Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 38 articles for you...
89

Fedora 43 pcs Important Arbitrary Code Execution Fix 2026-c0f7d885ee

Updated standalone web UI and HA Cluster Management Cockpit application to pcs- web-ui 0.1.24.3 (see CHANGELOG_WUI.md) Fixed a crash when running pcs resource|stonith list Fixed order of resources in sets when listing configuration of constraints. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-c0f7d885ee 2026-06-10 01:08:28.182950+00:00 -------------------------------------------------------------------------------- Name : pcs Product : Fedora 43 Version : 0.12.2 Release : 2.fc43 URL : https://github.com/ClusterLabs/pcs Summary : Pacemaker/Corosync Configuration System Description : pcs is a configuration tool for Corosync and Pacemaker. It permits users to easily view, modify and create high availability clusters based on Pacemaker. This package contains the pcs command-line utility and its server pcsd. -------------------------------------------------------------------------------- Update Information: Updated standalone web UI and HA Cluster Management Cockpit application to pcs- web-ui 0.1.24.3 (see CHANGELOG_WUI.md) Fixed a crash when running pcs resource|stonith list Fixed order of resources in sets when listing configuration of constraints -------------------------------------------------------------------------------- ChangeLog: * Fri May 15 2026 Michal Pospíšil - 0.12.2-2 - Updated standalone web UI and HA Cluster Management Cockpit application to pcs-web-ui 0.1.24.3 (see CHANGELOG_WUI.md) Resolves: rhbz#2454042 - Fixed a crash when running pcs resource|stonith list Resolves: rhbz#2458608 - Fixed order of resources in sets when listing configuration of constraints Resolves: rhbz#2461143 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2454042 - CVE-2026-4800 pcs: lodash: Arbitrary code execution via untrusted input in template imports [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454042 [ 2 ] Bug #2458608 -pcs resource list produces traceback https://bugzilla.redhat.com/show_bug.cgi?id=2458608 [ 3 ] Bug #2461143 - pcs constraint in default text mode orders resources alphabetically https://bugzilla.redhat.com/show_bug.cgi?id=2461143 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-c0f7d885ee' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Enhance your Fedora 43 pcs setup by applying important updates and fixes to avoid security risks.. Fedora pcs update security fixes management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 09, 2026 Important Fedora
219

RockyLinux 8 systems Major Patch Release RLSA-2026-20222 CVE-2026-1234

Important: pcs security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:10710", "synopsis": "Important: pcs security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for pcs.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.\n\nSecurity Fix(es):\n\n* lodash: lodash: Arbitrary code execution via untrusted input in template imports (CVE-2026-4800)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2453496", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453496", "description": ""}], "cves": [{"name": "CVE-2026-4800", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4800", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.1", "cwe": "CWE-94"}], "references": [], "publishedAt": "2026-04-28T00:04:30.549590Z", "rpms": {"Rocky Linux 9": {"nvras": ["pcs-0:0.11.10-1.el9_7.3.ppc64le.rpm", "pcs-0:0.11.10-1.el9_7.3.s390x.rpm", "pcs-0:0.11.10-1.el9_7.3.src.rpm", "pcs-0:0.11.10-1.el9_7.3.x86_64.rpm", "pcs-snmp-0:0.11.10-1.el9_7.3.ppc64le.rpm", "pcs-snmp-0:0.11.10-1.el9_7.3.s390x.rpm", "pcs-snmp-0:0.11.10-1.el9_7.3.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux 9 pcs security update fixes important arbitrary code execution issue. CVE-2026-4800 has a CVSS score of 8.1.. Rocky Linux, pcs update, arbitrary code execution, security advisory, CVE-2026-4800. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 28, 2026 Important Rocky Linux
219

Rocky Linux 8 pcs Moderate Denial of Service Update RLSA-2026-8093

Moderate: pcs security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:8093", "synopsis": "Moderate: pcs security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for pcs.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.\n\nSecurity Fix(es):\n\n* tornado-python: Tornado: Denial of Service via large multipart bodies (CVE-2026-31958)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2446765", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2446765", "description": ""}], "cves": [{"name": "CVE-2026-31958", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-31958", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "cvss3BaseScore": "5.3", "cwe": "CWE-770"}], "references": [], "publishedAt": "2026-04-16T12:00:37.623432Z", "rpms": {"Rocky Linux 8": {"nvras": ["pcs-0:0.10.18-2.el8_10.9.aarch64.rpm", "pcs-0:0.10.18-2.el8_10.9.src.rpm", "pcs-0:0.10.18-2.el8_10.9.x86_64.rpm", "pcs-snmp-0:0.10.18-2.el8_10.9.aarch64.rpm", "pcs-snmp-0:0.10.18-2.el8_10.9.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux issues a moderate security advisory for pcs due to a denial of service threat; update recommended for users.. Rocky Linux security advisory, pcs update, denial of service fix. . LinuxSecurity.com Team

