Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 4 articles for you...
100

SUSE Python-Pillow Important Memory Allocation Threat Advisory 2026-2875-1

An update that solves four vulnerabilities can now be installed.. # Security update for python-Pillow Announcement ID: SUSE-SU-2026:2875-1 Release Date: 2026-07-13T09:12:44Z Rating: important References: * bsc#1270409 * bsc#1270410 * bsc#1270411 * bsc#1270412 Cross-References: * CVE-2026-54059 * CVE-2026-54060 * CVE-2026-55379 * CVE-2026-55380 CVSS scores: * CVE-2026-54059 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54059 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54060 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54060 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55379 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55379 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55380 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55380 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for python-Pillow fixes the following issues * CVE-2026-54059: crafted PCF font data can cause excessive memory allocation (bsc#1270409). * CVE-2026-54060: a font can trigger excessive allocation during conversion or saving (bsc#1270410). * CVE-2026-55379: bypass of decompression bomb protection, allowing excessive memory allocation (bsc#1270411). * CVE-2026-55380: crafted .gd file can trigger excessive C-heap allocation when loaded (bsc#1270412). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the commandlisted for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2875=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-2875=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * python-Pillow-debuginfo-7.2.0-150300.3.27.1 * python3-Pillow-debuginfo-7.2.0-150300.3.27.1 * python-Pillow-debugsource-7.2.0-150300.3.27.1 * python3-Pillow-7.2.0-150300.3.27.1 * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * python-Pillow-debuginfo-7.2.0-150300.3.27.1 * python3-Pillow-tk-debuginfo-7.2.0-150300.3.27.1 * python3-Pillow-debuginfo-7.2.0-150300.3.27.1 * python3-Pillow-7.2.0-150300.3.27.1 * python3-Pillow-tk-7.2.0-150300.3.27.1 * python-Pillow-debugsource-7.2.0-150300.3.27.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54059.html * https://www.suse.com/security/cve/CVE-2026-54060.html * https://www.suse.com/security/cve/CVE-2026-55379.html * https://www.suse.com/security/cve/CVE-2026-55380.html * https://bugzilla.suse.com/show_bug.cgi?id=1270409 * https://bugzilla.suse.com/show_bug.cgi?id=1270410 * https://bugzilla.suse.com/show_bug.cgi?id=1270411 * https://bugzilla.suse.com/show_bug.cgi?id=1270412 . Install the important SUSE security update for python-Pillow, addressing memory allocation risks and four vulnerabilities.. python pillow security update, SUSE security advisory, important memory vulnerability, patch instructions for SUSE. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 13, 2026 Important SuSE
202

openSUSE Python-Pillow Important Memory Allocation Issues Vuln 2026-2875-1

An update that solves four vulnerabilities can now be installed.. # Security update for python-Pillow Announcement ID: SUSE-SU-2026:2875-1 Release Date: 2026-07-13T09:12:44Z Rating: important References: * bsc#1270409 * bsc#1270410 * bsc#1270411 * bsc#1270412 Cross-References: * CVE-2026-54059 * CVE-2026-54060 * CVE-2026-55379 * CVE-2026-55380 CVSS scores: * CVE-2026-54059 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54059 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54060 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54060 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55379 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55379 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55380 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55380 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for python-Pillow fixes the following issues * CVE-2026-54059: crafted PCF font data can cause excessive memory allocation (bsc#1270409). * CVE-2026-54060: a font can trigger excessive allocation during conversion or saving (bsc#1270410). * CVE-2026-55379: bypass of decompression bomb protection, allowing excessive memory allocation (bsc#1270411). * CVE-2026-55380: crafted .gd file can trigger excessive C-heap allocation when loaded (bsc#1270412). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the commandlisted for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2875=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-2875=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * python-Pillow-debuginfo-7.2.0-150300.3.27.1 * python3-Pillow-debuginfo-7.2.0-150300.3.27.1 * python-Pillow-debugsource-7.2.0-150300.3.27.1 * python3-Pillow-7.2.0-150300.3.27.1 * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * python-Pillow-debuginfo-7.2.0-150300.3.27.1 * python3-Pillow-tk-debuginfo-7.2.0-150300.3.27.1 * python3-Pillow-debuginfo-7.2.0-150300.3.27.1 * python3-Pillow-7.2.0-150300.3.27.1 * python3-Pillow-tk-7.2.0-150300.3.27.1 * python-Pillow-debugsource-7.2.0-150300.3.27.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54059.html * https://www.suse.com/security/cve/CVE-2026-54060.html * https://www.suse.com/security/cve/CVE-2026-55379.html * https://www.suse.com/security/cve/CVE-2026-55380.html * https://bugzilla.suse.com/show_bug.cgi?id=1270409 * https://bugzilla.suse.com/show_bug.cgi?id=1270410 * https://bugzilla.suse.com/show_bug.cgi?id=1270411 * https://bugzilla.suse.com/show_bug.cgi?id=1270412 . # Security update for python-Pillow Announcement ID: SUSE-SU-2026:2875-1 Release Date: 2026-07-13T09. update, solves, vulnerabilities, installed, security, python-pillow. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 13, 2026 Important OpenSUSE
202

