Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 598
Alerts This Week
Warning Icon 1 598

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 448 articles for you...
197

Debian 11 OpenJDK Important Denial of Service Risks DLA-4566-1

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect generation of cryptographic keys, denial of service, information disclosure, XEE/XEE attacks or incorrect validation of Kerberos credentials. For Debian 11 bullseye, these problems have been fixed in version. Debian LTS Advisory DLA-4566-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort May 06, 2026 https://wiki.debian.org/LTS Package : openjdk-11 Version : 11.0.31+11-1~deb11u1 CVE ID : CVE-2026-22007 CVE-2026-22013 CVE-2026-22016 CVE-2026-22018 CVE-2026-22021 CVE-2026-34268 CVE-2026-34282 Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect generation of cryptographic keys, denial of service, information disclosure, XEE/XEE attacks or incorrect validation of Kerberos credentials. For Debian 11 bullseye, these problems have been fixed in version 11.0.31+11-1~deb11u1. We recommend that you upgrade your openjdk-11 packages. For the detailed security status of openjdk-11 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/openjdk-11 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Learn about the latest security advisory for OpenJDK 11 in Debian, addressing critical vulnerabilities found and fixes implemented.. Debian OpenJDK security update, Java runtime vulnerabilities, OpenJDK security fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 06, 2026 Important Debian LTS
197

Debian 11 OpenJDK-17 Denial Of Service Info Disclosure DLA-4565-1

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect generation of cryptographic keys, denial of service, information disclosure, XEE/XEE attacks or incorrect validation of Kerberos credentials. For Debian 11 bullseye, these problems have been fixed in version. Debian LTS Advisory DLA-4565-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort May 06, 2026 https://wiki.debian.org/LTS Package : openjdk-17 Version : 17.0.19+10-1~deb11u1 CVE ID : CVE-2026-22007 CVE-2026-22013 CVE-2026-22016 CVE-2026-22018 CVE-2026-22021 CVE-2026-34268 CVE-2026-34282 Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect generation of cryptographic keys, denial of service, information disclosure, XEE/XEE attacks or incorrect validation of Kerberos credentials. For Debian 11 bullseye, these problems have been fixed in version 17.0.19+10-1~deb11u1. We recommend that you upgrade your openjdk-17 packages. For the detailed security status of openjdk-17 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/openjdk-17 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Recent Debian LTS advisory details fixes for multiple OpenJDK 17 vulnerabilities that could lead to severe security issues.. openjdk security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 06, 2026 Important Debian LTS
87

Debian DSA-6246-1 OpenJDK Critical Info Disclosure Denial of Service

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect generation of cryptographic keys, denial of service, information disclosure, XEE/XEE attacks or incorrect validation of Kerberos credentials. For the stable distribution (trixie), these problems have been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6246-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff May 03, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openjdk-25 CVE ID : CVE-2026-22007 CVE-2026-22008 CVE-2026-22013 CVE-2026-22016 CVE-2026-22018 CVE-2026-22021 CVE-2026-34268 CVE-2026-34282 Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect generation of cryptographic keys, denial of service, information disclosure, XEE/XEE attacks or incorrect validation of Kerberos credentials. For the stable distribution (trixie), these problems have been fixed in version 25.0.3+9-2~deb13u1. We recommend that you upgrade your openjdk-25 packages. For the detailed security status of openjdk-25 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/openjdk-25 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Debian DSA-6246-1 advisory details critical vulnerabilities in OpenJDK impacting cryptography and information security.. Debian security advisory, OpenJDK vulnerabilities, Java runtime issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 03, 2026 Critical Debian
87

