Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 17 articles for you...
202

Fedora Rawhide: 2025:15234-2 severe: jq vulnerabilities detected

An update that solves 3 vulnerabilities can now be installed.. # jq-1.8.1-1.1 on GA media Announcement ID: openSUSE-SU-2025:15233-1 Rating: moderate Cross-References: * CVE-2024-23337 * CVE-2025-48060 * CVE-2025-49014 CVSS scores: * CVE-2024-23337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-23337 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-48060 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-48060 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-49014 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-49014 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 3 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the jq-1.8.1-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * jq 1.8.1-1.1 * libjq-devel 1.8.1-1.1 * libjq1 1.8.1-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-23337.html * https://www.suse.com/security/cve/CVE-2025-48060.html * https://www.suse.com/security/cve/CVE-2025-49014.html . Oversee the patch deployment process in openSUSE Tumbleweed to tackle moderate vulnerabilities related to jq and improve overall system security.. jq security, openSUSE Tumbleweed, moderate vulnerabilities, system updates. . LinuxSecurity.com Team

Calendar%202 Jul 05, 2025 OpenSUSE
100

SUSE: 2025:0243-1 important: kernel live patch issues resolved

* bsc#1226324 * bsc#1227471 * bsc#1227651 * bsc#1228573 * bsc#1229553 . # Security update for the Linux Kernel (Live Patch 46 for SLE 15 SP3) Announcement ID: SUSE-SU-2025:0243-1 Release Date: 2025-01-27T11:33:48Z Rating: important References: * bsc#1226324 * bsc#1227471 * bsc#1227651 * bsc#1228573 * bsc#1229553 * bsc#1232637 * bsc#1233712 Cross-References: * CVE-2021-47291 * CVE-2021-47598 * CVE-2022-48956 * CVE-2024-36971 * CVE-2024-41059 * CVE-2024-43861 * CVE-2024-50264 CVSS scores: * CVE-2021-47291 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2021-47291 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2021-47598 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2021-47598 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-48956 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-48956 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-36971 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-36971 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-41059 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-41059 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-41059 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-43861 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-43861 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-50264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise Live Patching 15-SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.3.18-150300_59_167 fixes several issues. The following security issues were fixed: * CVE-2024-36971: Fixed __dst_negative_advice() race (bsc#1226324). * CVE-2024-50264: vsock/virtio: Initialization of the dangling pointer occurring in vsk-> trans (bsc#1233712). * CVE-2022-48956: ipv6: avoid use-after-free in ip6_fragment() (bsc#1232637). * CVE-2024-43861: Fix memory leak for not ip packets (bsc#1229553). * CVE-2021-47598: sch_cake: do not call cake_destroy() from cake_init() (bsc#1227471). * CVE-2021-47291: ipv6: fix another slab-out-of-bounds in fib6_nh_flush_exceptions (bsc#1227651). * CVE-2024-41059: hfsplus: fix uninit-value in copy_name (bsc#1228573). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-243=1 * SUSE Linux Enterprise Live Patching 15-SP3 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2025-243=1 ## Package List: * openSUSE Leap 15.3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_167-default-debuginfo-6-150300.7.6.1 * kernel-livepatch-5_3_18-150300_59_167-default-6-150300.7.6.1 * kernel-livepatch-SLE15-SP3_Update_46-debugsource-6-150300.7.6.1 * openSUSE Leap 15.3 (x86_64) * kernel-livepatch-5_3_18-150300_59_167-preempt-6-150300.7.6.1 * kernel-livepatch-5_3_18-150300_59_167-preempt-debuginfo-6-150300.7.6.1 * SUSE Linux Enterprise Live Patching 15-SP3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_167-default-6-150300.7.6.1 ## References: * https://www.suse.com/security/cve/CVE-2021-47291.html * https://www.suse.com/security/cve/CVE-2021-47598.html *https://www.suse.com/security/cve/CVE-2022-48956.html * https://www.suse.com/security/cve/CVE-2024-36971.html * https://www.suse.com/security/cve/CVE-2024-41059.html * https://www.suse.com/security/cve/CVE-2024-43861.html * https://www.suse.com/security/cve/CVE-2024-50264.html * https://bugzilla.suse.com/show_bug.cgi?id=1226324 * https://bugzilla.suse.com/show_bug.cgi?id=1227471 * https://bugzilla.suse.com/show_bug.cgi?id=1227651 * https://bugzilla.suse.com/show_bug.cgi?id=1228573 * https://bugzilla.suse.com/show_bug.cgi?id=1229553 * https://bugzilla.suse.com/show_bug.cgi?id=1232637 * https://bugzilla.suse.com/show_bug.cgi?id=1233712 . Safety enhancement for Linux Kernel Live Patch 46 in SLE 15 SP3 resolves various vulnerabilities, bolstering operational security.. Linux Kernel Updates,SUSE Linux Security,Live Patch 15 SP3,Kernel Fixes 2025. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 27, 2025 Important SuSE
100

