Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 82 articles for you...
202

openSUSE Leap 16.0: rust1.91 rust1.92 Moderate Update Advisory 2026:20062-1

An update that solves various issues can now be installed.. openSUSE security update: security update for rust1.91, rust1.92 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20062-1 Rating: moderate Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves various issues can now be installed. Description: This update for rust1.91 and rust1.92 fixes the following issues: Rust is shipped in 1.91.0 version. Please see https://github.com/rust-lang/rust/releases/tag/1.91.0 for changes. Rust is shipped in 1.92.0 version. Please see https://github.com/rust-lang/rust/releases/tag/1.92.0 for changes. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-155=1 Package List: - openSUSE Leap 16.0: cargo1.91-1.91.0-160000.1.1 cargo1.92-1.92.0-160000.1.1 rust1.91-1.91.0-160000.1.1 rust1.91-src-1.91.0-160000.1.1 rust1.92-1.92.0-160000.1.1 rust1.92-src-1.92.0-160000.1.1 . Update for openSUSE enhances rust1.91 and rust1.92, resolving notable issues and ensuring better stability.. openSUSE security update,rust packages,rust issues fix. . LinuxSecurity.com Team

Calendar%202 Jan 20, 2026 OpenSUSE
202

openSUSE Tumbleweed 2025:15189-1 moderate: libsoup security fixes

An update that solves 7 vulnerabilities can now be installed.. # libsoup-2_4-1-2.74.3-11.1 on GA media Announcement ID: openSUSE-SU-2025:15189-1 Rating: moderate Cross-References: * CVE-2025-32906 * CVE-2025-32909 * CVE-2025-32910 * CVE-2025-32912 * CVE-2025-32913 * CVE-2025-4948 * CVE-2025-4969 CVSS scores: * CVE-2025-32906 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2025-32909 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2025-32909 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-32910 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32910 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-32912 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32913 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4948 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4948 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-4969 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2025-4969 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 7 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the libsoup-2_4-1-2.74.3-11.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * libsoup-2_4-1 2.74.3-11.1 * libsoup-2_4-1-32bit 2.74.3-11.1 * libsoup2-devel 2.74.3-11.1 * libsoup2-devel-32bit 2.74.3-11.1 * libsoup2-lang 2.74.3-11.1 * typelib-1_0-Soup-2_4 2.74.3-11.1 ## References: * https://www.suse.com/security/cve/CVE-2025-32906.html * https://www.suse.com/security/cve/CVE-2025-32909.html * https://www.suse.com/security/cve/CVE-2025-32910.html * https://www.suse.com/security/cve/CVE-2025-32912.html *https://www.suse.com/security/cve/CVE-2025-32913.html * https://www.suse.com/security/cve/CVE-2025-4948.html * https://www.suse.com/security/cve/CVE-2025-4969.html . This bulletin outlines security updates for libsoup in openSUSE Tumbleweed targeting several threats.. openSUSE Tumbleweed, libsoup security, package update, moderate severity. . LinuxSecurity.com Team

Calendar%202 Jun 02, 2025 OpenSUSE
99

Slackware 15.0: 2025-133-01 critical: screen security patch

New screen packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] screen (SSA:2025-133-01) New screen packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/screen-4.9.1-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: attacher.c - prevent temporary 0666 mode on PTYs. avoid file existence test information leaks. socket.c - don't send signals with root privileges. For more information, see: https://www.cve.org/CVERecord?id=CVE-2025-46802 https://www.cve.org/CVERecord?id=CVE-2025-46804 https://www.cve.org/CVERecord?id=CVE-2025-46805 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/screen-4.9.1-i586-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/screen-4.9.1-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/ap/screen-5.0.1-i686-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ap/screen-5.0.1-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: 12659f919fe3c409660c8a05f0c2a88f screen-4.9.1-i586-1_slack15.0.txz Slackware x86_64 15.0 package: b00ec4f846556da49f9359d0f1bb54a7 screen-4.9.1-x86_64-1_slack15.0.txz Slackware -current package: 9b146ea9e136300faad8286b58291124 ap/screen-5.0.1-i686-1.txz Slackware x86_64 -current package: 5dbc1512f1f890739f1f6b1c77895137 ap/screen-5.0.1-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg screen-4.9.1-i586-1_slack15.0.txz +-----+ . Revised screen components for Slackware 15.0 resolve significant security vulnerabilities, with detailed corrections outlined.. screen security issue, Slackware update, software patch, package management, Linux system administration. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 13, 2025 Critical Slackware
217

