Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
100

SUSE Perl-Config-IniFiles Important OS Command Injection Vuln 2026-22329-1

An update that solves one vulnerability can now be installed.. # Security update for perl-Config-IniFiles Announcement ID: SUSE-SU-2026:22329-1 Release Date: 2026-06-22T14:30:38Z Rating: important References: * bsc#1268236 Cross-References: * CVE-2026-11527 CVSS scores: * CVE-2026-11527 ( SUSE ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-11527 ( NVD ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for perl-Config-IniFiles fixes the following issue * CVE-2026-11527: OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle (bsc#1268236). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1024=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1024=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * perl-Config-IniFiles-3.000003-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * perl-Config-IniFiles-3.000003-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11527.html * https://bugzilla.suse.com/show_bug.cgi?id=1268236 . This advisory covers a critical OS command injection and file overwrite in SUSE's perl-Config-IniFiles requiring urgent action.. SUSE Advisory, Perl Configuration, OS Command Injection, File Overwrite, Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 01, 2026 Important SuSE
100

SUSE Perl-Config-IniFiles Important OS Command Injection Fix 2026-2710-1

An update that solves one vulnerability can now be installed.. # Security update for perl-Config-IniFiles Announcement ID: SUSE-SU-2026:2710-1 Release Date: 2026-06-30T10:57:22Z Rating: important References: * bsc#1268236 Cross-References: * CVE-2026-11527 CVSS scores: * CVE-2026-11527 ( SUSE ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-11527 ( NVD ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for perl-Config-IniFiles fixes the following issue * CVE-2026-11527: OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle (bsc#1268236). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2710=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2710=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2710=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2710=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2710=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2710=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2710=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2710=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2710=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2710=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2710=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * perl-Config-IniFiles-2.94-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * perl-Config-IniFiles-2.94-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * perl-Config-IniFiles-2.94-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * perl-Config-IniFiles-2.94-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * perl-Config-IniFiles-2.94-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15SP5 (noarch) * perl-Config-IniFiles-2.94-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * perl-Config-IniFiles-2.94-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * perl-Config-IniFiles-2.94-150000.3.3.1 * Development Tools Module 15-SP7 (noarch) * perl-Config-IniFiles-2.94-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * perl-Config-IniFiles-2.94-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * perl-Config-IniFiles-2.94-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11527.html * https://bugzilla.suse.com/show_bug.cgi?id=1268236 . Security update for perl-Config-IniFiles addresses an important security flaw involving OS command injection in SUSE distributions.. perl Config IniFiles security update, SUSE Linux patch, Important security vulnerabilities, OS command injection mitigation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 Important SuSE
202

openSUSE perl-Config-IniFiles Important Command Injection Fix 2026-21012-1

An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for perl-config-inifiles ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21012-1 Rating: important References: * bsc#1268236 Cross-References: * CVE-2026-11527 CVSS scores: * CVE-2026-11527 ( SUSE ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for perl-Config-IniFiles fixes the following issue - CVE-2026-11527: OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle (bsc#1268236). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1024=1 Package List: - openSUSE Leap 16.0: perl-Config-IniFiles-3.000003-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-11527.html . A critical update for openSUSE addresses an important security issue in perl-Config-IniFiles, enhancing system robustness.. openSUSE security, perl-Config-IniFiles update, OS command injection, security patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 Important OpenSUSE
100

SUSE perl-HTTP-Daemon Important OS Command Injection Fix 2026-2408-1

An update that solves one vulnerability can now be installed.. # Security update for perl-HTTP-Daemon Announcement ID: SUSE-SU-2026:2408-1 Release Date: 2026-06-16T07:57:10Z Rating: important References: * bsc#1266370 Cross-References: * CVE-2026-8450 CVSS scores: * CVE-2026-8450 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-8450 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for perl-HTTP-Daemon fixes the following issues: * CVE-2026-8450: Fixed OS command injection via send_file() (bsc#1266370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2408=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2408=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * perl-HTTP-Daemon-6.01-9.8.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * perl-HTTP-Daemon-6.01-9.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8450.html * https://bugzilla.suse.com/show_bug.cgi?id=1266370 . A vital SUSE update for perl-HTTP-Daemon addresses an important command injection issue now available for installation.. SUSE Update, Security Fix, OS Command Injection, Perl Package, Important Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 16, 2026 Important SuSE
100

