Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 30 articles for you...
89

Fedora 43 Log4cxx Critical XML Character Issue Fix FEDORA-2026-31a8569c4b

Update to log4cxx 1.7.0. Fixes CVE-2026-40023: XMLLayout did not escape characters forbidden by the XML 1.0 specification, which could cause conforming XML parsers to reject the produced document, silently dropping log records.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-31a8569c4b 2026-07-18 00:27:50.464532+00:00 -------------------------------------------------------------------------------- Name : log4cxx Product : Fedora 43 Version : 1.7.0 Release : 2.fc43 URL : http://logging.apache.org/log4cxx/index.html Summary : A port to C++ of the Log4j project Description : Log4cxx is a popular logging package written in C++. One of its distinctive features is the notion of inheritance in loggers. Using a logger hierarchy it is possible to control which log statements are output at arbitrary granularity. This helps reduce the volume of logged output and minimize the cost of logging. -------------------------------------------------------------------------------- Update Information: Update to log4cxx 1.7.0. Fixes CVE-2026-40023: XMLLayout did not escape characters forbidden by the XML 1.0 specification, which could cause conforming XML parsers to reject the produced document, silently dropping log records. No ABI-relevant changes; liblog4cxx SONAME (%{sover}) is unchanged. -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 3 2026 Till Hofmann - 1.7.0-2 - Skip 2GB-message test on 32-bit architectures * Fri May 22 2026 Till Hofmann - 1.7.0-1 - Update to 1.7.0 * Fri Jan 16 2026 Fedora Release Engineering - 1.6.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2457923 - CVE-2026-40023 log4cxx: Apache Log4cxx: Log processing impairment due to unsanitized XML characters [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2457923 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-31a8569c4b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Addressing the critical XML parsing issue in log4cxx 1.7.0 on Fedora 43 with a severity rating and update instructions.. Fedora log4cxx XML log processing critical update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 17, 2026 Critical Fedora
202

openSUSE Leap 16.0 perl-XML-LibXML Major Heap Memory Update 2026-20908-1

An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for perl-xml-libxml ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20908-1 Rating: important References: * bsc#1264715 Cross-References: * CVE-2026-8177 CVSS scores: * CVE-2026-8177 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for perl-XML-LibXML fixes the following issue - CVE-2026-8177: read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences (bsc#1264715). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-893=1 Package List: - openSUSE Leap 16.0: perl-XML-LibXML-2.0210-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-8177.html . Critical update for openSUSE Leap 16.0 addressing CVE-2026-8177 impacting perl-XML-LibXML.. openSUSE security patch perl XML-LibXML CVE-2026-8177. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 08, 2026 Important OpenSUSE
100

