Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 512
Alerts This Week
Warning Icon 1 512

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
89

Fedora 43 vaultwarden Critical DoS and Access Issues Fix 2026-264f9ef567

update to 1.36.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-264f9ef567 2026-06-12 01:07:40.519543+00:00 -------------------------------------------------------------------------------- Name : vaultwarden Product : Fedora 43 Version : 1.36.0 Release : 1.fc43 URL : https://github.com/dani-garcia/vaultwarden Summary : Unofficial Bitwarden compatible server Description : Unofficial Bitwarden compatible server. -------------------------------------------------------------------------------- Update Information: update to 1.36.0 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 3 2026 Jonathan Wright - 1.36.0-1 - update to 1.36.0 rhbz#2368636 - Fix bitwarden mobile app not working rhbz#2437599 - Fix CVE-2025-58160 vaultwarden: Tracing log pollution - Fix CVE-2026-25537 vaultwarden: jsonwebtoken has Type Confusion that leads to potential authorization bypass - Fix CVE-2026-25727 vaultwarden: time affected by a stack exhaustion denial of service attack - Fix CVE-2026-26012 vaultwarden: Information disclosure due to bypassed collection permissions - Fix CVE-2026-27898 vaultwarden: Information disclosure via API partial update - Fix CVE-2026-27803 vaultwarden: Unauthorized collection management operations due to improper access control - Fix CVE-2026-27801 vaultwarden: Two-factor authentication bypass allows unauthorized access and data deletion * Sat Jan 17 2026 Fedora Release Engineering - 1.34.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Tue Jul 29 2025 Jonathan Wright - 1.34.2-1 - update to 1.34.2 rhbz#2368636 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2437473 - CVE-2026-25537 vaultwarden: jsonwebtoken has Type Confusion that leads to potential authorization bypass [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2437473 [ 2 ] Bug #2438166 - CVE-2026-25727 vaultwarden: time affected by a stack exhaustion denial of service attack [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2438166 [ 3 ] Bug #2439261 - CVE-2026-26012 vaultwarden: Vaultwarden: Information disclosure due to bypassed collection permissions [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2439261 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-264f9ef567' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Vaultwarden update to 1.36.0 for Fedora 43 addresses several security weaknesses; critical fixes included.. vaultwarden update Fedora 43 security fixes authorization bypass. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 11, 2026 Critical Fedora
89

Fedora 41: FEDORA-2025-5f07738947 critical: vaultwarden update

update to 1.33.2 fix CVE-2025-24898. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-5f07738947 2025-02-23 02:07:31.516788+00:00 -------------------------------------------------------------------------------- Name : vaultwarden Product : Fedora 41 Version : 1.33.2 Release : 1.fc41 URL : https://github.com/dani-garcia/vaultwarden Summary : Unofficial Bitwarden compatible server Description : Unofficial Bitwarden compatible server. -------------------------------------------------------------------------------- Update Information: update to 1.33.2 fix CVE-2025-24898 -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 10 2025 Jonathan Wright - 1.33.2-1 - update to 1.33.2 rhbz#2343535 Fix CVE-2025-0977 ssl::select_next_proto use after free rhbz#2344558 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-5f07738947' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do notreply to spam, report it: . Fedora Update Alert FEDORA-2025-8d6a0f2e04 upgrades vaultwarden to resolve security vulnerabilities on Mar 10, 2025.. Vaultwarden Security Update,Fedora 41 Patch,Critical Software Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 23, 2025 Critical Fedora
89

Fedora 40: 2025-0e5d6864d8 Critical: vaultwarden CVE-2025-24898 Update

update to 1.33.2 fix CVE-2025-24898. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-0e5d6864d8 2025-02-23 02:01:51.623894+00:00 -------------------------------------------------------------------------------- Name : vaultwarden Product : Fedora 40 Version : 1.33.2 Release : 1.fc40 URL : https://github.com/dani-garcia/vaultwarden Summary : Unofficial Bitwarden compatible server Description : Unofficial Bitwarden compatible server. -------------------------------------------------------------------------------- Update Information: update to 1.33.2 fix CVE-2025-24898 -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 10 2025 Jonathan Wright - 1.33.2-1 - update to 1.33.2 rhbz#2343535 Fix CVE-2025-0977 ssl::select_next_proto use after free rhbz#2344558 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-0e5d6864d8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do notreply to spam, report it: . Debian Security Alert concerning Nextcloud highlights critical vulnerabilities such as CVE-2025-25899 with version 22.1.3.. Fedora Security Update,Vaultwarden Upgrade,CVE Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 23, 2025 Critical Fedora
89

