Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 2 articles for you...
100

SUSE Linux Micro 6.1 libxslt libxml2 Moderate XML Issues 20657-1

An update that solves six vulnerabilities and has eight fixes can now be installed.. # Security update for libxslt, libxml2 Announcement ID: SUSE-SU-2026:20657-1 Release Date: 2026-03-06T11:35:58Z Rating: moderate References: * bsc#1247850 * bsc#1247858 * bsc#1250553 * bsc#1256804 * bsc#1256805 * bsc#1256807 * bsc#1256808 * bsc#1256809 * bsc#1256810 * bsc#1256811 * bsc#1256812 * bsc#1257593 * bsc#1257594 * bsc#1257595 Cross-References: * CVE-2025-10911 * CVE-2025-8732 * CVE-2026-0989 * CVE-2026-0990 * CVE-2026-0992 * CVE-2026-1757 CVSS scores: * CVE-2025-10911 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-10911 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-10911 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-8732 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-8732 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-8732 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8732 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-0989 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-0989 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-0989 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-0990 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-0990 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0990 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0992 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-0992 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-0992( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-1757 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-1757 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-1757 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has eight fixes can now be installed. ## Description: This update for libxslt, libxml2 fixes the following issues: libxml2: * CVE-2026-0990: call stack overflow leading to application crash due to infinite recursion in `xmlCatalogXMLResolveURI` (bsc#1256807, bsc#1256811) * CVE-2026-0992: excessive resource consumption when processing XML catalogs due to exponential behavior when handling ` ` elements (bsc#1256808, bsc#1256809, bsc#1256812) * CVE-2025-8732: infinite recursion in catalog parsing functions when processing malformed SGML catalog files (bsc#1247858, bsc#1247850) * CVE-2026-1757: memory leak in the `xmllint` interactive shell (bsc#1257593, bsc#1257594, bsc#1257595) * CVE-2025-10911: use-after-free with key data stored cross-RVT (bsc#1250553) * CVE-2026-0989: call stack exhaustion leading to application crash due to RelaxNG parser not limiting the recursion depth when resolving ` ` directives (bsc#1256804, bsc#1256805, bsc#1256810) libxslt: * CVE-2025-10911 will be fixed on libxml2 side instead [bsc#1250553] ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-429=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libxml2-tools-2.11.6-slfo.1.1_8.1 * libexslt0-1.1.38-slfo.1.1_6.1 * libxml2-2-2.11.6-slfo.1.1_8.1 * libxml2-debugsource-2.11.6-slfo.1.1_8.1 *libxslt1-debuginfo-1.1.38-slfo.1.1_6.1 * libxml2-2-debuginfo-2.11.6-slfo.1.1_8.1 * libxml2-tools-debuginfo-2.11.6-slfo.1.1_8.1 * python311-libxml2-debuginfo-2.11.6-slfo.1.1_8.1 * python311-libxml2-2.11.6-slfo.1.1_8.1 * libexslt0-debuginfo-1.1.38-slfo.1.1_6.1 * libxslt1-1.1.38-slfo.1.1_6.1 * libxml2-python-debugsource-2.11.6-slfo.1.1_8.1 * libxslt-debugsource-1.1.38-slfo.1.1_6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10911.html * https://www.suse.com/security/cve/CVE-2025-8732.html * https://www.suse.com/security/cve/CVE-2026-0989.html * https://www.suse.com/security/cve/CVE-2026-0990.html * https://www.suse.com/security/cve/CVE-2026-0992.html * https://www.suse.com/security/cve/CVE-2026-1757.html * https://bugzilla.suse.com/show_bug.cgi?id=1247850 * https://bugzilla.suse.com/show_bug.cgi?id=1247858 * https://bugzilla.suse.com/show_bug.cgi?id=1250553 * https://bugzilla.suse.com/show_bug.cgi?id=1256804 * https://bugzilla.suse.com/show_bug.cgi?id=1256805 * https://bugzilla.suse.com/show_bug.cgi?id=1256807 * https://bugzilla.suse.com/show_bug.cgi?id=1256808 * https://bugzilla.suse.com/show_bug.cgi?id=1256809 * https://bugzilla.suse.com/show_bug.cgi?id=1256810 * https://bugzilla.suse.com/show_bug.cgi?id=1256811 * https://bugzilla.suse.com/show_bug.cgi?id=1256812 * https://bugzilla.suse.com/show_bug.cgi?id=1257593 * https://bugzilla.suse.com/show_bug.cgi?id=1257594 * https://bugzilla.suse.com/show_bug.cgi?id=1257595 . Update addresses six security weaknesses in libxslt and libxml2 for SUSE Linux Micro 6.1. Immediate installation recommended.. libxml2 update, libxslt security, SUSE vulnerabilities, Linux micro security. . LinuxSecurity.com Team

