Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 17 articles for you...
217

Oracle Linux 7: ELSA-2025-21404 lasso Critical Type Confusion CVE-47151

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-21404 http://linux.oracle.com/errata/ELSA-2025-21404.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: lasso-2.5.1-8.0.1.el7_9.i686.rpm lasso-2.5.1-8.0.1.el7_9.x86_64.rpm lasso-devel-2.5.1-8.0.1.el7_9.i686.rpm lasso-devel-2.5.1-8.0.1.el7_9.x86_64.rpm lasso-python-2.5.1-8.0.1.el7_9.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/lasso-2.5.1-8.0.1.el7_9.src.rpm Related CVEs: CVE-2025-47151 Description of changes: [2.5.1-8.0.1] - Fixes CVE-2025-47151 lasso: Type confusion in Entr'ouvert Lasso [Orabug: 38658691] _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Critical Lasso security update for Oracle Linux 7 addresses CVE-2025-47151 to prevent potential exploits affecting security.. Oracle Linux 7, Lasso Update, Critical Security Fix, Remote Access Threats, CVE-2025-47151. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 12, 2025 Critical Oracle
100

SUSE: Lasso Critical Denial of Service & Code Exec Advisories 2025:21140-1

* bsc#1253092 * bsc#1253093 * bsc#1253095 Cross-References: . # Security update for lasso Announcement ID: SUSE-SU-2025:21140-1 Release Date: 2025-11-25T13:27:21Z Rating: critical References: * bsc#1253092 * bsc#1253093 * bsc#1253095 Cross-References: * CVE-2025-46404 * CVE-2025-46705 * CVE-2025-47151 CVSS scores: * CVE-2025-46404 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-46404 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-46404 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-46705 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-46705 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-46705 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47151 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-47151 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-47151 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for lasso fixes the following issues: * CVE-2025-46404: specially crafted SAML response can lead to a denial of service (bsc#1253092). * CVE-2025-46705: specially crafted SAML assertion response can lead to a denial of service (bsc#1253093). * CVE-2025-47151: type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality can lead to an arbitrary code execution (bsc#1253095). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patchSUSE-SLES-16.0-52=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-52=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * liblasso3-2.8.2-160000.3.1 * liblasso3-debuginfo-2.8.2-160000.3.1 * lasso-debuginfo-2.8.2-160000.3.1 * lasso-debugsource-2.8.2-160000.3.1 * liblasso-devel-2.8.2-160000.3.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * liblasso3-2.8.2-160000.3.1 * liblasso3-debuginfo-2.8.2-160000.3.1 * lasso-debuginfo-2.8.2-160000.3.1 * lasso-debugsource-2.8.2-160000.3.1 * liblasso-devel-2.8.2-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-46404.html * https://www.suse.com/security/cve/CVE-2025-46705.html * https://www.suse.com/security/cve/CVE-2025-47151.html * https://bugzilla.suse.com/show_bug.cgi?id=1253092 * https://bugzilla.suse.com/show_bug.cgi?id=1253093 * https://bugzilla.suse.com/show_bug.cgi?id=1253095 . Critical security update for lasso in SUSE addresses denial of service and code execution risks requiring immediate attention.. SUSE,Lasso,Critical Update,Security Fix,Denial of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 10, 2025 Critical SuSE
197

Debian 11 Lasso Important DoS Arbitrary Code Exec DLA-4397-1

Keane O'Kelley discovered several vulnerabilities in lasso, a library implementing Liberty Alliance and SAML protocols, which could result in denial of service or the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4397-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sylvain Beucler December 08, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : lasso Version : 2.6.1-3+deb11u1 CVE ID : CVE-2025-46404 CVE-2025-46705 CVE-2025-46784 CVE-2025-47151 Keane O'Kelley discovered several vulnerabilities in lasso, a library implementing Liberty Alliance and SAML protocols, which could result in denial of service or the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 2.6.1-3+deb11u1. We recommend that you upgrade your lasso packages. For the detailed security status of lasso please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/lasso Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Lasso security update for Debian LTS fixes multiple vulnerabilities that could lead to DoS or arbitrary code execution.. lasso security update, Debian LTS advisory, DoS vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 08, 2025 Important Debian LTS
217