Oracle Linux 9 ELSA-2025-4229: Important Thunderbird Security Fix

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-4229 http://linux.oracle.com/errata/ELSA-2025-4229.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: thunderbird-128.9.2-1.0.1.el9_5.x86_64.rpm aarch64: thunderbird-128.9.2-1.0.1.el9_5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//thunderbird-128.9.2-1.0.1.el9_5.src.rpm Related CVEs: CVE-2025-2830 CVE-2025-3522 CVE-2025-3523 Description of changes: [128.9.2-1.0.1] - Fix prefs for new nss [Orabug: 37079813] - Add Oracle prefs [128.9.2] - Add OpenELA debranding [128.9.2-1] - Update to 128.9.2 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 9 has released advisory updates for Thunderbird addressing a variety of security vulnerabilities. For further information, refer to the advisory link provided.. Oracle Linux Security, ThunderBird Update, Linux RPM Fixes, ELSA Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 01, 2025 Important Oracle
202

openSUSE: 2025:14892-1 moderate: ed25519-java-0.3.0-6.1 Advisory Security Update

An update that solves one vulnerability can now be installed.. # ed25519-java-0.3.0-6.1 on GA media Announcement ID: openSUSE-SU-2025:14892-1 Rating: moderate Cross-References: * CVE-2020-36843 CVSS scores: * CVE-2020-36843 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2020-36843 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the ed25519-java-0.3.0-6.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * ed25519-java 0.3.0-6.1 * ed25519-java-javadoc 0.3.0-6.1 ## References: * https://www.suse.com/security/cve/CVE-2020-36843.html . An important advisory for openSUSE regarding ed25519-java package security update and rating.. ed25519-java-0, media, announcement, opensuse-su-2025, 14892-1, rating, moderate. . LinuxSecurity.com Team

Calendar%202 Mar 16, 2025 OpenSUSE
100

SUSE: 2024:3054-1 Important: Python3 Code Execution Risk Mitigated

* bsc#1228105 Cross-References: * CVE-2024-6345 . # Security update for python3-setuptools Announcement ID: SUSE-SU-2024:3054-1 Rating: important References: * bsc#1228105 Cross-References: * CVE-2024-6345 CVSS scores: * CVE-2024-6345 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP5 * Basesystem Module 15-SP6 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * openSUSE Leap Micro 5.5 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python3-setuptools fixes the following issues: * CVE-2024-6345: Fixed code execution via download functions in the package_index module (bsc#1228105) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternativelyyou can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-3054=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-3054=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2024-3054=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-3054=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-3054=1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-3054=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-3054=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-3054=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2024-3054=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2024-3054=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2024-3054=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-3054=1 * openSUSE Leap Micro 5.5 zypper in -t patch openSUSE-Leap-Micro-5.5-2024-3054=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-3054=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-3054=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-3054=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-3054=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-3054=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patchSUSE-SLE-Micro-5.4-2024-3054=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 * Basesystem Module 15-SP5 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 * python3-setuptools-test-44.1.1-150400.9.9.1 * python3-setuptools-wheel-44.1.1-150400.9.9.1 * Basesystem Module 15-SP6 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 * python3-setuptools-test-44.1.1-150400.9.9.1 * python3-setuptools-wheel-44.1.1-150400.9.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 * python3-setuptools-test-44.1.1-150400.9.9.1 * python3-setuptools-wheel-44.1.1-150400.9.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 * python3-setuptools-test-44.1.1-150400.9.9.1 * python3-setuptools-wheel-44.1.1-150400.9.9.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 * python3-setuptools-test-44.1.1-150400.9.9.1 * python3-setuptools-wheel-44.1.1-150400.9.9.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 * python3-setuptools-test-44.1.1-150400.9.9.1 * python3-setuptools-wheel-44.1.1-150400.9.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 * python3-setuptools-test-44.1.1-150400.9.9.1 * python3-setuptools-wheel-44.1.1-150400.9.9.1 * SUSE Manager Proxy 4.3 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 * python3-setuptools-test-44.1.1-150400.9.9.1 * python3-setuptools-wheel-44.1.1-150400.9.9.1 * SUSE Manager Retail Branch Server 4.3 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 * python3-setuptools-test-44.1.1-150400.9.9.1 * python3-setuptools-wheel-44.1.1-150400.9.9.1 * SUSE Manager Server 4.3 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 *python3-setuptools-test-44.1.1-150400.9.9.1 * python3-setuptools-wheel-44.1.1-150400.9.9.1 * openSUSE Leap 15.4 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 * python3-setuptools-test-44.1.1-150400.9.9.1 * python3-setuptools-wheel-44.1.1-150400.9.9.1 * openSUSE Leap Micro 5.5 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 * openSUSE Leap 15.5 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 * python3-setuptools-test-44.1.1-150400.9.9.1 * python3-setuptools-wheel-44.1.1-150400.9.9.1 * openSUSE Leap 15.6 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 * python3-setuptools-test-44.1.1-150400.9.9.1 * python3-setuptools-wheel-44.1.1-150400.9.9.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * python3-setuptools-44.1.1-150400.9.9.1 ## References: * https://www.suse.com/security/cve/CVE-2024-6345.html * https://bugzilla.suse.com/show_bug.cgi?id=1228105 . Keep informed about the latest security notice concerning python3-setuptools, focusing on possible code execution vulnerabilities.. Python Code Execution, SUSE Security Update, Python3 Setuptools Issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 28, 2024 Important SuSE
99

