Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
100

SUSE: 2023:0581-1 High: Python3 Memory Corruption Vulnerability

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python3 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0942-2 Rating: moderate References: #1186819 Cross-References: CVE-2021-3572 CVSS scores: CVE-2021-3572 (NVD) : 5.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N CVE-2021-3572 (SUSE): 4.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N Affected Products: SUSE Linux Enterprise Micro 5.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python3 fixes the following issues: - CVE-2021-3572: Fixed an improper handling of unicode characters in pip (bsc#1186819). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Micro 5.2: zypper in -t patch SUSE-SUSE-MicroOS-5.2-2022-942=1 Package List: - SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64): libpython3_6m1_0-3.6.15-150300.10.21.1 libpython3_6m1_0-debuginfo-3.6.15-150300.10.21.1 python3-3.6.15-150300.10.21.1 python3-base-3.6.15-150300.10.21.1 python3-base-debuginfo-3.6.15-150300.10.21.1 python3-core-debugsource-3.6.15-150300.10.21.1 python3-debuginfo-3.6.15-150300.10.21.1 python3-debugsource-3.6.15-150300.10.21.1 References: https://www.suse.com/security/cve/CVE-2021-3572.html https://bugzilla.suse.com/1186819 . Addresses a vulnerability concern in python3 as part of SUSE Security Update ID: SUSE-SU-2022:0942-2 targeting moderate risk flaws.. SUSE Linux Micro 5.2, python3 security advisory, SUSE updates. . LinuxSecurity.com Team

Calendar%202 Apr 19, 2022 SuSE
100

SUSE: 2022:0075-1 moderate: Python38-Pip Character Encoding Vulnerability

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python39-pip ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0064-1 Rating: moderate References: #1186819 Cross-References: CVE-2021-3572 CVSS scores: CVE-2021-3572 (SUSE): 4.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N Affected Products: SUSE Linux Enterprise Module for Basesystem 15-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python39-pip fixes the following issues: - CVE-2021-3572: Fixed incorrect handling of unicode separators in git references (bsc#1186819). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2022-64=1 Package List: - SUSE Linux Enterprise Module for Basesystem 15-SP3 (noarch): python39-pip-20.2.4-7.8.1 References: https://www.suse.com/security/cve/CVE-2021-3572.html https://bugzilla.suse.com/1186819 . SUSE Security Patch for python39-pip addresses a significant threat. Make sure your devices are enhanced as needed.. SUSE Security, Python Pip Update, Unicode Handling Issue. . LinuxSecurity.com Team

Calendar%202 Jan 12, 2022 SuSE
202

openSUSE Leap 15.3: 2021:4001-1 Moderate: Python-Pip Unicode Fix

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for python-pip ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:4001-1 Rating: moderate References: #1186819 Cross-References: CVE-2021-3572 CVSS scores: CVE-2021-3572 (SUSE): 4.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-pip fixes the following issues: - CVE-2021-3572: Fixed incorrect handling of unicode separators in git references (bsc#1186819). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-4001=1 Package List: - openSUSE Leap 15.3 (noarch): python2-pip-20.0.2-6.15.1 python3-pip-20.0.2-6.15.1 References: https://www.suse.com/security/cve/CVE-2021-3572.html https://bugzilla.suse.com/1186819 . This patch addresses a character encoding bug in python-pip for openSUSE Leap 15.3 categorized with moderate importance.. OpenSUSE Python-Pip Update Unicode Handling Security. . LinuxSecurity.com Team

