Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 2 articles for you...
89

Fedora 42 pgbouncer 1.25.2 Auth Query Connection Issue Fix

Update to 1.25.2.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-cf2ba5b766 2026-05-18 01:23:32.591566+00:00 -------------------------------------------------------------------------------- Name : pgbouncer Product : Fedora 42 Version : 1.25.2 Release : 1.fc42 URL : https://www.pgbouncer.org Summary : Lightweight connection pooler for PostgreSQL Description : pgbouncer is a lightweight connection pooler for PostgreSQL and uses libevent for low-level socket handling. -------------------------------------------------------------------------------- Update Information: Update to 1.25.2. -------------------------------------------------------------------------------- ChangeLog: * Sat May 9 2026 Simone Caronni - 1.25.2-1 - Update to 1.25.2 * Sat Jan 17 2026 Fedora Release Engineering - 1.25.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2419513 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2419513 [ 2 ] Bug #2419514 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2419514 [ 3 ] Bug #2419515 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2419515 [ 4 ] Bug #2419516 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2419516 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-cf2ba5b766' at thecommand line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update pgbouncer for Fedora 42 addresses critical auth_query connection issues ensuring better database security.. pgbouncer update, Fedora security, PostgreSQL connection pooling. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 18, 2026 Important Fedora
89

Fedora 43 pgbouncer Essential Untrusted Search Path Security Fix Update

Update to 1.25.2.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fad57ac86d 2026-05-18 00:58:32.597423+00:00 -------------------------------------------------------------------------------- Name : pgbouncer Product : Fedora 43 Version : 1.25.2 Release : 1.fc43 URL : https://www.pgbouncer.org Summary : Lightweight connection pooler for PostgreSQL Description : pgbouncer is a lightweight connection pooler for PostgreSQL and uses libevent for low-level socket handling. -------------------------------------------------------------------------------- Update Information: Update to 1.25.2. -------------------------------------------------------------------------------- ChangeLog: * Sat May 9 2026 Simone Caronni - 1.25.2-1 - Update to 1.25.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2419513 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2419513 [ 2 ] Bug #2419514 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2419514 [ 3 ] Bug #2419515 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2419515 [ 4 ] Bug #2419516 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2419516 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fad57ac86d' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Critical update for Fedora 43 pgbouncer addresses untrusted search path security issue with CVE-2025-12819.. Fedora 43 update, pgbouncer security fix, PostgreSQL connection pooling. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 18, 2026 Important Fedora
89

Fedora 44 Pgbouncer Security Update for Untrusted Search Path Issue 2026

Update to 1.25.2.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d3d959a176 2026-05-18 00:40:49.529053+00:00 -------------------------------------------------------------------------------- Name : pgbouncer Product : Fedora 44 Version : 1.25.2 Release : 1.fc44 URL : https://www.pgbouncer.org Summary : Lightweight connection pooler for PostgreSQL Description : pgbouncer is a lightweight connection pooler for PostgreSQL and uses libevent for low-level socket handling. -------------------------------------------------------------------------------- Update Information: Update to 1.25.2. -------------------------------------------------------------------------------- ChangeLog: * Sat May 9 2026 Simone Caronni - 1.25.2-1 - Update to 1.25.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2419513 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2419513 [ 2 ] Bug #2419514 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2419514 [ 3 ] Bug #2419515 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2419515 [ 4 ] Bug #2419516 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2419516 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d3d959a176' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Explore the details of the Fedora 44 pgbouncer update addressing the untrusted search path security issue and how to apply it.. pgbouncer connection pooling PostgreSQL Fedora update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 18, 2026 Important Fedora
197

Debian 11: PgBouncer Moderate SQL Injection Risk DLA-4422-1 CVE-2025-12819

PgBouncer is a lightweight connection pooler for PostgreSQL. CVE-2025-12819 Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4422-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Andreas Henriksson December 27, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : pgbouncer Version : 1.15.0-1+deb11u2 CVE ID : CVE-2025-12819 Debian Bug : PgBouncer is a lightweight connection pooler for PostgreSQL. CVE-2025-12819 Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage. For Debian 11 bullseye, this problem has been fixed in version 1.15.0-1+deb11u2. We recommend that you upgrade your pgbouncer packages. For the detailed security status of pgbouncer please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/pgbouncer Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . CVE-2025-12819 details a moderate risk SQL injection flaw in PgBouncer on Debian. Upgrade recommended to mitigate risk.. PgBouncer Security, Debian Security Update, SQL Injection Risk, Vulnerability Patch, PgBouncer CVE. . LinuxSecurity.com Team

