Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 589
Alerts This Week
Warning Icon 1 589

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 8 articles for you...
202

openSUSE Leap 15 SP5 Kernel Enhancements Major Updates 10 Issues Fixed

An update that solves 11 vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 30 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:1049-1 Release Date: 2026-03-26T05:04:44Z Rating: important References: * bsc#1247240 * bsc#1250730 * bsc#1254755 * bsc#1255053 * bsc#1255378 * bsc#1255402 * bsc#1255595 * bsc#1256624 * bsc#1256644 * bsc#1257118 * bsc#1257629 Cross-References: * CVE-2022-50697 * CVE-2023-53257 * CVE-2023-53781 * CVE-2025-21738 * CVE-2025-38159 * CVE-2025-38488 * CVE-2025-40258 * CVE-2025-68284 * CVE-2025-68285 * CVE-2025-68813 * CVE-2025-71085 CVSS scores: * CVE-2022-50697 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2022-50697 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-53257 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2023-53257 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-53257 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-53257 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-53781 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2023-53781 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-21738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-21738 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-21738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38159 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38159 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38159 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2025-38488 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38488 ( SUSE ): 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38488 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40258 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40258 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68284 ( SUSE ): 7.0 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-68284 ( SUSE ): 7.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2025-68285 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-68285 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68813 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-68813 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71085 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71085 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.121 fixes various security issues The following security issues were fixed: * CVE-2022-50697: mrp: introduce active flags to prevent UAF when applicant uninit (bsc#1255595). * CVE-2023-53257: wifi: mac80211: check S1G action frame size (bsc#1250730). * CVE-2023-53781: smc: Fix use-after-free in tcp_write_timer_handler() (bsc#1254755). * CVE-2025-21738: ata: libata-sff: ensure that we cannot write outside the allocated buffer(bsc#1257118). * CVE-2025-38159: wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds (bsc#1257629). * CVE-2025-38488: smb: client: fix use-after-free in crypt_message when using async crypto (bsc#1247240). * CVE-2025-40258: mptcp: fix race condition in mptcp_schedule_work() (bsc#1255053). * CVE-2025-68284: libceph: prevent potential out-of-bounds writes in handle_auth_session_key() (bsc#1255378). * CVE-2025-68285: libceph: fix potential use-after-free in have_mon_and_osd_map() (bsc#1255402). * CVE-2025-68813: ipvs: fix ipv4 null-ptr-deref in route error path (bsc#1256644). * CVE-2025-71085: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (bsc#1256624). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-1049=1 SUSE-SLE- Module-Live-Patching-15-SP5-2026-1052=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-1052=1 SUSE-2026-1049=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_100-default-15-150500.2.2 * kernel-livepatch-5_14_21-150500_55_100-default-debuginfo-15-150500.2.2 * kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-8-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-8-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_25-debugsource-15-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_30-debugsource-8-150500.2.1 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_100-default-15-150500.2.2 * kernel-livepatch-5_14_21-150500_55_100-default-debuginfo-15-150500.2.2 * kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-8-150500.2.1 *kernel-livepatch-5_14_21-150500_55_121-default-8-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_25-debugsource-15-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_30-debugsource-8-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2022-50697.html * https://www.suse.com/security/cve/CVE-2023-53257.html * https://www.suse.com/security/cve/CVE-2023-53781.html * https://www.suse.com/security/cve/CVE-2025-21738.html * https://www.suse.com/security/cve/CVE-2025-38159.html * https://www.suse.com/security/cve/CVE-2025-38488.html * https://www.suse.com/security/cve/CVE-2025-40258.html * https://www.suse.com/security/cve/CVE-2025-68284.html * https://www.suse.com/security/cve/CVE-2025-68285.html * https://www.suse.com/security/cve/CVE-2025-68813.html * https://www.suse.com/security/cve/CVE-2025-71085.html * https://bugzilla.suse.com/show_bug.cgi?id=1247240 * https://bugzilla.suse.com/show_bug.cgi?id=1250730 * https://bugzilla.suse.com/show_bug.cgi?id=1254755 * https://bugzilla.suse.com/show_bug.cgi?id=1255053 * https://bugzilla.suse.com/show_bug.cgi?id=1255378 * https://bugzilla.suse.com/show_bug.cgi?id=1255402 * https://bugzilla.suse.com/show_bug.cgi?id=1255595 * https://bugzilla.suse.com/show_bug.cgi?id=1256624 * https://bugzilla.suse.com/show_bug.cgi?id=1256644 * https://bugzilla.suse.com/show_bug.cgi?id=1257118 * https://bugzilla.suse.com/show_bug.cgi?id=1257629 . Update for openSUSE solves 11 important issues in the kernel, enhancing security and stability.. openSUSE Kernel Update important security issues vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 26, 2026 Important OpenSUSE
91

