Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 494
Alerts This Week
Warning Icon 1 494

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 10 articles for you...
87

Debian DSA-6213-1 LXD Important Privilege Escalation Fix

Multiple security issues were discovered in LXD, a system container and virtual machine manager, which could result in restriction bypass or privilege escalation. For the oldstable distribution (bookworm), these problems have been fixed in version 5.0.2-5+deb12u5.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6213-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 15, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : lxd CVE ID : CVE-2026-34177 CVE-2026-34178 CVE-2026-34179 Multiple security issues were discovered in LXD, a system container and virtual machine manager, which could result in restriction bypass or privilege escalation. For the oldstable distribution (bookworm), these problems have been fixed in version 5.0.2-5+deb12u5. For the stable distribution (trixie), these problems have been fixed in version 5.0.2+git20231211.1364ae4-9+deb13u5. We recommend that you upgrade your lxd packages. For the detailed security status of lxd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/lxd Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Discover security issues fixed in LXD on Debian affecting system containers - upgrade for protection against threats.. Debian LXD Security Issues, Privilege Escalation Fix, Container Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 15, 2026 Important Debian
87

Debian DSA-6212-1 Incus Important Privilege Escalation Issues

Two security issues were discovered in Incus, a system container and virtual machine manager, which could result in restriction bypass or privilege escalation. For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u6.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6212-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 15, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : incus CVE ID : CVE-2026-34178 CVE-2026-34179 Two security issues were discovered in Incus, a system container and virtual machine manager, which could result in restriction bypass or privilege escalation. For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u6. We recommend that you upgrade your incus packages. For the detailed security status of incus please refer to its security tracker page at: https://security-tracker.debian.org/tracker/incus Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Two critical security issues fixed in Incus for Debian affecting privilege escalation and restriction bypass. Upgrade recommended.. Debian Incus Security Advisory Privilege Escalation Bypass Issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 15, 2026 Important Debian
87

Debian DSA-5901-1: addressing security vulnerabilities in mediawiki

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure, cross-site scripting or restriction bypass. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5901-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 13, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mediawiki CVE ID : CVE-2025-3469 CVE-2025-32696 CVE-2025-32697 CVE-2025-32698 CVE-2025-32699 CVE-2025-32700 Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure, cross-site scripting or restriction bypass. For the stable distribution (bookworm), these problems have been fixed in version 1:1.39.12-1~deb12u1. We recommend that you upgrade your mediawiki packages. For the detailed security status of mediawiki please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/mediawiki Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Uncover various vulnerabilities in MediaWiki that could result in data leakage, cross-site scripting (XSS), and circumvention of access controls.. Debian Security Advisories, MediaWiki Security Issues, Update MediaWiki. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 13, 2025 Important Debian
172

Ubuntu 22.04 & 20.04: USN-7035-1 Critical: AppArmor Mount Bypass

AppArmor restrictions could be bypassed for rules allowing mount operations. ========================================================================== Ubuntu Security Notice USN-7035-1 September 25, 2024 apparmor vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: AppArmor restrictions could be bypassed for rules allowing mount operations Software Description: - apparmor: Linux security system Details: It was discovered that the AppArmor policy compiler incorrectly generated looser restrictions than expected for rules allowing mount operations. A local attacker could possibly use this to bypass AppArmor restrictions in applications where some mount operations were permitted. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS apparmor 3.0.4-2ubuntu2.4 Ubuntu 20.04 LTS apparmor 2.13.3-7ubuntu5.4 In general, a standard system update will make all the necessary changes. After this update, applications confined by policies with mount operations restrictions may need to have the rules updated. References: https://ubuntu.com/security/notices/USN-7035-1 https://bugs.launchpad.net/apparmor/+bug/1597017 CVE-2016-1585 Package Information: https://launchpad.net/ubuntu/+source/apparmor/3.0.4-2ubuntu2.4 . Ubuntu Security Update USN-7036-1 addresses a potential kernel flaw and outlines critical measures for safeguarding system integrity.. apparmor update, ubuntu advisory, apparmor restrictions, security instructions. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 25, 2024 Critical Ubuntu
87

