Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 494
Alerts This Week
Warning Icon 1 494

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
89

Fedora 44 perl-Crypt-DSA Important Key Flaw CVE-2026-14570

This update, to the current upstream release, addresses a cryptographic flaw (modulo bias) in key generation that could lead to private key compromise (CVE-2026-14570) .. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fcfc08d46c 2026-07-12 01:10:38.798612+00:00 -------------------------------------------------------------------------------- Name : perl-Crypt-DSA Product : Fedora 44 Version : 1.22 Release : 1.fc44 URL : https://metacpan.org/release/Crypt-DSA Summary : Perl module for DSA signatures and key generation Description : Crypt::DSA is an implementation of the DSA (Digital Signature Algorithm) signature verification system. This package provides DSA signing, signature verification, and key generation. DSA (Digital Signature Algorithm) signatures are no longer considered to be adequate for security. This module should only be used for verifying old signatures and should not be used for new signatures. That being said, some technologies still require DSA signatures even now. Consider using other solutions or explicitly not using DSA signatures. Crypt-DSA-GMP is a possible replacement. -------------------------------------------------------------------------------- Update Information: This update, to the current upstream release, addresses a cryptographic flaw (modulo bias) in key generation that could lead to private key compromise (CVE-2026-14570) . -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 3 2026 Paul Howarth - 1.22-1 - Update to 1.22 - Hardening: Use a fresh, independent CSPRNG witness every round - Security fix: Modulo bias in key generation (CVE-2026-14570); an attack with hundreds of signatures could lead to full private-key compromise; keys should be considered compromised and new keys should be generated * Fri Jun 19 2026 Yaakov Selkowitz - 1.21-2 - Rebuilt for OpenSSL4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2497529 - CVE-2026-14570 perl-Crypt-DSA: Crypt::DSA: Private key recovery due to biased random number generation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2497529 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fcfc08d46c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . This Fedora advisory addresses a critical flaw in perl-Crypt-DSA affecting key generation, leading to potential private key compromise.. Fedora perl-Crypt-DSA security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 11, 2026 Important Fedora
89

Fedora 43 perl-Crypt-DSA Critical Key Generation Flaw CVE-2026-14570

This update, to the current upstream release, addresses a cryptographic flaw (modulo bias) in key generation that could lead to private key compromise (CVE-2026-14570) .. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b77b9c5f04 2026-07-12 00:58:35.903674+00:00 -------------------------------------------------------------------------------- Name : perl-Crypt-DSA Product : Fedora 43 Version : 1.22 Release : 1.fc43 URL : https://metacpan.org/release/Crypt-DSA Summary : Perl module for DSA signatures and key generation Description : Crypt::DSA is an implementation of the DSA (Digital Signature Algorithm) signature verification system. This package provides DSA signing, signature verification, and key generation. DSA (Digital Signature Algorithm) signatures are no longer considered to be adequate for security. This module should only be used for verifying old signatures and should not be used for new signatures. That being said, some technologies still require DSA signatures even now. Consider using other solutions or explicitly not using DSA signatures. Crypt-DSA-GMP is a possible replacement. -------------------------------------------------------------------------------- Update Information: This update, to the current upstream release, addresses a cryptographic flaw (modulo bias) in key generation that could lead to private key compromise (CVE-2026-14570) . -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 3 2026 Paul Howarth - 1.22-1 - Update to 1.22 - Hardening: Use a fresh, independent CSPRNG witness every round - Security fix: Modulo bias in key generation (CVE-2026-14570); an attack with hundreds of signatures could lead to full private-key compromise; keys should be considered compromised and new keys should be generated * Fri Jun 19 2026 Yaakov Selkowitz - 1.21-2 - Rebuilt for OpenSSL4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2497529 - CVE-2026-14570 perl-Crypt-DSA: Crypt::DSA: Private key recovery due to biased random number generation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2497529 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b77b9c5f04' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . A critical flaw in the Perl Crypt-DSA module allows for private key compromise. Immediate updates are strongly advised.. Fedora 43 security flaw, Crypt-DSA update, critical flaw in key generation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 11, 2026 Critical Fedora
89

