Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
197

Debian 11 systemd Critical Improper Access Control Exploit DLA-4533-1

The following vulnerabilities have been discovered systemd: CVE-2026-4105 The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged. Debian LTS Advisory DLA-4533-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Arnaud Rebillout April 15, 2026 https://wiki.debian.org/LTS Package : systemd Version : 247.3-7+deb11u8 CVE ID : CVE-2026-4105 CVE-2026-29111 CVE-2026-40225 CVE-2026-40226 Debian Bug : The following vulnerabilities have been discovered systemd: CVE-2026-4105 The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system. CVE-2026-29111 When an unprivileged IPC API call is made with spurious data, a stack overwrite occurs, with the attacker controlled content. CVE-2026-40225 udev: local root execution can occur via malicious hardware devices and unsanitized kernel output. CVE-2026-40226 nspawn: an escape-to-host action can occur via a crafted optional config file. For Debian 11 bullseye, these problems have been fixed in version 247.3-7+deb11u8. We recommend that you upgrade your systemd packages. For the detailed security status of systemd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/systemd Further information about Debian LTS security advisories, how to apply these updates to your systemand frequently asked questions can be found at: https://wiki.debian.org/LTS . Critical advisory for Debian LTS addressing improper access control vulnerabilities in systemd. Immediate action is required.. systemd vulnerabilities, Debian security advisory, access control flaws, local privilege escalation, Debian updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 15, 2026 Critical Debian LTS
172

