Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
217

Oracle Linux 9 ELSA-2025-7409 moderate: git security update

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-7409 http://linux.oracle.com/errata/ELSA-2025-7409.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: git-2.47.1-2.el9_6.x86_64.rpm git-all-2.47.1-2.el9_6.noarch.rpm git-core-2.47.1-2.el9_6.x86_64.rpm git-core-doc-2.47.1-2.el9_6.noarch.rpm git-credential-libsecret-2.47.1-2.el9_6.x86_64.rpm git-daemon-2.47.1-2.el9_6.x86_64.rpm git-email-2.47.1-2.el9_6.noarch.rpm git-gui-2.47.1-2.el9_6.noarch.rpm git-instaweb-2.47.1-2.el9_6.noarch.rpm git-subtree-2.47.1-2.el9_6.x86_64.rpm git-svn-2.47.1-2.el9_6.noarch.rpm gitk-2.47.1-2.el9_6.noarch.rpm gitweb-2.47.1-2.el9_6.noarch.rpm perl-Git-2.47.1-2.el9_6.noarch.rpm perl-Git-SVN-2.47.1-2.el9_6.noarch.rpm aarch64: git-2.47.1-2.el9_6.aarch64.rpm git-all-2.47.1-2.el9_6.noarch.rpm git-core-2.47.1-2.el9_6.aarch64.rpm git-core-doc-2.47.1-2.el9_6.noarch.rpm git-credential-libsecret-2.47.1-2.el9_6.aarch64.rpm git-daemon-2.47.1-2.el9_6.aarch64.rpm git-email-2.47.1-2.el9_6.noarch.rpm git-gui-2.47.1-2.el9_6.noarch.rpm git-instaweb-2.47.1-2.el9_6.noarch.rpm git-subtree-2.47.1-2.el9_6.aarch64.rpm git-svn-2.47.1-2.el9_6.noarch.rpm gitk-2.47.1-2.el9_6.noarch.rpm gitweb-2.47.1-2.el9_6.noarch.rpm perl-Git-2.47.1-2.el9_6.noarch.rpm perl-Git-SVN-2.47.1-2.el9_6.noarch.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//git-2.47.1-2.el9_6.src.rpm Related CVEs: CVE-2024-52005 Description of changes: [2.47.1-2] - add the option to sanitize sideband channel messages - Resolves: RHEL-84513 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Advisory ELSA-2025-7410 enhances OpenSSL to address security flaws, now available on Unbreakable Linux Network.. Oracle Linux Updates, Git Security Patch, Unbreakable Network, ELSA Security Advisory, Linux RPMs. . LinuxSecurity.comTeam

Calendar%202 May 23, 2025 Oracle
217

Oracle Linux 8: ELSA-2025-1215 moderate: tbb security update

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1215 http://linux.oracle.com/errata/ELSA-2025-1215.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: python3-tbb-2018.2-10.el8_10.1.x86_64.rpm tbb-2018.2-10.el8_10.1.i686.rpm tbb-2018.2-10.el8_10.1.x86_64.rpm tbb-devel-2018.2-10.el8_10.1.i686.rpm tbb-devel-2018.2-10.el8_10.1.x86_64.rpm tbb-doc-2018.2-10.el8_10.1.x86_64.rpm aarch64: python3-tbb-2018.2-10.el8_10.1.aarch64.rpm tbb-2018.2-10.el8_10.1.aarch64.rpm tbb-devel-2018.2-10.el8_10.1.aarch64.rpm tbb-doc-2018.2-10.el8_10.1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//tbb-2018.2-10.el8_10.1.src.rpm Related CVEs: CVE-2020-11023 Description of changes: [2018.2-10.1] - Remove jQuery from Doxygen files (RHEL-77669) [2018.2-10] - Apply patches from (BZ #1907561) - Bump release _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Red Hat Enterprise Linux ELSA-2025-2025: recent patches for tbb with moderate risk now accessible through the Oracle Linux Network.. Oracle Linux Security, TBB Update, Unbreakable Network, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 13, 2025 Important Oracle
217

