Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 14 articles for you...
100

SUSE Linux Enterprise Server 16.0 Advisory for Uriparser CVE-2025-67899

An update that solves one vulnerability can now be installed.. # Security update for uriparser Announcement ID: SUSE-SU-2026:22084-1 Release Date: 2026-06-05T13:44:18Z Rating: moderate References: * bsc#1255000 Cross-References: * CVE-2025-67899 CVSS scores: * CVE-2025-67899 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-67899 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-67899 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for uriparser fixes the following issue: * CVE-2025-67899: unbounded recursion and stack consumption (bsc#1255000). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-895=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-895=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * uriparser-doc-0.9.8-160000.4.1 * uriparser-debuginfo-0.9.8-160000.4.1 * uriparser-devel-0.9.8-160000.4.1 * liburiparser1-debuginfo-0.9.8-160000.4.1 * liburiparser1-0.9.8-160000.4.1 * uriparser-0.9.8-160000.4.1 * uriparser-debugsource-0.9.8-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * uriparser-doc-0.9.8-160000.4.1 * uriparser-debuginfo-0.9.8-160000.4.1 * uriparser-devel-0.9.8-160000.4.1 * liburiparser1-debuginfo-0.9.8-160000.4.1 * liburiparser1-0.9.8-160000.4.1 * uriparser-0.9.8-160000.4.1 * uriparser-debugsource-0.9.8-160000.4.1 ## References: *https://www.suse.com/security/cve/CVE-2025-67899.html * https://bugzilla.suse.com/show_bug.cgi?id=1255000 . SUSE Security Update resolves moderate security issue in uriparser. Recommended updates for affected systems.. SUSE security update, uriparser patch, moderate security issue, unbounded recursion, Linux Server. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 15, 2026 moderate SuSE
202

openSUSE Leap 16.0 uriparser Moderate Unbounded Recursion CVE-2025-67899

An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for uriparser ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20910-1 Rating: moderate References: * bsc#1255000 Cross-References: * CVE-2025-67899 CVSS scores: * CVE-2025-67899 ( SUSE ): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-67899 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for uriparser fixes the following issue: - CVE-2025-67899: unbounded recursion and stack consumption (bsc#1255000). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-895=1 Package List: - openSUSE Leap 16.0: liburiparser1-0.9.8-160000.4.1 uriparser-0.9.8-160000.4.1 uriparser-devel-0.9.8-160000.4.1 uriparser-doc-0.9.8-160000.4.1 References: * https://www.suse.com/security/cve/CVE-2025-67899.html . Update available for openSUSE addressing moderate security issue in uriparser related to stack consumption.. openSUSE, uriparser, unbounded recursion, security update. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 08, 2026 moderate OpenSUSE
202

openSUSE 15.6 uriparser Moderate Stack Consumption Issue 2026-0444-1

An update that solves one vulnerability can now be installed.. # Security update for uriparser Announcement ID: SUSE-SU-2026:0444-1 Release Date: 2026-02-11T09:59:48Z Rating: moderate References: * bsc#1255000 Cross-References: * CVE-2025-67899 CVSS scores: * CVE-2025-67899 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-67899 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-67899 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for uriparser fixes the following issues: * CVE-2025-67899: large input containing many commas can cause unbounded recursion and stack consumption (bsc#1255000). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-444=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-444=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * uriparser-0.8.5-150000.3.11.1 * uriparser-debuginfo-0.8.5-150000.3.11.1 * uriparser-devel-0.8.5-150000.3.11.1 * liburiparser1-debuginfo-0.8.5-150000.3.11.1 * uriparser-debugsource-0.8.5-150000.3.11.1 * liburiparser1-0.8.5-150000.3.11.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * uriparser-0.8.5-150000.3.11.1 * uriparser-debuginfo-0.8.5-150000.3.11.1 * uriparser-devel-0.8.5-150000.3.11.1 * liburiparser1-debuginfo-0.8.5-150000.3.11.1 * uriparser-debugsource-0.8.5-150000.3.11.1 * liburiparser1-0.8.5-150000.3.11.1 * openSUSE Leap 15.6 (x86_64) * liburiparser1-32bit-debuginfo-0.8.5-150000.3.11.1 * liburiparser1-32bit-0.8.5-150000.3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2025-67899.html * https://bugzilla.suse.com/show_bug.cgi?id=1255000 . Update for uriparser on openSUSE addresses stack consumption issue. Learn how to patch it quickly here.. openSUSE Patch Uriparser Stack Consumption Security Fix. . LinuxSecurity.com Team

