Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 14 articles for you...
202

openSUSE Security Advisory: python311-oauthlib-3.2.2-5.4 Moderate Risk

An update that solves one vulnerability can now be installed.. # python311-oauthlib-3.2.2-5.4 on GA media Announcement ID: openSUSE-SU-2025:15100-1 Rating: moderate Cross-References: * CVE-2022-36087 CVSS scores: * CVE-2022-36087 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the python311-oauthlib-3.2.2-5.4 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * python311-oauthlib 3.2.2-5.4 * python312-oauthlib 3.2.2-5.4 * python313-oauthlib 3.2.2-5.4 ## References: * https://www.suse.com/security/cve/CVE-2022-36087.html . Security notice for openSUSE highlighting a moderate threat in python311-oauthlib linked to CVE-2022-36087. Find specifics below.. openSUSE security, python library updates, supply chain security. . LinuxSecurity.com Team

Calendar%202 May 18, 2025 OpenSUSE
89

Fedora 41: FEDORA-2025-cd87acc644 moderate: python-pydantic-core update

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-cd87acc644 2025-04-21 16:44:59.680841+00:00 -------------------------------------------------------------------------------- Name : python-pydantic-core Product : Fedora 41 Version : 2.27.2 Release : 5.fc41 URL : https://github.com/pydantic/pydantic-core Summary : Core validation logic for pydantic written in rust Description : The pydantic-core project provides the core validation logic for pydantic written in Rust. -------------------------------------------------------------------------------- Update Information: Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9. Update rust-zip to 2.6.1, fixing GHSA-94vh-gphv-8pm8. -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 11 2025 Benjamin A. Beasley - 2.27.2-5 - Rebuilt with idna 1.x; no longer allow older idna versions * Fri Apr 11 2025 Benjamin A. Beasley - 2.27.2-4 - Expect maturin to handle license files * Sat Jan 18 2025 Fedora Release Engineering - 2.27.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Thu Dec 26 2024 Benjamin A. Beasley - 2.27.2-2 - Omit snapshot tests on EPEL10 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2277901 - rust-adblock-0.9.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2277901 [ 2 ] Bug #2291175 - rust-idna-1.0.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2291175 [ 3 ] Bug #2323618 - rust-url-2.5.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2323618 [ 4 ] Bug #2324926 - rust-cookie_store-0.21.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2324926 [ 5 ] Bug #2352783 - rust-zip-2.6.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2352783 [ 6 ] Bug #2358015 - Review Request: rust-write16 - UTF-16 analog of the Write trait https://bugzilla.redhat.com/show_bug.cgi?id=2358015 [ 7 ] Bug #2358018 - Review Request: rust-utf16_iter - Iterator by char over potentially-invalid UTF-16 in &[u16] https://bugzilla.redhat.com/show_bug.cgi?id=2358018 [ 8 ] Bug #2358020 - Review Request: rust-icu_locid - API for managing Unicode Language and Locale Identifiers https://bugzilla.redhat.com/show_bug.cgi?id=2358020 [ 9 ] Bug #2358105 - Review Request: rust-icu_provider_macros - Proc macros for ICU data providers https://bugzilla.redhat.com/show_bug.cgi?id=2358105 [ 10 ] Bug #2358290 - Review Request: rust-icu_provider - Trait and struct definitions for the ICU data provider https://bugzilla.redhat.com/show_bug.cgi?id=2358290 [ 11 ] Bug #2358292 - Review Request: rust-icu_locid_transform_data - Data for the icu_locid_transform crate https://bugzilla.redhat.com/show_bug.cgi?id=2358292 [ 12 ] Bug #2358507 - Review Request: rust-icu_locid_transform - API for Unicode Language and Locale Identifiers canonicalization https://bugzilla.redhat.com/show_bug.cgi?id=2358507 [ 13 ] Bug #2358521 - Review Request: rust-icu_properties_data - Data for the icu_properties crate https://bugzilla.redhat.com/show_bug.cgi?id=2358521 [ 14 ] Bug #2358522 - Review Request: rust-icu_normalizer_data - Data for the icu_normalizer crate https://bugzilla.redhat.com/show_bug.cgi?id=2358522 [ 15 ] Bug #2358527 - Review Request: rust-icu_properties - Definitions for Unicode properties https://bugzilla.redhat.com/show_bug.cgi?id=2358527 [ 16 ] Bug #2358606 - Review Request: rust-icu_normalizer - API for normalizing text into Unicode Normalization Forms https://bugzilla.redhat.com/show_bug.cgi?id=2358606 [ 17 ] Bug #2358642 - Review Request: rust-idna_adapter - Back end adapter for idna https://bugzilla.redhat.com/show_bug.cgi?id=2358642 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-cd87acc644' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Delve into the recent advancements with Fedora 41, showcasing numerous bug resolutions and improvements for python-pydantic-core.. Fedora updates, python-pydantic-core, rust library, security advisory, bug fix. . LinuxSecurity.com Team

