Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 136 articles for you...
100

SUSE openvswitch Important Heap Over-Read Vulnerabilities 2026-2481-1

An update that solves two vulnerabilities can now be installed.. # Security update for openvswitch Announcement ID: SUSE-SU-2026:2481-1 Release Date: 2026-06-22T10:55:16Z Rating: important References: * bsc#1262498 * bsc#1262499 Cross-References: * CVE-2026-5265 * CVE-2026-5367 CVSS scores: * CVE-2026-5265 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-5265 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-5367 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-5367 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for openvswitch fixes the following issues * CVE-2026-5265: heap over-read in ICMP error response generation (bsc#1262498). * CVE-2026-5367: heap over-read in OVN DHCPv6 client ID processing (bsc#1262499). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2481=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2481=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patchSUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2481=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2481=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2481=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2481=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2481=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * openvswitch-devel-2.14.2-150400.24.35.1 * openvswitch-test-2.14.2-150400.24.35.1 * ovn-vtep-debuginfo-20.06.2-150400.24.35.1 * openvswitch-debuginfo-2.14.2-150400.24.35.1 * libopenvswitch-2_14-0-debuginfo-2.14.2-150400.24.35.1 * openvswitch-debugsource-2.14.2-150400.24.35.1 * ovn-host-20.06.2-150400.24.35.1 * libovn-20_06-0-debuginfo-20.06.2-150400.24.35.1 * ovn-debuginfo-20.06.2-150400.24.35.1 * libopenvswitch-2_14-0-2.14.2-150400.24.35.1 * ovn-host-debuginfo-20.06.2-150400.24.35.1 * openvswitch-2.14.2-150400.24.35.1 * ovn-central-debuginfo-20.06.2-150400.24.35.1 * openvswitch-test-debuginfo-2.14.2-150400.24.35.1 * openvswitch-pki-2.14.2-150400.24.35.1 * python3-ovs-2.14.2-150400.24.35.1 * libovn-20_06-0-20.06.2-150400.24.35.1 * ovn-20.06.2-150400.24.35.1 * openvswitch-ipsec-2.14.2-150400.24.35.1 * ovn-vtep-20.06.2-150400.24.35.1 * openvswitch-vtep-2.14.2-150400.24.35.1 * ovn-docker-20.06.2-150400.24.35.1 * ovn-central-20.06.2-150400.24.35.1 * ovn-devel-20.06.2-150400.24.35.1 * openvswitch-vtep-debuginfo-2.14.2-150400.24.35.1 * openSUSE Leap 15.4 (noarch) * ovn-doc-20.06.2-150400.24.35.1 * openvswitch-doc-2.14.2-150400.24.35.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * openvswitch-devel-2.14.2-150400.24.35.1 * openvswitch-test-2.14.2-150400.24.35.1 *ovn-vtep-debuginfo-20.06.2-150400.24.35.1 * openvswitch-debuginfo-2.14.2-150400.24.35.1 * libopenvswitch-2_14-0-debuginfo-2.14.2-150400.24.35.1 * openvswitch-debugsource-2.14.2-150400.24.35.1 * ovn-host-20.06.2-150400.24.35.1 * libovn-20_06-0-debuginfo-20.06.2-150400.24.35.1 * ovn-debuginfo-20.06.2-150400.24.35.1 * libopenvswitch-2_14-0-2.14.2-150400.24.35.1 * ovn-host-debuginfo-20.06.2-150400.24.35.1 * openvswitch-2.14.2-150400.24.35.1 * ovn-central-debuginfo-20.06.2-150400.24.35.1 * openvswitch-test-debuginfo-2.14.2-150400.24.35.1 * openvswitch-pki-2.14.2-150400.24.35.1 * python3-ovs-2.14.2-150400.24.35.1 * libovn-20_06-0-20.06.2-150400.24.35.1 * ovn-20.06.2-150400.24.35.1 * openvswitch-ipsec-2.14.2-150400.24.35.1 * ovn-vtep-20.06.2-150400.24.35.1 * openvswitch-vtep-2.14.2-150400.24.35.1 * ovn-docker-20.06.2-150400.24.35.1 * ovn-central-20.06.2-150400.24.35.1 * ovn-devel-20.06.2-150400.24.35.1 * openvswitch-vtep-debuginfo-2.14.2-150400.24.35.