa-healthcheck, module.softhsm, bind-dyndb-ldap, module.ipa-healthcheck, python-yubico, python-jwcrypto, custodia, opendnssec, module.python-qrcode, module.python-kdcproxy, slapi-nis, module.python-yubico, module.python-jwcrypto, softhsm, module.ipa, module.slapi-nis, module.bind-dyndb-ldap, python-kdcproxy, module.opendnssec, ipa, python-qrcode, module.custodia, module.pyusb, pyusb.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Rocky Enterprise Software Foundation Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments. \n\nSecurity Fix(es):\n\n* python-kdcproxy: Unauthenticated SSRF via Realm?Controlled DNS SRV (CVE-2025-59088)\n\n* python-kdcproxy: Remote DoS via unbounded TCP upstream buffering (CVE-2025-59089)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2393955", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2393955", "description": ""}, {"ticket": "2393958", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2393958", "description": ""}], "cves": [{"name": "CVE-2025-59088", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-59088", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N", "cvss3BaseScore": "8.6", "cwe": "CWE-918"}, {"name": "CVE-2025-59089", "sourceBy": "MITRE","sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-59089", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-770"}], "references": [], "publishedAt": "2025-11-27T09:05:18.620599Z", "rpms": {"Rocky Linux 8": {"nvras": ["bind-dyndb-ldap-0:11.6-6.module+el8.10.0+1960+1ed527b3.aarch64.rpm", "bind-dyndb-ldap-0:11.6-6.module+el8.10.0+1960+1ed527b3.src.rpm", "bind-dyndb-ldap-0:11.6-6.module+el8.10.0+1960+1ed527b3.x86_64.rpm", "bind-dyndb-ldap-debuginfo-0:11.6-6.module+el8.10.0+1960+1ed527b3.aarch64.rpm", "bind-dyndb-ldap-debuginfo-0:11.6-6.module+el8.10.0+1960+1ed527b3.x86_64.rpm", "bind-dyndb-ldap-debugsource-0:11.6-6.module+el8.10.0+1960+1ed527b3.aarch64.rpm", "bind-dyndb-ldap-debugsource-0:11.6-6.module+el8.10.0+1960+1ed527b3.x86_64.rpm", "custodia-0:0.6.0-3.module+el8.9.0+1371+ffa84eb9.noarch.rpm", "custodia-0:0.6.0-3.module+el8.9.0+1371+ffa84eb9.src.rpm", "ipa-0:4.9.13-20.module+el8.10.0+2067+377bdd64.src.rpm", "ipa-0:4.9.13-20.module+el8.10.0+2066+d74ade98.src.rpm", "ipa-client-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-client-0:4.9.13-20.module+el8.10.0+2067+377bdd64.aarch64.rpm", "ipa-client-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "ipa-client-0:4.9.13-20.module+el8.10.0+2067+377bdd64.x86_64.rpm", "ipa-client-common-0:4.9.13-20.module+el8.10.0+2067+377bdd64.noarch.rpm", "ipa-client-common-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "ipa-client-debuginfo-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-client-debuginfo-0:4.9.13-20.module+el8.10.0+2067+377bdd64.aarch64.rpm", "ipa-client-debuginfo-0:4.9.13-20.module+el8.10.0+2067+377bdd64.x86_64.rpm", "ipa-client-debuginfo-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "ipa-client-epn-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-client-epn-0:4.9.13-20.module+el8.10.0+2067+377bdd64.aarch64.rpm", "ipa-client-epn-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm","ipa-client-epn-0:4.9.13-20.module+el8.10.0+2067+377bdd64.x86_64.rpm", "ipa-client-samba-0:4.9.13-20.module+el8.10.0+2067+377bdd64.aarch64.rpm", "ipa-client-samba-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-client-samba-0:4.9.13-20.module+el8.10.0+2067+377bdd64.x86_64.rpm", "ipa-client-samba-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "ipa-common-0:4.9.13-20.module+el8.10.0+2067+377bdd64.noarch.rpm", "ipa-common-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "ipa-debuginfo-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-debuginfo-0:4.9.13-20.module+el8.10.0+2067+377bdd64.aarch64.rpm", "ipa-debuginfo-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "ipa-debuginfo-0:4.9.13-20.module+el8.10.0+2067+377bdd64.x86_64.rpm", "ipa-debugsource-0:4.9.13-20.module+el8.10.0+2067+377bdd64.aarch64.rpm", "ipa-debugsource-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-debugsource-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "ipa-debugsource-0:4.9.13-20.module+el8.10.0+2067+377bdd64.x86_64.rpm", "ipa-healthcheck-0:0.12-6.module+el8.10.0+2054+aa003774.noarch.rpm", "ipa-healthcheck-0:0.12-6.module+el8.10.0+2053+a0a9dc19.src.rpm", "ipa-healthcheck-0:0.12-6.module+el8.10.0+2054+aa003774.src.rpm", "ipa-healthcheck-core-0:0.12-6.module+el8.10.0+2054+aa003774.noarch.rpm", "ipa-healthcheck-core-0:0.12-6.module+el8.10.0+2053+a0a9dc19.noarch.rpm", "ipa-python-compat-0:4.9.13-20.module+el8.10.0+2067+377bdd64.noarch.rpm", "ipa-python-compat-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "ipa-selinux-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "ipa-selinux-0:4.9.13-20.module+el8.10.0+2067+377bdd64.noarch.rpm", "ipa-server-