Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 490
Alerts This Week
Warning Icon 1 490

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":2,"type":"x","order":2,"pct":66.67,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 3 articles for you...
203

Mageia Krita-AI-Diffusion Critical Plugin Connection Issue 2026-0062

An update for Mageia 10 addresses a connectivity issue with the plugin and upgrades it to version 1.52.1, improving functionality for downloading models.. Publication date: 23 Jul 2026 URL: https://advisories.mageia.org/MGAA-2026-0062.html Type: bugfix Affected Mageia releases: 10 Description: The plugin can't connect to server to download models. This update fixes the reported issue and updates the plugin to version 1.52.1. References: - https://bugs.mageia.org/show_bug.cgi?id=35955 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.52.1 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.52.0 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.51.1 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.51.0 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.50.0 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.49.1 SRPMS: - 10/core/krita-ai-diffusion-1.52.1-1.mga10 . Krita-AI-Diffusion update for Mageia fixes plugin issue and enhances functionality with new release version.. Krita-AI-Diffusion, Mageia security advisory, plugin update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 23, 2026 Critical Mageia
172

Ubuntu 20.04 LTS GStreamer Base Significant DoS Attack Vulnerability Alert

GStreamer Base Plugins could be made to crash or run programs if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-8130-2 June 02, 2026 gst-plugins-base1.0 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: GStreamer Base Plugins could be made to crash or run programs if it opened a specially crafted file. Software Description: - gst-plugins-base1.0: GStreamer plugins Details: USN-8130-1 fixed a vulnerability in GStreamer Base Plugins. This update provides the corresponding update for Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. Original advisory details: It was discovered that GStreamer Base Plugins incorrectly handled certain AVI media files. A remote attacker could use this issue to cause GStreamer Base Plugins to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS gstreamer1.0-plugins-base 1.16.3-0ubuntu1.4+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS gstreamer1.0-plugins-base 1.14.5-0ubuntu1~18.04.3+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8130-2 https://ubuntu.com/security/notices/USN-8130-1 CVE-2026-2921 . GStreamer Base Plugins in Ubuntu could crash or execute arbitrary code with specially crafted files. Update recommended.. GStreamer Security Ubuntu, Plugin Denial of Service, Ubuntu Update Recommendations. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 03, 2026 Important Ubuntu
197

Debian 10 Buster DLA-3645-1: Moderate DoS in Apache Traffic Server

Two vulnerabilities were fixed in Apache Traffic Server, a reverse and forward proxy server. CVE-2023-41752 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3645-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk November 05, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : trafficserver Version : 8.1.7-0+deb10u3 CVE ID : CVE-2023-41752 CVE-2023-44487 Debian Bug : 1054427 Two vulnerabilities were fixed in Apache Traffic Server, a reverse and forward proxy server. CVE-2023-41752 s3_auth plugin exposes AWSAccessKeyId CVE-2023-44487 HTTP/2 Rapid Reset denial of service For Debian 10 buster, these problems have been fixed in version 8.1.7-0+deb10u3. We recommend that you upgrade your trafficserver packages. For the detailed security status of trafficserver please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/trafficserver Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Two vulnerabilities addressed in Apache Traffic Server for Debian LTS, with patches now accessible. Upgrade is advised.. Debian Traffic Server, Apache Proxy Security, s3_auth Plugin Fix. . LinuxSecurity.com Team

Calendar%202 Nov 05, 2023 Debian LTS
197

Debian 10 Buster: DLA-3069-1 Critical GStreamer Plugin Issues

Multiple vulnerabilities were discovered in plugins for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3069-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sebastian Dro"ge August 09, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : gst-plugins-good1.0 Version : 1.14.4-1+deb10u2 CVE ID : CVE-2022-1920 CVE-2022-1921 CVE-2022-1922 CVE-2022-1923 CVE-2022-1924 CVE-2022-1925 CVE-2022-2122 Multiple vulnerabilities were discovered in plugins for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened. For Debian 10 buster, these problems have been fixed in version 1.14.4-1+deb10u2. We recommend that you upgrade your gst-plugins-good1.0 packages. For the detailed security status of gst-plugins-good1.0 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/gst-plugins-good1.0 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A series of security flaws in GStreamer components fixed in Debian LTS DLA-3069-1. Update promptly to mitigate potential threats.. GStreamer Media Plugins, Debian LTS, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 09, 2022 Critical Debian LTS
197