openSUSE: 2023:0163-1 Important: Keepass Memory Protection Update

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for keepass ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0163-1 Rating: important References: #1211397 Cross-References: CVE-2023-32784 CVSS scores: CVE-2023-32784 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for keepass fixes the following issues: - Update to 2.54 * Security: + Improved process memory protection of secure edit controls (CVE-2023-32784, boo#1211397). * New Features: + Triggers, global URL overrides, password generator profiles and a few more settings are now stored in the enforced configuration file. + Added dialog 'Enforce Options (All Users)' (menu 'Tools' → 'Advanced Tools' → 'Enforce Options'), which facilitates storing certain options in the enforced configuration file. + In report dialogs, passwords (and other sensitive data) are now hidden using asterisks by default (if hiding is activated in the main window); the hiding can be toggled using the new '***' button in the toolbar. + The 'Print' command in most report dialogs now requires the 'Print' application policy flag, and the master key must be entered if the 'Print - No Key Repeat' application policy flag is deactivated. + The 'Export' command in most report dialogs now requires the 'Export' application policy flag, and the master key must be entered. + Single line edit dialogs now support hiding the value using asterisks. + Commands that require elevation now have a shield icon like on Windows. + TrlUtil: added 'Move Selected Unused Text to Dialog Control' command. * Improvements: * The content mode of the configuration elements '/Configuration/Application/TriggerSystem', '/Configuration/Integration/UrlSchemeOverrides' and '/Configuration/PasswordGenerator/UserProfiles' is now 'Replace' by default. * The built-in override for the 'ssh' URI scheme is now deactivated by default (it can be activated in the 'URL Overrides' dialog). * When opening the password generator dialog without a derived profile, the '(Automatically generated passwords for new entries)' profile is now selected by default, if profiles are enabled (otherwise the default profile is used). * The clipboard workarounds are now disabled by default (they are not needed anymore on most systems). * Improved clipboard clearing. * Improved starting of an elevated process. * Bugfixes: + In report dialogs, the 'Print' and 'Export' commands now always use the actual data (in previous versions, asterisks were printed/exported when the application policy flag 'Unhide Passwords' was turned off). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2023-163=1 Package List: - openSUSE Backports SLE-15-SP5 (noarch): keepass-2.54-bp155.2.3.1 References: https://www.suse.com/security/cve/CVE-2023-32784.html https://bugzilla.suse.com/1211397 . This revision addresses a significant issue within KeePass on openSUSE. Implement the recommended updates to enhance protection.. Keepass Update, OpenSUSE Patch, Security Fixes, Software Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 30, 2023 Important OpenSUSE
202

