Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
87

Debian libXfont Important Code Execution Risks DSA-6388-1

Several vulnerabilities were discovered in libXfont, the X11 font rasterisation library, which may result in arbitrary code execution in the X server context for authenticated X clients. For the stable distribution (trixie), these problems have been fixed in version 1:2.0.6-1+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6388-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso July 15, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libxfont CVE ID : CVE-2026-56001 CVE-2026-56002 CVE-2026-56003 Debian Bug : 1141702 Several vulnerabilities were discovered in libXfont, the X11 font rasterisation library, which may result in arbitrary code execution in the X server context for authenticated X clients. For the stable distribution (trixie), these problems have been fixed in version 1:2.0.6-1+deb13u1. We recommend that you upgrade your libxfont packages. For the detailed security status of libxfont please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libxfont Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Several critical issues in libXfont may lead to code execution; an upgrade is necessary for Debian users.. libXfont security issues, Debian advisory, code execution risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 15, 2026 Important Debian
89

Fedora 41: FEDORA-2025-2210d27149 critical: xwayland CVE fixes

xwayland 24.1.6 CVE fix for: CVE-2025-26594, CVE-2025-26595, CVE-2025-26596, CVE-2025-26597, CVE-2025-26598, CVE-2025-26599, CVE-2025-26600, CVE-2025-26601. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-2210d27149 2025-02-28 01:28:22.104211+00:00 -------------------------------------------------------------------------------- Name : xorg-x11-server-Xwayland Product : Fedora 41 Version : 24.1.6 Release : 1.fc41 URL : https://www.x.org/wiki/ Summary : Xwayland Description : Xwayland is an X server for running X clients under Wayland. -------------------------------------------------------------------------------- Update Information: xwayland 24.1.6 CVE fix for: CVE-2025-26594, CVE-2025-26595, CVE-2025-26596, CVE-2025-26597, CVE-2025-26598, CVE-2025-26599, CVE-2025-26600, CVE-2025-26601 -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 26 2025 Olivier Fourdan - 24.1.6-1 - xwayland 24.1.6 (#2343992) - CVE fix for: CVE-2025-26594, CVE-2025-26595, CVE-2025-26596, CVE-2025-26597, CVE-2025-26598, CVE-2025-26599, CVE-2025-26600, CVE-2025-26601 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2343992 - xorg-x11-server-Xwayland-24.1.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2343992 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-2210d27149' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Ensure you obtain the most current security patches for xwayland in Fedora 41, focusing on various CVE vulnerabilities to maintain system integrity.. Xserver,Fedora41,Xwayland,SecurityUpdates,CVEfix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 28, 2025 Critical Fedora
203

Mageia 7 & 8: MGASA-2021-0219 Critical: Libx11 Input Flaw

XLookupColor() and other X libraries function lack proper validation of the length of their string parameters. If those parameters can be controlled by an external application (for instance a color name that can be emitted via a terminal control sequence) it can lead to the emission of extra X protocol requests to the X server . MGASA-2021-0219 - Updated libx11 packages fix a security vulnerability Publication date: 23 May 2021 URL: https://advisories.mageia.org/MGASA-2021-0219.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-31535 XLookupColor() and other X libraries function lack proper validation of the length of their string parameters. If those parameters can be controlled by an external application (for instance a color name that can be emitted via a terminal control sequence) it can lead to the emission of extra X protocol requests to the X server (CVE-2021-31535). References: - https://bugs.mageia.org/show_bug.cgi?id=28940 - https://lists.x.org/archives/xorg-announce/2021-May/003088.html - https://lists.x.org/archives/xorg-announce/2021-May/003089.html - https://www.openwall.com/lists/oss-security/2021/05/18/3 - https://www.cve.org/CVERecord?id=CVE-2021-31535 SRPMS: - 8/core/libx11-1.7.0-1.1.mga8 - 7/core/libx11-1.6.12-1.1.mga7 . Ubuntu security notice for libx11 highlights severe vulnerabilities in XLoadQueryFont() function impacting versions 20.04 and 21.10.. Mageia Libx11 Security Update,X Server Flaw,Input Validation Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 22, 2021 Critical Mageia
99

