Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Multiple security vulnerabilities were discovered in Twig, a template engine for PHP, which could result in PHP code injection, sandbox bypass or cross-site scripting. For the oldstable distribution (bookworm), these problems have been fixed in version 3.5.1-1+deb12u3.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6320-1
Multiple security vulnerabilities were discovered in Twig, a template engine for PHP, which could result in PHP code injection, sandbox bypass or cross-site scripting. For the oldstable distribution (bookworm), these problems have been fixed in version 3.5.1-1+deb12u3.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6320-1
Important: vim security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:11509", "synopsis": "Important: vim security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for vim.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Vim (Vi IMproved) is an updated and improved version of the vi editor.\n\nSecurity Fix(es):\n\n* vim: arbitrary command execution via modeline sandbox bypass (CVE-2026-34982)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2455400", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2455400", "description": ""}], "cves": [{"name": "CVE-2026-34982", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34982", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N", "cvss3BaseScore": "8.2", "cwe": "CWE-78"}], "references": [], "publishedAt": "2026-04-30T18:00:45.302131Z", "rpms": {"Rocky Linux 8": {"nvras": ["vim-2:8.0.1763-22.el8_10.3.src.rpm", "vim-common-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-common-2:8.0.1763-22.el8_10.3.x86_64.rpm", "vim-common-debuginfo-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-common-debuginfo-2:8.0.1763-22.el8_10.3.x86_64.rpm", "vim-debuginfo-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-debuginfo-2:8.0.1763-22.el8_10.3.x86_64.rpm", "vim-debugsource-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-debugsource-2:8.0.1763-22.el8_10.3.x86_64.rpm", "vim-enhanced-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-enhanced-2:8.0.1763-22.el8_10.3.x86_64.rpm", "vim-enhanced-debuginfo-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-enhanced-debuginfo-2:8.0.1763-22.el8_10.3.x86_64.rpm","vim-filesystem-2:8.0.1763-22.el8_10.3.noarch.rpm", "vim-minimal-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-minimal-2:8.0.1763-22.el8_10.3.x86_64.rpm", "vim-minimal-debuginfo-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-minimal-debuginfo-2:8.0.1763-22.el8_10.3.x86_64.rpm", "vim-X11-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-X11-2:8.0.1763-22.el8_10.3.x86_64.rpm", "vim-X11-debuginfo-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-X11-debuginfo-2:8.0.1763-22.el8_10.3.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A critical vim security update for Rocky Linux 8 addresses arbitrary command execution risks related to modeline sandbox bypass.. vim security update, Rocky Linux 8, command execution fix. . Severity: Important. LinuxSecurity.com Team
Byambadalai Sumiya discovered that SimpleEval, a library for adding evaluatable expressions into Python projects, didn't fully restrict some module references, resulting in sandbox bypass. For Debian 11 bullseye, this problem has been fixed in version 0.9.10-1+deb11u1.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4543-1
Byambadalai Sumiya discovered that SimpleEval, a library for adding evaluatable expressions into Python projects, didn't fully restrict some module references, resulting in sandbox bypass. For the oldstable distribution (bookworm), this problem has been fixed in version 0.9.12-1+deb12u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6220-1
Multiple security vulnerabilities were discovered in Flatpak, an application deployment framework for desktop apps, which could allow a Flatpak app to delete arbitrary hosts on the host or break out of the sandbox resulting in code execution in the host context. For the stable distribution (trixie), these problems have been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6207-1
SimGear could be made to run programs as an administrator if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-7965-1 January 15, 2026 simgear vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: SimGear could be made to run programs as an administrator if it opened a specially crafted file. Software Description: - simgear: set of open-source libraries for assembling 3d simulations, games, and visualizations Details: It was discovered that SimGear could be made to bypass the sandboxing of Nasal scripts. An attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libsimgear-dev 1:2020.3.18+dfsg-2.1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS libsimgear-dev 1:2020.3.6+dfsg-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 20.04 LTS libsimgear-dev 1:2019.1.1+dfsg-3ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libsimgear-dev 1:2018.1.1+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libsimgear-dev 3.4.0-3ubuntu0.1~esm1 Available with Ubuntu Pro libsimgearcore3.4.0v5 3.4.0-3ubuntu0.1~esm1 Available with Ubuntu Pro libsimgearscene3.4.0v5 3.4.0-3ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7965-1 CVE-2025-0781 . A SimGear vulnerability allows potential code execution via crafted files, requiring a security update for Ubuntu systems.. SimGear Security Update, Ubuntu 24.04 LTS Review, Code Execution Risk. . Severity: Important. LinuxSecurity.com Team
Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, information disclosure or bypass of sandbox restrictions. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4248-1
Get the latest Linux and open source security news straight to your inbox.