Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
100

SUSE Openvswitch Important Heap Over-read Fix 2026-22145-1

An update that solves three vulnerabilities can now be installed.. # Security update for openvswitch Announcement ID: SUSE-SU-2026:22145-1 Release Date: 2026-06-17T08:39:16Z Rating: important References: * bsc#1261273 * bsc#1262498 * bsc#1262499 Cross-References: * CVE-2026-34956 * CVE-2026-5265 * CVE-2026-5367 CVSS scores: * CVE-2026-34956 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34956 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34956 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5265 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-5265 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-5367 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-5367 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities can now be installed. ## Description: This update for openvswitch fixes the following issues * CVE-2026-5265: heap over-read in ICMP error response generation (bsc#1262498). * CVE-2026-5367: heap over-read in OVN DHCPv6 client ID processing (bsc#1262499). * CVE-2026-34956: Invalid memory access in conntrack FTP alg (bsc#1261273). Changes for openvswitch: * Update ovn to 25.03.3 * Bug fixes * Add support for special port_security prefix "VRRPv3". This prefix allows CMS to allow all required traffic for a VRRPv3 virtual router behind LSP. See ovn-nb(5) man page for more details. * Fixed support for fragmented traffic in the userspace datapath. Added the "acl_ct_translation" NB_Global option to enable connection tracking based L4 field translation for stateful ACLs. When enabled allows proper handling of IP fragmentation in userspace datapaths. This option may break hardware offloading and is disabled by default. * Added disable_garp_rarp option tological_router table in order to disable GARP/RARP announcements by all the peer ports of this logical router. * Update openvswitch to 3.5.4 * Full changelog https://www.openvswitch.org/releases/NEWS-3.5.4.txt * OVS validated with DPDK 24.11.4. * Fixed buffer overflow during conntrack processing of alg=ftp in userspace datapath (CVE-2026-34956) (bsc#1261273). * Update openvswitch to 3.5.3 * Full changelog https://www.openvswitch.org/releases/NEWS-3.5.3.txt * Bug fixes ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-937=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * python3-openvswitch-debuginfo-3.5.4-160000.4.1 * libopenvswitch-3_5-0-debuginfo-3.5.4-160000.4.1 * openvswitch-3.5.4-160000.4.1 * openvswitch-debuginfo-3.5.4-160000.4.1 * libopenvswitch-3_5-0-3.5.4-160000.4.1 * openvswitch-debugsource-3.5.4-160000.4.1 * python3-openvswitch-3.5.4-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34956.html * https://www.suse.com/security/cve/CVE-2026-5265.html * https://www.suse.com/security/cve/CVE-2026-5367.html * https://bugzilla.suse.com/show_bug.cgi?id=1261273 * https://bugzilla.suse.com/show_bug.cgi?id=1262498 * https://bugzilla.suse.com/show_bug.cgi?id=1262499 . Update for openvswitch resolves important issues, enhancing security against vulnerabilities and improving performance.. openvswitch security update, SUSE Linux Micro 6.2, heap over-read fix, invalid memory access. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 18, 2026 Important SuSE
100