Calendar%202 Dec 13, 2021 OpenSUSE
100

SUSE: 2021:4001-1 Moderate: Python-Pip Unicode Handling Issue

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-pip ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:4001-1 Rating: moderate References: #1186819 Cross-References: CVE-2021-3572 CVSS scores: CVE-2021-3572 (SUSE): 4.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N Affected Products: SUSE Linux Enterprise Module for Python2 15-SP3 SUSE Linux Enterprise Module for Python2 15-SP2 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-pip fixes the following issues: - CVE-2021-3572: Fixed incorrect handling of unicode separators in git references (bsc#1186819). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Python2 15-SP3: zypper in -t patch SUSE-SLE-Module-Python2-15-SP3-2021-4001=1 - SUSE Linux Enterprise Module for Python2 15-SP2: zypper in -t patch SUSE-SLE-Module-Python2-15-SP2-2021-4001=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2021-4001=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2021-4001=1 Package List: - SUSE Linux Enterprise Module for Python2 15-SP3 (noarch): python2-pip-20.0.2-6.15.1 - SUSE Linux Enterprise Module for Python2 15-SP2 (noarch): python2-pip-20.0.2-6.15.1 - SUSE Linux Enterprise Module for Basesystem15-SP3 (noarch): python3-pip-20.0.2-6.15.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (noarch): python3-pip-20.0.2-6.15.1 References: https://www.suse.com/security/cve/CVE-2021-3572.html https://bugzilla.suse.com/1186819 . A critical patch for python-pip addresses unicode delimiter processing, safeguarding overall system safety and performance.. SUSE Linux Update, Python Pip Security, Software Patch Management. . LinuxSecurity.com Team

Calendar%202 Dec 13, 2021 SuSE
89

Fedora 33: FEDORA-2021-1b6848f31c Critical: Pip Unicode Handling Issue

Security fix for *pip incorrectly handled unicode separators in git references*.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-1b6848f31c 2021-05-28 01:10:41.955444 --------------------------------------------------------------------------------Name : python-pip Product : Fedora 33 Version : 20.2.2 Release : 2.fc33 URL : https://pip.pypa.io/en/stable/ Summary : A tool for installing and managing Python packages Description : pip is a package management system used to install and manage software packages written in Python. Many packages can be found in the Python Package Index (PyPI). pip is a recursive acronym that can stand for either "Pip Installs Packages" or "Pip Installs Python". --------------------------------------------------------------------------------Update Information: Security fix for *pip incorrectly handled unicode separators in git references*. --------------------------------------------------------------------------------ChangeLog: * Mon May 17 2021 Karolina Surma - 20.2.2-2 - Backport security fix from pip 21.1.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #1962856 - python-pip: pip incorrectly handled unicode separators in git references https://bugzilla.redhat.com/show_bug.cgi?id=1962856 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-1b6848f31c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Emergency patch released for Fedora 33 addressing python-pip's management of Unicode delimiters in git links. Essential update information included.. Python Packaging,Pip Management,Fedora Security,Unicode Handling. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 27, 2021 Critical Fedora
89

Fedora 34: Advisory 2021-3f378dda90 Critical: Pip Unicode Handling Issue

- Security fix for CVE-2021-28363. - Security fix for *pip incorrectly handled unicode separators in git references*.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-3f378dda90 2021-05-24 01:00:24.873951 --------------------------------------------------------------------------------Name : python-pip Product : Fedora 34 Version : 21.0.1 Release : 3.fc34 URL : https://pip.pypa.io/en/stable/ Summary : A tool for installing and managing Python packages Description : pip is a package management system used to install and manage software packages written in Python. Many packages can be found in the Python Package Index (PyPI). pip is a recursive acronym that can stand for either "Pip Installs Packages" or "Pip Installs Python". --------------------------------------------------------------------------------Update Information: - Security fix for CVE-2021-28363. - Security fix for *pip incorrectly handled unicode separators in git references*. --------------------------------------------------------------------------------ChangeLog: * Mon May 17 2021 Karolina Surma - 21.0.1-3 - Backport security fixes from pip 21.1.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #1945136 - CVE-2021-28363 python-urllib3: HTTPS proxy host name not validated when using default SSLContext https://bugzilla.redhat.com/show_bug.cgi?id=1945136 [ 2 ] Bug #1962856 - python-pip: pip incorrectly handled unicode separators in git references https://bugzilla.redhat.com/show_bug.cgi?id=1962856 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-3f378dda90' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html Allpackages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora 34 has rolled out patches for `python-pip` that tackle significant security vulnerabilities related to unicode processing. It is essential to implement these updates without delay.. Fedora Updates,Pip Security Fixes,Unicode Handling Issues,Python Package Management,Package Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 23, 2021 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200