Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 4 articles for you...
217

Oracle Linux 8 ELSA-2025-2034 critical: webkit2gtk3 updates

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-2034 http://linux.oracle.com/errata/ELSA-2025-2034.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: webkit2gtk3-2.46.6-1.el8_10.i686.rpm webkit2gtk3-2.46.6-1.el8_10.x86_64.rpm webkit2gtk3-devel-2.46.6-1.el8_10.i686.rpm webkit2gtk3-devel-2.46.6-1.el8_10.x86_64.rpm webkit2gtk3-jsc-2.46.6-1.el8_10.i686.rpm webkit2gtk3-jsc-2.46.6-1.el8_10.x86_64.rpm webkit2gtk3-jsc-devel-2.46.6-1.el8_10.i686.rpm webkit2gtk3-jsc-devel-2.46.6-1.el8_10.x86_64.rpm aarch64: webkit2gtk3-2.46.6-1.el8_10.aarch64.rpm webkit2gtk3-devel-2.46.6-1.el8_10.aarch64.rpm webkit2gtk3-jsc-2.46.6-1.el8_10.aarch64.rpm webkit2gtk3-jsc-devel-2.46.6-1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//webkit2gtk3-2.46.6-1.el8_10.src.rpm Related CVEs: CVE-2024-54543 CVE-2025-24143 CVE-2025-24150 CVE-2025-24158 CVE-2025-24162 Description of changes: [2.46.6-1] - Update to 2.46.6 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Essential security patches for Oracle Linux 8 targeting vulnerabilities in webkit2gtk3 components to maintain system reliability and protection.. Oracle Linux Security, webkit update, software security advisory, Linux RPM updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 07, 2025 Critical Oracle
197

Debian LTS: DLA-4009-1 moderate: webkit2gtk memory issue

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-54479 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4009-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort January 09, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : webkit2gtk Version : 2.46.5-1~deb11u1 CVE ID : CVE-2024-54479 CVE-2024-54502 CVE-2024-54505 CVE-2024-54508 The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-54479 Seunghyun Lee discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2024-54502 Brendon Tiszka discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2024-54505 Gary Kwong discovered that processing maliciously crafted web content may lead to memory corruption. CVE-2024-54508 linjy, chluo and Xiangwei Zhang discovered that processing maliciously crafted web content may lead to an unexpected process crash. For Debian 11 bullseye, these problems have been fixed in version 2.46.5-1~deb11u1. We recommend that you upgrade your webkit2gtk packages. For the detailed security status of webkit2gtk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/webkit2gtk Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS DLA-4010-1 resolves severe vulnerabilities in libxml2. Updating is advised for enhanced security.. Debian LTS, webkit2gtk updates, security advisory, process crash, memory issues. . LinuxSecurity.com Team

Calendar%202 Jan 09, 2025 Debian LTS
219

Rocky Linux 8 RLSA-2023:1919 Important: WebKitGTK Code Execution

Important: webkit2gtk3 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:1919", "synopsis": "Important: webkit2gtk3 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for webkit2gtk3.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.\n\nSecurity Fix(es):\n\n* WebKitGTK: use-after-free leads to arbitrary code execution (CVE-2023-28205)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2185724", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2185724", "description": ""}], "cves": [{"name": "CVE-2023-28205", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-28205", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2023-04-26T15:28:43.734178Z", "rpms": {"Rocky Linux 8": {"nvras": ["webkit2gtk3-0:2.36.7-1.el8_7.3.aarch64.rpm", "webkit2gtk3-0:2.36.7-1.el8_7.3.src.rpm", "webkit2gtk3-debuginfo-0:2.36.7-1.el8_7.3.aarch64.rpm", "webkit2gtk3-debugsource-0:2.36.7-1.el8_7.3.aarch64.rpm", "webkit2gtk3-devel-0:2.36.7-1.el8_7.3.aarch64.rpm", "webkit2gtk3-devel-debuginfo-0:2.36.7-1.el8_7.3.aarch64.rpm", "webkit2gtk3-jsc-0:2.36.7-1.el8_7.3.aarch64.rpm", "webkit2gtk3-jsc-debuginfo-0:2.36.7-1.el8_7.3.aarch64.rpm", "webkit2gtk3-jsc-devel-0:2.36.7-1.el8_7.3.aarch64.rpm", "webkit2gtk3-jsc-devel-debuginfo-0:2.36.7-1.el8_7.3.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important webkit2gtk3 enhancement for Rocky Linux 8 addresses vulnerabilities and theirconsequences. Ensure your safety!. web security update, webkit2gtk3 patch, critical fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 26, 2023 Important Rocky Linux
217

