Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
172

Ubuntu 26.04 LTS ngtcp2 High Remote Code Execution Vuln USN-8300-1

ngtcp2 could be made to run programs as your login if it received specially crafted network traffic when qlog was enabled.. ========================================================================== Ubuntu Security Notice USN-8300-1 May 25, 2026 ngtcp2 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: ngtcp2 could be made to run programs as your login if it received specially crafted network traffic when qlog was enabled. Software Description: - ngtcp2: RFC9000 QUIC protocol implementation Details: Zou Dikai discovered that ngtcp2 serialized peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog was enabled, a remote attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libngtcp2-16 1.16.0-1ubuntu0.1 libngtcp2-crypto-gnutls-dev 1.16.0-1ubuntu0.1 libngtcp2-crypto-gnutls8 1.16.0-1ubuntu0.1 libngtcp2-crypto-ossl-dev 1.16.0-1ubuntu0.1 libngtcp2-crypto-ossl0 1.16.0-1ubuntu0.1 libngtcp2-dev 1.16.0-1ubuntu0.1 Ubuntu 25.10 libngtcp2-16 1.11.0-1+deb13u1build0.25.10.1 libngtcp2-crypto-gnutls-dev 1.11.0-1+deb13u1build0.25.10.1 libngtcp2-crypto-gnutls8 1.11.0-1+deb13u1build0.25.10.1 libngtcp2-dev 1.11.0-1+deb13u1build0.25.10.1 ngtcp2-client 1.11.0-1+deb13u1build0.25.10.1 ngtcp2-server 1.11.0-1+deb13u1build0.25.10.1 Ubuntu 24.04 LTS libngtcp2-9 0.12.1+dfsg-1+deb12u1build0.24.04.1 libngtcp2-crypto-gnutls-dev 0.12.1+dfsg-1+deb12u1build0.24.04.1 libngtcp2-crypto-gnutls2 0.12.1+dfsg-1+deb12u1build0.24.04.1 libngtcp2-dev 0.12.1+dfsg-1+deb12u1build0.24.04.1 ngtcp2-client 0.12.1+dfsg-1+deb12u1build0.24.04.1 ngtcp2-server 0.12.1+dfsg-1+deb12u1build0.24.04.1 Ubuntu 22.04 LTS libngtcp2-0 0.1.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro libngtcp2-crypto-gnutls-dev 0.1.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro libngtcp2-crypto-gnutls0 0.1.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro libngtcp2-dev 0.1.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro ngtcp2-client 0.1.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro ngtcp2-server 0.1.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8300-1 CVE-2026-40170 Package Information: https://launchpad.net/ubuntu/+source/ngtcp2/1.16.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/ngtcp2/1.11.0-1+deb13u1build0.25.10.1 https://launchpad.net/ubuntu/+source/ngtcp2/0.12.1+dfsg-1+deb12u1build0.24.04.1 . ngtcp2 could run programs as your login through specially crafted traffic when qlog enabled in Ubuntu releases.. ngtcp2 security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 25, 2026 Critical Ubuntu
89

Fedora 44 ngtcp2 Critical Denial of Service Fix CVE-2026-40170

Update to 1.22.1 (rhbz#2452790) Fixes CVE-2026-40170. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-705eb9cf95 2026-04-28 01:29:45.334770+00:00 -------------------------------------------------------------------------------- Name : ngtcp2 Product : Fedora 44 Version : 1.22.1 Release : 1.fc44 URL : https://github.com/ngtcp2/ngtcp2 Summary : Implementation of RFC 9000 QUIC protocol Description : "Call it TCP/2. One More Time." ngtcp2 project is an effort to implement RFC9000 QUIC protocol. -------------------------------------------------------------------------------- Update Information: Update to 1.22.1 (rhbz#2452790) Fixes CVE-2026-40170 -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 20 2026 Petr Men\u0161k - 1.22.1-1 - Update to 1.22.1 (rhbz#2452790) - Fixes CVE-2026-40170 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452790 - ngtcp2-1.22.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2452790 [ 2 ] Bug #2459283 - CVE-2026-40170 ngtcp2: ngtcp2: Denial of service via stack buffer overflow during QUIC handshake [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2459283 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-705eb9cf95' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 44 ngtcp2 1.22.1 update fixes CVE-2026-40170 critical buffer overflow issue..ngtcp2 buffer overflow update Fedora critical. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 28, 2026 Critical Fedora
89

Fedora 43 ngtcp2 1.22.1 Critical DoS Fix CVE-2026-40170 Advisory

Update to 1.22.1 (rhbz#2452790) Fixes CVE-2026-40170. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a0f25484e9 2026-04-28 00:55:52.209310+00:00 -------------------------------------------------------------------------------- Name : ngtcp2 Product : Fedora 43 Version : 1.22.1 Release : 1.fc43 URL : https://github.com/ngtcp2/ngtcp2 Summary : Implementation of RFC 9000 QUIC protocol Description : "Call it TCP/2. One More Time." ngtcp2 project is an effort to implement RFC9000 QUIC protocol. -------------------------------------------------------------------------------- Update Information: Update to 1.22.1 (rhbz#2452790) Fixes CVE-2026-40170 -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 20 2026 Petr Men\u0161k - 1.22.1-1 - Update to 1.22.1 (rhbz#2452790) - Fixes CVE-2026-40170 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452790 - ngtcp2-1.22.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2452790 [ 2 ] Bug #2459283 - CVE-2026-40170 ngtcp2: ngtcp2: Denial of service via stack buffer overflow during QUIC handshake [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2459283 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a0f25484e9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 43 updates ngtcp2 to 1.22.1 addressing critical buffer overflow issue in QUIChandshake.. Fedora 43,nqtcp2 update,CVE-2026-40170,buffer overflow. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 28, 2026 Critical Fedora
87

Debian DSA-6222-1 ngtcp2 Important Buffer Overflow CVE-2026-40170

Zou Dikai discovered a buffer overflow in ngtcp2, a QUIC protocol library. For the oldstable distribution (bookworm), this problem has been fixed in version 0.12.1+dfsg-1+deb12u1. For the stable distribution (trixie), this problem has been fixed in version 1.11.0-1+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6222-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 21, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ngtcp2 CVE ID : CVE-2026-40170 Zou Dikai discovered a buffer overflow in ngtcp2, a QUIC protocol library. For the oldstable distribution (bookworm), this problem has been fixed in version 0.12.1+dfsg-1+deb12u1. For the stable distribution (trixie), this problem has been fixed in version 1.11.0-1+deb13u1. We recommend that you upgrade your ngtcp2 packages. For the detailed security status of ngtcp2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ngtcp2 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical buffer overflow in ngtcp2 library patched in recent Debian updates for oldstable and stable releases.. Debian Advisory, ngtcp2 Security, QUIC Library Fix, Buffer Overflow Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 21, 2026 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200