Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 6 articles for you...
87

Debian 12: DSA-5945-1 important: konsole telnet code execution

Dennis Dast discovered that the Konsole terminal emulator insecurely handled the telnet URI scheme, which could result in the execution of arbitrary code in some configurations. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5945-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff June 20, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : konsole CVE ID : CVE-2025-49091 Dennis Dast discovered that the Konsole terminal emulator insecurely handled the telnet URI scheme, which could result in the execution of arbitrary code in some configurations. For the stable distribution (bookworm), this problem has been fixed in version 4:22.12.3-1+deb12u1. We recommend that you upgrade your konsole packages. For the detailed security status of konsole please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/konsole Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Immediate alert concerning Konsole's security flaws impacting Debian installations. Update promptly to mitigate potential execution of unauthorized code.. Konsole security update, Debian security advisory, terminal emulator vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 20, 2025 Important Debian
89

Fedora 41: kitty 2025-756c627691 Security Advisory Updates

Update to 0.40.0 https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-756c627691 2025-03-17 01:37:24.408041+00:00 -------------------------------------------------------------------------------- Name : kitty Product : Fedora 41 Version : 0.40.0 Release : 2.fc41 URL : https://sw.kovidgoyal.net/kitty Summary : Cross-platform, fast, feature full, GPU based terminal emulator Description : - Offloads rendering to the GPU for lower system load and buttery smooth scrolling. Uses threaded rendering to minimize input latency. - Supports all modern terminal features: graphics (images), unicode, true-color, OpenType ligatures, mouse protocol, focus tracking, bracketed paste and several new terminal protocol extensions. - Supports tiling multiple terminal windows side by side in different layouts without needing to use an extra program like tmux. - Can be controlled from scripts or the shell prompt, even over SSH. - Has a framework for Kittens, small terminal programs that can be used to extend kitty's functionality. For example, they are used for Unicode input, Hints and Side-by-side diff. - Supports startup sessions which allow you to specify the window/tab layout, working directories and programs to run on startup. - Cross-platform: kitty works on Linux and macOS, but because it uses only OpenGL for rendering, it should be trivial to port to other Unix-like platforms. - Allows you to open the scrollback buffer in a separate window using arbitrary programs of your choice. This is useful for browsing the history comfortably in a pager or editor. - Has multiple copy/paste buffers, like vim. -------------------------------------------------------------------------------- Update Information: Update to0.40.0 https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 8 2025 Pavel Solovev - 0.40.0-1 - Update to 0.40.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2350858 - kitty-0.40.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2350858 [ 2 ] Bug #2352305 - CVE-2025-22870 kitty: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2352305 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-756c627691' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Explore Fedora 41 advisory for kitty, addressing critical HTTP proxy bypass issue with recommended updates.. update, https, kovidgoyal, net/kitty/changelog/#detailed-list-of-changes, ---------------. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 17, 2025 Important Fedora
89

Fedora 39: FEDORA-2024-c7b79bc227 Moderate: Kitty Rendering Improvements

rebuild for rhbz#2292712. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-c7b79bc227 2024-06-29 01:41:49.506039 -------------------------------------------------------------------------------- Name : kitty Product : Fedora 39 Version : 0.31.0 Release : 3.fc39 URL : https://sw.kovidgoyal.net/kitty Summary : Cross-platform, fast, feature full, GPU based terminal emulator Description : - Offloads rendering to the GPU for lower system load and buttery smooth scrolling. Uses threaded rendering to minimize input latency. - Supports all modern terminal features: graphics (images), unicode, true-color, OpenType ligatures, mouse protocol, focus tracking, bracketed paste and several new terminal protocol extensions. - Supports tiling multiple terminal windows side by side in different layouts without needing to use an extra program like tmux. - Can be controlled from scripts or the shell prompt, even over SSH. - Has a framework for Kittens, small terminal programs that can be used to extend kitty's functionality. For example, they are used for Unicode input, Hints and Side-by-side diff. - Supports startup sessions which allow you to specify the window/tab layout, working directories and programs to run on startup. - Cross-platform: kitty works on Linux and macOS, but because it uses only OpenGL for rendering, it should be trivial to port to other Unix-like platforms. - Allows you to open the scrollback buffer in a separate window using arbitrary programs of your choice. This is useful for browsing the history comfortably in a pager or editor. - Has multiple copy/paste buffers, like vim. -------------------------------------------------------------------------------- Update Information: rebuild for rhbz#2292712 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 20 2024 Pavel Solovev -0.31.0-3 - rebuild for rhbz#2292712 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-c7b79bc227' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Debian releases patches for fido, improving display performance and enriching command line interactions. Keep your system safe!. Fedora Updates, Terminal Emulator, Kitty Security, Software Security, Cross-Platform Applications. . LinuxSecurity.com Team