Gentoo Vim High Multiple Execution Threat GLSA-202601-02 CVE-2025-53905

Multiple vulnerabilities have been discovered in Vim and gVim, the worst of which could lead to execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202601-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Vim, gVim: Multiple Vulnerabilities Date: January 26, 2026 Bugs: #961498 ID: 202601-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in Vim and gVim, the worst of which could lead to execution of arbitrary code. Background ========== Vim is an efficient, highly configurable improved version of the classic ‘vi’ text editor. gVim is the GUI version of Vim. Affected packages ================= Package Vulnerable Unaffected -------------------- ------------ ------------ app-editors/gvim < 9.1.1652 > = 9.1.1652 app-editors/vim < 9.1.1652 > = 9.1.1652 app-editors/vim-core < 9.1.1652 > = 9.1.1652 Description =========== Multiple vulnerabilities have been discovered in Vim, gVim. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Vim, gVim users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-editors/vim-9.1.1652" All Vim, gVim users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-editors/vim-core-9.1.1652" All Vim, gVim users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=app-editors/gvim-9.1.1652" References ========== [ 1 ] CVE-2025-53905 https://nvd.nist.gov/vuln/detail/CVE-2025-53905 [ 2 ] CVE-2025-53906 https://nvd.nist.gov/vuln/detail/CVE-2025-53906 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202601-02 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2026 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5 . Critical vulnerabilities found in Vim and gVim could lead to arbitrary code execution. Upgrade recommended.. Vim vulnerabilities, Gentoo security advisory, gVim update, high-risk security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 26, 2026 Critical Gentoo
172

Ubuntu 20.04 LTS: MySQL Important Security Issues Update USN-7691-2

Several security issues were fixed in MySQL.. ======================================================================= Ubuntu Security Notice USN-7691-2 October 06, 2025 mysql-8.0 vulnerabilities ======================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in MySQL. Software Description: - mysql-8.0: MySQL database Details: USN-7691-1 fixed several vulnerabilities in MySQL. This update provides the corresponding update for Ubuntu 20.04 LTS. Original advisory details: Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 8.0.43 in Ubuntu 20.04 LTS In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-43.html https://www.oracle.com/security-alerts/cpujul2025.html Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS mysql-server 8.0.43-0ubuntu0.20.04.1+esm1 Available with Ubuntu Pro mysql-server-8.0 8.0.43-0ubuntu0.20.04.1+esm1 Available with Ubuntu Pro This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7691-2 https://ubuntu.com/security/notices/USN-7691-1 CVE-2025-50077, CVE-2025-50078, CVE-2025-50079, CVE-2025-50080, CVE-2025-50081, CVE-2025-50082, CVE-2025-50083,CVE-2025-50084, CVE-2025-50085, CVE-2025-50086, CVE-2025-50087, CVE-2025-50091, CVE-2025-50092, CVE-2025-50093, CVE-2025-50094, CVE-2025-50096, CVE-2025-50097, CVE-2025-50098, CVE-2025-50099, CVE-2025-50100, CVE-2025-50101, CVE-2025-50102, CVE-2025-50104, CVE-2025-53023 . Multiple security issues fixed in MySQL for Ubuntu 20.04 LTS, update recommended for improved safety.. MySQL update, Ubuntu 20.04 security, important security fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 06, 2025 Important Ubuntu
91