Ubuntu 20.04 LTS: Kernel Critical Flaws Exploit Risk USN-7655-1

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7655-1 July 18, 2025 linux-intel-iotg-5.15 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-intel-iotg-5.15: Linux kernel for Intel IoT platforms Details: Michael Randrianantenaina discovered that the Bluetooth driver in the Linux Kernel contained an improper access control vulnerability. A nearby attacker could use this to connect a rougue device and possibly execute arbitrary code. (CVE-2024-8805) It was discovered that the CIFS network file system implementation in the Linux kernel did not properly verify the target namespace when handling upcalls. An attacker could use this to expose sensitive information. (CVE-2025-2312) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - PA-RISC architecture; - PowerPC architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - ACPI drivers; - Serial ATA and Parallel ATA drivers; - Bluetooth drivers; - Bus devices; - Clock framework and drivers; - CPU frequency scaling framework; - Buffer Sharing and Synchronization framework; - DMA engine subsystem; - ARM SCMI message protocol; - GPU drivers; - HID subsystem; - HSI subsystem; - I2C subsystem; - I3C subsystem; - IIO subsystem; - InfiniBand drivers; - IOMMU subsystem; - IRQ chip drivers; - MCB driver; - Multiple devices driver; - Media drivers; - MemoryStick subsystem; - Multifunction device drivers; - PCI Endpoint Test driver; - MTD block device drivers; - Network drivers; - Mellanox network drivers; - NTB driver; -Device tree and open firmware driver; - PCI subsystem; - TI SCI PM domains driver; - PWM drivers; - Voltage and Current Regulator drivers; - Remote Processor subsystem; - S/390 drivers; - SCSI subsystem; - QCOM SoC drivers; - Samsung SoC drivers; - TCM subsystem; - Thermal drivers; - UFS subsystem; - Cadence USB3 driver; - ChipIdea USB driver; - USB Device Class drivers; - DesignWare USB3 driver; - USB Gadget drivers; - USB Type-C support driver; - USB Type-C Connector System Software Interface driver; - Backlight driver; - Framebuffer layer; - Xen hypervisor drivers; - BTRFS file system; - Ext4 file system; - F2FS file system; - File systems infrastructure; - JFS file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NTFS3 file system; - Proc file system; - SMB network file system; - Kernel stack handling interfaces; - Bluetooth subsystem; - IPv6 networking; - Network traffic control; - SCTP protocol; - RDMA verbs API; - SoC audio core drivers; - BPF subsystem; - Kernel command line parsing driver; - Tracing infrastructure; - Watch queue notification mechanism; - Memory management; - 802.1Q VLAN protocol; - Asynchronous Transfer Mode (ATM) subsystem; - Networking core; - IPv4 networking; - MAC80211 subsystem; - Management Component Transport Protocol (MCTP); - Multipath TCP; - Netfilter; - Open vSwitch; - Phonet protocol; - SMC sockets; - Sun RPC protocol; - TIPC protocol; - TLS protocol; - SoC Audio for Freescale CPUs drivers; - Virtio sound driver; - CPU Power monitoring subsystem; (CVE-2025-37989, CVE-2025-22071, CVE-2025-37808, CVE-2025-37983, CVE-2025-38001, CVE-2024-46816, CVE-2024-50125, CVE-2025-38575, CVE-2025-37766, CVE-2022-49168, CVE-2025-22025, CVE-2025-22035, CVE-2025-37923, CVE-2024-49989, CVE-2025-23148, CVE-2024-53051, CVE-2025-39728, CVE-2025-21956, CVE-2025-37741, CVE-2025-37970, CVE-2025-37798, CVE-2025-23157, CVE-2025-38177,CVE-2022-49535, CVE-2025-22027, CVE-2025-37756, CVE-2025-38023, CVE-2025-22066, CVE-2025-37780, CVE-2025-37995, CVE-2025-37739, CVE-2025-37932, CVE-2025-37982, CVE-2025-37812, CVE-2025-23156, CVE-2025-38005, CVE-2025-21839, CVE-2025-37892, CVE-2025-22073, CVE-2024-35866, CVE-2023-52757, CVE-2025-37785, CVE-2025-23150, CVE-2024-58093, CVE-2025-21992, CVE-2025-37905, CVE-2025-37836, CVE-2025-21964, CVE-2025-23140, CVE-2025-22056, CVE-2025-37915, CVE-2025-22054, CVE-2025-37859, CVE-2025-22050, CVE-2025-37811, CVE-2024-38540, CVE-2025-37794, CVE-2025-37839, CVE-2022-21546, CVE-2025-22089, CVE-2025-22079, CVE-2024-56751, CVE-2025-37789, CVE-2025-37790, CVE-2025-23159, CVE-2025-22097, CVE-2025-37883, CVE-2025-37829, CVE-2023-52572, CVE-2025-21962, CVE-2025-37823, CVE-2024-53203, CVE-2025-38000, CVE-2025-38152, CVE-2025-37771, CVE-2025-39735, CVE-2025-37992, CVE-2025-37937, CVE-2025-22081, CVE-2024-35943, CVE-2025-37803, CVE-2025-37940, CVE-2025-22005, CVE-2025-22014, CVE-2025-37742, CVE-2022-49063, CVE-2025-37890, CVE-2025-37969, CVE-2025-37788, CVE-2022-48893, CVE-2025-23161, CVE-2024-46753, CVE-2025-21853, CVE-2025-37817, CVE-2022-49636, CVE-2025-37985, CVE-2025-37787, CVE-2025-37810, CVE-2025-22008, CVE-2025-37824, CVE-2025-37765, CVE-2025-23145, CVE-2025-37830, CVE-2025-37913, CVE-2025-37881, CVE-2025-37967, CVE-2025-37912, CVE-2024-42230, CVE-2024-46821, CVE-2024-56608, CVE-2025-37805, CVE-2025-37838, CVE-2025-38637, CVE-2025-38024, CVE-2025-23138, CVE-2025-37949, CVE-2024-46751, CVE-2025-22007, CVE-2025-37844, CVE-2024-46812, CVE-2025-37889, CVE-2023-53034, CVE-2025-37927, CVE-2025-37998, CVE-2024-42322, CVE-2024-50280, CVE-2025-22086, CVE-2025-21963, CVE-2024-50272, CVE-2024-54458, CVE-2024-36908, CVE-2025-22062, CVE-2025-37994, CVE-2025-22044, CVE-2025-22018, CVE-2025-22010, CVE-2024-49960, CVE-2025-37768, CVE-2025-37911, CVE-2025-22060, CVE-2025-37781, CVE-2024-26686, CVE-2024-50047, CVE-2025-37850, CVE-2024-46742, CVE-2025-37797, CVE-2025-37767, CVE-2025-23136, CVE-2025-23158, CVE-2025-37792, CVE-2025-37749,CVE-2025-38009, CVE-2024-35867, CVE-2025-37885, CVE-2025-37914, CVE-2024-46774, CVE-2025-38094, CVE-2025-23163, CVE-2024-38541, CVE-2025-37819, CVE-2025-22020, CVE-2025-37857, CVE-2025-21975, CVE-2024-53144, CVE-2025-21991, CVE-2025-37867, CVE-2025-37930, CVE-2025-37796, CVE-2025-21968, CVE-2025-22075, CVE-2025-37997, CVE-2025-22063, CVE-2025-37840, CVE-2025-37909, CVE-2025-22045, CVE-2024-46787, CVE-2025-37738, CVE-2025-22055, CVE-2025-37862, CVE-2024-56664, CVE-2025-21959, CVE-2025-22004, CVE-2024-50258, CVE-2025-23146, CVE-2025-22021, CVE-2025-21994, CVE-2025-21957, CVE-2025-37758, CVE-2024-26739, CVE-2025-37858, CVE-2025-37757, CVE-2025-23142, CVE-2025-23151, CVE-2025-21996, CVE-2025-21970, CVE-2025-37770, CVE-2024-35790, CVE-2025-37773, CVE-2025-37990, CVE-2025-21941, CVE-2025-21999, CVE-2024-53128, CVE-2025-37851, CVE-2025-23147, CVE-2025-37964, CVE-2025-37841, CVE-2025-37875, CVE-2024-53168, CVE-2022-49728, CVE-2025-23144, CVE-2025-37991, CVE-2024-56551, CVE-2025-21981, CVE-2024-27402, CVE-2025-37740, CVE-2024-36945) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.15.0-1083-intel-iotg 5.15.0-1083.89~20.04.1 Available with Ubuntu Pro linux-image-intel 5.15.0.1083.89~20.04.1 Available with Ubuntu Pro linux-image-intel-iotg 5.15.0.1083.89~20.04.1 Available with Ubuntu Pro linux-image-intel-iotg-5.15 5.15.0.1083.89~20.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic,linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7655-1 CVE-2022-21546, CVE-2022-48893, CVE-2022-49063, CVE-2022-49168, CVE-2022-49535, CVE-2022-49636, CVE-2022-49728, CVE-2023-52572, CVE-2023-52757, CVE-2023-53034, CVE-2024-26686, CVE-2024-26739, CVE-2024-27402, CVE-2024-35790, CVE-2024-35866, CVE-2024-35867, CVE-2024-35943, CVE-2024-36908, CVE-2024-36945, CVE-2024-38540, CVE-2024-38541, CVE-2024-42230, CVE-2024-42322, CVE-2024-46742, CVE-2024-46751, CVE-2024-46753, CVE-2024-46774, CVE-2024-46787, CVE-2024-46812, CVE-2024-46816, CVE-2024-46821, CVE-2024-49960, CVE-2024-49989, CVE-2024-50047, CVE-2024-50125, CVE-2024-50258, CVE-2024-50272, CVE-2024-50280, CVE-2024-53051, CVE-2024-53128, CVE-2024-53144, CVE-2024-53168, CVE-2024-53203, CVE-2024-54458, CVE-2024-56551, CVE-2024-56608, CVE-2024-56664, CVE-2024-56751, CVE-2024-58093, CVE-2024-8805, CVE-2025-21839, CVE-2025-21853, CVE-2025-21941, CVE-2025-21956, CVE-2025-21957, CVE-2025-21959, CVE-2025-21962, CVE-2025-21963, CVE-2025-21964, CVE-2025-21968, CVE-2025-21970, CVE-2025-21975, CVE-2025-21981, CVE-2025-21991, CVE-2025-21992, CVE-2025-21994, CVE-2025-21996, CVE-2025-21999, CVE-2025-22004, CVE-2025-22005, CVE-2025-22007, CVE-2025-22008, CVE-2025-22010, CVE-2025-22014, CVE-2025-22018, CVE-2025-22020, CVE-2025-22021, CVE-2025-22025, CVE-2025-22027, CVE-2025-22035, CVE-2025-22044, CVE-2025-22045, CVE-2025-22050, CVE-2025-22054, CVE-2025-22055, CVE-2025-22056, CVE-2025-22060, CVE-2025-22062, CVE-2025-22063, CVE-2025-22066, CVE-2025-22071, CVE-2025-22073, CVE-2025-22075, CVE-2025-22079, CVE-2025-22081, CVE-2025-22086, CVE-2025-22089, CVE-2025-22097, CVE-2025-2312, CVE-2025-23136, CVE-2025-23138, CVE-2025-23140, CVE-2025-23142, CVE-2025-23144, CVE-2025-23145, CVE-2025-23146, CVE-2025-23147, CVE-2025-23148, CVE-2025-23150, CVE-2025-23151, CVE-2025-23156, CVE-2025-23157, CVE-2025-23158, CVE-2025-23159, CVE-2025-23161, CVE-2025-23163, CVE-2025-37738, CVE-2025-37739, CVE-2025-37740, CVE-2025-37741, CVE-2025-37742, CVE-2025-37749, CVE-2025-37756, CVE-2025-37757, CVE-2025-37758, CVE-2025-37765, CVE-2025-37766, CVE-2025-37767, CVE-2025-37768, CVE-2025-37770, CVE-2025-37771, CVE-2025-37773, CVE-2025-37780, CVE-2025-37781, CVE-2025-37785, CVE-2025-37787, CVE-2025-37788, CVE-2025-37789, CVE-2025-37790, CVE-2025-37792, CVE-2025-37794, CVE-2025-37796, CVE-2025-37797, CVE-2025-37798, CVE-2025-37803, CVE-2025-37805, CVE-2025-37808, CVE-2025-37810, CVE-2025-37811, CVE-2025-37812, CVE-2025-37817, CVE-2025-37819, CVE-2025-37823, CVE-2025-37824, CVE-2025-37829, CVE-2025-37830, CVE-2025-37836, CVE-2025-37838, CVE-2025-37839, CVE-2025-37840, CVE-2025-37841, CVE-2025-37844, CVE-2025-37850, CVE-2025-37851, CVE-2025-37857, CVE-2025-37858, CVE-2025-37859, CVE-2025-37862, CVE-2025-37867, CVE-2025-37875, CVE-2025-37881, CVE-2025-37883, CVE-2025-37885, CVE-2025-37889, CVE-2025-37890, CVE-2025-37892, CVE-2025-37905, CVE-2025-37909, CVE-2025-37911, CVE-2025-37912, CVE-2025-37913, CVE-2025-37914, CVE-2025-37915, CVE-2025-37923, CVE-2025-37927, CVE-2025-37930, CVE-2025-37932, CVE-2025-37937, CVE-2025-37940, CVE-2025-37949, CVE-2025-37964, CVE-2025-37967, CVE-2025-37969, CVE-2025-37970, CVE-2025-37982, CVE-2025-37983, CVE-2025-37985, CVE-2025-37989, CVE-2025-37990, CVE-2025-37991, CVE-2025-37992, CVE-2025-37994, CVE-2025-37995, CVE-2025-37997, CVE-2025-37998, CVE-2025-38000, CVE-2025-38001, CVE-2025-38005, CVE-2025-38009, CVE-2025-38023, CVE-2025-38024, CVE-2025-38094, CVE-2025-38152, CVE-2025-38177, CVE-2025-38575, CVE-2025-38637, CVE-2025-39728, CVE-2025-39735 . Various vulnerabilities in the Linux kernel of Ubuntu may result in unauthorized entrance or potential system breach.. Ubuntu Security, Linux Kernel, Privilege Escalation, Bluetooth Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 18, 2025 Critical Ubuntu
172