openSUSE 15-SP4: 2023:0157-1 Important KeePass Security Fix

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for keepass ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0157-1 Rating: important References: #1211397 Cross-References: CVE-2023-32784 CVSS scores: CVE-2023-32784 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for keepass fixes the following issues: Update to 2.54 * Security: + Improved process memory protection of secure edit controls (CVE-2023-32784, boo#1211397). * New Features: + Triggers, global URL overrides, password generator profiles and a few more settings are now stored in the enforced configuration file. + Added dialog 'Enforce Options (All Users)' (menu 'Tools' → 'Advanced Tools' → 'Enforce Options'), which facilitates storing certain options in the enforced configuration file. + In report dialogs, passwords (and other sensitive data) are now hidden using asterisks by default (if hiding is activated in the main window); the hiding can be toggled using the new '***' button in the toolbar. + The 'Print' command in most report dialogs now requires the 'Print' application policy flag, and the master key must be entered if the 'Print - No Key Repeat' application policy flag is deactivated. + The 'Export' command in most report dialogs now requires the 'Export' application policy flag, and the master key must be entered. + Single line edit dialogs now support hiding the value using asterisks. + Commands that require elevation now have a shield icon like on Windows. + TrlUtil: added 'Move Selected Unused Text to Dialog Control' command. * Improvements: * The content mode of the configuration elements '/Configuration/Application/TriggerSystem', '/Configuration/Integration/UrlSchemeOverrides' and '/Configuration/PasswordGenerator/UserProfiles' is now 'Replace' by default. * The built-in override for the 'ssh' URI scheme is now deactivated by default (it can be activated in the 'URL Overrides' dialog). * When opening the password generator dialog without a derived profile, the '(Automatically generated passwords for new entries)' profile is now selected by default, if profiles are enabled (otherwise the default profile is used). * The clipboard workarounds are now disabled by default (they are not needed anymore on most systems). * Improved clipboard clearing. * Improved starting of an elevated process. * Bugfixes: + In report dialogs, the 'Print' and 'Export' commands now always use the actual data (in previous versions, asterisks were printed/exported when the application policy flag 'Unhide Passwords' was turned off). - Update to 2.53.1 * When testing a KDF ('Test' button in the database settings dialog), KeePass now spawns a child process that performs the KDF computation (which allows to cancel the test more cleanly in the case of excessive parameters; security is unaffected, because dummy data is used for the test). * Removed the 'Export - No Key Repeat' application policy flag; KeePass now always asks for the current master key when trying to export data. * Minor other improvements. - Update to 2.53 * New Features: + For each entry listed on the 'History' tab page of the entry dialog, the fields modified with respect to the previous entry are displayed. + Added 'Compare' button on the 'History' tabpage of the entry dialog; when two (not necessarily consecutive) history entries are selected, clicking the button shows a detailed comparison (with values, etc.). + When editing an entry, the history entry list of the entry dialog now contains an entry called 'Dialog (unsaved)', which represents all data entered in the current dialog (other tab pages). + When editing an entry, the history entry list of the entry dialog now contains an entry called 'Current (TIME)', which is the entry that is currently stored in the database (without any changes made in the current dialog). + Added 'History' command in the 'Find' main menu; it lists all entry modifications (sorted by time). + Added filter box in most report dialogs (last modified entries, history, large entries, similar password clusters, password quality, history entry comparison, database file search, ...). + Added 'Print' button in most report dialogs. + Added 'Export' button in most report dialogs; supported formats are CSV and HTML. + Added {EDGE} placeholder, which is replaced by the executable path of the new (Chromium-based) Microsoft Edge, if installed. + Added URL override suggestion for Microsoft Edge in private mode in the URL override suggestions drop-down list of the entry dialog. + Added optional built-in global URL overrides for opening HTTP/HTTPS URLs with Microsoft Edge in private mode. + When trying to rearrange entries while automatic sorting is activated, KeePass now asks whether to deactivate automatic sorting. + Added access keys in the tags button drop-down menu of the entry/group dialogs. + Added access keys in the 'View' → 'Sort By' menu. + Added access keys in the entry templates menu. + Added access keys in the 'Perform Auto-Type' menu (which is displayed if the 'Showadditional auto-type menu commands' option is turned on). + Added {HMACOTP} and {TIMEOTP} in the 'Perform Auto-Type' menu. + Added keyboard shortcut Ctrl+T for the 'Copy Time-Based OTP' entry data command. + Added keyboard shortcut Ctrl+Shift+T for the 'Show Time-Based OTP' entry data command. + Enhanced Password Depot XML import module to support the new format (added support for the new node names, group icons, recycle bin, tags, favorites, auto-type delay conversion, history, enhanced icon mapping, enhanced date/time parsing, ...). + Added border for headings in HTML exports/printouts. + Added support for running KeePass in FIPS mode. * Improvements: + History entries listed on the 'History' tab page of the entry dialog are now sorted from newest to oldest. + The icons in the list on the 'History' tab page of the entry dialog now indicate the type of the entry. + History entry controls of the entry dialog are now disabled when creating a new entry. + The history entry 'Restore' button is now disabled when any change has been made in the current dialog. + The 'Password modified' time is now updated immediately when deleting a history entry. + Improved URL override suggestion for Microsoft Edge in the URL override suggestions drop-down list of the entry dialog (changed from 'microsoft-edge:{URL}' to 'cmd://{EDGE} "{URL}"'). + Improved optional built-in global URL overrides for opening HTTP/HTTPS URLs with Microsoft Edge (changed from 'microsoft-edge:{BASE}' to 'cmd://{EDGE} "{BASE}"'). + Reordered web browser URL overrides alphabetically. + Improved dynamic menu item access key assignment. + Improved item separation in the entry details view. + In most places, groups in a group path are now separated by right arrows instead of hyphens. +Improved last modification time comparison for plugin data dictionaries. + Unified generation of common HTML parts. + The 'Copy Initial Password' command in the 'Tools' menu of the entry dialog now requires the 'Copy' application policy flag. + Various UI text improvements. + Various code optimizations. + Minor other improvements. * Bugfixes: + The history entry 'Restore' button now always works as expected. - Update to 2.52 * New Features: + Added 'Copy Initial Password' command in the tools menu of the entry dialog; it copies (to the clipboard) the password that was current when the dialog was opened. + When multiple entries are selected (containing at least one attachment), the number of attachments is now displayed in the 'Attachments' submenu of the entry menu. + Added option 'Alt. item background color' (supporting the states 'Off', 'On, default color' and 'On, custom color'); this combines the previous two options 'Use alternating item background colors' and 'Custom alt. item color'. + Comment placeholders ({C:...}) may now contain balanced braces. + In the auto-type entry selection dialog, values in the 'Sequence - Comments' column are dereferenced now. + The time when the password of an entry was last changed is now displayed in the entry dialog on the 'History' tab page. + Added support for importing 1Password 8.7 1PUX files. + Added support for importing Key Folder 1.22 XML files. + Sticky Password XML import: added support for importing groups and expiry dates. + Steganos Password Manager CSV import: added support for the new encoding of double quotes. + Bitwarden JSON import: time-based one-time password generator settings are converted automatically now. + KeePass now checks the 'KeePass.exe.config' file and shows a warning message when finding a problem. + For development builds: added command for showing GC information. + Plugins can now load the header of a database file more easily. + Plugins can now subscribe to a master key change event. + TrlUtil: added workaround for .NET tab control focus bug. * Improvements: + Moved the command 'Save Attached File(s) To' into the 'Attachments' submenu of the entry menu and renamed it to 'Save File(s) To'. + The command for saving attached files is now available only if at least one of the selected entries has at least one attachment. + The {APPACTIVATE ...} auto-type command now ignores the options 'Cancel auto-type when the target window changes' and 'Cancel auto-type when the target window title changes'. + {APPACTIVATE ...