Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
100

SUSE MariaDB Critical Security Fix 12 Vulnerabilities 2026-2330-1

An update that solves 12 vulnerabilities can now be installed.. # Security update for mariadb Announcement ID: SUSE-SU-2026:2330-1 Release Date: 2026-06-10T07:39:59Z Rating: critical References: * bsc#1259176 * bsc#1261413 * bsc#1266435 * bsc#1266437 * bsc#1266438 * bsc#1266439 * bsc#1266440 * bsc#1266441 * bsc#1266442 * bsc#1266814 * bsc#1266815 * bsc#1267542 Cross-References: * CVE-2026-34303 * CVE-2026-3494 * CVE-2026-35549 * CVE-2026-44168 * CVE-2026-44169 * CVE-2026-44170 * CVE-2026-44171 * CVE-2026-44172 * CVE-2026-44173 * CVE-2026-48163 * CVE-2026-48165 * CVE-2026-49261 CVSS scores: * CVE-2026-34303 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3494 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3494 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-3494 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3494 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-35549 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35549 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35549 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44168 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-44168 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-44169 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44169 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-44170 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-44171 ( SUSE ): 5.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44171 ( SUSE ): 6.3CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44172 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44173 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L * CVE-2026-44173 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L * CVE-2026-48163 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-48163 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-48165 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-48165 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-49261 ( SUSE ): 9.4 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-49261 ( SUSE ): 9.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * Galera for Ericsson 15 SP7 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 12 vulnerabilities can now be installed. ## Description: This update for mariadb fixes the following issues: * CVE-2026-3494: audit plugin comment handling bypass (bsc#1259176). * CVE-2026-34303: mysql: optimizer unspecified vulnerability (bsc#1266435). * CVE-2026-35549: SHA2 auth plugin crash on large packets (bsc#1261413). * CVE-2026-44168: wsrep SST unsafe parameter handling on the donor side (bsc#1266442). * CVE-2026-44169: authorization bypass in role-based routine-level privilege check exposes stored routine definitions (bsc#1266441). * CVE-2026-44170: argument injection in CONNECT REST Xcurl on Windows via unsanitized URL (bsc#1266440). * CVE-2026-44171: path traversal in mbstream (bsc#1266439). * CVE-2026-44172: mysql_real_escape_string() incorrectly handled big5 (bsc#1266438). * CVE-2026-44173: FILEprivilege was not checked for subqueries in the FROM clause (bsc#1266437). * CVE-2026-48163: wsrep SST unsafe parameter handling on the donor side (bsc#1266815). * CVE-2026-48165: unsafe usage of `wsrep_sst_receive_address` values on the joiner side (bsc#1266814). * CVE-2026-49261: unsafe parameter handling in `wsrep_notify_cmd` (bsc#1267542). Changes for mariadb: * Update to 11.8.8: https://mariadb.com/docs/release-notes/community- server/11.8/11.8.8 https://mariadb.com/docs/release-notes/community- server/changelogs/11.8/11.8.8 * Update to 11.8.7: https://mariadb.com/docs/release-notes/community- server/11.8/11.8.7 https://mariadb.com/docs/release-notes/community- server/changelogs/11.8/11.8.7 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2330=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2330=1 * Galera for Ericsson 15 SP7 zypper in -t patch SUSE-SLE-Product-SLES-15-SP7-ERICSSON-2026-2330=1 ## Package List: * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libmariadbd-devel-11.8.8-150700.3.15.1 * mariadb-debugsource-11.8.8-150700.3.15.1 * libmariadbd19-debuginfo-11.8.8-150700.3.15.1 * mariadb-11.8.8-150700.3.15.1 * mariadb-client-11.8.8-150700.3.15.1 * libmariadbd19-11.8.8-150700.3.15.1 * mariadb-client-debuginfo-11.8.8-150700.3.15.1 * mariadb-debuginfo-11.8.8-150700.3.15.1 * mariadb-tools-11.8.8-150700.3.15.1 * mariadb-tools-debuginfo-11.8.8-150700.3.15.1 * Server Applications Module 15-SP7 (noarch) * mariadb-errormessages-11.8.8-150700.3.15.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * mariadb-debuginfo-11.8.8-150700.3.15.1 *mariadb-debugsource-11.8.8-150700.3.15.1 * mariadb-galera-11.8.8-150700.3.15.1 * Galera for Ericsson 15 SP7 (x86_64) * mariadb-debuginfo-11.8.8-150700.3.15.1 * mariadb-debugsource-11.8.8-150700.3.15.1 * mariadb-galera-11.8.8-150700.3.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34303.html * https://www.suse.com/security/cve/CVE-2026-3494.html * https://www.suse.com/security/cve/CVE-2026-35549.html * https://www.suse.com/security/cve/CVE-2026-44168.html * https://www.suse.com/security/cve/CVE-2026-44169.html * https://www.suse.com/security/cve/CVE-2026-44170.html * https://www.suse.com/security/cve/CVE-2026-44171.html * https://www.suse.com/security/cve/CVE-2026-44172.html * https://www.suse.com/security/cve/CVE-2026-44173.html * https://www.suse.com/security/cve/CVE-2026-48163.html * https://www.suse.com/security/cve/CVE-2026-48165.html * https://www.suse.com/security/cve/CVE-2026-49261.html * https://bugzilla.suse.com/show_bug.cgi?id=1259176 * https://bugzilla.suse.com/show_bug.cgi?id=1261413 * https://bugzilla.suse.com/show_bug.cgi?id=1266435 * https://bugzilla.suse.com/show_bug.cgi?id=1266437 * https://bugzilla.suse.com/show_bug.cgi?id=1266438 * https://bugzilla.suse.com/show_bug.cgi?id=1266439 * https://bugzilla.suse.com/show_bug.cgi?id=1266440 * https://bugzilla.suse.com/show_bug.cgi?id=1266441 * https://bugzilla.suse.com/show_bug.cgi?id=1266442 * https://bugzilla.suse.com/show_bug.cgi?id=1266814 * https://bugzilla.suse.com/show_bug.cgi?id=1266815 * https://bugzilla.suse.com/show_bug.cgi?id=1267542 . Critical security update for MariaDB on SUSE resolves 12 vulnerabilities. Install recommended patches immediately.. MariaDB security patch, SUSE Linux vulnerabilities, critical update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 10, 2026 Critical SuSE
89