Calendar 2 Dec 27, 2025 Debian LTS
197

Debian 11: DLA-4180-1 moderate: pgbouncer man-in-the-middle risks

PgBouncer is a lightweight connection pooler for PostgreSQL. CVE-2021-3539 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4180-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Andreas Henriksson May 27, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : pgbouncer Version : 1.15.0-1+deb11u1 CVE ID : CVE-2021-3935 CVE-2025-2291 Debian Bug : 1103394 PgBouncer is a lightweight connection pooler for PostgreSQL. CVE-2021-3539 When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1. CVE-2025-2291 Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password For Debian 11 bullseye, these problems have been fixed in version 1.15.0-1+deb11u1. We recommend that you upgrade your pgbouncer packages. For the detailed security status of pgbouncer please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/pgbouncer Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu LTS USN-5283-1 addresses vulnerabilities in apache2, including denial of service risks and potential privilege escalation.. pgbouncer, Debian, security advisory, PostgreSQL, authentication flaw. . LinuxSecurity.com Team

Calendar 2 May 27, 2025 Debian LTS
89

Fedora 42: Critical Security Advisory for pgbouncer Version 1.24.1

Update to 1.24.1, fixes CVE-2025-2291.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-25e04398c7 2025-04-25 02:11:13.705492+00:00 -------------------------------------------------------------------------------- Name : pgbouncer Product : Fedora 42 Version : 1.24.1 Release : 2.fc42 URL : https://www.pgbouncer.org Summary : Lightweight connection pooler for PostgreSQL Description : pgbouncer is a lightweight connection pooler for PostgreSQL and uses libevent for low-level socket handling. -------------------------------------------------------------------------------- Update Information: Update to 1.24.1, fixes CVE-2025-2291. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 17 2025 Simone Caronni - 1.24.1-2 - Update license * Thu Apr 17 2025 Simone Caronni - 1.24.1-1 - Update to 1.24.1 (CVE-2025-2291) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-25e04398c7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives:https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . -------------------------------------------------------------------------------- Fedora Update Notif. update, fixes, cve-2025-2291, -------------------------------------------------------------. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 25, 2025 Critical Fedora
89

Fedora 40: FEDORA-2025-31397c2b6c critical: pgbouncer DoS Risk

Update to 1.24.1, fixes CVE-2025-2291.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-31397c2b6c 2025-04-25 01:58:58.477104+00:00 -------------------------------------------------------------------------------- Name : pgbouncer Product : Fedora 40 Version : 1.24.1 Release : 2.fc40 URL : https://www.pgbouncer.org Summary : Lightweight connection pooler for PostgreSQL Description : pgbouncer is a lightweight connection pooler for PostgreSQL and uses libevent for low-level socket handling. -------------------------------------------------------------------------------- Update Information: Update to 1.24.1, fixes CVE-2025-2291. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 17 2025 Simone Caronni - 1.24.1-2 - Update license * Thu Apr 17 2025 Simone Caronni - 1.24.1-1 - Update to 1.24.1 (CVE-2025-2291) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-31397c2b6c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives:https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Linux Mint 21.1 introduces significant patch for sshd, tackling security flaw in remote access and enhancing system integrity.. Fedora pgbouncer fix, PostgreSQL connection pooler, security patch, Fedora security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 25, 2025 Critical Fedora
89

Fedora 41: 1.24.1 moderate: pgbouncer connection pooling fix

Update to 1.24.1, fixes CVE-2025-2291.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-d919f11f99 2025-04-25 01:47:40.996759+00:00 -------------------------------------------------------------------------------- Name : pgbouncer Product : Fedora 41 Version : 1.24.1 Release : 2.fc41 URL : https://www.pgbouncer.org Summary : Lightweight connection pooler for PostgreSQL Description : pgbouncer is a lightweight connection pooler for PostgreSQL and uses libevent for low-level socket handling. -------------------------------------------------------------------------------- Update Information: Update to 1.24.1, fixes CVE-2025-2291. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 17 2025 Simone Caronni - 1.24.1-2 - Update license * Thu Apr 17 2025 Simone Caronni - 1.24.1-1 - Update to 1.24.1 (CVE-2025-2291) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-d919f11f99' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives:https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 41 pgbouncer 1.24.1 release addresses critical vulnerabilities tied to CVE-2025-2291. Enhance the security of your PostgreSQL connections today.. Fedora 41, pgbouncer, PostgreSQL, CVE-2025-2291, connection pooling. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 25, 2025 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here