Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 31 articles for you...
219

Rocky Linux 8: curl Moderate Security Update RLSA-2025:23383

Moderate: curl security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:23383", "synopsis": "Moderate: curl security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for curl.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.\n\nSecurity Fix(es):\n\n* curl: libcurl: Curl out of bounds read for cookie path (CVE-2025-9086)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2394750", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2394750", "description": ""}], "cves": [{"name": "CVE-2025-9086", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-9086", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "cvss3BaseScore": "5.3", "cwe": "CWE-125"}], "references": [], "publishedAt": "2025-12-19T09:02:54.260652Z", "rpms": {"Rocky Linux 8": {"nvras": ["curl-0:7.61.1-34.el8_10.9.aarch64.rpm", "curl-0:7.61.1-34.el8_10.9.src.rpm", "curl-0:7.61.1-34.el8_10.9.x86_64.rpm", "curl-debuginfo-0:7.61.1-34.el8_10.9.aarch64.rpm", "curl-debuginfo-0:7.61.1-34.el8_10.9.i686.rpm", "curl-debuginfo-0:7.61.1-34.el8_10.9.x86_64.rpm", "curl-debugsource-0:7.61.1-34.el8_10.9.aarch64.rpm", "curl-debugsource-0:7.61.1-34.el8_10.9.i686.rpm", "curl-debugsource-0:7.61.1-34.el8_10.9.x86_64.rpm", "libcurl-0:7.61.1-34.el8_10.9.aarch64.rpm", "libcurl-0:7.61.1-34.el8_10.9.i686.rpm", "libcurl-0:7.61.1-34.el8_10.9.x86_64.rpm", "libcurl-debuginfo-0:7.61.1-34.el8_10.9.aarch64.rpm","libcurl-debuginfo-0:7.61.1-34.el8_10.9.i686.rpm", "libcurl-debuginfo-0:7.61.1-34.el8_10.9.x86_64.rpm", "libcurl-devel-0:7.61.1-34.el8_10.9.aarch64.rpm", "libcurl-devel-0:7.61.1-34.el8_10.9.i686.rpm", "libcurl-devel-0:7.61.1-34.el8_10.9.x86_64.rpm", "libcurl-minimal-0:7.61.1-34.el8_10.9.aarch64.rpm", "libcurl-minimal-0:7.61.1-34.el8_10.9.i686.rpm", "libcurl-minimal-0:7.61.1-34.el8_10.9.x86_64.rpm", "libcurl-minimal-debuginfo-0:7.61.1-34.el8_10.9.aarch64.rpm", "libcurl-minimal-debuginfo-0:7.61.1-34.el8_10.9.i686.rpm", "libcurl-minimal-debuginfo-0:7.61.1-34.el8_10.9.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. curl security update for Rocky Linux addresses moderate risk issue. Ensure your system is up to date with this patch.. Rocky Linux security update, curl security advisory, libcurl patch, moderate risk vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Dec 19, 2025 Rocky Linux
100

