Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
202

openSUSE: Chromium Important Update For Memory Access Issues 2025:0475-1

An update that fixes 5 vulnerabilities is now available.. openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0475-1 Rating: important References: #1254776 #1255115 Cross-References: CVE-2025-14174 CVE-2025-14372 CVE-2025-14373 CVE-2025-14765 CVE-2025-14766 Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for chromium fixes the following issues: - Chromium 143.0.7499.146 (boo#1255115): * CVE-2025-14765: Use after free in WebGPU * CVE-2025-14766: Out of bounds read and write in V8 - Chromium 143.0.7499.109 (boo#1254776): * CVE-2025-14372: Use after free in Password Manager * CVE-2025-14373: Inappropriate implementation in Toolbar * CVE-2025-14174: Out of bounds memory access in ANGLE Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-475=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 ppc64le x86_64): chromedriver-143.0.7499.146-bp156.2.209.1 chromium-143.0.7499.146-bp156.2.209.1 References: https://www.suse.com/security/cve/CVE-2025-14174.html https://www.suse.com/security/cve/CVE-2025-14372.html https://www.suse.com/security/cve/CVE-2025-14373.html https://www.suse.com/security/cve/CVE-2025-14765.html https://www.suse.com/security/cve/CVE-2025-14766.html https://bugzilla.suse.com/1254776 https://bugzilla.suse.com/1255115 . Update for openSUSE addresses multiple critical vulnerabilities in Chromium, enhancing its security andperformance.. openSUSE, chromium, security update, vulnerabilities, memory access. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 19, 2025 Important OpenSUSE
203

Mageia 8: 2023-0177 Moderate: Webkit2 Code Execution And DoS Risk

HTML document may be able to render iframes with sensitive user information (CVE-2022-0108) maliciously crafted web content may lead to arbitrary code execution. (CVE-2022-32885) use-after-free vulnerability exists in WebCore::RenderLayer. This issue . MGASA-2023-0177 - Updated webkit2 packages fix security vulnerability Publication date: 21 May 2023 URL: https://advisories.mageia.org/MGASA-2023-0177.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-0108, CVE-2022-32885, CVE-2023-25358, CVE-2023-27932, CVE-2023-27954, CVE-2023-28205 HTML document may be able to render iframes with sensitive user information (CVE-2022-0108) maliciously crafted web content may lead to arbitrary code execution. (CVE-2022-32885) use-after-free vulnerability exists in WebCore::RenderLayer. This issue allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. (CVE-2023-25358) maliciously crafted web content may bypass Same Origin Policy (CVE-2023-27932) Website may be able to track sensitive user information. Description: The issue was addressed by removing origin information. (CVE-2023-27954) maliciously crafted web content may lead to arbitrary code execution (CVE-2023-28205) References: - https://bugs.mageia.org/show_bug.cgi?id=31854 - https://webkitgtk.org/security/WSA-2023-0003.html - https://webkitgtk.org/2023/04/20/webkitgtk2.38.6-released.html - https://www.cve.org/CVERecord?id=CVE-2022-0108 - https://www.cve.org/CVERecord?id=CVE-2022-32885 - https://www.cve.org/CVERecord?id=CVE-2023-25358 - https://www.cve.org/CVERecord?id=CVE-2023-27932 - https://www.cve.org/CVERecord?id=CVE-2023-27954 - https://www.cve.org/CVERecord?id=CVE-2023-28205 SRPMS: - 8/core/webkit2-2.38.6-1.mga8 . Recent updates to webkit2 packages for Mageia bolster security by fixing critical vulnerabilities and promoting user protection.. Mageia Security Updates, Webkit2 Vulnerabilities, Code Execution Risks, Information Exposure. .LinuxSecurity.com Team

Calendar 2 May 21, 2023 Mageia
217

Oracle Linux 8 ELSA-2023-0016 Critical: Webkit2GTK3 Security Patch

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-0016 https://linux.oracle.com/errata/ELSA-2023-0016.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: webkit2gtk3-2.36.7-1.el8_7.1.i686.rpm webkit2gtk3-2.36.7-1.el8_7.1.x86_64.rpm webkit2gtk3-devel-2.36.7-1.el8_7.1.i686.rpm webkit2gtk3-devel-2.36.7-1.el8_7.1.x86_64.rpm webkit2gtk3-jsc-2.36.7-1.el8_7.1.i686.rpm webkit2gtk3-jsc-2.36.7-1.el8_7.1.x86_64.rpm webkit2gtk3-jsc-devel-2.36.7-1.el8_7.1.i686.rpm webkit2gtk3-jsc-devel-2.36.7-1.el8_7.1.x86_64.rpm aarch64: webkit2gtk3-2.36.7-1.el8_7.1.aarch64.rpm webkit2gtk3-devel-2.36.7-1.el8_7.1.aarch64.rpm webkit2gtk3-jsc-2.36.7-1.el8_7.1.aarch64.rpm webkit2gtk3-jsc-devel-2.36.7-1.el8_7.1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/webkit2gtk3-2.36.7-1.el8_7.1.src.rpm Related CVEs: CVE-2022-42856 Description of changes: [2.36.7-1.1] - Add patch for CVE-2022-42856 Resolves: #2153735 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Meeting ELSA-2023-0016 focuses on enhancements for webkit2gtk3, targeting the CVE-2022-42856 flaw.. Oracle Linux Update, Webkit2GTK3, Security Patch, CVE-2022-42856. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 05, 2023 Critical Oracle
89

