Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Multiple vulnerabilities where identified in polkit, a toolkit for defining and handling the policy that allows unprivileged processes to speak to privileged processes. CVE-2021-4115 Kevin Backhouse of GitHub Security Lab (GHSL) found that there is a. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4553-1
Multiple vulnerabilities have been discovered in Asterisk, the worst of which can lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202601-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Asterisk: Multiple Vulnerabilities Date: January 26, 2026 Bugs: #960930 ID: 202601-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in Asterisk, the worst of which can lead to arbitrary code execution. Background ========== Asterisk is an open source telephony engine and toolkit. Affected packages ================= Package Vulnerable Unaffected ----------------- ------------ ------------ net-misc/asterisk < 18.26.3 > = 18.26.3 Description =========== Multiple vulnerabilities have been discovered in Asterisk. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== # emerge --sync # emerge --ask --oneshot --verbose "> =net-misc/asterisk-18.26.3" References ========== [ 1 ] CVE-2025-1131 https://nvd.nist.gov/vuln/detail/CVE-2025-1131 [ 2 ] CVE-2025-49832 https://nvd.nist.gov/vuln/detail/CVE-2025-49832 [ 3 ] CVE-2025-57767 https://nvd.nist.gov/vuln/detail/CVE-2025-57767 [ 4 ] GHSA-64qc-9x89-rx5j [ 5 ] GHSA-mrq5-74j5-f5cr [ 6 ] GHSA-v9q8-9j8m-5xwp Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202601-04 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuringthe confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been discovered in UDisks, the worst of which can lead to execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202511-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: UDisks: Multiple Vulnerabilities Date: November 24, 2025 Bugs: #827863, #962126 ID: 202511-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in UDisks, the worst of which can lead to execution of arbitrary code. Background ========== UDisks provides a daemon, tools and libraries to access and manipulate disks, storage devices and technologies. Affected packages ================= Package Vulnerable Unaffected ------------- ------------ ------------ sys-fs/udisks < 2.10.2 > = 2.10.2 Description =========== Multiple vulnerabilities have been discovered in UDisks. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All UDisks users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-fs/udisks-2.10.2" References ========== [ 1 ] CVE-2021-3802 https://nvd.nist.gov/vuln/detail/CVE-2021-3802 [ 2 ] CVE-2025-8067 https://nvd.nist.gov/vuln/detail/CVE-2025-8067 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202511-01 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is ofutmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been discovered in GPL Ghostscript, the worst of which can lead to execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202508-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: GPL Ghostscript: Multiple Vulnerabilities Date: August 06, 2025 Bugs: #951285, #955140 ID: 202508-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in GPL Ghostscript, the worst of which can lead to execution of arbitrary code. Background ========== Ghostscript is an interpreter for the PostScript language and for PDF. Affected packages ================= Package Vulnerable Unaffected ------------------------ ------------ ------------ app-text/ghostscript-gpl < 10.05.1 > = 10.05.1 Description =========== Multiple vulnerabilities have been discovered in GPL Ghostscript. