Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 470
Alerts This Week
Warning Icon 1 470

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 253 articles for you...
197

Debian 11: DLA-4233-1 critical: nagvis injection and XSS issues

Multiple vulnerabilities were discovered in nagvis, a visualization addon for Nagios or Icinga. CVE-2024-38866 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4233-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Daniel Leidert June 28, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : nagvis Version : 1:1.9.25-2+deb11u2 CVE ID : CVE-2024-38866 CVE-2024-47090 Debian Bug : 1106686 Multiple vulnerabilities were discovered in nagvis, a visualization addon for Nagios or Icinga. CVE-2024-38866 A livestatus injection via dynmaps is possible. CVE-2024-47090 A potential XSS exists via the WYSIWYG editor. For Debian 11 bullseye, these problems have been fixed in version 1:1.9.25-2+deb11u2. We recommend that you upgrade your nagvis packages. For the detailed security status of nagvis please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/nagvis Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Explore essential security patches for Nagvis in Debian LTS fixing injection flaws and XSS risks. Upgrade immediately!. nagvis security, Debian LTS, software update, cybersecurity fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 28, 2025 Critical Debian LTS
197

Debian 11: DLA-4224-1 important: node-send template injection fixed

Template injection that can lead to XSS has been fixed in node-send, a Node.js module for streaming files over HTTP. For Debian 11 bullseye, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4224-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk June 23, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : node-send Version : 0.17.1-2+deb11u1 CVE ID : CVE-2024-43799 Debian Bug : 1081483 Template injection that can lead to XSS has been fixed in node-send, a Node.js module for streaming files over HTTP. For Debian 11 bullseye, this problem has been fixed in version 0.17.1-2+deb11u1. We recommend that you upgrade your node-send packages. For the detailed security status of node-send please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/node-send Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A vulnerability in template processing resulting in XSS has been resolved in node-send for Debian 11, update is advised.. Nodejs Security, Debian LTS Advisory, XSS Vulnerability, Package Update, Template Injection Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 23, 2025 Important Debian LTS
202

openSUSE Leap 15.3/15.6 moderate: rabbitmq-server XSS fix

An update that solves one vulnerability can now be installed.. # Security update for rabbitmq-server Announcement ID: SUSE-SU-2025:1466-1 Release Date: 2025-05-06T06:06:40Z Rating: moderate References: * bsc#1240071 Cross-References: * CVE-2025-30219 CVSS scores: * CVE-2025-30219 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-30219 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L * CVE-2025-30219 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for rabbitmq-server fixes the following issues: * CVE-2025-30219: Fixed XSS in an error message in Management UI (bsc#1240071) Other fixes: \- Disable parallel make, this causes build failures ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-1466=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1466=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2025-1466=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * rabbitmq-server-plugins-3.8.11-150300.3.19.1 * erlang-rabbitmq-client-3.8.11-150300.3.19.1 * rabbitmq-server-3.8.11-150300.3.19.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * rabbitmq-server-plugins-3.8.11-150300.3.19.1 * erlang-rabbitmq-client-3.8.11-150300.3.19.1 * rabbitmq-server-3.8.11-150300.3.19.1 * Server Applications Module 15-SP6 (aarch64 ppc64les390x x86_64) * rabbitmq-server-plugins-3.8.11-150300.3.19.1 * erlang-rabbitmq-client-3.8.11-150300.3.19.1 * rabbitmq-server-3.8.11-150300.3.19.1 ## References: * https://www.suse.com/security/cve/CVE-2025-30219.html * https://bugzilla.suse.com/show_bug.cgi?id=1240071 . An important patch for rabbitmq-server on openSUSE fixes a severe XSS vulnerability, enhancing the safety of user experiences.. openSUSE, security update, rabbitmq-server, xss fix, patch instructions. . LinuxSecurity.com Team

