Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
197

Debian LTS: DLA-4084-1: libmodbus Security Advisory Updates

Two separate issues where identified and have now been adressed in libmodbus. For one of the problems multiple CVE identifiers have been allocated to the same issue and all of them are mentioned below. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4084-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Andreas Henriksson March 11, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : libmodbus Version : 3.1.6-2+deb11u1 CVE ID : CVE-2022-0367 CVE-2024-10918 CVE-2024-36843 CVE-2024-36844 CVE-2024-36845 Debian Bug : 1074422 Two separate issues where identified and have now been adressed in libmodbus. For one of the problems multiple CVE identifiers have been allocated to the same issue and all of them are mentioned below. CVE-2022-0367 A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c. CVE-2024-10918 Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a Modbus request with an unexpected length. CVE-2024-36843 This is a duplicate of CVE-2022-0367 CVE-2024-36844 This is a duplicate of CVE-2022-0367 CVE-2024-36845 This is a duplicate of CVE-2022-0367 For Debian 11 bullseye, these problems have been fixed in version 3.1.6-2+deb11u1. We recommend that you upgrade your libmodbus packages. For the detailed security status of libmodbus please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libmodbus Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Security Advisory for Debian LTS addressing libmodbusvulnerabilities affecting versions 3.1.6-2+deb11u1, with critical updates.. separate, where, identified, adressed, libmodbus, problem. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 11, 2025 Critical Debian LTS
202

openSUSE: 2022:10196-1 Important: Libmodbus Buffer Overflow Security Fix

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for libmodbus ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10196-1 Rating: important References: #1195124 Cross-References: CVE-2022-0367 CVSS scores: CVE-2022-0367 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libmodbus fixes the following issues: - CVE-2022-0367: Fixed heap-based Buffer Overflow in modbus_reply (boo#1195124). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2022-10196=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): libmodbus-devel-3.1.6-bp154.2.3.1 libmodbus5-3.1.6-bp154.2.3.1 References: https://www.suse.com/security/cve/CVE-2022-0367.html https://bugzilla.suse.com/1195124 . Important security patch released for libmodbus concerning CVE-2022-0367. Address the buffer overflow vulnerability immediately!. openSUSE Update, libmodbus Patch, Security Advisory, Buffer Overflow Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 11, 2022 Important OpenSUSE
197

Debian Buster DLA-3098-1 Moderate: Libmodbus Buffer Overflow Attack

A heap-based buffer overflow flaw was found in libmodbus, a library for the Modbus protocol, which can be abused for a denial of service attack or memory corruption. . -------------------------------------------------------------------------Debian LTS Advisory DLA-3098-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany September 04, 2022 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : libmodbus Version : 3.1.4-2+deb10u2 CVE ID : CVE-2022-0367 A heap-based buffer overflow flaw was found in libmodbus, a library for the Modbus protocol, which can be abused for a denial of service attack or memory corruption. For Debian 10 buster, this problem has been fixed in version 3.1.4-2+deb10u2. We recommend that you upgrade your libmodbus packages. For the detailed security status of libmodbus please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libmodbus Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A Debian LTS security notice has been published, detailing a critical issue related to a buffer overflow in the libmodbus library which could potentially result in a denial of service.. libmodbus update, Debian security, buffer overflow fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 04, 2022 Important Debian LTS
172

Ubuntu 18.04 LTS USN-5173-1 Moderate: Libmodbus Crash Risk

libmodbus could be made to crash if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-5173-1 December 06, 2021 libmodbus vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: libmodbus could be made to crash if it received specially crafted input. Software Description: - libmodbus: Library to send/receive data according to the Modbus protocol Details: It was discovered that libmodbus incorrectly handled inputs. An attacker could possibly use this issue to cause a denial of service or other unspecified impact. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: libmodbus5 3.0.6-2+deb9u1build0.18.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5173-1 CVE-2019-14462, CVE-2019-14463 Package Information: https://launchpad.net/ubuntu/+source/libmodbus/3.0.6-2+deb9u1build0.18.04.1 . Upgrade libmodbus to mitigate security risks impacting Ubuntu 18.04 and avert possible system failures.. libmodbus, Ubuntu advisory, denial of service, security update. . LinuxSecurity.com Team

