Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 470
Alerts This Week
Warning Icon 1 470

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 301 articles for you...
203

Mageia 9 Sudo Critical Privilege Escalation Threat CVE-2026-35535

Security update. Publication date: 15 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0211.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-35535 Description: In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation. (CVE-2026-35535) References: - https://bugs.mageia.org/show_bug.cgi?id=35434 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/R55OTRP6IUWZLJBXLPP4BYUVXGGO7R5M/ - https://cdn2.qualys.com/advisory/2026/03/10/crack-armor.txt - https://bugs.launchpad.net/ubuntu/+source/sudo/+bug/2143042 - https://www.cve.org/CVERecord?id=CVE-2026-35535 SRPMS: - 9/core/sudo-1.9.15p5-1.2.mga9 . Discover a critical security advisory for Mageia 9 addressing a privilege escalation flaw in sudo. Immediate action required.. Mageia sudo security update, sudo privilege escalation, Mageia security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 15, 2026 Critical Mageia
197

Debian LTS DLA-4614-1 Sudo Critical Privilege Escalation Fix

Qualys released an advisory called CrackArmor reporting that in sudo, an application that provide limited super user privileges to specific users, a failure during a privilege drop before running the mailer is not a fatal error, which could lead to privilege escalation. For Debian 11 bullseye, this problem has been fixed in version. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4614-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Andreas Henriksson June 04, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : sudo Version : 1.9.5p2-3+deb11u4 CVE ID : CVE-2026-35535 Debian Bug : 1130593 Qualys released an advisory called CrackArmor reporting that in sudo, an application that provide limited super user privileges to specific users, a failure during a privilege drop before running the mailer is not a fatal error, which could lead to privilege escalation. For Debian 11 bullseye, this problem has been fixed in version 1.9.5p2-3+deb11u4. We recommend that you upgrade your sudo packages. For the detailed security status of sudo please refer to its security tracker page at: https://security-tracker.debian.org/tracker/sudo Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Fixes a privilege escalation issue in sudo for Debian 11 bullseye. Upgrade recommended to maintain security.. Debian Sudo Privilege Escalation, Debian Security Update, Sudo Vulnerability Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 04, 2026 Critical Debian LTS
197

Debian LTS Sudo Critical Privilege Escalation Fix DLA-4614-1 CVE-2026-35535

Qualys released an advisory called CrackArmor reporting that in sudo, an application that provide limited super user privileges to specific users, a failure during a privilege drop before running the mailer is not a fatal error, which could lead to privilege escalation. For Debian 11 bullseye, this problem has been fixed in version. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4614-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Andreas Henriksson June 04, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : sudo Version : 1.9.5p2-3+deb11u4 CVE ID : CVE-2026-35535 Debian Bug : 1130593 Qualys released an advisory called CrackArmor reporting that in sudo, an application that provide limited super user privileges to specific users, a failure during a privilege drop before running the mailer is not a fatal error, which could lead to privilege escalation. For Debian 11 bullseye, this problem has been fixed in version 1.9.5p2-3+deb11u4. We recommend that you upgrade your sudo packages. For the detailed security status of sudo please refer to its security tracker page at: https://security-tracker.debian.org/tracker/sudo Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS advises on a critical sudo security update addressing a privilege escalation issue. Update recommended.. Debian LTS,Sudo,Security Update,Privilege Escalation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 04, 2026 Critical Debian LTS
89

