Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 494
Alerts This Week
Warning Icon 1 494

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":2,"type":"x","order":2,"pct":66.67,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 9,991 articles for you...
203

Mageia socat Critical Heap Buffer Overflow Vuln 2026-0290

Mageia released an update on July 23, 2026, addressing a heap buffer overflow vulnerability in the SOCKS5 reply parser, impacting releases 10 and 9.. Publication date: 23 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0290.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-56123 Description: The updated package fixes a security vulnerability: Heap Buffer Overflow via SOCKS5 Reply Parser. (CVE-2026-56123) References: - https://bugs.mageia.org/show_bug.cgi?id=35794 - https://lists.opensuse.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/F6FLUO6FYZ6TSE43PLY7QJGUX4N2JXWW/ - https://ubuntu.com/security/notices/USN-8511-1 - https://www.cve.org/CVERecord?id=CVE-2026-56123 SRPMS: - 10/core/socat-1.8.1.0-1.1.mga10 - 9/core/socat-1.8.0.2-1.1.mga9 . A critical update fixes a heap buffer overflow vulnerability in socat affecting Mageia 9 and 10.. Mageia socat update buffer overflow security fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 23, 2026 Important Mageia
203

Mageia Apache Critical Security Issues Advisory 2026-0289 CVE-2026-29167

Mageia released updates for security vulnerabilities in Apache HTTP Server affecting versions 10 and 9, addressing multiple issues including buffer overflows and denial of service attacks.. Publication date: 23 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0289.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-29167, CVE-2026-29170, CVE-2026-34355, CVE-2026-34356, CVE-2026-42535, CVE-2026-42536, CVE-2026-43951, CVE-2026-44119, CVE-2026-44185, CVE-2026-44186, CVE-2026-44631, CVE-2026-48913, CVE-2026-49975 Description: The updated packages fix security vulnerabilities: Apache HTTP Server: mod_ldap per-dir use-after-free. (CVE-2026-29167) Apache HTTP Server: mod_proxy_ftp XSS. (CVE-2026-29170) Apache HTTP Server: mod_proxy_html buffer overflow. (CVE-2026-34355) Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow. (CVE-2026-34356) Apache HTTP Server: mod_dav_fs protected directory access. (CVE-2026-42535) Apache HTTP Server: mod_xml2enc heap overflow. (CVE-2026-42536) Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash. (CVE-2026-43951) Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules. (CVE-2026-44119) Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`. (CVE-2026-44185) Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp. (CVE-2026-44186) Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow. (CVE-2026-44631) Apache HTTP Server: mod_http2 memory corruption when file handles exhausted. (CVE-2026-48913) Apache HTTP Server: mod_http2 denial of service. (CVE-2026-49975) References: - https://bugs.mageia.org/show_bug.cgi?id=35625 - https://www.openwall.com/lists/oss-security/2026/06/03/3 - https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb - https://lists.debian.org/debian-security-announce/2026/msg00234.html - https://www.openwall.com/lists/oss-security/2026/06/08/4 -https://www.openwall.com/lists/oss-security/2026/06/08/5 - https://www.openwall.com/lists/oss-security/2026/06/08/6 - https://www.openwall.com/lists/oss-security/2026/06/08/7 - https://www.openwall.com/lists/oss-security/2026/06/08/8 - https://www.openwall.com/lists/oss-security/2026/06/08/9 - https://www.openwall.com/lists/oss-security/2026/06/08/10 - https://www.openwall.com/lists/oss-security/2026/06/08/11 - https://www.openwall.com/lists/oss-security/2026/06/08/12 - https://www.openwall.com/lists/oss-security/2026/06/08/13 - https://www.openwall.com/lists/oss-security/2026/06/08/14 - https://www.openwall.com/lists/oss-security/2026/06/08/15 - https://www.openwall.com/lists/oss-security/2026/06/08/16 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/7R2KWQ6IEDZQHPWK66QN6DG4LW6X3OUM/ - https://www.cve.org/CVERecord?id=CVE-2026-29167 - https://www.cve.org/CVERecord?id=CVE-2026-29170 - https://www.cve.org/CVERecord?id=CVE-2026-34355 - https://www.cve.org/CVERecord?id=CVE-2026-34356 - https://www.cve.org/CVERecord?id=CVE-2026-42535 - https://www.cve.org/CVERecord?id=CVE-2026-42536 - https://www.cve.org/CVERecord?id=CVE-2026-43951 - https://www.cve.org/CVERecord?id=CVE-2026-44119 - https://www.cve.org/CVERecord?id=CVE-2026-44185 - https://www.cve.org/CVERecord?id=CVE-2026-44186 - https://www.cve.org/CVERecord?id=CVE-2026-44631 - https://www.cve.org/CVERecord?id=CVE-2026-48913 - https://www.cve.org/CVERecord?id=CVE-2026-49975 SRPMS: - 10/core/apache-2.4.68-1.mga10 - 9/core/apache-2.4.68-1.mga9 . Multiple security issues in Apache HTTP Server addressed with Mageia updates. Important for system integrity and service continuity.. Apache HTTP Server, Mageia Security, Update Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 23, 2026 Critical Mageia
203

