Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 22 articles for you...
217

Oracle Linux 9 Podman Important ELSA-2026-38878 CVE-2026-39822

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-38878 http://linux.oracle.com/errata/ELSA-2026-38878.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: podman-5.8.2-5.0.1.el9_8.x86_64.rpm podman-docker-5.8.2-5.0.1.el9_8.noarch.rpm podman-plugins-5.8.2-5.0.1.el9_8.x86_64.rpm podman-remote-5.8.2-5.0.1.el9_8.x86_64.rpm podman-tests-5.8.2-5.0.1.el9_8.x86_64.rpm aarch64: podman-5.8.2-5.0.1.el9_8.aarch64.rpm podman-docker-5.8.2-5.0.1.el9_8.noarch.rpm podman-plugins-5.8.2-5.0.1.el9_8.aarch64.rpm podman-remote-5.8.2-5.0.1.el9_8.aarch64.rpm podman-tests-5.8.2-5.0.1.el9_8.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/podman-5.8.2-5.0.1.el9_8.src.rpm Related CVEs: CVE-2026-39822 Description of changes: [5.8.2-5.0.1] - Rework CNI/Netavark detection logic [JIRA: EVG-3769] - Rebuild on new golang to support experimental GODEBUG fipsnoenforceems - Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404] [6:5.8.2-5] - rebuild for CVE-2026-39822 - Resolves: RHEL-193646 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 9 updates for podman address critical security issues and enhance performance. Stay protected with the latest fixes.. Oracle Linux updates, podman security, software patching, system vulnerabilities, risk assessment. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 14, 2026 Important Oracle
202

openSUSE Flannel Important Security Fix Advisory 2026-0239-1

An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for flannel ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0239-1 Rating: important References: #1265780 #1266620 Cross-References: CVE-2026-33814 CVE-2026-39821 CVSS scores: CVE-2026-33814 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2026-39821 (SUSE): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for flannel fixes the following issues: - Update to version 0.28.7: * prepare for release v0.28.7 (#2485) * fix: use install-conf in chart (#2484) * fix: use semver tag type in Docker meta to support release events (#2483) * build(deps): bump github/codeql-action/upload-sarif (#2480) * build(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 (#2473), fix for CVE-2026-33814 (boo#1265780) and CVE-2026-39821 (boo#1266620) * build(deps): bump docker/build-push-action from 7.2.0 to 7.3.0 (#2479) * build(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 (#2478) * build(deps): bump docker/metadata-action from 6.1.0 to 6.2.0 (#2476) * build(deps): bump the tencent group with 2 updates (#2475) * build(deps): bump the etcd group with 4 updates (#2474) * fix: skip invalid CIDRs in subnet file readers (#2454) * subnet/etcd: recover subnet watch from compaction (#2471) * Bump the tencent group across 1 directory with 2 updates (#2461) * Bump actions/attest-build-provenance from 4.1.0 to 4.1.1 (#2467) * Bump actions/setup-go from 6.4.0 to 6.5.0 (#2468) * feat: new install_conf cmd to install flannel'sconfig file (#2466) * Bump the other-go-modules group with 2 updates (#2464) * Bump actions/checkout from 6.0.2 to 7.0.0 (#2465) * Bump github/codeql-action from 4.36.0 to 4.36.2 (#2463) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-239=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): flannel-0.28.7-bp157.2.12.1 - openSUSE Backports SLE-15-SP7 (noarch): flannel-k8s-yaml-0.28.7-bp157.2.12.1 References: https://www.suse.com/security/cve/CVE-2026-33814.html https://www.suse.com/security/cve/CVE-2026-39821.html https://bugzilla.suse.com/1265780 https://bugzilla.suse.com/1266620 . An important update to openSUSE flannel addresses critical issues to enhance security. Learn about the flaws and fixes.. openSUSE flannel security update, crucial patches, security advisory highlights. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 10, 2026 Important OpenSUSE
217

