Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
YARD could be made to expose sensitive information over the network.. ========================================================================== Ubuntu Security Notice USN-8394-1 June 05, 2026 yard vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: YARD could be made to expose sensitive information over the network. Software Description: - yard: A documentation generation tool for the Ruby programming language Details: It was discovered that YARD incorrectly sanitized paths in its built-in documentation server. An attacker could possibly use this issue to read arbitrary files from the server host. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS yard 0.9.38-1ubuntu0.1~esm1 Available with Ubuntu Pro yard-doc 0.9.38-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS yard 0.9.36-1ubuntu0.1~esm1 Available with Ubuntu Pro yard-doc 0.9.36-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS yard 0.9.26-1ubuntu0.1+esm1 Available with Ubuntu Pro yard-doc 0.9.26-1ubuntu0.1+esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS yard 0.9.24-1+deb11u1ubuntu0.1~esm1 Available with Ubuntu Pro yard-doc 0.9.24-1+deb11u1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS yard 0.9.12-2ubuntu0.1~esm2 Available with Ubuntu Pro yard-doc 0.9.12-2ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS yard 0.8.7.6+git20160220-3ubuntu0.1~esm2 Available with Ubuntu Pro yard-doc 0.8.7.6+git20160220-3ubuntu0.1~esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8394-1 CVE-2026-41493 . YARD on Ubuntu might expose sensitive data over the network, requiring updates to prevent information leaks and secure systems.. Ubuntu security, YARD vulnerability, network exposure, Linux updates, sensitive data. . Severity: Important. LinuxSecurity.com Team
curl could be made to expose sensitive information over the network.. ========================================================================== Ubuntu Security Notice USN-8227-1 May 04, 2026 curl vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: curl could be made to expose sensitive information over the network. Software Description: - curl: HTTP, HTTPS, and FTP client and client libraries Details: It was discovered that curl incorrectly reused non-TLS connections when TLS was required in some STARTTLS configurations. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-4873) It was discovered that curl incorrectly reused certain HTTP Negotiate connections. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-5545) It was discovered that curl incorrectly reused certain SMB connections. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-5773) It was discovered that curl could leak proxy credentials when handling redirects in some configurations. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-6253) It was discovered that curl could leak cookies because of stale custom cookie host handling in some requests. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-6276) It was discovered that curl could leak .netrc credentials when reusing proxy connections in some situations. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-6429) It was discovered that curl could leak Digest authentication state when switching proxies in some situations. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-7168) Update instructions: The problem can becorrected by updating your system to the following package versions: Ubuntu 26.04 LTS curl 8.18.0-1ubuntu2.1 libcurl3t64-gnutls 8.18.0-1ubuntu2.1 libcurl4t64 8.18.0-1ubuntu2.1 Ubuntu 25.10 curl 8.14.1-2ubuntu1.3 libcurl3t64-gnutls 8.14.1-2ubuntu1.3 libcurl4t64 8.14.1-2ubuntu1.3 Ubuntu 24.04 LTS curl 8.5.0-2ubuntu10.9 libcurl3t64-gnutls 8.5.0-2ubuntu10.9 libcurl4t64 8.5.0-2ubuntu10.9 Ubuntu 22.04 LTS curl 7.81.0-1ubuntu1.24 libcurl3-gnutls 7.81.0-1ubuntu1.24 libcurl3-nss 7.81.0-1ubuntu1.24 libcurl4 7.81.0-1ubuntu1.24 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8227-1 CVE-2026-4873, CVE-2026-5545, CVE-2026-5773, CVE-2026-6253, CVE-2026-6276, CVE-2026-6429, CVE-2026-7168 Package Information: https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.1 https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.3 https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.9 https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.24 . Critical Ubuntu curl advisory correcting multiple information leak risks due to improper connection handling. Update now!. Ubuntu curl network leak update security. . Severity: Important. LinuxSecurity.com Team