SUSE: 2025:1503-1 important: libsoup2 patch for multiple threats

* bsc#1240750 * bsc#1240752 * bsc#1240756 * bsc#1240757 * bsc#1241164 . # Security update for libsoup2 Announcement ID: SUSE-SU-2025:1503-1 Release Date: 2025-05-07T12:06:08Z Rating: important References: * bsc#1240750 * bsc#1240752 * bsc#1240756 * bsc#1240757 * bsc#1241164 * bsc#1241222 * bsc#1241686 * bsc#1241688 Cross-References: * CVE-2025-2784 * CVE-2025-32050 * CVE-2025-32052 * CVE-2025-32053 * CVE-2025-32907 * CVE-2025-32914 * CVE-2025-46420 * CVE-2025-46421 CVSS scores: * CVE-2025-2784 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-2784 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2025-2784 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2025-32050 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-32050 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-32050 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-32052 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-32052 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2025-32052 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2025-32053 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-32053 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2025-32053 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2025-32907 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-32907 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-32907 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32914 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-32914 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2025-46420 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-46420 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-46420 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-46421 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-46421 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves eight vulnerabilities can now be installed. ## Description: This update for libsoup2 fixes the following issues: * CVE-2025-2784: Fixed heap buffer over-read in `skip_insignificant_space` when sniffing conten (bsc#1240750) * CVE-2025-32050: Fixed integer overflow in append_param_quoted (bsc#1240752) * CVE-2025-32052: Fixed heap buffer overflow in sniff_unknown() (bsc#1240756) * CVE-2025-32053: Fixed heap buffer overflows in sniff_feed_or_html() and skip_insignificant_space() (bsc#1240757) * CVE-2025-32907: Fixed excessive memory consumption in server when client requests a large amount of overlapping ranges in a single HTTP request (bsc#1241222) * CVE-2025-32914: Fixed out of bounds read in `soup_multipart_new_from_message()` (bsc#1241164) * CVE-2025-46420: Fixed memory leak on soup_header_parse_quality_list() via soup-headers.c (bsc#1241686) * CVE-2025-46421: Fixed HTTP Authorization Header leak via an HTTP redirect (bsc#1241688) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-1503=1 openSUSE-SLE-15.6-2025-1503=1 * Basesystem Module 15-SP6 zypper in -t patchSUSE-SLE-Module-Basesystem-15-SP6-2025-1503=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * typelib-1_0-Soup-2_4-2.74.3-150600.4.6.1 * libsoup-2_4-1-2.74.3-150600.4.6.1 * libsoup2-devel-2.74.3-150600.4.6.1 * libsoup2-debugsource-2.74.3-150600.4.6.1 * libsoup-2_4-1-debuginfo-2.74.3-150600.4.6.1 * openSUSE Leap 15.6 (x86_64) * libsoup-2_4-1-32bit-debuginfo-2.74.3-150600.4.6.1 * libsoup2-devel-32bit-2.74.3-150600.4.6.1 * libsoup-2_4-1-32bit-2.74.3-150600.4.6.1 * openSUSE Leap 15.6 (noarch) * libsoup2-lang-2.74.3-150600.4.6.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libsoup-2_4-1-64bit-2.74.3-150600.4.6.1 * libsoup-2_4-1-64bit-debuginfo-2.74.3-150600.4.6.1 * libsoup2-devel-64bit-2.74.3-150600.4.6.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * typelib-1_0-Soup-2_4-2.74.3-150600.4.6.1 * libsoup-2_4-1-2.74.3-150600.4.6.1 * libsoup2-devel-2.74.3-150600.4.6.1 * libsoup2-debugsource-2.74.3-150600.4.6.1 * libsoup-2_4-1-debuginfo-2.74.3-150600.4.6.1 * Basesystem Module 15-SP6 (noarch) * libsoup2-lang-2.74.3-150600.4.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-2784.html * https://www.suse.com/security/cve/CVE-2025-32050.html * https://www.suse.com/security/cve/CVE-2025-32052.html * https://www.suse.com/security/cve/CVE-2025-32053.html * https://www.suse.com/security/cve/CVE-2025-32907.html * https://www.suse.com/security/cve/CVE-2025-32914.html * https://www.suse.com/security/cve/CVE-2025-46420.html * https://www.suse.com/security/cve/CVE-2025-46421.html * https://bugzilla.suse.com/show_bug.cgi?id=1240750 * https://bugzilla.suse.com/show_bug.cgi?id=1240752 * https://bugzilla.suse.com/show_bug.cgi?id=1240756 * https://bugzilla.suse.com/show_bug.cgi?id=1240757 * https://bugzilla.suse.com/show_bug.cgi?id=1241164 * https://bugzilla.suse.com/show_bug.cgi?id=1241222 * https://bugzilla.suse.com/show_bug.cgi?id=1241686 *https://bugzilla.suse.com/show_bug.cgi?id=1241688 . A critical patch for Fedora addresses various vulnerabilities in libcurl, improving overall system resilience and efficiency.. SUSE Linux, libsoup2 security, critical patches, openSUSE maintenance. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 07, 2025 Important SuSE
217

