Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
202

openSUSE 15.4 Cosign Moderate Attestation Verification Issue 2026-2365-1

An update that solves one vulnerability can now be installed.. # Security update for cosign Announcement ID: SUSE-SU-2026:2365-1 Release Date: 2026-06-11T07:58:20Z Rating: moderate References: * bsc#1261859 Cross-References: * CVE-2026-39395 CVSS scores: * CVE-2026-39395 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39395 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-39395 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-39395 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for cosign fixes the following issue * CVE-2026-39395: Incorrect attestation verification due to malformed payloads or mismatched predicate types (bsc#1261859). Changes for cosign: * update to 3.0.6: * Fix DSSE predicate check (GHSA-w6c6-c85g-mmv6) (#4801) * Handle whitespace-only certificate annotation (#4760) * fix(sign): closing SignerVerifier too early when signing with a security key (#4761) * Disallow --new-bundle-format and --rfc3161-timestamp (#4762) * support managed keys in conformance testing (#4728) * Add support for GCE metadata server env var (#4732) * fix: preserve per-layer annotations in WriteAttestationsReferrer (#4709) * Fix parsing of in-toto for string predicates * Mark batch of flags for deprecation (#4698) * disallow key and cert identity being used together during verification (#4636) * support key creation in GitLab group (#4704) * Set CGO_ENABLED=1 for fixing s390x failed build * build against a maintained golang version (upstream uses go1.20) ## Patch Instructions: To install thisSUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2365=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2365=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * cosign-3.0.6-150400.3.42.1 * cosign-debuginfo-3.0.6-150400.3.42.1 * openSUSE Leap 15.4 (noarch) * cosign-bash-completion-3.0.6-150400.3.42.1 * cosign-zsh-completion-3.0.6-150400.3.42.1 * cosign-fish-completion-3.0.6-150400.3.42.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cosign-3.0.6-150400.3.42.1 * cosign-debuginfo-3.0.6-150400.3.42.1 * Basesystem Module 15-SP7 (noarch) * cosign-bash-completion-3.0.6-150400.3.42.1 * cosign-zsh-completion-3.0.6-150400.3.42.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39395.html * https://bugzilla.suse.com/show_bug.cgi?id=1261859 . Update for cosign addresses a moderate risk vulnerability related to malformed payloads and verification issues.. openSUSE Cosign Update, Moderate Risk, Payload Vulnerability, Security Correction. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 11, 2026 moderate OpenSUSE
172

Ubuntu 18.04 LTS - USN-7553-4: Kernel Security Issues Fixed

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7553-4 June 09, 2025 linux-azure, linux-azure-4.15 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-azure-4.15: Linux kernel for Microsoft Azure Cloud systems - linux-azure: Linux kernel for Microsoft Azure Cloud systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Clock framework and drivers; - GPU drivers; - Parport drivers; - Ext4 file system; - JFFS2 file system; - JFS file system; - File systems infrastructure; - Sun RPC protocol; - USB sound devices; (CVE-2024-57850, CVE-2024-42301, CVE-2024-53155, CVE-2024-53168, CVE-2024-26966, CVE-2021-47211, CVE-2024-56596, CVE-2024-56551, CVE-2024-47701) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS linux-image-4.15.0-1189-azure 4.15.0-1189.204 Available with Ubuntu Pro linux-image-azure-lts-18.04 4.15.0.1189.157 Available with Ubuntu Pro Ubuntu 16.04 LTS linux-image-4.15.0-1189-azure 4.15.0-1189.204~16.04.1 Available with Ubuntu Pro linux-image-azure 4.15.0.1189.204~16.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all thirdparty kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7553-4 https://ubuntu.com/security/notices/USN-7553-3 https://ubuntu.com/security/notices/USN-7553-2 https://ubuntu.com/security/notices/USN-7553-1 CVE-2021-47211, CVE-2024-26966, CVE-2024-42301, CVE-2024-47701, CVE-2024-53155, CVE-2024-53168, CVE-2024-56551, CVE-2024-56596, CVE-2024-57850 . Ubuntu 20.04 and 18.04 received vital patches for the Linux kernel, tackling multiple severe vulnerabilities.. Linux Kernel Updates, Ubuntu Security, Azure Linux, Kernel Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 09, 2025 Critical Ubuntu
172

