Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
202

Ubuntu 22.04 Systemd-Service Improvements Major Resource Drain Fixes

An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for cockpit-subscriptions ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20532-1 Rating: important References: * bsc#1258637 Cross-References: * CVE-2026-26996 CVSS scores: * CVE-2026-26996 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-26996 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for cockpit-subscriptions fixes the following issue: - CVE-2026-26996: minimatch: ReDoS when glob pattern contains many consecutive wildcards followed by a literal character that doesn't appear in the test string (bsc#1258637). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-555=1 Package List: - openSUSE Leap 16.0: cockpit-subscriptions-12.1-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-26996.html . A critical update for openSUSE cockpit-subscriptions addresses a significant issue related to ReDoS vulnerabilities.. openSUSE security update, cockpit-subscriptions patch, CVE-2026-26996 fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 21, 2026 Important OpenSUSE
100

SUSE 2026 21111-1 cockpit-subscriptions Important ReDoS CVE-2026-26996

An update that solves one vulnerability can now be installed.. # Security update for cockpit-subscriptions Announcement ID: SUSE-SU-2026:21111-1 Release Date: 2026-04-14T12:13:04Z Rating: important References: * bsc#1258637 Cross-References: * CVE-2026-26996 CVSS scores: * CVE-2026-26996 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-26996 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-26996 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-26996 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for cockpit-subscriptions fixes the following issue: * CVE-2026-26996: minimatch: ReDoS when glob pattern contains many consecutive wildcards followed by a literal character that doesn't appear in the test string (bsc#1258637). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-555=1 ## Package List: * SUSE Linux Micro 6.2 (noarch) * cockpit-subscriptions-12.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-26996.html * https://bugzilla.suse.com/show_bug.cgi?id=1258637 . Update for SUSE cockpit-subscriptions fixes CVE-2026-26996 with important severity. Immediate action recommended.. SUSE Security Advisory, cockpit-subscriptions update, ReDoS issue resolution, SUSE Linux Micro security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 16, 2026 Important SuSE
100

SUSE Linux Patch 8.0 Fixing Major Vulnerability SUSE-PT-2027-45067-9

An update that solves one vulnerability can now be installed.. # Security update for cockpit-repos Announcement ID: SUSE-SU-2026:20967-1 Release Date: 2026-04-05T02:50:21Z Rating: important References: * bsc#1258637 Cross-References: * CVE-2026-26996 CVSS scores: * CVE-2026-26996 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-26996 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-26996 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-26996 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for cockpit-repos fixes the following issue: * CVE-2026-26996: minimatch: ReDoS when glob pattern contains many consecutive wildcards followed by a literal character that doesn't appear in the test string (bsc#1258637). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-478=1 ## Package List: * SUSE Linux Micro 6.2 (noarch) * cockpit-repos-4.7-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-26996.html * https://bugzilla.suse.com/show_bug.cgi?id=1258637 . An important update for SUSE Linux Micro to patch a critical minimatch issue, addressing performance and security risks.. SUSE Linux Micro,payload management,security patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 08, 2026 Important SuSE
100

SUSE Linux Micro 6.2 Cockpit-Repos Important ReDoS Warning 2026-20973-1

An update that solves one vulnerability can now be installed.. # Security update for cockpit-repos Announcement ID: SUSE-SU-2026:20973-1 Release Date: 2026-04-05T02:50:21Z Rating: important References: * bsc#1258637 Cross-References: * CVE-2026-26996 CVSS scores: * CVE-2026-26996 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-26996 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-26996 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-26996 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for cockpit-repos fixes the following issue: * CVE-2026-26996: minimatch: ReDoS when glob pattern contains many consecutive wildcards followed by a literal character that doesn't appear in the test string (bsc#1258637). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-478=1 ## Package List: * SUSE Linux Micro 6.2 (noarch) * cockpit-repos-4.7-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-26996.html * https://bugzilla.suse.com/show_bug.cgi?id=1258637 . SUSE update for cockpit-repos addresses important ReDoS issue due to CVE-2026-26996 that enhances system security.. SUSE Security Update,cockpit-repos ReDoS fix,system security updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 08, 2026 Important SuSE
172

