Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 58 articles for you...
217

Oracle Linux 8 Firefox Critical Security Notice ELSA-2026-21382

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-21382 http://linux.oracle.com/errata/ELSA-2026-21382.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: firefox-140.11.0-1.0.1.el8_10.x86_64.rpm aarch64: firefox-140.11.0-1.0.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/firefox-140.11.0-1.0.1.el8_10.src.rpm Related CVEs: CVE-2026-8388 CVE-2026-8391 CVE-2026-8401 CVE-2026-8946 CVE-2026-8947 CVE-2026-8950 CVE-2026-8953 CVE-2026-8954 CVE-2026-8955 CVE-2026-8956 CVE-2026-8957 CVE-2026-8958 CVE-2026-8961 CVE-2026-8962 CVE-2026-8968 CVE-2026-8970 CVE-2026-8974 CVE-2026-8975 Description of changes: [140.11.0-1.0.1] - Fix firefox-oracle-default-prefs.js for new nss [Orabug: 37079789] - diable wasi_sdk to prevent build failure with newer llvm [140.11.0] - Add debranding patches (Mustafa Gezen) - Add OpenELA default preferences (Louis Abel) [140.11.0-1] - Update to 140.11.0 ESR _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 8 advisory ELSA-2026-21382 details updated Firefox packages addressing important issues.. Oracle Linux Firefox Updates Security Advisory Remote Exploits. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 29, 2026 Important Oracle
219

