Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 7 articles for you...
89

Fedora 42: git-lfs Critical Fix for Cross-Origin Bypass 2025-f8d1e1df04

Update to latest version (#2404637) Fix CVE-2025-47910, CVE-2025-47906, CVE-2025-26625. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-f8d1e1df04 2025-10-29 01:45:52.929013+00:00 -------------------------------------------------------------------------------- Name : git-lfs Product : Fedora 42 Version : 3.7.1 Release : 1.fc42 URL : https://git-lfs.com/ Summary : Git extension for versioning large files Description : Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server. -------------------------------------------------------------------------------- Update Information: Update to latest version (#2404637) Fix CVE-2025-47910, CVE-2025-47906, CVE-2025-26625 -------------------------------------------------------------------------------- ChangeLog: * Mon Oct 20 2025 Elliott Sales de Andrade - 3.7.1-1 - Update to latest version (#2404637) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2398691 - CVE-2025-47910 git-lfs: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398691 [ 2 ] Bug #2399372 - CVE-2025-47906 git-lfs: Unexpected paths returned from LookPath in os/exec [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2399372 [ 3 ] Bug #2404637 - git-lfs-3.7.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2404637 [ 4 ] Bug #2404744 - CVE-2025-26625 git-lfs: Git LFS may write to arbitrary files via crafted symlinks [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2404744 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f8d1e1df04' atthe command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fix for multiple critical issues in git-lfs for Fedora 42, enhancing security against potential exploits and access.. git-lfs Fedora security update critical threat, cross-origin protection, file access security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 29, 2025 Critical Fedora
89

Fedora 39: FEDORA-2023-731133ab8e Moderate: PlantUML Local Access

Update plantuml to the latest version v1.2023.11. This update also includes fixes for CVE-2023-3431 and CVE-2023-3432.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-731133ab8e 2023-10-01 03:37:03.210259 -------------------------------------------------------------------------------- Name : plantuml Product : Fedora 39 Version : 1.2023.11 Release : 1.fc39 URL : https://plantuml.com/ Summary : Program to generate UML diagram from a text description Description : PlantUML is a program allowing to draw UML diagrams, using a simple and human readable text description. It is extremely useful for code documenting, sketching project architecture during team conversations and so on. PlantUML supports the following diagram types - sequence diagram - use case diagram - class diagram - activity diagram - component diagram - state diagram -------------------------------------------------------------------------------- Update Information: Update plantuml to the latest version v1.2023.11. This update also includes fixes for CVE-2023-3431 and CVE-2023-3432. -------------------------------------------------------------------------------- ChangeLog: * Sat Sep 23 2023 blinxen - 1:1.2023.11-1 - Update to version 1.2023.11 (rhbz#2232105) * Fri Sep 22 2023 blinxen - 1:1.2023.7-4 - Migrate license specification to SPDX -------------------------------------------------------------------------------- References: [ 1 ] Bug #2218063 - CVE-2023-3432 plantuml: URL Restriction Bypass in plantuml/plantuml https://bugzilla.redhat.com/show_bug.cgi?id=2218063 [ 2 ] Bug #2218066 - CVE-2023-3431 plantuml: Local file read through %load_json in plantuml/plantuml https://bugzilla.redhat.com/show_bug.cgi?id=2218066 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program.Use su -c 'dnf upgrade --advisory FEDORA-2023-731133ab8e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . PlantUML has been upgraded to version 1.2023.11 in Fedora 39, resolving significant security vulnerabilities and improving overall user experience.. PlantUMl,Fedora 39,Software Updates. . LinuxSecurity.com Team

Calendar 2 Oct 01, 2023 Fedora
197

Debian: DLA-3158-1 Critical: Wkhtmltopdf Local File Access Issue

It was found that wkhtmltopdf, a command line utility to render HTML files into PDF, allowed local filesystem access by default. This update disables local filesystem access, but it can be enabled if necessary with the --enable-local-file-access or the --allow options. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3158-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort October 24, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : wkhtmltopdf Version : 0.12.5-1+deb10u1 CVE ID : CVE-2020-21365 It was found that wkhtmltopdf, a command line utility to render HTML files into PDF, allowed local filesystem access by default. This update disables local filesystem access, but it can be enabled if necessary with the --enable-local-file-access or the --allow options. For Debian 10 buster, this problem has been fixed in version 0.12.5-1+deb10u1. We recommend that you upgrade your wkhtmltopdf packages. For the detailed security status of wkhtmltopdf please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/wkhtmltopdf Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-6758-1 covers the OpenSSL critical vulnerability in local applications. Upgrade immediately!. Debian LTS, Wkhtmltopdf Security, Local Filesystem Access, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 24, 2022 Critical Debian LTS
197

