Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 22 articles for you...
197

Debian jackson-core High Severity Denial of Service Information Leak Fix

Two security vulnerabilities have been found in jackson-core, a fast and powerful JSON library for Java, which may allow an attacker to cause a denial of service by using deeply nested JSON data or disclose sensitive information by abusing a flaw in how certain exception messages are handled in jackson- core.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4623-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany June 08, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : jackson-core Version : 2.14.1-2~deb11u1 CVE ID : CVE-2025-49128 CVE-2025-52999 Debian Bug : 1108367 Two security vulnerabilities have been found in jackson-core, a fast and powerful JSON library for Java, which may allow an attacker to cause a denial of service by using deeply nested JSON data or disclose sensitive information by abusing a flaw in how certain exception messages are handled in jackson- core. Please note that related and complementary jackson-* packages like jackson- databind or the jackson-dataformat-* packages had to be upgraded as well in order to fix build failures caused by the newer upstream release of jackson- core. For Debian 11 bullseye, these problems have been fixed in version 2.14.1-2~deb11u1. We recommend that you upgrade your jackson-* packages. For the detailed security status of jackson-core please refer to its security tracker page at: https://security-tracker.debian.org/tracker/jackson-core Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade jackson-core to fix denial of service risks and information disclosure issues.. jackson-core upgrade,debian security,JSON library vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 08, 2026 Critical Debian LTS
172

Ubuntu 24.04 LTS Apache Commons Lang Important DoS Vulnerability 2025-48924

Apache Commons Lang could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8364-1 June 02, 2026 libcommons-lang-java, libcommons-lang3-java vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Apache Commons Lang could be made to crash if it received specially crafted input. Software Description: - libcommons-lang-java: an extension of the java.lang package - libcommons-lang3-java: an extension of the java.lang package Details: It was discovered that Apache Commons Lang incorrectly handled recursion in the ClassUtils.getClass method. An attacker could possibly use this issue to cause Apache Commons Lang to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libcommons-lang-java 2.6-10ubuntu0.1 libcommons-lang3-java 3.14.0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS libcommons-lang-java 2.6-9ubuntu0.22.04.1 libcommons-lang3-java 3.11-1ubuntu0.1 Ubuntu 20.04 LTS libcommons-lang-java 2.6-9ubuntu0.20.04.1~esm1 Available with Ubuntu Pro libcommons-lang3-java 3.8-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libcommons-lang-java 2.6-8ubuntu0.1~esm1 Available with Ubuntu Pro libcommons-lang3-java 3.8-1~18.04.2+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libcommons-lang-java 2.6-6ubuntu2+esm1 Available with UbuntuPro libcommons-lang3-java 3.4-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 14.04 LTS libcommons-lang-java 2.6-3ubuntu2+esm1 Available with Ubuntu Pro libcommons-lang3-java 3.2.1-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8364-1 CVE-2025-48924 Package Information: https://launchpad.net/ubuntu/+source/libcommons-lang-java/2.6-9ubuntu0.22.04.1 https://launchpad.net/ubuntu/+source/libcommons-lang3-java/3.11-1ubuntu0.1 . Update your Ubuntu system to prevent Apache Commons Lang crashes and denial of service from crafted input.. Apache Commons Lang security, Denial of Service prevention, Ubuntu patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 02, 2026 Important Ubuntu
172

Ubuntu 24.04 LTS: USN-7603-1 severe: composer code execution risk

Several security issues were fixed in Composer.. ========================================================================== Ubuntu Security Notice USN-7603-1 June 30, 2025 composer vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Composer. Software Description: - composer: Dependency Manager for PHP Details: Thomas Chauchefoin discovered that Composer did not correctly handle certain arguments. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-24828, CVE-2023-43655) Ed Cradock discovered that Composer did not correctly handle the exclusion of certain files. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 22.04 LTS. (CVE-2024-24821) Martin Haunschmid discovered that Composer did not correctly handle git branch names. An attacker could possibly use this issue to execute arbitrary code. (CVE-2024-35241) Maciej Piechota discovered that Composer did not correctly handle VCS branch names. An attacker could possibly use this issue to execute arbitrary code. (CVE-2024-35242) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS composer 2.7.1-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS composer 2.2.6-2ubuntu4+esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS composer 1.10.1-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS composer 1.6.3-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS composer 1.0.0~beta2-1ubuntu0.1~esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7603-1 CVE-2022-24828, CVE-2023-43655, CVE-2024-24821, CVE-2024-35241, CVE-2024-35242 . Numerous vulnerabilities in Composer for Ubuntu editions present significant dangers necessitating prompt upgrades.. Ubuntu Composer security Arbitrary code execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 02, 2025 Critical Ubuntu
172