} auto-type command: if the specified window does not exist or cannot be focused, auto-type is aborted now. + Unified creation of fields with indices. + Improved database modification state and UI updating after imports/synchronizations. + In the master key creation/prompt dialogs, the [OK] button is now disabled when checking the 'Key file/provider' check box and selecting '(None)' in the combo box. + Improved drop-down menu width adjustment for certain combo boxes in the options dialog. + Improved hashing performance of protected binaries, UUIDs, ... + Performance improvements related to empty arrays. + Improved Mono framework version detection. + TrlUtil: improved preview dialog update performance. + Various UI text improvements. + Various code optimizations. + Minor other improvements. * Bugfixes: * Fixed a bug that caused a minimized main window to be restored to a normal window instead of a maximized window in certain situations. * The 'Help' menu item in the entry dialog and the 'Help' button in the entrystring field dialog now open the correct help sections. - Update to 2.51.1 * New Features: + Most dialogs with fixed size now detect whether they fit onto the current screen, and when a dialog does not fit (e.g. due to a very high DPI factor), its size is reduced and scroll bars are displayed. + Added plural entry command names in the main window (e.g. the command for editing the currently selected entry/entries is now called either 'Edit Entry' or 'Edit Entries', depending on the number of selected entries). + Added tooltip for the main part of the status bar of the main window. + Enhanced color buttons (tooltips, accessible names, ...) in the entry dialog, in the database settings dialog and in the options dialog. + Added 'Interface (2)' tab page in the options dialog, renamed the existing 'Interface' tab page to 'Interface (1)', moved some controls from 'Interface (1)' to 'Interface (2)'. + Enhanced font selection controls (with a checkbox that allows to return to the default, the button shows the currently selected font, tooltip, improved accessibility, ...) in the options dialog. + Added help links 'Dark theme' and 'Main font (size)' in the options dialog. + The options 'Custom alt. item color' and 'Esc keypress in main window' are now disabled if they are enforced (by an enforced configuration file). + Added support for opening URLs with Waterfox in private mode. + Added dialog for editing (HMAC-based and time-based) one-time password generator settings (can be opened using the 'OTP Generator Settings' commands in the entry dialog or in the 'Edit Entry (Quick)' menu of the main window). + Added entry commands 'Copy HMAC-Based OTP', 'Show HMAC-Based OTP', 'Copy Time-Based OTP' and 'Show Time-Based OTP' (in the 'Other Data' menu). + Added entrycommands 'Copy Title' and 'Copy Notes' (in the 'Other Data' menu). + When switching to the 'Generate' tab page of the password generator dialog (no database open), the entropy collection dialog is displayed now, if the option 'Show dialog for collecting user input as additional entropy' is turned on. + Added option 'Colorize password characters' in the HTML export/print dialog; the colors are customizable. + Added options 'Custom main font' and 'Custom password font' in the HTML export/print dialog. + Added horizontal entry separator lines in tabular HTML exports/printouts. + In the plugins dialog, the 'Delete old files from cache automatically' option and the 'Clear' button are now disabled if they are enforced (by an enforced configuration file). + Plugins can now change the expiry date of an entry more easily. * Improvements: + Improved main window initialization performance. + Improved initial emergence of a minimized or maximized main window (less flickering, improved performance, ...). + Improved names/tooltips of the database toolbar buttons in the main window. + Improved handling of bold/italic list fonts. + Improved entry list update performance in certain situations. + Improved dynamic menu deconstruction performance. + Fields starting with 'HmacOtp-' or 'TimeOtp-' are not shown in the entry string copy menu anymore. + Improved tooltips and accessibility of password repetition text boxes. + When a dark theme is active, the error background color of text boxes is darker now. + Improved accessibility of expiry control groups. + The title of the master key creation/change dialog is now adjusted to the context. + Improved 'Compression' tab page of the database settings dialog (extended 'None' option description, improvedaccessibility, ...). + If no color has been specified, the 'Custom alt. item color' button in the options dialog now shows the default color. + Improved HTML generation for HTML exports/printouts. + Improved default fonts used when printing or exporting to HTML. + In block HTML exports/printouts, field names are not italic anymore (unless the user has selected an italic main font). + In HTML exports/printouts, all field values except passwords are trimmed now. + HTML exports/printouts: improved encoding of white-space characters in passwords. + Improved horizontal entry separator lines in block HTML exports/printouts. + TrlUtil: improved control classification. + Increased Authenticode certificate key length. + Improved entry list update performance when duplicating entries. + Various CHM/help improvements. + Various UI text improvements. + Various code optimizations. + Minor other improvements. * Bugfixes: + The option 'Use alternating item background colors' is now compatible with automatic sorting again. + The command line parameter '-preselect:' now works as expected when the option 'Clear master key command line parameters after using them once' is turned on. + Font selections in the options dialog are now applied only when closing the dialog with [OK]. + Fixed an entry list scrolling bug. - Update to 2.50 * New Features: + On most Linux systems, AES-KDF is now about 4 times as fast as before, if the 'libgcrypt' library is installed. + On most Linux systems, Argon2d and Argon2id are now about 3 times as fast as before (for default parameters), if the 'libargon2' library is installed. + The option 'Enter master key on secure desktop' is now also supported by master key prompt dialogs shown during imports, confirmations(before exporting, printing, changing the master key, ...) and trigger actions. + The option 'Enter master key on secure desktop' is now also supported by master key creation/change dialogs. + The key file/provider combo boxes in the master key dialogs now have a tooltip that shows the current value, if the value is very long. + Added password generation button in the entry string field dialog. + When double-clicking the title cell of an entry in the main entry list while holding down the Shift key, the title is now copied to the clipboard. + Added support for detecting the latest versions of Chromium on Unix-like systems (for 'Open with ...' commands in the 'URL(s)' menu, for the {GOOGLECHROME} placeholder, ...). + In the 'URL(s)' menu, there now are separate commands for Google Chrome and Chromium, if both are installed. + Enhanced support for detecting Vivaldi, Brave, Pale Moon and Epiphany. + Added support for importing Kaspersky Password Manager 9.0.2 TXT files. + Bitwarden import module: added support for importing subfolders, and collection names are now imported as tags. + In the 'About KeePass' dialog, each item in the components list now has a tooltip that shows the file/folder path of the component, if it is installed. + In the 'About KeePass' dialog, a double-click onto a component now shows the component file/folder with the file manager. + In the 'About KeePass' dialog, the components list now has a context menu that provides the following new commands: 'Show with File Manager', 'Copy Version/Status' and 'Copy Path'. * Improvements: + If the option 'An entry matches if one of its tags is contained in the target window title' is turned on, auto-type now additionally considers tags inherited from groups. + The built-in password generationpatterns 'Hex Key - *-Bit' now use upper-case hexadecimal symbols. + Improved Spr variance check of the password generator (custom string references, ...). + All commands in the password generator menu (shown by the password generator buttons in entry/string dialogs) support the option 'Show dialog for collecting user input as additional entropy' now. * Bugfixes: + Column header context menus are not shown for non-report list views anymore. + When copying a URL to the clipboard fails, the main entry list is updated now. + Toggling the password generator option 'Show dialog for collecting user input as additional entropy' now causes a switch to the '(Custom)' profile. + In the TAN wizard dialog, group names containing ampersands are displayed correctly now. - Add recommends to libargon2-1 and libgrypt20 as Keepass can use those for faster operations. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2023-157=1 Package List: - openSUSE Backports SLE-15-SP4 (noarch): keepass-2.54-bp154.2.3.1 References: https://www.suse.com/security/cve/CVE-2023-32784.html https://bugzilla.suse.com/1211397 . Crucial openSUSE enhancement addressing significant vulnerabilities in KeePass, featuring improved memory safeguards and additional functionalities.. openSUSE Update,KeePass Security,KeePass 2.54,software fix,cross-platform security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 27, 2023 Important OpenSUSE
172