Fedora 43 python-ply Critical Unsafe Pickle Handling Fix 2026-516db080b7

Security fix for CVE-2025-56005. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-516db080b7 2026-03-29 00:48:39.566775+00:00 -------------------------------------------------------------------------------- Name : python-ply Product : Fedora 43 Version : 3.11 Release : 33.fc43 URL : http://www.dabeaz.com/ply/ Summary : Python Lex-Yacc Description : PLY is a straightforward lex/yacc implementation. Here is a list of its essential features: * It is implemented entirely in Python. * It uses LR-parsing which is reasonably efficient and well suited for larger grammars. * PLY provides most of the standard lex/yacc features including support for empty productions, precedence rules, error recovery, and support for ambiguous grammars. * PLY is straightforward to use and provides very extensive error checking. * PLY doesn't try to do anything more or less than provide the basic lex/yacc functionality. In other words, it's not a large parsing framework or a component of some larger system. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2025-56005 -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 25 2026 Charalampos Stratakis - 3.11-33 - Security fix for CVE-2025-56005 - Fixes: rhbz#2437981 * Sat Jan 17 2026 Fedora Release Engineering - 3.11-32 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Thu Dec 18 2025 Tom Callaway - 3.11-31 - fix build for Python 3.15 - use modern macros -------------------------------------------------------------------------------- References: [ 1 ] Bug #2437981 - CVE-2025-56005 python-ply: Unsafe pickle file handling in Ply [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2437981 -------------------------------------------------------------------------------- Thisupdate can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-516db080b7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Critical security fix for unsafe pickle handling in python-ply for Fedora 43. Protect your applications now!. Fedora security patch, python-ply update, critical security fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 29, 2026 Critical Fedora
89

Fedora 8: 2008-7619 Moderate: Unsafe Temp Directory Handling Fix

Update to R 2.7.2, also fixes security issue with unsafe temp directory handling in javareconf script.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2008-7619 2008-09-05 10:56:15 -------------------------------------------------------------------------------- Name : rpy Product : Fedora 8 Version : 1.0.3 Release : 3.fc8 URL : https://sourceforge.net/projects/rpy/ Summary : Python interface to the R language Description : RPy provides a robust Python interface to the R programming language. It can manage all kinds of R objects and can execute arbitrary R functions. All the errors from the R language are converted to Python exceptions. -------------------------------------------------------------------------------- Update Information: Update to R 2.7.2, also fixes security issue with unsafe temp directory handling in javareconf script. -------------------------------------------------------------------------------- ChangeLog: * Fri Aug 29 2008 Tom "spot" Callaway - 1.0.3-3 - rebuild against R-2.7.2 * Tue Jul 8 2008 Tom "spot" Callaway - 1.0.3-2 - rebuild against R 2.7.1 * Wed May 21 2008 José Matos - 1.0.3-1 - Update to 1.0.3 - Backport two patches from upstream (turn off debug and use the lapack version that R was compiled with) * Tue Apr 29 2008 Tom "spot" Callaway - 1.0.2-1 - update to 1.0.2 - R 2.7.0 * Wed Feb 13 2008 José Matos - 1.0.1-5 - BR texinfo -> texinfo-tex * Wed Feb 13 2008 José Matos - 1.0.1-4 - Rebuild for gcc 4.3 * Fri Feb 8 2008 Tom "spot" Callaway - 1.0.1-3 - rebuild for R 2.6.2 * Mon Feb 4 2008 José Matos - 1.0.1-2 - Sometimes _patch_'s guesses are not good enough. Redo patch to setup.py. * Sun Feb 3 2008 José Matos - 1.0.1-1 - New upstream release. * Mon Jan 7 2008 Tom "spot" Callaway - 1.0-0.7.RC3 - find the moved R headers in their new home (/usr/include/R) * Mon Jan 7 2008 Alex Lancaster - 1.0-0.6.RC3 - BuildRequires: R-devel rather than just R * MonNov 26 2007 Tom "spot" Callaway - 1.0-0.5.RC3 - really rebuild against R 2.6.1 - versioned buildrequires for R * Mon Nov 26 2007 Tom "spot" Callaway - 1.0-0.4.RC3 - rebuild against R 2.6.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #460658 - R: Insecure auxiliary /tmp file usage (symlink attack possible) https://bugzilla.redhat.com/show_bug.cgi?id=460658 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update rpy' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . R 2.7.2 update addresses a security vulnerability related to improper management of temporary directories in the javareconf script.. Fedora Update,rpy Update,Security Fix,Java Handling. . LinuxSecurity.com Team

Calendar%202 Sep 10, 2008 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200