Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 6 articles for you...
172

Ubuntu 18.04 LTS USN-7496-2 critical: Linux kernel FIPS update

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7496-2 May 07, 2025 linux-aws-fips, linux-fips, linux-gcp-fips vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-aws-fips: Linux kernel for Amazon Web Services (AWS) systems with FIPS - linux-fips: Linux kernel with FIPS - linux-gcp-fips: Linux kernel for Google Cloud Platform (GCP) systems with FIPS Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Block layer subsystem; - Character device driver; - Hardware crypto device drivers; - GPU drivers; - Media drivers; - Network drivers; - SCSI subsystem; - USB Gadget drivers; - Framebuffer layer; - Ceph distributed file system; - File systems infrastructure; - JFS file system; - Network file system (NFS) client; - NILFS2 file system; - SMB network file system; - Netfilter; - CAN network layer; - IPv6 networking; - MAC80211 subsystem; - Netlink; - Network traffic control; - SCTP protocol; - TIPC protocol; (CVE-2023-52664, CVE-2024-26974, CVE-2024-49944, CVE-2024-50256, CVE-2024-35864, CVE-2025-21971, CVE-2023-52741, CVE-2024-50296, CVE-2024-50237, CVE-2021-47191, CVE-2024-46771, CVE-2024-56770, CVE-2021-47163, CVE-2024-53063, CVE-2024-53140, CVE-2024-36015, CVE-2024-56650, CVE-2024-53173, CVE-2024-53066, CVE-2024-26689, CVE-2024-56651, CVE-2024-36934, CVE-2024-56598, CVE-2021-47219, CVE-2024-26915, CVE-2024-46780, CVE-2024-49925, CVE-2023-52458, CVE-2021-47150, CVE-2024-56631, CVE-2024-26996, CVE-2023-52927, CVE-2024-56642) Update instructions: The problem can be corrected by updating yoursystem to the following package versions: Ubuntu 18.04 LTS linux-image-4.15.0-1135-fips 4.15.0-1135.146 Available with Ubuntu Pro linux-image-4.15.0-2081-gcp-fips 4.15.0-2081.87 Available with Ubuntu Pro linux-image-4.15.0-2118-aws-fips 4.15.0-2118.124 Available with Ubuntu Pro linux-image-aws-fips 4.15.0.2118.112 Available with Ubuntu Pro linux-image-fips 4.15.0.1135.132 Available with Ubuntu Pro linux-image-gcp-fips 4.15.0.2081.79 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7496-2 https://ubuntu.com/security/notices/USN-7496-1 CVE-2021-47150, CVE-2021-47163, CVE-2021-47191, CVE-2021-47219, CVE-2023-52458, CVE-2023-52664, CVE-2023-52741, CVE-2023-52927, CVE-2024-26689, CVE-2024-26915, CVE-2024-26974, CVE-2024-26996, CVE-2024-35864, CVE-2024-36015, CVE-2024-36934, CVE-2024-46771, CVE-2024-46780, CVE-2024-49925, CVE-2024-49944, CVE-2024-50237, CVE-2024-50256, CVE-2024-50296, CVE-2024-53063, CVE-2024-53066, CVE-2024-53140, CVE-2024-53173, CVE-2024-56598, CVE-2024-56631, CVE-2024-56642, CVE-2024-56650, CVE-2024-56651, CVE-2024-56770, CVE-2025-21971 Package Information: . Crucial enhancements for Ubuntu 18.04 LTS kernel boost system defenses against multiple vulnerabilities. Promptresponse advised!. Linux Kernel, Ubuntu Security Updates, System Security, Linux FIPS Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 07, 2025 Critical Ubuntu
202

