Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 92 articles for you...
87

Debian Bookworm Dovecot Authentication Regression Fix DSA-6197-2

The Bookworm backport of the security fix for CVE-2025-59032 introduced a regression in authenticating against managesieved. For the oldstable distribution (bookworm), this problem has been fixed in version 1:2.3.19.1+dfsg1-2.1+deb12u3. We recommend that you upgrade your dovecot packages.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6197-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 06, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : dovecot The Bookworm backport of the security fix for CVE-2025-59032 introduced a regression in authenticating against managesieved. For the oldstable distribution (bookworm), this problem has been fixed in version 1:2.3.19.1+dfsg1-2.1+deb12u3. We recommend that you upgrade your dovecot packages. For the detailed security status of dovecot please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/dovecot Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Upgrade your Dovecot packages to fix authentication regression in Debian Bookworm caused by a recent security update.. Dovecot Upgrade, Debian Bookworm, Authentication Regression, Security Advisory, Vulnerability Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 06, 2026 Important Debian
197

Debian 11: DLA-4024-1 critical: POCO integer overflow issue

An integer overflow in Poco::UTF32Encoding() hase been fixed in the POCO C++ libraries for building network-based applications. For Debian 11 bullseye, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4024-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk January 20, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : poco Version : 1.10.0-6+deb11u2 CVE ID : CVE-2023-52389 An integer overflow in Poco::UTF32Encoding() hase been fixed in the POCO C++ libraries for building network-based applications. For Debian 11 bullseye, this problem has been fixed in version 1.10.0-6+deb11u2. We recommend that you upgrade your poco packages. For the detailed security status of poco please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/poco Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Integer overflow vulnerability addressed in POCO libraries for Debian LTS. Please upgrade to the patched version immediately.. Integer Overflow, Poco Libraries, Debian LTS, Security Advisory, C++ Applications. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 20, 2025 Critical Debian LTS
197

Debian 11 bullseye DLA-3895-1 critical: puredata setuid issue addressed

The realtime computer music and graphics system puredata does now terminate when dropping setuid privileges failed. For Debian 11 bullseye, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3895-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk September 25, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : puredata Version : 0.51.4-1+deb11u1 CVE ID : CVE-2023-47480 The realtime computer music and graphics system puredata does now terminate when dropping setuid privileges failed. For Debian 11 bullseye, this problem has been fixed in version 0.51.4-1+deb11u1. We recommend that you upgrade your puredata packages. For the detailed security status of puredata please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/puredata Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A high-severity security flaw in Puredata could cause privilege escalation. Users should promptly update to version 0.50-2+deb10u1 to ensure system security. Debian LTS, puredata security, setuid updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 25, 2024 Critical Debian LTS
197

Debian 10: DLA-3835-1 Severe: Roundcube Cross-Site Scripting Risks

Cross-site scripting (XSS) vulnerabilities were discovered in Roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could allow a remote attacker to load arbitrary JavaScript code and might lead to privilege escalation or information disclosure. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3835-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin June 17, 2024 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : roundcube Version : 1.3.17+dfsg.1-1~deb10u6 CVE ID : CVE-2024-37383 CVE-2024-37384 Debian Bug : 1071474 Cross-site scripting (XSS) vulnerabilities were discovered in Roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could allow a remote attacker to load arbitrary JavaScript code and might lead to privilege escalation or information disclosure. CVE-2024-37383 Valentin T. and Lutz Wolf of CrowdStrike discovered that Roundcube allows XSS via SVG animate attributes. CVE-2024-37384 Huy NguyỠn Phạm Nhật discovered that Roundcube allows XSS via list columns from user preferences. For Debian 10 buster, these problems have been fixed in version 1.3.17+dfsg.1-1~deb10u6. We recommend that you upgrade your roundcube packages. For the detailed security status of roundcube please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/roundcube Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Debian LTS advisory DLA-3836-1 highlights critical vulnerabilities in the DokuWiki software. Users are urged to perform updates to enhance system security.. Debian Security, Roundcube Updates, XSSFixes, LTS Advisory. . LinuxSecurity.com Team