Oracle Thunderbird Important Security Advisory ELSA-2026-33445

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-33445 http://linux.oracle.com/errata/ELSA-2026-33445.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: thunderbird-140.12.0-1.0.1.el8_10.x86_64.rpm aarch64: thunderbird-140.12.0-1.0.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/thunderbird-140.12.0-1.0.1.el8_10.src.rpm Related CVEs: CVE-2026-12289 CVE-2026-12290 CVE-2026-12291 CVE-2026-12292 CVE-2026-12294 CVE-2026-12295 CVE-2026-12296 CVE-2026-12297 CVE-2026-12298 CVE-2026-12299 CVE-2026-12302 CVE-2026-12304 CVE-2026-12305 CVE-2026-12306 CVE-2026-12307 CVE-2026-12308 CVE-2026-12309 CVE-2026-12310 CVE-2026-12311 CVE-2026-12312 CVE-2026-12313 CVE-2026-12314 CVE-2026-12315 CVE-2026-12324 CVE-2026-12325 CVE-2026-12327 CVE-2026-12328 CVE-2026-12329 CVE-2026-12330 Description of changes: [140.12.0-1.0.1] - Fix prefs for new nss [Orabug: 37079820] - Add Oracle prefs file [140.12.0] - Add OpenELA debranding [140.12.0-1] - Update to 140.12.0 ESR _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux updates for Thunderbird resolve multiple security issues. These essential fixes help maintain system integrity and security.. Oracle Linux Thunderbird update security issues correction. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 02, 2026 Important Oracle
100

SUSE Linux Micro 6.0 Security Update 2026-20863-1 Kernel Important Issues

An update that solves eight vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:20863-1 Release Date: 2026-03-24T16:49:35Z Rating: important References: * bsc#1247240 * bsc#1255053 * bsc#1255378 * bsc#1255402 * bsc#1255895 * bsc#1256624 * bsc#1256644 * bsc#1257669 Cross-References: * CVE-2025-38488 * CVE-2025-40258 * CVE-2025-40284 * CVE-2025-40297 * CVE-2025-68284 * CVE-2025-68285 * CVE-2025-68813 * CVE-2025-71085 CVSS scores: * CVE-2025-38488 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38488 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38488 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40258 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40258 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40284 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40284 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40297 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40297 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68284 ( SUSE ): 7.0 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-68284 ( SUSE ): 7.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2025-68285 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-68285 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68813 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-68813 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71085 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N *CVE-2025-71085 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues The following security issues were fixed: * CVE-2025-38488: smb: client: fix use-after-free in crypt_message when using async crypto (bsc#1247240). * CVE-2025-40258: mptcp: fix race condition in mptcp_schedule_work() (bsc#1255053). * CVE-2025-40284: Bluetooth: MGMT: cancel mesh send timer when hdev removed (bsc#1257669). * CVE-2025-40297: net: bridge: fix use-after-free due to MST port state bypass (bsc#1255895). * CVE-2025-68284: libceph: prevent potential out-of-bounds writes in handle_auth_session_key() (bsc#1255378). * CVE-2025-68285: libceph: fix potential use-after-free in have_mon_and_osd_map() (bsc#1255402). * CVE-2025-68813: ipvs: fix ipv4 null-ptr-deref in route error path (bsc#1256644). * CVE-2025-71085: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (bsc#1256624). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-313=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-34-default-6-1.1 * kernel-livepatch-MICRO-6-0_Update_11-debugsource-6-1.1 * kernel-livepatch-6_4_0-34-default-debuginfo-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-38488.html * https://www.suse.com/security/cve/CVE-2025-40258.html * https://www.suse.com/security/cve/CVE-2025-40284.html * https://www.suse.com/security/cve/CVE-2025-40297.html *https://www.suse.com/security/cve/CVE-2025-68284.html * https://www.suse.com/security/cve/CVE-2025-68285.html * https://www.suse.com/security/cve/CVE-2025-68813.html * https://www.suse.com/security/cve/CVE-2025-71085.html * https://bugzilla.suse.com/show_bug.cgi?id=1247240 * https://bugzilla.suse.com/show_bug.cgi?id=1255053 * https://bugzilla.suse.com/show_bug.cgi?id=1255378 * https://bugzilla.suse.com/show_bug.cgi?id=1255402 * https://bugzilla.suse.com/show_bug.cgi?id=1255895 * https://bugzilla.suse.com/show_bug.cgi?id=1256624 * https://bugzilla.suse.com/show_bug.cgi?id=1256644 * https://bugzilla.suse.com/show_bug.cgi?id=1257669 . Install the latest SUSE Linux Micro kernel patch addressing eight essential updates and security issues.. SUSE Linux Micro, Kernel Patch, Security Updates, Risk Management, Important Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 27, 2026 Important SuSE
100

