Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
172

Ubuntu 22.04 LTS Kernel Update USN-8275-1 Privilege Escalation

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-8275-1 May 19, 2026 linux-xilinx-zynqmp vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-xilinx-zynqmp: Linux kernel for Xilinx ZynqMP processors Details: Stonejiajia, Shir Tamari and Sagi Tzadik discovered that the OverlayFS implementation in the Ubuntu Linux kernel did not properly perform permission checks in certain situations. A local attacker could possibly use this to gain elevated privileges. (CVE-2023-2640) Shir Tamari and Sagi Tzadik discovered that the OverlayFS implementation in the Ubuntu Linux kernel did not properly perform permission checks in certain situations. A local attacker could possibly use this to gain elevated privileges. (CVE-2023-32629) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Block layer subsystem; - Drivers core; - Bluetooth drivers; - DMA engine subsystem; - GPU drivers; - HID subsystem; - Intel Trace Hub HW tracing drivers; - IIO ADC drivers; - IRQ chip drivers; - Modular ISDN driver; - LED subsystem; - UACCE accelerator framework; - Ethernet bonding driver; - Network drivers; - STMicroelectronics network drivers; - Ethernet team driver; - NVME drivers; - PHY drivers; - SLIMbus drivers; - W1 Dallas's 1-wire bus driver; - Xen hypervisor drivers; - BTRFS file system; - Ext4 file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NTFS3 file system; - SMB network file system; - NFC subsystem; - BPF subsystem; - IRQ subsystem; - Memorymanagement; - Bluetooth subsystem; - CAN network layer; - Networking core; - IPv4 networking; - IPv6 networking; - L2TP protocol; - NET/ROM layer; - Network traffic control; - SCTP protocol; - TLS protocol; - XFRM subsystem; - Creative Sound Blaster X-Fi driver; - USB sound devices; (CVE-2023-53421, CVE-2023-53520, CVE-2023-53662, CVE-2023-54207, CVE-2025-38057, CVE-2025-38125, CVE-2025-38232, CVE-2025-38408, CVE-2025-38591, CVE-2025-40149, CVE-2025-40164, CVE-2025-68211, CVE-2025-68340, CVE-2025-68365, CVE-2025-68725, CVE-2025-68817, CVE-2025-71162, CVE-2025-71163, CVE-2025-71185, CVE-2025-71186, CVE-2025-71188, CVE-2025-71190, CVE-2025-71191, CVE-2025-71194, CVE-2025-71196, CVE-2025-71197, CVE-2025-71199, CVE-2026-22997, CVE-2026-22998, CVE-2026-22999, CVE-2026-23001, CVE-2026-23003, CVE-2026-23011, CVE-2026-23026, CVE-2026-23033, CVE-2026-23037, CVE-2026-23038, CVE-2026-23049, CVE-2026-23056, CVE-2026-23058, CVE-2026-23061, CVE-2026-23063, CVE-2026-23064, CVE-2026-23071, CVE-2026-23073, CVE-2026-23075, CVE-2026-23076, CVE-2026-23078, CVE-2026-23080, CVE-2026-23083, CVE-2026-23084, CVE-2026-23085, CVE-2026-23087, CVE-2026-23089, CVE-2026-23090, CVE-2026-23091, CVE-2026-23093, CVE-2026-23095, CVE-2026-23096, CVE-2026-23097, CVE-2026-23098, CVE-2026-23099, CVE-2026-23101, CVE-2026-23103, CVE-2026-23105, CVE-2026-23108, CVE-2026-23112, CVE-2026-23119, CVE-2026-23120, CVE-2026-23121, CVE-2026-23124, CVE-2026-23125, CVE-2026-23128, CVE-2026-23133, CVE-2026-23145, CVE-2026-23146, CVE-2026-23150, CVE-2026-23164, CVE-2026-23167, CVE-2026-23170, CVE-2026-23209, CVE-2026-23273) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1070-xilinx-zynqmp 5.15.0-1070.74 linux-image-xilinx-zynqmp 5.15.0.1070.73 linux-image-xilinx-zynqmp-5.15 5.15.0.1070.73 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABIchange the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8275-1 CVE-2023-2640, CVE-2023-32629, CVE-2023-53421, CVE-2023-53520, CVE-2023-53662, CVE-2023-54207, CVE-2025-38057, CVE-2025-38125, CVE-2025-38232, CVE-2025-38408, CVE-2025-38591, CVE-2025-40149, CVE-2025-40164, CVE-2025-68211, CVE-2025-68340, CVE-2025-68365, CVE-2025-68725, CVE-2025-68817, CVE-2025-71162, CVE-2025-71163, CVE-2025-71185, CVE-2025-71186, CVE-2025-71188, CVE-2025-71190, CVE-2025-71191, CVE-2025-71194, CVE-2025-71196, CVE-2025-71197, CVE-2025-71199, CVE-2026-22997, CVE-2026-22998, CVE-2026-22999, CVE-2026-23001, CVE-2026-23003, CVE-2026-23011, CVE-2026-23026, CVE-2026-23033, CVE-2026-23037, CVE-2026-23038, CVE-2026-23049, CVE-2026-23056, CVE-2026-23058, CVE-2026-23061, CVE-2026-23063, CVE-2026-23064, CVE-2026-23071, CVE-2026-23073, CVE-2026-23075, CVE-2026-23076, CVE-2026-23078, CVE-2026-23080, CVE-2026-23083, CVE-2026-23084, CVE-2026-23085, CVE-2026-23087, CVE-2026-23089, CVE-2026-23090, CVE-2026-23091, CVE-2026-23093, CVE-2026-23095, CVE-2026-23096, CVE-2026-23097, CVE-2026-23098, CVE-2026-23099, CVE-2026-23101, CVE-2026-23103, CVE-2026-23105, CVE-2026-23108, CVE-2026-23112, CVE-2026-23119, CVE-2026-23120, CVE-2026-23121, CVE-2026-23124, CVE-2026-23125, CVE-2026-23128, CVE-2026-23133, CVE-2026-23145, CVE-2026-23146, CVE-2026-23150, CVE-2026-23164, CVE-2026-23167, CVE-2026-23170, CVE-2026-23209, CVE-2026-23273 Package Information: https://launchpad.net/ubuntu/+source/linux-xilinx-zynqmp/5.15.0-1070.74 . Severe security issues fixed in Ubuntu's Linux kernel for Xilinx ZynqMP processors requiring immediate attention.. XilinxZynqMP Linux Kernel, Ubuntu Security Notice, Kernel Update Instructions, Security Vulnerability Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 19, 2026 Important Ubuntu
172