SUSE 12 SP5 python3 Important Update 2026-1385-1 Fixes Five Issues

An update that solves five vulnerabilities can now be installed.. # Security update for python3 Announcement ID: SUSE-SU-2026:1385-1 Release Date: 2026-04-16T09:16:55Z Rating: important References: * bsc#1259611 * bsc#1259734 * bsc#1259735 * bsc#1259989 * bsc#1260026 Cross-References: * CVE-2025-13462 * CVE-2026-3479 * CVE-2026-3644 * CVE-2026-4224 * CVE-2026-4519 CVSS scores: * CVE-2025-13462 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-13462 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2025-13462 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3479 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3479 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-3479 ( NVD ): 0.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3644 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3644 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-3644 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4224 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-4224 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4224 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4519 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N * CVE-2026-4519 ( SUSE ): 6.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:N * CVE-2026-4519 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4519 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves five vulnerabilities can now be installed. ## Description: This update for python3 fixes the following issues: * CVE-2025-13462: incorrect parsing of TarInfo header when GNU long name and type AREGTYPE are combined (bsc#1259611). * CVE-2026-3479: improper resource argument validation can allow path traversal (bsc#1259989). * CVE-2026-3644: incomplete control character validation in http.cookies (bsc#1259734). * CVE-2026-4224: C stack overflow when parsing XML with deeply nested DTD content models (bsc#1259735). * CVE-2026-4519: leading dashes in URLs are accepted by the `webbrowser.open()` API and allow for web browser command line option injection (bsc#1260026). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-1385=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-1385=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) *python3-tk-debuginfo-3.4.10-25.180.1 * libpython3_4m1_0-debuginfo-3.4.10-25.180.1 * python3-debugsource-3.4.10-25.180.1 * python3-base-debuginfo-3.4.10-25.180.1 * python3-tk-3.4.10-25.180.1 * python3-devel-3.4.10-25.180.1 * python3-debuginfo-3.4.10-25.180.1 * python3-base-debugsource-3.4.10-25.180.1 * python3-3.4.10-25.180.1 * libpython3_4m1_0-3.4.10-25.180.1 * python3-curses-debuginfo-3.4.10-25.180.1 * python3-curses-3.4.10-25.180.1 * python3-base-3.4.10-25.180.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (ppc64le s390x x86_64) * python3-devel-debuginfo-3.4.10-25.180.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * python3-base-debuginfo-32bit-3.4.10-25.180.1 * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.180.1 * libpython3_4m1_0-32bit-3.4.10-25.180.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * python3-tk-debuginfo-3.4.10-25.180.1 * libpython3_4m1_0-debuginfo-3.4.10-25.180.1 * python3-debugsource-3.4.10-25.180.1 * python3-base-debuginfo-3.4.10-25.180.1 * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.180.1 * python3-base-debuginfo-32bit-3.4.10-25.180.1 * python3-devel-3.4.10-25.180.1 * python3-tk-3.4.10-25.180.1 * python3-debuginfo-3.4.10-25.180.1 * python3-base-debugsource-3.4.10-25.180.1 * python3-3.4.10-25.180.1 * libpython3_4m1_0-3.4.10-25.180.1 * python3-curses-debuginfo-3.4.10-25.180.1 * python3-curses-3.4.10-25.180.1 * libpython3_4m1_0-32bit-3.4.10-25.180.1 * python3-devel-debuginfo-3.4.10-25.180.1 * python3-base-3.4.10-25.180.1 ## References: * https://www.suse.com/security/cve/CVE-2025-13462.html * https://www.suse.com/security/cve/CVE-2026-3479.html * https://www.suse.com/security/cve/CVE-2026-3644.html * https://www.suse.com/security/cve/CVE-2026-4224.html * https://www.suse.com/security/cve/CVE-2026-4519.html * https://bugzilla.suse.com/show_bug.cgi?id=1259611 * https://bugzilla.suse.com/show_bug.cgi?id=1259734 * https://bugzilla.suse.com/show_bug.cgi?id=1259735 * https://bugzilla.suse.com/show_bug.cgi?id=1259989 * https://bugzilla.suse.com/show_bug.cgi?id=1260026 . Critical SUSE python3 update fixes five vulnerabilities and includes patch instructions for various server distros.. SUSE Python3 Update, Security Vulnerabilities, SUSE Advisory, Python3 Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 16, 2026 Important SuSE
172

Ubuntu 25.10 Policykit Important Denial of Service Issues USN-8173-1

Several security issues were fixed in polkit.. ========================================================================== Ubuntu Security Notice USN-8173-1 April 14, 2026 policykit-1 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in polkit. Software Description: - policykit-1: framework for managing administrative policies and privileges Details: It was discovered that polkit incorrectly handled nested elements in XML policy files. If an administrator were tricked into installing a malicious policy file, a remote attacker could possibly use this issue to cause polkit to crash, resulting in a denial of service. (CVE-2025-7519) Pavel Kohout discovered that the polkit polkit-agent-helper-1 utility incorrectly handled long input. A local attacker could possibly use this issue to cause polkit to crash, resulting in a denial of service. (CVE-2026-4897) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 polkitd 126-2ubuntu0.1 Ubuntu 24.04 LTS policykit-1 124-2ubuntu1.24.04.3 Ubuntu 22.04 LTS policykit-1 0.105-33ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8173-1 CVE-2025-7519, CVE-2026-4897 Package Information: https://launchpad.net/ubuntu/+source/policykit-1/126-2ubuntu0.1 https://launchpad.net/ubuntu/+source/policykit-1/124-2ubuntu1.24.04.3 https://launchpad.net/ubuntu/+source/policykit-1/0.105-33ubuntu0.1 . Multiple security fixes for policykit-1 in Ubuntu to address denial of service concerns. Update necessary for system integrity.. Ubuntu security, policykit-1 fixes, denial of service vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 14, 2026 Important Ubuntu
87

