Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 9 articles for you...
215

GNOME: CVE-2023-43641 Critical: Remote Code Execution Risk

A memory corruption vulnerability in the open-source libcue library can let attackers execute arbitrary code on Linux systems running the GNOME desktop environment. . libcue, a library designed for parsing cue sheet files, is integrated into the Tracker Miners file metadata indexer, which is included by default in the latest GNOME versions. Cue sheets (or CUE files) are plain text files containing the layout of audio tracks on a CD, such as length, name of song, and musician, and are also typically paired with the FLAC audio file format. GNOME is a widely used desktop environment across various Linux distributions such as Debian, Ubuntu, Fedora, Red Hat Enterprise, and SUSE Linux Enterprise. Attackers can successfully exploit the flaw in question (CVE-2023-43641) to execute malicious code by taking advantage of Tracker Miners automatically indexing all downloaded files to update the search index on GNOME Linux devices. . A flaw in libcue related to memory management permits malicious actors to execute unauthorized code on GNOME Linux platforms through the downloading of compromised files.. GNOME Linux,Runtimes,Execution Attacks. . Brittany Day

Calendar%202 Oct 09, 2023 User Avatar Brittany Day Desktop Security
210

Intel: CVE-2022-4139 Moderate: Kernel Graphics Driver Data Leak Issue

CVE-2022-4139 was made public as an i915 kernel graphics driver security issue affecting all Gen12 graphics -- from integrated Tigerlake graphics up through the latest Raptor Lake graphics as well as the in-development Meteor Lake code plus the discrete GPUs of DG2/Alchemist and Arctic Sound. . Intel has disclosed CVE-2022-4139 as an incorrect GPU TLB flushing issue within their Linux kernel graphics driver. In some cases the translation lookaside buffer (TLB) is not flushed at all. At the very least there could be random memory corruption or data leaks while it's not yet been determined if specific memory could be targeted on affected Linux kernel versions up to this point. All versions from Linux 5.4 up through today's latest kernel versions are believed to be impacted when using Intel Gen12 integrated/discrete graphics. This though amounts to an Intel driver issue and not a hardware problem itself. Linus Torvalds just merged this five lines of code for mitigating the TLB invalidation on Intel Gen12 graphics for the video and compute engines. The link for this article located at Phoronix is no longer available. . Intel revealed a flaw involving GPU TLB flushing within their Linux kernel driver, impacting Gen12 graphics ranging from Tigerlake through Raptor Lake.. Intel Graphics Driver, Kernel Patch, GPU TLB Issue, Linux Kernel Security, Memory Corruption. . Brittany Day

Calendar%202 Dec 02, 2022 User Avatar Brittany Day Security Vulnerabilities
210

GRUB: Security Advisory for UEFI Secure Boot Problems and Threats

Last summer, the GRUB bootloader was impacted by "BootHole" with security issues hitting its UEFI Secure Boot support. Now a new round of GRUB2 vulnerabilities affecting its UEFI Secure Boot support have been made public. . A new set of GRUB2 security vulnerabilities were made public today affecting its UEFI Secure Boot support. A set of eight CVEs were issued in 2020 and this year for the new issues. The issues include the possibility of specially crafted ACPI tables being loaded even if Secure Boot is active, memory corruption in GRUB's menu rendering, use-after-free in rmmod functionality, the cutmem command allowing privileged users to disable certain memory regions and in turn Secure Boot protections, arbitrary code execution even if Secure Boot is enabled, GRUB 2.05 accidentally re-introducing one of last year's vulnerabilities, and memory corruption from crafted USB device descriptors that could lead to arbitrary code execution. The link for this article located at Phoronix is no longer available. . Recent GRUB2 flaws unveil potential UEFI Secure Boot complications that jeopardize device safety. Discover further details.. GRUB Bootloader, UEFI Security, Boot Protection, Code Execution. . Brittany Day