SUSE 15 SP3: 2024:2773-1 Important Live Patch Security Update

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1221302 * bsc#1223059 . # Security update for the Linux Kernel (Live Patch 43 for SLE 15 SP3) Announcement ID: SUSE-SU-2024:2773-1 Rating: important References: * bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1221302 * bsc#1223059 * bsc#1223363 * bsc#1223514 * bsc#1223683 * bsc#1225013 * bsc#1225211 * bsc#1225310 Cross-References: * CVE-2021-46955 * CVE-2021-47383 * CVE-2022-48651 * CVE-2023-1829 * CVE-2024-23307 * CVE-2024-26610 * CVE-2024-26828 * CVE-2024-26852 * CVE-2024-26923 * CVE-2024-27398 * CVE-2024-35950 CVSS scores: * CVE-2021-46955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2021-47383 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-48651 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-1829 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-1829 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-23307 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-23307 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-26610 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2024-26828 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H * CVE-2024-26852 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-26923 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-27398 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-35950 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise Live Patching 15-SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves 11 vulnerabilities cannow be installed. ## Description: This update for the Linux Kernel 5.3.18-150300_59_158 fixes several issues. The following security issues were fixed: * CVE-2024-27398: Fixed use-after-free bug caused by sco_sock_timeout() (bsc#1225013). * CVE-2024-35950: drm/client: Fully protect modes with dev-> mode_config.mutex (bsc#1225310). * CVE-2021-47383: Fixed out-of-bound vmalloc access in imageblit (bsc#1225211). * CVE-2024-26923: Fixed false-positive lockdep splat for spin_lock() in __unix_gc() (bsc#1223683). * CVE-2024-26828: Fixed underflow in parse_server_interfaces() (bsc#1223363). * CVE-2021-46955: Fixed an out-of-bounds read with openvswitch, when fragmenting IPv4 packets (bsc#1220537). * CVE-2024-23307: Fixed Integer Overflow or Wraparound vulnerability in x86 and ARM md, raid, raid5 modules (bsc#1220145). * CVE-2024-26852: Fixed use-after-free in ip6_route_mpath_notify() (bsc#1223059). * CVE-2024-26610: Fixed memory corruption in wifi/iwlwifi (bsc#1221302). * CVE-2022-48651: Fixed an out-of-bound bug in ipvlan caused by unset skb-> mac_header (bsc#1223514). * CVE-2023-1829: Fixed a use-after-free vulnerability in the control index filter (tcindex) (bsc#1210619). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-2773=1 * SUSE Linux Enterprise Live Patching 15-SP3 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2024-2773=1 ## Package List: * openSUSE Leap 15.3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_158-default-5-150300.7.6.1 * kernel-livepatch-5_3_18-150300_59_158-default-debuginfo-5-150300.7.6.1 * kernel-livepatch-SLE15-SP3_Update_43-debugsource-5-150300.7.6.1 * openSUSE Leap 15.3 (x86_64) * kernel-livepatch-5_3_18-150300_59_158-preempt-debuginfo-5-150300.7.6.1 *kernel-livepatch-5_3_18-150300_59_158-preempt-5-150300.7.6.1 * SUSE Linux Enterprise Live Patching 15-SP3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_158-default-5-150300.7.6.1 ## References: * https://www.suse.com/security/cve/CVE-2021-46955.html * https://www.suse.com/security/cve/CVE-2021-47383.html * https://www.suse.com/security/cve/CVE-2022-48651.html * https://www.suse.com/security/cve/CVE-2023-1829.html * https://www.suse.com/security/cve/CVE-2024-23307.html * https://www.suse.com/security/cve/CVE-2024-26610.html * https://www.suse.com/security/cve/CVE-2024-26828.html * https://www.suse.com/security/cve/CVE-2024-26852.html * https://www.suse.com/security/cve/CVE-2024-26923.html * https://www.suse.com/security/cve/CVE-2024-27398.html * https://www.suse.com/security/cve/CVE-2024-35950.html * https://bugzilla.suse.com/show_bug.cgi?id=1210619 * https://bugzilla.suse.com/show_bug.cgi?id=1220145 * https://bugzilla.suse.com/show_bug.cgi?id=1220537 * https://bugzilla.suse.com/show_bug.cgi?id=1221302 * https://bugzilla.suse.com/show_bug.cgi?id=1223059 * https://bugzilla.suse.com/show_bug.cgi?id=1223363 * https://bugzilla.suse.com/show_bug.cgi?id=1223514 * https://bugzilla.suse.com/show_bug.cgi?id=1223683 * https://bugzilla.suse.com/show_bug.cgi?id=1225013 * https://bugzilla.suse.com/show_bug.cgi?id=1225211 * https://bugzilla.suse.com/show_bug.cgi?id=1225310 . Crucial Kernel Live Patch release for SUSE 15 SP3 tackles severe vulnerabilities, enhancing overall security of the platform.. SUSE Linux Update, Kernel Security Patch, SUSE Live Patching. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 06, 2024 Important SuSE
89