Ubuntu 22.04 LTS USN-7591-5 critical: Linux kernel Intel IoT issues

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7591-5 July 04, 2025 linux-intel-iotg vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-intel-iotg: Linux kernel for Intel IoT platforms Details: Michael Randrianantenaina discovered that the Bluetooth driver in the Linux Kernel contained an improper access control vulnerability. A nearby attacker could use this to connect a rougue device and possibly execute arbitrary code. (CVE-2024-8805) It was discovered that the CIFS network file system implementation in the Linux kernel did not properly verify the target namespace when handling upcalls. An attacker could use this to expose sensitive information. (CVE-2025-2312) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - PowerPC architecture; - x86 architecture; - ACPI drivers; - Clock framework and drivers; - GPU drivers; - HID subsystem; - InfiniBand drivers; - Media drivers; - MemoryStick subsystem; - Network drivers; - Mellanox network drivers; - NTB driver; - PCI subsystem; - Voltage and Current Regulator drivers; - Remote Processor subsystem; - SCSI subsystem; - QCOM SoC drivers; - Thermal drivers; - BTRFS file system; - Ext4 file system; - JFS file system; - Network file system (NFS) server daemon; - NTFS3 file system; - File systems infrastructure; - Proc file system; - SMB network file system; - IPv6 networking; - RDMA verbs API; - SoC audio core drivers; - Tracing infrastructure; -Watch queue notification mechanism; - 802.1Q VLAN protocol; - Asynchronous Transfer Mode (ATM) subsystem; - Bluetooth subsystem; - Networking core; - IPv4 networking; - Netfilter; - Network traffic control; - SMC sockets; - SoC Audio for Freescale CPUs drivers; (CVE-2025-23138, CVE-2025-21956, CVE-2025-21970, CVE-2025-22025, CVE-2024-46753, CVE-2025-21962, CVE-2025-37889, CVE-2025-21992, CVE-2025-39728, CVE-2025-22054, CVE-2025-21959, CVE-2024-53144, CVE-2022-49728, CVE-2024-58093, CVE-2025-38637, CVE-2025-21981, CVE-2025-21963, CVE-2025-21968, CVE-2025-22014, CVE-2024-46812, CVE-2025-22005, CVE-2025-21994, CVE-2025-22071, CVE-2025-22008, CVE-2022-49636, CVE-2025-22007, CVE-2023-53034, CVE-2025-22035, CVE-2025-22010, CVE-2025-22081, CVE-2025-22021, CVE-2024-46821, CVE-2025-21999, CVE-2025-38575, CVE-2025-22073, CVE-2025-22004, CVE-2024-42230, CVE-2025-21941, CVE-2024-56664, CVE-2025-22044, CVE-2025-39735, CVE-2025-22060, CVE-2025-22055, CVE-2025-21957, CVE-2025-21975, CVE-2025-22075, CVE-2025-22089, CVE-2025-37937, CVE-2025-38152, CVE-2025-22020, CVE-2025-22066, CVE-2025-22056, CVE-2025-22050, CVE-2025-21964, CVE-2025-21996, CVE-2025-22079, CVE-2025-23136, CVE-2025-22063, CVE-2024-36945, CVE-2025-22097, CVE-2025-37785, CVE-2025-21991, CVE-2025-22086, CVE-2025-22045, CVE-2025-22018) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1081-intel-iotg 5.15.0-1081.87 linux-image-intel-iotg 5.15.0.1081.81 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE,linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7591-5 https://ubuntu.com/security/notices/USN-7591-4 https://ubuntu.com/security/notices/USN-7591-3 https://ubuntu.com/security/notices/USN-7591-2 https://ubuntu.com/security/notices/USN-7591-1 CVE-2022-49636, CVE-2022-49728, CVE-2023-53034, CVE-2024-36945, CVE-2024-42230, CVE-2024-46753, CVE-2024-46812, CVE-2024-46821, CVE-2024-53144, CVE-2024-56664, CVE-2024-58093, CVE-2024-8805, CVE-2025-21941, CVE-2025-21956, CVE-2025-21957, CVE-2025-21959, CVE-2025-21962, CVE-2025-21963, CVE-2025-21964, CVE-2025-21968, CVE-2025-21970, CVE-2025-21975, CVE-2025-21981, CVE-2025-21991, CVE-2025-21992, CVE-2025-21994, CVE-2025-21996, CVE-2025-21999, CVE-2025-22004, CVE-2025-22005, CVE-2025-22007, CVE-2025-22008, CVE-2025-22010, CVE-2025-22014, CVE-2025-22018, CVE-2025-22020, CVE-2025-22021, CVE-2025-22025, CVE-2025-22035, CVE-2025-22044, CVE-2025-22045, CVE-2025-22050, CVE-2025-22054, CVE-2025-22055, CVE-2025-22056, CVE-2025-22060, CVE-2025-22063, CVE-2025-22066, CVE-2025-22071, CVE-2025-22073, CVE-2025-22075, CVE-2025-22079, CVE-2025-22081, CVE-2025-22086, CVE-2025-22089, CVE-2025-22097, CVE-2025-2312, CVE-2025-23136, CVE-2025-23138, CVE-2025-37785, CVE-2025-37889, CVE-2025-37937, CVE-2025-38152, CVE-2025-38575, CVE-2025-38637, CVE-2025-39728, CVE-2025-39735 Package Information: https://launchpad.net/ubuntu/+source/linux-intel-iotg/5.15.0-1081.87 . Several significant vulnerabilities addressed in Ubuntu's Linux kernel affecting Intel IoT devices. Ensure your systems are updated without delay.. Linux kernel security, Ubuntu security update, Intel IoT vulnerabilities, kernel patching, improper access control. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 04, 2025 Critical Ubuntu
172

Ubuntu 20.04 LTS USN-7598-1 critical: linux-azure-5.15 buffer overflow

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7598-1 June 24, 2025 linux-azure-5.15 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-azure-5.15: Linux kernel for Microsoft Azure cloud systems Details: Michael Randrianantenaina discovered that the Bluetooth driver in the Linux Kernel contained an improper access control vulnerability. A nearby attacker could use this to connect a rougue device and possibly execute arbitrary code. (CVE-2024-8805) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - PowerPC architecture; - x86 architecture; - ACPI drivers; - Clock framework and drivers; - GPU drivers; - HID subsystem; - InfiniBand drivers; - Media drivers; - MemoryStick subsystem; - Network drivers; - Mellanox network drivers; - NTB driver; - PCI subsystem; - Voltage and Current Regulator drivers; - Remote Processor subsystem; - SCSI subsystem; - QCOM SoC drivers; - Thermal drivers; - BTRFS file system; - Ext4 file system; - JFS file system; - Network file system (NFS) server daemon; - NTFS3 file system; - File systems infrastructure; - Proc file system; - SMB network file system; - IPv6 networking; - RDMA verbs API; - SoC audio core drivers; - Tracing infrastructure; - Watch queue notification mechanism; - 802.1Q VLAN protocol; - Asynchronous Transfer Mode (ATM) subsystem; - Bluetooth subsystem; - Networking core; - IPv4 networking; - Netfilter; - Network trafficcontrol; - SMC sockets; - Sun RPC protocol; - SoC Audio for Freescale CPUs drivers; (CVE-2025-21959, CVE-2025-21996, CVE-2024-46821, CVE-2025-38575, CVE-2025-22045, CVE-2025-21970, CVE-2025-21956, CVE-2025-21994, CVE-2025-23136, CVE-2025-39735, CVE-2025-23138, CVE-2025-22020, CVE-2025-21957, CVE-2025-22063, CVE-2025-21975, CVE-2025-22050, CVE-2024-53144, CVE-2025-21991, CVE-2025-22035, CVE-2024-42230, CVE-2025-22007, CVE-2025-22071, CVE-2025-22060, CVE-2025-22079, CVE-2025-21999, CVE-2025-22081, CVE-2025-22021, CVE-2025-21964, CVE-2024-56664, CVE-2024-56608, CVE-2025-38152, CVE-2025-21992, CVE-2024-56551, CVE-2025-22089, CVE-2025-22075, CVE-2024-53168, CVE-2022-49728, CVE-2022-49636, CVE-2025-22010, CVE-2025-38637, CVE-2025-22004, CVE-2025-21963, CVE-2025-22086, CVE-2025-22097, CVE-2025-21962, CVE-2025-22014, CVE-2024-46753, CVE-2025-22073, CVE-2025-22018, CVE-2025-22044, CVE-2025-21941, CVE-2025-39728, CVE-2025-22055, CVE-2025-37785, CVE-2025-22025, CVE-2025-22066, CVE-2023-53034, CVE-2025-22008, CVE-2025-22054, CVE-2025-37937, CVE-2025-37889, CVE-2025-22005, CVE-2025-21968, CVE-2024-58093, CVE-2024-36945, CVE-2025-21981, CVE-2025-22056, CVE-2024-46812) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.15.0-1091-azure 5.15.0-1091.100~20.04.1 Available with Ubuntu Pro linux-image-azure 5.15.0.1091.100~20.04.1 Available with Ubuntu Pro linux-image-azure-cvm 5.15.0.1091.100~20.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manuallyuninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7598-1 CVE-2022-49636, CVE-2022-49728, CVE-2023-53034, CVE-2024-36945, CVE-2024-42230, CVE-2024-46753, CVE-2024-46812, CVE-2024-46821, CVE-2024-53144, CVE-2024-53168, CVE-2024-56551, CVE-2024-56608, CVE-2024-56664, CVE-2024-58093, CVE-2024-8805, CVE-2025-21941, CVE-2025-21956, CVE-2025-21957, CVE-2025-21959, CVE-2025-21962, CVE-2025-21963, CVE-2025-21964, CVE-2025-21968, CVE-2025-21970, CVE-2025-21975, CVE-2025-21981, CVE-2025-21991, CVE-2025-21992, CVE-2025-21994, CVE-2025-21996, CVE-2025-21999, CVE-2025-22004, CVE-2025-22005, CVE-2025-22007, CVE-2025-22008, CVE-2025-22010, CVE-2025-22014, CVE-2025-22018, CVE-2025-22020, CVE-2025-22021, CVE-2025-22025, CVE-2025-22035, CVE-2025-22044, CVE-2025-22045, CVE-2025-22050, CVE-2025-22054, CVE-2025-22055, CVE-2025-22056, CVE-2025-22060, CVE-2025-22063, CVE-2025-22066, CVE-2025-22071, CVE-2025-22073, CVE-2025-22075, CVE-2025-22079, CVE-2025-22081, CVE-2025-22086, CVE-2025-22089, CVE-2025-22097, CVE-2025-23136, CVE-2025-23138, CVE-2025-37785, CVE-2025-37889, CVE-2025-37937, CVE-2025-38152, CVE-2025-38575, CVE-2025-38637, CVE-2025-39728, CVE-2025-39735 . Urgent security notice for Linux kernel in Ubuntu 20.04 highlights multiple flaws and necessitates prompt response.. Linux kernel vulnerabilities, Ubuntu security fix, Azure kernel update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 24, 2025 Critical Ubuntu
89

