Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
100

SUSE Munge Important Buffer Overflow Threat Update 2026-0448-1

An update that solves one vulnerability and has one security fix can now be installed.. # Security update for munge Announcement ID: SUSE-SU-2026:0448-1 Release Date: 2026-02-11T14:51:56Z Rating: important References: * bsc#1246088 * bsc#1257651 Cross-References: * CVE-2026-25506 CVSS scores: * CVE-2026-25506 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L * CVE-2026-25506 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L Affected Products: * HPC Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for munge fixes the following issues: * CVE-2026-25506: buffer overflow in message unpacking (bsc#1257651). * Make `logrotate` work on log as user `munge` to prevent local privilege escalation (bsc#1246088). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * HPC Module 12 zypper in -t patch SUSE-SLE-Module-HPC-12-2026-448=1 ## Package List: * HPC Module 12 (aarch64 x86_64) * munge-debuginfo-0.5.14-3.11.1 * munge-0.5.14-3.11.1 * libmunge2-0.5.14-3.11.1 * munge-debugsource-0.5.14-3.11.1 * munge-devel-0.5.14-3.11.1 *libmunge2-debuginfo-0.5.14-3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25506.html * https://bugzilla.suse.com/show_bug.cgi?id=1246088 * https://bugzilla.suse.com/show_bug.cgi?id=1257651 . Critical update for munge addresses buffer overflow and local escalation risks in SUSE using patch methods like zypper.. SUSE updates, munge security, buffer overflow, local privilege escalation. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 11, 2026 Important SuSE
198

ArchLinux: 202503-1: exim: privilege escalation

The package exim before version 4.98.2-1 is vulnerable to privilege escalation. . Arch Linux Security Advisory ASA-202503-1 ========================================= Severity: High Date : 2025-03-26 CVE-ID : CVE-2025-30232 Package : exim Type : privilege escalation Remote : No Link : https://security.archlinux.org/AVG-2859 Summary ======= The package exim before version 4.98.2-1 is vulnerable to privilege escalation. Resolution ========== Upgrade to 4.98.2-1. # pacman -Syu "exim> =4.98.2-1" The problem has been fixed upstream in version 4.98.2. Workaround ========== None. Description =========== A use-after-free has been discovered in exim that can lead to potential privilege escalation due to the lack of nulling out the debug_pretrigger_buf pointer before freeing the buffer by the storage management. Impact ====== A local unprivileged attacker is able to escalate privileges on the affected host. References ========== https://exim.org/static/doc/security/CVE-2025-30232.txt https://lists.exim.org/lurker/message/20250326.140105.6b97555b.en.html https://security.archlinux.org/CVE-2025-30232 . Exim prior to 4.98.2-1 on Arch Linux is vulnerable to high-severity privilege escalation. Upgrade recommended.. package, version, vulnerable, privilege, escalation, linux, security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 26, 2025 Critical ArchLinux
87

