Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 19 articles for you...
217

Oracle Linux 10 krb5 Major Security Patch ELSA-2026-19145

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-19145 http://linux.oracle.com/errata/ELSA-2026-19145.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: krb5-devel-1.21.3-10.0.1.el10_2.x86_64.rpm krb5-libs-1.21.3-10.0.1.el10_2.x86_64.rpm krb5-pkinit-1.21.3-10.0.1.el10_2.x86_64.rpm krb5-server-1.21.3-10.0.1.el10_2.x86_64.rpm krb5-server-ldap-1.21.3-10.0.1.el10_2.x86_64.rpm krb5-workstation-1.21.3-10.0.1.el10_2.x86_64.rpm krb5-xrealmauthz-1.21.3-10.0.1.el10_2.x86_64.rpm libkadm5-1.21.3-10.0.1.el10_2.x86_64.rpm aarch64: krb5-devel-1.21.3-10.0.1.el10_2.aarch64.rpm krb5-libs-1.21.3-10.0.1.el10_2.aarch64.rpm krb5-pkinit-1.21.3-10.0.1.el10_2.aarch64.rpm krb5-server-1.21.3-10.0.1.el10_2.aarch64.rpm krb5-server-ldap-1.21.3-10.0.1.el10_2.aarch64.rpm krb5-workstation-1.21.3-10.0.1.el10_2.aarch64.rpm krb5-xrealmauthz-1.21.3-10.0.1.el10_2.aarch64.rpm libkadm5-1.21.3-10.0.1.el10_2.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/krb5-1.21.3-10.0.1.el10_2.src.rpm Related CVEs: CVE-2026-40355 CVE-2026-40356 Description of changes: [1.21.3-10.0.1] - Fixed race condition in krb5_set_password() [Orabug: 33609767] [1.21.3-10] - Fix NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356) Resolves: RHEL-171588 RHEL-171597 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Security advisory for Oracle Linux 10 addresses important updates for krb5 components with notable security fixes.. Oracle Linux, krb5 update, security patch, Linux security, important advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 17, 2026 Important Oracle
89

Fedora 43 bind-dyndb-ldap Important DoS Resource Leak Fix 2026-b626e83a45

Update to 9.18.49 (rhbz#2480121) Security Fixes: Limit resolver server list size. (CVE-2026-3592) Fix GSS-API resource leak. (CVE-2026-3039) Disable recursion, UPDATE, and NOTIFY for non-IN views. (CVE-2026-5946). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b626e83a45 2026-05-26 01:20:50.020972+00:00 -------------------------------------------------------------------------------- Name : bind-dyndb-ldap Product : Fedora 43 Version : 11.11 Release : 13.fc43 URL : https://releases.pagure.org/bind-dyndb-ldap Summary : LDAP back-end plug-in for BIND Description : This package provides an LDAP back-end plug-in for BIND. It features support for dynamic updates and internal caching, to lift the load off of your LDAP server. -------------------------------------------------------------------------------- Update Information: Update to 9.18.49 (rhbz#2480121) Security Fixes: Limit resolver server list size. (CVE-2026-3592) Fix GSS-API resource leak. (CVE-2026-3039) Disable recursion, UPDATE, and NOTIFY for non-IN views. (CVE-2026-5946) Avoid unbounded recursion loop. (CVE-2026-5950) Fix outgoing zone transfers' quota issue. Feature Changes: Fix CPU spikes and slow queries when cache approaches memory limit. Bug Fixes: Fix named crash when processing SIG records in dynamic updates. Fix rndc modzone behavior for a zone in named.conf. Fix zone verification of NSEC3 signed zones. Prevent a crash when using both dns64 and filter-aaaa. Fixed an assertion failure when processing catalog zones. Prevent malicious DNSSEC zones from exhausting validator CPU. Fix rndc-confgen aborting on HMAC-SHA-384/512 keys above 512 bits. Prevent crafted queries from degrading RRL performance. Fix a bug in allow-query/allow-transfer catalog zone custom properties. Fix a memory leak issue in catalog zones. Fix suppressed missing-glue check in named-checkzone. Reject record sets too large to serve inDNS. Source: https://downloads.isc.org/isc/bind9/9.18.49/doc/arm/html/notes.html#notes-for- bind-9-18-49 -------------------------------------------------------------------------------- ChangeLog: * Wed May 20 2026 Petr Men\u0161k - 11.11-13 - Rebuilt for BIND 9.18.49 (rhbz#2480121) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2480121 - bind-9.18.49 is available https://bugzilla.redhat.com/show_bug.cgi?id=2480121 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b626e83a45' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 43 bind-dyndb-ldap update 2026-b626e83a45 with critical security fixes for multiple issues.. bind-dyndb-ldap updates, Fedora vulnerabilities, LDAP security fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 26, 2026 Important Fedora
203

