Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 164 articles for you...
219

Rocky Linux 8 openssl Moderate DoS Vulnerability RLSA-2026-38503

Moderate: openssl security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:38503", "synopsis": "Moderate: openssl security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for openssl.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.\n\nSecurity Fix(es):\n\n* openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing (CVE-2026-28390)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2456314", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2456314", "description": ""}], "cves": [{"name": "CVE-2026-28390", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28390", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-476"}], "references": [], "publishedAt": "2026-07-14T06:00:42.485918Z", "rpms": {"Rocky Linux 8": {"nvras": ["openssl-1:1.1.1k-17.el8_10.aarch64.rpm", "openssl-1:1.1.1k-17.el8_10.src.rpm", "openssl-1:1.1.1k-17.el8_10.x86_64.rpm", "openssl-debuginfo-1:1.1.1k-17.el8_10.aarch64.rpm", "openssl-debuginfo-1:1.1.1k-17.el8_10.i686.rpm", "openssl-debuginfo-1:1.1.1k-17.el8_10.x86_64.rpm", "openssl-perl-1:1.1.1k-17.el8_10.aarch64.rpm", "openssl-perl-1:1.1.1k-17.el8_10.x86_64.rpm", "openssl-debugsource-1:1.1.1k-17.el8_10.aarch64.rpm", "openssl-debugsource-1:1.1.1k-17.el8_10.i686.rpm", "openssl-debugsource-1:1.1.1k-17.el8_10.x86_64.rpm","openssl-devel-1:1.1.1k-17.el8_10.aarch64.rpm", "openssl-devel-1:1.1.1k-17.el8_10.i686.rpm", "openssl-devel-1:1.1.1k-17.el8_10.x86_64.rpm", "openssl-libs-1:1.1.1k-17.el8_10.aarch64.rpm", "openssl-libs-1:1.1.1k-17.el8_10.i686.rpm", "openssl-libs-1:1.1.1k-17.el8_10.x86_64.rpm", "openssl-libs-debuginfo-1:1.1.1k-17.el8_10.aarch64.rpm", "openssl-libs-debuginfo-1:1.1.1k-17.el8_10.i686.rpm", "openssl-libs-debuginfo-1:1.1.1k-17.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Moderate openssl update for Rocky Linux addresses denial of service issue related to NULL pointer dereference.. openssl security update, Rocky Linux 8, denial of service. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 14, 2026 moderate Rocky Linux
202