Fedora 40: FEDORA-2025-7fd2f66440 urgent: vaultwarden RCE Vulnerability

update to 1.33.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-7fd2f66440 2025-02-09 01:30:07.778658+00:00 -------------------------------------------------------------------------------- Name : vaultwarden Product : Fedora 40 Version : 1.33.0 Release : 1.fc40 URL : https://github.com/dani-garcia/vaultwarden Summary : Unofficial Bitwarden compatible server Description : Unofficial Bitwarden compatible server. -------------------------------------------------------------------------------- Update Information: update to 1.33.0 -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 30 2025 Jonathan Wright - 1.33.0-1 - update to 1.33.0 rhbz#2342073 Fix GHSA-f7r5-w49x-gxm3 Getting access to the Admin Panel via CSRF Fix CVE-2025-24364 RCE in the admin panel Fix CVE-2025-24365 escalation of privilege via variable confusion in OrgHeaders trait -------------------------------------------------------------------------------- References: [ 1 ] Bug #2342347 - CVE-2025-24365 vaultwarden: vaultwarden allows escalation of privilege via variable confusion in OrgHeaders trait [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2342347 [ 2 ] Bug #2342352 - CVE-2025-24364 vaultwarden: vaultwarden allows RCE in the admin panel [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2342352 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7fd2f66440' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Security notice for Fedora 40: vaultwarden patch addresses Remote Code Execution and elevation of privileges vulnerabilities.. Fedora Security Update, vaultwarden, Remote Code Execution, privilege escalation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 09, 2025 Critical Fedora
89

Fedora 41: Security Advisory FEDORA-2025-41f4056b0e Critical RCE Fix

update to 1.33.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-41f4056b0e 2025-02-08 02:15:29.328076+00:00 -------------------------------------------------------------------------------- Name : vaultwarden Product : Fedora 41 Version : 1.33.0 Release : 1.fc41 URL : https://github.com/dani-garcia/vaultwarden Summary : Unofficial Bitwarden compatible server Description : Unofficial Bitwarden compatible server. -------------------------------------------------------------------------------- Update Information: update to 1.33.0 -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 30 2025 Jonathan Wright - 1.33.0-1 - update to 1.33.0 rhbz#2342073 Fix GHSA-f7r5-w49x-gxm3 Getting access to the Admin Panel via CSRF Fix CVE-2025-24364 RCE in the admin panel Fix CVE-2025-24365 escalation of privilege via variable confusion in OrgHeaders trait -------------------------------------------------------------------------------- References: [ 1 ] Bug #2342348 - CVE-2025-24365 vaultwarden: vaultwarden allows escalation of privilege via variable confusion in OrgHeaders trait [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2342348 [ 2 ] Bug #2342353 - CVE-2025-24364 vaultwarden: vaultwarden allows RCE in the admin panel [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2342353 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-41f4056b0e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Essential patches deployed for vaultwarden in Fedora 41 target XSS and SQLi vulnerabilities. Prompt intervention needed to ensure security.. Fedora 41 Security Updates,vaultwarden RCE,CSRF Security Fixes,vaultwarden update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 08, 2025 Critical Fedora
89

Fedora 40: 2025-3dff292265 moderate: vaultwarden security patch

fix VW_VERSION in compiled code, patch security issues. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-3dff292265 2025-01-29 05:23:04.063048+00:00 -------------------------------------------------------------------------------- Name : vaultwarden Product : Fedora 40 Version : 1.32.7 Release : 4.fc40 URL : https://github.com/dani-garcia/vaultwarden Summary : Unofficial Bitwarden compatible server Description : Unofficial Bitwarden compatible server. -------------------------------------------------------------------------------- Update Information: fix VW_VERSION in compiled code, patch security issues -------------------------------------------------------------------------------- ChangeLog: * Tue Jan 21 2025 Jonathan Wright - 1.32.7-4 - Set VW_VERSION env var during build and install rhbz#2338534 * Sun Jan 19 2025 Fedora Release Engineering - 1.32.7-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Wed Jan 15 2025 Jonathan Wright - 1.32.7-2 - fix build on el9 with rust 1.79 * Fri Jan 3 2025 Jonathan Wright - 1.32.7-1 - update to 1.32.7 rhbz#2322181 - Fix CVE-2024-56335 * Tue Oct 22 2024 Jonathan Wright - 1.32.2-1 - update to 1.32.2 rhbz#2316657 * Sun Aug 11 2024 Jonathan Wright - 1.32.0-1 - update to 1.32.0 rhbz#2304045 Resolves CVE-2024-39924 Resolves CVE-2024-39925 Resolves CVE-2024-39926 * Fri Aug 2 2024 Jonathan Wright - 1.31.0-2 - Exclude s390x and ppc64le * Fri Jul 19 2024 Jonathan Wright - 1.31.0-1 - update to 1.31.0 rhbz#2297149 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2307705 - vaultwarden: FTBFS in Fedora 40 and 39 https://bugzilla.redhat.com/show_bug.cgi?id=2307705 [ 2 ] Bug #2333595 - CVE-2024-56335 vaultwarden: Privilege escalation allows organization groups to be updated/deleted if their UUID is known in vaultwarden[epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2333595 [ 3 ] Bug #2333596 - CVE-2024-56335 vaultwarden: Privilege escalation allows organization groups to be updated/deleted if their UUID is known in vaultwarden [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2333596 [ 4 ] Bug #2333597 - CVE-2024-56335 vaultwarden: Privilege escalation allows organization groups to be updated/deleted if their UUID is known in vaultwarden [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2333597 [ 5 ] Bug #2336825 - CVE-2024-55226 vaultwarden: uthenticated reflected XSS vulnerability [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2336825 [ 6 ] Bug #2336826 - CVE-2024-55226 vaultwarden: uthenticated reflected XSS vulnerability [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2336826 [ 7 ] Bug #2336827 - CVE-2024-55226 vaultwarden: uthenticated reflected XSS vulnerability [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2336827 [ 8 ] Bug #2336829 - CVE-2024-55225 vaultwarden: user spoofing via crafted authorization request [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2336829 [ 9 ] Bug #2336830 - CVE-2024-55225 vaultwarden: user spoofing via crafted authorization request [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2336830 [ 10 ] Bug #2336831 - CVE-2024-55225 vaultwarden: user spoofing via crafted authorization request [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2336831 [ 11 ] Bug #2336833 - CVE-2024-55224 vaultwarden: arbitrary code execution via injecting a crafted payload into the username field of an e-mail message [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2336833 [ 12 ] Bug #2336834 - CVE-2024-55224 vaultwarden: arbitrary code execution via injecting a crafted payload into the username field of an e-mail message [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2336834 [ 13 ] Bug #2336835 - CVE-2024-55224vaultwarden: arbitrary code execution via injecting a crafted payload into the username field of an e-mail message [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2336835 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-3dff292265' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Changes for Fedora 40's vaultwarden feature enhancements addressing vulnerabilities plus revisions to VW_VERSION in built binaries.. Vaultwarden updates, Fedora security, software patching. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 29, 2025 Important Fedora
89

