Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 21 articles for you...
203

Mageia ImageMagick Critical Code Injection Buffer Overflow Vuln 2026-0252

Security update. Publication date: 14 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0252.html Type: security Affected Mageia releases: 10 CVE: CVE-2026-48724, CVE-2026-48733, CVE-2026-48734, CVE-2026-49218, CVE-2026-49219, CVE-2026-48994, CVE-2026-53460, CVE-2026-53461, CVE-2026-53462, CVE-2026-53463, CVE-2026-53464, CVE-2026-53465, CVE-2026-53466, CVE-2026-53467, CVE-2026-55510, CVE-2026-55628, CVE-2026-55594, CVE-2026-55595, CVE-2026-55597, CVE-2026-25797, CVE-2026-55577 Description: The updated packages fix numerous security vulnerabilities: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797. (CVE-2026-25797) Heap Buffer Underwrite in Floyd-Steinberg depth dithering. (CVE-2026-48724) Infinite Loop in subimage-search with crafted image. (CVE-2026-48733) Stack Overflow in MVG decoder. (CVE-2026-48734) Policy Bypass in DCM decoder could result in image with invalid dimensions. (CVE-2026-49218) Policy Bypass can read disallowed files. (CVE-2026-49219) Heap Buffer Over-Write in MAT decoder on 32-bit systems. (CVE-2026-48994) Policy Bypass can trigger out-of-Memory condition. (CVE-2026-53460) Heap Buffer Over-Write in ICON decoder due to incorrect loop. (CVE-2026-53461) Use-After-Free when allocation in CheckPrimitiveExtent fails. (CVE-2026-53462) Null Pointer Dereference in distort operation when passing incorrect arguments. (CVE-2026-53463) Memory Leak in wand option parser when providing invalid arguments. (CVE-2026-53464) Heap Buffer Over-Write in SF3 encoder when writing multi-frame image. (CVE-2026-53465) Heap Buffer Over-Read in XCF decoder due to integer conversion overflow. (CVE-2026-53466) Information Disclosure in MNG decoder because allocated memory is left unchanged. (CVE-2026-53467) Use-After-Free in crafted 8BIM when identifying an image. (CVE-2026-55510) Heap Buffer Overflow in ImageMagick MVG decoder. (CVE-2026-55577) Stack Overflow in MVG decoder due to missing depthcheck. (CVE-2026-55594) Infinite Loop in connected-components when providing invalid arguments. (CVE-2026-55595) Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments. (CVE-2026-55597) Policy Bypass in concatenate operation due to missing checks. (CVE-2026-55628) References: - https://bugs.mageia.org/show_bug.cgi?id=35866 - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-2hhq-c99x-492r - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h36c-3666-h489 - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5v62-8fq6-cp9m - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gm48-c7f2-v67p - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8pj9-6897-74xc - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xcjm-wqff-m669 - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4v89-6mgq-6rgc - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-q62c-h75r-2xhc - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g22q-f7gc-5jhr - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-px7q-ggqj-hcf2 - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p9rq-q46c-g4x6 - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j989-f892-2335 - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-44cp-c3ww-9rv5 - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pjxj-pchx-4c3m - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h5r4-w88w-7ccr - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h58x-r7f7-rh84 - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m596-67p7-69wh - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r628-69v2-2f9c - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h7f2-f9cc-h2gv -https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jfq9-q63x-rc63 - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-99w9-hv66-rfv7 - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j8rh-v2r8-v94x - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7c7m-fpjw-gwcq - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6vxp-gfwf-hcr9 - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hwf3-r46v-5ggx - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8g53-9m3c-69xg - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qvxh-prvr-85w2 - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6jwg-7q3p-5fqm - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-ff5c-8x9r-8qcw - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vghg-5jrg-2398 - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-82mp-vp5c-9pf7 - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v3j6-27vc-7pw2 - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qh5g-q395-cx4j - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-c4v7-w88g-m6c4 - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hc76-7mpc-qjqh - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qhmf-7fc4-8q3h - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-56m6-8q75-f2rw - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wx47-rm3x-jx6p - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-rvhp-75f6-9jqh - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mx48-2qq3-23hf - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-76q6-2p6h-xjqr - https://www.cve.org/CVERecord?id=CVE-2026-48724 - https://www.cve.org/CVERecord?id=CVE-2026-48733 - https://www.cve.org/CVERecord?id=CVE-2026-48734 -https://www.cve.org/CVERecord?id=CVE-2026-49218 - https://www.cve.org/CVERecord?id=CVE-2026-49219 - https://www.cve.org/CVERecord?id=CVE-2026-48994 - https://www.cve.org/CVERecord?id=CVE-2026-53460 - https://www.cve.org/CVERecord?id=CVE-2026-53461 - https://www.cve.org/CVERecord?id=CVE-2026-53462 - https://www.cve.org/CVERecord?id=CVE-2026-53463 - https://www.cve.org/CVERecord?id=CVE-2026-53464 - https://www.cve.org/CVERecord?id=CVE-2026-53465 - https://www.cve.org/CVERecord?id=CVE-2026-53466 - https://www.cve.org/CVERecord?id=CVE-2026-53467 - https://www.cve.org/CVERecord?id=CVE-2026-55510 - https://www.cve.org/CVERecord?id=CVE-2026-55628 - https://www.cve.org/CVERecord?id=CVE-2026-55594 - https://www.cve.org/CVERecord?id=CVE-2026-55595 - https://www.cve.org/CVERecord?id=CVE-2026-55597 - https://www.cve.org/CVERecord?id=CVE-2026-25797 - https://www.cve.org/CVERecord?id=CVE-2026-55577 SRPMS: - 10/core/imagemagick-7.1.2.27-1.mga10 - 10/tainted/imagemagick-7.1.2.27-1.mga10.tainted . This Mageia advisory details critical updates for ImageMagick, addressing multiple security flaws impacting system integrity and stability.. imagemagick updates, mageia security, vulnerability management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 14, 2026 Critical Mageia
87

