Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 43 opkssh Important Update CVE-2026-39828 CVE-2026-39830

Update bundled golang.org/x/crypto to 0.53.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-12d4cde449 2026-07-02 01:07:29.331951+00:00 -------------------------------------------------------------------------------- Name : opkssh Product : Fedora 43 Version : 0.14.0 Release : 3.fc43 URL : https://github.com/openpubkey/opkssh Summary : OpenPubkey SSH Description : OpenPubkey SSH is a tool which enables ssh to be used with OpenID Connect allowing SSH access to be managed via identities like This email address is being protected from spambots. You need JavaScript enabled to view it. instead of long-lived SSH keys. -------------------------------------------------------------------------------- Update Information: Update bundled golang.org/x/crypto to 0.53.0 -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 22 2026 Till Hofmann - 0.14.0-3 - Update bundled golang.org/x/crypto to 0.53.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2489950 - CVE-2026-39828 opkssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489950 [ 2 ] Bug #2490498 - CVE-2026-39830 opkssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490498 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-12d4cde449' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Learn about the Fedora 43 opkssh update fixing critical issues with denial of service risks and unauthorized commands.. OpenPubkey SSH, Fedora 43, security advisory, golang.org crypto, denial of service. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 01, 2026 Important Fedora
98

Red Hat: RHSA-2017-3189-01 Important: Jackson-Databind Code Execution

An update for rh-eclipse47-jackson-databind is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: rh-eclipse47-jackson-databind security update Advisory ID: RHSA-2017:3189-01 Product: Red Hat Developer Tools Advisory URL: https://access.redhat.com/errata/RHSA-2017:3189 Issue date: 2017-11-13 CVE Names: CVE-2017-15095 ==================================================================== 1. Summary: An update for rh-eclipse47-jackson-databind is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7) - noarch Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7) - noarch 3. Description: The jackson-databind package provides general data-binding functionality for Jackson, which works on top of Jackson core streaming API. Security Fix(es): * A deserialization flaw was discovered in the jackson-databind which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously. (CVE-2017-15095) Red Hat would like to thank Liao Xinxi (NSFOCUS) for reporting this issue. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1506612 - CVE-2017-15095 jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-7525) 6. Package List: Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7): Source: rh-eclipse47-jackson-databind-2.7.6-3.3.el7.src.rpm noarch: rh-eclipse47-jackson-databind-2.7.6-3.3.el7.noarch.rpm rh-eclipse47-jackson-databind-javadoc-2.7.6-3.3.el7.noarch.rpm Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7): Source: rh-eclipse47-jackson-databind-2.7.6-3.3.el7.src.rpm noarch: rh-eclipse47-jackson-databind-2.7.6-3.3.el7.noarch.rpm rh-eclipse47-jackson-databind-javadoc-2.7.6-3.3.el7.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2017-15095 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2017 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFaCR6mXlSAg2UNWIIRArTDAJ97zSWosYMnDCr9SgvRIIi3PIMdZwCeJA9y XpdkSIBpifOcj4QQND2ELOQ=Wpd1 -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical patch released for rh-eclipse47-jackson-databind addresses vulnerabilities that could allow for unauthorized code execution. Discover more details here.. Red Hat security,jackson-databind,developer tools update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 13, 2017 Important Red Hat
197

Debian 7: DLA-1122-1 Critical Asterisk Command Injection Advisory

A security vulnerability was discovered in Asterisk, an Open Source PBX and telephony toolkit, that may lead to unauthorized command execution. . Hash: SHA512 Package : asterisk Version : 1:1.8.13.1~dfsg1-3+deb7u7 CVE ID : CVE-2017-14100 Debian Bug : 873908 A security vulnerability was discovered in Asterisk, an Open Source PBX and telephony toolkit, that may lead to unauthorized command execution. The app_minivm module has an "externnotify" program configuration option that is executed by the MinivmNotify dialplan application. The application uses the caller-id name and number as part of a built string passed to the OS shell for interpretation and execution. Since the caller-id name and number can come from an untrusted source, a crafted caller-id name or number allows an arbitrary shell command injection. For Debian 7 "Wheezy", these problems have been fixed in version 1:1.8.13.1~dfsg1-3+deb7u7. We recommend that you upgrade your asterisk packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Security patches for Asterisk address command injection weaknesses impacting Debian LTS. Enhanced protection through upgrade is advised.. Asterisk Security Update, Debian LTS Advisory, Command Injection Risk, Open Source PBX, Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 05, 2017 Critical Debian LTS
89

Fedora 24 Smb4k: Critical Threat Due To Unauthorized Execution

Security fix for CVE-2017-8849. https://kde.org/info/security/advisory-20170510-2.txt. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-aceb424894 2017-05-22 00:11:26.944147 --------------------------------------------------------------------------------Name : smb4k Product : Fedora 24 Version : 1.2.2 Release : 3.fc24 URL : https://sourceforge.net/p/smb4k/home/Home/ Summary : The SMB/CIFS Share Browser for KDE Description : Smb4K is an SMB/CIFS share browser for KDE. It uses the Samba software suite to access the SMB/CIFS shares of the local network neighborhood. Its purpose is to provide a program that's easy to use and has as many features as possible. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-8849. https://kde.org/info/security/advisory-20170510-2.txt --------------------------------------------------------------------------------References: [ 1 ] Bug #1449658 - CVE-2017-8849 smb4k: unauthorized local command execution as root [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1449658 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade smb4k' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Patch released for smb4k resolving exploit risk linked to unauthorized commandexecution in Fedora 24 software release.. smb4k Security Update, Fedora Software Vulnerability, SMB/CIFS Security Fix, Unauthorized Execution Fedora. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 22, 2017 Critical Fedora
89

Fedora 25: Update for smb4k Moderate Risk of Command Execution

Security fix for CVE-2017-8849. https://kde.org/info/security/advisory-20170510-2.txt. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-2cc18e2b3b 2017-05-20 03:07:28.221106 --------------------------------------------------------------------------------Name : smb4k Product : Fedora 25 Version : 1.2.2 Release : 3.fc25 URL : https://sourceforge.net/p/smb4k/home/Home/ Summary : The SMB/CIFS Share Browser for KDE Description : Smb4K is an SMB/CIFS share browser for KDE. It uses the Samba software suite to access the SMB/CIFS shares of the local network neighborhood. Its purpose is to provide a program that's easy to use and has as many features as possible. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-8849. https://kde.org/info/security/advisory-20170510-2.txt --------------------------------------------------------------------------------References: [ 1 ] Bug #1449658 - CVE-2017-8849 smb4k: unauthorized local command execution as root [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1449658 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade smb4k' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 25 releases important smb4k patch.Safeguard your machine from potential threats of local command execution vulnerabilities.. smb4k Update,Fedora 25 Security,smb4k Command Execution Issue. . LinuxSecurity.com Team

Calendar%202 May 20, 2017 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200