Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 494
Alerts This Week
Warning Icon 1 494

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 14 articles for you...
197

Debian LTS DLA-4681-1 p7zip Memory Corruption Fix CVE-2026-48092

Multiple memory corruption vulnerabilities were discovered in p7zip, a now unmaintained fork of 7-Zip, which itself is a file archiver handling multiple formats. To address these security vulnerabilities, whose fixes are unfortunately not isolated, this update again replaces p7zip with a. Debian LTS Advisory DLA-4681-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sylvain Beucler July 13, 2026 https://wiki.debian.org/LTS Package : p7zip Version : 16.02+really26.01+dfsg-0+deb11u1 CVE ID : CVE-2026-48092 CVE-2026-48095 CVE-2026-48101 CVE-2026-48102 CVE-2026-48103 CVE-2026-48104 CVE-2026-48111 CVE-2026-48112 Multiple memory corruption vulnerabilities were discovered in p7zip, a now unmaintained fork of 7-Zip, which itself is a file archiver handling multiple formats. To address these security vulnerabilities, whose fixes are unfortunately not isolated, this update again replaces p7zip with a recent 7-Zip (now v26.01), slightly modified to make it reasonably compatible with p7zip. CVE-2026-48092 SquashFS Fragment Offset Overflow CVE-2026-48095 Heap Buffer Write Overflow CVE-2026-48101 UEFI Capsule uninitialized heap memory disclosure CVE-2026-48102 UDF Field OOB Read CVE-2026-48103 WIM SecurityId OOB read CVE-2026-48104 SquashFS BlockToNode uninitialized heap read CVE-2026-48111 UEFI DEPEX OOB Read CVE-2026-48112 Ar SYMDEF OOB Read For Debian 11 bullseye, these problems have been fixed in version 16.02+really26.01+dfsg-0+deb11u1. We recommend that you upgrade your p7zip packages. For the detailed security status of p7zip please refer to its security tracker page at: https://security-tracker.debian.org/tracker/p7zip Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Multiple memory corruption issues in p7ziphave been resolved with this update. Upgrade your packages to ensure security.. p7zip memory issues, file archiving security, Debian LTS security. . LinuxSecurity.com Team

Calendar%202 Jul 13, 2026 Debian LTS
197

Debian 11 p7zip-rar DLA-4577-1 Memory Corruption DoS Risk CVE-2025-53816

Jaroslav Lobačevski from GitHub Security Lab discovered a memory corruption vulnerability in the RAR module of p7zip, a now unmaintained fork of 7-Zip, a file archiver handling multiple formats. It is unlikely it could lead to arbitrary code execution, but it may lead to denial of service.. Debian LTS Advisory DLA-4577-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sylvain Beucler May 11, 2026 https://wiki.debian.org/LTS Package : p7zip-rar Version : 16.02+really25.00+ds-0+deb11u1 CVE ID : CVE-2025-53816 Debian Bug : 1109494 Jaroslav Lobačevski from GitHub Security Lab discovered a memory corruption vulnerability in the RAR module of p7zip, a now unmaintained fork of 7-Zip, a file archiver handling multiple formats. It is unlikely it could lead to arbitrary code execution, but it may lead to denial of service. To address this vulnerability, whose fix is unfortunately not isolated, and to remain compatible with the new p7zip package (DLA-4576-1), this update replaces the p7zip code base with 7-Zip v25 (which now supports GNU/Linux natively), slightly modified to make it reasonably compatible with p7zip. For Debian 11 bullseye, this problem has been fixed in version 16.02+really25.00+ds-0+deb11u1. We recommend that you upgrade your p7zip-rar packages. For the detailed security status of p7zip-rar please refer to its security tracker page at: https://security-tracker.debian.org/tracker/p7zip-rar Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Explore the Debian LTS advisory for p7zip-rar addressing a memory corruption issue that could lead to denial of service.. Debian LTS, p7zip-rar, security update, denial of service, memory corruption. . LinuxSecurity.com Team

