Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":2,"type":"x","order":2,"pct":66.67,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
219

Rocky Linux 8 Python39 Important TLS Connection Security Fix RLSA-2023-6001

Important: python39:3.9 and python39-devel:3.9 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:5998", "synopsis": "Important: python39:3.9 and python39-devel:3.9 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for module.python-cffi, module.python-more-itertools, python-cffi, python-chardet, python-attrs, module.numpy, python-ply, module.python3x-pyparsing, module.python-psutil, python-wcwidth, python-pycparser, python-psutil, module.python-chardet, module.python-pluggy, module.python-PyMySQL, python-PyMySQL, module.python-toml, python-pysocks, module.python-attrs, numpy, python-wheel, PyYAML, module.python-wcwidth, module.python-wheel, module.python3x-six, module.python-pycparser, pybind11, module.PyYAML, module.python-lxml, module.Cython, pytest, python3x-six, python-pluggy, python-toml, module.python-pysocks, module.python-iniconfig, python-iniconfig, python-packaging, module.pybind11, python-more-itertools, python-py, python-lxml, module.python-packaging, module.pytest, module.python-py, module.python-ply, Cython, python3x-pyparsing.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.\n\nSecurity Fix(es):\n\n* python: TLS handshake bypass (CVE-2023-40217)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2235789", "sourceBy": "Red Hat", "sourceLink":"https://bugzilla.redhat.com/show_bug.cgi?id=2235789", "description": ""}], "cves": [{"name": "CVE-2023-40217", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-40217", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N", "cvss3BaseScore": "8.6", "cwe": "CWE-305"}], "references": [], "publishedAt": "2026-03-18T06:01:13.733535Z", "rpms": {"Rocky Linux 8": {"nvras": ["Cython-0:0.29.21-5.module+el8.10.0+1582+bc278001.src.rpm", "Cython-0:0.29.21-5.module+el8.10.0+1860+afcc1c71.src.rpm", "Cython-debugsource-0:0.29.21-5.module+el8.10.0+1860+afcc1c71.aarch64.rpm", "Cython-debugsource-0:0.29.21-5.module+el8.10.0+1582+bc278001.aarch64.rpm", "Cython-debugsource-0:0.29.21-5.module+el8.10.0+1582+bc278001.x86_64.rpm", "Cython-debugsource-0:0.29.21-5.module+el8.10.0+1860+afcc1c71.x86_64.rpm", "numpy-0:1.19.4-3.module+el8.10.0+1860+afcc1c71.src.rpm", "numpy-0:1.19.4-3.module+el8.10.0+1582+bc278001.src.rpm", "numpy-debugsource-0:1.19.4-3.module+el8.10.0+1582+bc278001.aarch64.rpm", "numpy-debugsource-0:1.19.4-3.module+el8.10.0+1860+afcc1c71.aarch64.rpm", "numpy-debugsource-0:1.19.4-3.module+el8.10.0+1582+bc278001.x86_64.rpm", "numpy-debugsource-0:1.19.4-3.module+el8.10.0+1860+afcc1c71.x86_64.rpm", "pybind11-0:2.7.1-1.module+el8.9.0+1357+a3b80af7.src.rpm", "pytest-0:6.0.2-2.module+el8.10.0+1860+afcc1c71.src.rpm", "pytest-0:6.0.2-2.module+el8.10.0+1582+bc278001.src.rpm", "python39-attrs-0:20.3.0-2.module+el8.10.0+1860+afcc1c71.noarch.rpm", "python39-attrs-0:20.3.0-2.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-cffi-0:1.14.3-2.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-cffi-0:1.14.3-2.module+el8.10.0+1860+afcc1c71.aarch64.rpm", "python39-cffi-0:1.14.3-2.