Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 45 articles for you...
89

Fedora 43 erlang-cowboy Important Gun Denial of Service Fix 2026-2aa86d411f

Gun ver. 2.4.1 and its dependencies New erlang-gun. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-2aa86d411f 2026-06-21 01:09:26.438203+00:00 -------------------------------------------------------------------------------- Name : erlang-cowboy Product : Fedora 43 Version : 2.16.1 Release : 1.fc43 URL : https://github.com/ninenines/cowboy Summary : Small, fast, modular HTTP server written in Erlang Description : Small, fast, modular HTTP server written in Erlang. -------------------------------------------------------------------------------- Update Information: Gun ver. 2.4.1 and its dependencies New erlang-gun -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 12 2026 Peter Lemenkov - 2.16.1-1 - Cowboy ver. 2.16.1 * Wed Jun 10 2026 Peter Lemenkov - 2.16.0-1 - Cowboy ver. 2.16.0 * Fri Jan 16 2026 Fedora Release Engineering - 2.12.0-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2486315 - erlang-cowlib-2.17.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2486315 [ 2 ] Bug #2486350 - erlang-gun-2.4.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2486350 [ 3 ] Bug #2486422 - CVE-2026-43972 erlang-gun: Gun: Cross-origin cookie injection leading to session fixation and account takeover. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486422 [ 4 ] Bug #2486423 - CVE-2026-43974 erlang-gun: gun: Denial of Service via unsolicited 101 Switching Protocols response [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486423 [ 5 ] Bug #2486424 - CVE-2026-43973 erlang-gun: gun: Denial of Service via unbounded HTTP/1.1 response buffering [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486424 [ 6 ]Bug #2487823 - erlang-cowboy-2.16.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2487823 [ 7 ] Bug #2487824 - erlang-cowlib-2.17.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2487824 [ 8 ] Bug #2487833 - erlang-gun-2.4.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2487833 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2aa86d411f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Explore Fedora 43's erlang-cowboy advisory detailing critical updates addressing session fixation and denial of service issues.. Fedora 43 updates, erlang-cowboy advisory, Denial of Service, session fixation, security issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 20, 2026 Important Fedora
89

Fedora 44 erlang-cowboy Critical DoS Session Fixation CVE-2026-43972

Gun ver. 2.4.1 and its dependencies New erlang-gun. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-c17ea7a74d 2026-06-21 00:58:50.478354+00:00 -------------------------------------------------------------------------------- Name : erlang-cowboy Product : Fedora 44 Version : 2.16.1 Release : 1.fc44 URL : https://github.com/ninenines/cowboy Summary : Small, fast, modular HTTP server written in Erlang Description : Small, fast, modular HTTP server written in Erlang. -------------------------------------------------------------------------------- Update Information: Gun ver. 2.4.1 and its dependencies New erlang-gun -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 12 2026 Peter Lemenkov - 2.16.1-1 - Cowboy ver. 2.16.1 * Wed Jun 10 2026 Peter Lemenkov - 2.16.0-1 - Cowboy ver. 2.16.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2486315 - erlang-cowlib-2.17.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2486315 [ 2 ] Bug #2486350 - erlang-gun-2.4.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2486350 [ 3 ] Bug #2486422 - CVE-2026-43972 erlang-gun: Gun: Cross-origin cookie injection leading to session fixation and account takeover. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486422 [ 4 ] Bug #2486423 - CVE-2026-43974 erlang-gun: gun: Denial of Service via unsolicited 101 Switching Protocols response [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486423 [ 5 ] Bug #2486424 - CVE-2026-43973 erlang-gun: gun: Denial of Service via unbounded HTTP/1.1 response buffering [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486424 [ 6 ] Bug #2487823 - erlang-cowboy-2.16.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2487823 [ 7 ] Bug#2487824 - erlang-cowlib-2.17.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2487824 [ 8 ] Bug #2487833 - erlang-gun-2.4.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2487833 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-c17ea7a74d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Critical updates for erlang-cowboy and erlang-gun resolve security flaws and improve functionality in Fedora 44.. erlang-cowboy, erlang-gun, fedora update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 20, 2026 Important Fedora
89