Ubuntu 22.04 LTS: USN-7452-1 critical: Multiple Linux kernel issues fixed

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7452-1 April 23, 2025 linux-gcp-6.8 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-gcp-6.8: Linux kernel for Google Cloud Platform (GCP) systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - MIPS architecture; - PowerPC architecture; - RISC-V architecture; - S390 architecture; - SuperH RISC architecture; - User-Mode Linux (UML); - x86 architecture; - Block layer subsystem; - Cryptographic API; - Compute Acceleration Framework; - ACPI drivers; - Drivers core; - RAM backed block device driver; - Compressed RAM block device driver; - TPM device driver; - Clock framework and drivers; - Data acquisition framework and drivers; - CPU frequency scaling framework; - Hardware crypto device drivers; - CXL (Compute Express Link) drivers; - EDAC drivers; - ARM SCMI message protocol; - ARM SCPI message protocol; - EFI core; - GPIO subsystem; - GPU drivers; - HID subsystem; - I3C subsystem; - IIO ADC drivers; - IIO subsystem; - InfiniBand drivers; - IOMMU subsystem; - LED subsystem; - Multiple devices driver; - Media drivers; - Multifunction device drivers; - MMC subsystem; - MTD block device drivers; - Network drivers; - Mellanox network drivers; - STMicroelectronics network drivers; - NVME drivers; - PCI subsystem; - PHY drivers; - Pin controllers subsystem; - x86 platform drivers; - i.MX PM domains; - Voltage and Current Regulator drivers; - StarFive reset controllerdrivers; - Real Time Clock drivers; - SCSI subsystem; - i.MX SoC drivers; - QCOM SoC drivers; - Xilinx SoC drivers; - SPI subsystem; - Media staging drivers; - TCM subsystem; - UFS subsystem; - DesignWare USB3 driver; - USB Dual Role (OTG-ready) Controller drivers; - USB Serial drivers; - USB Type-C support driver; - USB Type-C Port Controller Manager driver; - USB Type-C Connector System Software Interface driver; - vDPA drivers; - VFIO drivers; - Framebuffer layer; - Xen hypervisor drivers; - AFS file system; - BTRFS file system; - File systems infrastructure; - EROFS file system; - F2FS file system; - JFFS2 file system; - JFS file system; - Network file systems library; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NILFS2 file system; - NTFS3 file system; - Overlay file system; - Proc file system; - Diskquota system; - SMB network file system; - UBI file system; - DRM display driver; - BPF subsystem; - StackDepot library; - Bluetooth subsystem; - IP tunnels definitions; - Netfilter; - Tracing infrastructure; - User-space API (UAPI); - Kernel init infrastructure; - io_uring subsystem; - IPC subsystem; - DMA mapping infrastructure; - Kernel fork() syscall; - KCSAN framework; - RCU subsystem; - Arbitrary resource management; - Scheduler infrastructure; - Signal handling mechanism; - Task handling mechanism; - Timer subsystem; - KUnit library; - Memory management; - 9P file system network protocol; - CAN network layer; - Networking core; - DCCP (Datagram Congestion Control Protocol); - Ethtool driver; - HSR network protocol; - IEEE802154.4 network protocol; - IPv4 networking; - IPv6 networking; - IUCV driver; - MAC80211 subsystem; - Multipath TCP; - Packet sockets; - RxRPC session sockets; - Network traffic control; - SCTP protocol; - SMC sockets; - Sun RPC protocol; - TIPC protocol; - VMware vSockets driver; - Wirelessnetworking; - eXpress Data Path; - XFRM subsystem; - Integrity Measurement Architecture(IMA) framework; - Key management; - ALSA framework; - FireWire sound drivers; - HD-audio driver; - MediaTek ASoC drivers; - QCOM ASoC drivers; - SoC audio core drivers; - STMicroelectronics SoC drivers; - USB sound devices; (CVE-2024-56724, CVE-2024-50108, CVE-2024-56631, CVE-2024-50236, CVE-2022-49034, CVE-2024-50133, CVE-2024-53108, CVE-2024-56605, CVE-2024-56599, CVE-2024-56721, CVE-2024-53110, CVE-2024-56751, CVE-2024-53120, CVE-2024-53198, CVE-2024-57876, CVE-2024-50285, CVE-2024-53133, CVE-2024-56681, CVE-2024-56581, CVE-2025-21701, CVE-2024-53086, CVE-2024-53201, CVE-2024-56630, CVE-2024-53222, CVE-2024-50139, CVE-2024-53084, CVE-2024-53214, CVE-2024-53183, CVE-2024-56600, CVE-2024-50286, CVE-2024-53232, CVE-2024-56777, CVE-2024-56540, CVE-2024-50121, CVE-2024-50284, CVE-2024-56621, CVE-2024-53195, CVE-2024-50279, CVE-2024-53203, CVE-2024-50104, CVE-2024-50238, CVE-2024-53177, CVE-2024-53053, CVE-2024-50297, CVE-2024-56569, CVE-2024-53131, CVE-2024-56642, CVE-2024-56752, CVE-2024-53079, CVE-2024-56705, CVE-2024-56679, CVE-2024-50272, CVE-2024-53231, CVE-2024-53228, CVE-2024-50128, CVE-2024-53229, CVE-2024-53055, CVE-2024-53050, CVE-2024-50265, CVE-2024-56703, CVE-2024-53114, CVE-2024-50278, CVE-2024-56771, CVE-2024-56708, CVE-2024-53082, CVE-2024-50051, CVE-2024-50125, CVE-2024-53109, CVE-2024