Oracle Linux 8 ELSA-2024-8121 Moderate: Java Update Security Advisory

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-8121 http://linux.oracle.com/errata/ELSA-2024-8121.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: java-11-openjdk-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-demo-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-devel-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-headless-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-javadoc-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-javadoc-zip-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-jmods-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-src-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-static-libs-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-demo-fastdebug-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-demo-slowdebug-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-devel-fastdebug-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-devel-slowdebug-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-fastdebug-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-headless-fastdebug-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-headless-slowdebug-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-jmods-fastdebug-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-jmods-slowdebug-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-slowdebug-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-src-fastdebug-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-src-slowdebug-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-static-libs-fastdebug-11.0.25.0.9-2.0.1.el8.x86_64.rpm java-11-openjdk-static-libs-slowdebug-11.0.25.0.9-2.0.1.el8.x86_64.rpm aarch64: java-11-openjdk-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-demo-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-devel-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-headless-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-javadoc-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-javadoc-zip-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-jmods-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-src-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-static-libs-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-demo-fastdebug-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-demo-slowdebug-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-devel-fastdebug-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-devel-slowdebug-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-fastdebug-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-headless-fastdebug-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-headless-slowdebug-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-jmods-fastdebug-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-jmods-slowdebug-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-slowdebug-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-src-fastdebug-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-src-slowdebug-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-static-libs-fastdebug-11.0.25.0.9-2.0.1.el8.aarch64.rpm java-11-openjdk-static-libs-slowdebug-11.0.25.0.9-2.0.1.el8.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//java-11-openjdk-11.0.25.0.9-2.0.1.el8.src.rpm Related CVEs: CVE-2023-48161 CVE-2024-21208 CVE-2024-21210 CVE-2024-21217 CVE-2024-21235 Description of changes: [1:11.0.25.0.9-2.0.1] - Add Oracle vendor bug URL [Orabug: 34340155] [1:11.0.25.0.9-2] - Update to jdk-11.0.25+9 (GA) - Update release notes to 11.0.25+9 - Switch to GA mode for release - Related: RHEL-58772 - ** This tarball is embargoed until 2024-10-15 @ 1pm PT. ** [1:11.0.25.0.8-0.2.ea] - Update to jdk-11.0.25+8 (EA) - Update release notes to 11.0.25+8 - Related: RHEL-58772 [1:11.0.25.0.7-0.3.ea] - RHJDKBP-875 - Added gating.yaml and/or rpminspect.yaml - RHJDKBP-874 - Remove - Related: RHEL-58772 [1:11.0.25.0.7-0.1.ea] - Update to jdk-11.0.25+7 (EA) - Update release notes to 11.0.25+7 - Related: RHEL-58772 [1:11.0.25.0.6-0.3.ea] - Limit Java only tests to one 'jdk_test_arch' - Resolves: RHEL-59727 - Related: RHEL-58772 [1:11.0.25.0.6-0.2.ea] - Update to jdk-11.0.25+6 (EA) - Switch to EA mode - Update release notes to 11.0.25+6 - Related: RHEL-58772 _______________________________________________ El-errata mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux ELSA-2024-8150 introduces improvements to Java 11, focusing on resolving multiple technical challenges. For further details, please visit the advisory section.. Oracle Linux, Java Update, Security Advisory, RPM Package, Security Fix. . LinuxSecurity.com Team

Calendar%202 Oct 21, 2024 Oracle
217

Oracle Linux 8 ELSA-2024-5654 Moderate: Curl Security Update

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-5654 http://linux.oracle.com/errata/ELSA-2024-5654.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: curl-7.61.1-34.el8_10.2.x86_64.rpm libcurl-7.61.1-34.el8_10.2.i686.rpm libcurl-7.61.1-34.el8_10.2.x86_64.rpm libcurl-devel-7.61.1-34.el8_10.2.i686.rpm libcurl-devel-7.61.1-34.el8_10.2.x86_64.rpm libcurl-minimal-7.61.1-34.el8_10.2.i686.rpm libcurl-minimal-7.61.1-34.el8_10.2.x86_64.rpm aarch64: curl-7.61.1-34.el8_10.2.aarch64.rpm libcurl-7.61.1-34.el8_10.2.aarch64.rpm libcurl-devel-7.61.1-34.el8_10.2.aarch64.rpm libcurl-minimal-7.61.1-34.el8_10.2.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//curl-7.61.1-34.el8_10.2.src.rpm Related CVEs: CVE-2024-2398 Description of changes: [7.61.1-34.el8_10.2] - provide common cleanup method for push headers (CVE-2024-2398) [7.61.1-34.el8_10.1] - fix incorrect backport of bz2229800 (RHEL-44684) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Notice ELSA-2024-5678 issued for wget enhancements tackling moderate vulnerability concerns.. Oracle Linux, Security Advisory, curl Update. . LinuxSecurity.com Team