Ubuntu 16.04 ESM USN-5523-1 Moderate: LibTIFF Denial of Service Issues

Several security issues were fixed in LibTIFF.. =========================================================================Ubuntu Security Notice USN-5523-1 July 19, 2022 tiff vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: Several security issues were fixed in LibTIFF. Software Description: - tiff: Tag Image File Format (TIFF) library Details: It was discovered that LibTIFF was not properly performing checks to guarantee that allocated memory space existed, which could lead to a NULL pointer dereference via a specially crafted file. An attacker could possibly use this issue to cause a denial of service. (CVE-2022-0907, CVE-2022-0908) It was discovered that LibTIFF was not properly performing checks to avoid division calculations where the denominator value was zero, which could lead to an undefined behavior situation via a specially crafted file. An attacker could possibly use this issue to cause a denial of service. (CVE-2022-0909) It was discovered that LibTIFF was not properly performing bounds checks, which could lead to an out-of-bounds read via a specially crafted file. An attacker could possibly use this issue to cause a denial of service or to expose sensitive information. (CVE-2022-0924) It was discovered that LibTIFF was not properly performing the calculation of data that would eventually be used as a reference for bounds checking operations, which could lead to an out-of-bounds read via a specially crafted file. An attacker could possibly use this issue to cause a denial of service or to expose sensitive information. (CVE-2020-19131) It was discovered that LibTIFF was not properly terminating a function execution when processing incorrect data, which could lead to an out-of-bounds read via a specially crafted file. An attacker could possibly use this issue to cause a denial of serviceor to expose sensitive information. (CVE-2020-19144) It was discovered that LibTIFF was not properly performing checks when setting the value for data later used as reference during memory access, which could lead to an out-of-bounds read via a specially crafted file. An attacker could possibly use this issue to cause a denial of service or to expose sensitive information. (CVE-2022-22844) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: libtiff-opengl 4.0.6-1ubuntu0.8+esm2 libtiff-tools 4.0.6-1ubuntu0.8+esm2 libtiff5 4.0.6-1ubuntu0.8+esm2 libtiffxx5 4.0.6-1ubuntu0.8+esm2 Ubuntu 14.04 ESM: libtiff-opengl 4.0.3-7ubuntu0.11+esm2 libtiff-tools 4.0.3-7ubuntu0.11+esm2 libtiff5 4.0.3-7ubuntu0.11+esm2 libtiffxx5 4.0.3-7ubuntu0.11+esm2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5523-1 CVE-2020-19131, CVE-2020-19144, CVE-2022-0907, CVE-2022-0908, CVE-2022-0909, CVE-2022-0924, CVE-2022-22844 . Multiple vulnerabilities in LibTIFF are addressed to mitigate DoS risks in Ubuntu systems with essential updates.. LibTIFF Updates, Ubuntu Security Fixes, Memory Management Issues, Denial of Service Risks. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 19, 2022 Important Ubuntu
100