Mageia 9 Samba Security Advisory 2026-0142 CVE-2018-14628 and more

MGASA-2026-0142 - Updated samba packages fix security vulnerabilities. MGASA-2026-0142 - Updated samba packages fix security vulnerabilities Publication date: 16 May 2026 URL: https://advisories.mageia.org/MGASA-2026-0142.html Type: security Affected Mageia releases: 9 CVE: CVE-2018-14628, CVE-2025-10230, CVE-2025-9640 Description: An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store. (CVE-2018-14628) Command injection in wins server hook script. (CVE-2025-10230) vfs_streams_xattr uninitialized memory write possible. (CVE-2025-9640) References: - https://bugs.mageia.org/show_bug.cgi?id=34672 - https://www.openwall.com/lists/oss-security/2025/10/15/2 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14628 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-10230 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-9640 SRPMS: - 9/core/samba-4.17.12-1.2.mga9 . Mageia security advisory 2026-0142 highlights Samba package vulnerabilities and provides fixes for critical issues.. Samba Security Advisory, Mageia Samba Update, CVE-Information Leak, LDAP Vulnerability, Memory Management Issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 16, 2026 Important Mageia
219

Rocky Linux 10 RLSA-2026-3323 openldap-server Critical RCE Threat Alert

Moderate: 389-ds-base security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:3208", "synopsis": "Moderate: 389-ds-base security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for 389-ds-base.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.\n\nSecurity Fix(es):\n\n* 389-ds-base: 389-ds-base: Remote Code Execution and Denial of Service via heap buffer overflow (CVE-2025-14905)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2423624", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2423624", "description": ""}], "cves": [{"name": "CVE-2025-14905", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-14905", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.2", "cwe": "CWE-122"}], "references": [], "publishedAt": "2026-02-26T20:47:54.095478Z", "rpms": {"Rocky Linux 