Calendar 2 Jun 29, 2024 Fedora
89

Fedora 38: 2023-0418511dfe Moderate: Kitty Security Update

version 0.28.1, backport security fix.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-0418511dfe 2023-05-19 01:14:41.265566 --------------------------------------------------------------------------------Name : kitty Product : Fedora 38 Version : 0.28.1 Release : 4.fc38 URL : https://sw.kovidgoyal.net/kitty/ Summary : Cross-platform, fast, feature full, GPU based terminal emulator Description : - Offloads rendering to the GPU for lower system load and buttery smooth scrolling. Uses threaded rendering to minimize input latency. - Supports all modern terminal features: graphics (images), unicode, true-color, OpenType ligatures, mouse protocol, focus tracking, bracketed paste and several new terminal protocol extensions. - Supports tiling multiple terminal windows side by side in different layouts without needing to use an extra program like tmux. - Can be controlled from scripts or the shell prompt, even over SSH. - Has a framework for Kittens, small terminal programs that can be used to extend kitty's functionality. For example, they are used for Unicode input, Hints and Side-by-side diff. - Supports startup sessions which allow you to specify the window/tab layout, working directories and programs to run on startup. - Cross-platform: kitty works on Linux and macOS, but because it uses only OpenGL for rendering, it should be trivial to port to other Unix-like platforms. - Allows you to open the scrollback buffer in a separate window using arbitrary programs of your choice. This is useful for browsing the history comfortably in a pager or editor. - Has multiple copy/paste buffers, like vim. --------------------------------------------------------------------------------Update Information: version 0.28.1, backport security fix. --------------------------------------------------------------------------------ChangeLog: * Wed May 10 2023Pavel Solovev - 0.28.1-4 - Ask for permission before executing script files * Mon May 8 2023 Pavel Solovev - 0.28.1-3 - enable shell integration by default - remove unneeded weak dep, add ripgrep as a weak dep * Sat Apr 29 2023 Pavel Solovev - 0.28.1-2 - reenable s390x * Tue Apr 25 2023 Pavel Solovev - 0.28.1-1 - version 0.28.1 (rhbz#2188669) --------------------------------------------------------------------------------References: [ 1 ] Bug #2196802 - kitty: should not handle application/x-sh mime type by executing the script https://bugzilla.redhat.com/show_bug.cgi?id=2196802 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-0418511dfe' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest Fedora 38 update introduces kitty version 0.28.1, incorporating essential security enhancements aimed at optimizing overall system efficiency.. Fedora 38, kitty terminal, GPU rendering, terminal emulator, system update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 19, 2023 Important Fedora
89

Fedora 34: 2022-965978ed67 Critical: xterm Buffer Overflow

Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-965978ed67 2022-02-16 01:12:44.297197 --------------------------------------------------------------------------------Name : xterm Product : Fedora 34 Version : 370 Release : 3.fc34 URL : https://invisible-island.net/xterm/ Summary : Terminal emulator for the X Window System Description : The xterm program is a terminal emulator for the X Window System. It provides DEC VT102 and Tektronix 4014 compatible terminals for programs that can't use the window system directly. --------------------------------------------------------------------------------Update Information: Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild --------------------------------------------------------------------------------ChangeLog: * Sat Jan 22 2022 Fedora Release Engineering - 370-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild * Fri Jan 7 2022 Thomas E. Dickey - 370-2 - Trim configure options which are no longer necessary. - Resolves: rhbz#2038247 * Tue Nov 30 2021 Tomas Korbar - 370-1 - Rebase to version 370 - Resolves: rhbz#2023017 * Wed Sep 22 2021 Tomas Korbar - 369-1 - Rebase to version 369 - Resolves: rhbz#2006589 * Fri Jul 23 2021 Fedora Release Engineering - 368-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild * Wed Jul 14 2021 Petr Pisar - 368-2 - Rebuild against pcre2-10.37 (bug #1965025) * Tue Jun 8 2021 Tomas Korbar - 368-1 - Rebase to version 368 - Resolves: rhbz#1969214 * Fri May 21 2021 Joe Orton - 367-3 - drop luit support * Mon May 17 2021 Peter Hutterer 367-2 - Add luit to Requires - Resolves: rhbz#1959210 * Mon Apr 12 2021 Tomas Korbar - 367-1 - Rebase to version 367 - Resolves:rhbz#1943741 --------------------------------------------------------------------------------References: [ 1 ] Bug #2048677 - CVE-2022-24130 xterm: Buffer overflow in set_sixel in graphics_sixel.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2048677 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-965978ed67' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Immediate action required for xterm in Fedora to resolve a security vulnerability related to buffer overflow. Maintain system integrity and implement the update swiftly.. Fedora xterm update, buffer overflow fix, security advisory notification, terminal emulator security, Fedora 34 updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 15, 2022 Critical Fedora
89

