Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 24 articles for you...
172

Ubuntu 20.04 18.04 OpenStack Glance Security Flaws USN-8199-1

Several security issues were fixed in OpenStack Glance.. ========================================================================== Ubuntu Security Notice USN-8199-1 April 22, 2026 glance vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in OpenStack Glance. Software Description: - glance: OpenStack Image Registry and Delivery Service Details: Martin Kaesberger discovered that OpenStack Glance's image processing could return the contents of arbitrary files. An attacker could possibly use this issue to exfiltrate sensitive data. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-32498) Hyeongeun Ji and Abhishek Kekane discovered several server-side request forgery vulnerabilities in OpenStack Glance's image import. An attacker could possibly use this issue to bypass URL validation checks and redirect to internal services. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-34881) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS glance 2:20.2.0-0ubuntu1.2+esm2 Available with Ubuntu Pro glance-api 2:20.2.0-0ubuntu1.2+esm2 Available with Ubuntu Pro glance-common 2:20.2.0-0ubuntu1.2+esm2 Available with Ubuntu Pro python3-glance 2:20.2.0-0ubuntu1.2+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS glance 2:16.0.1-0ubuntu1.1+esm2 Available with Ubuntu Pro glance-api 2:16.0.1-0ubuntu1.1+esm2 Available with Ubuntu Pro glance-common 2:16.0.1-0ubuntu1.1+esm2 Available with Ubuntu Pro glance-registry 2:16.0.1-0ubuntu1.1+esm2 Available with Ubuntu Pro python-glance 2:16.0.1-0ubuntu1.1+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS glance 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro glance-api 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro glance-common 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro glance-glare 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro glance-registry 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro python-glance 2:12.0.0-0ubuntu2+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8199-1 CVE-2024-32498, CVE-2026-34881 . Review of Ubuntu's USN-8199-1 highlighting fixed security issues in OpenStack Glance affecting multiple LTS versions.. OpenStack Glance security, Ubuntu vulnerabilities, image processing issues. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 27, 2026 Important Ubuntu
89

Fedora 44 Calibre 9.6.0 Important Server-Side Request Forgery Patch

Update to 9.6.0. Fixes rhbz#2452087. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-7de23151cd 2026-04-25 01:21:36.171214+00:00 -------------------------------------------------------------------------------- Name : calibre Product : Fedora 44 Version : 9.6.0 Release : 1.fc44 URL : https://calibre-ebook.com/ Summary : E-book converter and library manager Description : Calibre is meant to be a complete e-library solution. It includes library management, format conversion, news feeds to ebook conversion as well as e-book reader sync features. Calibre is primarily a ebook cataloging program. It manages your ebook collection for you. It is designed around the concept of the logical book, i.e. a single entry in the database that may correspond to ebooks in several formats. It also supports conversion to and from a dozen different ebook formats. Supported input formats are: MOBI, LIT, PRC, EPUB, CHM, ODT, HTML, CBR, CBZ, RTF, TXT, PDF and LRS. -------------------------------------------------------------------------------- Update Information: Update to 9.6.0. Fixes rhbz#2452087 -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 29 2026 Kevin Fenzi - 9.6.0-1 - Update to 9.6.0. Fixes rhbz#2452087 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452087 - calibre-9.6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2452087 [ 2 ] Bug #2452379 - CVE-2026-33205 calibre: server-side request forgery in ebook viewer backend [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452379 [ 3 ] Bug #2452380 - CVE-2026-33206 calibre: path traversal allows reading arbitrary files when converting a text-based file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452380 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-7de23151cd' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update calibre 9.6.0 in Fedora 44 fixes critical security issues affecting e-book management system.. Fedora calibre update security 9.6.0. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 25, 2026 Critical Fedora
197

Debian 11 php7.4 Security Advisory DLA-4447-1 CVE-2025-14178 Heap Overflow

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in server side request forgery or denial of service. CVE-2025-14178 Heap buffer overflow in array_merge().. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4447-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin January 24, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : php7.4 Version : 7.4.33-1+deb11u10 CVE ID : CVE-2025-14178 Debian Bug : 1123574 Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in server side request forgery or denial of service. CVE-2025-14178 Heap buffer overflow in array_merge(). GHSA-www2-q4fc-65wf dns_get_record() and other DNS functions don't have any null contain check, which may lead to SSRF or unexpected behavior. While this has a (low) security impact, no CVE ID was assigned for this vulnerability yet. For Debian 11 bullseye, these problems have been fixed in version 7.4.33-1+deb11u10. We recommend that you upgrade your php7.4 packages. For the detailed security status of php7.4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/php7.4 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Explore the Debian LTS advisory for php7.4 addressing critical server-side vulnerabilities including denial of service risks.. Debian LTS, php7.4 security, DLA-4447-1, security update, heap overflow. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 24, 2026 Critical Debian LTS
87

