Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 13 articles for you...
202

openSUSE Tinyproxy Moderate Security Issues Advisory 2026-11060-1

An update that solves 3 vulnerabilities can now be installed.. # tinyproxy-1.11.3-3.1 on GA media Announcement ID: openSUSE-SU-2026:11060-1 Rating: moderate Cross-References: * CVE-2026-54387 * CVE-2026-54388 * CVE-2026-55202 Affected Products: * openSUSE Tumbleweed An update that solves 3 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the tinyproxy-1.11.3-3.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * tinyproxy 1.11.3-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54387.html * https://www.suse.com/security/cve/CVE-2026-54388.html * https://www.suse.com/security/cve/CVE-2026-55202.html . An update for openSUSE Tumbleweed fixes three vulnerabilities in tinyproxy version 1.11.3-3.1, enhancing system security.. OpenSUSE, tinyproxy, security update, system vulnerabilities, networking. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 19, 2026 moderate OpenSUSE
89

Fedora 44 Tinyproxy Critical DoS Bug Fix FEDORA-2026-9695fbdabb

Backport upstream fixes for CVE-2026-3945 and CVE-2026-31842.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9695fbdabb 2026-04-25 01:21:36.172703+00:00 -------------------------------------------------------------------------------- Name : tinyproxy Product : Fedora 44 Version : 1.11.2 Release : 7.fc44 URL : https://tinyproxy.github.io/ Summary : A small, efficient HTTP/SSL proxy daemon Description : tinyproxy is a small, efficient HTTP/SSL proxy daemon that is very useful in a small network setting, where a larger proxy like Squid would either be too resource intensive, or a security risk. -------------------------------------------------------------------------------- Update Information: Backport upstream fixes for CVE-2026-3945 and CVE-2026-31842. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 11 2026 Carl George - 1.11.2-7 - Backport upstream CVE fixes - Fixes CVE-2026-3945 - Fixes CVE-2026-31842 - Run upstream test suite -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452969 - CVE-2026-3945 tinyproxy: tinyproxy: Denial of Service via integer overflow in HTTP chunked transfer encoding parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452969 [ 2 ] Bug #2455913 - CVE-2026-31842 tinyproxy: HTTP Request parsing desynchronization via case-sensitive Transfer-Encoding handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455913 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9695fbdabb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Tinyproxy for Fedora 44 fixes critical issues related to DoS and HTTP request parsing errors, ensuring robust network performance.. tinyproxy Fedora security DoS patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 25, 2026 Important Fedora
89

Fedora 42 tinyproxy Severe DoS Flaws CVE-2026-3945 CVE-2026-31842 Patch

Backport upstream fixes for CVE-2026-3945 and CVE-2026-31842.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d67a979089 2026-04-22 11:41:11.030779+00:00 -------------------------------------------------------------------------------- Name : tinyproxy Product : Fedora 42 Version : 1.11.2 Release : 7.fc42 URL : https://tinyproxy.github.io/ Summary : A small, efficient HTTP/SSL proxy daemon Description : tinyproxy is a small, efficient HTTP/SSL proxy daemon that is very useful in a small network setting, where a larger proxy like Squid would either be too resource intensive, or a security risk. -------------------------------------------------------------------------------- Update Information: Backport upstream fixes for CVE-2026-3945 and CVE-2026-31842. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 11 2026 Carl George - 1.11.2-7 - Backport upstream CVE fixes - Fixes CVE-2026-3945 - Fixes CVE-2026-31842 - Run upstream test suite * Sat Jan 17 2026 Fedora Release Engineering - 1.11.2-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452969 - CVE-2026-3945 tinyproxy: tinyproxy: Denial of Service via integer overflow in HTTP chunked transfer encoding parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452969 [ 2 ] Bug #2455913 - CVE-2026-31842 tinyproxy: HTTP Request parsing desynchronization via case-sensitive Transfer-Encoding handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455913 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d67a979089' at the command line. For more information, refer to thednf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Backport upstream fixes for tinyproxy vulnerabilities CVE-2026-3945 and CVE-2026-31842 to enhance security.. tinyproxy fixes, Fedora security advisory, CVE-2026-3945 update, CVE-2026-31842 patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 22, 2026 Critical Fedora
89

Fedora 43 tinyproxy Denial of Service CVE-2026-3945 and CVE-2026-31842 Fix

Backport upstream fixes for CVE-2026-3945 and CVE-2026-31842.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d8daf8790f 2026-04-22 07:48:13.354945+00:00 -------------------------------------------------------------------------------- Name : tinyproxy Product : Fedora 43 Version : 1.11.2 Release : 7.fc43 URL : https://tinyproxy.github.io/ Summary : A small, efficient HTTP/SSL proxy daemon Description : tinyproxy is a small, efficient HTTP/SSL proxy daemon that is very useful in a small network setting, where a larger proxy like Squid would either be too resource intensive, or a security risk. -------------------------------------------------------------------------------- Update Information: Backport upstream fixes for CVE-2026-3945 and CVE-2026-31842. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 11 2026 Carl George - 1.11.2-7 - Backport upstream CVE fixes - Fixes CVE-2026-3945 - Fixes CVE-2026-31842 - Run upstream test suite * Sat Jan 17 2026 Fedora Release Engineering - 1.11.2-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452969 - CVE-2026-3945 tinyproxy: tinyproxy: Denial of Service via integer overflow in HTTP chunked transfer encoding parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452969 [ 2 ] Bug #2455913 - CVE-2026-31842 tinyproxy: HTTP Request parsing desynchronization via case-sensitive Transfer-Encoding handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455913 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d8daf8790f' at the command line. For more information, refer to thednf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Explore the latest Fedora 43 tinyproxy update addressing crucial CVE fixes and security vulnerabilities.. CVE-2026-3945 tinyproxy Fedora Denial of Service update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 22, 2026 Important Fedora
202