openSUSE Tumbleweed: 2025:14731-1 moderate: Mozilla Thunderbird Update

An update that solves 11 vulnerabilities can now be installed.. # MozillaThunderbird-128.7.0-1.1 on GA media Announcement ID: openSUSE-SU-2025:14731-1 Rating: moderate Cross-References: * CVE-2024-11704 * CVE-2025-0510 * CVE-2025-1009 * CVE-2025-1010 * CVE-2025-1011 * CVE-2025-1012 * CVE-2025-1013 * CVE-2025-1014 * CVE-2025-1015 * CVE-2025-1016 * CVE-2025-1017 CVSS scores: * CVE-2025-0510 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2025-1009 ( SUSE ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2025-1010 ( SUSE ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2025-1011 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-1012 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-1013 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2025-1014 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2025-1015 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-1016 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-1017 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Tumbleweed An update that solves 11 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the MozillaThunderbird-128.7.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * MozillaThunderbird 128.7.0-1.1 * MozillaThunderbird-openpgp-librnp 128.7.0-1.1 * MozillaThunderbird-translations-common 128.7.0-1.1 * MozillaThunderbird-translations-other 128.7.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-11704.html * https://www.suse.com/security/cve/CVE-2025-0510.html * https://www.suse.com/security/cve/CVE-2025-1009.html * https://www.suse.com/security/cve/CVE-2025-1010.html * https://www.suse.com/security/cve/CVE-2025-1011.html * https://www.suse.com/security/cve/CVE-2025-1012.html *https://www.suse.com/security/cve/CVE-2025-1013.html * https://www.suse.com/security/cve/CVE-2025-1014.html * https://www.suse.com/security/cve/CVE-2025-1015.html * https://www.suse.com/security/cve/CVE-2025-1016.html * https://www.suse.com/security/cve/CVE-2025-1017.html . A new update has been released for Mozilla Thunderbird, which tackles various security vulnerabilities on openSUSE Tumbleweed.. MozillaThunderbird, openSUSE, security update, advisory, software patch. . LinuxSecurity.com Team

Calendar%202 Feb 06, 2025 OpenSUSE
217

Oracle Linux 9: ELSA-2024-10791 moderate: PostgreSQL security issues

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-10791 http://linux.oracle.com/errata/ELSA-2024-10791.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: postgresql-13.18-1.el9_5.x86_64.rpm postgresql-contrib-13.18-1.el9_5.x86_64.rpm postgresql-plperl-13.18-1.el9_5.x86_64.rpm postgresql-plpython3-13.18-1.el9_5.x86_64.rpm postgresql-pltcl-13.18-1.el9_5.x86_64.rpm postgresql-private-libs-13.18-1.el9_5.x86_64.rpm postgresql-server-13.18-1.el9_5.x86_64.rpm postgresql-upgrade-13.18-1.el9_5.x86_64.rpm postgresql-docs-13.18-1.el9_5.x86_64.rpm postgresql-private-devel-13.18-1.el9_5.x86_64.rpm postgresql-server-devel-13.18-1.el9_5.x86_64.rpm postgresql-static-13.18-1.el9_5.x86_64.rpm postgresql-test-13.18-1.el9_5.x86_64.rpm postgresql-test-rpm-macros-13.18-1.el9_5.noarch.rpm postgresql-upgrade-devel-13.18-1.el9_5.x86_64.rpm aarch64: postgresql-13.18-1.el9_5.aarch64.rpm postgresql-contrib-13.18-1.el9_5.aarch64.rpm postgresql-plperl-13.18-1.el9_5.aarch64.rpm postgresql-plpython3-13.18-1.el9_5.aarch64.rpm postgresql-pltcl-13.18-1.el9_5.aarch64.rpm postgresql-private-libs-13.18-1.el9_5.aarch64.rpm postgresql-server-13.18-1.el9_5.aarch64.rpm postgresql-upgrade-13.18-1.el9_5.aarch64.rpm postgresql-docs-13.18-1.el9_5.aarch64.rpm postgresql-private-devel-13.18-1.el9_5.aarch64.rpm postgresql-server-devel-13.18-1.el9_5.aarch64.rpm postgresql-static-13.18-1.el9_5.aarch64.rpm postgresql-test-13.18-1.el9_5.aarch64.rpm postgresql-test-rpm-macros-13.18-1.el9_5.noarch.rpm postgresql-upgrade-devel-13.18-1.el9_5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//postgresql-13.18-1.el9_5.src.rpm Related CVEs: CVE-2024-10976 CVE-2024-10978 CVE-2024-10979 Description of changes: [13.18-1] - Update to 13.18 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . The OracleLinux Security Advisory ELSA-2024-10792 introduces critical updates for PostgreSQL that rectify major security vulnerabilities.. Oracle Linux Security, PostgreSQL Security, Linux Updates, Security Advisory, Threat Management. . LinuxSecurity.com Team

