Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 499
Alerts This Week
Warning Icon 1 499

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
203

Mageia 9 Tomcat Security Advisory MGASA-2026-0095 - Request Smuggling

MGASA-2026-0095 - Updated tomcat packages fix security vulnerabilities. MGASA-2026-0095 - Updated tomcat packages fix security vulnerabilities Publication date: 12 Apr 2026 URL: https://advisories.mageia.org/MGASA-2026-0095.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-24880, CVE-2026-25854, CVE-2026-29129, CVE-2026-29145, CVE-2026-29146, CVE-2026-32990, CVE-2026-34483, CVE-2026-34486, CVE-2026-34487, CVE-2026-34500 Description: Request smuggling via invalid chunk extension. (CVE-2026-24880) Occasionally open redirect. (CVE-2026-25854) TLS cipher order is not preserved. (CVE-2026-29129) OCSP checks sometimes soft-fail even when soft-fail is disabled. (CVE-2026-29145) EncryptInterceptor vulnerable to padding oracle attack by default. (CVE-2026-29146) Fix for CVE-2025-66614 is incomplete. (CVE-2026-32990) Incomplete escaping of JSON access logs. (CVE-2026-34483) Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor. (CVE-2026-34486) Cloud membership for clustering component exposed the Kubernetes bearer token. (CVE-2026-34487) OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled. (CVE-2026-34500) References: - https://bugs.mageia.org/show_bug.cgi?id=35341 - https://www.openwall.com/lists/oss-security/2026/04/09/20 - https://www.openwall.com/lists/oss-security/2026/04/09/21 - https://www.openwall.com/lists/oss-security/2026/04/09/22 - https://www.openwall.com/lists/oss-security/2026/04/09/23 - https://www.openwall.com/lists/oss-security/2026/04/09/24 - https://www.openwall.com/lists/oss-security/2026/04/09/25 - https://www.openwall.com/lists/oss-security/2026/04/09/26 - https://www.openwall.com/lists/oss-security/2026/04/09/27 - https://www.openwall.com/lists/oss-security/2026/04/09/28 - https://www.openwall.com/lists/oss-security/2026/04/09/29 - https://www.cve.org/CVERecord?id=CVE-2026-24880 - https://www.cve.org/CVERecord?id=CVE-2026-25854 - https://www.cve.org/CVERecord?id=CVE-2026-29129 -https://www.cve.org/CVERecord?id=CVE-2026-29145 - https://www.cve.org/CVERecord?id=CVE-2026-29146 - https://www.cve.org/CVERecord?id=CVE-2026-32990 - https://www.cve.org/CVERecord?id=CVE-2026-34483 - https://www.cve.org/CVERecord?id=CVE-2026-34486 - https://www.cve.org/CVERecord?id=CVE-2026-34487 - https://www.cve.org/CVERecord?id=CVE-2026-34500 SRPMS: - 9/core/tomcat-9.0.117-1.mga9 . Updated Tomcat packages in Mageia address security issues like request smuggling and padding oracle attacks.. Mageia Security Advisory, Tomcat Security Update, Request Smuggling Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 12, 2026 Important Mageia
197

Debian 11 phpseclib TLS Confusion and Padding Oracle Attack Overview

Two vulnerabilities were discovered in phpseclib, a PHP Secure Communications Library. CVE-2023-52892 Some characters in Subject Alternative Name fields in TLS certificates were incorrectly allowed to have a special meaning. Debian LTS Advisory DLA-4518-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta March 30, 2026 https://wiki.debian.org/LTS Package : phpseclib Version : 1.0.19-3+deb11u3 CVE ID : CVE-2023-52892 CVE-2026-32935 Two vulnerabilities were discovered in phpseclib, a PHP Secure Communications Library. CVE-2023-52892 Some characters in Subject Alternative Name fields in TLS certificates were incorrectly allowed to have a special meaning in regular expressions, leading to name confusion in X.509 certificate host verification. CVE-2026-32935 The AES-CBC implementation was susceptible to a padding oracle timing attack due to the use of a short-circuiting logical operator in the unpadding function. For Debian 11 bullseye, these problems have been fixed in version 1.0.19-3+deb11u3. We recommend that you upgrade your phpseclib packages. For the detailed security status of phpseclib please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/phpseclib Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Discover vulnerabilities in phpseclib affecting TLS verification and AES-CBC implementation. Upgrade recommended now.. Debian Security, phpseclib, TLS Certificate, AES-CBC, Padding Oracle Attack. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 30, 2026 Important Debian LTS
197

Debian 8 LTS: DLA-1701-1 critical: OpenSSL padding oracle attack

Juraj Somorovsky, Robert Merget and Nimrod Aviram discovered a padding oracle attack in OpenSSL. If an application encounters a fatal protocol error and then calls . Package : openssl Version : 1.0.1t-1+deb8u11 CVE ID : CVE-2019-1559 Juraj Somorovsky, Robert Merget and Nimrod Aviram discovered a padding oracle attack in OpenSSL. If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). AEAD ciphersuites are not impacted. For Debian 8 "Jessie", this problem has been fixed in version 1.0.1t-1+deb8u11. We recommend that you upgrade your openssl packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Package : openssl Version : 1.0.1t-1+deb8u11 CVE ID : CVE-2019-1559 Juraj Somorovsky, Robert Merget . juraj, somorovsky, robert, merget, nimrod, aviram, padding, oracle, attack, openssl. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 01, 2019 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200