Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 31 articles for you...
172

Ubuntu 24.10: USN-7178-1 critical: DPDK denial of service

DPDK could be made to crash if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-7178-1 December 19, 2024 dpdk vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: DPDK could be made to crash if it received specially crafted network traffic. Software Description: - dpdk: set of libraries for fast packet processing Details: It was discovered that DPDK incorrectly handled the Vhost library checksum offload feature. An malicious guest could possibly use this issue to cause the hypervisor's vSwitch to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 dpdk 23.11.2-0ubuntu1.1 Ubuntu 24.04 LTS dpdk 23.11-1ubuntu0.1 Ubuntu 22.04 LTS dpdk 21.11.6-0ubuntu0.22.04.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7178-1 CVE-2024-11614 Package Information: https://launchpad.net/ubuntu/+source/dpdk/23.11.2-0ubuntu1.1 https://launchpad.net/ubuntu/+source/dpdk/21.11.6-0ubuntu0.22.04.2 . Ubuntu Security Notice USN-7179-1 highlights vulnerabilities in OpenSSL due to specifically designed requests that could lead to service disruptions.. dpdk updates, Ubuntu security patches, network exploit details. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 19, 2024 Critical Ubuntu
172

Ubuntu 23.10 USN-6487-1 Critical: Avahi Denial Of Service Threat

Avahi could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-6487-1 November 20, 2023 avahi vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) - Ubuntu 14.04 LTS (Available with Ubuntu Pro) Summary: Avahi could be made to crash if it received specially crafted input. Software Description: - avahi: IPv4LL network address configuration daemon Details: Evgeny Vereshchagin discovered that Avahi contained several reachable assertions, which could lead to intentional assertion failures when specially crafted user input was given. An attacker could possibly use this issue to cause a denial of service. (CVE-2023-38469, CVE-2023-38470, CVE-2023-38471, CVE-2023-38472, CVE-2023-38473) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: avahi-daemon 0.8-10ubuntu1.1 libavahi-client3 0.8-10ubuntu1.1 libavahi-common3 0.8-10ubuntu1.1 libavahi-core7 0.8-10ubuntu1.1 Ubuntu 23.04: avahi-daemon 0.8-6ubuntu1.23.04.2 libavahi-client3 0.8-6ubuntu1.23.04.2 libavahi-common3 0.8-6ubuntu1.23.04.2 libavahi-core7 0.8-6ubuntu1.23.04.2 Ubuntu 22.04 LTS: avahi-daemon 0.8-5ubuntu5.2 libavahi-client3 0.8-5ubuntu5.2 libavahi-common3 0.8-5ubuntu5.2 libavahi-core7 0.8-5ubuntu5.2 Ubuntu 20.04 LTS: avahi-daemon 0.7-4ubuntu7.3 libavahi-client3 0.7-4ubuntu7.3 libavahi-common3 0.7-4ubuntu7.3 libavahi-core7 0.7-4ubuntu7.3 Ubuntu 18.04 LTS (Available with Ubuntu Pro): avahi-daemon 0.7-3.1ubuntu1.3+esm2 libavahi-client3 0.7-3.1ubuntu1.3+esm2 libavahi-common3 0.7-3.1ubuntu1.3+esm2 libavahi-core7 0.7-3.1ubuntu1.3+esm2 Ubuntu 16.04 LTS (Available with Ubuntu Pro): avahi-daemon 0.6.32~rc+dfsg-1ubuntu2.3+esm3 libavahi-client3 0.6.32~rc+dfsg-1ubuntu2.3+esm3 libavahi-common3 0.6.32~rc+dfsg-1ubuntu2.3+esm3 libavahi-core7 0.6.32~rc+dfsg-1ubuntu2.3+esm3 Ubuntu 14.04 LTS (Available with Ubuntu Pro): avahi-daemon 0.6.31-4ubuntu1.3+esm3 libavahi-client3 0.6.31-4ubuntu1.3+esm3 libavahi-common3 0.6.31-4ubuntu1.3+esm3 libavahi-core7 0.6.31-4ubuntu1.3+esm3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6487-1 CVE-2023-38469, CVE-2023-38470, CVE-2023-38471, CVE-2023-38472, CVE-2023-38473 Package Information: https://launchpad.net/ubuntu/+source/avahi/0.8-10ubuntu1.1 https://launchpad.net/ubuntu/+source/avahi/0.8-6ubuntu1.23.04.2 https://launchpad.net/ubuntu/+source/avahi/0.8-5ubuntu5.2 https://launchpad.net/ubuntu/+source/avahi/0.7-4ubuntu7.3 . Upgrade your Ubuntu system to resolve serious vulnerabilities in Avahi triggered by specially designed inputs, which may result in possible system failures.. Avahi Vulnerabilities, Denial of Service, Service Crash. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 20, 2023 Critical Ubuntu
172