Calendar%202 Apr 21, 2025 Fedora
89

Fedora 41 python-spotipy 2.25.1: CVE-2025-27154 DoS threat

update to version 2.25.1, CVE-2025-27154. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-fba1b24e4b 2025-03-08 01:23:45.593648+00:00 -------------------------------------------------------------------------------- Name : python-spotipy Product : Fedora 41 Version : 2.25.1 Release : 1.fc41 URL : https://github.com/spotipy-dev/spotipy Summary : A light weight Python library for the Spotify Web API Description : A light weight Python library for the Spotify Web API -------------------------------------------------------------------------------- Update Information: update to version 2.25.1, CVE-2025-27154 -------------------------------------------------------------------------------- ChangeLog: * Thu Feb 27 2025 Bill Pemberton - 2.25.1-1 - update to version 2.25.1 * Sat Jan 18 2025 Fedora Release Engineering - 2.25.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2348684 - python-spotipy-2.25.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2348684 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-fba1b24e4b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Fedora 41 has released a security notice for python-spotipy version 2.25.1, which addresses the critical CVE-2025-27154 vulnerability, urging users to update to enhance security. Fedora, python-spotipy, security updates, security advisory, CVE issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 08, 2025 Critical Fedora
87

Debian DSA-5704-1 Critical: Pillow Software Denial of Service Risk

Multiple security issues were discovered in Pillow, a Python imaging library, which could result in denial of service or the execution of arbitrary code if malformed images are processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5704-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff June 05, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : pillow CVE ID : CVE-2023-44271 CVE-2023-50447 CVE-2024-28219 Multiple security issues were discovered in Pillow, a Python imaging library, which could result in denial of service or the execution of arbitrary code if malformed images are processed. For the oldstable distribution (bullseye), these problems have been fixed in version 8.1.2+dfsg-0.3+deb11u2. For the stable distribution (bookworm), these problems have been fixed in version 9.4.0-1.1+deb12u1. We recommend that you upgrade your pillow packages. For the detailed security status of pillow please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/pillow Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Pillow, the popular Python Imaging Library, has critical security vulnerabilities impacting systems using Debian. This advisory highlights key issues and fixes.. Pillow Security, Debian Advisory, Python Library Update, Image Processing Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 05, 2024 Critical Debian
202

openSUSE: 2024:0125-1 important: python-Pillow code execution

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for python-Pillow ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0125-1 Rating: important References: #1219048 Cross-References: CVE-2023-50447 CVSS scores: CVE-2023-50447 (NVD) : 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2023-50447 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-Pillow fixes the following issues: - CVE-2023-50447: Fixed arbitrary code execution via the environment parameter (boo#1219048) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-125=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): python3-Pillow-8.4.0-bp155.3.3.1 python3-Pillow-tk-8.4.0-bp155.3.3.1 References: https://www.suse.com/security/cve/CVE-2023-50447.html https://bugzilla.suse.com/1219048 . openSUSE Security Notice: Security patch available for python-Pillow Notification ID: openSUSE-SU-2024:0451-2. Python Pillow Update, openSUSE Security Fix, Code Execution Risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 13, 2024 Important OpenSUSE
89

