Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Are host-based firewalls still worth using?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/158-are-host-based-firewalls-still-worth-using?task=poll.vote&format=json
158
radio
0
[{"id":510,"title":"Yes \u2014 every server needs one.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":511,"title":"No \u2014 perimeter and cloud security are enough.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":512,"title":"Only Internet-facing systems really benefit.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":513,"title":"iptables.conf is my security policy.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 9,991 articles for you...
203

Mageia SQLite Moderate NULL Pointer Denial of Service 2026-0305

Mageia reports two vulnerabilities in SQLite affecting versions 10 and 9, allowing denial of service and potential sensitive information disclosure due to NULL pointer dereference and malicious changeset handling.. Publication date: 28 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0305.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-50812, CVE-2026-50813 Description: CVE-2026-50812: A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer. CVE-2026-50813: An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path. References: - https://bugs.mageia.org/show_bug.cgi?id=35988 - https://www.cve.org/CVERecord?id=CVE-2026-50812 - https://www.cve.org/CVERecord?id=CVE-2026-50813 - https://www.cve.org/CVERecord?id=CVE-2026-50812 - https://www.cve.org/CVERecord?id=CVE-2026-50813 SRPMS: - 10/core/sqlite3-3.51.3-1.2.mga10 - 9/core/sqlite3-3.40.1-1.10.mga9 . Mageia security update addresses NULL pointer issue and data leak risks in SQLite, enhancing system protection. Learn more.. SQLite Security, Mageia Advisory, Denial of Service, Local Attacker Risks, Session Extension. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 28, 2026 Important Mageia
203

Mageia 10 Memcached Security Update Advisory ID 2026-0304

Mageia has released security updates for versions 10 and 9, addressing bugs and vulnerabilities in the memcached package with the new version 1.6.45.. Publication date: 28 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0304.html Type: security Affected Mageia releases: 10, 9 Description: The updated packages fix bugs including security ones. References: - https://bugs.mageia.org/show_bug.cgi?id=35811 - https://github.com/memcached/memcached/wiki/ReleaseNotes1643 - https://github.com/memcached/memcached/wiki/ReleaseNotes1644 - https://github.com/memcached/memcached/wiki/ReleaseNotes1645 SRPMS: - 10/core/memcached-1.6.45-1.mga10 - 9/core/memcached-1.6.45-1.mga9 . Detailed security update for Mageia addressing bugs in memcached, ensuring system integrity and performance improvements.. Mageia Memcached Security Update, Mageia System Maintenance, Memcached Bug Fixes. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Jul 28, 2026 Informational Mageia
203

Mageia 10 gscan2pdf Bugfix Advisory for Issue 2026-0073 Released

Mageia 10 addresses an issue with gscan2pdf by removing the obsolete dependency on perl-Gtk2-Ex-PodViewer, which is no longer needed due to a shift to Gtk3::SimpleList.. Publication date: 28 Jul 2026 URL: https://advisories.mageia.org/MGAA-2026-0073.html Type: bugfix Affected Mageia releases: 10 Description: perl-Gtk2-Ex-PodViewer depends on perl-Gtk2-Ex-Simple-List, but upstream gscan2pdf now explicitly depends on Gtk3::SimpleList, so this dependency seems to be indeed obsolete. Yjis update removes the dependency on perl-Gtk2-Ex-PodViewer. References: - https://bugs.mageia.org/show_bug.cgi?id=36021 SRPMS: - 10/core/gscan2pdf-2.13.5-2.1.mga10 . Important patch for gscan2pdf in Mageia 10 fixes outdated dependencies and enhances stability. Stay updated!. gscan2pdf patch, Mageia update, security fixes, Linux application, software stability. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Jul 28, 2026 Informational Mageia
89

Fedora 43 opkssh Low GQ-commitment PK Tokens Advisory 2026-168280f3c4

Fedora has released an update for opkssh version 0.16.0, fixing a security vulnerability in GQ-commitment PK Tokens, while updating dependencies and maintaining low severity due to limited exposure.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-168280f3c4 2026-07-28 01:18:17.119965+00:00 -------------------------------------------------------------------------------- Name : opkssh Product : Fedora 43 Version : 0.16.0 Release : 1.fc43 URL : https://github.com/openpubkey/opkssh Summary : OpenPubkey SSH Description : OpenPubkey SSH is a tool which enables ssh to be used with OpenID Connect allowing SSH access to be managed via identities like This email address is being protected from spambots. You need JavaScript enabled to view it. instead of long-lived SSH keys. -------------------------------------------------------------------------------- Update Information: Update to 0.16.0. This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively. -------------------------------------------------------------------------------- ChangeLog: * Sun Jul 19 2026 Till Hofmann - 0.16.0-1 - Update to 0.16.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2500487 - opkssh-0.16.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2500487 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-168280f3c4' at the command line. For more information, referto the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . A minor security fix in opkssh 0.16.0 addresses GitLab-CI GQ-commitment PK Tokens vulnerability for Fedora.. opkssh security, Fedora updates, GitLab integration, openpubkey dependency. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Jul 27, 2026 Low Fedora
89

