Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 19 articles for you...
172

Ubuntu 22.04 LTS: USN-7510-1 critical: Multiple Kernel Security Flaws

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7510-1 May 16, 2025 linux, linux-gkeop, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle, linux-oracle-5.15 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-gkeop: Linux kernel for Google Container Engine (GKE) systems - linux-ibm: Linux kernel for IBM cloud systems - linux-intel-iotg: Linux kernel for Intel IoT platforms - linux-kvm: Linux kernel for cloud environments - linux-lowlatency: Linux low latency kernel - linux-nvidia: Linux kernel for NVIDIA systems - linux-oracle: Linux kernel for Oracle Cloud systems - linux-ibm-5.15: Linux kernel for IBM cloud systems - linux-lowlatency-hwe-5.15: Linux low latency kernel - linux-oracle-5.15: Linux kernel for Oracle Cloud systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - PowerPC architecture; - x86 architecture; - Block layer subsystem; - Network block device driver; - Bus devices; - Character device driver; - TPM device driver; - Clock framework and drivers; - GPIO subsystem; - GPU drivers; - HID subsystem; - I2C subsystem; - InfiniBand drivers; - Media drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - PCI subsystem; - PPS (Pulse Per Second) driver; - PTP clock framework; - RapidIO drivers; - Real Time Clock drivers; - SLIMbus drivers; -QCOM SoC drivers; - Trusted Execution Environment drivers; - TTY drivers; - USB DSL drivers; - USB Device Class drivers; - USB core drivers; - USB Gadget drivers; - USB Host Controller drivers; - Renesas USBHS Controller drivers; - ACRN Hypervisor Service Module driver; - File systems infrastructure; - BTRFS file system; - F2FS file system; - Network file system (NFS) server daemon; - NILFS2 file system; - Overlay file system; - SMB network file system; - UBI file system; - KVM subsystem; - L3 Master device support module; - Process Accounting mechanism; - Padata parallel execution mechanism; - printk logging mechanism; - Scheduler infrastructure; - Timer subsystem; - Tracing infrastructure; - Memory management; - 802.1Q VLAN protocol; - B.A.T.M.A.N. meshing protocol; - Networking core; - IPv4 networking; - IPv6 networking; - Logical Link layer; - Multipath TCP; - Netfilter; - NFC subsystem; - Open vSwitch; - Rose network layer; - Network traffic control; - Wireless networking; - Landlock security; - Linux Security Modules (LSM) Framework; - Tomoyo security module; (CVE-2025-21731, CVE-2025-21926, CVE-2025-21830, CVE-2024-58010, CVE-2025-21745, CVE-2025-21871, CVE-2024-57980, CVE-2025-21916, CVE-2025-21735, CVE-2025-21763, CVE-2025-21799, CVE-2025-21811, CVE-2025-21814, CVE-2024-58083, CVE-2025-21922, CVE-2025-21802, CVE-2024-58034, CVE-2025-21758, CVE-2024-58069, CVE-2025-21905, CVE-2024-57986, CVE-2025-21718, CVE-2024-58020, CVE-2025-21858, CVE-2025-21749, CVE-2025-21928, CVE-2024-58085, CVE-2025-21795, CVE-2025-21744, CVE-2025-21776, CVE-2025-21804, CVE-2024-57973, CVE-2025-21848, CVE-2025-