Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 3 articles for you...
202

openSUSE Leap 16.0 Nano Moderate Denial of Service Vuln 2026-21166-1

An update that solves 3 vulnerabilities and has 4 bug fixes can now be installed.. openSUSE security update: security update for nano ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21166-1 Rating: moderate References: * bsc#1258260 * bsc#1262643 * bsc#1263022 * bsc#1263437 Cross-References: * CVE-2026-40556 * CVE-2026-6842 * CVE-2026-6843 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has 4 bug fixes can now be installed. Description: This update for nano fixes the following issues: Changes in nano: - Update to version 9.1: * When searching, the viewport is placed snug left where possible. * The ability to read and write files in old Mac format (a lone carriage return as line ending) was removed. * The ^T toggle between WhereIs and GotoLine was dropped. * Fix backups that were missing or had a wrong timestamp when --backup is active. * On a crash or kill, a .save file is no longer chmodded or chowned to the base file's permissions and owner. * The history code now creates the ~/.local directory with limited access rights (boo#1263437; the referenced CVE-2026-40556 was rejected upstream). * M-Ins and M-Del have become rebindable. - GNU nano 9.0: * When the cursor almost goes offscreen to the right, all lines are now scrolled sideways together, by just the amount needed to keep the cursor in view. Use --solosidescroll or 'set solosidescroll' to get back the old, jerky, single-line horizontal scrolling. * The viewport can be scrolled sideways (in steps of one tabsize) with M-< and M-> . See `man nanorc` if M-< and M-> should switch between buffers (as they did earlier). * M-Left, M-Right, M-Up, and M-Down have become rebindable. * Stopping the recording of a macro immediately after starting it cancels the recording and leaves an existing macro in place. * Feature toggles no longer break a chain of ^K cuts or M-6 copies, except the M-K cut-from-cursor toggle. * With --mouse and --indicator, one can click in the scrollbar area to roughly navigate within the buffer. * CVE-2026-6843: format string vulnerability leads to denial of service (boo#1262643) * create the ~/.local directory with limited access rights (CVE-2026-6842 boo#1263022, CVE-2026-40556 boo#1263437) - GNU nano 8.7.1: * fix build against glibc-2.43 (boo#1258260) - GNU nano 8.7: * At the Execute prompt, preceding the command with two pipe symbols allows implementing a copy-to-clipboard feature in nanorc on terminals that support OSC 52. See doc/sample.nanorc Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-361=1 Package List: - openSUSE Leap 16.0: nano-9.1-bp160.1.1 nano-lang-9.1-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2026-40556.html * https://www.suse.com/security/cve/CVE-2026-6842.html * https://www.suse.com/security/cve/CVE-2026-6843.html . Discover the latest openSUSE security update for nano addressing critical flaws and enhancing system integrity.. openSUSE nano update, security patch, software vulnerability, system security. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 moderate OpenSUSE
202

openSUSE Tumbleweed Nano Moderate Security Fix CVE-2026-40556 2026-11120-1

An update that solves one vulnerability can now be installed.. # nano-9.1-1.1 on GA media Announcement ID: openSUSE-SU-2026:11120-1 Rating: moderate Cross-References: * CVE-2026-40556 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the nano-9.1-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * nano 9.1-1.1 * nano-lang 9.1-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40556.html . An important update for openSUSE Tumbleweed resolves a security issue in the nano application with moderate severity.. openSUSE Tumbleweed nano update moderate severity patch. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 27, 2026 moderate OpenSUSE
202

openSUSE Tumbleweed Nano Moderate Security Issues Advisory 2026-10851-1

An update that solves 2 vulnerabilities can now be installed.. # nano-9.0-2.1 on GA media Announcement ID: openSUSE-SU-2026:10851-1 Rating: moderate Cross-References: * CVE-2026-6842 * CVE-2026-6843 Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the nano-9.0-2.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * nano 9.0-2.1 * nano-lang 9.0-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6842.html * https://www.suse.com/security/cve/CVE-2026-6843.html . Update for openSUSE Tumbleweed that addresses two moderate security issues in nano-9.0-2.1.. openSUSE Tumbleweed update, nano security fix, moderate vulnerabilities, package update. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 May 25, 2026 moderate OpenSUSE
89

Fedora 44 Nano Important Format String DoS Fix FEDORA-2026-3111ffa11a

fix CVE-2026-6842 and CVE-29026-6843 Resolves: CVE-2026-6842 Resolves: CVE-2026-6843 Resolves: rhbz#2455127 Resolves: rhbz#2455314. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3111ffa11a 2026-05-03 00:48:41.051402+00:00 -------------------------------------------------------------------------------- Name : nano Product : Fedora 44 Version : 8.7.1 Release : 2.fc44 URL : https://www.nano-editor.org Summary : A small text editor Description : GNU nano is a small and friendly text editor. -------------------------------------------------------------------------------- Update Information: fix CVE-2026-6842 and CVE-29026-6843 Resolves: CVE-2026-6842 Resolves: CVE-2026-6843 Resolves: rhbz#2455127 Resolves: rhbz#2455314 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 30 2026 Luk\u0161 Zaoral - 8.7.1-2 - fix CVE-2026-6842 and CVE-29026-6843 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455127 - [Security] Format String Vulnerability in nano's statusline() via errormessage Buffer https://bugzilla.redhat.com/show_bug.cgi?id=2455127 [ 2 ] Bug #2460502 - CVE-2026-6842 nano: nano: Local attacker can inject malicious .desktop launcher due to insecure directory permissions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460502 [ 3 ] Bug #2460503 - CVE-2026-6843 nano: nano: Format string vulnerability leads to Denial of Service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460503 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3111ffa11a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update for Fedora 44 addressing CVE-2026-6842 and CVE-2026-6843 vulnerabilities in nano editor available now.. Fedora Update, CVE-2026-6842, CVE-2026-6843, Nano Editor Security, Format String Vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 03, 2026 Important Fedora
172

