Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7496-2 May 07, 2025 linux-aws-fips, linux-fips, linux-gcp-fips vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-aws-fips: Linux kernel for Amazon Web Services (AWS) systems with FIPS - linux-fips: Linux kernel with FIPS - linux-gcp-fips: Linux kernel for Google Cloud Platform (GCP) systems with FIPS Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Block layer subsystem; - Character device driver; - Hardware crypto device drivers; - GPU drivers; - Media drivers; - Network drivers; - SCSI subsystem; - USB Gadget drivers; - Framebuffer layer; - Ceph distributed file system; - File systems infrastructure; - JFS file system; - Network file system (NFS) client; - NILFS2 file system; - SMB network file system; - Netfilter; - CAN network layer; - IPv6 networking; - MAC80211 subsystem; - Netlink; - Network traffic control; - SCTP protocol; - TIPC protocol; (CVE-2023-52664, CVE-2024-26974, CVE-2024-49944, CVE-2024-50256, CVE-2024-35864, CVE-2025-21971, CVE-2023-52741, CVE-2024-50296, CVE-2024-50237, CVE-2021-47191, CVE-2024-46771, CVE-2024-56770, CVE-2021-47163, CVE-2024-53063, CVE-2024-53140, CVE-2024-36015, CVE-2024-56650, CVE-2024-53173, CVE-2024-53066, CVE-2024-26689, CVE-2024-56651, CVE-2024-36934, CVE-2024-56598, CVE-2021-47219, CVE-2024-26915, CVE-2024-46780, CVE-2024-49925, CVE-2023-52458, CVE-2021-47150, CVE-2024-56631, CVE-2024-26996, CVE-2023-52927, CVE-2024-56642) Update instructions: The problem can be corrected by updating yoursystem to the following package versions: Ubuntu 18.04 LTS linux-image-4.15.0-1135-fips 4.15.0-1135.146 Available with Ubuntu Pro linux-image-4.15.0-2081-gcp-fips 4.15.0-2081.87 Available with Ubuntu Pro linux-image-4.15.0-2118-aws-fips 4.15.0-2118.124 Available with Ubuntu Pro linux-image-aws-fips 4.15.0.2118.112 Available with Ubuntu Pro linux-image-fips 4.15.0.1135.132 Available with Ubuntu Pro linux-image-gcp-fips 4.15.0.2081.79 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7496-2 https://ubuntu.com/security/notices/USN-7496-1 CVE-2021-47150, CVE-2021-47163, CVE-2021-47191, CVE-2021-47219, CVE-2023-52458, CVE-2023-52664, CVE-2023-52741, CVE-2023-52927, CVE-2024-26689, CVE-2024-26915, CVE-2024-26974, CVE-2024-26996, CVE-2024-35864, CVE-2024-36015, CVE-2024-36934, CVE-2024-46771, CVE-2024-46780, CVE-2024-49925, CVE-2024-49944, CVE-2024-50237, CVE-2024-50256, CVE-2024-50296, CVE-2024-53063, CVE-2024-53066, CVE-2024-53140, CVE-2024-53173, CVE-2024-56598, CVE-2024-56631, CVE-2024-56642, CVE-2024-56650, CVE-2024-56651, CVE-2024-56770, CVE-2025-21971 Package Information: . Crucial enhancements for Ubuntu 18.04 LTS kernel boost system defenses against multiple vulnerabilities. Promptresponse advised!. Linux Kernel, Ubuntu Security Updates, System Security, Linux FIPS Update. . Severity: Critical. LinuxSecurity.com Team
An update that solves 11 vulnerabilities can now be installed.. # MozillaThunderbird-128.7.0-1.1 on GA media Announcement ID: openSUSE-SU-2025:14731-1 Rating: moderate Cross-References: * CVE-2024-11704 * CVE-2025-0510 * CVE-2025-1009 * CVE-2025-1010 * CVE-2025-1011 * CVE-2025-1012 * CVE-2025-1013 * CVE-2025-1014 * CVE-2025-1015 * CVE-2025-1016 * CVE-2025-1017 CVSS scores: * CVE-2025-0510 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-1009 ( SUSE ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2025-1010 ( SUSE ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2025-1011 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-1012 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-1013 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2025-1014 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2025-1015 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-1016 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-1017 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Tumbleweed An update that solves 11 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the MozillaThunderbird-128.7.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * MozillaThunderbird 128.7.0-1.1 * MozillaThunderbird-openpgp-librnp 128.7.0-1.1 * MozillaThunderbird-translations-common 128.7.0-1.1 * MozillaThunderbird-translations-other 128.7.