SUSE: 2020:0668-1 Moderate: glibc Buffer Overflow and Fixes

An update that solves one vulnerability and has two fixes is now available. . SUSE Security Update: Security update for glibc ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0668-1 Rating: moderate References: #1163184 #1164505 #1165784 Cross-References: CVE-2020-10029 Affected Products: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 SUSE Linux Enterprise Module for Development Tools 15-SP1 SUSE Linux Enterprise Module for Basesystem 15-SP1 ______________________________________________________________________________ An update that solves one vulnerability and has two fixes is now available. Description: This update for glibc fixes the following issues: - CVE-2020-10029: Fixed a potential overflow in on-stack buffer during range reduction (bsc#1165784). - Fixed an issue where pthread were not always locked correctly (bsc#1164505). - Document mprotect and introduce section on memory protection (bsc#1163184). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2020-668=1 - SUSE Linux Enterprise Module for Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP1-2020-668=1 - SUSE Linux Enterprise Module for Basesystem 15-SP1: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2020-668=1 Package List: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (s390x x86_64): glibc-debugsource-2.26-13.39.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1(noarch): glibc-html-2.26-13.39.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (x86_64): glibc-32bit-debuginfo-2.26-13.39.1 glibc-devel-static-32bit-2.26-13.39.1 glibc-locale-base-32bit-2.26-13.39.1 glibc-locale-base-32bit-debuginfo-2.26-13.39.1 glibc-profile-32bit-2.26-13.39.1 glibc-utils-32bit-2.26-13.39.1 glibc-utils-32bit-debuginfo-2.26-13.39.1 glibc-utils-src-debugsource-2.26-13.39.1 - SUSE Linux Enterprise Module for Development Tools 15-SP1 (aarch64 ppc64le s390x x86_64): glibc-debuginfo-2.26-13.39.1 glibc-debugsource-2.26-13.39.1 glibc-devel-static-2.26-13.39.1 glibc-utils-2.26-13.39.1 glibc-utils-debuginfo-2.26-13.39.1 glibc-utils-src-debugsource-2.26-13.39.1 - SUSE Linux Enterprise Module for Development Tools 15-SP1 (x86_64): glibc-32bit-debuginfo-2.26-13.39.1 glibc-devel-32bit-2.26-13.39.1 glibc-devel-32bit-debuginfo-2.26-13.39.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64): glibc-2.26-13.39.1 glibc-debuginfo-2.26-13.39.1 glibc-debugsource-2.26-13.39.1 glibc-devel-2.26-13.39.1 glibc-devel-debuginfo-2.26-13.39.1 glibc-extra-2.26-13.39.1 glibc-extra-debuginfo-2.26-13.39.1 glibc-locale-2.26-13.39.1 glibc-locale-base-2.26-13.39.1 glibc-locale-base-debuginfo-2.26-13.39.1 glibc-profile-2.26-13.39.1 nscd-2.26-13.39.1 nscd-debuginfo-2.26-13.39.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (x86_64): glibc-32bit-2.26-13.39.1 glibc-32bit-debuginfo-2.26-13.39.1 glibc-locale-base-32bit-2.26-13.39.1 glibc-locale-base-32bit-debuginfo-2.26-13.39.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (noarch): glibc-i18ndata-2.26-13.39.1 glibc-info-2.26-13.39.1 References: https://www.suse.com/security/cve/CVE-2020-10029.html https://bugzilla.suse.com/1163184 https://bugzilla.suse.com/1164505 https://bugzilla.suse.com/1165784 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE announces a critical security patch for glibc, addressing a significant vulnerability related to memory corruption and potential buffer overflow risks within the impacted components.. SUSE Linux, glibc Update, Buffer Overflow, Memory Protection. . LinuxSecurity.com Team