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * openvswitch-devel-2.14.2-150400.24.35.1 * openvswitch-test-2.14.2-150400.24.35.1 * ovn-vtep-debuginfo-20.06.2-150400.24.35.1 * openvswitch-debuginfo-2.14.2-150400.24.35.1 * libopenvswitch-2_14-0-debuginfo-2.14.2-150400.24.35.1 * openvswitch-debugsource-2.14.2-150400.24.35.1 * ovn-host-20.06.2-150400.24.35.1 * libovn-20_06-0-debuginfo-20.06.2-150400.24.35.1 * ovn-debuginfo-20.06.2-150400.24.35.1 * libopenvswitch-2_14-0-2.14.2-150400.24.35.1 * ovn-host-debuginfo-20.06.2-150400.24.35.1 * openvswitch-2.14.2-150400.24.35.1 * ovn-central-debuginfo-20.06.2-150400.24.35.1 * openvswitch-test-debuginfo-2.14.2-150400.24.35.1 * openvswitch-pki-2.14.2-150400.24.35.1 * python3-ovs-2.14.2-150400.24.35.1 * libovn-20_06-0-20.06.2-150400.24.35.1 * ovn-20.06.2-150400.24.35.1 * openvswitch-ipsec-2.14.2-150400.24.35.1 *ovn-vtep-20.06.2-150400.24.35.1 * openvswitch-vtep-2.14.2-150400.24.35.1 * ovn-docker-20.06.2-150400.24.35.1 * ovn-central-20.06.2-150400.24.35.1 * ovn-devel-20.06.2-150400.24.35.1 * openvswitch-vtep-debuginfo-2.14.2-150400.24.35.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * openvswitch-devel-2.14.2-150400.24.35.1 * openvswitch-test-2.14.2-150400.24.35.1 * ovn-vtep-debuginfo-20.06.2-150400.24.35.1 * openvswitch-debuginfo-2.14.2-150400.24.35.1 * libopenvswitch-2_14-0-debuginfo-2.14.2-150400.24.35.1 * openvswitch-debugsource-2.14.2-150400.24.35.1 * ovn-host-20.06.2-150400.24.35.1 * libovn-20_06-0-debuginfo-20.06.2-150400.24.35.1 * ovn-debuginfo-20.06.2-150400.24.35.1 * libopenvswitch-2_14-0-2.14.2-150400.24.35.1 * ovn-host-debuginfo-20.06.2-150400.24.35.1 * ovn-central-debuginfo-20.06.2-150400.24.35.1 * openvswitch-2.14.2-150400.24.35.1 * openvswitch-test-debuginfo-2.14.2-150400.24.35.1 * openvswitch-pki-2.14.2-150400.24.35.1 * python3-ovs-2.14.2-150400.24.35.1 * libovn-20_06-0-20.06.2-150400.24.35.1 * ovn-20.06.2-150400.24.35.1 * openvswitch-ipsec-2.14.2-150400.24.35.1 * ovn-vtep-20.06.2-150400.24.35.1 * openvswitch-vtep-2.14.2-150400.24.35.1 * ovn-docker-20.06.2-150400.24.35.1 * ovn-central-20.06.2-150400.24.35.1 * ovn-devel-20.06.2-150400.24.35.1 * openvswitch-vtep-debuginfo-2.14.2-150400.24.35.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * openvswitch-devel-2.14.2-150400.24.35.1 * openvswitch-test-2.14.2-150400.24.35.1 * ovn-vtep-debuginfo-20.06.2-150400.24.35.1 * openvswitch-debuginfo-2.14.2-150400.24.35.1 * libopenvswitch-2_14-0-debuginfo-2.14.2-150400.24.35.1 * openvswitch-debugsource-2.14.2-150400.24.35.1 * ovn-host-20.06.2-150400.24.35.1 * libovn-20_06-0-debuginfo-20.06.2-150400.24.35.1 * ovn-debuginfo-20.06.2-150400.24.35.1 * libopenvswitch-2_14-0-2.14.2-150400.24.35.1 * ovn-host-debuginfo-20.06.2-150400.24.35.1 * ovn-central-debuginfo-20.06.2-150400.24.35.1 * openvswitch-2.14.2-150400.24.35.1 * openvswitch-test-debuginfo-2.14.2-150400.24.35.1 * openvswitch-pki-2.14.2-150400.24.35.1 * python3-ovs-2.14.2-150400.24.35.1 * libovn-20_06-0-20.06.2-150400.24.35.1 * ovn-20.06.2-150400.24.35.1 * openvswitch-ipsec-2.14.2-150400.24.35.1 * ovn-vtep-20.06.2-150400.24.35.1 * openvswitch-vtep-2.14.2-150400.24.35.1 * ovn-docker-20.06.2-150400.24.35.1 * ovn-central-20.06.2-150400.24.35.1 * ovn-devel-20.06.2-150400.24.35.1 * openvswitch-vtep-debuginfo-2.14.2-150400.24.35.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * openvswitch-devel-2.14.2-150400.24.35.1 * openvswitch-test-2.14.2-150400.24.35.1 * ovn-vtep-debuginfo-20.06.2-150400.24.35.1 * openvswitch-debuginfo-2.14.2-150400.24.35.1 * libopenvswitch-2_14-0-debuginfo-2.14.2-150400.24.35.1 * openvswitch-debugsource-2.14.2-150400.24.35.1 * ovn-host-20.06.2-150400.24.35.1 * libovn-20_06-0-debuginfo-20.06.2-150400.24.35.1 * ovn-debuginfo-20.06.2-150400.24.35.1 * libopenvswitch-2_14-0-2.14.2-150400.24.35.1 * ovn-host-debuginfo-20.06.2-150400.24.35.1 * openvswitch-2.14.2-150400.24.35.1 * ovn-central-debuginfo-20.06.2-150400.24.35.1 * openvswitch-test-debuginfo-2.14.2-150400.24.35.1 * openvswitch-pki-2.14.2-150400.24.35.1 * python3-ovs-2.14.2-150400.24.35.1 * libovn-20_06-0-20.06.2-150400.24.35.1 * ovn-20.06.2-150400.24.35.1 * openvswitch-ipsec-2.14.2-150400.24.35.1 * ovn-vtep-20.06.2-150400.24.35.1 * openvswitch-vtep-2.14.2-150400.24.35.1 * ovn-docker-20.06.2-150400.24.35.1 * ovn-central-20.06.2-150400.24.35.1 * ovn-devel-20.06.2-150400.24.35.1 * openvswitch-vtep-debuginfo-2.14.2-150400.24.35.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * openvswitch-devel-2.14.2-150400.24.35.1 *openvswitch-test-2.14.2-150400.24.35.1 * ovn-vtep-debuginfo-20.06.2-150400.24.35.1 * openvswitch-debuginfo-2.14.2-150400.24.35.1 * libopenvswitch-2_14-0-debuginfo-2.14.2-150400.24.35.1 * openvswitch-debugsource-2.14.2-150400.24.35.1 * ovn-host-20.06.2-150400.24.35.1 * libovn-20_06-0-debuginfo-20.06.2-150400.24.35.1 * ovn-debuginfo-20.06.2-150400.24.35.1 * libopenvswitch-2_14-0-2.14.2-150400.24.35.1 * ovn-host-debuginfo-20.06.2-150400.24.35.1 * openvswitch-2.14.2-150400.24.35.1 * ovn-central-debuginfo-20.06.2-150400.24.35.1 * openvswitch-test-debuginfo-2.14.2-150400.24.35.1 * openvswitch-pki-2.14.2-150400.24.35.1 * python3-ovs-2.14.2-150400.24.35.1 * libovn-20_06-0-20.06.2-150400.24.35.1 * ovn-20.06.2-150400.24.35.1 * openvswitch-ipsec-2.14.2-150400.24.35.1 * ovn-vtep-20.06.2-150400.24.35.1 * openvswitch-vtep-2.14.2-150400.24.35.1 * ovn-docker-20.06.2-150400.24.35.1 * ovn-central-20.06.2-150400.24.35.1 * ovn-devel-20.06.2-150400.24.35.1 * openvswitch-vtep-debuginfo-2.14.2-150400.24.35.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5265.html * https://www.suse.com/security/cve/CVE-2026-5367.html * https://bugzilla.suse.com/show_bug.cgi?id=1262498 * https://bugzilla.suse.com/show_bug.cgi?id=1262499 . Important security update for openvswitch on openSUSE addressing heap over-read issues. Install promptly.. openvswitch security patch, SUSE important update, heap over-read vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 22, 2026 Important SuSE
202