SUSE: 2025:02121-1 critical: helm login problem identified and addressed

* bsc#1241802 Cross-References: * CVE-2025-22872 . # Security update for helm Announcement ID: SUSE-SU-2025:02121-1 Release Date: 2025-06-26T08:34:33Z Rating: important References: * bsc#1241802 Cross-References: * CVE-2025-22872 CVSS scores: * CVE-2025-22872 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L * CVE-2025-22872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L * CVE-2025-22872 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L Affected Products: * Containers Module 15-SP6 * Containers Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP6 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for helm fixes the following issues: Update to version 3.18.3: * build(deps): bump golang.org/x/crypto from 0.38.0 to 0.39.0 6838ebc (dependabot[bot]) * fix: user username password for login 5b9e2f6 (Terry Howe) * Update pkg/registry/transport.go 2782412 (Terry Howe) * Update pkg/registry/transport.go e66cf6a (Terry Howe) * fix: add debug logging to oci transport 191f05c (Terry Howe) Update to version 3.18.2: * fix: legacy docker support broken for login 04cad46 (Terry Howe) * Handle an empty registry config file. bc9f8a2 (Matt Farina) Update to version 3.18.1: * Notes: * This release fixes regressions around template generation and OCI registry interaction in 3.18.0 * There are at least 2 known regressions unaddressed in this release. They are being worked on. * Empty registry configurationfiles. When the file exists but it is empty. * Login to Docker Hub on some domains fails. * Changelog * fix(client): skipnode utilization for PreCopy * fix(client): layers now returns manifest - remove duplicate from descriptors * fix(client): return nil on non-allowed media types * Prevent fetching newReference again as we have in calling method * Prevent failure when resolving version tags in oras memory store * Update pkg/plugin/plugin.go * Update pkg/plugin/plugin.go * Wait for Helm v4 before raising when platformCommand and Command are set * Fix 3.18.0 regression: registry login with scheme * Revert "fix (helm) : toToml` renders int as float [ backport to v3 ]" Update to version 3.18.0 (bsc#1241802, CVE-2025-22872): * Notable Changes * Add support for JSON Schema 2020 * Enabled cpu and memory profiling * Add hook annotation to output hook logs to client on error * Changelog * build(deps): bump the k8s-io group with 7 updates * fix: govulncheck workflow * bump version to v3.18.0 * fix:add proxy support when mTLS configured * docs: Note about http fallback for OCI registries * Bump net package to avoid CVE on dev-v3 * Bump toml * backport #30677to dev3 * build(deps): bump github.com/rubenv/sql-migrate from 1.7.2 to 1.8.0 * Add install test for TakeOwnership flag * Fix --take-ownership * build(deps): bump github.com/rubenv/sql-migrate from 1.7.1 to 1.7.2 * build(deps): bump golang.org/x/crypto from 0.36.0 to 0.37.0 * build(deps): bump golang.org/x/term from 0.30.0 to 0.31.0 * Testing text bump * Permit more Go version and not only 1.23.8 * Bumps github.com/distribution/distribution/v3 from 3.0.0-rc.3 to 3.0.0 * Unarchiving fix * Fix typo * Report as debug log, the time spent waiting for resources * build(deps): bump github.com/containerd/containerd from 1.7.26 to 1.7.27 * Update pkg/registry/fallback.go * automatic fallback to http * chore(oci):upgrade to ORAS v2 * Updating to 0.37.0 for x/net * build(deps): bump the k8s-io group with 7 updates * build(deps): bump golang.org/x/crypto from 0.35.0 to 0.36.0 * build(deps): bump github.com/opencontainers/image-spec * build(deps): bump github.com/containerd/containerd from 1.7.25 to 1.7.26 * build(deps): bump golang.org/x/crypto from 0.33.0 to 0.35.0 * Fix cherry-pick helm.sh/helm/v4 -> helm.sh/helm/v3 * Add HookOutputFunc and generic