Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
89

Fedora 43 Chromium Important CVE Multiple Issues Fix 2026-40cf884ac9

Update to 149.0.7827.114 CVE-2026-12007: Use after free Core CVE-2026-12008: Use after free DigitalCredentials CVE-2026-12009: Insufficient validation of untrusted input Accessibility CVE-2026-12010: Heap buffer overflow GPU. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-40cf884ac9 2026-06-19 01:08:57.989201+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 43 Version : 149.0.7827.114 Release : 1.fc43 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 149.0.7827.114 CVE-2026-12007: Use after free Core CVE-2026-12008: Use after free DigitalCredentials CVE-2026-12009: Insufficient validation of untrusted input Accessibility CVE-2026-12010: Heap buffer overflow GPU CVE-2026-12011: Use after free WebMIDI CVE-2026-12012: Use after free Network CVE-2026-12013: Use after free Media CVE-2026-12014: Use after free Cast CVE-2026-12015: Use after free Autofill CVE-2026-12016: Insufficient validation of untrusted input DevTools CVE-2026-12017: Insufficient validation of untrusted input Extensions CVE-2026-12018: Inappropriate implementation Mojo CVE-2026-12019: Out of bounds write Codecs CVE-2026-12020: Use after free Autofill CVE-2026-12022: Race Safe Browsing CVE-2026-12023: Use after free GPU CVE-2026-12024: Insufficient policy enforcement DevTools CVE-2026-12025: Insufficient validation of untrusted input Network CVE-2026-12026: Out of bounds read Video CVE-2026-12027: Insufficient policy enforcement Headless CVE-2026-12028: Use after free GPU CVE-2026-12029: Use after free Video CVE-2026-12030: Heap buffer overflow GPU CVE-2026-12031: Inappropriate implementation Views CVE-2026-12032: Inappropriate implementation Passwords CVE-2026-12033: Out of bounds read VideoCapture CVE-2026-12034: Insufficient validation of untrusted input Linux Toolkit Theming CVE-2026-12035: Use after free Views Disable AI Mode settings -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 12 2026 Than Ngo - 149.0.7827.114-1 - Update to 149.0.7827.114 * CVE-2026-12007: Use after free Core * CVE-2026-12008: Use after free DigitalCredentials * CVE-2026-12009: Insufficient validation of untrusted input Accessibility * CVE-2026-12010: Heap buffer overflow GPU * CVE-2026-12011: Use after free WebMIDI * CVE-2026-12012: Use after free Network * CVE-2026-12013: Use after free Media * CVE-2026-12014: Use after free Cast * CVE-2026-12015: Use after free Autofill * CVE-2026-12016: Insufficient validation of untrusted input DevTools * CVE-2026-12017: Insufficient validation of untrusted input Extensions * CVE-2026-12018: Inappropriate implementation Mojo * CVE-2026-12019: Out of bounds write Codecs * CVE-2026-12020: Use after free Autofill * CVE-2026-12022: Race Safe Browsing * CVE-2026-12023: Use after free GPU * CVE-2026-12024: Insufficient policy enforcement DevTools * CVE-2026-12025: Insufficient validation of untrusted input Network * CVE-2026-12026: Out of bounds read Video * CVE-2026-12027: Insufficient policy enforcement Headless * CVE-2026-12028: Use after free GPU * CVE-2026-12029: Use after free Video * CVE-2026-12030: Heap buffer overflow GPU * CVE-2026-12031: Inappropriate implementation Views * CVE-2026-12032: Inappropriate implementation Passwords * CVE-2026-12033: Out of bounds read VideoCapture * CVE-2026-12034: Insufficient validation of untrusted input Linux Toolkit Theming * CVE-2026-12035: Use after free Views - Disable AI Modesettings -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-40cf884ac9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . CVE-2026-12007 to CVE-2026-12035 address critical issues in Chromium on Fedora 43. Update now!. Chromium Heap Overflow Linux Fedora Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 18, 2026 Critical Fedora
217

Oracle Linux 10 ELSA-2025-14625 mod_http2 Moderate Untrusted Input

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-14625 http://linux.oracle.com/errata/ELSA-2025-14625.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: mod_http2-2.0.29-2.el10_0.1.x86_64.rpm aarch64: mod_http2-2.0.29-2.el10_0.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/mod_http2-2.0.29-2.el10_0.1.src.rpm Related CVEs: CVE-2025-49630 Description of changes: [2.0.29-2.1] - Resolves: RHEL-106263 - CVE-2025-49630 httpd: untrusted input from a client causes an assertion to fail in the Apache mod_proxy_http2 module _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 10 enhancements for mod_http2 resolve a Moderate concern involving unverified data from users that leads to malfunctions.. Oracle Linux 10, mod_http2, security patch, moderate alert, untrusted input. . LinuxSecurity.com Team