openSUSE Tinyproxy Moderate Security Issues Advisory 2026-11060-1

An update that solves 3 vulnerabilities can now be installed.. # tinyproxy-1.11.3-3.1 on GA media Announcement ID: openSUSE-SU-2026:11060-1 Rating: moderate Cross-References: * CVE-2026-54387 * CVE-2026-54388 * CVE-2026-55202 Affected Products: * openSUSE Tumbleweed An update that solves 3 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the tinyproxy-1.11.3-3.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * tinyproxy 1.11.3-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54387.html * https://www.suse.com/security/cve/CVE-2026-54388.html * https://www.suse.com/security/cve/CVE-2026-55202.html . An update for openSUSE Tumbleweed fixes three vulnerabilities in tinyproxy version 1.11.3-3.1, enhancing system security.. OpenSUSE, tinyproxy, security update, system vulnerabilities, networking. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 19, 2026 moderate OpenSUSE
202

openSUSE Tumbleweed flannel Moderate CVE-2026-44283 Advisory 2026-10980-1

An update that solves one vulnerability can now be installed.. # flannel-0.28.5-1.1 on GA media Announcement ID: openSUSE-SU-2026:10980-1 Rating: moderate Cross-References: * CVE-2026-44283 CVSS scores: * CVE-2026-44283 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44283 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the flannel-0.28.5-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * flannel 0.28.5-1.1 * flannel-k8s-yaml 0.28.5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44283.html . Update for openSUSE Tumbleweed resolves moderate vulnerability in flannel 0.28.5-1.1. Immediate installation recommended.. openSUSE Tumbleweed flannel update security patch moderate. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 11, 2026 moderate OpenSUSE
172

Ubuntu Linux Kernel Critical Escalation Issue USN-8390-1 CVE-2026-43284

The system could be made to run programs as an administrator.. ========================================================================== Ubuntu Security Notice USN-8390-1 June 04, 2026 linux, linux-azure, linux-azure-4.15, linux-azure-fips, linux-fips, linux-gcp-4.15, linux-gcp-fips, linux-kvm, linux-oracle vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 14.04 LTS Summary: The system could be made to run programs as an administrator. Software Description: - linux: Linux kernel - linux-azure-4.15: Linux kernel for Microsoft Azure Cloud systems - linux-azure-fips: Linux kernel for Microsoft Azure Cloud systems with FIPS - linux-fips: Linux kernel with FIPS - linux-gcp-4.15: Linux kernel for Google Cloud Platform (GCP) systems - linux-gcp-fips: Linux kernel for Google Cloud Platform (GCP) systems with FIPS - linux-kvm: Linux kernel for cloud environments - linux-oracle: Linux kernel for Oracle Cloud systems - linux-azure: Linux kernel for Microsoft Azure Cloud systems Details: It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could use this to escalate privileges, or possibly escape a container. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS linux-image-4.15.0-1148-fips 4.15.0-1148.160 Available with Ubuntu Pro linux-image-4.15.0-1155-oracle 4.15.0-1155.166 Available with Ubuntu Pro linux-image-4.15.0-1175-kvm 4.15.0-1175.180 Available with Ubuntu Pro linux-image-4.15.0-1186-gcp 4.15.0-1186.203 Available with Ubuntu Pro linux-image-4.15.0-1202-azure 4.15.0-1202.217 Available with Ubuntu Pro linux-image-4.15.0-2094-gcp-fips 4.15.0-2094.100 Available with Ubuntu Pro linux-image-4.15.0-2111-azure-fips 4.15.0-2111.117 Available with Ubuntu Pro linux-image-4.15.0-251-generic 4.15.0-251.263 Available with Ubuntu Pro linux-image-4.15.0-251-lowlatency 4.15.0-251.263 Available with Ubuntu Pro linux-image-azure-4.15 4.15.0.1202.170 Available with Ubuntu Pro linux-image-azure-fips 4.15.0.2111.107 Available with Ubuntu Pro linux-image-azure-fips-4.15 4.15.0.2111.107 Available with Ubuntu Pro linux-image-azure-lts-18.04 4.15.0.1202.170 Available with Ubuntu Pro linux-image-fips 4.15.0.1148.145 Available with Ubuntu Pro linux-image-gcp-4.15 4.15.0.1186.199 Available with Ubuntu Pro linux-image-gcp-fips 4.15.0.2094.92 Available with Ubuntu Pro linux-image-gcp-fips-4.15 4.15.0.2094.92 Available with Ubuntu Pro linux-image-gcp-lts-18.04 4.15.0.1186.199 Available with Ubuntu Pro linux-image-generic 4.15.0.251.235 Available with Ubuntu Pro linux-image-kvm 4.15.0.1175.166 Available with Ubuntu Pro linux-image-lowlatency 4.15.0.251.235 Available with Ubuntu Pro linux-image-oracle-4.15 4.15.0.1155.160 Available withUbuntu Pro linux-image-oracle-lts-18.04 4.15.0.1155.160 Available with Ubuntu Pro linux-image-virtual 4.15.0.251.235 Available with Ubuntu Pro Ubuntu 14.04 LTS linux-image-4.15.0-1202-azure 4.15.0-1202.217~14.04.1 Available with Ubuntu Pro linux-image-azure 4.15.0.1202.217~14.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8390-1 CVE-2026-43284 . Address critical privilege escalation in Ubuntu Linux kernel through timely updates. Security notice USN-8390-1 provides details.. Linux kernel update, Ubuntu security issues, privilege escalation fixes, critical security updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 04, 2026 Critical Ubuntu
172