openSUSE php8 Moderate Buffer Allocation Issue 2026-2880-1 CVE-2026-14355

An update that solves one vulnerability can now be installed.. # Security update for php8 Announcement ID: SUSE-SU-2026:2880-1 Release Date: 2026-07-13T09:39:59Z Rating: moderate References: * bsc#1270351 Cross-References: * CVE-2026-14355 CVSS scores: * CVE-2026-14355 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-14355 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-14355 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-14355 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for php8 fixes the following issue * CVE-2026-14355: The AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw (bsc#1270351). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2880=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * php8-bcmath-debuginfo-8.0.30-150400.4.68.1 * php8-zip-debuginfo-8.0.30-150400.4.68.1 * php8-mysql-8.0.30-150400.4.68.1 * php8-pcntl-8.0.30-150400.4.68.1 * php8-bcmath-8.0.30-150400.4.68.1 * php8-embed-debuginfo-8.0.30-150400.4.68.1 * apache2-mod_php8-8.0.30-150400.4.68.1 * php8-openssl-debuginfo-8.0.30-150400.4.68.1 * php8-opcache-debuginfo-8.0.30-150400.4.68.1 * php8-sockets-debuginfo-8.0.30-150400.4.68.1 * php8-fileinfo-8.0.30-150400.4.68.1 * php8-phar-8.0.30-150400.4.68.1 * php8-ctype-debuginfo-8.0.30-150400.4.68.1 * php8-ftp-debuginfo-8.0.30-150400.4.68.1 * php8-fileinfo-debuginfo-8.0.30-150400.4.68.1 * php8-fpm-debuginfo-8.0.30-150400.4.68.1 *php8-bz2-debuginfo-8.0.30-150400.4.68.1 * php8-readline-debuginfo-8.0.30-150400.4.68.1 * php8-tidy-8.0.30-150400.4.68.1 * php8-phar-debuginfo-8.0.30-150400.4.68.1 * php8-calendar-8.0.30-150400.4.68.1 * php8-gettext-debuginfo-8.0.30-150400.4.68.1 * php8-xsl-8.0.30-150400.4.68.1 * php8-fastcgi-debugsource-8.0.30-150400.4.68.1 * php8-gmp-debuginfo-8.0.30-150400.4.68.1 * php8-shmop-debuginfo-8.0.30-150400.4.68.1 * php8-posix-debuginfo-8.0.30-150400.4.68.1 * php8-readline-8.0.30-150400.4.68.1 * php8-bz2-8.0.30-150400.4.68.1 * php8-debuginfo-8.0.30-150400.4.68.1 * php8-sysvmsg-debuginfo-8.0.30-150400.4.68.1 * php8-sysvshm-8.0.30-150400.4.68.1 * php8-zip-8.0.30-150400.4.68.1 * php8-pcntl-debuginfo-8.0.30-150400.4.68.1 * php8-enchant-debuginfo-8.0.30-150400.4.68.1 * php8-opcache-8.0.30-150400.4.68.1 * php8-test-8.0.30-150400.4.68.1 * php8-ldap-8.0.30-150400.4.68.1 * php8-tokenizer-8.0.30-150400.4.68.1 * php8-pdo-debuginfo-8.0.30-150400.4.68.1 * php8-sodium-debuginfo-8.0.30-150400.4.68.1 * php8-curl-debuginfo-8.0.30-150400.4.68.1 * php8-devel-8.0.30-150400.4.68.1 * php8-sqlite-debuginfo-8.0.30-150400.4.68.1 * apache2-mod_php8-debuginfo-8.0.30-150400.4.68.1 * php8-dba-8.0.30-150400.4.68.1 * php8-sockets-8.0.30-150400.4.68.1 * php8-calendar-debuginfo-8.0.30-150400.4.68.1 * php8-sysvsem-8.0.30-150400.4.68.1 * php8-xmlreader-debuginfo-8.0.30-150400.4.68.1 * php8-xmlwriter-debuginfo-8.0.30-150400.4.68.1 * php8-gd-debuginfo-8.0.30-150400.4.68.1 * php8-ftp-8.0.30-150400.4.68.1 * php8-enchant-8.0.30-150400.4.68.1 * php8-odbc-8.0.30-150400.4.68.1 * php8-pgsql-8.0.30-150400.4.68.1 * php8-soap-8.0.30-150400.4.68.1 * php8-dba-debuginfo-8.0.30-150400.4.68.1 * php8-gettext-8.0.30-150400.4.68.1 * php8-ctype-8.0.30-150400.4.68.1 * php8-snmp-8.0.30-150400.4.68.1 * php8-dom-debuginfo-8.0.30-150400.4.68.1 * php8-tidy-debuginfo-8.0.30-150400.4.68.1 *php8-tokenizer-debuginfo-8.0.30-150400.4.68.1 * php8-snmp-debuginfo-8.0.30-150400.4.68.1 * php8-dom-8.0.30-150400.4.68.1 * php8-xmlwriter-8.0.30-150400.4.68.1 * apache2-mod_php8-debugsource-8.0.30-150400.4.68.1 * php8-sysvsem-debuginfo-8.0.30-150400.4.68.1 * php8-xmlreader-8.0.30-150400.4.68.1 * php8-fastcgi-debuginfo-8.0.30-150400.4.68.1 * php8-pgsql-debuginfo-8.0.30-150400.4.68.1 * php8-sysvmsg-8.0.30-150400.4.68.1 * php8-xsl-debuginfo-8.0.30-150400.4.68.1 * php8-openssl-8.0.30-150400.4.68.1 * php8-fastcgi-8.0.30-150400.4.68.1 * php8-shmop-8.0.30-150400.4.68.1 * php8-8.0.30-150400.4.68.1 * php8-fpm-debugsource-8.0.30-150400.4.68.1 * php8-debugsource-8.0.30-150400.4.68.1 * php8-exif-8.0.30-150400.4.68.1 * php8-iconv-debuginfo-8.0.30-150400.4.68.1 * php8-odbc-debuginfo-8.0.30-150400.4.68.1 * php8-sqlite-8.0.30-150400.4.68.1 * php8-zlib-8.0.30-150400.4.68.1 * php8-sysvshm-debuginfo-8.0.30-150400.4.68.1 * php8-fpm-8.0.30-150400.4.68.1 * php8-sodium-8.0.30-150400.4.68.1 * php8-embed-8.0.30-150400.4.68.1 * php8-soap-debuginfo-8.0.30-150400.4.68.1 * php8-embed-debugsource-8.0.30-150400.4.68.1 * php8-exif-debuginfo-8.0.30-150400.4.68.1 * php8-mysql-debuginfo-8.0.30-150400.4.68.1 * php8-intl-debuginfo-8.0.30-150400.4.68.1 * php8-cli-8.0.30-150400.4.68.1 * php8-iconv-8.0.30-150400.4.68.1 * php8-ldap-debuginfo-8.0.30-150400.4.68.1 * php8-curl-8.0.30-150400.4.68.1 * php8-intl-8.0.30-150400.4.68.1 * php8-posix-8.0.30-150400.4.68.1 * php8-gmp-8.0.30-150400.4.68.1 * php8-gd-8.0.30-150400.4.68.1 * php8-mbstring-8.0.30-150400.4.68.1 * php8-zlib-debuginfo-8.0.30-150400.4.68.1 * php8-cli-debuginfo-8.0.30-150400.4.68.1 * php8-pdo-8.0.30-150400.4.68.1 * php8-mbstring-debuginfo-8.0.30-150400.4.68.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14355.html * https://bugzilla.suse.com/show_bug.cgi?id=1270351 . # Security update for php8Announcement ID: SUSE-SU-2026:2880-1 Release Date: 2026-07-13T09:39:59Z R. update, solves, vulnerability, installed, security, announcemen. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Jul 13, 2026 Medium OpenSUSE
172

