Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 42 nginx-mod-fancyindex Update CVE-2026-1642 TLS Attack Fix

nginx-mod-fancyindex: Rebuild for 1.28.2 nginx-mod-headers-more: Rebuild for 1.28.2 nginx-mod-brotli:. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-0b8cc86e5b 2026-02-15 01:28:07.972874+00:00 -------------------------------------------------------------------------------- Name : nginx-mod-fancyindex Product : Fedora 42 Version : 0.5.2 Release : 15.fc42 URL : https://github.com/aperezdc/ngx-fancyindex Summary : Nginx FancyIndex module Description : The Fancy Index module makes possible the generation of file listings, like the built-in autoindex module does, but adding a touch of style. This is possible because the module allows a certain degree of customization of the generated content: * Custom headers. Either local or stored remotely. * Custom footers. Either local or stored remotely. * Add you own CSS style rules. * Allow choosing to sort elements by name (default), modification time, or size; both ascending (default), or descending. -------------------------------------------------------------------------------- Update Information: nginx-mod-fancyindex: Rebuild for 1.28.2 nginx-mod-headers-more: Rebuild for 1.28.2 nginx-mod-brotli: Rebuild for 1.28.2 nginx-mod-modsecurity: Rebuild for 1.28.2 nginx-mod-vts: Rebuild for 1.28.2 nginx-mod-naxsi: Rebuild for 1.28.2 nginx: Update to 1.28.2 fixes CVE-2026-1642 move log directory to nginx-filesystem subpackage (PR#20) delete Maxim Dounin's key, it's no longer listed on the nginx website -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 4 2026 Felix Kaechele - 0.5.2-15 - Rebuild for 1.28.2 * Fri Jan 16 2026 Fedora Release Engineering - 0.5.2-14 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2436870 - CVE-2026-1642nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2436870 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-0b8cc86e5b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fedora 42 nginx-mod-fancyindex update addresses CVE-2026-1642, fixing data injection through TLS proxied connections.. nginx-mod-fancyindex update, Fedora 42 security, CVE-2026-1642 issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 15, 2026 Critical Fedora
203

Critical Java Security Issues Addressed in Mageia 9 MGASA-2024-0061

The updated packages fix security vulnerabilities: Array out-of-bounds access due to missing range check in C1 compiler. (CVE-2024-20918) RSA padding issue and timing side-channel attack against TLS. (CVE-2024-20952) . MGASA-2024-0061 - Updated java 1.8.0, 11 & latest packages fix security vulnerabilities Publication date: 15 Mar 2024 URL: https://advisories.mageia.org/MGASA-2024-0061.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-20918, CVE-2024-20952, CVE-2024-20926, CVE-2024-20919, CVE-2024-20921, CVE-2024-20945 The updated packages fix security vulnerabilities: Array out-of-bounds access due to missing range check in C1 compiler. (CVE-2024-20918) RSA padding issue and timing side-channel attack against TLS. (CVE-2024-20952) Arbitrary Java code execution in Nashorn. (CVE-2024-20926) JVM class file verifier flaw allows unverified bytecode execution. (CVE-2024-20919) Range check loop optimization issue. (CVE-2024-20921) Logging of digital signature private keys. (CVE-2024-20945) References: - https://bugs.mageia.org/show_bug.cgi?id=32724 - https://access.redhat.com/errata/RHSA-2024:0225 - https://access.redhat.com/errata/RHSA-2024:0234 - https://access.redhat.com/errata/RHSA-2024:0249 - https://www.cve.org/CVERecord?id=CVE-2024-20918 - https://www.cve.org/CVERecord?id=CVE-2024-20952 - https://www.cve.org/CVERecord?id=CVE-2024-20926 - https://www.cve.org/CVERecord?id=CVE-2024-20919 - https://www.cve.org/CVERecord?id=CVE-2024-20921 - https://www.cve.org/CVERecord?id=CVE-2024-20945 SRPMS: - 9/core/java-11-openjdk-11.0.22.0.7-1.mga9 - 9/core/java-1.8.0-openjdk-1.8.0.402.b06-1.mga9 - 9/core/java-latest-openjdk-21.0.2.0.13-1.rolling.1.mga9 . Revised software components for Mageia 9 tackle vulnerabilities such as buffer overflows and timing infiltration.. Mageia Java Security Update, Java Out-Of-Bounds Issue, TLS Timing Attack. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 15, 2024 Critical Mageia
98

