Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 490
Alerts This Week
Warning Icon 1 490

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 65 articles for you...
172

Ubuntu 26.04 24.04 libssh2 Critical DoS RCE Vulnerabilities USN-8532-1

Several security issues were fixed in libssh2.. ========================================================================== Ubuntu Security Notice USN-8532-1 July 13, 2026 libssh2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS Summary: Several security issues were fixed in libssh2. Software Description: - libssh2: Client-side C library implementing the SSH2 protocol Details: It was discovered that libssh2 incorrectly handled certain publickey subsystem attributes. A remote attacker controlling a malicious SSH server could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2026-58050) It was discovered that libssh2 did not properly initialize publickey list entries before parsing. A remote attacker controlling a malicious SSH server could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2026-58051) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libssh2-1t64 1.11.1-1ubuntu0.26.04.3 Ubuntu 24.04 LTS libssh2-1t64 1.11.0-4.1ubuntu0.24.04.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8532-1 CVE-2026-58050, CVE-2026-58051 Package Information: https://launchpad.net/ubuntu/+source/libssh2/1.11.1-1ubuntu0.26.04.3 https://launchpad.net/ubuntu/+source/libssh2/1.11.0-4.1ubuntu0.24.04.3 . Recent fixes for libssh2 address critical security issues in Ubuntu affecting remote code execution and denial of service.. Ubuntu libssh2 security fix, remote code execution Ubuntu, denial of service vulnerability, libssh2 issues, security update Ubuntu. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 13, 2026 Critical Ubuntu
89

Fedora 43 libssh2 Important Remote Code Execution Vuln 2026-eed9e67393

This update addresses a few security issues, one of which could plausibly result in remote code execution.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-eed9e67393 2026-07-12 00:58:35.903616+00:00 -------------------------------------------------------------------------------- Name : libssh2 Product : Fedora 43 Version : 1.11.1 Release : 9.fc43 URL : https://www.libssh2.org/ Summary : A library implementing the SSH2 protocol Description : libssh2 is a library implementing the SSH2 protocol as defined by Internet Drafts: SECSH-TRANS(22), SECSH-USERAUTH(25), SECSH-CONNECTION(23), SECSH-ARCH(20), SECSH-FILEXFER(06)*, SECSH-DHGEX(04), and SECSH-NUMBERS(10). -------------------------------------------------------------------------------- Update Information: This update addresses a few security issues, one of which could plausibly result in remote code execution. -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 25 2026 Paul Howarth - 1.11.1-9 - Fix CVE-2025-15661: Information disclosure and denial of service via crafted SFTP response * Tue Jun 23 2026 Mikel Olasagasti Uranga - 1.11.1-8 - Fix CVE-2026-55200 & CVE-2026-55199 * Fri Jun 12 2026 Yaakov Selkowitz - 1.11.1-7 - Rebuilt for openssl 4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2491730 - CVE-2026-55199 libssh2: libssh2: Denial of Service via crafted SSH_MSG_EXT_INFO message [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491730 [ 2 ] Bug #2491738 - CVE-2026-55200 libssh2: libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491738 [ 3 ] Bug #2492698 - CVE-2025-15661 libssh2: libssh2: Information disclosure and denial of service via crafted SFTP response [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2492698 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-eed9e67393' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Addressing significant security issues in Fedora's libssh2 update that may lead to remote code execution risks.. Fedora Updates, Libssh2 Security, Remote Code Execution, Software Vulnerability, Library Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 11, 2026 Important Fedora
100

SUSE Linux Micro 6.0 libssh2_org Moderate DoS Vulnern 2026-22438-1

An update that solves one vulnerability can now be installed.. # Security update for libssh2_org Announcement ID: SUSE-SU-2026:22438-1 Release Date: 2026-07-01T09:39:44Z Rating: moderate References: * bsc#1268530 Cross-References: * CVE-2026-55199 CVSS scores: * CVE-2026-55199 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55199 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for libssh2_org fixes the following issue * CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-775=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libssh2_org-debugsource-1.11.0-3.1 * libssh2-1-debuginfo-1.11.0-3.1 * libssh2-1-1.11.0-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55199.html * https://bugzilla.suse.com/show_bug.cgi?id=1268530 . The SUSE update for libssh2_org addresses a moderate DoS issue with CVE-2026-55199.. SUSE Linux Micro libssh2 DoS security update. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 03, 2026 moderate SuSE
172