Debian: DLA-2643-1 Critical: GStreamer Plugin DoS Advisory

Multiple vulnerabilities were discovered in plugins for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2643-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort April 27, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : gst-plugins-ugly1.0 Version : 1.10.4-1+deb9u1 CVE ID : not yet available Multiple vulnerabilities were discovered in plugins for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened. For Debian 9 stretch, this problem has been fixed in version 1.10.4-1+deb9u1. We recommend that you upgrade your gst-plugins-ugly1.0 packages. For the detailed security status of gst-plugins-ugly1.0 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/gst-plugins-ugly1.0 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Announcement regarding the gst-plugins-ugly1.0 package in Debian LTS, focusing on several critical security vulnerabilities and potential threats related to code execution.. gst-plugins, Media Framework, Debian LTS. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 27, 2021 Critical Debian LTS
89

Fedora 28 Anki: FEDORA-2018-50039f6b61 Critical: .apkg Import Issue

Update to new upstream release 2.0.50. * fix a security issue in .apkg imports * fix a problem with plugin download * use python send2trash module from system * use correct shebang for python2 * upstream changelog: . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-50039f6b61 2018-04-17 00:11:16.755305 --------------------------------------------------------------------------------Name : anki Product : Fedora 28 Version : 2.0.50 Release : 1.fc28 URL : https://apps.ankiweb.net/ Summary : Flashcard program for using space repetition learning Description : Anki is a program designed to help you remember facts (such as words and phrases in a foreign language) as easily, quickly and efficiently as possible. Anki is based on a theory called spaced repetition. --------------------------------------------------------------------------------Update Information: Update to new upstream release 2.0.50. * fix a security issue in .apkg imports * fix a problem with plugin download * use python send2trash module from system * use correct shebang for python2 * upstream changelog: --------------------------------------------------------------------------------References: [ 1 ] Bug #1529540 - anki: Security issue in .apkg imports fixed in 2.0.47 https://bugzilla.redhat.com/show_bug.cgi?id=1529540 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade anki' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest Anki update, version 2.0.50, resolves security vulnerabilities in .apkg file imports and corrects issues related to downloading plugins.. Fedora Updates, Anki Security, Software Patches, Flashcard Software. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 17, 2018 Critical Fedora
87

Debian: DSA-4038-1 Critical: Shibboleth Service Provider Coding Error

Rod Widdowson of Steading System Software LLP discovered a coding error in the "Dynamic" metadata plugin of the Shibboleth Service Provider, causing the plugin to fail configuring itself with the filters provided and omitting whatever checks they are intended to perform. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4038-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso November 16, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : shibboleth-sp2 CVE ID : CVE-2017-16852 Debian Bug : 881857 Rod Widdowson of Steading System Software LLP discovered a coding error in the "Dynamic" metadata plugin of the Shibboleth Service Provider, causing the plugin to fail configuring itself with the filters provided and omitting whatever checks they are intended to perform. For the oldstable distribution (jessie), this problem has been fixed in version 2.5.3+dfsg-2+deb8u1. For the stable distribution (stretch), this problem has been fixed in version 2.6.0+dfsg1-4+deb9u1. We recommend that you upgrade your shibboleth-sp2 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Uncover the vital security patch for the Shibboleth Service Provider that tackles a programming flaw along with suggested resolutions.. Debian Shibboleth Update, Security Advisory, Software Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 16, 2017 Critical Debian
89

Fedora: 2016-a3bc78de2b Moderate: GStreamer Memory Corruption Issue

vmncdec: Sanity-check width/height before using it ---- Remove insecure nsf plugin (#1395126). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-a3bc78de2b 2016-12-15 23:54:24.668228 -------------------------------------------------------------------------------- Name : gstreamer-plugins-bad-free Product : Fedora 24 Version : 0.10.23 Release : 34.fc24 URL : https://gstreamer.freedesktop.org/ Summary : GStreamer streaming media framework "bad" plug-ins Description : GStreamer is a streaming media framework, based on graphs of elements which operate on media data. This package contains plug-ins that aren't tested well enough, or the code is not of good enough quality. -------------------------------------------------------------------------------- Update Information: vmncdec: Sanity-check width/height before using it ---- Remove insecure nsf plugin (#1395126) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1395126 - CVE-2016-9447 gstreamer-plugins-bad-free: Memory corruption flaw in NSF decoder https://bugzilla.redhat.com/show_bug.cgi?id=1395126 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade gstreamer-plugins-bad-free' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Caution advised forFedora 24 regarding gstreamer-plugins-bad-free over critical memory vulnerability, raising risk of exploitation.. Gstreamer Security, Fedora Update, Media Framework Issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 16, 2016 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":2,"type":"x","order":2,"pct":66.67,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200