Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 6 articles for you...
87

Debian Trixie Incus Critical DoS Security Advisory DSA-6244-1

Multiple security issues were discovered in Incus, a system container and virtual machine manager, which could result in denial of service, For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u7. We recommend that you upgrade your incus packages.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6244-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff May 02, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : incus CVE ID : CVE-2026-40195 CVE-2026-40197 CVE-2026-40243 CVE-2026-40251 CVE-2026-41647 CVE-2026-41648 CVE-2026-41684 CVE-2026-41685 Multiple security issues were discovered in Incus, a system container and virtual machine manager, which could result in denial of service, For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u7. We recommend that you upgrade your incus packages. For the detailed security status of incus please refer to its security tracker page at: https://security-tracker.debian.org/tracker/incus Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Multiple issues in Incus lead to denial of service risks. Upgrade immediately for security enhancements on Debian.. Denial of Service, Incus Security, Debian DSA 6244, System Container Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 02, 2026 Critical Debian
89

Fedora 42 Incus 6.23 Security Update Advisory 2026-4481307278

Remove incus dependency from incus-agent. Update to 6.23. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-4481307278 2026-04-20 01:04:24.758007+00:00 -------------------------------------------------------------------------------- Name : incus Product : Fedora 42 Version : 6.23 Release : 3.fc42 URL : https://linuxcontainers.org/incus Summary : Powerful system container and virtual machine manager Description : Container hypervisor based on LXC Incus offers a REST API to remotely manage containers over the network, using an image based work-flow and with support for live migration. This package contains the Incus daemon. -------------------------------------------------------------------------------- Update Information: Remove incus dependency from incus-agent. Update to 6.23 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 9 2026 Carl George - 6.23-3 - Remove incus dependency from incus-agent rhbz#2456888 * Mon Apr 6 2026 Reto Gantenbein - 6.23-2 - Fix static builds of vendored dependencies (RHBZ 2419661) * Mon Apr 6 2026 Reto Gantenbein - 6.23-1 - Update to 6.23 * Mon Mar 30 2026 Neal Gompa - 6.19.1-4 - Drop selinux subpackage in favor of container-selinux * Tue Feb 3 2026 Maxwell G - 6.19.1-3 - Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26 * Fri Jan 16 2026 Fedora Release Engineering - 6.19.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2390870 - incus: go-viper's mapstructure May Leak Sensitive Information in Logs [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2390870 [ 2 ] Bug #2398840 - CVE-2025-47910 incus: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398840 [3 ] Bug #2412795 - CVE-2025-58183 incus: Unbounded allocation when parsing GNU sparse map [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2412795 [ 4 ] Bug #2432454 - CVE-2026-23954 incus: container image templating arbitrary host file read and write [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2432454 [ 5 ] Bug #2432456 - CVE-2026-23953 incus: container environment configuration newline injection [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2432456 [ 6 ] Bug #2441165 - CVE-2025-69725 incus: Go-chi/chi: Open Redirect vulnerability allows redirection to malicious websites [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2441165 [ 7 ] Bug #2452041 - CVE-2026-33542 incus: Incus: Image cache poisoning due to insufficient image fingerprint validation [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2452041 [ 8 ] Bug #2452043 - CVE-2026-33897 incus: Incus: Arbitrary file read/write as root via pongo2 template chroot bypass [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2452043 [ 9 ] Bug #2452045 - CVE-2026-33711 incus: Incus: Local privilege escalation or denial of service via predictable temporary file paths [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2452045 [ 10 ] Bug #2452047 - CVE-2026-33743 incus: Incus: Denial of Service via specially crafted storage bucket backup [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2452047 [ 11 ] Bug #2452105 - CVE-2026-33898 incus: Incus: Privilege escalation and unauthorized access due to improper authentication token validation in web UI [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452105 [ 12 ] Bug #2456888 - Installing incus-agent installs the entire incus stack https://bugzilla.redhat.com/show_bug.cgi?id=2456888 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnfupgrade --advisory FEDORA-2026-4481307278' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . New update for Fedora 42 incus 6.23 removes dependencies and enhances security. Immediate action recommended.. Fedora Update, incus security, container management, software update. . Severity: Informational. LinuxSecurity.com Team