Slackware 15.0: 2024-136-01 Moderate: gdk-pixbuf2 DoS Threat

New gdk-pixbuf2 packages are available for Slackware 15.0 and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] gdk-pixbuf2 (SSA:2024-136-01) New gdk-pixbuf2 packages are available for Slackware 15.0 and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/gdk-pixbuf2-2.42.12-i586-1_slack15.0.txz: Upgraded. ani: Reject files with multiple INA or IART chunks. ani: Reject files with multiple anih chunks. ani: validate chunk size. Thanks to 0xvhp, pedrib, and Benjamin Gilbert. For more information, see: https://www.cve.org/CVERecord?id=CVE-2022-48622 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/gdk-pixbuf2-2.42.12-i586-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/gdk-pixbuf2-2.42.12-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/gdk-pixbuf2-2.42.12-i586-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/gdk-pixbuf2-2.42.12-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: b4be8911d6f57b20a18d0dd5ce4ac42a gdk-pixbuf2-2.42.12-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 5abbb8e210dd3567b105cb78f4f78552 gdk-pixbuf2-2.42.12-x86_64-1_slack15.0.txz Slackware -current package: f4b995edbc7e21a1b2d837284aefb004 l/gdk-pixbuf2-2.42.12-i586-1.txz Slackware x86_64 -currentpackage: 6e8c1d8a5aca9bb2f5967d8a5d15def4 l/gdk-pixbuf2-2.42.12-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg gdk-pixbuf2-2.42.12-i586-1_slack15.0.txz +-----+ . Recent updates to gdk-pixbuf2 in Slackware address a security vulnerability related to the presence of multiple IEND or IDAT chunks in certain image files.. gdk-pixbuf2,Slackware,security update,package fix. . LinuxSecurity.com Team

