Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-467e4d1489 2025-09-11 01:18:51.472351+00:00 -------------------------------------------------------------------------------- Name : rust-monitord Product : Fedora 41 Version : 0.10.1 Release : 2.fc41 URL : https://crates.io/crates/monitord Summary : Know how happy your systemd is Description : monitord is a library and daemon to gather statistics about systemd. -------------------------------------------------------------------------------- Update Information: Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160. -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 2 2025 Fabio Valentini - 0.10.1-2 - Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-467e4d1489' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 7.2.5 (CVE-2024-36469, CVE-2024-42325, CVE-2024-45700). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-700a59e277 2025-04-11 18:19:12.062480+00:00 -------------------------------------------------------------------------------- Name : zabbix Product : Fedora 42 Version : 7.2.5 Release : 1.fc42 URL : https://www.zabbix.com Summary : Open-source monitoring solution for your IT infrastructure Description : Zabbix is software that monitors numerous parameters of a network and the health and integrity of servers. Zabbix uses a flexible notification mechanism that allows users to configure e-mail based alerts for virtually any event. This allows a fast reaction to server problems. Zabbix offers excellent reporting and data visualization features based on the stored data. This makes Zabbix ideal for capacity planning. Zabbix supports both polling and trapping. All Zabbix reports and statistics, as well as configuration parameters are accessed through a web-based front end. A web-based front end ensures that the status of your network and the health of your servers can be assessed from any location. Properly configured, Zabbix can play an important role in monitoring IT infrastructure. This is equally true for small organizations with a few servers and for large companies with a multitude of servers. -------------------------------------------------------------------------------- Update Information: Update to 7.2.5 (CVE-2024-36469, CVE-2024-42325, CVE-2024-45700) -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 2 2025 Orion Poplawski - 1:7.2.5-1 - Update to 7.2.5 (CVE-2024-36469, CVE-2024-42325, CVE-2024-45700) * Tue Feb 11 2025 Zbigniew JÄdrzejewski-Szmek - 1:7.2.2-3 - Add sysusers.d config file to allow rpm to create users/groups automatically -------------------------------------------------------------------------------- This update canbe installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-700a59e277' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Important security patch for Zabbix version 7.2.5 on Fedora 42 resolves various vulnerabilities. Discover additional details here.. Fedora Update, Zabbix Security, Open Source Monitoring, IT Infrastructure, System Update. . Severity: Critical. LinuxSecurity.com Team
It was discovered that Atop, a monitor tool for system resources and process activity, always tried to connect to the port of atopgpud (an additional daemon gathering GPU statistics not shipped in Debian) while performing insufficient sanitising of the data read from this . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5892-1
address issues found in Static Application Security testing Fix a service startup issue Fix file open issue when kernel lockdown is in effect. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-d198253c42 2024-05-04 01:22:41.167429 -------------------------------------------------------------------------------- Name : stalld Product : Fedora 40 Version : 1.19.2 Release : 1.fc40 URL : Summary : Daemon that finds starving tasks and gives them a temporary boost Description : The stalld program monitors the set of system threads, looking for threads that are ready-to-run but have not been given processor time for some threshold period. When a starving thread is found, it is given a temporary boost using the SCHED_DEADLINE policy. The default is to allow 10 microseconds of runtime for 1 second of clock time. -------------------------------------------------------------------------------- Update Information: address issues found in Static Application Security testing Fix a service startup issue Fix file open issue when kernel lockdown is in effect -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 24 2024 Clark