Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 43 incus 6.23 Dependency Removed Advisory 2026-094b7621cf

Remove incus dependency from incus-agent. Update to 6.23. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-094b7621cf 2026-04-20 00:44:47.956847+00:00 -------------------------------------------------------------------------------- Name : incus Product : Fedora 43 Version : 6.23 Release : 3.fc43 URL : https://linuxcontainers.org/incus Summary : Powerful system container and virtual machine manager Description : Container hypervisor based on LXC Incus offers a REST API to remotely manage containers over the network, using an image based work-flow and with support for live migration. This package contains the Incus daemon. -------------------------------------------------------------------------------- Update Information: Remove incus dependency from incus-agent. Update to 6.23 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 9 2026 Carl George - 6.23-3 - Remove incus dependency from incus-agent rhbz#2456888 * Mon Apr 6 2026 Reto Gantenbein - 6.23-2 - Fix static builds of vendored dependencies (RHBZ 2419661) * Mon Apr 6 2026 Reto Gantenbein - 6.23-1 - Update to 6.23 * Mon Mar 30 2026 Neal Gompa - 6.19.1-4 - Drop selinux subpackage in favor of container-selinux * Tue Feb 3 2026 Maxwell G - 6.19.1-3 - Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26 * Fri Jan 16 2026 Fedora Release Engineering - 6.19.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2412713 - CVE-2025-58183 incus: Unbounded allocation when parsing GNU sparse map [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2412713 [ 2 ] Bug #2419345 - incus-6.23.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2419345 [ 3 ] Bug #2419661 - incus-agent must bestatically linked for VM exec to work https://bugzilla.redhat.com/show_bug.cgi?id=2419661 [ 4 ] Bug #2432455 - CVE-2026-23954 incus: container image templating arbitrary host file read and write [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2432455 [ 5 ] Bug #2432457 - CVE-2026-23953 incus: container environment configuration newline injection [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2432457 [ 6 ] Bug #2436657 - Incus VMs do not boot due to unknown audio driver https://bugzilla.redhat.com/show_bug.cgi?id=2436657 [ 7 ] Bug #2441179 - CVE-2025-69725 incus: Go-chi/chi: Open Redirect vulnerability allows redirection to malicious websites [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2441179 [ 8 ] Bug #2452042 - CVE-2026-33542 incus: Incus: Image cache poisoning due to insufficient image fingerprint validation [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2452042 [ 9 ] Bug #2452044 - CVE-2026-33897 incus: Incus: Arbitrary file read/write as root via pongo2 template chroot bypass [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2452044 [ 10 ] Bug #2452046 - CVE-2026-33711 incus: Incus: Local privilege escalation or denial of service via predictable temporary file paths [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2452046 [ 11 ] Bug #2452048 - CVE-2026-33743 incus: Incus: Denial of Service via specially crafted storage bucket backup [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2452048 [ 12 ] Bug #2452106 - CVE-2026-33945 incus: Incus: Privilege escalation and denial of service via path traversal in systemd credential configuration [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452106 [ 13 ] Bug #2456888 - Installing incus-agent installs the entire incus stack https://bugzilla.redhat.com/show_bug.cgi?id=2456888 -------------------------------------------------------------------------------- This update canbe installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-094b7621cf' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update to Fedora 43 incus 6.23, addressing dependency removal for incus-agent and enhancing container management.. Fedora 43 incus update, incus dependency removal, system container manager. . Severity: Informational. LinuxSecurity.com Team

Calendar 2 Apr 20, 2026 Informational Fedora
87

Debian DSA-6213-1 LXD Important Privilege Escalation Fix

Multiple security issues were discovered in LXD, a system container and virtual machine manager, which could result in restriction bypass or privilege escalation. For the oldstable distribution (bookworm), these problems have been fixed in version 5.0.2-5+deb12u5.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6213-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 15, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : lxd CVE ID : CVE-2026-34177 CVE-2026-34178 CVE-2026-34179 Multiple security issues were discovered in LXD, a system container and virtual machine manager, which could result in restriction bypass or privilege escalation. For the oldstable distribution (bookworm), these problems have been fixed in version 5.0.2-5+deb12u5. For the stable distribution (trixie), these problems have been fixed in version 5.0.2+git20231211.1364ae4-9+deb13u5. We recommend that you upgrade your lxd packages. For the detailed security status of lxd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/lxd Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Discover security issues fixed in LXD on Debian affecting system containers - upgrade for protection against threats.. Debian LXD Security Issues, Privilege Escalation Fix, Container Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 15, 2026 Important Debian
87