Ubuntu 20.04 LTS USN-6349-1: Critical Linux Kernel Denial of Service

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-6349-1 September 06, 2023 linux-azure vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-azure: Linux kernel for Microsoft Azure Cloud systems Details: Ruihan Li discovered that the bluetooth subsystem in the Linux kernel did not properly perform permissions checks when handling HCI sockets. A physically proximate attacker could use this to cause a denial of service (bluetooth communication). (CVE-2023-2002) Zi Fan Tan discovered that the binder IPC implementation in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-21255) Juan Jose Lopez Jaimez, Meador Inge, Simon Scannell, and Nenad Stojanovski discovered that the BPF verifier in the Linux kernel did not properly mark registers for precision tracking in certain situations, leading to an out- of-bounds access vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-2163) Zheng Zhang discovered that the device-mapper implementation in the Linux kernel did not properly handle locking during table_clear() operations. A local attacker could use this to cause a denial of service (kernel deadlock). (CVE-2023-2269) It was discovered that the DVB Core driver in the Linux kernel did not properly handle locking events in certain situations. A local attacker could use this to cause a denial of service (kernel deadlock). (CVE-2023-31084) It was discovered that the kernel-> user space relay implementation in the Linux kernel didnot properly perform certain buffer calculations, leading to an out-of-bounds read vulnerability. A local attacker could use this to cause a denial of service (system crash) or expose sensitive information (kernel memory). (CVE-2023-3268) It was discovered that the video4linux driver for Philips based TV cards in the Linux kernel contained a race condition during device removal, leading to a use-after-free vulnerability. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-35823) It was discovered that the SDMC DM1105 PCI device driver in the Linux kernel contained a race condition during device removal, leading to a use- after-free vulnerability. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-35824) It was discovered that the Renesas USB controller driver in the Linux kernel contained a race condition during device removal, leading to a use- after-free vulnerability. A privileged attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-35828) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: linux-image-5.4.0-1115-azure 5.4.0-1115.122 linux-image-azure-lts-20.04 5.4.0.1115.108 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-6349-1 CVE-2023-2002, CVE-2023-21255, CVE-2023-2163, CVE-2023-2269, CVE-2023-31084, CVE-2023-3268, CVE-2023-35823, CVE-2023-35824, CVE-2023-35828 Package Information: https://launchpad.net/ubuntu/+source/linux-azure/5.4.0-1115.122 . Critical patches released for Ubuntu 20.04 LTS targeting various kernel flaws impacting Azure environments.. Azure Linux Kernel Security, Ubuntu Kernel Update, Denial of Service Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 06, 2023 Critical Ubuntu
172

