Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 32 articles for you...
100

SUSE Enterprise Linux Micro 6.2 Systemd Major Vulnerability CVE-2026-4105

An update that solves two vulnerabilities, contains one feature and has three fixes can now be installed.. # Security update for systemd Announcement ID: SUSE-SU-2026:20998-1 Release Date: 2026-04-07T15:10:12Z Rating: important References: * bsc#1255326 * bsc#1258344 * bsc#1259418 * bsc#1259650 * bsc#1259697 * jsc#PED-14853 Cross-References: * CVE-2026-29111 * CVE-2026-4105 CVSS scores: * CVE-2026-29111 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-29111 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-29111 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4105 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-4105 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4105 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that solves two vulnerabilities, contains one feature and has three fixes can now be installed. ## Description: This update for systemd fixes the following issues: Update to systemd v257.13: Security issues: * CVE-2026-4105: privilege escalation due to improper access control in RegisterMachine D-Bus method (bsc#1259650). * CVE-2026-29111: local unprivileged user can trigger an assert in systemd (bsc#1259418). * udev: local root execution via malicious hardware devices and unsanitized kernel output (bsc#1259697). Non security issues: * Avoid shipping (empty) directories and ghost files in /var (jsc#PED-14853). * Sign systemd-boot EFI binary on aarch64 (bsc#1258344) * terminal-util: stop doing 0/upper bound check in tty_is_vc() (bsc#1255326) Changelog: * 6941d92dc2 machined: reject invalid class types when registering machines (bsc#1259650 CVE-2026-4105) * 03bb697b8d udev: check for invalid chars in various fields received from the kernel(bsc#1259697) * 54588d2ded core: validate input cgroup path more prudently (bsc#1259418 CVE-2026-29111) * fb9d92682b terminal-util: stop doing 0/upper bound check in tty_is_vc() (bsc#1255326) For a complete list of changes, visit: ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-485=1 ## Package List: * SUSE Linux Micro Extras 6.2 (aarch64 ppc64le s390x x86_64) * systemd-debuginfo-257.13-160000.1.1 * systemd-devel-257.13-160000.1.1 * systemd-debugsource-257.13-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-29111.html * https://www.suse.com/security/cve/CVE-2026-4105.html * https://bugzilla.suse.com/show_bug.cgi?id=1255326 * https://bugzilla.suse.com/show_bug.cgi?id=1258344 * https://bugzilla.suse.com/show_bug.cgi?id=1259418 * https://bugzilla.suse.com/show_bug.cgi?id=1259650 * https://bugzilla.suse.com/show_bug.cgi?id=1259697 * https://jira.suse.com/browse/PED-14853 . SUSE updates systemd to fix privilege escalation issues and more for Linux Micro 6.2.. SUSE systemd update important security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 13, 2026 Important SuSE
100

SUSE Linux Micro 6.2 systemd Important Privilege Escalation CVE-2026-4105

An update that solves two vulnerabilities, contains one feature and has three fixes can now be installed.. # Security update for systemd Announcement ID: SUSE-SU-2026:21003-1 Release Date: 2026-04-07T15:08:39Z Rating: important References: * bsc#1255326 * bsc#1258344 * bsc#1259418 * bsc#1259650 * bsc#1259697 * jsc#PED-14853 Cross-References: * CVE-2026-29111 * CVE-2026-4105 CVSS scores: * CVE-2026-29111 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-29111 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-29111 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4105 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-4105 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4105 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities, contains one feature and has three fixes can now be installed. ## Description: This update for systemd fixes the following issues: Update to systemd v257.13: Security issues: * CVE-2026-4105: privilege escalation due to improper access control in RegisterMachine D-Bus method (bsc#1259650). * CVE-2026-29111: local unprivileged user can trigger an assert in systemd (bsc#1259418). * udev: local root execution via malicious hardware devices and unsanitized kernel output (bsc#1259697). Non security issues: * Avoid shipping (empty) directories and ghost files in /var (jsc#PED-14853). * Sign systemd-boot EFI binary on aarch64 (bsc#1258344) * terminal-util: stop doing 0/upper bound check in tty_is_vc() (bsc#1255326) Changelog: * 6941d92dc2 machined: reject invalid class types when registering machines (bsc#1259650 CVE-2026-4105) * 03bb697b8d udev: check for invalid chars in various fields received from the kernel (bsc#1259697) * 54588d2ded core:validate input cgroup path more prudently (bsc#1259418 CVE-2026-29111) * fb9d92682b terminal-util: stop doing 0/upper bound check in tty_is_vc() (bsc#1255326) For a complete list of changes, visit: ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-485=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * systemd-portable-257.13-160000.1.1 * libsystemd0-debuginfo-257.13-160000.1.1 * libsystemd0-257.13-160000.1.1 * udev-257.13-160000.1.1 * systemd-debugsource-257.13-160000.1.1 * libudev1-debuginfo-257.13-160000.1.1 * systemd-container-257.13-160000.1.1 * systemd-experimental-debuginfo-257.13-160000.1.1 * udev-debuginfo-257.13-160000.1.1 * systemd-experimental-257.13-160000.1.1 * systemd-container-debuginfo-257.13-160000.1.1 * systemd-journal-remote-257.13-160000.1.1 * systemd-portable-debuginfo-257.13-160000.1.1 * systemd-journal-remote-debuginfo-257.13-160000.1.1 * systemd-debuginfo-257.13-160000.1.1 * systemd-257.13-160000.1.1 * libudev1-257.13-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-29111.html * https://www.suse.com/security/cve/CVE-2026-4105.html * https://bugzilla.suse.com/show_bug.cgi?id=1255326 * https://bugzilla.suse.com/show_bug.cgi?id=1258344 * https://bugzilla.suse.com/show_bug.cgi?id=1259418 * https://bugzilla.suse.com/show_bug.cgi?id=1259650 * https://bugzilla.suse.com/show_bug.cgi?id=1259697 * https://jira.suse.com/browse/PED-14853 . An important update for SUSE systemd fixes security flaws allowing privilege escalation and local execution risks.. SUSE Linux systemd update privilege escalation security. . Severity: Important.LinuxSecurity.com Team