Oracle Linux 9 ELSA-2025-21462 Lasso Critical Type Confusion

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-21462 http://linux.oracle.com/errata/ELSA-2025-21462.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: lasso-2.7.0-11.el9_7.3.i686.rpm lasso-2.7.0-11.el9_7.3.x86_64.rpm lasso-devel-2.7.0-11.el9_7.3.i686.rpm lasso-devel-2.7.0-11.el9_7.3.x86_64.rpm python3-lasso-2.7.0-11.el9_7.3.x86_64.rpm aarch64: lasso-2.7.0-11.el9_7.3.aarch64.rpm lasso-devel-2.7.0-11.el9_7.3.aarch64.rpm python3-lasso-2.7.0-11.el9_7.3.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/lasso-2.7.0-11.el9_7.3.src.rpm Related CVEs: CVE-2025-47151 Description of changes: [ - 2.7.0-11.3] - Fix CVE-2025-47151 lasso: Type confusion in Entr'ouvert Lasso Resolves: RHEL-126684 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 9 updates address a critical type confusion issue in Lasso. Implement in your environment immediately.. Oracle Linux,Lasso,Critical Update,Security Advisory,Linux Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 26, 2025 Critical Oracle
217

Oracle Linux 8: ELSA-2025-21628 Lasso Critical Type Confusion

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-21628 http://linux.oracle.com/errata/ELSA-2025-21628.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: lasso-2.6.0-14.el8_10.i686.rpm lasso-2.6.0-14.el8_10.x86_64.rpm lasso-devel-2.6.0-14.el8_10.i686.rpm lasso-devel-2.6.0-14.el8_10.x86_64.rpm python3-lasso-2.6.0-14.el8_10.x86_64.rpm aarch64: lasso-2.6.0-14.el8_10.aarch64.rpm lasso-devel-2.6.0-14.el8_10.aarch64.rpm python3-lasso-2.6.0-14.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/lasso-2.6.0-14.el8_10.src.rpm Related CVEs: CVE-2025-47151 Description of changes: [2.6.0-14] - Fixing CVE-2025-47151 Resolves: RHEL-126687 CVE-2025-47151 lasso: Type confusion in Entr'ouvert Lasso _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Critical ELSA-2025-21628 advisory for Oracle Linux addressing Type confusion in Lasso, see for available updates.. Critical Advisory, Oracle Linux, Lasso Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 20, 2025 Critical Oracle
172

Ubuntu 25.04 Lasso Critical Denial of Service Vulnerabilities USN-7872-1

Several security issues were fixed in Lasso.. ========================================================================== Ubuntu Security Notice USN-7872-1 November 18, 2025 lasso vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Lasso. Software Description: - lasso: Liberty Alliance and SAML protocol Library Details: It was discovered that Lasso incorrectly handled certain malformed SAML responses. A remote attacker could possibly use this issue to cause Lasso to crash, resulting in a denial of service. (CVE-2025-46404) It was discovered that Lasso incorrectly handled certain malformed SAML assertion responses. A remote attacker could possibly use this issue to cause Lasso to crash, resulting in a denial of service. (CVE-2025-46705) It was discovered that Lasso incorrectly handled certain malformed SAML responses. A remote attacker could possibly use this issue to cause Lasso to consume memory, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2025-46784) It was discovered that Lasso incorrectly handled certain malformed SAML responses. A remote attacker could use this issue to cause Lasso to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2025-47151) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 liblasso-perl 2.8.2-8ubuntu0.1 liblasso3t64 2.8.2-8ubuntu0.1 python3-lasso 2.8.2-8ubuntu0.1 Ubuntu 24.04 LTS liblasso-perl 2.8.2-2ubuntu0.1 liblasso3t64 2.8.2-2ubuntu0.1 python3-lasso 2.8.2-2ubuntu0.1 Ubuntu 22.04 LTS liblasso-perl 2.7.0-2ubuntu0.1 liblasso3 2.7.0-2ubuntu0.1 python3-lasso 2.7.0-2ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7872-1 CVE-2025-46404, CVE-2025-46705, CVE-2025-46784, CVE-2025-47151 Package Information: https://launchpad.net/ubuntu/+source/lasso/2.8.2-8ubuntu0.1 https://launchpad.net/ubuntu/+source/lasso/2.8.2-2ubuntu0.1 https://launchpad.net/ubuntu/+source/lasso/2.7.0-2ubuntu0.1 . Ensure your Ubuntu system is secure by addressing critical Lasso issues affecting multiple releases urgently.. Lasso Security, Ubuntu Update, Denial of Service, SAML Protocol, Security Notice. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 18, 2025 Critical Ubuntu
219