Kerberos could be made to expose sensitive information over the network.. ========================================================================== Ubuntu Security Notice USN-7542-1 May 28, 2025 krb5 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Kerberos could be made to expose sensitive information over the network. Software Description: - krb5: MIT Kerberos Network Authentication Protocol Details: It was discovered that Kerberos allowed the usage of weak cryptographic standards. An attacker could possibly use this issue to expose sensitive information. This update introduces the allow_rc4 and allow_des3 configuration options, and disables the usage of RC4 and 3DES ciphers by default. Users are advised to discontinue their usage and upgrade to stronger encryption protocols. If the use of the insecure RC4 and 3DES algorithms is necessary, they can be enabled with the aforementioned configuration options. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libk5crypto3 1.20.1-6ubuntu2.6 libkrb5-3 1.20.1-6ubuntu2.6 Ubuntu 22.04 LTS libk5crypto3 1.19.2-2ubuntu0.7 libkrb5-3 1.19.2-2ubuntu0.7 Ubuntu 20.04 LTS libk5crypto3 1.17-6ubuntu4.11 libkrb5-3 1.17-6ubuntu4.11 Ubuntu 18.04 LTS libk5crypto3 1.16-2ubuntu0.4+esm5 Available with Ubuntu Pro libkrb5-3 1.16-2ubuntu0.4+esm5 Available with Ubuntu Pro Ubuntu 16.04 LTS libk5crypto3 1.13.2+dfsg-5ubuntu2.2+esm7 Available with Ubuntu Pro libkrb5-3 1.13.2+dfsg-5ubuntu2.2+esm7 Available with Ubuntu Pro Ubuntu 14.04 LTS libk5crypto3 1.12+dfsg-2ubuntu5.4+esm7 Available with Ubuntu Pro libkrb5-3 1.12+dfsg-2ubuntu5.4+esm7 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7542-1 CVE-2025-3576 Package Information: https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.6 https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.7 https://launchpad.net/ubuntu/+source/krb5/1.17-6ubuntu4.11 . A newly discovered weakness in Kerberos can leak critical data via network traffic. To bolster your system's security, promptly update your Ubuntu machine.. Kerberos, network security, Ubuntu updates, cryptography. . Severity: Critical. LinuxSecurity.com Team
mod_auth_openidc could be made to expose sensitive information over the network.. ========================================================================== Ubuntu Security Notice USN-7446-1 April 23, 2025 libapache2-mod-auth-openidc vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: mod_auth_openidc could be made to expose sensitive information over the network. Software Description: - libapache2-mod-auth-openidc: OpenID Connect Relying Party implementation for Apache Details: It was discovered that mod_auth_openidc incorrectly handled certain POST requests. An attacker could possibly use this issue to obtain sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 libapache2-mod-auth-openidc 2.4.16.10-1ubuntu1 Ubuntu 24.10 libapache2-mod-auth-openidc 2.4.15.7-2ubuntu0.1 Ubuntu 24.04 LTS libapache2-mod-auth-openidc 2.4.15.1-1ubuntu0.1 Ubuntu 22.04 LTS libapache2-mod-auth-openidc 2.4.11-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7446-1 CVE-2025-31492 Package Information: https://launchpad.net/ubuntu/+source/libapache2-mod-auth-openidc/2.4.16.10-1ubuntu1 https://launchpad.net/ubuntu/+source/libapache2-mod-auth-openidc/2.4.15.7-2ubuntu0.1 https://launchpad.net/ubuntu/+source/libapache2-mod-auth-openidc/2.4.15.1-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libapache2-mod-auth-openidc/2.4.11-1ubuntu0.1 . Debian security advisory targets mod_auth_openidc vulnerability affecting internet exposure. Urgent patch advised for safeguarding confidential information.. mod_auth_openidc, Ubuntu updates, security notice, data protection, network vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Yelp