Calendar 2 Apr 20, 2026 Informational Fedora
89

Fedora 43 incus 6.23 Dependency Removed Advisory 2026-094b7621cf

Remove incus dependency from incus-agent. Update to 6.23. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-094b7621cf 2026-04-20 00:44:47.956847+00:00 -------------------------------------------------------------------------------- Name : incus Product : Fedora 43 Version : 6.23 Release : 3.fc43 URL : https://linuxcontainers.org/incus Summary : Powerful system container and virtual machine manager Description : Container hypervisor based on LXC Incus offers a REST API to remotely manage containers over the network, using an image based work-flow and with support for live migration. This package contains the Incus daemon. -------------------------------------------------------------------------------- Update Information: Remove incus dependency from incus-agent. Update to 6.23 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 9 2026 Carl George - 6.23-3 - Remove incus dependency from incus-agent rhbz#2456888 * Mon Apr 6 2026 Reto Gantenbein - 6.23-2 - Fix static builds of vendored dependencies (RHBZ 2419661) * Mon Apr 6 2026 Reto Gantenbein - 6.23-1 - Update to 6.23 * Mon Mar 30 2026 Neal Gompa - 6.19.1-4 - Drop selinux subpackage in favor of container-selinux * Tue Feb 3 2026 Maxwell G - 6.19.1-3 - Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26 * Fri Jan 16 2026 Fedora Release Engineering - 6.19.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2412713 - CVE-2025-58183 incus: Unbounded allocation when parsing GNU sparse map [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2412713 [ 2 ] Bug #2419345 - incus-6.23.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2419345 [ 3 ] Bug #2419661 - incus-agent must bestatically linked for VM exec to work https://bugzilla.redhat.com/show_bug.cgi?id=2419661 [ 4 ] Bug #2432455 - CVE-2026-23954 incus: container image templating arbitrary host file read and write [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2432455 [ 5 ] Bug #2432457 - CVE-2026-23953 incus: container environment configuration newline injection [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2432457 [ 6 ] Bug #2436657 - Incus VMs do not boot due to unknown audio driver https://bugzilla.redhat.com/show_bug.cgi?id=2436657 [ 7 ] Bug #2441179 - CVE-2025-69725 incus: Go-chi/chi: Open Redirect vulnerability allows redirection to malicious websites [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2441179 [ 8 ] Bug #2452042 - CVE-2026-33542 incus: Incus: Image cache poisoning due to insufficient image fingerprint validation [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2452042 [ 9 ] Bug #2452044 - CVE-2026-33897 incus: Incus: Arbitrary file read/write as root via pongo2 template chroot bypass [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2452044 [ 10 ] Bug #2452046 - CVE-2026-33711 incus: Incus: Local privilege escalation or denial of service via predictable temporary file paths [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2452046 [ 11 ] Bug #2452048 - CVE-2026-33743 incus: Incus: Denial of Service via specially crafted storage bucket backup [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2452048 [ 12 ] Bug #2452106 - CVE-2026-33945 incus: Incus: Privilege escalation and denial of service via path traversal in systemd credential configuration [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452106 [ 13 ] Bug #2456888 - Installing incus-agent installs the entire incus stack https://bugzilla.redhat.com/show_bug.cgi?id=2456888 -------------------------------------------------------------------------------- This update canbe installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-094b7621cf' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update to Fedora 43 incus 6.23, addressing dependency removal for incus-agent and enhancing container management.. Fedora 43 incus update, incus dependency removal, system container manager. . Severity: Informational. LinuxSecurity.com Team

Calendar 2 Apr 20, 2026 Informational Fedora
87

Debian DSA-6212-1 Incus Important Privilege Escalation Issues

Two security issues were discovered in Incus, a system container and virtual machine manager, which could result in restriction bypass or privilege escalation. For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u6.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6212-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 15, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : incus CVE ID : CVE-2026-34178 CVE-2026-34179 Two security issues were discovered in Incus, a system container and virtual machine manager, which could result in restriction bypass or privilege escalation. For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u6. We recommend that you upgrade your incus packages. For the detailed security status of incus please refer to its security tracker page at: https://security-tracker.debian.org/tracker/incus Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Two critical security issues fixed in Incus for Debian affecting privilege escalation and restriction bypass. Upgrade recommended.. Debian Incus Security Advisory Privilege Escalation Bypass Issues. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 15, 2026 Important Debian
202