Oracle Linux 9 ELSA-2024-5529 Moderate: Curl Security Update

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-5529 http://linux.oracle.com/errata/ELSA-2024-5529.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: curl-7.76.1-29.el9_4.1.x86_64.rpm curl-minimal-7.76.1-29.el9_4.1.x86_64.rpm libcurl-7.76.1-29.el9_4.1.i686.rpm libcurl-7.76.1-29.el9_4.1.x86_64.rpm libcurl-devel-7.76.1-29.el9_4.1.i686.rpm libcurl-devel-7.76.1-29.el9_4.1.x86_64.rpm libcurl-minimal-7.76.1-29.el9_4.1.i686.rpm libcurl-minimal-7.76.1-29.el9_4.1.x86_64.rpm aarch64: curl-7.76.1-29.el9_4.1.aarch64.rpm curl-minimal-7.76.1-29.el9_4.1.aarch64.rpm libcurl-7.76.1-29.el9_4.1.aarch64.rpm libcurl-devel-7.76.1-29.el9_4.1.aarch64.rpm libcurl-minimal-7.76.1-29.el9_4.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//curl-7.76.1-29.el9_4.1.src.rpm Related CVEs: CVE-2024-2398 Description of changes: [7.76.1-29.el9_4.1] - provide common cleanup method for push headers (CVE-2024-2398) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Notice ELSA-2024-5529 provides crucial updates for curl packages. Important bug fixes and download resources are accessible.. Oracle Linux, curl update, security advisory, RPMs, ELSA-2024-5529. . LinuxSecurity.com Team

Calendar%202 Aug 19, 2024 Oracle
203

Mageia 8: MGASA-2022-0405 Critical Curl Security Advisory

When doing HTTP(S) transfers, libcurl might erroneously use the read callback (CURLOPT_READFUNCTION) to ask for data to send, even when the CURLOPT_POSTFIELDS option has been set, if the same handle previously was used to issue a PUT request which used that callback. (CVE-2022-32221) . MGASA-2022-0405 - Updated curl packages fix security vulnerability Publication date: 01 Nov 2022 URL: https://advisories.mageia.org/MGASA-2022-0405.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-32221 When doing HTTP(S) transfers, libcurl might erroneously use the read callback (CURLOPT_READFUNCTION) to ask for data to send, even when the CURLOPT_POSTFIELDS option has been set, if the same handle previously was used to issue a PUT request which used that callback. (CVE-2022-32221) References: - https://bugs.mageia.org/show_bug.cgi?id=31031 - https://curl.se/docs/CVE-2022-32221.html - https://www.cve.org/CVERecord?id=CVE-2022-32221 SRPMS: - 8/core/curl-7.74.0-1.9.mga8 . Tackling vulnerabilities in libcurl for HTTP(S) communications in Mageia 8 to promote secure data exchanges.. mageia 8,curl security,HTTP transfer vulnerability,libcurl update,security patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 01, 2022 Critical Mageia
219