Oracle Linux 8 ELSA-2022-6541 Important: Webkit2 Security Patch

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-6540 https://linux.oracle.com/errata/ELSA-2022-6540.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: webkit2gtk3-2.36.7-1.el8_6.i686.rpm webkit2gtk3-2.36.7-1.el8_6.x86_64.rpm webkit2gtk3-devel-2.36.7-1.el8_6.i686.rpm webkit2gtk3-devel-2.36.7-1.el8_6.x86_64.rpm webkit2gtk3-jsc-2.36.7-1.el8_6.i686.rpm webkit2gtk3-jsc-2.36.7-1.el8_6.x86_64.rpm webkit2gtk3-jsc-devel-2.36.7-1.el8_6.i686.rpm webkit2gtk3-jsc-devel-2.36.7-1.el8_6.x86_64.rpm aarch64: webkit2gtk3-2.36.7-1.el8_6.aarch64.rpm webkit2gtk3-devel-2.36.7-1.el8_6.aarch64.rpm webkit2gtk3-jsc-2.36.7-1.el8_6.aarch64.rpm webkit2gtk3-jsc-devel-2.36.7-1.el8_6.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/webkit2gtk3-2.36.7-1.el8_6.src.rpm Related CVEs: CVE-2022-32893 Description of changes: [2.36.7-1] - Update to 2.36.7 Related: #2123429 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Advisory ELSA-2022-6541 outlines critical enhancements for OpenSSL to address vulnerabilities and bolster protection measures significantly.. Oracle Linux Update, Webkit Security Patch, ELSA-2022-6540. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 22, 2022 Important Oracle
203

Mageia 8 MGASA-2022-0254 Critical: Webkit2 Security Fix

The webkit2 package has been updated to version 2.36.4, fixing several security issues and other bugs. References: - https://bugs.mageia.org/show_bug.cgi?id=30608 . MGASA-2022-0254 - Updated webkit2 packages fix security vulnerability Publication date: 12 Jul 2022 URL: https://advisories.mageia.org/MGASA-2022-0254.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-22662, CVE-2022-22677, CVE-2022-26710 The webkit2 package has been updated to version 2.36.4, fixing several security issues and other bugs. References: - https://bugs.mageia.org/show_bug.cgi?id=30608 - https://webkitgtk.org/2022/07/05/webkitgtk2.36.4-released.html - https://webkitgtk.org/security/WSA-2022-0006.html - https://www.cve.org/CVERecord?id=CVE-2022-22662 - https://www.cve.org/CVERecord?id=CVE-2022-22677 - https://www.cve.org/CVERecord?id=CVE-2022-26710 SRPMS: - 8/core/webkit2-2.36.4-1.mga8 . MGASA-2022-0255 pertains to important vulnerabilities in the webkit2 components for Mageia 8. Prompt attention is necessary.. Mageia Security Advisory, webkit2 Update, Mageia Package Fix, Webkit Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 12, 2022 Critical Mageia
87