Calendar%202 Dec 13, 2024 Oracle
197

Debian 11: DLA-3958-1 critical vulnerability in libmodule-scandeps-perl

The Qualys Threat Research Unit discovered that libmodule-scandeps-perl, a Perl module to recursively scan Perl code for dependencies, allows an attacker to execute arbitrary shell commands via specially crafted file names. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3958-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Salvatore Bonaccorso November 19, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libmodule-scandeps-perl Version : 1.30-1+deb11u1 CVE ID : CVE-2024-10224 The Qualys Threat Research Unit discovered that libmodule-scandeps-perl, a Perl module to recursively scan Perl code for dependencies, allows an attacker to execute arbitrary shell commands via specially crafted file names. Details can be found in the Qualys advisory at https:// For Debian 11 bullseye, this problem has been fixed in version 1.30-1+deb11u1. We recommend that you upgrade your libmodule-scandeps-perl packages. For the detailed security status of libmodule-scandeps-perl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libmodule-scandeps-perl Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Debian LTS Advisory DLA-3958-1 highlights vulnerabilities in libmodule-scandeps-perl that could enable unauthorized shell command execution.. libmodule-scandeps-perl, security update, debian advisory, threat research. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 19, 2024 Critical Debian LTS
91

Gentoo: 202401-17 normal: privilege escalation vulnerability in libgit2

A vulnerability has been found in libgit2 which could result in privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202401-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libgit2: Privilege Escalation Vulnerability Date: January 14, 2024 Bugs: #857792 ID: 202401-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been found in libgit2 which could result in privilege escalation. Background ========== libgit2 is a portable, pure C implementation of the Git core methods provided as a re-entrant linkable library with a solid API. Affected packages ================= Package Vulnerable Unaffected ---------------- ------------ ------------ dev-libs/libgit2 < 1.4.4 > = 1.4.4 Description =========== A vulnerability has been discovered in libgit2. Please review the CVE identifier referenced below for details. Impact ====== Usages of a malicious crafted Git repository could allow the creator of the repository to elevate privileges to those of the user accessing the repository. Workaround ========== Administrators can ensure that their usages of libgit2 only interact with repositories which have only been modified by trusted users. Resolution ========== All libgit2 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/libgit2-1.4.4" References ========== [ 1 ] CVE-2022-29187 https://nvd.nist.gov/vuln/detail/CVE-2022-29187 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202401-17 Concerns? ========= Security is a primary focus of GentooLinux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo Linux Advisory GLSA 202401-18 alerts on a security vulnerability in libxml2, which could lead to unauthorized access and significant security concerns.. Gentoo Linux, Privilege Escalation, libgit2, Security Advisory, GLSA. . LinuxSecurity.com Team

Calendar%202 Jan 14, 2024 Gentoo
100

SUSE: 2023:4922-1 moderate: python-cryptography buffer overflow

* bsc#1217592 Cross-References: * CVE-2023-49083 . # Security update for python-cryptography Announcement ID: SUSE-SU-2023:4921-1 Rating: moderate References: * bsc#1217592 Cross-References: * CVE-2023-49083 CVSS scores: * CVE-2023-49083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-49083 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves one vulnerability can now be installed. ## Description: This update for python-cryptography fixes the following issues: * CVE-2023-49083: Fixed a NULL pointer dereference when loading certificates from a PKCS#7 bundle (bsc#1217592). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2023-4921=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-4921=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-4921=1 ## Package List: * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * python-cryptography-debugsource-3.3.2-150200.22.1 * python-cryptography-debuginfo-3.3.2-150200.22.1 * python3-cryptography-debuginfo-3.3.2-150200.22.1 * python3-cryptography-3.3.2-150200.22.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * python-cryptography-debugsource-3.3.2-150200.22.1 * python-cryptography-debuginfo-3.3.2-150200.22.1 * python3-cryptography-debuginfo-3.3.2-150200.22.1 * python3-cryptography-3.3.2-150200.22.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * python-cryptography-debugsource-3.3.2-150200.22.1 *python-cryptography-debuginfo-3.3.2-150200.22.1 * python3-cryptography-debuginfo-3.3.2-150200.22.1 * python3-cryptography-3.3.2-150200.22.1 ## References: * https://www.suse.com/security/cve/CVE-2023-49083.html * https://bugzilla.suse.com/show_bug.cgi?id=1217592 . SUSE has issued a security notice regarding the python-cryptography flaw CVE-2023-49083. It is crucial for users to perform updates without delay.. SUSE Linux Enterprise Micro, Python Cryptography Update, Security Patch. . LinuxSecurity.com Team