AlmaLinux 9 Database PostgreSQL Significant Security Update RLSA-2026-3920

Important: postgresql:15 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:3896", "synopsis": "Important: postgresql:15 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for pg_repack, pgaudit, module.postgres-decoderbufs, module.pgaudit, module.pg_repack, postgres-decoderbufs.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "PostgreSQL is an advanced object-relational database management system (DBMS).\n\nSecurity Fix(es):\n\n* postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code (CVE-2026-2006)\n\n* postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code (CVE-2026-2004)\n\n* postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code (CVE-2026-2005)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2439324", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2439324", "description": ""}, {"ticket": "2439325", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2439325", "description": ""}, {"ticket": "2439326", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2439326", "description": ""}], "cves": [{"name": "CVE-2026-2004", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-2004", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-1287"}, {"name": "CVE-2026-2005", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-2005", "cvss3ScoringVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-120"}, {"name": "CVE-2026-2006", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-2006", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-1285"}], "references": [], "publishedAt": "2026-03-06T06:02:50.093230Z", "rpms": {"Rocky Linux 9": {"nvras": ["pgaudit-0:1.7.0-1.module+el9.7.0+40011+28af63c9.aarch64.rpm", "pgaudit-0:1.7.0-1.module+el9.7.0+40011+28af63c9.ppc64le.rpm", "pgaudit-0:1.7.0-1.module+el9.7.0+40011+28af63c9.s390x.rpm", "pgaudit-0:1.7.0-1.module+el9.7.0+40011+28af63c9.src.rpm", "pgaudit-0:1.7.0-1.module+el9.7.0+40011+28af63c9.x86_64.rpm", "pgaudit-debuginfo-0:1.7.0-1.module+el9.7.0+40011+28af63c9.aarch64.rpm", "pgaudit-debuginfo-0:1.7.0-1.module+el9.7.0+40011+28af63c9.ppc64le.rpm", "pgaudit-debuginfo-0:1.7.0-1.module+el9.7.0+40011+28af63c9.s390x.rpm", "pgaudit-debuginfo-0:1.7.0-1.module+el9.7.0+40011+28af63c9.x86_64.rpm", "pgaudit-debugsource-0:1.7.0-1.module+el9.7.0+40011+28af63c9.aarch64.rpm", "pgaudit-debugsource-0:1.7.0-1.module+el9.7.0+40011+28af63c9.ppc64le.rpm", "pgaudit-debugsource-0:1.7.0-1.module+el9.7.0+40011+28af63c9.s390x.rpm", "pgaudit-debugsource-0:1.7.0-1.module+el9.7.0+40011+28af63c9.x86_64.rpm", "pg_repack-0:1.4.8-2.module+el9.7.0+40011+28af63c9.aarch64.rpm", "pg_repack-0:1.4.8-2.module+el9.7.0+40011+28af63c9.ppc64le.rpm", "pg_repack-0:1.4.8-2.module+el9.7.0+40011+28af63c9.s390x.rpm", "pg_repack-0:1.4.8-2.module+el9.7.0+40011+28af63c9.src.rpm", "pg_repack-0:1.4.8-2.module+el9.7.0+40011+28af63c9.x86_64.rpm", "pg_repack-debuginfo-0:1.4.8-2.module+el9.7.0+40011+28af63c9.aarch64.rpm", "pg_repack-debuginfo-0:1.4.8-2.module+el9.7.0+40011+28af63c9.ppc64le.rpm", "pg_repack-debuginfo-0:1.4.8-2.module+el9.7.0+40011+28af63c9.s390x.rpm", "pg_repack-debuginfo-0:1.4.8-2.module+el9.7.0+40011+28af63c9.x86_64.rpm", "pg_repack-debugsource-0:1.4.8-2.module+el9.7.0+40011+28af63c9.aarch64.rpm","pg_repack-debugsource-0:1.4.8-2.module+el9.7.0+40011+28af63c9.ppc64le.rpm", "pg_repack-debugsource-0:1.4.8-2.module+el9.7.0+40011+28af63c9.s390x.rpm", "pg_repack-debugsource-0:1.4.8-2.module+el9.7.0+40011+28af63c9.x86_64.rpm", "postgres-decoderbufs-0:1.9.7-1.Final.module+el9.7.0+40011+28af63c9.aarch64.rpm", "postgres-decoderbufs-0:1.9.7-1.Final.module+el9.7.0+40011+28af63c9.ppc64le.rpm", "postgres-decoderbufs-0:1.9.7-1.Final.module+el9.7.0+40011+28af63c9.s390x.rpm", "postgres-decoderbufs-0:1.9.7-1.Final.module+el9.7.0+40011+28af63c9.src.rpm", "postgres-decoderbufs-0:1.9.7-1.Final.module+el9.7.0+40011+28af63c9.x86_64.rpm", "postgres-decoderbufs-debuginfo-0:1.9.7-1.Final.module+el9.7.0+40011+28af63c9.aarch64.rpm", "postgres-decoderbufs-debuginfo-0:1.9.7-1.Final.module+el9.7.0+40011+28af63c9.ppc64le.rpm", "postgres-decoderbufs-debuginfo-0:1.9.7-1.Final.module+el9.7.0+40011+28af63c9.s390x.rpm", "postgres-decoderbufs-debuginfo-0:1.9.7-1.Final.module+el9.7.0+40011+28af63c9.x86_64.rpm", "postgres-decoderbufs-debugsource-0:1.9.7-1.Final.module+el9.7.0+40011+28af63c9.aarch64.rpm", "postgres-decoderbufs-debugsource-0:1.9.7-1.Final.module+el9.7.0+40011+28af63c9.ppc64le.rpm", "postgres-decoderbufs-debugsource-0:1.9.7-1.Final.module+el9.7.0+40011+28af63c9.s390x.rpm", "postgres-decoderbufs-debugsource-0:1.9.7-1.Final.module+el9.7.0+40011+28af63c9.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important update for postgresql addressing multiple security flaws and providing fixes for Rocky Linux users.. Rocky Linux Security, PostgreSQL Update, Important Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 06, 2026 Important Rocky Linux
197