Debian 11 DSA-5116-1 Critical: WPE WebKit Code Execution Threat

The following vulnerabilities have been discovered in the WPE WebKit web engine: CVE-2022-22624 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5116-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Alberto Garcia April 08, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : wpewebkit CVE ID : CVE-2022-22624 CVE-2022-22628 CVE-2022-22629 The following vulnerabilities have been discovered in the WPE WebKit web engine: CVE-2022-22624 Kirin discovered that processing maliciously crafted web content may lead to arbitrary code execution. CVE-2022-22628 Kirin discovered that Processing maliciously crafted web content may lead to arbitrary code execution. CVE-2022-22629 Jeonghoon Shin discovered that processing maliciously crafted web content may lead to arbitrary code execution. For the stable distribution (bullseye), these problems have been fixed in version 2.36.0-2~deb11u1. We recommend that you upgrade your wpewebkit packages. For the detailed security status of wpewebkit please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/wpewebkit Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Important release for WPE WebKit tackles several vulnerabilities, notably risks of unauthorized code execution.. debian security,wpewebkit update,code execution fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 08, 2022 Critical Debian
89

Fedora 25: 2016-f17c8c6aaf moderate: Remove Webkit1 and WebkitGTK3

* get rid of webkit1/webkitgtk3. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-f17c8c6aaf 2016-09-27 00:29:22.123650 -------------------------------------------------------------------------------- Name : vfrnav Product : Fedora 25 Version : 20160429 Release : 1.fc25 URL : Summary : VFR/IFR Navigation Description : This is a navigation application for VFR and IFR flying. -------------------------------------------------------------------------------- Update Information: * get rid of webkit1/webkitgtk3 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update vfrnav' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The newest Fedora release for vfrnav boosts functionality by eliminating outdated web tech. This is crucial for the user experience.. Fedora Updates, vfrnav Security, Application Performance, Navigation Software. . LinuxSecurity.com Team

Calendar%202 Sep 27, 2016 Fedora
172

Ubuntu 12.04 LTS: USN-1617-1 Severe: WebKit Remote Attack Fix

Multiple security vulnerabilities were fixed in WebKit.. =========================================================================Ubuntu Security Notice USN-1617-1 October 25, 2012 webkit vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: Multiple security vulnerabilities were fixed in WebKit. Software Description: - webkit: Web content engine library for GTK+ Details: A large number of security issues were discovered in the WebKit browser and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: libjavascriptcoregtk-1.0-0 1.8.3-0ubuntu0.12.04.1 libjavascriptcoregtk-3.0-0 1.8.3-0ubuntu0.12.04.1 libwebkitgtk-1.0-0 1.8.3-0ubuntu0.12.04.1 libwebkitgtk-3.0-0 1.8.3-0ubuntu0.12.04.1 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1617-1 CVE-2011-3031, CVE-2011-3038, CVE-2011-3042, CVE-2011-3043, CVE-2011-3044, CVE-2011-3051, CVE-2011-3053, CVE-2011-3059, CVE-2011-3060, CVE-2011-3064, CVE-2011-3067, CVE-2011-3076, CVE-2011-3081, CVE-2011-3086, CVE-2011-3090, CVE-2012-1521, CVE-2012-3598, CVE-2012-3601, CVE-2012-3604, CVE-2012-3611, CVE-2012-3612, CVE-2012-3617, CVE-2012-3625, CVE-2012-3626, CVE-2012-3627, CVE-2012-3628, CVE-2012-3645, CVE-2012-3652, CVE-2012-3657, CVE-2012-3669, CVE-2012-3670, CVE-2012-3671, CVE-2012-3672, CVE-2012-3674, CVE-2012-3674, https://bugs.launchpad.net/ubuntu/+source/webkit/+bug/1058339 PackageInformation: https://launchpad.net/ubuntu/+source/webkit/1.8.3-0ubuntu0.12.04.1 . A series of WebKit security flaws have been patched in Ubuntu 12.04 LTS, enhancing browser safety. Ensure you update to safeguard your system.. WebKit Exploit Fix, Ubuntu Security Update, Browser Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 25, 2012 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200