Calendar%202 Mar 18, 2026 SuSE
100

SUSE Linux Micro 6.0 libxslt libxml2 Moderate XML Issues and Memory Leak

An update that solves six vulnerabilities and has eight fixes can now be installed.. # Security update for libxslt, libxml2 Announcement ID: SUSE-SU-2026:20707-1 Release Date: 2026-03-06T11:58:49Z Rating: moderate References: * bsc#1247850 * bsc#1247858 * bsc#1250553 * bsc#1256804 * bsc#1256805 * bsc#1256807 * bsc#1256808 * bsc#1256809 * bsc#1256810 * bsc#1256811 * bsc#1256812 * bsc#1257593 * bsc#1257594 * bsc#1257595 Cross-References: * CVE-2025-10911 * CVE-2025-8732 * CVE-2026-0989 * CVE-2026-0990 * CVE-2026-0992 * CVE-2026-1757 CVSS scores: * CVE-2025-10911 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-10911 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-10911 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-8732 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-8732 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-8732 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8732 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-0989 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-0989 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-0989 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-0990 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-0990 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0990 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0992 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-0992 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-0992( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-1757 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-1757 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-1757 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has eight fixes can now be installed. ## Description: This update for libxslt, libxml2 fixes the following issues: Changes in libxml2: * CVE-2026-0990: call stack overflow may lead to application crash due to infinite recursion in `xmlCatalogXMLResolveURI` (bsc#1256807, bsc#1256811). * CVE-2026-0992: excessive resource consumption when processing XML catalogs due to exponential behavior when handling `nextCatalog` elements (bsc#1256809, bsc#1256812). * CVE-2025-8732: infinite recursion in catalog parsing functions when processing malformed SGML catalog files (bsc#1247858). * CVE-2026-1757: memory leak in the `xmllint` interactive shell (bsc#1257594, bsc#1257595). * CVE-2025-10911: parsing xsl nodes may lead to use-after-free with key data stored cross-RVT (bsc#1250553). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-608=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libxml2-debugsource-2.11.6-12.1 * libexslt0-debuginfo-1.1.38-8.1 * python311-libxml2-debuginfo-2.11.6-12.1 * libxslt1-1.1.38-8.1 * libxml2-python-debugsource-2.11.6-12.1 * libexslt0-1.1.38-8.1 * libxml2-2-2.11.6-12.1 * libxslt-debugsource-1.1.38-8.1 * libxml2-tools-debuginfo-2.11.6-12.1 * libxslt1-debuginfo-1.1.38-8.1 * libxml2-2-debuginfo-2.11.6-12.1 * python311-libxml2-2.11.6-12.1 *libxml2-tools-2.11.6-12.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10911.html * https://www.suse.com/security/cve/CVE-2025-8732.html * https://www.suse.com/security/cve/CVE-2026-0989.html * https://www.suse.com/security/cve/CVE-2026-0990.html * https://www.suse.com/security/cve/CVE-2026-0992.html * https://www.suse.com/security/cve/CVE-2026-1757.html * https://bugzilla.suse.com/show_bug.cgi?id=1247850 * https://bugzilla.suse.com/show_bug.cgi?id=1247858 * https://bugzilla.suse.com/show_bug.cgi?id=1250553 * https://bugzilla.suse.com/show_bug.cgi?id=1256804 * https://bugzilla.suse.com/show_bug.cgi?id=1256805 * https://bugzilla.suse.com/show_bug.cgi?id=1256807 * https://bugzilla.suse.com/show_bug.cgi?id=1256808 * https://bugzilla.suse.com/show_bug.cgi?id=1256809 * https://bugzilla.suse.com/show_bug.cgi?id=1256810 * https://bugzilla.suse.com/show_bug.cgi?id=1256811 * https://bugzilla.suse.com/show_bug.cgi?id=1256812 * https://bugzilla.suse.com/show_bug.cgi?id=1257593 * https://bugzilla.suse.com/show_bug.cgi?id=1257594 * https://bugzilla.suse.com/show_bug.cgi?id=1257595 . Update for SUSE addresses several important issues in libxslt and libxml2, enhancing system security against potential threats.. libxslt security, libxml2 update, SUSE vulnerabilities, system security fixes, Linux application security. . LinuxSecurity.com Team

