Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 470
Alerts This Week
Warning Icon 1 470

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 12 articles for you...
197

Debian 11 Thunderbird Security Fix DLA-4594-1 Multiple Code Execution

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.11.0esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.. Debian LTS Advisory DLA-4594-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort May 22, 2026 https://wiki.debian.org/LTS Package : thunderbird Version : 1:140.11.0esr-1~deb11u1 CVE ID : CVE-2026-8388 CVE-2026-8391 CVE-2026-8401 CVE-2026-8946 CVE-2026-8947 CVE-2026-8950 CVE-2026-8953 CVE-2026-8954 CVE-2026-8955 CVE-2026-8956 CVE-2026-8957 CVE-2026-8958 CVE-2026-8961 CVE-2026-8962 CVE-2026-8968 CVE-2026-8970 CVE-2026-8974 CVE-2026-8975 Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.11.0esr-1~deb11u1. We recommend that you upgrade your thunderbird packages. For the detailed security status of thunderbird please refer to its security tracker page at: https://security-tracker.debian.org/tracker/thunderbird Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade Thunderbird in Debian 11 bullseye to fix multiple security issues and avoid code execution risks.. Debian package security, thunderbird update, arbitrary code execution, software patch, Debian security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 22, 2026 Critical Debian LTS
197

Debian 11 mbedtls DLA-4551-1 CVE-2025-59438 Timing Leak

CVE-2025-59438 Observable Timing Discrepancy. The presence of a padding error could leak through timings, enabling the attacker to recover information about the secret. CVE-2026-34871. Debian LTS Advisory DLA-4551-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Andrej Shadura April 27, 2026 https://wiki.debian.org/LTS Package : mbedtls Version : 2.16.9-0.1+deb11u4 CVE ID : CVE-2025-59438 CVE-2026-34871 CVE-2025-59438 Observable Timing Discrepancy. The presence of a padding error could leak through timings, enabling the attacker to recover information about the secret. CVE-2026-34871 On systems where getrandom() was not available, /dev/urandom would be used a fallback instead of /dev/random. For Debian 11 bullseye, these problems have been fixed in version 2.16.9-0.1+deb11u4. We recommend that you upgrade your mbedtls packages. For the detailed security status of mbedtls please refer to its security tracker page at: https://security-tracker.debian.org/tracker/mbedtls Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Explore the Debian LTS security advisory DLA-4551-1 for mbedtls vulnerabilities, including timing discrepancies and update recommendations.. Debian LTS, mbedtls security, timing discrepancy, information leak, security advisories. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 27, 2026 Important Debian LTS
91

Gentoo: GLSA-202407-02 Normal Severity: SDL_ttf Memory Write Issue

A vulnerability has been discovered in SDL_ttf, which can lead to arbitrary memory writes.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202407-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: SDL_ttf: Arbitrary Memory Write Date: July 01, 2024 Bugs: #843434 ID: 202407-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in SDL_ttf, which can lead to arbitrary memory writes. Background ========== SDL_ttf is a wrapper around the FreeType and Harfbuzz libraries, allowing you to use TrueType fonts to render text in SDL applications. Affected packages ================= Package Vulnerable Unaffected ------------------- ------------ ------------ media-libs/sdl2-ttf < 2.20.0 > = 2.20.0 Description =========== A vulnerability has been discovered in SDL_ttf. Please review the CVE identifier referenced below for details. Impact ====== SDL_ttf was discovered to contain an arbitrary memory write via the function TTF_RenderText_Solid(). This vulnerability is triggered via a crafted TTF file. Workaround ========== There is no known workaround at this time. Resolution ========== All SDL_ttf users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/sdl2-ttf-2.20.0" References ========== [ 1 ] CVE-2022-27470 https://nvd.nist.gov/vuln/detail/CVE-2022-27470 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202407-02 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines isof utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5 . A recent vulnerability in SDL_ttf has been discovered in Gentoo Linux, outlined in advisory GLSA 202407-02, categorized with normal severity. Users should update their systems promptly. Gentoo Linux, SDL_ttf, Arbitrary Memory Write, Security Updates, Software Vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Jul 01, 2024 Gentoo
89