Fedora 39: 2024-6d1d9f70d2 critical: fonttools XML Injection

Security fix for CVE-2023-45139. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-6d1d9f70d2 2024-01-25 00:38:48.210927 -------------------------------------------------------------------------------- Name : fonttools Product : Fedora 39 Version : 4.43.1 Release : 1.fc39 URL : https://github.com/fonttools/fonttools/ Summary : Tools to manipulate font files Description : fontTools is a library for manipulating fonts, written in Python. The project includes the TTX tool, that can convert TrueType and OpenType fonts to and from an XML text format, which is also called TTX. It supports TrueType, OpenType, AFM and to an extent Type 1 and some Mac-specific formats. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-45139 -------------------------------------------------------------------------------- ChangeLog: * Sun Oct 8 2023 Parag Nemade - 4.43.1-1 - Update to 4.43.1 version (#2241574) * Tue Aug 22 2023 Parag Nemade - 4.42.1-1 - Update to 4.42.1 version (#2232931) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2257808 - CVE-2023-45139 fonttools: XML External Entity Injection (XXE) Vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=2257808 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-6d1d9f70d2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Keep updated on CVE-2023-45139 impacting fonttools in Fedora 39; ensure you upgrade for safeguarding against security risks.. Fonttools Security Fix, XXE Vulnerability Advisory, Fedora Software Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 25, 2024 Critical Fedora
89

Fedora 36: 2023-7ed04fe4a7 Moderate: Certifi Library Trust Issue

Update to 2022.12.7, fixes CVE-2022-23491.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-7ed04fe4a7 2023-03-30 01:14:14.931077 --------------------------------------------------------------------------------Name : mingw-python-certifi Product : Fedora 36 Version : 2022.12.7 Release : 1.fc36 URL : https://certifi.io/ Summary : MinGW Windows Python certifi library Description : MinGW Windows Python certifi. --------------------------------------------------------------------------------Update Information: Update to 2022.12.7, fixes CVE-2022-23491. --------------------------------------------------------------------------------ChangeLog: * Tue Mar 21 2023 Sandro Mani - 2022.12.7-1 - Update to 2022.12.7 * Thu Jul 21 2022 Fedora Release Engineering - 2021.10.8-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Mon Feb 14 2022 Sandro Mani - 2021.10.8-1 - Update to 2021.10.8 --------------------------------------------------------------------------------References: [ 1 ] Bug #2180096 - CVE-2022-23491 mingw-python-certifi: python-certifi: untrusted root certificates [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2180096 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-7ed04fe4a7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribesend an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . MinGW Windows Python ssl-cert updated to resolve untrusted root certificates issue on Fedora 37, crucial for safeguarding system integrity.. Fedora, Certifi Update, Software Fix, Python Dependency. . LinuxSecurity.com Team

Calendar%202 Mar 30, 2023 Fedora
172

Ubuntu 20.04 LTS USN-5812-1: Urllib3 Denial Of Service Risk

urllib3 could be made to stop responding if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-5812-1 January 19, 2023 python-urllib3 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: urllib3 could be made to stop responding if it received specially crafted network traffic. Software Description: - python-urllib3: HTTP library with thread-safe connection pooling Details: It was discovered that urllib3 incorrectly handled certain characters in URLs. A remote attacker could possibly use this issue to cause urllib3 to consume resources, leading to a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: python3-urllib3 1.25.8-2ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5812-1 CVE-2021-33503 Package Information: https://launchpad.net/ubuntu/+source/python-urllib3/1.25.8-2ubuntu0.2 . USN-5820-1 security alert addresses a python-requests denial of service flaw affecting Ubuntu platforms. python urllib3, Ubuntu security, denial of service, network traffic issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 19, 2023 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200