Debian 11: DLA-4359-1 strongswan Critical Buffer Overflow Exploit

Xu Biang discovered a buffer overflow bug in the eap-mschapv2 plugin of strongSwan, an IKE/IPsec suite. The eap-mschapv2 plugin does not correctly check the length of an . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4359-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany November 03, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : strongswan Version : 5.9.1-1+deb11u5 CVE ID : CVE-2025-62291 Xu Biang discovered a buffer overflow bug in the eap-mschapv2 plugin of strongSwan, an IKE/IPsec suite. The eap-mschapv2 plugin does not correctly check the length of an EAP-MSCHAPv2 Failure Request packet on the client, which can cause an integer underflow that leads to a crash, and a heap-based buffer overflow that's potentially exploitable for remote code execution. For Debian 11 bullseye, this problem has been fixed in version 5.9.1-1+deb11u5. We recommend that you upgrade your strongswan packages. For the detailed security status of strongswan please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/strongswan Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade strongSwan due to critical buffer overflow vulnerability leading to remote code execution. Advisory DLA-4359-1.. Debian LTS, strongswan, buffer overflow, security update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 03, 2025 Critical Debian LTS
100

SUSE: PostgreSQL14 Important Code Execution Vuln 2025:03020-1

* bsc#1248119 * bsc#1248120 * bsc#1248122 Cross-References: . # Security update for postgresql14 Announcement ID: SUSE-SU-2025:03020-1 Release Date: 2025-08-29T08:32:27Z Rating: important References: * bsc#1248119 * bsc#1248120 * bsc#1248122 Cross-References: * CVE-2025-8713 * CVE-2025-8714 * CVE-2025-8715 CVSS scores: * CVE-2025-8713 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-8713 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2025-8713 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2025-8714 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-8714 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-8714 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-8715 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-8715 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-8715 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for postgresql14 fixes the following issues: Upgrade to 14.19: * CVE-2025-8713: optimizer statistics can expose sampled data within a view, partition, or child table (bsc#1248120). * CVE-2025-8714: untrusted data inclusion in `pg_dump` lets superuser of origin server execute arbitrary code in psql client (bsc#1248122). * CVE-2025-8715: improper neutralization of newlines in `pg_dump` allows execution of arbitrary code in psql client and in restore target server (bsc#1248119). ## PatchInstructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-3020=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-3020=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * postgresql14-14.19-3.60.1 * postgresql14-contrib-14.19-3.60.1 * postgresql14-devel-debuginfo-14.19-3.60.1 * postgresql14-pltcl-debuginfo-14.19-3.60.1 * postgresql14-plpython-debuginfo-14.19-3.60.1 * postgresql14-server-14.19-3.60.1 * postgresql14-debuginfo-14.19-3.60.1 * postgresql14-pltcl-14.19-3.60.1 * postgresql14-plpython-14.19-3.60.1 * postgresql14-devel-14.19-3.60.1 * postgresql14-debugsource-14.19-3.60.1 * postgresql14-plperl-debuginfo-14.19-3.60.1 * postgresql14-server-debuginfo-14.19-3.60.1 * postgresql14-plperl-14.19-3.60.1 * postgresql14-contrib-debuginfo-14.19-3.60.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * postgresql14-docs-14.19-3.60.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (ppc64le s390x x86_64) * postgresql14-server-devel-debuginfo-14.19-3.60.1 * postgresql14-server-devel-14.19-3.60.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * postgresql14-14.19-3.60.1 * postgresql14-contrib-14.19-3.60.1 * postgresql14-devel-debuginfo-14.19-3.60.1 * postgresql14-pltcl-debuginfo-14.19-3.60.1 * postgresql14-plpython-debuginfo-14.19-3.60.1 * postgresql14-server-14.19-3.60.1 * postgresql14-debuginfo-14.19-3.60.1 * postgresql14-pltcl-14.19-3.60.1 * postgresql14-plpython-14.19-3.60.1 * postgresql14-server-devel-14.19-3.60.1 * postgresql14-devel-14.19-3.60.1 * postgresql14-debugsource-14.19-3.60.1 *postgresql14-plperl-debuginfo-14.19-3.60.1 * postgresql14-server-devel-debuginfo-14.19-3.60.1 * postgresql14-server-debuginfo-14.19-3.60.1 * postgresql14-plperl-14.19-3.60.1 * postgresql14-contrib-debuginfo-14.19-3.60.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * postgresql14-docs-14.19-3.60.1 ## References: * https://www.suse.com/security/cve/CVE-2025-8713.html * https://www.suse.com/security/cve/CVE-2025-8714.html * https://www.suse.com/security/cve/CVE-2025-8715.html * https://bugzilla.suse.com/show_bug.cgi?id=1248119 * https://bugzilla.suse.com/show_bug.cgi?id=1248120 * https://bugzilla.suse.com/show_bug.cgi?id=1248122 . SUSE has launched vital security updates for PostgreSQL 14, addressing vulnerabilities that threaten system stability and data security risks involved. SUSE Linux, PostgreSQL, Security Patch, Update Instructions, Arbitrary Code. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 29, 2025 Important SuSE
91