Fedora 0.9.16 Critical: Ethereal Buffer Overflow Fix Released

These updated ethereal packages fix a security problem found in versions prior to 0.9.16. It also fixes several other minor bugs and problems. . ---------------------------------------------------------------------Fedora Update Notification FEDORA-2003-022 2003-11-25 ---------------------------------------------------------------------Name : ethereal Version : 0.9.16 Release : 2.FC1.1 Summary : Network traffic analyzer Description : Ethereal is a network traffic analyzer for Unix-ish operating systems. This package lays base for libpcap, a packet capture and filtering library, contains command-line utilities, contains plugins and documentation for ethereal. A graphical user interface is packaged separately to GTK+ package. ---------------------------------------------------------------------Update Information: These updated ethereal packages fix a security problem found in versions prior to 0.9.16. It also fixes several other minor bugs and problems. All users of ethereal are recommended to update to these newest packages. ---------------------------------------------------------------------* Tue Nov 25 2003 Phil Knirsch 0.9.16-2.FC1.1 - Added BuildRequires for elfutils-devel (#89466). - Fixed buggy desktop entry (#105704). - Fixed out of bound array access (#110749). - Build Fedora core 1 errata for ethereal. * Fri Nov 07 2003 Phil Knirsch 0.9.16-2 - rebuilt * Wed Nov 05 2003 Phil Knirsch 0.9.16-1 - Updated to latest upstream version 0.9.16 ---------------------------------------------------------------------This update can be downloaded from: SRPMS/ethereal-0.9.16-2.FC1.1.src.rpm md5 sum: 4fea34a2e0e7e6c48dde6b2c08de549d i386/ethereal-0.9.16-2.FC1.1.i386.rpm md5 sum: 7e2d061e1e1c08fa6da4ab292647d6b4 i386/ethereal-gnome-0.9.16-2.FC1.1.i386.rpm md5 sum: 0695ec2615b93668fecf2c750770815e i386/debug/ethereal-debuginfo-0.9.16-2.FC1.1.i386.rpm md5 sum: 670e64737be107e8c3e0c138de4c714a This update can also be installedwith the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . ---------------------------------------------------------------------Fedora Update Notification FEDO. these, updated, ethereal, packages, security, problem, found, versions, prior. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 08, 2023 Critical Fedora
197

Debian 10 Buster: DLA-3205-1 Moderate: Inetutils Buffer Oversight

Several security vulnerabilities were discovered in inetutils, a collection of common network programs. CVE-2019-0053 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3205-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin November 25, 2022 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : inetutils Version : 2:1.9.4-7+deb10u2 CVE ID : CVE-2019-0053 CVE-2021-40491 CVE-2022-39028 Debian Bug : 945861 956084 993476 Several security vulnerabilities were discovered in inetutils, a collection of common network programs. CVE-2019-0053 inetutils' telnet client doesn't sufficiently validate environment variables, which can lead to stack-based buffer overflows. This issue is limited to local exploitation from restricted shells. CVE-2021-40491 inetutils' ftp client before 2.2 does not validate addresses returned by PSV/LSPV responses to make sure they match the server address. A malicious server can exploit this flaw to reach services in the client's private network. (This is similar to curl's CVE-2020-8284.) CVE-2022-39028 inetutils's telnet server through 2.3 has a NULL pointer dereference which a client can trigger by sending 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many crashes within a short time interval, the telnet service would become unavailable after inetd logs a "telnet/tcp server failing (looping), service terminated" error. For Debian 10 buster, these problems have been fixed in version 2:1.9.4-7+deb10u2. We recommend that you upgrade your inetutils packages. For the detailed security status of inetutils please refer to its security tracker pageat: https://security-tracker.debian.org/tracker/source-package/inetutils Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Debian Long Term Support Advisory DLA-3205-1 identifies several security vulnerabilities in inetutils. It is advisable to upgrade promptly to maintain system integrity.. Debian LTS, inetutils, security update, buffer overflow, network program. . LinuxSecurity.com Team