Debian: python-urllib3 Important Denial of Service DSA-6102-1

Several vulnerabilities were discovered in python-urllib3, a HTTP library with thread-safe connection pooling for Python3, which could result in denial of service or request forgery. For the oldstable distribution (bookworm), these problems have been fixed in version 1.26.12-1+deb12u2.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6102-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso January 17, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : python-urllib3 CVE ID : CVE-2025-50181 CVE-2025-66418 CVE-2026-21441 Debian Bug : 1108076 1122030 1125062 Several vulnerabilities were discovered in python-urllib3, a HTTP library with thread-safe connection pooling for Python3, which could result in denial of service or request forgery. For the oldstable distribution (bookworm), these problems have been fixed in version 1.26.12-1+deb12u2. For the stable distribution (trixie), these problems have been fixed in version 2.3.0-3+deb13u1. We recommend that you upgrade your python-urllib3 packages. For the detailed security status of python-urllib3 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/python-urllib3 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Python-urllib3 vulnerabilities fixed to prevent DoS and forgery issues in Debian’s oldstable and stable distributions.. Debian Security, Python urllib3, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 17, 2026 Important Debian
197

Debian: python-urllib3 Critical Denial of Service CVE-2025-50181 DLA-4421-1

Vulnerabilities were found in python-urllib3, an HTTP library with thread-safe connection pooling for Python, which could lead to denial of service or request forgery. CVE-2025-50181 Redirects were not disabled when retries are disabled on PoolManager. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4421-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin December 26, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : python-urllib3 Version : 1.26.5-1~exp1+deb11u2 CVE ID : CVE-2025-50181 CVE-2025-66418 Debian Bug : 1108076 1122030 Vulnerabilities were found in python-urllib3, an HTTP library with thread-safe connection pooling for Python, which could lead to denial of service or request forgery. CVE-2025-50181 Redirects were not disabled when retries are disabled on PoolManager instantiation. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level remained vulnerable. CVE-2025-66418 The number of links in the decompression chain was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps which could lead to denial of service. For Debian 11 bullseye, these problems have been fixed in version 1.26.5-1~exp1+deb11u2. We recommend that you upgrade your python-urllib3 packages. For the detailed security status of python-urllib3 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/python-urllib3 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Critical security update for python-urllib3 in Debian LTS fixes denial of service and request forgery issuesincluding CVE-2025-50181.. Debian python-urllib3 security critical update denial service forgery. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 26, 2025 Critical Debian LTS
172