Gentoo: GLSA-202505-07 critical: FreeType remote execution

A vulnerability has been discovered in FreeType, which can lead to remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202505-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: FreeType: Remote Code Execution Date: May 14, 2025 Bugs: #951286 ID: 202505-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in FreeType, which can lead to remote code execution. Background ========== FreeType is a high-quality and portable font engine. Affected packages ================= Package Vulnerable Unaffected ------------------- ------------ ------------ media-libs/freetype < 2.13.1 > = 2.13.1 Description =========== Multiple vulnerabilities have been discovered in FreeType. Please review the CVE identifiers referenced below for details. Impact ====== An out of bounds write exists in FreeType when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild. Workaround ========== There is no known workaround at this time. Resolution ========== All FreeType users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/freetype-2.13.1" References ========== [ 1 ] CVE-2025-27363 https://nvd.nist.gov/vuln/detail/CVE-2025-27363 Availability ============ This GLSAand any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202505-07 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2025 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5 . A critical flaw in FreeType affecting Gentoo could lead to remote code execution; updating is necessary to mitigate the risk.. FreeType Code Execution, Gentoo Security, Remote Code Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 14, 2025 Critical Gentoo
172

Ubuntu 14.04 LTS: USN-7181-1 critical: Salt remote code execution

Salt could be made to crash or run programs if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-7181-1 January 06, 2025 salt vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Salt could be made to crash or run programs if it received specially crafted network traffic. Software Description: - salt: Infrastructure management built on a dynamic communication bus Details: It was discovered that Salt incorrectly handled web requests when the SSH client was enabled. An attacker could possibly use this issue to achieve remote code execution or obtain sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS salt-common 0.17.5+ds-1ubuntu0.1~esm4 Available with Ubuntu Pro salt-master 0.17.5+ds-1ubuntu0.1~esm4 Available with Ubuntu Pro salt-minion 0.17.5+ds-1ubuntu0.1~esm4 Available with Ubuntu Pro salt-ssh 0.17.5+ds-1ubuntu0.1~esm4 Available with Ubuntu Pro salt-syndic 0.17.5+ds-1ubuntu0.1~esm4 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7181-1 CVE-2020-16846 .Stay informed about a critical Salt vulnerability in Ubuntu 14.04 LTS. Follow the update steps to secure your systems from potential attack vectors. Salt Security, Ubuntu Security Notice, Remote Code Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 06, 2025 Critical Ubuntu
91