Fedora 39: FEDORA-2024-a53b24023d Critical: Prometheus Exporter SSH Attack

Security fix for CVE-2023-48795. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-a53b24023d 2024-01-29 06:23:44.937502 -------------------------------------------------------------------------------- Name : prometheus-podman-exporter Product : Fedora 39 Version : 1.7.0 Release : 1.fc39 URL : https://github.com/containers/prometheus-podman-exporter Summary : Prometheus exporter for podman environment Description : Prometheus exporter for podman environments exposing containers, pods, images, volumes and networks information. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-48795 -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 21 2024 Navid Yaghoobi - 1.7.0-1 - release v1.7.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2255105 - CVE-2023-48795 prometheus-podman-exporter: ssh: Prefix truncation attack on Binary Packet Protocol (BPP) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2255105 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a53b24023d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . A patch for the prometheus-podman-exporter in Fedora 39 resolves CVE-2023-48795 to improve system security.. Fedora 39 Prometheus Exporter, CVE-2023-48795 Fix, Podman Security Update, SSH Attack Mitigation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 29, 2024 Critical Fedora
202

openSUSE: 2024:0229-1 Important: MozillaFirefox Security Issues

This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 115.7.0 ESR (MFSA2024-02) (bsc#1218955):. # Security update for MozillaFirefox Announcement ID: SUSE-SU-2024:0229-1 Rating: important References: * bsc#1218955 Cross-References: * CVE-2024-0741 * CVE-2024-0742 * CVE-2024-0746 * CVE-2024-0747 * CVE-2024-0749 * CVE-2024-0750 * CVE-2024-0751 * CVE-2024-0753 * CVE-2024-0755 CVSS scores: Affected Products: * Desktop Applications Module 15-SP5 * openSUSE Leap 15.5 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves nine vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 115.7.0 ESR (MFSA2024-02) (bsc#1218955): *CVE-2024-0741: Out of bounds write in ANGLE * CVE-2024-0742: Failure to update user input timestamp * CVE-2024-0746: Crash when listing printers on Linux * CVE-2024-0747: Bypass of Content Security Policy when directive unsafe- inline was set * CVE-2024-0749: Phishing site popup could show local origin in address bar * CVE-2024-0750: Potential permissions request bypass via clickjacking * CVE-2024-0751: Privilege escalation through devtools * CVE-2024-0753: HSTS policy on subdomain could bypass policy of upper domain * CVE-2024-0755: Memory safety bugs fixed in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-229=1 * Desktop Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP5-2024-229=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-229=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-229=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-229=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-229=1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-229=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-229=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-229=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patchSUSE-SLE-Product-SLES-15-SP4-LTSS-2024-229=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-229=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-229=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-229=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-229=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * MozillaFirefox-branding-upstream-115.7.0-150200.152.123.1 * openSUSE Leap 15.5 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * Desktop Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * Desktop Applications Module 15-SP5 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise HighPerformance Computing LTSS 15 SP3 (aarch64 x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) *MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 *MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Enterprise Storage 7.1 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 ## References: * https://www.suse.com/security/cve/CVE-2024-0741.html * https://www.suse.com/security/cve/CVE-2024-0742.html * https://www.suse.com/security/cve/CVE-2024-0746.html * https://www.suse.com/security/cve/CVE-2024-0747.html * https://www.suse.com/security/cve/CVE-2024-0749.html * https://www.suse.com/security/cve/CVE-2024-0750.html * https://www.suse.com/security/cve/CVE-2024-0751.html * https://www.suse.com/security/cve/CVE-2024-0753.html * https://www.suse.com/security/cve/CVE-2024-0755.html * https://bugzilla.suse.com/show_bug.cgi?id=1218955 . Apply the critical security patch for MozillaFirefox to resolve various vulnerabilities and improve overall system protection.. MozillaFirefox Update, openSUSE Security,Important Software Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 25, 2024 Important OpenSUSE
217

