Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 28 articles for you...
203

Mageia 9 PuTTY Critical Signature Failure Double Free CVE-2026-4115

Security update. Publication date: 15 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0210.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-4115 Description: ECDSA signature verification can be made to fail an assertion. Server can provoke a double free in RSA KEX code. Telnet session data is marked with trust sigils after authenticating to a proxy. PuTTY Ed25519 Signature ecc-ssh.c eddsa_verify signature verification. (CVE-2026-4115) References: - https://bugs.mageia.org/show_bug.cgi?id=35585 - https://www.openwall.com/lists/oss-security/2026/05/24/11 - https://lists.tartarus.org/pipermail/putty-announce/2026/000042.html - https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/rsakex-double-free.html - https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/telnet-trust-sigil.html - https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/eddsa-overlarge-s.html - https://www.cve.org/CVERecord?id=CVE-2026-4115 SRPMS: - 9/core/putty-0.84-1.mga9 . Critical security update for Mageia 9 addressing multiple issues in PuTTY due to signature failures and memory errors.. Mageia security update, PuTTY vulnerabilities, ECDSA issues, critical security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 15, 2026 Critical Mageia
89

Fedora 43 Putty Important Fix for Security Issues 2026-61f53cc218

This is an update fixing several security related problems in putty.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-61f53cc218 2026-06-10 01:08:28.182994+00:00 -------------------------------------------------------------------------------- Name : putty Product : Fedora 43 Version : 0.84 Release : 1.fc43 URL : http://www.chiark.greenend.org.uk/~sgtatham/putty/ Summary : SSH, Telnet and Rlogin client Description : Putty is a SSH, Telnet & Rlogin client - this time for Linux. -------------------------------------------------------------------------------- Update Information: This is an update fixing several security related problems in putty. -------------------------------------------------------------------------------- ChangeLog: * Mon May 25 2026 Jaroslav Škarvada - 0.84-1 - New version Resolves: rhbz#2480724 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2480724 - putty-0.84 is available https://bugzilla.redhat.com/show_bug.cgi?id=2480724 [ 2 ] Bug #2481658 - CVE-2026-48850 putty: double free vulnerability in RSA KEX code [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481658 [ 3 ] Bug #2481659 - CVE-2026-48851 putty: TELNET session data is marked with trust sigils after authenticating to a proxy [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481659 [ 4 ] Bug #2481662 - CVE-2026-48852 putty: assertion failure in ECDSA signature verification [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481662 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-61f53cc218' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update addresses security issues in Putty on Fedora 43, ensuring safer remote connections and data integrity.. Putty Update, Fedora Security, SSH Client Upgrade, Putty Security Fix, Fedora Vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 09, 2026 Important Fedora
89

Fedora 44 Putty Important Fix for Double Free Vulnerability 2026-1ab61e6e20

This is an update fixing several security related problems in putty.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-1ab61e6e20 2026-06-10 00:54:41.795258+00:00 -------------------------------------------------------------------------------- Name : putty Product : Fedora 44 Version : 0.84 Release : 1.fc44 URL : http://www.chiark.greenend.org.uk/~sgtatham/putty/ Summary : SSH, Telnet and Rlogin client Description : Putty is a SSH, Telnet & Rlogin client - this time for Linux. -------------------------------------------------------------------------------- Update Information: This is an update fixing several security related problems in putty. -------------------------------------------------------------------------------- ChangeLog: * Mon May 25 2026 Jaroslav Škarvada - 0.84-1 - New version Resolves: rhbz#2480724 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2480724 - putty-0.84 is available https://bugzilla.redhat.com/show_bug.cgi?id=2480724 [ 2 ] Bug #2481658 - CVE-2026-48850 putty: double free vulnerability in RSA KEX code [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481658 [ 3 ] Bug #2481659 - CVE-2026-48851 putty: TELNET session data is marked with trust sigils after authenticating to a proxy [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481659 [ 4 ] Bug #2481662 - CVE-2026-48852 putty: assertion failure in ECDSA signature verification [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481662 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1ab61e6e20' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fixes multiple security issues in Putty, ensuring safer SSH sessions in Fedora 44. Update now!. Putty update Fedora security SSH. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 09, 2026 Important Fedora
202

Significant security update for Putty now available in openSUSE Leap 16-0

An update that solves various issues can now be installed.. openSUSE security update: security update for putty ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20851-1 Rating: important Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves various issues can now be installed. Description: This update for putty fixes the following issues: Changes in putty: - Update to release 0.84 * Fixed a remotely triggerable double-free in RSA key exchange. * Fixed a remotely triggerable crash (assertion failure - program termination) in NIST ECDSA signature verification. * Fixed marking of Telnet and Rlogin session data with a trust sigil after you authenticated to a proxy (possibly allowing a server to spoof a repeat proxy password prompt). * New ability to run a specified command before starting the connection, e.g. to perform wake-on-LAN or a port knock. * Display 'pre-edit text', showing the progress of using multiple keystrokes to compose a single Unicode character. * Improved support for to running the GUI tools on Wayland (fixed startup issues and tuned performance). * Configuring a SSH certificate authority used to fail unless you manually made a config directory, now fixed. * Fixed a spurious "Network error: Socket is not connected" when authenticating to some HTTP proxies. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-281=1 Package List: - openSUSE Leap 16.0: putty-0.84-bp160.1.1 . OpenSUSE security update fixes critical putty issues, enhancing remote access functionality with patch installation instructions.. openSUSE putty security update, important software fixes, remoteaccess vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 01, 2026 Important OpenSUSE
202