Calendar%202 Mar 18, 2026 SuSE
197

Debian 10: DLA-3172-1 Critical: Libxml2 Integer Overflow and Memory Error

It was discovered that libxml2, the GNOME XML library, was vulnerable to integer overflows and memory corruption. CVE-2022-40303 . -------------------------------------------------------------------------Debian LTS Advisory DLA-3172-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany October 30, 2022 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : libxml2 Version : 2.9.4+dfsg1-7+deb10u5 CVE ID : CVE-2022-40303 CVE-2022-40304 Debian Bug : 1022224 1022225 It was discovered that libxml2, the GNOME XML library, was vulnerable to integer overflows and memory corruption. CVE-2022-40303 Parsing a XML document with the XML_PARSE_HUGE option enabled can result in an integer overflow because safety checks were missing in some functions. Also, the xmlParseEntityValue function did not have any length limitation. CVE-2022-40304 When a reference cycle is detected in the XML entity cleanup function the XML entity data can be stored in a dictionary. In this case, the dictionary becomes corrupted resulting in logic errors, including memory errors like double free. For Debian 10 buster, these problems have been fixed in version 2.9.4+dfsg1-7+deb10u5. We recommend that you upgrade your libxml2 packages. For the detailed security status of libxml2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libxml2 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Debian LTS security advisory DLA-3172-1 concerns critical vulnerabilities in the libxml2 library, specifically focusing on issues such as integer overflows and memory corruption risks.. Libxml2, Memory Corruption, IntegerOverflow, Debian Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 30, 2022 Critical Debian LTS
203

Mageia 2021-0213 Critical: libxml2 Buffer Overflow and Other Issues

The updated packages fix security vulnerabilities: Use-after-free in xmlEncodeEntitiesInternal() in entities.c. (CVE-2021-3516) . MGASA-2021-0213 - Updated libxml2 packages fix security vulnerabilities Publication date: 19 May 2021 URL: https://advisories.mageia.org/MGASA-2021-0213.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-3516, CVE-2021-3517, CVE-2021-3518, CVE-2021-3537 The updated packages fix security vulnerabilities: Use-after-free in xmlEncodeEntitiesInternal() in entities.c. (CVE-2021-3516) Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c. (CVE-2021-3517) Use-after-free in xmlXIncludeDoProcess() in xinclude.c. (CVE-2021-3518) NULL pointer dereference in valid.c in xmlValidBuildAContentModel. (CVE-2021-3537) References: - https://bugs.mageia.org/show_bug.cgi?id=28902 - https://lists.debian.org/debian-lts-announce/2021/05/msg00008.html - - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/QVM4UJ3376I6ZVOYMHBNX4GY3NIV52WV/ - https://www.cve.org/CVERecord?id=CVE-2021-3516 - https://www.cve.org/CVERecord?id=CVE-2021-3517 - https://www.cve.org/CVERecord?id=CVE-2021-3518 - https://www.cve.org/CVERecord?id=CVE-2021-3537 SRPMS: - 8/core/libxml2-2.9.10-7.1.mga8 - 7/core/libxml2-2.9.9-2.6.mga7 . Enhanced libxml2 distributions address numerous security flaws, encompassing use-after-free errors and buffer overrun vulnerabilities.. libxml2 updates,Mageia security,buffer overflow fixes,security vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 19, 2021 Critical Mageia
89