21844, CVE-2024-56721, CVE-2024-58079, CVE-2025-21781, CVE-2025-21866, CVE-2024-58052, CVE-2024-58017, CVE-2024-58071, CVE-2025-21791, CVE-2024-26982, CVE-2025-21787, CVE-2024-58090, CVE-2025-21951, CVE-2025-21846, CVE-2025-21722, CVE-2024-58001,CVE-2025-21715, CVE-2025-21919, CVE-2025-21904, CVE-2024-57977, CVE-2025-21785, CVE-2025-21950, CVE-2025-21924, CVE-2024-57979, CVE-2025-21711, CVE-2024-47726, CVE-2024-58002, CVE-2025-21914, CVE-2024-58086, CVE-2024-58005, CVE-2025-21835, CVE-2024-58051, CVE-2025-21761, CVE-2025-21760, CVE-2025-21767, CVE-2025-21766, CVE-2025-21726, CVE-2025-21865, CVE-2024-58014, CVE-2025-21878, CVE-2025-21934, CVE-2024-58007, CVE-2025-21898, CVE-2025-21806, CVE-2024-58058, CVE-2025-21779, CVE-2024-58063, CVE-2025-21708, CVE-2025-21684, CVE-2024-57834, CVE-2025-21971, CVE-2025-21762, CVE-2025-21728, CVE-2024-58076, CVE-2025-21704, CVE-2025-21719, CVE-2025-21948, CVE-2025-21707, CVE-2025-21917, CVE-2025-21782, CVE-2025-21943, CVE-2025-21765, CVE-2025-21721, CVE-2024-58016, CVE-2025-21859, CVE-2025-21909, CVE-2025-21748, CVE-2025-21912, CVE-2025-21736, CVE-2025-21862, CVE-2024-57978, CVE-2025-21826, CVE-2025-21920, CVE-2025-21772, CVE-2025-21877, CVE-2025-21935, CVE-2024-56599, CVE-2025-21820, CVE-2025-21764, CVE-2025-21796, CVE-2025-21887, CVE-2025-21753, CVE-2025-21910, CVE-2024-57981, CVE-2025-21727, CVE-2025-21875, CVE-2024-58072, CVE-2024-58055, CVE-2025-21925, CVE-2025-21823, CVE-2025-21647) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1066-gkeop 5.15.0-1066.74 linux-image-5.15.0-1076-ibm 5.15.0-1076.79 linux-image-5.15.0-1078-nvidia 5.15.0-1078.79 linux-image-5.15.0-1078-nvidia-lowlatency 5.15.0-1078.79 linux-image-5.15.0-1079-intel-iotg 5.15.0-1079.85 linux-image-5.15.0-1080-kvm 5.15.0-1080.85 linux-image-5.15.0-1081-oracle 5.15.0-1081.87 linux-image-5.15.0-140-generic 5.15.0-140.150 linux-image-5.15.0-140-generic-64k 5.15.0-140.150 linux-image-5.15.0-140-generic-lpae 5.15.0-140.150 linux-image-5.15.0-140-lowlatency 5.15.0-140.150 linux-image-5.15.0-140-lowlatency-64k 5.15.0-140.150 linux-image-generic 5.15.0.140.135 linux-image-generic-64k 5.15.0.140.135 linux-image-generic-lpae 5.15.0.140.135 linux-image-gkeop 5.15.0.1066.65 linux-image-gkeop-5.15 5.15.0.1066.65 linux-image-ibm 5.15.0.1076.72 linux-image-intel-iotg 5.15.0.1079.79 linux-image-kvm 5.15.0.1080.76 linux-image-lowlatency 5.15.0.140.126 linux-image-lowlatency-64k 5.15.0.140.126 linux-image-nvidia 5.15.0.1078.78 linux-image-nvidia-lowlatency 5.15.0.1078.78 linux-image-oracle-lts-22.04 5.15.0.1081.77 linux-image-virtual 5.15.0.140.135 Ubuntu 20.04 LTS linux-image-5.15.0-1076-ibm 5.15.0-1076.79~20.04.1 linux-image-5.15.0-1081-oracle 5.15.0-1081.87~20.04.1 linux-image-5.15.0-140-lowlatency 5.15.0-140.150~20.04.1 linux-image-5.15.0-140-lowlatency-64k 5.15.0-140.150~20.04.1 linux-image-ibm 5.15.0.1076.79~20.04.1 linux-image-lowlatency-64k-hwe-20.04 5.15.0.140.150~20.04.1 linux-image-lowlatency-hwe-20.04 5.15.0.140.150~20.04.1 linux-image-oracle 5.15.0.1081.87~20.