Ubuntu 22.04 LTS USN-6260-1 Critical: Kernel Denial Of Service Risks

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-6260-1 July 27, 2023 linux-aws-5.19, linux-gcp-5.19, linux-hwe-5.19 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-aws-5.19: Linux kernel for Amazon Web Services (AWS) systems - linux-gcp-5.19: Linux kernel for Google Cloud Platform (GCP) systems - linux-hwe-5.19: Linux hardware enablement (HWE) kernel Details: It was discovered that the NTFS file system implementation in the Linux kernel did not properly check buffer indexes in certain situations, leading to an out-of-bounds read vulnerability. A local attacker could possibly use this to expose sensitive information (kernel memory). (CVE-2022-48502) Stonejiajia, Shir Tamari and Sagi Tzadik discovered that the OverlayFS implementation in the Ubuntu Linux kernel did not properly perform permission checks in certain situations. A local attacker could possibly use this to gain elevated privileges. (CVE-2023-2640) It was discovered that the IP-VLAN network driver for the Linux kernel did not properly initialize memory in some situations, leading to an out-of- bounds write vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-3090) Mingi Cho discovered that the netfilter subsystem in the Linux kernel did not properly validate the status of a nft chain while performing a lookup by id, leading to a use-after-free vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-31248) It was discovered that the Ricoh R5C592 MemoryStick card reader driver in the Linux kernel contained a racecondition during module unload, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-3141) Shir Tamari and Sagi Tzadik discovered that the OverlayFS implementation in the Ubuntu Linux kernel did not properly perform permission checks in certain situations. A local attacker could possibly use this to gain elevated privileges. (CVE-2023-32629) Querijn Voet discovered that a race condition existed in the io_uring subsystem in the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-3389) It was discovered that the netfilter subsystem in the Linux kernel did not properly handle some error conditions, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-3390) Tanguy Dubroca discovered that the netfilter subsystem in the Linux kernel did not properly handle certain pointer data type, leading to an out-of- bounds write vulnerability. A privileged attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-35001) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: linux-image-5.19.0-1029-aws 5.19.0-1029.30~22.04.1 linux-image-5.19.0-1030-gcp 5.19.0-1030.32~22.04.1 linux-image-5.19.0-50-generic 5.19.0-50.50 linux-image-5.19.0-50-generic-64k 5.19.0-50.50 linux-image-5.19.0-50-generic-lpae 5.19.0-50.50 linux-image-aws 5.19.0.1029.30~22.04.13 linux-image-gcp 5.19.0.1030.32~22.04.2 linux-image-generic-64k-hwe-22.04 5.19.0.50.22 linux-image-generic-hwe-22.04 5.19.0.50.22 linux-image-generic-lpae-hwe-22.04 5.19.0.50.22 linux-image-virtual-hwe-22.04 5.19.0.50.22 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-6260-1 CVE-2022-48502, CVE-2023-2640, CVE-2023-3090, CVE-2023-31248, CVE-2023-3141, CVE-2023-32629, CVE-2023-3389, CVE-2023-3390, CVE-2023-35001 Package Information: https://launchpad.net/ubuntu/+source/linux-aws-5.19/5.19.0-1029.30~22.04.1 https://launchpad.net/ubuntu/+source/linux-gcp-5.19/5.19.0-1030.32~22.04.1 https://launchpad.net/ubuntu/+source/linux-hwe-5.19/5.19.0-50.50 . Numerous weaknesses discovered in the Linux kernel for Ubuntu; please upgrade rapidly to maintain system integrity and safeguarding.. Linux Kernel, Ubuntu Security, Kernel Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 27, 2023 Critical Ubuntu
89