Calendar%202 Feb 11, 2026 OpenSUSE
89

Fedora 43: uriparser Important Unbounded Recursion Fix CVE-2025-67899

Update to uriparser-1.0.0, fixes CVE-2025-67899.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-5c12420f33 2025-12-20 00:52:30.902724+00:00 -------------------------------------------------------------------------------- Name : uriparser Product : Fedora 43 Version : 1.0.0 Release : 1.fc43 URL : https://uriparser.github.io/ Summary : URI parsing library - RFC 3986 Description : Uriparser is a strictly RFC 3986 compliant URI parsing library written in C. uriparser is cross-platform, fast, supports Unicode and is licensed under the New BSD license. -------------------------------------------------------------------------------- Update Information: Update to uriparser-1.0.0, fixes CVE-2025-67899. -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 15 2025 Sandro Mani - 1.0.0-1 - Update to 1.0.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2423026 - CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2423026 [ 2 ] Bug #2423027 - CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2423027 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-5c12420f33' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fixes critical unbounded recursion issue in uriparser for Fedora 43, enhancing security against stack consumption risk.. Fedora 43, uriparser, stack security, security patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 20, 2025 Important Fedora
202

openSUSE 15.5: 2023:3354-1 Critical: LibX11 Out-of-Bounds Read Issue

This update for re2c fixes the following issues: CVE-2018-21232: Fixed excess stack consumption due to uncontrolled recursion in find_fixed_tags (bsc#1170890).. # Security update for re2c Announcement ID: SUSE-SU-2023:3353-1 Rating: moderate References: * #1170890 Cross-References: * CVE-2018-21232 CVSS scores: * CVE-2018-21232 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for re2c fixes the following issues: * CVE-2018-21232: Fixed excess stack consumption due to uncontrolled recursion in find_fixed_tags (bsc#1170890). ## Patch Instructions: To install this SUSE Moderate update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3353=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-3353=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-3353=1 * Basesystem Module 15-SP5 zypper in -t patchSUSE-SLE-Module-Basesystem-15-SP5-2023-3353=1 * SUSE Manager Proxy 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-3353=1 * SUSE Manager Retail Branch Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.2-2023-3353=1 * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-3353=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * re2c-debugsource-1.0.3-150000.3.3.1 * re2c-debuginfo-1.0.3-150000.3.3.1 * re2c-1.0.3-150000.3.3.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * re2c-debugsource-1.0.3-150000.3.3.1 * re2c-debuginfo-1.0.3-150000.3.3.1 * re2c-1.0.3-150000.3.3.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * re2c-debugsource-1.0.3-150000.3.3.1 * re2c-debuginfo-1.0.3-150000.3.3.1 * re2c-1.0.3-150000.3.3.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * re2c-debugsource-1.0.3-150000.3.3.1 * re2c-debuginfo-1.0.3-150000.3.3.1 * re2c-1.0.3-150000.3.3.1 * SUSE Manager Proxy 4.2 (x86_64) * re2c-debugsource-1.0.3-150000.3.3.1 * re2c-debuginfo-1.0.3-150000.3.3.1 * re2c-1.0.3-150000.3.3.1 * SUSE Manager Retail Branch Server 4.2 (x86_64) * re2c-debugsource-1.0.3-150000.3.3.1 * re2c-debuginfo-1.0.3-150000.3.3.1 * re2c-1.0.3-150000.3.3.1 * SUSE Manager Server 4.2 (ppc64le s390x x86_64) * re2c-debugsource-1.0.3-150000.3.3.1 * re2c-debuginfo-1.0.3-150000.3.3.1 * re2c-1.0.3-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2018-21232.html * https://bugzilla.suse.com/show_bug.cgi?id=1170890 . Re2c has updated to fix CVE-2018-21232, a vulnerability causing excessive stack usage and potential denial of service. Update for better stability. re2c Update, openSUSE Patch, Security Fix, Stack Consumption. . LinuxSecurity.com Team