Fedora 41: FEDORA-2025-4cb7637c98 moderate: vaultwarden execution risk

fix VW_VERSION in compiled code, patch security issues update to 1.32.7. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-4cb7637c98 2025-01-29 05:01:23.704796+00:00 -------------------------------------------------------------------------------- Name : vaultwarden Product : Fedora 41 Version : 1.32.7 Release : 4.fc41 URL : https://github.com/dani-garcia/vaultwarden Summary : Unofficial Bitwarden compatible server Description : Unofficial Bitwarden compatible server. -------------------------------------------------------------------------------- Update Information: fix VW_VERSION in compiled code, patch security issues update to 1.32.7 -------------------------------------------------------------------------------- ChangeLog: * Tue Jan 21 2025 Jonathan Wright - 1.32.7-4 - Set VW_VERSION env var during build and install rhbz#2338534 * Sun Jan 19 2025 Fedora Release Engineering - 1.32.7-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Wed Jan 15 2025 Jonathan Wright - 1.32.7-2 - fix build on el9 with rust 1.79 * Fri Jan 3 2025 Jonathan Wright - 1.32.7-1 - update to 1.32.7 rhbz#2322181 - Fix CVE-2024-56335 * Tue Oct 22 2024 Jonathan Wright - 1.32.2-1 - update to 1.32.2 rhbz#2316657 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2307705 - vaultwarden: FTBFS in Fedora 40 and 39 https://bugzilla.redhat.com/show_bug.cgi?id=2307705 [ 2 ] Bug #2333595 - CVE-2024-56335 vaultwarden: Privilege escalation allows organization groups to be updated/deleted if their UUID is known in vaultwarden [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2333595 [ 3 ] Bug #2333596 - CVE-2024-56335 vaultwarden: Privilege escalation allows organization groups to be updated/deleted if their UUID is known in vaultwarden [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2333596 [ 4 ] Bug #2333597 - CVE-2024-56335 vaultwarden: Privilege escalation allows organization groups to be updated/deleted if their UUID is known in vaultwarden [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2333597 [ 5 ] Bug #2336825 - CVE-2024-55226 vaultwarden: uthenticated reflected XSS vulnerability [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2336825 [ 6 ] Bug #2336826 - CVE-2024-55226 vaultwarden: uthenticated reflected XSS vulnerability [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2336826 [ 7 ] Bug #2336827 - CVE-2024-55226 vaultwarden: uthenticated reflected XSS vulnerability [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2336827 [ 8 ] Bug #2336829 - CVE-2024-55225 vaultwarden: user spoofing via crafted authorization request [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2336829 [ 9 ] Bug #2336830 - CVE-2024-55225 vaultwarden: user spoofing via crafted authorization request [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2336830 [ 10 ] Bug #2336831 - CVE-2024-55225 vaultwarden: user spoofing via crafted authorization request [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2336831 [ 11 ] Bug #2336833 - CVE-2024-55224 vaultwarden: arbitrary code execution via injecting a crafted payload into the username field of an e-mail message [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2336833 [ 12 ] Bug #2336834 - CVE-2024-55224 vaultwarden: arbitrary code execution via injecting a crafted payload into the username field of an e-mail message [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2336834 [ 13 ] Bug #2336835 - CVE-2024-55224 vaultwarden: arbitrary code execution via injecting a crafted payload into the username field of an e-mail message [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2336835 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-4cb7637c98' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Patch for vaultwarden on Fedora 41 mitigates privilege elevation and cross-site scripting vulnerabilities in release 1.32.7.. vaultwarden updates,vulnerability management,security fixes. . LinuxSecurity.com Team

Calendar%202 Jan 29, 2025 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200