Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
89

Fedora 44 mingw-qt6-qtsensors Patch Release 2026-80776b1ef4

Qt 6.10.3 bugfix update.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-70776c2dc3 2026-04-25 01:21:36.172096+00:00 -------------------------------------------------------------------------------- Name : mingw-qt6-qtsensors Product : Fedora 44 Version : 6.10.3 Release : 1.fc44 URL : http://qt.io/ Summary : Qt6 for Windows - QtSensors component Description : This package contains the Qt software toolkit for developing cross-platform applications. This is the Windows version of Qt, for use in conjunction with the Fedora Windows cross-compiler. -------------------------------------------------------------------------------- Update Information: Qt 6.10.3 bugfix update. -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 31 2026 Jan Grulich - 6.10.3-1 - 6.10.3 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-70776c2dc3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do notreply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Get the latest on the Qt 6.10.3 bugfix update for Fedora 44, focusing on security enhancements and usage.. Fedora 44, Qt 6.10.3, bugfix update, mingw, cross-platform. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Apr 25, 2026 Informational Fedora
172

Ubuntu 20.04 LTS: Linux Kernel Critical Security Update USN-7754-1

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7754-1 September 17, 2025 linux, linux-aws, linux-aws-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-raspi, linux-raspi-5.4, linux-xilinx-zynqmp vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-bluefield: Linux kernel for NVIDIA BlueField platforms - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-ibm: Linux kernel for IBM cloud systems - linux-iot: Linux kernel for IoT platforms - linux-kvm: Linux kernel for cloud environments - linux-raspi: Linux kernel for Raspberry Pi systems - linux-xilinx-zynqmp: Linux kernel for Xilinx ZynqMP processors - linux-aws-5.4: Linux kernel for Amazon Web Services (AWS) systems - linux-gcp-5.4: Linux kernel for Google Cloud Platform (GCP) systems - linux-hwe-5.4: Linux hardware enablement (HWE) kernel - linux-ibm-5.4: Linux kernel for IBM cloud systems - linux-raspi-5.4: Linux kernel for Raspberry Pi systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network traffic control; (CVE-2025-38350, CVE-2025-37752, CVE-2024-57996) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.4.0-1054-iot 5.4.0-1054.57 Available with Ubuntu Pro linux-image-5.4.0-1068-xilinx-zynqmp 5.4.0-1068.72 Available with Ubuntu Pro linux-image-5.4.0-1096-ibm 5.4.0-1096.101 Available with Ubuntu Pro linux-image-5.4.0-1109-bluefield 5.4.0-1109.116 Available with Ubuntu Pro linux-image-5.4.0-1133-raspi 5.4.0-1133.146 Available with Ubuntu Pro linux-image-5.4.0-1137-kvm 5.4.0-1137.146 Available with Ubuntu Pro linux-image-5.4.0-1150-aws 5.4.0-1150.160 Available with Ubuntu Pro linux-image-5.4.0-1153-gcp 5.4.0-1153.162 Available with Ubuntu Pro linux-image-5.4.0-221-generic 5.4.0-221.241 Available with Ubuntu Pro linux-image-5.4.0-221-generic-lpae 5.4.0-221.241 Available with Ubuntu Pro linux-image-5.4.0-221-lowlatency 5.4.0-221.241 Available with Ubuntu Pro linux-image-aws-5.4 5.4.0.1150.147 Available with Ubuntu Pro linux-image-aws-lts-20.04 5.4.0.1150.147 Available with Ubuntu Pro linux-image-bluefield 5.4.0.1109.105 Available with Ubuntu Pro linux-image-bluefield-5.4 5.4.0.1109.105 