Ubuntu QEMU Medium Regression Denial of Service Fix USN-8412-3

USN-8412-1 introduced a regression in QEMU. ========================================================================== Ubuntu Security Notice USN-8412-3 June 28, 2026 qemu regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: USN-8412-1 introduced a regression in QEMU Software Description: - qemu: Machine emulator and virtualizer Details: USN-8412-1 fixed vulnerabilities QEMU. On Ubuntu 20.04 LTS, the fix for CVE-2024-4467 was incomplete and prevented the creation of boot volumes from qcow2 images. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Felipe Franciosi, Raphael Norwitz, and Peter Turschmid discovered that the iSCSI block driver in QEMU incorrectly handled certain responses from an iSCSI server. A remote attacker could possibly use this issue to cause QEMU to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-1711) It was discovered that the iSCSI block driver in QEMU incorrectly handled certain memory operations, leading to a heap-based buffer over-read. An attacker could possibly use this issue to expose sensitive information from the host. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-11947) Ziming Zhang discovered that the SM501 display driver in QEMU contained an integer overflow. A local attacker could possibly use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-12829) Gaoning Pan and Xingwei Li discovered that the USB xHCI controller implementation in QEMU contained an infinite loop. An attacker inside the guest could possibly use this issue to cause QEMU to hang, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2020-14394) Lei Sun discovered that QEMUincorrectly handled certain MemoryRegionOps objects, leading to a NULL pointer dereference. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2020-15469) Alexander Bulekov discovered that the e1000e network device implementation in QEMU contained a use-after-free. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-15859) Ziming Zhang discovered that the XGMAC Ethernet controller in QEMU contained a buffer overflow. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-15863) Alexander Bulekov discovered that the SDHCI device emulation in QEMU contained a heap-based buffer overflow. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-17380) Sergej Schumilo, Cornelius Aschermann, and Simon Wörner discovered that the USB xHCI controller implementation in QEMU did not check a return value, leading to a use-after-free. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-25084) Gaoning Pan, Yongkang Jia, and Yi Ren discovered that the USB OHCI controller implementation in QEMU contained a stack-based buffer over- read. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-25624) It was discovered that the USB OHCI controller implementation in QEMU contained an infinite loop. An attacker inside theguest could possibly use this issue to cause QEMU to consume resources, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-25625) Cheolwoo Myung discovered that the USB EHCI emulation in QEMU did not handle DMA memory map failures, leading to a reachable assertion. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-25723) Gaoning Pan discovered that the network device emulation in QEMU could be made to trigger an assertion failure when processing packets that lacked a valid layer 3 protocol. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-27617) Wenxiang Qian discovered that the ATAPI emulation in QEMU did not properly validate a buffer index, leading to an out-of-bounds read. An attacker inside the guest could possibly use this issue to expose sensitive information or cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-29443) Cheolwoo Myung discovered that the ESP SCSI emulation in QEMU contained a NULL pointer dereference. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2020-35504) Cheolwoo Myung discovered that the am53c974 SCSI host bus adapter emulation in QEMU contained a NULL pointer dereference. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2020-35505) It was discovered that the SDHCI controller emulation in QEMU contained out-of-bounds read and write issues. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-3409) It was discovered that several network device emulations in QEMU contained an infinite loop when operating in loopback mode. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-3416) Alexander Bulekov discovered that the floppy disk emulation in QEMU contained a heap-based buffer overflow. An attacker inside the guest could possibly use this issue to expose sensitive information or cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-3507) Remy Noel discovered that the USB redirector device emulation in QEMU performed an unbounded stack allocation when combining USB packets. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-3527) It was discovered that the QXL display device emulation in QEMU contained an integer overflow, leading to a heap-based buffer overflow. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-4206) It was discovered that the QXL display device emulation in QEMU performed a double fetch of guest-controlled values, leading to a heap-based buffer overflow. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-4207) It was discovered that the 9pfs server implementation in QEMU contained a race condition, leading to a use-after-free. A malicious 9pclient could possibly use this issue to escalate privileges. This issue only affected Ubuntu 14.04 LTS. (CVE-2021-20181) Gaoning Pan discovered that the floppy disk emulation in QEMU contained a NULL pointer dereference. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-20196) Gaoning Pan discovered that the vmxnet3 network device emulation in QEMU contained an integer overflow. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-20203) It was discovered that the ARM Generic Interrupt Controller emulation in QEMU contained an out-of-bounds heap access. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-20221) Alexander Bulekov, Cheolwoo Myung, Sergej Schumilo, Cornelius Aschermann, and Simon Wörner discovered that the e1000 network device emulation in QEMU contained an infinite loop. An attacker inside the guest could possibly use this issue to cause QEMU to consume resources, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-20257) It was discovered that the 9p passthrough file system implementation in QEMU did not prevent opening special files on the host. A malicious guest could possibly use this issue to escape the exported 9p tree. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2023-2861) It was discovered that the virtio crypto device emulation in QEMU did not properly validate certain buffer lengths, leading to a heap buffer overflow. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service, orpossibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2023-3180) It was discovered that the built-in VNC server in QEMU contained a NULL pointer dereference when cleaning up a connection that failed during the handshake. A remote attacker could possibly use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2023-3354) It was discovered that QEMU could incorrectly direct a guest I/O operation to disk offset 0 instead of the intended offset. An attacker inside the guest could possibly use this issue to read or overwrite sensitive data, potentially gaining control of the host. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2023-5088) It was discovered that several virtio device emulations in QEMU did not properly guard against DMA reentrancy, leading to a double free. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2024-3446) It was discovered that the SDHCI device emulation in QEMU contained a heap- based buffer overflow. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service. (CVE-2024-3447) It was discovered that the QEMU disk image utility (qemu-img) did not properly handle certain crafted image files. An attacker could possibly use this issue to cause qemu-img to consume excessive resources or access an unintended external file, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2024-4467) Cyrille Chatras discovered that the LSI53C895A SCSI Host Bus Adapter emulation in QEMU contained a use-after-free. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2024-6519) It was discovered that the NBD server in QEMU contained an improper synchronization issue during socket closure. A remote attacker could possibly use this issue to cause QEMU to crash, resulting in a denial of service. (CVE-2024-7409) It was discovered that the USB emulation in QEMU contained a reachable assertion. An attacker inside the guest could possibly use this issue to cause QEMU to crash, resulting in a denial of service. (CVE-2024-8354) It was discovered that QEMU incorrectly handled resources during the VNC WebSocket handshake, leading to a use-after-free. A remote attacker could possibly use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2025-11234) It was discovered that QEMU could be made to read out of bounds when reading VMDK images. An attacker could possibly use this issue to expose sensitive information or cause QEMU to crash, resulting in a denial of service. (CVE-2026-2243) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS qemu 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-block-extra 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-guest-agent 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-kvm 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-system 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-system-arm 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-system-common 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-system-data 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-system-gui 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-system-mips 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-system-misc 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-system-ppc 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-system-s390x 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-system-sparc 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-system-x86 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-system-x86-microvm 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-system-x86-xen 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-user 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-user-binfmt 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-user-static 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro qemu-utils 1:4.2-3ubuntu6.30+esm3 Available with Ubuntu Pro After a standard system update you need to restart all QEMU virtual machines to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8412-3 https://ubuntu.com/security/notices/USN-8412-2 https://ubuntu.com/security/notices/USN-8412-1 https://launchpad.net/bugs/2158180 . Fix for QEMU regression affecting Ubuntu 20.04 LTS with potential denial of service is detailed within this advisory.. QEMU regression exploit,directory denial of service,image handling error,Ubuntu 20.04 security. . Severity: Medium.LinuxSecurity.com Team