Debian DSA-6057-1 LXD Important Local Privilege Escalation CVE-2025-64507

It was discovered that LXD, a system container and virtual machine manager, is prone to a local privilege escalation vulnerability if unprivileged users are allowed to access LXD through lxd-user. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-6057-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso November 13, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : lxd CVE ID : CVE-2025-64507 It was discovered that LXD, a system container and virtual machine manager, is prone to a local privilege escalation vulnerability if unprivileged users are allowed to access LXD through lxd-user. For the oldstable distribution (bookworm), this problem has been fixed in version 5.0.2-5+deb12u2. We recommend that you upgrade your lxd packages. For the detailed security status of lxd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/lxd Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . LXD contains a security flaw allowing local privilege escalation for unprivileged users; upgrade recommended.. local privilege escalation, lxd upgrade, debian security, system container vulnerability, DSA-6057-1. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 13, 2025 Important Debian
87

Debian: Incus Important Privilege Escalation CVE-2025-64507 DSA-6051-1

It was discovered that Incus, a system container and virtual machine manager, is prone to a local privilege escalation vulnerability unprivileged users are allowed access to Incus through incus-user. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-6051-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso November 10, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : incus CVE ID : CVE-2025-64507 It was discovered that Incus, a system container and virtual machine manager, is prone to a local privilege escalation vulnerability unprivileged users are allowed access to Incus through incus-user. For the stable distribution (trixie), this problem has been fixed in version 6.0.4-2+deb13u2. We recommend that you upgrade your incus packages. For the detailed security status of incus please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/incus Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Incus local privilege escalation flaw discovered. Update is important for Debian users to prevent unauthorized access.. Incus Security, Debian Advisory, Local Privilege Escalation, System Container, CVE-2025-64507. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 10, 2025 Important Debian
89

Fedora 41: incus update 2025-5fce1e4f70 critical: DoS issues fixed

Rebase to Incus 6.12 to fix a variety of issues. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-5fce1e4f70 2025-05-07 03:58:50.599123+00:00 -------------------------------------------------------------------------------- Name : incus Product : Fedora 41 Version : 6.12 Release : 1.fc41 URL : https://linuxcontainers.org/incus Summary : Powerful system container and virtual machine manager Description : Container hypervisor based on LXC Incus offers a REST API to remotely manage containers over the network, using an image based work-flow and with support for live migration. This package contains the Incus daemon. -------------------------------------------------------------------------------- Update Information: Rebase to Incus 6.12 to fix a variety of issues -------------------------------------------------------------------------------- ChangeLog: * Mon May 5 2025 Reto Gantenbein - 6.12-1 - Update to incus-6.12 * Fri Jan 17 2025 Fedora Release Engineering - 6.8-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2292123 - incus changes the mode of /run/incus back to 0700 https://bugzilla.redhat.com/show_bug.cgi?id=2292123 [ 2 ] Bug #2340645 - incus: FTBFS in Fedora rawhide/f42 https://bugzilla.redhat.com/show_bug.cgi?id=2340645 [ 3 ] Bug #2341879 - incus-6.12.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2341879 [ 4 ] Bug #2347480 - CVE-2025-27144 incus: Go JOSE's Parsing Vulnerable to Denial of Service [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2347480 [ 5 ] Bug #2350832 - CVE-2025-22869 incus: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2350832 [ 6 ] Bug #2352303 - CVE-2025-22870incus: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2352303 [ 7 ] Bug #2354445 - CVE-2025-30204 incus: jwt-go allows excessive memory allocation during header parsing [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2354445 [ 8 ] Bug #2360678 - Incus version in Fedora 42 is incompatible with released QEMU version https://bugzilla.redhat.com/show_bug.cgi?id=2360678 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-5fce1e4f70' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Updating to Incus 6.12 tackles several challenges related to container oversight in Fedora 41, improving both security and operational efficiency.. System Containers, Fedora Updates, Incus Management. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 07, 2025 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here