Fedora 44 PIE Vulnerability in Sudo Might Allow Code Execution Risks

Version 1.4.5 This release contains vulnerability fixes for the following security advisories: GHSA-h842-vjwg-pxxx - Sudo-elevated arbitrary file deletion via extra.pie- installed-binary metadata in UninstallUsingUnlink GHSA-pm6p-666q-hvj5 - Sudo-elevated root code execution via TOCTOU between self-. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-e5d5fc359d 2026-06-04 01:48:27.004460+00:00 -------------------------------------------------------------------------------- Name : pie Product : Fedora 44 Version : 1.4.5 Release : 1.fc44 URL : https://github.com/php/pie Summary : PHP Installer for Extensions Description : PIE (PHP Installer for Extensions). PIE can install an extension to any installed PHP version. A list of extensions that support PIE can be found on https://packagist.org/extensions. Documentation: /usr/share/doc/pie/docs/usage.md -------------------------------------------------------------------------------- Update Information: Version 1.4.5 This release contains vulnerability fixes for the following security advisories: GHSA-h842-vjwg-pxxx - Sudo-elevated arbitrary file deletion via extra.pie- installed-binary metadata in UninstallUsingUnlink GHSA-pm6p-666q-hvj5 - Sudo-elevated root code execution via TOCTOU between self- update verify and write GHSA-f67f-c344-cqqr - PIE self-update accepts any historically-attested pie.phar (rollback gap) GHSA-vcv4-gmjc-mxvq - php-ext.build-path traversal escapes PIE's vendor extract directory GHSA-8xmh-xrvp-hwrf - WindowsInstall::copyExtraFile lacks destination containment check (Windows-only path traversal) GHSA-p4j8-36rr-gjfq - Self-update attestation verification is scoped to --owner=php, not --repo=php/pie -------------------------------------------------------------------------------- ChangeLog: * Tue May 26 2026 Remi Collet - 1.4.5-1 - update to1.4.5 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e5d5fc359d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Critical security fixes for PIE in Fedora 44 address elevated privileges and file issues. Update now to secure your system.. Fedora Update, PIE Installer, Security Fixes, Code Execution, Vulnerability Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 04, 2026 Critical Fedora
89

Fedora 43 pie 1.4.5 Important Sudo Code Execution Threats

Version 1.4.5 This release contains vulnerability fixes for the following security advisories: GHSA-h842-vjwg-pxxx - Sudo-elevated arbitrary file deletion via extra.pie- installed-binary metadata in UninstallUsingUnlink GHSA-pm6p-666q-hvj5 - Sudo-elevated root code execution via TOCTOU between self-. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b2fe14ec86 2026-06-04 01:35:07.681084+00:00 -------------------------------------------------------------------------------- Name : pie Product : Fedora 43 Version : 1.4.5 Release : 1.fc43 URL : https://github.com/php/pie Summary : PHP Installer for Extensions Description : PIE (PHP Installer for Extensions). PIE can install an extension to any installed PHP version. A list of extensions that support PIE can be found on https://packagist.org/extensions. Documentation: /usr/share/doc/pie/docs/usage.md -------------------------------------------------------------------------------- Update Information: Version 1.4.5 This release contains vulnerability fixes for the following security advisories: GHSA-h842-vjwg-pxxx - Sudo-elevated arbitrary file deletion via extra.pie- installed-binary metadata in UninstallUsingUnlink GHSA-pm6p-666q-hvj5 - Sudo-elevated root code execution via TOCTOU between self- update verify and write GHSA-f67f-c344-cqqr - PIE self-update accepts any historically-attested pie.phar (rollback gap) GHSA-vcv4-gmjc-mxvq - php-ext.build-path traversal escapes PIE's vendor extract directory GHSA-8xmh-xrvp-hwrf - WindowsInstall::copyExtraFile lacks destination containment check (Windows-only path traversal) GHSA-p4j8-36rr-gjfq - Self-update attestation verification is scoped to --owner=php, not --repo=php/pie -------------------------------------------------------------------------------- ChangeLog: * Tue May 26 2026 Remi Collet - 1.4.5-1 - update to1.4.5 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b2fe14ec86' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fedora 43 pie 1.4.5 update addresses critical sudo file deletion and code execution flaws.. Fedora 43, pie update, PHP security, code execution, installation issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 04, 2026 Important Fedora
219