Calendar%202 May 11, 2026 Debian LTS
197

Debian LTS DLA-4576-1 p7zip Critical RCE DoS Issues Fixed

Multiple vulnerabilities were discovered in p7zip, a now unmaintained fork of 7-Zip, a file archiver handling multiple formats. To address these security vulnerabilities, whose fixes are unfortunately not isolated, this update replaces p7zip with 7-Zip v25 (which now supports GNU/Linux natively), slightly modified to make it. Debian LTS Advisory DLA-4576-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sylvain Beucler May 11, 2026 https://wiki.debian.org/LTS Package : p7zip Version : 16.02+really25.01+dfsg-0+deb11u1 CVE ID : CVE-2022-47069 CVE-2023-31102 CVE-2023-40481 CVE-2023-52168 CVE-2023-52169 CVE-2024-11612 CVE-2025-11001 CVE-2025-11002 CVE-2025-53817 CVE-2025-55188 Debian Bug : 1111068 Multiple vulnerabilities were discovered in p7zip, a now unmaintained fork of 7-Zip, a file archiver handling multiple formats. To address these security vulnerabilities, whose fixes are unfortunately not isolated, this update replaces p7zip with 7-Zip v25 (which now supports GNU/Linux natively), slightly modified to make it reasonably compatible with p7zip. CVE-2022-47069 heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd CVE-2023-31102 Ppmd7.c allows an integer underflow and invalid read operation via a crafted 7Z archive. CVE-2023-40481 SquashFS File Parsing Out-Of-Bounds Write RCE CVE-2023-52168 heap-based buffer overflow in NTFS handler CVE-2023-52169 out-of-bounds read in NTFS handler CVE-2024-11612 CopyCoder Infinite Loop Denial-of-Service CVE-2025-11001 ZIP File Parsing Directory Traversal RCE CVE-2025-11002 ZIP File Parsing Directory Traversal RCE CVE-2025-53817 null pointer dereference in the Compound handler may lead to denial of service CVE-2025-55188 does not always properly handle symbolic links For Debian 11 bullseye, these problems have been fixedin version 16.02+really25.01+dfsg-0+deb11u1. We recommend that you upgrade your p7zip packages. For the detailed security status of p7zip please refer to its security tracker page at: https://security-tracker.debian.org/tracker/p7zip Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade p7zip on Debian LTS to address multiple critical vulnerabilities. Ensure system protection and stability.. Debian p7zip vulnerabilities RCE DoS security patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 11, 2026 Important Debian LTS
100

SUSE: 2024:2625-1 Important: p7zip Buffer Overflow and Read Issues

* bsc#1227358 * bsc#1227359 Cross-References: * CVE-2023-52168 . # Security update for p7zip Announcement ID: SUSE-SU-2024:2625-1 Rating: important References: * bsc#1227358 * bsc#1227359 Cross-References: * CVE-2023-52168 * CVE-2023-52169 CVSS scores: * CVE-2023-52168 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2023-52169 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H Affected Products: * Basesystem Module 15-SP5 * Basesystem Module 15-SP6 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Manager Proxy 4.3 * SUSE Manager Retail BranchServer 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for p7zip fixes the following issues: * CVE-2023-52168: Fixed heap-based buffer overflow in the NTFS handler allows two bytes to be overwritten at multiple offsets (bsc#1227358) * CVE-2023-52169: Fixed out-of-bounds read in NTFS handler (bsc#1227359) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-2625=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-2625=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-2625=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2024-2625=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-2625=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-2625=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-2625=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-2625=1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-2625=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-2625=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-2625=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-2625=1 * SUSE Linux EnterpriseServer for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-2625=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-2625=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-2625=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2024-2625=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2024-2625=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2024-2625=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-2625=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * openSUSE Leap 15.5 (noarch) * p7zip-doc-16.02-150200.14.12.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * openSUSE Leap 15.6 (noarch) * p7zip-doc-16.02-150200.14.12.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 *p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Manager Proxy 4.3 (x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * p7zip-full-16.02-150200.14.12.1 * p7zip-debugsource-16.02-150200.14.12.1 * p7zip-16.02-150200.14.12.1 * p7zip-full-debuginfo-16.02-150200.14.12.1 ## References: * https://www.suse.com/security/cve/CVE-2023-52168.html * https://www.suse.com/security/cve/CVE-2023-52169.html * https://bugzilla.suse.com/show_bug.cgi?id=1227358 * https://bugzilla.suse.com/show_bug.cgi?id=1227359 . Urgent update for p7zip addresses memory leaks and read vulnerabilities in SUSE software, enhancing system protection. Take action immediately!. p7zip security update, SUSE Linux vulnerabilities, enterprise storage patch, buffer overflow fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 30, 2024 Important SuSE
100

SUSE: 2024:2475-1 Important: p7zip Heap Overflow and Read Issues

* bsc#1227358 * bsc#1227359 Cross-References: * CVE-2023-52168 . # Security update for p7zip Announcement ID: SUSE-SU-2024:2475-1 Rating: important References: * bsc#1227358 * bsc#1227359 Cross-References: * CVE-2023-52168 * CVE-2023-52169 CVSS scores: * CVE-2023-52168 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2023-52169 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for p7zip fixes the following issues: * CVE-2023-52168: Fixed heap-based buffer overflow in the NTFS handler allows two bytes to be overwritten at multiple offsets (bsc#1227358) * CVE-2023-52169: Fixed out-of-bounds read in NTFS handler (bsc#1227359) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2475=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2475=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2475=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * p7zip-debugsource-9.20.1-7.6.1 * p7zip-9.20.1-7.6.1 * p7zip-debuginfo-9.20.1-7.6.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * p7zip-debugsource-9.20.1-7.6.1 * p7zip-9.20.1-7.6.1 * p7zip-debuginfo-9.20.1-7.6.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * p7zip-debugsource-9.20.1-7.6.1 * p7zip-9.20.1-7.6.1 *p7zip-debuginfo-9.20.1-7.6.1 ## References: * https://www.suse.com/security/cve/CVE-2023-52168.html * https://www.suse.com/security/cve/CVE-2023-52169.html * https://bugzilla.suse.com/show_bug.cgi?id=1227358 * https://bugzilla.suse.com/show_bug.cgi?id=1227359 . Essential p7zip enhancements for SUSE rectify serious security vulnerabilities. Apply updates immediately to bolster system protection.. p7zip Security Update,SUSE Patch Guide,Important Linux Advisory,Buffer Overflow Issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 15, 2024 Important SuSE
203