Ubuntu 22.04 LTS USN-7289-3 Critical: Linux Kernel Security Issues

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7289-3 February 25, 2025 linux-ibm vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-ibm: Linux kernel for IBM cloud systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - x86 architecture; - Block layer subsystem; - ACPI drivers; - GPU drivers; - HID subsystem; - I2C subsystem; - IIO ADC drivers; - IIO subsystem; - InfiniBand drivers; - IOMMU subsystem; - IRQ chip drivers; - Multiple devices driver; - Media drivers; - Network drivers; - STMicroelectronics network drivers; - Parport drivers; - Pin controllers subsystem; - Direct Digital Synthesis drivers; - TCM subsystem; - TTY drivers; - USB Dual Role (OTG-ready) Controller drivers; - USB Serial drivers; - USB Type-C support driver; - USB Type-C Connector System Software Interface driver; - BTRFS file system; - File systems infrastructure; - Network file system (NFS) client; - NILFS2 file system; - NTFS3 file system; - SMB network file system; - User-space API (UAPI); - io_uring subsystem; - BPF subsystem; - Timer substystem drivers; - Tracing infrastructure; - Closures library; - Memory management; - Amateur Radio drivers; - Bluetooth subsystem; - Networking core; - IPv4 networking; - MAC80211 subsystem; - Multipath TCP; - Netfilter; - Network traffic control; - SCTP protocol; - XFRM subsystem; - Key management; - FireWire sound drivers; - HD-audio driver; - QCOM ASoC drivers; - STMicroelectronics SoCdrivers; - KVM core; (CVE-2024-50117, CVE-2024-50230, CVE-2024-50131, CVE-2024-50128, CVE-2024-50142, CVE-2024-50141, CVE-2024-50267, CVE-2024-41066, CVE-2024-50236, CVE-2024-50205, CVE-2024-50202, CVE-2024-50209, CVE-2024-50148, CVE-2024-50171, CVE-2024-50074, CVE-2024-50268, CVE-2024-50265, CVE-2024-50160, CVE-2024-50143, CVE-2024-50296, CVE-2024-50101, CVE-2024-50103, CVE-2024-39497, CVE-2024-50151, CVE-2024-50127, CVE-2024-50150, CVE-2024-50229, CVE-2024-50115, CVE-2024-50058, CVE-2024-50292, CVE-2024-50010, CVE-2024-50247, CVE-2024-50110, CVE-2024-53088, CVE-2024-50116, CVE-2024-26718, CVE-2024-53097, CVE-2024-50192, CVE-2024-50234, CVE-2024-41080, CVE-2024-42291, CVE-2024-50195, CVE-2024-40965, CVE-2024-50278, CVE-2024-50290, CVE-2024-50162, CVE-2024-53066, CVE-2024-50085, CVE-2024-50099, CVE-2024-50237, CVE-2024-50156, CVE-2024-50185, CVE-2024-50273, CVE-2024-50302, CVE-2024-50249, CVE-2024-50208, CVE-2024-50232, CVE-2024-50287, CVE-2024-50262, CVE-2024-50194, CVE-2024-40953, CVE-2024-50083, CVE-2024-50082, CVE-2024-53063, CVE-2024-50086, CVE-2024-50193, CVE-2024-50282, CVE-2024-50201, CVE-2024-50134, CVE-2024-53061, CVE-2024-50299, CVE-2024-50279, CVE-2024-50198, CVE-2024-53104, CVE-2024-50244, CVE-2024-50167, CVE-2024-53052, CVE-2024-50196, CVE-2024-50182, CVE-2024-35887, CVE-2024-53042, CVE-2023-52913, CVE-2024-53055, CVE-2024-50301, CVE-2024-42252, CVE-2024-50259, CVE-2024-50218, CVE-2024-50168, CVE-2024-50245, CVE-2024-50163, CVE-2024-50036, CVE-2024-50154, CVE-2024-53059, CVE-2024-50257, CVE-2024-53101, CVE-2024-50295, CVE-2024-50269, CVE-2024-53058, CVE-2024-50072, CVE-2024-50251, CVE-2024-50153, CVE-2024-50233, CVE-2024-50199) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1070-ibm 5.15.0-1070.73 linux-image-ibm 5.15.0.1070.66 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change thekernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7289-3 https://ubuntu.com/security/notices/USN-7289-2 https://ubuntu.com/security/notices/USN-7289-1 CVE-2023-52913, CVE-2024-26718, CVE-2024-35887, CVE-2024-39497, CVE-2024-40953, CVE-2024-40965, CVE-2024-41066, CVE-2024-41080, CVE-2024-42252, CVE-2024-42291, CVE-2024-50010, CVE-2024-50036, CVE-2024-50058, CVE-2024-50072, CVE-2024-50074, CVE-2024-50082, CVE-2024-50083, CVE-2024-50085, CVE-2024-50086, CVE-2024-50099, CVE-2024-50101, CVE-2024-50103, CVE-2024-50110, CVE-2024-50115, CVE-2024-50116, CVE-2024-50117, CVE-2024-50127, CVE-2024-50128, CVE-2024-50131, CVE-2024-50134, CVE-2024-50141, CVE-2024-50142, CVE-2024-50143, CVE-2024-50148, CVE-2024-50150, CVE-2024-50151, CVE-2024-50153, CVE-2024-50154, CVE-2024-50156, CVE-2024-50160, CVE-2024-50162, CVE-2024-50163, CVE-2024-50167, CVE-2024-50168, CVE-2024-50171, CVE-2024-50182, CVE-2024-50185, CVE-2024-50192, CVE-2024-50193, CVE-2024-50194, CVE-2024-50195, CVE-2024-50196, CVE-2024-50198, CVE-2024-50199, CVE-2024-50201, CVE-2024-50202, CVE-2024-50205, CVE-2024-50208, CVE-2024-50209, CVE-2024-50218, CVE-2024-50229, CVE-2024-50230, CVE-2024-50232, CVE-2024-50233, CVE-2024-50234, CVE-2024-50236, CVE-2024-50237, CVE-2024-50244, CVE-2024-50245, CVE-2024-50247, CVE-2024-50249, CVE-2024-50251, CVE-2024-50257, CVE-2024-50259, CVE-2024-50262, CVE-2024-50265, CVE-2024-50267, CVE-2024-50268, CVE-2024-50269, CVE-2024-50273, CVE-2024-50278, CVE-2024-50279, CVE-2024-50282, CVE-2024-50287, CVE-2024-50290, CVE-2024-50292,CVE-2024-50295, CVE-2024-50296, CVE-2024-50299, CVE-2024-50301, CVE-2024-50302, CVE-2024-53042, CVE-2024-53052, CVE-2024-53055, CVE-2024-53058, CVE-2024-53059, CVE-2024-53061, CVE-2024-53063, CVE-2024-53066, CVE-2024-53088, CVE-2024-53097, CVE-2024-53101, CVE-2024-53104 Package Information: https://launchpad.net/ubuntu/+source/linux-ibm/5.15.0-1070.73 . Recent patches addressing numerous vulnerabilities in the Linux kernel for Ubuntu 22.04 LTS on IBM hardware have been released. This update is essential for maintaining system security.. Linux Kernel Fixes, Ubuntu 22.04 LTS, Linux-IBM Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 25, 2025 Critical Ubuntu
172