10": {"nvras": ["389-ds-base-debugsource-0:3.1.3-7.el10_1.ppc64le.rpm", "389-ds-base-bdb-debuginfo-0:3.1.3-7.el10_1.s390x.rpm", "389-ds-base-bdb-0:3.1.3-7.el10_1.s390x.rpm", "389-ds-base-0:3.1.3-7.el10_1.x86_64.rpm", "389-ds-base-bdb-0:3.1.3-7.el10_1.x86_64.rpm", "389-ds-base-libs-0:3.1.3-7.el10_1.aarch64.rpm", "389-ds-base-debugsource-0:3.1.3-7.el10_1.s390x.rpm", "389-ds-base-devel-0:3.1.3-7.el10_1.aarch64.rpm", "389-ds-base-debuginfo-0:3.1.3-7.el10_1.x86_64.rpm", "389-ds-base-debugsource-0:3.1.3-7.el10_1.aarch64.rpm","389-ds-base-bdb-debuginfo-0:3.1.3-7.el10_1.ppc64le.rpm", "389-ds-base-snmp-debuginfo-0:3.1.3-7.el10_1.aarch64.rpm", "389-ds-base-libs-0:3.1.3-7.el10_1.s390x.rpm", "389-ds-base-libs-0:3.1.3-7.el10_1.x86_64.rpm", "389-ds-base-libs-debuginfo-0:3.1.3-7.el10_1.x86_64.rpm", "389-ds-base-debugsource-0:3.1.3-7.el10_1.x86_64.rpm", "389-ds-base-0:3.1.3-7.el10_1.src.rpm", "389-ds-base-devel-0:3.1.3-7.el10_1.s390x.rpm", "389-ds-base-snmp-0:3.1.3-7.el10_1.s390x.rpm", "389-ds-base-libs-debuginfo-0:3.1.3-7.el10_1.s390x.rpm", "389-ds-base-snmp-0:3.1.3-7.el10_1.x86_64.rpm", "389-ds-base-libs-debuginfo-0:3.1.3-7.el10_1.aarch64.rpm", "389-ds-base-0:3.1.3-7.el10_1.ppc64le.rpm", "389-ds-base-debuginfo-0:3.1.3-7.el10_1.ppc64le.rpm", "389-ds-base-bdb-0:3.1.3-7.el10_1.ppc64le.rpm", "389-ds-base-devel-0:3.1.3-7.el10_1.x86_64.rpm", "389-ds-base-libs-0:3.1.3-7.el10_1.ppc64le.rpm", "389-ds-base-snmp-0:3.1.3-7.el10_1.ppc64le.rpm", "389-ds-base-snmp-debuginfo-0:3.1.3-7.el10_1.s390x.rpm", "389-ds-base-devel-0:3.1.3-7.el10_1.ppc64le.rpm", "389-ds-base-bdb-debuginfo-0:3.1.3-7.el10_1.x86_64.rpm", "389-ds-base-debuginfo-0:3.1.3-7.el10_1.aarch64.rpm", "python3-lib389-0:3.1.3-7.el10_1.noarch.rpm", "389-ds-base-bdb-debuginfo-0:3.1.3-7.el10_1.aarch64.rpm", "389-ds-base-0:3.1.3-7.el10_1.aarch64.rpm", "389-ds-base-snmp-debuginfo-0:3.1.3-7.el10_1.x86_64.rpm", "389-ds-base-snmp-0:3.1.3-7.el10_1.aarch64.rpm", "389-ds-base-libs-debuginfo-0:3.1.3-7.el10_1.ppc64le.rpm", "389-ds-base-snmp-debuginfo-0:3.1.3-7.el10_1.ppc64le.rpm", "389-ds-base-debuginfo-0:3.1.3-7.el10_1.s390x.rpm", "389-ds-base-bdb-0:3.1.3-7.el10_1.aarch64.rpm", "389-ds-base-0:3.1.3-7.el10_1.s390x.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. 389-ds-base security update for Rocky Linux addresses moderate risk including remote code execution and denial of service.. Rocky Linux security update, 389-ds-base fix, LDAP server security. . LinuxSecurity.com Team