openSUSE 15.4 openvswitch Moderate Invalid Memory Access Vuln 2026-1871-1

An update that solves one vulnerability can now be installed.. # Security update for openvswitch Announcement ID: SUSE-SU-2026:1871-1 Release Date: 2026-05-15T15:22:14Z Rating: moderate References: * bsc#1261273 Cross-References: * CVE-2026-34956 CVSS scores: * CVE-2026-34956 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34956 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34956 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for openvswitch fixes the following issue: * CVE-2026-34956: Invalid memory access in conntrack FTP alg (bsc#1261273). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1871=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libopenvswitch-2_14-0-debuginfo-2.14.2-150400.24.32.1 * openvswitch-debugsource-2.14.2-150400.24.32.1 * openvswitch-pki-2.14.2-150400.24.32.1 * libovn-20_06-0-20.06.2-150400.24.32.1 * ovn-vtep-debuginfo-20.06.2-150400.24.32.1 * python3-ovs-2.14.2-150400.24.32.1 * ovn-vtep-20.06.2-150400.24.32.1 * libovn-20_06-0-debuginfo-20.06.2-150400.24.32.1 * ovn-docker-20.06.2-150400.24.32.1 * ovn-20.06.2-150400.24.32.1 * openvswitch-test-debuginfo-2.14.2-150400.24.32.1 * ovn-central-20.06.2-150400.24.32.1 * openvswitch-2.14.2-150400.24.32.1 * openvswitch-vtep-debuginfo-2.14.2-150400.24.32.1 * openvswitch-vtep-2.14.2-150400.24.32.1 * ovn-host-debuginfo-20.06.2-150400.24.32.1 * ovn-central-debuginfo-20.06.2-150400.24.32.1 * ovn-host-20.06.2-150400.24.32.1 * openvswitch-test-2.14.2-150400.24.32.1 *openvswitch-ipsec-2.14.2-150400.24.32.1 * libopenvswitch-2_14-0-2.14.2-150400.24.32.1 * ovn-debuginfo-20.06.2-150400.24.32.1 * openvswitch-debuginfo-2.14.2-150400.24.32.1 * ovn-devel-20.06.2-150400.24.32.1 * openvswitch-devel-2.14.2-150400.24.32.1 * openSUSE Leap 15.4 (noarch) * openvswitch-doc-2.14.2-150400.24.32.1 * ovn-doc-20.06.2-150400.24.32.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34956.html * https://bugzilla.suse.com/show_bug.cgi?id=1261273 . Update available for openvswitch on openSUSE fixing moderate issue with invalid memory access leading to potential risk.. openvswitch security update, SUSE patch information, memory access vulnerability. . LinuxSecurity.com Team

Calendar%202 May 15, 2026 SuSE
100

SUSE Linux 12 SP5 Openvswitch Moderate Memory Access Advisory 2026-1482-1

An update that solves one vulnerability can now be installed.. # Security update for openvswitch Announcement ID: SUSE-SU-2026:1482-1 Release Date: 2026-04-20T10:10:04Z Rating: moderate References: * bsc#1261273 Cross-References: * CVE-2026-34956 CVSS scores: * CVE-2026-34956 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34956 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for openvswitch fixes the following issues: * CVE-2026-34956: invalid memory access via crafted FTP payloads in userspace conntrack flows specifying the FTP alg handler (bsc#1261273). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-1482=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libopenvswitch-2_11-0-2.11.5-3.30.1 * openvswitch-debuginfo-2.11.5-3.30.1 * openvswitch-debugsource-2.11.5-3.30.1 * openvswitch-2.11.5-3.30.1 * libopenvswitch-2_11-0-debuginfo-2.11.5-3.30.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34956.html * https://bugzilla.suse.com/show_bug.cgi?id=1261273 . SUSE issues a moderate security advisory for Openvswitch addressing invalid memory access vulnerability. Install now.. openvswitch security patch,SUSE update,moderate threat fix. . LinuxSecurity.com Team

