Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
202

openSUSE Memcached Important Timing Side-Channel Vuln 2026-20884-1

An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for memcached ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20884-1 Rating: important References: * bsc#1265873 * bsc#1265881 Cross-References: * CVE-2026-47783 * CVE-2026-47784 CVSS scores: * CVE-2026-47783 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-47784 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for memcached fixes the following issues - CVE-2026-47783: timing side-channel in SASL password database authentication (username) (bsc#1265873). - CVE-2026-47784: timing side-channel in SASL password database authentication (password) (bsc#1265881). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-877=1 Package List: - openSUSE Leap 16.0: memcached-1.6.38-160000.3.1 memcached-devel-1.6.38-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-47783.html * https://www.suse.com/security/cve/CVE-2026-47784.html . A vital openSUSE update for memcached addressing important side-channel vulnerabilities. Patch recommended for security.. openSUSE security, memcached update, vulnerability patch, timing issue fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 03, 2026 Important OpenSUSE
219

Rocky Linux 8 RLSA-2024:1687 Important: Nodejs DoS Attack Fixes

Important: nodejs:20 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:1687", "synopsis": "Important: nodejs:20 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for nodejs-nodemon, module.nodejs, nodejs, module.nodejs-nodemon, module.nodejs-packaging, nodejs-packaging.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Node.js is a software development platform for building fast and scalable\nnetwork applications in the JavaScript programming language.\n\nSecurity Fix(es):\n\n* nodejs: vulnerable to timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding (Marvin) (CVE-2023-46809)\n\n* nodejs: reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks (CVE-2024-22019)\n\n* nodejs: code injection and privilege escalation through Linux capabilities (CVE-2024-21892)\n\n* nodejs: path traversal by monkey-patching buffer internals (CVE-2024-21896)\n\n* nodejs: multiple permission model bypasses due to improper path traversal sequence sanitization (CVE-2024-21891)\n\n* nodejs: improper handling of wildcards in --allow-fs-read and --allow-fs-write (CVE-2024-21890)\n\n* nodejs: setuid() does not drop all privileges due to io_uring (CVE-2024-22017)", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2264569", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2264569", "description": ""}, {"ticket": "2264574", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2264574", "description": ""}, {"ticket": "2264582", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2264582", "description": ""}, {"ticket": "2265717", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2265717", "description": ""}, {"ticket": "2265720","sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2265720", "description": ""}, {"ticket": "2265722", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2265722", "description": ""}, {"ticket": "2265727", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2265727", "description": ""}], "cves": [{"name": "CVE-2023-46809", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-46809", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-21890", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-21890", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-21891", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-21891", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-21892", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-21892", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-21896", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-21896", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-22017", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-22017", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-22019", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-22019", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-05-06T13:04:21.002456Z", "rpms": {"Rocky Linux 8": {"nvras": ["nodejs-1:20.11.1-1.module+el8.9.0+1776+addd4aec.aarch64.rpm", "nodejs-1:20.11.1-1.module+el8.9.0+1776+addd4aec.src.rpm", "nodejs-1:20.11.1-1.module+el8.9.0+1776+addd4aec.x86_64.rpm","nodejs-debuginfo-1:20.11.1-1.module+el8.9.0+1776+addd4aec.aarch64.rpm", "nodejs-debuginfo-1:20.11.1-1.module+el8.9.0+1776+addd4aec.x86_64.rpm", "nodejs-debugsource-1:20.11.1-1.module+el8.9.0+1776+addd4aec.aarch64.rpm", "nodejs-debugsource-1:20.11.1-1.module+el8.9.0+1776+addd4aec.x86_64.rpm", "nodejs-devel-1:20.11.1-1.module+el8.9.0+1776+addd4aec.aarch64.rpm", "nodejs-devel-1:20.11.1-1.module+el8.9.0+1776+addd4aec.x86_64.rpm", "nodejs-docs-1:20.11.1-1.module+el8.9.0+1776+addd4aec.noarch.rpm", "nodejs-full-i18n-1:20.11.1-1.module+el8.9.0+1776+addd4aec.aarch64.rpm", "nodejs-full-i18n-1:20.11.1-1.module+el8.9.0+1776+addd4aec.x86_64.rpm", "nodejs-nodemon-0:3.0.1-1.module+el8.8.0+1459+02651ab6.noarch.rpm", "nodejs-nodemon-0:3.0.1-1.module+el8.8.0+1459+02651ab6.src.rpm", "nodejs-packaging-0:2021.06-4.module+el8.7.0+1072+5b168780.noarch.rpm", "nodejs-packaging-0:2021.06-4.module+el8.7.0+1072+5b168780.src.rpm", "nodejs-packaging-bundler-0:2021.06-4.module+el8.7.0+1072+5b168780.noarch.rpm", "npm-1:10.2.4-1.20.11.1.1.module+el8.9.0+1776+addd4aec.aarch64.rpm", "npm-1:10.2.4-1.20.11.1.1.module+el8.9.0+1776+addd4aec.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Node.js security patches tackle severe flaws in Rocky Linux. Discover the key resolutions that matter.. Nodejs Security Fixes,Rocky Linux Advisories,Important Security Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 06, 2024 Important Rocky Linux
203

