Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 45 articles for you...
89

Fedora 44 acl Critical Symlink Traversal Fix FEDORA-2026-6b9a652463

rebase to v2.4.0 to fix CVE-2026-54369 and CVE-2026-54370 Resolves: CVE-2026-54369 Resolves: CVE-2026-54370. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6b9a652463 2026-07-11 01:06:30.201359+00:00 -------------------------------------------------------------------------------- Name : acl Product : Fedora 44 Version : 2.4.0 Release : 1.fc44 URL : https://savannah.nongnu.org/projects/acl Summary : Access control list utilities Description : This package contains the getfacl and setfacl utilities needed for manipulating access control lists. -------------------------------------------------------------------------------- Update Information: rebase to v2.4.0 to fix CVE-2026-54369 and CVE-2026-54370 Resolves: CVE-2026-54369 Resolves: CVE-2026-54370 -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 9 2026 Lukáš Zaoral - 2.4.0-1 - rebase to v2.4.0 to fix the following CVEs: - CVE-2026-54369 - Symlink traversal privilege escalation via libacl functions - CVE-2026-54370 - TOCTOU Symlink Traversal via getfacl/setfacl -------------------------------------------------------------------------------- References: [ 1 ] Bug #2494173 - CVE-2026-54370 acl: TOCTOU Symlink Traversal via getfacl/setfacl [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494173 [ 2 ] Bug #2494174 - CVE-2026-54369 acl: Symlink traversal privilege escalation via libacl functions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494174 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6b9a652463' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key.More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical Fedora 44 acl update since it fixes symlink privilege escalation issues to enhance system security.. Fedora acl update, privilege escalation, symlink vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 10, 2026 Critical Fedora
100

SUSE Linux Micro crun Moderate Symlink Issue Advisory 2026-22395-1

An update that solves one vulnerability can now be installed.. # Security update for crun Announcement ID: SUSE-SU-2026:22395-1 Release Date: 2026-06-24T08:59:37Z Rating: moderate References: * bsc#1268302 Cross-References: * CVE-2026-47766 CVSS scores: * CVE-2026-47766 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for crun fixes the following issue * CVE-2026-47766: crun follows rootfs /dev symlink while creating default devices (bsc#1268302). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-766=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * crun-debuginfo-1.14-3.1 * crun-1.14-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-47766.html * https://bugzilla.suse.com/show_bug.cgi?id=1268302 . This security update addresses one moderate issue in crun related to symlink handling, applicable for SUSE Micro.. SUSE Linux Micro, crun security, moderate update. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 03, 2026 moderate SuSE
217

Oracle Linux 8 ELSA-2026-30852 perl-Archive-Tar Important Security Advisory

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-30852 http://linux.oracle.com/errata/ELSA-2026-30852.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: perl-Archive-Tar-2.30-2.el8_10.noarch.rpm aarch64: perl-Archive-Tar-2.30-2.el8_10.noarch.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/perl-Archive-Tar-2.30-2.el8_10.src.rpm Related CVEs: CVE-2026-42496 Description of changes: [2.30-2] - Fix CVE-2026-42496: validate symlink and hardlink targets in secure extract mode - Resolves: RHEL-181654 [2.30-1] - 2.30 bump [2.28-1] - 2.28 bump - Fixes CVE-2018-12015 (directory traversal) (bug #1588761) [2.26-6] - Do not run optional test on RHEL [2.26-5] - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild [2.26-4] - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild [2.26-3] - Perl 5.26 re-rebuild of bootstrapped packages [2.26-2] - Perl 5.26 rebuild [2.26-1] - 2.26 bump [2.24-2] - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 8 Security Advisory ELSA-2026-30852 fixes important issues with perl-Archive-Tar.. Oracle Linux 8, perl-Archive-Tar, security fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 Important Oracle
89

Fedora 43 util-linux Important SUID Symlink Attack CVE-2026-27456

upstream update, fixes security-related bugs CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device. The SUID mount follows symlinks when resolving loop backing file paths. On systems where non-root users are permitted to mount loop devices (via 'user' option in fstab), this allows access to. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-840b40ef4c 2026-04-10 00:59:15.834457+00:00 -------------------------------------------------------------------------------- Name : util-linux Product : Fedora 43 Version : 2.41.4 Release : 7.fc43 URL : https://en.wikipedia.org/wiki/Util-linux Summary : Collection of basic system utilities Description : The util-linux package contains a large variety of low-level system utilities that are necessary for a Linux system to function. Among others, util-linux contains the fdisk configuration tool and the login program. -------------------------------------------------------------------------------- Update Information: upstream update, fixes security-related bugs CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device. The SUID mount follows symlinks when resolving loop backing file paths. On systems where non-root users are permitted to mount loop devices (via 'user' option in fstab), this allows access to arbitrary files. CWE-190 - Integer overflow in libblkid parse_dos_extended(). A crafted MBR disk image can cause uint32_t wraparound in EBR chain processing, causing reported partitions to not match the on-disk layout. Tools like udisks may then register a partition at logical sector 0. -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 1 2026 Karel Zak - 2.41.4-7 - upgrade to upstream release v2.41.4 * Mon Jan 12 2026 Karel Zak - 2.41.3-9 - enable BuildRequires for parsers * Mon Jan 12 2026 Karel Zak - 2.41.3-8 - fix built on newgcc (bison based code and libblkid API) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-840b40ef4c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fixes security flaws in util-linux for Fedora 43, addressing symlink attacks and integer overflow issues.. Fedora update, util-linux security, mount symlink attack, integer overflow, system utilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 10, 2026 Important Fedora
172