openSUSE Unveils SLE-15-SP8 Security Update for tinyproxy Vulnerability

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for tinyproxy ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0111-1 Rating: important References: #1261024 Cross-References: CVE-2026-3945 Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for tinyproxy fixes the following issues: - CVE-2026-3945: Fixed denial of service by unauthenticated remote attacker (boo#1261024) - Update to release 1.11.3 * conf: add BasicAuthRealm feature * basic auth: fix error status 401 vs 407 * tinyproxy.conf.5: explain what a site_spec looks like * tinyproxy.conf.5: add an IPv6 example to allow/deny section * reqs: fix integer overflow in port number processing Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-111=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): tinyproxy-1.11.3-bp157.2.6.1 References: https://www.suse.com/security/cve/CVE-2026-3945.html https://bugzilla.suse.com/1261024 . A critical update for openSUSE tinyproxy addresses denial of service vulnerability CVE-2026-3945. Apply patch now!. openSUSE Security Update, tinyproxy Denial of Service, CVE-2026-3945 Fix, SLE-15-SP7 Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 01, 2026 Important OpenSUSE
89

Fedora 42: Fix for Tinyproxy High Integer Overflow CVE-2025-63938

Add upstream patch to fix CVE-2025-63938.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-a177cf4e1e 2025-12-11 01:00:50.567616+00:00 -------------------------------------------------------------------------------- Name : tinyproxy Product : Fedora 42 Version : 1.11.2 Release : 5.fc42 URL : https://tinyproxy.github.io/ Summary : A small, efficient HTTP/SSL proxy daemon Description : tinyproxy is a small, efficient HTTP/SSL proxy daemon that is very useful in a small network setting, where a larger proxy like Squid would either be too resource intensive, or a security risk. -------------------------------------------------------------------------------- Update Information: Add upstream patch to fix CVE-2025-63938. -------------------------------------------------------------------------------- ChangeLog: * Tue Dec 2 2025 Carl George - 1.11.2-5 - Add upstream patch to fix CVE-2025-63938 * Fri Jul 25 2025 Fedora Release Engineering - 1.11.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2417329 - CVE-2025-63938 tinyproxy: Tinyproxy integer overflow [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2417329 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a177cf4e1e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Tinyproxy updated in Fedora 42 to address CVE-2025-63938 integer overflow vulnerability. Update now!. Fedora Security Patch,tinyproxy CVE Fix,integer overflow vulnerability,tinyproxy update,high severity advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 11, 2025 Important Fedora
89

Fedora 43: Important Update for tinyproxy Integer Overflow Issue

Add upstream patch to fix CVE-2025-63938.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-72fbf180c7 2025-12-04 00:51:14.440723+00:00 -------------------------------------------------------------------------------- Name : tinyproxy Product : Fedora 43 Version : 1.11.2 Release : 5.fc43 URL : https://tinyproxy.github.io/ Summary : A small, efficient HTTP/SSL proxy daemon Description : tinyproxy is a small, efficient HTTP/SSL proxy daemon that is very useful in a small network setting, where a larger proxy like Squid would either be too resource intensive, or a security risk. -------------------------------------------------------------------------------- Update Information: Add upstream patch to fix CVE-2025-63938. -------------------------------------------------------------------------------- ChangeLog: * Tue Dec 2 2025 Carl George - 1.11.2-5 - Add upstream patch to fix CVE-2025-63938 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2417330 - CVE-2025-63938 tinyproxy: Tinyproxy integer overflow [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2417330 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-72fbf180c7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe sendan email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 43 security advisory for tinyproxy addressing CVE-2025-63938 with upstream patch implementation.. Fedora 43 tinyproxy patch CVE-2025-63938 integer overflow. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 04, 2025 Critical Fedora
203

Mageia 9: MGASA-2025-0003 critical: tinyproxy remote execution risk

Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function.. (CVE-2022-40468) A use-after-free vulnerability exists in the HTTP Connection Headers . MGASA-2025-0003 - Updated tinyproxy packages fix security vulnerabilities Publication date: 10 Jan 2025 URL: https://advisories.mageia.org/MGASA-2025-0003.html Type: security Affected Mageia releases: 9 CVE: CVE-2022-40468, CVE-2023-49606 Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function.. (CVE-2022-40468) A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability. (CVE-2023-49606) References: - https://bugs.mageia.org/show_bug.cgi?id=33206 - https://www.openwall.com/lists/oss-security/2024/05/07/1 - - - https://ubuntu.com/security/notices/USN-7140-1 - https://ubuntu.com/security/notices/USN-7190-1 - https://www.cve.org/CVERecord?id=CVE-2022-40468 - https://www.cve.org/CVERecord?id=CVE-2023-49606 SRPMS: - 9/core/tinyproxy-1.10.0-3.1.mga9 . The Mageia team has released updates for tinyproxy to fix severe security issues highlighted in advisory MGASA-2025-0003.. tinyproxy security, Mageia advisory, heap data leak, remote code execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 10, 2025 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200