Fedora 43 Perl-Mojolicious Important CSRF Token Fix FEDORA-2026-6f12b08313

The Fedora update for perl-Mojolicious version 9.48 addresses a security flaw related to CSRF tokens, enhancing protection against BREACH attacks by masking tokens with random values per request.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6f12b08313 2026-07-28 01:18:17.119958+00:00 -------------------------------------------------------------------------------- Name : perl-Mojolicious Product : Fedora 43 Version : 9.48 Release : 1.fc43 URL : https://metacpan.org/release/Mojolicious Summary : A next generation web framework for Perl Description : Back in the early days of the web there was this wonderful Perl library called CGI, many people only learned Perl because of it. It was simple enough to get started without knowing much about the language and powerful enough to keep you going, learning by doing was much fun. While most of the techniques used are outdated now, the idea behind it is not. Mojolicious is a new attempt at implementing this idea using state of the art technology. -------------------------------------------------------------------------------- Update Information: Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session. -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 14 2026 Emmanuel Seyman - 9.48-1 - Update to 9.48 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2500953 - CVE-2026-15747 perl-Mojolicious: Mojolicious: Information disclosure via BREACH compression oracle [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500953 -------------------------------------------------------------------------------- This update can be installed with the "dnf" updateprogram. Use su -c 'dnf upgrade --advisory FEDORA-2026-6f12b08313' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Mojolicious 9.48 improves security by masking CSRF tokens, preventing BREACH attacks and enhancing session handling.. Mojolicious security update, Fedora security advisory, CSRF token protection. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 27, 2026 Important Fedora
89

Fedora 43 RPM Heap Overflow and Command Injection Vulnerability Advisory

Fedora 43 has released an update for the RPM package management system, rebasing it to version 6.0.2, addressing security issues like heap buffer overflow and command injection.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a9f0d5370e 2026-07-28 01:18:17.119933+00:00 -------------------------------------------------------------------------------- Name : rpm Product : Fedora 43 Version : 6.0.2 Release : 1.fc43 URL : https://rpm.org/ Summary : The RPM package management system Description : The RPM Package Manager (RPM) is a powerful command line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages. Each software package consists of an archive of files along with information about the package like its version, a description, etc. -------------------------------------------------------------------------------- Update Information: Rebase to 6.0.2 (https://rpm.org/releases/6.0.2) -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 16 2026 Michal Domonkos - 6.0.2-1 - Rebase to 6.0.2 (https://rpm.org/releases/6.0.2) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2482483 - CVE-2026-44605 rpm: heap buffer overflow in NDB slot table parsing [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2482483 [ 2 ] Bug #2482484 - CVE-2026-44604 rpm: Command injection in rpmuncompress doUntar() via unescaped archive top-level directory name in popen() shell command [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2482484 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a9f0d5370e' at the command line. For more information, refer to the dnfdocumentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Critical updates for rpm in Fedora 43 resolve heap overflow and command injection issues. Get the latest fixes now.. Fedora RPM Package Management Heap Overflow Command Injection. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 27, 2026 Critical Fedora
89

Fedora 44 opkssh Low GQ-commitment PK Tokens Issue Advisory 2026-a0bf40ecfe

Fedora 44 has updated OpenPubkey SSH to version 0.16.0, which includes a security fix for GQ-commitment PK Tokens, although vulnerability risk for opkssh is low.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a0bf40ecfe 2026-07-28 01:00:27.224333+00:00 -------------------------------------------------------------------------------- Name : opkssh Product : Fedora 44 Version : 0.16.0 Release : 1.fc44 URL : https://github.com/openpubkey/opkssh Summary : OpenPubkey SSH Description : OpenPubkey SSH is a tool which enables ssh to be used with OpenID Connect allowing SSH access to be managed via identities like This email address is being protected from spambots. You need JavaScript enabled to view it. instead of long-lived SSH keys. -------------------------------------------------------------------------------- Update Information: Update to 0.16.0. This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively. -------------------------------------------------------------------------------- ChangeLog: * Sun Jul 19 2026 Till Hofmann - 0.16.0-1 - Update to 0.16.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2500487 - opkssh-0.16.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2500487 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a0bf40ecfe' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . A security advisory for Fedora 44 notifying an update for opkssh to fix GQ-commitment PK Tokens affecting GitLab.. opkssh security update GQ-commitment PK Tokens Fedora. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Jul 27, 2026 Low Fedora
89

Fedora 44 perl-Mojolicious Critical CSRF Attack Mitigation 2026-4334fd85bc

The Fedora update for perl-Mojolicious 9.48 addresses a security issue with CSRF tokens vulnerable to BREACH attacks by masking tokens with a fresh random value for each request.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-4334fd85bc 2026-07-28 01:00:27.224317+00:00 -------------------------------------------------------------------------------- Name : perl-Mojolicious Product : Fedora 44 Version : 9.48 Release : 1.fc44 URL : https://metacpan.org/release/Mojolicious Summary : A next generation web framework for Perl Description : Back in the early days of the web there was this wonderful Perl library called CGI, many people only learned Perl because of it. It was simple enough to get started without knowing much about the language and powerful enough to keep you going, learning by doing was much fun. While most of the techniques used are outdated now, the idea behind it is not. Mojolicious is a new attempt at implementing this idea using state of the art technology. -------------------------------------------------------------------------------- Update Information: Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session. -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 14 2026 Emmanuel Seyman - 9.48-1 - Update to 9.48 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2500953 - CVE-2026-15747 perl-Mojolicious: Mojolicious: Information disclosure via BREACH compression oracle [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500953 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su-c 'dnf upgrade --advisory FEDORA-2026-4334fd85bc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Mojolicious 9.48 addresses a critical CSRF token issue by masking tokens with fresh random values. Update recommended.. perl mojolicious security patch fedora csrf. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 27, 2026 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Are host-based firewalls still worth using?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/158-are-host-based-firewalls-still-worth-using?task=poll.vote&format=json
158
radio
0
[{"id":510,"title":"Yes \u2014 every server needs one.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":511,"title":"No \u2014 perimeter and cloud security are enough.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":512,"title":"Only Internet-facing systems really benefit.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":513,"title":"iptables.conf is my security policy.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200