Calendar%202 Aug 27, 2025 Oracle
89

Fedora 39: FEDORA-2024-5d581b2365 critical: apache-commons-io DoS Risk

Fixes possible denial of service attack on untrusted input. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-5d581b2365 2024-10-20 00:53:34.129991 -------------------------------------------------------------------------------- Name : apache-commons-io Product : Fedora 39 Version : 2.11.0 Release : 5.fc39 URL : https://commons.apache.org/proper/commons-io/ Summary : Utilities to assist with developing IO functionality Description : Commons-IO contains utility classes, stream implementations, file filters, and endian classes. It is a library of utilities to assist with developing IO functionality. -------------------------------------------------------------------------------- Update Information: Fixes possible denial of service attack on untrusted input -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 4 2024 Mikolaj Izdebski - Fix possible denial of service attack on untrusted input - Resolves: rhbz#2316397 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2316397 - CVE-2024-47554 apache-commons-io: Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2316397 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-5d581b2365' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Crucial security patch for Fedora 39 tackling possible vulnerabilities through apache-commons-io to prevent service disruption.. Fedora 39 Security, apache-commons-io Update, Denial of Service Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 20, 2024 Critical Fedora
203

Mageia 8: MGASA-2022-0268 Critical: Chromium Update to 103.0.5060.134

The chromium-browser-stable package has been updated to version 103.0.5060.134 branch, fixing many bugs and 11 CVE. Some of them are listed below. Use after free in Guest View. (CVE-2022-2477) Use after free in PDF. (CVE-2022-2478) Insufficient validation of untrusted input in File. (CVE-2022-2479) . MGASA-2022-0268 - Updated chromium-browser-stable packages fix security vulnerability Publication date: 29 Jul 2022 URL: https://advisories.mageia.org/MGASA-2022-0268.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-2477, CVE-2022-2478, CVE-2022-2479, CVE-2022-2480, CVE-2022-2481, CVE-2022-2163 The chromium-browser-stable package has been updated to version 103.0.5060.134 branch, fixing many bugs and 11 CVE. Some of them are listed below. Use after free in Guest View. (CVE-2022-2477) Use after free in PDF. (CVE-2022-2478) Insufficient validation of untrusted input in File. (CVE-2022-2479) Use after free in Service Worker API. (CVE-2022-2480) Use after free in Views. (CVE-2022-2481) Use after free in Cast UI and Toolbar. (CVE-2022-2163) Various fixes from internal audits, fuzzing and other initiatives References: - https://bugs.mageia.org/show_bug.cgi?id=30655 - https://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop_19.html - https://blog.chromium.org/2022/05/chrome-103-beta-early-navigation-hints.html - https://www.cve.org/CVERecord?id=CVE-2022-2477 - https://www.cve.org/CVERecord?id=CVE-2022-2478 - https://www.cve.org/CVERecord?id=CVE-2022-2479 - https://www.cve.org/CVERecord?id=CVE-2022-2480 - https://www.cve.org/CVERecord?id=CVE-2022-2481 - https://www.cve.org/CVERecord?id=CVE-2022-2163 SRPMS: - 8/core/chromium-browser-stable-103.0.5060.134-1.mga8 . Recent enhancements to chromium-browser-stable in Mageia address a variety of security concerns. Uncover the vulnerabilities that have been resolved here.. chromium browser, Mageia 8, security updates, bug fixes, software patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 29, 2022 Critical Mageia
89