Calendar%202 Dec 20, 2023 SuSE
89

Fedora 35: FEDORA-2021-46dc82116b Critical: Community-MySQL Update

**MySQL 8.0.27** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-27.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-46dc82116b 2021-11-10 02:52:52.381127 --------------------------------------------------------------------------------Name : community-mysql Product : Fedora 35 Version : 8.0.27 Release : 1.fc35 URL : https://www.mysql.com/ Summary : MySQL client programs and shared libraries Description : MySQL is a multi-user, multi-threaded SQL database server. MySQL is a client/server implementation consisting of a server daemon (mysqld) and many different client programs and libraries. The base package contains the standard MySQL client programs and generic MySQL files. --------------------------------------------------------------------------------Update Information: **MySQL 8.0.27** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-27.html --------------------------------------------------------------------------------ChangeLog: * Sun Oct 31 2021 Lars Tangvald - 8.0.27-1 - Update to MySQL 8.0.27 --------------------------------------------------------------------------------References: [ 1 ] Bug #2015421 - community-mysql-8.0.27 is available https://bugzilla.redhat.com/show_bug.cgi?id=2015421 [ 2 ] Bug #2016141 - CVE-2021-2478 CVE-2021-2479 CVE-2021-2481 CVE-2021-35546 CVE-2021-35575 CVE-2021-35577 CVE-2021-35591 CVE-2021-35596 CVE-2021-35597 CVE-2021-35602 CVE-2021-35604 CVE-2021-35607 CVE-2021-35608 CVE-2021-35610 ... community-mysql: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2016141 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-46dc82116b' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora 36 revisions for community-postgresql 14.2, highlighting significant concerns and resolutions. Discover additional insights regarding this version update.. Fedora Update, MySQL 8.0.27, community-mysql, security issues, database security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 09, 2021 Critical Fedora
91

Gentoo: GLSA-202101-07 Moderate: NodeJS Code Execution Risk

Multiple vulnerabilities have been found in NodeJS, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202101-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: NodeJS: Multiple vulnerabilities Date: January 11, 2021 Bugs: #726836, #731654, #742893, #754942, #763588 ID: 202101-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in NodeJS, the worst of which could result in the arbitrary execution of code. Background ========= Node.js is a JavaScript runtime built on Chrome’s V8 JavaScript engine. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-libs/nodejs < 15.5.1 > = 12.20.1:0/12 > = 14.15.1:0/14 > = 15.5.1:0/15 Description ========== Multiple vulnerabilities have been discovered in NodeJS. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All NodeJS 15 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-libs/nodejs-15.5.1" All NodeJS 14 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-libs/nodejs-14.15.1" References ========= [ 1 ]CVE-2020-15095 https://nvd.nist.gov/vuln/detail/CVE-2020-15095 [ 2 ] CVE-2020-8172 https://nvd.nist.gov/vuln/detail/CVE-2020-8172 [ 3 ] CVE-2020-8174 https://nvd.nist.gov/vuln/detail/CVE-2020-8174 [ 4 ] CVE-2020-8201 https://nvd.nist.gov/vuln/detail/CVE-2020-8201 [ 5 ] CVE-2020-8251 https://nvd.nist.gov/vuln/detail/CVE-2020-8251 [ 6 ] CVE-2020-8265 https://nvd.nist.gov/vuln/detail/CVE-2020-8265 [ 7 ] CVE-2020-8277 https://nvd.nist.gov/vuln/detail/CVE-2020-8277 [ 8 ] CVE-2020-8287 https://nvd.nist.gov/vuln/detail/CVE-2020-8287 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202101-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2021 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . NodeJS contains several security flaws that could enable code execution. Ensure you upgrade to the most recent versions for complete security.. NodeJS Threats, Gentoo NodeJS Upgrade, Code Execution Risks. . LinuxSecurity.com Team

Calendar%202 Jan 11, 2021 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200