Debian Libxml-Parser-Perl Heap Overflow Issue DSA-6182-1 CVE-2006-10003

Joris van Rantwijk discovered that libxml-parser-perl, a Perl module for parsing XML files, is prone to a heap-based buffer overflow flaw when parsing an XML file with very deep element nesting. For the oldstable distribution (bookworm), this problem has been fixed in version 2.46-4+deb12u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6182-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso March 28, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libxml-parser-perl CVE ID : CVE-2006-10003 Debian Bug : 378412 Joris van Rantwijk discovered that libxml-parser-perl, a Perl module for parsing XML files, is prone to a heap-based buffer overflow flaw when parsing an XML file with very deep element nesting. For the oldstable distribution (bookworm), this problem has been fixed in version 2.46-4+deb12u1. For the stable distribution (trixie), this problem has been fixed in version 2.47-2~deb13u1. We recommend that you upgrade your libxml-parser-perl packages. For the detailed security status of libxml-parser-perl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libxml-parser-perl Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Libxml-parser-perl faces an important heap overflow flaw, prompting updates for Debian users to mitigate risks.. Debian Security Advisory, libxml-parser-perl update, buffer overflow fix, XML parser security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 28, 2026 Important Debian
203

Mageia 9: Expat Critical Memory Allocation Risk MGASA-2025-0240

MGASA-2025-0240 - Updated expat packages fix security vulnerabilities. MGASA-2025-0240 - Updated expat packages fix security vulnerabilities Publication date: 18 Oct 2025 URL: https://advisories.mageia.org/MGASA-2025-0240.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-8176, CVE-2025-59375 Description: Improper restriction of xml entity expansion depth in libexpat. (CVE-2024-8176) This is an extension of the fix published in MGASA-2025-0109 that was determined by upstream to be incomplete. Libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing. (CVE-2025-59375) References: - https://bugs.mageia.org/show_bug.cgi?id=34640 - https://bugs.mageia.org/show_bug.cgi?id=34111 - https://www.openwall.com/lists/oss-security/2025/09/24/11 - https://advisories.mageia.org/MGASA-2025-0109.html - https://www.cve.org/CVERecord?id=CVE-2025-8176 - https://www.cve.org/CVERecord?id=CVE-2025-59375 SRPMS: - 9/core/expat-2.7.3-1.mga9 . Expat package updates in Mageia fix critical security issues related to XML parsing depth and memory allocation risks.. Mageia Security, Expat Update, XML Parsing Depth, Memory Allocation, Security Risks. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 18, 2025 Critical Mageia
197

Debian 11 bullseye DLA-4018-2: ruby2.7 regression fix for XML

A regression was identified in rexml gem. A corner case of XML namespace default namespace was not handled correctly, and thus rexml failed to parse valid XML file. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4018-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès February 11, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : ruby2.7 Version : 2.7.4-1+deb11u4 A regression was identified in rexml gem. A corner case of XML namespace default namespace was not handled correctly, and thus rexml failed to parse valid XML file. For Debian 11 bullseye, this problem has been fixed in version 2.7.4-1+deb11u4. We recommend that you upgrade your ruby2.7 packages. For the detailed security status of ruby2.7 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ruby2.7 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Make certain that ruby2.7 is updated to prevent XML parsing problems outlined in Advisory DLA-4018-3.. Debian LTS, Ruby2.7, XML Parsing, Security Update, Regression Issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 11, 2025 Important Debian LTS
197

Debian 11: DLA-4018-1 moderate: ruby2.7 multiple DoS vulnerabilities

Multiple vulnerabilities were found in ruby a popular programming language. CVE-2024-35176 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4018-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Bastien Roucariès January 17, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : ruby2.7 Version : 2.7.4-1+deb11u3 CVE ID : CVE-2024-35176 CVE-2024-39908 CVE-2024-41123 CVE-2024-41946 CVE-2024-43398 CVE-2024-49761 Multiple vulnerabilities were found in ruby a popular programming language. CVE-2024-35176 The REXML gem has a Denial of Service (DoS) vulnerability when it parses an XML that has many ` ] and ]> . If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. CVE-2024-41946 The REXML gem had a Denial of Service (DoS) vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. CVE-2024-43398 REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a Denial of Service (DoS) vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like REXML::Document.new, you may be impacted to this vulnerability. If you use other parser APIs such as stream parser API and SAX2 parser API, you are not impacted. CVE-2024-49761 REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). For Debian 11 bullseye, these problems have been fixed in version 2.7.4-1+deb11u3. We recommend that you upgrade your ruby2.7 packages. For the detailed security status of ruby2.7 please refer to its securitytracker page at: https://security-tracker.debian.org/tracker/source-package/ruby2.7 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Numerous vulnerabilities in ruby2.7 resolved in Debian LTS Advisory DLA-4018-1 released on January 17, 2025.. ruby2.7 advisory, DoS vulnerability, XML parsing issues, Debian security. . LinuxSecurity.com Team

Calendar%202 Jan 18, 2025 Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200