Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
100

SUSE: 2022:2179-1 Moderate: OpenSSL Shell Injection Threat

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for openssl ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2179-1 Rating: moderate References: #1200550 Cross-References: CVE-2022-2068 CVSS scores: CVE-2022-2068 (SUSE): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE CaaS Platform 4.0 SUSE Enterprise Storage 6 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server for SAP 15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for openssl fixes the following issues: - CVE-2022-2068: Fixed more shell code injection issues in c_rehash. (bsc#1200550) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2022-2179=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2022-2179=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2022-2179=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2022-2179=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patchSUSE-SLE-Product-HPC-15-SP1-ESPOS-2022-2179=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2022-2179=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE Linux Enterprise Server for SAP 15-SP1 (ppc64le x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.33.1 libopenssl1_1-1.1.0i-150100.14.33.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-1.1.0i-150100.14.33.1 openssl-1_1-1.1.0i-150100.14.33.1 openssl-1_1-debuginfo-1.1.0i-150100.14.33.1 openssl-1_1-debugsource-1.1.0i-150100.14.33.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.33.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (aarch64 ppc64le s390x x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.33.1 libopenssl1_1-1.1.0i-150100.14.33.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-1.1.0i-150100.14.33.1 openssl-1_1-1.1.0i-150100.14.33.1 openssl-1_1-debuginfo-1.1.0i-150100.14.33.1 openssl-1_1-debugsource-1.1.0i-150100.14.33.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.33.1 - SUSE Linux Enterprise Server 15-SP1-BCL (x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.33.1 libopenssl-1_1-devel-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.33.1 openssl-1_1-1.1.0i-150100.14.33.1 openssl-1_1-debuginfo-1.1.0i-150100.14.33.1 openssl-1_1-debugsource-1.1.0i-150100.14.33.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (aarch64 x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.33.1 libopenssl1_1-1.1.0i-150100.14.33.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-1.1.0i-150100.14.33.1 openssl-1_1-1.1.0i-150100.14.33.1 openssl-1_1-debuginfo-1.1.0i-150100.14.33.1 openssl-1_1-debugsource-1.1.0i-150100.14.33.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.33.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (aarch64 x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.33.1 libopenssl1_1-1.1.0i-150100.14.33.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-1.1.0i-150100.14.33.1 openssl-1_1-1.1.0i-150100.14.33.1 openssl-1_1-debuginfo-1.1.0i-150100.14.33.1 openssl-1_1-debugsource-1.1.0i-150100.14.33.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.33.1 - SUSE Enterprise Storage 6 (aarch64 x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.33.1 libopenssl1_1-1.1.0i-150100.14.33.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-1.1.0i-150100.14.33.1 openssl-1_1-1.1.0i-150100.14.33.1 openssl-1_1-debuginfo-1.1.0i-150100.14.33.1 openssl-1_1-debugsource-1.1.0i-150100.14.33.1 - SUSE Enterprise Storage 6 (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.33.1 - SUSE CaaS Platform 4.0 (x86_64): libopenssl-1_1-devel-1.1.0i-150100.14.33.1 libopenssl-1_1-devel-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-1.1.0i-150100.14.33.1 libopenssl1_1-32bit-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-debuginfo-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-1.1.0i-150100.14.33.1 libopenssl1_1-hmac-32bit-1.1.0i-150100.14.33.1 openssl-1_1-1.1.0i-150100.14.33.1 openssl-1_1-debuginfo-1.1.0i-150100.14.33.1 openssl-1_1-debugsource-1.1.0i-150100.14.33.1 References: https://www.suse.com/security/cve/CVE-2022-2068.html https://bugzilla.suse.com/1200550 . SUSE has released a Security Update targeting the OpenSSL flaw CVE-2022-2068, classified with a moderate severity level, applicable to multiple SUSE offerings.. SUSE OpenSSL Update, SUSE Security Advisory, Linux Security Update. . LinuxSecurity.com Team

