Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
100

SUSE: 2022:3208-2 Important: openssl-1_0 Security Vulnerability Resolve

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libnl-1_1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3207-1 Rating: moderate References: #1020123 Cross-References: CVE-2017-0386 CVSS scores: CVE-2017-0386 (NVD) : 7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2017-0386 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libnl-1_1 fixes the following issues: - CVE-2017-0386: Fixed an issue that could enable a local malicious application to execute arbitrary code within the context of a different process. This only affects setups were libnl is passed untrusted arguments. (bsc#1020123) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-3207=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-3207=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libnl-1_1-debugsource-1.1.4-6.3.1 libnl-1_1-devel-1.1.4-6.3.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libnl-1_1-debugsource-1.1.4-6.3.1 libnl1-1.1.4-6.3.1 libnl1-debuginfo-1.1.4-6.3.1 - SUSE Linux EnterpriseServer 12-SP5 (s390x x86_64): libnl1-32bit-1.1.4-6.3.1 libnl1-debuginfo-32bit-1.1.4-6.3.1 References: https://www.suse.com/security/cve/CVE-2017-0386.html https://bugzilla.suse.com/1020123 . Patch for libnl-1_1 resolves localized execution flaws in SUSE 12-SP5, mitigating arbitrary code execution dangers.. SUSE Update, libnl Security, Local Execution Fix, Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 08, 2022 Important SuSE
198

Arch Linux: ASA-201706-35 Medium: libnl Elevation of Privileges

The package libnl before version 3.3.0-1 is vulnerable to privilege escalation. . Arch Linux Security Advisory ASA-201706-35 ========================================= Severity: Medium Date : 2017-06-28 CVE-ID : CVE-2017-0553 Package : libnl Type : privilege escalation Remote : No Link : https://security.archlinux.org/AVG-292 Summary ====== The package libnl before version 3.3.0-1 is vulnerable to privilege escalation. Resolution ========= Upgrade to 3.3.0-1. # pacman -Syu "libnl> =3.3.0-1" The problem has been fixed upstream in version 3.3.0. Workaround ========= None. Description ========== An integer overflow vulnerability has been found in the nlmsg_reserve() function of libnl < 3.3.0, allowing local privilege escalation. Impact ===== A local attacker is able to escalate privileges. References ========= http://git.infradead.org/users/tgr/libnl.git/commitdiff/3e18948f17148e6a3c4255bdeaaf01ef6081ceeb?hp=3dd2a0f26fa59896b4b4a262cf309a4be4aa70d3 https://security.archlinux.org/CVE-2017-0553 . The Debian Security Advisory DSA-2021-005 addresses a high severity vulnerability in OpenSSL prior to version 1.1.1k.. Arch Linux, libnl, privilege escalation, security advisory. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Jun 28, 2017 Medium ArchLinux
172

Ubuntu 12.04 ESM: USN-3311-2 Critical Libnl Denial of Service

libnl could be made to run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-3311-2 June 19, 2017 libnl3 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: libnl could be made to run programs as an administrator. Software Description: - libnl3: library for dealing with netlink sockets Details: USN-3311-1 fixed a vulnerability in libnl. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that libnl incorrectly handled memory when performing certain operations. A local attacker could possibly use this issue to cause libnl to crash, resulting in a denial of service, or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: libnl-3-200 3.2.3-2ubuntu2.1 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3311-2 https://ubuntu.com/security/notices/USN-3311-1 CVE-2017-0553 . =========================================================================Ubuntu Security Notice USN-. libnl, programs, administrator, ===========================================. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 19, 2017 Critical Ubuntu
172

Ubuntu 17.04 USN-3311-1 Critical: libnl Denial Of Service Risk

libnl could be made to crash or run programs.. =========================================================================Ubuntu Security Notice USN-3311-1 June 06, 2017 libnl3 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 17.04 - Ubuntu 16.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: libnl could be made to crash or run programs. Software Description: - libnl3: library for dealing with netlink sockets Details: It was discovered that libnl incorrectly handled memory when performing certain operations. A local attacker could possibly use this issue to cause libnl to crash, resulting in a denial of service, or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 17.04: libnl-3-200 3.2.29-0ubuntu2.1 Ubuntu 16.10: libnl-3-200 3.2.27-1ubuntu0.16.10.1 Ubuntu 16.04 LTS: libnl-3-200 3.2.27-1ubuntu0.16.04.1 Ubuntu 14.04 LTS: libnl-3-200 3.2.21-1ubuntu4.1 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3311-1 CVE-2017-0553 Package Information: https://launchpad.net/ubuntu/+source/libnl3/3.2.29-0ubuntu2.1 https://launchpad.net/ubuntu/+source/libnl3/3.2.27-1ubuntu0.16.10.1 https://launchpad.net/ubuntu/+source/libnl3/3.2.27-1ubuntu0.16.04.1 https://launchpad.net/ubuntu/+source/libnl3/3.2.21-1ubuntu4.1 . Ubuntu Security Notice USN-3312-1 reports on a critical flaw in libcurl that poses threats to various distributions, potentially leading to data leaks.. Ubuntu Security Notice, libnl3, Denial Of Service, Memory Handling Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 06, 2017 Critical Ubuntu
197

Debian 7 Wheezy DLA-891-1 Moderate: Libnl Security Issue

It was discovered that there was a FIXME in libnl, a FIXME... For Debian 7 "Wheezy", this issue has been fixed in libnl version 1.1-7+deb7u1. . Hash: SHA256 Package : libnl Version : 1.1-7+deb7u1 CVE ID : CVE-2017-0553 Debian Bug : It was discovered that there was a FIXME in libnl, a FIXME... For Debian 7 "Wheezy", this issue has been fixed in libnl version 1.1-7+deb7u1. We recommend that you upgrade your libnl packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . Hash: SHA256 Package : libnl Version : 1.1-7+deb7u1 CVE ID : CVE-2017-0553 Debian Bug : It was disco. fixme, there, libnl, debian, 'wheezy'. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 10, 2017 Important Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200