Red Hat OpenJDK 8u312 Important: RHSA-2021-3960-01 TLS Attack Fixed

The Red Hat Build of OpenJDK 8 (java-1.8.0-openjdk) is now available for portable Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: OpenJDK 8u312 security update for Portable Linux Builds Advisory ID: RHSA-2021:3960-01 Product: OpenJDK Advisory URL: https://access.redhat.com/errata/RHSA-2021:3960 Issue date: 2021-10-25 Keywords: openjdk,linux CVE Names: CVE-2021-35550 CVE-2021-35556 CVE-2021-35559 CVE-2021-35561 CVE-2021-35564 CVE-2021-35565 CVE-2021-35567 CVE-2021-35578 CVE-2021-35586 CVE-2021-35588 CVE-2021-35603 ==================================================================== 1. Summary: The Red Hat Build of OpenJDK 8 (java-1.8.0-openjdk) is now available for portable Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: The OpenJDK 8 packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit. This release of the Red Hat build of OpenJDK 8 (1.8.0.312) for portable Linux serves as a replacement for Red Hat build of OpenJDK 8 (1.8.0.302) and includes security and bug fixes as well as enhancements. For further information, refer to the release notes linked to in the References section. Security Fix(es): * OpenJDK: Loop in HttpsServer triggered during TLS session close (JSSE, 8254967) (CVE-2021-35565) * OpenJDK: Incorrect principal selection when using Kerberos Constrained Delegation (Libraries, 8266689) (CVE-2021-35567) *OpenJDK: Weak ciphers preferred over stronger ones for TLS (JSSE, 8264210) (CVE-2021-35550) * OpenJDK: Excessive memory allocation in RTFParser (Swing, 8265167) (CVE-2021-35556) * OpenJDK: Excessive memory allocation in RTFReader (Swing, 8265580) (CVE-2021-35559) * OpenJDK: Excessive memory allocation in HashMap and HashSet (Utility, 8266097) (CVE-2021-35561) * OpenJDK: Certificates with end dates too far in the future can corrupt keystore (Keytool, 8266137) (CVE-2021-35564) * OpenJDK: Unexpected exception raised during TLS handshake (JSSE, 8267729) (CVE-2021-35578) * OpenJDK: Excessive memory allocation in BMPImageReader (ImageIO, 8267735) (CVE-2021-35586) * OpenJDK: Incomplete validation of inner class references in ClassFileParser (Hotspot, 8268071) (CVE-2021-35588) * OpenJDK: Non-constant comparison during TLS handshakes (JSSE, 8269618) (CVE-2021-35603) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: _using_openjdk_8_for_rhel/installing-openjdk8-on-rhel#installing-jdk8-on-rh el-using-archive 4. Bugs fixed (https://bugzilla.redhat.com/): 2014508 - CVE-2021-35565 OpenJDK: Loop in HttpsServer triggered during TLS session close (JSSE, 8254967) 2014515 - CVE-2021-35556 OpenJDK: Excessive memory allocation in RTFParser (Swing, 8265167) 2014518 - CVE-2021-35559 OpenJDK: Excessive memory allocation in RTFReader (Swing, 8265580) 2014524 - CVE-2021-35561 OpenJDK: Excessive memory allocation in HashMap and HashSet (Utility, 8266097) 2015061 - CVE-2021-35564 OpenJDK: Certificates with end dates too far in the future can corrupt keystore (Keytool, 8266137) 2015308 - CVE-2021-35586 OpenJDK: Excessive memory allocation in BMPImageReader (ImageIO, 8267735) 2015311 - CVE-2021-35603 OpenJDK:Non-constant comparison during TLS handshakes (JSSE, 8269618) 2015648 - CVE-2021-35550 OpenJDK: Weak ciphers preferred over stronger ones for TLS (JSSE, 8264210) 2015653 - CVE-2021-35578 OpenJDK: Unexpected exception raised during TLS handshake (JSSE, 8267729) 2015658 - CVE-2021-35567 OpenJDK: Incorrect principal selection when using Kerberos Constrained Delegation (Libraries, 8266689) 2015659 - CVE-2021-35588 OpenJDK: Incomplete validation of inner class references in ClassFileParser (Hotspot, 8268071) 5. References: https://access.redhat.com/security/cve/CVE-2021-35550 https://access.redhat.com/security/cve/CVE-2021-35556 https://access.redhat.com/security/cve/CVE-2021-35559 https://access.redhat.com/security/cve/CVE-2021-35561 https://access.redhat.com/security/cve/CVE-2021-35564 https://access.redhat.com/security/cve/CVE-2021-35565 https://access.redhat.com/security/cve/CVE-2021-35567 https://access.redhat.com/security/cve/CVE-2021-35578 https://access.redhat.com/security/cve/CVE-2021-35586 https://access.redhat.com/security/cve/CVE-2021-35588 https://access.redhat.com/security/cve/CVE-2021-35603 https://access.redhat.com/security/updates/classification/#important 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYXabj9zjgjWX9erEAQioxA//cz69TA3G8WheB94kj65qC/kSCYJGQ/TQ SFLdCdt/QpRWQGsuFfes9/1HFsb1o9YRilKrFSjUegoMLAHwJwFeewXktPvM0/eH PFqm2nx46jbTzEvsyfq1DCLXM2WCMBbz9yknnI/xhlf7D80WaQUQio16bLueSkkP /ckSSx0OB3tl3c90NUz+2JEKClu81D4Vn8UwdPjIWqjbeJC6KJmOkltJZFOPPqEf XbKftitTecnlOP3nAZeM2heNBI5FUoKeSJBqs+QnPSV6k8pUeEXv7AeLiazPHoB+ 3kBFTTpp9QAi3qQl2zOueZxjUk+0Vy7z9w5VetmqF3z/atfdRIQ5s7fKWOhZgBTr k1V3wrYAtZapnBITB4HFynQET5DldyqUgKTSAMIvnim8lkipzPA+ZpC4KEujHx7a aoo0Edy4WEDLyU5HlYH8+Ebqn07xM7nNDquaCMukosDCU05BVH2iDm66w0DPcH3w YaE3B5xxE8VNHcysnZUef4DBcPNVv9JSzG7cTGVwVt2CuF8WKA/jwus0KCpubE1n Ya8X6wusCGO1+sGk5Ur2g+phu0nhgie0HKgUp6WCIMg8PwR07mzG8UbuWxFiz7zE ejgXzala7owLxj8SqvQVMKDG7wPrjanWAN+2el4uxHNxRhcxl0+ngq1Uq35V4NX1 H1wysjsN9H8=402Q -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Important security patch for OpenJDK 8u312, targeting significant flaws affecting versatile Linux installations.. OpenJDK Update, Red Hat Security, Java Vulnerability Fix, Portable Linux, TLS Attack. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 25, 2021 Important Red Hat
89