Debian: DLA-2901-1 Moderate: Libxfont Local File Access Threat

n issue has been found in libxfont, an X11 font rasterisation library. By creating symlinks, a local attacker can open (but not read) local files as user root. This might create unwanted actions with special files like . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2901-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz January 25, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libxfont Version : 1:2.0.1-3+deb9u2 CVE ID : CVE-2017-16611 n issue has been found in libxfont, an X11 font rasterisation library. By creating symlinks, a local attacker can open (but not read) local files as user root. This might create unwanted actions with special files like /dev/watchdog. For Debian 9 stretch, this problem has been fixed in version 1:2.0.1-3+deb9u2. We recommend that you upgrade your libxfont packages. For the detailed security status of libxfont please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libxfont Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2902-1 tackles local directory traversal flaw in libgraphics. Urgent upgrade is advised.. Debian LTS, libxfont, local access, security fix. . LinuxSecurity.com Team

Calendar 2 Jan 25, 2022 Debian LTS
172

Ubuntu 20.04 LTS USN-4664-1: Aptdaemon Security Issues Detected

Several security issues were fixed in Aptdaemon.. =========================================================================Ubuntu Security Notice USN-4664-1 December 08, 2020 aptdaemon vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Aptdaemon. Software Description: - aptdaemon: transaction based package management service Details: Kevin Backhouse discovered that Aptdaemon incorrectly handled certain properties. A local attacker could use this issue to test for the presence of local files. (CVE-2020-16128) Kevin Backhouse discovered that Aptdaemon incorrectly handled permission checks. A local attacker could possibly use this issue to cause a denial of service. (CVE-2020-27349) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: aptdaemon 1.1.1+bzr982-0ubuntu34.1 Ubuntu 20.04 LTS: aptdaemon 1.1.1+bzr982-0ubuntu32.3 Ubuntu 18.04 LTS: aptdaemon 1.1.1+bzr982-0ubuntu19.5 Ubuntu 16.04 LTS: aptdaemon 1.1.1+bzr982-0ubuntu14.5 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4664-1 CVE-2020-16128, CVE-2020-27349 Package Information: https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu34.1 https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu32.3 https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu19.5 https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu14.5 . Ubuntu security bulletin concerning Aptdaemon vulnerabilities that may allow for local file exposure and possible denial ofservice scenarios.. Aptdaemon vulnerabilities, Ubuntu update, local file access issues. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 08, 2020 Important Ubuntu
200

Scientific Linux 6: SLSA-2020:2049-1 Critical: Thunderbird Security Update

Mozilla: Use-after-free during worker shutdown (CVE-2020-12387) * Mozilla: Memory safety bugs fixed in Firefox 76 and Firefox ESR 68.8 (CVE-2020-12395) * usrsctp: Buffer overflow in AUTH chunk input validation (CVE-2020-6831) * Mozilla: Arbitrary local file access with 'Copy as cURL' (CVE-2020-12392) * Mozilla: Sender Email Address Spoofing using encoded Unicode characters (CVE-2020-12397) [More...]. Synopsis: Critical: thunderbird security update Advisory ID: SLSA-2020:2049-1 Issue Date: 2020-05-11 CVE Numbers: None -- Security Fix(es): * Mozilla: Use-after-free during worker shutdown (CVE-2020-12387) * Mozilla: Memory safety bugs fixed in Firefox 76 and Firefox ESR 68.8 (CVE-2020-12395) * usrsctp: Buffer overflow in AUTH chunk input validation (CVE-2020-6831) * Mozilla: Arbitrary local file access with 'Copy as cURL' (CVE-2020-12392) * Mozilla: Sender Email Address Spoofing using encoded Unicode characters(CVE-2020-12397) -- SL6 x86_64 thunderbird-68.8.0-1.el6_10.x86_64.rpm thunderbird-debuginfo-68.8.0-1.el6_10.x86_64.rpm i386 thunderbird-68.8.0-1.el6_10.i686.rpm thunderbird-debuginfo-68.8.0-1.el6_10.i686.rpm - Scientific Linux Development Team . Important Thunderbird security patch addresses multiple vulnerabilities in Scientific Linux systems. Keep your data safe!. thunderbird security update, Scientific Linux advisory, buffer overflow fix, use-after-free vulnerability, local file access issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 11, 2020 Critical Scientific Linux
200

SciLinux Advisory SLSA-2020:2036-1: Critical Firefox Buffer Overflow Issues

Mozilla: Use-after-free during worker shutdown (CVE-2020-12387) * Mozilla: Memory safety bugs fixed in Firefox 76 and Firefox ESR 68.8 (CVE-2020-12395) * Mozilla: Buffer overflow in SCTP chunk input validation (CVE-2020-6831) * Mozilla: Arbitrary local file access with 'Copy as cURL' (CVE-2020-12392) SL6 x86_64 firefox-68.8.0-1.el6_10.x86_64.rpm firefox-debuginfo-68.8.0-1.el6_10. [More...]. Synopsis: Critical: firefox security update Advisory ID: SLSA-2020:2036-1 Issue Date: 2020-05-06 CVE Numbers: None -- Security Fix(es): * Mozilla: Use-after-free during worker shutdown (CVE-2020-12387) * Mozilla: Memory safety bugs fixed in Firefox 76 and Firefox ESR 68.8 (CVE-2020-12395) * Mozilla: Buffer overflow in SCTP chunk input validation (CVE-2020-6831) * Mozilla: Arbitrary local file access with 'Copy as cURL' (CVE-2020-12392) -- SL6 x86_64 firefox-68.8.0-1.el6_10.x86_64.rpm firefox-debuginfo-68.8.0-1.el6_10.x86_64.rpm firefox-68.8.0-1.el6_10.i686.rpm firefox-debuginfo-68.8.0-1.el6_10.i686.rpm i386 firefox-68.8.0-1.el6_10.i686.rpm firefox-debuginfo-68.8.0-1.el6_10.i686.rpm - Scientific Linux Development Team . Crucial Firefox patch addresses buffer overflow, memory safety, and unauthorized file access issues. firefox security update, buffer overflow, memory safety, local file access, SLSA advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 06, 2020 Critical Scientific Linux
98

