Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
89

Fedora 40: 2025-e6f5710dba critical: perl String Comparison Timing Attack

This release fixes CVE-2024-13939 (leaking the length of a secret string). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e6f5710dba 2025-04-17 19:32:14.984687+00:00 -------------------------------------------------------------------------------- Name : perl-String-Compare-ConstantTime Product : Fedora 40 Version : 0.321 Release : 19.fc40 URL : https://metacpan.org/dist/String-Compare-ConstantTime Summary : Timing side-channel protected string compare Description : This module provides one function, "equals", which works like perl's "eq", but which does not provide a timing side-channel. Such comparison is useful when matching against a secret string. -------------------------------------------------------------------------------- Update Information: This release fixes CVE-2024-13939 (leaking the length of a secret string) -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 1 2025 Petr Pisar - 0.321-19 - Fix CVE-2024-13939 (leaking the length of a secret string) (bug #2355704) * Tue Aug 6 2024 Miroslav Suchý - 0.321-18 - convert license to SPDX -------------------------------------------------------------------------------- References: [ 1 ] Bug #2355663 - CVE-2024-13939 String-Compare-ConstantTime: String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string https://bugzilla.redhat.com/show_bug.cgi?id=2355663 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e6f5710dba' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keysused by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- . The perl-String-Compare-ConstantTime package update addresses the length leakage vulnerability in Fedora 40. Improvements made to the secure string comparison protocol.. Fedora Update, perl module, string comparison, timing attack, security fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 17, 2025 Critical Fedora
203

Mageia 7: MGASA-2021-0131 Critical: Ansible Data Leak Fix

User data leak in snmp_facts module (CVE-2021-20178). Multiple collections exposed secured values (CVE-2021-20191). In basic.py, no_log with fallback option (CVE-2021-20228). The ansible package has been patched to fix these issues. . MGASA-2021-0131 - Updated ansible packages fix security vulnerability Publication date: 12 Mar 2021 URL: https://advisories.mageia.org/MGASA-2021-0131.html Type: security Affected Mageia releases: 7 CVE: CVE-2021-20178, CVE-2021-20191, CVE-2021-20228 User data leak in snmp_facts module (CVE-2021-20178). Multiple collections exposed secured values (CVE-2021-20191). In basic.py, no_log with fallback option (CVE-2021-20228). The ansible package has been patched to fix these issues. References: - https://bugs.mageia.org/show_bug.cgi?id=28436 - https://access.redhat.com/errata/RHSA-2021:0664 - https://www.cve.org/CVERecord?id=CVE-2021-20178 - https://www.cve.org/CVERecord?id=CVE-2021-20191 - https://www.cve.org/CVERecord?id=CVE-2021-20228 SRPMS: - 7/core/ansible-2.7.18-1.2.mga7 . Revised Ansible distributions for Mageia address several security vulnerabilities linked to information leaks and module disclosures.. Ansible Patch Update, Mageia Security Fix, Data Exposure Resolution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 11, 2021 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here