Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
202

openSUSE Backports 15-SP7 Botan Important TLS Bypass Vuln 2026-0142-1

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for Botan ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0142-1 Rating: important References: #1261880 Cross-References: CVE-2026-34582 CVSS scores: CVE-2026-34582 (SUSE): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for Botan fixes the following issues: - CVE-2026-34582: client authentication bypass in TLS 1.3 implementation (boo#1261880) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-142=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): Botan-3.5.0-bp157.2.3.1 libbotan-3-5-3.5.0-bp157.2.3.1 libbotan-devel-3.5.0-bp157.2.3.1 python3-botan-3.5.0-bp157.2.3.1 - openSUSE Backports SLE-15-SP7 (aarch64_ilp32): libbotan-3-5-64bit-3.5.0-bp157.2.3.1 libbotan-devel-64bit-3.5.0-bp157.2.3.1 - openSUSE Backports SLE-15-SP7 (x86_64): libbotan-3-5-32bit-3.5.0-bp157.2.3.1 libbotan-devel-32bit-3.5.0-bp157.2.3.1 - openSUSE Backports SLE-15-SP7 (noarch): Botan-doc-3.5.0-bp157.2.3.1 References: https://www.suse.com/security/cve/CVE-2026-34582.html https://bugzilla.suse.com/1261880 . Important update for openSUSE addresses TLS authentication bypass issue in Botan. Apply patch promptly for security.. openSUSE update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 20, 2026 Important OpenSUSE
89

Fedora 42 cpp-httplib Critical TLS Bypass Fix CVE-2026-32627

Update to 0.37.2 Fixes silent TLS certificate verification bypass on HTTPS Redirect via proxy (CVE-2026-32627, rhbz#2448105) Source: https://github.com/yhirose/cpp-httplib/releases/tag/v0.37.2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-04a531cece 2026-04-01 01:08:42.227682+00:00 -------------------------------------------------------------------------------- Name : cpp-httplib Product : Fedora 42 Version : 0.37.2 Release : 1.fc42 URL : https://github.com/yhirose/cpp-httplib Summary : A C++11 single-file header-only cross platform HTTP/HTTPS library Description : A C++11 single-file header-only cross platform HTTP/HTTPS library. It's extremely easy to setup. Just include the httplib.h file in your code! -------------------------------------------------------------------------------- Update Information: Update to 0.37.2 Fixes silent TLS certificate verification bypass on HTTPS Redirect via proxy (CVE-2026-32627, rhbz#2448105) Source: https://github.com/yhirose/cpp-httplib/releases/tag/v0.37.2 -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 17 2026 Petr Men\u0161k - 0.37.2-1 - Update to 0.37.2 - Fixes silent TLS certificate verification bypass on HTTPS Redirect via proxy (CVE-2026-32627, rhbz#2448105) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2448105 - CVE-2026-32627 cpp-httplib: silent TLS certificate verification bypass on HTTPS Redirect via proxy [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2448105 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-04a531cece' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label Allpackages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update for Fedora 42 cpp-httplib fixes critical TLS certificate verification bypass issue.. Fedora 42,tls bypass,security advisory,cpp-httplib,update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 01, 2026 Critical Fedora
203

Mageia 9 Python-openssl Important TLS Vulnerability Fix MGASA-2026-0074

MGASA-2026-0074 - Updated python-openssl packages fix security vulnerabilities. MGASA-2026-0074 - Updated python-openssl packages fix security vulnerabilities Publication date: 31 Mar 2026 URL: https://advisories.mageia.org/MGASA-2026-0074.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-27448, CVE-2026-27459 Description: pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback. (CVE-2026-27448) pyOpenSSL DTLS cookie callback buffer overflow. (CVE-2026-27459) References: - https://bugs.mageia.org/show_bug.cgi?id=35254 - https://www.openwall.com/lists/oss-security/2026/03/20/5 - https://github.com/pyca/pyopenssl/security/advisories/GHSA-5pwr-322w-8jr4 - https://github.com/pyca/pyopenssl/security/advisories/GHSA-vp96-hxj8-p424 - https://ubuntu.com/security/notices/USN-8115-1 - https://www.cve.org/CVERecord?id=CVE-2026-27448 - https://www.cve.org/CVERecord?id=CVE-2026-27459 SRPMS: - 9/core/python-openssl-23.0.0-1.1.mga9 . Updated python-openssl packages resolve critical vulnerabilities for Mageia 9, ensuring enhanced security and stability.. Mageia security update, python-openssl patch, TLS vulnerability fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 01, 2026 Important Mageia
202

