Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 10 articles for you...
100

SUSE Linux Micro 6.0: 2025:20187-1 important kernel-livepatch security fix

* bsc#1235218 * bsc#1235916 Cross-References: * CVE-2024-56600 . # Security update for kernel-livepatch-MICRO-6-0_Update_4 Announcement ID: SUSE-SU-2025:20187-1 Release Date: 2025-04-17T09:25:13Z Rating: important References: * bsc#1235218 * bsc#1235916 Cross-References: * CVE-2024-56600 * CVE-2024-57882 CVSS scores: * CVE-2024-56600 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-57882 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-57882 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2024-57882 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_4 fixes the following issues: * CVE-2024-56600: net: inet6: Fixed dangling sk pointer in inet6_create() (bsc#1235218). * CVE-2024-57882: mptcp: Fixed TCP options overflow (bsc#1235916). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-13=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_4-debugsource-2-1.2 * kernel-livepatch-6_4_0-24-default-2-1.2 * kernel-livepatch-6_4_0-24-default-debuginfo-2-1.2 ## References: * https://www.suse.com/security/cve/CVE-2024-56600.html * https://www.suse.com/security/cve/CVE-2024-57882.html * https://bugzilla.suse.com/show_bug.cgi?id=1235218 *https://bugzilla.suse.com/show_bug.cgi?id=1235916 . SUSE 2025:20187-2 significant revision for kernel-livepatch resolving severe vulnerabilities in SUSE Linux Micro 6.1.. kernel livepatch, SUSE security update, critical patch, Linux Micro security, TCP overflow fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 04, 2025 Important SuSE
100

SUSE Linux Micro 6.0: 2025:20339-1 Moderate Update for Kernel Livepatch

* bsc#1233019 * bsc#1233678 * bsc#1234847 Cross-References: . # Security update for kernel-livepatch-MICRO-6-0-RT_Update_2 Announcement ID: SUSE-SU-2025:20339-1 Release Date: May 22, 2025, 1:03 p.m. Rating: moderate References: * bsc#1233019 * bsc#1233678 * bsc#1234847 Cross-References: * CVE-2024-50115 * CVE-2024-53042 * CVE-2024-53156 CVSS scores: * CVE-2024-50115 ( SUSE ): 4.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:H * CVE-2024-50115 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H * CVE-2024-50115 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-53042 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-53042 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-53156 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-53156 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53156 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_2 fixes the following issues: * CVE-2024-53042: ipv4: ip_tunnel: Fix suspicious RCU usage warning in ip_tunnel_init_flow() (bsc#1233678) * CVE-2024-53156: wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service() (bsc#1234847) * CVE-2024-50115: KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory (bsc#1233019) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-24=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-10-rt-5-1.1 * kernel-livepatch-6_4_0-10-rt-debuginfo-5-1.1 *kernel-livepatch-MICRO-6-0-RT_Update_2-debugsource-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-50115.html * https://www.suse.com/security/cve/CVE-2024-53042.html * https://www.suse.com/security/cve/CVE-2024-53156.html * https://bugzilla.suse.com/show_bug.cgi?id=1233019 * https://bugzilla.suse.com/show_bug.cgi?id=1233678 * https://bugzilla.suse.com/show_bug.cgi?id=1234847 . Address vulnerabilities in SUSE Linux Micro 6.0, remediating three significant security defects via a kernel live patch deployment.. SUSE Linux Micro, kernel update, security fix, network vulnerabilities. . LinuxSecurity.com Team