Fedora 33: FEDORA-2020-64859a826b Critical: Xen Permissions Issues

xenstore watch notifications lacking permission checks [XSA-115, CVE-2020-29480] (#1908091) Xenstore: new domains inheriting existing node permissions [XSA-322, CVE-2020-29481] (#1908095) Xenstore: wrong path length check [XSA-323, CVE-2020-29482] (#1908096) Xenstore: guests can crash xenstored via watchs [XSA-324, CVE-2020-29484] (#1908088) Xenstore: guests can disturb domain cleanup. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-64859a826b 2020-12-25 01:21:55.445209 --------------------------------------------------------------------------------Name : xen Product : Fedora 33 Version : 4.14.0 Release : 14.fc33 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor --------------------------------------------------------------------------------Update Information: xenstore watch notifications lacking permission checks [XSA-115, CVE-2020-29480] (#1908091) Xenstore: new domains inheriting existing node permissions [XSA-322, CVE-2020-29481] (#1908095) Xenstore: wrong path length check [XSA-323, CVE-2020-29482] (#1908096) Xenstore: guests can crash xenstored via watchs [XSA-324, CVE-2020-29484] (#1908088) Xenstore: guests can disturb domain cleanup [XSA-325, CVE-2020-29483] (#1908087) oxenstored memory leak in reset_watches [XSA-330, CVE-2020-29485] (#1908000) undue recursion in x86 HVM context switch code [XSA-348, CVE-2020-29566] (#1908085) oxenstored: node ownership can be changed by unprivileged clients [XSA-352, CVE-2020-29486] (#1908003) oxenstored: permissions not checked on root node [XSA-353, CVE-2020-29479] (#1908002) infinite loop when cleaning up IRQ vectors [XSA-356, CVE-2020-29567] (#1907932) FIFO event channels control block related ordering [XSA-358, CVE-2020-29570] (#1907931) FIFO event channels controlstructure ordering [XSA-359, CVE-2020-29571] (#1908089) --------------------------------------------------------------------------------ChangeLog: * Tue Dec 15 2020 Michael Young - 4.14.0-14 - xenstore watch notifications lacking permission checks [XSA-115, CVE-2020-29480] (#1908091) - Xenstore: new domains inheriting existing node permissions [XSA-322, CVE-2020-29481] (#1908095) - Xenstore: wrong path length check [XSA-323, CVE-2020-29482] (#1908096) - Xenstore: guests can crash xenstored via watchs [XSA-324, CVE-2020-29484] (#1908088) - Xenstore: guests can disturb domain cleanup [XSA-325, CVE-2020-29483] (#1905648) - oxenstored memory leak in reset_watches [XSA-330, CVE-2020-29485] (#1908000) - undue recursion in x86 HVM context switch code [XSA-348, CVE-2020-29566] (#1908085) - oxenstored: node ownership can be changed by unprivileged clients [XSA-352, CVE-2020-29486] (#1908003) - oxenstored: permissions not checked on root node [XSA-353, CVE-2020-29479] (#1908003) - infinite loop when cleaning up IRQ vectors [XSA-356, CVE-2020-29567] (#1907932) - FIFO event channels control block related ordering [XSA-358, CVE-2020-29570] (#1907931) - FIFO event channels control structure ordering [XSA-359, CVE-2020-29571] (#1908089) * Sat Dec 5 2020 Jeff Law - 4.14.0-13 - Work around another gcc-11 stringop-overflow diagnostic --------------------------------------------------------------------------------References: [ 1 ] Bug #1905623 - CVE-2020-29485 xen: oxenstored memory leak in reset_watches (XSA-330) https://bugzilla.redhat.com/show_bug.cgi?id=1905623 [ 2 ] Bug #1905626 - CVE-2020-29482 xen: Xenstore: wrong path length check (XSA-323) https://bugzilla.redhat.com/show_bug.cgi?id=1905626 [ 3 ] Bug #1905632 - CVE-2020-29481 xen: Xenstore: new domains inheriting existing node permissions (XSA-322) https://bugzilla.redhat.com/show_bug.cgi?id=1905632 [ 4 ] Bug #1905635 - CVE-2020-29484 xen: Xenstore: guests can crash xenstored viawatchs (XSA-324) https://bugzilla.redhat.com/show_bug.cgi?id=1905635 [ 5 ] Bug #1905648 - CVE-2020-29483 xen: Xenstore: guests can disturb domain cleanup (XSA-325) https://bugzilla.redhat.com/show_bug.cgi?id=1905648 [ 6 ] Bug #1905652 - CVE-2020-29486 xen: oxenstored: node ownership can be changed by unprivileged clients (XSA-352) https://bugzilla.redhat.com/show_bug.cgi?id=1905652 [ 7 ] Bug #1905656 - CVE-2020-29567 xen: infinite loop when cleaning up IRQ vectors (XSA-356) https://bugzilla.redhat.com/show_bug.cgi?id=1905656 [ 8 ] Bug #1905668 - CVE-2020-29479 xen: oxenstored: permissions not checked on root node (XSA-353) https://bugzilla.redhat.com/show_bug.cgi?id=1905668 [ 9 ] Bug #1905669 - CVE-2020-29566 xen: undue recursion in x86 HVM context switch code (XSA-348) https://bugzilla.redhat.com/show_bug.cgi?id=1905669 [ 10 ] Bug #1905672 - CVE-2020-29480 xen: xenstore watch notifications lacking permission checks (XSA-115) https://bugzilla.redhat.com/show_bug.cgi?id=1905672 [ 11 ] Bug #1905675 - CVE-2020-29570 xen: FIFO event channels control block related ordering (XSA-358) https://bugzilla.redhat.com/show_bug.cgi?id=1905675 [ 12 ] Bug #1905676 - CVE-2020-29571 xen: FIFO event channels control structure ordering https://bugzilla.redhat.com/show_bug.cgi?id=1905676 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-64859a826b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Important Fedora 33 patch for Xen addresses significant security vulnerabilities regarding access permissions and additional aspects for virtualization platforms.. Xen Security,Fedora Xen Update,Virtual Machine Monitor,Crash Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 24, 2020 Critical Fedora
172