Ubuntu 22.04 LTS USN-7021-5: Critical Kernel Flaws Updated

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7021-5 October 31, 2024 linux-azure-fde vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-azure-fde: Linux kernel for Microsoft Azure CVM cloud systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - GPU drivers; - BTRFS file system; - F2FS file system; - GFS2 file system; - BPF subsystem; - Netfilter; - RxRPC session sockets; - Integrity Measurement Architecture(IMA) framework; (CVE-2024-27012, CVE-2024-38570, CVE-2024-42228, CVE-2024-41009, CVE-2024-39494, CVE-2024-42160, CVE-2024-39496, CVE-2024-26677) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1073-azure-fde 5.15.0-1073.82.1 linux-image-azure-fde-lts-22.04 5.15.0.1073.82.50 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7021-5 https://ubuntu.com/security/notices/USN-7021-4 https://ubuntu.com/security/notices/USN-7021-3 https://ubuntu.com/security/notices/USN-7021-2 https://ubuntu.com/security/notices/USN-7021-1 CVE-2024-26677, CVE-2024-27012, CVE-2024-38570, CVE-2024-39494, CVE-2024-39496, CVE-2024-41009, CVE-2024-42160, CVE-2024-42228 Package Information: https://launchpad.net/ubuntu/+source/linux-azure-fde/5.15.0-1073.82.1 . Uncover the Ubuntu 22.04 LTS security notice USN-7021-5, which pertains to critical kernel vulnerabilities and essential system updates.. Ubuntu Kernel Security, Linux Azure FDE, System Update Advisory, Security Flaw Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 31, 2024 Critical Ubuntu
203

Mageia 9: 2024-0284 Critical Ntfs-3g Use-After-Free Exploit

NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. (CVE-2023-52890) References: - https://bugs.mageia.org/show_bug.cgi?id=33530 . MGASA-2024-0284 - Updated ntfs-3g packages fix security vulnerability Publication date: 09 Sep 2024 URL: https://advisories.mageia.org/MGASA-2024-0284.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-52890 NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. (CVE-2023-52890) References: - https://bugs.mageia.org/show_bug.cgi?id=33530 - - https://www.cve.org/CVERecord?id=CVE-2023-52890 SRPMS: - 9/core/ntfs-3g-2022.10.3-1.1.mga9 . Mageia 2024-0284 patches a serious vulnerability in ntfs-3g that necessitates prompt action from users.. ntfs-3g updates, Mageia security, use-after-free flaw, software vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 09, 2024 Critical Mageia
89

Fedora 39: FEDORA-2024-c611359ae1 Critical Security Update for MySQL

MySQL 8.0.39 Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-38.html https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-39.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-c611359ae1 2024-08-23 01:23:04.730539 -------------------------------------------------------------------------------- Name : community-mysql Product : Fedora 39 Version : 8.0.39 Release : 1.fc39 URL : https://www.mysql.com/ Summary : MySQL client programs and shared libraries Description : MySQL is a multi-user, multi-threaded SQL database server. MySQL is a client/server implementation consisting of a server daemon (mysqld) and many different client programs and libraries. The base package contains the standard MySQL client programs and generic MySQL files. -------------------------------------------------------------------------------- Update Information: MySQL 8.0.39 Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-38.html https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-39.html -------------------------------------------------------------------------------- ChangeLog: * Mon Aug 12 2024 Michal Schorm - 8.0.39-1 - Rebase to 8.0.39 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2258841 - CVE-2024-20960 CVE-2024-20961 CVE-2024-20962 CVE-2024-20963 CVE-2024-20964 CVE-2024-20965 CVE-2024-20966 CVE-2024-20967 CVE-2024-20969 CVE-2024-20970 CVE-2024-20971 CVE-2024-20972 CVE-2024-20973 ... community-mysql: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2258841 [ 2 ] Bug #2258842 - CVE-2024-20960 CVE-2024-20961 CVE-2024-20962 CVE-2024-20963 CVE-2024-20964 CVE-2024-20965 CVE-2024-20966 CVE-2024-20967 CVE-2024-20969 CVE-2024-20970 CVE-2024-20971 CVE-2024-20972 CVE-2024-20973 ... mysql:8.0/community-mysql: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2258842 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-c611359ae1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Fedora 39's Community-mysql enhancements address various concerns, accompanied by detailed release notes and setup instructions.. Fedora, MySQL, Security Updates, Database Flaws, Community Packages. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 23, 2024 Critical Fedora
172