Calendar%202 Jun 29, 2026 Medium Ubuntu
89

Fedora 43 perl-ExtUtils-Builder-Compiler Medium Threat Update CVE-2026-8463

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-f2c746ff8e 2026-06-05 04:07:33.979975+00:00 -------------------------------------------------------------------------------- Name : perl-ExtUtils-Builder-Compiler Product : Fedora 43 Version : 0.036 Release : 1.fc43 URL : https://metacpan.org/dist/ExtUtils-Builder-Compiler Summary : Interface around different compilers Description : This is an interface wrapping around different compilers. It's usually not used directly but by a portability layer like ExtUtils::Builder::Autodetect::C. -------------------------------------------------------------------------------- Update Information: Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463 -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 22 2026 Charles R. Anderson 0.036-1 - Update to 0.036 * Mon Jan 19 2026 Charles R. Anderson 0.035-1 - Update to 0.035 * Mon Jan 19 2026 Charles R. Anderson 0.034-1 - Update to 0.034 * Sat Jan 17 2026 Fedora Release Engineering - 0.031-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-f2c746ff8e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Critical update for Fedora 43 addressing CVE-2026-8463 in perl-ExtUtils-Builder-Compiler with essential fixes.. Fedora security update, perl ExtUtils Builder Compiler, CVE-2026-8463 fix. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Jun 05, 2026 Medium Fedora
89

Fedora 43 python-wsgidav Medium Auth Risk CVE-2026-48099

4.3.4 / 2026-05-24 Resolve security advisory CVE-2026-48099. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-7d942b469f 2026-06-03 01:17:29.592069+00:00 -------------------------------------------------------------------------------- Name : python-wsgidav Product : Fedora 43 Version : 4.3.4 Release : 1.fc43 URL : https://github.com/mar10/wsgidav Summary : Generic and extendable WebDAV server based on WSGI Description : A generic and extendable WebDAV server written in Python and based on WSGI. Main features: • WsgiDAV is a stand-alone WebDAV server with SSL support, that can be installed and run as Python command line script. • The python-pam library is needed as extra requirement if pam-login authentication is used on Linux or OSX. • WebDAV is a superset of HTTP, so WsgiDAV is also a performant, multi-threaded web server with SSL support. • WsgiDAV is also a Python library that implements the WSGI protocol and can be run behind any WSGI compliant web server. • WsgiDAV is implemented as a configurable stack of WSGI middleware applications. Its open architecture allows to extend the functionality and integrate WebDAV services into your project. Typical use cases are: • Expose data structures as virtual, editable file systems. • Allow online editing of MS Office documents. -------------------------------------------------------------------------------- Update Information: 4.3.4 / 2026-05-24 Resolve security advisory CVE-2026-48099 -------------------------------------------------------------------------------- ChangeLog: * Mon May 25 2026 Benjamin A. Beasley - 4.3.4-1 - Update to 4.3.4 upstream release - Resolves: rhbz#2481045 * Wed May 20 2026 Benjamin A. Beasley - 4.3.3-21 - Use various long options * Wed May 20 2026 Benjamin A. Beasley - 4.3.3-20 - Use long pyprojectoptions -------------------------------------------------------------------------------- References: [ 1 ] Bug #2481045 - python-wsgidav-4.3.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2481045 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-7d942b469f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update for python-wsgidav resolves CVE-2026-48099 in Fedora 43, addressing potential authentication risks.. python webdav server, fedora update, python-wsgidav security. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Jun 03, 2026 Medium Fedora
89