Ubuntu 24.10 introduces USN-7280-2 addressing critical Python SSRF flaw

Python could allow Server-Side Request Forgery (SSRF) attacks.. ========================================================================== Ubuntu Security Notice USN-7280-2 May 22, 2025 python vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Python could allow Server-Side Request Forgery (SSRF) attacks. Software Description: - python3.13: An interactive high-level object-oriented language - python2.7: An interactive high-level object-oriented language - python3.11: An interactive high-level object-oriented language - python3.9: An interactive high-level object-oriented language - python3.6: An interactive high-level object-oriented language - python3.7: An interactive high-level object-oriented language - python3.8: An interactive high-level object-oriented language - python3.4: An interactive high-level object-oriented language Details: USN-7280-1 fixed a vulnerability in Python. This update provides the corresponding updates for some additional Python packages in Ubuntu releases. Original advisory details: It was discovered that Python incorrectly handled parsing domain names that included square brackets. A remote attacker could possibly use this issue to perform a Server-Side Request Forgery (SSRF) attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 python3.13 3.13.0-1ubuntu0.2 python3.13-minimal 3.13.0-1ubuntu0.2 Ubuntu 22.04 LTS python2.7 2.7.18-13ubuntu1.5+esm6 Available with Ubuntu Pro python2.7-minimal 2.7.18-13ubuntu1.5+esm6 Available with Ubuntu Pro python3.11 3.11.0~rc1-1~22.04.1~esm3 Available with Ubuntu Pro python3.11-minimal 3.11.0~rc1-1~22.04.1~esm3 Available with Ubuntu Pro Ubuntu 20.04 LTS python2.7 2.7.18-1~20.04.7+esm7 Available with Ubuntu Pro python2.7-minimal 2.7.18-1~20.04.7+esm7 Available with Ubuntu Pro python3.9 3.9.5-3ubuntu0~20.04.1+esm4 Available with Ubuntu Pro python3.9-minimal 3.9.5-3ubuntu0~20.04.1+esm4 Available with Ubuntu Pro Ubuntu 18.04 LTS python2.7 2.7.17-1~18.04ubuntu1.13+esm11 Available with Ubuntu Pro python2.7-minimal 2.7.17-1~18.04ubuntu1.13+esm11 Available with Ubuntu Pro python3.6 3.6.9-1~18.04ubuntu1.13+esm4 Available with Ubuntu Pro python3.6-minimal 3.6.9-1~18.04ubuntu1.13+esm4 Available with Ubuntu Pro python3.7 3.7.5-2ubuntu1~18.04.2+esm5 Available with Ubuntu Pro python3.7-minimal 3.7.5-2ubuntu1~18.04.2+esm5 Available with Ubuntu Pro python3.8 3.8.0-3ubuntu1~18.04.2+esm4 Available with Ubuntu Pro python3.8-minimal 3.8.0-3ubuntu1~18.04.2+esm4 Available with Ubuntu Pro Ubuntu 16.04 LTS python2.7 2.7.12-1ubuntu0~16.04.18+esm16 Available with Ubuntu Pro python2.7-minimal 2.7.12-1ubuntu0~16.04.18+esm16 Available with Ubuntu Pro Ubuntu 14.04 LTS python2.7 2.7.6-8ubuntu0.6+esm25 Available with Ubuntu Pro python2.7-minimal 2.7.6-8ubuntu0.6+esm25 Available with Ubuntu Pro python3.4 3.4.3-1ubuntu1~14.04.7+esm15 Available with Ubuntu Pro python3.4-minimal 3.4.3-1ubuntu1~14.04.7+esm15 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7280-2 https://ubuntu.com/security/notices/USN-7280-1 CVE-2025-0938 Package Information: https://launchpad.net/ubuntu/+source/python3.13/3.13.0-1ubuntu0.2 . A significant patch for Python targets SSRF vulnerabilities across various Ubuntu releases, reducing the chances of exploitation.. Python Security, Ubuntu Updates, SSRF Vulnerability, Python Releases. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 22, 2025 Critical Ubuntu
172

Ubuntu 16.04 LTS USN-6274-1: XMLTooling Server-Side Action Threat

XMLTooling could be made to allow for unintended server side actions if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-6274-1 August 03, 2023 xmltooling vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: XMLTooling could be made to allow for unintended server side actions if it received specially crafted input. Software Description: - xmltooling: C++ XML parsing library with encryption support Details: Jurien de Jong discovered that XMLTooling did not properly handle certain KeyInfo element content within an XML signature. An attacker could possibly use this issue to achieve server-side request forgery. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS (Available with Ubuntu Pro): libxmltooling6v5 1.5.6-2ubuntu0.3+esm1 After a standard system update you need to restart the shibd process to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6274-1 CVE-2023-36661 . Unforeseen server behaviors linked to OpenSSL weakness outlined in Ubuntu Security Notice USN-6298-1 from September 2023.. XMLTooling Vulnerability, Ubuntu Updates, Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 03, 2023 Critical Ubuntu
203

Mageia 8: MGASA-2023-0126 Moderate: Python-CairoSVG DoS Risk

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or denial of service. Version 2.7.0 disables CairoSVG's ability to access other . MGASA-2023-0126 - Updated python-cairosvg packages fix security vulnerability Publication date: 06 Apr 2023 URL: https://advisories.mageia.org/MGASA-2023-0126.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-27586 CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or denial of service. Version 2.7.0 disables CairoSVG's ability to access other files online by default. (CVE-2023-27586) References: - https://bugs.mageia.org/show_bug.cgi?id=31730 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/5HDBMOMLE6GFKXPLKIWFWM2Q6V4DQKXP/ - https://github.com/Kozea/CairoSVG/security/advisories/GHSA-rwmf-w63j-p7gv - https://www.cve.org/CVERecord?id=CVE-2023-27586 SRPMS: - 8/core/python-cairosvg-2.5.1-1.2.mga8 . The latest python-cairosvg versions include an essential security patch addressing vulnerabilities related to forgery and potential denial of service attacks.. CairoSVG, Python Security, Server-Side Risks, Mageia Updates. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 06, 2023 Important Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here