Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
89

Fedora 42 libssh 0.11.4 Critical Denial of Service Issues 2026-0d8264f449

New upstream release fixing various security issues.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-0d8264f449 2026-02-18 00:54:04.864913+00:00 -------------------------------------------------------------------------------- Name : libssh Product : Fedora 42 Version : 0.11.4 Release : 1.fc42 URL : http://www.libssh.org Summary : A library implementing the SSH protocol Description : The ssh library was designed to be used by programmers needing a working SSH implementation by the mean of a library. The complete control of the client is made by the programmer. With libssh, you can remotely execute programs, transfer files, use a secure and transparent tunnel for your remote programs. With its Secure FTP implementation, you can play with remote files easily, without third-party programs others than libcrypto (from openssl). -------------------------------------------------------------------------------- Update Information: New upstream release fixing various security issues. -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 10 2026 Jakub Jelen - 0.11.4-1 - New upstream release fixing following security issues: - CVE-2025-14821: libssh loads configuration files from the C:\etc directory on Windows - CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request() - CVE-2026-0965: Possible Denial of Service when parsing unexpected configuration files - CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input - CVE-2026-0967: Specially crafted patterns could cause DoS - CVE-2026-0968: OOB Read in sftp_parse_longname() -------------------------------------------------------------------------------- References: [ 1 ] Bug #2438452 - libssh-0.12.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2438452 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-0d8264f449' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Libssh update for Fedora 42 addresses multiple security issues including DoS, buffer underflow, and more.. libssh security advisory Fedora DoS buffer underflow. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 18, 2026 Critical Fedora
100

SUSE Curl Moderate SFTP Regression Fix Advisory 2026-0494-1 CVE-2023-27534

An update that solves one vulnerability can now be installed.. # Security update for curl Announcement ID: SUSE-SU-2026:0494-1 Release Date: 2026-02-13T09:59:35Z Rating: moderate References: * bsc#1219273 Cross-References: * CVE-2023-27534 CVSS scores: * CVE-2023-27534 ( SUSE ): 4.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2023-27534 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-27534 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for curl fixes the following issues: * CVE-2023-27534: Regression fix for SFTP path ~ resolving discrepancy (bsc#1219273) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-494=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-494=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * nghttp2-debuginfo-1.39.2-3.20.1 * libnghttp2-devel-1.39.2-3.20.1 * curl-8.0.1-11.117.1 * curl-debugsource-8.0.1-11.117.1 * nghttp2-debugsource-1.39.2-3.20.1 * curl-debuginfo-8.0.1-11.117.1 * libcurl4-debuginfo-8.0.1-11.117.1 * libnghttp2-14-debuginfo-1.39.2-3.20.1 * libnghttp2-14-1.39.2-3.20.1 * libcurl4-8.0.1-11.117.1 * libcurl-devel-8.0.1-11.117.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390xx86_64) * libcurl4-debuginfo-32bit-8.0.1-11.117.1 * libnghttp2-14-debuginfo-32bit-1.39.2-3.20.1 * libnghttp2-14-32bit-1.39.2-3.20.1 * libcurl4-32bit-8.0.1-11.117.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * nghttp2-debuginfo-1.39.2-3.20.1 * libcurl4-debuginfo-32bit-8.0.1-11.117.1 * curl-8.0.1-11.117.1 * libnghttp2-devel-1.39.2-3.20.1 * libcurl4-32bit-8.0.1-11.117.1 * curl-debugsource-8.0.1-11.117.1 * nghttp2-debugsource-1.39.2-3.20.1 * libnghttp2-14-32bit-1.39.2-3.20.1 * libnghttp2-14-debuginfo-32bit-1.39.2-3.20.1 * curl-debuginfo-8.0.1-11.117.1 * libcurl4-debuginfo-8.0.1-11.117.1 * libnghttp2-14-debuginfo-1.39.2-3.20.1 * libnghttp2-14-1.39.2-3.20.1 * libcurl4-8.0.1-11.117.1 * libcurl-devel-8.0.1-11.117.1 ## References: * https://www.suse.com/security/cve/CVE-2023-27534.html * https://bugzilla.suse.com/show_bug.cgi?id=1219273 . Update for curl resolves SFTP regression issue on SUSE with moderate severity. Ensure systems are patched promptly.. curl update, SUSE security, moderation update. . LinuxSecurity.com Team