Fedora 33: rpki-client 2021-31012ee5a0 Security Advisory

rpki-client 7.5 untrusted input: - Fail repository synchronisation after 15min runtime. - Limit the number of repositories per TAL. - Don't allow `DOCTYPE` definitions in RRDP XML files. - Fix detection of HTTP redirect loops. * Limit the number of concurrent `rsync` processes. * Fix `CRLF` in TAL files.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-31012ee5a0 2021-11-18 01:57:22.428442 --------------------------------------------------------------------------------Name : rpki-client Product : Fedora 33 Version : 7.5 Release : 1.fc33 URL : https://www.rpki-client.org/ Summary : RPKI validator to support BGP Origin Validation Description : The OpenBSD rpki-client is a free, easy-to-use implementation of the Resource Public Key Infrastructure (RPKI) for Relying Parties (RP) to facilitate validation of the Route Origin of a BGP announcement. The program queries the RPKI repository system, downloads and validates Route Origin Authorisations (ROAs) and finally outputs Validated ROA Payloads (VRPs) in the configuration format of OpenBGPD, BIRD, and also as CSV or JSON objects for consumption by other routing stacks. --------------------------------------------------------------------------------Update Information: rpki-client 7.5 =============== * Make rpki-client more resilient regarding untrusted input: - Fail repository synchronisation after 15min runtime. - Limit the number of repositories per TAL. - Don't allow `DOCTYPE` definitions in RRDP XML files. - Fix detection of HTTP redirect loops. * Limit the number of concurrent `rsync` processes. * Fix `CRLF` in TAL files. --------------------------------------------------------------------------------ChangeLog: * Tue Nov 9 2021 Robert Scheck 7.5-1 - Upgrade to 7.5 (#2021523) --------------------------------------------------------------------------------References: [ 1 ] Bug #2021523 -rpki-client-7.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2021523 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-31012ee5a0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Enhancements for Fedora 33's rpki-client boost input management and resolve several challenges tied to repository syncing.. rpki-client, Fedora security, repository synchronization, BGP validation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 17, 2021 Critical Fedora
89

Fedora 35: 2021-c9852f0be4 Moderate: rpki-client Untrusted Input Fix

rpki-client 7.5 untrusted input: - Fail repository synchronisation after 15min runtime. - Limit the number of repositories per TAL. - Don't allow `DOCTYPE` definitions in RRDP XML files. - Fix detection of HTTP redirect loops. * Limit the number of concurrent `rsync` processes. * Fix `CRLF` in TAL files.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-c9852f0be4 2021-11-18 01:13:15.271873 --------------------------------------------------------------------------------Name : rpki-client Product : Fedora 35 Version : 7.5 Release : 1.fc35 URL : https://www.rpki-client.org/ Summary : RPKI validator to support BGP Origin Validation Description : The OpenBSD rpki-client is a free, easy-to-use implementation of the Resource Public Key Infrastructure (RPKI) for Relying Parties (RP) to facilitate validation of the Route Origin of a BGP announcement. The program queries the RPKI repository system, downloads and validates Route Origin Authorisations (ROAs) and finally outputs Validated ROA Payloads (VRPs) in the configuration format of OpenBGPD, BIRD, and also as CSV or JSON objects for consumption by other routing stacks. --------------------------------------------------------------------------------Update Information: rpki-client 7.5 =============== * Make rpki-client more resilient regarding untrusted input: - Fail repository synchronisation after 15min runtime. - Limit the number of repositories per TAL. - Don't allow `DOCTYPE` definitions in RRDP XML files. - Fix detection of HTTP redirect loops. * Limit the number of concurrent `rsync` processes. * Fix `CRLF` in TAL files. --------------------------------------------------------------------------------ChangeLog: * Tue Nov 9 2021 Robert Scheck 7.5-1 - Upgrade to 7.5 (#2021523) --------------------------------------------------------------------------------References: [ 1 ] Bug #2021523 -rpki-client-7.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2021523 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-c9852f0be4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Debian Security Alert for libcurl 7.81 mitigates buffer overflow, enhancing server communication.. rpki-client, repository update, Fedora 35, security advisory. . LinuxSecurity.com Team

Calendar%202 Nov 17, 2021 Fedora
89

Fedora: 2021-2f9642ec0c moderate: rpki-client Untrusted Input Issues

rpki-client 7.5 untrusted input: - Fail repository synchronisation after 15min runtime. - Limit the number of repositories per TAL. - Don't allow `DOCTYPE` definitions in RRDP XML files. - Fix detection of HTTP redirect loops. * Limit the number of concurrent `rsync` processes. * Fix `CRLF` in TAL files.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-2f9642ec0c 2021-11-18 01:06:07.484993 --------------------------------------------------------------------------------Name : rpki-client Product : Fedora 34 Version : 7.5 Release : 1.fc34 URL : https://www.rpki-client.org/ Summary : RPKI validator to support BGP Origin Validation Description : The OpenBSD rpki-client is a free, easy-to-use implementation of the Resource Public Key Infrastructure (RPKI) for Relying Parties (RP) to facilitate validation of the Route Origin of a BGP announcement. The program queries the RPKI repository system, downloads and validates Route Origin Authorisations (ROAs) and finally outputs Validated ROA Payloads (VRPs) in the configuration format of OpenBGPD, BIRD, and also as CSV or JSON objects for consumption by other routing stacks. --------------------------------------------------------------------------------Update Information: rpki-client 7.5 =============== * Make rpki-client more resilient regarding untrusted input: - Fail repository synchronisation after 15min runtime. - Limit the number of repositories per TAL. - Don't allow `DOCTYPE` definitions in RRDP XML files. - Fix detection of HTTP redirect loops. * Limit the number of concurrent `rsync` processes. * Fix `CRLF` in TAL files. --------------------------------------------------------------------------------ChangeLog: * Tue Nov 9 2021 Robert Scheck 7.5-1 - Upgrade to 7.5 (#2021523) --------------------------------------------------------------------------------References: [ 1 ] Bug #2021523 -rpki-client-7.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2021523 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-2f9642ec0c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora Patch Alert for rpki-tool correcting unverified data vulnerabilities and enhancing repository alignment.. rpki-client, Fedora, BGP validation, resource infrastructure. . LinuxSecurity.com Team