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-11704.html * https://www.suse.com/security/cve/CVE-2025-0510.html * https://www.suse.com/security/cve/CVE-2025-1009.html * https://www.suse.com/security/cve/CVE-2025-1010.html * https://www.suse.com/security/cve/CVE-2025-1011.html * https://www.suse.com/security/cve/CVE-2025-1012.html *https://www.suse.com/security/cve/CVE-2025-1013.html * https://www.suse.com/security/cve/CVE-2025-1014.html * https://www.suse.com/security/cve/CVE-2025-1015.html * https://www.suse.com/security/cve/CVE-2025-1016.html * https://www.suse.com/security/cve/CVE-2025-1017.html . A new update has been released for Mozilla Thunderbird, which tackles various security vulnerabilities on openSUSE Tumbleweed.. MozillaThunderbird, openSUSE, security update, advisory, software patch. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-10791 http://linux.oracle.com/errata/ELSA-2024-10791.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: postgresql-13.18-1.el9_5.x86_64.rpm postgresql-contrib-13.18-1.el9_5.x86_64.rpm postgresql-plperl-13.18-1.el9_5.x86_64.rpm postgresql-plpython3-13.18-1.el9_5.x86_64.rpm postgresql-pltcl-13.18-1.el9_5.x86_64.rpm postgresql-private-libs-13.18-1.el9_5.x86_64.rpm postgresql-server-13.18-1.el9_5.x86_64.rpm postgresql-upgrade-13.18-1.el9_5.x86_64.rpm postgresql-docs-13.18-1.el9_5.x86_64.rpm postgresql-private-devel-13.18-1.el9_5.x86_64.rpm postgresql-server-devel-13.18-1.el9_5.x86_64.rpm postgresql-static-13.18-1.el9_5.x86_64.rpm postgresql-test-13.18-1.el9_5.x86_64.rpm postgresql-test-rpm-macros-13.18-1.el9_5.noarch.rpm postgresql-upgrade-devel-13.18-1.el9_5.x86_64.rpm aarch64: postgresql-13.18-1.el9_5.aarch64.rpm postgresql-contrib-13.18-1.el9_5.aarch64.rpm postgresql-plperl-13.18-1.el9_5.aarch64.rpm postgresql-plpython3-13.18-1.el9_5.aarch64.rpm postgresql-pltcl-13.18-1.el9_5.aarch64.rpm postgresql-private-libs-13.18-1.el9_5.aarch64.rpm postgresql-server-13.18-1.el9_5.aarch64.rpm postgresql-upgrade-13.18-1.el9_5.aarch64.rpm postgresql-docs-13.18-1.el9_5.aarch64.rpm postgresql-private-devel-13.18-1.el9_5.aarch64.rpm postgresql-server-devel-13.18-1.el9_5.aarch64.rpm postgresql-static-13.18-1.el9_5.aarch64.rpm postgresql-test-13.18-1.el9_5.aarch64.rpm postgresql-test-rpm-macros-13.18-1.el9_5.noarch.rpm postgresql-upgrade-devel-13.18-1.el9_5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//postgresql-13.18-1.el9_5.src.rpm Related CVEs: CVE-2024-10976 CVE-2024-10978 CVE-2024-10979 Description of changes: [13.18-1] - Update to 13.18 _______________________________________________ El-errata mailing list
The Qualys Threat Research Unit discovered that libmodule-scandeps-perl, a Perl module to recursively scan Perl code for dependencies, allows an attacker to execute arbitrary shell commands via specially crafted file names. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3958-1
A vulnerability has been found in libgit2 which could result in privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202401-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libgit2: Privilege Escalation Vulnerability Date: January 14, 2024 Bugs: #857792 ID: 202401-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been found in libgit2 which could result in privilege escalation. Background ========== libgit2 is a portable, pure C implementation of the Git core methods provided as a re-entrant linkable library with a solid API. Affected packages ================= Package Vulnerable Unaffected ---------------- ------------ ------------ dev-libs/libgit2 < 1.4.4 > = 1.4.4 Description =========== A vulnerability has been discovered in libgit2. Please review the CVE identifier referenced below for details. Impact ====== Usages of a malicious crafted Git repository could allow the creator of the repository to elevate privileges to those of the user accessing the repository. Workaround ========== Administrators can ensure that their usages of libgit2 only interact with repositories which have only been modified by trusted users. Resolution ========== All libgit2 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/libgit2-1.4.4" References ========== [ 1 ] CVE-2022-29187 https://nvd.nist.gov/vuln/detail/CVE-2022-29187 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202401-17 Concerns? ========= Security is a primary focus of GentooLinux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