Rocky Linux 8 RLSA-2022:6159 Moderate: Curl Security Update

Moderate: curl security update. \{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2022:6159', 'synopsis': 'Moderate: curl security update', 'severity': 'Moderate', 'topic': 'An update for curl is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': 'The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['2099300', '2099306'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-32206.json:::CVE-2022-32206', 'Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-32208.json:::CVE-2022-32208'], 'references': [], 'publishedAt': '2022-08-29T22:14:20.960911Z', 'rpms': ['curl-7.61.1-22.el8_6.4.aarch64.rpm', 'curl-7.61.1-22.el8_6.4.src.rpm', 'curl-7.61.1-22.el8_6.4.x86_64.rpm', 'curl-debuginfo-7.61.1-22.el8_6.4.aarch64.rpm', 'curl-debuginfo-7.61.1-22.el8_6.4.i686.rpm', 'curl-debuginfo-7.61.1-22.el8_6.4.x86_64.rpm', 'curl-debugsource-7.61.1-22.el8_6.4.aarch64.rpm', 'curl-debugsource-7.61.1-22.el8_6.4.i686.rpm', 'curl-debugsource-7.61.1-22.el8_6.4.x86_64.rpm', 'libcurl-7.61.1-22.el8_6.4.aarch64.rpm', 'libcurl-7.61.1-22.el8_6.4.i686.rpm', 'libcurl-7.61.1-22.el8_6.4.x86_64.rpm', 'libcurl-debuginfo-7.61.1-22.el8_6.4.aarch64.rpm', 'libcurl-debuginfo-7.61.1-22.el8_6.4.i686.rpm', 'libcurl-debuginfo-7.61.1-22.el8_6.4.x86_64.rpm', 'libcurl-devel-7.61.1-22.el8_6.4.aarch64.rpm', 'libcurl-devel-7.61.1-22.el8_6.4.i686.rpm','libcurl-devel-7.61.1-22.el8_6.4.x86_64.rpm', 'libcurl-minimal-7.61.1-22.el8_6.4.aarch64.rpm', 'libcurl-minimal-7.61.1-22.el8_6.4.i686.rpm', 'libcurl-minimal-7.61.1-22.el8_6.4.x86_64.rpm', 'libcurl-minimal-debuginfo-7.61.1-22.el8_6.4.aarch64.rpm', 'libcurl-minimal-debuginfo-7.61.1-22.el8_6.4.i686.rpm', 'libcurl-minimal-debuginfo-7.61.1-22.el8_6.4.x86_64.rpm']}\. Rocky Linux has released a security advisory regarding a moderate curl update that affects file transfer operations, enhancing protection against potential vulnerabilities. Rocky Linux Curl Update, Linux Server Security Patches, Moderate Risk Advisory. . LinuxSecurity.com Team

Calendar%202 Sep 02, 2022 Rocky Linux
219

Rocky Linux 8 RLSA-2021:4059 Moderate: Curl Security Update

Moderate: curl security update. \{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2021:4059', 'synopsis': 'Moderate: curl security update', 'severity': 'Moderate', 'topic': 'An update for curl is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': 'The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['2003175', '2003191'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-22946.json:::CVE-2021-22946', 'Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-22947.json:::CVE-2021-22947'], 'references': [], 'publishedAt': '2021-11-03T01:25:03.261193Z', 'rpms': ['curl-7.61.1-18.el8_4.2.aarch64.rpm', 'curl-7.61.1-18.el8_4.2.src.rpm', 'curl-7.61.1-18.el8_4.2.x86_64.rpm', 'curl-debuginfo-7.61.1-18.el8_4.2.aarch64.rpm', 'curl-debuginfo-7.61.1-18.el8_4.2.i686.rpm', 'curl-debuginfo-7.61.1-18.el8_4.2.x86_64.rpm', 'curl-debugsource-7.61.1-18.el8_4.2.aarch64.rpm', 'curl-debugsource-7.61.1-18.el8_4.2.i686.rpm', 'curl-debugsource-7.61.1-18.el8_4.2.x86_64.rpm', 'libcurl-7.61.1-18.el8_4.2.aarch64.rpm', 'libcurl-7.61.1-18.el8_4.2.i686.rpm', 'libcurl-7.61.1-18.el8_4.2.x86_64.rpm', 'libcurl-debuginfo-7.61.1-18.el8_4.2.aarch64.rpm', 'libcurl-debuginfo-7.61.1-18.el8_4.2.i686.rpm', 'libcurl-debuginfo-7.61.1-18.el8_4.2.x86_64.rpm', 'libcurl-devel-7.61.1-18.el8_4.2.aarch64.rpm', 'libcurl-devel-7.61.1-18.el8_4.2.i686.rpm','libcurl-devel-7.61.1-18.el8_4.2.x86_64.rpm', 'libcurl-minimal-7.61.1-18.el8_4.2.aarch64.rpm', 'libcurl-minimal-7.61.1-18.el8_4.2.i686.rpm', 'libcurl-minimal-7.61.1-18.el8_4.2.x86_64.rpm', 'libcurl-minimal-debuginfo-7.61.1-18.el8_4.2.aarch64.rpm', 'libcurl-minimal-debuginfo-7.61.1-18.el8_4.2.i686.rpm', 'libcurl-minimal-debuginfo-7.61.1-18.el8_4.2.x86_64.rpm']}\. The latest moderate curl security update for Rocky Linux 8 addresses critical vulnerabilities affecting file transfers and downloads, enhancing system security.. curl Security Update, Rocky Linux Security, libcurl Package Update, Moderate Threat Advisory. . LinuxSecurity.com Team