Calendar%202 Mar 13, 2020 SuSE
98

Red Hat 5 ELS RHSA-2018-2602 Important: Kernel Memory Protection Issue

An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security update Advisory ID: RHSA-2018:2602-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2018:2602 Issue date: 2018-08-29 CVE Names: CVE-2018-3620 CVE-2018-3646 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server (v. 5 ELS) - i386, noarch, s390x, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * Modern operating systems implement virtualization of physical memory to efficiently use available system resources and provide inter-domain protection through access control and isolation. The L1TF issue was found in the way the x86 microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimization) in combination with handling of page-faults caused by terminated virtual to physical address resolving process. As a result, an unprivileged attacker could use this flaw to read privileged memory of the kernel or other processes and/or cross guest/host boundaries to read host memory by conducting targeted cacheside-channel attacks. (CVE-2018-3620, CVE-2018-3646) Red Hat would like to thank Intel OSSIRT (Intel.com) for reporting these issues. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1585005 - CVE-2018-3620 CVE-2018-3646 Kernel: hw: cpu: L1 terminal fault (L1TF) 6. Package List: Red Hat Enterprise Linux Server (v. 5ELS): Source: kernel-2.6.18-434.el5.src.rpm i386: kernel-2.6.18-434.el5.i686.rpm kernel-PAE-2.6.18-434.el5.i686.rpm kernel-PAE-debuginfo-2.6.18-434.el5.i686.rpm kernel-PAE-devel-2.6.18-434.el5.i686.rpm kernel-debug-2.6.18-434.el5.i686.rpm kernel-debug-debuginfo-2.6.18-434.el5.i686.rpm kernel-debug-devel-2.6.18-434.el5.i686.rpm kernel-debuginfo-2.6.18-434.el5.i686.rpm kernel-debuginfo-common-2.6.18-434.el5.i686.rpm kernel-devel-2.6.18-434.el5.i686.rpm kernel-headers-2.6.18-434.el5.i386.rpm kernel-xen-2.6.18-434.el5.i686.rpm kernel-xen-debuginfo-2.6.18-434.el5.i686.rpm kernel-xen-devel-2.6.18-434.el5.i686.rpm noarch: kernel-doc-2.6.18-434.el5.noarch.rpm s390x: kernel-2.6.18-434.el5.s390x.rpm kernel-debug-2.6.18-434.el5.s390x.rpm kernel-debug-debuginfo-2.6.18-434.el5.s390x.rpm kernel-debug-devel-2.6.18-434.el5.s390x.rpm kernel-debuginfo-2.6.18-434.el5.s390x.rpm kernel-debuginfo-common-2.6.18-434.el5.s390x.rpm kernel-devel-2.6.18-434.el5.s390x.rpm kernel-headers-2.6.18-434.el5.s390x.rpm kernel-kdump-2.6.18-434.el5.s390x.rpm kernel-kdump-debuginfo-2.6.18-434.el5.s390x.rpm kernel-kdump-devel-2.6.18-434.el5.s390x.rpm x86_64: kernel-2.6.18-434.el5.x86_64.rpm kernel-debug-2.6.18-434.el5.x86_64.rpm kernel-debug-debuginfo-2.6.18-434.el5.x86_64.rpm kernel-debug-devel-2.6.18-434.el5.x86_64.rpm kernel-debuginfo-2.6.18-434.el5.x86_64.rpm kernel-debuginfo-common-2.6.18-434.el5.x86_64.rpm kernel-devel-2.6.18-434.el5.x86_64.rpm kernel-headers-2.6.18-434.el5.x86_64.rpm kernel-xen-2.6.18-434.el5.x86_64.rpm kernel-xen-debuginfo-2.6.18-434.el5.x86_64.rpm kernel-xen-devel-2.6.18-434.el5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2018-3620 https://access.redhat.com/security/cve/CVE-2018-3646 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details athttps://access.redhat.com/security/team/contact Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBW4bl89zjgjWX9erEAQj9pQ/8C7p6nQdJOOZJed/nnSnKY/Q/qQbJ7OCJ 8XGQrasq/G1sKDMLLZgn4qsvO7m++/mjbJkwicciWbw4W6exWr13XIF0hStYcGUD YciZMDJhbCT5ZHL3rumrcgdVKGo7Ig5p2cwJHTozV3UAK2jXuv4pH2L/6C9QXSlc DWiNgK63iaGHxmayu1tRnLDoGhNYZUf+cGOCXJsNGtMeLuK19DdpFmqmNtkaEo0Z OSsI53cxtVP48bVsnHJn8fMeih8Bn6/v5NQ408LXf4zGgHg7p0rFWVPQhVQbiPjC tFOjT6/Jg5w36J3lBky6tEXkK7CNfxsHPQ5jJ/9PsigyruHQJfbA2A9St1o6WBYs LtSw3P47POSy+w01n07hPump2ejObYBa8Aaja0uV8AykVVrSaB2XBqMs+jtJCvuc OLqUHvqogqFpfg68Vc5Q8G8bPi5W3j2s7BEdDeYc4ykppBVwoyyXj5E29+kQo/8r pvCmzDwfuJY/maFsSchovpW2lBGDz5KtCZKfXCblc/igAnG++iyDB+84r1BPwxoi nsKJF1dZ4EhZP9i13RtmGlMwLhr0+L62oCCq8ErmNBqjQX3rggEddhWej166Hk7T fDgDFrJyTaIticrfrfLQZByZ6CY10qM/GtbHaCQd6pZ8Yq9wQvYXwbpcSn0UeEBc 0wYKoQUCEuQ=ZBXE -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical kernel security patch for Red Hat Enterprise Linux, targeting substantial vulnerabilities and necessitating a system restart.. RedHat Kernel Update, Security Advisory Bandwidth, Memory Protection, Important Update, Linux Server Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 29, 2018 Important Red Hat
200

