Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 504
Alerts This Week
Warning Icon 1 504

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":2,"type":"x","order":2,"pct":66.67,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
87

Ubuntu: nginx Vulnerability in HTTP/3 Handling DSA-6006-1

This update for Jetty, a Java servlet engine and web server, addresses a protocol-level vulnerability in HTTP/2 support also referred to as "MadeYouReset". . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6005-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff September 19, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : jetty9 CVE ID : CVE-2025-5115 This update for Jetty, a Java servlet engine and web server, addresses a protocol-level vulnerability in HTTP/2 support also referred to as "MadeYouReset". For the oldstable distribution (bookworm), this problem has been fixed in version 9.4.57-1.1~deb12u1. For the stable distribution (trixie), this problem has been fixed in version 9.4.57-1.1~deb13u1. We recommend that you upgrade your jetty9 packages. For the detailed security status of jetty9 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/jetty9 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Tackling a significant security flaw in Jetty's handling of HTTP/2 with essential patches.. Jetty9 Update, Protocol Vulnerability, Debian Security, HTTP2 Support, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 19, 2025 Important Debian
197

Debian 11: DLA-4106-2 Low Security Update for Jetty9 Regression

The security update DLA-4106-1 for jetty9 incorrectly required an unavailable dependency on sysvinit-utils > = 3.05 when installing the jetty9 binary package. This issue has been addressed by reverting back to requiring only the lsb-base binary package. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4106-2 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Markus Koschany April 05, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : jetty9 Version : 9.4.57-0+deb11u2 The security update DLA-4106-1 for jetty9 incorrectly required an unavailable dependency on sysvinit-utils > = 3.05 when installing the jetty9 binary package. This issue has been addressed by reverting back to requiring only the lsb-base binary package. For Debian 11 bullseye, this problem has been fixed in version 9.4.57-0+deb11u2. We recommend that you upgrade your jetty9 packages. For the detailed security status of jetty9 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/jetty9 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Resolved compatibility challenge in the latest jetty9 package for Debian. Update suggested for optimal performance.. jetty9 update, debian security, dependency issue, regression fix. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Apr 04, 2025 Low Debian LTS
87

Debian 11: DSA-5894-1: jetty9 critical Denial of Service advisory

Jetty 9 is a Java based web server and servlet engine. Several security vulnerabilities have been discovered which may allow remote attackers to cause a denial of service by repeatedly sending crafted requests which can trigger OutofMemory errors and exhaust the server's memory. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5894-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Markus Koschany April 05, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : jetty9 CVE ID : CVE-2024-6762 CVE-2024-8184 CVE-2024-9823 Debian Bug : 1085697 Jetty 9 is a Java based web server and servlet engine. Several security vulnerabilities have been discovered which may allow remote attackers to cause a denial of service by repeatedly sending crafted requests which can trigger OutofMemory errors and exhaust the server's memory. CVE-2024-6762: In addition PushSessionCacheFilter and PushCacheFilter have been deprecated. These classes should no longer be used in a production environment. For the stable distribution (bookworm), these problems have been fixed in version 9.4.57-0+deb12u1. We recommend that you upgrade your jetty9 packages. For the detailed security status of jetty9 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/jetty9 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Jetty 9 encountered several severe vulnerabilities that permitted remote denial-of-service (DoS) assaults through specially designed requests, necessitating an immediate resolution.. jetty9, denial of service, debian security, remoteattack, OutOfMemory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 04, 2025 Critical Debian
87

Debian 11/12: DSA-5664-1 critical advisory for Jetty 9 DoS threat

Jetty 9 is a Java based web server and servlet engine. It was discovered that remote attackers may leave many HTTP/2 connections in ESTABLISHED state (not closed), TCP congested and idle. Eventually the server will stop accepting new connections from valid clients which can cause a denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5664-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Markus Koschany April 17, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : jetty9 CVE ID : CVE-2024-22201 Jetty 9 is a Java based web server and servlet engine. It was discovered that remote attackers may leave many HTTP/2 connections in ESTABLISHED state (not closed), TCP congested and idle. Eventually the server will stop accepting new connections from valid clients which can cause a denial of service. For the oldstable distribution (bullseye), this problem has been fixed in version 9.4.50-4+deb11u2. For the stable distribution (bookworm), this problem has been fixed in version 9.4.50-4+deb12u3. We recommend that you upgrade your jetty9 packages. For the detailed security status of jetty9 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/jetty9 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Jetty 9 security notice uncovers a denial of service flaw and includes patches for Debian's stable and oldstable versions.. Jetty Server, Denial of Service Threats, Java Web Server Updates, Debian Security Advisories. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 17, 2024 Critical Debian
197