Fedora 43 libpng Addresses Medium Severity Memory Bug CVE-2026-34757

updated to 1.6.58 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a109a9ac2c 2026-06-02 01:10:43.197462+00:00 -------------------------------------------------------------------------------- Name : libpng Product : Fedora 43 Version : 1.6.58 Release : 1.fc43 URL : http://www.libpng.org/pub/png/ Summary : A library of functions for manipulating PNG image format files Description : The libpng package contains a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. PNG is a bit-mapped graphics format similar to the GIF format. PNG was created to replace the GIF format, since GIF uses a patented data compression algorithm. Libpng should be installed if you need to manipulate PNG format image files. -------------------------------------------------------------------------------- Update Information: updated to 1.6.58 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the fix for CVE-2026-33416 in 1.6.56. 1.6.57 is released with fixes for the following security vulnerability: CVE-2026-34757 (medium severity): Use-after-free memory bug in the chunk setter API. The hIST variant has existed since version 1.0.9, but the PLTE and tRNS ones are regressions introduced in the fix for CVE-2026-33416 in 1.6.56(oops). -------------------------------------------------------------------------------- ChangeLog: * Thu May 21 2026 Michal Hlavinka - 2:1.6.58-1 - updated to 1.6.58 (#2456815) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2460625 - CVE-2026-22020 libpng: OpenJDK: Update LibPNG (Oracle CPU 2026-04) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460625 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a109a9ac2c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fix for medium severity memory bug in libpng 1.6.58 for Fedora 43 addresses regressions and improves functionality.. libpng update, Fedora security advisory, medium severity fix, memory issue, libpng 1.6.58. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Jun 02, 2026 Medium Fedora
89

Fedora 43 libpng Moderate Use-After-Free Resolution 2026-a109a9ac2c

updated to 1.6.58 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a109a9ac2c 2026-06-02 01:10:43.197462+00:00 -------------------------------------------------------------------------------- Name : libpng Product : Fedora 43 Version : 1.6.58 Release : 1.fc43 URL : http://www.libpng.org/pub/png/ Summary : A library of functions for manipulating PNG image format files Description : The libpng package contains a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. PNG is a bit-mapped graphics format similar to the GIF format. PNG was created to replace the GIF format, since GIF uses a patented data compression algorithm. Libpng should be installed if you need to manipulate PNG format image files. -------------------------------------------------------------------------------- Update Information: updated to 1.6.58 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the fix for CVE-2026-33416 in 1.6.56. 1.6.57 is released with fixes for the following security vulnerability: CVE-2026-34757 (medium severity): Use-after-free memory bug in the chunk setter API. The hIST variant has existed since version 1.0.9, but the PLTE and tRNS ones are regressions introduced in the fix for CVE-2026-33416 in 1.6.56(oops). -------------------------------------------------------------------------------- ChangeLog: * Thu May 21 2026 Michal Hlavinka - 2:1.6.58-1 - updated to 1.6.58 (#2456815) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2460625 - CVE-2026-22020 libpng: OpenJDK: Update LibPNG (Oracle CPU 2026-04) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460625 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a109a9ac2c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fedora 43 addresses libpng with a medium severity use-after-free bug patch in update 2026-a109a9ac2c.. Fedora libpng update use-after-free memory issue. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Jun 01, 2026 Medium Fedora
89

Fedora 44 Libpng Medium Use-After-Free Memory Bug 2026-67c1138ed2

updated to 1.6.58 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-67c1138ed2 2026-05-29 01:10:57.991217+00:00 -------------------------------------------------------------------------------- Name : libpng Product : Fedora 44 Version : 1.6.58 Release : 1.fc44 URL : http://www.libpng.org/pub/png/ Summary : A library of functions for manipulating PNG image format files Description : The libpng package contains a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. PNG is a bit-mapped graphics format similar to the GIF format. PNG was created to replace the GIF format, since GIF uses a patented data compression algorithm. Libpng should be installed if you need to manipulate PNG format image files. -------------------------------------------------------------------------------- Update Information: updated to 1.6.58 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the fix for CVE-2026-33416 in 1.6.56. 1.6.57 is released with fixes for the following security vulnerability: CVE-2026-34757 (medium severity): Use-after-free memory bug in the chunk setter API. The hIST variant has existed since version 1.0.9, but the PLTE and tRNS ones are regressions introduced in the fix for CVE-2026-33416 in 1.6.56(oops). -------------------------------------------------------------------------------- ChangeLog: * Thu May 21 2026 Michal Hlavinka - 2:1.6.58-1 - updated to 1.6.58 (#2456815) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2460625 - CVE-2026-22020 libpng: OpenJDK: Update LibPNG (Oracle CPU 2026-04) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460625 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-67c1138ed2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Libpng Fedora 44 update addresses a medium severity use-after-free memory issue, ensuring PNG file manipulation integrity.. Fedora updates, Libpng issues, memory bug, PNG manipulation. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 May 29, 2026 Medium Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200