openSUSE: icinga2 Important TLS Bypass CVE-2024-49369 Advisory 2025:0457-1

An update that solves one vulnerability and has one errata is now available.. openSUSE Security Update: Security update for icinga2 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0457-1 Rating: important References: #1084909 #1233310 Cross-References: CVE-2024-49369 CVSS scores: CVE-2024-49369 (SUSE): 10 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for icinga2 fixes the following issues: - Update to 2.14.5 * Bug Fixes - Don't close anonymous connections before sending the response for a certificate request #10337 - Performance data: Don't discard min/max values even if crit/warn thresholds aren\u2019t given #10339 - Fix a failing test case on systems time_t is only 32 bits #10343 * Documentation - Document the -X option for the mail-host-notification and mail-service-notification commands #10335 - Include Nagios in the migration docs #10324 - Remove RHEL 7 from installation instructions #10334 - Add instructions for installing build dependencies on Windows Server #10336 - Update to 2.14.4 * Crash Fixes - Invalid DateTime#format() arguments in config and console on Windows Server 2016 and older. #10112 - Downtime scheduling at runtime with non-existent trigger. #10049 - Object creation at runtime during Icinga DB initialization. #10151 - Comment on a service of a non-existent host. #9861 * Miscellaneous Bugfixes - Lost notifications after recovery outside the notification time period. #10187 - TimePeriod/ScheduledDowntime exceeding specified daterange. #9983 #10107 - Clean up failure for obsolete Downtimes. #10062 - ifw-api check command: use correct process-finished handler. #10140 - Email notification scripts: strip 0x0D (CR) for a proper Content-Type. #10061 - Several fixes and improvements of the code quality. #10066 #10214 #10254 #10263 #10264 * Cluster and API - Sync runtime objects in topological order to honor their dependencies. #10000 - Make parallel config syncs more robust. #10013 - After object creation via API fails, clean up properly for the next try. #10111 - Close HTTPS connections properly to prevent leaks. #10005 #10006 - Reduce the number of cluster messages in memory at the same time. #9991 #9999 #10210 - Once a cluster connection shall be closed, stop communicating. #10213 #10221 - Remove unnecessary blocking of semaphores. #9992 #9994 - Reduce unnecessary cluster messages setting the next check time. #10011 * Icinga DB and IDO - IDO: fix object relations after aborted synchronization. #10065 - Icinga DB, IDO: limit all timestamps to four year digits. #10058 #10059 - Icinga DB: limit execution_time and latency (milliseconds) to database schema. #10060 * Troubleshooting - Add /v1/debug/malloc_info which calls malloc_info(3) if available. #10015 - Add log messages about own network I/O. #9993 #10141 #10207 - Several fixes and improvements of log messages. #9997 #10021 #10209 * Windows - Update OpenSSL shipped on Windows to v3.0.15. #10170 - Update Boost shipped on Windows to v1.86. #10114 - Support CMake v3.29. #10037 - Don't require to build .msi as admin. #10137 - Build configuration scripts: allow custom $CMAKE_ARGS. #10312 * Documentation - Distributed Monitoring: add section "External CA/PKI". #9825 - Explain how to enable/disabledebug logging on the fly. #9981 - Update supported OS versions and repository configuration. #10064 #10090 #10120 #10135 #10136 #10205 - Several fixes and improvements. #9960 #10050 #10071 #10156 #10194 - Replace broken links. #10115 #10118 #10282 - Fix typographical and similarly trivial errors. #9953 #9967 #10056 #10116 #10152 #10153 #10204 - Update to 2.14.3 - Security: fix TLS certificate validation bypass. CVE-2024-49369 (boo#1233310) - Security: update OpenSSL shipped on Windows to v3.0.15. - Windows: sign MSI packages with a certificate