Calendar%202 May 07, 2025 OpenSUSE
89

Fedora 41: workrave 2025-d611c8d114 critical: xss autoescape exploit

Unretireing the package.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-d611c8d114 2025-04-17 19:46:50.126382+00:00 -------------------------------------------------------------------------------- Name : workrave Product : Fedora 41 Version : 1.11.0~rc.1 Release : 1.fc41 URL : https://workrave.org/ Summary : Program that assists in the recovery and prevention of RSI Description : Workrave is a program that assists in the recovery and prevention of Repetitive Strain Injury (RSI). The program frequently alerts you to take micro-pauses, rest breaks and restricts you to your daily limit. -------------------------------------------------------------------------------- Update Information: Unretireing the package. -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 8 2025 Łukasz Wojniłowicz - 1.11.0~rc.1-1 - Unretirement import (fedora#2351398). -------------------------------------------------------------------------------- References: [ 1 ] Bug #2322802 - GNOME applet incompatible with GNOME 47 https://bugzilla.redhat.com/show_bug.cgi?id=2322802 [ 2 ] Bug #2328917 - CVE-2023-2142 workrave: Nunjucks autoescape bypass leads to cross site scripting [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2328917 [ 3 ] Bug #2328918 - CVE-2023-2142 workrave: Nunjucks autoescape bypass leads to cross site scripting [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2328918 [ 4 ] Bug #2351398 - Review Request: workrave - Program that assists in the recovery and prevention of RSI https://bugzilla.redhat.com/show_bug.cgi?id=2351398 [ 5 ] Bug #2358210 - F42FailsToInstall: workrave https://bugzilla.redhat.com/show_bug.cgi?id=2358210 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2025-d611c8d114' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Ubuntu 23.10 maintainer patch addresses privilege escalation vulnerability, crucial for system security.. Fedora 41 Update, workrave, security advisory, autoescape bypass, XSS risk. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 17, 2025 Critical Fedora
197

Debian 11: DLA-4113-1 critical: php-horde-imp XSS session hijack

An XSS vulnerability was discovered in Horde IMP, the webmail component of the Horde groupware platform. An attacker could hijack a user session by sending a crafted e-mail to an IMP user. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4113-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sylvain Beucler April 03, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : php-horde-imp Version : 6.2.27-2+deb11u1 CVE ID : CVE-2025-30349 Debian Bug : 1042715 An XSS vulnerability was discovered in Horde IMP, the webmail component of the Horde groupware platform. An attacker could hijack a user session by sending a crafted e-mail to an IMP user. Additionally, adjustments were made to handle the move to CKEditor v4 (see DLA-4112-1). For Debian 11 bullseye, this problem has been fixed in version 6.2.27-2+deb11u1. We recommend that you upgrade your php-horde-imp packages. For the detailed security status of php-horde-imp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/php-horde-imp Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A vulnerability in Horde IMP related to XSS could enable malicious actors to take over user sessions through specially designed emails. To ensure security, please update php-horde-imp.. Horde IMP, security advisory, Debian Linux, XSS attack, user session security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 03, 2025 Critical Debian LTS
89

Fedora 41: FEDORA-2024-2cb3145f8d critical: tomcat XSS Fix

Automatic update for tomcat-9.0.98-1.fc41. Changelog for tomcat * Mon Dec 09 2024 Packit - 1:9.0.98-1 - Update to version 9.0.98 - Resolves: rhbz#2331168. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2cb3145f8d 2024-12-25 01:50:07.031361+00:00 -------------------------------------------------------------------------------- Name : tomcat Product : Fedora 41 Version : 9.0.98 Release : 1.fc41 URL : http://tomcat.apache.org/ Summary : Apache Servlet/JSP Engine, RI for Servlet 4.0/JSP 2.3 API Description : Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. -------------------------------------------------------------------------------- Update Information: Automatic update for tomcat-9.0.98-1.fc41. Changelog for tomcat * Mon Dec 09 2024 Packit - 1:9.0.98-1 - Update to version 9.0.98 - Resolves: rhbz#2331168 * Mon Dec 02 2024 Dimitris Soumis - 1:9.0.97-1 - Update to version 9.0.97 - Resolves: rhbz#2327090 Automatic update for tomcat-9.0.97-1.fc41. Changelog for tomcat * Mon Dec 02 2024 Dimitris Soumis - 1:9.0.97-1 - Update to version 9.0.97 - Resolves: rhbz#2327090 -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 9 2024 Packit - 1:9.0.98-1 - Update to version 9.0.98 - Resolves: rhbz#2331168 * Mon Dec 2 2024 Dimitris Soumis - 1:9.0.97-1 - Update to version 9.0.97 - Resolves: rhbz#2327090 -------------------------------------------------------------------------------- References: [ 1] Bug #2327090 - CVE-2024-52318 tomcat: incorrect JSP tag recycling leads to XSS [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2327090 [ 2 ] Bug #2331168 - tomcat-9.0.98 is available https://bugzilla.redhat.com/show_bug.cgi?id=2331168 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2cb3145f8d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Upgrade for Tomcat 9.0.98 on Fedora introduced measures that mitigate known vulnerabilities while bolstering system integrity with advanced features.. Fedora Update, Tomcat Security, Software Release, Patch Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 25, 2024 Critical Fedora
197