Ubuntu 26.04 LTS libssh2 Important DoS Remote Code Exec USN-8486-1

Several security issues were fixed in libssh2.. ========================================================================== Ubuntu Security Notice USN-8486-1 June 30, 2026 libssh2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS Summary: Several security issues were fixed in libssh2. Software Description: - libssh2: Client-side C library implementing the SSH2 protocol Details: It was discovered that libssh2 incorrectly handled the sftp_symlink() function. A malicious SSH server or machine-in-the-middle attacker could possibly use this issue to obtain sensitive information or cause a denial of service. (CVE-2025-15661) It was discovered that libssh2 had a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler. A malicious SSH server could possibly use this issue to cause a client CPU exhaustion loop, resulting in a denial of service. (CVE-2026-55199) It was discovered that libssh2 incorrectly handled packet length fields. A remote attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-55200) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libssh2-1t64 1.11.1-1ubuntu0.26.04.2 Ubuntu 25.10 libssh2-1t64 1.11.1-1ubuntu0.25.10.2 Ubuntu 24.04 LTS libssh2-1t64 1.11.0-4.1ubuntu0.24.04.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8486-1 CVE-2025-15661, CVE-2026-55199, CVE-2026-55200 Package Information: https://launchpad.net/ubuntu/+source/libssh2/1.11.1-1ubuntu0.26.04.2 https://launchpad.net/ubuntu/+source/libssh2/1.11.1-1ubuntu0.25.10.2 https://launchpad.net/ubuntu/+source/libssh2/1.11.0-4.1ubuntu0.24.04.2 . Multiple security flaws have been addressed in libssh2 affecting multiple Ubuntu versions. Update recommended to ensure security.. libssh2 update Ubuntu security issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 Important Ubuntu
89

Fedora 44 libssh2 Critical Remote Code Execution Advisory 2026-ca858b3ed8

This update addresses a few security issues, one of which could plausibly result in remote code execution.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-ca858b3ed8 2026-06-29 00:57:02.525499+00:00 -------------------------------------------------------------------------------- Name : libssh2 Product : Fedora 44 Version : 1.11.1 Release : 9.fc44 URL : https://www.libssh2.org/ Summary : A library implementing the SSH2 protocol Description : libssh2 is a library implementing the SSH2 protocol as defined by Internet Drafts: SECSH-TRANS(22), SECSH-USERAUTH(25), SECSH-CONNECTION(23), SECSH-ARCH(20), SECSH-FILEXFER(06)*, SECSH-DHGEX(04), and SECSH-NUMBERS(10). -------------------------------------------------------------------------------- Update Information: This update addresses a few security issues, one of which could plausibly result in remote code execution. -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 25 2026 Paul Howarth - 1.11.1-9 - Fix CVE-2025-15661: Information disclosure and denial of service via crafted SFTP response * Tue Jun 23 2026 Mikel Olasagasti Uranga - 1.11.1-8 - Fix CVE-2026-55200 & CVE-2026-55199 * Fri Jun 12 2026 Yaakov Selkowitz - 1.11.1-7 - Rebuilt for openssl 4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2491730 - CVE-2026-55199 libssh2: libssh2: Denial of Service via crafted SSH_MSG_EXT_INFO message [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491730 [ 2 ] Bug #2491738 - CVE-2026-55200 libssh2: libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491738 [ 3 ] Bug #2492698 - CVE-2025-15661 libssh2: libssh2: Information disclosure and denial of service via crafted SFTP response [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2492698 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ca858b3ed8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update for Fedora addressing critical security issues in libssh2, includes remote code execution risk and denial of service.. Fedora libssh2 remote code execution denial of service update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 28, 2026 Critical Fedora
202