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7510-1 CVE-2024-26982, CVE-2024-47726, CVE-2024-56599, CVE-2024-56721, CVE-2024-57834, CVE-2024-57973, CVE-2024-57977, CVE-2024-57978, CVE-2024-57979, CVE-2024-57980, CVE-2024-57981, CVE-2024-57986, CVE-2024-58001, CVE-2024-58002, CVE-2024-58005,CVE-2024-58007, CVE-2024-58010, CVE-2024-58014, CVE-2024-58016, CVE-2024-58017, CVE-2024-58020, CVE-2024-58034, CVE-2024-58051, CVE-2024-58052, CVE-2024-58055, CVE-2024-58058, CVE-2024-58063, CVE-2024-58069, CVE-2024-58071, CVE-2024-58072, CVE-2024-58076, CVE-2024-58079, CVE-2024-58083, CVE-2024-58085, CVE-2024-58086, CVE-2024-58090, CVE-2025-21647, CVE-2025-21684, CVE-2025-21704, CVE-2025-21707, CVE-2025-21708, CVE-2025-21711, CVE-2025-21715, CVE-2025-21718, CVE-2025-21719, CVE-2025-21721, CVE-2025-21722, CVE-2025-21726, CVE-2025-21727, CVE-2025-21728, CVE-2025-21731, CVE-2025-21735, CVE-2025-21736, CVE-2025-21744, CVE-2025-21745, CVE-2025-21748, CVE-2025-21749, CVE-2025-21753, CVE-2025-21758, CVE-2025-21760, CVE-2025-21761, CVE-2025-21762, CVE-2025-21763, CVE-2025-21764, CVE-2025-21765, CVE-2025-21766, CVE-2025-21767, CVE-2025-21772, CVE-2025-21776, CVE-2025-21779, CVE-2025-21781, CVE-2025-21782, CVE-2025-21785, CVE-2025-21787, CVE-2025-21791, CVE-2025-21795, CVE-2025-21796, CVE-2025-21799, CVE-2025-21802, CVE-2025-21804, CVE-2025-21806, CVE-2025-21811, CVE-2025-21814, CVE-2025-21820, CVE-2025-21823, CVE-2025-21826, CVE-2025-21830, CVE-2025-21835, CVE-2025-21844, CVE-2025-21846, CVE-2025-21848, CVE-2025-21858, CVE-2025-21859, CVE-2025-21862, CVE-2025-21865, CVE-2025-21866, CVE-2025-21871, CVE-2025-21875, CVE-2025-21877, CVE-2025-21878, CVE-2025-21887, CVE-2025-21898, CVE-2025-21904, CVE-2025-21905, CVE-2025-21909, CVE-2025-21910, CVE-2025-21912, CVE-2025-21914, CVE-2025-21916, CVE-2025-21917, CVE-2025-21919, CVE-2025-21920, CVE-2025-21922, CVE-2025-21924, CVE-2025-21925, CVE-2025-21926, CVE-2025-21928, CVE-2025-21934, CVE-2025-21935, CVE-2025-21943, CVE-2025-21948, CVE-2025-21950, CVE-2025-21951, CVE-2025-21971 Package Information: https://launchpad.net/ubuntu/+source/linux/5.15.0-140.150 https://launchpad.net/ubuntu/+source/linux-gkeop/5.15.0-1066.74 https://launchpad.net/ubuntu/+source/linux-ibm/5.15.0-1076.79 https://launchpad.net/ubuntu/+source/linux-intel-iotg/5.15.0-1079.85 https://launchpad.net/ubuntu/+source/linux-kvm/5.15.0-1080.85 https://launchpad.net/ubuntu/+source/linux-lowlatency/5.15.0-140.150 https://launchpad.net/ubuntu/+source/linux-nvidia/5.15.0-1078.79 https://launchpad.net/ubuntu/+source/linux-oracle/5.15.0-1081.87 https://launchpad.net/ubuntu/+source/linux-ibm-5.15/5.15.0-1076.79~20.04.1 https://launchpad.net/ubuntu/+source/linux-lowlatency-hwe-5.15/5.15.0-140.150~20.04.1 https://launchpad.net/ubuntu/+source/linux-oracle-5.15/5.15.0-1081.87~20.04.1 . Urgent patch released targeting various security flaws in the Linux kernel for Ubuntu platforms. Ensure you implement it without delay.. Ubuntu Security, Kernel Update, Linux Security Notice, System Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 16, 2025 Critical Ubuntu
217