the OS trusts by default. - Update to 2.14.2 - InfluxDB: truncate timestamps to whole seconds to save disk space. #9969 - HttpServerConnection: log request processing time as well. #9970 - Update Boost shipped on Windows to v1.84. #9970 - Update to 2.14.1 * Security - Automatically renew own root CA and distribute it to all nodes. #9933 - Update OpenSSL shipped on Windows to v3.0.12. #9946 - Disable TLS renegotiation (handshake on existing connection). #9946 * Bugfixes - Icinga DB feature: fix crash due to missing NULL pointer check. #9946 - Icinga DB feature: fix data written into Redis crashing the Go daemon. #9946 - GelfWriter: fix deadlock on stop/reload caused by busy queue. #9947 - Don't lose notifications due to too long output, truncate it. #9947 * Enhancements - Discard duplicate problem notifications due to state filtering. #9932 - Speed up API filters targeting specific hosts/services to O(1). #9944 - POST /v1/console/*: return HTTP 503 while Icinga is reloading. #9947 - Update Boost shipped on Windows to v1.83. #9946 - Documentation: several fixes and improvements. #9921 - Update to 2.14.0 * Breaking Changes - Remove CheckResultReader (which has been deprecated since v2.9). #9714 - Remove StatusDataWriter(which has been deprecated since v2.9). #9715 - ElasticsearchWriter: drop support for Elasticsearch < v7. #9812 - Consider a checkable unreachable once one Dependency fails. Previously all of them had to fail. (Consult the upgrading docs.) #8218 - API: reject config modifications during reload with HTTP status 503. #9445 - icinga2 daemon: to reduce config load time, write file needed by icinga2 object list only if --dump-objects is given. #9586 #9591 - Default email notification scripts: link to Icinga DB Web, not the monitoring module. (Consult the upgrading docs.) #9742 #9757 - API: for security reasons hide TicketSalt in /v1/variables. #7863 * Icinga 2 Config DSL - Disallow global variable modification after config commit start (i.e. inside object/apply T "x" { ... }) to reduce config load time. #9740 - Forbid Dependency cycles at config load time. #8389 - Allow only strings in the arrays Host#groups, Service#groups and User#groups. Needed for consistency, especially by the IDO. #9057 - Disallow empty object names. (They worked only partially anyway.) #9409 * Enhancements - Significantly reduce config load time of large setups. #8118 #9555 #9557 #9572 #9577 #9603 #9608 #9627 #9648 #9657 #9662 - Allow to connect dependencies via redundancy groups. Only parents within one group are assumed to provide redundancy for each other. #8218 - Built-in check command ifw-api, communicates directly with the Icinga for Windows REST API. (Doesn't spawn a PowerShell process for that.) #9062 - JournaldLogger which logs to systemd journal. #9000 - API: POST /v1/objects: allow to discard some previously modified attributes, i.e. to restore the config files' values. #9783 - ElasticsearchWriter: support Elasticsearch v8. #9812 - Support $env.ENV_VAR_NAME$ macros. #8302 - Speed up Icinga DB config dump. #9524 - Default mail notification scripts: also print $host.notes$ and $service.notes$. #9713 - Enable built-in OpenSSL DH parameters to allow DHE TLS ciphers. #9811 - Clean up global default TLS cipher list to improve security. #9809 - Influxdb(2)Writer: write more precise timestamps (nanoseconds). #9599 * Bugfixes - Icinga DB feature: normalize several Redis data not to crash the Go daemon. #9772 #9775 #9792 #9793 #9794 #9805 - Fix parsing of perfdata across multiple lines in plugin output. #8969 - icinga check: fix last reload failure time. #8429 #9827 - Resolve macros inside custom vars of IcingaApplication. #9779 - SELinux: allow Icinga and its plugins to write to syslog. #9688 - ElasticsearchWriter: fix data buffer flush race condition during stop. #9810 - Trigger flexible