Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
89

Fedora 42: 2025-ce51c124a5 critical: perl string comparison length leakage

This release fixes CVE-2024-13939 (leaking the length of a secret string). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-ce51c124a5 2025-04-17 18:59:47.310408+00:00 -------------------------------------------------------------------------------- Name : perl-String-Compare-ConstantTime Product : Fedora 42 Version : 0.321 Release : 22.fc42 URL : https://metacpan.org/dist/String-Compare-ConstantTime Summary : Timing side-channel protected string compare Description : This module provides one function, "equals", which works like perl's "eq", but which does not provide a timing side-channel. Such comparison is useful when matching against a secret string. -------------------------------------------------------------------------------- Update Information: This release fixes CVE-2024-13939 (leaking the length of a secret string) -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 1 2025 Petr Pisar - 0.321-22 - Fix CVE-2024-13939 (leaking the length of a secret string) (bug #2355705) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2355663 - CVE-2024-13939 String-Compare-ConstantTime: String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string https://bugzilla.redhat.com/show_bug.cgi?id=2355663 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-ce51c124a5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can befound at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . The patch resolves CVE-2024-14550, averting the exposure of sensitive data in the JSON library of Ubuntu 23.04.. timing attack, secret string, security alert, Fedora update, module fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 17, 2025 Critical Fedora
172

Ubuntu: 6851-1 High Severity: Netplan Command Injection Risk

Netplan could reveal secrets or execute commands with specially crafted configuration file.. ========================================================================== Ubuntu Security Notice USN-6851-1 June 26, 2024 netplan.io vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Netplan could reveal secrets or execute commands with specially crafted configuration file. Software Description: - netplan.io: Declarative network configuration for various backends Details: Andreas Hasenack discovered that netplan incorrectly handled the permissions for netdev files containing wireguard configuration. An attacker could use this to obtain wireguard secret keys. It was discovered that netplan configuration could be manipulated into injecting arbitrary commands while setting up network interfaces. An attacker could use this to execute arbitrary commands or escalate privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libnetplan1 1.0-2ubuntu1.1 netplan-generator 1.0-2ubuntu1.1 netplan.io 1.0-2ubuntu1.1 Ubuntu 23.10 libnetplan0 0.107-5ubuntu0.3 netplan-generator 0.107-5ubuntu0.3 netplan.io 0.107-5ubuntu0.3 Ubuntu 22.04 LTS libnetplan0 0.106.1-7ubuntu0.22.04.3 netplan.io 0.106.1-7ubuntu0.22.04.3 Ubuntu 20.04 LTS libnetplan0 0.104-0ubuntu2~20.04.5 netplan.io 0.104-0ubuntu2~20.04.5 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6851-1 CVE-2022-4968, https://bugs.launchpad.net/netplan/+bug/1987842,https://bugs.launchpad.net/ubuntu/+source/netplan.io/+bug/2065738, Package Information: https://launchpad.net/ubuntu/+source/netplan.io/1.0-2ubuntu1.1 https://launchpad.net/ubuntu/+source/netplan.io/0.107-5ubuntu0.3 https://launchpad.net/ubuntu/+source/netplan.io/0.106.1-7ubuntu0.22.04.3 https://launchpad.net/ubuntu/+source/netplan.io/0.104-0ubuntu2~20.04.5 . Uncover the Ubuntu 6851-1 announcement concerning netplan.io weaknesses and measures to prevent command execution vulnerabilities.. Netplan Security Advisory, Ubuntu Security Update, Network Configuration Vulnerability. . LinuxSecurity.com Team

Calendar%202 Jun 26, 2024 Ubuntu
100

SUSE: 2022:0734-1 Important: Python-Twisted Secret Exposure Fix

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-Twisted ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0734-1 Rating: important References: #1195667 Cross-References: CVE-2022-21712 CVSS scores: CVE-2022-21712 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2022-21712 (SUSE): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N Affected Products: HPE Helion Openstack 8 SUSE Linux Enterprise High Performance Computing 12 SUSE Linux Enterprise Module for Web Scripting 12 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12 SUSE Linux Enterprise Server for SAP Applications 12-SP3 SUSE Linux Enterprise Server for SAP Applications 12-SP4 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud Crowbar 9 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-Twisted fixes the following issues: - CVE-2022-21712: Fixed secret exposure in cross-origin redirects (bsc#1195667, GHSA-92x2-jw7w-xvvx) from Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2022-734=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2022-734=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2022-734=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2022-734=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2022-734=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2022-734=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): python-Twisted-15.2.1-9.11.1 python-Twisted-debuginfo-15.2.1-9.11.1 python-Twisted-debugsource-15.2.1-9.11.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): python-Twisted-15.2.1-9.11.1 python-Twisted-debuginfo-15.2.1-9.11.1 python-Twisted-debugsource-15.2.1-9.11.1 - SUSE OpenStack Cloud 9 (x86_64): python-Twisted-15.2.1-9.11.1 python-Twisted-debuginfo-15.2.1-9.11.1 python-Twisted-debugsource-15.2.1-9.11.1 - SUSE OpenStack Cloud 8 (x86_64): python-Twisted-15.2.1-9.11.1 python-Twisted-debuginfo-15.2.1-9.11.1 python-Twisted-debugsource-15.2.1-9.11.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): python-Twisted-15.2.1-9.11.1 python-Twisted-debuginfo-15.2.1-9.11.1 python-Twisted-debugsource-15.2.1-9.11.1 - HPE Helion Openstack 8 (x86_64): python-Twisted-15.2.1-9.11.1 python-Twisted-debuginfo-15.2.1-9.11.1 python-Twisted-debugsource-15.2.1-9.11.1 References: https://www.suse.com/security/cve/CVE-2022-21712.html https://bugzilla.suse.com/1195667 . Critical security patch released for python-Twisted in openSUSE. Fixes vulnerabilities in confidential data leakage during cross-origin redirects.. SUSE Linux, Python Twisted, Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 04, 2022 Important SuSE
100

