Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
202

openSUSE opam Important File Installation Issue CVE-2026-57825

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for opam ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0250-1 Rating: important References: Cross-References: CVE-2026-57825 Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for opam fixes the following issues: Update to version 2.5.2: - CVE-2026-57825: Fixed a bug that allowed a package to install files anywhere on the system using a symlink to an external directory without warning the user and asking for their permission. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-250=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 ppc64le s390x x86_64): opam-2.5.2-bp157.2.6.1 opam-devel-2.5.2-bp157.2.6.1 opam-installer-2.5.2-bp157.2.6.1 References: https://www.suse.com/security/cve/CVE-2026-57825.html . Update available for openSUSE fixes important issues in opam, enhancing system security with CVE-2026-57825.. opam update security, openSUSE CVE-2026, important update package. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 17, 2026 Important OpenSUSE
172

Ubuntu: 3863-2 Critical: APT Man-In-The-Middle Package Installation

An attacker could trick APT into installing altered packages.. =========================================================================Ubuntu Security Notice USN-3863-2 January 22, 2019 apt vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: An attacker could trick APT into installing altered packages. Software Description: - apt: Advanced front-end for dpkg Details: USN-3863-1 fixed a vulnerability in APT. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: Max Justicz discovered that APT incorrectly handled certain parameters during redirects. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could potentially be used to install altered packages. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: apt 0.8.16~exp12ubuntu10.28 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3863-2 https://ubuntu.com/security/notices/USN-3863-1 CVE-2019-3462 . =========================================================================Ubuntu Security Notice USN-. attacker, trick, installing, altered, packages, ======================================. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 22, 2019 Critical Ubuntu
172

Debian 10.3: 4825-2 Urgent Package Manager Security Flaw

An attacker could trick APT into installing altered packages.. =========================================================================Ubuntu Security Notice USN-3746-1 August 20, 2018 apt vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: An attacker could trick APT into installing altered packages. Software Description: - apt: Advanced front-end for dpkg Details: It was discovered that APT incorrectly handled the mirror method (mirror://). If a remote attacker were able to perform a man-in-the-middle attack, this flaw could potentially be used to install altered packages in environments configured to use mirror:// entries. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: apt 1.6.3ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3746-1 CVE-2018-0501 Package Information: https://launchpad.net/ubuntu/+source/apt/1.6.3ubuntu0.1 . It's crucial to upgrade Ubuntu 18.04 LTS to address the APT security flaw that may lead to compromised package installations. Ensure your system is safeguarded.. APT Vulnerability, Ubuntu Update, Man-In-The-Middle Threat. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 20, 2018 Critical Ubuntu
87

Debian: DSA-3297-1 Urgent Notice on Package Authentication Issue

It was discovered that unattended-upgrades, a script for automatic installation of security upgrades, did not properly authenticate downloaded packages when the force-confold or force-confnew dpkg options were enabled via the DPkg::Options::* apt configuration. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3297-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Alessandro Ghedini June 29, 2015 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : unattended-upgrades CVE ID : CVE-2015-1330 It was discovered that unattended-upgrades, a script for automatic installation of security upgrades, did not properly authenticate downloaded packages when the force-confold or force-confnew dpkg options were enabled via the DPkg::Options::* apt configuration. For the oldstable distribution (wheezy), this problem has been fixed in version 0.79.5+wheezy2. For the stable distribution (jessie), this problem has been fixed in version 0.83.3.2+deb8u1. For the unstable distribution (sid), this problem will be fixed shortly. We recommend that you upgrade your unattended-upgrades packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Debian Security Advisory DSA-3298-1 regarding apt includes vulnerabilities impacting secure foreground downloads.. Unattended Upgrades, Debian Security Patch, Package Authentication Flaw. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 29, 2015 Important Debian
172

Ubuntu 10.04 LTS: 968-1 Critical: Dell Latitude 2110 Code Execution Issue

It was discovered that the Ubuntu image shipped on some Dell Latitude2110 systems was accidentally configured to allow unauthenticated packageinstallations. A remote attacker intercepting network communications ora malicious archive mirror server could exploit this to trick the userinto installing unsigned packages, resulting in arbitrary code execution [More...]. ==========================================================Ubuntu Security Notice USN-968-1 August 05, 2010 base-files vulnerability CVE-2010-0834 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 9.10 Ubuntu 10.04 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 9.10: base-files 5.0.0ubuntu7.1 Ubuntu 10.04 LTS: base-files 5.0.0ubuntu20.10.04.2 In general, a standard system update will make all the necessary changes. Details follow: It was discovered that the Ubuntu image shipped on some Dell Latitude 2110 systems was accidentally configured to allow unauthenticated package installations. A remote attacker intercepting network communications or a malicious archive mirror server could exploit this to trick the user into installing unsigned packages, resulting in arbitrary code execution with root privileges. Updated packages for Ubuntu 9.10: Source archives: Size/MD5: 853 a699f7de48cd09591785129b4840ef56 Size/MD5: 74901 d802a9135ce2e49e065926b69e16e646 Architecture independent packages: Size/MD5: 788 558c290ae2250679a3836da80fa3ebc0 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 68358 67faf1b12530db1c708ba12994d88f60 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 68354 ec91c2c47ba30e2a3f2c5ee3ef73d812 lpia architecture (Low Power Intel Architecture): Size/MD5: 68360 1feaa5345fd288eca0fdd180ee12e140 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 68364 4543aabd986eced6a2dadd78ab93daf9 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 68366 2ccfbeddb349e6999d93d2505ed40a10 Updated packages for Ubuntu 10.04: Source archives: Size/MD5: 876 9afddf09156582a48e57c76fab0cf4fa Size/MD5: 76356 d57362eab34a8e9f6cf27b595143c332 Architecture independent packages: Size/MD5: 788 3e937b94118602fc84aab4adbe3f9e97 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 70240 2ecf9c810ef2f2315f63881068d8b839 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 70236 d780378cf42209eeb90ed2f68940b837 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 70230 3a5889ee074ddf43e7be7e6cbbc81c16 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 70236 c1fdeedbea2bcb8423ea745406ec3a05 . Dell Latitude 2110 devices are exposed to a flaw that allows improper software installations, creating a threat to system security.. Dell Latitude 2110, Ubuntu Critical Issues, Package Installation Flaw. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 05, 2010 Critical Ubuntu
89

