Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 11 articles for you...
202

openSUSE 16.0 ovmf Moderate Padding Oracle Bug Fix 2026-20499-1

An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for ovmf ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20499-1 Rating: moderate References: * bsc#1252441 Cross-References: * CVE-2025-59438 CVSS scores: * CVE-2025-59438 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-59438 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for ovmf fixes the following issue: - CVE-2025-59438: mbedtls: padding oracle attack possible through timing of cipher error reporting (bsc#1252441). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-514=1 Package List: - openSUSE Leap 16.0: ovmf-202502-160000.4.1 ovmf-tools-202502-160000.4.1 qemu-ovmf-ia32-202502-160000.4.1 qemu-ovmf-x86_64-202502-160000.4.1 qemu-ovmf-x86_64-debug-202502-160000.4.1 qemu-uefi-aarch32-202502-160000.4.1 qemu-uefi-aarch64-202502-160000.4.1 qemu-uefi-riscv64-202502-160000.4.1 References: * https://www.suse.com/security/cve/CVE-2025-59438.html . Update for openSUSE ovmf addresses a moderate security issue involving CVE-2025-59438 and includes a bug fix.. openSUSE security update, ovmf package security, timing attack patch. . LinuxSecurity.com Team

Calendar%202 Apr 21, 2026 OpenSUSE
87

Debian DSA-6187-1 php-phpseclib3 Important AES-CBC Padding Oracle Attack

It was discovered that the AES-CBC implementation in the PHP Secure Communications Library was susceptible to a padding oracle timing attack. For the oldstable distribution (bookworm), these problems have been fixed in version 3.0.19-1+deb12u4. This update also fixes CVE-2023-52892. For the stable distribution (trixie), these problems have been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6187-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff March 29, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : php-phpseclib3 CVE ID : CVE-2026-32935 It was discovered that the AES-CBC implementation in the PHP Secure Communications Library was susceptible to a padding oracle timing attack. For the oldstable distribution (bookworm), these problems have been fixed in version 3.0.19-1+deb12u4. This update also fixes CVE-2023-52892. For the stable distribution (trixie), these problems have been fixed in version 3.0.43-2+deb13u1. We recommend that you upgrade your php-phpseclib3 packages. For the detailed security status of php-phpseclib3 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/php-phpseclib3 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical update for Debian php-phpseclib3 addresses padding oracle timing attack risk in AES-CBC implementation.. Debian php-phpseclib3 AES-CBC update padding oracle. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 29, 2026 Important Debian
87

Debian php-phpseclib Vulnerability DSA-6186-1 Critical Timing Attack Issue

It was discovered that the AES-CBC implementation in the PHP Secure Communications Library was susceptible to a padding oracle timing attack. For the oldstable distribution (bookworm), these problems have been fixed in version 2.0.42-1+deb12u3. This update also fixes CVE-2023-52892. For the stable distribution (trixie), these problems have been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6186-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff March 29, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : php-phpseclib CVE ID : CVE-2026-32935 It was discovered that the AES-CBC implementation in the PHP Secure Communications Library was susceptible to a padding oracle timing attack. For the oldstable distribution (bookworm), these problems have been fixed in version 2.0.42-1+deb12u3. This update also fixes CVE-2023-52892. For the stable distribution (trixie), these problems have been fixed in version 2.0.48-3+deb13u1. We recommend that you upgrade your php-phpseclib packages. For the detailed security status of php-phpseclib please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/php-phpseclib Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . AES-CBC implementation in php-phpseclib is vulnerable to padding oracle timing attacks. Upgrade to secure your system now!. php-phpseclib, Debian Security, padding oracle, AES-CBC, CVE-2023-52892. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 29, 2026 Critical Debian
89

Fedora 43 php-phpseclib Update 2.0.52 Vulnerability Disclosure Risk

Update to v2.0.52. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d1feefa819 2026-03-28 00:45:01.878008+00:00 -------------------------------------------------------------------------------- Name : php-phpseclib Product : Fedora 43 Version : 2.0.52 Release : 1.fc43 URL : https://github.com/phpseclib/phpseclib Summary : PHP Secure Communications Library Description : MIT-licensed pure-PHP implementations of an arbitrary-precision integer arithmetic library, fully PKCS#1 (v2.1) compliant RSA, DES, 3DES, RC4, Rijndael, AES, Blowfish, Twofish, SSH-1, SSH-2, SFTP, and X.509 -------------------------------------------------------------------------------- Update Information: Update to v2.0.52 -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 19 2026 Artur Frenszek-Iwicki - 2.0.52-1 - Update to v2.0.52 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2449636 - CVE-2026-32935 php-phpseclib: phpseclib: Information disclosure via padding oracle timing attack when using AES in CBC mode [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2449636 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d1feefa819' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fedora 43 updates php-phpseclib to v2.0.52 addressing AES information disclosure risks via timing attacks.. Fedora security phpseclib updates information disclosure AES. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 28, 2026 Important Fedora
172