Calendar%202 Jun 24, 2022 SuSE
100

SUSE CaaS Platform 4.0: SUSE-SU-2020:3760-1 Moderate: Security Fixes

An update that fixes 8 vulnerabilities is now available. . SUSE Security Update: Security changes in Kubernetes, etcd, and helm; Bugfix in cri-o package ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:3760-1 Rating: moderate References: #1174219 #1174951 #1176752 #1176753 #1176754 #1176755 #1177661 #1177662 Cross-References: CVE-2020-15106 CVE-2020-15112 CVE-2020-15184 CVE-2020-15185 CVE-2020-15186 CVE-2020-15187 CVE-2020-8565 CVE-2020-8566 Affected Products: SUSE Linux Enterprise Module for Containers 15-SP1 SUSE CaaS Platform 4.0 ______________________________________________________________________________ An update that fixes 8 vulnerabilities is now available. Description: = Required Actions == Kubernetes & etcd (Security fixes) This fix involves an upgrade of Kubernetes and some add-ons. See ates.html#_updating_kubernetes_components for the upgrade procedure. == Skuba & helm/helm3 In order to update skuba and helm or helm 3, you need to update the management workstation. See detailed instructions at ates.html#_update_management_workstation = Known Issues Modifying the file `/etc/sysconfig/kubelet` directly is not supported: documentation at us.html#_configuring_kubelet Be sure to check the Release Notes at https://www.suse.com/releasenotes/x86_64/SUSE-CAASP/4/index.html for any additional known issues or behavioral changes. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Containers 15-SP1: zypper in -t patch SUSE-SLE-Module-Containers-15-SP1-2020-3760=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaSPlatform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE Linux Enterprise Module for Containers 15-SP1 (x86_64): kubernetes-client-1.17.13-4.21.2 kubernetes-common-1.17.13-4.21.2 - SUSE CaaS Platform 4.0 (x86_64): caasp-release-4.2.4-24.36.1 cri-o-1.16.1-3.37.3 cri-o-kubeadm-criconfig-1.16.1-3.37.3 etcdctl-3.4.13-4.15.1 helm-2.16.12-3.10.1 kubernetes-client-1.17.13-4.21.2 kubernetes-common-1.17.13-4.21.2 kubernetes-kubeadm-1.17.13-4.21.2 kubernetes-kubelet-1.17.13-4.21.2 skuba-1.4.11-3.49.2 terraform-provider-aws-2.59.0-1.6.1 - SUSE CaaS Platform 4.0 (noarch): skuba-update-1.4.11-3.49.2 References: https://www.suse.com/security/cve/CVE-2020-15106.html https://www.suse.com/security/cve/CVE-2020-15112.html https://www.suse.com/security/cve/CVE-2020-15184.html https://www.suse.com/security/cve/CVE-2020-15185.html https://www.suse.com/security/cve/CVE-2020-15186.html https://www.suse.com/security/cve/CVE-2020-15187.html https://www.suse.com/security/cve/CVE-2020-8565.html https://www.suse.com/security/cve/CVE-2020-8566.html https://bugzilla.suse.com/1174219 https://bugzilla.suse.com/1174951 https://bugzilla.suse.com/1176752 https://bugzilla.suse.com/1176753 https://bugzilla.suse.com/1176754 https://bugzilla.suse.com/1176755 https://bugzilla.suse.com/1177661 https://bugzilla.suse.com/1177662 . SUSE unveils a vital security patch aimed at resolving vulnerabilities in Kubernetes, etcd, and Helm, providing solutions for various concerns.. SUSE CaaS Platform, Kubernetes Security, Update Instructions. . LinuxSecurity.com Team

Calendar%202 Dec 11, 2020 SuSE
100

SUSE CaaS Platform 3.0: 2018:4020-1 Critical Security Fix For Kubernetes

An update that solves two vulnerabilities and has 7 fixes is now available. . SUSE Security Update: Security update for cri-o and kubernetes packages ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:4020-1 Rating: important References: #1084765 #1095131 #1108195 #1111341 #1112967 #1112980 #1114645 #1116933 #1118198 Cross-References: CVE-2016-8859 CVE-2018-1002105 Affected Products: SUSE CaaS Platform 3.0 ______________________________________________________________________________ An update that solves two vulnerabilities and has 7 fixes is now available. Description: This update provide fixes for kubernetes, kubernetes-salt, cri-o, and caasp-container-manifests: - VUL-0: kubernetes: proxy request handling in kube-apiserver can leave vulnerable TCP connections (bsc#1118198) - Error in Velum when applying the k8s 1.10.8 on CRI-O cluster (bsc#1116933) - Update regexp for SUSE images (bsc#1111341) - Require kubernetes-kubelet for kubeadm (bsc#1084765) - Move deprecated flags to kubelet config.yaml (bsc#1114645) - Update to k8s 1.10.x (bsc#1114645) - Fix kubelet failing to get device for dir "/var/lib/kubelet (bsc#1095131) - Set NOFILE and NPROC limit to 1048576 to align with Docker/containerd and the upstream unit file. (bsc#1112980) - Update cluster-proportional-autoscaler-amd64 in typha addon to w/ fix for (CVE-2016-8859) - Add a whitelist for returned events so we only save events that we care about (bsc#1112967) - Aggregation layer needs configuration (bsc#1108195) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE CaaS Platform 3.0: To install this update, use the SUSE CaaS Platform Velum dashboard. It will informyou if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE CaaS Platform 3.0 (noarch): caasp-container-manifests-3.0.0+git_r291_33f7b2d-3.6.3 kubernetes-salt-3.0.0+git_r888_7af7095-3.33.2 - SUSE CaaS Platform 3.0 (x86_64): cri-o-1.10.6-4.8.5 cri-tools-1.0.0beta2-3.3.3 kubernetes-client-1.10.11-4.8.2 kubernetes-common-1.10.11-4.8.2 kubernetes-kubelet-1.10.11-4.8.2 kubernetes-master-1.10.11-4.8.2 kubernetes-node-1.10.11-4.8.2 References: https://www.suse.com/security/cve/CVE-2016-8859.html https://www.suse.com/security/cve/CVE-2018-1002105.html https://bugzilla.suse.com/1084765 https://bugzilla.suse.com/1095131 https://bugzilla.suse.com/1108195 https://bugzilla.suse.com/1111341 https://bugzilla.suse.com/1112967 https://bugzilla.suse.com/1112980 https://bugzilla.suse.com/1114645 https://bugzilla.suse.com/1116933 https://bugzilla.suse.com/1118198 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE has issued a Security Update addressing two vulnerabilities found in the cri-o and kubernetes packages, along with significant ratings and patch information.. SUSE CaaS Platform,kubernetes,cri-o,security update,patch management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 07, 2018 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200