Fedora 41: 2025-3eb7c0066f important: apache-commons-beanutils access issue

Fix improper access control vulnerability Resolves: CVE-2025-48734. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-3eb7c0066f 2025-06-22 01:13:34.506386+00:00 -------------------------------------------------------------------------------- Name : apache-commons-beanutils Product : Fedora 41 Version : 1.9.4 Release : 39.fc41 URL : https://commons.apache.org/proper/commons-beanutils/ Summary : Java utility methods for accessing and modifying the properties of arbitrary JavaBeans Description : The scope of this package is to create a package of Java utility methods for accessing and modifying the properties of arbitrary JavaBeans. No dependencies outside of the JDK are required, so the use of this package is very lightweight. -------------------------------------------------------------------------------- Update Information: Fix improper access control vulnerability Resolves: CVE-2025-48734 -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 13 2025 Mikolaj Izdebski - 1.9.4-39 - Fix improper access control vulnerability * Thu Jan 16 2025 Fedora Release Engineering - 1.9.4-38 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Mon Jan 13 2025 Mikolaj Izdebski - 1.9.4-37 - Update upstream URL * Fri Nov 29 2024 Mikolaj Izdebski - 1.9.4-34 - Update javapackages test plan to f42 * Tue Sep 3 2024 Mikolaj Izdebski - 1.9.4-33 - Use %autosetup -C -------------------------------------------------------------------------------- References: [ 1 ] Bug #2369088 - CVE-2025-48734 apache-commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2369088 -------------------------------------------------------------------------------- This update can be installed with the"dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-3eb7c0066f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . The Fedora 41 update resolves a security vulnerability in apache-commons-beanutils, improving access controls and overall system protection.. Fedora, apache-commons-beanutils, security update, access control, CVE. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 22, 2025 Important Fedora
172