Calendar%202 Nov 25, 2022 Debian LTS
172

Ubuntu: 5021-1 High: Curl Connection Handling Risks and Updates

Several security issues were fixed in curl.. =========================================================================Ubuntu Security Notice USN-5021-1 July 22, 2021 curl vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.04 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in curl. Software Description: - curl: HTTP, HTTPS, and FTP client and client libraries Details: Harry Sintonen and Tomas Hoger discovered that curl incorrectly handled TELNET connections when the -t option was used on the command line. Uninitialized data possibly containing sensitive information could be sent to the remote server, contrary to expectations. (CVE-2021-22898, CVE-2021-22925) Harry Sintonen discovered that curl incorrectly reused connections in the connection pool. This could result in curl reusing the wrong connections. (CVE-2021-22924) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.04: curl 7.74.0-1ubuntu2.1 libcurl3-gnutls 7.74.0-1ubuntu2.1 libcurl3-nss 7.74.0-1ubuntu2.1 libcurl4 7.74.0-1ubuntu2.1 Ubuntu 20.04 LTS: curl 7.68.0-1ubuntu2.6 libcurl3-gnutls 7.68.0-1ubuntu2.6 libcurl3-nss 7.68.0-1ubuntu2.6 libcurl4 7.68.0-1ubuntu2.6 Ubuntu 18.04 LTS: curl 7.58.0-2ubuntu3.14 libcurl3-gnutls 7.58.0-2ubuntu3.14 libcurl3-nss 7.58.0-2ubuntu3.14 libcurl4 7.58.0-2ubuntu3.14 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5021-1 CVE-2021-22898, CVE-2021-22924, CVE-2021-22925 PackageInformation: https://launchpad.net/ubuntu/+source/curl/7.74.0-1ubuntu2.1 https://launchpad.net/ubuntu/+source/curl/7.68.0-1ubuntu2.6 https://launchpad.net/ubuntu/+source/curl/7.58.0-2ubuntu3.14 . Numerous vulnerabilities resolved in curl impacting different Ubuntu versions. System update advised for enhanced security.. Curl Security Issues, Ubuntu Patch Updates, Security Recommendations. . LinuxSecurity.com Team

Calendar%202 Jul 22, 2021 Ubuntu
91

Gentoo: GLSA-202101-28 Normal Severity: ncurses Denial of Service

Multiple vulnerabilities have been found in ncurses, the worst of which could result in a Denial of Service condition.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202101-28 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: ncurses: Multiple vulnerabilities Date: January 26, 2021 Bugs: #698210 ID: 202101-28 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in ncurses, the worst of which could result in a Denial of Service condition. Background ========= A console display library. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-apps/ncurses < 6.2 > = 6.2 Description ========== Multiple vulnerabilities have been discovered in ncurses. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All ncurses users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-apps/ncurses-6.2" References ========= [ 1 ] CVE-2019-17594 https://nvd.nist.gov/vuln/detail/CVE-2019-17594 [ 2 ] CVE-2019-17595 https://nvd.nist.gov/vuln/detail/CVE-2019-17595 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202101-28 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuringthe confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2021 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Several security flaws identified in ncurses could result in Denial of Service (DoS) scenarios. It is advised that Gentoo users perform updates promptly.. Gentoo Security Updates,Ncurses Software Patch,Denial of Service Risk,Security Advisory,Software Vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Jan 25, 2021 Gentoo
91