Debian OpenJDK 17 Critical Cryptographic Failures Advisory DSA-6237-1

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect generation of cryptographic keys, denial of service, information disclosure, XEE/XEE attacks or incorrect validation of Kerberos credentials. For the oldstable distribution (bookworm), these problems have been fixed. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6237-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 29, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openjdk-17 CVE ID : CVE-2026-22007 CVE-2026-22013 CVE-2026-22016 CVE-2026-22018 CVE-2026-22021 CVE-2026-34268 CVE-2026-34282 Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect generation of cryptographic keys, denial of service, information disclosure, XEE/XEE attacks or incorrect validation of Kerberos credentials. For the oldstable distribution (bookworm), these problems have been fixed in version 17.0.19+10-1~deb12u2. We recommend that you upgrade your openjdk-17 packages. For the detailed security status of openjdk-17 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/openjdk-17 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Several security issues in OpenJDK 17 fixed in Debian DSA-6237-1 related to cryptographic failures and DoS.. OpenJDK 17, Debian security advisory, cryptographic vulnerabilities, information disclosure, software update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 29, 2026 Critical Debian
87

Debian OpenJDK DSA-6231-1 Important Crypto Key Issues CVE-2026-22007

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect generation of cryptographic keys, denial of service, information disclosure, XEE/XEE attacks or incorrect validation of Kerberos credentials. For the stable distribution (trixie), these problems have been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6231-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 27, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openjdk-21 CVE ID : CVE-2026-22007 CVE-2026-22013 CVE-2026-22016 CVE-2026-22018 CVE-2026-22021 CVE-2026-34268 CVE-2026-34282 Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect generation of cryptographic keys, denial of service, information disclosure, XEE/XEE attacks or incorrect validation of Kerberos credentials. For the stable distribution (trixie), these problems have been fixed in version 21.0.11+10-1~deb13u2. We recommend that you upgrade your openjdk-21 packages. For the detailed security status of openjdk-21 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/openjdk-21 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . OpenJDK Java runtime has multiple security issues fixed in Debian DSA-6231-1. Ensure you upgrade openjdk-21 now.. OpenJDK, Java, Debian, security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 27, 2026 Important Debian
89

Fedora 42 java-25-openjdk Critical Update FEDORA-2026-1ad57632f2

January 2026 annual updates January 2026 security update. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-1ad57632f2 2026-02-10 01:08:32.523381+00:00 -------------------------------------------------------------------------------- Name : java-25-openjdk Product : Fedora 42 Version : 25.0.2.0.10 Release : 2.fc42 URL : https://openjdk.org/ Summary : OpenJDK 25 Runtime Environment Description : The OpenJDK 25 runtime environment. -------------------------------------------------------------------------------- Update Information: January 2026 annual updates January 2026 security update -------------------------------------------------------------------------------- ChangeLog: * Tue Jan 27 2026 Jiri Vanek - 1:25.0.2.0.10-3 - RPMAUTOSPEC: unresolvable merge -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1ad57632f2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it:https://forge.fedoraproject.org/infra/tickets/issues/new . January 2026 security update for java-25-openjdk on Fedora 42 with critical updates required.. Fedora 42, java-25-openjdk, security update, openjdk, critical fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 10, 2026 Critical Fedora
87

Debian Trixie OpenJDK Important Man-in-the-Middle Attacks DSA-6119-1

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect certificate validation, CRLF injection or man-in-the-middle attacks. For the stable distribution (trixie), these problems have been fixed in version 25.0.2+10-1~deb13u2. This version of OpenJDK now also requires. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6119-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff February 05, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openjdk-25 CVE ID : CVE-2026-21925 CVE-2026-21932 CVE-2026-21933 CVE-2026-21945 Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect certificate validation, CRLF injection or man-in-the-middle attacks. For the stable distribution (trixie), these problems have been fixed in version 25.0.2+10-1~deb13u2. This version of OpenJDK now also requires jtreg8 for running the testsuite, which has been backported into trixie as 8.1+1+ds1-1~deb13u1. We recommend that you upgrade your openjdk-25 packages. For the detailed security status of openjdk-25 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/openjdk-25 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . OpenJDK updates fix major issues, enhancing protection against attacks like CRLF injection in Debian's trixie distribution.. OpenJDK updates, Debian trixie, Java runtime vulnerabilities, man-in-the-middle attacks. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 05, 2026 Important Debian
172