Fedora 44 python-django5 Faces High ASGI Denial-of-Service Vulnerability

Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST Fixes CVE-2026-6907: Potential exposure of private data due to incorrect. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9b7a6474a1 2026-05-21 00:54:04.884708+00:00 -------------------------------------------------------------------------------- Name : python-django5 Product : Fedora 44 Version : 5.2.14 Release : 1.fc44 URL : https://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST Fixes CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware Fixes CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation Fixes CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin Fixes CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable Fixes CVE-2026-33033: Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload Fixes CVE-2026-33034: Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass Fixes CVE-2026-25674: Potential incorrect permissions on newly created file system objects -------------------------------------------------------------------------------- ChangeLog: * Tue May 12 2026 Michel Lind - 5.2.14-1 - Update to version 5.2.14; Resolves RHBZ#2444117 - Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass - Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST - Fixes CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware - Fixes CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation - Fixes CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin - Fixes CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable - Fixes CVE-2026-33033: Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload - Fixes CVE-2026-33034: Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass - Fixes CVE-2026-25674: Potential incorrect permissions on newly created file system objects -------------------------------------------------------------------------------- References: [ 1 ] Bug #2444117 - python-django5-5.2.14 is available https://bugzilla.redhat.com/show_bug.cgi?id=2444117 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9b7a6474a1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Explore fixes for critical denial-of-service and session issues in Fedora 44's python-django5 package with this advisory.. python-django5 advisory 2026-9b7a6474a1 Fedora update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 21, 2026 Important Fedora
89

Fedora 44 python-django6 Security Advisory CVE-2026-5766 Denial of Service

Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST Fixes CVE-2026-6907: Potential exposure of private data due to incorrect. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-de6e24ae07 2026-05-21 00:54:04.884700+00:00 -------------------------------------------------------------------------------- Name : python-django6 Product : Fedora 44 Version : 6.0.5 Release : 1.fc44 URL : https://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST Fixes CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware Fixes CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation Fixes CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin Fixes CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable Fixes CVE-2026-33033: Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload Fixes CVE-2026-33034: Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass Fixes CVE-2026-25674: Potential incorrect permissions on newly created file system objects -------------------------------------------------------------------------------- ChangeLog: * Tue May 12 2026 Michel Lind - 6.0.5-1 - Update to version 6.0.5; Resolves RHBZ#2444118 - Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass - Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST - Fixes CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware - Fixes CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation - Fixes CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin - Fixes CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable - Fixes CVE-2026-33033: Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload - Fixes CVE-2026-33034: Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass - Fixes CVE-2026-25674: Potential incorrect permissions on newly created file system objects -------------------------------------------------------------------------------- References: [ 1 ] Bug #2444118 - python-django6-6.0.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2444118 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-de6e24ae07' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Django security update for potential DoS threats and session fixation; crucial for latest Fedora systems.. Django security update, Fedora 44 update, DoS vulnerabilities, session fixation risk, privilege escalation fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 21, 2026 Important Fedora
89

Ubuntu 24 node-express10 Major RCE Vulnerability Patch 2026-a1234567bc

Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST Fixes CVE-2026-6907: Potential exposure of private data due to incorrect. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b9548393aa 2026-05-14 04:02:29.141273+00:00 -------------------------------------------------------------------------------- Name : python-django5 Product : Fedora 42 Version : 5.2.14 Release : 1.fc42 URL : https://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST Fixes CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware Fixes CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation Fixes CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin Fixes CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable Fixes CVE-2026-33033: Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload Fixes CVE-2026-33034: Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass Fixes CVE-2026-25674: Potential incorrect permissions on newly created file system objects -------------------------------------------------------------------------------- ChangeLog: * Tue May 12 2026 Michel Lind - 5.2.14-1 - Update to version 5.2.14; Resolves RHBZ#2444117 - Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass - Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST - Fixes CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware - Fixes CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation - Fixes CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin - Fixes CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable - Fixes CVE-2026-33033: Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload - Fixes CVE-2026-33034: Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass - Fixes CVE-2026-25674: Potential incorrect permissions on newly created file system objects -------------------------------------------------------------------------------- References: [ 1 ] Bug #2444117 - python-django5-5.2.14 is available https://bugzilla.redhat.com/show_bug.cgi?id=2444117 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b9548393aa' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Addressing multiple issues in python-django5 for Fedora 42, including denial of service, session fixation, and privilege abuse.. Fedora Update, python-django5, Denial of Service, Security Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 14, 2026 Critical Fedora
202