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All GPL Ghostscript users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-text/ghostscript-gpl-10.05.1" References ========== [ 1 ] CVE-2025-27830 https://nvd.nist.gov/vuln/detail/CVE-2025-27830 [ 2 ] CVE-2025-27831 https://nvd.nist.gov/vuln/detail/CVE-2025-27831 [ 3 ] CVE-2025-27832 https://nvd.nist.gov/vuln/detail/CVE-2025-27832 [ 4 ] CVE-2025-27833 https://nvd.nist.gov/vuln/detail/CVE-2025-27833 [ 5 ] CVE-2025-27834 https://nvd.nist.gov/vuln/detail/CVE-2025-27834 [ 6 ] CVE-2025-27835 https://nvd.nist.gov/vuln/detail/CVE-2025-27835 [ 7 ] CVE-2025-27836 https://nvd.nist.gov/vuln/detail/CVE-2025-27836 [ 8 ] CVE-2025-27837 https://nvd.nist.gov/vuln/detail/CVE-2025-27837 [ 9 ] CVE-2025-46646 https://nvd.nist.gov/vuln/detail/CVE-2025-46646 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202508-02 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been discovered in Git, the worst of which could lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202507-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Git: Multiple Vulnerabilities Date: July 08, 2025 Bugs: #959733 ID: 202507-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in Git, the worst of which could lead to arbitrary code execution. Background ========== Git is a free and open source distributed version control system designed to handle everything from small to very large projects with speed and efficiency. Affected packages ================= Package Vulnerable Unaffected ----------- ------------ ------------ dev-vcs/git < 2.49.1 > = 2.49.1 Description =========== Multiple vulnerabilities have been discovered in Git. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Git users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-vcs/git-2.49.1" References ========== [ 1 ] CVE-2025-27613 https://nvd.nist.gov/vuln/detail/CVE-2025-27613 [ 2 ] CVE-2025-27614 https://nvd.nist.gov/vuln/detail/CVE-2025-27614 [ 3 ] CVE-2025-46334 https://nvd.nist.gov/vuln/detail/CVE-2025-46334 [ 4 ] CVE-2025-46835 https://nvd.nist.gov/vuln/detail/CVE-2025-46835 [ 5 ] CVE-2025-48384 https://nvd.nist.gov/vuln/detail/CVE-2025-48384 [ 6 ] CVE-2025-48385 https://nvd.nist.gov/vuln/detail/CVE-2025-48385 [ 7 ] CVE-2025-48386 https://nvd.nist.gov/vuln/detail/CVE-2025-48386 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202507-09 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been discovered in sudo, the worst of which could result in privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202507-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: sudo: Privilege escalation Date: July 01, 2025 Bugs: #959314 ID: 202507-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in sudo, the worst of which could result in privilege escalation. Background ========== sudo allows a system administrator to give users the ability to run commands as other users. Affected packages ================= Package Vulnerable Unaffected -------------- ------------ ------------ app-admin/sudo < 1.9.17_p1 > = 1.9.17_p1 Description =========== Multiple vulnerabilities have been discovered in sudo. Please review the CVE identifiers referenced below for details. Impact ====== An attacker can escalate privileges to root by providing a special argument to sudo's --chroot (which is used for chroot purposes). Please review the referenced CVE identifier for details. Workaround ========== There is no known workaround at this time. Resolution ========== All sudo users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-admin/sudo-1.9.17_p1" References ========== [ 1 ] CVE-2025-32462 https://nvd.nist.gov/vuln/detail/CVE-2025-32462 [ 2 ] CVE-2025-32463 https://nvd.nist.gov/vuln/detail/CVE-2025-32463 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202507-01 Concerns? ========= Security is a primaryfocus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been discovered in GStreamer and GStreamer Plugins, the worst of which could lead to code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202506-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: GStreamer, GStreamer Plugins: Multiple Vulnerabilities Date: June 12, 2025 Bugs: #948198 ID: 202506-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in GStreamer and GStreamer Plugins, the worst of which could lead to code execution. Background ========== GStreamer is an open source multimedia framework. Affected packages ================= Package Vulnerable Unaffected --------------------------- ------------ ------------ media-libs/gst-plugins-base < 1.24.10 > = 1.24.10 media-libs/gstreamer < 1.24.10 > = 1.24.10 Description =========== Multiple vulnerabilities have been discovered in GStreamer, GStreamer Plugins. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All GStreamer, GStreamer Plugins users should upgrade to the latest versions: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/gstreamer-1.24.10" "> =media-libs/gst-plugins-bad-1.24.10" References ========== [ 1 ] CVE-2024-44331 https://nvd.nist.gov/vuln/detail/CVE-2024-44331 [ 2 ] CVE-2024-47537 https://nvd.nist.gov/vuln/detail/CVE-2024-47537 [ 3 ] CVE-2024-47538 https://nvd.nist.gov/vuln/detail/CVE-2024-47538 [ 4 ] CVE-2024-47539 https://nvd.nist.gov/vuln/detail/CVE-2024-47539 [ 5 ] CVE-2024-47540 https://nvd.nist.gov/vuln/detail/CVE-2024-47540 [ 6 ] CVE-2024-47541 https://nvd.nist.gov/vuln/detail/CVE-2024-47541 [ 7 ] CVE-2024-47542 https://nvd.nist.gov/vuln/detail/CVE-2024-47542 [ 8 ] CVE-2024-47543 https://nvd.nist.gov/vuln/detail/CVE-2024-47543 [ 9 ] CVE-2024-47544 https://nvd.nist.gov/vuln/detail/CVE-2024-47544 [ 10 ] CVE-2024-47545 https://nvd.nist.gov/vuln/detail/CVE-2024-47545 [ 11 ] CVE-2024-47546 https://nvd.nist.gov/vuln/detail/CVE-2024-47546 [ 12 ] CVE-2024-47596 https://nvd.nist.gov/vuln/detail/CVE-2024-47596 [ 13 ] CVE-2024-47597 https://nvd.nist.gov/vuln/detail/CVE-2024-47597 [ 14 ] CVE-2024-47598 https://nvd.nist.gov/vuln/detail/CVE-2024-47598 [ 15 ] CVE-2024-47599 https://nvd.nist.gov/vuln/detail/CVE-2024-47599 [ 16 ] CVE-2024-47600 https://nvd.nist.gov/vuln/detail/CVE-2024-47600 [ 17 ] CVE-2024-47601 https://nvd.nist.gov/vuln/detail/CVE-2024-47601 [ 18 ] CVE-2024-47602 https://nvd.nist.gov/vuln/detail/CVE-2024-47602 [ 19 ] CVE-2024-47603 https://nvd.nist.gov/vuln/detail/CVE-2024-47603 [ 20 ] CVE-2024-47606 https://nvd.nist.gov/vuln/detail/CVE-2024-47606 [ 21 ] CVE-2024-47607 https://nvd.nist.gov/vuln/detail/CVE-2024-47607 [ 22 ] CVE-2024-47613 https://nvd.nist.gov/vuln/detail/CVE-2024-47613 [ 23 ] CVE-2024-47615 https://nvd.nist.gov/vuln/detail/CVE-2024-47615 [ 24 ] CVE-2024-47774 https://nvd.nist.gov/vuln/detail/CVE-2024-47774 [ 25 ] CVE-2024-47775 https://nvd.nist.gov/vuln/detail/CVE-2024-47775 [ 26 ] CVE-2024-47776 https://nvd.nist.gov/vuln/detail/CVE-2024-47776 [ 27 ] CVE-2024-47777 https://nvd.nist.gov/vuln/detail/CVE-2024-47777 [ 28 ] CVE-2024-47778 https://nvd.nist.gov/vuln/detail/CVE-2024-47778 [ 29 ] CVE-2024-47834 https://nvd.nist.gov/vuln/detail/CVE-2024-47834 [ 30 ] CVE-2024-47835 https://nvd.nist.gov/vuln/detail/CVE-2024-47835 [ 31 ]GStreamer-SA-2024-0003 [ 32 ] GStreamer-SA-2024-0004 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202506-02 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been discovered in NVIDIA Drivers, the worst of which could result in arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202505-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: NVIDIA Drivers: Multiple Vulnerabilities Date: May 12, 2025 Bugs: #954339 ID: 202505-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in NVIDIA Drivers, the worst of which could result in arbitrary code execution. Background ========== NVIDIA Drivers are NVIDIA's accelerated graphics driver. Affected packages ================= Package Vulnerable Unaffected -------------------------- ------------ ------------- x11-drivers/nvidia-drivers < 535.247.01 > = 535.247.01 Description =========== A vulnerability has been discovered in NVIDIA Drivers. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifier for details. Workaround ========== There is no known workaround at this time. Resolution ========== All NVIDIA Drivers 535 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =x11-drivers/nvidia-drivers-535.247.01:0/535" All NVIDIA Drivers 550 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =x11-drivers/nvidia-drivers-550.163.01:0/550" All NVIDIA Drivers 570 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =x11-drivers/nvidia-drivers-570.133.07:0/570" References ========== [ 1 ] CVE-2025-23244 https://nvd.nist.gov/vuln/detail/CVE-2025-23244 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202505-04 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.