SUSE Linux Micro VIM Major OS Command Injection Fix 2026-21880-1

An update that solves five vulnerabilities and has one fix can now be installed.. # Security update for vim Announcement ID: SUSE-SU-2026:21880-1 Release Date: 2026-06-01T10:45:03Z Rating: important References: * bsc#1262395 * bsc#1264706 * bsc#1264707 * bsc#1264708 * bsc#1265349 * bsc#1265360 Cross-References: * CVE-2026-42307 * CVE-2026-43961 * CVE-2026-44656 * CVE-2026-45130 * CVE-2026-46483 CVSS scores: * CVE-2026-42307 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-43961 ( SUSE ): 5.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43961 ( SUSE ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2026-44656 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44656 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-44656 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44656 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-45130 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-45130 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-45130 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46483 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46483 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-46483 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-46483 ( NVD ): 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for vim fixesthe following issues * CVE-2026-42307: Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim (bsc#1264706). * CVE-2026-43961: Vimscript Code Injection in netrw NetrwMarkFile() via crafted filename (bsc#1265349). * CVE-2026-44656: Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's: find command-line completion (bsc#1264707). * CVE-2026-45130: Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when loading a crafted spell file (.spl) with UTF-8 encoding active (bsc#1264708). * CVE-2026-46483: command injection via `tar#Vimuntar()` in `runtime/autoload/tar.vim` when decompressing `.tgz` archives on Unix-like systems (bsc#1265360). Changes for vim: * Update to v9.2.0530. * Fix for incorrectly detecting scientific parameter files as bitbake recipies. (bsc#1262395) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-557=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * vim-debugsource-9.2.0530-slfo.1.1_1.1 * vim-small-9.2.0530-slfo.1.1_1.1 * vim-small-debuginfo-9.2.0530-slfo.1.1_1.1 * SUSE Linux Micro 6.1 (noarch) * vim-data-common-9.2.0530-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42307.html * https://www.suse.com/security/cve/CVE-2026-43961.html * https://www.suse.com/security/cve/CVE-2026-44656.html * https://www.suse.com/security/cve/CVE-2026-45130.html * https://www.suse.com/security/cve/CVE-2026-46483.html * https://bugzilla.suse.com/show_bug.cgi?id=1262395 * https://bugzilla.suse.com/show_bug.cgi?id=1264706 * https://bugzilla.suse.com/show_bug.cgi?id=1264707 *https://bugzilla.suse.com/show_bug.cgi?id=1264708 * https://bugzilla.suse.com/show_bug.cgi?id=1265349 * https://bugzilla.suse.com/show_bug.cgi?id=1265360 . Important security update for VIM resolves multiple vulnerabilities including command injection and buffer overflow issues.. SUSE security, VIM update, command injection, buffer overflow, Linux patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 02, 2026 Important SuSE
203

Mageia 9 vim Essential OS Command Execution Patch MGASA-2026-0124

MGASA-2026-0123 - Updated vim packages fix security vulnerabilities. MGASA-2026-0123 - Updated vim packages fix security vulnerabilities Publication date: 09 May 2026 URL: https://advisories.mageia.org/MGASA-2026-0123.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-39881, CVE-2026-41411, CVE-2026-42307 Description: Ex command injection in Vims NetBeans integration. (CVE-2026-39881) Command injection via backtick expansion in tag filenames in Vim < v9.2.0357. (CVE-2026-41411) OS Command Injection in netrw affects Vim < 9.2.0383. (CVE-2026-42307) OS Command Injection via 'path' completion affects Vim < 9.2.0435. References: - https://bugs.mageia.org/show_bug.cgi?id=35332 - https://www.openwall.com/lists/oss-security/2026/04/07/13 - https://github.com/vim/vim/security/advisories/GHSA-mr87-rhgv-7pw6 - https://www.openwall.com/lists/oss-security/2026/04/15/7 - https://github.com/vim/vim/security/advisories/GHSA-cwgx-gcj7-6qh8 - https://www.openwall.com/lists/oss-security/2026/04/22/8 - https://github.com/vim/vim/security/advisories/GHSA-85ch-p2qr-m5gx - https://www.openwall.com/lists/oss-security/2026/05/03/11 - https://github.com/vim/vim/security/advisories/GHSA-hwg5-3cxw-wvvg - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39881 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41411 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42307 SRPMS: - 9/core/vim-9.2.437-1.mga9 . Updated vim packages fix multiple security issues including command injection vulnerabilities in Mageia 9.. Mageia Security Advisory, vim OS Command Injection, Mageia Packages Update, vim Vulnerabilities, Vulnerability Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 09, 2026 Critical Mageia
203