downtimes not in the past if checkable is already down. #9726 - Send downtime expiration notifications immediately, not after up to a minute. #9726 * Cluster - Don't hang in timed out connection attempt. #9711 #9725 - Fix lost acknowledgements after re-connect. #9718 - cluster-zone check: don't complain about not connected other local zone members if there aren't any. #8595 - Allow agent to update executions delegated to it via /v1/actions/execute-command. #8627 * API - Disallow breaking inter-object relationships by changing relationship attributes at runtime, e.g. Service#host_name. #9407 - Correct several HTTP response status codes. #7958 #9354 - Correct Boolean field types previously reported by /v1/types as Number. #9514 * CLI - icinga2 daemon: fix -DConfiguration.Concurrency= flag which now allows to override the number of threads. #9643 - icinga2 node wizard: avoid unnecessary chown(2) which may fail and abort the wizard. #8744 - Correct several log messages. #8895 #8965 #9663 * ITL - Add linux_netdev check command. #9045 + Command Argument Changes - disk: don't pass -m (disk_megabytes) by default. #9642 - disk: pass -X fuse.portal (disk_exclude_type) by default. #9459 - http: support multiple -k (http_header) as array. #8574 - icmp: double defaults for -w (icmp_wpl) and -c (icmp_cpl). #9041 - logfiles: pass --winwarncrit (logfiles_winwarncrit) without argument. #9056 - nwc_health: pass SNMPv3-only args only when using SNMPv3. #9095 - vmware-esx-dc-runtime-tools and vmware-esx-soap-vm-runtime-tools: - rename --open-vm-tools to --open_vm_tools_ok (vmware_openvmtools). #9611 - Update to 2.13.8 * Bugfixes - Icinga DB feature: normalize several Redis data not to crash the Go daemon. #9814 - Don't hang in timed out connection attempt. #9815 - Trigger flexible downtimes not in the past if checkable is already down. #9817 - ElasticsearchWriter: fix data buffer flush race condition during stop. #9818 - SELinux: allow Icinga and its plugins to write to syslog. #9819 - Fix lost acknowledgements after re-connect. #9820 - Fix parsing of perfdata across multiple lines in plugin output. #9821 - cluster-zone check: don't complain about not connected other local zone members if there aren't any. #9822 * Updates - Update Boost shipped on Windows to v1.82. #9816 - Update OpenSSL shipped on Windows to v3.0.9. #9816 - Update vendored https://github.com/nlohmann/json to v3.9.1. #9816 - Update vendored https://github.com/nemtrif/utfcpp to v3.2.3. #9816 - Update to 2.13.7 * Security - Windows: update bundled OpenSSL to v1.1.1t. #9672 * Bugfixes - SELinux: fix user and domain creation by explicitly setting the role. #9690 - Signal handlers: don't interrupt and break plugins spawning. #9682 - Icinga DB: take check\_period into account during overdue calculation. #9679 - Avoid corrupted files: use fsync(2)/FlushFileBuffers() everywhere. #9681 - Solaris: fix compile error. #9680 * Enhancements - Windows: update bundled Boost to v1.81. #9678 - Documentation: several fixes and improvements. #9671 Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2025-457=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 x86_64): icinga2-2.14.5-bp157.3.3.1 icinga2-bin-2.14.5-bp157.3.3.1 icinga2-common-2.14.5-bp157.3.3.1 icinga2-doc-2.14.5-bp157.3.3.1 icinga2-ido-mysql-2.14.5-bp157.3.3.1 icinga2-ido-pgsql-2.14.5-bp157.3.3.1 nano-icinga2-2.14.5-bp157.3.3.1 vim-icinga2-2.14.5-bp157.3.3.1 References: https://www.suse.com/security/cve/CVE-2024-49369.html https://bugzilla.suse.com/1084909 https://bugzilla.suse.com/1233310 . Update resolves important issue with icinga2 related to TLS certificate validation bypass. Immediate action required.. icinga2 update, openSUSE security, TLS security fix, important security patch, icinga2 vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 04, 2025 Important OpenSUSE
100

