Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 531
Alerts This Week
Warning Icon 1 531

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 9,991 articles for you...
203

Mageia 10 9 perl-String-Util Critical Regex DoS CVE-2026-14895

Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0272.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-14895 Description: The updated package fixes a security vulnerability: String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. (CVE-2026-14895) References: - https://bugs.mageia.org/show_bug.cgi?id=35858 - https://www.openwall.com/lists/oss-security/2026/07/07/18 - https://www.cve.org/CVERecord?id=CVE-2026-14895 SRPMS: - 10/core/perl-String-Util-1.350.0-2.1.mga10 - 9/core/perl-String-Util-1.340.0-1.1.mga9 . This update addresses a critical denial of service flaw in Perl String::Util affecting Mageia 10 and 9. Discover more.. Mageia, Perl, Denial of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 19, 2026 Critical Mageia
203

Mageia 10 Clamav Moderate Memory Corruption Issues Advisory 2026-0271

Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0271.html Type: security Affected Mageia releases: 10 CVE: CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244 Description: The updated packages fix security vulnerabilities: PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20213) FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20214) 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20215) InstallShield File Format Processing Resource Exhaustion Vulnerability. (CVE-2026-20216) PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20217) ALZ Archive Processing Denial of Service Vulnerability. (CVE-2026-20243) DMG File Processing Denial of Service Vulnerability. (CVE-2026-20244) References: - https://bugs.mageia.org/show_bug.cgi?id=35841 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/N4HZVOZRQX4MIQVALYKDCGBZUHHVH4QN/ - https://github.com/Cisco-Talos/clamav/releases/tag/clamav-1.4.5 - https://www.cve.org/CVERecord?id=CVE-2026-20213 - https://www.cve.org/CVERecord?id=CVE-2026-20214 - https://www.cve.org/CVERecord?id=CVE-2026-20215 - https://www.cve.org/CVERecord?id=CVE-2026-20216 - https://www.cve.org/CVERecord?id=CVE-2026-20217 - https://www.cve.org/CVERecord?id=CVE-2026-20243 - https://www.cve.org/CVERecord?id=CVE-2026-20244 SRPMS: - 10/core/clamav-1.4.5-1.mga10 . Mageia security update addresses multiple Out-of-Bounds Memory Corruption and Denial of Service issues in clamav.. Mageia update, clamav security, memory corruption issue, denial of service, security fix. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 19, 2026 moderate Mageia
203

Mageia 10 Erlang Important SFTP Info Leak Vuln 2026-0270

Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0270.html Type: security Affected Mageia releases: 10 CVE: CVE-2026-48855 Description: The updated packages fix a security vulnerability: SFTP READLINK response leaks absolute backend filesystem path when root is configured. (CVE-2026-48855) References: - https://bugs.mageia.org/show_bug.cgi?id=35839 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/O2CL6CSAYWT3KK6GLRNIWD7YDNMWHJ4N/ - https://github.com/erlang/otp/security/advisories/GHSA-pv7g-pjrq-x2fh - https://cna.erlef.org/cves/CVE-2026-48855.html - https://osv.dev/vulnerability/EEF-CVE-2026-48855 - https://www.cve.org/CVERecord?id=CVE-2026-48855 SRPMS: - 10/core/erlang-27.3.4.13-1.mga10 . Critical update for Mageia addressing sensitive SFTP leak issues in Erlang packages. Immediate action recommended to secure systems.. Mageia security advisory, erlang update, SFTP exploit, information leak. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 19, 2026 Important Mageia
203

Mageia 10 perl-Mojolicious Critical Memory Exhaustion Fix CVE-2026-14803

Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0269.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-14803 Description: The updated package fixes a security vulnerability: Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. (CVE-2026-14803) References: - https://bugs.mageia.org/show_bug.cgi?id=35835 - https://www.openwall.com/lists/oss-security/2026/07/06/2 - https://metacpan.org/release/SRI/Mojolicious-9.47/changes - https://www.cve.org/CVERecord?id=CVE-2026-14803 SRPMS: - 10/core/perl-Mojolicious-9.420.0-1.1.mga10 - 9/core/perl-Mojolicious-9.310.0-1.1.mga9 . Update for Mageia addresses critical memory exhaustion flaw in perl-Mojolicious, improving overall system safety.. Mageia security update, memory exhaustion, perl-Mojolicious, CVE-2026-14803, security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 19, 2026 Critical Mageia
203