Ubuntu 24.04 Linux Kernel High Copy Fail Escalation USN-8277-2

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-8277-2 May 22, 2026 linux-oracle-6.17 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-oracle-6.17: Linux kernel for Oracle Cloud systems Details: It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - S390 architecture; - Cryptographic API; - GPU drivers; - Ethernet bonding driver; - Network file system (NFS) server daemon; - Distributed Switch Architecture; - Netfilter; - Control group (cgroup); - Kernel kexec() syscall; - Memory management; - MAC80211 subsystem; - Multipath TCP; - Packet sockets; - TLS protocol; - Unix domain sockets; (CVE-2025-71088, CVE-2025-71090, CVE-2025-71127, CVE-2025-71134, CVE-2025-71139, CVE-2025-71141, CVE-2025-71142, CVE-2025-71144, CVE-2025-71152, CVE-2025-71155, CVE-2026-23274, CVE-2026-23351, CVE-2026-23394, CVE-2026-31419, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS linux-image-6.17.0-1014-oracle 6.17.0-1014.14~24.04.1 linux-image-6.17.0-1014-oracle-64k 6.17.0-1014.14~24.04.1 linux-image-oracle 6.17.0-1014.14~24.04.1 linux-image-oracle-6.17 6.17.0-1014.14~24.04.1 linux-image-oracle-64k 6.17.0-1014.14~24.04.1 linux-image-oracle-64k-6.17 6.17.0-1014.14~24.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8277-2 https://ubuntu.com/security/notices/USN-8277-1 CVE-2025-71088, CVE-2025-71090, CVE-2025-71127, CVE-2025-71134, CVE-2025-71139, CVE-2025-71141, CVE-2025-71142, CVE-2025-71144, CVE-2025-71152, CVE-2025-71155, CVE-2026-23274, CVE-2026-23351, CVE-2026-23394, CVE-2026-31419, CVE-2026-31431, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078 Package Information: https://launchpad.net/ubuntu/+source/linux-oracle-6.17/6.17.0-1014.14~24.04.1 . Several security issues were found in Ubuntu's Linux kernel, requiring immediate updates to maintain system integrity and security.. Ubuntu Security Notice, Linux Kernel, Privilege Escalation, Security Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 22, 2026 Important Ubuntu
202

