Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
172

Ubuntu 24.10 USN-7285-1 critical: nginx session bypass and buffer overflow

Several security issues were fixed in nginx.. ========================================================================== Ubuntu Security Notice USN-7285-1 February 24, 2025 nginx vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in nginx. Software Description: - nginx: small, powerful, scalable web/proxy server Details: It was discovered that nginx incorrectly handled when multiple server blocks are configured to share the same IP address and port. An attacker could use this issue to use session resumption to bypass client certificate authentication requirements on these servers. This issue only affected Ubuntu 24.10. A buffer overflow and a null pointer deref was fixed in nginx rtmp module (#LP 1977718). This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 nginx 1.26.0-2ubuntu3.2 nginx-common 1.26.0-2ubuntu3.2 nginx-core 1.26.0-2ubuntu3.2 nginx-dev 1.26.0-2ubuntu3.2 nginx-doc 1.26.0-2ubuntu3.2 nginx-extras 1.26.0-2ubuntu3.2 nginx-full 1.26.0-2ubuntu3.2 nginx-light 1.26.0-2ubuntu3.2 Ubuntu 22.04 LTS libnginx-mod-rtmp 1.18.0-6ubuntu14.6 nginx 1.18.0-6ubuntu14.6 nginx-common 1.18.0-6ubuntu14.6 nginx-core 1.18.0-6ubuntu14.6 nginx-doc 1.18.0-6ubuntu14.6 nginx-extras 1.18.0-6ubuntu14.6 nginx-full 1.18.0-6ubuntu14.6 nginx-light 1.18.0-6ubuntu14.6 Ubuntu 20.04 LTS libnginx-mod-rtmp 1.18.0-0ubuntu1.7 nginx 1.18.0-0ubuntu1.7 nginx-common 1.18.0-0ubuntu1.7 nginx-core 1.18.0-0ubuntu1.7 nginx-doc 1.18.0-0ubuntu1.7 nginx-extras 1.18.0-0ubuntu1.7 nginx-full 1.18.0-0ubuntu1.7 nginx-light 1.18.0-0ubuntu1.7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7285-1 CVE-2025-23419, https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1977718 Package Information: https://launchpad.net/ubuntu/+source/nginx/1.26.0-2ubuntu3.2 https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.6 https://launchpad.net/ubuntu/+source/nginx/1.18.0-0ubuntu1.7 . Multiple security issues were fixed in nginx for Ubuntu versions. Follow the guidance for necessary updates.. nginx updates, Ubuntu vulnerabilities, web server patches. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 24, 2025 Critical Ubuntu
87

Debian DSA-3438-1 Critical: Xscreensaver Monitor Unplug Crash Risk

It was discovered that unplugging one of the monitors in a multi-monitor setup can cause xscreensaver to crash. Someone with physical access to a machine could use this problem to bypass a locked session. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3438-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Michael Gilbert January 09, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : xscreensaver CVE ID : CVE-2015-8025 Debian Bug : 802914 It was discovered that unplugging one of the monitors in a multi-monitor setup can cause xscreensaver to crash. Someone with physical access to a machine could use this problem to bypass a locked session. For the oldstable distribution (wheezy), this problem has been fixed in version 5.15-3+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 5.30-1+deb8u1. For the testing (stretch) and unstable (sid) distributions, this problem has been fixed in version 5.34-1. We recommend that you upgrade your xscreensaver packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . - ------------------------------------------------------------------------- Debian Security Advisory. unplugging, monitors, multi-monitor, setup, cause, xscreensave. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 10, 2016 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200