yaml unmarshaller * clarify fix error message * fix err check * add short circuit return * Add hook annotations to output pod logs to client on success and fail * chore: use []error instead of []string * Update cmd/helm/profiling.go * chore: update profiling doc in CONTRIBUTING.md * Update CONTRIBUTING guide * Prefer environment variables to CLI flags * Move pprof paths to HELM_PPROF env variable * feat: Add flags to enable CPU and memory profiling * build(deps): bump github.com/distribution/distribution/v3 * build(deps): bump github.com/spf13/cobra from 1.8.1 to 1.9.1 * Moving to SetOut and SetErr for Cobra * build(deps): bump the k8s-io group with 7 updates * build(deps): bump golang.org/x/crypto from 0.32.0 to 0.33.0 * build(deps): bump golang.org/x/term from 0.28.0 to 0.29.0 * build(deps): bump golang.org/x/text from 0.21.0 to 0.22.0 * build(deps): bump github.com/spf13/pflag from 1.0.5 to 1.0.6 * build(deps): bump github.com/cyphar/filepath-securejoin * build(deps): bump github.com/evanphx/json-patch * build(deps): bump the k8s-io group with 7 updates * fix: check group for resource info match * Bump github.com/cyphar/filepath-securejoin from 0.3.6 to 0.4.0 * add test for nullifying nested global value * Ensuring the file paths are clean prior to passing to securejoin * Bump github.com/containerd/containerd from 1.7.24 to 1.7.25 * Bump golang.org/x/crypto from 0.31.0 to 0.32.0 * Bump golang.org/x/term from 0.27.0 to 0.28.0 * bump version to v3.17.0 * Bump github.com/moby/term from 0.5.0 to 0.5.2 * Add test case for removing an entire object * Tests for bugfix: Override subcharts with null values #12879 * feat: Added multi-platform plugin hook support to v3 * This commit fixes the issue where the yaml.Unmarshaller converts all int values into float64, this passes in option to decoder, which enables conversion of int into . * merge null child chart objects ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-2121=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-2121=1 * Containers Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Containers-15-SP6-2025-2121=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2025-2121=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-2121=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-2121=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * helm-3.18.3-150000.1.50.1 * helm-debuginfo-3.18.3-150000.1.50.1 * openSUSE Leap 15.6 (noarch) * helm-fish-completion-3.18.3-150000.1.50.1 * helm-bash-completion-3.18.3-150000.1.50.1 * helm-zsh-completion-3.18.3-150000.1.50.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * helm-3.18.3-150000.1.50.1 * helm-debuginfo-3.18.3-150000.1.50.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * helm-bash-completion-3.18.3-150000.1.50.1 * Containers Module 15-SP6 (aarch64 ppc64le s390x x86_64) * helm-3.18.3-150000.1.50.1 * helm-debuginfo-3.18.3-150000.1.50.1 * Containers Module 15-SP6 (noarch) *helm-zsh-completion-3.18.3-150000.1.50.1 * helm-bash-completion-3.18.3-150000.1.50.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * helm-3.18.3-150000.1.50.1 * helm-debuginfo-3.18.3-150000.1.50.1 * Containers Module 15-SP7 (noarch) * helm-zsh-completion-3.18.3-150000.1.50.1 * helm-bash-completion-3.18.3-150000.1.50.1 * SUSE Package Hub 15 15-SP6 (noarch) * helm-fish-completion-3.18.3-150000.1.50.1 * SUSE Package Hub 15 15-SP7 (noarch) * helm-fish-completion-3.18.3-150000.1.50.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22872.html * https://bugzilla.suse.com/show_bug.cgi?id=1241802 . Essential enhancement for helm tackles significant vulnerabilities to fortify SUSE system defense and preserve data reliability.. SUSE security update, helm patch instructions, critical helm issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 26, 2025 Important SuSE
172