Debian: Firefox-ESR Critical Arbitrary Code Execution DSA-5980-1

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape or bypass of the same-origin policy. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5980-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff August 20, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : firefox-esr CVE ID : CVE-2025-9179 CVE-2025-9180 CVE-2025-9181 CVE-2025-9185 Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape or bypass of the same-origin policy. For the oldstable distribution (bookworm), these problems have been fixed in version 128.14.0esr-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in version 128.14.0esr-1~deb13u1. We recommend that you upgrade your firefox-esr packages. For the detailed security status of firefox-esr please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/firefox-esr Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Several vulnerabilities in Firefox-ESR need urgent patches to avert potential exploitation and bypass of security measures. Take action immediately.. Debian Security, Mozilla Firefox, Security Update, Code Execution, Policy Bypass. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 20, 2025 Critical Debian
100

SUSE: 2024:3343-1 important: kubernetes1.24 resource consumption issue

* bsc#1062303 * bsc#1194400 * bsc#1211630 * bsc#1211631 * bsc#1214406 . # Security update for kubernetes1.24 Announcement ID: SUSE-SU-2024:3343-1 Rating: important References: * bsc#1062303 * bsc#1194400 * bsc#1211630 * bsc#1211631 * bsc#1214406 * bsc#1216109 * bsc#1216123 * bsc#1219964 * bsc#1221400 * bsc#1222539 * bsc#1226136 * bsc#1229858 * bsc#1229867 * bsc#1229869 * bsc#1230323 Cross-References: * CVE-2021-25743 * CVE-2023-2727 * CVE-2023-2728 * CVE-2023-39325 * CVE-2023-44487 * CVE-2023-45288 * CVE-2024-0793 * CVE-2024-24786 * CVE-2024-3177 CVSS scores: * CVE-2021-25743 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2021-25743 ( NVD ): 3.0 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N * CVE-2023-2727 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2023-2727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2023-2728 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2023-2728 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2023-39325 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-39325 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-44487 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-44487 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45288 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-0793 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2024-24786 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-3177 ( SUSE ): 2.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2024-3177 ( NVD ): 2.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N Affected Products: * openSUSE Leap 15.3 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Server 15SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves nine vulnerabilities and has six security fixes can now be installed. ## Description: This update for kubernetes1.24 fixes the following issues: * CVE-2021-25743: escape, meta and control sequences in raw data output to terminal not neutralized. (bsc#1194400) * CVE-2023-2727: bypass of policies imposed by the ImagePolicyWebhook admission plugin. (bsc#1211630) * CVE-2023-2728: bypass of the mountable secrets policy enforced by the ServiceAccount admission plugin. (bsc#1211631) * CVE-2023-39325: go1.20: excessive resource consumption when dealing with rapid stream resets. (bsc#1229869) * CVE-2023-44487: google.golang.org/grpc, kube-apiserver: HTTP/2 rapid reset vulnerability. (bsc#1229869) * CVE-2023-45288: golang.org/x/net: