Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 43 Log4cxx Critical XML Character Issue Fix FEDORA-2026-31a8569c4b

Update to log4cxx 1.7.0. Fixes CVE-2026-40023: XMLLayout did not escape characters forbidden by the XML 1.0 specification, which could cause conforming XML parsers to reject the produced document, silently dropping log records.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-31a8569c4b 2026-07-18 00:27:50.464532+00:00 -------------------------------------------------------------------------------- Name : log4cxx Product : Fedora 43 Version : 1.7.0 Release : 2.fc43 URL : http://logging.apache.org/log4cxx/index.html Summary : A port to C++ of the Log4j project Description : Log4cxx is a popular logging package written in C++. One of its distinctive features is the notion of inheritance in loggers. Using a logger hierarchy it is possible to control which log statements are output at arbitrary granularity. This helps reduce the volume of logged output and minimize the cost of logging. -------------------------------------------------------------------------------- Update Information: Update to log4cxx 1.7.0. Fixes CVE-2026-40023: XMLLayout did not escape characters forbidden by the XML 1.0 specification, which could cause conforming XML parsers to reject the produced document, silently dropping log records. No ABI-relevant changes; liblog4cxx SONAME (%{sover}) is unchanged. -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 3 2026 Till Hofmann - 1.7.0-2 - Skip 2GB-message test on 32-bit architectures * Fri May 22 2026 Till Hofmann - 1.7.0-1 - Update to 1.7.0 * Fri Jan 16 2026 Fedora Release Engineering - 1.6.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2457923 - CVE-2026-40023 log4cxx: Apache Log4cxx: Log processing impairment due to unsanitized XML characters [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2457923 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-31a8569c4b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Addressing the critical XML parsing issue in log4cxx 1.7.0 on Fedora 43 with a severity rating and update instructions.. Fedora log4cxx XML log processing critical update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 17, 2026 Critical Fedora
89

Fedora 38: FEDORA-2023-6b4d3ca766 Moderate Netconsole Daemon Update

Update to 0.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-6b4d3ca766 2023-11-04 03:41:29.345912 -------------------------------------------------------------------------------- Name : netconsd Product : Fedora 38 Version : 0.4 Release : 1.fc38 URL : Summary : The Netconsole Daemon Description : This is a daemon for receiving and processing logs from the Linux Kernel, as emitted over a network by the kernel's netconsole module. It supports both the old "legacy" text-only format, and the new extended format added in v4.4. The core of the daemon does nothing but process messages and drop them: in order to make the daemon useful, the user must supply one or more "output modules". These modules are shared object files which expose a small ABI that is called by netconsd with the content and metadata for netconsole messages it receives. -------------------------------------------------------------------------------- Update Information: Update to 0.4 -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 25 2023 Davide Cavalca - 0.4-1 - Update to 0.4 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-6b4d3ca766' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest revision of netconsd 0.4 for Fedora 38 enhances log handling features. Please refer to the documentation for instructions on performing the upgrade.. Fedora Update, Log Processing, Linux Daemon. . LinuxSecurity.com Team

Calendar%202 Nov 04, 2023 Fedora
89

Fedora 37: FEDORA-2023-ebbe7e9887 Critical Update for Netconsole Daemon

Update to 0.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-ebbe7e9887 2023-11-03 01:09:39.384885 -------------------------------------------------------------------------------- Name : netconsd Product : Fedora 37 Version : 0.4 Release : 1.fc37 URL : Summary : The Netconsole Daemon Description : This is a daemon for receiving and processing logs from the Linux Kernel, as emitted over a network by the kernel's netconsole module. It supports both the old "legacy" text-only format, and the new extended format added in v4.4. The core of the daemon does nothing but process messages and drop them: in order to make the daemon useful, the user must supply one or more "output modules". These modules are shared object files which expose a small ABI that is called by netconsd with the content and metadata for netconsole messages it receives. -------------------------------------------------------------------------------- Update Information: Update to 0.4 -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 25 2023 Davide Cavalca - 0.4-1 - Update to 0.4 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-ebbe7e9887' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest update for netconsd v0.4 on Fedora 37 enhances the ability to log kernel messages transmitted via the network.. Fedora Update, Netconsole Daemon, Kernel Security, System Logging, Software Maintenance. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 03, 2023 Critical Fedora
89

Fedora 38: 2023-f25098f499 Critical Update for Netconsole Daemon

Update to 0.2 to address CVE-2023-28753; Fixes: RHBZ#2181655. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-f25098f499 2023-04-02 00:15:32.501413 --------------------------------------------------------------------------------Name : netconsd Product : Fedora 38 Version : 0.2 Release : 1.fc38 URL : https://facebookmicrosites.github.io/netconsd/ Summary : The Netconsole Daemon Description : This is a daemon for receiving and processing logs from the Linux Kernel, as emitted over a network by the kernel's netconsole module. It supports both the old "legacy" text-only format, and the new extended format added in v4.4. The core of the daemon does nothing but process messages and drop them: in order to make the daemon useful, the user must supply one or more "output modules". These modules are shared object files which expose a small ABI that is called by netconsd with the content and metadata for netconsole messages it receives. --------------------------------------------------------------------------------Update Information: Update to 0.2 to address CVE-2023-28753; Fixes: RHBZ#2181655 --------------------------------------------------------------------------------ChangeLog: * Fri Mar 24 2023 Davide Cavalca - 0.2-1 - Update to 0.2 to address CVE-2023-28753; Fixes: RHBZ#2181655 --------------------------------------------------------------------------------References: [ 1 ] Bug #2181655 - netconsd-0.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2181655 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-f25098f499' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. Moredetails on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . In response to CVE-2023-28753, the update refines netconsd, boosting log management functionality and resolving urgent vulnerabilities.. netconsole Daemon Update,Fedora Security Notification,CVE-2023-28753 Fix,Log Processing Daemon. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 02, 2023 Critical Fedora
87

Ubuntu: DSA-3089-2 Urgent: Syslog Buffer Overflow Vulnerability

Mancha discovered a vulnerability in rsyslog, a system for log processing. This vulnerability is an integer overflow that can be triggered by malformed messages to a server, if this one accepts data from untrusted sources, provoking message loss. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3047-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Luciano Bello October 08, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : rsyslog CVE ID : CVE-2014-3683 Mancha discovered a vulnerability in rsyslog, a system for log processing. This vulnerability is an integer overflow that can be triggered by malformed messages to a server, if this one accepts data from untrusted sources, provoking message loss. This vulnerability can be seen as an incomplete fix of CVE-2014-3634 (DSA 3040-1). For the stable distribution (wheezy), this problem has been fixed in version 5.8.11-3+deb7u2. For the testing distribution (jessie), this problem has been fixed in version 8.4.2-1. For the unstable distribution (sid), this problem has been fixed in version 8.4.2-1. We recommend that you upgrade your rsyslog packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance the rsyslog configuration to address an integer overflow vulnerability that could compromise log handling, ultimately preventing message loss.. rsyslog security update, debian advisory, integer overflow issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 08, 2014 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200