Ubuntu 20.04 LTS: USN-7516-1 critical: Linux kernel security issues

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7516-1 May 16, 2025 linux, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-oracle vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-oracle: Linux kernel for Oracle Cloud systems - linux-azure-5.4: Linux kernel for Microsoft Azure cloud systems - linux-gcp-5.4: Linux kernel for Google Cloud Platform (GCP) systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - PowerPC architecture; - Block layer subsystem; - Drivers core; - Network block device driver; - Character device driver; - GPU drivers; - HID subsystem; - InfiniBand drivers; - Media drivers; - Network drivers; - PPS (Pulse Per Second) driver; - PTP clock framework; - RapidIO drivers; - Real Time Clock drivers; - SCSI subsystem; - SLIMbus drivers; - QCOM SoC drivers; - Trusted Execution Environment drivers; - USB DSL drivers; - USB Device Class drivers; - USB core drivers; - USB Gadget drivers; - USB Host Controller drivers; - Renesas USBHS Controller drivers; - File systems infrastructure; - BTRFS file system; - NILFS2 file system; - UBI file system; - KVM subsystem; - L3 Master device support module; - Process Accounting mechanism; - printk logging mechanism; - Scheduler infrastructure; - Tracing infrastructure; - Memorymanagement; - 802.1Q VLAN protocol; - B.A.T.M.A.N. meshing protocol; - Bluetooth subsystem; - Networking core; - IPv4 networking; - IPv6 networking; - Logical Link layer; - NFC subsystem; - Open vSwitch; - Rose network layer; - Network traffic control; - Wireless networking; - Tomoyo security module; (CVE-2025-21866, CVE-2025-21846, CVE-2025-21971, CVE-2025-21909, CVE-2024-58083, CVE-2025-21811, CVE-2025-21776, CVE-2024-58051, CVE-2025-21917, CVE-2025-21935, CVE-2025-21785, CVE-2021-47191, CVE-2025-21765, CVE-2025-21704, CVE-2025-21647, CVE-2024-58069, CVE-2025-21877, CVE-2025-21948, CVE-2024-58007, CVE-2024-58001, CVE-2025-21871, CVE-2024-58055, CVE-2025-21848, CVE-2025-21925, CVE-2024-58058, CVE-2025-21814, CVE-2025-21905, CVE-2025-21898, CVE-2025-21926, CVE-2025-21760, CVE-2024-57973, CVE-2025-21806, CVE-2024-58071, CVE-2025-21761, CVE-2025-21762, CVE-2024-57986, CVE-2025-21708, CVE-2025-21744, CVE-2024-26996, CVE-2024-50055, CVE-2024-58020, CVE-2025-21858, CVE-2025-21715, CVE-2025-21904, CVE-2025-21920, CVE-2024-56599, CVE-2025-21781, CVE-2025-21764, CVE-2025-21865, CVE-2025-21772, CVE-2024-58072, CVE-2025-21928, CVE-2025-21859, CVE-2025-21721, CVE-2025-21719, CVE-2025-21914, CVE-2025-21753, CVE-2024-58009, CVE-2024-57981, CVE-2024-58063, CVE-2024-58052, CVE-2025-21722, CVE-2024-57977, CVE-2025-21736, CVE-2025-21922, CVE-2024-26982, CVE-2025-21718, CVE-2025-21916, CVE-2025-21749, CVE-2025-21787, CVE-2024-58085, CVE-2024-58010, CVE-2024-57979, CVE-2024-57980, CVE-2025-21782, CVE-2025-21791, CVE-2025-21728, CVE-2023-52741, CVE-2025-21934, CVE-2024-58002, CVE-2025-21735, CVE-2025-21910, CVE-2025-21823, CVE-2024-58090, CVE-2025-21862, CVE-2025-21731, CVE-2025-21835, CVE-2024-58017, CVE-2024-58014, CVE-2025-21763) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.4.0-1144-oracle 