Mageia 10 nmap Important Integer Underflow Fix CVE-2026-58058

Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0268.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-58058 Description: The updated packages fix a security vulnerability: Integer Underflow in IPv6 Extension Header Parsing. (CVE-2026-58058) References: - https://bugs.mageia.org/show_bug.cgi?id=35812 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/MIIROUN7QWWO22LUS5B4KPZ4DNYFQYJZ/ - https://github.com/bikini/exploitarium/tree/main/nmap-ipv6-extlen-wrap-poc - https://www.cve.org/CVERecord?id=CVE-2026-58058 SRPMS: - 10/core/nmap-7.98-1.1.mga10 - 9/core/nmap-7.95-1.1.mga9 . Mageia security update 2026-0268 for nmap addresses critical integer underflow issues. Immediate update recommended.. mageia nmap integer underflow security update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 19, 2026 Important Mageia
203

Mageia 10 Perl CSS Minifier XS Critical Memory Leak CVE-2026-13593

Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0267.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-13593 Description: The updated package fixes a security vulnerability: CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. (CVE-2026-13593) References: - https://bugs.mageia.org/show_bug.cgi?id=35781 - https://www.openwall.com/lists/oss-security/2026/06/29/18 - https://lists.opensuse.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/3PEXBYM5REIQMMQ2BZA2J2AXW7M4U673/ - https://www.cve.org/CVERecord?id=CVE-2026-13593 SRPMS: - 10/core/perl-CSS-Minifier-XS-0.150.0-1.mga10 - 9/core/perl-CSS-Minifier-XS-0.150.0-1.mga9 . Update for Mageia addressing a moderate memory leak in perl-CSS-Minifier-XS versions before 0.14, fixing CVE-2026-13593.. Mageia perl CSS Minifier XS memory leak vulnerability. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 19, 2026 moderate Mageia
203

Mageia 10 9 Important Perl Bytes Random Secure CVE-2026-11625

Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0266.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-11625 Description: The updated package fixes a security vulnerability: Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. (CVE-2026-11625) References: - https://bugs.mageia.org/show_bug.cgi?id=35767 - https://www.openwall.com/lists/oss-security/2026/06/26/5 - https://github.com/daoswald/Bytes-Random-Secure/issues/3 - https://www.cve.org/CVERecord?id=CVE-2026-11625 SRPMS: - 10/core/perl-Bytes-Random-Secure-0.290.0-7.1.mga10 - 9/core/perl-Bytes-Random-Secure-0.290.0-6.1.mga9 . The Mageia advisory details a security fix for perl-Bytes-Random-Secure to address CVE-2026-11625, ensuring process state integrity.. Mageia security update, perl-Bytes-Random-Secure fix, process security issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 19, 2026 Important Mageia
89

Fedora 44 OpenSSH Critical Remote Copy Misplacement CVE-2026-59996

CVE-2026-59996: Fix remote glob result of ".." causing files to be placed in unintended parent directories when scp performs remote-to-remote copy via the local host CVE-2026-60002: Fix use-after-free in cached hostkey during key re-exchange. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-c9d8542bb3 2026-07-19 05:46:37.002248+00:00 -------------------------------------------------------------------------------- Name : openssh Product : Fedora 44 Version : 10.2p1 Release : 13.fc44 URL : http://www.openssh.com/portable.html Summary : An open source implementation of SSH protocol version 2 Description : SSH (Secure SHell) is a program for logging into and executing commands on a remote machine. SSH is intended to replace rlogin and rsh, and to provide secure encrypted communications between two untrusted hosts over an insecure network. X11 connections and arbitrary TCP/IP ports can also be forwarded over the secure channel. OpenSSH is OpenBSD's version of the last free version of SSH, bringing it up to date in terms of security and features. This package includes the core files necessary for both the OpenSSH client and server. To make this package useful, you should also install openssh-clients, openssh-server, or both. -------------------------------------------------------------------------------- Update Information: CVE-2026-59996: Fix remote glob result of ".." causing files to be placed in unintended parent directories when scp performs remote-to-remote copy via the local host CVE-2026-60002: Fix use-after-free in cached hostkey during key re-exchange -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 17 2026 Zoltan Fridrich - 10.2p1-13 - CVE-2026-59996: Fix remote glob result of ".." causing files to be placed in unintended parent directories when scp performs remote-to-remote copy via the local host Resolves: rhbz#2498027 - CVE-2026-60002: Fix use-after-free in cached hostkey during key re-exchange Resolves: rhbz#2497966 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2497966 - CVE-2026-60002 openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2497966 [ 2 ] Bug #2498027 - CVE-2026-59996 openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2498027 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-c9d8542bb3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fedora 44 openssh updates address critical issues including remote file misplacement and use-after-free vulnerabilities. Upgrade now.. openssh update, fedora vulnerability, remote copy security, scp issue, use-after-free bug. . Severity: Critical.LinuxSecurity.com Team

Calendar%202 Jul 19, 2026 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200