-50257, CVE-2024-50107, CVE-2024-50290, CVE-2024-50211, CVE-2024-56609, CVE-2024-53190, CVE-2024-50232, CVE-2024-53134, CVE-2024-50142, CVE-2024-50166, CVE-2024-53051, CVE-2024-53224, CVE-2024-57872, CVE-2024-53200, CVE-2024-56685, CVE-2025-21700, CVE-2024-43098, CVE-2024-56604, CVE-2024-50218, CVE-2024-53113, CVE-2024-50242, CVE-2024-50223, CVE-2024-53099, CVE-2024-50162, CVE-2024-56587, CVE-2025-21756, CVE-2024-50126, CVE-2024-50067, CVE-2024-56539, CVE-2024-50153, CVE-2024-50251, CVE-2024-56726, CVE-2024-56780, CVE-2024-56700, CVE-2024-53059, CVE-2024-50252, CVE-2024-50269, CVE-2024-50163,CVE-2024-50248, CVE-2024-56578, CVE-2024-50240, CVE-2024-53155, CVE-2024-56613, CVE-2024-50118, CVE-2024-53091, CVE-2024-57838, CVE-2024-53094, CVE-2024-56638, CVE-2024-53175, CVE-2024-53062, CVE-2024-57843, CVE-2024-50210, CVE-2024-53237, CVE-2024-50115, CVE-2024-50164, CVE-2024-50208, CVE-2024-53068, CVE-2024-41932, CVE-2024-45828, CVE-2024-56635, CVE-2024-50112, CVE-2024-50289, CVE-2024-53197, CVE-2024-49906, CVE-2024-50304, CVE-2024-56625, CVE-2024-56785, CVE-2024-49899, CVE-2024-48876, CVE-2024-53236, CVE-2024-50216, CVE-2024-56756, CVE-2024-53178, CVE-2024-53095, CVE-2024-56786, CVE-2024-50111, CVE-2024-56643, CVE-2024-56584, CVE-2024-50298, CVE-2024-53089, CVE-2024-56550, CVE-2024-50221, CVE-2024-50160, CVE-2024-53188, CVE-2024-53066, CVE-2024-53047, CVE-2024-56765, CVE-2024-56601, CVE-2024-53146, CVE-2024-56597, CVE-2024-56622, CVE-2024-50205, CVE-2024-56647, CVE-2024-56651, CVE-2024-56572, CVE-2024-56568, CVE-2024-53087, CVE-2024-50152, CVE-2024-53230, CVE-2024-50276, CVE-2024-56562, CVE-2024-56565, CVE-2024-56596, CVE-2024-50237, CVE-2024-53194, CVE-2024-53176, CVE-2024-56754, CVE-2024-56593, CVE-2024-50225, CVE-2024-47143, CVE-2024-50301, CVE-2025-21831, CVE-2024-53151, CVE-2024-50259, CVE-2024-50150, CVE-2024-53145, CVE-2024-56590, CVE-2024-50222, CVE-2024-53058, CVE-2024-56687, CVE-2024-56690, CVE-2024-56538, CVE-2024-53044, CVE-2024-50292, CVE-2024-56577, CVE-2024-50235, CVE-2024-50172, CVE-2024-53127, CVE-2024-56615, CVE-2024-53088, CVE-2024-50141, CVE-2024-53223, CVE-2024-50135, CVE-2024-50262, CVE-2024-53174, CVE-2024-56545, CVE-2024-53093, CVE-2024-56586, CVE-2024-53118, CVE-2024-56727, CVE-2024-57874, CVE-2024-50267, CVE-2024-53048, CVE-2024-50250, CVE-2024-56533, CVE-2024-53196, CVE-2024-57849, CVE-2024-50010, CVE-2024-53129, CVE-2024-53119, CVE-2024-56742, CVE-2024-53045, CVE-2024-50226, CVE-2024-53173, CVE-2024-53220, CVE-2024-53185, CVE-2024-50294, CVE-2024-53181, CVE-2024-53150, CVE-2024-47809, CVE-2024-56746, CVE-2024-53233, CVE-2024-56620, CVE-2024-53213, CVE-2024-53163, CVE-2024-56648,CVE-2024-56640, CVE-2024-48873, CVE-2024-53209, CVE-2024-50246, CVE-2024-50258, CVE-2024-57850, CVE-2024-56549, CVE-2024-56627, CVE-2024-56778, CVE-2024-56720, CVE-2024-50256, CVE-2024-56725, CVE-2024-56729, CVE-2024-53046, CVE-2024-56573, CVE-2024-53112, CVE-2024-53115, CVE-2024-50234, CVE-2024-53172, CVE-2024-56558, CVE-2024-56787, CVE-2024-53184, CVE-2024-50131, CVE-2024-50255, CVE-2024-50155, CVE-2024-53187, CVE-2024-49569, CVE-2024-56616, CVE-2024-53147, CVE-2024-53123, CVE-2024-53162, CVE-2024-53126, CVE-2024-53061, CVE-2024-53210, CVE-2024-50138, CVE-2024-53105, CVE-2024-56644, CVE-2024-50105, CVE-2024-50207, CVE-2024-53158, CVE-2024-50261, CVE-2024-56693, CVE-2024-41935, CVE-2024-53128, CVE-2024-50116, CVE-2024-50143, CVE-2025-21702, CVE-2024-53072, CVE-2024-53100, CVE-2024-42122, CVE-2024-50303, CVE-2024-50124, CVE-2024-56606, CVE-2024-56557, CVE-2024-53083, CVE-2024-50299, CVE-2024-56589, CVE-2024-50296, CVE-2024-50275, CVE-2024-56698, CVE-2024-50245, CVE-2024-50263, CVE-2024-56633, CVE-2024-50230, CVE-2024-56579, CVE-2024-50231, CVE-2024-50295, CVE-2024-56611, CVE-2024-56689, CVE-2024-50159, CVE-2024-53680, CVE-2024-56551, CVE-2024-56748, CVE-2024-50249, CVE-2024-53168, CVE-2024-56632, CVE-2024-53060, CVE-2024-41014, CVE-2024-53121, CVE-2024-50145, CVE-2024-53081, CVE-2024-50151, CVE-2024-56781, CVE-2024-50110, CVE-2024-53148, CVE-2024-56567, CVE-2024-56641, CVE-2024-53208, CVE-2024-56619, CVE-2024-52332, CVE-2024-56775, CVE-2024-56626, CVE-2024-56688, CVE-2024-53215, CVE-2024-56783, CVE-2024-50103, CVE-2024-53226, CVE-2024-50282, CVE-2024-56755, CVE-2024-50268, CVE-2024-50271, CVE-2024-53076, CVE-2024-56610, CVE-2024-56636, CVE-2024-44955, CVE-2024-56623, CVE-2024-56694, CVE-2024-56608, CVE-2024-56576, CVE-2024-56692, CVE-2024-56723, CVE-2024-53191, CVE-2024-56677, CVE-2024-48875, CVE-2024-53106, CVE-2024-56678, CVE-2024-50273, CVE-2024-50206, CVE-2024-50170, CVE-2024-56594, CVE-2024-56707, CVE-2024-56649, CVE-2024-50167, CVE-2024-56691, CVE-2024-56683, CVE-2024-53052, CVE-2024-56747, CVE-2024-47141,CVE-2024-56543, CVE-2024-56574, CVE-2024-53085, CVE-2024-50136, CVE-2024-56779, CVE-2