Calendar%202 Jun 17, 2024 Debian LTS
91

Gentoo: GLSA-202402-14 High: QtWebEngine Multiple Risks Detected

Multiple vulnerabilities have been discovered in QtWebEngine, the worst of which could lead to remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202402-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: QtWebEngine: Multiple Vulnerabilities Date: February 18, 2024 Bugs: #922189 ID: 202402-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in QtWebEngine, the worst of which could lead to remote code execution. Background ========== QtWebEngine is a library for rendering dynamic web content in Qt5 and Qt6 C++ and QML applications. Affected packages ================= Package Vulnerable Unaffected ------------------ ------------------- -------------------- dev-qt/qtwebengine < 5.15.12_p20240122 > = 5.15.12_p20240122 Description =========== Multiple vulnerabilities have been discovered in QtWebEngine. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All QtWebEngine users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-qt/qtwebengine-5.15.12_p20240122" References ========== [ 1 ] CVE-2023-5997 https://nvd.nist.gov/vuln/detail/CVE-2023-5997 [ 2 ] CVE-2023-6112 https://nvd.nist.gov/vuln/detail/CVE-2023-6112 [ 3 ] CVE-2023-6345 https://nvd.nist.gov/vuln/detail/CVE-2023-6345 [ 4 ] CVE-2023-6346 https://nvd.nist.gov/vuln/detail/CVE-2023-6346 [ 5 ] CVE-2023-6347 https://nvd.nist.gov/vuln/detail/CVE-2023-6347 [ 6 ]CVE-2023-6348 https://nvd.nist.gov/vuln/detail/CVE-2023-6348 [ 7 ] CVE-2023-6350 https://nvd.nist.gov/vuln/detail/CVE-2023-6350 [ 8 ] CVE-2023-6351 https://nvd.nist.gov/vuln/detail/CVE-2023-6351 [ 9 ] CVE-2023-6508 https://nvd.nist.gov/vuln/detail/CVE-2023-6508 [ 10 ] CVE-2023-6509 https://nvd.nist.gov/vuln/detail/CVE-2023-6509 [ 11 ] CVE-2023-6510 https://nvd.nist.gov/vuln/detail/CVE-2023-6510 [ 12 ] CVE-2023-6511 https://nvd.nist.gov/vuln/detail/CVE-2023-6511 [ 13 ] CVE-2023-6512 https://nvd.nist.gov/vuln/detail/CVE-2023-6512 [ 14 ] CVE-2023-6702 https://nvd.nist.gov/vuln/detail/CVE-2023-6702 [ 15 ] CVE-2023-6703 https://nvd.nist.gov/vuln/detail/CVE-2023-6703 [ 16 ] CVE-2023-6704 https://nvd.nist.gov/vuln/detail/CVE-2023-6704 [ 17 ] CVE-2023-6705 https://nvd.nist.gov/vuln/detail/CVE-2023-6705 [ 18 ] CVE-2023-6706 https://nvd.nist.gov/vuln/detail/CVE-2023-6706 [ 19 ] CVE-2023-6707 https://nvd.nist.gov/vuln/detail/CVE-2023-6707 [ 20 ] CVE-2023-7024 https://nvd.nist.gov/vuln/detail/CVE-2023-7024 [ 21 ] CVE-2024-0222 https://nvd.nist.gov/vuln/detail/CVE-2024-0222 [ 22 ] CVE-2024-0223 https://nvd.nist.gov/vuln/detail/CVE-2024-0223 [ 23 ] CVE-2024-0224 https://nvd.nist.gov/vuln/detail/CVE-2024-0224 [ 24 ] CVE-2024-0225 https://nvd.nist.gov/vuln/detail/CVE-2024-0225 [ 25 ] CVE-2024-0333 https://nvd.nist.gov/vuln/detail/CVE-2024-0333 [ 26 ] CVE-2024-0517 https://nvd.nist.gov/vuln/detail/CVE-2024-0517 [ 27 ] CVE-2024-0518 https://nvd.nist.gov/vuln/detail/CVE-2024-0518 [ 28 ] CVE-2024-0519 https://nvd.nist.gov/vuln/detail/CVE-2024-0519 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202402-14 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concernsshould be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Mitigating critical security flaws in QtWebEngine is essential for Gentoo users. Prioritize safety and update now!. QtWebEngine Vulnerabilities, Gentoo Upgrade, Remote Execution, High Severity Issues. . LinuxSecurity.com Team