could be made to expose sensitive information over the network.. ========================================================================== Ubuntu Security Notice USN-7447-1 April 23, 2025 yelp, yelp-xsl vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Yelp could be made to expose sensitive information over the network. Software Description: - yelp: Help browser for GNOME - yelp-xsl: XSL stylesheets for the yelp help browser Details: It was discovered that Yelp incorrectly handled paths in ghelp URLs. A remote attacker could use this issue to trick users into opening malicious downloaded help files and exfiltrate sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 yelp 42.2-2ubuntu0.1 yelp-xsl 42.1-3ubuntu0.1 Ubuntu 24.10 yelp 42.2-1ubuntu0.24.10.1 yelp-xsl 42.1-2ubuntu0.24.10.1 Ubuntu 24.04 LTS yelp 42.2-1ubuntu0.24.04.1 yelp-xsl 42.1-2ubuntu0.24.04.1 Ubuntu 22.04 LTS yelp 42.1-1ubuntu0.1 yelp-xsl 42.0-1ubuntu0.1 Ubuntu 20.04 LTS yelp 3.36.2-0ubuntu1.1 yelp-xsl 3.36.0-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7447-1 CVE-2025-3155 Package Information: https://launchpad.net/ubuntu/+source/yelp/42.2-2ubuntu0.1 https://launchpad.net/ubuntu/+source/yelp-xsl/42.1-3ubuntu0.1 https://launchpad.net/ubuntu/+source/yelp/42.2-1ubuntu0.24.10.1 https://launchpad.net/ubuntu/+source/yelp-xsl/42.1-2ubuntu0.24.10.1 https://launchpad.net/ubuntu/+source/yelp/42.2-1ubuntu0.24.04.1 https://launchpad.net/ubuntu/+source/yelp-xsl/42.1-2ubuntu0.24.04.1 https://launchpad.net/ubuntu/+source/yelp/42.1-1ubuntu0.1 https://launchpad.net/ubuntu/+source/yelp-xsl/42.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/yelp/3.36.2-0ubuntu1.1 https://launchpad.net/ubuntu/+source/yelp-xsl/3.36.0-1ubuntu0.1 . Ubuntu users can now download a vital update that resolves a security flaw in Yelp, safeguarding against data breaches. Ensure your information remains secure from unauthorized access.. Ubuntu Update, Yelp Exposure, Security Notice, Data Protection. . Severity: Critical. LinuxSecurity.com Team
go-gh could be made to expose sensitive information over the network.. ========================================================================== Ubuntu Security Notice USN-7362-1 March 20, 2025 golang-github-cli-go-gh-v2 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS Summary: go-gh could be made to expose sensitive information over the network. Software Description: - golang-github-cli-go-gh-v2: Go module for interacting with gh and the GitHub API from the command line Details: It was discovered that go-gh incorrectly handled authentication tokens. An attacker could possibly use this issue to leak authentication tokens to the wrong host. (CVE-2024-53859) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 golang-github-cli-go-gh-v2-dev 2.6.0-1ubuntu0.24.10.1 Ubuntu 24.04 LTS golang-github-cli-go-gh-v2-dev 2.6.0-1ubuntu0.24.04.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7362-1 CVE-2024-53859 Package Information: https://launchpad.net/ubuntu/+source/golang-github-cli-go-gh-v2/2.6.0-1ubuntu0.24.10.1 . A critical security advisory for Ubuntu covering go-gh exposure of sensitive information and recommended updates.. go-gh, expose, sensitive, information, network, ==============================. . Severity: Critical. LinuxSecurity.com Team
OpenJDK 21 could be made to expose sensitive information over the network.. ========================================================================== Ubuntu Security Notice USN-7254-1 February 05, 2025 openjdk-21 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: OpenJDK 21 could be made to expose sensitive information over the network. Software Description: - openjdk-21: Open Source Java implementation Details: It was discovered that the Hotspot component of OpenJDK 21 did not properly handle API access under certain circumstances. An unauthenticated attacker could possibly use this issue to access unauthorized resources and expose sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 openjdk-21-jdk 21.0.6+7-1~24.10.1 openjdk-21-jdk-headless 21.0.6+7-1~24.10.1 openjdk-21-jre 21.0.6+7-1~24.10.1 openjdk-21-jre-headless 