Ubuntu Rolling Edge 22.04-2.3 Critical Patch 2026-20345-3

An update that solves 6 vulnerabilities can now be installed.. # incus-6.23-1.1 on GA media Announcement ID: openSUSE-SU-2026:10450-1 Rating: moderate Cross-References: * CVE-2026-33542 * CVE-2026-33711 * CVE-2026-33743 * CVE-2026-33897 * CVE-2026-33898 * CVE-2026-33945 CVSS scores: * CVE-2026-33542 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:N * CVE-2026-33897 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-33945 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Tumbleweed An update that solves 6 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the incus-6.23-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * incus 6.23-1.1 * incus-bash-completion 6.23-1.1 * incus-fish-completion 6.23-1.1 * incus-tools 6.23-1.1 * incus-zsh-completion 6.23-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33542.html * https://www.suse.com/security/cve/CVE-2026-33711.html * https://www.suse.com/security/cve/CVE-2026-33743.html * https://www.suse.com/security/cve/CVE-2026-33897.html * https://www.suse.com/security/cve/CVE-2026-33898.html * https://www.suse.com/security/cve/CVE-2026-33945.html . Learn about the openSUSE update for incus version 6.23-1.1 addressing multiple security issues with moderate severity.. openSUSE Tumbleweed, incus 6.23-1.1, moderate security update. . LinuxSecurity.com Team

Calendar 2 Mar 31, 2026 OpenSUSE
87

Debian Trixie DSA-6184-1 Incus Important Denial of Service CVE-2026-28384

Multiple security issues were discovered in Incus, a system container and virtual machine manager, which could result in denial of service or the execution of arbitrary commands. For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u5.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6184-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff March 29, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : incus CVE ID : CVE-2026-28384 CVE-2026-33542 CVE-2026-33743 Multiple security issues were discovered in Incus, a system container and virtual machine manager, which could result in denial of service or the execution of arbitrary commands. For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u5. We recommend that you upgrade your incus packages. For the detailed security status of incus please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/incus Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical security issues in Incus system container manager fixed in Debian's stable trixie distribution with urgent updates.. Debian Security Advisory, Incus system container, Denial of Service Fix, Arbitrary Commands Vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 29, 2026 Important Debian
202

openSUSE Leap 15.4 Kernel 5.14-2.1 High Stability Patch 2026-19876-3

An update that solves 2 vulnerabilities can now be installed.. # incus-6.22-1.1 on GA media Announcement ID: openSUSE-SU-2026:10280-1 Rating: moderate Cross-References: * CVE-2026-23953 * CVE-2026-23954 Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the incus-6.22-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * incus 6.22-1.1 * incus-bash-completion 6.22-1.1 * incus-fish-completion 6.22-1.1 * incus-tools 6.22-1.1 * incus-zsh-completion 6.22-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23953.html * https://www.suse.com/security/cve/CVE-2026-23954.html . Two vulnerabilities fixed in Incus 6.22-1.1 enhance openSUSE Tumbleweed's security. Immediate update recommended.. openSUSE Tumbleweed, Incus 6.22-1.1, security patch. . LinuxSecurity.com Team

Calendar 2 Mar 05, 2026 OpenSUSE
87

Debian Trixie DSA-6109-1 Incus Critical Command Execution Issues

Two security issues were discovered in Incus, a system container and virtual machine manager, which could result the in execution of arbitrary commands via malformed images. For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u4.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6109-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff January 23, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : incus CVE ID : CVE-2026-23953 CVE-2026-23954 Two security issues were discovered in Incus, a system container and virtual machine manager, which could result the in execution of arbitrary commands via malformed images. For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u4. We recommend that you upgrade your incus packages. For the detailed security status of incus please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/incus Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical security advisory for Incus in Debian Trixie addressing arbitrary command execution risks via malformed images.. Incus Debian Trixie Security Update Arbitrary Command Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 23, 2026 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here