5.4.0-1144.154 linux-image-5.4.0-1149-gcp 5.4.0-1149.158 linux-image-5.4.0-216-generic 5.4.0-216.236 linux-image-5.4.0-216-generic-lpae 5.4.0-216.236 linux-image-5.4.0-216-lowlatency 5.4.0-216.236 linux-image-gcp-lts-20.04 5.4.0.1149.151 linux-image-generic 5.4.0.216.208 linux-image-generic-lpae 5.4.0.216.208 linux-image-lowlatency 5.4.0.216.208 linux-image-oem 5.4.0.216.208 linux-image-oem-osp1 5.4.0.216.208 linux-image-oracle-lts-20.04 5.4.0.1144.138 linux-image-virtual 5.4.0.216.208 Ubuntu 18.04 LTS linux-image-5.4.0-1149-gcp 5.4.0-1149.158~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-1151-azure 5.4.0-1151.158~18.04.1 Available with Ubuntu Pro linux-image-azure 5.4.0.1151.158~18.04.1 Available with Ubuntu Pro linux-image-gcp 5.4.0.1149.158~18.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7516-1 CVE-2021-47191, CVE-2023-52741, CVE-2024-26982, CVE-2024-26996, CVE-2024-50055, CVE-2024-56599, CVE-2024-57973, CVE-2024-57977, CVE-2024-57979, CVE-2024-57980, CVE-2024-57981, CVE-2024-57986, CVE-2024-58001, CVE-2024-58002, CVE-2024-58007, CVE-2024-58009, CVE-2024-58010, CVE-2024-58014, CVE-2024-58017, CVE-2024-58020, CVE-2024-58051, CVE-2024-58052,CVE-2024-58055, CVE-2024-58058, CVE-2024-58063, CVE-2024-58069, CVE-2024-58071, CVE-2024-58072, CVE-2024-58083, CVE-2024-58085, CVE-2024-58090, CVE-2025-21647, CVE-2025-21704, CVE-2025-21708, CVE-2025-21715, CVE-2025-21718, CVE-2025-21719, CVE-2025-21721, CVE-2025-21722, CVE-2025-21728, CVE-2025-21731, CVE-2025-21735, CVE-2025-21736, CVE-2025-21744, CVE-2025-21749, CVE-2025-21753, CVE-2025-21760, CVE-2025-21761, CVE-2025-21762, CVE-2025-21763, CVE-2025-21764, CVE-2025-21765, CVE-2025-21772, CVE-2025-21776, CVE-2025-21781, CVE-2025-21782, CVE-2025-21785, CVE-2025-21787, CVE-2025-21791, CVE-2025-21806, CVE-2025-21811, CVE-2025-21814, CVE-2025-21823, CVE-2025-21835, CVE-2025-21846, CVE-2025-21848, CVE-2025-21858, CVE-2025-21859, CVE-2025-21862, CVE-2025-21865, CVE-2025-21866, CVE-2025-21871, CVE-2025-21877, CVE-2025-21898, CVE-2025-21904, CVE-2025-21905, CVE-2025-21909, CVE-2025-21910, CVE-2025-21914, CVE-2025-21916, CVE-2025-21917, CVE-2025-21920, CVE-2025-21922, CVE-2025-21925, CVE-2025-21926, CVE-2025-21928, CVE-2025-21934, CVE-2025-21935, CVE-2025-21948, CVE-2025-21971 Package Information: https://launchpad.net/ubuntu/+source/linux/5.4.0-216.236 https://launchpad.net/ubuntu/+source/linux-gcp/5.4.0-1149.158 https://launchpad.net/ubuntu/+source/linux-oracle/5.4.0-1144.154 . A range of vulnerabilities fixed in the recent Ubuntu Linux kernel release to bolster system defenses.. Ubuntu Kernel, Linux Security, System Update, Software Patch, Security Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 16, 2025 Critical Ubuntu
202