Available with Ubuntu Pro linux-image-gcp-5.4 5.4.0.1153.155 Available with Ubuntu Pro linux-image-gcp-lts-20.04 5.4.0.1153.155 Available with Ubuntu Pro linux-image-generic 5.4.0.221.213 Available with Ubuntu Pro linux-image-generic-5.4 5.4.0.221.213 Available with Ubuntu Pro linux-image-generic-lpae 5.4.0.221.213 Available with Ubuntu Pro linux-image-generic-lpae-5.4 5.4.0.221.213 Available with Ubuntu Pro linux-image-ibm-5.4 5.4.0.1096.125 Available with Ubuntu Pro linux-image-ibm-lts-20.04 5.4.0.1096.125 Available with Ubuntu Pro linux-image-kvm 5.4.0.1137.133 Available with Ubuntu Pro linux-image-kvm-5.4 5.4.0.1137.133 Available with Ubuntu Pro linux-image-lowlatency 5.4.0.221.213 Available with Ubuntu Pro linux-image-lowlatency-5.4 5.4.0.221.213 Available with Ubuntu Pro linux-image-oem 5.4.0.221.213 Available with Ubuntu Pro linux-image-oem-osp1 5.4.0.221.213 Available with Ubuntu Pro linux-image-raspi 5.4.0.1133.164 Available with Ubuntu Pro linux-image-raspi-5.4 5.4.0.1133.164 Available with Ubuntu Pro linux-image-raspi2 5.4.0.1133.164 Available with Ubuntu Pro linux-image-virtual 5.4.0.221.213 Available with Ubuntu Pro linux-image-virtual-5.4 5.4.0.221.213 Available with Ubuntu Pro linux-image-xilinx-zynqmp 5.4.0.1068.68 Available with Ubuntu Pro linux-image-xilinx-zynqmp-5.4 5.4.0.1068.68 Available with Ubuntu Pro Ubuntu 18.04 LTS linux-image-5.4.0-1096-ibm 5.4.0-1096.101~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-1133-raspi 5.4.0-1133.146~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-1150-aws 5.4.0-1150.160~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-1153-gcp 5.4.0-1153.162~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-221-generic 5.4.0-221.241~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-221-lowlatency 5.4.0-221.241~18.04.1 Available with Ubuntu Pro linux-image-aws 5.4.0.1150.160~18.04.1 Available with Ubuntu Pro linux-image-aws-5.4 5.4.0.1150.160~18.04.1 Available with Ubuntu Pro linux-image-gcp 5.4.0.1153.162~18.04.1 Available with Ubuntu Pro linux-image-gcp-5.4 5.4.0.1153.162~18.04.1 Available with Ubuntu Pro linux-image-generic-5.4 5.4.0.221.241~18.04.1 Available with Ubuntu Pro linux-image-generic-hwe-18.04 5.4.0.221.241~18.04.1 Available with Ubuntu Pro linux-image-ibm 5.4.0.1096.101~18.04.1 Available with Ubuntu Pro linux-image-ibm-5.4 5.4.0.1096.101~18.04.1 Available with Ubuntu Pro linux-image-lowlatency-5.4 5.4.0.221.241~18.04.1 Available with Ubuntu Pro linux-image-lowlatency-hwe-18.04 5.4.0.221.241~18.04.1 Available with Ubuntu Pro linux-image-oem 5.4.0.221.241~18.04.1 Available with Ubuntu Pro linux-image-oem-osp1 5.4.0.221.241~18.04.1 Available with UbuntuPro linux-image-raspi-5.4 5.4.0.1133.146~18.04.1 Available with Ubuntu Pro linux-image-raspi-hwe-18.04 5.4.0.1133.146~18.04.1 Available with Ubuntu Pro linux-image-snapdragon-5.4 5.4.0.221.241~18.04.1 Available with Ubuntu Pro linux-image-snapdragon-hwe-18.04 5.4.0.221.241~18.04.1 Available with Ubuntu Pro linux-image-virtual-5.4 5.4.0.221.241~18.04.1 Available with Ubuntu Pro linux-image-virtual-hwe-18.04 5.4.0.221.241~18.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7754-1 CVE-2024-57996, CVE-2025-37752, CVE-2025-38350 . Numerous vulnerabilities within the Linux kernel have been addressed in Ubuntu Security Notice USN-7755-1. Update your systems immediately!. Linux Kernel Update, Ubuntu Security Patch, Network Security Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 17, 2025 Critical Ubuntu
202