Ubuntu 20.04 & 18.04 LTS USN-6086-1 Critical Minimatch Risk

minimatch could be made to crash if it opened a specially crafted input file.. =========================================================================Ubuntu Security Notice USN-6086-1 May 18, 2023 node-minimatch vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: minimatch could be made to crash if it opened a specially crafted input file. Software Description: - node-minimatch: A glob matcher in javascript Details: It was discovered that minimatch incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: node-minimatch 3.0.4-4ubuntu0.1 Ubuntu 18.04 LTS: node-minimatch 3.0.4-3+deb10u1build0.18.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6086-1 CVE-2022-3517 Package Information: https://launchpad.net/ubuntu/+source/node-minimatch/3.0.4-4ubuntu0.1 https://launchpad.net/ubuntu/+source/node-minimatch/3.0.4-3+deb10u1build0.18.04.1 . Ubuntu 20.04 and 18.04 LTS are exposed to a vulnerability in minimatch, which may lead to possible denial of service. Immediate update is necessary.. node-minimatch update, ubuntu security notice, denial of service exploits. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 18, 2023 Critical Ubuntu
98

Red Hat: RHSA-2016-1583-01 Moderate: Minimatch Denial Of Service

An update for rh-nodejs4-nodejs-minimatch is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-nodejs4-nodejs-minimatch security update Advisory ID: RHSA-2016:1583-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2016:1583.html Issue date: 2016-08-09 CVE Names: CVE-2016-1000023 ==================================================================== 1. Summary: An update for rh-nodejs4-nodejs-minimatch is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.6) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.7) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.1) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.2) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch 3. Description: Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript RegExp objects. Security Fix(es): * A regular expressiondenial of service flaw was found in Minimatch. An attacker able to make an application using Minimatch to perform matching using a specially crafted glob pattern could cause the application to consume an excessive amount of CPU. (CVE-2016-1000023) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1348509 - CVE-2016-1000023 nodejs-minimatch: Regular expression denial-of-service 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6): Source: rh-nodejs4-nodejs-minimatch-3.0.2-1.el6.src.rpm noarch: rh-nodejs4-nodejs-minimatch-3.0.2-1.el6.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.6): Source: rh-nodejs4-nodejs-minimatch-3.0.2-1.el6.src.rpm noarch: rh-nodejs4-nodejs-minimatch-3.0.2-1.el6.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.7): Source: rh-nodejs4-nodejs-minimatch-3.0.2-1.el6.src.rpm noarch: rh-nodejs4-nodejs-minimatch-3.0.2-1.el6.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6): Source: rh-nodejs4-nodejs-minimatch-3.0.2-1.el6.src.rpm noarch: rh-nodejs4-nodejs-minimatch-3.0.2-1.el6.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7): Source: rh-nodejs4-nodejs-minimatch-3.0.2-1.el7.src.rpm noarch: rh-nodejs4-nodejs-minimatch-3.0.2-1.el7.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.1): Source: rh-nodejs4-nodejs-minimatch-3.0.2-1.el7.src.rpm noarch: rh-nodejs4-nodejs-minimatch-3.0.2-1.el7.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.2): Source: rh-nodejs4-nodejs-minimatch-3.0.2-1.el7.src.rpm noarch: rh-nodejs4-nodejs-minimatch-3.0.2-1.el7.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v.7): Source: rh-nodejs4-nodejs-minimatch-3.0.2-1.el7.src.rpm noarch: rh-nodejs4-nodejs-minimatch-3.0.2-1.el7.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2016-1000023 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFXqawYXlSAg2UNWIIRAtdmAJ9lGkj95j/T7JXR91BochGvRa5YRwCdGd3+ 9yWZvLJXl5zpPR2DcwNATns=bVWG -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Patch released addresses vulnerability in Minimatch for Red Hat Software Collections, categorized as moderate severity.. Red Hat Software Collections, Minimatch Security Update, Node.js Security Fix. . LinuxSecurity.com Team

Calendar%202 Aug 09, 2016 Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200