Gentoo: 202102-02 Normal: Mozilla Thunderbird Multiple Code Execution Risks

Multiple vulnerabilities have been found in Mozilla Thunderbird, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202102-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Mozilla Thunderbird: Multiple vulnerabilities Date: February 01, 2021 Bugs: #767394 ID: 202102-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Mozilla Thunderbird, the worst of which could result in the arbitrary execution of code. Background ========= Mozilla Thunderbird is a popular open-source email client from the Mozilla project. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-client/thunderbird < 78.7.0 > = 78.7.0 2 mail-client/thunderbird-bin < 78.7.0 > = 78.7.0 ------------------------------------------------------------------- 2 affected packages Description ========== Multiple vulnerabilities have been discovered in Mozilla Thunderbird. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Mozilla Thunderbird users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-client/thunderbird-78.7.0" All Mozilla Thunderbird binary users should upgrade to thelatest version: # emerge --sync # emerge --ask --oneshot -v "> =mail-client/thunderbird-bin-78.7.0" References ========= [ 1 ] CVE-2020-15685 https://nvd.nist.gov/vuln/detail/CVE-2020-15685 [ 2 ] CVE-2020-26976 https://nvd.nist.gov/vuln/detail/CVE-2020-26976 [ 3 ] CVE-2021-23953 https://nvd.nist.gov/vuln/detail/CVE-2021-23953 [ 4 ] CVE-2021-23954 https://nvd.nist.gov/vuln/detail/CVE-2021-23954 [ 5 ] CVE-2021-23960 https://nvd.nist.gov/vuln/detail/CVE-2021-23960 [ 6 ] CVE-2021-23964 https://nvd.nist.gov/vuln/detail/CVE-2021-23964 [ 7 ] Upstream advisory (MFSA-2021-05) https://www.mozilla.org/en-US/security/advisories/mfsa2021-05/ Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202102-02 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2021 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Mozilla Firefox encounters major threats due to various weaknesses. Update immediately for better protection and performance.. Mozilla Thunderbird, Gentoo Security, Multiple Risks, Software Upgrade. . LinuxSecurity.com Team

Calendar%202 Jan 31, 2021 Gentoo
91

Gentoo: GLSA-202007-05 Normal: libexif Multiple Code Execution Threats

Multiple vulnerabilities have been found in libexif, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202007-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libexif: Multiple vulnerabilities Date: July 26, 2020 Bugs: #708728 ID: 202007-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in libexif, the worst of which could result in the arbitrary execution of code. Background ========= libexif is a library for parsing, editing and saving Exif metadata from images. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/libexif < 0.6.22 > = 0.6.22 Description ========== Multiple vulnerabilities have been discovered in libexif. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All libexif users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/libexif-0.6.22" References ========= [ 1 ] CVE-2016-6328 https://nvd.nist.gov/vuln/detail/CVE-2016-6328 [ 2 ] CVE-2019-9278 https://nvd.nist.gov/vuln/detail/CVE-2019-9278 [ 3 ] CVE-2020-0093 https://nvd.nist.gov/vuln/detail/CVE-2020-0093 [ 4 ] CVE-2020-12767 https://nvd.nist.gov/vuln/detail/CVE-2020-12767 [ 5 ] CVE-2020-13112 https://nvd.nist.gov/vuln/detail/CVE-2020-13112 [ 6 ] CVE-2020-13113 https://nvd.nist.gov/vuln/detail/CVE-2020-13113 [ 7 ] CVE-2020-13114 https://nvd.nist.gov/vuln/detail/CVE-2020-13114 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202007-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org . License ====== Copyright 2020 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo GLSA 202007-06 warns of serious vulnerabilities in libjpeg, crucial for image manipulation. Immediate action recommended.. Gentoo, libexif, code execution, security advisory, image processing. . LinuxSecurity.com Team

Calendar%202 Jul 26, 2020 Gentoo
91

Gentoo: GLSA-202007-03 Normal: Cacti Multiple Code Execution Risks

Multiple vulnerabilities have been found in Cacti, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202007-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Cacti: Multiple vulnerabilities Date: July 26, 2020 Bugs: #728678, #732522 ID: 202007-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Cacti, the worst of which could result in the arbitrary execution of code. Background ========= Cacti is a complete frontend to rrdtool. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-analyzer/cacti < 1.2.13 > = 1.2.13 2 net-analyzer/cacti-spine < 1.2.13 > = 1.2.13 ------------------------------------------------------------------- 2 affected packages Description ========== Multiple vulnerabilities have been discovered in Cacti. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Cacti users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-analyzer/cacti-1.2.13" All Cacti Spine users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =net-analyzer/cacti-spine-1.2.13" References ========= [ 1 ]CVE-2020-11022 https://nvd.nist.gov/vuln/detail/CVE-2020-11022 [ 2 ] CVE-2020-11023 https://nvd.nist.gov/vuln/detail/CVE-2020-11023 [ 3 ] CVE-2020-14295 https://nvd.nist.gov/vuln/detail/CVE-2020-14295 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202007-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org . License ====== Copyright 2020 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Cacti running on Gentoo Linux presents various vulnerabilities, including one that permits unauthorized code execution. It is recommended to update to reduce potential threats.. Cacti Security, Gentoo Linux Advisory, Code Execution Risks. . LinuxSecurity.com Team