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-cffi-0:1.14.3-2.module+el8.10.0+1860+afcc1c71.x86_64.rpm", "python39-cffi-debuginfo-0:1.14.3-2.module+el8.10.0+1860+afcc1c71.aarch64.rpm", "python39-cffi-debuginfo-0:1.14.3-2.module+el8.10.0+1582+bc278001.aarch64.rpm","python39-cffi-debuginfo-0:1.14.3-2.module+el8.10.0+1860+afcc1c71.x86_64.rpm", "python39-cffi-debuginfo-0:1.14.3-2.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-chardet-0:3.0.4-19.module+el8.10.0+1860+afcc1c71.noarch.rpm", "python39-chardet-0:3.0.4-19.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-Cython-0:0.29.21-5.module+el8.10.0+1860+afcc1c71.aarch64.rpm", "python39-Cython-0:0.29.21-5.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-Cython-0:0.29.21-5.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-Cython-0:0.29.21-5.module+el8.10.0+1860+afcc1c71.x86_64.rpm", "python39-Cython-debuginfo-0:0.29.21-5.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-Cython-debuginfo-0:0.29.21-5.module+el8.10.0+1860+afcc1c71.aarch64.rpm", "python39-Cython-debuginfo-0:0.29.21-5.module+el8.10.0+1860+afcc1c71.x86_64.rpm", "python39-Cython-debuginfo-0:0.29.21-5.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-iniconfig-0:1.1.1-2.module+el8.9.0+1332+dd574197.noarch.rpm", "python39-lxml-0:4.6.5-1.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-lxml-0:4.6.5-1.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-lxml-debuginfo-0:4.6.5-1.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-lxml-debuginfo-0:4.6.5-1.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-more-itertools-0:8.5.0-2.module+el8.10.0+1860+afcc1c71.noarch.rpm", "python39-more-itertools-0:8.5.0-2.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-numpy-0:1.19.4-3.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-numpy-0:1.19.4-3.module+el8.10.0+1860+afcc1c71.aarch64.rpm", "python39-numpy-0:1.19.4-3.module+el8.10.0+1860+afcc1c71.x86_64.rpm", "python39-numpy-0:1.19.4-3.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-numpy-debuginfo-0:1.19.4-3.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-numpy-debuginfo-0:1.19.4-3.module+el8.10.0+1860+afcc1c71.aarch64.rpm", "python39-numpy-debuginfo-0:1.19.4-3.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-numpy-debuginfo-0:1.19.4-3.module+el8.10.0+1860+afcc1c71.x86_64.rpm","python39-numpy-doc-0:1.19.4-3.module+el8.10.0+1860+afcc1c71.noarch.rpm", "python39-numpy-doc-0:1.19.4-3.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-numpy-f2py-0:1.19.4-3.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-numpy-f2py-0:1.19.4-3.module+el8.10.0+1860+afcc1c71.aarch64.rpm", "python39-numpy-f2py-0:1.19.4-3.module+el8.10.0+1860+afcc1c71.x86_64.rpm", "python39-numpy-f2py-0:1.19.4-3.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-packaging-0:20.4-4.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-packaging-0:20.4-4.module+el8.10.0+1860+afcc1c71.noarch.rpm", "python39-pluggy-0:0.13.1-3.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-pluggy-0:0.13.1-3.module+el8.10.0+1860+afcc1c71.noarch.rpm", "python39-ply-0:3.11-10.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-ply-0:3.11-10.module+el8.10.0+1860+afcc1c71.noarch.rpm", "python39-psutil-0:5.8.0-4.module+el8.9.0+1357+a3b80af7.aarch64.rpm", "python39-psutil-0:5.8.0-4.module+el8.9.0+1357+a3b80af7.x86_64.rpm", "python39-psutil-debuginfo-0:5.8.0-4.module+el8.9.0+1357+a3b80af7.aarch64.rpm", "python39-psutil-debuginfo-0:5.8.0-4.module+el8.9.0+1357+a3b80af7.x86_64.rpm", "python39-py-0:1.10.0-1.