024-53111, CVE-2024-53139, CVE-2024-56704, CVE-2024-56745, CVE-2024-53234, CVE-2024-53138, CVE-2024-50130, CVE-2024-48881, CVE-2024-53107, CVE-2024-53218, CVE-2024-56602, CVE-2024-56531, CVE-2024-53154, CVE-2024-56532, CVE-2024-53130, CVE-2024-50215, CVE-2024-50147, CVE-2024-56607, CVE-2024-50137, CVE-2024-47794, CVE-2024-50158, CVE-2024-50239, CVE-2024-56645, CVE-2024-53171, CVE-2024-56592, CVE-2024-56772, CVE-2024-50288, CVE-2024-50156, CVE-2024-53180, CVE-2024-53169, CVE-2024-56634, CVE-2024-56728, CVE-2024-56722, CVE-2024-50209, CVE-2024-56588, CVE-2024-53096, CVE-2024-56548, CVE-2024-53166, CVE-2024-56773, CVE-2024-56575, CVE-2024-56650, CVE-2024-50127, CVE-2024-56744, CVE-2024-56546, CVE-2024-50154, CVE-2024-53202, CVE-2024-56782, CVE-2024-50270, CVE-2024-53157, CVE-2024-50243, CVE-2024-56583, CVE-2024-53239, CVE-2025-21993, CVE-2024-56603, CVE-2024-56629, CVE-2024-53135, CVE-2024-56739, CVE-2024-50283, CVE-2024-56580, CVE-2024-50169, CVE-2024-56774, CVE-2024-53042, CVE-2024-53227, CVE-2024-53067, CVE-2024-50224, CVE-2024-50247, CVE-2024-53122, CVE-2024-53090, CVE-2024-53221, CVE-2024-50146, CVE-2024-53219, CVE-2024-53142, CVE-2024-56570, CVE-2024-56566, CVE-2024-50140, CVE-2024-56776, CVE-2024-50287, CVE-2024-53161, CVE-2024-50300, CVE-2024-53160, CVE-2024-50203, CVE-2024-53217, CVE-2024-50244, CVE-2024-53043, CVE-2024-50280, CVE-2024-56637, CVE-2024-53117, CVE-2024-56701, CVE-2024-50291, CVE-2024-50120, CVE-2024-53101, CVE-2024-50220, CVE-2024-56561) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-6.8.0-1028-gcp 6.8.0-1028.30~22.04.1 linux-image-6.8.0-1028-gcp-64k 6.8.0-1028.30~22.04.1 linux-image-gcp 6.8.0-1028.30~22.04.1 linux-image-gcp-64k 6.8.0-1028.30~22.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to anunavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7452-1 CVE-2022-49034, CVE-2024-41014, CVE-2024-41932, CVE-2024-41935, CVE-2024-42122, CVE-2024-43098, CVE-2024-44955, CVE-2024-45828, CVE-2024-47141, CVE-2024-47143, CVE-2024-47794, CVE-2024-47809, CVE-2024-48873, CVE-2024-48875, CVE-2024-48876, CVE-2024-48881, CVE-2024-49569, CVE-2024-49899, CVE-2024-49906, CVE-2024-50010, CVE-2024-50051, CVE-2024-50067, CVE-2024-50103, CVE-2024-50104, CVE-2024-50105, CVE-2024-50107, CVE-2024-50108, CVE-2024-50110, CVE-2024-50111, CVE-2024-50112, CVE-2024-50115, CVE-2024-50116, CVE-2024-50118, CVE-2024-50120, CVE-2024-50121, CVE-2024-50124, CVE-2024-50125, CVE-2024-50126, CVE-2024-50127, CVE-2024-50128, CVE-2024-50130, CVE-2024-50131, CVE-2024-50133, CVE-2024-50135, CVE-2024-50136, CVE-2024-50137, CVE-2024-50138, CVE-2024-50139, CVE-2024-50140, CVE-2024-50141, CVE-2024-50142, CVE-2024-50143, CVE-2024-50145, CVE-2024-50146, CVE-2024-50147, CVE-2024-50150, CVE-2024-50151, CVE-2024-50152, CVE-2024-50153, CVE-2024-50154, CVE-2024-50155, CVE-2024-50156, CVE-2024-50158, CVE-2024-50159, CVE-2024-50160, CVE-2024-50162, CVE-2024-50163, CVE-2024-50164, CVE-2024-50166, CVE-2024-50167, CVE-2024-50169, CVE-2024-50170, CVE-2024-50172, CVE-2024-50203, CVE-2024-50205, CVE-2024-50206, CVE-2024-50207, CVE-2024-50208, CVE-2024-50209, CVE-2024-50210, CVE-2024-50211, CVE-2024-50215, CVE-2024-50216, CVE-2024-50218, CVE-2024-50220, CVE-2024-50221, CVE-2024-50222, CVE-2024-50223, CVE-2024-50224, CVE-2024-50225, CVE-2024-50226, CVE-2024-50230, CVE-2024-50231, CVE-2024-50232, CVE-2024-50234, CVE-2024-50235, CVE-2024-50236, CVE-2024-50237, CVE-2024-50238, CVE-2024-50239, CVE-2024-50240, CVE-2024-50242, CVE-2024-50243, CVE-2024-50244, CVE-2024-50245, CVE-2024-50246, CVE-2024-50247, CVE-2024-50248, CVE-2024-50249, CVE-2024-50250, CVE-2024-50251, CVE-2024-50252, CVE-2024-50255, CVE-2024-50256, CVE-2024-50257, CVE-2024-50258, CVE-2024-50259, CVE-2024-50261, CVE-2024-50262, CVE-2024-50263, CVE-2024-50265, CVE-2024-50267, CVE-2024-50268, CVE-2024-50269, CVE-2024-50270, CVE-2024-50271, CVE-2024-50272, CVE-2024-50273, CVE-2024-50275, CVE-2024-50276, CVE-2024-50278, CVE-2024-50279, CVE-2024-50280, CVE-2024-50282, CVE-2024-50283, CVE-2024-50284, CVE-2024-50285, CVE-2024-50286, CVE-2024-50287, CVE-2024-50288, CVE-2024-50289, CVE-2024-50290, CVE-2024-50291, CVE-2024-50292, CVE-2024-50294, CVE-2024-50295, CVE-2024-50296, CVE-2024-50297, CVE-2024-50298, CVE-2024-50299, CVE-2024-50300, CVE-2024-50301, CVE-2024-50303, CVE-2024-50304, CVE-2024-52332, CVE-2024-53042, CVE-2024-53043, CVE-2024-53044, CVE-2024-53045, CVE-2024-53046, CVE-2024-53047, CVE-2024-53048, CVE-2024-53050, CVE-2024-53051, CVE-2024-53052, CVE-2024-53053, CVE-2024-53055, CVE-2024-53058, CVE-2024-53059, CVE-2024-53060, CVE-2024-53061, CVE-2024-53062, CVE-2024-53066, CVE-2024-53067, CVE-2024-53068, CVE-2024-53072, CVE-2024-53076, CVE-2024-53079, CVE-2024-53081, CVE-2024-53082, CVE-2024-53083, CVE-2024-53084, CVE-2024-53085, CVE-2024-53086, CVE-2024-53087