Slackware: 2021-139-01 Moderate: LibX11 Request Length Issue

New libX11 packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] libX11 (SSA:2021-139-01) New libX11 packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/libX11-1.7.1-i586-1_slack14.2.txz: Upgraded. This update fixes missing request length checks in libX11 that can lead to the emission of extra X protocol requests to the X server. For more information, see: https://lists.x.org/archives/xorg-announce/2021-May/003088.html https://www.cve.org/CVERecord?id=CVE-2021-31535 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.0: Updated package for Slackware x86_64 14.0: Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package for Slackware 14.2: Updated package for Slackware x86_64 14.2: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.0 package: 037e061214b75602fecda02dbeff4594 libX11-1.7.1-i486-1_slack14.0.txz Slackware x86_64 14.0 package: 2d361c4a57965f7717c6baeeb64bfbdc libX11-1.7.1-x86_64-1_slack14.0.txz Slackware 14.1 package: 2d248166e3300b2eddf1bf7cdfd9c48e libX11-1.7.1-i486-1_slack14.1.txz Slackware x86_64 14.1 package: 1cbc196fc2b572d9ef1d782780e715c4 libX11-1.7.1-x86_64-1_slack14.1.txz Slackware 14.2 package: e7a8f6730ee2a9f0c1d1b882ef19a328 libX11-1.7.1-i586-1_slack14.2.txz Slackware x86_64 14.2 package: 93c50f408507ca0ec710ec0652911fc5 libX11-1.7.1-x86_64-1_slack14.2.txz Slackware -current package: c4e7afb55aa5cbac724d078bac62d48e x/libX11-1.7.1-i586-1.txz Slackware x86_64 -current package: 4c6d385206e5c2ba7614b1301b850115 x/libX11-1.7.1-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg libX11-1.7.1-i586-1_slack14.2.txz +-----+ . Recent updates to the libX11 packages for Slackware address a significant security vulnerability, enhancing overall system safety and integrity.. libX11,Slackware Security,Software Update. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 May 19, 2021 Medium Slackware
172

Ubuntu 14.10: USN-2438-1 Moderate: X Server Privilege Escalation

Several security issues were fixed in the NVIDIA graphics drivers.. =========================================================================Ubuntu Security Notice USN-2438-1 December 10, 2014 nvidia-graphics-drivers-304, nvidia-graphics-drivers-304-updates, nvidia-graphics-drivers-331, nvidia-graphics-drivers-331-updates vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Several security issues were fixed in the NVIDIA graphics drivers. Software Description: - nvidia-graphics-drivers-304: NVIDIA binary Xorg driver - nvidia-graphics-drivers-304-updates: NVIDIA binary Xorg driver - nvidia-graphics-drivers-331: NVIDIA binary Xorg driver - nvidia-graphics-drivers-331-updates: NVIDIA binary Xorg driver Details: It was discovered that the NVIDIA graphics drivers incorrectly handled GLX indirect rendering support. An attacker able to connect to an X server, either locally or remotely, could use these issues to cause the X server to crash or execute arbitrary code resulting in possible privilege escalation. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: nvidia-304 304.125-0ubuntu0.1 nvidia-304-updates 304.125-0ubuntu0.1 nvidia-331 331.113-0ubuntu0.1 nvidia-331-updates 331.113-0ubuntu0.1 Ubuntu 14.04 LTS: nvidia-304 304.125-0ubuntu0.0.1 nvidia-304-updates 304.125-0ubuntu0.0.1 nvidia-331 331.113-0ubuntu0.0.4 nvidia-331-updates 331.113-0ubuntu0.0.4 Ubuntu 12.04 LTS: nvidia-304 304.125-0ubuntu0.0.0.1 nvidia-304-updates 304.125-0ubuntu0.0.0.1 nvidia-331 331.113-0ubuntu0.0.0.3 nvidia-331-updates 331.113-0ubuntu0.0.0.3 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2438-1 CVE-2014-8091, CVE-2014-8098, CVE-2014-8298 Package Information: https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.125-0ubuntu0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331-updates/331.113-0ubuntu0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.125-0ubuntu0.0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331-updates/331.113-0ubuntu0.0.4 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.125-0ubuntu0.0.0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.0.3 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331-updates/331.113-0ubuntu0.0.0.3 . NVIDIA graphics drivers vulnerabilities fixed in Ubuntu 2438-1 advisory. Update needed to avoid privilege escalation risks.. NVIDIA Drivers Threat, Ubuntu 14.10 Update, X Server Vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Dec 10, 2014 Ubuntu
91