Mageia dnsmasq Critical Denial of Service Vulnerabilities 2026-0288

Mageia released updates for dnsmasq to fix critical security vulnerabilities, including a heap-based buffer overflow and an out-of-bounds read, potentially enabling remote denial of service attacks.. Publication date: 23 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0288.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-12725, CVE-2026-12969 Description: The updated dnsmasq packages fix multiple security issues: A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service. (CVE-2026-12725) An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via a crafted NXDOMAIN response to cause a 10-byte heap out-of-bounds read, potentially accessing stale data from prior transactions. (CVE-2026-12969) References: - https://bugs.mageia.org/show_bug.cgi?id=35935 - https://app.opencve.io/cve/CVE-2026-12725 - https://app.opencve.io/cve/CVE-2026-12969 - https://ubuntu.com/security/notices/USN-8542-1 - https://bugzilla.redhat.com/show_bug.cgi?id=2490763 - https://bugzilla.redhat.com/show_bug.cgi?id=2491663 - https://thekelleys.org.uk/dnsmasq/CHANGELOG - https://www.cve.org/CVERecord?id=CVE-2026-12725 - https://www.cve.org/CVERecord?id=CVE-2026-12969 SRPMS: - 10/core/dnsmasq-2.93-1.mga10 - 9/core/dnsmasq-2.93-1.mga9 . A critical security advisory for Mageia addressing dnsmasq issues leading to potential denial of service attacks.. dnsmasq security, buffer overflow, denial of service, Mageia advisory. . Severity: Critical.LinuxSecurity.com Team

Calendar%202 Jul 23, 2026 Critical Mageia
203

Mageia Krita-AI-Diffusion Critical Plugin Connection Issue 2026-0062

An update for Mageia 10 addresses a connectivity issue with the plugin and upgrades it to version 1.52.1, improving functionality for downloading models.. Publication date: 23 Jul 2026 URL: https://advisories.mageia.org/MGAA-2026-0062.html Type: bugfix Affected Mageia releases: 10 Description: The plugin can't connect to server to download models. This update fixes the reported issue and updates the plugin to version 1.52.1. References: - https://bugs.mageia.org/show_bug.cgi?id=35955 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.52.1 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.52.0 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.51.1 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.51.0 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.50.0 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.49.1 SRPMS: - 10/core/krita-ai-diffusion-1.52.1-1.mga10 . Krita-AI-Diffusion update for Mageia fixes plugin issue and enhances functionality with new release version.. Krita-AI-Diffusion, Mageia security advisory, plugin update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 23, 2026 Critical Mageia
203

Mageia 10 nut Package Bug Fix Advisory for Issue 2026-0061 Released

An update for Mageia 10 corrects the nut-scanner startup issue and refreshes nut packages to the latest version, improving functionality and maintenance.. Publication date: 23 Jul 2026 URL: https://advisories.mageia.org/MGAA-2026-0061.html Type: bugfix Affected Mageia releases: 10 Description: nut-scanner failed to start. This update fixes the issue and also updates the nut packages to the latest maintained release. References: - https://bugs.mageia.org/show_bug.cgi?id=35938 SRPMS: - 10/core/nut-2.8.5-1.mga10 . A security update addresses nut issues in Mageia 10, ensuring system stability and functionality improvements.. Mageia update, nut package, security patch. . LinuxSecurity.com Team