openSUSE 15 SP6: 2025:0670-1 critical: Kernel security patch

An update that solves two vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 2 for SLE 15 SP6) Announcement ID: SUSE-SU-2025:0669-1 Release Date: 2025-02-24T09:03:58Z Rating: important References: * bsc#1227371 * bsc#1236783 Cross-References: * CVE-2024-36974 * CVE-2024-53104 CVSS scores: * CVE-2024-36974 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53104 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 6.4.0-150600_23_14 fixes several issues. The following security issues were fixed: * CVE-2024-36974: net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP (bsc#1227371). * CVE-2024-53104: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format (bsc#1236783). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-669=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-669=1 ## Package List: * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_14-default-debuginfo-9-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_2-debugsource-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_14-default-9-150600.2.1 * SUSE Linux Enterprise Live Patching 15-SP6(ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_14-default-debuginfo-9-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_2-debugsource-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_14-default-9-150600.2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-36974.html * https://www.suse.com/security/cve/CVE-2024-53104.html * https://bugzilla.suse.com/show_bug.cgi?id=1227371 * https://bugzilla.suse.com/show_bug.cgi?id=1236783 . Crucial Linux Kernel security patch addresses pair of flaws in openSUSE and SLE 15 SP6. Prompt response recommended.. Linux Kernel Security Patch, openSUSE Update, Critical Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 24, 2025 Critical OpenSUSE
217