Calendar%202 May 29, 2025 SuSE
217

Oracle Linux 8: ELSA-2025-1676 Important: Bind9 Security Fix

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1676 http://linux.oracle.com/errata/ELSA-2025-1676.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: bind9.16-9.16.23-0.22.el8_10.2.x86_64.rpm bind9.16-chroot-9.16.23-0.22.el8_10.2.x86_64.rpm bind9.16-dnssec-utils-9.16.23-0.22.el8_10.2.x86_64.rpm bind9.16-libs-9.16.23-0.22.el8_10.2.x86_64.rpm bind9.16-license-9.16.23-0.22.el8_10.2.noarch.rpm bind9.16-utils-9.16.23-0.22.el8_10.2.x86_64.rpm python3-bind9.16-9.16.23-0.22.el8_10.2.noarch.rpm bind9.16-devel-9.16.23-0.22.el8_10.2.i686.rpm bind9.16-devel-9.16.23-0.22.el8_10.2.x86_64.rpm bind9.16-doc-9.16.23-0.22.el8_10.2.noarch.rpm bind9.16-libs-9.16.23-0.22.el8_10.2.i686.rpm aarch64: bind9.16-9.16.23-0.22.el8_10.2.aarch64.rpm bind9.16-chroot-9.16.23-0.22.el8_10.2.aarch64.rpm bind9.16-dnssec-utils-9.16.23-0.22.el8_10.2.aarch64.rpm bind9.16-libs-9.16.23-0.22.el8_10.2.aarch64.rpm bind9.16-license-9.16.23-0.22.el8_10.2.noarch.rpm bind9.16-utils-9.16.23-0.22.el8_10.2.aarch64.rpm python3-bind9.16-9.16.23-0.22.el8_10.2.noarch.rpm bind9.16-devel-9.16.23-0.22.el8_10.2.aarch64.rpm bind9.16-doc-9.16.23-0.22.el8_10.2.noarch.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//bind9.16-9.16.23-0.22.el8_10.2.src.rpm Related CVEs: CVE-2024-11187 Description of changes: [32:9.16.23-0.22.2] - Fix application of patch for CVE-2024-11187 - Resolves: RHEL-77103 [32:9.16.23-0.22.1] - Limit additional section records CPU processing (CVE-2024-11187) - Fix test backport changes _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Essential patches for bind9 on Oracle Linux 8 targeting CVE-2024-11187 are now released, featuring vital security enhancements.. Oracle Linux Update, Bind9 Fix, Security Patch, ELSA-2025-1676. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 24, 2025 Important Oracle
100

SUSE 15 SP3: 2025:0499-2 critical: kernel immediate patch

* bsc#1229644 * bsc#1230998 * bsc#1231993 Cross-References: . # Security update for the Linux Kernel (Live Patch 47 for SLE 15 SP3) Announcement ID: SUSE-SU-2025:0449-1 Release Date: 2025-02-12T11:33:31Z Rating: important References: * bsc#1229644 * bsc#1230998 * bsc#1231993 Cross-References: * CVE-2022-48912 * CVE-2024-45016 * CVE-2024-47684 CVSS scores: * CVE-2022-48912 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-48912 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45016 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45016 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47684 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-47684 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47684 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise Live Patching 15-SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves three vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.3.18-150300_59_170 fixes several issues. The following security issues were fixed: * CVE-2024-45016: netem: fix return value if duplicate enqueue fails (bsc#1230998). * CVE-2022-48912: Fix use-after-free in __nf_register_net_hook() (bsc#1229641) * CVE-2024-47684: tcp: check skb is non-NULL in tcp_rto_delta_us() (bsc#1231993). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-449=1SUSE-2025-453=1 * SUSE Linux Enterprise Live Patching 15-SP3 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2025-449=1 SUSE-SLE- Module-Live-Patching-15-SP3-2025-453=1 ## Package List: * openSUSE Leap 15.3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_161-default-debuginfo-11-150300.2.1 * kernel-livepatch-5_3_18-150300_59_170-default-debuginfo-5-150300.2.1 * kernel-livepatch-5_3_18-150300_59_161-default-11-150300.2.1 * kernel-livepatch-5_3_18-150300_59_170-default-5-150300.2.1 * kernel-livepatch-SLE15-SP3_Update_47-debugsource-5-150300.2.1 * kernel-livepatch-SLE15-SP3_Update_44-debugsource-11-150300.2.1 * openSUSE Leap 15.3 (x86_64) * kernel-livepatch-5_3_18-150300_59_161-preempt-11-150300.2.1 * kernel-livepatch-5_3_18-150300_59_170-preempt-5-150300.2.1 * kernel-livepatch-5_3_18-150300_59_161-preempt-debuginfo-11-150300.2.1 * kernel-livepatch-5_3_18-150300_59_170-preempt-debuginfo-5-150300.2.1 * SUSE Linux Enterprise Live Patching 15-SP3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_170-default-debuginfo-5-150300.2.1 * kernel-livepatch-SLE15-SP3_Update_47-debugsource-5-150300.2.1 * kernel-livepatch-5_3_18-150300_59_161-default-11-150300.2.1 * kernel-livepatch-5_3_18-150300_59_170-default-5-150300.2.1 ## References: * https://www.suse.com/security/cve/CVE-2022-48912.html * https://www.suse.com/security/cve/CVE-2024-45016.html * https://www.suse.com/security/cve/CVE-2024-47684.html * https://bugzilla.suse.com/show_bug.cgi?id=1229644 * https://bugzilla.suse.com/show_bug.cgi?id=1230998 * https://bugzilla.suse.com/show_bug.cgi?id=1231993 . Essential security patches for Linux Kernel highlighting issues within live patch for SUSE Linux Enterprise 15 SP3.. LinuxKernelSecurity, LivePatching, KernelUpdates, SUSESecurity. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 12, 2025 Critical SuSE
100