Gentoo: 202401-33 High Risk: WebKitGTK+ Remote Code Execution

Multiple vulnerabilities have been found in WebKitGTK+, the worst of which may lead to remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202401-33 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: WebKitGTK+: Multiple Vulnerabilities Date: January 31, 2024 Bugs: #915222, #918667 ID: 202401-33 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been found in WebKitGTK+, the worst of which may lead to remote code execution. Background ========== WebKitGTK+ is a full-featured port of the WebKit rendering engine, suitable for projects requiring any kind of web integration, from hybrid HTML/CSS applications to full-fledged web browsers. Affected packages ================= Package Vulnerable Unaffected ------------------- ------------ ------------- net-libs/webkit-gtk < 2.42.2:4 > = 2.42.2:4 < 2.42.2:4.1 > = 2.42.2:4.1 < 2.42.2:6 > = 2.42.2:6 Description =========== Multiple vulnerabilities have been discovered in WebKitGTK+. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All WebKitGTK+ users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-libs/webkit-gtk-2.42.2" References ========== [ 1 ] CVE-2023-32359 https://nvd.nist.gov/vuln/detail/CVE-2023-32359 [ 2 ] CVE-2023-35074 https://nvd.nist.gov/vuln/detail/CVE-2023-35074 [ 3 ] CVE-2023-39434 https://nvd.nist.gov/vuln/detail/CVE-2023-39434 [ 4 ] CVE-2023-39928 https://nvd.nist.gov/vuln/detail/CVE-2023-39928 [ 5 ] CVE-2023-40451 https://nvd.nist.gov/vuln/detail/CVE-2023-40451 [ 6 ] CVE-2023-41074 https://nvd.nist.gov/vuln/detail/CVE-2023-41074 [ 7 ] CVE-2023-41983 https://nvd.nist.gov/vuln/detail/CVE-2023-41983 [ 8 ] CVE-2023-41993 https://nvd.nist.gov/vuln/detail/CVE-2023-41993 [ 9 ] CVE-2023-42852 https://nvd.nist.gov/vuln/detail/CVE-2023-42852 [ 10 ] CVE-2023-42890 https://nvd.nist.gov/vuln/detail/CVE-2023-42890 [ 11 ] WSA-2023-0009 https://webkitgtk.org/security/WSA-2023-0009.html Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202401-33 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Numerous weaknesses in WebKitGTK+ present serious threats. A software upgrade is essential for safeguarding system integrity and ensuring security.. WebKitGTK+ Security,Gentoo Advisory,Remote Code Execution,High Severity Vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Jan 31, 2024 Gentoo
172

Ubuntu 23.10 USN-6592-1 urgent: remote code execution risk in libssh

Several security issues were fixed in libssh.. ========================================================================== Ubuntu Security Notice USN-6592-1 January 22, 2024 libssh vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in libssh. Software Description: - libssh: A tiny C SSH library Details: It was discovered that libssh incorrectly handled the ProxyCommand and the ProxyJump features. A remote attacker could possibly use this issue to inject malicious code into the command of the features mentioned through the hostname parameter. (CVE-2023-6004) It was discovered that libssh incorrectly handled return codes when performing message digest operations. A remote attacker could possibly use this issue to cause libssh to crash, obtain sensitive information, or execute arbitrary code. (CVE-2023-6918) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: libssh-4 0.10.5-3ubuntu1.2 Ubuntu 23.04: libssh-4 0.10.4-2ubuntu0.3 Ubuntu 22.04 LTS: libssh-4 0.9.6-2ubuntu0.22.04.3 Ubuntu 20.04 LTS: libssh-4 0.9.3-2ubuntu2.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6592-1 CVE-2023-6004, CVE-2023-6918 Package Information: https://launchpad.net/ubuntu/+source/libssh/0.10.5-3ubuntu1.2 https://launchpad.net/ubuntu/+source/libssh/0.10.4-2ubuntu0.3 https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.3 https://launchpad.net/ubuntu/+source/libssh/0.9.3-2ubuntu2.5 . Ubuntu has remedied several security flaws in the libssl library, mitigatingthe chances of unauthorized code execution and potential system instabilities.. libssh security update, Ubuntu security notice, remote code execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 22, 2024 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200