Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 6 articles for you...
87

Debian Oldstable php-twig Vulnerabilities for PHP Code Injection DSA-6320-1

Multiple security vulnerabilities were discovered in Twig, a template engine for PHP, which could result in PHP code injection, sandbox bypass or cross-site scripting. For the oldstable distribution (bookworm), these problems have been fixed in version 3.5.1-1+deb12u3.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6320-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff June 02, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : php-twig CVE ID : CVE-2024-51754 CVE-2026-46628 CVE-2026-46629 CVE-2026-46637 CVE-2026-47730 CVE-2026-46633 Multiple security vulnerabilities were discovered in Twig, a template engine for PHP, which could result in PHP code injection, sandbox bypass or cross-site scripting. For the oldstable distribution (bookworm), these problems have been fixed in version 3.5.1-1+deb12u3. We recommend that you upgrade your php-twig packages. For the detailed security status of php-twig please refer to its security tracker page at: https://security-tracker.debian.org/tracker/php-twig Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Multiple vulnerabilities in php-twig template engine could lead to code injection and cross-site attacks. Upgrade recommended.. Debian Security Advisory, PHP Template Engine, Twig Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 02, 2026 Critical Debian
87

Debian Bookworm PackageKit Local Privilege Escalation Advisory DSA-6226-1

Maik Schaefer discovered that a TOCTOU race condition in PackageKit (a package management service over a DBus interface) could result in local privilege escalation. For the oldstable distribution (bookworm), this problem has been fixed in version 1.2.6-5+deb12u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6226-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 22, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : packagekit CVE ID : not yet available Maik Schaefer discovered that a TOCTOU race condition in PackageKit (a package management service over a DBus interface) could result in local privilege escalation. For the oldstable distribution (bookworm), this problem has been fixed in version 1.2.6-5+deb12u1. For the stable distribution (trixie), this problem has been fixed in version 1.3.1-1+deb13u1. We recommend that you upgrade your packagekit packages. For the detailed security status of packagekit please refer to its security tracker page at: https://security-tracker.debian.org/tracker/packagekit Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . PackageKit faces a critical local privilege escalation issue; update recommended to maintain Debian system security and integrity.. PackageKit Update, Debian Security, Local Privilege Escalation, Security Advisory, Debian Bookworm. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 22, 2026 Important Debian
87

Debian DSA-6208-1 MediaWiki High Info Disclosure and Permission Issues

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure or incomplete permission checks. For the oldstable distribution (bookworm), these problems have been fixed in version 1:1.39.17-1+deb12u2.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6208-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 12, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mediawiki CVE ID : CVE-2026-34086 CVE-2026-34087 CVE-2026-34088 CVE-2026-34091 CVE-2026-34092 CVE-2026-34093 CVE-2026-34094 CVE-2026-34095 CVE-2026-5266 Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure or incomplete permission checks. For the oldstable distribution (bookworm), these problems have been fixed in version 1:1.39.17-1+deb12u2. For the stable distribution (trixie), these problems have been fixed in version 1:1.43.8+dfsg-1~deb13u1. We recommend that you upgrade your mediawiki packages. For the detailed security status of mediawiki please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/mediawiki Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Advisory DSA-6208-1 addresses multiple MediaWiki security issues leading to information exposure. Upgrade now.. Debian Advisory, MediaWiki Security, Information Disclosure, Permission Checks. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 12, 2026 Important Debian
87

Debian Bookworm Freeciv Critical DoS Issue DSA-6173-1 CVE-2026-33250

Louis Moureaux discovered that incorrect packet processing in the game server of Freeciv, a free clone of the turn based strategy game Civilization, could result in denial of service. For the oldstable distribution (bookworm), this problem has been fixed in version 3.0.6-1+deb12u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6173-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff March 21, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : freeciv CVE ID : CVE-2026-33250 Louis Moureaux discovered that incorrect packet processing in the game server of Freeciv, a free clone of the turn based strategy game Civilization, could result in denial of service. For the oldstable distribution (bookworm), this problem has been fixed in version 3.0.6-1+deb12u1. For the stable distribution (trixie), this problem has been fixed in version 3.1.4+ds-2+deb13u1. We recommend that you upgrade your freeciv packages. For the detailed security status of freeciv please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/freeciv Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Louis Moureaux found a packet processing issue in Freeciv causing denial of service for Debian users. Upgrade advised.. Freeciv Denial of Service, Debian Security Issue, Freeciv Version Upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 21, 2026 Critical Debian
87