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-py-0:1.10.0-1.module+el8.10.0+1860+afcc1c71.noarch.rpm", "python39-pybind11-0:2.7.1-1.module+el8.9.0+1357+a3b80af7.aarch64.rpm", "python39-pybind11-0:2.7.1-1.module+el8.9.0+1357+a3b80af7.x86_64.rpm", "python39-pybind11-devel-0:2.7.1-1.module+el8.9.0+1357+a3b80af7.aarch64.rpm", "python39-pybind11-devel-0:2.7.1-1.module+el8.9.0+1357+a3b80af7.x86_64.rpm", "python39-pycparser-0:2.20-3.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-pycparser-0:2.20-3.module+el8.10.0+1860+afcc1c71.noarch.rpm", "python39-PyMySQL-0:0.10.1-2.module+el8.10.0+1860+afcc1c71.noarch.rpm", "python39-PyMySQL-0:0.10.1-2.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-pyparsing-0:2.4.7-5.module+el8.10.0+1860+afcc1c71.noarch.rpm", "python39-pyparsing-0:2.4.7-5.module+el8.10.0+1582+bc278001.noarch.rpm","python39-pysocks-0:1.7.1-4.module+el8.10.0+1860+afcc1c71.noarch.rpm", "python39-pysocks-0:1.7.1-4.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-pytest-0:6.0.2-2.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-pytest-0:6.0.2-2.module+el8.10.0+1860+afcc1c71.noarch.rpm", "python39-pyyaml-0:5.4.1-1.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-pyyaml-0:5.4.1-1.module+el8.10.0+1860+afcc1c71.aarch64.rpm", "python39-pyyaml-0:5.4.1-1.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-pyyaml-0:5.4.1-1.module+el8.10.0+1860+afcc1c71.x86_64.rpm", "python39-pyyaml-debuginfo-0:5.4.1-1.module+el8.10.0+1860+afcc1c71.aarch64.rpm", "python39-pyyaml-debuginfo-0:5.4.1-1.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-pyyaml-debuginfo-0:5.4.1-1.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-pyyaml-debuginfo-0:5.4.1-1.module+el8.10.0+1860+afcc1c71.x86_64.rpm", "python39-six-0:1.15.0-3.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-six-0:1.15.0-3.module+el8.10.0+1860+afcc1c71.noarch.rpm", "python39-toml-0:0.10.1-5.module+el8.9.0+1332+dd574197.noarch.rpm", "python39-wcwidth-0:0.2.5-3.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-wcwidth-0:0.2.5-3.module+el8.10.0+1860+afcc1c71.noarch.rpm", "python39-wheel-1:0.35.1-4.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-wheel-1:0.35.1-4.module+el8.10.0+1860+afcc1c71.noarch.rpm", "python39-wheel-wheel-1:0.35.1-4.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-wheel-wheel-1:0.35.1-4.module+el8.10.0+1860+afcc1c71.noarch.rpm", "python3x-pyparsing-0:2.4.7-5.module+el8.10.0+1860+afcc1c71.src.rpm", "python3x-pyparsing-0:2.4.7-5.module+el8.10.0+1582+bc278001.src.rpm", "python3x-six-0:1.15.0-3.module+el8.10.0+1860+afcc1c71.src.rpm", "python3x-six-0:1.15.0-3.module+el8.10.0+1582+bc278001.src.rpm", "python-attrs-0:20.3.0-2.module+el8.10.0+1582+bc278001.src.rpm", "python-attrs-0:20.3.0-2.module+el8.10.0+1860+afcc1c71.src.rpm", "python-cffi-0:1.14.3-2.module+el8.10.0+1582+bc278001.src.rpm","python-cffi-0:1.14.3-2.module+el8.10.0+1860+afcc1c71.src.rpm", "python-cffi-debugsource-0:1.14.3-2.module+el8.10.0+1582+bc278001.aarch64.rpm", "python-cffi-debugsource-0:1.14.3-2.module+el8.10.0+1860+afcc1c71.aarch64.rpm", "python-cffi-debugsource-0:1.14.3-2.module+el8.10.0+1582+bc278001.x86_64.rpm", "python-cffi-debugsource-0:1.14.3-2.module+el8.10.0+1860+