Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
203

Mageia 9: Serious Remote Code Execution Flaw in Konsole MGASA-2025-0308

MGASA-2025-0308 - Updated konsole packages fix security vulnerability. MGASA-2025-0308 - Updated konsole packages fix security vulnerability Publication date: 21 Nov 2025 URL: https://advisories.mageia.org/MGASA-2025-0308.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-49091 Description: KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed regardless of whether the ssh, telnet, or rlogin binary is available. In this mode, there is a code path where if that binary is not available, Konsole falls back to using /bin/bash for the given arguments (i.e., the URL) provided. This allows an attacker to execute arbitrary code. (CVE-2025-49091) References: - https://bugs.mageia.org/show_bug.cgi?id=34364 - https://www.openwall.com/lists/oss-security/2025/06/10/5 - - https://www.cve.org/CVERecord?id=CVE-2025-49091 SRPMS: - 9/core/konsole-23.04.3-1.2.mga9 . Konsole updates address critical remote code execution vulnerability affecting Mageia users. Urgent patching recommended.. Konsole Update, Mageia Security Advisory, Remote Code Execution, Vulnerability Management. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 21, 2025 Important Mageia
217

Oracle Linux 7 ELSA-2025-12346 Konsole Important Command Issue

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-12346 http://linux.oracle.com/errata/ELSA-2025-12346.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: konsole-4.10.5-5.0.1.el7.x86_64.rpm konsole-part-4.10.5-5.0.1.el7.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/konsole-4.10.5-5.0.1.el7.src.rpm Related CVEs: CVE-2025-49091 Description of changes: [4.10.5-5.0.1] - Clear the arguments if the command is not found [Orabug: 38260855][CVE-2025-49091] _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Fedora Server 35 upgrades for terminal resolve critical command failures and boost security measures. Keep informed with ELSA-2025-98765.. Oracle Linux, ELSA-2025-12346, konsole, security updates, command injection. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 14, 2025 Important Oracle
202

openSUSE: Konsole Important Remote Code Exec Vulnerability 2025:0206-1

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for konsole ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0206-1 Rating: important References: #1244569 Cross-References: CVE-2025-49091 Affected Products: openSUSE Backports SLE-15-SP6 openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for konsole fixes the following issues: - CVE-2025-49091: Fixed potential remote code execution in a certain scenario with url open (boo#1244569) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2025-206=1 - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-206=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 ppc64le s390x x86_64): konsole-23.08.5-bp157.2.3.1 konsole-debuginfo-23.08.5-bp157.2.3.1 konsole-debugsource-23.08.5-bp157.2.3.1 konsole-part-23.08.5-bp157.2.3.1 konsole-part-debuginfo-23.08.5-bp157.2.3.1 - openSUSE Backports SLE-15-SP7 (noarch): konsole-part-lang-23.08.5-bp157.2.3.1 konsole-zsh-completion-23.08.5-bp157.2.3.1 - openSUSE Backports SLE-15-SP6 (aarch64 ppc64le s390x x86_64): konsole-23.08.5-bp156.2.3.1 konsole-part-23.08.5-bp156.2.3.1 - openSUSE Backports SLE-15-SP6 (noarch): konsole-part-lang-23.08.5-bp156.2.3.1 konsole-zsh-completion-23.08.5-bp156.2.3.1 References: https://www.suse.com/security/cve/CVE-2025-49091.html https://bugzilla.suse.com/1244569 . Important security patch released foropenSUSE terminal addressing potential remote code execution vulnerabilities. Update using zypper or YaST.. openSUSE update, konsole security, remote execution fix, important patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jul 26, 2025 Important OpenSUSE
197

Debian 11: DLA-4220-1 critical: konsole remote code execution

It was discovered that there was a potential remote code execution vulnerability in konsole, the X terminal emulator of the KDE desktop environmne.t . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4220-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Chris Lamb June 17, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : konsole Version : 4:20.12.3-1+deb11u1 CVE ID : CVE-2025-49091 Debian Bug : 1107672 It was discovered that there was a potential remote code execution vulnerability in konsole, the X terminal emulator of the KDE desktop environmne.t This vulnerability could have been exploited when loading URLs from scheme handlers such as a "ssh://" or "telnet://". For Debian 11 bullseye, this problem has been fixed in version 4:20.12.3-1+deb11u1. We recommend that you upgrade your konsole packages. For the detailed security status of konsole please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/konsole Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Important patch for terminal emulator to address remote execution flaw in Debian LTS. Update is highly advised for enhanced protection.. Debian konsole security update, remote code execution, konsole vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 17, 2025 Critical Debian LTS
198

Ubuntu: 303103-1 medium: gnome-terminal privilege escalation

The package konsole before version 25.04.2-1 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-202506-5 ========================================= Severity: High Date : 2025-06-11 CVE-ID : CVE-2025-49091 Package : konsole Type : arbitrary code execution Remote : Yes Link : https://security.archlinux.org/AVG-2897 Summary ======= The package konsole before version 25.04.2-1 is vulnerable to arbitrary code execution. Resolution ========== Upgrade to 25.04.2-1. # pacman -Syu "konsole> =25.04.2-1" The problem has been fixed upstream in version 25.04.2. Workaround ========== None. Description =========== Konsole supports loading URLs from the scheme handlers such as telnet://URL. This can be executed regardless of whether the telnet binary is available. In this mode konsole had a path where if telnet was not available it would fall back to using bash for the given arguments provided; which is the URL provided. This allows an attacker to execute arbitrary code. Browsers typically provide a prompt when a user opens an external scheme handler which would look suspicious, requiring user interaction to be exploitable. Impact ====== A remote attacker can trick a user into opening a specially crafted URL that exploits Konsole’s scheme handler fallback mechanism, leading to arbitrary code execution. References ========== https://kde.org/info/security/advisory-20250609-1.txt https://www.proofnet.de/publikationen/konsole_rce.html https://nvd.nist.gov/vuln/detail/CVE-2025-49091 https://www.openwall.com/lists/oss-security/2025/06/10/5 https://security.archlinux.org/CVE-2025-49091 . Arch Linux Security Notice ASA-202506-5: Critical vulnerability identified in konsole enabling arbitrary code execution.. archlinux security advisory, konsole security issue, code execution risk. . LinuxSecurity.com Team

Calendar 2 Jun 13, 2025 ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here