Mageia 9 Vim Important OS Command Injection and Buffer Overflow 2026-0049

MGASA-2026-0049 - Updated vim packages fix security vulnerabilities. MGASA-2026-0049 - Updated vim packages fix security vulnerabilities Publication date: 06 Mar 2026 URL: https://advisories.mageia.org/MGASA-2026-0049.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-28417, CVE-2026-28418, CVE-2026-28419, CVE-2026-28420, CVE-2026-28421, CVE-2026-28422 Description: OS Command Injection in netrw affects Vim < 9.2.0073. (CVE-2026-28417) Heap-based Buffer Overflow in Emacs tags parsing affects Vim < 9.2.0074. (CVE-2026-28418) Heap-based Buffer Underflow in Emacs tags parsing affects Vim < 9.2.0075. (CVE-2026-28419) Heap-based Buffer Overflow and OOB Read in :terminal affects Vim < 9.2.0076. (CVE-2026-28420) Multiple Vulnerabilities in Swap File Recovery affect Vim < 9.2.0077. (CVE-2026-28421) Stack-buffer-overflow in build_stl_str_hl() affects Vim < 9.2.0078. (CVE-2026-28422) References: - https://bugs.mageia.org/show_bug.cgi?id=35167 - https://www.openwall.com/lists/oss-security/2026/02/27/6 - https://www.openwall.com/lists/oss-security/2026/02/27/7 - https://www.openwall.com/lists/oss-security/2026/02/27/8 - https://www.openwall.com/lists/oss-security/2026/02/27/9 - https://www.openwall.com/lists/oss-security/2026/02/27/10 - https://www.openwall.com/lists/oss-security/2026/02/27/11 - https://www.cve.org/CVERecord?id=CVE-2026-28417 - https://www.cve.org/CVERecord?id=CVE-2026-28418 - https://www.cve.org/CVERecord?id=CVE-2026-28419 - https://www.cve.org/CVERecord?id=CVE-2026-28420 - https://www.cve.org/CVERecord?id=CVE-2026-28421 - https://www.cve.org/CVERecord?id=CVE-2026-28422 SRPMS: - 9/core/vim-9.2.106-1.mga9 . Updated Vim packages for Mageia mitigate critical security flaws, including command injection and buffer overflows.. Mageia security advisory, Vim update, command injection, buffer overflow. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 06, 2026 Important Mageia
98

