Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
219

Rocky Linux 9 RLSA-2026-8474 Important Vulnerabilities in .NET 9.0 DDoS

Important: .NET 9.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:8474", "synopsis": "Important: .NET 9.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dotnet9.0.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.116 and .NET Runtime 9.0.15.Security Fix(es):\n\n* dotnet: .NET: Security Bypass and Denial of Service Vulnerability (CVE-2026-26171)\n\n* dotnet: .NET: Denial of Service via stack overflow (CVE-2026-32203)\n\n* dotnet: .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform (CVE-2026-33116)\n\n* dotnet: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw (CVE-2026-32178)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2457739", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457739", "description": ""}, {"ticket": "2457740", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457740", "description": ""}, {"ticket": "2457741", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457741", "description": ""}, {"ticket": "2457781", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457781", "description": ""}], "cves": [{"name": "CVE-2026-26171", "sourceBy": "MITRE", "sourceLink":"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26171", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}, {"name": "CVE-2026-32178", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32178", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "7.5", "cwe": null}, {"name": "CVE-2026-32203", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32203", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-787"}, {"name": "CVE-2026-33116", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33116", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}], "references": [], "publishedAt": "2026-04-19T00:04:03.622890Z", "rpms": {"Rocky Linux 9": {"nvras": ["aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.s390x.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.s390x.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.s390x.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet9.0-0:9.0.116-1.el9_7.src.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.s390x.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el9_7.aarch64.rpm","dotnet9.0-debugsource-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el9_7.s390x.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.aarch64.rpm","dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-aot-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-aot-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-aot-9.0-debuginfo-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-aot-9.0-debuginfo-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.aarch64.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.ppc64le.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.s390x.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. New important security update for .NET 9.0 on Rocky Linux, addressing multiple vulnerabilities and enhancing security.. dotnet security, Rocky Linux update, important vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 19, 2026 Important Rocky Linux
100

SUSE: netty Moderate SMTP Injection CVE-2025-59419 Advisory 2025:4087-1

* bsc#1252097 Cross-References: * CVE-2025-59419 . # Security update for netty, netty-tcnative Announcement ID: SUSE-SU-2025:4087-1 Release Date: 2025-11-12T19:35:33Z Rating: moderate References: * bsc#1252097 Cross-References: * CVE-2025-59419 CVSS scores: * CVE-2025-59419 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-59419 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-59419 ( NVD ): 5.5 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Development Tools Module 15-SP6 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP6 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for netty, netty-tcnative fixes the following issues: * CVE-2025-59419: fixed SMTP command injection vulnerability that allowed email forgery (bsc#1252097) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-4087=1 * Development Tools Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-4087=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2025-4087=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-4087=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-4087=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * netty-tcnative-2.0.74-150200.3.33.1 * netty-4.1.128-150200.4.37.1 * openSUSE Leap 15.6 (noarch) * netty-javadoc-4.1.128-150200.4.37.1 * netty-tcnative-javadoc-2.0.74-150200.3.33.1 * Development Tools Module 15-SP6 (aarch64 ppc64le s390x x86_64) * netty-tcnative-2.0.74-150200.3.33.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * netty-tcnative-2.0.74-150200.3.33.1 * netty-tcnative-debugsource-2.0.74-150200.3.33.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * netty-4.1.128-150200.4.37.1 * SUSE Package Hub 15 15-SP6 (noarch) * netty-javadoc-4.1.128-150200.4.37.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * netty-4.1.128-150200.4.37.1 * SUSE Package Hub 15 15-SP7 (noarch) * netty-javadoc-4.1.128-150200.4.37.1 ## References: * https://www.suse.com/security/cve/CVE-2025-59419.html * https://bugzilla.suse.com/show_bug.cgi?id=1252097 . A SUSE security advisory addressing a moderate SMTP command injection in netty with CVE-2025-59419 requires immediate action.. SUSE security advisory, netty SMTP injection, netty-tcnative update, netty vulnerability, Linux security patch. . LinuxSecurity.com Team

