Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 4 articles for you...
89

Fedora 43 OpenSSL Critical Update Rebase 3.5.7 Advisories 2026-840334a045

Rebase to OpenSSL 3.5.7. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-840334a045 2026-06-21 01:09:26.438169+00:00 -------------------------------------------------------------------------------- Name : openssl Product : Fedora 43 Version : 3.5.7 Release : 1.fc43 URL : http://www.openssl.org/ Summary : Utilities from the general purpose cryptography library with TLS implementation Description : The OpenSSL toolkit provides support for secure communications between machines. OpenSSL includes a certificate management tool and shared libraries which provide various cryptographic algorithms and protocols. -------------------------------------------------------------------------------- Update Information: Rebase to OpenSSL 3.5.7 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 10 2026 Dmitry Belyavskiy - 1:3.5.7-1 - Rebase to OpenSSL 3.5.7 Resolves: CVE-2026-45447 Resolves: CVE-2026-34182 Resolves: CVE-2026-34183 Resolves: CVE-2026-42764 Resolves: CVE-2026-45445 Resolves: CVE-2026-7383 Resolves: CVE-2026-9076 Resolves: CVE-2026-34180 Resolves: CVE-2026-34181 Resolves: CVE-2026-42766 Resolves: CVE-2026-42767 Resolves: CVE-2026-42768 Resolves: CVE-2026-42769 Resolves: CVE-2026-42770 Resolves: CVE-2026-45446 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-840334a045' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fedora 43 updates openssl to version 3.5.7, addressing multiple critical issues for secure communications. Learn more!. Fedora OpenSSL Rebase Critical Issues Secure Communications. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 20, 2026 Critical Fedora
89

Fedora 43 expat Update Critical XML Parser Rebase CVE 2026-89f45c355d

Rebase to version 2.8.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-89f45c355d 2026-05-21 01:26:51.960413+00:00 -------------------------------------------------------------------------------- Name : expat Product : Fedora 43 Version : 2.8.1 Release : 1.fc43 URL : https://libexpat.github.io/ Summary : An XML parser library Description : This is expat, the C library for parsing XML, written by James Clark. Expat is a stream oriented XML parser. This means that you register handlers with the parser prior to starting the parse. These handlers are called when the parser discovers the associated structures in the document being parsed. A start tag is an example of the kind of structures for which you may register handlers. -------------------------------------------------------------------------------- Update Information: Rebase to version 2.8.1 -------------------------------------------------------------------------------- ChangeLog: * Tue May 12 2026 Tomas Korbar - 2.8.1-1 - Rebase to version 2.8.1 * Mon Mar 23 2026 Tomas Korbar - 2.7.5-1 - Rebase to 2.7.5 * Mon Feb 9 2026 Miro Hron\u010dok - 2.7.4-1 - Update to 2.7.4 - Enable versioned symbols - Fixes: rhbz#2435633 * Fri Jan 16 2026 Fedora Release Engineering - 2.7.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2448482 - expat-2.8.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2448482 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-89f45c355d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPGkey. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 43 expat library update addresses critical improvements and fixes for XML parsing. Detailed info inside.. Fedora expat update XML parser security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 21, 2026 Critical Fedora
89

Fedora 44 expat Update 2.8.1 Rebase Notification 2026-4ef690dc30

Rebase to version 2.8.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-4ef690dc30 2026-05-15 02:33:10.357482+00:00 -------------------------------------------------------------------------------- Name : expat Product : Fedora 44 Version : 2.8.1 Release : 1.fc44 URL : https://libexpat.github.io/ Summary : An XML parser library Description : This is expat, the C library for parsing XML, written by James Clark. Expat is a stream oriented XML parser. This means that you register handlers with the parser prior to starting the parse. These handlers are called when the parser discovers the associated structures in the document being parsed. A start tag is an example of the kind of structures for which you may register handlers. -------------------------------------------------------------------------------- Update Information: Rebase to version 2.8.1 -------------------------------------------------------------------------------- ChangeLog: * Tue May 12 2026 Tomas Korbar - 2.8.1-1 - Rebase to version 2.8.1 * Mon Mar 23 2026 Tomas Korbar - 2.7.5-1 - Rebase to 2.7.5 * Mon Feb 9 2026 Miro Hron\u010dok - 2.7.4-1 - Update to 2.7.4 - Enable versioned symbols - Fixes: rhbz#2435633 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2448482 - expat-2.8.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2448482 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-4ef690dc30' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 44 updates expat to version 2.8.1, improving XML parsing functionality and performance. Learn more now!. Fedora expat update XML parser. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 May 15, 2026 Informational Fedora
89