Oracle Linux 9 ELSA-2025-20018 kernel important update advisory

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-20018 http://linux.oracle.com/errata/ELSA-2025-20018.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: aarch64: bpftool-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-container-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-container-debug-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-core-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-debug-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-debug-core-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-debug-devel-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-debug-modules-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-debug-modules-extra-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-devel-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-doc-5.15.0-304.171.4.el9uek.noarch.rpm kernel-uek-modules-5.15.0-304.171.4.el9uek.aarch64.rpm kernel-uek-modules-extra-5.15.0-304.171.4.el9uek.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//kernel-uek-5.15.0-304.171.4.el9uek.src.rpm Related CVEs: CVE-2024-46770 CVE-2024-53060 CVE-2024-53070 CVE-2024-53097 CVE-2024-53206 CVE-2024-53226 Description of changes: [5.15.0-304.171.4.el9uek] - Revert "unicode: Don't special case ignorable code points" (Linus Torvalds) - Revert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K" (Aurelien Jarno) - tcp: Fix use-after-free of nreq in reqsk_timer_handler(). (Kuniyuki Iwashima) - lib/buildid: Fix build ID parsing logic (Jiri Olsa) - powerpc/vdso: Flag VDSO64 entry points as functions (Christophe Leroy) - mm: krealloc: Fix MTE false alarm in __do_krealloc (Qun-Wei Lin) - Revert "ALSA: hda/conexant: Mute speakers at suspend / shutdown" (Jarosław Janik) - usb: dwc3: fix fault at system suspend if device was already runtime suspended (Roger Quadros) - ACPI: PRM: Clean up guid type in struct prm_handler_info (DanCarpenter) - RDMA/hns: Fix NULL pointer derefernce in hns_roce_map_mr_sg() (Junxian Huang) - mm: revert "mm: shmem: fix data-race in shmem_getattr()" (Andrew Morton) - ACPI: CPPC: Fix _CPC register setting issue (Lifeng Zheng) - scsi: qla2xxx: Fix abort in bsg timeout (Quinn Tran) - drm/amdgpu: prevent NULL pointer dereference if ATIF is not supported (Antonio Quartulli) - RDMA/bnxt_re: Check cqe flags to know imm_data vs inv_irkey (Kashyap Desai) - vhost_scsi: log write descriptors (Dongli Zhang) [Orabug: 37393531] - vhost-scsi: protect vq-> log_base with vq-> mutex (Dongli Zhang) [Orabug: 37393531] [5.15.0-304.171.3.el9uek] - build: populate modules_thick.builtin for dirs containing only modules (Nick Alcock) [Orabug: 37381702] - mtd: fix use-after-free in mtd release (Alexander Usyskin) [Orabug: 37371929] - mtd: Clean refcounting with MTD_PARTITIONED_MASTER (Miquel Raynal) [Orabug: 37371929] - mtd: call external _get and _put in right order (Alexander Usyskin) [Orabug: 37371929] - nvmem: core: Check input parameter for NULL in nvmem_unregister() (Andy Shevchenko) [Orabug: 37371929] - Revert "ocfs2: fix the la space leak when unmounting an ocfs2 volume" (Sherry Yang) [Orabug: 37364544] - x86/pkeys: Ensure updated PKRU value is XRSTOR'd (Aruna Ramakrishna) [Orabug: 37361290] - x86/pkeys: Change caller of update_pkru_in_sigframe() (Aruna Ramakrishna) [Orabug: 37361290] - cgroup: cgroup-v1: do not exclude cgrp_dfl_root (Vishal Verma) [Orabug: 37347419] - mm/memcontrol: Fix memcg stat calculation (Aruna Ramakrishna) [Orabug: 37306542] [5.15.0-304.171.2.el9uek] - uek-rpm: Add mstflint_access module to the core list (Thomas Tai) [Orabug: 37345530] - uek-rpm/ol8/config-aarch64-emb3: Enable CONFIG_ARM_SDE_INTERFACE (Thomas Tai) [Orabug: 37345530] - sunrpc: fix a NULL deref in svc_process() when -> sv_stats doesn't exist (Calum Mackay) [Orabug: 37329531] - Partial revert "rds: Add inc/frag cache statistics" (Hans Westgaard Ry) [Orabug: 37232315] [5.15.0-304.171.1.el9uek] - kpcimgr: assign CPUto handle PCIE transactions during kexec (Joe Dobosenski) [Orabug: 37295980] - kexec: update start address for LPI table data (Joe Dobosenski) [Orabug: 37295980] - kpcimgr: fix flush_icache_range arguments (Joe Dobosenski) [Orabug: 37295980] - embedded2: Enable CONFIG_SQUASHFS_ZSTD to support zstd compression (Joe Dobosenski) [Orabug: 37295980] - embedded2: Support booting an encrypted root filesystem (Joe Dobosenski) [Orabug: 37295980] - Update embedded2 config for UEK7 (Joe Dobosenski) [Orabug: 37295980] - Pensando: kernel config changes for kdump (Rob Gardner) [Orabug: 34091165] [Orabug: 37295980] - arm64: Reserve elfcorehdr before scanning reserved memory from device tree (Joe Dobosenski) [Orabug: 37295980] - arm64: kexec: add support for kexec with spin-table (Henry Willard) [Orabug: 32549965] [Orabug: 37295980] - drivers/soc/pensando/cap_mem.c: Support DM region mapping. (David Clear) [Orabug: 37295980] - drivers/edac: elba: Support multiple DDR bypass ranges. (David Clear) [Orabug: 37295980] - mmc: sdhci-cadence: Enable host driver defined bounce buffer (Brad Larson) [Orabug: 37295980] - Fix NULL pointer dereference in cn_filter() (Anjali Kulkarni) [Orabug: 37280567] - selftests: connector: Fix input argument error paths to skip (Shuah Khan) [Orabug: 37280567] - connector/cn_proc: Selftest for proc connector (Anjali Kulkarni) [Orabug: 37280567] - connector/cn_proc: Allow non-root users access (Anjali Kulkarni) [Orabug: 37280567] - connector/cn_proc: Performance improvements (Anjali Kulkarni) [Orabug: 37280567] - connector/cn_proc: Add filtering to fix some bugs (Anjali Kulkarni) [Orabug: 37280567] - netlink: Add new netlink_release function (Anjali Kulkarni) [Orabug: 37280567] - ice: Add netif_device_attach/detach into PF reset flow (Dawid Osuchowski) [Orabug: 37214589] {CVE-2024-46770} _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . The Oracle Linux security advisory ELSA-2025-20018outlines critical updates and mitigations pertaining to kernel security flaws. Discover further.. Oracle Linux Security, system update advisory, kernel security patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 14, 2025 Important Oracle
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200