afcc1c71.x86_64.rpm", "python-chardet-0:3.0.4-19.module+el8.10.0+1582+bc278001.src.rpm", "python-chardet-0:3.0.4-19.module+el8.10.0+1860+afcc1c71.src.rpm", "python-chardet-0:3.0.4-19.module+el8.9.0+1418+f0d66789.src.rpm", "python-iniconfig-0:1.1.1-2.module+el8.9.0+1332+dd574197.src.rpm", "python-lxml-0:4.6.5-1.module+el8.10.0+1582+bc278001.src.rpm", "python-lxml-debugsource-0:4.6.5-1.module+el8.10.0+1582+bc278001.aarch64.rpm", "python-lxml-debugsource-0:4.6.5-1.module+el8.10.0+1582+bc278001.x86_64.rpm", "python-more-itertools-0:8.5.0-2.module+el8.10.0+1860+afcc1c71.src.rpm", "python-more-itertools-0:8.5.0-2.module+el8.10.0+1582+bc278001.src.rpm", "python-packaging-0:20.4-4.module+el8.10.0+1860+afcc1c71.src.rpm", "python-packaging-0:20.4-4.module+el8.10.0+1582+bc278001.src.rpm", "python-pluggy-0:0.13.1-3.module+el8.10.0+1860+afcc1c71.src.rpm", "python-pluggy-0:0.13.1-3.module+el8.10.0+1582+bc278001.src.rpm", "python-ply-0:3.11-10.module+el8.10.0+1582+bc278001.src.rpm", "python-ply-0:3.11-10.module+el8.10.0+1860+afcc1c71.src.rpm", "python-ply-0:3.11-10.module+el8.9.0+1418+f0d66789.src.rpm", "python-psutil-0:5.8.0-4.module+el8.9.0+1357+a3b80af7.src.rpm", "python-psutil-debugsource-0:5.8.0-4.module+el8.9.0+1357+a3b80af7.aarch64.rpm", "python-psutil-debugsource-0:5.8.0-4.module+el8.9.0+1357+a3b80af7.x86_64.rpm", "python-py-0:1.10.0-1.module+el8.10.0+1582+bc278001.src.rpm", "python-py-0:1.10.0-1.module+el8.10.0+1860+afcc1c71.src.rpm", "python-pycparser-0:2.20-3.module+el8.10.0+1582+bc278001.src.rpm", "python-pycparser-0:2.20-3.module+el8.10.0+1860+afcc1c71.src.rpm", "python-PyMySQL-0:0.10.1-2.module+el8.10.0+1860+afcc1c71.src.rpm","python-PyMySQL-0:0.10.1-2.module+el8.10.0+1910+234ad790.src.rpm", "python-PyMySQL-0:0.10.1-2.module+el8.10.0+1582+bc278001.src.rpm", "python-PyMySQL-0:0.10.1-2.module+el8.10.0+1592+61442852.src.rpm", "python-pysocks-0:1.7.1-4.module+el8.10.0+1860+afcc1c71.src.rpm", "python-pysocks-0:1.7.1-4.module+el8.9.0+1418+f0d66789.src.rpm", "python-pysocks-0:1.7.1-4.module+el8.10.0+1582+bc278001.src.rpm", "python-toml-0:0.10.1-5.module+el8.9.0+1332+dd574197.src.rpm", "python-wcwidth-0:0.2.5-3.module+el8.10.0+1860+afcc1c71.src.rpm", "python-wcwidth-0:0.2.5-3.module+el8.10.0+1582+bc278001.src.rpm", "python-wheel-1:0.35.1-4.module+el8.10.0+1582+bc278001.src.rpm", "python-wheel-1:0.35.1-4.module+el8.10.0+1860+afcc1c71.src.rpm", "PyYAML-0:5.4.1-1.module+el8.10.0+1860+afcc1c71.src.rpm", "PyYAML-0:5.4.1-1.module+el8.9.0+1418+f0d66789.src.rpm", "PyYAML-0:5.4.1-1.module+el8.10.0+1582+bc278001.src.rpm", "PyYAML-debugsource-0:5.4.1-1.module+el8.10.0+1582+bc278001.aarch64.rpm", "PyYAML-debugsource-0:5.4.1-1.module+el8.10.0+1860+afcc1c71.aarch64.rpm", "PyYAML-debugsource-0:5.4.1-1.module+el8.9.0+1418+f0d66789.aarch64.rpm", "PyYAML-debugsource-0:5.4.1-1.module+el8.10.0+1582+bc278001.x86_64.rpm", "PyYAML-debugsource-0:5.4.1-1.module+el8.9.0+1418+f0d66789.x86_64.rpm", "PyYAML-debugsource-0:5.4.1-1.module+el8.10.0+1860+afcc1c71.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux releases important python39 updates to resolve security risks including TLS handshake bypass vulnerability.. python39 security updates,RHSA-2023:5998,Rocky Linux patch,python vulnerability fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 18, 2026 Important Rocky Linux
99

