Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 436
Alerts This Week
Warning Icon 1 436

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
197

Debian 11: libfcgi Critical Integer Overflow Buffer Overflow DLA-4329-1

An issue has been found in libfcgi, a FastCGI bridge from CGI. The issue is related to an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4329-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz October 13, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libfcgi Version : 2.4.2-2+deb11u1 CVE ID : CVE-2025-23016 An issue has been found in libfcgi, a FastCGI bridge from CGI. The issue is related to an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. For Debian 11 bullseye, this problem has been fixed in version 2.4.2-2+deb11u1. We recommend that you upgrade your libfcgi packages. For the detailed security status of libfcgi please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libfcgi Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Critical libfcgi update addresses integer overflow and buffer overflow risks. Upgrade recommended for Debian 11 users.. libfcgi security update, Debian LTS, integer overflow risk, buffer overflow fix, Debian 11 security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 13, 2025 Critical Debian LTS
172

Ubuntu: 7527-1 critical: libfcgi-perl arbitrary code execution

libfcgi-perl could be made to crash or execute arbitrary code.. ========================================================================== Ubuntu Security Notice USN-7527-1 May 22, 2025 libfcgi-perl vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: libfcgi-perl could be made to crash or execute arbitrary code. Software Description: - libfcgi-perl: Fast CGI module for perl Details: It was discovered that libfcgi-perl incorrectly handled certain inputs. An attacker could possibly use this issue to cause a crash or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS libfcgi-perl 0.79-1ubuntu0.1 Ubuntu 18.04 LTS libfcgi-perl 0.78-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libfcgi-perl 0.77-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7527-1 CVE-2025-40907 Package Information: https://launchpad.net/ubuntu/+source/libfcgi-perl/0.79-1ubuntu0.1 . Ubuntu Security Notice USN-7528-1 pertains to a vulnerability in libcurl that could result in system instability or unauthorized code execution.. Libfcgi-perl, Ubuntu Security Notice, Execute Arbitrary Code, Crash Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 22, 2025 Critical Ubuntu
172

Ubuntu 25.04: USN-7486-1 critical: libfcgi arbitrary code execution

FastCGI could be made to crash or execute arbitrary code.. ========================================================================== Ubuntu Security Notice USN-7486-1 May 06, 2025 libfcgi vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: FastCGI could be made to crash or execute arbitrary code. Software Description: - libfcgi: FastCGI bridge from CGI Details: It was discovered that FastCGI incorrectly handled certain inputs. An attacker could possibly use this issue to cause a crash or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 libfcgi0t64 2.4.2-2.1ubuntu0.25.04.1 Ubuntu 24.10 libfcgi0t64 2.4.2-2.1ubuntu0.24.10.1 Ubuntu 24.04 LTS libfcgi0t64 2.4.2-2.1ubuntu0.24.04.1 Ubuntu 22.04 LTS libfcgi0ldbl 2.4.2-2ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7486-1 CVE-2025-23016 Package Information: https://launchpad.net/ubuntu/+source/libfcgi/2.4.2-2.1ubuntu0.25.04.1 https://launchpad.net/ubuntu/+source/libfcgi/2.4.2-2.1ubuntu0.24.10.1 https://launchpad.net/ubuntu/+source/libfcgi/2.4.2-2.1ubuntu0.24.04.1 https://launchpad.net/ubuntu/+source/libfcgi/2.4.2-2ubuntu0.1 . A vulnerability in FastCGI on Ubuntu poses risks of potential system crashes or the execution of arbitrary code. It's crucial to update the libfcgi package to mitigate this security issue.. libfcgi update, Ubuntu security, FastCGI CVE, system update, arbitrary code execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 06, 2025 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200