Calendar%202 Sep 02, 2022 Rocky Linux
100

SUSE: 2022:1204-1 Important: Curl and Python Security Updates

The container bci/python was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:1204-1 Container Tags : bci/python:3 , bci/python:3.6 , bci/python:3.6-15.41 Container Release : 15.41 Severity : important Type : security References : 1196490 1197443 1197743 1197771 1197794 1198446 1198614 1198723 1198766 1199132 1199223 1199224 1199240 CVE-2022-1304 CVE-2022-22576 CVE-2022-23308 CVE-2022-27775 CVE-2022-27776 CVE-2022-27781 CVE-2022-27782 CVE-2022-29155 CVE-2022-29824 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:1655-1 Released: Fri May 13 15:36:10 2022 Summary: Recommended update for pam Type: recommended Severity: moderate References: 1197794 This update for pam fixes the following issue: - Do not include obsolete header files (bsc#1197794) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:1657-1 Released: Fri May 13 15:39:07 2022 Summary: Security update for curl Type: security Severity: moderate References: 1198614,1198723,1198766,CVE-2022-22576,CVE-2022-27775,CVE-2022-27776 This update for curl fixes the following issues: - CVE-2022-27776: Fixed auth/cookie leak on redirect (bsc#1198766) - CVE-2022-27775: Fixed bad local IPv6 connection reuse (bsc#1198723) - CVE-2022-22576: Fixed OAUTH2 bearer bypass in connection re-use (bsc#1198614) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:1658-1 Released: Fri May 13 15:40:20 2022 Summary: Recommended update for libpsl Type: recommended Severity: important References: 1197771 This update for libpsl fixes the following issues: - Fix libpsl compilation issues (bsc#1197771) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:1670-1 Released: Mon May 16 10:06:30 2022 Summary: Security update for openldap2 Type: security Severity: important References: 1199240,CVE-2022-29155 This update for openldap2 fixes the following issues: - CVE-2022-29155: Fixed SQL injection in back-sql (bsc#1199240). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:1688-1 Released: Mon May 16 14:02:49 2022 Summary: Security update for e2fsprogs Type: security Severity: important References: 1198446,CVE-2022-1304 This update for e2fsprogs fixes the following issues: - CVE-2022-1304: Fixed out-of-bounds read/write leading to segmentation fault and possibly arbitrary code execution. (bsc#1198446) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:1691-1 Released: Mon May 16 15:13:39 2022 Summary: Recommended update for augeas Type: recommended Severity: moderate References: 1197443 This update for augeas fixes the following issue: - Sysctl keys can contain some more non-alphanumeric characters. (bsc#1197443) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:1709-1 Released: Tue May 17 17:35:47 2022 Summary: Recommended update for libcbor Type: recommended Severity: important References: 1197743 This update for libcbor fixes the following issues: - Fix build errors occuring on SUSE Linux Enterprise 15 Service Pack 4 ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:1750-1 Released: Thu May 19 15:28:20 2022 Summary: Security update for libxml2 Type: security Severity: important References: 1196490,1199132,CVE-2022-23308,CVE-2022-29824 This update for libxml2fixes the following issues: - CVE-2022-23308: Fixed a use-after-free of ID and IDREF attributes (bsc#1196490). - CVE-2022-29824: Fixed integer overflow that could have led to an out-of-bounds write in buf.c (xmlBuf*) and tree.c (xmlBuffer*) (bsc#1199132). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:1870-1 Released: Fri May 27 10:03:40 2022 Summary: Security update for curl Type: security Severity: important References: 1199223,1199224,CVE-2022-27781,CVE-2022-27782 This update for curl fixes the following issues: - CVE-2022-27781: Fixed CERTINFO never-ending busy-loop (bsc#1199223) - CVE-2022-27782: Fixed TLS and SSH connection too eager reuse (bsc#1199224) The following package changes have been done: - curl-7.66.0-150200.4.33.1 updated - libaugeas0-1.10.1-150000.3.12.1 updated - libcbor0-0.5.0-150100.4.6.1 updated - libcom_err2-1.43.8-150000.4.33.1 updated - libcurl4-7.66.0-150200.4.33.1 updated - libldap-2_4-2-2.4.46-150200.14.8.1 updated - libldap-data-2.4.46-150200.14.8.1 updated - libpsl5-0.20.1-150000.3.3.1 updated - libxml2-2-2.9.7-150000.3.46.1 updated - pam-1.3.0-150000.6.58.3 updated - container:sles15-image-15.0.0-17.17.5 updated . SUSE Container Update Advisory: bci/nodejs features security patches for numerous components resolving critical vulnerabilities.. SUSE Security Updates, Python Patch, Curl Security Fixes, Container Security, Linux Security Patches. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 28, 2022 Important SuSE
172