Slackware 15.0: OpenVPN Important State Exhaustion Issue SSA:2025-323-01

New openvpn packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] openvpn (SSA:2025-323-01) New openvpn packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/openvpn-2.6.16-i586-1_slack15.0.txz: Upgraded. This update fixes a security issue: Fix memcmp check for the hmac verification in the 3way handshake. This bug renders the HMAC based protection against state exhaustion on receiving spoofed TLS handshake packets in the OpenVPN server inefficient. For more information, see: https://www.cve.org/CVERecord?id=CVE-2025-13086 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/openvpn-2.6.16-i586-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/openvpn-2.6.16-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/openvpn-2.6.16-i686-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/openvpn-2.6.16-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: f3800e33112d44d10d846224eb480e81 openvpn-2.6.16-i586-1_slack15.0.txz Slackware x86_64 15.0 package: cdaa50283a4666a8833606e3845e4f31 openvpn-2.6.16-x86_64-1_slack15.0.txz Slackware -current package: 0ad85260fe495647e4cc543207e65905 n/openvpn-2.6.16-i686-1.txz Slackwarex86_64 -current package: d911262d05d67dfc9f0f8f642a87b0f4 n/openvpn-2.6.16-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg openvpn-2.6.16-i586-1_slack15.0.txz +-----+ . New openvpn packages for Slackware 15.0 address security issues in the TLS handshake process. Upgrade recommended.. openvpn security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 19, 2025 Important Slackware
172