Calendar%202 Aug 21, 2024 Oracle
217

Oracle Linux 7: ELSA-2023-7505 Critical Thunderbirds Threat Fix

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-7505 https://linux.oracle.com/errata/ELSA-2023-7505.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: thunderbird-115.5.0-1.0.1.el7_9.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates//thunderbird-115.5.0-1.0.1.el7_9.src.rpm Related CVEs: CVE-2023-6204 CVE-2023-6205 CVE-2023-6206 CVE-2023-6207 CVE-2023-6208 CVE-2023-6209 CVE-2023-6212 Description of changes: [115.5.0-1.0.1] - Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js - Enabled aarch64 build [115.5.0-1] - Update to 115.5.0 build1 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . The Ubuntu Security Advisory USN-2023-5678 highlights critical patches for Firefox, bolstering its protective features.. Oracle Linux Update, Thunderbird Fix, Security Advisory, Linux Patch, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 29, 2023 Critical Oracle
217

Enterprise Linux 4: ELSA-2007-0229 Low Severity: GDB Exec Issue

The following updated rpms for Enterprise Linux 4 have been uploaded to the Unbreakable Linux Network: . Enterprise Linux Security Advisory ELSA-2007-0229 https://access.redhat.com/errata/RHSA-2007:0229.html The following updated rpms for Enterprise Linux 4 have been uploaded to the Unbreakable Linux Network: i386: gdb-6.3.0.0-1.143.el4.i386.rpm x86_64: gdb-6.3.0.0-1.143.el4.x86_64.rpm SRPMS: https://oss.oracle.com:443/el4/SRPMS-updates/gdb-6.3.0.0-1.143.el4.src.rpm Description of changes: [ 6.3.0.0-1.143] - Fix unhandled race cases of exec() from threaded program (BZ 202689). - Add testcase for exec() from threaded program (BZ 202689). [6.3.0.0-1.142] - Fixed zombie threads regression from the stale threads crash fix (BZ 195429). [ 6.3.0.0-1.141] - Fix bogus 0x0 unwind of the thread's topmost function clone(3) (BZ 216506). [ 6.3.0.0-1.140] - Fix deadlock accessing invalid address; for corrupted backtraces (BZ 210614). [6.3.0.0-1.139] - Fix a race in Patch168 occasionally leaving processes stopped (BZ 202705). [6.3.0.0-1.138] - Fix `gcore' command for 32bit inferiors on 64bit hosts. [ 6.3.0.0-1.137] - Support TLS symbols for -lpthread programs w/o -debuginfo package (BZ 185337). - Suggest TLS `errno' resolving by hand if no -lpthread was found (BZ 185337). [6.3.0.0-1.136] - Do not step into asynchronously invoked signal handlers (BZ 202712). [6.3.0.0-1.135] - Avoid false warning on shared objects bfd close on ia64 (BZ 200402). - Bugfix segv on the source display by ^X 1 (fixes Patch130, BZ 200048). - Bugfix object names completion (fixes Patch116, BZ 193763). - Avoid crash of 'info threads' if stale threads exist (BZ 195429). - Fix occasional failure to load shared libraries (BZ 202682). - Fix exec() from threaded program, partial CVS backport (BZ 202689). [6.3.0.0-1.134] - Fix bug in patch for CVE-2006-4146. (BZ 203876) [6.3.0.0-1.133] - BuildReq flex, bison, sharutils and, on multilib systems, 32-bit glibc-devel. - Add slash between dir and file names in edit command (BZ 192261, BZ 199156). - Avoid overflows and underflows in dwarf expression computation stack. . Corporate Unix Safety Notification CUSA-2010-0155 for strace mitigates data inconsistency issues and enhances platform reliability.. Enterprise Linux Updates, GDB Security Fix, Security Advisories, Linux RPM Updates. . Severity: Low. LinuxSecurity.com Team

Calendar%202 May 17, 2007 Low Oracle
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200