Mageia 9: 2024-0031 Critical GnuTLS Update on DoS and Timing Attacks

The updated packages fix security vulnerabilities: A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to . MGASA-2024-0031 - Updated gnutls packages fix security vulnerabilities Publication date: 09 Feb 2024 URL: https://advisories.mageia.org/MGASA-2024-0031.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-0567, CVE-2024-0553 The updated packages fix security vulnerabilities: A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack. (CVE-2024-0567) A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981. (CVE-2024-0553) References: - https://bugs.mageia.org/show_bug.cgi?id=32755 - https://www.openwall.com/lists/oss-security/2024/01/19/3 - https://www.cve.org/CVERecord?id=CVE-2024-0567 - https://www.cve.org/CVERecord?id=CVE-2024-0553 SRPMS: - 9/core/gnutls-3.8.0-2.2.mga9 . Mageia 2024-0031 delivers gnutls updates resolving critical vulnerabilities for improved security measures.. GnuTLS Security Update,Mageia 2024-0031,Denial Of Service,Timing Attack. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 09, 2024 Critical Mageia
202

openSUSE Leap: 15.1, 15.0 Security Advisory for Libcryptopp Timing Issue

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for libcryptopp ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1968-1 Rating: moderate References: #1143532 Cross-References: CVE-2019-14318 Affected Products: openSUSE Leap 15.1 openSUSE Leap 15.0 openSUSE Backports SLE-15-SP1 openSUSE Backports SLE-15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libcryptopp fixes the following issues: - CVE-2019-14318: Fixed a timing side channel vulnerability in the ECDSA signature generation (boo#1143532). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-1968=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1968=1 - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2019-1968=1 - openSUSE Backports SLE-15: zypper in -t patch openSUSE-2019-1968=1 Package List: - openSUSE Leap 15.1 (i586 x86_64): libcryptopp-debugsource-5.6.5-lp151.3.3.1 libcryptopp-devel-5.6.5-lp151.3.3.1 libcryptopp5_6_5-5.6.5-lp151.3.3.1 libcryptopp5_6_5-debuginfo-5.6.5-lp151.3.3.1 - openSUSE Leap 15.1 (x86_64): libcryptopp5_6_5-32bit-5.6.5-lp151.3.3.1 libcryptopp5_6_5-32bit-debuginfo-5.6.5-lp151.3.3.1 - openSUSE Leap 15.0 (i586 x86_64): libcryptopp-debugsource-5.6.5-lp150.2.3.1 libcryptopp-devel-5.6.5-lp150.2.3.1 libcryptopp5_6_5-5.6.5-lp150.2.3.1 libcryptopp5_6_5-debuginfo-5.6.5-lp150.2.3.1 - openSUSE Leap 15.0 (x86_64): libcryptopp5_6_5-32bit-5.6.5-lp150.2.3.1 libcryptopp5_6_5-32bit-debuginfo-5.6.5-lp150.2.3.1 - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): libcryptopp-devel-5.6.5-bp151.4.3.1 libcryptopp5_6_5-5.6.5-bp151.4.3.1 - openSUSE Backports SLE-15-SP1 (aarch64_ilp32): libcryptopp5_6_5-64bit-5.6.5-bp151.4.3.1 - openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64): libcryptopp-debugsource-5.6.5-bp150.3.3.1 libcryptopp-devel-5.6.5-bp150.3.3.1 libcryptopp5_6_5-5.6.5-bp150.3.3.1 libcryptopp5_6_5-debuginfo-5.6.5-bp150.3.3.1 - openSUSE Backports SLE-15 (aarch64_ilp32): libcryptopp5_6_5-64bit-5.6.5-bp150.3.3.1 libcryptopp5_6_5-64bit-debuginfo-5.6.5-bp150.3.3.1 References: https://www.suse.com/security/cve/CVE-2019-14318.html https://bugzilla.suse.com/1143532 -- . Addressed timing side-channel vulnerabilities in libcryptopp for openSUSE. Patch released for impacted versions.. libcryptopp update, openSUSE security, timing issue fix. . LinuxSecurity.com Team