Ubuntu 25.04: OpenJDK 21 Severe Memory Issue USN-7668-1 CVE-2025-50106

Several security issues were fixed in OpenJDK 21.. ========================================================================== Ubuntu Security Notice USN-7668-1 July 24, 2025 openjdk-21 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in OpenJDK 21. Software Description: - openjdk-21: Open Source Java implementation Details: It was discovered that the 2D component of OpenJDK 21 did not properly manage memory under certain circumstances. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2025-30749, CVE-2025-50106) Mashroor Hasan Bhuiyan discovered that the JSSE component of OpenJDK 21 did not properly manage TLS 1.3 handshakes under certain circumstances. An attacker could possibly use this issue to obtain sensitive information. (CVE-2025-30754) Martin van Wingerden and Violeta Georgieva of Broadcom discovered that the Networking component of OpenJDK 24 did not properly manage network connections under certain circumstances. An attacker could possibly use this issue to obtain sensitive information. (CVE-2025-50059) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 openjdk-21-jdk 21.0.8+9~us1-0ubuntu1~25.04.1 openjdk-21-jdk-headless 21.0.8+9~us1-0ubuntu1~25.04.1 openjdk-21-jre 21.0.8+9~us1-0ubuntu1~25.04.1 openjdk-21-jre-headless 21.0.8+9~us1-0ubuntu1~25.04.1 openjdk-21-jre-zero 21.0.8+9~us1-0ubuntu1~25.04.1 Ubuntu 24.04 LTS openjdk-21-jdk 21.0.8+9~us1-0ubuntu1~24.04.1 openjdk-21-jdk-headless 21.0.8+9~us1-0ubuntu1~24.04.1 openjdk-21-jre 21.0.8+9~us1-0ubuntu1~24.04.1 openjdk-21-jre-headless 21.0.8+9~us1-0ubuntu1~24.04.1 openjdk-21-jre-zero 21.0.8+9~us1-0ubuntu1~24.04.1 Ubuntu 22.04 LTS openjdk-21-jdk 21.0.8+9~us1-0ubuntu1~22.04.1 openjdk-21-jdk-headless 21.0.8+9~us1-0ubuntu1~22.04.1 openjdk-21-jre 21.0.8+9~us1-0ubuntu1~22.04.1 openjdk-21-jre-headless 21.0.8+9~us1-0ubuntu1~22.04.1 openjdk-21-jre-zero 21.0.8+9~us1-0ubuntu1~22.04.1 Ubuntu 20.04 LTS openjdk-21-jdk 21.0.8+9~us1-0ubuntu1~20.04.1 Available with Ubuntu Pro openjdk-21-jdk-headless 21.0.8+9~us1-0ubuntu1~20.04.1 Available with Ubuntu Pro openjdk-21-jre 21.0.8+9~us1-0ubuntu1~20.04.1 Available with Ubuntu Pro openjdk-21-jre-headless 21.0.8+9~us1-0ubuntu1~20.04.1 Available with Ubuntu Pro openjdk-21-jre-zero 21.0.8+9~us1-0ubuntu1~20.04.1 Available with Ubuntu Pro This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart Java applications to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7668-1 CVE-2025-30749, CVE-2025-30754, CVE-2025-50059, CVE-2025-50106 Package Information: https://launchpad.net/ubuntu/+source/openjdk-21/21.0.8+9~us1-0ubuntu1~25.04.1 https://launchpad.net/ubuntu/+source/openjdk-21/21.0.8+9~us1-0ubuntu1~24.04.1 https://launchpad.net/ubuntu/+source/openjdk-21/21.0.8+9~us1-0ubuntu1~22.04.1 . Vital security patch released for OpenJDK 21 addressing memory handling and TLS vulnerabilities across various Ubuntu distributions.. OpenJDK Java Security, Ubuntu Java Update, Java 21 Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 25, 2025 Critical Ubuntu
197

Debian 11: DLA-3937-1 critical: nss memory issues and TLS handshake exploit

nss - Network Security Service libraries This is a set of libraries designed to support cross-platform development of security-enabled client and server applications. It can support SSLv2 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3937-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Arturo Borrero Gonzalez October 27, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : nss Version : 2:3.61-1+deb11u4 CVE ID : CVE-2024-0743 CVE-2024-6602 CVE-2024-6609 nss - Network Security Service libraries This is a set of libraries designed to support cross-platform development of security-enabled client and server applications. It can support SSLv2 and v4, TLS, PKCS #5, #7, #11, #12, S/MIME, X.509 v3 certificates and other security standards. Among other utilities, this package includes: * certutil: manages certificate and key databases (cert7.db and key3.db) * modutil: manages the database of PKCS11 modules (secmod.db) * pk12util: imports/exports keys and certificates between the cert/key databases and files in PKCS12 format. * shlibsign: creates .chk files for use in FIPS mode. * signtool: creates digitally-signed jar archives containing files and/or code. * ssltap: proxy requests for an SSL server and display the contents of the messages exchanged between the client and server. CVE-2024-0743 An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. CVE-2024-6602 A mismatch between allocator and deallocator could have lead to memory corruption. CVE-2024-6609 When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. For Debian 11 bullseye, these problems have been fixed in version 2:3.61-1+deb11u4. We recommend that you upgrade your nss packages. For thedetailed security status of nss please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/nss Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS has rolled out an update for nss libraries that fixes critical security vulnerabilities, including memory corruption and TLS issues, enhancing security and stability. nss libraries, Debian LTS, network security, software update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 28, 2024 Critical Debian LTS
91