SUSE 15 SP6: 2024:3626-1 important: Linux Kernel RT security patch

* bsc#1228349 * bsc#1228786 Cross-References: * CVE-2024-40909 . # Security update for the Linux Kernel RT (Live Patch 1 for SLE 15 SP6) Announcement ID: SUSE-SU-2024:3626-1 Release Date: 2024-10-15T02:33:30Z Rating: important References: * bsc#1228349 * bsc#1228786 Cross-References: * CVE-2024-40909 * CVE-2024-40954 CVSS scores: * CVE-2024-40909 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-40909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-40954 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-40954 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 6.4.0-150600_10_5 fixes several issues. The following security issues were fixed: * CVE-2024-40954: net: do not leave a dangling sk pointer, when socket creation fails (bsc#1227808) * CVE-2024-40909: bpf: Fix a potential use-after-free in bpf_link_free() (bsc#1228349). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2024-3626=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (x86_64) * kernel-livepatch-SLE15-SP6-RT_Update_1-debugsource-3-150600.1.8.1 * kernel-livepatch-6_4_0-150600_10_5-rt-debuginfo-3-150600.1.8.1 * kernel-livepatch-6_4_0-150600_10_5-rt-3-150600.1.8.1 ## References: * https://www.suse.com/security/cve/CVE-2024-40909.html * https://www.suse.com/security/cve/CVE-2024-40954.html *https://bugzilla.suse.com/show_bug.cgi?id=1228349 * https://bugzilla.suse.com/show_bug.cgi?id=1228786 . The latest security patch tackles issues in Linux Kernel RT for SLE 15 SP6, featuring critical fixes and comprehensive guidance.. Linux Kernel Security, Live Patch Update, SUSE Security Advisory, BPF Issues, Network Vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 15, 2024 Important SuSE
203

Mageia: 2024-0085 Moderate: Libreswan Denial of Service Issues

The updated package fixes security vulnerabilities: pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. (CVE-2023-30570) An issue was discovered in Libreswan before 4.12. When an IKEv2 Child SA . MGASA-2024-0085 - Updated libreswan packages fix security vulnerabilities Publication date: 24 Mar 2024 URL: https://advisories.mageia.org/MGASA-2024-0085.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-30570, CVE-2023-38710, CVE-2023-38711, CVE-2023-38712 The updated package fixes security vulnerabilities: pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. (CVE-2023-30570) An issue was discovered in Libreswan before 4.12. When an IKEv2 Child SA REKEY packet contains an invalid IPsec protocol ID number of 0 or 1, an error notify INVALID_SPI is sent back. The notify payload's protocol ID is copied from the incoming packet, but the code that verifies outgoing packets fails an assertion that the protocol ID must be ESP (2) or AH(3) and causes the pluto daemon to crash and restart. (CVE-2023-38710) An issue was discovered in Libreswan before 4.12. When an IKEv1 Quick Mode connection configured with ID_IPV4_ADDR or ID_IPV6_ADDR receives an IDcr payload with ID_FQDN, a NULL pointer dereference causes a crash and restart of the pluto daemon. (CVE-2023-38711) An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify message, a NULL pointer dereference on the deleted state causes the pluto daemon to crash and restart. (CVE-2023-38712) References: - https://bugs.mageia.org/show_bug.cgi?id=31865 - https://libreswan.org/security/CVE-2023-30570/CVE-2023-30570.txt - https://access.redhat.com/errata/RHSA-2023:2120 -https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/APPXJHIVUBS4I2AVIB6C36ED6XNUYVC2/ - https://libreswan.org/security/CVE-2023-38710/ - https://libreswan.org/security/CVE-2023-38711/ - https://libreswan.org/security/CVE-2023-38712/ - https://www.cve.org/CVERecord?id=CVE-2023-30570 - https://www.cve.org/CVERecord?id=CVE-2023-38710 - https://www.cve.org/CVERecord?id=CVE-2023-38711 - https://www.cve.org/CVERecord?id=CVE-2023-38712 SRPMS: - 9/core/libreswan-4.12-1.mga9 . Recent Libreswan updates bolster system security by addressing critical flaws in Mageia, announced on 24 Mar 2024.. Libreswan Security Update,Mageia Security Advisory,Network Security Fixes,Denial of Service. . LinuxSecurity.com Team