openSUSE Leap 16.0 python-Django Moderate Security Issues 2026-20704-1

An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed.. openSUSE security update: security update for python-django ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20704-1 Rating: moderate References: * bsc#1264152 * bsc#1264153 * bsc#1264154 Cross-References: * CVE-2026-35192 * CVE-2026-5766 * CVE-2026-6907 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed. Description: This update for python-Django fixes the following issues: Changes in python-Django: - CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass (bsc#1264153) - CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST (bsc#1264154) - CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware (bsc#1264152) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-234=1 Package List: - openSUSE Leap 16.0: python313-Django-5.2.4-bp160.8.1 References: * https://www.suse.com/security/cve/CVE-2026-35192.html * https://www.suse.com/security/cve/CVE-2026-5766.html * https://www.suse.com/security/cve/CVE-2026-6907.html . Update for python-Django on openSUSE fixes three issues affecting system security and overall reliability.. openSUSE python-Django security update moderate bug fixes. . LinuxSecurity.com Team

Calendar%202 May 08, 2026 OpenSUSE
100

SUSE: 2025:01586-2 important: rack session fixation and memory issues

* bsc#1242894 * bsc#1242899 Cross-References: * CVE-2025-32441 . # Security update for rubygem-rack Announcement ID: SUSE-SU-2025:01586-2 Release Date: 2025-06-03T09:17:07Z Rating: important References: * bsc#1242894 * bsc#1242899 Cross-References: * CVE-2025-32441 * CVE-2025-46727 CVSS scores: * CVE-2025-32441 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-32441 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2025-32441 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2025-46727 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-46727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-46727 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for rubygem-rack fixes the following issues: * CVE-2025-46727: possible memory exhaustion due to unbounded parameter parsing in Rack::QueryParser (bsc#1242894). * CVE-2025-32441: deleted sessions can be restored and occupied by unauthenticated users when the Rack::Session::Pool middleware is being used (bsc#1242899). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2025-1586=1 ## Package List: * SUSE Linux Enterprise High Availability Extension 15 SP7 (aarch64 ppc64le s390x x86_64) * ruby2.5-rubygem-rack-2.0.8-150000.3.31.1 ## References: * https://www.suse.com/security/cve/CVE-2025-32441.html *https://www.suse.com/security/cve/CVE-2025-46727.html * https://bugzilla.suse.com/show_bug.cgi?id=1242894 * https://bugzilla.suse.com/show_bug.cgi?id=1242899 . SUSE's latest release tackles Rack complications, resolving memory depletion and enhancing session restoration. Discover further details within.. rubygem-rack, update instructions, security issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 04, 2025 Important SuSE
197

Debian 10: DLA-3121-1 Critical: Firefox-ESR Code Execution Risks

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, CSP bypass or session fixation. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3121-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort September 26, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : firefox-esr Version : 102.3.0esr-1~deb10u2 CVE ID : CVE-2022-40956 CVE-2022-40957 CVE-2022-40958 CVE-2022-40959 CVE-2022-40960 CVE-2022-40962 Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, CSP bypass or session fixation. This update brings back support for the i386 and arm64 architectures. Support for the armhf architecture is still missing, pending some changes to the buildd network. For Debian 10 buster, these problems have been fixed in version 102.3.0esr-1~deb10u2. We recommend that you upgrade your firefox-esr packages. For the detailed security status of firefox-esr please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/firefox-esr Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Transition to Firefox-ESR in response to severe vulnerabilities that permit unauthorized code execution alongside various other security threats.. Mozilla Firefox, Debian LTS, Firefox Security, Security Update, Code Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 26, 2022 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200