Calendar%202 Aug 18, 2023 OpenSUSE
98

Red Hat Quarkus 2.13.8 Moderate Update For Security Issues

An update is now available for Red Hat build of Quarkus. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For more. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat build of Quarkus 2.13.8 release and security update Advisory ID: RHSA-2023:3809-01 Product: Red Hat build of Quarkus Advisory URL: https://access.redhat.com/errata/RHSA-2023:3809 Issue date: 2023-06-29 CVE Names: CVE-2022-45787 CVE-2023-0481 CVE-2023-0482 CVE-2023-1436 CVE-2023-1584 CVE-2023-2974 CVE-2023-26053 CVE-2023-28867 ==================================================================== 1. Summary: An update is now available for Red Hat build of Quarkus. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For more information, see the CVE links in the References section. 2. Description: This release of Red Hat build of Quarkus 2.13.8 includes security updates, bug fixes, and enhancements. For more information, see the release notes page listed in the References section. Security Fixes: * CVE-2023-1436 jettison: Uncontrolled Recursion in JSONArray [quarkus-2] * CVE-2023-26053 gradle: usage of long IDs for PGP keys is unsafe and is subject to collision attacks [quarkus-2] * CVE-2023-28867 graphql-java: crafted GraphQL query causes stack consumption [quarkus-2] * CVE-2023-1584 quarkus-oidc: ID and access tokens leak via the authorization code flow [quarkus-2] * CVE-2023-0482 RESTEasy: creation of insecure temp files [quarkus-2] * CVE-2022-3782 keycloak: path traversal viadouble URL encoding [quarkus-2] * CVE-2023-0481 io.quarkus-quarkus-parent: quarkus: insecure permissions on temp files [quarkus-2] * CVE-2022-45787 apache-james-mime4j: Temporary File Information Disclosure in MIME4J TempFileStorageProvider [quarkus-2] For more information about the security issues, including the impact, a CVSS score, acknowledgments, and other related information, see the CVE links listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2158916 - CVE-2022-45787 apache-james-mime4j: Temporary File Information Disclosure in MIME4J TempFileStorageProvider 2163533 - CVE-2023-0481 quarkus: insecure permissions on temp files 2166004 - CVE-2023-0482 RESTEasy: creation of insecure temp files 2174854 - CVE-2023-26053 gradle: usage of long IDs for PGP keys is unsafe and is subject to collision attacks 2180886 - CVE-2023-1584 quarkus-oidc: ID and access tokens leak via the authorization code flow 2181977 - CVE-2023-28867 graphql-java: crafted GraphQL query causes stack consumption 2182788 - CVE-2023-1436 jettison: Uncontrolled Recursion in JSONArray 2211026 - CVE-2023-2974 quarkus-core: TLS protocol configured with quarkus.http.ssl.protocols is not enforced, client can enforce weaker supported TLS protocol 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): QUARKUS-2672 - Infinispan client is not aligned with newly released Red Hat Data Grid 8.4 QUARKUS-2787 - Rest Data Panache: Correct Open API integration QUARKUS-2846 - Ensure that new line chars don't break Panache projection QUARKUS-2978 - ExceptionMapper is not working in DEV mode QUARKUS-3158 - Do not create session and PKCE encryption keys if only bearer tokens are expected QUARKUS-3159 - 2.13: Do not support any Origin by default if CORS is enabled QUARKUS-3161 - Fixsecurity-csrf-prevention.adoc QUARKUS-3164 - Logging with Panache: fix LocalVariablesSorter usage QUARKUS-3167 - Make SDKMAN releases minor for maintenance and preview releases QUARKUS-3168 - Backport Ensure that ConfigBuilder classes work in native mode to 2.13 QUARKUS-3169 - New home for Narayana LRA coordinator Docker images QUARKUS-3170 - Fix truststore REST Client config when password is not set QUARKUS-3173 - Reinitialize sun.security.pkcs11.P11Util at runtime QUARKUS-3174 - Prevent SSE writing from potentially causing accumulation of headersQUARKUS-3175 - Filter out RESTEasy related warning in ProviderConfigInjectionWarningsTest QUARKUS-3176 - Make sure parent modules are loaded into workspace before those that depend on them QUARKUS-3177 - Fix copy paste error in qute docs QUARKUS-3178 - Pass `--userns=keep-id` to podman only when in rootless mode QUARKUS-3179 - Fix stuck HTTP2 request when sent challenge has resumed request QUARKUS-3181 - Make sure quarkus:go-offline properly supports test scoped dependencies QUARKUS-3184 - Use SchemaType.ARRAY instead of "ARRAY" for native support QUARKUS-3185 - Simplify logic in create-app.adoc and allow to define stream QUARKUS-3187 - Allow context propagation for OpenTelemetry QUARKUS-3188 - Fix RestAssured URL handling and unexpected restarts in QuarkusProdModeTest QUARKUS-3191 - Drop ':z' bind option when using MacOS and Podman QUARKUS-3194 - Exclude Netty's reflection configuration files QUARKUS-3195 - Integrate the api dependency from Infinispan 14 (#ISPN-14268) QUARKUS-3205 - Missing JARs and other discrepancies related to xpp3 dependency in 2.13.8. 6.References: https://access.redhat.com/security/cve/CVE-2022-45787 https://access.redhat.com/security/cve/CVE-2023-0481 https://access.redhat.com/security/cve/CVE-2023-0482 https://access.redhat.com/security/cve/CVE-2023-1436 https://access.redhat.com/security/cve/CVE-2023-1584 https://access.redhat.com/security/cve/CVE-2023-2974 https://access.redhat.com/security/cve/CVE-2023-26053 https://access.redhat.com/security/cve/CVE-2023-28867 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_build_of_quarkus/2.13 https://access.redhat.com/articles/4966181 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZJ2oPdzjgjWX9erEAQg7vA//XRjryfzKARIPLNbuzypdOTlJ4YXfwNgb JZZLBVMxv7ckStVpyklHkg1IdmqgjGJki4dDKpS/dMRIcKibRHq5v92mJp/fYX4H meoN9H06RvMarWPzVodY+lo2kS5p6xcgd1+tOQhqJYMvVuuY58tOFvbLhDYgcU4x dDXwS3mLN4URrs0Jk4pop1z/E8An/xVJmCG2QRybpsmC9XxVi0jETDJ1278Gxe1q iUOgvONd4XjA+rPI+5iEt2hA2VG2IjvzzERmZA9+n7MuxkYP+QTSIFR/CldhATNy y/Vuy7ZzLVDd4DODqexWLv98GjKJnR48jwjA/KB0ZcSD9jum+C4el9514VxQlwf5 bIc1K8lspc97RKyiJaq/J0PYNXYjHZ0dd53U6eqntxKBJcvu468j1xKv68y3pLHg 0QFTbqtq55F9KTNhRqeMEuC0ly6EuwLl+0jDkpTIqPNjuzDDwLBaTjlm4aEYXSF6 9CMoNpQCwq5/6TeyH+9pScWKSWO0jblCiY4tJojJ0V5vPIs8U+2CJmb0iJzx3tKj PUY4Wz3KCnFLwgU+laCznvW2IrmrFnSCm3cTm1Y36i9jfX1Y4NZhxonN8avn+ty3 eF5AtyFLgE5KmlkwkUy+F3HAZb9qzRzHHjRPw4xbkekEZp28t7xifOuKGOWfFYT2 WUbTnwA26jw=JLoW -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A new release addresses significant vulnerabilities in Red Hat's Quarkus 2.13.8, introducing essential patches and improvements.. Red Hat Quarkus Security Update, RHSA-2023-3809-01, Quarkus Security Issues. . LinuxSecurity.com Team