Calendar%202 Mar 03, 2021 User Avatar Brittany Day Security Vulnerabilities
78

Firefox 39 Security Advisory Four Critical Threats Fixed

Mozilla has rolled out a new version of its Firefox browser, an update that includes patches for four critical security vulnerabilities and several less-severe bugs. IN all, Firefox 39 patches 13 vulnerabilities, including two high-risk bugs and six moderate-level ones. The most dangerous vulnerabilities, however, include a pair of use-after-free bugs in one part of the browser and another in a separate component, as well as a number of memory corruption flaws. . . Mozilla releases Firefox 39 update, addressing four major vulnerabilities along with various minor glitches.. Firefox Security Updates,Critical Security Patches,Memory Corruption Flaws. . LinuxSecurity.com Team

Calendar%202 Jul 09, 2015 User Avatar LinuxSecurity.com Team Vendors/Products
78

VLC Media Player Severe Memory Corruption Threats CVE-2023-XXXX-1

There are two memory corruption vulnerabilities in some versions of the VLC open-source media player that can allow an attacker to run arbitrary code on vulnerable machines. . Neither one of the vulnerabilities has been fixed by VideoLAN, the organization that maintains VLC. Security researcher Veysel Hatas reported the vulnerabilities to VideoLAN in December and published the advisories on Full Disclosure on Friday. One of the bugs is a DEP access violation vulnerability and the other is is a write access flaw. The link for this article located at ThreatPost is no longer available. . Two memory management vulnerabilities in VLC may allow attackers to execute unauthorized commands on unpatched systems. Stay informed about effective countermeasures. VLC Media Player, memory corruption, code execution risks. . LinuxSecurity.com Team

Calendar%202 Jan 21, 2015 User Avatar LinuxSecurity.com Team Vendors/Products
78

Mozilla: Critical Updates For Firefox and Thunderbird Security Threats

Following the release of new versions of its open source Firefox web browser, Thunderbird email client and SeaMonkey suite, Mozilla has detailed the security fixes included in each of the updates. According to the project's Security Center page for Firefox, version 10.0 closes a total of 8 security holes in the browser, 5 of which are rated as "Critical" by Mozilla.. The critical issues include an exploitable crash when processing a malformed embedded XSLT stylesheet, potential memory corruption when decoding Ogg Vorbis files, XPConnect security checks being bypassed by frame scripts, a use after free error in child nodes from nsDOMAttribute and various memory safety hazards. These vulnerabilities could be exploited remotely by an attacker to, for example, execute arbitrary code on a victim's system. The link for this article located at H Security is no longer available. . Mozilla has announced crucial security updates for Firefox, Thunderbird, and SeaMonkey to address vulnerabilities that could lead to remote exploitation.. Mozilla Firefox Security, Thunderbird Update, SeaMonkey Fixes, Remote Exploits. . LinuxSecurity.com Team

Calendar%202 Feb 01, 2012 User Avatar LinuxSecurity.com Team Vendors/Products
78

Wireshark: 1.2.15 and 1.4.4 Critical: Memory Corruption Issue

The Wireshark developers have announced the release of version 1.2.15 and 1.4.4 of their open source, cross-platform network protocol analyser; maintenance updates address two highly critical security vulnerabilities that could cause the application to crash.. The first issue (CVE-2011-0538), discovered by Huzaifa Sidhpurwala of the Red Hat Security Response Team, could lead to memory corruption when reading a .pcap file in the pcap-ng format The link for this article located at H Security is no longer available. . The first issue (CVE-2011-0538), discovered by Huzaifa Sidhpurwala of the Red Hat Security Response . wireshark, developers, announced, release, version, their, source. . LinuxSecurity.com Team

Calendar%202 Mar 03, 2011 User Avatar LinuxSecurity.com Team Vendors/Products
83

Red Hat Advisory: Xpdf Critical Risks to CUPS and Poppler Security

According to a report from Red Hat, two vulnerabilities in the free PDF reader Xpdf can be exploited via manipulated PDF documents to compromise a victim's system. The flaws are reportedly due to an uninitialised pointer and an array index error.. These problems extend to a number of applications that use the Xpdf code, including, poppler, CUPS, gPDF and KPDF. However, Red Hat hasn't released specific information about affected versions. Whether the document viewer Evince, which relies on poppler, is also affected is unknown. The link for this article located at H Security is no longer available. . Multiple weaknesses identified in Xpdf may affect numerous programs like CUPS and poppler, presenting potential security risks.. Xpdf Security Risks, CUPS Flaws, Poppler Issues. . LinuxSecurity.com Team

Calendar%202 Oct 13, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200