Ubuntu: 4376-1 Moderate: OpenSSL Timing Attack and RNG Issues

Several security issues were fixed in OpenSSL.. =========================================================================Ubuntu Security Notice USN-4376-1 May 28, 2020 openssl vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.10 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in OpenSSL. Software Description: - openssl: Secure Socket Layer (SSL) cryptographic library and tools Details: Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin, Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL incorrectly handled ECDSA signatures. An attacker could possibly use this issue to perform a timing side-channel attack and recover private ECDSA keys. (CVE-2019-1547) Matt Caswell discovered that OpenSSL incorrectly handled the random number generator (RNG). This may result in applications that use the fork() system call sharing the same RNG state between the parent and the child, contrary to expectations. This issue only affected Ubuntu 18.04 LTS and Ubuntu 19.10. (CVE-2019-1549) Guido Vranken discovered that OpenSSL incorrectly performed the x86_64 Montgomery squaring procedure. While unlikely, a remote attacker could possibly use this issue to recover private keys. (CVE-2019-1551) Bernd Edlinger discovered that OpenSSL incorrectly handled certain decryption functions. In certain scenarios, a remote attacker could possibly use this issue to perform a padding oracle attack and decrypt traffic. (CVE-2019-1563) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10: libssl1.1 1.1.1c-1ubuntu4.1 Ubuntu 18.04 LTS: libssl1.1 1.1.1-1ubuntu2.1~18.04.6 Ubuntu 16.04 LTS: libssl1.0.0 1.0.2g-1ubuntu4.16 After a standard system update you needto reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4376-1 CVE-2019-1547, CVE-2019-1549, CVE-2019-1551, CVE-2019-1563 Package Information: https://launchpad.net/ubuntu/+source/openssl/1.1.1c-1ubuntu4.1 https://launchpad.net/ubuntu/+source/openssl/1.1.1-1ubuntu2.1~18.04.6 https://launchpad.net/ubuntu/+source/openssl/1.0.2g-1ubuntu4.16 . =========================================================================Ubuntu Security Notice USN-. security, openssl, =====================================================. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 28, 2020 Important Ubuntu
87

Debian OpenSSL1.0 Critical Timing Attack CVE-2019-1547 CVE-2019-1563

Two security issues were discovered in OpenSSL: A timing attack against ECDSA and a padding oracle in PKCS7_dataDecode() and CMS_decrypt_set1_pkey(). . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4540-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff October 01, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openssl1.0 CVE ID : CVE-2019-1547 CVE-2019-1563 Two security issues were discovered in OpenSSL: A timing attack against ECDSA and a padding oracle in PKCS7_dataDecode() and CMS_decrypt_set1_pkey(). For the oldstable distribution (stretch), these problems have been fixed in version 1.0.2t-1~deb9u1. We recommend that you upgrade your openssl1.0 packages. For the detailed security status of openssl1.0 please refer to its security tracker page at: Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian issue DSA-4540-1 alerts users of critical timing and padding attacks on OpenSSL requiring urgent updates.. Debian Advisory, OpenSSL Attack, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 01, 2019 Critical Debian
87

Debian OpenSSL Critical Timing Attack and Padding Issues DSA-4539-1

Three security issues were discovered in OpenSSL: A timing attack against ECDSA, a padding oracle in PKCS7_dataDecode() and CMS_decrypt_set1_pkey() and it was discovered that a feature of the random number generator (RNG) intended to protect against shared RNG state between parent and child . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4539-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff October 01, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openssl CVE ID : CVE-2019-1547 CVE-2019-1549 CVE-2019-1563 Three security issues were discovered in OpenSSL: A timing attack against ECDSA, a padding oracle in PKCS7_dataDecode() and CMS_decrypt_set1_pkey() and it was discovered that a feature of the random number generator (RNG) intended to protect against shared RNG state between parent and child processes in the event of a fork() syscall was not used by default. For the oldstable distribution (stretch), these problems have been fixed in version 1.1.0l-1~deb9u1. For the stable distribution (buster), these problems have been fixed in version 1.1.1d-0+deb10u1. We recommend that you upgrade your openssl packages. For the detailed security status of openssl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/openssl Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . OpenSSL encounters various vulnerabilities such as side-channel attacks and improper padding. Users on Debian systems are urged to perform an upgrade.. OpenSSL Security Update, Debian DSA-4539-1, Security Advisories. . Severity:Critical. LinuxSecurity.com Team

Calendar%202 Oct 01, 2019 Critical Debian
200

Scientific Linux SL7: SLSA-2019-2304-1 Moderate OpenSSL Security Update

openssl: 0-byte record padding oracle (CVE-2019-1559) * openssl: timing side channel attack in the DSA signature algorithm (CVE-2018-0734) SL7 x86_64 openssl-1.0.2k-19.el7.x86_64.rpm openssl-libs-1.0.2k-19.el7.i686.rpm openssl-devel-1.0.2k-19.el7.x86_64.rpm openssl-libs-1.0.2k-19.el7.x86_64.rpm openssl-devel-1.0.2k-19.el7.i686.rpm openssl-static-1.0.2k-19.el7.i686.r [More...]. Synopsis: Moderate: openssl security and bug fix update Advisory ID: SLSA-2019:2304-1 Issue Date: 2019-08-06 CVE Numbers: CVE-2019-1559 CVE-2018-0734 -- Security Fix(es): * openssl: 0-byte record padding oracle (CVE-2019-1559) * openssl: timing side channel attack in the DSA signature algorithm (CVE-2018-0734) -- SL7 x86_64 openssl-1.0.2k-19.el7.x86_64.rpm openssl-libs-1.0.2k-19.el7.i686.rpm openssl-devel-1.0.2k-19.el7.x86_64.rpm openssl-libs-1.0.2k-19.el7.x86_64.rpm openssl-devel-1.0.2k-19.el7.i686.rpm openssl-static-1.0.2k-19.el7.i686.rpm openssl-perl-1.0.2k-19.el7.x86_64.rpm openssl-static-1.0.2k-19.el7.x86_64.rpm openssl-debuginfo-1.0.2k-19.el7.i686.rpm openssl-debuginfo-1.0.2k-19.el7.x86_64.rpm - Scientific Linux Development Team . A substantial OpenSSL patch for Scientific Linux SL7 addresses major vulnerabilities including side-channel exploits and padding oracle attacks.. openssl update, security patch, Scientific Linux, bug fix, padding oracle. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 26, 2019 Important Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200