Rocky Linux 8 RLSA-2025-21628 Lasso High Security Patch

Critical: lasso security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:21628", "synopsis": "Critical: lasso security update", "severity": "SEVERITY_CRITICAL", "topic": "An update is available for lasso.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The lasso packages provide the Lasso library that implements the Liberty Alliance Single Sign-On standards, including the SAML and SAML2 specifications. It allows handling of the whole life-cycle of SAML-based federations and provides bindings for multiple languages.\n\nSecurity Fix(es):\n\n* lasso: Type confusion in Entr'ouvert Lasso (CVE-2025-47151)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2412739", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2412739", "description": ""}], "cves": [{"name": "CVE-2025-47151", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-47151", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "9.8", "cwe": "CWE-843"}], "references": [], "publishedAt": "2025-11-18T09:00:59.220200Z", "rpms": {"Rocky Linux 8": {"nvras": ["lasso-0:2.6.0-14.el8_10.aarch64.rpm", "lasso-0:2.6.0-14.el8_10.i686.rpm", "lasso-0:2.6.0-14.el8_10.src.rpm", "lasso-0:2.6.0-14.el8_10.x86_64.rpm", "lasso-debuginfo-0:2.6.0-14.el8_10.aarch64.rpm", "lasso-debuginfo-0:2.6.0-14.el8_10.i686.rpm", "lasso-debuginfo-0:2.6.0-14.el8_10.x86_64.rpm", "lasso-debugsource-0:2.6.0-14.el8_10.aarch64.rpm", "lasso-debugsource-0:2.6.0-14.el8_10.i686.rpm", "lasso-debugsource-0:2.6.0-14.el8_10.x86_64.rpm", "lasso-devel-0:2.6.0-14.el8_10.aarch64.rpm","lasso-devel-0:2.6.0-14.el8_10.i686.rpm", "lasso-devel-0:2.6.0-14.el8_10.x86_64.rpm", "python3-lasso-0:2.6.0-14.el8_10.aarch64.rpm", "python3-lasso-0:2.6.0-14.el8_10.x86_64.rpm", "python3-lasso-debuginfo-0:2.6.0-14.el8_10.aarch64.rpm", "python3-lasso-debuginfo-0:2.6.0-14.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux reveals critical lasso security update for 8, fixing significant type confusion issues. Immediate action recommended.. Rocky Linux 8, Lasso update, Type confusion, Security patch, CVSS score. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 18, 2025 Critical Rocky Linux
87

Debian: DSA-6058-1 lasso Critical Denial of Service CVE-2025-46404

Keane O'Kelley discovered several vulnerabilities in lasso, a library implementing Liberty Alliance and SAML protocols, which could result in denial of service or the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-6058-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso November 15, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : lasso CVE ID : CVE-2025-46404 CVE-2025-46705 CVE-2025-47151 Keane O'Kelley discovered several vulnerabilities in lasso, a library implementing Liberty Alliance and SAML protocols, which could result in denial of service or the execution of arbitrary code. For the oldstable distribution (bookworm), these problems have been fixed in version 2.8.1-1+deb12u1. For the stable distribution (trixie), these problems have been fixed in version 2.8.2-9+deb13u1. We recommend that you upgrade your lasso packages. For the detailed security status of lasso please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/lasso Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Multiple critical vulnerabilities in lasso could lead to a denial of service or arbitrary code execution. Upgrade recommended.. lasso security, Debian advisory, denial of service, security update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 15, 2025 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200