Debian Bookworm DSA-6149-1 NSS Critical Integer Overflow CVE-2026-2781

Clay Ver Valen discovered an integer overflow in the AES-GCM implementation of the Mozilla Network Security Service libraries. For the oldstable distribution (bookworm), this problem has been fixed in version 2:3.87.1-1+deb12u2. For the stable distribution (trixie), this problem has been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6149-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff February 26, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : nss CVE ID : CVE-2026-2781 Clay Ver Valen discovered an integer overflow in the AES-GCM implementation of the Mozilla Network Security Service libraries. For the oldstable distribution (bookworm), this problem has been fixed in version 2:3.87.1-1+deb12u2. For the stable distribution (trixie), this problem has been fixed in version 2:3.110-1+deb13u1. We recommend that you upgrade your nss packages. For the detailed security status of nss please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/nss Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Integer overflow fix in NSS for Debian oldstable and stable distributions. Upgrade now to protect your system.. Debian, NSS, security advisory, integer overflow, upgrades. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 26, 2026 Critical Debian
87

Debian Oldstable BIND9 Critical Denial of Service DSA-6107-1 CVE-2025-13878

Vlatko Kosturjak discovered that BIND, a DNS server implementation, does not properly handle malformed BRID/HHIT records, which may result in denial of service (named daemon crash). For the oldstable distribution (bookworm), this problem has been fixed in version 1:9.18.44-1~deb12u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6107-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso January 22, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : bind9 CVE ID : CVE-2025-13878 Vlatko Kosturjak discovered that BIND, a DNS server implementation, does not properly handle malformed BRID/HHIT records, which may result in denial of service (named daemon crash). For the oldstable distribution (bookworm), this problem has been fixed in version 1:9.18.44-1~deb12u1. For the stable distribution (trixie), this problem has been fixed in version 1:9.20.18-1~deb13u1. We recommend that you upgrade your bind9 packages. For the detailed security status of bind9 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/bind9 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . BIND DNS Server faces denial of service risk from malformed records. Upgrade to latest version for safety.. DNS Server Security, Debian Bind9, Denial of Service Risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 22, 2026 Important Debian
87

Debian: Request Tracker4 Critical CSV Injection DSA-6032-1 CVE-2025-61873

It was discovered that Request Tracker, an extensible trouble-ticket tracking system is prone to a CSV injection via ticket values with special characters that are exported to a TSV from search results. For the oldstable distribution (bookworm), this problem has been fixed in version 4.4.6+dfsg-1.1+deb12u3.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6032-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso October 22, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : request-tracker4 CVE ID : CVE-2025-61873 It was discovered that Request Tracker, an extensible trouble-ticket tracking system is prone to a CSV injection via ticket values with special characters that are exported to a TSV from search results. For the oldstable distribution (bookworm), this problem has been fixed in version 4.4.6+dfsg-1.1+deb12u3. We recommend that you upgrade your request-tracker4 packages. For the detailed security status of request-tracker4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/request-tracker4 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Request Tracker faces a CSV injection issue; Debian has issued a security advisory DSA-6032-1 to address this critical flaw. Upgrade now!. Debian Security Advisory, Request Tracker, CSV Injection. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 22, 2025 Critical Debian
87

Debian: DSA-5707-1 Moderate: Correction for VLC Buffer Overflow Issue

A buffer overflow was discovered in the MMS module of the VLC media player. For the oldstable distribution (bullseye), this problem has been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5707-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff June 11, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : vlc CVE ID : not yet available A buffer overflow was discovered in the MMS module of the VLC media player. For the oldstable distribution (bullseye), this problem has been fixed in version 3.0.21-0+deb11u1. For the stable distribution (bookworm), this problem has been fixed in version 3.0.21-0+deb12u1. We recommend that you upgrade your vlc packages. For the detailed security status of vlc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/vlc Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance VLC media player to mitigate buffer overflow vulnerabilities as outlined in the Debian DSA-5707-1 security bulletin.. Debian Security Updates, Media Player Vulnerabilities, Buffer Overflow Fixes. . LinuxSecurity.com Team

Calendar%202 Jun 11, 2024 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200