* bsc#1217592 Cross-References: * CVE-2023-49083 . # Security update for python-cryptography Announcement ID: SUSE-SU-2023:4921-1 Rating: moderate References: * bsc#1217592 Cross-References: * CVE-2023-49083 CVSS scores: * CVE-2023-49083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-49083 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves one vulnerability can now be installed. ## Description: This update for python-cryptography fixes the following issues: * CVE-2023-49083: Fixed a NULL pointer dereference when loading certificates from a PKCS#7 bundle (bsc#1217592). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2023-4921=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-4921=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-4921=1 ## Package List: * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * python-cryptography-debugsource-3.3.2-150200.22.1 * python-cryptography-debuginfo-3.3.2-150200.22.1 * python3-cryptography-debuginfo-3.3.2-150200.22.1 * python3-cryptography-3.3.2-150200.22.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * python-cryptography-debugsource-3.3.2-150200.22.1 * python-cryptography-debuginfo-3.3.2-150200.22.1 * python3-cryptography-debuginfo-3.3.2-150200.22.1 * python3-cryptography-3.3.2-150200.22.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * python-cryptography-debugsource-3.3.2-150200.22.1 *python-cryptography-debuginfo-3.3.2-150200.22.1 * python3-cryptography-debuginfo-3.3.2-150200.22.1 * python3-cryptography-3.3.2-150200.22.1 ## References: * https://www.suse.com/security/cve/CVE-2023-49083.html * https://bugzilla.suse.com/show_bug.cgi?id=1217592 . SUSE has issued a security notice regarding the python-cryptography flaw CVE-2023-49083. It is crucial for users to perform updates without delay.. SUSE Linux Enterprise Micro, Python Cryptography Update, Security Patch. . LinuxSecurity.com Team
**MySQL 8.0.27** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-27.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-46dc82116b 2021-11-10 02:52:52.381127 --------------------------------------------------------------------------------Name : community-mysql Product : Fedora 35 Version : 8.0.27 Release : 1.fc35 URL : https://www.mysql.com/ Summary : MySQL client programs and shared libraries Description : MySQL is a multi-user, multi-threaded SQL database server. MySQL is a client/server implementation consisting of a server daemon (mysqld) and many different client programs and libraries. The base package contains the standard MySQL client programs and generic MySQL files. --------------------------------------------------------------------------------Update Information: **MySQL 8.0.27** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-27.html --------------------------------------------------------------------------------ChangeLog: * Sun Oct 31 2021 Lars Tangvald - 8.0.27-1 - Update to MySQL 8.0.27 --------------------------------------------------------------------------------References: [ 1 ] Bug #2015421 - community-mysql-8.0.27 is available https://bugzilla.redhat.com/show_bug.cgi?id=2015421 [ 2 ] Bug #2016141 - CVE-2021-2478 CVE-2021-2479 CVE-2021-2481 CVE-2021-35546 CVE-2021-35575 CVE-2021-35577 CVE-2021-35591 CVE-2021-35596 CVE-2021-35597 CVE-2021-35602 CVE-2021-35604 CVE-2021-35607 CVE-2021-35608 CVE-2021-35610 ... community-mysql: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2016141 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-46dc82116b' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Multiple vulnerabilities have been found in NodeJS, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202101-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: NodeJS: Multiple vulnerabilities Date: January 11, 2021 Bugs: #726836, #731654, #742893, #754942, #763588 ID: 202101-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in NodeJS, the worst of which could result in the arbitrary execution of code. Background ========= Node.js is a JavaScript runtime built on Chrome’s V8 JavaScript engine. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-libs/nodejs < 15.5.1 > = 12.20.1:0/12 > = 14.15.1:0/14 > = 15.5.1:0/15 Description ========== Multiple vulnerabilities have been discovered in NodeJS. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All NodeJS 15 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-libs/nodejs-15.5.1" All NodeJS 14 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-libs/nodejs-14.15.1" References ========= [ 1 ]CVE-2020-15095 https://nvd.nist.gov/vuln/detail/CVE-2020-15095 [ 2 ] CVE-2020-8172 https://nvd.nist.gov/vuln/detail/CVE-2020-8172 [ 3 ] CVE-2020-8174 https://nvd.nist.gov/vuln/detail/CVE-2020-8174 [ 4 ] CVE-2020-8201 https://nvd.nist.gov/vuln/detail/CVE-2020-8201 [ 5 ] CVE-2020-8251 https://nvd.nist.gov/vuln/detail/CVE-2020-8251 [ 6 ] CVE-2020-8265 https://nvd.nist.gov/vuln/detail/CVE-2020-8265 [ 7 ] CVE-2020-8277 https://nvd.nist.gov/vuln/detail/CVE-2020-8277 [ 8 ] CVE-2020-8287 https://nvd.nist.gov/vuln/detail/CVE-2020-8287 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202101-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.