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-server-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "ipa-server-common-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "ipa-server-debuginfo-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm","ipa-server-debuginfo-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "ipa-server-dns-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "ipa-server-trust-ad-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-server-trust-ad-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "ipa-server-trust-ad-debuginfo-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-server-trust-ad-debuginfo-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "opendnssec-0:2.1.7-2.module+el8.10.0+1960+1ed527b3.aarch64.rpm", "opendnssec-0:2.1.7-2.module+el8.10.0+1960+1ed527b3.src.rpm", "opendnssec-0:2.1.7-2.module+el8.10.0+1960+1ed527b3.x86_64.rpm", "opendnssec-debuginfo-0:2.1.7-2.module+el8.10.0+1960+1ed527b3.aarch64.rpm", "opendnssec-debuginfo-0:2.1.7-2.module+el8.10.0+1960+1ed527b3.x86_64.rpm", "opendnssec-debugsource-0:2.1.7-2.module+el8.10.0+1960+1ed527b3.aarch64.rpm", "opendnssec-debugsource-0:2.1.7-2.module+el8.10.0+1960+1ed527b3.x86_64.rpm", "python3-custodia-0:0.6.0-3.module+el8.9.0+1371+ffa84eb9.noarch.rpm", "python3-ipaclient-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "python3-ipaclient-0:4.9.13-20.module+el8.10.0+2067+377bdd64.noarch.rpm", "python3-ipalib-0:4.9.13-20.module+el8.10.0+2067+377bdd64.noarch.rpm", "python3-ipalib-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "python3-ipaserver-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "python3-ipatests-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "python3-jwcrypto-0:0.5.0-2.module+el8.10.0+1819+0aeba2f1.noarch.rpm", "python3-jwcrypto-0:0.5.0-2.module+el8.10.0+1818+2dfda7a6.noarch.rpm", "python3-kdcproxy-0:0.4-5.module+el8.10.0+2094+d7886766.2.noarch.rpm", "python3-pyusb-0:1.0.0-9.1.module+el8.9.0+1372+09f67869.noarch.rpm", "python3-pyusb-0:1.0.0-9.1.module+el8.9.0+1371+ffa84eb9.noarch.rpm", "python3-qrcode-0:5.3-1.module+el8.10.0+1916+6bb8cf6b.noarch.rpm", "python3-qrcode-0:5.3-1.module+el8.10.0+1915+3c70f7d9.noarch.rpm", "python3-qrcode-core-0:5.3-1.module+el8.10.0+1916+6bb8cf6b.noarch.rpm","python3-qrcode-core-0:5.3-1.module+el8.10.0+1915+3c70f7d9.noarch.rpm", "python3-yubico-0:1.3.2-9.1.module+el8.9.0+1371+ffa84eb9.noarch.rpm", "python3-yubico-0:1.3.2-9.1.module+el8.9.0+1372+09f67869.noarch.rpm", "python-jwcrypto-0:0.5.0-2.module+el8.10.0+1818+2dfda7a6.src.rpm", "python-jwcrypto-0:0.5.0-2.module+el8.10.0+1819+0aeba2f1.src.rpm", "python-kdcproxy-0:0.4-5.module+el8.9.0+1371+ffa84eb9.src.rpm", "python-kdcproxy-0:0.4-5.module+el8.10.0+1915+3c70f7d9.1.src.rpm", "python-kdcproxy-0:0.4-5.module+el8.10.0+2094+d7886766.2.src.rpm", "python-qrcode-0:5.3-1.module+el8.10.0+1915+3c70f7d9.src.rpm", "python-qrcode-0:5.3-1.module+el8.10.0+1916+6bb8cf6b.src.rpm", "python-yubico-0:1.3.2-9.1.module+el8.9.0+1372+09f67869.src.rpm", "python-yubico-0:1.3.2-9.1.module+el8.9.0+1371+ffa84eb9.src.rpm", "pyusb-0:1.0.0-9.1.module+el8.9.0+1372+09f67869.src.rpm", "pyusb-0:1.0.0-9.1.module+el8.9.0+1371+ffa84eb9.src.rpm", "slapi-nis-0:0.60.0-4.module+el8.9.0+1573+39ab85f4.aarch64.rpm", "slapi-nis-0:0.60.0-4.module+el8.9.0+1573+39ab85f4.src.rpm", "slapi-nis-0:0.60.0-4.module+el8.9.0+1573+39ab85f4.x86_64.rpm", "slapi-nis-debuginfo-0:0.60.0-4.module+el8.9.0+1573+39ab85f4.aarch64.rpm", "slapi-nis-debuginfo-0:0.60.0-4.module+el8.9.0+1573+39ab85f4.x86_64.rpm", "slapi-nis-debugsource-0:0.60.0-4.module+el8.9.0+1573+39ab85f4.aarch64.rpm", "slapi-nis-debugsource-0:0.60.0-4.module+el8.9.0+1573+39ab85f4.x86_64.rpm", "softhsm-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.aarch64.rpm", "softhsm-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.src.rpm", "softhsm-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.x86_64.rpm", "softhsm-debuginfo-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.aarch64.rpm", "softhsm-debuginfo-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.x86_64.rpm", "softhsm-debugsource-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.aarch64.rpm", "softhsm-debugsource-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.x86_64.rpm", "softhsm-devel-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.aarch64.rpm", "softhsm-devel-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.x86_64.rpm","python3-kdcproxy-0:0.4-5.module+el8.10.0+1915+3c70f7d9.1.noarch.rpm", "python3-kdcproxy-0:0.4-5.module+el8.9.0+1371+ffa84eb9.noarch.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux 8 receives an important security update for idm affecting multiple applications with significant DoS risks.. Rocky Linux security updates DoS SSRF. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 27, 2025 Important Rocky Linux
89