Calendar%202 Jul 23, 2026 Mageia
203

Mageia 10 Warpinator Important Bugfix Security Update 2026-0060

An update for Mageia 10 fixes a launch issue with warpinator caused by a grpcio module version stamp mismatch, aligning it with the distro's provided version.. Publication date: 23 Jul 2026 URL: https://advisories.mageia.org/MGAA-2026-0060.html Type: bugfix Affected Mageia releases: 10 Description: warpinator uses the grpcio module, but with a stamp of the used module version. The stamp was not in accordance with the version of the provided module in the distro, preventing launch. This update fixes that. References: - https://bugs.mageia.org/show_bug.cgi?id=35891 SRPMS: - 10/core/warpinator-2.0.4-1.mga10 . This security advisory addresses an issue with warpinator in Mageia 10, ensuring it launches correctly after update.. Mageia Security Update, Warpinator Bugfix, Linux Software Advisory, Mageia Vulnerability. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 23, 2026 moderate Mageia
202

openSUSE Leap 16.0 trivy Important Privilege Escalation Vuln 2026-21395-1

openSUSE has released a security update for trivy addressing three vulnerabilities, which includes fixes for privilege escalation and credential forwarding, available for openSUSE Leap 16.0.. openSUSE security update: security update for trivy ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21395-1 Rating: important References: * bsc#1266495 * bsc#1271658 * bsc#1271670 Cross-References: * CVE-2026-39821 * CVE-2026-50151 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-50151 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed. Description: This update for trivy fixes the following issues - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266495). - CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271658). - CVE-2026-56852: trivy: infinite loop on truncated/invalid UTF-8 input (bsc#1271670). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1305=1 Package List: - openSUSE Leap 16.0: trivy-0.72.0-160000.2.1 References: * https://www.suse.com/security/cve/CVE-2026-39821.html *https://www.suse.com/security/cve/CVE-2026-50151.html * https://www.suse.com/security/cve/CVE-2026-56852.html . This OpenSUSE advisory details important updates fixing multiple issues in Trivy, improving security and functionality.. OpenSUSE, Trivy, privilege escalation, credential forwarding, security update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 23, 2026 Important OpenSUSE
219

Rocky Linux cifs-utils Important RLSA-2026-39575 Local Privilege Escalation

An important update for cifs-utils on Rocky Linux 8 addresses security vulnerabilities, including a local privilege escalation issue, while also providing bug fixes and enhancements.. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:39575", "synopsis": "Important: cifs-utils security, bug fix, and enhancement update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for cifs-utils.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The SMB/CIFS protocol is a standard file sharing protocol widely deployed on Microsoft Windows machines. The cifs-utils packages contain tools for mounting shares on Linux using the SMB/CIFS protocol. The tools in this package work in conjunction with support in the kernel to allow one to mount a SMB/CIFS share onto a client and use it as if it were a standard Linux file system.\n\nSecurity Fix(es):\n\n* cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall (CVE-2026-12505)\n\nBug Fix(es) and Enhancement(s):\n\n* add sssd method for mapping SID to UID/GID in man page of mount.cifs [rhel-8.10.z] (JIRA:Rocky Linux-41059)\n\n* Update the mount.cifs man page to match the 3*echo_interval reconnection timeout (JIRA:Rocky Linux-80397)\n\n* cifs-utils: regression with kerberos mount [rhel-8.10.z] (JIRA:Rocky Linux-192933)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2489805", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2489805", "description": ""}], "cves": [{"name": "CVE-2026-12505", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-12505", "cvss3ScoringVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-250"}], "references": [], "publishedAt": "2026-07-23T12:00:46.971123Z", "rpms": {"Rocky Linux 8": {"nvras": ["cifs-utils-0:7.0-5.el8_10.aarch64.rpm", "cifs-utils-0:7.0-5.el8_10.src.rpm", "cifs-utils-0:7.0-5.el8_10.x86_64.rpm", "cifs-utils-debuginfo-0:7.0-5.el8_10.aarch64.rpm", "cifs-utils-debuginfo-0:7.0-5.el8_10.x86_64.rpm", "cifs-utils-debugsource-0:7.0-5.el8_10.aarch64.rpm", "cifs-utils-debugsource-0:7.0-5.el8_10.i686.rpm", "cifs-utils-debugsource-0:7.0-5.el8_10.x86_64.rpm", "cifs-utils-devel-0:7.0-5.el8_10.aarch64.rpm", "cifs-utils-devel-0:7.0-5.el8_10.i686.rpm", "cifs-utils-devel-0:7.0-5.el8_10.x86_64.rpm", "pam_cifscreds-0:7.0-5.el8_10.aarch64.rpm", "pam_cifscreds-0:7.0-5.el8_10.x86_64.rpm", "pam_cifscreds-debuginfo-0:7.0-5.el8_10.aarch64.rpm", "pam_cifscreds-debuginfo-0:7.0-5.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. An important update for cifs-utils addresses a local privilege escalation security issue and enhances functionality on Rocky Linux.. Rocky Linux Cifs-Utils Security Update Privilege Escalation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 23, 2026 Important Rocky Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":2,"type":"x","order":2,"pct":66.67,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200