Calendar%202 Nov 17, 2021 Fedora
98

Red Hat: RHSA-2020-2471-01 Important Update: .NET Core Denial of Service

An update for .NET Core is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: .NET Core on Red Hat Enterprise Linux 8 security update Advisory ID: RHSA-2020:2471-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2471 Issue date: 2020-06-10 CVE Names: CVE-2020-1108 ==================================================================== 1. Summary: An update for .NET Core is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - x86_64 3. Description: .NET Core is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. A new version of .NET Core that addresses a security vulnerability is now available. The updated version is .NET Core Runtime 2.1.19 and SDK 2.1.515. Security Fix(es): * dotnet: Denial of service via untrusted input (CVE-2020-1108) This is an additional update to comprehensively address CVE-2020-1108. Default inclusions for applications built with .NET Core have been updated to reference the newest versions and their security fixes. For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1827643 - CVE-2020-1108 dotnet: Denial of service via untrusted input 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: dotnet-2.1.515-1.el8_2.src.rpm x86_64: dotnet-debuginfo-2.1.515-1.el8_2.x86_64.rpm dotnet-debugsource-2.1.515-1.el8_2.x86_64.rpm dotnet-host-fxr-2.1-2.1.19-1.el8_2.x86_64.rpm dotnet-host-fxr-2.1-debuginfo-2.1.19-1.el8_2.x86_64.rpm dotnet-runtime-2.1-2.1.19-1.el8_2.x86_64.rpm dotnet-runtime-2.1-debuginfo-2.1.19-1.el8_2.x86_64.rpm dotnet-sdk-2.1-2.1.515-1.el8_2.x86_64.rpm dotnet-sdk-2.1.5xx-2.1.515-1.el8_2.x86_64.rpm dotnet-sdk-2.1.5xx-debuginfo-2.1.515-1.el8_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-1108 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXuCsFtzjgjWX9erEAQj6KA//beE9DAZalm/Ax2Tj5HQtqkqtRGaIVaad u1uHo3KwlmO2ixwmBQJHJbMHfdWWU46jYNdfMh6QduQqi/LKLa+Cqb+68f2inqFb 7H0f0AlS6O3ta9W9jx40OC2xqMqkg5OjI3pm909RHLLtDjfXOFgz7FtTxiABsr1R imsU62VS1RnzQWY87/36l8k3JE2gSksx+tbWtcu94/6g18H6/4G1G1Sr8JvVYPPZ 6JbNTcjiATwHQP+QuitpTn+LXhbrRDzTb1EOH4H1JOXOWGCcjLZv4FA7Tw+O4A7N 7NR5sEl9ZA2dYliGvNTJndZgyWq3W2zpfigrkGQeHxKRvN5j7SSyf+K3H/t/eUv5 lANNeXwQp3PnQfxHHPHXt93GylA/Y+DmxMPiuTxPeq/uuQxPtEQf1I1UwVXkE2Mw XDnVKiIMVwnI7J7BWK+eYPDePH6oiX89QzqeJwnY30RwSvgLJ6gdlOwzQWU4xHtp 48vXGQ1LXb6iNKOjaHZUDuCFAqvYTkpMXyqzK+NcAIgsKoEg3WqoiaenTxMON1fV SQtGPxGNSyfBAgtJs04yKGoi621vr74H2gFxw7ghGH+zbqjrFMGVZCzdrmYeXSGU VnsCz+6WoOo/e8r091xBt055d/nQVbLmcGlll5MmPzU7iqtCXWXZZlJ7a9v9hm2R 1gTejqZdPx0=KO/H -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical update for .NET Core has been released for Red Hat Enterprise Linux 8, classified as Important, addressing a vulnerability that could lead to Denial of Service.. Red Hat Update, .NET Core Security, Denial of Service Fix, Red Hat Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 10, 2020 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200