excessive CPU consumption when processing unlimited sets of headers. (bsc#1229869) * CVE-2024-0793: kube-controller-manager pod crash when processing malformed HPA v1 manifests. (bsc#1219964) * CVE-2024-3177: bypass of the mountable secrets policy enforced by the ServiceAccount admission plugin. (bsc#1222539) * CVE-2024-24786: github.com/golang/protobuf: infinite loop when unmarshaling invalid JSON. (bsc#1229867) Bug fixes: * Use -trimpath in non-DBG mode for reproducible builds. (bsc#1062303) * Fix multiple issues for successful `kubeadm init` run. (bsc#1214406) * Update go to version 1.22.5 in build requirements. (bsc#1229858) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-3343=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-3343=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-3343=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-3343=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-3343=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64) * kubernetes1.24-proxy-1.24.17-150300.7.6.1 * kubernetes1.24-kubeadm-1.24.17-150300.7.6.1 * kubernetes1.24-client-common-1.24.17-150300.7.6.1 * kubernetes1.24-kubelet-common-1.24.17-150300.7.6.1 * kubernetes1.24-scheduler-1.24.17-150300.7.6.1 * kubernetes1.24-client-1.24.17-150300.7.6.1 * kubernetes1.24-kubelet-1.24.17-150300.7.6.1 * kubernetes1.24-controller-manager-1.24.17-150300.7.6.1 * kubernetes1.24-apiserver-1.24.17-150300.7.6.1 * openSUSE Leap 15.3 (noarch) * kubernetes1.24-client-fish-completion-1.24.17-150300.7.6.1 * kubernetes1.24-client-bash-completion-1.24.17-150300.7.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * kubernetes1.24-client-1.24.17-150300.7.6.1 * kubernetes1.24-client-common-1.24.17-150300.7.6.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * kubernetes1.24-client-1.24.17-150300.7.6.1 * kubernetes1.24-client-common-1.24.17-150300.7.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * kubernetes1.24-client-1.24.17-150300.7.6.1 * kubernetes1.24-client-common-1.24.17-150300.7.6.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * kubernetes1.24-client-1.24.17-150300.7.6.1 * kubernetes1.24-client-common-1.24.17-150300.7.6.1 ## References: * https://www.suse.com/security/cve/CVE-2021-25743.html * https://www.suse.com/security/cve/CVE-2023-2727.html * https://www.suse.com/security/cve/CVE-2023-2728.html * https://www.suse.com/security/cve/CVE-2023-39325.html * https://www.suse.com/security/cve/CVE-2023-44487.html *https://www.suse.com/security/cve/CVE-2023-45288.html * https://www.suse.com/security/cve/CVE-2024-0793.html * https://www.suse.com/security/cve/CVE-2024-24786.html * https://www.suse.com/security/cve/CVE-2024-3177.html * https://bugzilla.suse.com/show_bug.cgi?id=1062303 * https://bugzilla.suse.com/show_bug.cgi?id=1194400 * https://bugzilla.suse.com/show_bug.cgi?id=1211630 * https://bugzilla.suse.com/show_bug.cgi?id=1211631 * https://bugzilla.suse.com/show_bug.cgi?id=1214406 * https://bugzilla.suse.com/show_bug.cgi?id=1216109 * https://bugzilla.suse.com/show_bug.cgi?id=1216123 * https://bugzilla.suse.com/show_bug.cgi?id=1219964 * https://bugzilla.suse.com/show_bug.cgi?id=1221400 * https://bugzilla.suse.com/show_bug.cgi?id=1222539 * https://bugzilla.suse.com/show_bug.cgi?id=1226136 * https://bugzilla.suse.com/show_bug.cgi?id=1229858 * https://bugzilla.suse.com/show_bug.cgi?id=1229867 * https://bugzilla.suse.com/show_bug.cgi?id=1229869 * https://bugzilla.suse.com/show_bug.cgi?id=1230323 . Critical security patch for kubernetes 1.24 on SUSE; addresses various vulnerabilities. Update now for improved system safety.. SUSE Kubernetes Update, Security Update, Important Patches, Threat Mitigation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 19, 2024 Important SuSE
203