openSUSE Leap 16.0 Mozilla Firefox Moderate Networking Memory Safety Issue

An update that solves 4 vulnerabilities and has one bug fix can now be installed.. openSUSE security update: security update for mozillafirefox ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20741-1 Rating: moderate References: * bsc#1264378 Cross-References: * CVE-2026-8090 * CVE-2026-8091 * CVE-2026-8092 * CVE-2026-8094 CVSS scores: * CVE-2026-8090 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8091 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8092 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8094 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 4 vulnerabilities and has one bug fix can now be installed. Description: This update for MozillaFirefox fixes the following issues Updated to Firefox Extended Support Release 140.10.2 ESR (bsc#1264378,MFSA 2026-41): - CVE-2026-8090: Use-after-free in the DOM: Networking component. - CVE-2026-8091: Incorrect boundary conditions in the Audio/Video: Playback component. - CVE-2026-8092: Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2. - CVE-2026-8094: Other issue in the WebRTC component. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-732=1 Package List: - openSUSE Leap 16.0: MozillaFirefox-140.10.2-160000.1.1 MozillaFirefox-branding-upstream-140.10.2-160000.1.1 MozillaFirefox-devel-140.10.2-160000.1.2 MozillaFirefox-translations-common-140.10.2-160000.1.1 MozillaFirefox-translations-other-140.10.2-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-8090.html *https://www.suse.com/security/cve/CVE-2026-8091.html * https://www.suse.com/security/cve/CVE-2026-8092.html * https://www.suse.com/security/cve/CVE-2026-8094.html . Update for openSUSE fixes Mozilla Firefox issues and addresses four vulnerabilities with moderate severity recommendations.. openSUSE MozillaFirefox Update, MozillaFirefox Security, Firefox Vulnerabilities, OpenSUSE Vulnerabilities, Mozilla Security Advisory. . LinuxSecurity.com Team

Calendar%202 May 19, 2026 OpenSUSE
100

SUSE MozillaFirefox Important Update for Multiple Threats 2026-1830-1

An update that solves eight vulnerabilities can now be installed.. # Security update for MozillaFirefox Announcement ID: SUSE-SU-2026:1830-1 Release Date: 2026-05-12T12:00:51Z Rating: important References: * bsc#1263110 * bsc#1264378 Cross-References: * CVE-2026-7320 * CVE-2026-7321 * CVE-2026-7322 * CVE-2026-7323 * CVE-2026-8090 * CVE-2026-8091 * CVE-2026-8092 * CVE-2026-8094 CVSS scores: * CVE-2026-7320 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-7321 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-7322 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-7323 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-8090 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8090 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-8091 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8091 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-8092 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8092 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-8094 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8094 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issues Updated to Firefox Extended Support Release 140.10.2 ESR (bsc#1264378,MFSA 2026-41): * CVE-2026-8090: Use-after-free in the DOM: Networking component. * CVE-2026-8092: Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2. * CVE-2026-8094: Other issue in the WebRTC component. Updated to Firefox Extended Support Release 140.10.1 ESR (bsc#1263110,MFSA 2026-36): * CVE-2026-7320: Information disclosure due to incorrect boundary conditions in the Audio/Video component. * CVE-2026-7321: Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. * CVE-2026-7322: Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. * CVE-2026-7323: Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1. * CVE-2026-8091: Incorrect boundary conditions in the Audio/Video: Playback component. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-1830=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-1830=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-140.10.2-112.313.1 * MozillaFirefox-debugsource-140.10.2-112.313.1 * MozillaFirefox-translations-common-140.10.2-112.313.1 * MozillaFirefox-debuginfo-140.10.2-112.313.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * MozillaFirefox-devel-140.10.2-112.313.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * MozillaFirefox-140.10.2-112.313.1 * MozillaFirefox-debugsource-140.10.2-112.313.1 * MozillaFirefox-translations-common-140.10.2-112.313.1 * MozillaFirefox-debuginfo-140.10.2-112.313.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * MozillaFirefox-devel-140.10.2-112.313.1 ## References: * https://www.suse.com/security/cve/CVE-2026-7320.html *https://www.suse.com/security/cve/CVE-2026-7321.html * https://www.suse.com/security/cve/CVE-2026-7322.html * https://www.suse.com/security/cve/CVE-2026-7323.html * https://www.suse.com/security/cve/CVE-2026-8090.html * https://www.suse.com/security/cve/CVE-2026-8091.html * https://www.suse.com/security/cve/CVE-2026-8092.html * https://www.suse.com/security/cve/CVE-2026-8094.html * https://bugzilla.suse.com/show_bug.cgi?id=1263110 * https://bugzilla.suse.com/show_bug.cgi?id=1264378 . Important update for MozillaFirefox resolves multiple issues with significant security implications. Upgrade recommended.. MozillaFirefox Update, SUSE Security Patch, CVSS Important, Security Advisory Notification. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 13, 2026 Important SuSE
203