SUSE: 2024:0785-1 Important: Python3 TLS Bypass And Symlink Flaw

* bsc#1214692 * bsc#1219666 Cross-References: * CVE-2023-40217 . # Security update for python3 Announcement ID: SUSE-SU-2024:0785-1 Rating: important References: * bsc#1214692 * bsc#1219666 Cross-References: * CVE-2023-40217 * CVE-2023-6597 CVSS scores: * CVE-2023-40217 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2023-40217 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2023-6597 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 * Web and Scripting Module 12 An update that solves two vulnerabilities can now be installed. ## Description: This update for python3 fixes the following issues: * CVE-2023-40217: Fixed bypass TLS handshake on closed sockets (bsc#1214692). * CVE-2023-6597: Fixed symlink bug in cleanup (bsc#1219666). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Web and Scripting Module 12 zypper in -t patchSUSE-SLE-Module-Web-Scripting-12-2024-785=1 * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-785=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-785=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-785=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-785=1 ## Package List: * Web and Scripting Module 12 (aarch64 ppc64le s390x x86_64) * libpython3_4m1_0-3.4.10-25.124.1 * python3-curses-3.4.10-25.124.1 * libpython3_4m1_0-debuginfo-3.4.10-25.124.1 * python3-base-3.4.10-25.124.1 * python3-base-debugsource-3.4.10-25.124.1 * python3-base-debuginfo-3.4.10-25.124.1 * python3-3.4.10-25.124.1 * python3-debugsource-3.4.10-25.124.1 * python3-debuginfo-3.4.10-25.124.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * python3-devel-3.4.10-25.124.1 * python3-base-debugsource-3.4.10-25.124.1 * python3-base-debuginfo-3.4.10-25.124.1 * python3-dbm-3.4.10-25.124.1 * python3-debugsource-3.4.10-25.124.1 * python3-debuginfo-3.4.10-25.124.1 * python3-dbm-debuginfo-3.4.10-25.124.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (ppc64le s390x x86_64) * python3-devel-debuginfo-3.4.10-25.124.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * libpython3_4m1_0-3.4.10-25.124.1 * python3-curses-3.4.10-25.124.1 * libpython3_4m1_0-debuginfo-3.4.10-25.124.1 * python3-curses-debuginfo-3.4.10-25.124.1 * python3-base-3.4.10-25.124.1 * python3-base-debugsource-3.4.10-25.124.1 * python3-devel-3.4.10-25.124.1 * python3-base-debuginfo-3.4.10-25.124.1 * python3-3.4.10-25.124.1 * python3-debugsource-3.4.10-25.124.1 * python3-debuginfo-3.4.10-25.124.1 * python3-tk-3.4.10-25.124.1 *python3-tk-debuginfo-3.4.10-25.124.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * python3-devel-debuginfo-3.4.10-25.124.1 * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.124.1 * libpython3_4m1_0-32bit-3.4.10-25.124.1 * python3-base-debuginfo-32bit-3.4.10-25.124.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * libpython3_4m1_0-3.4.10-25.124.1 * python3-curses-3.4.10-25.124.1 * libpython3_4m1_0-debuginfo-3.4.10-25.124.1 * python3-curses-debuginfo-3.4.10-25.124.1 * python3-base-3.4.10-25.124.1 * python3-base-debugsource-3.4.10-25.124.1 * python3-devel-3.4.10-25.124.1 * python3-base-debuginfo-3.4.10-25.124.1 * python3-3.4.10-25.124.1 * python3-debugsource-3.4.10-25.124.1 * python3-debuginfo-3.4.10-25.124.1 * python3-tk-3.4.10-25.124.1 * python3-tk-debuginfo-3.4.10-25.124.1 * SUSE Linux Enterprise Server 12 SP5 (ppc64le s390x x86_64) * python3-devel-debuginfo-3.4.10-25.124.1 * SUSE Linux Enterprise Server 12 SP5 (s390x x86_64) * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.124.1 * libpython3_4m1_0-32bit-3.4.10-25.124.1 * python3-base-debuginfo-32bit-3.4.10-25.124.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * libpython3_4m1_0-3.4.10-25.124.1 * python3-curses-3.4.10-25.124.1 * libpython3_4m1_0-debuginfo-3.4.10-25.124.1 * python3-curses-debuginfo-3.4.10-25.124.1 * python3-base-3.4.10-25.124.1 * python3-base-debugsource-3.4.10-25.124.1 * python3-devel-3.4.10-25.124.1 * python3-base-debuginfo-3.4.10-25.124.1 * python3-3.4.10-25.124.1 * python3-debugsource-3.4.10-25.124.1 * python3-debuginfo-3.4.10-25.124.1 * python3-devel-debuginfo-3.4.10-25.124.1 * python3-tk-debuginfo-3.4.10-25.124.1 * python3-tk-3.4.10-25.124.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.124.1 * libpython3_4m1_0-32bit-3.4.10-25.124.1 *python3-base-debuginfo-32bit-3.4.10-25.124.1 ## References: * https://www.suse.com/security/cve/CVE-2023-40217.html * https://www.suse.com/security/cve/CVE-2023-6597.html * https://bugzilla.suse.com/show_bug.cgi?id=1214692 * https://bugzilla.suse.com/show_bug.cgi?id=1219666 . Important Python 3 security release for SUSE tackling vulnerabilities related to TLS handshake evasion and symlink attack flaws.. python3 update,SUSE patch,security advisory,cybersecurity update,SUSE vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 06, 2024 Important SuSE
172