Fedora 40 freeipa 2025-6baf694c75 critical advisory for CVE-2024-11029

CVE-2024-11029 Release note: https://www.freeipa.org/release-notes/4-12-3.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-6baf694c75 2025-01-27 01:55:15.215313+00:00 -------------------------------------------------------------------------------- Name : freeipa Product : Fedora 40 Version : 4.12.2 Release : 3.fc40 URL : http://www.freeipa.org/ Summary : The Identity, Policy and Audit system Description : IPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts). -------------------------------------------------------------------------------- Update Information: CVE-2024-11029 Release note: https://www.freeipa.org/release-notes/4-12-3.html -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 15 2025 Alexander Bokovoy - 4.12.2-3 - CVE-2024-11029 - Release notes: https://www.freeipa.org/release-notes/4-12-3.html -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-6baf694c75' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . CentOS's cPanel faces crucial patches targeting vulnerabilities alongside comprehensive advice for its users.. Fedora freeipa updates, security issues, identity management patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 27, 2025 Critical Fedora
89

Fedora 41: FEDORA-2025-b21777d1b5 critical: freeipa security advisory

CVE-2024-11029 Release note: https://www.freeipa.org/release-notes/4-12-3.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-b21777d1b5 2025-01-27 01:38:38.335848+00:00 -------------------------------------------------------------------------------- Name : freeipa Product : Fedora 41 Version : 4.12.2 Release : 7.fc41 URL : http://www.freeipa.org/ Summary : The Identity, Policy and Audit system Description : IPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts). -------------------------------------------------------------------------------- Update Information: CVE-2024-11029 Release note: https://www.freeipa.org/release-notes/4-12-3.html -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 15 2025 Alexander Bokovoy - 4.12.2-7 - CVE-2024-11029 - Release notes: https://www.freeipa.org/release-notes/4-12-3.html -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-b21777d1b5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 41 has issued a security advisory for FreeIPA regarding CVE-2024-11029, highlighting vulnerabilities in authentication mechanisms requiring immediate user action. Fedora 41, freeipa, security advisory, identity management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 27, 2025 Critical Fedora
89

