Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 5 articles for you...
202

Fedora syncthing Patch Release 2026-10764-1 CVE-2021-XXXX Moderate Severity

An update that solves one vulnerability can now be installed.. # syncthing-2.1.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:10764-1 Rating: moderate Cross-References: * CVE-2020-11022 CVSS scores: * CVE-2020-11022 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the syncthing-2.1.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * syncthing 2.1.0-1.1 * syncthing-relaysrv 2.1.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2020-11022.html . Update for syncthing solves moderate vulnerability in openSUSE Tumbleweed, addresses CVE-2020-11022.. OpenSUSE Security Update, syncthing Vulnerability Fix, Moderate Linux Threat. . LinuxSecurity.com Team

Calendar 2 May 14, 2026 OpenSUSE
89

Fedora 41: FEDORA-2024-aa6e72c713 moderate: Fix for ZIP Handling Issue

Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-aa6e72c713 2024-11-06 03:51:37.801150 -------------------------------------------------------------------------------- Name : syncthing Product : Fedora 41 Version : 1.28.0 Release : 1.fc41 URL : https://syncthing.net Summary : Continuous File Synchronization Description : Syncthing replaces other file synchronization services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet. Using syncthing, that control is returned to you. This package contains the syncthing client binary and systemd services. -------------------------------------------------------------------------------- Update Information: Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0 -------------------------------------------------------------------------------- ChangeLog: * Mon Oct 28 2024 Fabio Valentini - 1.28.0-1 - Update to version 1.28.0; Fixes RHBZ#2319211 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2292676 - CVE-2024-24789 syncthing: golang: archive/zip: Incorrect handling of certain ZIP files [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2292676 [ 2 ] Bug #2292720 - CVE-2024-24789 syncthing: golang: archive/zip: Incorrect handling of certain ZIP files [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2292720 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-aa6e72c713' at the command line. For moreinformation, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 41 has introduced an update for Syncthing to version 1.28.0, featuring crucial security fixes and performance improvements for users to enjoy enhanced functionality. Fedora 41 Update, Syncthing 1.28.0 Security, File Synchronization, Golang Security Fix. . LinuxSecurity.com Team

Calendar 2 Nov 06, 2024 Fedora
89

Fedora 39: 2024-4fc7cdc194 moderate: syncthing update to version 1.28.0

Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-4fc7cdc194 2024-11-06 02:43:53.691855 -------------------------------------------------------------------------------- Name : syncthing Product : Fedora 39 Version : 1.28.0 Release : 1.fc39 URL : https://syncthing.net Summary : Continuous File Synchronization Description : Syncthing replaces other file synchronization services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet. Using syncthing, that control is returned to you. This package contains the syncthing client binary and systemd services. -------------------------------------------------------------------------------- Update Information: Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0 -------------------------------------------------------------------------------- ChangeLog: * Mon Oct 28 2024 Fabio Valentini - 1.28.0-1 - Update to version 1.28.0; Fixes RHBZ#2319211 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2292676 - CVE-2024-24789 syncthing: golang: archive/zip: Incorrect handling of certain ZIP files [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2292676 [ 2 ] Bug #2292720 - CVE-2024-24789 syncthing: golang: archive/zip: Incorrect handling of certain ZIP files [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2292720 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-4fc7cdc194' at the command line. For moreinformation, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . The latest iteration of Fedora's syncthing, version 1.28.0, incorporates notable enhancements and resolutions, improving both the security and efficiency of file synchronization.. Fedora Updates, syncthing, file synchronization, security updates, bug fixes. . LinuxSecurity.com Team

Calendar 2 Nov 06, 2024 Fedora
89

Fedora 38: FEDORA-2024-b93312a597 Critical: Syncthing Memory Exhaustion

Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-b93312a597 2024-02-21 01:38:35.302031 -------------------------------------------------------------------------------- Name : syncthing Product : Fedora 38 Version : 1.27.3 Release : 1.fc38 URL : https://syncthing.net Summary : Continuous File Synchronization Description : Syncthing replaces other file synchronization services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet. Using syncthing, that control is returned to you. This package contains the syncthing client binary and systemd services. -------------------------------------------------------------------------------- Update Information: Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 12 2024 Fabio Valentini - 1.27.3-1 - Update to version 1.27.3; Fixes RHBZ#2263121 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2257833 - CVE-2023-49295 syncthing: quic-go: memory exhaustion attack against QUIC's path validation mechanism [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257833 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2024-b93312a597' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest Syncthing 1.27.3 has been released for Fedora 38, fixing critical memory leaks in the QUIC protocol. Visit the official Syncthing docs for details.. Syncthing Update, Fedora 38, File Synchronization, Memory Exhaustion, DNF Upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 21, 2024 Critical Fedora
89

Fedora 39 Syncthing 1.27.3 Critical Update Against Memory Attack

Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-c46536abe6 2024-02-21 01:31:44.025637 -------------------------------------------------------------------------------- Name : syncthing Product : Fedora 39 Version : 1.27.3 Release : 1.fc39 URL : https://syncthing.net Summary : Continuous File Synchronization Description : Syncthing replaces other file synchronization services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet. Using syncthing, that control is returned to you. This package contains the syncthing client binary and systemd services. -------------------------------------------------------------------------------- Update Information: Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 12 2024 Fabio Valentini - 1.27.3-1 - Update to version 1.27.3; Fixes RHBZ#2263121 * Sun Feb 11 2024 Maxwell G - 1.27.2-3 - Rebuild for golang 1.22.0 * Sat Jan 27 2024 Fedora Release Engineering - 1.27.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2257833 - CVE-2023-49295 syncthing: quic-go: memory exhaustion attack against QUIC's path validation mechanism [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257833 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-c46536abe6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 39 has updated Syncthing to version 1.27.3, addressing the CVE-2023-49295 security issue while enhancing file management and monitoring capabilities.. Fedora Software Update, Syncthing Patch, QUIC Memory Attack. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 21, 2024 Critical Fedora
89