Oracle Linux 8 ELSA-2023-4570 Moderate: iperf3 Security Update

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-4570 https://linux.oracle.com/errata/ELSA-2023-4570.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: iperf3-3.5-7.el8_8.i686.rpm iperf3-3.5-7.el8_8.x86_64.rpm aarch64: iperf3-3.5-7.el8_8.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//iperf3-3.5-7.el8_8.src.rpm Related CVEs: CVE-2023-38403 Description of changes: [3.5-7] - Fixes CVE-2023-38403 Resolves: rhbz#2223729 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 8 iperf3 security patch ELSA-2023-4571 addresses CVE-2023-38404 to bolster system protection.. iperf3 Security, Oracle Updates, Network Security Fix, Linux Advisory. . LinuxSecurity.com Team

Calendar%202 Aug 17, 2023 Oracle
217

Oracle Linux 7 ELSA-2023-3151 Critical Thunderbird Update for Aarch64

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-3151 https://linux.oracle.com/errata/ELSA-2023-3151.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: thunderbird-102.11.0-1.0.1.el7_9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates//thunderbird-102.11.0-1.0.1.el7_9.src.rpm Related CVEs: CVE-2023-32205 CVE-2023-32206 CVE-2023-32207 CVE-2023-32211 CVE-2023-32212 CVE-2023-32213 CVE-2023-32215 Description of changes: [102.11.0-1.0.1] - Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js - Enabled aarch64 build [102.11.0-1] - Update to 102.11.0 build1 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Crucial security patch released for Oracle Linux 7 addressing vulnerabilities in Firefox to improve overall system integrity and resilience.. Oracle Linux, Thunderbird Security, Aarch64 Update, System Stability, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 18, 2023 Critical Oracle
100

SUSE Security Advisory 2022:3919-1: Critical Kubevirt Patch Released

An update that contains security fixes can now be installed. . SUSE Security Update: Security update for kubevirt ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3919-1 Rating: important References: Affected Products: SUSE Enterprise Storage 7.1 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise Module for Containers 15-SP3 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Manager Proxy 4.2 SUSE Manager Retail Branch Server 4.2 SUSE Manager Server 4.2 openSUSE Leap 15.3 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update rebuilds the kubevirt stack to include recent security updates in its basecontainers. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-3919=1 - SUSE Linux Enterprise Module for Containers 15-SP3: zypper in -t patch SUSE-SLE-Module-Containers-15-SP3-2022-3919=1 Package List: - openSUSE Leap 15.3 (x86_64): kubevirt-container-disk-0.49.0-150300.8.15.1 kubevirt-container-disk-debuginfo-0.49.0-150300.8.15.1 kubevirt-manifests-0.49.0-150300.8.15.1 kubevirt-tests-0.49.0-150300.8.15.1 kubevirt-tests-debuginfo-0.49.0-150300.8.15.1 kubevirt-virt-api-0.49.0-150300.8.15.1 kubevirt-virt-api-debuginfo-0.49.0-150300.8.15.1 kubevirt-virt-controller-0.49.0-150300.8.15.1 kubevirt-virt-controller-debuginfo-0.49.0-150300.8.15.1 kubevirt-virt-handler-0.49.0-150300.8.15.1 kubevirt-virt-handler-debuginfo-0.49.0-150300.8.15.1 kubevirt-virt-launcher-0.49.0-150300.8.15.1 kubevirt-virt-launcher-debuginfo-0.49.0-150300.8.15.1 kubevirt-virt-operator-0.49.0-150300.8.15.1 kubevirt-virt-operator-debuginfo-0.49.0-150300.8.15.1 kubevirt-virtctl-0.49.0-150300.8.15.1 kubevirt-virtctl-debuginfo-0.49.0-150300.8.15.1 obs-service-kubevirt_containers_meta-0.49.0-150300.8.15.1 - SUSE Linux Enterprise Module for Containers 15-SP3 (x86_64): kubevirt-manifests-0.49.0-150300.8.15.1 kubevirt-virtctl-0.49.0-150300.8.15.1 kubevirt-virtctl-debuginfo-0.49.0-150300.8.15.1 References: . SUSE issues critical security patch for kubevirt impacting multiple SUSE solutions. Upgrade immediately to maintain system integrity.. Kubevirt Security Update,SUSE Container Fixes,SUSE Update Instructions,SUSE Linux Enterprise. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 08, 2022 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200