, CVE-2024-53088, CVE-2024-53089, CVE-2024-53090, CVE-2024-53091, CVE-2024-53093, CVE-2024-53094, CVE-2024-53095, CVE-2024-53096, CVE-2024-53099, CVE-2024-53100, CVE-2024-53101, CVE-2024-53105, CVE-2024-53106, CVE-2024-53107, CVE-2024-53108, CVE-2024-53109, CVE-2024-53110, CVE-2024-53111, CVE-2024-53112, CVE-2024-53113, CVE-2024-53114, CVE-2024-53115, CVE-2024-53117, CVE-2024-53118, CVE-2024-53119, CVE-2024-53120, CVE-2024-53121, CVE-2024-53122, CVE-2024-53123, CVE-2024-53126, CVE-2024-53127, CVE-2024-53128, CVE-2024-53129, CVE-2024-53130, CVE-2024-53131, CVE-2024-53133, CVE-2024-53134, CVE-2024-53135, CVE-2024-53138, CVE-2024-53139, CVE-2024-53142, CVE-2024-53145, CVE-2024-53146, CVE-2024-53147, CVE-2024-53148, CVE-2024-53150, CVE-2024-53151, CVE-2024-53154, CVE-2024-53155, CVE-2024-53157, CVE-2024-53158, CVE-2024-53160, CVE-2024-53161, CVE-2024-53162, CVE-2024-53163, CVE-2024-53166, CVE-2024-53168, CVE-2024-53169, CVE-2024-53171, CVE-2024-53172, CVE-2024-53173, CVE-2024-53174, CVE-2024-53175, CVE-2024-53176, CVE-2024-53177, CVE-2024-53178, CVE-2024-53180, CVE-2024-53181, CVE-2024-53183, CVE-2024-53184, CVE-2024-53185, CVE-2024-53187, CVE-2024-53188, CVE-2024-53190, CVE-2024-53191, CVE-2024-53194, CVE-2024-53195, CVE-2024-53196, CVE-2024-53197, CVE-2024-53198, CVE-2024-53200, CVE-2024-53201, CVE-2024-53202, CVE-2024-53203, CVE-2024-53208, CVE-2024-53209, CVE-2024-53210, CVE-2024-53213, CVE-2024-53214, CVE-2024-53215, CVE-2024-53217, CVE-2024-53218, CVE-2024-53219, CVE-2024-53220, CVE-2024-53221, CVE-2024-53222, CVE-2024-53223, CVE-2024-53224, CVE-2024-53226, CVE-2024-53227, CVE-2024-53228, CVE-2024-53229, CVE-2024-53230, CVE-2024-53231, CVE-2024-53232, CVE-2024-53233, CVE-2024-53234, CVE-2024-53236, CVE-2024-53237, CVE-2024-53239, CVE-2024-53680, CVE-2024-56531, CVE-2024-56532, CVE-2024-56533, CVE-2024-56538, CVE-2024-56539, CVE-2024-56540, CVE-2024-56543, CVE-2024-56545, CVE-2024-56546, CVE-2024-56548, CVE-2024-56549, CVE-2024-56550, CVE-2024-56551, CVE-2024-56557, CVE-2024-56558, CVE-2024-56561, CVE-2024-56562, CVE-2024-56565, CVE-2024-56566, CVE-2024-56567, CVE-2024-56568, CVE-2024-56569, CVE-2024-56570, CVE-2024-56572, CVE-2024-56573, CVE-2024-56574, CVE-2024-56575, CVE-2024-56576, CVE-2024-56577, CVE-2024-56578, CVE-2024-56579, CVE-2024-56580, CVE-2024-56581, CVE-2024-56583, CVE-2024-56584, CVE-2024-56586, CVE-2024-56587, CVE-2024-56588, CVE-2024-56589, CVE-2024-56590, CVE-2024-56592, CVE-2024-56593, CVE-2024-56594, CVE-2024-56596, CVE-2024-56597, CVE-2024-56599, CVE-2024-56600, CVE-2024-56601, CVE-2024-56602, CVE-2024-56603, CVE-2024-56604, CVE-2024-56605, CVE-2024-56606, CVE-2024-56607, CVE-2024-56608, CVE-2024-56609, CVE-2024-56610, CVE-2024-56611, CVE-2024-56613, CVE-2024-56615, CVE-2024-56616, CVE-2024-56619, CVE-2024-56620, CVE-2024-56621, CVE-2024-56622, CVE-2024-56623, CVE-2024-56625, CVE-2024-56626, CVE-2024-56627, CVE-2024-56629, CVE-2024-56630, CVE-2024-56631, CVE-2024-56632, CVE-2024-56633, CVE-2024-56634, CVE-2024-56635, CVE-2024-56636, CVE-2024-56637, CVE-2024-56638, CVE-2024-56640, CVE-2024-56641, CVE-2024-56642, CVE-2024-56643, CVE-2024-56644, CVE-2024-56645, CVE-2024-56647, CVE-2024-56648, CVE-2024-56649, CVE-2024-56650, CVE-2024-56651, CVE-2024-56677, CVE-2024-56678, CVE-2024-56679, CVE-2024-56681, CVE-2024-56683, CVE-2024-56685, CVE-2024-56687, CVE-2024-56688, CVE-2024-56689, CVE-2024-56690, CVE-2024-56691, CVE-2024-56692, CVE-2024-56693, CVE-2024-56694, CVE-2024-56698, CVE-2024-56700, CVE-2024-56701, CVE-2024-56703, CVE-2024-56704, CVE-2024-56705, CVE-2024-56707, CVE-2024-56708, CVE-2024-56720, CVE-2024-56721, CVE-2024-56722, CVE-2024-56723, CVE-2024-56724, CVE-2024-56725, CVE-2024-56726, CVE-2024-56727, CVE-2024-56728, CVE-2024-56729, CVE-2024-56739, CVE-2024-56742, CVE-2024-56744, CVE-2024-56745, CVE-2024-56746, CVE-2024-56747, CVE-2024-56748, CVE-2024-56751, CVE-2024-56752, CVE-2024-56754, CVE-2024-56755, CVE-2024-56756, CVE-2024-56765, CVE-2024-56771, CVE-2024-56772, CVE-2024-56773, CVE-2024-56774, CVE-2024-56775, CVE-2024-56776, CVE-2024-56777, CVE-2024-56778, CVE-2024-56779, CVE-2024-56780, CVE-2024-56781, CVE-2024-56782, CVE-2024-56783, CVE-2024-56785, CVE-2024-56786, CVE-2024-56787, CVE-2024-57838, CVE-2024-57843, CVE-2024-57849, CVE-2024-57850, CVE-2024-57872, CVE-2024-57874, CVE-2024-57876, CVE-2025-21700, CVE-2025-21701, CVE-2025-21702, CVE-2025-21756, CVE-2025-21831, CVE-2025-21993 Package Information: https://launchpad.net/ubuntu/+source/linux-gcp-6.8/6.8.0-1028.30~22.04.1 . A multitude of challenges tackledin the Ubuntu kernel revision bolster overall system robustness and safeguard against emerging vulnerabilities.. Linux Kernel Update, Ubuntu Security Notice, System Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 23, 2025 Critical Ubuntu
172