Calendar%202 May 16, 2024 Slackware
202

openSUSE Leap 15.5 SUSE-SU-2024:0831-1 Moderate: openssl-1_0_0 DoS

This update for openssl-1_0_0 fixes the following issues: CVE-2024-0727: Denial of service when processing a maliciously formatted PKCS12 file (bsc#1219243).. # Security update for openssl-1_0_0 Announcement ID: SUSE-SU-2024:0831-1 Rating: moderate References: * bsc#1219243 Cross-References: * CVE-2024-0727 CVSS scores: * CVE-2024-0727 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2024-0727 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Legacy Module 15-SP5 * openSUSE Leap 15.5 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for openssl-1_0_0 fixes the following issues: * CVE-2024-0727: Denial of service when processing a maliciously formatted PKCS12 file (bsc#1219243). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Legacy Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP5-2024-831=1 * SUSELinux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-831=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-831=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-831=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-831=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-831=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-831=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-831=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-831=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-831=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-831=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-831=1 ## Package List: * Legacy Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libopenssl1_0_0-1.0.2p-150000.3.91.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.91.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.91.1 * libopenssl1_0_0-hmac-1.0.2p-150000.3.91.1 * openssl-1_0_0-1.0.2p-150000.3.91.1 * libopenssl10-debuginfo-1.0.2p-150000.3.91.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl10-1.0.2p-150000.3.91.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * libopenssl1_0_0-1.0.2p-150000.3.91.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.91.1 *openssl-1_0_0-debugsource-1.0.2p-150000.3.91.1 * openssl-1_0_0-1.0.2p-150000.3.91.1 * libopenssl10-debuginfo-1.0.2p-150000.3.91.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl10-1.0.2p-150000.3.91.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libopenssl1_0_0-1.0.2p-150000.3.91.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.91.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.91.1 * libopenssl1_0_0-hmac-1.0.2p-150000.3.91.1 * openssl-1_0_0-1.0.2p-150000.3.91.1 * libopenssl10-debuginfo-1.0.2p-150000.3.91.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl10-1.0.2p-150000.3.91.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libopenssl1_0_0-1.0.2p-150000.3.91.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.91.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.91.1 * libopenssl1_0_0-hmac-1.0.2p-150000.3.91.1 * openssl-1_0_0-1.0.2p-150000.3.91.1 * libopenssl10-debuginfo-1.0.2p-150000.3.91.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl10-1.0.2p-150000.3.91.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * libopenssl1_0_0-1.0.2p-150000.3.91.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.91.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.91.1 * openssl-1_0_0-1.0.2p-150000.3.91.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.91.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * libopenssl1_0_0-1.0.2p-150000.3.91.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.91.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.91.1 * openssl-1_0_0-1.0.2p-150000.3.91.1 * libopenssl10-debuginfo-1.0.2p-150000.3.91.1 *openssl-1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl10-1.0.2p-150000.3.91.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * libopenssl1_0_0-1.0.2p-150000.3.91.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.91.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.91.1 * libopenssl1_0_0-hmac-1.0.2p-150000.3.91.1 * openssl-1_0_0-1.0.2p-150000.3.91.1 * libopenssl10-debuginfo-1.0.2p-150000.3.91.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl10-1.0.2p-150000.3.91.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * libopenssl1_0_0-1.0.2p-150000.3.91.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.91.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.91.1 * openssl-1_0_0-1.0.2p-150000.3.91.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.91.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * libopenssl1_0_0-1.0.2p-150000.3.91.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.91.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.91.1 * openssl-1_0_0-1.0.2p-150000.3.91.1 * libopenssl10-debuginfo-1.0.2p-150000.3.91.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl10-1.0.2p-150000.3.91.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libopenssl1_0_0-1.0.2p-150000.3.91.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.91.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.91.1 * libopenssl1_0_0-hmac-1.0.2p-150000.3.91.1 * openssl-1_0_0-1.0.2p-150000.3.91.1 * libopenssl10-debuginfo-1.0.2p-150000.3.91.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl10-1.0.2p-150000.3.91.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) *libopenssl1_0_0-1.0.2p-150000.3.91.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.91.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.91.1 * openssl-1_0_0-1.0.2p-150000.3.91.1 * libopenssl10-debuginfo-1.0.2p-150000.3.91.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl10-1.0.2p-150000.3.91.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libopenssl1_0_0-1.0.2p-150000.3.91.1 * libopenssl-1_0_0-devel-1.0.2p-150000.3.91.1 * libopenssl1_0_0-steam-debuginfo-1.0.2p-150000.3.91.1 * openssl-1_0_0-cavs-1.0.2p-150000.3.91.1 * openssl-1_0_0-cavs-debuginfo-1.0.2p-150000.3.91.1 * openssl-1_0_0-debugsource-1.0.2p-150000.3.91.1 * libopenssl1_0_0-hmac-1.0.2p-150000.3.91.1 * libopenssl1_0_0-steam-1.0.2p-150000.3.91.1 * openssl-1_0_0-1.0.2p-150000.3.91.1 * libopenssl10-debuginfo-1.0.2p-150000.3.91.1 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.91.1 * libopenssl10-1.0.2p-150000.3.91.1 * openSUSE Leap 15.5 (x86_64) * libopenssl1_0_0-32bit-debuginfo-1.0.2p-150000.3.91.1 * libopenssl1_0_0-32bit-1.0.2p-150000.3.91.1 * libopenssl1_0_0-steam-32bit-1.0.2p-150000.3.91.1 * libopenssl1_0_0-steam-32bit-debuginfo-1.0.2p-150000.3.91.1 * libopenssl-1_0_0-devel-32bit-1.0.2p-150000.3.91.1 * libopenssl1_0_0-hmac-32bit-1.0.2p-150000.3.91.1 * openSUSE Leap 15.5 (noarch) * openssl-1_0_0-doc-1.0.2p-150000.3.91.1 ## References: * https://www.suse.com/security/cve/CVE-2024-0727.html * https://bugzilla.suse.com/show_bug.cgi?id=1219243 . Notice regarding openssl-1_0_0 patch addressing security flaw, refer to CVE-2024-0727 for specifics and follow provided setup guidelines.. OpenSSL Update, SUSE Advisory, Denial of Service Fix, Package Update. . LinuxSecurity.com Team

Calendar%202 Mar 11, 2024 OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200