Calendar%202 Apr 13, 2026 Important SuSE
100

SUSE: TIFF Low Segmentation Fault Memory Leak Issue 2025:03345-1

* bsc#1247582 * bsc#1248117 * bsc#1248330 Cross-References: . # Security update for tiff Announcement ID: SUSE-SU-2025:03345-1 Release Date: 2025-09-24T13:56:00Z Rating: low References: * bsc#1247582 * bsc#1248117 * bsc#1248330 Cross-References: * CVE-2025-8534 * CVE-2025-8961 * CVE-2025-9165 CVSS scores: * CVE-2025-8534 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-8534 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-8534 ( NVD ): 1.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8534 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-8961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-8961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-8961 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8961 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-9165 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-9165 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-9165 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-9165 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for tiff fixes the following issues: * CVE-2025-9165: local execution manipulation leading to memory leak (bsc#1248330). * CVE-2025-8534: null pointer dereference in function PS_Lvl2page (bsc#1247582). * CVE-2025-8961: segmentation fault via main function of tiffcrop utility (bsc#1248117). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3345=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3345=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3345=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3345=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-3345=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-3345=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-3345=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-3345=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-3345=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) *libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 * Basesystem Module 15-SP6 (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.55.1 * libtiff5-32bit-4.0.9-150000.45.55.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 * Basesystem Module 15-SP7 (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.55.1 * libtiff5-32bit-4.0.9-150000.45.55.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 * SUSELinux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libtiff5-debuginfo-4.0.9-150000.45.55.1 * tiff-debuginfo-4.0.9-150000.45.55.1 * libtiff5-4.0.9-150000.45.55.1 * tiff-debugsource-4.0.9-150000.45.55.1 ## References: * https://www.suse.com/security/cve/CVE-2025-8534.html * https://www.suse.com/security/cve/CVE-2025-8961.html * https://www.suse.com/security/cve/CVE-2025-9165.html * https://bugzilla.suse.com/show_bug.cgi?id=1247582 * https://bugzilla.suse.com/show_bug.cgi?id=1248117 * https://bugzilla.suse.com/show_bug.cgi?id=1248330 . New release for tiff addresses several problems such as memory corruption and crash issues on SUSE platforms. Installation is advised.. SUSE update TIFF memory leak segmentation fault. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Sep 24, 2025 Low SuSE
197

Debian LTS DLA-4169-1: dropbear local command execution risk fixed

Marcin Nowak discovered that dbclient(1) hostname arguments with a comma (for multihop) are passed to the shell which could result in running arbitrary shell commands locally. That could be a security issue in situations where dbclient(1) is passed untrusted hostname arguments. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4169-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin May 17, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : dropbear Version : 2020.81-3+deb11u3 CVE ID : CVE-2025-47203 Marcin Nowak discovered that dbclient(1) hostname arguments with a comma (for multihop) are passed to the shell which could result in running arbitrary shell commands locally. That could be a security issue in situations where dbclient(1) is passed untrusted hostname arguments. For Debian 11 bullseye, this problem has been fixed in version 2020.81-3+deb11u3. We recommend that you upgrade your dropbear packages. For the detailed security status of dropbear please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/dropbear Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Potential vulnerability in DBclient hostname parameters of dropbear could allow for local command execution. Debian users are advised to update.. Debian LTS, dropbear update, security patch, local commands, command execution. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 17, 2025 Important Debian LTS
100