Ubuntu OS Version 22 System Alert ULAN-2026-54321 CVE-2026-67890

Important: sudo security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:12310", "synopsis": "Important: sudo security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for sudo.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root.\n\nSecurity Fix(es):\n\n* sudo: Sudo: Privilege escalation due to failure in privilege drop calls (CVE-2026-35535)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2454714", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2454714", "description": ""}], "cves": [{"name": "CVE-2026-35535", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35535", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.4", "cwe": "CWE-272"}], "references": [], "publishedAt": "2026-05-03T12:03:41.515195Z", "rpms": {"Rocky Linux 9": {"nvras": ["sudo-0:1.9.5p2-15.el9_7.aarch64.rpm", "sudo-0:1.9.5p2-15.el9_7.ppc64le.rpm", "sudo-0:1.9.5p2-15.el9_7.s390x.rpm", "sudo-0:1.9.5p2-15.el9_7.src.rpm", "sudo-0:1.9.5p2-15.el9_7.x86_64.rpm", "sudo-debuginfo-0:1.9.5p2-15.el9_7.aarch64.rpm", "sudo-debuginfo-0:1.9.5p2-15.el9_7.ppc64le.rpm", "sudo-debuginfo-0:1.9.5p2-15.el9_7.s390x.rpm", "sudo-debuginfo-0:1.9.5p2-15.el9_7.x86_64.rpm", "sudo-debugsource-0:1.9.5p2-15.el9_7.aarch64.rpm", "sudo-debugsource-0:1.9.5p2-15.el9_7.ppc64le.rpm","sudo-debugsource-0:1.9.5p2-15.el9_7.s390x.rpm", "sudo-debugsource-0:1.9.5p2-15.el9_7.x86_64.rpm", "sudo-python-plugin-0:1.9.5p2-15.el9_7.aarch64.rpm", "sudo-python-plugin-0:1.9.5p2-15.el9_7.ppc64le.rpm", "sudo-python-plugin-0:1.9.5p2-15.el9_7.s390x.rpm", "sudo-python-plugin-0:1.9.5p2-15.el9_7.x86_64.rpm", "sudo-python-plugin-debuginfo-0:1.9.5p2-15.el9_7.aarch64.rpm", "sudo-python-plugin-debuginfo-0:1.9.5p2-15.el9_7.ppc64le.rpm", "sudo-python-plugin-debuginfo-0:1.9.5p2-15.el9_7.s390x.rpm", "sudo-python-plugin-debuginfo-0:1.9.5p2-15.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Stay safe with this important sudo security update for Rocky Linux. Learn about critical privilege escalation fixing details here.. Rocky Linux sudo security upgrade CVE-2026-35535 privilege escalation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 03, 2026 Important Rocky Linux
217

Oracle Linux 9 ELSA-2026-12310 sudo Important Privilege Escalation

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-12310 http://linux.oracle.com/errata/ELSA-2026-12310.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: sudo-1.9.5p2-15.el9_7.x86_64.rpm sudo-python-plugin-1.9.5p2-15.el9_7.x86_64.rpm aarch64: sudo-1.9.5p2-15.el9_7.aarch64.rpm sudo-python-plugin-1.9.5p2-15.el9_7.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/sudo-1.9.5p2-15.el9_7.src.rpm Related CVEs: CVE-2026-35535 Description of changes: [1.9.5p2-15] RHEL 9.7.0 ERRATUM - CVE-2026-35535 - Privilege escalation due to failure in privilege drop calls Resolves: RHEL-166065 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Critical update for Oracle Linux 9 addressing important sudo privilege escalation flaw requiring immediate attention.. Oracle Linux, sudo security, privilege escalation, Linux updates, Important advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 01, 2026 Important Oracle
219

Rocky Linux 8 RLSA-2026-11356 Sudo Authorization Bypass Risk Notification

Important: sudo security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:11521", "synopsis": "Important: sudo security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for sudo.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root.\n\nSecurity Fix(es):\n\n* sudo: Sudo: Privilege escalation due to failure in privilege drop calls (CVE-2026-35535)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2454714", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2454714", "description": ""}], "cves": [{"name": "CVE-2026-35535", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35535", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.4", "cwe": "CWE-272"}], "references": [], "publishedAt": "2026-04-30T18:00:45.302131Z", "rpms": {"Rocky Linux 8": {"nvras": ["sudo-0:1.9.5p2-1.el8_10.5.aarch64.rpm", "sudo-0:1.9.5p2-1.el8_10.5.src.rpm", "sudo-0:1.9.5p2-1.el8_10.5.x86_64.rpm", "sudo-debuginfo-0:1.9.5p2-1.el8_10.5.aarch64.rpm", "sudo-debuginfo-0:1.9.5p2-1.el8_10.5.x86_64.rpm", "sudo-debugsource-0:1.9.5p2-1.el8_10.5.aarch64.rpm", "sudo-debugsource-0:1.9.5p2-1.el8_10.5.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important sudo security update available for Rocky Linux 8 to address privilege escalation risk.. Rocky Linux Sudo Update ImportantPrivilege Escalation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 30, 2026 Important Rocky Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200