Ubuntu 14.04 LTS: USN-7064-2 moderate: nano privilege escalation

nano could be made to give users administrator privileges.. ========================================================================== Ubuntu Security Notice USN-7064-2 October 29, 2024 nano vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: nano could be made to give users administrator privileges. Software Description: - nano: small, friendly text editor inspired by Pico Details: USN-7064-1 fixed a vulnerability in nano. This update provides the corresponding update for Ubuntu 14.04 LTS. Original advisory details: It was discovered that nano allowed a possible privilege escalation through an insecure temporary file. If nano was killed while editing, the permissions granted to the emergency save file could be used by an attacker to escalate privileges using a malicious symlink. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS nano 2.2.6-1ubuntu1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7064-2 https://ubuntu.com/security/notices/USN-7064-1 CVE-2024-5742 . The Ubuntu Security Notice USN-7064-2 addresses a security flaw in nano that could allow for privilege escalation. For further information, click here.. Ubuntu Security, nano Update, Privilege Escalation, Security Notice, System Update. . LinuxSecurity.com Team

Calendar%202 Oct 29, 2024 Ubuntu
172

Ubuntu 24.04 LTS Security Advisory USN-7064-1: nano privilege escalation

nano could be made to give users administrator privileges.. ========================================================================== Ubuntu Security Notice USN-7064-1 October 15, 2024 nano vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: nano could be made to give users administrator privileges. Software Description: - nano: small, friendly text editor inspired by Pico Details: It was discovered that nano allowed a possible privilege escalation through an insecure temporary file. If nano was killed while editing, the permissions granted to the emergency save file could be used by an attacker to escalate privileges using a malicious symlink. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS nano 7.2-2ubuntu0.1 Ubuntu 22.04 LTS nano 6.2-1ubuntu0.1 Ubuntu 20.04 LTS nano 4.8-1ubuntu1.1 Ubuntu 18.04 LTS nano 2.9.3-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS nano 2.5.3-2ubuntu2+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7064-1 CVE-2024-5742 Package Information: https://launchpad.net/ubuntu/+source/nano/7.2-2ubuntu0.1 https://launchpad.net/ubuntu/+source/nano/6.2-1ubuntu0.1 https://launchpad.net/ubuntu/+source/nano/4.8-1ubuntu1.1 . Ubuntu has released security patches addressing a critical privilege escalation flaw in nano across various LTS versions. Prompt action is crucial for your system's protection. nano update, Ubuntu security patch, privilege escalation, system updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 15, 2024 Critical Ubuntu
217

Oracle Linux 8 ELSA-2024-6986: nano Low Severity Update and Fixes

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-6986 http://linux.oracle.com/errata/ELSA-2024-6986.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: nano-2.9.8-3.el8_10.x86_64.rpm aarch64: nano-2.9.8-3.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//nano-2.9.8-3.el8_10.src.rpm Related CVEs: CVE-2024-5742 Description of changes: [2.9.8-3] - fix incomplete backport of the fix for the emergency file replacement vulnerability (RHEL-35236) [2.9.8-2] - fix emergency file replacement vulnerability (RHEL-35236) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Notice ELSA-2024-6987: Security updates for nano utilities in release 8. New RPM packages have been made available.. Oracle Linux, security updates, low severity, Linux packages, nano. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Sep 27, 2024 Low Oracle
202

openSUSE: 2024:0157-2 Important: nano Privilege Escalation Fix

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for nano ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0157-2 Rating: important References: #1226099 Cross-References: CVE-2024-5742 CVSS scores: CVE-2024-5742 (SUSE): 6.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for nano fixes the following issues: - CVE-2024-5742: Avoid privilege escalations via symlink attacks on emergency save file (boo#1226099) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2024-157=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64): nano-7.2-bp156.3.3.1 nano-debuginfo-7.2-bp156.3.3.1 nano-debugsource-7.2-bp156.3.3.1 - openSUSE Backports SLE-15-SP6 (noarch): nano-lang-7.2-bp156.3.3.1 References: https://www.suse.com/security/cve/CVE-2024-5742.html https://bugzilla.suse.com/1226099 . openSUSE Security Bulletin regarding vim, noted by Announcement ID openSUSE-SU-2024:0162-1, includes critical patches and enhancements.. openSUSE Security, nano Update, Privilege Escalation Fix, Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 23, 2024 Important OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200