Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
100

SUSE 2025:02229-1 critical: libssh buffer overflow and integrity issues

* bsc#1245309 * bsc#1245310 * bsc#1245311 * bsc#1245314 . # Security update for libssh Announcement ID: SUSE-SU-2025:02229-1 Release Date: 2025-07-04T16:02:38Z Rating: important References: * bsc#1245309 * bsc#1245310 * bsc#1245311 * bsc#1245314 Cross-References: * CVE-2025-4877 * CVE-2025-4878 * CVE-2025-5318 * CVE-2025-5372 CVSS scores: * CVE-2025-4877 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-4877 ( SUSE ): 4.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2025-4878 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-4878 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5318 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-5318 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5318 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5372 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2025-5372 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2025-5372 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for libssh fixes the following issues: * CVE-2025-5318: Fixed likely read beyond bounds in sftp server handle management (bsc#1245311). * CVE-2025-4877: Fixed write beyond bounds in binary to base64 conversion functions (bsc#1245309). * CVE-2025-4878: Fixed use of uninitialized variable in privatekey_from_file() (bsc#1245310). * CVE-2025-5372: Fixed cases where ssh_kdf() returns a success code on certain failures (bsc#1245314). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-2229=1 openSUSE-SLE-15.6-2025-2229=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-2229=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-2229=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libssh4-0.9.8-150600.11.3.1 * libssh-debugsource-0.9.8-150600.11.3.1 * libssh-devel-0.9.8-150600.11.3.1 * libssh4-debuginfo-0.9.8-150600.11.3.1 * libssh-config-0.9.8-150600.11.3.1 * openSUSE Leap 15.6 (x86_64) * libssh4-32bit-0.9.8-150600.11.3.1 * libssh4-32bit-debuginfo-0.9.8-150600.11.3.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libssh4-64bit-0.9.8-150600.11.3.1 * libssh4-64bit-debuginfo-0.9.8-150600.11.3.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libssh4-0.9.8-150600.11.3.1 * libssh-debugsource-0.9.8-150600.11.3.1 * libssh-devel-0.9.8-150600.11.3.1 * libssh4-debuginfo-0.9.8-150600.11.3.1 * libssh-config-0.9.8-150600.11.3.1 * Basesystem Module 15-SP6 (x86_64) * libssh4-32bit-0.9.8-150600.11.3.1 * libssh4-32bit-debuginfo-0.9.8-150600.11.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libssh4-0.9.8-150600.11.3.1 * libssh-debugsource-0.9.8-150600.11.3.1 * libssh-devel-0.9.8-150600.11.3.1 * libssh4-debuginfo-0.9.8-150600.11.3.1 * libssh-config-0.9.8-150600.11.3.1 * Basesystem Module 15-SP7 (x86_64) * libssh4-32bit-0.9.8-150600.11.3.1 *libssh4-32bit-debuginfo-0.9.8-150600.11.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-4877.html * https://www.suse.com/security/cve/CVE-2025-4878.html * https://www.suse.com/security/cve/CVE-2025-5318.html * https://www.suse.com/security/cve/CVE-2025-5372.html * https://bugzilla.suse.com/show_bug.cgi?id=1245309 * https://bugzilla.suse.com/show_bug.cgi?id=1245310 * https://bugzilla.suse.com/show_bug.cgi?id=1245311 * https://bugzilla.suse.com/show_bug.cgi?id=1245314 . Canonical has launched a vital OpenSSL update addressing major flaws that threaten data integrity. Update immediately.. libssh security update,SUSE important advisory,ssh vulnerability patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 04, 2025 Critical SuSE
203

Mageia 9: MGASA-2025-0088 erlang SSH packet size security issue

SSH SFTP packet size not verified properly in Erlang OTP. (CVE-2025-26618) References: - https://bugs.mageia.org/show_bug.cgi?id=34067 . MGASA-2025-0088 - Updated erlang packages fix security vulnerability Publication date: 06 Mar 2025 URL: https://advisories.mageia.org/MGASA-2025-0088.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-26618 SSH SFTP packet size not verified properly in Erlang OTP. (CVE-2025-26618) References: - https://bugs.mageia.org/show_bug.cgi?id=34067 - https://ubuntu.com/security/notices/USN-7313-1 - https://www.cve.org/CVERecord?id=CVE-2025-26618 SRPMS: - 9/core/erlang-24.3.4.15-1.1.mga9 . Erlang security alert MGASA-2025-0088 pertains to weaknesses in SSH SFTP packet size validation. For comprehensive information, consult the latest updates.. Erlang Security Fix, SSH SFTP Issue, Mageia Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 06, 2025 Important Mageia
89