Calendar%202 Aug 20, 2019 OpenSUSE
202

openSUSE Leap 15.0: 2018:4050-1 Moderate: OpenSSL Timing Issues

An update that solves two vulnerabilities and has three fixes is now available.. openSUSE Security Update: Security update for openssl-1_0_0 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:4050-1 Rating: moderate References: #1100078 #1112209 #1113534 #1113652 #1113742 Cross-References: CVE-2018-0734 CVE-2018-5407 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that solves two vulnerabilities and has three fixes is now available. Description: This update for openssl-1_0_0 fixes the following issues: Security issues fixed: - CVE-2018-0734: Fixed timing vulnerability in DSA signature generation (bsc#1113652). - CVE-2018-5407: Added elliptic curve scalar multiplication timing attack defenses that fixes "PortSmash" (bsc#1113534). Non-security issues fixed: - Added missing timing side channel patch for DSA signature generation (bsc#1113742). - Set TLS version to 0 in msg_callback for record messages to avoid confusing applications (bsc#1100078). - Fixed infinite loop in DSA generation with incorrect parameters (bsc#1112209) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-1518=1 Package List: - openSUSE Leap 15.0 (i586 x86_64): libopenssl-1_0_0-devel-1.0.2p-lp150.2.9.1 libopenssl1_0_0-1.0.2p-lp150.2.9.1 libopenssl1_0_0-debuginfo-1.0.2p-lp150.2.9.1 libopenssl1_0_0-hmac-1.0.2p-lp150.2.9.1 libopenssl1_0_0-steam-1.0.2p-lp150.2.9.1 libopenssl1_0_0-steam-debuginfo-1.0.2p-lp150.2.9.1 openssl-1_0_0-1.0.2p-lp150.2.9.1 openssl-1_0_0-cavs-1.0.2p-lp150.2.9.1 openssl-1_0_0-cavs-debuginfo-1.0.2p-lp150.2.9.1 openssl-1_0_0-debuginfo-1.0.2p-lp150.2.9.1 openssl-1_0_0-debugsource-1.0.2p-lp150.2.9.1 - openSUSE Leap 15.0 (noarch): openssl-1_0_0-doc-1.0.2p-lp150.2.9.1 - openSUSE Leap 15.0 (x86_64): libopenssl-1_0_0-devel-32bit-1.0.2p-lp150.2.9.1 libopenssl1_0_0-32bit-1.0.2p-lp150.2.9.1 libopenssl1_0_0-32bit-debuginfo-1.0.2p-lp150.2.9.1 libopenssl1_0_0-hmac-32bit-1.0.2p-lp150.2.9.1 libopenssl1_0_0-steam-32bit-1.0.2p-lp150.2.9.1 libopenssl1_0_0-steam-32bit-debuginfo-1.0.2p-lp150.2.9.1 References: https://www.suse.com/security/cve/CVE-2018-0734.html https://www.suse.com/security/cve/CVE-2018-5407.html https://bugzilla.suse.com/1100078 https://bugzilla.suse.com/1112209 https://bugzilla.suse.com/1113534 https://bugzilla.suse.com/1113652 https://bugzilla.suse.com/1113742 -- . Debian security patch addresses vulnerabilities in openssl-1_0_0 with effective solutions. Crucial for your system's protection.. OpenSSL Update, openSUSE Updates, Security Fixes. . LinuxSecurity.com Team

Calendar%202 Dec 08, 2018 OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200