Oracle Linux 8 ELSA-2025-0837 Important: unbound Security Updates

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-0837 http://linux.oracle.com/errata/ELSA-2025-0837.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: python3-unbound-1.16.2-5.8.el8_10.x86_64.rpm unbound-1.16.2-5.8.el8_10.x86_64.rpm unbound-devel-1.16.2-5.8.el8_10.i686.rpm unbound-devel-1.16.2-5.8.el8_10.x86_64.rpm unbound-libs-1.16.2-5.8.el8_10.i686.rpm unbound-libs-1.16.2-5.8.el8_10.x86_64.rpm aarch64: python3-unbound-1.16.2-5.8.el8_10.aarch64.rpm unbound-1.16.2-5.8.el8_10.aarch64.rpm unbound-devel-1.16.2-5.8.el8_10.aarch64.rpm unbound-libs-1.16.2-5.8.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//unbound-1.16.2-5.8.el8_10.src.rpm Related CVEs: CVE-2024-1488 CVE-2024-8508 Description of changes: [1.16.2-5.8] - Prevent unbounded name compression (CVE-2024-8508) [1.16.2-5.7] - Rebuild to propagate to CentOS Stream (RHEL-25500) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . The Fedora Linux Security Announcement FLSA-2025-0421 delivers essential updates for OpenSSL in order to address critical vulnerabilities.. Oracle Linux, Unbreakable Linux, Unbound Security, Important Update, Linux Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 31, 2025 Important Oracle
217

Oracle Linux 8 ELSA-2024-8024: Thunderbird Important Security Fix

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-8024 http://linux.oracle.com/errata/ELSA-2024-8024.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: thunderbird-128.3.1-1.0.1.el8_10.x86_64.rpm aarch64: thunderbird-128.3.1-1.0.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//thunderbird-128.3.1-1.0.1.el8_10.src.rpm Related CVEs: CVE-2024-9680 Description of changes: [128.3.1-1.0.1] - Fix prefs for new nss [Orabug: 37079820] - Add Oracle prefs file [128.3.1] - Add OpenELA debranding [128.3.1-1] - Update to 128.3.1 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 8 has been released with essential security updates that tackle vulnerabilities in Thunderbird. Consult the documentation for details on the implemented patches and modifications. Oracle Linux, Thunderbird updates, security patches, Linux RPM updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 15, 2024 Important Oracle
217

Oracle Linux 7 ELSA-2024-12158 Moderate: OpenSSH Security Patch

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-12158 https://linux.oracle.com/errata/ELSA-2024-12158.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: openssh-7.4p1-23.0.3.el7_9.aarch64.rpm openssh-askpass-7.4p1-23.0.3.el7_9.aarch64.rpm openssh-clients-7.4p1-23.0.3.el7_9.aarch64.rpm openssh-keycat-7.4p1-23.0.3.el7_9.aarch64.rpm openssh-server-7.4p1-23.0.3.el7_9.aarch64.rpm openssh-cavs-7.4p1-23.0.3.el7_9.aarch64.rpm openssh-ldap-7.4p1-23.0.3.el7_9.aarch64.rpm openssh-server-sysvinit-7.4p1-23.0.3.el7_9.aarch64.rpm pam_ssh_agent_auth-0.10.3-2.23.0.3.el7_9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates//openssh-7.4p1-23.0.3.el7_9.src.rpm Related CVEs: CVE-2023-48795 Description of changes: [7.4p1-23.0.3] - add KEX_INITIAL flag [Orabug: 36160445] - implement "strict key exchange" [CVE-2023-48795][Orabug: 36160445] _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Advisory ELSA-2024-12158 has been issued to resolve vulnerabilities in openssh for the aarch64 architecture, alongside the release of the patched packages.. Oracle Linux, Openssh Security, ELSA-2024-12158, Linux Updates, Aarch64 Threats. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 14, 2024 Important Oracle
217