Calendar%202 Mar 24, 2024 Mageia
202

openSUSE Leap 15.5 SUSE-SU-2023:2250-2 Important: Network Security Fix

This update for openvswitch fixes the following issues: CVE-2022-4338: Fixed Integer Underflow in Organization Specific TLV (bsc#1206580).. # Security update for openvswitch Announcement ID: SUSE-SU-2023:2250-2 Rating: important References: * #1206580 * #1206581 Cross-References: * CVE-2022-4337 * CVE-2022-4338 CVSS scores: * CVE-2022-4337 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2022-4337 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2022-4338 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2022-4338 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 An update that solves two vulnerabilities can now be installed. ## Description: This update for openvswitch fixes the following issues: * CVE-2022-4338: Fixed Integer Underflow in Organization Specific TLV (bsc#1206580). * CVE-2022-4337: Fixed Out-of-Bounds Read in Organization Specific TLV (bsc#1206581). ## Patch Instructions: To install this SUSE Important update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-2250=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * openvswitch-debuginfo-2.14.2-150400.24.6.1 * openvswitch-test-2.14.2-150400.24.6.1 * libopenvswitch-2_14-0-debuginfo-2.14.2-150400.24.6.1 * ovn-central-debuginfo-20.06.2-150400.24.6.1 * libovn-20_06-0-debuginfo-20.06.2-150400.24.6.1 * ovn-vtep-debuginfo-20.06.2-150400.24.6.1 * ovn-debuginfo-20.06.2-150400.24.6.1 * ovn-central-20.06.2-150400.24.6.1 * openvswitch-devel-2.14.2-150400.24.6.1 * ovn-20.06.2-150400.24.6.1 * python3-ovs-2.14.2-150400.24.6.1 * ovn-devel-20.06.2-150400.24.6.1 * openvswitch-2.14.2-150400.24.6.1 * openvswitch-vtep-2.14.2-150400.24.6.1 *libovn-20_06-0-20.06.2-150400.24.6.1 * ovn-docker-20.06.2-150400.24.6.1 * openvswitch-pki-2.14.2-150400.24.6.1 * ovn-host-20.06.2-150400.24.6.1 * libopenvswitch-2_14-0-2.14.2-150400.24.6.1 * ovn-vtep-20.06.2-150400.24.6.1 * openvswitch-test-debuginfo-2.14.2-150400.24.6.1 * ovn-host-debuginfo-20.06.2-150400.24.6.1 * openvswitch-debugsource-2.14.2-150400.24.6.1 * openvswitch-ipsec-2.14.2-150400.24.6.1 * openvswitch-vtep-debuginfo-2.14.2-150400.24.6.1 * openSUSE Leap 15.5 (noarch) * openvswitch-doc-2.14.2-150400.24.6.1 * ovn-doc-20.06.2-150400.24.6.1 ## References: * https://www.suse.com/security/cve/CVE-2022-4337.html * https://www.suse.com/security/cve/CVE-2022-4338.html * https://bugzilla.suse.com/show_bug.cgi?id=1206580 * https://bugzilla.suse.com/show_bug.cgi?id=1206581 . The latest patch for openvswitch resolves critical memory corruption and buffer management vulnerabilities, thereby improving overall system integrity.. openvswitch update, network security update, important patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 17, 2023 Important OpenSUSE
99

Slackware 15.0: 2023-075-02 Critical: Openssh Memory Safety Fix

New openssh packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] openssh (SSA:2023-075-02) New openssh packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/openssh-9.3p1-i586-1_slack15.0.txz: Upgraded. This release contains fixes for a security problem and a memory safety problem. The memory safety problem is not believed to be exploitable, but we report most network-reachable memory faults as security bugs. For more information, see: https://www.openssh.org/txt/release-9.3 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 15.0 package: 07944e3ca61d1c9d8ebc02f71a3ee8e1 openssh-9.3p1-i586-1_slack15.0.txz Slackware x86_64 15.0 package: d6ef21123235b557bdf6b77a764f1dc0 openssh-9.3p1-x86_64-1_slack15.0.txz Slackware -current package: c7d1568ef653d89c13ffb21260df3df3 n/openssh-9.3p1-i586-1.txz Slackware x86_64 -current package: 4a8b353dea034c092447d8ba22e9df47 n/openssh-9.3p1-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg openssh-9.3p1-i586-1_slack15.0.txz +-----+ . Explore fresh OpenSSH offerings for Slackware to swiftly address vital security and memory safety concerns.. Slackware Update, Openssh Patch, Network Security Fix, Memory Safety Issue. . Severity: Critical.LinuxSecurity.com Team

Calendar%202 Mar 17, 2023 Critical Slackware
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200