Fedora 33: FEDORA-2020-ff317550e4 Moderate: mingw-libxml2 Buffer Overflow

Add correct fix for CVE-2020-24977 (RHBZ#1877788), thanks: Jan de Groot.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-ff317550e4 2020-11-20 01:38:40.112323 --------------------------------------------------------------------------------Name : mingw-libxml2 Product : Fedora 33 Version : 2.9.10 Release : 8.fc33 URL : Summary : MinGW Windows libxml2 XML processing library Description : MinGW Windows libxml2 XML processing library. --------------------------------------------------------------------------------Update Information: Add correct fix for CVE-2020-24977 (RHBZ#1877788), thanks: Jan de Groot. --------------------------------------------------------------------------------ChangeLog: * Wed Nov 11 2020 Richard W.M. Jones - 2.9.10-8 - Add correct fix for CVE-2020-24977 (RHBZ#1877788), thanks: Jan de Groot. --------------------------------------------------------------------------------References: [ 1 ] Bug #1877788 - CVE-2020-24977 libxml2: Buffer Overflow vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c https://bugzilla.redhat.com/show_bug.cgi?id=1877788 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-ff317550e4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code ofConduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The buffer overflow vulnerability in mingw-libxml2 on Fedora 33 has been addressed through advisory FEDORA-2020-ff317550e4. Update using 'dnf update mingw-libxml2' to ensure security. mingw-libxml2, buffer overflow, Fedora updates. . LinuxSecurity.com Team

Calendar%202 Nov 19, 2020 Fedora
89

Fedora 32: FEDORA-2020-b60dbdd538 Critical: mingw-libxml2 Buffer Overflow

Add fix for CVE-2020-24977 (RHBZ#1877788, RHBZ#1877789).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-b60dbdd538 2020-09-19 22:37:58.507772 --------------------------------------------------------------------------------Name : mingw-libxml2 Product : Fedora 32 Version : 2.9.10 Release : 3.fc32 URL : Summary : MinGW Windows libxml2 XML processing library Description : MinGW Windows libxml2 XML processing library. --------------------------------------------------------------------------------Update Information: Add fix for CVE-2020-24977 (RHBZ#1877788, RHBZ#1877789). --------------------------------------------------------------------------------ChangeLog: * Fri Sep 11 2020 Richard W.M. Jones - 2.9.10-7 - Add fix for CVE-2020-24977 (RHBZ#1877788, RHBZ#1877789). * Tue Jul 28 2020 Fedora Release Engineering - 2.9.10-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1877788 - CVE-2020-24977 libxml2: Buffer Overflow vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c https://bugzilla.redhat.com/show_bug.cgi?id=1877788 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-b60dbdd538' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribesend an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora 32 enhances mingw-libxml2 with a vital remedy for the buffer overflow issue CVE-2020-24977. Take action immediately!. mingw-libxml2. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 19, 2020 Critical Fedora
98