Ubuntu 7385-1: Linux kernel (IBM) Security Advisory Updates

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7385-1 March 27, 2025 linux-ibm vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-ibm: Linux kernel for IBM cloud systems Details: Michael Randrianantenaina discovered that the Bluetooth driver in the Linux Kernel contained an improper access control vulnerability. A nearby attacker could use this to connect a rougue device and possibly execute arbitrary code. (CVE-2024-8805) Attila Szász discovered that the HFS+ file system implementation in the Linux Kernel contained a heap overflow vulnerability. An attacker could use a specially crafted file system image that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2025-0927) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - ACPI drivers; - Drivers core; - ATA over ethernet (AOE) driver; - Network block device driver; - Ublk userspace block driver; - Compressed RAM block device driver; - TPM device driver; - CPU frequency scaling framework; - Hardware crypto device drivers; - DAX dirext access to differentiated memory framework; - ARM SCMI message protocol; - EFI core; - GPU drivers; - HID subsystem; - I2C subsystem; - I3C subsystem; - IIO subsystem; - InfiniBand drivers; - Input Device core drivers; - IOMMU subsystem; - IRQ chip drivers; -Mailbox framework; - Media drivers; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - STMicroelectronics network drivers; - NTB driver; - Virtio pmem driver; - Parport drivers; - PCI subsystem; - Alibaba DDR Sub-System Driveway PMU driver; - Pin controllers subsystem; - x86 platform drivers; - Powercap sysfs driver; - Remote Processor subsystem; - SCSI subsystem; - SuperH / SH-Mobile drivers; - Direct Digital Synthesis drivers; - Thermal drivers; - TTY drivers; - UFS subsystem; - USB Device Class drivers; - USB Gadget drivers; - USB Host Controller drivers; - TI TPS6598x USB Power Delivery controller driver; - vDPA drivers; - Virtio Host (VHOST) subsystem; - Framebuffer layer; - AFS file system; - BTRFS file system; - File systems infrastructure; - Ceph distributed file system; - Ext4 file system; - F2FS file system; - JFS file system; - Network file systems library; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NILFS2 file system; - NTFS3 file system; - SMB network file system; - BPF subsystem; - Network file system (NFS) superblock; - Virtio network driver; - Network traffic control; - Network sockets; - TCP network protocol; - User-space API (UAPI); - io_uring subsystem; - Perf events; - Kernel thread helper (kthread); - Padata parallel execution mechanism; - RCU subsystem; - Arbitrary resource management; - Static call mechanism; - Timer subsystem; - Tracing infrastructure; - Maple Tree data structure library; - Memory management; - Bluetooth subsystem; - Ethernet bridge; - CAN network layer; - Networking core; - Distributed Switch Architecture; - IPv4 networking; - IPv6 networking; - MAC80211 subsystem; - IEEE 802.15.4 subsystem; - Multipath TCP; - NCSI (Network ControllerSideband Interface) driver; - Netfilter; - Netlink; - RxRPC session sockets; - SCTP protocol; - TIPC protocol; - Unix domain sockets; - Wireless networking; - eXpress Data Path; - AudioScience HPI driver; - KVM core; (CVE-2024-49927, CVE-2024-47719, CVE-2024-49878, CVE-2024-50200, CVE-2024-50013, CVE-2024-50187, CVE-2024-49852, CVE-2024-49913, CVE-2024-50080, CVE-2024-49903, CVE-2024-47745, CVE-2024-50184, CVE-2024-50117, CVE-2024-49863, CVE-2024-49973, CVE-2024-47727, CVE-2024-53170, CVE-2024-49933, CVE-2024-49900, CVE-2024-50095, CVE-2024-49928, CVE-2024-49858, CVE-2024-47731, CVE-2024-49896, CVE-2024-53104, CVE-2024-49972, CVE-2024-49969, CVE-2024-50176, CVE-2024-47739, CVE-2024-49995, CVE-2024-49982, CVE-2024-50044, CVE-2024-49957, CVE-2024-47748, CVE-2024-47744, CVE-2024-49978, CVE-2024-49879, CVE-2024-49987, CVE-2024-49929, CVE-2024-49905, CVE-2024-47723, CVE-2024-53144, CVE-2024-50066, CVE-2024-47735, CVE-2024-50057, CVE-2024-49890, CVE-2024-49963, CVE-2024-49955, CVE-2024-49974, CVE-2024-50049, CVE-2024-47710, CVE-2024-47682, CVE-2024-47734, CVE-2024-47691, CVE-2024-49999, CVE-2024-50098, CVE-2024-47672, CVE-2024-50056, CVE-2024-49983, CVE-2024-50005, CVE-2024-50045, CVE-2024-49866, CVE-2024-49953, CVE-2024-47750, CVE-2024-49917, CVE-2024-50026, CVE-2024-50009, CVE-2024-47718, CVE-2024-50070, CVE-2024-47700, CVE-2024-49986, CVE-2024-49907, CVE-2024-49884, CVE-2024-50085, CVE-2024-50087, CVE-2024-49875, CVE-2024-47728, CVE-2024-49861, CVE-2024-49851, CVE-2024-49980, CVE-2024-49898, CVE-2024-47681, CVE-2024-49965, CVE-2024-49960, CVE-2024-50020, CVE-2024-50012, CVE-2024-50186, CVE-2024-49889, CVE-2024-50030, CVE-2024-50046, CVE-2024-50180, CVE-2024-49966, CVE-2024-49897, CVE-2024-49985, CVE-2024-49918, CVE-2024-47754, CVE-2024-50082, CVE-2024-47757, CVE-2024-47711, CVE-2024-47737, CVE-2024-47716, CVE-2024-50069, CVE-2024-47696, CVE-2024-50031, CVE-2024-50202, CVE-2024-47713, CVE-2024-49894, CVE-2024-49921, CVE-2024-50022, CVE-2024-49856,CVE-2024-47740, CVE-2024-49868, CVE-2024-49919, CVE-2024-47679, CVE-2024-47695, CVE-2024-47714, CVE-2024-49996, CVE-2024-50196, CVE-2024-49997, CVE-2024-49883, CVE-2024-49936, CVE-2024-49962, CVE-2024-47673, CVE-2024-56663, CVE-2024-49892, CVE-2024-47685, CVE-2024-50233, CVE-2024-49891, CVE-2024-47738, CVE-2024-49870, CVE-2024-49885, CVE-2024-50025, CVE-2024-50006, CVE-2024-49968, CVE-2024-47709, CVE-2024-47751, CVE-2024-50058, CVE-2024-50086, CVE-2024-50072, CVE-2024-50195, CVE-2024-56582, CVE-2024-50014, CVE-2024-49886, CVE-2024-47743, CVE-2024-50185, CVE-2024-50193, CVE-2024-49909, CVE-2024-50077, CVE-2024-49930, CVE-2024-49946, CVE-2024-50192, CVE-2024-50041, CVE-2024-47698, CVE-2024-50188, CVE-2024-49977, CVE-2024-47687, CVE-2024-49945, CVE-2024-50008, CVE-2024-49859, CVE-2024-50062, CVE-2024-49880, CVE-2024-47671, CVE-2024-49867, CVE-2024-49912, CVE-2024-56614, CVE-2024-49862, CVE-2024-50021, CVE-2024-47670, CVE-2024-49911, CVE-2024-49855, CVE-2024-47712, CVE-2024-50229, CVE-2024-50096, CVE-2024-49895, CVE-2024-47677, CVE-2024-49934, CVE-2024-53156, CVE-2024-49893, CVE-2024-49925, CVE-2024-50063, CVE-2024-49926, CVE-2024-50201, CVE-2024-50033, CVE-2024-50199, CVE-2024-49874, CVE-2024-47732, CVE-2024-50078, CVE-2024-49935, CVE-2024-49902, CVE-2024-49989, CVE-2024-47675, CVE-2024-50064, CVE-2024-50015, CVE-2024-41016, CVE-2024-49949, CVE-2024-50090, CVE-2024-49860, CVE-2024-50036, CVE-2024-50084, CVE-2024-50182, CVE-2024-50061, CVE-2024-47702, CVE-2024-47730, CVE-2024-49951, CVE-2024-49938, CVE-2024-50088, CVE-2024-50198, CVE-2024-49998, CVE-2024-49931, CVE-2024-49944, CVE-2024-50000, CVE-2024-49954, CVE-2024-47753, CVE-2024-49976, CVE-2024-50048, CVE-2024-49881, CVE-2024-50093, CVE-2024-50019, CVE-2024-50059, CVE-2024-50016, CVE-2024-50068, CVE-2024-49920, CVE-2024-50035, CVE-2024-50197, CVE-2024-47699, CVE-2024-49914, CVE-2024-50191, CVE-2024-50083, CVE-2024-47701, CVE-2024-49877, CVE-2024-50017, CVE-2024-49915, CVE-2024-50001, CVE-2024-49864, CVE-2024-50189