Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
172

Ubuntu 25.10: Erlang Critical DoS Issue Fix USN-7831-1 CVE-2025-48038

Several security issues were fixed in Erlang.. ========================================================================== Ubuntu Security Notice USN-7831-1 October 21, 2025 erlang vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Erlang. Software Description: - erlang: Concurrent, real-time, distributed functional language Details: It was discovered that Erlang incorrectly handled resource allocation and consumption in the SFTP SSH module. An attacker could possibly use this issue cause Erlang to consume excessive resources, leading to a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 erlang 1:27.3.4.1+dfsg-1ubuntu0.1 erlang-ssh 1:27.3.4.1+dfsg-1ubuntu0.1 Ubuntu 25.04 erlang 1:27.3+dfsg-1ubuntu1.3 erlang-ssh 1:27.3+dfsg-1ubuntu1.3 Ubuntu 24.04 LTS erlang 1:25.3.2.8+dfsg-1ubuntu4.5 erlang-ssh 1:25.3.2.8+dfsg-1ubuntu4.5 Ubuntu 22.04 LTS erlang 1:24.2.1+dfsg-1ubuntu0.6 erlang-ssh 1:24.2.1+dfsg-1ubuntu0.6 Ubuntu 20.04 LTS erlang 1:22.2.7+dfsg-1ubuntu0.5+esm1 Available with Ubuntu Pro erlang-ssh 1:22.2.7+dfsg-1ubuntu0.5+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS erlang 1:20.2.2+dfsg-1ubuntu2+esm2 Available with Ubuntu Pro erlang-ssh 1:20.2.2+dfsg-1ubuntu2+esm2 Available withUbuntu Pro Ubuntu 16.04 LTS erlang 1:18.3-dfsg-1ubuntu3.1+esm2 Available with Ubuntu Pro erlang-ssh 1:18.3-dfsg-1ubuntu3.1+esm2 Available with Ubuntu Pro Ubuntu 14.04 LTS erlang 1:16.b.3-dfsg-1ubuntu2.2+esm1 Available with Ubuntu Pro erlang-ssh 1:16.b.3-dfsg-1ubuntu2.2+esm1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7831-1 CVE-2025-48038, CVE-2025-48039, CVE-2025-48040, CVE-2025-48041 Package Information: https://launchpad.net/ubuntu/+source/erlang/1:27.3.4.1+dfsg-1ubuntu0.1 https://launchpad.net/ubuntu/+source/erlang/1:25.3.2.8+dfsg-1ubuntu4.5 https://launchpad.net/ubuntu/+source/erlang/1:24.2.1+dfsg-1ubuntu0.6 . Multiple security issues in Erlang for Ubuntu fixed; updates recommended for stability and protection against DoS.. Erlang security, Ubuntu updates, resource management, Denial of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 21, 2025 Critical Ubuntu
89

Fedora 42 Release: Critical Update for Kubernetes 1.32 Resource Management

Update to release v1.32.6. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-b8463b0972 2025-06-29 01:03:14.526432+00:00 -------------------------------------------------------------------------------- Name : kubernetes1.32 Product : Fedora 42 Version : 1.32.6 Release : 1.fc42 URL : https://github.com/kubernetes/kubernetes Summary : Open Source Production-Grade Container Scheduling And Management Platform Description : Production-Grade Container Scheduling and Management. Installs kubelet, the kubernetes agent on each machine in a cluster. The kubernetes-client sub-package, containing kubectl, is recommended but not strictly required. The kubernetes-client sub-package should be installed on control plane machines. -------------------------------------------------------------------------------- Update Information: Update to release v1.32.6 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 19 2025 Bradley G Smith - 1.32.6-1 - Update to release v1.32.6 - Resolves: rhbz#2373848,rhbz#2373847 - Resolves: CVE-2025-4563 - Upstream fixes and cleanups -------------------------------------------------------------------------------- References: [ 1 ] Bug #2373847 - CVE-2025-4563 kubernetes1.32: NodeRestriction Admission Controller Dynamic Resource Allocation Bypass [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2373847 [ 2 ] Bug #2373848 - CVE-2025-4563 kubernetes1.32: NodeRestriction Admission Controller Dynamic Resource Allocation Bypass [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373848 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-b8463b0972' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Kubernetes version 1.32.6 patch for Fedora release 42 corrects a significant bug in resource distribution. Update is advised.. kubernetes upgrade, Fedora security, container management. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 29, 2025 Critical Fedora
197