Fedora 33: FEDORA-2020-f43efd09e8 Moderate: Chromium Browser Security

Update to 87.0.4280.88. As with pretty much every chromium release ever, this fixes some security bugs. This batch is: CVE-2020-16037 CVE-2020-16038 CVE-2020-16039 CVE-2020-16040 CVE-2020-16041 CVE-2020-16042. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-f43efd09e8 2020-12-10 01:13:07.369048 --------------------------------------------------------------------------------Name : chromium Product : Fedora 33 Version : 87.0.4280.88 Release : 1.fc33 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser Description : Chromium is an open-source web browser, powered by WebKit (Blink). --------------------------------------------------------------------------------Update Information: Update to 87.0.4280.88. As with pretty much every chromium release ever, this fixes some security bugs. This batch is: CVE-2020-16037 CVE-2020-16038 CVE-2020-16039 CVE-2020-16040 CVE-2020-16041 CVE-2020-16042 --------------------------------------------------------------------------------ChangeLog: * Thu Dec 3 2020 Tom Callaway - 87.0.4280.88-1 - update to 87.0.4280.88 --------------------------------------------------------------------------------References: [ 1 ] Bug #1904510 - CVE-2020-16037 chromium-browser: Use after free in clipboard https://bugzilla.redhat.com/show_bug.cgi?id=1904510 [ 2 ] Bug #1904511 - CVE-2020-16038 chromium-browser: Use after free in media https://bugzilla.redhat.com/show_bug.cgi?id=1904511 [ 3 ] Bug #1904512 - CVE-2020-16039 chromium-browser: Use after free in extensions https://bugzilla.redhat.com/show_bug.cgi?id=1904512 [ 4 ] Bug #1904513 - CVE-2020-16040 chromium-browser: Insufficient data validation in V8 https://bugzilla.redhat.com/show_bug.cgi?id=1904513 [ 5 ] Bug #1904514 - CVE-2020-16041 chromium-browser: Out of bounds read in networking https://bugzilla.redhat.com/show_bug.cgi?id=1904514 [ 6 ] Bug #1904515 - CVE-2020-16042 chromium-browser: Uninitialized Use in V8 https://bugzilla.redhat.com/show_bug.cgi?id=1904515 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-f43efd09e8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora's Chromium update resolves several security vulnerabilities with effective fixes and enhanced usability updates.. Fedora Update, Chromium Browser, Security Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 09, 2020 Important Fedora
87

Debian: DSA 980-1 Critical: Tutos Remote SQL Injection and XSS Threats

Joxean Koret discovered several security problems in tutos, a web-based team organization software. The Common Vulnerabilities and Exposures Project identifies the following problems.... - --------------------------------------------------------------------------Debian Security Advisory DSA 980-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff February 22nd, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : tutos Vulnerability : several Problem-Type : remote Debian-specific: no CVE ID : CVE-2004-2161 CVE-2004-2162 Debian Bug : 318633 Joxean Koret discovered several security problems in tutos, a web-based team organization software. The Common Vulnerabilities and Exposures Project identifies the following problems: CVE-2004-2161 An SQL injection vulnerability allows the execution of SQL commands through the link_id parameter in file_overview.php. CVE-2004-2162 Cross-Site-Scripting vulnerabilities in the search function of the address book and in app_new.php allow the execution of web script code. The old stable distribution (woody) does not contain tutos packages. For the stable distribution (sarge) these problems have been fixed in version 1.1.20031017-2+1sarge1. The unstable distribution (sid) does no longer contain tutos packages. We recommend that you upgrade your tutos package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. DebianGNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 575 7babaefc5a7e57afc2fb421d5829c4cf Size/MD5 checksum: 4955293 c9c539f0d5504d69377e326870db18c3 Architecture independent components: Size/MD5 checksum: 4760050 39bb9b2f3e9655c7060f04a5dac83e09 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Various vulnerabilities detected in tutos software, notably SQL injection risks. Users on Debian are recommended to perform updates.. tutos vulnerabilities, SQL injection fix, Debian security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 22, 2006 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here