Fedora 38: 2023-3e84bba241 Moderate: Tang Race Condition Fix

Fixes CVE-2023-1672. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-3e84bba241 2023-06-23 01:00:55.101941 --------------------------------------------------------------------------------Name : tang Product : Fedora 38 Version : 14 Release : 1.fc38 URL : https://github.com/latchset/tang Summary : Network Presence Binding Daemon Description : Tang is a small daemon for binding data to the presence of a third party. --------------------------------------------------------------------------------Update Information: Fixes CVE-2023-1672 --------------------------------------------------------------------------------ChangeLog: * Wed Jun 14 2023 Sergio Arroutbi - 14-1 - New upstream release - v14 Resolves: rhbz#2180990 --------------------------------------------------------------------------------References: [ 1 ] Bug #2180999 - CVE-2023-1672 tang: Race condition exists in the key generation and rotation functionality https://bugzilla.redhat.com/show_bug.cgi?id=2180999 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-3e84bba241' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines:https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 38 tango release rectifies CVE-2023-1680 by resolving an encryption algorithm vulnerability successfully.. tang update,Fedora 38,key generation flaw,security patch. . LinuxSecurity.com Team

Calendar%202 Jun 23, 2023 Fedora
91

Gentoo: GLSA-202007-62 Normal: Weak Key Generation in PyCrypto

A flaw in PyCrypto allow remote attackers to obtain sensitive information.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202007-62 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: PyCrypto: Weak key generation Date: July 31, 2020 Bugs: #703682 ID: 202007-62 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A flaw in PyCrypto allow remote attackers to obtain sensitive information. Background ========= PyCrypto is the Python Cryptography Toolkit. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-python/pycrypto

Calendar%202 Jul 31, 2020 Gentoo
202

openSUSE: 2020:0955-1 Moderate: mozilla-nss Key Generation Risk

An update that solves one vulnerability and has one errata is now available.. openSUSE Security Update: Security update for mozilla-nss ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0955-1 Rating: moderate References: #1168669 #1173032 Cross-References: CVE-2020-12402 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for mozilla-nss fixes the following issues: mozilla-nss was updated to version 3.53.1 - CVE-2020-12402: Fixed a potential side channel attack during RSA key generation (bsc#1173032) - Fixed various FIPS issues in libfreebl3 which were causing segfaults in the test suite of chrony (bsc#1168669). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2020-955=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): libfreebl3-3.53.1-lp152.2.4.1 libfreebl3-debuginfo-3.53.1-lp152.2.4.1 libfreebl3-hmac-3.53.1-lp152.2.4.1 libsoftokn3-3.53.1-lp152.2.4.1 libsoftokn3-debuginfo-3.53.1-lp152.2.4.1 libsoftokn3-hmac-3.53.1-lp152.2.4.1 mozilla-nss-3.53.1-lp152.2.4.1 mozilla-nss-certs-3.53.1-lp152.2.4.1 mozilla-nss-certs-debuginfo-3.53.1-lp152.2.4.1 mozilla-nss-debuginfo-3.53.1-lp152.2.4.1 mozilla-nss-debugsource-3.53.1-lp152.2.4.1 mozilla-nss-devel-3.53.1-lp152.2.4.1 mozilla-nss-sysinit-3.53.1-lp152.2.4.1 mozilla-nss-sysinit-debuginfo-3.53.1-lp152.2.4.1 mozilla-nss-tools-3.53.1-lp152.2.4.1 mozilla-nss-tools-debuginfo-3.53.1-lp152.2.4.1 - openSUSE Leap 15.2 (x86_64): libfreebl3-32bit-3.53.1-lp152.2.4.1 libfreebl3-32bit-debuginfo-3.53.1-lp152.2.4.1 libfreebl3-hmac-32bit-3.53.1-lp152.2.4.1 libsoftokn3-32bit-3.53.1-lp152.2.4.1 libsoftokn3-32bit-debuginfo-3.53.1-lp152.2.4.1 libsoftokn3-hmac-32bit-3.53.1-lp152.2.4.1 mozilla-nss-32bit-3.53.1-lp152.2.4.1 mozilla-nss-32bit-debuginfo-3.53.1-lp152.2.4.1 mozilla-nss-certs-32bit-3.53.1-lp152.2.4.1 mozilla-nss-certs-32bit-debuginfo-3.53.1-lp152.2.4.1 mozilla-nss-sysinit-32bit-3.53.1-lp152.2.4.1 mozilla-nss-sysinit-32bit-debuginfo-3.53.1-lp152.2.4.1 References: https://www.suse.com/security/cve/CVE-2020-12402.html https://bugzilla.suse.com/1168669 https://bugzilla.suse.com/1173032 -- . The recent update for mozilla-nss fixes a critical vulnerability in RSA key generation that could be exploited through side channel methods and enhances FIPS compliance. openSUSE Security Update, Mozilla NSS Fix, RSA Key Generation Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 13, 2020 Important OpenSUSE
202