openSUSE 2024:14583-1 moderate: MozillaFirefox security advisory

An update that solves 17 vulnerabilities can now be installed.. # MozillaFirefox-133.0.3-1.1 on GA media Announcement ID: openSUSE-SU-2024:14583-1 Rating: moderate Cross-References: * CVE-2024-11691 * CVE-2024-11692 * CVE-2024-11693 * CVE-2024-11694 * CVE-2024-11695 * CVE-2024-11696 * CVE-2024-11697 * CVE-2024-11698 * CVE-2024-11699 * CVE-2024-11700 * CVE-2024-11701 * CVE-2024-11702 * CVE-2024-11703 * CVE-2024-11704 * CVE-2024-11705 * CVE-2024-11706 * CVE-2024-11708 Affected Products: * openSUSE Tumbleweed An update that solves 17 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the MozillaFirefox-133.0.3-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * MozillaFirefox 133.0.3-1.1 * MozillaFirefox-branding-upstream 133.0.3-1.1 * MozillaFirefox-devel 133.0.3-1.1 * MozillaFirefox-translations-common 133.0.3-1.1 * MozillaFirefox-translations-other 133.0.3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-11691.html * https://www.suse.com/security/cve/CVE-2024-11692.html * https://www.suse.com/security/cve/CVE-2024-11693.html * https://www.suse.com/security/cve/CVE-2024-11694.html * https://www.suse.com/security/cve/CVE-2024-11695.html * https://www.suse.com/security/cve/CVE-2024-11696.html * https://www.suse.com/security/cve/CVE-2024-11697.html * https://www.suse.com/security/cve/CVE-2024-11698.html * https://www.suse.com/security/cve/CVE-2024-11699.html * https://www.suse.com/security/cve/CVE-2024-11700.html * https://www.suse.com/security/cve/CVE-2024-11701.html * https://www.suse.com/security/cve/CVE-2024-11702.html * https://www.suse.com/security/cve/CVE-2024-11703.html * https://www.suse.com/security/cve/CVE-2024-11704.html * https://www.suse.com/security/cve/CVE-2024-11705.html * https://www.suse.com/security/cve/CVE-2024-11706.html * https://www.suse.com/security/cve/CVE-2024-11708.html . This patchfor MozillaFirefox on Fedora resolves 17 vulnerabilities classified with a moderate level of severity.. MozillaFirefox update, openSUSE advisory, security issue, software update, security measures. . LinuxSecurity.com Team

Calendar%202 Dec 17, 2024 OpenSUSE
91

Gentoo: 200407-13 High: PHP Remote Code Execution Risk Advisory

Multiple security vulnerabilities, potentially allowing remote code execution, were found and fixed in PHP.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200407-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: PHP: Multiple security vulnerabilities Date: July 15, 2004 Bugs: #56985 ID: 200407-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple security vulnerabilities, potentially allowing remote code execution, were found and fixed in PHP. Background ========= PHP is a general-purpose scripting language widely used to develop web-based applications. It can run inside a web server using the mod_php module or the CGI version of PHP, or can run stand-alone in a CLI. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-php/php = 4.3.8 2 dev-php/mod_php = 4.3.8 3 dev-php/php-cgi = 4.3.8 ------------------------------------------------------------------- 3 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== Several security vulnerabilities were found and fixed in version 4.3.8 of PHP. The strip_tags() function, used to sanitize user input, could in certain cases allow tags containing \0 characters (CAN-2004-0595). When memory_limit is used, PHP might unsafely interrupt other functions (CAN-2004-0594). The ftok and itpc functions were missing safe_mode checks. It was possible to bypass open_basedir restrictionsusing MySQL's LOAD DATA LOCAL function. Furthermore, the IMAP extension was incorrectly allocating memory and alloca() calls were replaced with emalloc() for better stack protection. Impact ===== Successfully exploited, the memory_limit problem could allow remote excution of arbitrary code. By exploiting the strip_tags vulnerability, it is possible to pass HTML code that would be considered as valid tags by the Microsoft Internet Explorer and Safari browsers. Using ftok, itpc or MySQL's LOAD DATA LOCAL, it is possible to bypass PHP configuration restrictions. Workaround ========= There is no known workaround that would solve all these problems. All users are encouraged to upgrade to the latest available versions. Resolution ========= All PHP, mod_php and php-cgi users should upgrade to the latest stable version: # emerge sync # emerge -pv "> =dev-php/php-4.3.8" # emerge "> =dev-php/php-4.3.8" # emerge -pv "> =dev-php/mod_php-4.3.8" # emerge "> =dev-php/mod_php-4.3.8" # emerge -pv "> =dev-php/php-cgi-4.3.8" # emerge "> =dev-php/php-cgi-4.3.8" References ========= [ 1 ] CAN-2004-0594 https://www.cve.org/CVERecord?id=CAN-2004-0594 [ 2 ] CAN-2004-0595 https://www.cve.org/CVERecord?id=CAN-2004-0595 [ 3 ] E-Matters Advisory 11/2004 [ 4 ] E-Matters Advisory 12/2004 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200407-13 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2004 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alikelicense. https://creativecommons.org/licenses/by-sa/1.0/ . Recent PHP flaws discovered on Gentoo highlight immediate updates necessary to avert potential remote code execution threats.. PHP Security Issues, Gentoo Updates, Remote Exec Threats, Software Vulnerability Fixes. . LinuxSecurity.com Team

Calendar%202 Jul 15, 2004 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200