Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
172

Critical Tang Key Access Vulnerability in Ubuntu 23.04 USN-6489-1

Tang could allow unintended access to secret keys.. ========================================================================== Ubuntu Security Notice USN-6489-1 November 20, 2023 tang vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) Summary: Tang could allow unintended access to secret keys. Software Description: - tang: network-based cryptographic binding server Details: Brian McDermott discovered that Tang incorrectly handled permissions when creating/rotating keys. A local attacker could possibly use this issue to read the keys. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: tang-common 11-2ubuntu0.1 Ubuntu 22.04 LTS: tang-common 11-1ubuntu0.1 Ubuntu 20.04 LTS: tang 7-1ubuntu0.2 Ubuntu 18.04 LTS (Available with Ubuntu Pro): tang 6-1ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6489-1 CVE-2023-1672 Package Information: https://launchpad.net/ubuntu/+source/tang/11-2ubuntu0.1 https://launchpad.net/ubuntu/+source/tang/11-1ubuntu0.1 https://launchpad.net/ubuntu/+source/tang/7-1ubuntu0.2 . The Ubuntu Security Notice USN-6490-1 highlights a critical flaw in the curl library, which may permit unauthorized exposure of sensitive data.. Ubuntu Security,Tang Vulnerability,Access Control,Key Management. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 20, 2023 Critical Ubuntu
197

Debian 10 Buster: DLA-3648-1 Moderate: Tang Binding Issue Fix

It was discovered that there was a race condition in Tang, a network-based cryptographic binding server. This flaw resulted in a small time window whereby newly-generated private keys were readable by other processes on the same machine. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3648-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Chris Lamb November 07, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : tang Version : 7-1+deb10u2 CVE ID : CVE-2023-1672 Debian Bug : 1038119 It was discovered that there was a race condition in Tang, a network-based cryptographic binding server. This flaw resulted in a small time window whereby newly-generated private keys were readable by other processes on the same machine. For Debian 10 buster, this problem has been fixed in version 7-1+deb10u2. We recommend that you upgrade your tang packages. For the detailed security status of tang please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/tang Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance Tang security on Debian 10 Buster to fix vulnerabilities from race conditions. Follow these steps to update, upgrade, and monitor your setup. Tang Security Advisory, Debian LTS Update, Cryptographic Binding Server. . LinuxSecurity.com Team

Calendar 2 Nov 07, 2023 Debian LTS
89

Fedora 38: 2023-3e84bba241 Moderate: Tang Race Condition Fix

Fixes CVE-2023-1672. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-3e84bba241 2023-06-23 01:00:55.101941 --------------------------------------------------------------------------------Name : tang Product : Fedora 38 Version : 14 Release : 1.fc38 URL : https://github.com/latchset/tang Summary : Network Presence Binding Daemon Description : Tang is a small daemon for binding data to the presence of a third party. --------------------------------------------------------------------------------Update Information: Fixes CVE-2023-1672 --------------------------------------------------------------------------------ChangeLog: * Wed Jun 14 2023 Sergio Arroutbi - 14-1 - New upstream release - v14 Resolves: rhbz#2180990 --------------------------------------------------------------------------------References: [ 1 ] Bug #2180999 - CVE-2023-1672 tang: Race condition exists in the key generation and rotation functionality https://bugzilla.redhat.com/show_bug.cgi?id=2180999 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-3e84bba241' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines:https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 38 tango release rectifies CVE-2023-1680 by resolving an encryption algorithm vulnerability successfully.. tang update,Fedora 38,key generation flaw,security patch. . LinuxSecurity.com Team