21.0.6+7-1~24.10.1 openjdk-21-jre-zero 21.0.6+7-1~24.10.1 Ubuntu 24.04 LTS openjdk-21-jdk 21.0.6+7-1~24.04.1 openjdk-21-jdk-headless 21.0.6+7-1~24.04.1 openjdk-21-jre 21.0.6+7-1~24.04.1 openjdk-21-jre-headless 21.0.6+7-1~24.04.1 openjdk-21-jre-zero 21.0.6+7-1~24.04.1 Ubuntu 22.04 LTS openjdk-21-jdk 21.0.6+7-1~22.04.1 openjdk-21-jdk-headless 21.0.6+7-1~22.04.1 openjdk-21-jre 21.0.6+7-1~22.04.1 openjdk-21-jre-headless 21.0.6+7-1~22.04.1 openjdk-21-jre-zero 21.0.6+7-1~22.04.1 Ubuntu 20.04 LTS openjdk-21-jdk 21.0.6+7-1~20.04.1 openjdk-21-jdk-headless 21.0.6+7-1~20.04.1 openjdk-21-jre 21.0.6+7-1~20.04.1 openjdk-21-jre-headless 21.0.6+7-1~20.04.1 openjdk-21-jre-zero 21.0.6+7-1~20.04.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart Java applications to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7254-1 CVE-2025-21502 Package Information: https://launchpad.net/ubuntu/+source/openjdk-21/21.0.6+7-1~24.10.1 https://launchpad.net/ubuntu/+source/openjdk-21/21.0.6+7-1~24.04.1 https://launchpad.net/ubuntu/+source/openjdk-21/21.0.6+7-1~22.04.1 https://launchpad.net/ubuntu/+source/openjdk-21/21.0.6+7-1~20.04.1 . OpenJDK 21 patch enhances security measures on Ubuntu, safeguarding against sensitive information leaks during transmission.. OpenJDK Security, Ubuntu Network Threat, Sensitive Data Protection. . Severity: Critical. LinuxSecurity.com Team
OpenJDK 11 could be made to expose sensitive information over the network.. ========================================================================== Ubuntu Security Notice USN-7252-1 February 05, 2025 openjdk-lts vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: OpenJDK 11 could be made to expose sensitive information over the network. Software Description: - openjdk-lts: Open Source Java implementation Details: It was discovered that the Hotspot component of OpenJDK 11 did not properly handle API access under certain circumstances. An unauthenticated attacker could possibly use this issue to access unauthorized resources and expose sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 openjdk-11-jdk 11.0.26+4-1ubuntu1~24.10 openjdk-11-jdk-headless 11.0.26+4-1ubuntu1~24.10 openjdk-11-jre 11.0.26+4-1ubuntu1~24.10 openjdk-11-jre-headless 11.0.26+4-1ubuntu1~24.10 openjdk-11-jre-zero 11.0.26+4-1ubuntu1~24.10 Ubuntu 24.04 LTS openjdk-11-jdk 11.0.26+4-1ubuntu1~24.04 openjdk-11-jdk-headless 11.0.26+4-1ubuntu1~24.04 openjdk-11-jre 11.0.26+4-1ubuntu1~24.04 openjdk-11-jre-headless 11.0.26+4-1ubuntu1~24.04 openjdk-11-jre-zero 11.0.26+4-1ubuntu1~24.04 Ubuntu 22.04 LTS openjdk-11-jdk 11.0.26+4-1ubuntu1~22.04 openjdk-11-jdk-headless 11.0.26+4-1ubuntu1~22.04 openjdk-11-jre 11.0.26+4-1ubuntu1~22.04 openjdk-11-jre-headless 11.0.26+4-1ubuntu1~22.04 openjdk-11-jre-zero 11.0.26+4-1ubuntu1~22.04 Ubuntu 20.04 LTS openjdk-11-jdk 11.0.26+4-1ubuntu1~20.04 openjdk-11-jdk-headless 11.0.26+4-1ubuntu1~20.04 openjdk-11-jre 11.0.26+4-1ubuntu1~20.04 openjdk-11-jre-headless 11.0.26+4-1ubuntu1~20.04 openjdk-11-jre-zero 11.0.26+4-1ubuntu1~20.04 Ubuntu 18.04 LTS openjdk-11-jdk 11.0.26+4-1ubuntu1~18.04 Available with Ubuntu Pro openjdk-11-jdk-headless 11.0.26+4-1ubuntu1~18.04 Available with Ubuntu Pro openjdk-11-jre 11.0.26+4-1ubuntu1~18.04 Available with Ubuntu Pro openjdk-11-jre-headless 11.0.26+4-1ubuntu1~18.04 Available with Ubuntu Pro openjdk-11-jre-zero 11.0.26+4-1ubuntu1~18.04 Available with Ubuntu Pro This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart Java applications to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7252-1 CVE-2025-21502 Package Information: https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.26+4-1ubuntu1~24.10 https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.26+4-1ubuntu1~24.04 https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.26+4-1ubuntu1~22.04 https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.26+4-1ubuntu1~20.04 . Uncover theessential news regarding OpenJDK 11 affecting Ubuntu platforms. Find out how to resolve the designated network vulnerability problem.. openjdk updates, Ubuntu security, network security, openjdk vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.