Red Hat Enterprise Linux 7: RHSA-2020-1190-01 Moderate: Libxml2 DoS Issues

An update for libxml2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libxml2 security update Advisory ID: RHSA-2020:1190-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:1190 Issue date: 2020-03-31 CVE Names: CVE-2015-8035 CVE-2016-5131 CVE-2017-15412 CVE-2017-18258 CVE-2018-14404 CVE-2018-14567 ==================================================================== 1. Summary: An update for libxml2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The libxml2 library is a development toolbox providing the implementation of various XML standards. Security Fix(es): * libxml2: Use after free triggered by XPointer paths beginning with range-to (CVE-2016-5131) * libxml2: Use after free inxmlXPathCompOpEvalPositionalPredicate() function in xpath.c (CVE-2017-15412) * libxml2: DoS caused by incorrect error detection during XZ decompression (CVE-2015-8035) * libxml2: NULL pointer dereference in xmlXPathCompOpEval() function in xpath.c (CVE-2018-14404) * libxml2: Unrestricted memory usage in xz_head() function in xzlib.c (CVE-2017-18258) * libxml2: Infinite loop caused by incorrect error detection during LZMA decompression (CVE-2018-14567) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.8 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The desktop must be restarted (log out, then log back in) for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1277146 - CVE-2015-8035 libxml2: DoS caused by incorrect error detection during XZ decompression 1358641 - CVE-2016-5131 libxml2: Use after free triggered by XPointer paths beginning with range-to 1523128 - CVE-2017-15412 libxml2: Use after free in xmlXPathCompOpEvalPositionalPredicate() function in xpath.c 1566749 - CVE-2017-18258 libxml2: Unrestricted memory usage in xz_head() function in xzlib.c 1595985 - CVE-2018-14404 libxml2: NULL pointer dereference in xmlXPathCompOpEval() function in xpath.c 1619875 - CVE-2018-14567 libxml2: Infinite loop caused by incorrect error detection during LZMA decompression 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: libxml2-2.9.1-6.el7.4.src.rpm x86_64: libxml2-2.9.1-6.el7.4.i686.rpm libxml2-2.9.1-6.el7.4.x86_64.rpm libxml2-debuginfo-2.9.1-6.el7.4.i686.rpm libxml2-debuginfo-2.9.1-6.el7.4.x86_64.rpm libxml2-python-2.9.1-6.el7.4.x86_64.rpm Red Hat EnterpriseLinux Client Optional (v. 7): x86_64: libxml2-debuginfo-2.9.1-6.el7.4.i686.rpm libxml2-debuginfo-2.9.1-6.el7.4.x86_64.rpm libxml2-devel-2.9.1-6.el7.4.i686.rpm libxml2-devel-2.9.1-6.el7.4.x86_64.rpm libxml2-static-2.9.1-6.el7.4.i686.rpm libxml2-static-2.9.1-6.el7.4.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: libxml2-2.9.1-6.el7.4.src.rpm x86_64: libxml2-2.9.1-6.el7.4.i686.rpm libxml2-2.9.1-6.el7.4.x86_64.rpm libxml2-debuginfo-2.9.1-6.el7.4.i686.rpm libxml2-debuginfo-2.9.1-6.el7.4.x86_64.rpm libxml2-python-2.9.1-6.el7.4.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: libxml2-debuginfo-2.9.1-6.el7.4.i686.rpm libxml2-debuginfo-2.9.1-6.el7.4.x86_64.rpm libxml2-devel-2.9.1-6.el7.4.i686.rpm libxml2-devel-2.9.1-6.el7.4.x86_64.rpm libxml2-static-2.9.1-6.el7.4.i686.rpm libxml2-static-2.9.1-6.el7.4.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: libxml2-2.9.1-6.el7.4.src.rpm ppc64: libxml2-2.9.1-6.el7.4.ppc.rpm libxml2-2.9.1-6.el7.4.ppc64.rpm libxml2-debuginfo-2.9.1-6.el7.4.ppc.rpm libxml2-debuginfo-2.9.1-6.el7.4.ppc64.rpm libxml2-devel-2.9.1-6.el7.4.ppc.rpm libxml2-devel-2.9.1-6.el7.4.ppc64.rpm libxml2-python-2.9.1-6.el7.4.ppc64.rpm ppc64le: libxml2-2.9.1-6.el7.4.ppc64le.rpm libxml2-debuginfo-2.9.1-6.el7.4.ppc64le.rpm libxml2-devel-2.9.1-6.el7.4.ppc64le.rpm libxml2-python-2.9.1-6.el7.4.ppc64le.rpm s390x: libxml2-2.9.1-6.el7.4.s390.rpm libxml2-2.9.1-6.el7.4.s390x.rpm libxml2-debuginfo-2.9.1-6.el7.4.s390.rpm libxml2-debuginfo-2.9.1-6.el7.4.s390x.rpm libxml2-devel-2.9.1-6.el7.4.s390.rpm libxml2-devel-2.9.1-6.el7.4.s390x.rpm libxml2-python-2.9.1-6.el7.4.s390x.rpm x86_64: libxml2-2.9.1-6.el7.4.i686.rpm libxml2-2.9.1-6.el7.4.x86_64.rpm libxml2-debuginfo-2.9.1-6.el7.4.i686.rpm libxml2-debuginfo-2.9.1-6.el7.4.x86_64.rpm libxml2-devel-2.9.1-6.el7.4.i686.rpm libxml2-devel-2.9.1-6.el7.4.x86_64.rpm libxml2-python-2.9.1-6.el7.4.