Ubuntu 22.04 LTS USN-6513-2 moderate: Python DoS and TLS Bypass

Several security issues were fixed in Python.. ========================================================================== Ubuntu Security Notice USN-6513-2 November 27, 2023 python3.8, python3.10, python3.11 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in Python. Software Description: - python3.11: An interactive high-level object-oriented language - python3.10: An interactive high-level object-oriented language - python3.8: An interactive high-level object-oriented language Details: USN-6513-1 fixed vulnerabilities in Python. This update provides the corresponding updates for Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.04. Original advisory details: It was discovered that Python incorrectly handled certain plist files. If a user or an automated system were tricked into processing a specially crafted plist file, an attacker could possibly use this issue to consume resources, resulting in a denial of service. (CVE-2022-48564) It was discovered that Python instances of ssl.SSLSocket were vulnerable to a bypass of the TLS handshake. An attacker could possibly use this issue to cause applications to treat unauthenticated received data before TLS handshake as authenticated data after TLS handshake. (CVE-2023-40217) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: python3.11 3.11.4-1~23.04.1 Ubuntu 22.04 LTS: python3.10 3.10.12-1~22.04.3 Ubuntu 20.04 LTS: python3.8 3.8.10-0ubuntu1~20.04.9 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6513-2 https://ubuntu.com/security/notices/USN-6513-1 CVE-2023-40217 Package Information: https://launchpad.net/ubuntu/+source/python3.11/3.11.4-1~23.04.1 https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.3 . The latest Ubuntu release tackles vulnerabilities in Ruby, enhancing security measures and protecting systems from potential risks.. Ubuntu Security, Python Fixes, System Vulnerability, Linux Advisory, Python Update. . LinuxSecurity.com Team