Debian: DLA-3924-1 high: php-horde-mime-viewer XSS threat

It was discovered that there was a potential XSS vulnerability in php-horde-mime-viewer, a MIME viewer library for the Horde groupware platform. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3924-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Tobias Frost October 19, 2024 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : php-horde-mime-viewer Version : 2.2.4+debian0-2~deb11u1 CVE ID : CVE-2022-26874 Debian Bug : It was discovered that there was a potential XSS vulnerability in php-horde-mime-viewer, a MIME viewer library for the Horde groupware platform. For Debian 11 bullseye, this problem has been fixed in version 2.2.4+debian0-2~deb11u1. We recommend that you upgrade your php-horde-mime-viewer packages. For the detailed security status of php-horde-mime-viewer please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/php-horde-mime-viewer Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3924-2 mitigates vulnerabilities in php-horde-mime-viewer concerning XSS; users are advised to update.. php-horde-mime-viewer, XSS threat, Debian updates. . LinuxSecurity.com Team

Calendar%202 Oct 19, 2024 Debian LTS
89

Fedora 41: FEDORA-2024-92d80d7f9a high: WebKitGTK Cross-Origin Risks

Update to 2.46.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-92d80d7f9a 2024-10-10 00:15:44.893528 -------------------------------------------------------------------------------- Name : webkit2gtk4.0 Product : Fedora 41 Version : 2.46.1 Release : 2.fc41 URL : https://www.webkitgtk.org/ Summary : WebKitGTK for GTK 3 and libsoup 2 Description : WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. This package contains WebKitGTK for GTK 3 and libsoup 2. -------------------------------------------------------------------------------- Update Information: Update to 2.46.1 -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 3 2024 Michael Catanzaro - 2.46.1-2 - Add patch to fix build with LLVM 19 * Tue Oct 1 2024 Pete Walter - 2.46.1-1 - Update to 2.46.1 * Tue Oct 1 2024 Pete Walter - 2.46.0-2 - Add missing sysprof-capture-4 BuildRequires * Wed Sep 18 2024 Pete Walter - 2.46.0-1 - Update to 2.46.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2314731 - CVE-2024-44187 webkit2gtk4.0: A malicious website may exfiltrate data cross-origin [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2314731 [ 2 ] Bug #2314733 - CVE-2024-40857 webkit2gtk4.0: Processing maliciously crafted web content may lead to universal cross site scripting [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2314733 [ 3 ] Bug #2314743 - CVE-2024-27851 webkit2gtk4.0: Processing maliciously crafted web content may lead to arbitrary code execution [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2314743 [ 4 ] Bug #2314747 - CVE-2024-23271 webkit2gtk4.0: A malicious website may cause unexpected cross-origin behavior [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2314747 [ 5 ] Bug #2314749 -CVE-2024-27838 webkit2gtk4.0: A maliciously crafted webpage may be able to fingerprint the user [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2314749 [ 6 ] Bug #2314752 - CVE-2024-27833 webkit2gtk4.0: Processing maliciously crafted web content may lead to arbitrary code execution [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2314752 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-92d80d7f9a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 41 has released a WebKitGTK security advisory addressing significant vulnerabilities, including threats related to cross-origin data leaks and potential code execution exploits.. Fedora 41 WebKitGTK updates, security patch, web rendering engine, XSS risk, data exfiltration. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 10, 2024 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200