Oracle Linux 9 ELSA-2023-1909 Critical: Java Security Update

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-1909 https://linux.oracle.com/errata/ELSA-2023-1909.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: java-1.8.0-openjdk-1.8.0.372.b07-1.0.1.el9_1.x86_64.rpm java-1.8.0-openjdk-demo-1.8.0.372.b07-1.0.1.el9_1.x86_64.rpm java-1.8.0-openjdk-devel-1.8.0.372.b07-1.0.1.el9_1.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.372.b07-1.0.1.el9_1.x86_64.rpm java-1.8.0-openjdk-javadoc-1.8.0.372.b07-1.0.1.el9_1.noarch.rpm java-1.8.0-openjdk-javadoc-zip-1.8.0.372.b07-1.0.1.el9_1.noarch.rpm java-1.8.0-openjdk-src-1.8.0.372.b07-1.0.1.el9_1.x86_64.rpm java-1.8.0-openjdk-demo-fastdebug-1.8.0.372.b07-1.0.1.el9_1.x86_64.rpm java-1.8.0-openjdk-demo-slowdebug-1.8.0.372.b07-1.0.1.el9_1.x86_64.rpm java-1.8.0-openjdk-devel-fastdebug-1.8.0.372.b07-1.0.1.el9_1.x86_64.rpm java-1.8.0-openjdk-devel-slowdebug-1.8.0.372.b07-1.0.1.el9_1.x86_64.rpm java-1.8.0-openjdk-fastdebug-1.8.0.372.b07-1.0.1.el9_1.x86_64.rpm java-1.8.0-openjdk-headless-fastdebug-1.8.0.372.b07-1.0.1.el9_1.x86_64.rpm java-1.8.0-openjdk-headless-slowdebug-1.8.0.372.b07-1.0.1.el9_1.x86_64.rpm java-1.8.0-openjdk-slowdebug-1.8.0.372.b07-1.0.1.el9_1.x86_64.rpm java-1.8.0-openjdk-src-fastdebug-1.8.0.372.b07-1.0.1.el9_1.x86_64.rpm java-1.8.0-openjdk-src-slowdebug-1.8.0.372.b07-1.0.1.el9_1.x86_64.rpm aarch64: java-1.8.0-openjdk-1.8.0.372.b07-1.0.1.el9_1.aarch64.rpm java-1.8.0-openjdk-demo-1.8.0.372.b07-1.0.1.el9_1.aarch64.rpm java-1.8.0-openjdk-devel-1.8.0.372.b07-1.0.1.el9_1.aarch64.rpm java-1.8.0-openjdk-headless-1.8.0.372.b07-1.0.1.el9_1.aarch64.rpm java-1.8.0-openjdk-javadoc-1.8.0.372.b07-1.0.1.el9_1.noarch.rpm java-1.8.0-openjdk-javadoc-zip-1.8.0.372.b07-1.0.1.el9_1.noarch.rpm java-1.8.0-openjdk-src-1.8.0.372.b07-1.0.1.el9_1.aarch64.rpm java-1.8.0-openjdk-demo-fastdebug-1.8.0.372.b07-1.0.1.el9_1.aarch64.rpm java-1.8.0-openjdk-demo-slowdebug-1.8.0.372.b07-1.0.1.el9_1.aarch64.rpm java-1.8.0-openjdk-devel-fastdebug-1.8.0.372.b07-1.0.1.el9_1.aarch64.rpm java-1.8.0-openjdk-devel-slowdebug-1.8.0.372.b07-1.0.1.el9_1.aarch64.rpm java-1.8.0-openjdk-fastdebug-1.8.0.372.b07-1.0.1.el9_1.aarch64.rpm java-1.8.0-openjdk-headless-fastdebug-1.8.0.372.b07-1.0.1.el9_1.aarch64.rpm java-1.8.0-openjdk-headless-slowdebug-1.8.0.372.b07-1.0.1.el9_1.aarch64.rpm java-1.8.0-openjdk-slowdebug-1.8.0.372.b07-1.0.1.el9_1.aarch64.rpm java-1.8.0-openjdk-src-fastdebug-1.8.0.372.b07-1.0.1.el9_1.aarch64.rpm java-1.8.0-openjdk-src-slowdebug-1.8.0.372.b07-1.0.1.el9_1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//java-1.8.0-openjdk-1.8.0.372.b07-1.0.1.el9_1.src.rpm Related CVEs: CVE-2023-21930 CVE-2023-21937 CVE-2023-21938 CVE-2023-21939 CVE-2023-21954 CVE-2023-21967 CVE-2023-21968 Description of changes: [1.8.0.372.b07-1.0.1] - Replace upstream references [Orabug: 34340145] [1:1.8.0.372.b07-1] - Update to shenandoah-jdk8u372-b07 (GA) - Update release notes for shenandoah-8u372-b07. - Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07 - Reintroduce jconsole-plugin.patch from RHEL 9 - Update generate_tarball.sh to add support for passing a boot JDK to the configure run - Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace - Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs - Drop JDK-8275535/RH2053256 patch which is now upstream - Include JDK-8271199 backport early ahead of 8u382 (RH2175317) - ** This tarball is embargoed until 2023-04-18 @ 1pm PT. ** - Resolves: rhbz#2185182 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Notice ELSA-2023-1909 highlights significant vulnerabilities found in Java 1.8 updates.. Oracle Linux, Java, Security Update, OpenJDK, Critical Alert. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 26, 2023 Critical Oracle
87