Calendar%202 Dec 06, 2021 Ubuntu
197

Debian 9: DLA-2825-1 Moderate: libmodbus Out Of Bound Reads

Two issues have been found in libmodbus, a library for the Modbus protocol. Both issues are related to out of bound reads, which could result in a . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2825-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz November 22, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libmodbus Version : 3.0.6-2+deb9u1 CVE ID : CVE-2019-14462 CVE-2019-14463 Two issues have been found in libmodbus, a library for the Modbus protocol. Both issues are related to out of bound reads, which could result in a denial of service or other unspecified impact. For Debian 9 stretch, these problems have been fixed in version 3.0.6-2+deb9u1. We recommend that you upgrade your libmodbus packages. For the detailed security status of libmodbus please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libmodbus Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2840-2 highlights severe vulnerabilities in libxml2 related to buffer overflows. Take immediate action!. Debian LTS, Libmodbus Out Of Bounds, Security Update. . LinuxSecurity.com Team

Calendar%202 Nov 22, 2021 Debian LTS
89

Fedora 29 libmodbus Advisory FEDORA-2019-355f6e10c1 Critical CVEs

Addresses CVE-2019-14462 and CVE-2019-14463. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-355f6e10c1 2019-08-25 03:02:58.350184 --------------------------------------------------------------------------------Name : libmodbus Product : Fedora 29 Version : 3.0.8 Release : 1.fc29 URL : Summary : A Modbus library Description : libmodbus is a C library designed to provide a fast and robust implementation of the Modbus protocol. It runs on Linux, Mac OS X, FreeBSD, QNX and Windows. This package contains the libmodbus shared library. --------------------------------------------------------------------------------Update Information: Addresses CVE-2019-14462 and CVE-2019-14463 --------------------------------------------------------------------------------ChangeLog: * Fri Aug 16 2019 Eric Sandeen - 3.0.8-1 - New upstream release - Addresses CVE-2019-14462 and CVE-2019-14463 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-355f6e10c1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives:https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Essential enhancements for libmodbus in Fedora 29 tackling vulnerabilities associated with CVE-2019-14462 and CVE-2019-14463.. Fedora Updates, libmodbus Security, Modbus Protocol, Fedora Security Advisory, CVE Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 24, 2019 Critical Fedora
89

Fedora 30: 2019-4942e01cdc Moderate: libmodbus Security Fix

Addresses CVE-2019-14462 and CVE-2019-14463. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-4942e01cdc 2019-08-25 00:56:58.831376 --------------------------------------------------------------------------------Name : libmodbus Product : Fedora 30 Version : 3.0.8 Release : 1.fc30 URL : Summary : A Modbus library Description : libmodbus is a C library designed to provide a fast and robust implementation of the Modbus protocol. It runs on Linux, Mac OS X, FreeBSD, QNX and Windows. This package contains the libmodbus shared library. --------------------------------------------------------------------------------Update Information: Addresses CVE-2019-14462 and CVE-2019-14463 --------------------------------------------------------------------------------ChangeLog: * Fri Aug 16 2019 Eric Sandeen - 3.0.8-1 - New upstream release - Addresses CVE-2019-14462 and CVE-2019-14463 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-4942e01cdc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives:https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora 30 Users are urged to update libmodbus to address vulnerabilities CVE-2019-14462 and CVE-2019-14463 and ensure system security and integrity. Fedora Update, libmodbus Security, Modbus Protocol, Security Patch. . LinuxSecurity.com Team

Calendar%202 Aug 24, 2019 Fedora
89

Fedora 23: FEDORA-2023-bf12897e2f Serious: libmodbus Memory Leak Issue

fix remote buffer overflow vulnerability on write requests. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-ae14784e4e 2016-03-09 20:10:53.638820 -------------------------------------------------------------------------------- Name : libmodbus Product : Fedora 23 Version : 3.0.6 Release : 1.fc23 URL : Summary : A Modbus library Description : libmodbus is a C library designed to provide a fast and robust implementation of the Modbus protocol. It runs on Linux, Mac OS X, FreeBSD, QNX and Windows. This package contains the libmodbus shared library. -------------------------------------------------------------------------------- Update Information: fix remote buffer overflow vulnerability on write requests -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libmodbus' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Addresses critical remote buffer overflow flaw in libmodbus for Fedora 23. Mandatory upgrade for enhanced security.. Fedora Security, Libmodbus Update, Buffer Overflow Fix, Linux Software, Threat Mitigation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 09, 2016 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200