,CVE-2024-50101, CVE-2024-47704, CVE-2024-50024, CVE-2024-50038, CVE-2024-49850, CVE-2024-50027, CVE-2024-49952, CVE-2024-50074, CVE-2024-50171, CVE-2024-53165, CVE-2024-47689, CVE-2024-49865, CVE-2024-49853, CVE-2024-47742, CVE-2024-49994, CVE-2024-50179, CVE-2024-47686, CVE-2024-49975, CVE-2024-49948, CVE-2024-50099, CVE-2024-50175, CVE-2024-50028, CVE-2024-49947, CVE-2024-47741, CVE-2024-49888, CVE-2024-50055, CVE-2024-47749, CVE-2024-49992, CVE-2024-47715, CVE-2024-49922, CVE-2024-47756, CVE-2024-50023, CVE-2024-47720, CVE-2024-50194, CVE-2024-47688, CVE-2024-49991, CVE-2024-47705, CVE-2024-49942, CVE-2024-50047, CVE-2024-49981, CVE-2024-49950, CVE-2024-47684, CVE-2024-50065, CVE-2024-49939, CVE-2024-47726, CVE-2024-47697, CVE-2024-49959, CVE-2024-47690, CVE-2024-50040, CVE-2024-50002, CVE-2024-50029, CVE-2024-47752, CVE-2024-49924, CVE-2024-50073, CVE-2024-47733, CVE-2024-50075, CVE-2024-49937, CVE-2024-47707, CVE-2024-47692, CVE-2024-47703, CVE-2024-49988, CVE-2024-50060, CVE-2024-50039, CVE-2024-49961, CVE-2024-50042, CVE-2024-50148, CVE-2024-47678, CVE-2024-49923, CVE-2024-49901, CVE-2024-47706, CVE-2024-49882, CVE-2024-47693, CVE-2024-49876, CVE-2024-47747, CVE-2024-49871, CVE-2024-50076, CVE-2024-50183, CVE-2024-50007, CVE-2024-49958, CVE-2024-50134) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS linux-image-6.8.0-1022-ibm 6.8.0-1022.22 linux-image-ibm 6.8.0-1022.22 linux-image-ibm-classic 6.8.0-1022.22 linux-image-ibm-lts-24.04 6.8.0-1022.22 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic,linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7385-1 CVE-2024-41016, CVE-2024-47670, CVE-2024-47671, CVE-2024-47672, CVE-2024-47673, CVE-2024-47675, CVE-2024-47677, CVE-2024-47678, CVE-2024-47679, CVE-2024-47681, CVE-2024-47682, CVE-2024-47684, CVE-2024-47685, CVE-2024-47686, CVE-2024-47687, CVE-2024-47688, CVE-2024-47689, CVE-2024-47690, CVE-2024-47691, CVE-2024-47692, CVE-2024-47693, CVE-2024-47695, CVE-2024-47696, CVE-2024-47697, CVE-2024-47698, CVE-2024-47699, CVE-2024-47700, CVE-2024-47701, CVE-2024-47702, CVE-2024-47703, CVE-2024-47704, CVE-2024-47705, CVE-2024-47706, CVE-2024-47707, CVE-2024-47709, CVE-2024-47710, CVE-2024-47711, CVE-2024-47712, CVE-2024-47713, CVE-2024-47714, CVE-2024-47715, CVE-2024-47716, CVE-2024-47718, CVE-2024-47719, CVE-2024-47720, CVE-2024-47723, CVE-2024-47726, CVE-2024-47727, CVE-2024-47728, CVE-2024-47730, CVE-2024-47731, CVE-2024-47732, CVE-2024-47733, CVE-2024-47734, CVE-2024-47735, CVE-2024-47737, CVE-2024-47738, CVE-2024-47739, CVE-2024-47740, CVE-2024-47741, CVE-2024-47742, CVE-2024-47743, CVE-2024-47744, CVE-2024-47745, CVE-2024-47747, CVE-2024-47748, CVE-2024-47749, CVE-2024-47750, CVE-2024-47751, CVE-2024-47752, CVE-2024-47753, CVE-2024-47754, CVE-2024-47756, CVE-2024-47757, CVE-2024-49850, CVE-2024-49851, CVE-2024-49852, CVE-2024-49853, CVE-2024-49855, CVE-2024-49856, CVE-2024-49858, CVE-2024-49859, CVE-2024-49860, CVE-2024-49861, CVE-2024-49862, CVE-2024-49863, CVE-2024-49864, CVE-2024-49865, CVE-2024-49866, CVE-2024-49867, CVE-2024-49868, CVE-2024-49870, CVE-2024-49871, CVE-2024-49874, CVE-2024-49875, CVE-2024-49876, CVE-2024-49877, CVE-2024-49878, CVE-2024-49879, CVE-2024-49880, CVE-2024-49881, CVE-2024-49882, CVE-2024-49883, CVE-2024-49884, CVE-2024-49885, CVE-2024-49886, CVE-2024-49888, CVE-2024-49889, CVE-2024-49890, CVE-2024-49891, CVE-2024-49892, CVE-2024-49893, CVE-2024-49894, CVE-2024-49895, CVE-2024-49896, CVE-2024-49897, CVE-2024-49898, CVE-2024-49900, CVE-2024-49901, CVE-2024-49902, CVE-2024-49903, CVE-2024-49905, CVE-2024-49907, CVE-2024-49909, CVE-2024-49911, CVE-2024-49912, CVE-2024-49913, CVE-2024-49914, CVE-2024-49915, CVE-2024-49917, CVE-2024-49918, CVE-2024-49919, CVE-2024-49920, CVE-2024-49921, CVE-2024-49922, CVE-2024-49923, CVE-2024-49924, CVE-2024-49925, CVE-2024-49926, CVE-2024-49927, CVE-2024-49928, CVE-2024-49929, CVE-2024-49930, CVE-2024-49931, CVE-2024-49933, CVE-2024-49934, CVE-2024-49935, CVE-2024-49936, CVE-2024-49937, CVE-2024-49938, CVE-2024-49939, CVE-2024-49942, CVE-2024-49944, CVE-2024-49945, CVE-2024-49946, CVE-2024-49947, CVE-2024-49948, CVE-2024-49949, CVE-2024-49950, CVE-2024-49951, CVE-2024-49952, CVE-2024-49953, CVE-2024-49954, CVE-2024-49955, CVE-2024-49957, CVE-2024-49958, CVE-2024-49959, CVE-2024-49960, CVE-2024-49961, CVE-2024-49962, CVE-2024-49963, CVE-2024-49965, CVE-2024-49966, CVE-2024-49968, CVE-2024-49969, CVE-2024-49972, CVE-2024-49973, CVE-2024-49974, CVE-2024-49975, CVE-2024-49976, CVE-2024-49977, CVE-2024-49978, CVE-2024-49980, CVE-2024-49981, CVE-2024-49982, CVE-2024-49983, CVE-2024-49985, CVE-2024-49986, CVE-2024-49987, CVE-2024-49988, CVE-2024-49989, CVE-2024-49991, CVE-2024-49992, CVE-2024-49994, CVE-2024-49995, CVE-2024-49996, CVE-2024-49997, CVE-2024-49998, CVE-2024-49999, CVE-2024-50000, CVE-2024-50001, CVE-2024-50002, CVE-2024-50005, CVE-2024-50006, CVE-2024-50007, CVE-2024-50008, CVE-2024-50009, CVE-2024-50012, CVE-2024-50013, CVE-2024-50014, CVE-2024-50015, CVE-2024-50016, CVE-2024-50017, CVE-2024-50019, CVE-2024-50020, CVE-2024-50021, CVE-2024-50022, CVE-2024-50023, CVE-2024-50024, CVE-2024-50025, CVE-2024-50026, CVE-2024-50027, CVE-2024-50028, CVE-2024-50029, CVE-2024-50030, CVE-2024-50031, CVE-2024-50033, CVE-2024-50035, CVE-2024-50036, CVE-2024-50038, CVE-2024-50039, CVE-2024-50040, CVE-2024-50041, CVE-2024-50042, CVE-2024-50044, CVE-2024-50045, CVE-2024-50046, CVE-2024-50047, CVE-2024-50048, CVE-2024-50049, CVE-2024-50055, CVE-2024-50056, CVE-2024-50057, CVE-2024-50058, CVE-2024-50059, CVE-2024-50060, CVE-2024-50061, CVE-2024-50062, CVE-2024-50063, CVE-2024-50064, CVE-2024-50065, CVE-2024-50066, CVE-2024-50068, CVE-2024-50069, CVE-2024-50070, CVE-2024-50072, CVE-2024-50073, CVE-2024-50074, CVE-2024-50075, CVE-2024-50076, CVE-2024-50077, CVE-2024-50078, CVE-2024-50080, CVE-2024-50082, CVE-2024-50083, CVE-2024-50084, CVE-2024-50085, CVE-2024-50086, CVE-2024-50087, CVE-2024-50088, CVE-2024-50090, CVE-2024-50093, CVE-2024-50095, CVE-2024-50096, CVE-2024-50098, CVE-2024-50099, CVE-2024-50101, CVE-2024-50117, CVE-2024-50134, CVE-2024-50148, CVE-2024-50171, CVE-2024-50175, CVE-2024-50176, CVE-2024-50179, CVE-2024-50180, CVE-2024-50182, CVE-2024-50183, CVE-2024-50184, CVE-2024-50185, CVE-2024-50186, CVE-2024-50187, CVE-2024-50188, CVE-2024-50189, CVE-2024-50191, CVE-2024-50192, CVE-2024-50193, CVE-2024-50194, CVE-2024-50195, CVE-2024-50196, CVE-2024-50197, CVE-2024-50198, CVE-2024-50199, CVE-2024-50200, CVE-2024-50201, CVE-2024-50202, CVE-2024-50229, CVE-2024-50233, CVE-2024-53104, CVE-2024-53144, CVE-2024-53156, CVE-2024-53165, CVE-2024-53170, CVE-2024-56582, CVE-2024-56614, CVE-2024-56663, CVE-2024-8805, CVE-2025-0927 Package Information: https://launchpad.net/ubuntu/+source/linux-ibm/6.8.0-1022.22 . Significant updates for Ubuntu's Linux kernel address critical vulnerabilities to enhance system security.. security, linux, kernel, ============================================. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 27, 2025 Critical Ubuntu
172