Debian: DSA-5257-2 Critical Update For AMGPU Driver Problems

The security update announced as DSA 5257-1 caused regressions on certain systems using the amdgpu driver. Updated packages are now available to correct this issue. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5257-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso October 23, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : linux Debian Bug : 1022025 The security update announced as DSA 5257-1 caused regressions on certain systems using the amdgpu driver. Updated packages are now available to correct this issue. For the stable distribution (bullseye), this problem has been fixed in version 5.10.149-2. We recommend that you upgrade your linux packages. For the detailed security status of linux please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/linux Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Following DSA-5257-1, a regression fix for Debian’s linux package is provided to rectify amdgpu driver issues.. Debian Security, Linux Update, AMDGPU Issues, Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 23, 2022 Critical Debian
198

Arch Linux 2021-07-21 High: Privilege Escalation In Linux Package

The package linux before version 5.13.4.arch1-1 is vulnerable to privilege escalation. . Arch Linux Security Advisory ASA-202107-48 ========================================= Severity: High Date : 2021-07-21 CVE-ID : CVE-2021-3609 CVE-2021-3612 CVE-2021-33909 Package : linux Type : privilege escalation Remote : No Link : https://security.archlinux.org/AVG-2181 Summary ====== The package linux before version 5.13.4.arch1-1 is vulnerable to privilege escalation. Resolution ========= Upgrade to 5.13.4.arch1-1. # pacman -Syu "linux> =5.13.4.arch1-1" The problems have been fixed upstream in version 5.13.4.arch1. Workaround ========= None. Description ========== - CVE-2021-3609 (privilege escalation) A race condition in net/can/bcm.c in the Linux kernel before version 5.13.2 allows for local privilege escalation to root. The CAN BCM networking protocol allows to register a CAN message receiver for a specified socket. The function bcm_rx_handler() is run for incoming CAN messages. Simultaneously to running this function, the socket can be closed and bcm_release() will be called. Inside bcm_release(), struct bcm_op and struct bcm_sock are freed while bcm_rx_handler() is still running, finally leading to multiple use-after-free's. - CVE-2021-3612 (privilege escalation) An out-of-bounds memory write security issue was found in the Linux kernel’s joystick devices subsystem before version 5.13.2, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. - CVE-2021-33909 (privilege escalation) An privilege escalation security issue has been found in the filesystem layer of the Linux kernel before version 5.13.4. An unprivileged local attacker can obtain full root privileges by creating, mounting, and deleting a deep directory structure whose total path length exceeds 1GB, which leads to an uncontrolled out-of-bounds write. Impact ===== An unprivilegedlocal attacker could obtain full root privileges or crash the system. References ========= https://www.openwall.com/lists/oss-security/2021/06/19/1 https://www.openwall.com/lists/oss-security/2021/06/19/2 https://github.com/nrb547/kernel-exploitation/blob/main/cve-2021-3609/cve-2021-3609.md https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.13.2&id=014f8baa9d240c4cf7180d37abd625fd4a4527c8 https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.12.17&id=d8a5cf5cfc07a296c78bd515671e374b8d8db022 https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.10.50&id=b52e0cf0bfc1ede495de36aec86f6013efa18f60 https://bugzilla.redhat.com/show_bug.cgi?id=1974079 https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.13.2&id=81acf1015233b3ee1d9834ba4fcca087a75c0c1b https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.12.17&id=b88243d8f1c7eb2a834fd7cd1ea9691554240d3a https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.10.50&id=b4c35e9e8061b2386da1aa0d708e991204e76c45 https:// https://https:// https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.13.4&id=71de462034c69525a5049fbdf3903c5833cbce04 https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.12.19&id=514b6531b1cbb64199db63bfdb80953d71998cca https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.10.52&id=174c34d9cda1b5818419b8f5a332ced10755e52f https://security.archlinux.org/CVE-2021-3609 https://security.archlinux.org/CVE-2021-3612 https://security.archlinux.org/CVE-2021-33909 . Debian Linux security bulletin highlights substantial privilege elevation threats within the core package. Immediate updates are essential for safeguarding systems.. Arch Linux Privilege Escalation, Linux Kernel Exploit, Security Advisory Details. . LinuxSecurity.com Team