Fedora 38: 2024-3fd1bc9276 Critical Prometheus Exporter SSH Issue

Security fix for CVE-2023-48795. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-3fd1bc9276 2024-01-29 07:52:32.484208 -------------------------------------------------------------------------------- Name : prometheus-podman-exporter Product : Fedora 38 Version : 1.7.0 Release : 1.fc38 URL : https://github.com/containers/prometheus-podman-exporter Summary : Prometheus exporter for podman environment Description : Prometheus exporter for podman environments exposing containers, pods, images, volumes and networks information. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-48795 -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 21 2024 Navid Yaghoobi - 1.7.0-1 - release v1.7.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2255105 - CVE-2023-48795 prometheus-podman-exporter: ssh: Prefix truncation attack on Binary Packet Protocol (BPP) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2255105 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-3fd1bc9276' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The Fedora 38 release addresses a vulnerability in the prometheus-podman-exporter associated with CVE-2023-48795 to enhance overall security.. Prometheus Podman Exporter, SSH Attack, Fedora Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 29, 2024 Critical Fedora
100

SUSE: 2018:2853-1 Important: python-paramiko SSH Transport Concern

An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for python-paramiko ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:2853-1 Rating: important References: #1085276 #1106148 Cross-References: CVE-2018-7750 Affected Products: SUSE CaaS Platform ALL ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for python-paramiko to version 1.18.5 fixes the following issues: This security issue was fixed: - CVE-2018-7750: transport.py in the SSH server implementation of Paramiko did not properly check whether authentication is completed processing other requests. A customized SSH client could have skipped the authentication step (bsc#1085276) This non-security issue was fixed: - Prevent connection problems with ssh servers due to no acceptable macs being available (bsc#1106148) For additional changes please check the changelog. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE CaaS Platform ALL: To install this update, use the SUSE CaaS Platform Velum dashboard. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE CaaS Platform ALL (noarch): python-paramiko-1.18.5-10.6.1 References: https://www.suse.com/security/cve/CVE-2018-7750.html https://bugzilla.suse.com/1085276 https://bugzilla.suse.com/1106148 _______________________________________________ sle-security-updates mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . Critical vulnerabilities addressed in python-paramiko following SUSE Security Advisory SUSE-SU-2018:2853-1.. SUSE CaaS Platform, python-paramiko, security update, SSH transport issue. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 25, 2018 Important SuSE
197

Debian Wheezy: DLA-1144-1 Moderate: git-annex Remote Command Execution

git-annex before 6.20170818 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, as demonstrated by an ssh://-eProxyCommand= URL, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-1000116, and CVE-2017-1000117. . Package : git-annex Version : 3.20120629+deb7u1 CVE ID : CVE-2017-12976 Debian Bug : 873088 git-annex before 6.20170818 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, as demonstrated by an ssh://-eProxyCommand= URL, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-1000116, and CVE-2017-1000117. For Debian 7 "Wheezy", these problems have been fixed in version 3.20120629+deb7u1. We recommend that you upgrade your git-annex packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance git-annex in response to operational error using ssh address containing hyphen in the hostname. Update to version 3.20120629+deb7u1 fixes the problems.. git-annex, Debian LTS, remote execution flaw, ssh commands issue. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 27, 2017 Important Debian LTS
197

Debian 7 Wheezy DLA-1068-1 Critical: Git Remote Command Execution

Joern Schneeweisz discovered that git, a distributed revision control system, did not correctly handle maliciously constructed ssh:// URLs. This allowed an attacker to run an arbitrary shell command, for instance via git submodules. . Hash: SHA512 Package : git Version : 1:1.7.10.4-1+wheezy5 CVE ID : CVE-2017-1000117 Joern Schneeweisz discovered that git, a distributed revision control system, did not correctly handle maliciously constructed ssh:// URLs. This allowed an attacker to run an arbitrary shell command, for instance via git submodules. For Debian 7 "Wheezy", these problems have been fixed in version 1:1.7.10.4-1+wheezy5. We recommend that you upgrade your git packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade Git on Debian 7 Wheezy to address SSH URL handling vulnerabilities by modifying the sources list and installing the latest version directly. Debian Security, Git Security, Remote Command Execution, Security Patches, System Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 27, 2017 Critical Debian LTS
200