Fedora 39 FEDORA-2024-1d1b485611 Critical: FreeIPA Authentication Issues

Fix CVE-2024-2698 and CVE-2024-3183. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-1d1b485611 2024-06-29 01:41:49.505912 -------------------------------------------------------------------------------- Name : freeipa Product : Fedora 39 Version : 4.12.1 Release : 1.fc39 URL : http://www.freeipa.org/ Summary : The Identity, Policy and Audit system Description : IPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts). -------------------------------------------------------------------------------- Update Information: Fix CVE-2024-2698 and CVE-2024-3183 -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 11 2024 Julien Rische - 4.12.1-1 - Upstream release 4.12.1 - Release notes: https://www.freeipa.org/release-notes/4-12-1.html - Security release: CVE-2024-2698 CVE-2024-3183 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2291164 - CVE-2024-3183 freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2291164 [ 2 ] Bug #2291165 - CVE-2024-2698 freeipa: delegation rules allow a proxy service to impersonate any user to access another target service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2291165 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-1d1b485611' at the command line. For moreinformation, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Recent patches for Fedora 39's freeipa target the vulnerabilities CVE-2024-2698 and CVE-2024-3183 and are now released.. FreeIPA Security Update, Fedora Updates, Identity Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 29, 2024 Critical Fedora
89

Fedora 40: FEDORA-2024-2a466c6514 Critical: FreeIPA User Access Breach

Fix CVE-2024-2698 and CVE-2024-3183. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2a466c6514 2024-06-27 02:02:42.637986 -------------------------------------------------------------------------------- Name : freeipa Product : Fedora 40 Version : 4.12.1 Release : 1.fc40 URL : http://www.freeipa.org/ Summary : The Identity, Policy and Audit system Description : IPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts). -------------------------------------------------------------------------------- Update Information: Fix CVE-2024-2698 and CVE-2024-3183 -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 11 2024 Julien Rische - 4.12.1-1 - Upstream release 4.12.1 - Release notes: https://www.freeipa.org/release-notes/4-12-1.html - Security release: CVE-2024-2698 CVE-2024-3183 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2291164 - CVE-2024-3183 freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2291164 [ 2 ] Bug #2291165 - CVE-2024-2698 freeipa: delegation rules allow a proxy service to impersonate any user to access another target service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2291165 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2a466c6514' at the command line. For moreinformation, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Stay protected with Fedora 40's freeipa security patches addressing issues CVE-2024-2698 and CVE-2024-3183. Ensure your system is secure!. Fedora Security Advisory, FreeIPA Update, Identity Management, Critical Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 27, 2024 Critical Fedora
219