Mageia 9 MGASA-2024-0306: Moderate Suricata Packet Handling Issues

CVE-2024-37151 Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. CVE-2024-38534 Crafted modbus traffic can lead to unlimited resource accumulation within a flow . MGASA-2024-0306 - Updated suricata packages fix security vulnerabilities Publication date: 17 Sep 2024 URL: https://advisories.mageia.org/MGASA-2024-0306.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-37151, CVE-2024-38534, CVE-2024-38535, CVE-2024-38536 CVE-2024-37151 Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. CVE-2024-38534 Crafted modbus traffic can lead to unlimited resource accumulation within a flow CVE-2024-38535, CVE-2024-38536 Suricata can run out of memory when parsing crafted HTTP/2 traffic. References: - https://bugs.mageia.org/show_bug.cgi?id=33431 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/JJWELU75TPOICUA2UGNZDY7QQJBB7HYJ/ - https://www.cve.org/CVERecord?id=CVE-2024-37151 - https://www.cve.org/CVERecord?id=CVE-2024-38534 - https://www.cve.org/CVERecord?id=CVE-2024-38535 - https://www.cve.org/CVERecord?id=CVE-2024-38536 SRPMS: - 9/core/suricata-6.0.20-1.mga9 . Revised Nginx bundles for Fedora solve serious vulnerability concerns, tackling request processing and memory exploitation problems.. Mageia Security, Suricata Updates, Resource Management, Packet Handling, Security Fixes. . LinuxSecurity.com Team

Calendar%202 Sep 17, 2024 Mageia
172

Ubuntu 23.10: USN-6822-1 Security Alert for Node.js Policy Bypass Issues

Several security issues were fixed in Node.js.. ========================================================================== Ubuntu Security Notice USN-6822-1 June 10, 2024 nodejs vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Node.js. Software Description: - nodejs: An open-source, cross-platform JavaScript runtime environment. Details: It was discovered that Node.js incorrectly handled certain inputs when it is using the policy mechanism. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to bypass the policy mechanism. (CVE-2023-32002, CVE-2023-32006) It was discovered that Node.js incorrectly handled certain inputs when it is using the policy mechanism. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to perform a privilege escalation. (CVE-2023-32559) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10 libnode108 18.13.0+dfsg1-1ubuntu2.3 nodejs 18.13.0+dfsg1-1ubuntu2.3 Ubuntu 22.04 LTS libnode72 12.22.9~dfsg-1ubuntu3.6 nodejs 12.22.9~dfsg-1ubuntu3.6 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6822-1 CVE-2023-32002, CVE-2023-32006, CVE-2023-32559 Package Information: https://launchpad.net/ubuntu/+source/nodejs/18.13.0+dfsg1-1ubuntu2.3 https://launchpad.net/ubuntu/+source/nodejs/12.22.9~dfsg-1ubuntu3.6 . Ubuntu Security Alert USN-6822-1 pertains to security flaws in Node.js that impact several versions ofUbuntu, along with associated patches.. Ubuntu Node.js Security Updates, Node.js Vulnerabilities, Ubuntu Security Notices. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 11, 2024 Important Ubuntu
89