Scientific Linux 5: Kexec-Tools Moderate Security Update and Fixes

Moderate: kexec-tools security, bug fix, and enhancement update. Date: Tue, 6 Mar 2012 14:48:49 -0600 Reply-To: This email address is being protected from spambots. You need JavaScript enabled to view it. Sender: Security Errata for Scientific Linux From: This email address is being protected from spambots. You need JavaScript enabled to view it. Subject: Security ERRATA Moderate: kexec-tools on SL5.x i386/x86_64 Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. Synopsis: Moderate: kexec-tools security, bug fix, and enhancement update Issue Date: 2012-02-21 CVE Numbers: CVE-2011-3588 The kexec-tools package contains the /sbin/kexec binary and utilities that together form the user-space component of the kernel's kexec feature. The /sbin/kexec binary facilitates a new kernel to boot using the kernel's kexec feature either on a normal or a panic reboot. The kexec fastboot mechanism allows booting a Linux kernel from the context of an already running kernel. Kdump used the SSH (Secure Shell) "StrictHostKeyChecking=no" option when dumping to SSH targets, causing the target kdump server's SSH host key not to be checked. This could make it easier for a man-in-the-middle attacker on the local network to impersonate the kdump SSH target server and possibly gain access to sensitive information in the vmcore dumps. (CVE-2011-3588) The mkdumprd utility created initrd files with world-readable permissions. A local user could possibly use this flaw to gain access to sensitive information, such as the private SSH key used to authenticate to a remote server when kdump was configured to dump to an SSH target. (CVE-2011-3589) The mkdumprd utility included unneeded sensitive files (such as all files from the "/root/.ssh/" directory and the host's private SSH keys) in the resulting initrd. This could lead to an information leak when initrd files were previously created with world-readable permissions. Note: With this update, only the SSH client configuration, known hosts files, and the SSH key configured via the newly introduced sshkey option in "/etc/kdump.conf" are included in the initrd. The default is the key generated when running the "service kdump propagate"command, "/root/.ssh/kdump_id_rsa". (CVE-2011-3590) This updated kexec-tools package also includes numerous bug fixes and enhancements. All users of kexec-tools are advised to upgrade to this updated package, which resolves these security issues, fixes these bugs and adds these enhancements. SL5: i386 kexec-tools-1.102pre-154.el5.i386.rpm kexec-tools-debuginfo-1.102pre-154.el5.i386.rpm x86_64 kexec-tools-1.102pre-154.el5.x86_64.rpm kexec-tools-debuginfo-1.102pre-154.el5.x86_64.rpm - Scientific Linux Development Team . This release fixes notable security vulnerabilities in the kexec-tools software that may enable unauthorized data exposure.. kexec-tools update, SL5 security patch, SSH file permissions fix. . LinuxSecurity.com Team

Calendar 2 Mar 06, 2012 Scientific Linux
200

Scientific Linux Security Advisory SL4.x, SL5.x: openssh Low Severity Issue

Low: openssh security update. Date: Fri, 22 Aug 2008 13:59:13 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for openssh on SL4.x, SL5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Low: openssh security update Issue date: 2008-08-22 CVE Names: CVE-2007-4752 These packages fix a low severity flaw in the way ssh handles X11 cookies when creating X11 forwarding connections. When ssh was unable to create untrusted cookie, ssh used a trusted cookie instead, possibly allowing the administrative user of a untrusted remote server, or untrusted application run on the remote server, to gain unintended access to a userslocal X server. (CVE-2007-4752) To address concerns about these, and past openssh packages, we have done an intensive review of the source rpm's of these, and past openssh packages. Our conclusion is that these, and past packages have NOT been compromised. Either at the source level, or the compiled binary level. SL 4.x SRPMS: openssh-3.9p1-11.el4_7.src.rpm i386: openssh-3.9p1-11.el4_7.i386.rpm openssh-askpass-3.9p1-11.el4_7.i386.rpm openssh-askpass-gnome-3.9p1-11.el4_7.i386.rpm openssh-clients-3.9p1-11.el4_7.i386.rpm openssh-server-3.9p1-11.el4_7.i386.rpm x86_64: openssh-3.9p1-11.el4_7.x86_64.rpm openssh-askpass-3.9p1-11.el4_7.x86_64.rpm openssh-askpass-gnome-3.9p1-11.el4_7.x86_64.rpm openssh-clients-3.9p1-11.el4_7.x86_64.rpm openssh-server-3.9p1-11.el4_7.x86_64.rpm SL 5.x SRPMS: openssh-4.3p2-26.el5_2.1.src.rpm i386: openssh-4.3p2-26.el5_2.1.i386.rpm openssh-askpass-4.3p2-26.el5_2.1.i386.rpm openssh-clients-4.3p2-26.el5_2.1.i386.rpm openssh-server-4.3p2-26.el5_2.1.i386.rpm x86_64: openssh-4.3p2-26.el5_2.1.x86_64.rpm openssh-askpass-4.3p2-26.el5_2.1.x86_64.rpm openssh-clients-4.3p2-26.el5_2.1.x86_64.rpm openssh-server-4.3p2-26.el5_2.1.x86_64.rpm -Connie Sieh -Troy Dawson . The latest openssh security patch resolves a minor vulnerability concerning X11 forwarding tokens in ScientificLinux.. openssh Update, Scientific Linux, Security Update, X11 Forwarding Issue. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Aug 22, 2008 Low Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here