Fedora 41: expat 2024-ccc5045ab9 moderate: XML parser update

Rebase to version 2.6.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ccc5045ab9 2024-11-11 02:18:50.551758 -------------------------------------------------------------------------------- Name : expat Product : Fedora 41 Version : 2.6.4 Release : 1.fc41 URL : https://libexpat.github.io/ Summary : An XML parser library Description : This is expat, the C library for parsing XML, written by James Clark. Expat is a stream oriented XML parser. This means that you register handlers with the parser prior to starting the parse. These handlers are called when the parser discovers the associated structures in the document being parsed. A start tag is an example of the kind of structures for which you may register handlers. -------------------------------------------------------------------------------- Update Information: Rebase to version 2.6.4 -------------------------------------------------------------------------------- ChangeLog: * Thu Nov 7 2024 Tomas Korbar - 2.6.4-1 - Rebase to version 2.6.4 - Resolves: CVE-2024-50602 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ccc5045ab9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . This guide provides a crucial security advisory and step-by-step update instructions for Fedora 41 users to upgrade to expat library version 2.6.4. expat library, Fedora update, XML parser security, software rebase. . LinuxSecurity.com Team

Calendar%202 Nov 11, 2024 Fedora
89

Ubuntu 22.04: 2023-fad76bcd12 High: gnome-terminal Buffer Overflow

Rebase to version 375. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-8cf76a9ceb 2022-11-23 01:19:40.756740 --------------------------------------------------------------------------------Name : xterm Product : Fedora 35 Version : 375 Release : 1.fc35 URL : https://invisible-island.net/xterm/ Summary : Terminal emulator for the X Window System Description : The xterm program is a terminal emulator for the X Window System. It provides DEC VT102 and Tektronix 4014 compatible terminals for programs that can't use the window system directly. --------------------------------------------------------------------------------Update Information: Rebase to version 375 --------------------------------------------------------------------------------ChangeLog: * Mon Oct 31 2022 Tomas Korbar - 375-1 - Rebase to version 375 - Resolves: rhbz#2137784 * Tue Oct 11 2022 Tomas Korbar - 374-1 - Rebase to version 374 - Resolves: rhbz#2133585 * Wed Oct 5 2022 Tomas Korbar - 373-1 - Rebase to version 373 - Resolves: rhbz#2129661 * Sat Jul 23 2022 Fedora Release Engineering - 372-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Mon Apr 25 2022 Tomas Korbar - 372-1 - Rebase to version 372 - Resolves: rhbz#2062511 --------------------------------------------------------------------------------References: [ 1 ] Bug #2137784 - xterm-375 is available https://bugzilla.redhat.com/show_bug.cgi?id=2137784 [ 2 ] Bug #2142481 - CVE-2022-45063 xterm: code execution via OSC 50 input sequences [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2142481 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-8cf76a9ceb' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Upgrade xterm on Fedora 35 to version 375 to boost system security by addressing vulnerabilities linked to unauthorized code execution. Fedora Updates,xterm Security,Terminal Emulator Upgrade. . LinuxSecurity.com Team