openSUSE: 2018:2597-1 Moderate: libressl Timing Attack Fix

An update that solves two vulnerabilities and has one errata is now available.. openSUSE Security Update: Security update for libressl ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:2597-1 Rating: moderate References: #1065363 #1086778 #1097779 Cross-References: CVE-2018-12434 CVE-2018-8970 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: This update for libressl to version 2.8.0 fixes the following issues: Security issues fixed: - CVE-2018-12434: Avoid a timing side-channel leak when generating DSA and ECDSA signatures. (boo#1097779) - Reject excessively large primes in DH key generation. - CVE-2018-8970: Fixed a bug in int_x509_param_set_hosts, calling strlen() if name length provided is 0 to match the OpenSSL behaviour. (boo#1086778) - Fixed an out-of-bounds read and crash in DES-fcrypt (boo#1065363) You can find a detailed list of changes [here]( .txt). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-953=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): libcrypto43-2.8.0-11.1 libcrypto43-debuginfo-2.8.0-11.1 libressl-2.8.0-11.1 libressl-debuginfo-2.8.0-11.1 libressl-debugsource-2.8.0-11.1 libressl-devel-2.8.0-11.1 libssl45-2.8.0-11.1 libssl45-debuginfo-2.8.0-11.1 libtls17-2.8.0-11.1 libtls17-debuginfo-2.8.0-11.1 - openSUSE Leap 42.3 (x86_64): libcrypto43-32bit-2.8.0-11.1 libcrypto43-debuginfo-32bit-2.8.0-11.1 libressl-devel-32bit-2.8.0-11.1 libssl45-32bit-2.8.0-11.1 libssl45-debuginfo-32bit-2.8.0-11.1 libtls17-32bit-2.8.0-11.1 libtls17-debuginfo-32bit-2.8.0-11.1 - openSUSE Leap 42.3 (noarch): libressl-devel-doc-2.8.0-11.1 References: https://www.suse.com/security/cve/CVE-2018-12434.html https://www.suse.com/security/cve/CVE-2018-8970.html https://bugzilla.suse.com/1065363 https://bugzilla.suse.com/1086778 https://bugzilla.suse.com/1097779 -- . This modification tackles several concerns in libressl for openSUSE Leap 15.1, enhancing safety and dependability.. libressl Update, openSUSE Security Update, libressl Fixes. . LinuxSecurity.com Team

Calendar%202 Sep 04, 2018 OpenSUSE
172

Ubuntu: 3138-1 Critical: Python-Cryptography Key Generation Flaw

python-cryptography could generate incorrect keys.. =========================================================================Ubuntu Security Notice USN-3138-1 November 28, 2016 python-cryptography vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.10 - Ubuntu 16.04 LTS Summary: python-cryptography could generate incorrect keys. Software Description: - python-cryptography: Cryptography Python library Details: Markus Döring discovered that python-cryptography incorrectly handled certain HKDF lengths. This could result in python-cryptography returning an empty string instead of the expected derived key. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.10: python-cryptography 1.5-2ubuntu0.1 python3-cryptography 1.5-2ubuntu0.1 Ubuntu 16.04 LTS: python-cryptography 1.2.3-1ubuntu0.1 python3-cryptography 1.2.3-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3138-1 CVE-2016-9243 Package Information: https://launchpad.net/ubuntu/+source/python-cryptography/1.5-2ubuntu0.1 https://launchpad.net/ubuntu/+source/python-cryptography/1.2.3-1ubuntu0.1 . Critical alert regarding python-cryptography flaw impacting Ubuntu platforms—verify the integrity and precision of your key generation.. Python Cryptography, Cryptography Fix, Ubuntu Security Notice. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 28, 2016 Critical Ubuntu
87

Debian: DSA-2502-1 Critical: Python-Crypto Remote Programming Error

It was discovered that that the ElGamal code in PythonCrypto, a collection of cryptographic algorithms and protocols for Python used insecure insufficient prime numbers in key generation, which lead to a weakened signature or public key space, allowing easier brute force . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2502-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff June 24, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : python-crypto Vulnerability : programming error Problem type : remote Debian-specific: no CVE ID : CVE-2012-2417 It was discovered that that the ElGamal code in PythonCrypto, a collection of cryptographic algorithms and protocols for Python used insecure insufficient prime numbers in key generation, which lead to a weakened signature or public key space, allowing easier brute force attacks on such keys. For the stable distribution (squeeze), this problem has been fixed in version 2.1.0-2+squeeze1. For the unstable distribution (sid), this problem has been fixed in version 2.6-1. We recommend that you upgrade your python-crypto packages. After installing this update, previously generated keys need to be regenerated. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance ElGamal key creation in python-crypto to resolve vulnerabilities against brute-force exploits and bolster overall security.. PythonCrypto Security Update, ElGamal Key Weakness, Debian Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 24, 2012 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200