openSUSE Putty Important Program Crash Fix Advisory 2026-20851-1

An update that solves various issues can now be installed.. openSUSE security update: security update for putty ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20851-1 Rating: important Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves various issues can now be installed. Description: This update for putty fixes the following issues: Changes in putty: - Update to release 0.84 * Fixed a remotely triggerable double-free in RSA key exchange. * Fixed a remotely triggerable crash (assertion failure - program termination) in NIST ECDSA signature verification. * Fixed marking of Telnet and Rlogin session data with a trust sigil after you authenticated to a proxy (possibly allowing a server to spoof a repeat proxy password prompt). * New ability to run a specified command before starting the connection, e.g. to perform wake-on-LAN or a port knock. * Display 'pre-edit text', showing the progress of using multiple keystrokes to compose a single Unicode character. * Improved support for to running the GUI tools on Wayland (fixed startup issues and tuned performance). * Configuring a SSH certificate authority used to fail unless you manually made a config directory, now fixed. * Fixed a spurious "Network error: Socket is not connected" when authenticating to some HTTP proxies. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-281=1 Package List: - openSUSE Leap 16.0: putty-0.84-bp160.1.1 . Update for openSUSE Leap 16.0 addressing important security flaws in Putty ensuring stable connections.. openSUSE security, putty patch, important update, software stability. . Severity: Important.LinuxSecurity.com Team

Calendar%202 Jun 01, 2026 Important OpenSUSE
197

Debian LTS DLA-3839-1 Critical: Putty ECDSA Key Compromise Risk

A biased ECDSA nonce generation allowed an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. In other words, an adversary may already have enough signature information to compromise a victim's . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3839-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès June 20, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : putty Version : 0.74-1+deb11u1~deb10u2 CVE ID : CVE-2024-31497 A biased ECDSA nonce generation allowed an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. In other words, an adversary may already have enough signature information to compromise a victim's private key, even if there is no further use of vulnerable PuTTY versions. This allowed an attacker to (for instance) log in to any servers the victim uses that key for. To obtain these signatures, an attacker need only briefly compromise any server the victim uses the key to authenticate to. Therefore, if you have any NIST-P521 ECDSA key, we strongly recommend you to replace it with a freshly new created with a fixed version of putty. Then, to revoke the old public key and remove it from any machine where you use it to login into, so that a signature from the compromised key has no value any more. The only affected key type is 521-bit ECDSA. That is, a key that appears in Windows PuTTYgen with ecdsa-sha2-nistp521 at the start of the 'Key fingerprint' box, or is described as 'NIST p521', or has an id starting ecdsa-sha2-nistp521 in the SSH protocol or the key file. Other sizes of ECDSA, and other key algorithms, are unaffected. In particular, Ed25519 is not affected. For Debian 10 buster, this problem has been fixed in version 0.74-1+deb11u1~deb10u2. Werecommend that you upgrade your putty packages. For the detailed security status of putty please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/putty Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-1234-1 addresses vulnerabilities in OpenSSH that jeopardize RSA key integrity under specific conditions.. Putty Security, Debian LTS Advisory, ECDSA Attack, NIST P-521 Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 20, 2024 Critical Debian LTS
197

Debian LTS DLA-3794-1 Critical: Putty SSH Threat Remediation

Putty, a Telnet/SSH client for X, was vulnerable. CVE-2019-17069 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3794-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès April 25, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : putty Version : 0.74-1+deb11u1~deb10u1 CVE ID : CVE-2019-17069 CVE-2020-14002 CVE-2021-36367 CVE-2023-48795 Debian Bug : 990901 Putty, a Telnet/SSH client for X, was vulnerable. CVE-2019-17069 PuTTY allowed remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNECT message. CVE-2020-14002 PuTTY had an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allowed man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). CVE-2021-36367 PuTTY proceeded with establishing an SSH session even if it has never sent a substantive authentication response. This made it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user). CVE-2023-48795 PuTTY was vulnerable to Terrapin attack. The SSH transport protocol with certain OpenSSH extensions, allowed remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. Forexample, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305 and (if CBC is used) the -etm MAC algorithms. For Debian 10 buster, this problem has been fixed in version 0.74-1+deb11u1~deb10u1. We recommend that you upgrade your putty packages. For the detailed security status of putty please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/putty Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3794-1 addresses critical security vulnerabilities in PuTTY, urging users to upgrade promptly to safeguard their data integrity. putty updates, debian security, SSH client, remote access, Linux security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 25, 2024 Critical Debian LTS
202

openSUSE: 2024:0111-2 Critical: Putty Vulnerability Fix

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for putty ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0111-1 Rating: important References: Cross-References: CVE-2024-31497 Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for putty fixes the following issues: Update to release 0.81 * Fix CVE-2024-31497: NIST P521 / ecdsa-sha2-nistp521 signatures are no longer generated with biased values of k. The previous bias compromises private keys. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-111=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): putty-0.81-bp155.2.6.1 References: https://www.suse.com/security/cve/CVE-2024-31497.html . This crucial software patch for WinSCP tackles vulnerabilities and guarantees enhanced protection for your system. Update today!. openSUSE Security Update, Putty Advisory, Important Security Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 19, 2024 Important OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200