Calendar 2 Jun 23, 2023 Fedora
89

Fedora 37 Update: FEDORA-2023-eb9bec6e8c Critical Tang Race Condition Fix

Fixes CVE-2023-1672. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-eb9bec6e8c 2023-06-23 01:00:50.019322 --------------------------------------------------------------------------------Name : tang Product : Fedora 37 Version : 14 Release : 1.fc37 URL : https://github.com/latchset/tang Summary : Network Presence Binding Daemon Description : Tang is a small daemon for binding data to the presence of a third party. --------------------------------------------------------------------------------Update Information: Fixes CVE-2023-1672 --------------------------------------------------------------------------------ChangeLog: * Wed Jun 14 2023 Sergio Arroutbi - 14-1 - New upstream release - v14 Resolves: rhbz#2180990 --------------------------------------------------------------------------------References: [ 1 ] Bug #2180999 - CVE-2023-1672 tang: Race condition exists in the key generation and rotation functionality https://bugzilla.redhat.com/show_bug.cgi?id=2180999 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-eb9bec6e8c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines ListArchives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 37 tang has received an update that addresses a concurrency flaw, boosting both security and system resilience.. Fedora Tang Update, Network Presence Daemon, Race Condition Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 23, 2023 Critical Fedora
89

Fedora 34: Important Tang Update Addresses Significant Key Leak Issue

Security fix for CVE-2021-4076. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-aa1d373ed0 2021-12-23 01:25:07.749353 --------------------------------------------------------------------------------Name : tang Product : Fedora 34 Version : 11 Release : 1.fc34 URL : https://github.com/latchset/tang Summary : Network Presence Binding Daemon Description : Tang is a small daemon for binding data to the presence of a third party. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-4076 --------------------------------------------------------------------------------ChangeLog: * Tue Dec 14 2021 Sergio Correia - 11-1 - New upstream release - v11. Resolves: CVE-2021-4076 --------------------------------------------------------------------------------References: [ 1 ] Bug #2029814 - CVE-2021-4076 tang: private key leak https://bugzilla.redhat.com/show_bug.cgi?id=2029814 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-aa1d373ed0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines:https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Urgent notification for Tang in Fedora 34 resolving confidential key exposure problem. Apply now for improved protection.. Tang Daemon Update,Fedora Security Fix,CVE-2021-4076 Resolution. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 22, 2021 Important Fedora
89

Fedora 35: 2021-1fe489496f Urgent: Vulnerability in Tang Key Exposure

Security fix for CVE-2021-4076. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-1fe489496f 2021-12-23 00:39:33.251213 --------------------------------------------------------------------------------Name : tang Product : Fedora 35 Version : 11 Release : 1.fc35 URL : https://github.com/latchset/tang Summary : Network Presence Binding Daemon Description : Tang is a small daemon for binding data to the presence of a third party. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-4076 --------------------------------------------------------------------------------ChangeLog: * Tue Dec 14 2021 Sergio Correia - 11-1 - New upstream release - v11. Resolves: CVE-2021-4076 --------------------------------------------------------------------------------References: [ 1 ] Bug #2029814 - CVE-2021-4076 tang: private key leak https://bugzilla.redhat.com/show_bug.cgi?id=2029814 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-1fe489496f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines:https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Ubuntu 22.04 security patch addresses CVE-2021-4505 mitigating critical vulnerability in encryption methods. Update through APT for fortified protection.. Fedora Update,Tang Daemon,Private Key Protection,Security Fix,CVE-2021-4076. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 22, 2021 Critical Fedora
87

Debian Bullseye: DSA-5025-1 Critical: Tang Key Exposure

A flaw was discovered in tang, a network-based cryptographic binding server, which could result in leak of private keys. For the stable distribution (bullseye), this problem has been fixed in . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5025-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso December 19, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : tang CVE ID : CVE-2021-4076 A flaw was discovered in tang, a network-based cryptographic binding server, which could result in leak of private keys. For the stable distribution (bullseye), this problem has been fixed in version 8-3+deb11u1. We recommend that you upgrade your tang packages. For the detailed security status of tang please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/tang Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Debian Security Notice DSA-5026-1 highlights an urgent vulnerability in the software package 'xyz', jeopardizing user data integrity and accessing sensitive information.. Debian Security Advisory,Tang Security Update,Private Key Exposure,Network-Based Services. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 19, 2021 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here