Fedora 26 Minicom 2.7.1 Moderate Severity Update Notification

Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-0642394b5a 2017-07-27 14:26:19.255151 --------------------------------------------------------------------------------Name : minicom Product : Fedora 26 Version : 2.7.1 Release : 1.fc26 URL : Summary : A text-based modem control and terminal emulation program Description : Minicom is a simple text-based modem control and terminal emulation program somewhat similar to MSDOS Telix. Minicom includes a dialing directory, full ANSI and VT100 emulation, an (external) scripting language, and other features. --------------------------------------------------------------------------------Update Information: Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade minicom' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 26 introduces an updated Minicom package, addressing security vulnerabilities present in version 2.7.1 from upstream.. Fedora Security Update, Minicom Software Update, Terminal Emulator Fix. . LinuxSecurity.com Team

Calendar 2 Jul 27, 2017 Fedora
87

Debian DSA-3813-1: Important Terminology Command Execution Risk

Nicolas Braud-Santoni discovered that incorrect sanitising of character escape sequences in the Terminology terminal emulator may result in the execution of arbitrary commands. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3712-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff November 13, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : terminology CVE ID : CVE-2015-8971 Nicolas Braud-Santoni discovered that incorrect sanitising of character escape sequences in the Terminology terminal emulator may result in the execution of arbitrary commands. For the stable distribution (jessie), this problem has been fixed in version 0.7.0-1+deb8u1. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you upgrade your terminology packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Safeguard your CLI interface against unsolicited command execution via this essential security patch for Ubuntu.. Terminology Security, Debian Update, Command Execution Risk. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 13, 2016 Important Debian
89

Fedora 22: Shellinabox 2.19 moderate: DNS Rebinding Attack

* Added support for middle-click paste * Improved iOS support * New logic to enable soft keyboard icon * Disable HTTPS fallback using the URL /plain. Consequently disables automatic upgrades from HTTP to HTTPS (CVE-2015-8400). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-463143720f 2016-01-07 23:40:26.816421 -------------------------------------------------------------------------------- Name : shellinabox Product : Fedora 22 Version : 2.19 Release : 1.fc22 URL : https://github.com/shellinabox/shellinabox Summary : Web based AJAX terminal emulator Description : Shell In A Box implements a web server that can export arbitrary command line tools to a web based terminal emulator. This emulator is accessible to any JavaScript and CSS enabled web browser and does not require any additional browser plugins. -------------------------------------------------------------------------------- Update Information: * Added support for middle-click paste * Improved iOS support * New logic to enable soft keyboard icon * Disable HTTPS fallback using the URL /plain. Consequently disables automatic upgrades from HTTP to HTTPS (CVE-2015-8400) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1287579 - CVE-2015-8400 shellinabox: DNS rebinding attack due to HTTP fallback [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287579 [ 2 ] Bug #1287578 - CVE-2015-8400 shellinabox: DNS rebinding attack due to HTTP fallback [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287578 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update shellinabox' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Elevate your Fedora setup with an upgraded shellinabox, addressing DNS rebinding vulnerabilities and enhancing compatibility with iOS devices.. Shell In A Box, Fedora Update, Terminal Emulator, DNS Issue, iOS Support. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 08, 2016 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here