Fedora 39 FEDORA-2023-0d46257314 Critical: Syncthing 1.26.0 Security Update

Update to version 1.26.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.26.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-0d46257314 2023-11-18 01:37:22.840201 -------------------------------------------------------------------------------- Name : syncthing Product : Fedora 39 Version : 1.26.0 Release : 1.fc39 URL : https://syncthing.net Summary : Continuous File Synchronization Description : Syncthing replaces other file synchronization services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet. Using syncthing, that control is returned to you. This package contains the syncthing client binary and systemd services. -------------------------------------------------------------------------------- Update Information: Update to version 1.26.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.26.0 -------------------------------------------------------------------------------- ChangeLog: * Thu Nov 9 2023 Fabio Valentini - 1.26.0-1 - Update to version 1.26.0; Fixes RHBZ#2248507 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2248412 - syncthing: golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-39325) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2248412 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-0d46257314' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key.More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 39 security bulletin for syncthing release 1.26.0 covering essential enhancements and remedies for data syncing issues.. Fedora 39, Syncthing Update, File Synchronization, Security Release. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 18, 2023 Critical Fedora
89

Fedora 38: FEDORA-2023-d58c8eeb7c Critical: Syncthing File Sync Issue

Update to version 1.26.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.26.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-d58c8eeb7c 2023-11-18 01:25:52.283227 -------------------------------------------------------------------------------- Name : syncthing Product : Fedora 38 Version : 1.26.0 Release : 1.fc38 URL : https://syncthing.net Summary : Continuous File Synchronization Description : Syncthing replaces other file synchronization services with something open, trustworthy and decentralized. Your data is your data alone and you deserve to choose where it is stored, if it is shared with some third party and how it's transmitted over the Internet. Using syncthing, that control is returned to you. This package contains the syncthing client binary and systemd services. -------------------------------------------------------------------------------- Update Information: Update to version 1.26.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.26.0 -------------------------------------------------------------------------------- ChangeLog: * Thu Nov 9 2023 Fabio Valentini - 1.26.0-1 - Update to version 1.26.0; Fixes RHBZ#2248507 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2248412 - syncthing: golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-39325) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2248412 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-d58c8eeb7c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key.More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Enhance the security of your Fedora 38 setup utilizing Syncthing version 1.26.0, amplifying the benefits of decentralized file synchronization capabilities.. Fedora 38 Syncthing, Continuous File Sync, Software Update Notification. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 18, 2023 Critical Fedora
202

openSUSE 15 SP5: 2023:0126-1 Moderate: Syncthing XSS Fix

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for syncthing ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0126-1 Rating: moderate References: #1212085 Cross-References: CVE-2022-46165 CVSS scores: CVE-2022-46165 (NVD) : 4.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N CVE-2022-46165 (SUSE): 4.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for syncthing fixes the following issues: - Update to 1.13.5 * This release fixes CVE-2022-46165 “Cross-site Scripting (XSS) in Web GUI” * Bugfixes: #8503: "syncthing cli config devices add" reflect error when using --addresses flag #8764: Ignore patterns creating during folder addition are not loaded #8778: Tests fail on Windows with Go 1.20 #8779: Test cleanup fails all model tests on Windows on Go 1.20 #8859: Incorrect handling of path for auto accepted folder * Other issues: #8799: "fatal error: checkptr: converted pointer straddles multiple allocations" in crypto tests - Update to 1.23.4 - Bugfixes: #8851: "Running global migration to fix encryption file sizes" on every start - Update to 1.23.3 * Bugfixes: #5408: Selection of time in versions GUI not possible without editing the string inside the textfield #8277: Mutual encrypted sharing doesn't work (both sides with password) #8556: Increased file size when sharing between encrypted devices #8599: Key generation at connect time is slow for encrypted connections * Enhancements: #7859: Allow sub-second watcher delay (use case: remote development) * Otherissues: #8828: cmd/stdiscosrv: TestDatabaseGetSet flake - Adding a desktop file for the Web UI - Update to 1.23.2 * Bugfixes: #8749: Relay listener does not restart sometimes * Enhancements: #8660: GUI editor for xattr filter patterns #8781: gui: Remove duplicate Spanish translation * Other issues: #8768: Update quic-go for Go 1.20 Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2023-126=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): syncthing-1.23.5-bp155.2.3.1 syncthing-relaysrv-1.23.5-bp155.2.3.1 References: https://www.suse.com/security/cve/CVE-2022-46165.html https://bugzilla.suse.com/1212085 . Follow these steps to deploy the Syncthing patch addressing the moderate severity XSS vulnerability and ensure your system's security during the process. openSUSE Update,syncthing Security,Cross-Site Scripting Fix. . LinuxSecurity.com Team

Calendar 2 Jun 16, 2023 OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here