Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 3 articles for you...
87

Debian: python-internetarchive Critical Path Handling Fix DSA-6035-1

It was discovered that insecure path handling in the Python interface to the Internet Archive/archive.org could result in overwriting a user's files. For the oldstable distribution (bookworm), this problem has been fixed in version 3.3.0-2~deb12u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6035-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff October 23, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : python-internetarchive CVE ID : CVE-2025-58438 It was discovered that insecure path handling in the Python interface to the Internet Archive/archive.org could result in overwriting a user's files. For the oldstable distribution (bookworm), this problem has been fixed in version 3.3.0-2~deb12u1. For the stable distribution (trixie), this problem has been fixed in version 5.4.0-2~deb13u1. We recommend that you upgrade your python-internetarchive packages. For the detailed security status of python-internetarchive please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/python-internetarchive Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Insecure path handling in Python Internet Archive fixed in Debian updates to prevent file overwriting.. python internetarchive, debian advisory, insecure paths, security updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 23, 2025 Critical Debian
172

Ubuntu 22.04 LTS: USN-7271-1 critical python-virtualenv remote code exec

python-virtualenv could be made to crash or run programs as your login if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-7271-1 February 18, 2025 python-virtualenv vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: python-virtualenv could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - python-virtualenv: Python virtual environment creator Details: It was discovered that virtualenv incorrectly handled paths when activating virtual environments. An attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS python3-virtualenv 20.13.0+ds-2ubuntu0.1~esm1 Available with Ubuntu Pro virtualenv 20.13.0+ds-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS python3-virtualenv 20.0.17-1ubuntu0.4+esm1 Available with Ubuntu Pro virtualenv 20.0.17-1ubuntu0.4+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7271-1 CVE-2024-53899 . Ubuntu Security Notice USN-7271-2 outlines vulnerabilities in the python-virtualenv package that pose risks to system integrity.. python-virtualenv, remote CodeExecution, ubuntu security, update instructions. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 18, 2025 Critical Ubuntu
197

Debian 11: DLA-4046-1 urgent fix for ark archive path issue

A flaw was discovered in ark, an archive utility for the KDE platform. Ark extracted archives with absolute paths to the corresponding location on the user's file system. Absolute paths are now treated as relative paths to prevent overwriting of sensitive information. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4046-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany February 08, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : ark Version : 4:20.12.2-1+deb11u1 CVE ID : CVE-2024-57966 A flaw was discovered in ark, an archive utility for the KDE platform. Ark extracted archives with absolute paths to the corresponding location on the user's file system. Absolute paths are now treated as relative paths to prevent overwriting of sensitive information. For Debian 11 bullseye, this problem has been fixed in version 4:20.12.2-1+deb11u1. We recommend that you upgrade your ark packages. For the detailed security status of ark please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ark Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Debian LTS Advisory DLA-4046-1 highlights a critical security flaw in the ark application, urging admin upgrades to secure against unauthorized file access and ensure system integrity. archive utility, sensitive data protection, debian updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 08, 2025 Important Debian LTS
89

Fedora 39: FEDORA-2024-c94f884440 critical: less command injection

Security fix for CVE-2024-32487 - less with LESSOPEN mishandles \n in paths. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-c94f884440 2024-09-22 02:03:26.291758 -------------------------------------------------------------------------------- Name : less Product : Fedora 39 Version : 633 Release : 4.fc39 URL : https://www.greenwoodsoftware.com/less/ Summary : A text file browser similar to more, but better Description : The less utility is a text file browser that resembles more, but has more capabilities. Less allows you to move backwards in the file as well as forwards. Since less doesn't have to read the entire input file before it starts, less starts up more quickly than text editors (for example, vi). You should install less because it is a basic utility for viewing text files, and you'll use it frequently. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2024-32487 - less with LESSOPEN mishandles \n in paths -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 21 2024 Michal Hlavinka - 643-6 - fix CVE-2024-32487 - less with LESSOPEN mishandles \n in paths (#2274981) * Sun Jul 28 2024 Michal Hlavinka - 633-3 - fix incorrect display when filename contains control chars -------------------------------------------------------------------------------- References: [ 1 ] Bug #2274980 - CVE-2024-32487 less: OS command injection https://bugzilla.redhat.com/show_bug.cgi?id=2274980 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-c94f884440' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora's latest security patch for less tackles CVE-2024-32487, a serious command injection vulnerability. Important advisory information provided.. Fedora Security Advisory,CVE-2024-32487,Less Command Injection,Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 22, 2024 Critical Fedora
100

SUSE: 2023:4646-2 Moderate: Haproxy Update for Path Issues

* bsc#1214102 * bsc#1217653 Cross-References: * CVE-2023-40225 . # Security update for haproxy Announcement ID: SUSE-SU-2023:4646-1 Rating: moderate References: * bsc#1214102 * bsc#1217653 Cross-References: * CVE-2023-40225 * CVE-2023-45539 CVSS scores: * CVE-2023-40225 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-40225 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2023-45539 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2023-45539 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N Affected Products: * SUSE Linux Enterprise High Availability Extension 15 SP1 * SUSE Linux Enterprise High Performance Computing 15 SP1 * SUSE Linux Enterprise Server 15 SP1 * SUSE Linux Enterprise Server 15 SP1 Business Critical Linux 15-SP1 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 * SUSE Manager Proxy 4.0 * SUSE Manager Retail Branch Server 4.0 * SUSE Manager Server 4.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for haproxy fixes the following issues: * CVE-2023-45539: Fixed misinterpretation of a path_end rule with # as part of the URI component (bsc#1217653). * CVE-2023-40225: reject any empty content-length header value (bsc#1214102). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP1 zypper in -t patch SUSE-SLE-Product-HA-15-SP1-2023-4646=1 ## Package List: * SUSE Linux Enterprise High Availability Extension 15 SP1 (aarch64 ppc64le s390x x86_64) * haproxy-debugsource-2.0.31-150100.8.34.1 * haproxy-debuginfo-2.0.31-150100.8.34.1 * haproxy-2.0.31-150100.8.34.1 ## References: * https://www.suse.com/security/cve/CVE-2023-40225.html *https://www.suse.com/security/cve/CVE-2023-45539.html * https://bugzilla.suse.com/show_bug.cgi?id=1214102 * https://bugzilla.suse.com/show_bug.cgi?id=1217653 . Enhance the security of your HAProxy installation by updating and monitoring for CVE issues in SUSE systems.. SUSE Linux, Haproxy Update, Security Measures, Path Handling Fix. . LinuxSecurity.com Team