Williams - 1.19.2 - Make fill_process_comm() open comm file as READ_ONLY - throttlectl.sh: use legal value for exit on fail - stalld: free malloc'd buffer on function exit - throttling.c: null terminate input buffer - stalld.conf: Fix stalld service start fail - Conditionalize BPF and queue_track build per architecture - clean up Makefile install logic and add .bz2 to .gitignore - modify Makefiles so install works with relative paths - rename 'redhat' to 'systemd' and remove redhat packaging logic - update SPDX tags to non-deprecated values - stalld: Add -a/--affinity option - Adding SPDX license info to each file - man/stalld.8: change starving threshold to match code - utils: Fix freeing of invalidpointer - add bpftool as BuildRequires -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-d198253c42' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
A vulnerability has been found in Glances which may lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202402-30 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Glances: Arbitrary Code Execution Date: February 26, 2024 Bugs: #791565 ID: 202402-30 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been found in Glances which may lead to arbitrary code execution. Background ========== Glances is an open-source system cross-platform monitoring tool. It allows real-time monitoring of various aspects of your system such as CPU, memory, disk, network usage etc. Affected packages ================= Package Vulnerable Unaffected ------------------- ------------ ------------ sys-process/glances < 3.1.7 > = 3.1.7 Description =========== A vulnerability in XML parsing may lead to a variety of XML attacks. Impact ====== A vulnerability in XML parsing may lead to a variety of XML attacks. Workaround ========== There is no known workaround at this time. Resolution ========== All Glances users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-process/glances-3.1.7" References ========== Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202402-30 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
0.9.24 release. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-54e4356732 2020-07-25 01:07:00.449297 --------------------------------------------------------------------------------Name : bashtop Product : Fedora 31 Version : 0.9.24 Release : 1.fc31 URL : https://github.com/aristocratos/bashtop Summary : Linux resource monitor Description : Resource monitor written in Bash that shows usage and stats for processor, memory, disks, network and processes. --------------------------------------------------------------------------------Update Information: 0.9.24 release --------------------------------------------------------------------------------ChangeLog: * Thu Jul 16 2020 Germano Massullo - 0.9.24-1 - 0.9.24 release --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-54e4356732' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
It was discovered that there were a number of cross-site scripting vulnerabilities in cacti, a web interface for monitoring systems. For Debian 8 "Jessie", this issue has been fixed in cacti version . Package : cacti Version : 0.8.8b+dfsg-8+deb8u9 CVE ID : CVE-2020-7106 It was discovered that there were a number of cross-site scripting vulnerabilities in cacti, a web interface for monitoring systems. For Debian 8 "Jessie", this issue has been fixed in cacti version 0.8.8b+dfsg-8+deb8u9. We recommend that you upgrade your cacti packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Updated collectd packages are now available for Red Hat OpenStack Platform 10.0 Operational Tools for RHEL 7. Red Hat Product Security has rated this update as having a security impact of. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: collectd security update Advisory ID: RHSA-2018:1605-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2018:1605 Issue date: 2018-05-17 CVE Names: CVE-2017-16820 ==================================================================== 1. Summary: Updated collectd packages are now available for Red Hat OpenStack Platform 10.0 Operational Tools for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 10.0 Operational Tools for RHEL 7 - x86_64 3. Description: Red Hat OpenStack Platform Operational Tools provides the facilities for monitoring a private or public Red Hat OpenStack Platform cloud. collectd is a small C-language daemon, which reads various system metrics periodically and updates RRD files (creating them if necessary). Because the daemon does not start up each time it updates files, it has a low system footprint. Security fix: * collectd: double free in csnmp_read_table function in snmp.c (CVE-2017-16820) For more details about the security issue, including impact, a CVSS score, and other related information, refer to the CVE page listed in the References section. 