Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Ubuntu 23.10: 2024-5f1c128d9f major: security vulnerabilities patched

Update to uriparser-0.9.8.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-410d4ecabe 2024-05-14 01:32:20.839827 -------------------------------------------------------------------------------- Name : uriparser Product : Fedora 38 Version : 0.9.8 Release : 1.fc38 URL : https://uriparser.github.io/ Summary : URI parsing library - RFC 3986 Description : Uriparser is a strictly RFC 3986 compliant URI parsing library written in C. uriparser is cross-platform, fast, supports Unicode and is licensed under the New BSD license. -------------------------------------------------------------------------------- Update Information: Update to uriparser-0.9.8. -------------------------------------------------------------------------------- ChangeLog: * Sun May 5 2024 Sandro Mani - 0.9.8-1 - Update to 0.9.8 * Sat Jan 27 2024 Fedora Release Engineering - 0.9.7-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 Neal Gompa - 0.9.7-4 - Move cmake files to the devel subpackage * Sat Jul 22 2023 Fedora Release Engineering - 0.9.7-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2278811 - CVE-2024-34402 CVE-2024-34403 uriparser: various flaws [fedora-38] https://bugzilla.redhat.com/show_bug.cgi?id=2278811 [ 2 ] Bug #2278812 - CVE-2024-34402 CVE-2024-34403 uriparser: various flaws [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2278812 [ 3 ] Bug #2278813 - CVE-2024-34402 CVE-2024-34403 uriparser: various flaws [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2278813 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-410d4ecabe' at thecommand line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Critical patches for Fedora 38 resolve vulnerabilities in uriparser. Please update to version 0.9.8 to ensure better security.. Fedora 38 Security, Uriparser Fix, Software Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 14, 2024 Important Fedora
89

Fedora: 40: 2024-2843f37353 Severe: perl-Clipboard Command Execution

Update to 0.29 - Fixes 'clipbrowse command execution with multi-line clipboard text including "| sh"'. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2843f37353 2024-04-19 21:20:20.799127 -------------------------------------------------------------------------------- Name : perl-Clipboard Product : Fedora 40 Version : 0.29 Release : 1.fc40 URL : https://metacpan.org/dist/Clipboard Summary : Copy and paste with any OS Description : Who doesn't remember the first time they learned to copy and paste, and generated an exponentially growing text document? Yes, that's right, clipboards are magical. -------------------------------------------------------------------------------- Update Information: Update to 0.29 - Fixes 'clipbrowse command execution with multi-line clipboard text including "| sh"' -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 10 2024 Xavier Bachelot - 0.29-1 - Update to 0.29 (RHBZ#2273832) - Fixes RHBZ#2257224 and RHBZ#2257225 - Convert License: to SPDX -------------------------------------------------------------------------------- References: [ 1 ] Bug #2257225 - perl-Clipboard: clipbrowse command execution with multi-line clipboard text including "| sh" [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257225 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2843f37353' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Debian Security Notice regarding python-tkinter resolves arbitrary code execution vulnerability linked to multi-line text handling in the clipboard.. perl-clipboard update,Fedora update notification,command execution fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 19, 2024 Critical Fedora
89