Fedora Core 5: System Update For cman-kernel Enhancements

Packages updated to load with the latest FC5 kernel (2.6.16-1.2096_FC5). ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-431 2006-04-27 ---------------------------------------------------------------------Product : Fedora Core 5 Name : cman-kernel Version : 2.6.15.1 Release : 0.FC5.19 Summary : cman-kernel - The Cluster Manager kernel modules Description : cman-kernel - The Cluster Manager kernel modules ---------------------------------------------------------------------Update Information: Packages updated to load with the latest FC5 kernel (2.6.16-1.2096_FC5) ------------------------------------------------------------------------------------------------------------------------------------------This update can be downloaded from: 43770925277b22a798b7a8010ed822c6e5046d00 SRPMS/cman-kernel-2.6.15.1-0.FC5.19.src.rpm 9ac83aba05447c1530b4c903431109efa5d166e4 x86_64/cman-kernel-2.6.15.1-0.FC5.19.x86_64.rpm 2d383d1632a60098df6aeae605e05cfc2b35563e x86_64/cman-kernheaders-2.6.15.1-0.FC5.19.x86_64.rpm f3dfe00d8b96c794ba9b02c5a8682c460c37cbab x86_64/cman-kernel-xenU-2.6.15.1-0.FC5.19.x86_64.rpm 27cf8ffab13b9c2ca82fda8327ad3e97ef873b3a x86_64/cman-kernel-xen0-2.6.15.1-0.FC5.19.x86_64.rpm 6800ef30a539b44f0a1ae3c7de66dd385ce064c9 x86_64/debug/cman-kernel-debuginfo-2.6.15.1-0.FC5.19.x86_64.rpm 7ac9ebd65c94e0da65e0ec045d0b55c055521b64 i386/cman-kernel-2.6.15.1-0.FC5.19.i686.rpm 6480d155653574e657da270bbd521ba2520cb5e4 i386/cman-kernheaders-2.6.15.1-0.FC5.19.i686.rpm c4c94dbf44fc89f90b8253353b500cd781201506 i386/cman-kernel-smp-2.6.15.1-0.FC5.19.i686.rpm 6091d0bfee9bbc8f9b958b9c8408bd883ad6e44f i386/cman-kernel-xenU-2.6.15.1-0.FC5.19.i686.rpm 6d98a69b3c7832474638058a6c49b6dc21d48c9b i386/cman-kernel-xen0-2.6.15.1-0.FC5.19.i686.rpm eb4cb914b1205047c5169167ebd8ec80e4258e05 i386/debug/cman-kernel-debuginfo-2.6.15.1-0.FC5.19.i686.rpm This update can beinstalled with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Verify that your Fedora Core 5 environment is equipped with the latest vital improvements in kernel handling.. Fedora Core 5, Cluster Manager Kernel, System Update, Kernel Upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 27, 2006 Critical Fedora
89

Fedora Core 3: RHEL-2008-400 Urgent Dictionary Package Enhancement

Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-300 2005-04-04 ---------------------------------------------------------------------Product : Fedora Core 3 Name : words Version : 3.0 Release : 2.2 Summary : A dictionary of English words for the /usr/share/dict directory. Description : The words file is a dictionary of English words for the /usr/share/dict directory. Some programs use this database of words to check spelling. Password checkers use it to look for bad passwords. ---------------------------------------------------------------------* Mon Apr 4 2005 Karel Zak 3-2.2 - sort with --ignore-case (#147949) ---------------------------------------------------------------------This update can be downloaded from: 95eec17a39d1249675c01f743e4ea31f SRPMS/words-3.0-2.2.src.rpm 5106a950ca5959c1961c1454e9628ea6 x86_64/words-3.0-2.2.noarch.rpm 5106a950ca5959c1961c1454e9628ea6 i386/words-3.0-2.2.noarch.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . This enhancement boosts the language toolkit for Fedora Core 3, refining spell verification and bolstering password protection.. Fedora Core 3, Dictionary Update, Package Enhancement, Password Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 04, 2005 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200