4. Solution: Before applying this update, ensure all previously released errata relevant to your system have been applied. Red Hat OpenStack Platform 10 runs on Red Hat EnterpriseLinux 7.5. The Red Hat OpenStack Platform 10 Release Notes contain the following: * An explanation of the way in which the provided components interact to form a working cloud computing environment. * Technology Previews, Recommended Practices, and Known Issues. * The channels required for Red Hat OpenStack Platform 10, including which channels need to be enabled and disabled. The Release Notes are available at: This update is available through 'yum update' on systems registered through Red Hat Subscription Manager. For more information about Red Hat Subscription Manager, see: nt/1/html/RHSM/index.html 5. Bugs fixed (https://bugzilla.redhat.com/): 1516447 - CVE-2017-16820 collectd: double free in csnmp_read_table function in snmp.c 1550149 - [UPDATES]Failed to on dependencies if collectd sub-packages are installed 6. Package List: Red Hat OpenStack Platform 10.0 Operational Tools for RHEL7: Source: collectd-5.8.0-10.el7ost.src.rpm intel-cmt-cat-1.0.1-1.el7ost.src.rpm x86_64: collectd-5.8.0-10.el7ost.x86_64.rpm collectd-apache-5.8.0-10.el7ost.x86_64.rpm collectd-ascent-5.8.0-10.el7ost.x86_64.rpm collectd-bind-5.8.0-10.el7ost.x86_64.rpm collectd-ceph-5.8.0-10.el7ost.x86_64.rpm collectd-curl-5.8.0-10.el7ost.x86_64.rpm collectd-curl_json-5.8.0-10.el7ost.x86_64.rpm collectd-curl_xml-5.8.0-10.el7ost.x86_64.rpm collectd-dbi-5.8.0-10.el7ost.x86_64.rpm collectd-debuginfo-5.8.0-10.el7ost.x86_64.rpm collectd-disk-5.8.0-10.el7ost.x86_64.rpm collectd-dns-5.8.0-10.el7ost.x86_64.rpm collectd-drbd-5.8.0-10.el7ost.x86_64.rpm collectd-email-5.8.0-10.el7ost.x86_64.rpm collectd-generic-jmx-5.8.0-10.el7ost.x86_64.rpm collectd-ipmi-5.8.0-10.el7ost.x86_64.rpm collectd-iptables-5.8.0-10.el7ost.x86_64.rpm collectd-ipvs-5.8.0-10.el7ost.x86_64.rpm collectd-java-5.8.0-10.el7ost.x86_64.rpm collectd-log_logstash-5.8.0-10.el7ost.x86_64.rpm collectd-mcelog-5.8.0-10.el7ost.x86_64.rpm collectd-memcachec-5.8.0-10.el7ost.x86_64.rpm collectd-mysql-5.8.0-10.el7ost.x86_64.rpm collectd-netlink-5.8.0-10.el7ost.x86_64.rpm collectd-nginx-5.8.0-10.el7ost.x86_64.rpm collectd-notify_email-5.8.0-10.el7ost.x86_64.rpm collectd-openldap-5.8.0-10.el7ost.x86_64.rpm collectd-ovs-events-5.8.0-10.el7ost.x86_64.rpm collectd-ovs-stats-5.8.0-10.el7ost.x86_64.rpm collectd-ping-5.8.0-10.el7ost.x86_64.rpm collectd-postgresql-5.8.0-10.el7ost.x86_64.rpm collectd-python-5.8.0-10.el7ost.x86_64.rpm collectd-rdt-5.8.0-10.el7ost.x86_64.rpm collectd-rrdcached-5.8.0-10.el7ost.x86_64.rpm collectd-rrdtool-5.8.0-10.el7ost.x86_64.rpm collectd-sensors-5.8.0-10.el7ost.x86_64.rpm collectd-smart-5.8.0-10.el7ost.x86_64.rpm collectd-snmp-5.8.0-10.el7ost.x86_64.rpm collectd-snmp-agent-5.8.0-10.el7ost.x86_64.rpm collectd-turbostat-5.8.0-10.el7ost.x86_64.rpm collectd-utils-5.8.0-10.el7ost.x86_64.rpm collectd-virt-5.8.0-10.el7ost.x86_64.rpm collectd-write_http-5.8.0-10.el7ost.x86_64.rpm collectd-write_sensu-5.8.0-10.el7ost.x86_64.rpm collectd-write_tsdb-5.8.0-10.el7ost.x86_64.rpm collectd-zookeeper-5.8.0-10.el7ost.x86_64.rpm intel-cmt-cat-1.0.1-1.el7ost.x86_64.rpm libcollectdclient-5.8.0-10.el7ost.x86_64.rpm perl-Collectd-5.8.0-10.el7ost.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2017-16820 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBWv2fStzjgjWX9erEAQi2uA/+OEDMby47/e/vOXPZ/VVeiUzist1i2ATp NifJGxcQr4BU7NeO7A/AVi7uJEnOfZ5eDIfDUV30XutnWV1NUcaY4l4n0ezJTHtZ 05DYEIqfg/ZaSRvbEdMdJzgz7GhcpwMGKuTsKzu2lcRFBUheAwAr8nRGSRGGeFfc qRiVry+oZr/smAXmAt5IgG1VPpOD1RGrtzCH4KyOJNtEJqlmRsCouRRqLIEX8bLn lt907OueLYiYw3KC488MY20hnCsGZJTdUwCAPG/3VeqirbTS//S1yeSsKug4Gls1 YTSHW2LS3GHHrwrRUGRr2oZnQlbSDwz+kmH4HNxrzhpaIfKCFKoNA+UtyBkhov6S Pt1WBZcGMHQXDbEyl9lDfYj8QUcnqSd/Ezsfvazzy8+oqGtmq/cM1q5zIi2L2HJJ bv+BVja57Ydk2g3NqERxxpflS5FxoR88bXmFDLgrnGHisf5iehKZ6BHE9x0JGci4 Uc85AU6guYiaT5EcOCY/05z2zA5h4tRNrnFocFU6N6gYPjH18yTWa1IiU2PFidL9 7Jq0E9AL1gP7eLGoBac2n0eCzIe3bS+oo1wr4QE0FkqKBDDLpZaFY+3/iK6pY6Or HsidxC9BhIYbGRmyE/HBAey5VEH2zXWYzPool3P+9qUeZDtzzGd8QkA2c1YdUFL/ 5BD6zoMmAlc=qPF8 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.