Ubuntu 16.04/14.04: USN-5079-4 Critical Curl Regression Alert

USN-5079-2 introduced a regression in curl.. =========================================================================Ubuntu Security Notice USN-5079-4 September 21, 2021 curl regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: USN-5079-2 introduced a regression in curl. Software Description: - curl: HTTP, HTTPS, and FTP client and client libraries Details: USN-5079-2 fixed vulnerabilities in curl. One of the fixes introduced a regression. This update fixes the problem. Original advisory details: Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS. When receiving certain responses from servers, curl would continue without TLS even when the option to require a successful upgrade to TLS was specified. (CVE-2021-22946) Patrick Monnerat discovered that curl incorrectly handled responses received before STARTTLS. A remote attacker could possibly use this issue to inject responses and intercept communications. (CVE-2021-22947) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: curl 7.47.0-1ubuntu2.19+esm2 libcurl3 7.47.0-1ubuntu2.19+esm2 libcurl3-gnutls 7.47.0-1ubuntu2.19+esm2 libcurl3-nss 7.47.0-1ubuntu2.19+esm2 Ubuntu 14.04 ESM: curl 7.35.0-1ubuntu2.20+esm9 libcurl3 7.35.0-1ubuntu2.20+esm9 libcurl3-gnutls 7.35.0-1ubuntu2.20+esm9 libcurl3-nss 7.35.0-1ubuntu2.20+esm9 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5079-4 https://ubuntu.com/security/notices/USN-5079-1 https://bugs.launchpad.net/ubuntu/+source/curl/+bug/1944120 . Ubuntu Security Notice USN-5080-5 tackles a newlyidentified vulnerability in OpenSSL affecting Ubuntu 18.04 and 20.04 LTS systems.. curl Regression, Ubuntu Update, Ubuntu Security Notice, TLS Issue, Package Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 21, 2021 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200