Scientific Linux 6 x86/x64: SLSA-2018-2390-1 Important Kernel Fixes

Modern operating systems implement virtualization of physical memory to efficiently use available system resources and provide inter-domain protection through access control and isolation. The L1TF issue was found in the way the x86 microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimisation) in combination with handling of page-fault [More...]. Synopsis: Important: kernel security and bug fix update Advisory ID: SLSA-2018:2390-1 Issue Date: 2018-08-14 CVE Numbers: CVE-2018-1000004 CVE-2017-15265 CVE-2018-7566 CVE-2017-0861 CVE-2018-3693 CVE-2018-3646 CVE-2018-10901 -- Security Fix(es): * Modern operating systems implement virtualization of physical memory to efficiently use available system resources and provide inter-domain protection through access control and isolation. The L1TF issue was found in the way the x86 microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimisation) in combination with handling of page-faults caused by terminated virtual to physical address resolving process. As a result, an unprivileged attacker could use this flaw to read privileged memory of the kernel or other processes and/or cross guest/host boundaries to read host memory by conducting targeted cache side-channel attacks. (CVE-2018-3620, CVE-2018-3646) * An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions past bounds check. The flaw relies on the presence of a precisely-defined instruction sequence in the privileged code and the fact that memory writes occur to an address which depends on the untrusted value. Such writes cause an update into the microprocessor's data cache even for speculatively executed instructions that never actually commit (retire). As a result, an unprivilegedattacker could use this flaw to influence speculative execution and/or read privileged memory by conducting targeted cache side- channel attacks. (CVE-2018-3693) * kernel: kvm: vmx: host GDT limit corruption (CVE-2018-10901) * kernel: Use-after-free in snd_pcm_info function in ALSA subsystem potentially leads to privilege escalation (CVE-2017-0861) * kernel: Use-after-free in snd_seq_ioctl_create_port() (CVE-2017-15265) * kernel: race condition in snd_seq_write() may lead to UAF or OOB-access (CVE-2018-7566) * kernel: Race condition in sound system can lead to denial of service (CVE-2018-1000004) Bug Fix(es): * The Least recently used (LRU) operations are batched by caching pages in per-cpu page vectors to prevent contention of the heavily used lru_lock spinlock. The page vectors can hold even the compound pages. Previously, the page vectors were cleared only if they were full. Subsequently, the amount of memory held in page vectors, which is not reclaimable, was sometimes too high. Consequently the page reclamation started the Out of Memory (OOM) killing processes. With this update, the underlying source code has been fixed to clear LRU page vectors each time when a compound page is added to them. As a result, OOM killing processes due to high amounts of memory held in page vectors no longer occur. -- SL6 x86_64 kernel-2.6.32-754.3.5.el6.x86_64.rpm kernel-debug-2.6.32-754.3.5.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-754.3.5.el6.i686.rpm kernel-debug-debuginfo-2.6.32-754.3.5.el6.x86_64.rpm kernel-debug-devel-2.6.32-754.3.5.el6.i686.rpm kernel-debug-devel-2.6.32-754.3.5.el6.x86_64.rpm kernel-debuginfo-2.6.32-754.3.5.el6.i686.rpm kernel-debuginfo-2.6.32-754.3.5.el6.x86_64.rpm kernel-debuginfo-common-i686-2.6.32-754.3.5.el6.i686.rpm kernel-debuginfo-common-x86_64-2.6.32-754.3.5.el6.x86_64.rpm kernel-devel-2.6.32-754.3.5.el6.x86_64.rpm kernel-headers-2.6.32-754.3.5.el6.x86_64.rpm perf-2.6.32-754.3.5.el6.x86_64.rpm perf-debuginfo-2.6.32-754.3.5.el6.i686.rpm perf-debuginfo-2.6.32-754.3.5.el6.x86_64.rpm python-perf-debuginfo-2.6.32-754.3.5.el6.i686.rpm python-perf-debuginfo-2.6.32-754.3.5.el6.x86_64.rpm python-perf-2.6.32-754.3.5.el6.x86_64.rpm i386 kernel-2.6.32-754.3.5.el6.i686.rpm kernel-debug-2.6.32-754.3.5.el6.i686.rpm kernel-debug-debuginfo-2.6.32-754.3.5.el6.i686.rpm kernel-debug-devel-2.6.32-754.3.5.el6.i686.rpm kernel-debuginfo-2.6.32-754.3.5.el6.i686.rpm kernel-debuginfo-common-i686-2.6.32-754.3.5.el6.i686.rpm kernel-devel-2.6.32-754.3.5.el6.i686.rpm kernel-headers-2.6.32-754.3.5.el6.i686.rpm perf-2.6.32-754.3.5.el6.i686.rpm perf-debuginfo-2.6.32-754.3.5.el6.i686.rpm python-perf-debuginfo-2.6.32-754.3.5.el6.i686.rpm python-perf-2.6.32-754.3.5.el6.i686.rpm noarch kernel-abi-whitelists-2.6.32-754.3.5.el6.noarch.rpm kernel-doc-2.6.32-754.3.5.el6.noarch.rpm kernel-firmware-2.6.32-754.3.5.el6.noarch.rpm - Scientific Linux Development Team . A recent update for the Scientific Linux kernel addresses multiple security issues, improving overall system integrity and memory management.. Kernel Update, Security Fix, Scientific Linux, Memory Protection. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 15, 2018 Important Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200