Debian 10 Buster: DLA-3647-1 Moderate Issue in Trapperkeeper Jetty9

The recent update of jetty9, released as DLA 3641-1, caused a regression in PuppetDB, a major component of Puppet that helps you manage and automate the configuration of servers. More specifically another package, trapperkeeper- webserver-jetty9-clojure, still used the deprecated SslContextFactory class . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3647-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany November 07, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : trapperkeeper-webserver-jetty9-clojure Version : 1.7.0-2+deb10u2 Debian Bug : 1055348 The recent update of jetty9, released as DLA 3641-1, caused a regression in PuppetDB, a major component of Puppet that helps you manage and automate the configuration of servers. More specifically another package, trapperkeeper- webserver-jetty9-clojure, still used the deprecated SslContextFactory class which made PuppetDB fail to start. This update makes use of the preferred new SslContextFactory#Server class now. For Debian 10 buster, this problem has been fixed in version 1.7.0-2+deb10u2. We recommend that you upgrade your trapperkeeper-webserver-jetty9-clojure packages. For the detailed security status of trapperkeeper-webserver-jetty9-clojure please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/trapperkeeper-webserver-jetty9-clojure Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-5012-1 tackles a flaw in Apache Tomcat caused by the recent version upgrade. Ensure to upgrade the tomcat9 packages.. trapperkeeper-webserver, jetty9 update, puppetdb configuration, security issues, debiansecurity. . LinuxSecurity.com Team

Calendar%202 Nov 06, 2023 Debian LTS
197

Debian 10 LTS DLA-3641-1 Critical: Jetty9 Remote Exploits

Two remotely exploitable security vulnerabilities were discovered in Jetty 9, a Java based web server and servlet engine. The HTTP/2 protocol implementation did not sufficiently verify if HPACK header . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3641-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany October 30, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : jetty9 Version : 9.4.50-4+deb10u1 CVE ID : CVE-2020-27218 CVE-2023-36478 CVE-2023-44487 Debian Bug : 976211 Two remotely exploitable security vulnerabilities were discovered in Jetty 9, a Java based web server and servlet engine. The HTTP/2 protocol implementation did not sufficiently verify if HPACK header values exceed their size limit. Furthermore the HTTP/2 protocol allowed a denial of service (server resource consumption) because request cancellation can reset many streams quickly. This problem is also known as Rapid Reset Attack. In addition this version also addresses CVE-2020-27218. If GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request. For Debian 10 buster, these problems have been fixed in version 9.4.50-4+deb10u1. We recommend that you upgrade your jetty9 packages. For the detailed security status of jetty9 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/jetty9 Further information about Debian LTS security advisories, how to apply theseupdates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Promptly update jetty9 to address significant security vulnerabilities affecting HTTP/2, which could allow for remote exploitation.. jetty9 security update, remote exploit fix, Debian LTS vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 30, 2023 Critical Debian LTS
197

Debian 9: DLA-2688-1 Critical: Jetty9 Information Leak Risk

Steven Seeley discovered that in jetty, a Java servlet engine and webserver, requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory. An attacker may access sensitive information regarding the implementation of a web . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2688-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sylvain Beucler June 17, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : jetty9 Version : 9.2.30-0+deb9u2 CVE ID : CVE-2021-28169 Steven Seeley discovered that in jetty, a Java servlet engine and webserver, requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory. An attacker may access sensitive information regarding the implementation of a web application. For Debian 9 stretch, this problem has been fixed in version 9.2.30-0+deb9u2. We recommend that you upgrade your jetty9 packages. For the detailed security status of jetty9 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/jetty9 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A security notice DLA-2688-1 highlights vulnerabilities related to the safeguarding of sensitive data. Ensure you apply the update immediately!. jetty Security Update, Debian LTS Advisory, Web Application Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 17, 2021 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":2,"type":"x","order":2,"pct":66.67,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200