Calendar%202 Nov 22, 2022 Fedora
89

Fedora 35: 2022-1151f65e9a Critical: Postgresql JDBC Security Update

Rebase on upstream version 42.2.25. This rebase fixes CVE-2022-21724.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-1151f65e9a 2022-04-14 16:06:11.136474 --------------------------------------------------------------------------------Name : postgresql-jdbc Product : Fedora 35 Version : 42.2.25 Release : 1.fc35 URL : https://jdbc.postgresql.org/ Summary : JDBC driver for PostgreSQL Description : PostgreSQL is an advanced Object-Relational database management system. The postgresql-jdbc package includes the .jar files needed for Java programs to access a PostgreSQL database. --------------------------------------------------------------------------------Update Information: Rebase on upstream version 42.2.25. This rebase fixes CVE-2022-21724. --------------------------------------------------------------------------------ChangeLog: * Wed Apr 6 2022 Zuzana Miklankova - 42.2.25-1 - rebase to version 42.2.25 --------------------------------------------------------------------------------References: [ 1 ] Bug #2050863 - CVE-2022-21724 jdbc-postgresql: Unchecked Class Instantiation when providing Plugin Classes https://bugzilla.redhat.com/show_bug.cgi?id=2050863 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-1151f65e9a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. Tounsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Essential Fedora patch resolves vulnerabilities in the postgresql-jdbc library, enhancing database connection security and safeguarding user data.. Postgresql-Jdbc Driver, Fedora Update, Security Fix, JDBC Security, Database Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 14, 2022 Critical Fedora
89

Fedora 35: 2022-9bb794c5f5 Moderate: Libarchive Rebase to Version 3.5.3

Rebase to version 3.5.3. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-9bb794c5f5 2022-02-24 23:06:26.903943 --------------------------------------------------------------------------------Name : libarchive Product : Fedora 35 Version : 3.5.3 Release : 1.fc35 URL : https://www.libarchive.org/ Summary : A library for handling streaming archive formats Description : Libarchive is a programming library that can create and read several different streaming archive formats, including most popular tar variants, several cpio formats, and both BSD and GNU ar variants. It can also write shar archives and read ISO9660 CDROM images and ZIP archives. --------------------------------------------------------------------------------Update Information: Rebase to version 3.5.3 --------------------------------------------------------------------------------ChangeLog: * Mon Feb 14 2022 Lukas Javorsky - 3.5.3-1 - Rebase to version 3.5.3 --------------------------------------------------------------------------------References: [ 1 ] Bug #1984647 - CVE-2021-36976 libarchive: use-after-free in copy_string() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1984647 [ 2 ] Bug #2024238 - CVE-2021-31566 libarchive: symbolic links incorrectly followed when changing modes, times, ACL and flags of a file while extracting an archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2024238 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-9bb794c5f5' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Libarchive update for Fedora 35 addresses security issues while enhancing archive handling functionalities.. Libarchive Update, Fedora Security, Package Management, Archive Handling. . LinuxSecurity.com Team

Calendar%202 Feb 24, 2022 Fedora
89

Fedora 35: FEDORA-2022-c4786825dd Critical: Expat 2.4.4 Update

Rebase to version 2.4.4. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-c4786825dd 2022-02-16 01:25:55.828007 --------------------------------------------------------------------------------Name : expat Product : Fedora 35 Version : 2.4.4 Release : 1.fc35 URL : https://libexpat.github.io/ Summary : An XML parser library Description : This is expat, the C library for parsing XML, written by James Clark. Expat is a stream oriented XML parser. This means that you register handlers with the parser prior to starting the parse. These handlers are called when the parser discovers the associated structures in the document being parsed. A start tag is an example of the kind of structures for which you may register handlers. --------------------------------------------------------------------------------Update Information: Rebase to version 2.4.4 --------------------------------------------------------------------------------ChangeLog: * Mon Jan 31 2022 Tomas Korbar - 2.4.4-1 - Rebase to version 2.4.4 - Resolves: rhbz#2048187 * Thu Jan 20 2022 Fedora Release Engineering - 2.4.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild * Tue Jan 18 2022 Tomas Korbar - 2.4.3-2 - Change specfile according to Sebastian Pippings suggestions --------------------------------------------------------------------------------References: [ 1 ] Bug #2048187 - expat-2.4.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2048187 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-c4786825dd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used bythe Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Upgrade expat to version 2.4.4 in Fedora 35 by updating your system and using the command: `sudo dnf install expat-2.4.4` for better performance. expat update, library security, Fedora release, XML parser, software upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 15, 2022 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200