Calendar 2 Feb 13, 2026 SuSE
202

openSUSE 15.3 Update 2025:0901-1 Fixes Moderate Erlang SFTP Vulnerability

An update that solves one vulnerability can now be installed.. # Security update for erlang Announcement ID: SUSE-SU-2025:0901-1 Release Date: 2025-03-18T09:59:04Z Rating: moderate References: * bsc#1237467 Cross-References: * CVE-2025-26618 CVSS scores: * CVE-2025-26618 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-26618 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-26618 ( NVD ): 7.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for erlang fixes the following issues: * CVE-2025-26618: Fixed SSH SFTP packet size not verified properly in Erlang OTP (bsc#1237467). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-901=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-901=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2025-901=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * erlang-observer-23.3.4.19-150300.3.17.1 * erlang-dialyzer-src-23.3.4.19-150300.3.17.1 * erlang-debuginfo-23.3.4.19-150300.3.17.1 * erlang-et-src-23.3.4.19-150300.3.17.1 * erlang-observer-src-23.3.4.19-150300.3.17.1 * erlang-dialyzer-23.3.4.19-150300.3.17.1 * erlang-23.3.4.19-150300.3.17.1 *erlang-wx-src-23.3.4.19-150300.3.17.1 * erlang-diameter-23.3.4.19-150300.3.17.1 * erlang-debugsource-23.3.4.19-150300.3.17.1 * erlang-src-23.3.4.19-150300.3.17.1 * erlang-reltool-src-23.3.4.19-150300.3.17.1 * erlang-doc-23.3.4.19-150300.3.17.1 * erlang-jinterface-src-23.3.4.19-150300.3.17.1 * erlang-et-23.3.4.19-150300.3.17.1 * erlang-debugger-23.3.4.19-150300.3.17.1 * erlang-reltool-23.3.4.19-150300.3.17.1 * erlang-jinterface-23.3.4.19-150300.3.17.1 * erlang-epmd-23.3.4.19-150300.3.17.1 * erlang-dialyzer-debuginfo-23.3.4.19-150300.3.17.1 * erlang-wx-debuginfo-23.3.4.19-150300.3.17.1 * erlang-wx-23.3.4.19-150300.3.17.1 * erlang-diameter-src-23.3.4.19-150300.3.17.1 * erlang-debugger-src-23.3.4.19-150300.3.17.1 * erlang-epmd-debuginfo-23.3.4.19-150300.3.17.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * erlang-observer-23.3.4.19-150300.3.17.1 * erlang-dialyzer-src-23.3.4.19-150300.3.17.1 * erlang-debuginfo-23.3.4.19-150300.3.17.1 * erlang-et-src-23.3.4.19-150300.3.17.1 * erlang-observer-src-23.3.4.19-150300.3.17.1 * erlang-dialyzer-23.3.4.19-150300.3.17.1 * erlang-23.3.4.19-150300.3.17.1 * erlang-wx-src-23.3.4.19-150300.3.17.1 * erlang-diameter-23.3.4.19-150300.3.17.1 * erlang-debugsource-23.3.4.19-150300.3.17.1 * erlang-src-23.3.4.19-150300.3.17.1 * erlang-reltool-src-23.3.4.19-150300.3.17.1 * erlang-doc-23.3.4.19-150300.3.17.1 * erlang-jinterface-src-23.3.4.19-150300.3.17.1 * erlang-et-23.3.4.19-150300.3.17.1 * erlang-debugger-23.3.4.19-150300.3.17.1 * erlang-reltool-23.3.4.19-150300.3.17.1 * erlang-jinterface-23.3.4.19-150300.3.17.1 * erlang-epmd-23.3.4.19-150300.3.17.1 * erlang-dialyzer-debuginfo-23.3.4.19-150300.3.17.1 * erlang-wx-debuginfo-23.3.4.19-150300.3.17.1 * erlang-wx-23.3.4.19-150300.3.17.1 * erlang-diameter-src-23.3.4.19-150300.3.17.1 * erlang-debugger-src-23.3.4.19-150300.3.17.1 *erlang-epmd-debuginfo-23.3.4.19-150300.3.17.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * erlang-epmd-23.3.4.19-150300.3.17.1 * erlang-23.3.4.19-150300.3.17.1 * erlang-debugsource-23.3.4.19-150300.3.17.1 * erlang-debuginfo-23.3.4.19-150300.3.17.1 * erlang-epmd-debuginfo-23.3.4.19-150300.3.17.1 ## References: * https://www.suse.com/security/cve/CVE-2025-26618.html * https://bugzilla.suse.com/show_bug.cgi?id=1237467 . Recent updates address the SFTP complications observed in Erlang on openSUSE systems. Detailed instructions for applying the patch are provided.. openSUSE Security Update, erlang Patch Instructions, moderate RFC. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Mar 18, 2025 Medium OpenSUSE
197

Debian 10: DLA-3763-1 critical: curl path traversal exploit

curl was affected by a path traversal vulnerability. SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3763-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès March 17, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : curl Version : 7.64.0-4+deb10u9 CVE ID : CVE-2023-27534 curl was affected by a path traversal vulnerability. SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user. For Debian 10 buster, this problem has been fixed in version 7.64.0-4+deb10u9. We recommend that you upgrade your curl packages. For the detailed security status of curl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/curl Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3764-1 tackles a vulnerability in wget posing a security threat due to arbitrary file access.. curl Path Traversal Update, Debian Security Patch, Critical Curl Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 17, 2024 Critical Debian LTS
197