Gentoo: 200806-07 High: X.Org X Server Remote Code Execution

Multiple vulnerabilities have been discovered in the X.Org X server, possibly allowing for the remote execution of arbitrary code with root privileges. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200806-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: X.Org X server: Multiple vulnerabilities Date: June 19, 2008 Bugs: #225419 ID: 200806-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been discovered in the X.Org X server, possibly allowing for the remote execution of arbitrary code with root privileges. Background ========= The X Window System is a graphical windowing system based on a client/server model. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 x11-base/xorg-server < 1.3.0.0-r6 > = 1.3.0.0-r6 Description ========== Regenrecht reported multiple vulnerabilities in various X server extensions via iDefense: * The SProcSecurityGenerateAuthorization() and SProcRecordCreateContext() functions of the RECORD and Security extensions are lacking proper parameter validation (CVE-2008-1377). * An integer overflow is possible in the function ShmPutImage() of the MIT-SHM extension (CVE-2008-1379). * The RENDER extension contains several possible integer overflows in the AllocateGlyph() function (CVE-2008-2360) which could possibly lead to a heap-based buffer overflow. Further possible integer overflows have been found in the ProcRenderCreateCursor() function (CVE-2008-2361) as well as in the SProcRenderCreateLinearGradient(), SProcRenderCreateRadialGradient() and SProcRenderCreateConicalGradient() functions (CVE-2008-2362). Impact ===== Exploitation of these vulnerabilities could possibly lead to the remote execution of arbitrary code with root privileges, if the server is running as root, which is the default. It is also possible to crash the server by making use of these vulnerabilities. Workaround ========= It is possible to avoid these vulnerabilities by disabling the affected server extensions. Therefore edit the configuration file (/etc/X11/xorg.conf) to contain the following in the appropriate places: Section "Extensions" Option "MIT-SHM" "disable" Option "RENDER" "disable" Option "SECURITY" "disable" EndSection Section "Module" Disable "record" EndSection Resolution ========= All X.org X Server users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =x11-base/xorg-server-1.3.0.0-r6" References ========= [ 1 ] CVE-2008-1377 https://www.cve.org/CVERecord?id=CVE-2008-1377 [ 2 ] CVE-2008-1379 https://www.cve.org/CVERecord?id=CVE-2008-1379 [ 3 ] CVE-2008-2360 https://www.cve.org/CVERecord?id=CVE-2008-2360 [ 4 ] CVE-2008-2361 https://www.cve.org/CVERecord?id=CVE-2008-2361 [ 5 ] CVE-2008-2362 https://www.cve.org/CVERecord?id=CVE-2008-2362 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200806-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2008 Gentoo Foundation, Inc; referenced text belongs to its owner(s). Thecontents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Critical warnings issued for Arch Linux users regarding vulnerabilities in the GNOME desktop environment that could potentially permit unauthorized remote access.. Gentoo Linux,X.Org X Server,Remote Execution Threats. . LinuxSecurity.com Team

Calendar%202 Jun 19, 2008 Gentoo
89

Fedora Core 5: Critical GDM Update 2.14.4-1.fc5.3 For Path Issue

This update resolves an issue in gdm-2.14.4-1.fc5.2 where GDM would choose the wrong X server path.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-674 2006-06-07 ---------------------------------------------------------------------Product : Fedora Core 5 Name : gdm Version : 2.14.4 Release : 1.fc5.3 Summary : The GNOME Display Manager. Description : Gdm (the GNOME Display Manager) is a highly configurable reimplementation of xdm, the X Display Manager. Gdm allows you to log into your system with the X Window System running and supports running several different X sessions on your local machine at the same time. ---------------------------------------------------------------------Update Information: This update resolves an issue in gdm-2.14.4-1.fc5.2 where GDM would choose the wrong X server path. ---------------------------------------------------------------------* Wed Jun 7 2006 Ray Strode - 1:2.14.4-1.fc5.3 - Add BuildRequires on xorg-x11-server-Xorg (bug 194295) * Tue Jun 6 2006 Matthias Clasen - 1:2.14.4-1.fc.2 - Require system-logos, not fedora-logos - Add missing BuildRequires ---------------------------------------------------------------------This update can be downloaded from: 85c3d3610d92ff1b9db5d788c4ef92e94adda63f SRPMS/gdm-2.14.4-1.fc5.3.src.rpm 85c3d3610d92ff1b9db5d788c4ef92e94adda63f noarch/gdm-2.14.4-1.fc5.3.src.rpm 8de08db5348fbb72447de1acc84c47c907338dcd ppc/debug/gdm-debuginfo-2.14.4-1.fc5.3.ppc.rpm e44217b31d1a3d1562583d761bca1dd95ce87921 ppc/gdm-2.14.4-1.fc5.3.ppc.rpm c07e40e0763f8f4ab08da7787607601ca3adb60b x86_64/debug/gdm-debuginfo-2.14.4-1.fc5.3.x86_64.rpm 0b7fa1528b766a803caed6a218fc6b8c740de18f x86_64/gdm-2.14.4-1.fc5.3.x86_64.rpm 13af10dd7c3e974c2e5b68bbe65bfb7d84fad15b i386/debug/gdm-debuginfo-2.14.4-1.fc5.3.i386.rpm 0909acbd7e048202332a6e3a737cd6c5cc42a85e i386/gdm-2.14.4-1.fc5.3.i386.rpm This updatecan be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ---------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Resolve GDM directory problems in Fedora Core 5 with this patch to improve security and reliability for your operating environment.. Fedora Core Security,GDM Stability Update,X Server Path Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 07, 2006 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200