Debian: DSA-5642-1 Moderate: php-dompdf-svg-lib Denial Of Service Risks

Three security issues were discovered in php-svg-lib, a PHP library to read, parse and export to PDF SVG files, which could result in denial of service, restriction bypass or the execution of arbitrary code. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5642-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff March 20, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : php-dompdf-svg-lib CVE ID : CVE-2023-50251 CVE-2023-50252 CVE-2024-25117 Three security issues were discovered in php-svg-lib, a PHP library to read, parse and export to PDF SVG files, which could result in denial of service, restriction bypass or the execution of arbitrary code. For the stable distribution (bookworm), these problems have been fixed in version 0.5.0-3+deb12u1. We recommend that you upgrade your php-dompdf-svg-lib packages. For the detailed security status of php-dompdf-svg-lib please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/php-dompdf-svg-lib Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Several vulnerabilities in php-dompdf-svg-lib may lead to Denial of Service, unauthorized access, or remote code execution. Suggested immediate updates.. php Svg Library, Debian Security, DoS Threats, Code Execution Risks. . LinuxSecurity.com Team

Calendar%202 Mar 20, 2024 Debian
202

openSUSE: 2023:3830-1 Moderate: Fix xrdp Session Handling Issue

This update for xrdp fixes the following issues: CVE-2023-40184: Fixed restriction bypass via improper session handling (bsc#1214805).. # Security update for xrdp Announcement ID: SUSE-SU-2023:3830-1 Rating: moderate References: * #1214805 Cross-References: * CVE-2023-40184 CVSS scores: * CVE-2023-40184 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2023-40184 ( NVD ): 2.6 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for xrdp fixes the following issues: * CVE-2023-40184: Fixed restriction bypass via improper session handling (bsc#1214805). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3830=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-3830=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-3830=1 * Basesystem Module 15-SP5 zypper in -t patchSUSE-SLE-Module-Basesystem-15-SP5-2023-3830=1 * SUSE Manager Proxy 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-3830=1 * SUSE Manager Retail Branch Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.2-2023-3830=1 * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-3830=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * xrdp-debugsource-0.9.13.1-150200.4.24.1 * libpainter0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-devel-0.9.13.1-150200.4.24.1 * libpainter0-0.9.13.1-150200.4.24.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-0.9.13.1-150200.4.24.1 * librfxencode0-0.9.13.1-150200.4.24.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * xrdp-debugsource-0.9.13.1-150200.4.24.1 * libpainter0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-devel-0.9.13.1-150200.4.24.1 * libpainter0-0.9.13.1-150200.4.24.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-0.9.13.1-150200.4.24.1 * librfxencode0-0.9.13.1-150200.4.24.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * xrdp-debugsource-0.9.13.1-150200.4.24.1 * libpainter0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-devel-0.9.13.1-150200.4.24.1 * libpainter0-0.9.13.1-150200.4.24.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-0.9.13.1-150200.4.24.1 * librfxencode0-0.9.13.1-150200.4.24.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * xrdp-debugsource-0.9.13.1-150200.4.24.1 * libpainter0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-devel-0.9.13.1-150200.4.24.1 * libpainter0-0.9.13.1-150200.4.24.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-0.9.13.1-150200.4.24.1 *librfxencode0-0.9.13.1-150200.4.24.1 * SUSE Manager Proxy 4.2 (x86_64) * xrdp-debugsource-0.9.13.1-150200.4.24.1 * libpainter0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-devel-0.9.13.1-150200.4.24.1 * libpainter0-0.9.13.1-150200.4.24.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-0.9.13.1-150200.4.24.1 * librfxencode0-0.9.13.1-150200.4.24.1 * SUSE Manager Retail Branch Server 4.2 (x86_64) * xrdp-debugsource-0.9.13.1-150200.4.24.1 * libpainter0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-devel-0.9.13.1-150200.4.24.1 * libpainter0-0.9.13.1-150200.4.24.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-0.9.13.1-150200.4.24.1 * librfxencode0-0.9.13.1-150200.4.24.1 * SUSE Manager Server 4.2 (ppc64le s390x x86_64) * xrdp-debugsource-0.9.13.1-150200.4.24.1 * libpainter0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-devel-0.9.13.1-150200.4.24.1 * libpainter0-0.9.13.1-150200.4.24.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-0.9.13.1-150200.4.24.1 * librfxencode0-0.9.13.1-150200.4.24.1 ## References: * https://www.suse.com/security/cve/CVE-2023-40184.html * https://bugzilla.suse.com/show_bug.cgi?id=1214805 . A critical patch for xrdp focusing on mitigating security loopholes related to access control on openSUSE platforms. Discover further details now!. xrdp Security Update, openSUSE Advisory, restriction bypass fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 27, 2023 Important OpenSUSE
197