Calendar%202 Apr 20, 2026 SuSE
202

ubuntu 22.04 viavm5 Significant Memory Leak SUSE-SU-2023-8205-3

An update that solves one vulnerability can now be installed.. # Security update for openvswitch3 Announcement ID: SUSE-SU-2026:1440-1 Release Date: 2026-04-17T13:44:11Z Rating: moderate References: * bsc#1261273 Cross-References: * CVE-2026-34956 CVSS scores: * CVE-2026-34956 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34956 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Micro 5.5 An update that solves one vulnerability can now be installed. ## Description: This update for openvswitch3 fixes the following issues: * CVE-2026-34956: invalid memory access via crafted FTP payloads in userspace conntrack flows specifying the FTP alg handler (bsc#1261273). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-1440=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-1440=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * openvswitch3-pki-3.1.7-150500.3.28.1 * ovn3-host-debuginfo-23.03.3-150500.3.28.1 * openvswitch3-vtep-debuginfo-3.1.7-150500.3.28.1 * ovn3-devel-23.03.3-150500.3.28.1 * openvswitch3-test-debuginfo-3.1.7-150500.3.28.1 * openvswitch3-ipsec-3.1.7-150500.3.28.1 * ovn3-23.03.3-150500.3.28.1 * python3-ovs3-3.1.7-150500.3.28.1 * openvswitch3-debuginfo-3.1.7-150500.3.28.1 * ovn3-central-debuginfo-23.03.3-150500.3.28.1 * openvswitch3-test-3.1.7-150500.3.28.1 * ovn3-central-23.03.3-150500.3.28.1 * openvswitch3-3.1.7-150500.3.28.1 * openvswitch3-debugsource-3.1.7-150500.3.28.1 * libovn-23_03-0-debuginfo-23.03.3-150500.3.28.1 * ovn3-vtep-23.03.3-150500.3.28.1 *ovn3-vtep-debuginfo-23.03.3-150500.3.28.1 * libopenvswitch-3_1-0-3.1.7-150500.3.28.1 * openvswitch3-devel-3.1.7-150500.3.28.1 * openvswitch3-vtep-3.1.7-150500.3.28.1 * ovn3-docker-23.03.3-150500.3.28.1 * libovn-23_03-0-23.03.3-150500.3.28.1 * libopenvswitch-3_1-0-debuginfo-3.1.7-150500.3.28.1 * ovn3-host-23.03.3-150500.3.28.1 * ovn3-debuginfo-23.03.3-150500.3.28.1 * openSUSE Leap 15.5 (noarch) * ovn3-doc-23.03.3-150500.3.28.1 * openvswitch3-doc-3.1.7-150500.3.28.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * openvswitch3-debuginfo-3.1.7-150500.3.28.1 * ovn3-central-debuginfo-23.03.3-150500.3.28.1 * openvswitch3-pki-3.1.7-150500.3.28.1 * libopenvswitch-3_1-0-3.1.7-150500.3.28.1 * ovn3-debuginfo-23.03.3-150500.3.28.1 * ovn3-docker-23.03.3-150500.3.28.1 * libovn-23_03-0-23.03.3-150500.3.28.1 * ovn3-vtep-23.03.3-150500.3.28.1 * python3-ovs3-3.1.7-150500.3.28.1 * ovn3-host-debuginfo-23.03.3-150500.3.28.1 * libopenvswitch-3_1-0-debuginfo-3.1.7-150500.3.28.1 * ovn3-central-23.03.3-150500.3.28.1 * ovn3-host-23.03.3-150500.3.28.1 * openvswitch3-vtep-debuginfo-3.1.7-150500.3.28.1 * openvswitch3-3.1.7-150500.3.28.1 * openvswitch3-debugsource-3.1.7-150500.3.28.1 * libovn-23_03-0-debuginfo-23.03.3-150500.3.28.1 * openvswitch3-vtep-3.1.7-150500.3.28.1 * ovn3-vtep-debuginfo-23.03.3-150500.3.28.1 * ovn3-23.03.3-150500.3.28.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34956.html * https://bugzilla.suse.com/show_bug.cgi?id=1261273 . This update for openvswitch3 on openSUSE addresses a moderate severity issue of invalid memory access, improving network safety.. openvswitch3 update, openSUSE security, network exploit fix, memory access vulnerability. . LinuxSecurity.com Team

Calendar%202 Apr 17, 2026 OpenSUSE
100

SUSE: 2022:1589-1 Important: PackageKit Security Vulnerability Resolution

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for mutt ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1478-1 Rating: moderate References: #1198518 Cross-References: CVE-2022-1328 CVSS scores: CVE-2022-1328 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2022-1328 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for mutt fixes the following issues: - CVE-2022-1328: Fixed an invalid memory access when reading untrusted uuencoded data. This could result in including private memory in replies (bsc#1198518). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-1478=1 Package List: - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): mutt-1.10.1-55.27.1 mutt-debuginfo-1.10.1-55.27.1 mutt-debugsource-1.10.1-55.27.1 References: https://www.suse.com/security/cve/CVE-2022-1328.html https://bugzilla.suse.com/1198518 . SUSE Security Update for pinentry resolves a vulnerability related to improper input validation. Advisory ID: SUSE-SU-2022:1580-1, high severity.. SUSE Linux Update, Mutt Software Fix, Memory Access Issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 29, 2022 Important SuSE
89