Ubuntu 20.04 LTS: USN-4576-1 Critical: Linux Kernel Denial of Service

Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-4576-1 October 14, 2020 linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-azure: Linux kernel for Microsoft Azure Cloud systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-kvm: Linux kernel for cloud environments - linux-oracle: Linux kernel for Oracle Cloud systems - linux-raspi: Linux kernel for Raspberry Pi (V8) systems - linux-aws-5.4: Linux kernel for Amazon Web Services (AWS) systems - linux-azure-5.4: Linux kernel for Microsoft Azure cloud systems - linux-gcp-5.4: Linux kernel for Google Cloud Platform (GCP) systems - linux-hwe-5.4: Linux hardware enablement (HWE) kernel - linux-oracle-5.4: Linux kernel for Oracle Cloud systems - linux-raspi-5.4: Linux kernel for Raspberry Pi (V8) systems Details: Hador Manor discovered that the DCCP protocol implementation in the Linux kernel improperly handled socket reuse, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-16119) Jay Shin discovered that the ext4 file system implementation in the Linux kernel did not properly handle directory access with broken indexing, leading to an out-of-bounds read vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2020-14314) David Alan Gilbert discovered that the XFS file systemimplementation in the Linux kernel did not properly perform metadata validation in some circumstances. A local attacker could use this to cause a denial of service. (CVE-2020-14385) Giuseppe Scrivano discovered that the overlay file system in the Linux kernel did not properly perform permission checks in some situations. A local attacker could possibly use this to bypass intended restrictions and gain read access to restricted files. (CVE-2020-16120) It was discovered that a race condition existed in the hugetlb sysctl implementation in the Linux kernel. A privileged attacker could use this to cause a denial of service (system crash). (CVE-2020-25285) It was discovered that the block layer subsystem in the Linux kernel did not properly handle zero-length requests. A local attacker could use this to cause a denial of service. (CVE-2020-25641) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: linux-image-5.4.0-1021-raspi 5.4.0-1021.24 linux-image-5.4.0-1026-kvm 5.4.0-1026.27 linux-image-5.4.0-1028-aws 5.4.0-1028.29 linux-image-5.4.0-1028-gcp 5.4.0-1028.29 linux-image-5.4.0-1028-oracle 5.4.0-1028.29 linux-image-5.4.0-1031-azure 5.4.0-1031.32 linux-image-5.4.0-51-generic 5.4.0-51.56 linux-image-5.4.0-51-generic-lpae 5.4.0-51.56 linux-image-5.4.0-51-lowlatency 5.4.0-51.56 linux-image-aws 5.4.0.1028.29 linux-image-azure 5.4.0.1031.29 linux-image-gcp 5.4.0.1028.36 linux-image-generic 5.4.0.51.54 linux-image-generic-hwe-20.04 5.4.0.51.54 linux-image-generic-lpae 5.4.0.51.54 linux-image-generic-lpae-hwe-20.04 5.4.0.51.54 linux-image-gke 5.4.0.1028.36 linux-image-kvm 5.4.0.1026.24 linux-image-lowlatency 5.4.0.51.54 linux-image-lowlatency-hwe-20.04 5.4.0.51.54 linux-image-oem 5.4.0.51.54 linux-image-oem-osp1 5.4.0.51.54 linux-image-oracle 5.4.0.1028.25 linux-image-raspi 5.4.0.1021.56 linux-image-raspi2 5.4.0.1021.56 linux-image-virtual 5.4.0.51.54 linux-image-virtual-hwe-20.04 5.4.0.51.54 Ubuntu 18.04 LTS: linux-image-5.4.0-1021-raspi 5.4.0-1021.24~18.04.1 linux-image-5.4.0-1028-aws 5.4.0-1028.29~18.04.1 linux-image-5.4.0-1028-gcp 5.4.0-1028.29~18.04.1 linux-image-5.4.0-1028-oracle 5.4.0-1028.29~18.04.1 linux-image-5.4.0-1031-azure 5.4.0-1031.32~18.04.1 linux-image-5.4.0-51-generic 5.4.0-51.56~18.04.1 linux-image-5.4.0-51-generic-lpae 5.4.0-51.56~18.04.1 linux-image-5.4.0-51-lowlatency 5.4.0-51.56~18.04.1 linux-image-aws 5.4.0.1028.13 linux-image-azure 5.4.0.1031.13 linux-image-gcp 5.4.0.1028.16 linux-image-generic-hwe-18.04 5.4.0.51.56~18.04.45 linux-image-generic-lpae-hwe-18.04 5.4.0.51.56~18.04.45 linux-image-lowlatency-hwe-18.04 5.4.0.51.56~18.04.45 linux-image-oracle 5.4.0.1028.12 linux-image-raspi-hwe-18.04 5.4.0.1021.25 linux-image-snapdragon-hwe-18.04 5.4.0.51.56~18.04.45 linux-image-virtual-hwe-18.04 5.4.0.51.56~18.04.45 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4576-1 CVE-2020-14314, CVE-2020-14385, CVE-2020-16119, CVE-2020-16120, CVE-2020-25285, CVE-2020-25641 Package Information: https://launchpad.net/ubuntu/+source/linux/5.4.0-51.56 https://launchpad.net/ubuntu/+source/linux-aws/5.4.0-1028.29 https://launchpad.net/ubuntu/+source/linux-azure/5.4.0-1031.32 https://launchpad.net/ubuntu/+source/linux-kvm/5.4.0-1026.27 https://launchpad.net/ubuntu/+source/linux-raspi/5.4.0-1021.24 https://launchpad.net/ubuntu/+source/linux-azure-5.4/5.4.0-1031.32~18.04.1 https://launchpad.net/ubuntu/+source/linux-gcp-5.4/5.4.0-1028.29~18.04.1 https://launchpad.net/ubuntu/+source/linux-hwe-5.4/5.4.0-51.56~18.04.1 https://launchpad.net/ubuntu/+source/linux-oracle-5.4/5.4.0-1028.29~18.04.1 https://launchpad.net/ubuntu/+source/linux-raspi-5.4/5.4.0-1021.24~18.04.1 . Multiple kernel vulnerabilities were patched in Ubuntu 20.04 and 18.04 LTS, improving overall security and system reliability.. Ubuntu Security Notice, Linux Kernel Security, AWS Linux Kernel. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 13, 2020 Critical Ubuntu
172

