Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
172

Ubuntu 25.04: USN-7611-1 critical: Linux kernel network flaws

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7611-1 July 02, 2025 linux, linux-gcp, linux-raspi, linux-realtime vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-raspi: Linux kernel for Raspberry Pi systems - linux-realtime: Linux kernel for Real-time systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Netfilter; - Network traffic control; (CVE-2025-38000, CVE-2025-37890, CVE-2025-38001, CVE-2025-37997, CVE-2025-37932) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 linux-image-6.14.0-1005-realtime 6.14.0-1005.5 linux-image-6.14.0-1008-raspi 6.14.0-1008.8 linux-image-6.14.0-1009-gcp 6.14.0-1009.9 linux-image-6.14.0-1009-gcp-64k 6.14.0-1009.9 linux-image-6.14.0-23-generic 6.14.0-23.23 linux-image-6.14.0-23-generic-64k 6.14.0-23.23 linux-image-gcp 6.14.0-1009.9 linux-image-gcp-6.14 6.14.0-1009.9 linux-image-gcp-64k 6.14.0-1009.9 linux-image-gcp-64k-6.14 6.14.0-1009.9 linux-image-generic 6.14.0-23.23 linux-image-generic-6.14 6.14.0-23.23 linux-image-generic-64k 6.14.0-23.23 linux-image-generic-64k-6.14 6.14.0-23.23 linux-image-raspi 6.14.0-1008.8 linux-image-raspi-6.14 6.14.0-1008.8 linux-image-realtime 6.14.0-1005.5 linux-image-realtime-6.14 6.14.0-1005.5 linux-image-virtual 6.14.0-23.23 linux-image-virtual-6.14 6.14.0-23.23 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7611-1 CVE-2025-37890, CVE-2025-37932, CVE-2025-37997, CVE-2025-38000, CVE-2025-38001 Package Information: https://launchpad.net/ubuntu/+source/linux/6.14.0-23.23 https://launchpad.net/ubuntu/+source/linux-gcp/6.14.0-1009.9 https://launchpad.net/ubuntu/+source/linux-raspi/6.14.0-1008.8 https://launchpad.net/ubuntu/+source/linux-realtime/6.14.0-1005.5 . Numerous significant security weaknesses addressed in the core of Ubuntu Linux to thwart potential exploitation and maintain system reliability.. Ubuntu 25.04 security, Linux kernel patches, network security flaws. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 02, 2025 Critical Ubuntu
202

openSUSE: 2023:3647-1 Important: Fixes For Network Flaws in Kernel

This update for the Linux Kernel 5.14.21-150400_24_60 fixes several issues. The following security issues were fixed:. # Security update for the Linux Kernel (Live Patch 11 for SLE 15 SP4) Announcement ID: SUSE-SU-2023:3647-1 Rating: important References: * #1208839 * #1210630 * #1211187 * #1211395 * #1212849 * #1213063 Cross-References: * CVE-2023-1077 * CVE-2023-2156 * CVE-2023-2176 * CVE-2023-3090 * CVE-2023-32233 * CVE-2023-35001 CVSS scores: * CVE-2023-1077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-1077 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-2156 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-2156 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-2176 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-2176 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-3090 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-3090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-32233 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-32233 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-35001 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-35001 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves six vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.14.21-150400_24_60 fixes several issues. The following security issues were fixed: * CVE-2023-32233: Fixed ause-after-free in Netfilter nf_tables when processing batch requests (bsc#1211187). * CVE-2023-2156: Fixed a flaw in the networking subsystem within the handling of the RPL protocol (bsc#1211395). * CVE-2023-35001: Fixed an out-of-bounds memory access flaw in nft_byteorder that could allow a local attacker to escalate their privilege (bsc#1213063). * CVE-2023-1077: Fixed a type confusion in pick_next_rt_entity(), that could cause memory corruption (bsc#1208839). * CVE-2023-2176: Fixed an out-of-boundary read in compare_netdev_and_ip in drivers/infiniband/core/cma.c in RDMA (bsc#1210630). * CVE-2023-3090: Fixed a heap out-of-bounds write in the ipvlan network driver (bsc#1212849). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2023-3652=1 SUSE-SLE- Module-Live-Patching-15-SP4-2023-3647=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2023-3647=1 SUSE-2023-3652=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_55-default-debuginfo-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_55-default-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_10-debugsource-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_11-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_60-default-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_60-default-debuginfo-5-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_55-default-debuginfo-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_10-debugsource-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_55-default-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_11-debugsource-5-150400.2.1 *kernel-livepatch-5_14_21-150400_24_60-default-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_60-default-debuginfo-5-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2023-1077.html * https://www.suse.com/security/cve/CVE-2023-2156.html * https://www.suse.com/security/cve/CVE-2023-2176.html * https://www.suse.com/security/cve/CVE-2023-3090.html * https://www.suse.com/security/cve/CVE-2023-32233.html * https://www.suse.com/security/cve/CVE-2023-35001.html * https://bugzilla.suse.com/show_bug.cgi?id=1208839 * https://bugzilla.suse.com/show_bug.cgi?id=1210630 * https://bugzilla.suse.com/show_bug.cgi?id=1211187 * https://bugzilla.suse.com/show_bug.cgi?id=1211395 * https://bugzilla.suse.com/show_bug.cgi?id=1212849 * https://bugzilla.suse.com/show_bug.cgi?id=1213063 . An essential upgrade for the Linux Kernel enhances the safety and reliability of Fedora and Red Hat environments.. Kernel Live Patching, SUSE Updates, Linux Kernel Security, Security Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 18, 2023 Important OpenSUSE
100

SUSE: 2021:0999-1 Critical: MozillaFirefox Memory Safety and Network Flaws

An update that fixes four vulnerabilities is now available. . SUSE Security Update: Security update for MozillaFirefox ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0999-1 Rating: important References: #1183942 Cross-References: CVE-2021-23981 CVE-2021-23982 CVE-2021-23984 CVE-2021-23987 Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 7 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP2-LTSS-ERICSSON SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for MozillaFirefox fixes the following issues: - Firefox was updated to 78.9.0 ESR (MFSA 2021-11, bsc#1183942) * CVE-2021-23981: Texture upload into an unbound backing buffer resulted in an out-of-bound read * CVE-2021-23982: Internal network hosts could have been probed by a malicious webpage * CVE-2021-23984: Malicious extensions could have spoofed popup information * CVE-2021-23987: Memory safety