Fedora 30: 2019-8fb8240d14 Critical: Chromium Buffer Overflow Issues

Update to Chromium 75.0.3770.100. The usual pile of bugs and CVE fixes. vaapi support disabled, just too broken. :( Fixes CVE-2019-5805 CVE-2019-5806 CVE-2019-5807 CVE-2019-5808 CVE-2019-5809 CVE-2019-5810 CVE-2019-5811 CVE-2019-5813 CVE-2019-5814 CVE-2019-5815 CVE-2019-5818 CVE-2019-5819 CVE-2019-5820 CVE-2019-5821 CVE-2019-5822 CVE-2019-5824 CVE-2019-5825. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-8fb8240d14 2019-07-01 01:08:52.795587 --------------------------------------------------------------------------------Name : chromium Product : Fedora 30 Version : 75.0.3770.100 Release : 2.fc30 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser Description : Chromium is an open-source web browser, powered by WebKit (Blink). --------------------------------------------------------------------------------Update Information: Update to Chromium 75.0.3770.100. The usual pile of bugs and CVE fixes. vaapi support disabled, just too broken. :( Fixes CVE-2019-5805 CVE-2019-5806 CVE-2019-5807 CVE-2019-5808 CVE-2019-5809 CVE-2019-5810 CVE-2019-5811 CVE-2019-5813 CVE-2019-5814 CVE-2019-5815 CVE-2019-5818 CVE-2019-5819 CVE-2019-5820 CVE-2019-5821 CVE-2019-5822 CVE-2019-5824 CVE-2019-5825 CVE-2019-5826 CVE-2019-5827 CVE-2019-5828 CVE-2019-5829 CVE-2019-5830 CVE-2019-5831 CVE-2019-5832 CVE-2019-5833 CVE-2019-5834 CVE-2019-5835 CVE-2019-5836 CVE-2019-5837 CVE-2019-5838 CVE-2019-5839 CVE-2019-5840 CVE-2019-5842 --------------------------------------------------------------------------------ChangeLog: * Tue Jun 25 2019 Tom Callaway - 75.0.3770.100-2 - fix v8 compile with gcc * Thu Jun 20 2019 Tom Callaway - 75.0.3770.100-1 - update to 75.0.3770.100 * Fri Jun 14 2019 Tom Callaway - 75.0.3770.90-1 - update to 75.0.3770.90 * Wed Jun 5 2019 Tom Callaway - 75.0.3770.80-1 - update to 75.0.3770.80 - disable vaapi (via conditional), too broken * Fri May31 2019 Tom Callaway - 74.0.3729.169-1 - update to 74.0.3729.169 * Thu Apr 11 2019 Tom Callaway - 73.0.3683.103-1 - update to 73.0.3683.103 - add CLONE_VFORK logic to seccomp filter for linux to handle glibc 2.29 change --------------------------------------------------------------------------------References: [ 1 ] Bug #1720544 - CVE-2019-5842 chromium-browser: Use-after-free in Blink https://bugzilla.redhat.com/show_bug.cgi?id=1720544 [ 2 ] Bug #1718269 - CVE-2019-5840 chromium-browser: Popup blocker bypass https://bugzilla.redhat.com/show_bug.cgi?id=1718269 [ 3 ] Bug #1718268 - CVE-2019-5839 chromium-browser: Incorrect handling of certain code points in Blink https://bugzilla.redhat.com/show_bug.cgi?id=1718268 [ 4 ] Bug #1718267 - CVE-2019-5838 chromium-browser: Overly permissive tab access in Extensions https://bugzilla.redhat.com/show_bug.cgi?id=1718267 [ 5 ] Bug #1718266 - CVE-2019-5837 chromium-browser: Cross-origin resources size disclosure in Appcache https://bugzilla.redhat.com/show_bug.cgi?id=1718266 [ 6 ] Bug #1718264 - CVE-2019-5836 chromium-browser: Heap buffer overflow in Angle https://bugzilla.redhat.com/show_bug.cgi?id=1718264 [ 7 ] Bug #1718263 - CVE-2019-5835 chromium-browser: Out of bounds read in Swiftshader https://bugzilla.redhat.com/show_bug.cgi?id=1718263 [ 8 ] Bug #1718262 - CVE-2019-5834 chromium-browser: URL spoof in Omnibox on iOS https://bugzilla.redhat.com/show_bug.cgi?id=1718262 [ 9 ] Bug #1718261 - CVE-2019-5833 chromium-browser: Inconsistent security UI placement https://bugzilla.redhat.com/show_bug.cgi?id=1718261 [ 10 ] Bug #1718260 - CVE-2019-5832 chromium-browser: Incorrect CORS handling in XHR https://bugzilla.redhat.com/show_bug.cgi?id=1718260 [ 11 ] Bug #1718259 - CVE-2019-5831 chromium-browser: Incorrect map processing in V8 https://bugzilla.redhat.com/show_bug.cgi?id=1718259 [ 12 ] Bug #1718258 - CVE-2019-5830 chromium-browser:Incorrectly credentialed requests in CORS https://bugzilla.redhat.com/show_bug.cgi?id=1718258 [ 13 ] Bug #1718257 - CVE-2019-5829 chromium-browser: Use after free in Download Manager https://bugzilla.redhat.com/show_bug.cgi?id=1718257 [ 14 ] Bug #1718256 - CVE-2019-5828 chromium-browser: Use after free in ServiceWorker https://bugzilla.redhat.com/show_bug.cgi?id=1718256 [ 15 ] Bug #1706805 - CVE-2019-5827 chromium-browser: out-of-bounds access in SQLite https://bugzilla.redhat.com/show_bug.cgi?id=1706805 [ 16 ] Bug #1706812 - CVE-2019-5824 chromium-browser: parameter passing error in media player leading to unauthorized access https://bugzilla.redhat.com/show_bug.cgi?id=1706812 [ 17 ] Bug #1707248 - CVE-2019-5826 chromium-browser: Use-after-free in IndexedDB https://bugzilla.redhat.com/show_bug.cgi?id=1707248 [ 18 ] Bug #1707247 - CVE-2019-5825 chromium-browser: Out-of-bounds write in V8 https://bugzilla.redhat.com/show_bug.cgi?id=1707247 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-8fb8240d14' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives:https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Resolves various problems in Chromium following the Fedora 30 update, addressing severe crashes and vulnerabilities tied to buffer handling.. Chromium Update, Fedora Security, Open Source Browser. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 30, 2019 Critical Fedora
87