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): ppc64: libxml2-debuginfo-2.9.1-6.el7.4.ppc.rpm libxml2-debuginfo-2.9.1-6.el7.4.ppc64.rpm libxml2-static-2.9.1-6.el7.4.ppc.rpm libxml2-static-2.9.1-6.el7.4.ppc64.rpm ppc64le: libxml2-debuginfo-2.9.1-6.el7.4.ppc64le.rpm libxml2-static-2.9.1-6.el7.4.ppc64le.rpm s390x: libxml2-debuginfo-2.9.1-6.el7.4.s390.rpm libxml2-debuginfo-2.9.1-6.el7.4.s390x.rpm libxml2-static-2.9.1-6.el7.4.s390.rpm libxml2-static-2.9.1-6.el7.4.s390x.rpm x86_64: libxml2-debuginfo-2.9.1-6.el7.4.i686.rpm libxml2-debuginfo-2.9.1-6.el7.4.x86_64.rpm libxml2-static-2.9.1-6.el7.4.i686.rpm libxml2-static-2.9.1-6.el7.4.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: libxml2-2.9.1-6.el7.4.src.rpm x86_64: libxml2-2.9.1-6.el7.4.i686.rpm libxml2-2.9.1-6.el7.4.x86_64.rpm libxml2-debuginfo-2.9.1-6.el7.4.i686.rpm libxml2-debuginfo-2.9.1-6.el7.4.x86_64.rpm libxml2-devel-2.9.1-6.el7.4.i686.rpm libxml2-devel-2.9.1-6.el7.4.x86_64.rpm libxml2-python-2.9.1-6.el7.4.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: libxml2-debuginfo-2.9.1-6.el7.4.i686.rpm libxml2-debuginfo-2.9.1-6.el7.4.x86_64.rpm libxml2-static-2.9.1-6.el7.4.i686.rpm libxml2-static-2.9.1-6.el7.4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2015-8035 https://access.redhat.com/security/cve/CVE-2016-5131 https://access.redhat.com/security/cve/CVE-2017-15412 https://access.redhat.com/security/cve/CVE-2017-18258 https://access.redhat.com/security/cve/CVE-2018-14404 https://access.redhat.com/security/cve/CVE-2018-14567 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/7/html/7.8_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGPSIGNATURE----- Version: GnuPG v1 iQIVAwUBXoOdR9zjgjWX9erEAQhgbQ/+JolcknqNffv7HQZNxYOtS/M2Zx/E3IB4 QwmkXhfmgV44ig4prUpghE/+O5eTUPjqSq6rHjih/pjCjG4bVcK6BptxBFi7WQwo GM0ryvm0p0fib0dy+Ov3NNC6Dhg32NIVwC0pWTIEdYcOGBfDY3mXlLXx5aHefisu p1C7F6rP4xxMRDOlQhAB4UPMkPSD/MtKIyxIEqiAT5olybSTl0um2AB5XtLlCbkT h4IXDsAyswvBIS/bxnyZkn6oHEiD3JBwcP+ZU0jgSEy34O92ttV7hRQb1H1+YHOO li1bX5IcbmFzATwBfCZQmNfrp/XU4Ra28GT/3JGntnhhxFmz1xe/h5YNJTwZ+0TX yxKZdAz3brm/mt6uvbY4PpGERyA+X/Moz4ToXCEL2jVfSXbOuajRtCV8Cp3X7bCd Ed2imuXZQPpUXNVdF73RJ7YB6vEhQRIdlKgEXzPPpuHFH1HprvSLoJyrDD1T8bfx TVrrmvtWKtXq0DYSD7wGw23WZJJeUIgyKiZNTlIxvb0c7r8+aZ+toY07sZlBkTCA cjWNRnHDNkdYH2ZoNPQlzYzk5rSYGqhoOvF85pNCY4v4fofyMEnyAY7MEZ/Z991X Ko2ShKSzEtKSMcx2B2wPg+hFcACP8HbKxSbW3SzoCSKCOGEAPLQlJ5eHXwLOAO3Q IZIK7xZywNw=8RZh -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://access.redhat.com/security/updates/advisory . Oracle has published a notable safety alert regarding OpenSSL for Solaris 11, tackling significant vulnerabilities in SSL/TLS protocols.. libxml2 Update, Red Hat Security, RHEL Advisory, Memory Management, XML Library. . LinuxSecurity.com Team

Calendar%202 Mar 31, 2020 Red Hat
89

Fedora 24: BATIK Security Update Critical: CVE-2017-5662 XML Issue

Security fix for CVE-2017-5662. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-aff3dd3101 2017-05-09 21:16:27.649955 --------------------------------------------------------------------------------Name : batik Product : Fedora 24 Version : 1.8 Release : 9.fc24 URL : https://xmlgraphics.apache.org/batik/ Summary : Scalable Vector Graphics for Java Description : Batik is a Java(tm) technology based toolkit for applications that want to use images in the Scalable Vector Graphics (SVG) format for various purposes, such as viewing, generation or manipulation. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-5662 --------------------------------------------------------------------------------References: [ 1 ] Bug #1443592 - CVE-2017-5662 batik: XML external entity processing vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=1443592 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade batik' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Important security patch released for Batik in Fedora 24 to fix vulnerability related to XML external entity handling.. Batik Security Update, Fedora 24 Update, XML Graphics Fix. . Severity: Critical.LinuxSecurity.com Team

Calendar%202 May 10, 2017 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200