Calendar%202 Apr 16, 2026 Rocky Linux
89

Fedora 43 pcs Important Prototype Pollution Security Notice 2026-88c901f6a2

Rebased pcs to the newest major version (see CHANGELOG.md) Updated standalone web UI and HA Cluster Management Cockpit application to pcs- web-ui 0.1.24.2 (see CHANGELOG_WUI.md) Fixed FTBFS with Python 3.15 Fixed issues with installing pcs on Fedora 43+, upgrade and uninstall. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-88c901f6a2 2026-03-15 00:55:01.242067+00:00 -------------------------------------------------------------------------------- Name : pcs Product : Fedora 43 Version : 0.12.2 Release : 1.fc43 URL : https://github.com/ClusterLabs/pcs Summary : Pacemaker/Corosync Configuration System Description : pcs is a configuration tool for Corosync and Pacemaker. It permits users to easily view, modify and create high availability clusters based on Pacemaker. This package contains the pcs command-line utility and its server pcsd. -------------------------------------------------------------------------------- Update Information: Rebased pcs to the newest major version (see CHANGELOG.md) Updated standalone web UI and HA Cluster Management Cockpit application to pcs- web-ui 0.1.24.2 (see CHANGELOG_WUI.md) Fixed FTBFS with Python 3.15 Fixed issues with installing pcs on Fedora 43+, upgrade and uninstall -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 5 2026 Michal Posp\u0161il - 0.12.2-1 - Rebased pcs to the newest major version (see CHANGELOG.md) - Updated standalone web UI and HA Cluster Management Cockpit application to pcs-web-ui 0.1.24.2 (see CHANGELOG_WUI.md) Resolves: rhbz#2432985, rhbz#2433035 - Fixed FTBFS with Python 3.15 Resolves: rhbz#2440684 - Fixed issues with installing pcs on Fedora 43+, upgrade and uninstall * Fri Jan 16 2026 Fedora Release Engineering - 0.12.1-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2433035 - CVE-2025-13465 pcs: prototype pollution in _.unset and _.omit functions [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2433035 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-88c901f6a2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update for Fedora 43 pcs addresses important issues, including prototype pollution and installation fixes.. Fedora pcs update, pcs server management, Fedora upgrade advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 15, 2026 Important Fedora
89

Fedora 44 pcs Important Update Fixes Installation Issues 2026-015b33238d

Rebased pcs to the newest major version (see CHANGELOG.md) Updated standalone web UI and HA Cluster Management Cockpit application to pcs- web-ui 0.1.24.2 (see CHANGELOG_WUI.md) Fixed FTBFS with Python 3.15 Fixed issues with installing pcs on Fedora 43+, upgrade and uninstall. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-015b33238d 2026-03-15 00:15:25.518032+00:00 -------------------------------------------------------------------------------- Name : pcs Product : Fedora 44 Version : 0.12.2 Release : 1.fc44 URL : https://github.com/ClusterLabs/pcs Summary : Pacemaker/Corosync Configuration System Description : pcs is a configuration tool for Corosync and Pacemaker. It permits users to easily view, modify and create high availability clusters based on Pacemaker. This package contains the pcs command-line utility and its server pcsd. -------------------------------------------------------------------------------- Update Information: Rebased pcs to the newest major version (see CHANGELOG.md) Updated standalone web UI and HA Cluster Management Cockpit application to pcs- web-ui 0.1.24.2 (see CHANGELOG_WUI.md) Fixed FTBFS with Python 3.15 Fixed issues with installing pcs on Fedora 43+, upgrade and uninstall -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 5 2026 Michal Posp\u0161il - 0.12.2-1 - Rebased pcs to the newest major version (see CHANGELOG.md) - Updated standalone web UI and HA Cluster Management Cockpit application to pcs-web-ui 0.1.24.2 (see CHANGELOG_WUI.md) Resolves: rhbz#2432985, rhbz#2433035 - Fixed FTBFS with Python 3.15 Resolves: rhbz#2440684 - Fixed issues with installing pcs on Fedora 43+, upgrade and uninstall -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-015b33238d' at the command line.For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update for Fedora 44 pcs tool fixing issues and improving performance for high availability cluster management.. Fedora Update, pcs Configuration, Cluster Management, High Availability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 15, 2026 Important Fedora
219

Rocky Linux PCs Medium Denial of Service Vulnerability Fix - RLSA-2026-0930

Moderate: pcs security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:0930", "synopsis": "Moderate: pcs security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for pcs.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.\n\nSecurity Fix(es):\n\n* tornado: Tornado Quadratic DoS via Repeated Header Coalescing (CVE-2025-67725)\n\n* tornado: Tornado Quadratic DoS via Crafted Multipart Parameters (CVE-2025-67726)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2421722", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2421722", "description": ""}, {"ticket": "2421733", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2421733", "description": ""}], "cves": [{"name": "CVE-2025-67725", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-67725", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "cvss3BaseScore": "5.3", "cwe": "CWE-400"}, {"name": "CVE-2025-67726", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-67726", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "cvss3BaseScore": "5.3", "cwe": "CWE-834"}], "references": [], "publishedAt": "2026-01-23T09:04:43.105327Z", "rpms": {"Rocky Linux 8": {"nvras": ["pcs-0:0.10.18-2.el8_10.8.aarch64.rpm", "pcs-0:0.10.18-2.el8_10.8.src.rpm", "pcs-0:0.10.18-2.el8_10.8.x86_64.rpm", "pcs-snmp-0:0.10.18-2.el8_10.8.aarch64.rpm", "pcs-snmp-0:0.10.18-2.el8_10.8.x86_64.rpm"]}}, "rebootSuggested":false, "buildReferences": []}. Moderate pcs security update for Rocky Linux 8 addresses DoS threats with CVEs CVE-2025-67725 and CVE-2025-67726.. Rocky Linux pcs security DoS update. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jan 23, 2026 moderate Rocky Linux
219

