Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 41: FEDORA-2025-d3dee9f37d critical: yarnpkg pbkdf2 library fix

Update bundled pbkdf2 library.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-d3dee9f37d 2025-07-05 01:45:24.506251+00:00 -------------------------------------------------------------------------------- Name : yarnpkg Product : Fedora 41 Version : 1.22.22 Release : 9.fc41 URL : https://github.com/yarnpkg/yarn Summary : Fast, reliable, and secure dependency management. Description : Fast, reliable, and secure dependency management. -------------------------------------------------------------------------------- Update Information: Update bundled pbkdf2 library. -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 24 2025 Sandro Mani - 1.22.22-9 - Add CVE-2025-6545_6547.prebundle.patch and regenerate bundle. Fixes CVE-2025-6545 and CVE-2025-6547. -------------------------------------------------------------------------------- References: [ 1 ] Bug #2374429 - CVE-2025-6547 yarnpkg: pbkdf2 silently returns static keys [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2374429 [ 2 ] Bug #2374433 - CVE-2025-6545 yarnpkg: pbkdf2 silently returns predictable key material [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2374433 [ 3 ] Bug #2374438 - CVE-2025-6547 yarnpkg: pbkdf2 silently returns static keys [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2374438 [ 4 ] Bug #2374443 - CVE-2025-6545 yarnpkg: pbkdf2 silently returns predictable key material [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2374443 [ 5 ] Bug #2374450 - CVE-2025-6547 yarnpkg: pbkdf2 silently returns static keys [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2374450 [ 6 ] Bug #2374455 - CVE-2025-6545 yarnpkg: pbkdf2 silently returns predictable key material [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2374455 [ 7 ] Bug #2374462 - CVE-2025-6547 yarnpkg:pbkdf2 silently returns static keys [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2374462 [ 8 ] Bug #2374465 - CVE-2025-6545 yarnpkg: pbkdf2 silently returns predictable key material [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2374465 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-d3dee9f37d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Important patch for yarnpkg in Fedora addressing vulnerabilities in the pbkdf2 library. Immediate upgrade suggested.. Fedora Update,yarnpkg security,dependency management fix,pbkdf2 issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 05, 2025 Critical Fedora
89

Fedora 42: 2025-96ff8c2897 important: yarnpkg pbkdf2 key material

Update bundled pbkdf2 library.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-96ff8c2897 2025-07-04 00:01:57.047516+00:00 -------------------------------------------------------------------------------- Name : yarnpkg Product : Fedora 42 Version : 1.22.22 Release : 9.fc42 URL : https://github.com/yarnpkg/yarn Summary : Fast, reliable, and secure dependency management. Description : Fast, reliable, and secure dependency management. -------------------------------------------------------------------------------- Update Information: Update bundled pbkdf2 library. -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 24 2025 Sandro Mani - 1.22.22-9 - Add CVE-2025-6545_6547.prebundle.patch and regenerate bundle. Fixes CVE-2025-6545 and CVE-2025-6547. -------------------------------------------------------------------------------- References: [ 1 ] Bug #2374429 - CVE-2025-6547 yarnpkg: pbkdf2 silently returns static keys [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2374429 [ 2 ] Bug #2374433 - CVE-2025-6545 yarnpkg: pbkdf2 silently returns predictable key material [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2374433 [ 3 ] Bug #2374438 - CVE-2025-6547 yarnpkg: pbkdf2 silently returns static keys [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2374438 [ 4 ] Bug #2374443 - CVE-2025-6545 yarnpkg: pbkdf2 silently returns predictable key material [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2374443 [ 5 ] Bug #2374450 - CVE-2025-6547 yarnpkg: pbkdf2 silently returns static keys [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2374450 [ 6 ] Bug #2374455 - CVE-2025-6545 yarnpkg: pbkdf2 silently returns predictable key material [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2374455 [ 7 ] Bug #2374462 - CVE-2025-6547 yarnpkg:pbkdf2 silently returns static keys [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2374462 [ 8 ] Bug #2374465 - CVE-2025-6545 yarnpkg: pbkdf2 silently returns predictable key material [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2374465 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-96ff8c2897' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Significant update for yarnpkg in Fedora 42 bolsters scrypt encryption library protection, addressing multiple security flaws.. yarnpkg security update,fedora 42 advisory,dependency management threat. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jul 04, 2025 Important Fedora
197

Debian Buster DLA-3669-1: Critical Update for Cryptojs Weak Parameters

Thomas Neil James Shadwell reported that cryptojs, a collection of cryptographic algorithms implemented in JavaScript, had default PBKDF2 settings 1000 times weaker than when specified back in 1993, and 1.3M times weaker than OWASP's current recommendations. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3669-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin November 27, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : cryptojs Version : 3.1.2+dfsg-2+deb10u1 CVE ID : CVE-2023-46233 Debian Bug : 1055525 Thomas Neil James Shadwell reported that cryptojs, a collection of cryptographic algorithms implemented in JavaScript, had default PBKDF2 settings 1000 times weaker than when specified back in 1993, and 1.3M times weaker than OWASP's current recommendations. The default settings are now changed to use SHA256 with 250k iterations. For Debian 10 buster, this problem has been fixed in version 3.1.2+dfsg-2+deb10u1. We recommend that you upgrade your cryptojs packages. For the detailed security status of cryptojs please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/cryptojs Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS DLA-3669-1 details a critical update for cryptojs addressing weak PBKDF2 settings.. Cryptojs Security, Debian LTS Update, Cryptography Flaw, PBKDF2 Settings, Algorithm Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 27, 2023 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here