Mageia 7 Security Advisory: MGASA-2021-0305 Critical p7zip Crash

In p7zip-17.03, the function NCompress::CCopyCoder::Code in CPP/7zip/Common/StreamObjects.cpp will call outStream-> Write where a memcpy uses a NULL pointer as destination address, leading to a crash (CVE-2021-3465). Null pointer dereference in function Reserve() found in p7zip 16.02 . MGASA-2021-0305 - Updated p7zip package fixes security vulnerabilities Publication date: 30 Jun 2021 URL: https://advisories.mageia.org/MGASA-2021-0305.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-3465 In p7zip-17.03, the function NCompress::CCopyCoder::Code in CPP/7zip/Common/StreamObjects.cpp will call outStream-> Write where a memcpy uses a NULL pointer as destination address, leading to a crash (CVE-2021-3465). Null pointer dereference in function Reserve() found in p7zip 16.02 (rhbz#1951218). Null Pointer Dereference in function NArchive::NLzh::CItem::GetUnixTime found in p7zip 16.02 (rhbz#1951224). The p7zip package has been patched to fix these issues. Also, the Mageia 7 package has been updated to version 17.03. References: - https://bugs.mageia.org/show_bug.cgi?id=28903 - https://github.com/jinfeihan57/p7zip/releases - - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/OJQ6YRT2OALFI2LGZSLJD5T74MV6PJ7V/ - https://www.cve.org/CVERecord?id=CVE-2021-3465 SRPMS: - 8/core/p7zip-17.03-1.1.mga8 - 7/core/p7zip-17.03-1.1.mga7 . MGASA-2021-0306 upgrades p7zip to address vulnerabilities, resolving crashes linked to null pointer dereference issues.. p7zip Security Fix, Mageia Software Update, Null Pointer Crash. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 30, 2021 Critical Mageia
202

openSUSE 15.2: SUSE-SU-2021:0684-1 Moderate: p7zip Crash Fix

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for p7zip ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0684-1 Rating: moderate References: #1184699 Cross-References: CVE-2021-3465 CVSS scores: CVE-2021-3465 (SUSE): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for p7zip fixes the following issues: - CVE-2021-3465: Fixed a NULL pointer dereference in NCompress:CCopyCoder:Code (bsc#1184699) This update was imported from the SUSE:SLE-15-SP2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-684=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): p7zip-16.02-lp152.8.3.1 p7zip-debugsource-16.02-lp152.8.3.1 p7zip-full-16.02-lp152.8.3.1 p7zip-full-debuginfo-16.02-lp152.8.3.1 - openSUSE Leap 15.2 (noarch): p7zip-doc-16.02-lp152.8.3.1 References: https://www.suse.com/security/cve/CVE-2021-3465.html https://bugzilla.suse.com/1184699 . Important p7zip security patch resolves CVE-2021-3465 for openSUSE Leap 15.2, complete with installation guidelines provided.. openSUSE Security,p7zip Update,Security Fixes. . LinuxSecurity.com Team

Calendar%202 May 07, 2021 OpenSUSE
100

SUSE: 2021:1491-1 Moderate Security Update for p7zip NULL Pointer

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for p7zip ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:1491-1 Rating: moderate References: #1184699 Cross-References: CVE-2021-3465 CVSS scores: CVE-2021-3465 (SUSE): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for p7zip fixes the following issues: - CVE-2021-3465: Fixed a NULL pointer dereference in NCompress:CCopyCoder:Code (bsc#1184699) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2021-1491=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2021-1491=1 Package List: - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): p7zip-16.02-14.5.1 p7zip-debugsource-16.02-14.5.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): p7zip-16.02-14.5.1 p7zip-debugsource-16.02-14.5.1 p7zip-full-16.02-14.5.1 p7zip-full-debuginfo-16.02-14.5.1 References: https://www.suse.com/security/cve/CVE-2021-3465.html https://bugzilla.suse.com/1184699 . SUSE Security Bulletin: Addresses a notable vulnerability in p7zip under Announcement ID: SUSE-SU-2021:1492-1.. SUSE Linux Enterprise Module,p7zip,moderateupdate. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 04, 2021 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200