Ubuntu 6190-2 Critical Advisory: AccountsService DoS Risk and Mitigation

AccountsService could be made to crash or run programs if it received specially crafted messages.. ========================================================================== Ubuntu Security Notice USN-6190-2 September 25, 2023 accountsservice vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) - Ubuntu 14.04 LTS (Available with Ubuntu Pro) Summary: AccountsService could be made to crash or run programs if it received specially crafted messages. Software Description: - accountsservice: query and manipulate user account information Details: USN-6190-1 fixed a vulnerability in AccountsService. This update provides the corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: Kevin Backhouse discovered that AccountsService incorrectly handled certain D-Bus messages. A local attacker could use this issue to cause AccountsService to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS (Available with Ubuntu Pro): accountsservice 0.6.45-1ubuntu1.3+esm1 libaccountsservice0 0.6.45-1ubuntu1.3+esm1 Ubuntu 16.04 LTS (Available with Ubuntu Pro): accountsservice 0.6.40-2ubuntu11.6+esm1 libaccountsservice0 0.6.40-2ubuntu11.6+esm1 Ubuntu 14.04 LTS (Available with Ubuntu Pro): accountsservice 0.6.35-0ubuntu7.3+esm3 libaccountsservice0 0.6.35-0ubuntu7.3+esm3 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6190-2 https://ubuntu.com/security/notices/USN-6190-1 CVE-2023-3297 . The vulnerability present in the AccountsService could enable local attackers tocompromise services or run unrestricted code on Ubuntu machines.. AccountsService Exploit, Ubuntu Security, Denial of Service Risk, Software Update, Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 25, 2023 Critical Ubuntu
100

SUSE: 2022:4621-1 Important: FreeRADIUS Server Critical Issues

An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for freeradius-server ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:4621-1 Rating: important References: #1206204 #1206205 #1206206 Cross-References: CVE-2022-41859 CVE-2022-41860 CVE-2022-41861 CVSS scores: CVE-2022-41859 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2022-41860 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2022-41861 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for freeradius-server fixes the following issues: - CVE-2022-41859: Fixes an information leakage in EAP-PWD (bsc#1206204). - CVE-2022-41860: Fixes a crash on unknown option in EAP-SIM (bsc#1206205). - CVE-2022-41861: Fixes a crash on invalid abinary data (bsc#1206206). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-4621=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-4621=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): freeradius-server-debuginfo-3.0.19-3.12.1 freeradius-server-debugsource-3.0.19-3.12.1 freeradius-server-devel-3.0.19-3.12.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): freeradius-server-3.0.19-3.12.1 freeradius-server-debuginfo-3.0.19-3.12.1 freeradius-server-debugsource-3.0.19-3.12.1 freeradius-server-doc-3.0.19-3.12.1 freeradius-server-krb5-3.0.19-3.12.1 freeradius-server-krb5-debuginfo-3.0.19-3.12.1 freeradius-server-ldap-3.0.19-3.12.1 freeradius-server-ldap-debuginfo-3.0.19-3.12.1 freeradius-server-libs-3.0.19-3.12.1 freeradius-server-libs-debuginfo-3.0.19-3.12.1 freeradius-server-mysql-3.0.19-3.12.1 freeradius-server-mysql-debuginfo-3.0.19-3.12.1 freeradius-server-perl-3.0.19-3.12.1 freeradius-server-perl-debuginfo-3.0.19-3.12.1 freeradius-server-postgresql-3.0.19-3.12.1 freeradius-server-postgresql-debuginfo-3.0.19-3.12.1 freeradius-server-python-3.0.19-3.12.1 freeradius-server-python-debuginfo-3.0.19-3.12.1 freeradius-server-sqlite-3.0.19-3.12.1 freeradius-server-sqlite-debuginfo-3.0.19-3.12.1 freeradius-server-utils-3.0.19-3.12.1 freeradius-server-utils-debuginfo-3.0.19-3.12.1 References: https://www.suse.com/security/cve/CVE-2022-41859.html https://www.suse.com/security/cve/CVE-2022-41860.html https://www.suse.com/security/cve/CVE-2022-41861.html https://bugzilla.suse.com/1206204 https://bugzilla.suse.com/1206205 https://bugzilla.suse.com/1206206 . New release for freeradius-server tackles three significant vulnerabilities. Check out the specifics regarding the security flaws and the implemented corrections.. FreeRADIUS Server Fixes,SUSE Patch Instructions,Enterprise Security Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 27, 2022 Important SuSE
172

Ubuntu 20.04 USN-5766-1: heimdal Denial Of Service Threat

Heimdal could be made to crash if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-5766-1 December 07, 2022 heimdal vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: Heimdal could be made to crash if it received specially crafted network traffic. Software Description: - heimdal: Heimdal Kerberos Network Authentication Protocol Details: It was discovered that Heimdal did not properly manage memory when normalizing Unicode. An attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libwind0-heimdal 7.7.0+dfsg-1ubuntu1.2 Ubuntu 18.04 LTS: libwind0-heimdal 7.5.0+dfsg-1ubuntu0.2 Ubuntu 16.04 ESM: libwind0-heimdal 1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm2 Ubuntu 14.04 ESM: libwind0-heimdal 1.6~git20131207+dfsg-1ubuntu1.2+esm2 After a standard system update you need to restart any application using Heimdal libraries to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5766-1 CVE-2022-41916 Package Information: https://launchpad.net/ubuntu/+source/heimdal/7.7.0+dfsg-1ubuntu1.2 https://launchpad.net/ubuntu/+source/heimdal/7.5.0+dfsg-1ubuntu0.2 . The Heimdal flaw impacts various Debian releases. Ensure updates are applied quickly to avoid system failures triggered by specific network requests.. Heimdal Vulnerability, Ubuntu Security, Service Crash Risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 07, 2022 Important Ubuntu
217