Debian 3.0: DSA 155-1 Critical: kdelibs SSL Flaw And Threats

Due to a security engineering oversight, the SSL library from KDE,which Konqueror uses, doesn't check whether an intermediatecertificate for a connection is signed by the certificate authority assafe for the purpose, but accepts it when it is signed.. -------------------------------------------------------------------------- Debian Security Advisory DSA 155-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze August 17th, 2002 Debian -- Debian security FAQ -------------------------------------------------------------------------- Package : kdelibs Vulnerability : privacy escalation with Konquerer Problem-Type : remote and local Debian-specific: no Due to a security engineering oversight, the SSL library from KDE, which Konqueror uses, doesn't check whether an intermediate certificate for a connection is signed by the certificate authority as safe for the purpose, but accepts it when it is signed. This makes it possible for anyone with a valid VeriSign SSL site certificate to forge any other VeriSign SSL site certificate, and abuse Konqueror users. A local root exploit using artsd has been discovered which exploited an insecure use of a format string. The exploit wasn't working on a Debian system since artsd wasn't running setuid root. Neither artsd nor artswrapper need to be setuid root anymore since current computer systems are fast enuogh to handle the audio data in time. Theese problems have been fixed in version 2.2.2-13.woody.2 for the current stable stable distribution (woody). The old stable distribution (potato) is not affected, since it doesn't contain KDE packages. The unstable distribution (sid) is not yet fixed, but new packages are expected in the future, the fixed version will be version 2.2.2-14 or higher. We recommend that you upgrade your kdelibs and libarts packages and restart Konquerer. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are usingthe apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody -------------------------------- Source archives: Size/MD5 checksum: 1353 6d3afab0283f8ed78182cc4cd589e3aa Size/MD5 checksum: 37757 a275d8046f3e3e55667999a9cee8da11 Size/MD5 checksum: 6396699 7a9277a2e727821338f751855c2ce5d3 Alpha architecture: Size/MD5 checksum: 7531410 f4bc703fb176dbbddbd6bbe49804ba83 Size/MD5 checksum: 137240 190891a3c0fef082ccf13773edba2421 Size/MD5 checksum: 1019270 486bd20490b9719224e196d4a841d929 ARM architecture: Size/MD5 checksum: 6587724 62dd551e38d7d05a10582a93476ad004 Size/MD5 checksum: 103294 8c220ecf60463fdaa7d760b63b66dcaa Size/MD5 checksum: 649542 92942b23b750c5a35e85799be75a0b74 Intel IA-32 architecture: Size/MD5 checksum: 6617430 93a871489d1a1f32383b0c0514545a1a Size/MD5 checksum: 104714 b289a9eb6b4533ae251c774e608fad7a Size/MD5 checksum: 622918 dd63dcfcf246d68dd7290203ec728bb9 Intel IA-64 architecture: Size/MD5 checksum: 8839684 3b3e75ab35d4f1ad784501dd846f47e2 Size/MD5 checksum: 152264 16b2767335efd8b9be6ce0c4e53591e4 Size/MD5 checksum: 1043554 aef7406f318114957c138f0c73e995b5 HP Precision architecture: Size/MD5 checksum: 7343042 9598ffafb15f6f475c9d968e7379a6f0 Size/MD5 checksum: 116182 fef2669769195ae7a0fffc8af9b3e4a6 Size/MD5 checksum: 1108370 e0451bccbfd2607437fd533a4289577a Motorola 680x0 architecture: Size/MD5 checksum: 6482780 25eea2c82ce16c02c70c20b9e8e84ed3 Size/MD5 checksum: 102350 339f2012e6d948ccdc72e86ab0c9707d Size/MD5 checksum: 626630 43d5e7580584ba1180be6d1931d7162a Big endian MIPS architecture: Size/MD5 checksum: 628248802b0ed0c55873d7dd3e164c14803bad0 Size/MD5 checksum: 105688 c4b304e33706f8c403ddd2fd7abdb4fb Size/MD5 checksum: 618968 042b025250637c2c20685426b4aa9940 Little endian MIPS architecture: Size/MD5 checksum: 6188974 75e0cb5f0accf3a19332ada0c8493d40 Size/MD5 checksum: 104638 996725d47377ddd8c3cd61e9812b8503 Size/MD5 checksum: 611868 00c1a37f7d7c73bdc905981bcc604c0f PowerPC architecture: Size/MD5 checksum: 6725896 186a74697ee20bac21ebfbd136a2d94a Size/MD5 checksum: 104784 33b024d9470b9f35c2c8a102d45f617b Size/MD5 checksum: 689064 3a4da07fdfd1d68e64384a88bc136ad2 IBM S/390 architecture: Size/MD5 checksum: 6662796 9b1eeb84d8d6434691be1c6525c3724e Size/MD5 checksum: 107204 9776b47d7a6422aebb5429d8db10121a Size/MD5 checksum: 630562 2bd1ae83bb772d2d69a414ecc7c41612 Sun Sparc architecture: Size/MD5 checksum: 6578464 f13e301c02ad68abca4463a2647967b3 Size/MD5 checksum: 116494 7509215017a945ba715d77851ebad64c Size/MD5 checksum: 662558 af629316aeec854052127c29a8c0d99c Please note that the kdelibs source package produces more binary packages than the ones listed above, which are note relevant for the fixed problems, though. These files will probably be moved into the stable distribution on its next revision. --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Advisory DSA 155-1 discusses a critical flaw in kdelibs SSL affecting user privacy and remote access risks.. kdelibs Exploit, Debian Security Advisory, SSL Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 21, 2002 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here