Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
zabbix a popular network monitoring solution was affected by a vulnerabilty. Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.. Debian LTS Advisory DLA-4473-1
New version 1.10.6. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-1e3425e7ea 2026-01-21 01:30:15.162774+00:00 -------------------------------------------------------------------------------- Name : libpcap Product : Fedora 42 Version : 1.10.6 Release : 1.fc42 URL : https://www.tcpdump.org/ Summary : A system-independent interface for user-level packet capture Description : Libpcap provides a portable framework for low-level network monitoring. Libpcap can provide network statistics collection, security monitoring and network debugging. Since almost every system vendor provides a different interface for packet capture, the libpcap authors created this system-independent API to ease in porting and to alleviate the need for several system-dependent packet capture modules in each application. Install libpcap if you need to do low-level network traffic monitoring on your network. -------------------------------------------------------------------------------- Update Information: New version 1.10.6 -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 5 2026 Michal Ruprich - 14:1.10.6-1 - New version 1.10.6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2426393 - libpcap-1.10.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2426393 [ 2 ] Bug #2426630 - CVE-2025-11961 libpcap: libpcap: Memory corruption via malformed MAC-48 address input [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2426630 [ 3 ] Bug #2426631 - CVE-2025-11961 libpcap: libpcap: Memory corruption via malformed MAC-48 address input [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2426631 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c'dnf upgrade --advisory FEDORA-2026-1e3425e7ea' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
New version 1.10.6. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-274010c760 2026-01-07 00:49:01.527406+00:00 -------------------------------------------------------------------------------- Name : libpcap Product : Fedora 43 Version : 1.10.6 Release : 1.fc43 URL : https://www.tcpdump.org/ Summary : A system-independent interface for user-level packet capture Description : Libpcap provides a portable framework for low-level network monitoring. Libpcap can provide network statistics collection, security monitoring and network debugging. Since almost every system vendor provides a different interface for packet capture, the libpcap authors created this system-independent API to ease in porting and to alleviate the need for several system-dependent packet capture modules in each application. Install libpcap if you need to do low-level network traffic monitoring on your network. -------------------------------------------------------------------------------- Update Information: New version 1.10.6 -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 5 2026 Michal Ruprich - 14:1.10.6-1 - New version 1.10.6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2426393 - libpcap-1.10.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2426393 [ 2 ] Bug #2426630 - CVE-2025-11961 libpcap: libpcap: Memory corruption via malformed MAC-48 address input [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2426630 [ 3 ] Bug #2426631 - CVE-2025-11961 libpcap: libpcap: Memory corruption via malformed MAC-48 address input [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2426631 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c'dnf upgrade --advisory FEDORA-2026-274010c760' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 20250602 with fixes for CVE-2025-48964. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-885e731f6f 2025-08-07 01:11:45.458396+00:00 -------------------------------------------------------------------------------- Name : iputils Product : Fedora 41 Version : 20250602 Release : 3.fc41 URL : https://github.com/iputils/iputils Summary : Network monitoring tools including ping Description : The iputils package contains basic utilities for monitoring a network, including ping. The ping command sends a series of ICMP protocol ECHO_REQUEST packets to a specified network host to discover whether the target machine is alive and receiving network traffic. -------------------------------------------------------------------------------- Update Information: Update to 20250602 with fixes for CVE-2025-48964 -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 25 2025 Jan Macku - 20250602-3 - remove build dependency on openssl-devel removed in s20200821 * Thu Jul 24 2025 Fedora Release Engineering - 20250602-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Sun Jul 13 2025 Kevin Fenzi - 20250602-1 - Update to 20250602. Fixes rhbz#2369782 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2382663 - CVE-2025-48964 iputils: iputils integer overflow [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2382663 [ 2 ] Bug #2382664 - CVE-2025-48964 iputils: iputils integer overflow [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2382664 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-885e731f6f' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fix for CVE-2025-47268. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-7e1b66f54e 2025-05-24 01:46:25.887858+00:00 -------------------------------------------------------------------------------- Name : iputils Product : Fedora 41 Version : 20240905 Release : 4.fc41 URL : https://github.com/iputils/iputils Summary : Network monitoring tools including ping Description : The iputils package contains basic utilities for monitoring a network, including ping. The ping command sends a series of ICMP protocol ECHO_REQUEST packets to a specified network host to discover whether the target machine is alive and receiving network traffic. -------------------------------------------------------------------------------- Update Information: Fix for CVE-2025-47268 -------------------------------------------------------------------------------- ChangeLog: * Sat May 17 2025 Kevin Fenzi - 20240905-4 - Add upstream patch for CVE-2025-47268. * Fri Jan 17 2025 Fedora Release Engineering - 20240905-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Sun Jan 12 2025 Zbigniew JÄdrzejewski-Szmek - 20240905-2 - Rebuilt for the bin-sbin merge (2nd attempt) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2364303 - CVE-2025-47268 iputils: Signed Integer Overflow in Timestamp Multiplication in iputils ping [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2364303 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7e1b66f54e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project canbe found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- . Critical patch applied for Signed Integer Overflow in iputils ping for Fedora 41, mitigating CVE-2025-47268.. iputils update,Fedora 41,network monitoring tools,signed integer overflow. . Severity: Critical. LinuxSecurity.com Team
Several security vulnerabilities have been discovered in zabbix, a network monitoring solution, potentially among other effects allowing denial of service, information disclosure or remote code inclusion. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4131-1
Improper form input field validation has been fixed in Zabbix, a network monitoring solution. For Debian 10 buster, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3798-1
Several security vulnerabilities have been discovered in zabbix, a network monitoring solution, potentially allowing an attacker to perform a stored XSS, Server-Side Request Forgery (SSRF), exposure of sensitive information, a system crash, or arbitrary code execution. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3717-1
Get the latest Linux and open source security news straight to your inbox.