openSUSE libssh2 Moderate Security Issues Advisory 2026-11109-1

An update that solves 4 vulnerabilities can now be installed.. # libssh2-1-1.11.1-3.1 on GA media Announcement ID: openSUSE-SU-2026:11109-1 Rating: moderate Cross-References: * CVE-2025-15661 * CVE-2026-55199 * CVE-2026-55200 * CVE-2026-7598 CVSS scores: * CVE-2025-15661 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-55199 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55200 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-7598 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-7598 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Tumbleweed An update that solves 4 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the libssh2-1-1.11.1-3.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * libssh2-1 1.11.1-3.1 * libssh2-1-32bit 1.11.1-3.1 * libssh2-devel 1.11.1-3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-15661.html * https://www.suse.com/security/cve/CVE-2026-55199.html * https://www.suse.com/security/cve/CVE-2026-55200.html * https://www.suse.com/security/cve/CVE-2026-7598.html . An update is now available for libssh2-1 with moderate severity addressing critical security issues in openSUSE Tumbleweed.. libssh2-1 vulnerabilities, openSUSE update, libssh2 security, moderate severity, security advisory. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 26, 2026 moderate OpenSUSE
87

Debian libssh2 Critical Memory Disclosure DoS Exec Code DSA-6365-1

Multiple security vulnerabilities were discovered in libssh2, a client-side C library implementing the SSH2 protocol which could result in memory disclosure, denial of service or potentially the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6365-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff June 25, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libssh2 CVE ID : CVE-2025-15661 CVE-2026-7598 CVE-2026-55199 CVE-2026-55200 Multiple security vulnerabilities were discovered in libssh2, a client-side C library implementing the SSH2 protocol which could result in memory disclosure, denial of service or potentially the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in version 1.11.1-1+deb13u1. We recommend that you upgrade your libssh2 packages. For the detailed security status of libssh2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libssh2 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Numerous security flaws found in libssh2 could lead to memory disclosure, DoS, or arbitrary code execution. Update advised.. libssh2 security fix, Debian advisory, security vulnerabilities, memory disclosure, denial of service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 25, 2026 Critical Debian
89

Fedora 43 libssh2 Important Heap Overflow CVE-2026-7598

This update addresses CVE-2026-7598, a potential heap buffer overflow, which could be triggered remotely by supplying very long username and/or password strings.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-1b9134cdc9 2026-06-07 01:06:43.462152+00:00 -------------------------------------------------------------------------------- Name : libssh2 Product : Fedora 43 Version : 1.11.1 Release : 6.fc43 URL : https://www.libssh2.org/ Summary : A library implementing the SSH2 protocol Description : libssh2 is a library implementing the SSH2 protocol as defined by Internet Drafts: SECSH-TRANS(22), SECSH-USERAUTH(25), SECSH-CONNECTION(23), SECSH-ARCH(20), SECSH-FILEXFER(06)*, SECSH-DHGEX(04), and SECSH-NUMBERS(10). -------------------------------------------------------------------------------- Update Information: This update addresses CVE-2026-7598, a potential heap buffer overflow, which could be triggered remotely by supplying very long username and/or password strings. -------------------------------------------------------------------------------- ChangeLog: * Fri May 22 2026 Paul Howarth - 1.11.1-6 - Fix CVE-2026-7598: integer overflow via large username or password arguments (https://github.com/libssh2/libssh2/pull/1858) * Fri Jan 16 2026 Fedora Release Engineering - 1.11.1-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2468328 - CVE-2026-7598 libssh2: integer overflow via large username or password arguments [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2468328 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1b9134cdc9' at the command line. For more information, refer tothe dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Critical heap overflow vulnerability in libssh2 library on Fedora 43 addressed by advisory FEDORA-2026-1b9134cdc9.. libssh2 security patch, Fedora update, heap overflow, CVE-2026-7598. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 07, 2026 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200