Ubuntu 24.04 LTS Filelock Important Symlink DoS 2026-22701

Several security issues were fixed in Filelock.. ========================================================================== Ubuntu Security Notice USN-7999-1 February 02, 2026 python-filelock vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Filelock. Software Description: - python-filelock: A platform-independent file lock for Python Details: It was discovered that Filelock incorrectly handled symlinks in temp files. A local attacker could possibly use this issue to cause lock operations to fail or behave unexpectedly. (CVE-2026-22701) It was discovered that the file locking implementation in the Filelock package contained a race condition. A local attacker could possibly use this to cause a denial of service or corrupt arbitrary user files. (CVE-2025-68146) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python3-filelock 3.13.1-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS python3-filelock 3.6.0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS python3-filelock 3.0.12-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS python-filelock 3.0.4-1ubuntu0.1~esm1 Available with Ubuntu Pro python3-filelock 3.0.4-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7999-1 CVE-2025-68146, CVE-2026-22701 . Several security issues were fixed in Filelock affecting multiple Ubuntu LTS releases.Critical updates are recommended.. python-filelock update, Ubuntu security, file locking issues, Denial of Service, local attacker. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 03, 2026 Important Ubuntu
89

Fedora 41: yarnpkg Fix CVE-2025-59343 Tar-fs Symlink Bypass

Fix CVE-2025-59343.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-4dd58248ff 2025-10-09 01:14:09.802852+00:00 -------------------------------------------------------------------------------- Name : yarnpkg Product : Fedora 41 Version : 1.22.22 Release : 12.fc41 URL : https://github.com/yarnpkg/yarn Summary : Fast, reliable, and secure dependency management. Description : Fast, reliable, and secure dependency management. -------------------------------------------------------------------------------- Update Information: Fix CVE-2025-59343. -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 30 2025 Sandro Mani - 1.22.22-12 - Regenerate bundle, fixes CVE-2025-59343 - Patch out eslint and commitizen devDependencies to reduce dependencies -------------------------------------------------------------------------------- References: [ 1 ] Bug #2397971 - CVE-2025-59343 yarnpkg: tar-fs symlink validation bypass [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2397971 [ 2 ] Bug #2397973 - CVE-2025-59343 yarnpkg: tar-fs symlink validation bypass [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2397973 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-4dd58248ff' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fix for CVE-2025-59343 improves Yarnpkg security on Fedora 41, addressing potential symlink bypass issues effectively.. Fedora 41, yarnpkg, CVE fix, symlink validation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 09, 2025 Important Fedora
197

Debian 11: node-tar-fs Important Symlink Bypass DLA-4313-1 CVE-2025-59343

node-tar-fs versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. . From: Xavier Guimard To: This email address is being protected from spambots. You need JavaScript enabled to view it. Subject: [SECURITY] [DLA 4313-1] node-tar-fs security update - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4313-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Yadd September 27, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : node-tar-fs Version : 2.1.3-0+deb11u2 CVE ID : CVE-2025-59343 Debian Bug : node-tar-fs versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. For Debian 11 bullseye, this problem has been fixed in version 2.1.3-0+deb11u2. We recommend that you upgrade your node-tar-fs packages. For the detailed security status of node-tar-fs please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/node-tar-fs Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . node-tar-fs versions prior to specified versions have been found at risk of a specific security issue. Upgrade recommended.. node-tar-fs symlink bypass Debian upgrade security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 28, 2025 Important Debian LTS
87

Debian: Critical Symlink Bypass Vulnerability in node-tar-fs DSA-6013-1

It was discovered that the symlink validation in node-tar-fs, a Node.js module that provides filesystem-like access to tar files, could be bypassed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6013-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff September 28, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : node-tar-fs CVE ID : CVE-2025-59343 It was discovered that the symlink validation in node-tar-fs, a Node.js module that provides filesystem-like access to tar files, could be bypassed. For the oldstable distribution (bookworm), this problem has been fixed in version 2.1.3-0+deb12u2. For the stable distribution (trixie), this problem has been fixed in version 3.0.9+~cs2.0.4-1+deb13u1. We recommend that you upgrade your node-tar-fs packages. For the detailed security status of node-tar-fs please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/node-tar-fs Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical security flaw in node-tar-fs allows symlink validation bypass. Update recommended for Debian systems.. node-tar-fs, symlink, filesystem, security advisory, Debian. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 28, 2025 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200