Red Hat Enterprise Linux 8: RHSA-2020-2031-01 Critical: Firefox Update

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Critical: firefox security update Advisory ID: RHSA-2020:2031-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2031 Issue date: 2020-05-06 CVE Names: CVE-2020-6831 CVE-2020-12387 CVE-2020-12392 CVE-2020-12395 ==================================================================== 1. Summary: An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 68.8.0 ESR. Security Fix(es): * Mozilla: Use-after-free during worker shutdown (CVE-2020-12387) * Mozilla: Memory safety bugs fixed in Firefox 76 and Firefox ESR 68.8 (CVE-2020-12395) * Mozilla: Buffer overflow in SCTP chunk input validation (CVE-2020-6831) * Mozilla: Arbitrary local file access with 'Copy as cURL' (CVE-2020-12392) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4.Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, Firefox must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1831761 - CVE-2020-12387 Mozilla: Use-after-free during worker shutdown 1831763 - CVE-2020-6831 Mozilla: Buffer overflow in SCTP chunk input validation 1831764 - CVE-2020-12392 Mozilla: Arbitrary local file access with 'Copy as cURL' 1831765 - CVE-2020-12395 Mozilla: Memory safety bugs fixed in Firefox 76 and Firefox ESR 68.8 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: firefox-68.8.0-1.el8_2.src.rpm aarch64: firefox-68.8.0-1.el8_2.aarch64.rpm firefox-debuginfo-68.8.0-1.el8_2.aarch64.rpm firefox-debugsource-68.8.0-1.el8_2.aarch64.rpm ppc64le: firefox-68.8.0-1.el8_2.ppc64le.rpm firefox-debuginfo-68.8.0-1.el8_2.ppc64le.rpm firefox-debugsource-68.8.0-1.el8_2.ppc64le.rpm s390x: firefox-68.8.0-1.el8_2.s390x.rpm firefox-debuginfo-68.8.0-1.el8_2.s390x.rpm firefox-debugsource-68.8.0-1.el8_2.s390x.rpm x86_64: firefox-68.8.0-1.el8_2.x86_64.rpm firefox-debuginfo-68.8.0-1.el8_2.x86_64.rpm firefox-debugsource-68.8.0-1.el8_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-6831 https://access.redhat.com/security/cve/CVE-2020-12387 https://access.redhat.com/security/cve/CVE-2020-12392 https://access.redhat.com/security/cve/CVE-2020-12395 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXrJ40tzjgjWX9erEAQhPEg/5AV9V68w1Pwr0fBV0sldXKFnPF+xJ2/2r eV9Bv46+Tb0gOlak7cLqmbL3FCNhNH2qV2b48UKrvfHZgWu/bIozLyq+JmCeExrk o0II7XaKja5hBdvKqlKX/4q5sm9PWR+Oay6kX6cR6PwZg91mbJ81QdRuCWBqvCXM 251NMmjzaFBnlLmfhBq/5cRxiNB36UMwn3RTB3Ai0z94WG3XYIEIVujBOjMlaxEq hn78HOUz34AuCu+kvaJwH3/L3Qtqu2FChlT56bk+TmYx+02mezS6ivhF7+gmal47 379sI7tKEY7CgqFWctrxAeGLzKI/zVR0ucoY9AFrJA1YaY36d6RTsdAQlrX76S6z 4SjhXXKNSnWlGqLkJtIu5oBFPXeGs6zUm8bvWLutQXPmQcUL1CwsCV72BTzzAHIm zxOE04EU0b3f2UWObI3VUYjbtOxj+YUEyBNdNRaN42JEJgq+S1XjHx+nsdBfXJqY HZ28fJ8ddzfDiGzkbczrYd8aKcIBIQ6qSbt0kT2ddg4Zm+TYHCk7f0nLGp00Fhwe k3RjH2q9f+8s/D/XcHjoOvgJaZ4gispSLdxRM6vZeHoS4whcH5mbaCDeU7IMUU+J s03BH0QOOz5ShDaIpuWzMYitQi5SwZCoxhvtKOSJio2ejhiIY8A+aBirfV0BfsIh NOHKwK5q/UY=XmB/ -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Important Firefox security patch now released for Red Hat Enterprise Linux 8 to tackle various vulnerabilities efficiently.. Red Hat Update, firefox security, critical update, linux enterprise, security patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 06, 2020 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here