Calendar%202 Nov 27, 2023 Ubuntu
98

Red Hat Enterprise Linux 8.6: RHSA-2023-5531-01 Important TLS Bypass

An update for python3 is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: python3 security update Advisory ID: RHSA-2023:5531-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5531 Issue date: 2023-10-09 CVE Names: CVE-2023-40217 ===================================================================== 1. Summary: An update for python3 is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.8.6) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS EUS (v.8.6) - aarch64, ppc64le, s390x, x86_64 3. Description: Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python: TLS handshake bypass (CVE-2023-40217) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2235789 - CVE-2023-40217 python: TLS handshake bypass 6. Package List: Red Hat Enterprise Linux AppStream EUS (v.8.6): aarch64: platform-python-debug-3.6.8-47.el8_6.2.aarch64.rpm platform-python-devel-3.6.8-47.el8_6.2.aarch64.rpm python3-debuginfo-3.6.8-47.el8_6.2.aarch64.rpm python3-debugsource-3.6.8-47.el8_6.2.aarch64.rpm python3-idle-3.6.8-47.el8_6.2.aarch64.rpm python3-tkinter-3.6.8-47.el8_6.2.aarch64.rpm ppc64le: platform-python-debug-3.6.8-47.el8_6.2.ppc64le.rpm platform-python-devel-3.6.8-47.el8_6.2.ppc64le.rpm python3-debuginfo-3.6.8-47.el8_6.2.ppc64le.rpm python3-debugsource-3.6.8-47.el8_6.2.ppc64le.rpm python3-idle-3.6.8-47.el8_6.2.ppc64le.rpm python3-tkinter-3.6.8-47.el8_6.2.ppc64le.rpm s390x: platform-python-debug-3.6.8-47.el8_6.2.s390x.rpm platform-python-devel-3.6.8-47.el8_6.2.s390x.rpm python3-debuginfo-3.6.8-47.el8_6.2.s390x.rpm python3-debugsource-3.6.8-47.el8_6.2.s390x.rpm python3-idle-3.6.8-47.el8_6.2.s390x.rpm python3-tkinter-3.6.8-47.el8_6.2.s390x.rpm x86_64: platform-python-3.6.8-47.el8_6.2.i686.rpm platform-python-debug-3.6.8-47.el8_6.2.i686.rpm platform-python-debug-3.6.8-47.el8_6.2.x86_64.rpm platform-python-devel-3.6.8-47.el8_6.2.i686.rpm platform-python-devel-3.6.8-47.el8_6.2.x86_64.rpm python3-debuginfo-3.6.8-47.el8_6.2.i686.rpm python3-debuginfo-3.6.8-47.el8_6.2.x86_64.rpm python3-debugsource-3.6.8-47.el8_6.2.i686.rpm python3-debugsource-3.6.8-47.el8_6.2.x86_64.rpm python3-idle-3.6.8-47.el8_6.2.i686.rpm python3-idle-3.6.8-47.el8_6.2.x86_64.rpm python3-test-3.6.8-47.el8_6.2.i686.rpm python3-tkinter-3.6.8-47.el8_6.2.i686.rpm python3-tkinter-3.6.8-47.el8_6.2.x86_64.rpm Red Hat Enterprise Linux BaseOS EUS(v.8.6): Source: python3-3.6.8-47.el8_6.2.src.rpm aarch64: platform-python-3.6.8-47.el8_6.2.aarch64.rpm python3-debuginfo-3.6.8-47.el8_6.2.aarch64.rpm python3-debugsource-3.6.8-47.el8_6.2.aarch64.rpm python3-libs-3.6.8-47.el8_6.2.aarch64.rpm python3-test-3.6.8-47.el8_6.2.aarch64.rpm ppc64le: platform-python-3.6.8-47.el8_6.2.ppc64le.rpm python3-debuginfo-3.6.8-47.el8_6.2.ppc64le.rpm python3-debugsource-3.6.8-47.el8_6.2.ppc64le.rpm python3-libs-3.6.8-47.el8_6.2.ppc64le.rpm python3-test-3.6.8-47.el8_6.2.ppc64le.rpm s390x: platform-python-3.6.8-47.el8_6.2.s390x.rpm python3-debuginfo-3.6.8-47.el8_6.2.s390x.rpm python3-debugsource-3.6.8-47.el8_6.2.s390x.rpm python3-libs-3.6.8-47.el8_6.2.s390x.rpm python3-test-3.6.8-47.el8_6.2.s390x.rpm x86_64: platform-python-3.6.8-47.el8_6.2.x86_64.rpm python3-debuginfo-3.6.8-47.el8_6.2.i686.rpm python3-debuginfo-3.6.8-47.el8_6.2.x86_64.rpm python3-debugsource-3.6.8-47.el8_6.2.i686.rpm python3-debugsource-3.6.8-47.el8_6.2.x86_64.rpm python3-libs-3.6.8-47.el8_6.2.i686.rpm python3-libs-3.6.8-47.el8_6.2.x86_64.rpm python3-test-3.6.8-47.el8_6.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-40217 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJlJBu+AAoJENzjgjWX9erETsAQAKhY4n2S1DHnsBPu5N1gwk21 MsOEGKvSk9fOL8+2T4FZIlqTwakdudj/HfpeD8ieoNI5NGQo0/CdlCUpg3cf2yxK 0UK5FEr/wKwVVKB0tTuwge7PHSuWvqVPKfqxtPdgJZRsXbJ4eNBh65fOFJ7Z7kiY +uKnqy8BnqEGt87uiO8HuphfoN7sLK7aWj6jsXpVm8lyJ3BLNqcxeUgM6iyrJmf6 nKTlKirIrSgKGgPfU6G7+WJGQHWP+gOKqmrnbeu6QwslP21uWsC3DNHLaGDFx5aZ cM4F+wxgZ+S+a4ZTfT2d5XKcdp459gD2IiZ8oAftschQPR9WIdP4kOD2p47qd/3k g9dH5lU+rinhZxLqXUyS5V1kd386p5ZjeUbX9Dv76k7DbGOoDEOlR5mK4ENrDstN WjYV+mREy51UNmrql0G8aZPDVmuIMmjLPq1KUGkW61MIOEaTcaKGxikIN/J2TYxm C5D92+qGV1zvbLHd2Bh7MmvrzC45F8TKIDXAw4x0cNDEF3y/DeiSXrzlBxTNG9KD 3jVnVV1LIu75qp5ZcM7z6y1UC+kSCTif56NWVGN5SDTzlUs6Uhyotw5Q6KSfHQLL EdujROpFBQRi/f0cAQHLFCp453A7Dl9sSkVps8BZJQj2s+1097JG4RYGebnNvK9K 9eFj8JEdpxo7J3c5VZH9 =fmrV -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A significant security update for python3 in Red Hat Enterprise Linux 8.6 resolves a TLS vulnerability that could lead to critical risks.. python3 Security Update, Red Hat Advisory, TLS Bypass Fix, Enterprise Linux Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 09, 2023 Important Red Hat
99