Calendar%202 Jun 29, 2023 Red Hat
89

Fedora 37: 2022-c4b56e4400 Critical: NULL Pointer And Stack Issues

- Fix CVE-2022-44789 (rhbz#2148261) - Fix CVE-2022-30975 (rhbz#2088596) - Fix CVE-2022-30974 (rhbz#2088591). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-c4b56e4400 2022-12-20 01:27:52.482891 --------------------------------------------------------------------------------Name : mujs Product : Fedora 37 Version : 1.3.2 Release : 1.fc37 URL : https://mujs.com/ Summary : An embeddable Javascript interpreter Description : MuJS is a lightweight Javascript interpreter designed for embedding in other software to extend them with scripting capabilities. --------------------------------------------------------------------------------Update Information: - Fix CVE-2022-44789 (rhbz#2148261) - Fix CVE-2022-30975 (rhbz#2088596) - Fix CVE-2022-30974 (rhbz#2088591) --------------------------------------------------------------------------------ChangeLog: * Thu Dec 1 2022 Alain Vigne 1.3.2-1 - upstream release 1.3.2 - Fix CVE-2022-44789 (rhbz#2148261) - Fix CVE-2022-30975 (rhbz#2088596) - Fix CVE-2022-30974 (rhbz#2088591) --------------------------------------------------------------------------------References: [ 1 ] Bug #2088590 - CVE-2022-30974 mujs: stack consumption because of unlimited recursion in compile() in regexp.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2088590 [ 2 ] Bug #2088594 - CVE-2022-30975 mujs: NULL pointer dereference in jsP_dumpsyntax() in jsdump.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2088594 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-c4b56e4400' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details onthe GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest MuJS patch for Fedora 37 addresses several vulnerabilities, notably correcting NULL dereference flaws and stack overflow concerns.. MuJS Update,Fedora 37,Javascript Interpreter Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 20, 2022 Critical Fedora
203

Mageia 7: 2021-0333 Moderate: libcroco Stack Consumption Issue

libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption (CVE-2020-12825). References: - https://bugs.mageia.org/show_bug.cgi?id=27108 . MGASA-2021-0333 - Updated libcroco and gettext packages fix security vulnerability Publication date: 10 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0333.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-12825 libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption (CVE-2020-12825). References: - https://bugs.mageia.org/show_bug.cgi?id=27108 - https://access.redhat.com/errata/RHSA-2020:4072 - https://gitlab.gnome.org/Archive/libcroco/-/issues/8 - https://www.cve.org/CVERecord?id=CVE-2020-12825 SRPMS: - 7/core/libcroco-0.6.13-1.2.mga7 - 7/core/gettext-0.19.8.1-4.1.mga7 . The latest versions of libcroco and gettext have resolved a significant stack overflow vulnerability on Mageia. Update today!. libcroco Security, Stack Consumption Issue, Mageia Security Update, gettext Fix. . LinuxSecurity.com Team

Calendar%202 Jul 10, 2021 Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200