bugs Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2021-999=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2021-999=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2021-999=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2021-999=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2021-999=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-999=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2021-999=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2021-999=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2021-999=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-999=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2021-999=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2021-999=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2021-999=1 - SUSE Linux Enterprise Server 12-SP2-LTSS-ERICSSON: zypper in -t patch SUSE-SLE-SERVER-12-SP2-LTSS-ERICSSON-2021-999=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2021-999=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2021-999=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2021-999=1 Package List: - SUSE OpenStack Cloud Crowbar9 (x86_64): MozillaFirefox-78.9.0-112.54.1 MozillaFirefox-debuginfo-78.9.0-112.54.1 MozillaFirefox-debugsource-78.9.0-112.54.1 MozillaFirefox-devel-78.9.0-112.54.1 MozillaFirefox-translations-common-78.9.0-112.54.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): MozillaFirefox-78.9.0-112.54.1 MozillaFirefox-debuginfo-78.9.0-112.54.1 MozillaFirefox-debugsource-78.9.0-112.54.1 MozillaFirefox-devel-78.9.0-112.54.1 MozillaFirefox-translations-common-78.9.0-112.54.1 - SUSE OpenStack Cloud 9 (x86_64): MozillaFirefox-78.9.0-112.54.1 MozillaFirefox-debuginfo-78.9.0-112.54.1 MozillaFirefox-debugsource-78.9.0-112.54.1 MozillaFirefox-devel-78.9.0-112.54.1 MozillaFirefox-translations-common-78.9.0-112.54.1 - SUSE OpenStack Cloud 8 (x86_64): MozillaFirefox-78.9.0-112.54.1 MozillaFirefox-debuginfo-78.9.0-112.54.1 MozillaFirefox-debugsource-78.9.0-112.54.1 MozillaFirefox-devel-78.9.0-112.54.1 MozillaFirefox-translations-common-78.9.0-112.54.1 - SUSE OpenStack Cloud 7 (s390x x86_64): MozillaFirefox-78.9.0-112.54.1 MozillaFirefox-debuginfo-78.9.0-112.54.1 MozillaFirefox-debugsource-78.9.0-112.54.1 MozillaFirefox-devel-78.9.0-112.54.1 MozillaFirefox-translations-common-78.9.0-112.54.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): MozillaFirefox-debuginfo-78.9.0-112.54.1 MozillaFirefox-debugsource-78.9.0-112.54.1 MozillaFirefox-devel-78.9.0-112.54.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): MozillaFirefox-78.9.0-112.54.1 MozillaFirefox-debuginfo-78.9.0-112.54.1 MozillaFirefox-debugsource-78.9.0-112.54.1 MozillaFirefox-devel-78.9.0-112.54.1 MozillaFirefox-translations-common-78.9.0-112.54.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): MozillaFirefox-78.9.0-112.54.1 MozillaFirefox-debuginfo-78.9.0-112.54.1 MozillaFirefox-debugsource-78.9.0-112.54.1 MozillaFirefox-devel-78.9.0-112.54.1 MozillaFirefox-translations-common-78.9.0-112.54.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): MozillaFirefox-78.9.0-112.54.1 MozillaFirefox-debuginfo-78.9.0-112.54.1 MozillaFirefox-debugsource-78.9.0-112.54.1 MozillaFirefox-devel-78.9.0-112.54.1 MozillaFirefox-translations-common-78.9.0-112.54.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): MozillaFirefox-78.9.0-112.54.1 MozillaFirefox-debuginfo-78.9.0-112.54.1 MozillaFirefox-debugsource-78.9.0-112.54.1 MozillaFirefox-devel-78.9.0-112.54.1 MozillaFirefox-translations-common-78.9.0-112.54.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64 ppc64le s390x x86_64): MozillaFirefox-78.9.0-112.54.1 MozillaFirefox-debuginfo-78.9.0-112.54.1 MozillaFirefox-debugsource-78.9.0-112.54.1 MozillaFirefox-devel-78.9.0-112.54.1 MozillaFirefox-translations-common-78.9.0-112.54.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 ppc64le s390x x86_64): MozillaFirefox-78.9.0-112.54.1 MozillaFirefox-debuginfo-78.9.0-112.54.1 MozillaFirefox-debugsource-78.9.0-112.54.1 MozillaFirefox-devel-78.9.0-112.54.1 MozillaFirefox-translations-common-78.9.0-112.54.