Calendar%202 Feb 26, 2026 Rocky Linux
217

Oracle Linux 10 ELSA-2025-7508 moderate: java-21-openjdk security advisory

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-7508 http://linux.oracle.com/errata/ELSA-2025-7508.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable LinuxNetwork: x86_64: java-21-openjdk-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-demo-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-demo-fastdebug-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-demo-slowdebug-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-devel-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-devel-fastdebug-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-devel-slowdebug-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-fastdebug-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-headless-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-headless-fastdebug-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-headless-slowdebug-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-javadoc-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-javadoc-zip-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-jmods-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-jmods-fastdebug-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-jmods-slowdebug-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-slowdebug-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-src-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-src-fastdebug-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-src-slowdebug-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-static-libs-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-static-libs-fastdebug-21.0.7.0.6-1.0.1.el10.x86_64.rpm java-21-openjdk-static-libs-slowdebug-21.0.7.0.6-1.0.1.el10.x86_64.rpm aarch64: java-21-openjdk-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-demo-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-demo-fastdebug-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-demo-slowdebug-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-devel-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-devel-fastdebug-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-devel-slowdebug-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-fastdebug-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-headless-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-headless-fastdebug-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-headless-slowdebug-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-javadoc-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-javadoc-zip-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-jmods-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-jmods-fastdebug-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-jmods-slowdebug-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-slowdebug-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-src-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-src-fastdebug-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-src-slowdebug-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-static-libs-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-static-libs-fastdebug-21.0.7.0.6-1.0.1.el10.aarch64.rpm java-21-openjdk-static-libs-slowdebug-21.0.7.0.6-1.0.1.el10.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/java-21-openjdk-21.0.7.0.6-1.0.1.el10.src.rpm Related CVEs: CVE-2025-21587 CVE-2025-30691 CVE-2025-30698 Description of changes: [1:21.0.7.0.6-1.0.1] - Add Oracle vendor bug URL [Orabug: 34340155] [1:21.0.7.0.6-1] - Update to jdk-21.0.7+6 (GA) - Update release notes to 21.0.7+6 - Rebase FIPS support against 21.0.7+5 - Require tzdata 2025a due to upstream inclusion of JDK-8347965 - ** This tarball is embargoed until 2025-04-15 @ 1pm PT. ** - Resolves: RHEL-86986 - Resolves: RHEL-86636 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 10 now provides updated java-21-openjdk packages addressing important security vulnerabilities. Please verify available updates immediately.. Oracle Linux, Java OpenJDK, Security Advisory, Package Update, Moderate Risk. . LinuxSecurity.com Team

Calendar%202 Jun 30, 2025 Oracle
197

Debian LTS 11: DLA-4021-1 critical: 389-ds-base multiple security risks

This update fixes multiple vulnerabilities in 389-ds-base LDAP server. CVE-2021-3652 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4021-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Andrej Shadura January 19, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : 389-ds-base Version : 1.4.4.11-2+deb11u1 CVE ID : CVE-2021-3652 CVE-2021-4091 CVE-2022-0918 CVE-2022-0996 CVE-2022-2850 CVE-2024-2199 CVE-2024-3657 CVE-2024-5953 CVE-2024-8445 This update fixes multiple vulnerabilities in 389-ds-base LDAP server. CVE-2021-3652 If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled. CVE-2021-4091 A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash. CVE-2022-0918 A vulnerability allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing. CVE-2022-0996 A vulnerability allows expired passwords to access the database to cause improper authentication. CVE-2022-2850 When the content synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial ofservice. This CVE is assigned against an incomplete fix of CVE-2021-3514. CVE-2024-2199 A denial of service vulnerability that may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input. CVE-2024-3657 A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service. CVE-2024-5953 This issue may allow an authenticated user to cause a server denial of service while attempting to log in with a user with a malformed hash in their password. CVE-2024-8445 The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input. For Debian 11 bullseye, these problems have been fixed in version 1.4.4.11-2+deb11u1. We recommend that you upgrade your 389-ds-base packages. For the detailed security status of 389-ds-base please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/389-ds-base Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Essential patches for Debian LTS resolve security issues in 389-ds-base LDAP. Vital for maintaining system integrity and performance.. Debian LTS, 389-ds-base, security update, LDAP issues, server vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 20, 2025 Critical Debian LTS
98