RHEL 9: RHSA-2023:5459-01 Important: Ghostscript OS Command Injection

An update for ghostscript is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: ghostscript security update Advisory ID: RHSA-2023:5459-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5459 Issue date: 2023-10-05 CVE Names: CVE-2023-36664 ===================================================================== 1. Summary: An update for ghostscript is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, noarch, ppc64le, s390x, x86_64 Red Hat Enterprise Linux CRB (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: The Ghostscript suite contains utilities for rendering PostScript and PDF documents. Ghostscript translates PostScript code to common bitmap formats so that the code can be displayed or printed. Security Fix(es): * ghostscript: vulnerable to OS command injection due to mishandles permission validation for pipe devices (CVE-2023-36664) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2217798 - CVE-2023-36664 ghostscript: vulnerable to OS command injection due to mishandles permission validation for pipe devices 6. Package List: Red Hat Enterprise Linux AppStream (v.9): Source: ghostscript-9.54.0-10.el9_2.src.rpm aarch64: ghostscript-9.54.0-10.el9_2.aarch64.rpm ghostscript-debuginfo-9.54.0-10.el9_2.aarch64.rpm ghostscript-debugsource-9.54.0-10.el9_2.aarch64.rpm ghostscript-gtk-debuginfo-9.54.0-10.el9_2.aarch64.rpm ghostscript-tools-dvipdf-9.54.0-10.el9_2.aarch64.rpm ghostscript-tools-fonts-9.54.0-10.el9_2.aarch64.rpm ghostscript-tools-printing-9.54.0-10.el9_2.aarch64.rpm ghostscript-x11-9.54.0-10.el9_2.aarch64.rpm ghostscript-x11-debuginfo-9.54.0-10.el9_2.aarch64.rpm libgs-9.54.0-10.el9_2.aarch64.rpm libgs-debuginfo-9.54.0-10.el9_2.aarch64.rpm noarch: ghostscript-doc-9.54.0-10.el9_2.noarch.rpm ppc64le: ghostscript-9.54.0-10.el9_2.ppc64le.rpm ghostscript-debuginfo-9.54.0-10.el9_2.ppc64le.rpm ghostscript-debugsource-9.54.0-10.el9_2.ppc64le.rpm ghostscript-gtk-debuginfo-9.54.0-10.el9_2.ppc64le.rpm ghostscript-tools-dvipdf-9.54.0-10.el9_2.ppc64le.rpm ghostscript-tools-fonts-9.54.0-10.el9_2.ppc64le.rpm ghostscript-tools-printing-9.54.0-10.el9_2.ppc64le.rpm ghostscript-x11-9.54.0-10.el9_2.ppc64le.rpm ghostscript-x11-debuginfo-9.54.0-10.el9_2.ppc64le.rpm libgs-9.54.0-10.el9_2.ppc64le.rpm libgs-debuginfo-9.54.0-10.el9_2.ppc64le.rpm s390x: ghostscript-9.54.0-10.el9_2.s390x.rpm ghostscript-debuginfo-9.54.0-10.el9_2.s390x.rpm ghostscript-debugsource-9.54.0-10.el9_2.s390x.rpm ghostscript-gtk-debuginfo-9.54.0-10.el9_2.s390x.rpm ghostscript-tools-dvipdf-9.54.0-10.el9_2.s390x.rpm ghostscript-tools-fonts-9.54.0-10.el9_2.s390x.rpm ghostscript-tools-printing-9.54.0-10.el9_2.s390x.rpm ghostscript-x11-9.54.0-10.el9_2.s390x.rpm ghostscript-x11-debuginfo-9.54.0-10.el9_2.s390x.rpm libgs-9.54.0-10.el9_2.s390x.rpm libgs-debuginfo-9.54.0-10.el9_2.s390x.rpm x86_64: ghostscript-9.54.0-10.el9_2.x86_64.rpm ghostscript-debuginfo-9.54.0-10.el9_2.i686.rpm ghostscript-debuginfo-9.54.0-10.el9_2.x86_64.rpm ghostscript-debugsource-9.54.0-10.el9_2.i686.rpm ghostscript-debugsource-9.54.0-10.el9_2.x86_64.rpm ghostscript-gtk-debuginfo-9.54.0-10.el9_2.i686.rpm ghostscript-gtk-debuginfo-9.54.0-10.el9_2.x86_64.rpm ghostscript-tools-dvipdf-9.54.0-10.el9_2.x86_64.rpm