Rocky Linux 9 release triggers urgent security update for memory issue

Important: pcs security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:19512", "synopsis": "Important: pcs security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for pcs.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.\n\nSecurity Fix(es):\n\n* rubygem-rack: Rack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parameters (CVE-2025-59830)\n\n* rack: Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion) (CVE-2025-61770)\n\n* rack: Rack's multipart parser buffers large non?file fields entirely in memory, enabling DoS (memory exhaustion) (CVE-2025-61771)\n\n* rack: Rack memory exhaustion denial of service (CVE-2025-61772)\n\n* rubygem-rack: Unbounded read in `Rack::Request` form parsing can lead to memory exhaustion (CVE-2025-61919)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2398167", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2398167", "description": ""}, {"ticket": "2402174", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2402174", "description": ""}, {"ticket": "2402175", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2402175", "description": ""}, {"ticket": "2402200", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2402200", "description": ""}, {"ticket": "2403180", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2403180", "description":""}], "cves": [{"name": "CVE-2025-59830", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-59830", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-770"}, {"name": "CVE-2025-61770", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61770", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-400"}, {"name": "CVE-2025-61771", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61771", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1284"}, {"name": "CVE-2025-61772", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61772", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "cvss3BaseScore": "5.3", "cwe": "CWE-400"}, {"name": "CVE-2025-61919", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61919", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-400"}], "references": [], "publishedAt": "2025-11-06T09:06:17.598112Z", "rpms": {"Rocky Linux 9": {"nvras": ["pcs-0:0.11.9-2.el9_6.2.ppc64le.rpm", "pcs-0:0.11.9-2.el9_6.2.s390x.rpm", "pcs-0:0.11.9-2.el9_6.2.src.rpm", "pcs-0:0.11.9-2.el9_6.2.x86_64.rpm", "pcs-snmp-0:0.11.9-2.el9_6.2.ppc64le.rpm", "pcs-snmp-0:0.11.9-2.el9_6.2.s390x.rpm", "pcs-snmp-0:0.11.9-2.el9_6.2.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Crucial pcs security update available for Rocky Linux 9 addressing multiple DoS risks. Immediate action recommended!. pcs update, Rocky Linux security, important patches, DoS vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 06, 2025 Important Rocky Linux
219

Rocky Linux 8 pcs Important Denial Service Issues RLSA-2025-19719

Important: pcs security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:19719", "synopsis": "Important: pcs security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for pcs.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.\n\nSecurity Fix(es):\n\n* rubygem-rack: Rack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parameters (CVE-2025-59830)\n\n* rack: Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion) (CVE-2025-61770)\n\n* rack: Rack's multipart parser buffers large non?file fields entirely in memory, enabling DoS (memory exhaustion) (CVE-2025-61771)\n\n* rack: Rack memory exhaustion denial of service (CVE-2025-61772)\n\n* rubygem-rack: Unbounded read in `Rack::Request` form parsing can lead to memory exhaustion (CVE-2025-61919)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2398167", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2398167", "description": ""}, {"ticket": "2402174", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2402174", "description": ""}, {"ticket": "2402175", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2402175", "description": ""}, {"ticket": "2402200", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2402200", "description": ""}, {"ticket": "2403180", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2403180", "description":""}], "cves": [{"name": "CVE-2025-59830", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-59830", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-770"}, {"name": "CVE-2025-61770", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61770", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-400"}, {"name": "CVE-2025-61771", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61771", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1284"}, {"name": "CVE-2025-61772", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61772", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "cvss3BaseScore": "5.3", "cwe": "CWE-400"}, {"name": "CVE-2025-61919", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61919", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-400"}], "references": [], "publishedAt": "2025-11-05T09:00:57.474063Z", "rpms": {"Rocky Linux 8": {"nvras": ["pcs-0:0.10.18-2.el8_10.7.aarch64.rpm", "pcs-0:0.10.18-2.el8_10.7.src.rpm", "pcs-0:0.10.18-2.el8_10.7.x86_64.rpm", "pcs-snmp-0:0.10.18-2.el8_10.7.aarch64.rpm", "pcs-snmp-0:0.10.18-2.el8_10.7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A critical pcs security update for Rocky Linux 8 addresses multiple DoS issues and flaws related to memory exhaustion.. Rocky Linux, pcs security, DoS vulnerabilities, important update, memory exhaustion. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 05, 2025 Important Rocky Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200