Calendar%202 Nov 12, 2025 SuSE
202

openSUSE 15.6: netty, netty-tcnative Moderate SMTP Injection 2025:4087-1

An update that solves one vulnerability can now be installed.. # Security update for netty, netty-tcnative Announcement ID: SUSE-SU-2025:4087-1 Release Date: 2025-11-12T19:35:33Z Rating: moderate References: * bsc#1252097 Cross-References: * CVE-2025-59419 CVSS scores: * CVE-2025-59419 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-59419 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-59419 ( NVD ): 5.5 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Development Tools Module 15-SP6 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP6 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for netty, netty-tcnative fixes the following issues: * CVE-2025-59419: fixed SMTP command injection vulnerability that allowed email forgery (bsc#1252097) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-4087=1 * Development Tools Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-4087=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2025-4087=1 * SUSE Package Hub 1515-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-4087=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-4087=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * netty-tcnative-2.0.74-150200.3.33.1 * netty-4.1.128-150200.4.37.1 * openSUSE Leap 15.6 (noarch) * netty-javadoc-4.1.128-150200.4.37.1 * netty-tcnative-javadoc-2.0.74-150200.3.33.1 * Development Tools Module 15-SP6 (aarch64 ppc64le s390x x86_64) * netty-tcnative-2.0.74-150200.3.33.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * netty-tcnative-2.0.74-150200.3.33.1 * netty-tcnative-debugsource-2.0.74-150200.3.33.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * netty-4.1.128-150200.4.37.1 * SUSE Package Hub 15 15-SP6 (noarch) * netty-javadoc-4.1.128-150200.4.37.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * netty-4.1.128-150200.4.37.1 * SUSE Package Hub 15 15-SP7 (noarch) * netty-javadoc-4.1.128-150200.4.37.1 ## References: * https://www.suse.com/security/cve/CVE-2025-59419.html * https://bugzilla.suse.com/show_bug.cgi?id=1252097 . Security update for openSUSE addresses a moderate SMTP command injection issue in netty and netty-tcnative.. openSUSE security update, netty command injection, netty-tcnative fix. . LinuxSecurity.com Team

Calendar%202 Nov 12, 2025 OpenSUSE
202

openSUSE: javamail Moderate SMTP Injection Fix SUSE-SU-2025:03025-1

An update that solves one vulnerability can now be installed.. # Security update for javamail Announcement ID: SUSE-SU-2025:03025-1 Release Date: 2025-08-29T12:42:38Z Rating: moderate References: * bsc#1246873 Cross-References: * CVE-2025-7962 CVSS scores: * CVE-2025-7962 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-7962 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-7962 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-7962 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for javamail fixes the following issues: * Update to version 1.6.2 * CVE-2025-7962: Fixed an improper neutralization of \r and \n UTF-8 characters can lead to SMTP injection (bsc#1246873) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-3025=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-3025=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-3025=1 ## Package List: * openSUSE Leap15.6 (noarch) * javamail-1.6.2-150200.3.7.1 * javamail-javadoc-1.6.2-150200.3.7.1 * Basesystem Module 15-SP6 (noarch) * javamail-1.6.2-150200.3.7.1 * Basesystem Module 15-SP7 (noarch) * javamail-1.6.2-150200.3.7.1 ## References: * https://www.suse.com/security/cve/CVE-2025-7962.html * https://bugzilla.suse.com/show_bug.cgi?id=1246873 . Critical security alert regarding javamail email transmission flaw in openSUSE. Implement updates to secure your systems.. SUSE Linux, javamail, security update, SMTP injection, moderate risk. . LinuxSecurity.com Team