Gentoo 202201-34: Mutt and NeoMutt Expose Sensitive Data Risks

A weakness was discovered in Mutt and NeoMutt's TLS handshake handling. To: This email address is being protected from spambots. You need JavaScript enabled to view it. Subject: [ GLSA 202101-32 ] Mutt, NeoMutt: Information disclosure - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202101-32 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Mutt, NeoMutt: Information disclosure Date: January 26, 2021 Bugs: #755833, #755866 ID: 202101-32 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A weakness was discovered in Mutt and NeoMutt's TLS handshake handling Background ========= Mutt is a small but very powerful text-based mail client. NeoMutt is a command line mail reader (or MUA). It’s a fork of Mutt with added features. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-client/mutt < 2.0.2 > = 2.0.2 2 mail-client/neomutt < 20201120 > = 20201120 ------------------------------------------------------------------- 2 affected packages Description ========== A weakness in TLS handshake handling was found which may allow information disclosure. Impact ===== A remote attacker may be able to cause information disclosure. Workaround ========= There is no known workaround at this time. Resolution ========= All Mutt users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-client/mutt-2.0.2" All NeoMutt users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=mail-client/neomutt-20201120" References ========= [ 1 ] CVE-2020-28896 https://nvd.nist.gov/vuln/detail/CVE-2020-28896 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202101-32 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2021 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Mutt and NeoMutt identified a vulnerability in the TLS handshake process that could lead to potential information leaks. It's advised to upgrade.. Mutt Information Disclosure, NeoMutt TLS Handshake, Linux Email Client Security. . LinuxSecurity.com Team

Calendar%202 Jan 26, 2021 Gentoo
100

SUSE: 2020:1770-1 Important: Squid TLS Handshake Denial of Service

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for squid ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:1770-1 Rating: important References: #1173304 Cross-References: CVE-2020-14059 Affected Products: SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for squid fixes the following issues: squid was updated to version 4.12 Security issue fixed: - CVE-2020-14059: Fixed an issue where a client could potentially deny the service of a server during TLS Handshake (bsc#1173304). Other issues addressed: - Reverted to slow search for new SMP shm pages due to a regression - Fixed an issue where negative responses were never cached - Fixed stall if transaction was overwriting a recently active cache entry Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2020-1770=1 Package List: - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): squid-4.12-4.12.1 squid-debuginfo-4.12-4.12.1 squid-debugsource-4.12-4.12.1 References: https://www.suse.com/security/cve/CVE-2020-14059.html https://bugzilla.suse.com/1173304 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Patch for nginx resolves CVE-2021-22951 with critical exposure to service disruption rectified.. SUSE Linux Security Update, squid Software Update, TLS Handshake Issue. .Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 26, 2020 Important SuSE
87