Ubuntu 25.10 OpenJDK 17 Critical Risk RCE DoS USN-7998-1

Several security issues were fixed in OpenJDK 17.. ========================================================================== Ubuntu Security Notice USN-7998-1 February 03, 2026 openjdk-17 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in OpenJDK 17. Software Description: - openjdk-17: Open Source Java implementation Details: It was discovered that the RMI component of OpenJDK 17 would establish RMI TCP endpoint connections to a remote host without setting an endpoint identification algorithm. An unauthenticated remote attacker could possibly use this issue to steal sensitive information. (CVE-2026-21925) Mingijung discovered that the AWT and JavaFX componenets of OpenJDK 17 could run programs if Desktop.browse() was supplied a filename as a URI. An unauthenticated remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-21932) Zhihui Chen discovered that the Networking component of OpenJDK 17 was suceptible to a CRLF injection vulnerability via the HttpServer class. An unauthenticated remote attacker could possibly use this issue to modify files or leak sensitive information. (CVE-2026-21933) Ireneusz Pastusiak discovered that the Security component of OpenJDK 17 failed to verify provided URIs point to a legitimate source when AIA is enabled. An unauthenticated remote attacker could possibly use this issue to redirect users to malicious hosts. (CVE-2026-21945) In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://openjdk.org/groups/vulnerability/advisories/2026-01-20 Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 openjdk-17-jdk 17.0.18+8-1~25.10.1 openjdk-17-jdk-headless 17.0.18+8-1~25.10.1 openjdk-17-jre 17.0.18+8-1~25.10.1 openjdk-17-jre-headless 17.0.18+8-1~25.10.1 openjdk-17-jre-zero 17.0.18+8-1~25.10.1 Ubuntu 24.04 LTS openjdk-17-jdk 17.0.18+8-1~24.04.1 openjdk-17-jdk-headless 17.0.18+8-1~24.04.1 openjdk-17-jre 17.0.18+8-1~24.04.1 openjdk-17-jre-headless 17.0.18+8-1~24.04.1 openjdk-17-jre-zero 17.0.18+8-1~24.04.1 Ubuntu 22.04 LTS openjdk-17-jdk 17.0.18+8-1~22.04.1 openjdk-17-jdk-headless 17.0.18+8-1~22.04.1 openjdk-17-jre 17.0.18+8-1~22.04.1 openjdk-17-jre-headless 17.0.18+8-1~22.04.1 openjdk-17-jre-zero 17.0.18+8-1~22.04.1 Ubuntu 20.04 LTS openjdk-17-jdk 17.0.18+8-1~20.04 Available with Ubuntu Pro openjdk-17-jdk-headless 17.0.18+8-1~20.04 Available with Ubuntu Pro openjdk-17-jre 17.0.18+8-1~20.04 Available with Ubuntu Pro openjdk-17-jre-headless 17.0.18+8-1~20.04 Available with Ubuntu Pro openjdk-17-jre-zero 17.0.18+8-1~20.04 Available with Ubuntu Pro Ubuntu 18.04 LTS openjdk-17-jdk 17.0.18+8-1~18.04 Available with Ubuntu Pro openjdk-17-jdk-headless 17.0.18+8-1~18.04 Available with Ubuntu Pro openjdk-17-jre 17.0.18+8-1~18.04 Available with Ubuntu Pro openjdk-17-jre-headless 17.0.18+8-1~18.04 Available with Ubuntu Pro openjdk-17-jre-zero 17.0.18+8-1~18.04 Available with Ubuntu Pro This update uses a new upstream release, which includesadditional bug fixes. After a standard system update you need to restart Java applications to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7998-1 CVE-2026-21925, CVE-2026-21932, CVE-2026-21933, CVE-2026-21945 Package Information: https://launchpad.net/ubuntu/+source/openjdk-17/17.0.18+8-1~25.10.1 https://launchpad.net/ubuntu/+source/openjdk-17/17.0.18+8-1~24.04.1 . Several security issues fixed in OpenJDK 17 could permit remote code execution and information exposure in Ubuntu updates.. OpenJDK 17 security advisory, Ubuntu security update, remote code execution, information disclosure. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 03, 2026 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200