Ubuntu 7384-1: Linux kernel (Azure) Security Advisory Updates

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7384-1 March 27, 2025 linux-azure vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-azure: Linux kernel for Microsoft Azure Cloud systems Details: Michael Randrianantenaina discovered that the Bluetooth driver in the Linux Kernel contained an improper access control vulnerability. A nearby attacker could use this to connect a rougue device and possibly execute arbitrary code. (CVE-2024-8805) Attila Szász discovered that the HFS+ file system implementation in the Linux Kernel contained a heap overflow vulnerability. An attacker could use a specially crafted file system image that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2025-0927) It was discovered that the CIFS network file system implementation in the Linux kernel did not properly verify the target namespace when handling upcalls. An attacker could use this to expose sensitive information. (CVE-2025-2312) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - ACPI drivers; - Drivers core; - ATA over ethernet (AOE) driver; - Network block device driver; - Ublk userspace block driver; - Compressed RAM block device driver; - TPM device driver; - CPU frequency scaling framework; - Hardware crypto device drivers; - DAX dirext access to differentiated memory framework; - ARM SCMImessage protocol; - EFI core; - GPU drivers; - HID subsystem; - I2C subsystem; - I3C subsystem; - IIO subsystem; - InfiniBand drivers; - Input Device core drivers; - IOMMU subsystem; - IRQ chip drivers; - Mailbox framework; - Media drivers; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - STMicroelectronics network drivers; - NTB driver; - Virtio pmem driver; - Parport drivers; - PCI subsystem; - Alibaba DDR Sub-System Driveway PMU driver; - Pin controllers subsystem; - x86 platform drivers; - Powercap sysfs driver; - Remote Processor subsystem; - SCSI subsystem; - SuperH / SH-Mobile drivers; - Direct Digital Synthesis drivers; - Thermal drivers; - TTY drivers; - UFS subsystem; - USB Device Class drivers; - USB Gadget drivers; - USB Host Controller drivers; - TI TPS6598x USB Power Delivery controller driver; - vDPA drivers; - Virtio Host (VHOST) subsystem; - Framebuffer layer; - AFS file system; - BTRFS file system; - File systems infrastructure; - Ceph distributed file system; - Ext4 file system; - F2FS file system; - JFS file system; - Network file systems library; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NILFS2 file system; - NTFS3 file system; - SMB network file system; - BPF subsystem; - Network file system (NFS) superblock; - Virtio network driver; - Network traffic control; - Network sockets; - TCP network protocol; - User-space API (UAPI); - io_uring subsystem; - Perf events; - Kernel thread helper (kthread); - Padata parallel execution mechanism; - RCU subsystem; - Arbitrary resource management; - Static call mechanism; - Timer subsystem; - Tracing infrastructure; - Maple Tree data structure library; - Memory management; - Bluetooth subsystem; - Ethernetbridge; - CAN network layer; - Networking core; - Distributed Switch Architecture; - IPv4 networking; - IPv6 networking; - MAC80211 subsystem; - IEEE 802.15.4 subsystem; - Multipath TCP; - NCSI (Network Controller Sideband Interface) driver; - Netfilter; - Netlink; - RxRPC session sockets; - SCTP protocol; - TIPC protocol; - Unix domain sockets; - Wireless networking; - eXpress Data Path; - AudioScience HPI driver; - KVM core; (CVE-2024-49994, CVE-2024-47740, CVE-2024-49936, CVE-2024-47716, CVE-2024-47733, CVE-2024-50075, CVE-2024-49870, CVE-2024-50007, CVE-2024-49897, CVE-2024-49915, CVE-2024-47756, CVE-2024-47700, CVE-2024-49946, CVE-2024-50012, CVE-2024-47750, CVE-2024-49863, CVE-2024-50059, CVE-2024-50026, CVE-2024-49995, CVE-2024-50035, CVE-2024-47751, CVE-2024-50096, CVE-2024-50082, CVE-2024-50090, CVE-2024-50000, CVE-2024-47690, CVE-2024-47741, CVE-2024-49898, CVE-2024-47685, CVE-2024-50038, CVE-2024-49957, CVE-2024-47682, CVE-2024-50002, CVE-2024-47709, CVE-2024-50201, CVE-2024-49927, CVE-2024-50076, CVE-2024-56582, CVE-2024-47742, CVE-2024-47734, CVE-2024-50040, CVE-2024-49862, CVE-2024-49942, CVE-2024-50193, CVE-2024-49880, CVE-2024-50008, CVE-2024-49949, CVE-2024-50056, CVE-2024-50099, CVE-2024-50180, CVE-2024-50045, CVE-2024-49923, CVE-2024-49987, CVE-2024-49884, CVE-2024-50031, CVE-2024-47705, CVE-2024-47728, CVE-2024-49969, CVE-2024-50077, CVE-2024-50188, CVE-2024-49852, CVE-2024-49890, CVE-2024-47745, CVE-2024-50058, CVE-2024-50186, CVE-2024-47749, CVE-2024-56614, CVE-2024-50021, CVE-2024-50055, CVE-2024-47727, CVE-2024-47677, CVE-2024-49922, CVE-2024-50015, CVE-2024-50084, CVE-2024-47689, CVE-2024-50101, CVE-2024-47699, CVE-2024-49947, CVE-2024-49999, CVE-2024-49868, CVE-2024-50184, CVE-2024-50187, CVE-2024-47757, CVE-2024-49900, CVE-2024-47703, CVE-2024-49975, CVE-2024-47692, CVE-2024-49980, CVE-2024-49951, CVE-2024-49930, CVE-2024-49867, CVE-2024-49860, CVE-2024-50009, CVE-2024-50072,CVE-2024-50229, CVE-2024-49954, CVE-2024-50183, CVE-2024-49858, CVE-2024-49909, CVE-2024-49926, CVE-2024-47754, CVE-2024-50027, CVE-2024-50200, CVE-2024-50196, CVE-2024-50086, CVE-2024-47739, CVE-2024-49978, CVE-2024-49983, CVE-2024-49894, CVE-2024-49973, CVE-2024-49888, CVE-2024-49974, CVE-2024-47672, CVE-2024-49977, CVE-2024-47738, CVE-2024-49893, CVE-2024-49876, CVE-2024-49960, CVE-2024-49955, CVE-2024-47670, CVE-2024-47706, CVE-2024-49931, CVE-2024-47686, CVE-2024-49855, CVE-2024-49901, CVE-2024-47752, CVE-2024-47675, CVE-2024-47704, CVE-2024-47735, CVE-2024-47744, CVE-2024-50088, CVE-2024-50070, CVE-2024-47707, CVE-2024-50176, CVE-2024-50080, CVE-2024-50175, CVE-2024-47731, CVE-2024-49853, CVE-2024-49929, CVE-2024-49989, CVE-2024-49921, CVE-2024-49965, CVE-2024-49891, CVE-2024-50005, CVE-2024-47715, CVE-2024-50085, CVE-2024-50189, CVE-2024-47723, CVE-2024-50020, CVE-2024-49902, CVE-2024-47730, CVE-2024-53156, CVE-2024-49895, CVE-2024-49997, CVE-2024-50192, CVE-2024-49850, CVE-2024-50062, CVE-2024-50033, CVE-2024-49972, CVE-2024-49945, CVE-2024-50036, CVE-2024-50202, CVE-2024-50095, CVE-2024-49913, CVE-2024-50049, CVE-2024-50148, CVE-2024-49948, CVE-2024-49866, CVE-2024-49963, CVE-2024-49907, CVE-2024-50117, CVE-2024-49885, CVE-2024-49874, CVE-2024-50198, CVE-2024-49856, CVE-2024-49986, CVE-2024-49871, CVE-2024-50028, CVE-2024-49889, CVE-2024-50024, CVE-2024-47687, CVE-2024-50065, CVE-2024-49953, CVE-2024-47748, CVE-2024-47747, CVE-2024-47673, CVE-2024-49928, CVE-2024-50191, CVE-2024-50016, CVE-2024-53170, CVE-2024-49933, CVE-2024-50029, CVE-2024-50098, CVE-2024-49988, CVE-2024-49985, CVE-2024-50042, CVE-2024-50171, CVE-2024-50233, CVE-2024-49976, CVE-2024-49996, CVE-2024-49950, CVE-2024-49968, CVE-2024-50083, CVE-2024-49966, CVE-2024-49851, CVE-2024-50066, CVE-2024-49864, CVE-2024-50048, CVE-2024-50069, CVE-2024-50001, CVE-2024-50194, CVE-2024-47693, CVE-2024-49905, CVE-2024-50134, CVE-2024-49944, CVE-2024-50060, CVE-2024-49892, CVE-2024-49982, CVE-2024-49883,CVE-2024-49875, CVE-2024-47691, CVE-2024-47714, CVE-2024-47712, CVE-2024-50025, CVE-2024-50023, CVE-2024-47726, CVE-2024-50041, CVE-2024-49896, CVE-2024-50195, CVE-2024-47679, CVE-2024-47678, CVE-2024-49877, CVE-2024-47684, CVE-2024-47719, CVE-2024-49937, CVE-2024-53144, CVE-2024-47737, CVE-2024-49998, CVE-2024-49879, CVE-2024-50019, CVE-2024-50093, CVE-2024-50073, CVE-2024-50064, CVE-2024-50006, CVE-2024-47695, CVE-2024-49882, CVE-2024-50179, CVE-2024-49865, CVE-2024-47702, CVE-2024-50046, CVE-2024-49919, CVE-2024-47697, CVE-2024-50017, CVE-2024-50014, CVE-2024-49861, CVE-2024-50197, CVE-2024-49886, CVE-2024-49938, CVE-2024-49991, CVE-2024-49981, CVE-2024-56663, CVE-2024-49914, CVE-2024-49920, CVE-2024-47671, CVE-2024-49961, CVE-2024-47698, CVE-2024-49952, CVE-2024-47688, CVE-2024-50078, CVE-2024-50199, CVE-2024-49918, CVE-2024-50044, CVE-2024-50013, CVE-2024-47711, CVE-2024-49917, CVE-2024-50057, CVE-2024-47718, CVE-2024-49911, CVE-2024-49912, CVE-2024-53165, CVE-2024-50068, CVE-2024-50087, CVE-2024-47720, CVE-2024-49958, CVE-2024-49934, CVE-2024-49859, CVE-2024-47710, CVE-2024-49903, CVE-2024-49925, CVE-2024-50061, CVE-2024-41016, CVE-2024-47696, CVE-2024-47701, CVE-2024-49939, CVE-2024-49924, CVE-2024-49935, CVE-2024-50030, CVE-2024-50074, CVE-2024-47681, CVE-2024-47743, CVE-2024-49992, CVE-2024-49881, CVE-2024-50063, CVE-2024-47713, CVE-2024-50039, CVE-2024-50185, CVE-2024-49962, CVE-2024-50182, CVE-2024-50022, CVE-2024-49959, CVE-2024-50047, CVE-2024-53104, CVE-2024-49878, CVE-2024-47732, CVE-2024-47753) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS linux-image-6.8.0-1025-azure 6.8.0-1025.30 linux-image-6.8.0-1025-azure-fde 6.8.0-1025.30 linux-image-azure-fde-lts-24.04 6.8.0-1025.30 linux-image-azure-lts-24.04 6.8.0-1025.30 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABIchange the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7384-1 CVE-2024-41016, CVE-2024-47670, CVE-2024-47671, CVE-2024-47672, CVE-2024-47673, CVE-2024-47675, CVE-2024-47677, CVE-2024-47678, CVE-2024-47679, CVE-2024-47681, CVE-2024-47682, CVE-2024-47684, CVE-2024-47685, CVE-2024-47686, CVE-2024-47687, CVE-2024-47688, CVE-2024-47689, CVE-2024-47690, CVE-2024-47691, CVE-2024-47692, CVE-2024-47693, CVE-2024-47695, CVE-2024-47696, CVE-2024-47697, CVE-2024-47698, CVE-2024-47699, CVE-2024-47700, CVE-2024-47701, CVE-2024-47702, CVE-2024-47703, CVE-2024-47704, CVE-2024-47705, CVE-2024-47706, CVE-2024-47707, CVE-2024-47709, CVE-2024-47710, CVE-2024-47711, CVE-2024-47712, CVE-2024-47713, CVE-2024-47714, CVE-2024-47715, CVE-2024-47716, CVE-2024-47718, CVE-2024-47719, CVE-2024-47720, CVE-2024-47723, CVE-2024-47726, CVE-2024-47727, CVE-2024-47728, CVE-2024-47730, CVE-2024-47731, CVE-2024-47732, CVE-2024-47733, CVE-2024-47734, CVE-2024-47735, CVE-2024-47737, CVE-2024-47738, CVE-2024-47739, CVE-2024-47740, CVE-2024-47741, CVE-2024-47742, CVE-2024-47743, CVE-2024-47744, CVE-2024-47745, CVE-2024-47747, CVE-2024-47748, CVE-2024-47749, CVE-2024-47750, CVE-2024-47751, CVE-2024-47752, CVE-2024-47753, CVE-2024-47754, CVE-2024-47756, CVE-2024-47757, CVE-2024-49850, CVE-2024-49851, CVE-2024-49852, CVE-2024-49853, CVE-2024-49855, CVE-2024-49856, CVE-2024-49858, CVE-2024-49859, CVE-2024-49860, CVE-2024-49861, CVE-2024-49862, CVE-2024-49863, CVE-2024-49864, CVE-2024-49865, CVE-2024-49866, CVE-2024-49867, CVE-2024-49868, CVE-2024-49870, CVE-2024-49871,CVE-2024-49874, CVE-2024-49875, CVE-2024-49876, CVE-2024-49877, CVE-2024-49878, CVE-2024-49879, CVE-2024-49880, CVE-2024-49881, CVE-2024-49882, CVE-2024-49883, CVE-2024-49884, CVE-2024-49885, CVE-2024-49886, CVE-2024-49888, CVE-2024-49889, CVE-2024-49890, CVE-2024-49891, CVE-2024-49892, CVE-2024-49893, CVE-2024-49894, CVE-2024-49895, CVE-2024-49896, CVE-2024-49897, CVE-2024-49898, CVE-2024-49900, CVE-2024-49901, CVE-2024-49902, CVE-2024-49903, CVE-2024-49905, CVE-2024-49907, CVE-2024-49909, CVE-2024-49911, CVE-2024-49912, CVE-2024-49913, CVE-2024-49914, CVE-2024-49915, CVE-2024-49917, CVE-2024-49918, CVE-2024-49919, CVE-2024-49920, CVE-2024-49921, CVE-2024-49922, CVE-2024-49923, CVE-2024-49924, CVE-2024-49925, CVE-2024-49926, CVE-2024-49927, CVE-2024-49928, CVE-2024-49929, CVE-2024-49930, CVE-2024-49931, CVE-2024-49933, CVE-2024-49934, CVE-2024-49935, CVE-2024-49936, CVE-2024-49937, CVE-2024-49938, CVE-2024-49939, CVE-2024-49942, CVE-2024-49944, CVE-2024-49945, CVE-2024-49946, CVE-2024-49947, CVE-2024-49948, CVE-2024-49949, CVE-2024-49950, CVE-2024-49951, CVE-2024-49952, CVE-2024-49953, CVE-2024-49954, CVE-2024-49955, CVE-2024-49957, CVE-2024-49958, CVE-2024-49959, CVE-2024-49960, CVE-2024-49961, CVE-2024-49962, CVE-2024-49963, CVE-2024-49965, CVE-2024-49966, CVE-2024-49968, CVE-2024-49969, CVE-2024-49972, CVE-2024-49973, CVE-2024-49974, CVE-2024-49975, CVE-2024-49976, CVE-2024-49977, CVE-2024-49978, CVE-2024-49980, CVE-2024-49981, CVE-2024-49982, CVE-2024-49983, CVE-2024-49985, CVE-2024-49986, CVE-2024-49987, CVE-2024-49988, CVE-2024-49989, CVE-2024-49991, CVE-2024-49992, CVE-2024-49994, CVE-2024-49995, CVE-2024-49996, CVE-2024-49997, CVE-2024-49998, CVE-2024-49999, CVE-2024-50000, CVE-2024-50001, CVE-2024-50002, CVE-2024-50005, CVE-2024-50006, CVE-2024-50007, CVE-2024-50008, CVE-2024-50009, CVE-2024-50012, CVE-2024-50013, CVE-2024-50014, CVE-2024-50015, CVE-2024-50016, CVE-2024-50017,CVE-2024-50019, CVE-2024-50020, CVE-2024-50021, CVE-2024-50022, CVE-2024-50023, CVE-2024-50024, CVE-2024-50025, CVE-2024-50026, CVE-2024-50027, CVE-2024-50028, CVE-2024-50029, CVE-2024-50030, CVE-2024-50031, CVE-2024-50033, CVE-2024-50035, CVE-2024-50036, CVE-2024-50038, CVE-2024-50039, CVE-2024-50040, CVE-2024-50041, CVE-2024-50042, CVE-2024-50044, CVE-2024-50045, CVE-2024-50046, CVE-2024-50047, CVE-2024-50048, CVE-2024-50049, CVE-2024-50055, CVE-2024-50056, CVE-2024-50057, CVE-2024-50058, CVE-2024-50059, CVE-2024-50060, CVE-2024-50061, CVE-2024-50062, CVE-2024-50063, CVE-2024-50064, CVE-2024-50065, CVE-2024-50066, CVE-2024-50068, CVE-2024-50069, CVE-2024-50070, CVE-2024-50072, CVE-2024-50073, CVE-2024-50074, CVE-2024-50075, CVE-2024-50076, CVE-2024-50077, CVE-2024-50078, CVE-2024-50080, CVE-2024-50082, CVE-2024-50083, CVE-2024-50084, CVE-2024-50085, CVE-2024-50086, CVE-2024-50087, CVE-2024-50088, CVE-2024-50090, CVE-2024-50093, CVE-2024-50095, CVE-2024-50096, CVE-2024-50098, CVE-2024-50099, CVE-2024-50101, CVE-2024-50117, CVE-2024-50134, CVE-2024-50148, CVE-2024-50171, CVE-2024-50175, CVE-2024-50176, CVE-2024-50179, CVE-2024-50180, CVE-2024-50182, CVE-2024-50183, CVE-2024-50184, CVE-2024-50185, CVE-2024-50186, CVE-2024-50187, CVE-2024-50188, CVE-2024-50189, CVE-2024-50191, CVE-2024-50192, CVE-2024-50193, CVE-2024-50194, CVE-2024-50195, CVE-2024-50196, CVE-2024-50197, CVE-2024-50198, CVE-2024-50199, CVE-2024-50200, CVE-2024-50201, CVE-2024-50202, CVE-2024-50229, CVE-2024-50233, CVE-2024-53104, CVE-2024-53144, CVE-2024-53156, CVE-2024-53165, CVE-2024-53170, CVE-2024-56582, CVE-2024-56614, CVE-2024-56663, CVE-2024-8805, CVE-2025-0927, CVE-2025-2312 Package Information: https://launchpad.net/ubuntu/+source/linux-azure/6.8.0-1025.30 . Critical updates for Ubuntu 24.04 LTS addressing multiple security issues in the Linux kernel for Azure.. security, linux, kernel,============================================. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 27, 2025 Critical Ubuntu
87

Debian: DSA-5144-1 Moderate: HTCondor Authentication Threat

Several flaws have been discovered in HTCondor, a distributed workload management system, which allow users with only READ access to any daemon to use a different authentication method than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5144-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Markus Koschany May 22, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : condor CVE ID : CVE-2019-18823 CVE-2022-26110 Debian Bug : 963777 1008634 Several flaws have been discovered in HTCondor, a distributed workload management system, which allow users with only READ access to any daemon to use a different authentication method than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is possible to impersonate another user and submit or remove jobs. For the oldstable distribution (buster), these problems have been fixed in version 8.6.8~dfsg.1-2+deb10u1. We recommend that you upgrade your condor packages. For the detailed security status of condor please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/condor Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Numerous vulnerabilities exist within HTCondor that permit unauthorized authentication techniques. Suggested enhancements to bolster security measures.. HTCondor Security Update, Debian DSA-5144-1, Authentication Flaw. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 22, 2022 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200