Ubuntu 20.04 LTS USN-7294-2 High: Kernel Security Issues

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7294-2 February 27, 2025 linux-aws, linux-oracle, linux-oracle-5.4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-oracle: Linux kernel for Oracle Cloud systems - linux-oracle-5.4: Linux kernel for Oracle Cloud systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Block layer subsystem; - ACPI drivers; - Drivers core; - ATA over ethernet (AOE) driver; - TPM device driver; - GPIO subsystem; - GPU drivers; - HID subsystem; - I2C subsystem; - InfiniBand drivers; - Mailbox framework; - Multiple devices driver; - Media drivers; - Network drivers; - NTB driver; - Virtio pmem driver; - Parport drivers; - PCI subsystem; - SPI subsystem; - Direct Digital Synthesis drivers; - USB Device Class drivers; - USB Dual Role (OTG-ready) Controller drivers; - USB Serial drivers; - USB Type-C support driver; - Framebuffer layer; - BTRFS file system; - Ceph distributed file system; - Ext4 file system; - F2FS file system; - File systems infrastructure; - JFS file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NILFS2 file system; - SMB network file system; - Network traffic control; - Network sockets; - TCP network protocol; - BPF subsystem; - Perf events; - Arbitrary resource management; - Timer substystem drivers; - Tracing infrastructure; - Closures library; -Memory management; - Amateur Radio drivers; - Bluetooth subsystem; - Ethernet bridge; - CAN network layer; - Networking core; - IPv4 networking; - IPv6 networking; - MAC80211 subsystem; - Netfilter; - Netlink; - SCTP protocol; - TIPC protocol; - Wireless networking; - XFRM subsystem; - Key management; - FireWire sound drivers; - AudioScience HPI driver; - Amlogic Meson SoC drivers; - KVM core; (CVE-2024-53063, CVE-2024-50236, CVE-2024-47699, CVE-2024-50044, CVE-2024-49877, CVE-2024-47692, CVE-2024-50116, CVE-2024-47679, CVE-2024-50134, CVE-2024-50045, CVE-2024-50301, CVE-2024-40965, CVE-2024-47684, CVE-2024-49944, CVE-2024-43863, CVE-2024-50059, CVE-2024-50007, CVE-2024-49973, CVE-2024-50251, CVE-2024-47674, CVE-2024-49982, CVE-2024-50143, CVE-2024-49883, CVE-2024-49851, CVE-2024-44931, CVE-2024-49949, CVE-2024-47747, CVE-2024-46853, CVE-2024-50233, CVE-2024-49924, CVE-2024-50033, CVE-2024-50024, CVE-2024-49995, CVE-2024-47737, CVE-2024-50194, CVE-2024-47712, CVE-2024-50273, CVE-2024-50229, CVE-2024-49896, CVE-2024-50199, CVE-2024-50202, CVE-2024-49868, CVE-2024-50035, CVE-2024-50184, CVE-2024-49882, CVE-2024-49962, CVE-2024-50299, CVE-2024-35887, CVE-2024-50287, CVE-2024-50265, CVE-2024-50148, CVE-2024-47757, CVE-2024-47742, CVE-2024-49902, CVE-2024-50302, CVE-2024-50096, CVE-2024-49952, CVE-2024-50099, CVE-2024-49963, CVE-2024-49900, CVE-2024-46731, CVE-2024-50131, CVE-2024-47723, CVE-2024-50237, CVE-2024-50269, CVE-2024-50142, CVE-2024-49867, CVE-2024-49985, CVE-2024-47670, CVE-2024-50008, CVE-2024-49938, CVE-2024-49878, CVE-2024-49955, CVE-2024-53104, CVE-2024-49894, CVE-2024-50039, CVE-2024-50279, CVE-2024-50006, CVE-2024-40953, CVE-2024-50180, CVE-2024-49860, CVE-2024-50117, CVE-2024-47701, CVE-2024-47698, CVE-2024-50171, CVE-2024-50151, CVE-2024-50082, CVE-2024-50290, CVE-2024-49975, CVE-2024-49903, CVE-2024-38544, CVE-2024-50218, CVE-2024-49948, CVE-2024-50282, CVE-2024-49965, CVE-2024-49959, CVE-2024-42252, CVE-2024-47749, CVE-2024-47756,CVE-2024-47672, CVE-2024-50127, CVE-2024-46854, CVE-2024-50230, CVE-2024-41066, CVE-2024-49957, CVE-2024-47713, CVE-2023-52458, CVE-2024-50167, CVE-2024-49997, CVE-2024-47685, CVE-2024-49879, CVE-2024-53059, CVE-2024-53101, CVE-2024-49958, CVE-2024-47710, CVE-2024-47706, CVE-2024-50074, CVE-2024-50296, CVE-2024-49892, CVE-2024-46849, CVE-2024-50205, CVE-2024-50168, CVE-2024-50267, CVE-2024-50262, CVE-2024-47709, CVE-2024-50195, CVE-2024-35896, CVE-2024-47696, CVE-2024-47740, CVE-2024-40911, CVE-2024-49966, CVE-2021-47469, CVE-2024-49981, CVE-2024-50234, CVE-2024-50179, CVE-2024-47697, CVE-2024-50150, CVE-2023-52917, CVE-2024-50040, CVE-2024-53061, CVE-2024-50278, CVE-2024-47671, CVE-2024-53066, CVE-2024-41016) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.4.0-1138-oracle 5.4.0-1138.147 linux-image-5.4.0-1140-aws 5.4.0-1140.150 linux-image-aws-lts-20.04 5.4.0.1140.137 linux-image-oracle-lts-20.04 5.4.0.1138.131 Ubuntu 18.04 LTS linux-image-5.4.0-1138-oracle 5.4.0-1138.147~18.04.1 Available with Ubuntu Pro linux-image-oracle 5.4.0.1138.147~18.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7294-2 https://ubuntu.com/security/notices/USN-7294-1 CVE-2021-47469, CVE-2023-52458, CVE-2023-52917, CVE-2024-35887, CVE-2024-35896, CVE-2024-38544, CVE-2024-40911,CVE-2024-40953, CVE-2024-40965, CVE-2024-41016, CVE-2024-41066, CVE-2024-42252, CVE-2024-43863, CVE-2024-44931, CVE-2024-46731, CVE-2024-46849, CVE-2024-46853, CVE-2024-46854, CVE-2024-47670, CVE-2024-47671, CVE-2024-47672, CVE-2024-47674, CVE-2024-47679, CVE-2024-47684, CVE-2024-47685, CVE-2024-47692, CVE-2024-47696, CVE-2024-47697, CVE-2024-47698, CVE-2024-47699, CVE-2024-47701, CVE-2024-47706, CVE-2024-47709, CVE-2024-47710, CVE-2024-47712, CVE-2024-47713, CVE-2024-47723, CVE-2024-47737, CVE-2024-47740, CVE-2024-47742, CVE-2024-47747, CVE-2024-47749, CVE-2024-47756, CVE-2024-47757, CVE-2024-49851, CVE-2024-49860, CVE-2024-49867, CVE-2024-49868, CVE-2024-49877, CVE-2024-49878, CVE-2024-49879, CVE-2024-49882, CVE-2024-49883, CVE-2024-49892, CVE-2024-49894, CVE-2024-49896, CVE-2024-49900, CVE-2024-49902, CVE-2024-49903, CVE-2024-49924, CVE-2024-49938, CVE-2024-49944, CVE-2024-49948, CVE-2024-49949, CVE-2024-49952, CVE-2024-49955, CVE-2024-49957, CVE-2024-49958, CVE-2024-49959, CVE-2024-49962, CVE-2024-49963, CVE-2024-49965, CVE-2024-49966, CVE-2024-49973, CVE-2024-49975, CVE-2024-49981, CVE-2024-49982, CVE-2024-49985, CVE-2024-49995, CVE-2024-49997, CVE-2024-50006, CVE-2024-50007, CVE-2024-50008, CVE-2024-50024, CVE-2024-50033, CVE-2024-50035, CVE-2024-50039, CVE-2024-50040, CVE-2024-50044, CVE-2024-50045, CVE-2024-50059, CVE-2024-50074, CVE-2024-50082, CVE-2024-50096, CVE-2024-50099, CVE-2024-50116, CVE-2024-50117, CVE-2024-50127, CVE-2024-50131, CVE-2024-50134, CVE-2024-50142, CVE-2024-50143, CVE-2024-50148, CVE-2024-50150, CVE-2024-50151, CVE-2024-50167, CVE-2024-50168, CVE-2024-50171, CVE-2024-50179, CVE-2024-50180, CVE-2024-50184, CVE-2024-50194, CVE-2024-50195, CVE-2024-50199, CVE-2024-50202, CVE-2024-50205, CVE-2024-50218, CVE-2024-50229, CVE-2024-50230, CVE-2024-50233, CVE-2024-50234, CVE-2024-50236, CVE-2024-50237, CVE-2024-50251, CVE-2024-50262, CVE-2024-50265, CVE-2024-50267, CVE-2024-50269, CVE-2024-50273, CVE-2024-50278, CVE-2024-50279,CVE-2024-50282, CVE-2024-50287, CVE-2024-50290, CVE-2024-50296, CVE-2024-50299, CVE-2024-50301, CVE-2024-50302, CVE-2024-53059, CVE-2024-53061, CVE-2024-53063, CVE-2024-53066, CVE-2024-53101, CVE-2024-53104 Package Information: https://launchpad.net/ubuntu/+source/linux-aws/5.4.0-1140.150 https://launchpad.net/ubuntu/+source/linux-oracle/5.4.0-1138.147 . A recently released security notice outlines critical updates for Ubuntu's Linux core aimed at mitigating several significant vulnerabilities present within the platforms.. Ubuntu Security Advisory,Linux Kernel Update,Linux System Security. . LinuxSecurity.com Team