Calendar%202 Jul 22, 2021 ArchLinux
198

Arch Linux: ASA-202105-18 Medium: djvulibre Arbitrary Code Risk

The package djvulibre before version 3.5.28-3 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-202105-18 ========================================= Severity: Medium Date : 2021-05-25 CVE-ID : CVE-2021-3500 CVE-2021-32490 CVE-2021-32491 CVE-2021-32492 CVE-2021-32493 Package : djvulibre Type : arbitrary code execution Remote : No Link : https://security.archlinux.org/AVG-1899 Summary ====== The package djvulibre before version 3.5.28-3 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 3.5.28-3. # pacman -Syu "djvulibre> =3.5.28-3" The problems have been fixed upstream but no release is available yet. Workaround ========= None. Description ========== - CVE-2021-3500 (arbitrary code execution) A security issue was found in djvulibre. A stack overflow in the function DJVU::DjVuDocument::get_djvu_file() may lead to an application crash and other consequences via a crafted djvu file. - CVE-2021-32490 (arbitrary code execution) A security issue was found in djvulibre. An out of bounds write in the function DJVU::filter_bv() may lead to an application crash and other consequences via a crafted djvu file. - CVE-2021-32491 (arbitrary code execution) A security issue was found in djvulibre. An integer overflow in the function render() in tools/ddjvu may lead to an application crash and other consequences via a crafted djvu file. - CVE-2021-32492 (arbitrary code execution) A security issue was found in djvulibre. An out of bounds read in the function DJVU::DataPool::has_data() may lead to an application crash and other consequences via a crafted djvu file. - CVE-2021-32493 (arbitrary code execution) A security issue was found in djvulibre. A heap buffer overflow in the function DJVU::GBitmap::decode() may lead to an application crash and other consequences via a crafted djvu file. Impact ===== An attacker could cause a crash, or possible execute arbitrary code, using a crafted djvufile. References ========= https://bugs.archlinux.org/task/70787 https://bugzilla.redhat.com/show_bug.cgi?id=1943685 https://bugzilla.redhat.com/show_bug.cgi?id=1943411 https://src.fedoraproject.org/rpms/djvulibre/blob/rawhide/f/djvulibre-3.5.27-djvuport-stack-overflow.patch https://bugzilla.redhat.com/show_bug.cgi?id=1943693 https://bugzilla.redhat.com/show_bug.cgi?id=1943408 https://bugzilla.redhat.com/attachment.cgi?id=1770184&action=diff https://src.fedoraproject.org/rpms/djvulibre/blob/rawhide/f/djvulibre-3.5.27-check-image-size.patch https://bugzilla.redhat.com/show_bug.cgi?id=1943684 https://bugzilla.redhat.com/show_bug.cgi?id=1943409 https://bugzilla.redhat.com/attachment.cgi?id=1770218&action=diff https://src.fedoraproject.org/rpms/djvulibre/blob/4b8d9b4bcb10c24739ca2dcd68a7fba4abe90860/f/djvulibre-3.5.27-integer-overflow.patch https://bugzilla.redhat.com/show_bug.cgi?id=1943686 https://bugzilla.redhat.com/show_bug.cgi?id=1943410 https://bugzilla.redhat.com/attachment.cgi?id=1770220&action=diff https://src.fedoraproject.org/rpms/djvulibre/blob/rawhide/f/djvulibre-3.5.27-check-input-pool.patch https://bugzilla.redhat.com/show_bug.cgi?id=1943690 https://bugzilla.redhat.com/show_bug.cgi?id=1943424 https://bugzilla.redhat.com/attachment.cgi?id=1774554&action=diff https://src.fedoraproject.org/rpms/djvulibre/blob/rawhide/f/djvulibre-3.5.27-unsigned-short-overflow.patch https://security.archlinux.org/CVE-2021-3500 https://security.archlinux.org/CVE-2021-32490 https://security.archlinux.org/CVE-2021-32491 https://security.archlinux.org/CVE-2021-32492 https://security.archlinux.org/CVE-2021-32493 . A security notice for Arch Linux indicates a medium-level threat associated with djvulibre, posing risks of arbitrary code execution.. Arbitrary Code Execution,Djvulibre,Arch Linux,Security Advisory. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 May 26, 2021 Medium ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200