Debian: DSA-2162-2 Critical Alert: OpenSSL Memory Crash Vulnerability

Neel Mehta discovered that an incorrectly formatted ClientHello handshake message could cause OpenSSL to parse past the end of the message. This allows an attacker to crash an application using OpenSSL by triggering an invalid memory access. Additionally, some applications may be vulnerable . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2162-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Nico Golde February 14, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openssl Vulnerability : invalid memory access Problem type : remote Debian-specific: no CVE ID : CVE-2011-0014 Neel Mehta discovered that an incorrectly formatted ClientHello handshake message could cause OpenSSL to parse past the end of the message. This allows an attacker to crash an application using OpenSSL by triggering an invalid memory access. Additionally, some applications may be vulnerable to expose contents of a parsed OCSP nonce extension. Packages in the oldstable distribution (lenny) are not affected by this problem. For the stable distribution (squeeze), this problem has been fixed in version 0.9.8o-4squeeze1. For the testing distribution (wheezy), this problem has been fixed in version 0.9.8o-5. For the unstable distribution (sid), this problem has been fixed in version 0.9.8o-5. We recommend that you upgrade your invalid memory access packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest OpenSSL refresh targeting memory handling flaws uncovers possible remote exploitation threats in Debian platforms.. Memory Access Exploit, Debian Update, OpenSSLSecurity Patch, Remote Attack Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 14, 2011 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200