Fedora 26: Security Update For Erlang 19.3.6.4 Critical TLS Attack

* Ver. 19.3.6.4. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-93b6236635 2017-12-12 12:25:26.722943 --------------------------------------------------------------------------------Name : erlang Product : Fedora 26 Version : 19.3.6.4 Release : 1.fc26 URL : https://www.erlang.org Summary : General-purpose programming language and runtime environment Description : Erlang is a general-purpose programming language and runtime environment. Erlang has built-in support for concurrency, distribution and fault tolerance. Erlang is used in several large telecommunication systems from Ericsson. --------------------------------------------------------------------------------Update Information: * Ver. 19.3.6.4 --------------------------------------------------------------------------------References: [ 1 ] Bug #1520400 - CVE-2017-1000385 erlang: TLS server vulnerable to Adaptive Chosen Ciphertext attack allowing plaintext recovery or MITM attack https://bugzilla.redhat.com/show_bug.cgi?id=1520400 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade erlang' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 26 has released an essential Erlang security patch that remedies a severe TLS flaw, presenting various risks for potentialattacks.. Erlang Security,Fedora Update,TLS Vulnerability,Attack Mitigation,Runtime Environment. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 12, 2017 Critical Fedora
99

Slackware: Critical Fix for OpenSSL TLS Attack - 2014-098-01 Update

New openssl packages are available for Slackware 14.0, 14.1, and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] openssl (SSA:2014-098-01) New openssl packages are available for Slackware 14.0, 14.1, and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +--------------------------+ patches/packages/openssl-1.0.1g-i486-1_slack14.1.txz: Upgraded. This update fixes two security issues: A missing bounds check in the handling of the TLS heartbeat extension can be used to reveal up to 64k of memory to a connected client or server. Thanks for Neel Mehta of Google Security for discovering this bug and to Adam Langley and Bodo Moeller for preparing the fix. Fix for the attack described in the paper "Recovering OpenSSL ECDSA Nonces Using the FLUSH+RELOAD Cache Side-channel Attack" by Yuval Yarom and Naomi Benger. Details can be obtained from: https://eprint.iacr.org/2014/140 For more information, see: https://www.cve.org/CVERecord?id=CVE-2014-0160 https://www.cve.org/CVERecord?id=CVE-2014-0076 (* Security fix *) patches/packages/openssl-solibs-1.0.1g-i486-1_slack14.1.txz: Upgraded. +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated packages for Slackware 14.0: Updated packages for Slackware x86_64 14.0: Updated packages for Slackware 14.1: Updated packages for Slackware x86_64 14.1: Updated packages for Slackware -current: Updated packages for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.0 packages: 5467a62ebfbe9a9bfff64dcc4cfcdf7d openssl-1.0.1g-i486-1_slack14.0.txz bdadd9920f2ce6fe4a0a7bd0d96f99df openssl-solibs-1.0.1g-i486-1_slack14.0.txz Slackwarex86_64 14.0 packages: 11ede2992e2b5d15bd3ffc5807571350 openssl-1.0.1g-x86_64-1_slack14.0.txz 858ea6409aab45a67a880458ce48f923 openssl-solibs-1.0.1g-x86_64-1_slack14.0.txz Slackware 14.1 packages: 8638083d9768ffcc4b7c597806ca634c openssl-1.0.1g-i486-1_slack14.1.txz 4d9dfe9db9e1f286ead72fc60971807b openssl-solibs-1.0.1g-i486-1_slack14.1.txz Slackware x86_64 14.1 packages: d85f8f451f71dd606f3adb59e582322a openssl-1.0.1g-x86_64-1_slack14.1.txz 43ff4bbfe26f99e7a3b9145146d191a0 openssl-solibs-1.0.1g-x86_64-1_slack14.1.txz Slackware -current packages: 265a66855320207d4a7567ac5ae9a747 a/openssl-solibs-1.0.1g-i486-1.txz bf07a4b17f1c78a4081e2cfb711b8748 n/openssl-1.0.1g-i486-1.txz Slackware x86_64 -current packages: 27e5135d764bd87bdb784b288e416b22 a/openssl-solibs-1.0.1g-x86_64-1.txz 5ef747eed99ac34102b34d8d0eaed3a8 n/openssl-1.0.1g-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the packages as root: # upgradepkg openssl-1.0.1g-i486-1_slack14.1.txz openssl-solibs-1.0.1g-i486-1_slack14.1.txz +-----+ . Slackware has released updated OpenSSL packages to address severe security vulnerabilities, enhancing both user data safety and system reliability.. Slackware Security, OpenSSL Update, Critical Software Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 08, 2014 Critical Slackware
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200