Fedora 40 Kubernetes Update: Resolves Policy Bypass in ServiceAccount

Update Kubernetes to v1.29.4 for Fedora 40. Resolves CVE-2024-3177: Bypassing mountable secrets policy imposed by the ServiceAccount admission plugin. Additional bug and regression fixes include a bump to Golang.org/x/net to v0.23.0 to address CVE-2023-45288 .. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ce2eefc399 2024-04-25 00:59:19.184672 -------------------------------------------------------------------------------- Name : kubernetes Product : Fedora 40 Version : 1.29.4 Release : 1.fc40 URL : https://kubernetes.io/ Summary : Open Source Production-Grade Container Scheduling And Management Platform Description : Open Source Production-Grade Container Scheduling And Management Platform Installs kubelet, the kubernetes agent on each machine in a cluster. The kubernetes-client sub-package, containing kubectl, is recommended but not strictly required. The kubernetes-client sub-package should be installed on control plane machines. -------------------------------------------------------------------------------- Update Information: Update Kubernetes to v1.29.4 for Fedora 40. Resolves CVE-2024-3177: Bypassing mountable secrets policy imposed by the ServiceAccount admission plugin. Additional bug and regression fixes include a bump to Golang.org/x/net to v0.23.0 to address CVE-2023-45288 . -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 16 2024 Bradley G Smith - 1.29.4-1 - Update to v1.29.4 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ce2eefc399' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. Moredetails on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Kubernetes upgraded to v1.29.4 on Fedora 40, addressing a policy evasion vulnerability and correcting various bugs.. Kubernetes Security Federation, Fedora Updates, Open Source Container Management, ServiceAccount Threat. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 25, 2024 Important Fedora
87

Debian Bookworm: DSA-5589-1 critical: Node.js HTTP Request Attack

Multiple vulnerabilities were discovered in Node.js, which could result in HTTP request smuggling, bypass of policy feature checks, denial of service or loading of incorrect ICU data. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5589-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff December 27, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : nodejs CVE ID : CVE-2023-23918 CVE-2023-23919 CVE-2023-23920 CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590 CVE-2023-32002 CVE-2023-32006 CVE-2023-32559 CVE-2023-38552 CVE-2023-39333 Debian Bug : 1031834 1039990 1050739 1054892 Multiple vulnerabilities were discovered in Node.js, which could result in HTTP request smuggling, bypass of policy feature checks, denial of service or loading of incorrect ICU data. For the stable distribution (bookworm), these problems have been fixed in version 18.19.0+dfsg-6~deb12u1. In addition node-undici has been updated in version 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3 to ensure compatibility with the updated Node version. We recommend that you upgrade your nodejs packages. For the detailed security status of nodejs please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/nodejs Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Stay updated on Debian DSA-5589-1 regarding security vulnerabilities in Node.js and the measures to enhance its safety and performance.. Node.js Security Update, Debian DSA-5589-1, HTTP Request SMuggling. . Severity: Critical. LinuxSecurity.comTeam

Calendar%202 Dec 27, 2023 Critical Debian
203

Mageia: 2023-0264 High Severity Nodejs Security Threats Report

This is a security release. As well, it fixes v8 headers detection (mga#28809) The following CVEs are fixed in this release: CVE-2023-32002: Policies can be bypassed via Module._load (High) . MGASA-2023-0264 - Updated nodejs packages fix security vulnerability Publication date: 24 Sep 2023 URL: https://advisories.mageia.org/MGASA-2023-0264.html Type: security Affected Mageia releases: 8, 9 CVE: CVE-2023-32002, CVE-2023-32006, CVE-2023-32559 This is a security release. As well, it fixes v8 headers detection (mga#28809) The following CVEs are fixed in this release: CVE-2023-32002: Policies can be bypassed via Module._load (High) CVE-2023-32006: Policies can be bypassed by module.constructor.createRequire (Medium) CVE-2023-32559: Policies can be bypassed via process.binding (Medium) OpenSSL Security Releases OpenSSL security advisory 14th July. OpenSSL security advisory 19th July. OpenSSL security advisory 31st July More detailed information on each of the vulnerabilities can be found in August 2023 Security Releases blog post. References: - https://bugs.mageia.org/show_bug.cgi?id=32176 - https://bugs.mageia.org/show_bug.cgi?id=28809 - https://github.com/nodejs/node/releases/tag/v18.17.1 - https://github.com/nodejs/node/releases/tag/v18.17.0 - https://www.cve.org/CVERecord?id=CVE-2023-32002 - https://www.cve.org/CVERecord?id=CVE-2023-32006 - https://www.cve.org/CVERecord?id=CVE-2023-32559 SRPMS: - 8/core/nodejs-18.17.1-1.mga8 - 9/core/nodejs-18.17.1-1.mga9 . Mageia 2023-0265 brings essential enhancements for python, tackling critical and moderate level vulnerabilities within the framework.. nodejs security update,Mageia release,security flaws,policy bypass,security fixes. . LinuxSecurity.com Team

Calendar%202 Sep 24, 2023 Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200