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): MozillaFirefox-78.9.0-112.54.1 MozillaFirefox-debuginfo-78.9.0-112.54.1 MozillaFirefox-debugsource-78.9.0-112.54.1 MozillaFirefox-devel-78.9.0-112.54.1 MozillaFirefox-translations-common-78.9.0-112.54.1 - SUSE Linux Enterprise Server 12-SP2-LTSS-ERICSSON (x86_64): MozillaFirefox-78.9.0-112.54.1 MozillaFirefox-debuginfo-78.9.0-112.54.1 MozillaFirefox-debugsource-78.9.0-112.54.1 MozillaFirefox-devel-78.9.0-112.54.1 MozillaFirefox-translations-common-78.9.0-112.54.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): MozillaFirefox-78.9.0-112.54.1 MozillaFirefox-debuginfo-78.9.0-112.54.1 MozillaFirefox-debugsource-78.9.0-112.54.1 MozillaFirefox-devel-78.9.0-112.54.1 MozillaFirefox-translations-common-78.9.0-112.54.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): MozillaFirefox-78.9.0-112.54.1 MozillaFirefox-debuginfo-78.9.0-112.54.1 MozillaFirefox-debugsource-78.9.0-112.54.1 MozillaFirefox-devel-78.9.0-112.54.1 MozillaFirefox-translations-common-78.9.0-112.54.1 - HPE Helion Openstack 8 (x86_64): MozillaFirefox-78.9.0-112.54.1 MozillaFirefox-debuginfo-78.9.0-112.54.1 MozillaFirefox-debugsource-78.9.0-112.54.1 MozillaFirefox-devel-78.9.0-112.54.1 MozillaFirefox-translations-common-78.9.0-112.54.1 References: https://www.suse.com/security/cve/CVE-2021-23981.html https://www.suse.com/security/cve/CVE-2021-23982.html https://www.suse.com/security/cve/CVE-2021-23984.html https://www.suse.com/security/cve/CVE-2021-23987.html https://bugzilla.suse.com/1183942 . Addresses three security issues in MozillaFirefox: crucial update applicable to several SUSE versions. Find out how to apply the fix.. MozillaFirefox Update, SUSE Security Patch, Software Update Instructions. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 31, 2021 Important SuSE
89

Fedora 24: Security Update for DHCP Authentication Issues - Critical

Fixes CVE-2017-3142 and CVE-2017-3143. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-59127a606c 2017-07-27 14:24:45.247239 --------------------------------------------------------------------------------Name : dhcp Product : Fedora 24 Version : 4.3.4 Release : 4.fc24 URL : Summary : Dynamic host configuration protocol software Description : DHCP (Dynamic Host Configuration Protocol) --------------------------------------------------------------------------------Update Information: Fixes CVE-2017-3142 and CVE-2017-3143 --------------------------------------------------------------------------------References: [ 1 ] Bug #1466610 - CVE-2017-3143 bind99: bind: An error in TSIG authentication can permit unauthorized dynamic updates [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1466610 [ 2 ] Bug #1466612 - CVE-2017-3142 bind99: bind: An error in TSIG authentication can permit unauthorized zone transfers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1466612 [ 3 ] Bug #1471747 - ddns updates broken since rebuild with bind99 9.9.10 https://bugzilla.redhat.com/show_bug.cgi?id=1471747 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade dhcp' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. .Resolves urgent vulnerabilities in DHCP within Fedora 24. Information regarding patches and potential risks provided.. Fedora Security Update, DHCP Software Fix, Network Protocol Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 27, 2017 Critical Fedora
98

Red Hat 2.1 RHSA-2006:0191-01 Critical: Multiple Kernel Exploits