Debian 10 LTS: DLA-3834-1 Critical: Netty Denial Of Service Fix

Julien Viet discovered that Netty, a Java NIO client/server socket framework, was vulnerable to allocation of resources without limits or throttling due to the accumulation of data in the HttpPostRequestDecoder. This would allow an attacker to cause a denial of service. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3834-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany June 21, 2024 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : netty Version : 1:4.1.33-1+deb10u5 CVE ID : CVE-2024-29025 Debian Bug : 1068110 Julien Viet discovered that Netty, a Java NIO client/server socket framework, was vulnerable to allocation of resources without limits or throttling due to the accumulation of data in the HttpPostRequestDecoder. This would allow an attacker to cause a denial of service. For Debian 10 buster, this problem has been fixed in version 1:4.1.33-1+deb10u5. We recommend that you upgrade your netty packages. For the detailed security status of netty please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/netty Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3845-1 tackles a significant security issue in OpenSSL, providing urgent updates to protect users from potential exploits.. Netty Security, Debian LTS, Denial of Service, Resource Management, Java Framework. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 21, 2024 Critical Debian LTS
100

SUSE: 2018:2305-1 Moderate: ffmpeg Security Issues Fixed

An update that fixes 5 vulnerabilities is now available. . SUSE Security Update: Security update for ffmpeg ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:2305-1 Rating: moderate References: #1100356 #1102687 #1102688 #1102689 #1102899 Cross-References: CVE-2018-13302 CVE-2018-1999010 CVE-2018-1999011 CVE-2018-1999012 CVE-2018-1999013 Affected Products: SUSE Linux Enterprise Workstation Extension 15 SUSE Linux Enterprise Module for Desktop Applications 15 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for ffmpeg fixes the following issues: Security issues fixed: - CVE-2018-13302: Fixed out of array access issue (bsc#1100356). - CVE-2018-1999010: Fixed multiple out of array access vulnerabilities in the mms protocol that could result in accessing out of bound data via specially crafted input files (bnc#1102899) - CVE-2018-1999011: Fixed a heap buffer overflow in asf_o format demuxer that could result in remote code execution (bnc#1102689) - CVE-2018-1999012: Fixed an infinite loop vulnerability in pva format demuxer that could result in excessive amount of ressource allocation like CPU an RAM (CVE-2018-1999012 bnc#1102688). - CVE-2018-1999013: Fixed an use-after-free vulnerability in the realmedia demuxer that could allow remote attackers to read heap memory (bnc#1102687) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 15: zypper in -t patch SUSE-SLE-Product-WE-15-2018-1544=1 - SUSE Linux Enterprise Module for Desktop Applications 15: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-2018-1544=1 Package List: - SUSE Linux Enterprise Workstation Extension 15 (x86_64): ffmpeg-debuginfo-3.4.2-4.5.1 ffmpeg-debugsource-3.4.2-4.5.1 libavcodec-devel-3.4.2-4.5.1 libavformat-devel-3.4.2-4.5.1 libavformat57-3.4.2-4.5.1 libavformat57-debuginfo-3.4.2-4.5.1 libavresample-devel-3.4.2-4.5.1 libavresample3-3.4.2-4.5.1 libavresample3-debuginfo-3.4.2-4.5.1 - SUSE Linux Enterprise Module for Desktop Applications 15 (aarch64 ppc64le s390x x86_64): ffmpeg-debuginfo-3.4.2-4.5.1 ffmpeg-debugsource-3.4.2-4.5.1 libavcodec57-3.4.2-4.5.1 libavcodec57-debuginfo-3.4.2-4.5.1 libavutil-devel-3.4.2-4.5.1 libavutil55-3.4.2-4.5.1 libavutil55-debuginfo-3.4.2-4.5.1 libpostproc-devel-3.4.2-4.5.1 libpostproc54-3.4.2-4.5.1 libpostproc54-debuginfo-3.4.2-4.5.1 libswresample-devel-3.4.2-4.5.1 libswresample2-3.4.2-4.5.1 libswresample2-debuginfo-3.4.2-4.5.1 libswscale-devel-3.4.2-4.5.1 libswscale4-3.4.2-4.5.1 libswscale4-debuginfo-3.4.2-4.5.1 References: https://www.suse.com/security/cve/CVE-2018-13302.html https://www.suse.com/security/cve/CVE-2018-1999010.html https://www.suse.com/security/cve/CVE-2018-1999011.html https://www.suse.com/security/cve/CVE-2018-1999012.html https://www.suse.com/security/cve/CVE-2018-1999013.html https://bugzilla.suse.com/1100356 https://bugzilla.suse.com/1102687 https://bugzilla.suse.com/1102688 https://bugzilla.suse.com/1102689 https://bugzilla.suse.com/1102899 . A patch for SUSE that resolves various vulnerabilities in libavcodec, boosting overall system security and stability.. SUSE Update, ffmpeg Security, Software Update, Patch Management. . LinuxSecurity.com Team

Calendar 2 Aug 11, 2018 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here