Slackware 14.1: 2016-141-01 Urgent: Curl TLS Security Bypass Issue

New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] curl (SSA:2016-141-01) New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. Here are the details from the Slackware 14.1 ChangeLog: +--------------------------+ patches/packages/curl-7.49.0-i486-1_slack14.1.txz: Upgraded. Fixed a TLS certificate check bypass with mbedTLS/PolarSSL. For more information, see: https://curl.se/docs/CVE-2016-3739.html https://www.cve.org/CVERecord?id=CVE-2016-3739 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 13.0: Updated package for Slackware x86_64 13.0: Updated package for Slackware 13.1: Updated package for Slackware x86_64 13.1: Updated package for Slackware 13.37: Updated package for Slackware x86_64 13.37: Updated package for Slackware 14.0: Updated package for Slackware x86_64 14.0: Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 13.0 package: d657e1ea76588050d686770665617019 curl-7.49.0-i486-1_slack13.0.txz Slackware x86_64 13.0 package: 9abe0a5a965d68287c418be47eea479b curl-7.49.0-x86_64-1_slack13.0.txz Slackware 13.1 package: 7235f0e3fb0a51ec1c1853b069d0f871 curl-7.49.0-i486-1_slack13.1.txz Slackware x86_64 13.1 package: 0585a8ef272683fb349cba00dd2b00b3 curl-7.49.0-x86_64-1_slack13.1.txz Slackware 13.37 package: b08998240795985d4571b8c0e102c077 curl-7.49.0-i486-1_slack13.37.txz Slackwarex86_64 13.37 package: d794f422f773c9d882ab56bc4cf89827 curl-7.49.0-x86_64-1_slack13.37.txz Slackware 14.0 package: f3183e6f2dec4ced5a939ca34def4b70 curl-7.49.0-i486-1_slack14.0.txz Slackware x86_64 14.0 package: 4e35da7c15e7adadaf377ec5998faa3f curl-7.49.0-x86_64-1_slack14.0.txz Slackware 14.1 package: 5019d5453754d35a124cf1bb7a3a10a7 curl-7.49.0-i486-1_slack14.1.txz Slackware x86_64 14.1 package: be69e1b1fa061c51ee0770e85bb1aeef curl-7.49.0-x86_64-1_slack14.1.txz Slackware -current package: a96e0edea184dbb4250dc226a29bd575 n/curl-7.49.0-i586-1.txz Slackware x86_64 -current package: 8aec9ab909548d72e415e55b89c4a1c8 n/curl-7.49.0-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg curl-7.49.0-i486-1_slack14.1.txz +-----+ . Curl libraries have been refreshed for Slackware to resolve a crucial TLS certificate bypass vulnerability. System update is advised to strengthen security measures.. Slackware Security,Curl TLS Fix,Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 20, 2016 Important Slackware
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200