Rocky Linux 9 RLSA-2024:3754 Important: ipa Authentication Fix

Important: ipa security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:3754", "synopsis": "Important: ipa security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for ipa.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Rocky Enterprise Software Foundation Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.\n\nSecurity Fix(es):\n\n* freeipa: delegation rules allow a proxy service to impersonate any user to access another target service (CVE-2024-2698)\n\n* freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force (CVE-2024-3183)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2270353", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2270353", "description": ""}, {"ticket": "2270685", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2270685", "description": ""}], "cves": [{"name": "CVE-2024-2698", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-2698", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-3183", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-3183", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-06-14T14:00:35.848917Z", "rpms": {"Rocky Linux 9": {"nvras": ["ipa-0:4.11.0-15.el9_4.src.rpm", "ipa-client-0:4.11.0-15.el9_4.aarch64.rpm","ipa-client-0:4.11.0-15.el9_4.ppc64le.rpm", "ipa-client-0:4.11.0-15.el9_4.s390x.rpm", "ipa-client-0:4.11.0-15.el9_4.x86_64.rpm", "ipa-client-common-0:4.11.0-15.el9_4.noarch.rpm", "ipa-client-debuginfo-0:4.11.0-15.el9_4.aarch64.rpm", "ipa-client-debuginfo-0:4.11.0-15.el9_4.ppc64le.rpm", "ipa-client-debuginfo-0:4.11.0-15.el9_4.s390x.rpm", "ipa-client-debuginfo-0:4.11.0-15.el9_4.x86_64.rpm", "ipa-client-epn-0:4.11.0-15.el9_4.aarch64.rpm", "ipa-client-epn-0:4.11.0-15.el9_4.ppc64le.rpm", "ipa-client-epn-0:4.11.0-15.el9_4.s390x.rpm", "ipa-client-epn-0:4.11.0-15.el9_4.x86_64.rpm", "ipa-client-samba-0:4.11.0-15.el9_4.aarch64.rpm", "ipa-client-samba-0:4.11.0-15.el9_4.ppc64le.rpm", "ipa-client-samba-0:4.11.0-15.el9_4.s390x.rpm", "ipa-client-samba-0:4.11.0-15.el9_4.x86_64.rpm", "ipa-common-0:4.11.0-15.el9_4.noarch.rpm", "ipa-selinux-0:4.11.0-15.el9_4.noarch.rpm", "ipa-server-0:4.11.0-15.el9_4.aarch64.rpm", "ipa-server-0:4.11.0-15.el9_4.ppc64le.rpm", "ipa-server-0:4.11.0-15.el9_4.s390x.rpm", "ipa-server-0:4.11.0-15.el9_4.x86_64.rpm", "ipa-server-common-0:4.11.0-15.el9_4.noarch.rpm", "ipa-server-debuginfo-0:4.11.0-15.el9_4.aarch64.rpm", "ipa-server-debuginfo-0:4.11.0-15.el9_4.ppc64le.rpm", "ipa-server-debuginfo-0:4.11.0-15.el9_4.s390x.rpm", "ipa-server-debuginfo-0:4.11.0-15.el9_4.x86_64.rpm", "ipa-server-dns-0:4.11.0-15.el9_4.noarch.rpm", "ipa-server-trust-ad-0:4.11.0-15.el9_4.aarch64.rpm", "ipa-server-trust-ad-0:4.11.0-15.el9_4.ppc64le.rpm", "ipa-server-trust-ad-0:4.11.0-15.el9_4.s390x.rpm", "ipa-server-trust-ad-0:4.11.0-15.el9_4.x86_64.rpm", "ipa-server-trust-ad-debuginfo-0:4.11.0-15.el9_4.aarch64.rpm", "ipa-server-trust-ad-debuginfo-0:4.11.0-15.el9_4.ppc64le.rpm", "ipa-server-trust-ad-debuginfo-0:4.11.0-15.el9_4.s390x.rpm", "ipa-server-trust-ad-debuginfo-0:4.11.0-15.el9_4.x86_64.rpm", "python3-ipaclient-0:4.11.0-15.el9_4.noarch.rpm", "python3-ipalib-0:4.11.0-15.el9_4.noarch.rpm", "python3-ipaserver-0:4.11.0-15.el9_4.noarch.rpm", "python3-ipatests-0:4.11.0-15.el9_4.noarch.rpm"]}}, "rebootSuggested": false,"buildReferences": []}. The latest ipa patch from Rocky Linux tackles security flaws affecting identity verification and user access.. Rocky Linux Security Update, ipa Vulnerability Fix, Identity Management Improvements. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 14, 2024 Important Rocky Linux
89

Fedora 38: 2024-403145c4fb Critical: FreeIPA CSRF Issue

Upstream security release for CVE-2023-5455. Release notes: https://www.freeipa.org/release-notes/4-10-3.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-403145c4fb 2024-01-26 00:42:11.401778 -------------------------------------------------------------------------------- Name : freeipa Product : Fedora 38 Version : 4.10.3 Release : 1.fc38 URL : https://www.freeipa.org/ Summary : The Identity, Policy and Audit system Description : IPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts). -------------------------------------------------------------------------------- Update Information: Upstream security release for CVE-2023-5455. Release notes: https://www.freeipa.org/release-notes/4-10-3.html -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 10 2024 Alexander Bokovoy - 4.10.3-1 - Security release: CVE-2023-5455 - Resolves: rhbz#2257646 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2257646 - CVE-2023-5455 freeipa: ipa: Invalid CSRF protection [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257646 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-403145c4fb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Latest update from upstream security for FreeIPA addresses CVE-2023-5455, essential for identity management and access control.. Fedora Updates, FreeIPA Security, Identity Management, CSRF Protection. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 26, 2024 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200