Debian: DSA-4663-1 High: OpenJDK-14 Denial Of Service Vulnerability

Several vulnerabilities have been discovered in the OpenJDK Java runtime, resulting in denial of service, insecure TLS handshakes, bypass of sandbox restrictions or HTTP response splitting attacks. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4662-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 24, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openjdk-11 CVE ID : CVE-2020-2754 CVE-2020-2755 CVE-2020-2756 CVE-2020-2757 CVE-2020-2767 CVE-2020-2773 CVE-2020-2778 CVE-2020-2781 CVE-2020-2800 CVE-2020-2803 CVE-2020-2805 CVE-2020-2816 CVE-2020-2830 Several vulnerabilities have been discovered in the OpenJDK Java runtime, resulting in denial of service, insecure TLS handshakes, bypass of sandbox restrictions or HTTP response splitting attacks. For the stable distribution (buster), these problems have been fixed in version 11.0.7+10-3~deb10u1. We recommend that you upgrade your openjdk-11 packages. For the detailed security status of openjdk-11 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/openjdk-11 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance OpenJDK-11 to mitigate various vulnerabilities such as denial of service attacks and unsafe TLS negotiation. . OpenJDK Security Advisory, Debian DSA-4662-1, Java Runtime Update, TLS Security Fix. . LinuxSecurity.com Team

Calendar%202 Apr 24, 2020 Debian
200

Scientific Linux 6 & 7 Moderate: SLSA-2016:0008-1 OpenSSL Update

Moderate: openssl security update. Date: Fri, 8 Jan 2016 14:31:35 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: openssl on SL6.x, SL7.x i386/x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Moderate: openssl security update Advisory ID: SLSA-2016:0008-1 Issue Date: 2016-01-07 CVE Numbers: CVE-2015-7575 -- A flaw was found in the way TLS 1.2 could use the MD5 hash function for signing ServerKeyExchange and Client Authentication packets during a TLS handshake. A man-in-the-middle attacker able to force a TLS connection to use the MD5 hash function could use this flaw to conduct collision attacks to impersonate a TLS server or an authenticated TLS client. (CVE-2015-7575) For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. -- SL6 x86_64 openssl-1.0.1e-42.el6_7.2.i686.rpm openssl-1.0.1e-42.el6_7.2.x86_64.rpm openssl-debuginfo-1.0.1e-42.el6_7.2.i686.rpm openssl-debuginfo-1.0.1e-42.el6_7.2.x86_64.rpm openssl-devel-1.0.1e-42.el6_7.2.i686.rpm openssl-devel-1.0.1e-42.el6_7.2.x86_64.rpm openssl-perl-1.0.1e-42.el6_7.2.x86_64.rpm openssl-static-1.0.1e-42.el6_7.2.x86_64.rpm i386 openssl-1.0.1e-42.el6_7.2.i686.rpm openssl-debuginfo-1.0.1e-42.el6_7.2.i686.rpm openssl-devel-1.0.1e-42.el6_7.2.i686.rpm openssl-perl-1.0.1e-42.el6_7.2.i686.rpm openssl-static-1.0.1e-42.el6_7.2.i686.rpm SL7 x86_64 openssl-1.0.1e-51.el7_2.2.x86_64.rpm openssl-debuginfo-1.0.1e-51.el7_2.2.i686.rpm openssl-debuginfo-1.0.1e-51.el7_2.2.x86_64.rpm openssl-libs-1.0.1e-51.el7_2.2.i686.rpm openssl-libs-1.0.1e-51.el7_2.2.x86_64.rpm openssl-devel-1.0.1e-51.el7_2.2.i686.rpm openssl-devel-1.0.1e-51.el7_2.2.x86_64.rpm openssl-perl-1.0.1e-51.el7_2.2.x86_64.rpm openssl-static-1.0.1e-51.el7_2.2.i686.rpm openssl-static-1.0.1e-51.el7_2.2.x86_64.rpm - Scientific Linux Development Team . Significant OpenSSL patch released for CentOS resolving vulnerabilities in the TLS handshakeprocess affecting client verification.. openssl security, scientific linux advisory, tls 1.2 issue, moderate security update. . LinuxSecurity.com Team

Calendar%202 Jan 08, 2016 Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":2,"type":"x","order":2,"pct":66.67,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200