SUSE: 2022:3208-2 Important: openssl-1_0 Security Vulnerability Resolve

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libnl-1_1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3207-1 Rating: moderate References: #1020123 Cross-References: CVE-2017-0386 CVSS scores: CVE-2017-0386 (NVD) : 7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2017-0386 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libnl-1_1 fixes the following issues: - CVE-2017-0386: Fixed an issue that could enable a local malicious application to execute arbitrary code within the context of a different process. This only affects setups were libnl is passed untrusted arguments. (bsc#1020123) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-3207=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-3207=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libnl-1_1-debugsource-1.1.4-6.3.1 libnl-1_1-devel-1.1.4-6.3.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libnl-1_1-debugsource-1.1.4-6.3.1 libnl1-1.1.4-6.3.1 libnl1-debuginfo-1.1.4-6.3.1 - SUSE Linux EnterpriseServer 12-SP5 (s390x x86_64): libnl1-32bit-1.1.4-6.3.1 libnl1-debuginfo-32bit-1.1.4-6.3.1 References: https://www.suse.com/security/cve/CVE-2017-0386.html https://bugzilla.suse.com/1020123 . Patch for libnl-1_1 resolves localized execution flaws in SUSE 12-SP5, mitigating arbitrary code execution dangers.. SUSE Update, libnl Security, Local Execution Fix, Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 08, 2022 Important SuSE
172

Ubuntu 22.04 LTS USN-5426-1 Critical: Needrestart Execution Risk

needrestart could be made to run programs.. =========================================================================Ubuntu Security Notice USN-5426-1 May 17, 2022 needrestart vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 21.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: needrestart could be made to run programs. Software Description: - needrestart: check which daemons need to be restarted after library upgrades Details: Jakub Wilk discovered that needrestart incorrectly used some regular expressions. A local attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: needrestart 3.5-5ubuntu2.1 Ubuntu 21.10: needrestart 3.5-4ubuntu2.1 Ubuntu 20.04 LTS: needrestart 3.4-6ubuntu0.1 Ubuntu 18.04 LTS: needrestart 3.1-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5426-1 CVE-2022-30688 Package Information: https://launchpad.net/ubuntu/+source/needrestart/3.5-5ubuntu2.1 https://launchpad.net/ubuntu/+source/needrestart/3.5-4ubuntu2.1 https://launchpad.net/ubuntu/+source/needrestart/3.4-6ubuntu0.1 https://launchpad.net/ubuntu/+source/needrestart/3.1-1ubuntu0.1 . Critical notice for Ubuntu users concerning the needrestart flaw that permits local exploits to run unauthorized applications.. Needrestart Vulnerability, Local Execution Risk, Ubuntu Security Notice. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 17, 2022 Critical Ubuntu
91

Gentoo: GLSA-202107-03 High: Libqb Local Code Execution Threat

An insecure temporary file usage has been reported in libqb possibly allowing local code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202107-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: libqb: Insecure temporary file Date: July 03, 2021 Bugs: #699860 ID: 202107-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An insecure temporary file usage has been reported in libqb possibly allowing local code execution. Background ========= libqb is a library with the primary purpose of providing high-performance, reusable features for client-server architecture, such as logging, tracing, inter-process communication (IPC), and polling. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-cluster/libqb < 1.0.5 > = 1.0.5 Description ========== It was discovered that libqb used predictable filenames (under /dev/shm and /tmp) without O_EXCL. Impact ===== A local attacker could perform symlink attacks to overwrite arbitrary files with the privileges of the user running the application linked against libqb. Workaround ========= There is no known workaround at this time. Resolution ========= All libqb users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-cluster/libqb-1.0.5" References ========= [ 1 ] CVE-2019-12779 https://nvd.nist.gov/vuln/detail/CVE-2019-12779 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo SecurityWebsite: https://security.gentoo.org/glsa/202107-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2021 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Libqb faces a vulnerability related to improper handling of temporary files, enabling potential local execution; users are advised to upgrade.. libqb,local Execution,gentoo security,high severity,insecure file. . LinuxSecurity.com Team

Calendar%202 Jul 03, 2021 Gentoo
203

Mageia 7, 8: 2021-0128 Moderate Local Code Execution via Libcaca Overflow

A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context (CVE-2021-3410). References: - https://bugs.mageia.org/show_bug.cgi?id=28556 . MGASA-2021-0128 - Updated libcaca packages fix a security vulnerability Publication date: 12 Mar 2021 URL: https://advisories.mageia.org/MGASA-2021-0128.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-3410 A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context (CVE-2021-3410). References: - https://bugs.mageia.org/show_bug.cgi?id=28556 - https://lists.debian.org/debian-lts-announce/2021/03/msg00006.html - https://www.cve.org/CVERecord?id=CVE-2021-3410 SRPMS: - 8/core/libcaca-0.99-0.beta19.5.1.mga8 - 7/core/libcaca-0.99-0.beta19.3.1.mga7 . Revised libcaca distributions fix a buffer overflow vulnerability, enabling local arbitrary code execution in Mageia systems. Discover further details.. libcaca security update, buffer overflow fix, Mageia security advisory, software vulnerability update, caca_resize issue. . LinuxSecurity.com Team

Calendar%202 Mar 11, 2021 Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200