Calendar%202 Feb 18, 2024 Gentoo
91

Gentoo: GLSA-202401-18 High: zlib Buffer Overflow Threat Detected

A vulnerability has been found in zlib that can lead to a heap-based buffer overflow.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202401-18 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: zlib: Buffer Overflow Date: January 15, 2024 Bugs: #916484 ID: 202401-18 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been found in zlib that can lead to a heap-based buffer overflow. Background ========== zlib is a widely used free and patent unencumbered data compression library. Affected packages ================= Package Vulnerable Unaffected ------------- ------------ ------------ sys-libs/zlib < 1.2.13-r2 > = 1.2.13-r2 Description =========== A vulnerability has been discovered in zlib. Please review the CVE identifier referenced below for details. Impact ====== MiniZip in zlib through 1.3 has an integer overflow and resultant heap- based buffer overflow in ZipOpenNewFileInZip4_64 via a long filename, comment, or extra field. Workaround ========== There is no known workaround at this time. Resolution ========== All zlib users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-libs/zlib-1.2.13-r2" References ========== [ 1 ] CVE-2023-45853 https://nvd.nist.gov/vuln/detail/CVE-2023-45853 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202401-18 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressedto This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Critical alert for Gentoo users regarding a severe zlib vulnerability. Update at once to protect your systems.. zlib buffer overflow,high severity advisory,gentoo upgrade recommendation,security threats. . LinuxSecurity.com Team

Calendar%202 Jan 15, 2024 Gentoo
197

Debian 10 DLA-3440-1 Critical Fix: Cups Buffer Overflow DoS Issue

An issue has been found in cups, the Common UNIX Printing System. Due to a buffer overflow vulnerability in the function format_log_line() a remote attackers could cause a denial-of-service(DoS). The vulnerability . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3440-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz June 01, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : cups Version : 2.2.10-6+deb10u7 CVE ID : CVE-2023-32324 An issue has been found in cups, the Common UNIX Printing System. Due to a buffer overflow vulnerability in the function format_log_line() a remote attackers could cause a denial-of-service(DoS). The vulnerability can be triggered when the configuration file cupsd.conf sets the value of "loglevel" to "DEBUG". For Debian 10 buster, this problem has been fixed in version 2.2.10-6+deb10u7. We recommend that you upgrade your cups packages. For the detailed security status of cups please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/cups Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-5683-1 addresses significant security vulnerability in Apache. Users are urged to update to prevent potential exploitation.. cups security, Debian LTS, DoS fix, buffer overflow, Linux printing. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 01, 2023 Critical Debian LTS
197

Debian 10 Buster: DLA-3334-1 Critical: Sofia-Sip DoS Update

Denial of service (crash) via a crafted UDP message that leads to internal assert was fixed in sofia-sip, a SIP (Session Initiation Protocol) User-Agent library. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3334-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk February 22, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : sofia-sip Version : 1.12.11+20110422.1-2.1+deb10u3 CVE ID : CVE-2022-47516 Debian Bug : 1031792 Denial of service (crash) via a crafted UDP message that leads to internal assert was fixed in sofia-sip, a SIP (Session Initiation Protocol) User-Agent library. For Debian 10 buster, this problem has been fixed in version 1.12.11+20110422.1-2.1+deb10u3. We recommend that you upgrade your sofia-sip packages. For the detailed security status of sofia-sip please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/sofia-sip Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . An update has been released for sofia-sip to resolve a Denial of Service vulnerability linked to specially designed UDP packets. It is advised to upgrade promptly.. sofiasip, denial of service, debian security, udp message, security update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 22, 2023 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200