Ubuntu: 12.10, 12.04 LTS, 11.10, 10.04 LTS: Critical Django Issues

Several security issues were fixed in Django.. =========================================================================Ubuntu Security Notice USN-1757-1 March 07, 2013 python-django vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.10 - Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 10.04 LTS Summary: Several security issues were fixed in Django. Software Description: - python-django: High-level Python web development framework Details: James Kettle discovered that Django did not properly filter the Host HTTP header when processing certain requests. An attacker could exploit this to generate and display arbitrary URLs to users. Although this issue had been previously addressed in USN-1632-1, this update adds additional hardening measures to host header validation. This update also adds a new ALLOWED_HOSTS setting that can be set to a list of acceptable values for headers. (CVE-2012-4520) Orange Tsai discovered that Django incorrectly performed permission checks when displaying the history view in the admin interface. An administrator could use this flaw to view the history of any object, regardless of intended permissions. (CVE-2013-0305) It was discovered that Django incorrectly handled a large number of forms when generating formsets. An attacker could use this flaw to cause Django to consume memory, resulting in a denial of service. (CVE-2013-0306) It was discovered that Django incorrectly deserialized XML. An attacker could use this flaw to perform entity-expansion and external-entity/DTD attacks. This updated modified Django behaviour to no longer allow DTDs, perform entity expansion, or fetch external entities/DTDs. (CVE-2013-1664, CVE-2013-1665) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: python-django 1.4.1-2ubuntu0.3 Ubuntu12.04 LTS: python-django 1.3.1-4ubuntu1.6 Ubuntu 11.10: python-django 1.3-2ubuntu1.6 Ubuntu 10.04 LTS: python-django 1.1.1-2ubuntu1.8 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1757-1 CVE-2012-4520, CVE-2013-0305, CVE-2013-0306, CVE-2013-1664, CVE-2013-1665 Package Information: https://launchpad.net/ubuntu/+source/python-django/1.4.1-2ubuntu0.3 https://launchpad.net/ubuntu/+source/python-django/1.3.1-4ubuntu1.6 https://launchpad.net/ubuntu/+source/python-django/1.3-2ubuntu1.6 https://launchpad.net/ubuntu/+source/python-django/1.1.1-2ubuntu1.8 . Django has released security patches that rectify several vulnerabilities. The update guidelines are provided for numerous Ubuntu distributions.. Django Security Updates, Python-Django Issues, Ubuntu Vulnerability Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 07, 2013 Critical Ubuntu
200

Scientific Linux: CVE-2012-1682 Critical: Java Runtime Permission Issue

Critical: java-1.6.0-openjdk security update. Date: Tue, 4 Sep 2012 11:14:13 -0500 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Critical: java-1.6.0-openjdk on SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Critical: java-1.6.0-openjdk security update Issue Date: 2012-09-03 CVE Numbers: CVE-2012-1682 CVE-2012-0547 These packages provide the OpenJDK 6 Java Runtime Environment and the OpenJDK 6 Software Development Kit. It was discovered that the Beans component in OpenJDK did not perform permission checks properly. An untrusted Java application or applet could use this flaw to use classes from restricted packages, allowing it to bypass Java sandbox restrictions. (CVE-2012-1682) A hardening fix was applied to the AWT component in OpenJDK, removing functionality from the restricted SunToolkit class that was used in combination with other flaws to bypass Java sandbox restrictions. (CVE-2012-0547) Note: If the web browser plug-in provided by the icedtea-web package was installed, the issues exposed via Java applets could have been exploited without user interaction if a user visited a malicious website. This erratum also upgrades the OpenJDK package to IcedTea6 1.11.4. All users of java-1.6.0-openjdk are advised to upgrade to these updated packages, which resolve these issues. All running instances of OpenJDK Java must be restarted for the update to take effect. SL6 x86_64 java-1.6.0-openjdk-1.6.0.0-1.49.1.11.4.el6_3.x86_64.rpm java-1.6.0-openjdk-demo-1.6.0.0-1.49.1.11.4.el6_3.x86_64.rpm java-1.6.0-openjdk-devel-1.6.0.0-1.49.1.11.4.el6_3.x86_64.rpm java-1.6.0-openjdk-javadoc-1.6.0.0-1.49.1.11.4.el6_3.x86_64.rpm java-1.6.0-openjdk-src-1.6.0.0-1.49.1.11.4.el6_3.x86_64.rpm i386 java-1.6.0-openjdk-1.6.0.0-1.49.1.11.4.el6_3.i686.rpm java-1.6.0-openjdk-demo-1.6.0.0-1.49.1.11.4.el6_3.i686.rpm java-1.6.0-openjdk-devel-1.6.0.0-1.49.1.11.4.el6_3.i686.rpm java-1.6.0-openjdk-javadoc-1.6.0.0-1.49.1.11.4.el6_3.i686.rpm java-1.6.0-openjdk-src-1.6.0.0-1.49.1.11.4.el6_3.i686.rpm - Scientific Linux Development Team . Urgent security patch for java-1.6.0-openjdk tackling major validation oversight vulnerabilities.. Java Update, Security Erratum, SL6 Java Runtime, OpenJDK Patch, Critical Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 04, 2012 Critical Scientific Linux
98