Calendar%202 Feb 27, 2025 Ubuntu
172

Ubuntu 20.04 LTS: USN-7166-3 Critical: linux-hwe-5.15 Kernel Issues

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7166-3 December 20, 2024 linux-hwe-5.15 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-hwe-5.15: Linux hardware enablement (HWE) kernel Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - RISC-V architecture; - S390 architecture; - x86 architecture; - Block layer subsystem; - ACPI drivers; - Drivers core; - ATA over ethernet (AOE) driver; - TPM device driver; - Clock framework and drivers; - Buffer Sharing and Synchronization framework; - EFI core; - GPIO subsystem; - GPU drivers; - HID subsystem; - I2C subsystem; - InfiniBand drivers; - Input Device core drivers; - Mailbox framework; - Media drivers; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - Microsoft Azure Network Adapter (MANA) driver; - STMicroelectronics network drivers; - NTB driver; - Virtio pmem driver; - PCI subsystem; - x86 platform drivers; - S/390 drivers; - SCSI subsystem; - SPI subsystem; - Thermal drivers; - USB Device Class drivers; - USB Type-C Port Controller Manager driver; - VFIO drivers; - Virtio Host (VHOST) subsystem; - Framebuffer layer; - 9P distributed file system; - BTRFS file system; - Ceph distributed file system; - File systems infrastructure; - Ext4 file system; - F2FS file system; - GFS2 file system; - JFS file system; - Network file system(NFS) client; - Network file system (NFS) server daemon; - NILFS2 file system; - Network file system (NFS) superblock; - Bluetooth subsystem; - Network traffic control; - Network sockets; - TCP network protocol; - BPF subsystem; - Perf events; - Kernel thread helper (kthread); - Padata parallel execution mechanism; - Arbitrary resource management; - Static call mechanism; - Tracing infrastructure; - Memory management; - Ethernet bridge; - CAN network layer; - Networking core; - IPv4 networking; - IPv6 networking; - MAC80211 subsystem; - Multipath TCP; - Netfilter; - Netlink; - SCTP protocol; - TIPC protocol; - SELinux security module; - Simplified Mandatory Access Control Kernel framework; - AudioScience HPI driver; - Amlogic Meson SoC drivers; - USB sound devices; (CVE-2024-49944, CVE-2024-49907, CVE-2024-50062, CVE-2024-36893, CVE-2024-49985, CVE-2024-49903, CVE-2024-49886, CVE-2024-50180, CVE-2024-47757, CVE-2024-49938, CVE-2024-49902, CVE-2024-47709, CVE-2024-49884, CVE-2024-49967, CVE-2024-49977, CVE-2024-47734, CVE-2024-49954, CVE-2024-49963, CVE-2024-47747, CVE-2024-50008, CVE-2024-47696, CVE-2024-50038, CVE-2024-46695, CVE-2024-47705, CVE-2024-49957, CVE-2024-38538, CVE-2024-50019, CVE-2024-38544, CVE-2024-50003, CVE-2024-50095, CVE-2024-50000, CVE-2024-49981, CVE-2024-49863, CVE-2024-47710, CVE-2024-49983, CVE-2024-26947, CVE-2024-46852, CVE-2024-49871, CVE-2024-49936, CVE-2024-47720, CVE-2024-49881, CVE-2024-47672, CVE-2024-50040, CVE-2024-49997, CVE-2024-50044, CVE-2023-52532, CVE-2024-47740, CVE-2024-44942, CVE-2024-49948, CVE-2023-52621, CVE-2024-49959, CVE-2024-47718, CVE-2024-50188, CVE-2024-47699, CVE-2024-47756, CVE-2024-47723, CVE-2024-46849, CVE-2024-50035, CVE-2024-50189, CVE-2024-47684, CVE-2024-49900, CVE-2024-50024, CVE-2024-49851, CVE-2024-49860, CVE-2024-49924, CVE-2024-49946, CVE-2024-44940, CVE-2023-52904, CVE-2024-47679, CVE-2024-47748,CVE-2023-52917, CVE-2024-47735, CVE-2024-46858, CVE-2024-35904, CVE-2024-47673, CVE-2024-49878, CVE-2024-47739, CVE-2024-49973, CVE-2024-49935, CVE-2024-49875, CVE-2024-49896, CVE-2024-47690, CVE-2024-50007, CVE-2024-49933, CVE-2024-49958, CVE-2024-49913, CVE-2024-49883, CVE-2024-47742, CVE-2024-41016, CVE-2024-50002, CVE-2024-49969, CVE-2024-46853, CVE-2024-50031, CVE-2024-47698, CVE-2024-47749, CVE-2024-50059, CVE-2024-49966, CVE-2024-50093, CVE-2024-27072, CVE-2024-50186, CVE-2024-49895, CVE-2024-38632, CVE-2024-49995, CVE-2024-38545, CVE-2024-38667, CVE-2024-36968, CVE-2024-49952, CVE-2024-50001, CVE-2024-47697, CVE-2024-50045, CVE-2024-49856, CVE-2024-49852, CVE-2024-47712, CVE-2023-52639, CVE-2024-49975, CVE-2024-42158, CVE-2024-49962, CVE-2024-50181, CVE-2024-42156, CVE-2024-46855, CVE-2024-47693, CVE-2024-47670, CVE-2024-47706, CVE-2024-50184, CVE-2024-49965, CVE-2024-39463, CVE-2024-50191, CVE-2024-49866, CVE-2024-49890, CVE-2024-49877, CVE-2024-49879, CVE-2024-49927, CVE-2024-50039, CVE-2024-46859, CVE-2024-47674, CVE-2024-50096, CVE-2024-50013, CVE-2024-46854, CVE-2024-49868, CVE-2024-49882, CVE-2024-47671, CVE-2024-50179, CVE-2024-44931, CVE-2024-50046, CVE-2024-50006, CVE-2024-49892, CVE-2024-49949, CVE-2024-42079, CVE-2024-46865, CVE-2024-47692, CVE-2024-47713, CVE-2024-47701, CVE-2024-49889, CVE-2024-49894, CVE-2024-50015, CVE-2024-49858, CVE-2024-49955, CVE-2024-49867, CVE-2024-35951, CVE-2024-50033, CVE-2024-49982, CVE-2024-47695, CVE-2024-50049, CVE-2024-49930, CVE-2024-50041, CVE-2024-47737, CVE-2024-47685) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.15.0-127-generic 5.15.0-127.137~20.04.1 linux-image-5.15.0-127-generic-64k 5.15.0-127.137~20.04.1 linux-image-5.15.0-127-generic-lpae 5.15.0-127.137~20.04.1 linux-image-generic-64k-hwe-20.04 5.15.0.127.137~20.04.1 linux-image-generic-hwe-20.04 5.15.0.127.137~20.04.1 linux-image-generic-lpae-hwe-20.04 5.15.0.127.137~20.04.1 linux-image-oem-20.04 5.15.0.127.137~20.04.1 linux-image-oem-20.04b 5.15.0.127.137~20.04.1 linux-image-oem-20.04c 5.15.0.127.137~20.04.1 linux-image-oem-20.04d 5.15.0.127.137~20.04.1 linux-image-virtual-hwe-20.04 5.15.0.127.137~20.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7166-3 https://ubuntu.com/security/notices/USN-7166-2 https://ubuntu.com/security/notices/USN-7166-1 CVE-2023-52532, CVE-2023-52621, CVE-2023-52639, CVE-2023-52904, CVE-2023-52917, CVE-2024-26947, CVE-2024-27072, CVE-2024-35904, CVE-2024-35951, CVE-2024-36893, CVE-2024-36968, CVE-2024-38538, CVE-2024-38544, CVE-2024-38545, CVE-2024-38632, CVE-2024-38667, CVE-2024-39463, CVE-2024-41016, CVE-2024-42079, CVE-2024-42156, CVE-2024-42158, CVE-2024-44931, CVE-2024-44940, CVE-2024-44942, CVE-2024-46695, CVE-2024-46849, CVE-2024-46852, CVE-2024-46853, CVE-2024-46854, CVE-2024-46855, CVE-2024-46858, CVE-2024-46859, CVE-2024-46865, CVE-2024-47670, CVE-2024-47671, CVE-2024-47672, CVE-2024-47673, CVE-2024-47674, CVE-2024-47679, CVE-2024-47684, CVE-2024-47685, CVE-2024-47690, CVE-2024-47692, CVE-2024-47693, CVE-2024-47695, CVE-2024-47696, CVE-2024-47697, CVE-2024-47698, CVE-2024-47699, CVE-2024-47701, CVE-2024-47705, CVE-2024-47706, CVE-2024-47709, CVE-2024-47710, CVE-2024-47712, CVE-2024-47713, CVE-2024-47718, CVE-2024-47720,CVE-2024-47723, CVE-2024-47734, CVE-2024-47735, CVE-2024-47737, CVE-2024-47739, CVE-2024-47740, CVE-2024-47742, CVE-2024-47747, CVE-2024-47748, CVE-2024-47749, CVE-2024-47756, CVE-2024-47757, CVE-2024-49851, CVE-2024-49852, CVE-2024-49856, CVE-2024-49858, CVE-2024-49860, CVE-2024-49863, CVE-2024-49866, CVE-2024-49867, CVE-2024-49868, CVE-2024-49871, CVE-2024-49875, CVE-2024-49877, CVE-2024-49878, CVE-2024-49879, CVE-2024-49881, CVE-2024-49882, CVE-2024-49883, CVE-2024-49884, CVE-2024-49886, CVE-2024-49889, CVE-2024-49890, CVE-2024-49892, CVE-2024-49894, CVE-2024-49895, CVE-2024-49896, CVE-2024-49900, CVE-2024-49902, CVE-2024-49903, CVE-2024-49907, CVE-2024-49913, CVE-2024-49924, CVE-2024-49927, CVE-2024-49930, CVE-2024-49933, CVE-2024-49935, CVE-2024-49936, CVE-2024-49938, CVE-2024-49944, CVE-2024-49946, CVE-2024-49948, CVE-2024-49949, CVE-2024-49952, CVE-2024-49954, CVE-2024-49955, CVE-2024-49957, CVE-2024-49958, CVE-2024-49959, CVE-2024-49962, CVE-2024-49963, CVE-2024-49965, CVE-2024-49966, CVE-2024-49967, CVE-2024-49969, CVE-2024-49973, CVE-2024-49975, CVE-2024-49977, CVE-2024-49981, CVE-2024-49982, CVE-2024-49983, CVE-2024-49985, CVE-2024-49995, CVE-2024-49997, CVE-2024-50000, CVE-2024-50001, CVE-2024-50002, CVE-2024-50003, CVE-2024-50006, CVE-2024-50007, CVE-2024-50008, CVE-2024-50013, CVE-2024-50015, CVE-2024-50019, CVE-2024-50024, CVE-2024-50031, CVE-2024-50033, CVE-2024-50035, CVE-2024-50038, CVE-2024-50039, CVE-2024-50040, CVE-2024-50041, CVE-2024-50044, CVE-2024-50045, CVE-2024-50046, CVE-2024-50049, CVE-2024-50059, CVE-2024-50062, CVE-2024-50093, CVE-2024-50095, CVE-2024-50096, CVE-2024-50179, CVE-2024-50180, CVE-2024-50181, CVE-2024-50184, CVE-2024-50186, CVE-2024-50188, CVE-2024-50189, CVE-2024-50191 Package Information: https://launchpad.net/ubuntu/+source/linux-hwe-5.15/5.15.0-127.137~20.04.1 . The newest Fedora bulletin tackles various core vulnerabilities, offering essentialpatches for improved protection.. Ubuntu security, kernel update, HWE, system vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 20, 2024 Critical Ubuntu
89