SUSE: 2022:0499-1 Important: python-Twisted Secret Exposure Fix

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-Twisted ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0499-1 Rating: important References: #1195667 Cross-References: CVE-2022-21712 CVSS scores: CVE-2022-21712 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2022-21712 (SUSE): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N Affected Products: SUSE Enterprise Storage 7 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 SUSE Linux Enterprise Module for Server Applications 15-SP3 SUSE Linux Enterprise Realtime Extension 15-SP2 SUSE Linux Enterprise Server 15-SP2-BCL SUSE Linux Enterprise Server 15-SP2-LTSS SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server for SAP 15-SP2 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Manager Proxy 4.1 SUSE Manager Proxy 4.2 SUSE Manager Retail Branch Server 4.1 SUSE Manager Server 4.1 SUSE Manager Server 4.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-Twisted fixes the following issues: - CVE-2022-21712: Fixed secret exposure in cross-origin redirects by properly removing sensitive headers when redirecting to a different origin (bsc#1195667). Patch Instructions: To installthis SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.1-2022-499=1 - SUSE Manager Retail Branch Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.1-2022-499=1 - SUSE Manager Proxy 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.1-2022-499=1 - SUSE Linux Enterprise Server for SAP 15-SP2: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2022-499=1 - SUSE Linux Enterprise Server 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2022-499=1 - SUSE Linux Enterprise Server 15-SP2-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-BCL-2022-499=1 - SUSE Linux Enterprise Realtime Extension 15-SP2: zypper in -t patch SUSE-SLE-Product-RT-15-SP2-2022-499=1 - SUSE Linux Enterprise Module for Server Applications 15-SP3: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP3-2022-499=1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP3-2022-499=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2022-499=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-ESPOS-2022-499=1 - SUSE Enterprise Storage 7: zypper in -t patch SUSE-Storage-7-2022-499=1 Package List: - SUSE Manager Server 4.1 (ppc64le s390x x86_64): python3-Twisted-19.10.0-3.6.1 python3-Twisted-debuginfo-19.10.0-3.6.1 - SUSE Manager Retail Branch Server 4.1 (x86_64): python3-Twisted-19.10.0-3.6.1 python3-Twisted-debuginfo-19.10.0-3.6.1 - SUSE Manager Proxy 4.1 (x86_64): python3-Twisted-19.10.0-3.6.1 python3-Twisted-debuginfo-19.10.0-3.6.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (ppc64le x86_64): python3-Twisted-19.10.0-3.6.1 python3-Twisted-debuginfo-19.10.0-3.6.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (aarch64 ppc64le s390x x86_64): python3-Twisted-19.10.0-3.6.1 python3-Twisted-debuginfo-19.10.0-3.6.1 - SUSE Linux Enterprise Server 15-SP2-BCL (x86_64): python3-Twisted-19.10.0-3.6.1 python3-Twisted-debuginfo-19.10.0-3.6.1 - SUSE Linux Enterprise Realtime Extension 15-SP2 (x86_64): python3-Twisted-19.10.0-3.6.1 python3-Twisted-debuginfo-19.10.0-3.6.1 - SUSE Linux Enterprise Module for Server Applications 15-SP3 (aarch64 ppc64le s390x x86_64): python-Twisted-debuginfo-19.10.0-3.6.1 python-Twisted-debugsource-19.10.0-3.6.1 python3-Twisted-19.10.0-3.6.1 python3-Twisted-debuginfo-19.10.0-3.6.1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (aarch64 ppc64le s390x x86_64): python-Twisted-debugsource-19.10.0-3.6.1 python3-Twisted-19.10.0-3.6.1 python3-Twisted-debuginfo-19.10.0-3.6.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (aarch64 x86_64): python3-Twisted-19.10.0-3.6.1 python3-Twisted-debuginfo-19.10.0-3.6.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (aarch64 x86_64): python3-Twisted-19.10.0-3.6.1 python3-Twisted-debuginfo-19.10.0-3.6.1 - SUSE Enterprise Storage 7 (aarch64 x86_64): python3-Twisted-19.10.0-3.6.1 python3-Twisted-debuginfo-19.10.0-3.6.1 References: https://www.suse.com/security/cve/CVE-2022-21712.html https://bugzilla.suse.com/1195667 . SUSE Security Upgrade for python-Twisted tackles a severe vulnerability relating to the leakage of secrets in redirects. Continue reading for more information.. SUSE Security Update, python-Twisted, Patch Instructions, Critical Issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 18, 2022 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200