Red Hat: RHSA-2012-0677-01 Moderate: PostgreSQL Security Fix

Updated postgresql packages that fix two security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: postgresql security update Advisory ID: RHSA-2012:0677-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2012:0677.html Issue date: 2012-05-21 CVE Names: CVE-2012-0866 CVE-2012-0868 ==================================================================== 1. Summary: Updated postgresql packages that fix two security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 3. Description: PostgreSQL is an advanced object-relational database management system (DBMS). The pg_dump utility inserted object names literally into comments in the SQL script it produces. An unprivileged database user could create an object whose name includes a newline followed by an SQL command. This SQL command might then be executed by a privileged user during later restore of the backup dump, allowing privilege escalation. (CVE-2012-0868) CREATE TRIGGER did not do a permissions check on the trigger function to be called. This could possibly allow an authenticated database user to call a privileged trigger function on data of theirchoosing. (CVE-2012-0866) All PostgreSQL users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. If the postgresql service is running, it will be automatically restarted after installing this update. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 797222 - CVE-2012-0866 postgresql: Absent permission checks on trigger function to be called when creating a trigger 797917 - CVE-2012-0868 postgresql: SQL injection due unsanitized newline characters in object names 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: postgresql-8.1.23-4.el5_8.i386.rpm postgresql-contrib-8.1.23-4.el5_8.i386.rpm postgresql-debuginfo-8.1.23-4.el5_8.i386.rpm postgresql-docs-8.1.23-4.el5_8.i386.rpm postgresql-libs-8.1.23-4.el5_8.i386.rpm postgresql-python-8.1.23-4.el5_8.i386.rpm postgresql-tcl-8.1.23-4.el5_8.i386.rpm x86_64: postgresql-8.1.23-4.el5_8.x86_64.rpm postgresql-contrib-8.1.23-4.el5_8.x86_64.rpm postgresql-debuginfo-8.1.23-4.el5_8.i386.rpm postgresql-debuginfo-8.1.23-4.el5_8.x86_64.rpm postgresql-docs-8.1.23-4.el5_8.x86_64.rpm postgresql-libs-8.1.23-4.el5_8.i386.rpm postgresql-libs-8.1.23-4.el5_8.x86_64.rpm postgresql-python-8.1.23-4.el5_8.x86_64.rpm postgresql-tcl-8.1.23-4.el5_8.x86_64.rpm RHEL Desktop Workstation (v. 5client): Source: i386: postgresql-debuginfo-8.1.23-4.el5_8.i386.rpm postgresql-devel-8.1.23-4.el5_8.i386.rpm postgresql-pl-8.1.23-4.el5_8.i386.rpm postgresql-server-8.1.23-4.el5_8.i386.rpm postgresql-test-8.1.23-4.el5_8.i386.rpm x86_64: postgresql-debuginfo-8.1.23-4.el5_8.i386.rpm postgresql-debuginfo-8.1.23-4.el5_8.x86_64.rpm postgresql-devel-8.1.23-4.el5_8.i386.rpm postgresql-devel-8.1.23-4.el5_8.x86_64.rpm postgresql-pl-8.1.23-4.el5_8.x86_64.rpm postgresql-server-8.1.23-4.el5_8.x86_64.rpm postgresql-test-8.1.23-4.el5_8.