Fedora 34: 2021-33819e6b09 Critical Kernel Update for Severe Flaws

The 5.13.12 stable kernel update contains a number of important fixes across the tree.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-33819e6b09 2021-08-21 01:05:40.547355 --------------------------------------------------------------------------------Name : kernel Product : Fedora 34 Version : 5.13.12 Release : 200.fc34 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package --------------------------------------------------------------------------------Update Information: The 5.13.12 stable kernel update contains a number of important fixes across the tree. --------------------------------------------------------------------------------ChangeLog: * Wed Aug 18 2021 Justin M. Forbes [5.13.12-200] - kernel-5.13.12-0 (Justin M. Forbes) * Tue Aug 17 2021 Justin M. Forbes [5.13.11-0] - bpf: Fix integer overflow involving bucket_size (Tatsuhiko Yasumatsu) - kernel-5.13.10-0 (Justin M. Forbes) - Fix up backport of Dell XPS 9710 quirk (Justin M. Forbes) - ASoC: Intel: sof_sdw_max98373: remove useless inits (Pierre-Louis Bossart) - ASoC: Intel: update sof_pcm512x quirks (Pierre-Louis Bossart) - ASoC: SOF: Intel: Use DMI string to search for adl_mx98373_rt5682 variant (jairaj arava) - ASoC: Intel: sof_sdw: add quirk for Dell XPS 9710 (Pierre-Louis Bossart) - kernel-5.13.9-0 (Justin M. Forbes) - drm/i915/dp: Use max params for older panels (Kai-Heng Feng) - pinctrl: tigerlake: Fix GPIO mapping for newer version of software (Andy Shevchenko) - kernel-5.13.8-0 (Justin M. Forbes) - Re-enable sermouse for x86 (rhbz 1974002) (Justin M. Forbes) - Revert CRYPTO_ECDH and CRYPTO_ECDA from builtin to module to fix fips (Justin M. Forbes) - drm/rockchip: remove existing generic drivers to take over the device (Javier Martinez Canillas) - powerpc/pseries: Fix regression while building external modules (Srikar Dronamraju) - kernel-5.13.7-0 (Justin M.Forbes) - kernel-5.13.6-0 (Justin M. Forbes) - kernel-5.13.5-0 (Justin M. Forbes) - iwlwifi Add support for ax201 in Samsung Galaxy Book Flex2 Alpha (Justin M. Forbes) - Revert "usb: renesas-xhci: Fix handling of unknown ROM state" (Justin M. Forbes) - RHEL configs need this too (Justin M. Forbes) - kernel-5.13.4-0 (Justin M. Forbes) - Config update for 5.13.4 (Justin M. Forbes) - kernel-5.13.3-0 (Justin M. Forbes) - Don't tag a release as [redhat] (Justin M. Forbes) - platform/x86: amd-pmc: Fix missing unlock on error in amd_pmc_send_cmd() (Yang Yingliang) --------------------------------------------------------------------------------References: [ 1 ] Bug #1983686 - CVE-2021-3653 kernel: SVM nested virtualization issue in KVM (AVIC support) https://bugzilla.redhat.com/show_bug.cgi?id=1983686 [ 2 ] Bug #1983988 - CVE-2021-3656 kernel: SVM nested virtualization issue in KVM (VMLOAD/VMSAVE) https://bugzilla.redhat.com/show_bug.cgi?id=1983988 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-33819e6b09' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives:https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . The 5.13.12 kernel release for Fedora 34 introduces essential patches that remedy a variety of significant vulnerabilities present in the operating environment.. Fedora Kernel Update, Critical Fixes, System Update, Open Source Software. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 20, 2021 Critical Fedora
89

Fedora 31: FEDORA-2020-df444e464e critical: python-pillow Flaw Fix

Update to 6.2.2, fixes CVE-2020-5313, CVE-2020-5312, CVE-2020-5311, CVE-2020-5310.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-df444e464e 2020-01-31 01:59:12.858062 --------------------------------------------------------------------------------Name : python-pillow Product : Fedora 31 Version : 6.2.2 Release : 1.fc31 URL : Summary : Python image processing library Description : Python image processing library, fork of the Python Imaging Library (PIL) This library provides extensive file format support, an efficient internal representation, and powerful image processing capabilities. There are four subpackages: tk (tk interface), qt (PIL image wrapper for Qt), devel (development) and doc (documentation). --------------------------------------------------------------------------------Update Information: Update to 6.2.2, fixes CVE-2020-5313, CVE-2020-5312, CVE-2020-5311, CVE-2020-5310. --------------------------------------------------------------------------------ChangeLog: * Fri Jan 17 2020 Sandro Mani - 6.2.2-1 - Update to 6.2.2 * Tue Nov 26 2019 Sandro Mani - 6.1.0-4 - Backport patches for CVE-2019-16865 --------------------------------------------------------------------------------References: [ 1 ] Bug #1789541 - CVE-2020-5310 CVE-2020-5311 CVE-2020-5312 CVE-2020-5313 python-pillow: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1789541 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-df444e464e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Python-pillow upgrade for Fedora 31 resolves various critical vulnerabilities to improve the library's safety.. Python Pillow, Fedora Update, Image Processing Library. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 30, 2020 Critical Fedora
89

Fedora 25: FEDORA-2016-9299ce1c7d Severe: MediaWiki Multiple Flaws

https://www.mediawiki.org/wiki/MediaWiki_1.27. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-9299ce1c7d 2016-09-06 18:18:46.585861 -------------------------------------------------------------------------------- Name : mediawiki Product : Fedora 25 Version : 1.27.1 Release : 1.fc25 URL : https://www.mediawiki.org/wiki/MediaWiki Summary : A wiki engine Description : MediaWiki is the software used for Wikipedia and the other Wikimedia Foundation websites. Compared to other wikis, it has an excellent range of features and support for high-traffic websites using multiple servers This package supports wiki farms. Read the instructions for creating wiki instances under /usr/share/doc/mediawiki/README.RPM. Remember to remove the config dir after completing the configuration. -------------------------------------------------------------------------------- Update Information: https://www.mediawiki.org/wiki/MediaWiki_1.27 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1369613 - CVE-2016-6331 CVE-2016-6332 CVE-2016-6333 CVE-2016-6334 CVE-2016-6335 CVE-2016-6336 mediawiki: multiple flaws fixed in 1.27.1, 1.26.4 and 1.23.15 https://bugzilla.redhat.com/show_bug.cgi?id=1369613 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mediawiki' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The latest Fedora 25 security notice outlines critical updates for MediaWiki alongside various bug resolutions; significant patch details provided. Fedora Security Update, MediaWiki Updates, Severe Flaws. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 06, 2016 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200