Calendar%202 Aug 29, 2025 OpenSUSE
100

SUSE Releases Advisory for Moderate SMTP Injection Fix CVE-2025-7962

* bsc#1246873 Cross-References: * CVE-2025-7962 . # Security update for javamail Announcement ID: SUSE-SU-2025:03025-1 Release Date: 2025-08-29T12:42:38Z Rating: moderate References: * bsc#1246873 Cross-References: * CVE-2025-7962 CVSS scores: * CVE-2025-7962 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-7962 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-7962 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-7962 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for javamail fixes the following issues: * Update to version 1.6.2 * CVE-2025-7962: Fixed an improper neutralization of \r and \n UTF-8 characters can lead to SMTP injection (bsc#1246873) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-3025=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-3025=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-3025=1 ## Package List: * openSUSE Leap 15.6 (noarch) * javamail-1.6.2-150200.3.7.1 * javamail-javadoc-1.6.2-150200.3.7.1 * Basesystem Module 15-SP6 (noarch) * javamail-1.6.2-150200.3.7.1 * Basesystem Module 15-SP7 (noarch) * javamail-1.6.2-150200.3.7.1 ## References: * https://www.suse.com/security/cve/CVE-2025-7962.html * https://bugzilla.suse.com/show_bug.cgi?id=1246873 . SUSE has released a javamail update that resolves a moderate vulnerability in SMTP injection tied to CVE-2025-7962. Detailed installation guidelines are provided.. SUSE javamail update SMTP CVE-2025-7962. . LinuxSecurity.com Team

Calendar%202 Aug 29, 2025 SuSE
197

Debian 10 Buster DLA-3829-1 Critical: Sendmail SMTP Injection Risk

sendmail allowed SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3829-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès June 15, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : sendmail Version : 8.15.2-14~deb10u2 CVE ID : CVE-2023-51765 Debian Bug : 1059386 sendmail allowed SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports . but some other popular e-mail servers do not. This particular injection vulnerability has been closed, unfortunatly full closure need to reject mail that contain NUL (0x00 byte). This is slighly non conformant with RFC and could be opt-out by setting confREJECT_NUL to 'false' in sendmail.mc file. For Debian 10 buster, this problem has been fixed in version 8.15.2-14~deb10u2. We recommend that you upgrade your sendmail packages. For the detailed security status of sendmail please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/sendmail Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-4891-1 tackles the vulnerability in apache2's remote code execution issue, enhancing server integrity.. sendmail Security, Debian Updates, SMTP Injection, Email Security, LTS Advisory. . Severity: Critical.LinuxSecurity.com Team

Calendar%202 Jun 15, 2024 Critical Debian LTS
87

Debian: DSA-3966-1 Critical Advisory For Ruby 2.3 Denial Of Service

Multiple vulnerabilities were discovered in the interpreter for the Ruby language: CVE-2015-9096 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3966-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff September 05, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ruby2.3 CVE ID : CVE-2015-9096 CVE-2016-7798 CVE-2017-0899 CVE-2017-0900 CVE-2017-0901 CVE-2017-0902 CVE-2017-14064 Multiple vulnerabilities were discovered in the interpreter for the Ruby language: CVE-2015-9096 SMTP command injection in Net::SMTP. CVE-2016-7798 Incorrect handling of initialization vector in the GCM mode in the OpenSSL extension. CVE-2017-0900 Denial of service in the RubyGems client. CVE-2017-0901 Potential file overwrite in the RubyGems client. CVE-2017-0902 DNS hijacking in the RubyGems client. CVE-2017-14064 Heap memory disclosure in the JSON library. For the stable distribution (stretch), these problems have been fixed in version 2.3.3-1+deb9u1. This update also hardens RubyGems against malicious termonal escape sequences (CVE-2017-0899). We recommend that you upgrade your ruby2.3 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Several vulnerabilities addressed in Ruby 2.3 by Debian DSA-3966-1. Security enhancements suggest an upgrade is advisable.. Debian Ruby Update,Ruby Security Update,SMTP Injection,Denial Of Service,OpenSSL Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 05, 2017 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200