Debian: DLA-2338-2 Moderate: ProFTPD Segmentation Fault Issue

The update of proftpd-dfsg released as DLA-2338-1 incorrectly destroyed the memory pool in function sftp_kex_handle in contrib/mod_sftp/kex.c which may cause a segmentation fault and thus prevent sftp connections. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2338-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany August 25, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : proftpd-dfsg Version : 1.3.5e+r1.3.5b-4+deb9u2 Debian Bug : 968967 The update of proftpd-dfsg released as DLA-2338-1 incorrectly destroyed the memory pool in function sftp_kex_handle in contrib/mod_sftp/kex.c which may cause a segmentation fault and thus prevent sftp connections. For Debian 9 stretch, this problem has been fixed in version 1.3.5e+r1.3.5b-4+deb9u2. We recommend that you upgrade your proftpd-dfsg packages. For the detailed security status of proftpd-dfsg please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2340-3 resolves a critical vulnerability in openssl impacting secure communications.. Debian LTS, ProFTPD, Memory Issues, SFTP Connections, Security Updates. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 25, 2020 Important Debian LTS
197

Debian Jessie: DLA-1730-4 Critical: libssh2 Buffer Error Fix

Several more boundary checks have been backported to libssh2's src/sftp.c. Furthermore, all boundary checks in src/sftp.c now result in an LIBSSH2_ERROR_BUFFER_TOO_SMALL error code, rather than a . Package : libssh2 Version : 1.4.3-4.1+deb8u5 CVE ID : CVE-2019-3860 Several more boundary checks have been backported to libssh2's src/sftp.c. Furthermore, all boundary checks in src/sftp.c now result in an LIBSSH2_ERROR_BUFFER_TOO_SMALL error code, rather than a LIBSSH2_ERROR_ OUT_OF_BOUNDARY error code. As a side note, it was discovered that libssh2's SFTP implementation from Debian jessie only works well against OpenSSH SFTP servers from Debian wheezy, tests against newer OpenSSH versions (such as available in Debian jessie and beyond) interim-fail with SFTP protocol error "Error opening remote file". Operation might continue after this error, this depends on application implementations. For Debian 8 "Jessie", this problem has been fixed in version 1.4.3-4.1+deb8u5. We recommend that you upgrade your libssh2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail: This email address is being protected from spambots. You need JavaScript enabled to view it., https://sunweavers.net/ . Enhance your Debian 8 security by updating the libssh2 package to fix CVE-2019-3860 buffer errors. Follow the provided steps to upgrade safely. libssh2 Update,debian security advisory,SFTP Fix,buffer overflow. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 30, 2019 Critical Debian LTS
197

Debian 8: DLA-1753-2 Moderate: ProFTPD Regression with SFTP

The update of proftpd-dfsg issued as DLA-1753-1 caused a regression when using the sftp module. Login to the sftp server was impossible when the SFTPPAMEngine option was turned on (#926719). . Package : proftpd-dfsg Version : 1.3.5e+r1.3.5-2+deb8u1 CVE ID : not available Debian Bug : 923926 926719 The update of proftpd-dfsg issued as DLA-1753-1 caused a regression when using the sftp module. Login to the sftp server was impossible when the SFTPPAMEngine option was turned on (#926719). This update reverts to upstream version 1.3.5 again since even the latest upstream release 1.3.6 is still affected by different sftp related bugs (#927270). All fixes for the memory leaks were backported separately now. For Debian 8 "Jessie", this problem has been fixed in version 1.3.5e+r1.3.5-2+deb8u1. We recommend that you upgrade your proftpd-dfsg packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Notice regarding proftpd-dfsg, a resolution for the sftp regression bug has been implemented on Debian 8. It is advisable to perform an upgrade.. Proftpd Upgrade, Debian Security, SFTP Module Fix. . LinuxSecurity.com Team

Calendar 2 May 01, 2019 Debian LTS
87

Debian: 103101 High: Buffer Overflows In TFTP And SFTP Services

Vulnerabilities have been found in the bootpd and ftp programs.. Date Reported: 04 Jan 1999 Affected Packages: netstd Vulnerable: Yes For more information: Fixed in: Source archives: g.tar.gz Intel architecture: Motorola 680x0 architecture: . Critical notice concerning Ubuntu: substantial memory overflow vulnerabilities discovered in tftpd and httpd elements affecting netutils package.. Debian, Buffer Overflows, TFTP Service, SFTP Service. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 12, 2000 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here