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: postgresql-8.1.23-4.el5_8.i386.rpm postgresql-contrib-8.1.23-4.el5_8.i386.rpm postgresql-debuginfo-8.1.23-4.el5_8.i386.rpm postgresql-devel-8.1.23-4.el5_8.i386.rpm postgresql-docs-8.1.23-4.el5_8.i386.rpm postgresql-libs-8.1.23-4.el5_8.i386.rpm postgresql-pl-8.1.23-4.el5_8.i386.rpm postgresql-python-8.1.23-4.el5_8.i386.rpm postgresql-server-8.1.23-4.el5_8.i386.rpm postgresql-tcl-8.1.23-4.el5_8.i386.rpm postgresql-test-8.1.23-4.el5_8.i386.rpm ia64: postgresql-8.1.23-4.el5_8.ia64.rpm postgresql-contrib-8.1.23-4.el5_8.ia64.rpm postgresql-debuginfo-8.1.23-4.el5_8.i386.rpm postgresql-debuginfo-8.1.23-4.el5_8.ia64.rpm postgresql-devel-8.1.23-4.el5_8.ia64.rpm postgresql-docs-8.1.23-4.el5_8.ia64.rpm postgresql-libs-8.1.23-4.el5_8.i386.rpm postgresql-libs-8.1.23-4.el5_8.ia64.rpm postgresql-pl-8.1.23-4.el5_8.ia64.rpm postgresql-python-8.1.23-4.el5_8.ia64.rpm postgresql-server-8.1.23-4.el5_8.ia64.rpm postgresql-tcl-8.1.23-4.el5_8.ia64.rpm postgresql-test-8.1.23-4.el5_8.ia64.rpm ppc: postgresql-8.1.23-4.el5_8.ppc.rpm postgresql-8.1.23-4.el5_8.ppc64.rpm postgresql-contrib-8.1.23-4.el5_8.ppc.rpm postgresql-debuginfo-8.1.23-4.el5_8.ppc.rpm postgresql-debuginfo-8.1.23-4.el5_8.ppc64.rpm postgresql-devel-8.1.23-4.el5_8.ppc.rpm postgresql-devel-8.1.23-4.el5_8.ppc64.rpm postgresql-docs-8.1.23-4.el5_8.ppc.rpm postgresql-libs-8.1.23-4.el5_8.ppc.rpm postgresql-libs-8.1.23-4.el5_8.ppc64.rpm postgresql-pl-8.1.23-4.el5_8.ppc.rpm postgresql-python-8.1.23-4.el5_8.ppc.rpm postgresql-server-8.1.23-4.el5_8.ppc.rpm postgresql-tcl-8.1.23-4.el5_8.ppc.rpm postgresql-test-8.1.23-4.el5_8.ppc.rpm s390x: postgresql-8.1.23-4.el5_8.s390x.rpm postgresql-contrib-8.1.23-4.el5_8.s390x.rpm postgresql-debuginfo-8.1.23-4.el5_8.s390.rpm postgresql-debuginfo-8.1.23-4.el5_8.s390x.rpm postgresql-devel-8.1.23-4.el5_8.s390.rpm postgresql-devel-8.1.23-4.el5_8.s390x.rpm postgresql-docs-8.1.23-4.el5_8.s390x.rpm postgresql-libs-8.1.23-4.el5_8.s390.rpm postgresql-libs-8.1.23-4.el5_8.s390x.rpm postgresql-pl-8.1.23-4.el5_8.s390x.rpm postgresql-python-8.1.23-4.el5_8.s390x.rpm postgresql-server-8.1.23-4.el5_8.s390x.rpm postgresql-tcl-8.1.23-4.el5_8.s390x.rpm postgresql-test-8.1.23-4.el5_8.s390x.rpm x86_64: postgresql-8.1.23-4.el5_8.x86_64.rpm postgresql-contrib-8.1.23-4.el5_8.x86_64.rpm postgresql-debuginfo-8.1.23-4.el5_8.i386.rpm postgresql-debuginfo-8.1.23-4.el5_8.x86_64.rpm postgresql-devel-8.1.23-4.el5_8.i386.rpm postgresql-devel-8.1.23-4.el5_8.x86_64.rpm postgresql-docs-8.1.23-4.el5_8.x86_64.rpm postgresql-libs-8.1.23-4.el5_8.i386.rpm postgresql-libs-8.1.23-4.el5_8.x86_64.rpm postgresql-pl-8.1.23-4.el5_8.x86_64.rpm postgresql-python-8.1.23-4.el5_8.x86_64.rpm postgresql-server-8.1.23-4.el5_8.x86_64.rpm postgresql-tcl-8.1.23-4.el5_8.x86_64.rpm postgresql-test-8.1.23-4.el5_8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2012-0866 https://access.redhat.com/security/cve/CVE-2012-0868 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2012 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFPuniMXlSAg2UNWIIRAnEFAJsHEqIwbTv34djIrCFzTgZKLvQ+bQCcC/li MIPNfyIUQhp+R//KWA/422g=7uqX -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Oracle has issued a patch for MySQL tackling two significant vulnerabilities. Safeguard your databases accordingly.. PostgreSQL Security Update, Red Hat Advisory, Database Security. . LinuxSecurity.com Team

Calendar%202 May 21, 2012 Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200