Calendar%202 Jul 26, 2020 Gentoo
91

Gentoo: GLSA-202006-08 Normal: WebKitGTK+ Multiple Threats

Multiple vulnerabilities have been found in WebKitGTK+, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202006-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: WebKitGTK+: Multiple vulnerabilities Date: June 13, 2020 Bugs: #712260 ID: 202006-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in WebKitGTK+, the worst of which could result in the arbitrary execution of code. Background ========= WebKitGTK+ is a full-featured port of the WebKit rendering engine, suitable for projects requiring any kind of web integration, from hybrid HTML/CSS applications to full-fledged web browsers. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-libs/webkit-gtk < 2.28.2 > = 2.28.2 Description ========== Multiple vulnerabilities have been discovered in WebKitGTK+. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All WebKitGTK+ users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-libs/webkit-gtk-2.28.2" References ========= [ 1 ] CVE-2020-10018 https://nvd.nist.gov/vuln/detail/CVE-2020-10018 [ 2 ] CVE-2020-10018 https://nvd.nist.gov/vuln/detail/CVE-2020-10018 [ 3 ] CVE-2020-11793 https://nvd.nist.gov/vuln/detail/CVE-2020-11793 [ 4 ] CVE-2020-11793 https://nvd.nist.gov/vuln/detail/CVE-2020-11793 [ 5 ] CVE-2020-3885 https://nvd.nist.gov/vuln/detail/CVE-2020-3885 [ 6 ] CVE-2020-3894 https://nvd.nist.gov/vuln/detail/CVE-2020-3894 [ 7 ] CVE-2020-3895 https://nvd.nist.gov/vuln/detail/CVE-2020-3895 [ 8 ] CVE-2020-3897 https://nvd.nist.gov/vuln/detail/CVE-2020-3897 [ 9 ] CVE-2020-3899 https://nvd.nist.gov/vuln/detail/CVE-2020-3899 [ 10 ] CVE-2020-3900 https://nvd.nist.gov/vuln/detail/CVE-2020-3900 [ 11 ] CVE-2020-3901 https://nvd.nist.gov/vuln/detail/CVE-2020-3901 [ 12 ] CVE-2020-3902 https://nvd.nist.gov/vuln/detail/CVE-2020-3902 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202006-08 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2020 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Various vulnerabilities found in WebKitGTK+ may result in unauthorized code execution. All users are advised to update promptly.. WebKitGTK+ Security, Gentoo Linux Updates, Code Execution Risk. . LinuxSecurity.com Team

Calendar%202 Jun 12, 2020 Gentoo
91

Gentoo: GLSA-201908-08 Normal: CUPS Multiple Code Execution Risks

Multiple vulnerabilities have been found in CUPS, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201908-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: CUPS: Multiple vulnerabilities Date: August 15, 2019 Bugs: #660954 ID: 201908-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in CUPS, the worst of which could result in the arbitrary execution of code. Background ========= CUPS, the Common Unix Printing System, is a full-featured print server. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-print/cups < 2.2.8 > = 2.2.8 Description ========== Multiple vulnerabilities have been discovered in CUPS. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All CUPS users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-print/cups-2.2.8" References ========= [ 1 ] CVE-2017-15400 https://nvd.nist.gov/vuln/detail/CVE-2017-15400 [ 2 ] CVE-2018-4180 https://nvd.nist.gov/vuln/detail/CVE-2018-4180 [ 3 ] CVE-2018-4181 https://nvd.nist.gov/vuln/detail/CVE-2018-4181 [ 4 ] CVE-2018-4182 https://nvd.nist.gov/vuln/detail/CVE-2018-4182 [ 5 ] CVE-2018-4183 https://nvd.nist.gov/vuln/detail/CVE-2018-4183 [ 6 ] CVE-2018-6553 https://nvd.nist.gov/vuln/detail/CVE-2018-6553 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201908-08 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2019 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Serious flaws identified in CUPS may allow for unauthorized code execution. Update immediately to ensure protection.. Gentoo Linux,CUPS vulnerabilities,multiple security issues,CUPS update. . LinuxSecurity.com Team

Calendar%202 Aug 15, 2019 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200