Oracle Linux 9 ELSA-2022-6763 Critical: BIND Security Fixes

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-6763 https://linux.oracle.com/errata/ELSA-2022-6763.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: bind-9.16.23-1.el9_0.1.x86_64.rpm bind-chroot-9.16.23-1.el9_0.1.x86_64.rpm bind-dnssec-doc-9.16.23-1.el9_0.1.noarch.rpm bind-dnssec-utils-9.16.23-1.el9_0.1.x86_64.rpm bind-libs-9.16.23-1.el9_0.1.x86_64.rpm bind-license-9.16.23-1.el9_0.1.noarch.rpm bind-utils-9.16.23-1.el9_0.1.x86_64.rpm python3-bind-9.16.23-1.el9_0.1.noarch.rpm bind-devel-9.16.23-1.el9_0.1.i686.rpm bind-devel-9.16.23-1.el9_0.1.x86_64.rpm bind-libs-9.16.23-1.el9_0.1.i686.rpm aarch64: bind-9.16.23-1.el9_0.1.aarch64.rpm bind-chroot-9.16.23-1.el9_0.1.aarch64.rpm bind-dnssec-doc-9.16.23-1.el9_0.1.noarch.rpm bind-dnssec-utils-9.16.23-1.el9_0.1.aarch64.rpm bind-libs-9.16.23-1.el9_0.1.aarch64.rpm bind-license-9.16.23-1.el9_0.1.noarch.rpm bind-utils-9.16.23-1.el9_0.1.aarch64.rpm python3-bind-9.16.23-1.el9_0.1.noarch.rpm bind-devel-9.16.23-1.el9_0.1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates/bind-9.16.23-1.el9_0.1.src.rpm Related CVEs: CVE-2022-3080 CVE-2022-38177 CVE-2022-38178 Description of changes: [32:9.16.23-1.1] - Fix possible serve-stale related crash (CVE-2022-3080) - Fix memory leak in ECDSA verify processing (CVE-2022-38177) - Fix memory leak in EdDSA verify processing (CVE-2022-38178) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 9 security patch tackles various vulnerabilities in BIND. Find comprehensive information on updates and resolutions.. Oracle Linux Security,BIND Update,Security Fixes,Critical Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 03, 2022 Critical Oracle
89

Fedora 35: 2022-3a63897745 Critical: grpcurl Service Crash

Rebuild for CVE-2022-27191. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-3a63897745 2022-04-28 05:50:06.248389 --------------------------------------------------------------------------------Name : grpcurl Product : Fedora 35 Version : 1.8.6 Release : 2.fc35 URL : https://github.com/fullstorydev/grpcurl Summary : Like cURL, but for gRPC: Command-line tool for interacting with gRPC servers Description : Like cURL, but for gRPC: Command-line tool for interacting with gRPC servers. --------------------------------------------------------------------------------Update Information: Rebuild for CVE-2022-27191 --------------------------------------------------------------------------------ChangeLog: * Sat Apr 16 2022 Fabio Alessandro Locati 1.8.6-2 - Rebuilt for CVE-2022-27191 --------------------------------------------------------------------------------References: [ 1 ] Bug #2074262 - CVE-2022-27191 golang-x-crypto: golang: crash in a golang.org/x/crypto/ssh server [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2074262 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-3a63897745' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . The recent patch for grpcurl on Fedora 35 tackles a severe service failure issue tied to CVE-2022-27191. Ensure you upgrade promptly to enhance security and stability.. Fedora Update, grpcurl, Critical Service Crash. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 28, 2022 Critical Fedora
197

Debian LTS: DLA-2915-1 Moderate: ConnMan Denial of Service Issues

Several issues were found in ConnMan, a connection manager for embedded devices, that could cause denial of service via service crash or excessive CPU usage. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2915-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort February 09, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : connman Version : 1.33-3+deb9u3 CVE ID : CVE-2021-33833 CVE-2022-23096 CVE-2022-23097 CVE-2022-23098 Several issues were found in ConnMan, a connection manager for embedded devices, that could cause denial of service via service crash or excessive CPU usage. For Debian 9 stretch, these problems have been fixed in version 1.33-3+deb9u3. We recommend that you upgrade your connman packages. For the detailed security status of connman please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/connman Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance ConnMan on Debian to address multiple service failure issues and enhance CPU performance concerns.. Debian Security, ConnMan Update, Denial of Service, Service Crash, Reliability Patch. . LinuxSecurity.com Team

Calendar%202 Feb 09, 2022 Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200