Gentoo: GLSA-202012-05 Normal: Chromium And Google Chrome Code Risk

Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202012-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Chromium, Google Chrome: Multiple vulnerabilities Date: December 07, 2020 Bugs: #755227, #758368 ID: 202012-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execution of code. Background ========= Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web. Google Chrome is one fast, simple, and secure browser for all your devices. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-client/chromium < 87.0.4280.88 > = 87.0.4280.88 2 www-client/google-chrome < 87.0.4280.88 > = 87.0.4280.88 ------------------------------------------------------------------- 2 affected packages Description ========== Multiple vulnerabilities have been discovered in Chromium and Google Chrome. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Chromium users should upgrade to the latest version: #emerge --sync # emerge --ask --oneshot -v "> =www-client/chromium-87.0.4280.88" All Google Chrome users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =www-client/google-chrome-87.0.4280.88" References ========= [ 1 ] CVE-2020-16014 https://nvd.nist.gov/vuln/detail/CVE-2020-16014 [ 2 ] CVE-2020-16015 https://nvd.nist.gov/vuln/detail/CVE-2020-16015 [ 3 ] CVE-2020-16018 https://nvd.nist.gov/vuln/detail/CVE-2020-16018 [ 4 ] CVE-2020-16019 https://nvd.nist.gov/vuln/detail/CVE-2020-16019 [ 5 ] CVE-2020-16020 https://nvd.nist.gov/vuln/detail/CVE-2020-16020 [ 6 ] CVE-2020-16021 https://nvd.nist.gov/vuln/detail/CVE-2020-16021 [ 7 ] CVE-2020-16022 https://nvd.nist.gov/vuln/detail/CVE-2020-16022 [ 8 ] CVE-2020-16023 https://nvd.nist.gov/vuln/detail/CVE-2020-16023 [ 9 ] CVE-2020-16024 https://nvd.nist.gov/vuln/detail/CVE-2020-16024 [ 10 ] CVE-2020-16025 https://nvd.nist.gov/vuln/detail/CVE-2020-16025 [ 11 ] CVE-2020-16026 https://nvd.nist.gov/vuln/detail/CVE-2020-16026 [ 12 ] CVE-2020-16027 https://nvd.nist.gov/vuln/detail/CVE-2020-16027 [ 13 ] CVE-2020-16028 https://nvd.nist.gov/vuln/detail/CVE-2020-16028 [ 14 ] CVE-2020-16029 https://nvd.nist.gov/vuln/detail/CVE-2020-16029 [ 15 ] CVE-2020-16030 https://nvd.nist.gov/vuln/detail/CVE-2020-16030 [ 16 ] CVE-2020-16031 https://nvd.nist.gov/vuln/detail/CVE-2020-16031 [ 17 ] CVE-2020-16032 https://nvd.nist.gov/vuln/detail/CVE-2020-16032 [ 18 ] CVE-2020-16033 https://nvd.nist.gov/vuln/detail/CVE-2020-16033 [ 19 ] CVE-2020-16034 https://nvd.nist.gov/vuln/detail/CVE-2020-16034 [ 20 ] CVE-2020-16036 https://nvd.nist.gov/vuln/detail/CVE-2020-16036 [ 21 ] CVE-2020-16037 https://nvd.nist.gov/vuln/detail/CVE-2020-16037 [ 22 ] CVE-2020-16038 https://nvd.nist.gov/vuln/detail/CVE-2020-16038 [ 23 ] CVE-2020-16039 https://nvd.nist.gov/vuln/detail/CVE-2020-16039 [ 24 ] CVE-2020-16040 https://nvd.nist.gov/vuln/detail/CVE-2020-16040 [ 25 ] CVE-2020-16041 https://nvd.nist.gov/vuln/detail/CVE-2020-16041 [ 26 ] CVE-2020-16042 https://nvd.nist.gov/vuln/detail/CVE-2020-16042 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202012-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2020 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Various vulnerabilities in Chromium and Google Chrome might allow for unauthorized code execution. It is advised to update promptly to maintain security.. Chromium Security, Google Chrome Update, Code Execution Risk. . LinuxSecurity.com Team

Calendar%202 Dec 06, 2020 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200