Mageia 9 Firefox Important Networking Privilege Escalation MGASA-2026-0124

MGASA-2026-0124 - Updated rootcerts, nss & firefox packages fix security vulnerabilities. MGASA-2026-0124 - Updated rootcerts, nss & firefox packages fix security vulnerabilities Publication date: 09 May 2026 URL: https://advisories.mageia.org/MGASA-2026-0124.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-6746, CVE-2026-6747, CVE-2026-6748, CVE-2026-6749, CVE-2026-6750, CVE-2026-6751, CVE-2026-6752, CVE-2026-6753, CVE-2026-6754, CVE-2026-6757, CVE-2026-6759, CVE-2026-6761, CVE-2026-6762, CVE-2026-6763, CVE-2026-6764, CVE-2026-6765, CVE-2026-6766 Description: Use-after-free in the DOM: Core & HTML component. (CVE-2026-6746) Use-after-free in the WebRTC component. (CVE-2026-6747) Uninitialized memory in the Audio/Video: Web Codecs component. (CVE-2026-6748) Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. (CVE-2026-6749) Privilege escalation in the Graphics: WebRender component. (CVE-2026-6750) Uninitialized memory in the Audio/Video: Web Codecs component. (CVE-2026-6751) Incorrect boundary conditions in the WebRTC component. (CVE-2026-6752) Incorrect boundary conditions in the WebRTC component. (CVE-2026-6753) Use-after-free in the JavaScript Engine component. (CVE-2026-6754) Invalid pointer in the JavaScript: WebAssembly component. (CVE-2026-6757) Use-after-free in the Widget: Cocoa component. (CVE-2026-6759) Privilege escalation in the Networking component. (CVE-2026-6761) Spoofing issue in the DOM: Core & HTML component. (CVE-2026-6762) Mitigation bypass in the File Handling component. (CVE-2026-6763) Incorrect boundary conditions in the DOM: Device Interfaces component. (CVE-2026-6764) Information disclosure in the Form Autofill component. (CVE-2026-6765) Incorrect boundary conditions in the Libraries component in NSS. (CVE-2026-6766) Other issue in the Libraries component in NSS. (CVE-2026-6767) Privilege escalation in the Debugger component. (CVE-2026-6769) Other issue inthe Storage: IndexedDB component. (CVE-2026-6770) Mitigation bypass in the DOM: Security component. (CVE-2026-6771) Incorrect boundary conditions in the Libraries component in NSS. (CVE-2026-6772) Incorrect boundary conditions in the WebRTC: Networking component. (CVE-2026-6776) Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150. (CVE-2026-6785) Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150. (CVE-2026-6786) Information disclosure due to incorrect boundary conditions in the Audio/Video component. (CVE-2026-7320) Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. (CVE-2026-7321) Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. (CVE-2026-7322) Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1. (CVE-2026-7323) References: - https://bugs.mageia.org/show_bug.cgi?id=35403 - https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_123.html - https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_123_1.html - https://www.firefox.com/en-US/firefox/140.10.0/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa2026-32/ - https://www.firefox.com/en-US/firefox/140.10.1/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa2026-36/ - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6746 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6747 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6748 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6749 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6750 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6751 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6752 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6753 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6754 -https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6757 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6759 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6761 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6762 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6763 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6764 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6765 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6766 SRPMS: - 9/core/rootcerts-20260412.00-1.mga9 - 9/core/nss-3.123.1-1.mga9 - 9/core/firefox-140.10.1-1.mga9 - 9/core/firefox-l10n-140.10.1-1.mga9 . Updated rootcerts and Firefox packages in Mageia address multiple security concerns with varying severity levels.. Mageia Security Advisory, Firefox Updates, Rootcerts Vulnerability, Networking Issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 09, 2026 Important Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200