Calendar%202 Dec 14, 2023 SuSE
203

Mageia 8: 2022-0356 Moderate: Golang DoS and Path Handling Issues

In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error. (CVE-2022-27664) JoinPath and URL.JoinPath do not remove ../ path elements appended to a . MGASA-2022-0356 - Updated golang packages fix security vulnerability Publication date: 05 Oct 2022 URL: https://advisories.mageia.org/MGASA-2022-0356.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-27664, CVE-2022-32190 In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error. (CVE-2022-27664) JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "", despite the JoinPath documentation stating that ../ path elements are removed from the result. (CVE-2022-32190) References: - https://bugs.mageia.org/show_bug.cgi?id=30835 - https://groups.google.com/g/golang-announce/c/x49AQzIVX-s - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/TXS2OQ57KZC5XZKK5UW4SYKPVQAHIOJX/ - - https://www.cve.org/CVERecord?id=CVE-2022-27664 - https://www.cve.org/CVERecord?id=CVE-2022-32190 SRPMS: - 8/core/golang-1.18.6-1.mga8 . Revised Go modules tackle security vulnerabilities related to denial of service and resource path management in Mageia 8 identified in MGASA-2022-0356.. Golang Security Update, Mageia 8 Advisory, Denial of Service. . LinuxSecurity.com Team

Calendar%202 Oct 05, 2022 Mageia
203

Mageia 8, MGASA-2022-0280: Moderate Path Issue in Ruby-Sinatra

Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. (CVE-2022-29970) References: - https://bugs.mageia.org/show_bug.cgi?id=30542 . MGASA-2022-0280 - Updated ruby-sinatra packages fix security vulnerability Publication date: 13 Aug 2022 URL: https://advisories.mageia.org/MGASA-2022-0280.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-29970 Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. (CVE-2022-29970) References: - https://bugs.mageia.org/show_bug.cgi?id=30542 - https://lists.suse.com/pipermail/sle-security-updates/2022-June/011265.html - https://www.cve.org/CVERecord?id=CVE-2022-29970 SRPMS: - 8/core/ruby-sinatra-2.0.8.1-1.1.mga8 . Python-flask libraries upgraded to resolve image hosting bug in Mageia. Urgent vulnerability notice issued.. Ruby Sinatra,Mageia Security,Static File Validation,Sinatra Update,Mageia Advisory. . LinuxSecurity.com Team

Calendar%202 Aug 13, 2022 Mageia
172

Ubuntu 4167-1: Samba Security Advisory on Remote Attacks and DoS

Several security issues were fixed in Samba.. =========================================================================Ubuntu Security Notice USN-4167-1 October 29, 2019 samba vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.10 - Ubuntu 19.04 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Samba. Software Description: - samba: SMB/CIFS file, print, and login server for Unix Details: Michael Hanselmann discovered that the Samba client code incorrectly handled path separators. If a user were tricked into connecting to a malicious server, a remote attacker could use this issue to cause the client to access local pathnames instead of network pathnames. (CVE-2019-10218) Simon Fonteneau and Björn Baumbach discovered that Samba incorrectly handled the check password script. This issue could possibly bypass custom password complexity checks, contrary to expectations. This issue only affected Ubuntu 18.04 LTS, Ubuntu 19.04, and Ubuntu 19.10. (CVE-2019-14833) Adam Xu discovered that Samba incorrectly handled the dirsync LDAP control. A remote attacker with "get changes" permissions could possibly use this issue to cause Samba to crash, resulting in a denial of service. (CVE-2019-14847) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10: libsmbclient 2:4.10.7+dfsg-0ubuntu2.2 samba 2:4.10.7+dfsg-0ubuntu2.2 Ubuntu 19.04: libsmbclient 2:4.10.0+dfsg-0ubuntu2.6 samba 2:4.10.0+dfsg-0ubuntu2.6 Ubuntu 18.04 LTS: libsmbclient 2:4.7.6+dfsg~ubuntu-0ubuntu2.13 samba 2:4.7.6+dfsg~ubuntu-0ubuntu2.13 Ubuntu 16.04 LTS: libsmbclient 2:4.3.11+dfsg-0ubuntu0.16.04.23 samba 2:4.3.11+dfsg-0ubuntu0.16.04.23 In general, a standard system update will make all the necessary changes. References: CVE-2019-10218, CVE-2019-14833, CVE-2019-14847 Package Information: https://launchpad.net/ubuntu/+source/samba/2:4.10.7+dfsg-0ubuntu2.2 https://launchpad.net/ubuntu/+source/samba/2:4.10.0+dfsg-0ubuntu2.6 https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.13 https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.23 . Various vulnerabilities regarding Samba were resolved in Ubuntu 19.10 and prior versions, affecting both authentication processes and the overall stability of services.. Samba Vulnerabilities, Ubuntu Security Notice, Remote Attack Mitigation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 29, 2019 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200