Ubuntu 22.04 LTS: USN-6950-3 Critical Oracle Kernel Update

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-6950-3 August 13, 2024 linux-oracle vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-oracle: Linux kernel for Oracle Cloud systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - Block layer subsystem; - Bluetooth drivers; - Clock framework and drivers; - FireWire subsystem; - GPU drivers; - InfiniBand drivers; - Multiple devices driver; - EEPROM drivers; - Network drivers; - Pin controllers subsystem; - Remote Processor subsystem; - S/390 drivers; - SCSI drivers; - 9P distributed file system; - Network file system client; - SMB network file system; - Socket messages infrastructure; - Dynamic debug library; - Bluetooth subsystem; - Networking core; - IPv4 networking; - IPv6 networking; - Multipath TCP; - NSH protocol; - Phonet protocol; - TIPC protocol; - Wireless networking; - Key management; - ALSA framework; - HD-audio driver; (CVE-2024-36883, CVE-2024-36940, CVE-2024-36902, CVE-2024-36975, CVE-2024-36964, CVE-2024-36938, CVE-2024-36931, CVE-2024-35848, CVE-2024-26900, CVE-2024-36967, CVE-2024-36904, CVE-2024-27398, CVE-2024-36031, CVE-2023-52585, CVE-2024-36886, CVE-2024-36937, CVE-2024-36954, CVE-2024-36916, CVE-2024-36905, CVE-2024-36959, CVE-2024-26980, CVE-2024-26936, CVE-2024-36928, CVE-2024-36889, CVE-2024-36929, CVE-2024-36933, CVE-2024-27399, CVE-2024-36946, CVE-2024-36906, CVE-2024-36965, CVE-2024-36957,CVE-2024-36941, CVE-2024-36897, CVE-2024-36952, CVE-2024-36947, CVE-2024-36950, CVE-2024-36880, CVE-2024-36017, CVE-2023-52882, CVE-2024-36969, CVE-2024-38600, CVE-2024-36955, CVE-2024-36960, CVE-2024-27401, CVE-2024-36919, CVE-2024-36934, CVE-2024-35947, CVE-2024-36953, CVE-2024-36944, CVE-2024-36939) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1065-oracle 5.15.0-1065.71 linux-image-oracle-lts-22.04 5.15.0.1065.61 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-6950-3 https://ubuntu.com/security/notices/USN-6950-2 https://ubuntu.com/security/notices/USN-6950-1 CVE-2023-52585, CVE-2023-52882, CVE-2024-26900, CVE-2024-26936, CVE-2024-26980, CVE-2024-27398, CVE-2024-27399, CVE-2024-27401, CVE-2024-35848, CVE-2024-35947, CVE-2024-36017, CVE-2024-36031, CVE-2024-36880, CVE-2024-36883, CVE-2024-36886, CVE-2024-36889, CVE-2024-36897, CVE-2024-36902, CVE-2024-36904, CVE-2024-36905, CVE-2024-36906, CVE-2024-36916, CVE-2024-36919, CVE-2024-36928, CVE-2024-36929, CVE-2024-36931, CVE-2024-36933, CVE-2024-36934, CVE-2024-36937, CVE-2024-36938, CVE-2024-36939, CVE-2024-36940, CVE-2024-36941, CVE-2024-36944, CVE-2024-36946, CVE-2024-36947, CVE-2024-36950, CVE-2024-36952, CVE-2024-36953, CVE-2024-36954, CVE-2024-36955, CVE-2024-36957, CVE-2024-36959, CVE-2024-36960, CVE-2024-36964, CVE-2024-36965, CVE-2024-36967, CVE-2024-36969, CVE-2024-36975,CVE-2024-38600 Package Information: https://launchpad.net/ubuntu/+source/linux-oracle/5.15.0-1065.71 . Uncover essential patches for Ubuntu 22.04 LTS that tackle several oracle kernel vulnerabilities. Protect your environment today!. Ubuntu Security, Oracle Kernel, Linux Updates, System Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 13, 2024 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200