Red Hat 8 RHSA-2023-4655-01 Moderate: Directory Server Security Fix

An update for the redhat-ds:11 module is now available for Red Hat Directory Server 11.6 for RHEL 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: redhat-ds:11 security, bug fix, and enhancement update Advisory ID: RHSA-2023:4655-01 Product: Red Hat Directory Server Advisory URL: https://access.redhat.com/errata/RHSA-2023:4655 Issue date: 2023-08-15 CVE Names: CVE-2023-1055 ===================================================================== 1. Summary: An update for the redhat-ds:11 module is now available for Red Hat Directory Server 11.6 for RHEL 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Directory Server 11.6 for RHEL 8 - noarch, x86_64 3. Description: Red Hat Directory Server is an LDAPv3-compliant directory server. The suite of packages includes the Lightweight Directory Access Protocol (LDAP) server, as well as command-line utilities and Web UI packages for server administration. Security Fix(s): * RHDS: LDAP browser tries to decode userPassword instead of userCertificate attribute (CVE-2023-1055) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Users of Red Hat Directory Server 11 are advised to upgrade to these updated packages. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2168719 - lib389 password policy DN handling is incorrect 2173517 - CVE-2023-1055 RHDS: LDAP browser tries to decode userPassword instead of userCertificate attribute 6. Package List: Red Hat Directory Server 11.6 for RHEL 8: Source: 389-ds-base-1.4.3.34-1.module+el8dsrv+18380+8350b80e.src.rpm noarch: cockpit-389-ds-1.4.3.34-1.module+el8dsrv+18380+8350b80e.noarch.rpm python3-lib389-1.4.3.34-1.module+el8dsrv+18380+8350b80e.noarch.rpm x86_64: 389-ds-base-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-debuginfo-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-debugsource-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-devel-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-legacy-tools-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-legacy-tools-debuginfo-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-libs-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-libs-debuginfo-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-snmp-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-snmp-debuginfo-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-1055 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/security/cve/CVE-2023-1055 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJk24qZAAoJENzjgjWX9erEmCIP/AmA/1/kGxF8ACrP6GFQ+pCL xPjbaBzDbz9LlHFyUC7cnyPUIFro80TXBB4P/H1fc1koeZ2yF0KAEBsIzKnocI9H SKJllWkP3C1a0mPjaNZ4N84wYRKEfNJ2IucUpfGZKLcJ8rxomoSdpOMLaZqHm3px E0JC0Vv88XUARwGeuVKtI+6j6Ou5FzNoCd4Kd1XvrMzv7KAbVJxkB9Xoenf8ZbUp NuLV8qiPBCHkrsbE+fMBQ6B5vbOgzX3hPUf/jPIdusGX82FRnqUf/gambzmnuUDq gihVYAWwnl+wzYKHvQpvGdJlxNYonxnuKfyNJc6Q469AKobGTiAvrFz0qy6Gbfv/ hodfwNF5fJc0E/62518Qq72mTmYBECIvK17kmnqhkFlS2x9luaGQ31R8Qlxi88z0 b+klA6RdNdL8bf9NF20ti4z949aIJSzDcNtXoVk8ysxBPB6hCxM+7qjY6PVGY3VH 8C7CgOyy1Oruq1SNJOR7RxCSsTbf9RwUrgpvf7ySaDUNf/pQJVyS++UR5IDvEjnv XJg3dIIYwS8ePiQy8EKgS6UNS/9xv/PH5hRgcK8qepkpb9inkO9Ky6fK/9oReRU3 +nQQZuUvmw4lW+HpawT99/Mi1m1A+y74FN+Z+OtscGRan35ub5rC1CNp8yIHkZvm 16T5+anvXr2FBWHheGsu =csV1 -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Alert: Security bulletin for Red Hat Directory Server version 11.6 highlights moderate-risk vulnerabilities. Updates and mitigation steps are accessible.. Red Hat Directory Server, Redhat DS, LDAP Security, Security Advisory, Bug Fixes. . LinuxSecurity.com Team

Calendar%202 Aug 15, 2023 Red Hat
197

Debian 10 Buster DLA-3285-1 Moderate: Libapache-Session LDAP Security

In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3285-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Guilhem Moulin January 28, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : libapache-session-browseable-perl Version : 1.3.0-1+deb10u1 CVE ID : CVE-2020-36659 In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. This update changes the default behavior to require X.509 validation against the distribution bundle /etc/ssl/certs/ca-certificates.crt. Previous behavior can reverted by setting `ldapVerify => "none"` when initializing the Apache::Session::Browseable::LDAP object. NOTE: this update is a prerequisite for LemonLDAP::NG's CVE-2020-16093 fix when its session backend is set to Apache::Session::Browseable::LDAP. For Debian 10 buster, this problem has been fixed in version 1.3.0-1+deb10u1. We recommend that you upgrade your libapache-session-browseable-perl packages. For the detailed security status of libapache-session-browseable-perl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libapache-session-browseable-perl Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance your libapache-session-browseable-perl installations to incorporate essential X.509 certificate verification enhancements from Debian..libapache-session,x.509,security update,ldap,debian. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 28, 2023 Important Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200