ghostscript-tools-fonts-9.54.0-10.el9_2.x86_64.rpm ghostscript-tools-printing-9.54.0-10.el9_2.x86_64.rpm ghostscript-x11-9.54.0-10.el9_2.x86_64.rpm ghostscript-x11-debuginfo-9.54.0-10.el9_2.i686.rpm ghostscript-x11-debuginfo-9.54.0-10.el9_2.x86_64.rpm libgs-9.54.0-10.el9_2.i686.rpm libgs-9.54.0-10.el9_2.x86_64.rpm libgs-debuginfo-9.54.0-10.el9_2.i686.rpm libgs-debuginfo-9.54.0-10.el9_2.x86_64.rpm Red Hat Enterprise Linux CRB (v.9): aarch64: ghostscript-debuginfo-9.54.0-10.el9_2.aarch64.rpm ghostscript-debugsource-9.54.0-10.el9_2.aarch64.rpm ghostscript-gtk-debuginfo-9.54.0-10.el9_2.aarch64.rpm ghostscript-x11-debuginfo-9.54.0-10.el9_2.aarch64.rpm libgs-debuginfo-9.54.0-10.el9_2.aarch64.rpm libgs-devel-9.54.0-10.el9_2.aarch64.rpm ppc64le: ghostscript-debuginfo-9.54.0-10.el9_2.ppc64le.rpm ghostscript-debugsource-9.54.0-10.el9_2.ppc64le.rpm ghostscript-gtk-debuginfo-9.54.0-10.el9_2.ppc64le.rpm ghostscript-x11-debuginfo-9.54.0-10.el9_2.ppc64le.rpm libgs-debuginfo-9.54.0-10.el9_2.ppc64le.rpm libgs-devel-9.54.0-10.el9_2.ppc64le.rpm s390x: ghostscript-debuginfo-9.54.0-10.el9_2.s390x.rpm ghostscript-debugsource-9.54.0-10.el9_2.s390x.rpm ghostscript-gtk-debuginfo-9.54.0-10.el9_2.s390x.rpm ghostscript-x11-debuginfo-9.54.0-10.el9_2.s390x.rpm libgs-debuginfo-9.54.0-10.el9_2.s390x.rpm libgs-devel-9.54.0-10.el9_2.s390x.rpm x86_64: ghostscript-9.54.0-10.el9_2.i686.rpm ghostscript-debuginfo-9.54.0-10.el9_2.i686.rpm ghostscript-debuginfo-9.54.0-10.el9_2.x86_64.rpm ghostscript-debugsource-9.54.0-10.el9_2.i686.rpm ghostscript-debugsource-9.54.0-10.el9_2.x86_64.rpm ghostscript-gtk-debuginfo-9.54.0-10.el9_2.i686.rpm ghostscript-gtk-debuginfo-9.54.0-10.el9_2.x86_64.rpm ghostscript-tools-fonts-9.54.0-10.el9_2.i686.rpm ghostscript-tools-printing-9.54.0-10.el9_2.i686.rpm ghostscript-x11-debuginfo-9.54.0-10.el9_2.i686.rpm ghostscript-x11-debuginfo-9.54.0-10.el9_2.x86_64.rpm libgs-debuginfo-9.54.0-10.el9_2.i686.rpm libgs-debuginfo-9.54.0-10.el9_2.x86_64.rpm libgs-devel-9.54.0-10.el9_2.i686.rpm libgs-devel-9.54.0-10.el9_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-36664 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details athttps://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJlHtW/AAoJENzjgjWX9erEzTYP/Rxu6j7kaq1Es1kR2Uljdb0t kB4cZPAe4Xh6xb7LG+j4gGUC4dtW+7dcRkdUtT8TFJDN2zukebDye6c8/3gzxCnB CViSHv/wLdQBfo4uhhxoElKWTKOBzcqrEFcdr70zvNNQRVr7HzAStbqpoCm/SajM Zena9VKJAgtZ+LxUq+2sBmVQ4NQgFevBaB1um5Qy53xDnV6YOGY1yW/8Wtxaf9ed VurIMNi3r0I77U8uGUVgd/HN3iE2jddqSWOxT6U9h8MG5TCP/gIQ0SAdlg2W4EQQ 5y1gMXLOWax2ySPb4Wehl9fdN90dz4cAam1YNaSiMQRfVKDVkrny9QNq8rUWsvPh yXNwoNR9S8TdDQsPswjJFetE8G1ijiRHj3oYf2os6jQ1iaAFiHp9GPVFyEeENRcf ivhLdiJuyVAyjzd1SYLZpKz8EfSYp7D+s53tqJvr3cHL2tfa0oYsVDg22JmT10wJ zCn0BIU/SfZn5TYp6QTZxuSLoCyX5hYKnjqxiwBgFNMNu5qGpPT3Z0aZ0BuRGS41 Zj18w5VeGZwnQx1rH9tO4UYIAFvAS9oJB1iYEkA1Tjuj15NDG/QyxbvNngbvD90m geL3R1gq+XwN/a9LJLCOEXzpa3i8BgF/gVbGl/n783581ZB96Cnl2GHZ+aLt1Hi4 BLiftePwnI7gxJcGVcIR =3HAx -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical vulnerability fix released for Ghostscript in Red Hat Enterprise Linux 9 addressing command execution flaw.. Ghostscript Update, Red Hat Enterprise, OS Command Injection, Important Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 05, 2023 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200