Debian 10 Buster DLA-3322-1 Moderate: Runc SELinux Bypass

runc, as used in Docker and other products, allows AppArmor and SELinux restriction bypass, and thus a malicious Docker image could breach isolation. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3322-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sylvain Beucler February 18, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : golang-github-opencontainers-selinux Version : 1.0.0~rc1+git20170621.5.4a2974b-1+deb10u1 CVE ID : CVE-2019-16884 Debian Bug : 942027 runc, as used in Docker and other products, allows AppArmor and SELinux restriction bypass, and thus a malicious Docker image could breach isolation. This update carries SELinux-related fixes in the golang-github-opencontainers-selinux library, that will be leveraged in the upcoming runc security update. For Debian 10 buster, this problem has been fixed in version 1.0.0~rc1+git20170621.5.4a2974b-1+deb10u1. We recommend that you upgrade your golang-github-opencontainers-selinux packages. For the detailed security status of golang-github-opencontainers-selinux please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/golang-github-opencontainers-selinux Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3323-1 concerning a vulnerability in systemd that could lead to privilege escalation on containerized services.. Debian LTS, SELinux Fix, Runc Security, Docker Isolation. . LinuxSecurity.com Team

Calendar%202 Feb 18, 2023 Debian LTS
100

SUSE: 2023:2025-2 Critical: Linux Kernel Live Patch 30 for SLE 15 SP1

An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 30 for SLE 15 SP1) ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1949-1 Rating: important References: #1199602 #1199834 Cross-References: CVE-2022-30594 CVSS scores: CVE-2022-30594 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-30594 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise High Performance Computing 15-SP1 SUSE Linux Enterprise Module for Live Patching 15-SP1 SUSE Linux Enterprise Server 15-SP1 SUSE Linux Enterprise Server for SAP Applications 15-SP1 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for the Linux Kernel 4.12.14-150100_197_111 fixes several issues. The following security issue was fixed: - CVE-2022-30594: Fixed restriction bypass on setting the PT_SUSPEND_SECCOMP flag (bnc#1199602). - Add missing module_mutex lock to module notifier for previous live patches (bsc#1199834). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Live Patching 15-SP1: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP1-2022-1949=1 Package List: - SUSE Linux Enterprise Module for Live Patching 15-SP1 (ppc64le x86_64): kernel-livepatch-4_12_14-150100_197_111-default-3-150100.2.2 References: https://www.suse.com/security/cve/CVE-2022-30594.html https://bugzilla.suse.com/1199602 https://bugzilla.suse.com/1199834 . SUSE Security Update for Linux Kernel tackles urgent vulnerabilities in Live Patch 30 for SLE 15 SP2 alongside suggested actions.. Linux Kernel, SUSE Security Update, Live Patching, Kernel Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 06, 2022 Critical SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200