Updated kernel packages that fix a number of security issues as well as other bugs are now available for Red Hat Enterprise Linux 2.1 (32 bit architectures) This security advisory has been rated as having important security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Important: kernel security update Advisory ID: RHSA-2006:0191-01 Advisory URL: https://access.redhat.com/errata/RHSA-2006:0191.html Issue date: 2006-02-01 Updated on: 2006-02-01 Product: Red Hat Enterprise Linux CVE Names: CVE-2002-2185 CVE-2004-1058 CVE-2004-1073 CVE-2005-0124 CVE-2005-0400 CVE-2005-0815 CVE-2005-2458 CVE-2005-2709 CVE-2005-2973 CVE-2005-3180 CVE-2005-3275 CVE-2005-3806 - ---------------------------------------------------------------------1. Summary: Updated kernel packages that fix a number of security issues as well as other bugs are now available for Red Hat Enterprise Linux 2.1 (32 bit architectures) This security advisory has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 3. Problem description: The Linux kernel handles the basic functions of the operating system. These new kernel packages contain fixes for the security issues described below: - - a flaw in network IGMP processing that a allowed a remote user on the local network to cause a denial of service (disabling of multicast reports) if the system is running multicast applications (CVE-2002-2185, moderate) - - a race condition that allowed local users to read the environment variables of another process (CVE-2004-1058, low) - - a flaw in the open_exec function of execve that allowed a local user to readsetuid ELF binaries that should otherwise be protected by standard permissions. (CVE-2004-1073, moderate). Red Hat originally reported this flaw as being fixed by RHSA-2004:504, but a patch for this issue was missing from that update. - - a flaw in the coda module that allowed a local user to cause a denial of service (crash) or possibly gain privileges (CVE-2005-0124, moderate) - - a potential leak of kernel data from ext2 file system handling (CVE-2005-0400, low) - - flaws in ISO-9660 file system handling that allowed the mounting of an invalid image on a CD-ROM to cause a denial of service (crash) or potentially execute arbitrary code (CVE-2005-0815, moderate) - - a flaw in gzip/zlib handling internal to the kernel that may allow a local user to cause a denial of service (crash) (CVE-2005-2458, low) - - a flaw in procfs handling during unloading of modules that allowed a local user to cause a denial of service or potentially gain privileges (CVE-2005-2709, moderate) - - a flaw in IPv6 network UDP port hash table lookups that allowed a local user to cause a denial of service (hang) (CVE-2005-2973, important) - - a network buffer info leak using the orinoco driver that allowed a remote user to possibly view uninitialized data (CVE-2005-3180, important) - - a flaw in IPv4 network TCP and UDP netfilter handling that allowed a local user to cause a denial of service (crash) (CVE-2005-3275, important) - - a flaw in the IPv6 flowlabel code that allowed a local user to cause a denial of service (crash) (CVE-2005-3806, important) The following bugs were also addressed: - - Handle set_brk() errors in binfmt_elf/aout - - Correct error handling in shmem_ioctl - - Correct scsi error return - - Fix netdump time keeping bug - - Fix netdump link-down freeze - - Fix FAT fs deadlock All Red Hat Enterprise Linux 2.1 users are advised to upgrade their kernels to the packages associated with their machine architectures and configurations as listed inthis erratum. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed (http://bugzilla.redhat.com/): 133115 - CVE-2004-1058 /proc/ /cmdline information disclosure 137214 - netconsole freezes during printk() when output link not up 144155 - binfmt_aout DoS 146081 - CVE-2005-0124 Coverity: coda fs flaw 152401 - CVE-2005-0400 ext2 mkdir() directory entry random kernel memory leak 152407 - CVE-2005-0815 isofs range checking flaws 152553 - CVE-2004-1073 looks unfixed in RHEL2.1 165682 - CVE-2005-2458 gzip/zlib flaws 168926 - CVE-2005-2709 More sysctl flaws 170280 - CVE-2005-3180 orinoco driver information leakage 170777 - CVE-2005-2973 ipv6 infinite loop 171387 - CVE-2005-3275 NAT DoS 174085 - CVE-2005-3806 ipv6 DOS 174811 - CVE-2002-2185 IGMP DoS 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 31a7a8bf00a649471f351e4c8527793d kernel-2.4.9-e.68.src.rpm i386: 65d2bb250a3647ca0042aeb1963a30b8 kernel-2.4.9-e.68.athlon.rpm 5df6d6315fab4e0bccc72f3e3b848e80 kernel-2.4.9-e.68.i686.rpm b5161ec68ef49c692a791815f8addce1 kernel-BOOT-2.4.9-e.68.i386.rpm 6862bc8e59b6d764525a095492849e75 kernel-debug-2.4.9-e.68.i686.rpm fd8225c7d253bc954042421e8190b79b kernel-doc-2.4.9-e.68.i386.rpm a0d9c5c91191994d754c00e9422b052a kernel-enterprise-2.4.9-e.68.i686.rpm 9b34d912bded4d839a717acec5437776 kernel-headers-2.4.9-e.68.i386.rpm e26872f9afdf55393554a7753717d58a kernel-smp-2.4.9-e.68.athlon.rpm dce34945223d1b037aab1dbc2bc19a1f kernel-smp-2.4.9-e.68.i686.rpm 9fbcbe7084d697a330f502c4749be39a kernel-source-2.4.9-e.68.i386.rpm 5e067e3c643f50e4155f2b31e340c5ca kernel-summit-2.4.9-e.68.i686.rpm Red HatEnterprise Linux ES version 2.1: SRPMS: 31a7a8bf00a649471f351e4c8527793d kernel-2.4.9-e.68.src.rpm i386: 65d2bb250a3647ca0042aeb1963a30b8 kernel-2.4.9-e.68.athlon.rpm 5df6d6315fab4e0bccc72f3e3b848e80 kernel-2.4.9-e.68.i686.rpm b5161ec68ef49c692a791815f8addce1 kernel-BOOT-2.4.9-e.68.i386.rpm 6862bc8e59b6d764525a095492849e75 kernel-debug-2.4.9-e.68.i686.rpm fd8225c7d253bc954042421e8190b79b kernel-doc-2.4.9-e.68.i386.rpm 9b34d912bded4d839a717acec5437776 kernel-headers-2.4.9-e.68.i386.rpm e26872f9afdf55393554a7753717d58a kernel-smp-2.4.9-e.68.athlon.rpm dce34945223d1b037aab1dbc2bc19a1f kernel-smp-2.4.9-e.68.i686.rpm 9fbcbe7084d697a330f502c4749be39a kernel-source-2.4.9-e.68.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: 31a7a8bf00a649471f351e4c8527793d kernel-2.4.9-e.68.src.rpm i386: 65d2bb250a3647ca0042aeb1963a30b8 kernel-2.4.9-e.68.athlon.rpm 5df6d6315fab4e0bccc72f3e3b848e80 kernel-2.4.9-e.68.i686.rpm b5161ec68ef49c692a791815f8addce1 kernel-BOOT-2.4.9-e.68.i386.rpm 6862bc8e59b6d764525a095492849e75 kernel-debug-2.4.9-e.68.i686.rpm fd8225c7d253bc954042421e8190b79b kernel-doc-2.4.9-e.68.i386.rpm a0d9c5c91191994d754c00e9422b052a kernel-enterprise-2.4.9-e.68.i686.rpm 9b34d912bded4d839a717acec5437776 kernel-headers-2.4.9-e.68.i386.rpm e26872f9afdf55393554a7753717d58a kernel-smp-2.4.9-e.68.athlon.rpm dce34945223d1b037aab1dbc2bc19a1f kernel-smp-2.4.9-e.68.i686.rpm 9fbcbe7084d697a330f502c4749be39a kernel-source-2.4.9-e.68.i386.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7.References: https://www.cve.org/CVERecord?id=CVE-2002-2185 https://www.cve.org/CVERecord?id=CVE-2004-1058 https://www.cve.org/CVERecord?id=CVE-2004-1073 https://www.cve.org/CVERecord?id=CVE-2005-0124 https://www.cve.org/CVERecord?id=CVE-2005-0400 https://www.cve.org/CVERecord?id=CVE-2005-0815 https://www.cve.org/CVERecord?id=CVE-2005-2458 https://www.cve.org/CVERecord?id=CVE-2005-2709 https://www.cve.org/CVERecord?id=CVE-2005-2973 https://www.cve.org/CVERecord?id=CVE-2005-3180 https://www.cve.org/CVERecord?id=CVE-2005-3275 https://www.cve.org/CVERecord?id=CVE-2005-3806 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2006 Red Hat, Inc. . - --------------------------------------------------------------------- Red Hat Security Advisory Sy. updated, kernel, packages, number, security, other. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 01, 2006 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200