Fedora 32: FEDORA-2020-23432b7b72 Critical Buffer Overflow Fix

Fix buffer overflow (RHBZ #1897485) A global buffer overflow was discovered in the check_chunk_name function via a crafted png file.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-23432b7b72 2020-11-22 01:20:51.854150 --------------------------------------------------------------------------------Name : pngcheck Product : Fedora 32 Version : 2.3.0 Release : 4.fc32 URL : http://www.libpng.org/pub/png/apps/pngcheck.html Summary : Verifies the integrity of PNG, JNG and MNG files Description : pngcheck verifies the integrity of PNG, JNG and MNG files (by checking the internal 32-bit CRCs [checksums] and decompressing the image data); it can optionally dump almost all of the chunk-level information in the image in human-readable form. For example, it can be used to print the basic statistics about an image (dimensions, bit depth, etc.); to list the color and transparency info in its palette (assuming it has one); or to extract the embedded text annotations. This is a command-line program with batch capabilities. The current release supports all PNG, MNG and JNG chunks, including the newly approved sTER stereo-layout chunk. It correctly reports errors in all but two of the images in Chris Nokleberg's brokensuite-20061204. --------------------------------------------------------------------------------Update Information: Fix buffer overflow (RHBZ #1897485) A global buffer overflow was discovered in the check_chunk_name function via a crafted png file. --------------------------------------------------------------------------------ChangeLog: * Fri Nov 13 2020 Benjamin A. Beasley - 2.3.0-4 - Fix buffer overflow (RHBZ #1897485) --------------------------------------------------------------------------------References: [ 1 ] Bug #1897485 - Private bug https://bugzilla.redhat.com/show_bug.cgi?id=1897485 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-23432b7b72' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Correction implemented for the global buffer overflow within the pngcheck operation to guarantee file safety. Prompt upgrade is advised for all users.. pngcheck Update, Fedora Notification, Buffer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 21, 2020 Critical Fedora
202

openSUSE Leap 15.0: 2019:2629-1 Low Severity: libxml2 Security Update

An update that contains security fixes can now be installed.. openSUSE Security Update: Security update for libxml2 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:2629-1 Rating: low References: #1123919 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for libxml2 doesn't fix any additional security issues, but correct its rpm changelog to reflect all CVEs that have been fixed over the past. This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-2629=1 Package List: - openSUSE Leap 15.0 (i586 x86_64): libxml2-2-2.9.7-lp150.2.14.1 libxml2-2-debuginfo-2.9.7-lp150.2.14.1 libxml2-debugsource-2.9.7-lp150.2.14.1 libxml2-devel-2.9.7-lp150.2.14.1 libxml2-tools-2.9.7-lp150.2.14.1 libxml2-tools-debuginfo-2.9.7-lp150.2.14.1 - openSUSE Leap 15.0 (noarch): libxml2-doc-2.9.7-lp150.2.14.1 - openSUSE Leap 15.0 (x86_64): libxml2-2-32bit-2.9.7-lp150.2.14.1 libxml2-2-32bit-debuginfo-2.9.7-lp150.2.14.1 libxml2-devel-32bit-2.9.7-lp150.2.14.1 References: https://bugzilla.suse.com/1123919 -- . Critical patch for libxml2 package on openSUSE Leap 15.0. Updates address known CVE vulnerabilities and outline installation procedures.. openSUSE updates, libxml2 security, openSUSE patches. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Dec 03, 2019 Low OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200