Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 594
Alerts This Week
Warning Icon 1 594

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 9,991 articles for you...
203

Mageia sqlite3 Important Memory Corruption Buffer Overflow Vuln 2026-0278

Security update. Publication date: 20 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0278.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-11822, CVE-2026-11824 Description: The updated packages fix security vulnerabilities: SQLite before 3.53.2 Memory Corruption in FTS5 Extension. (CVE-2026-11822) SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate. (CVE-2026-11824) References: - https://bugs.mageia.org/show_bug.cgi?id=35740 - https://lists.opensuse.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/WSARHTYMOLWR6EKE3FP43GM4U37WSA2O/ - https://ubuntu.com/security/notices/USN-8480-1 - https://www.cve.org/CVERecord?id=CVE-2026-11822 - https://www.cve.org/CVERecord?id=CVE-2026-11824 SRPMS: - 10/core/sqlite3-3.51.3-1.1.mga10 - 9/core/sqlite3-3.40.1-1.9.mga9 . Updates for Mageia address critical issues in sqlite3, fixing memory corruption and buffer errors to enhance security.. Mageia security update sqlite3 buffer overflow memory corruption. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 20, 2026 Important Mageia
203

Mageia XMLStarlet Important XML External Entity Vuln 2026-0277

Security update. Publication date: 20 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0277.html Type: security Affected Mageia releases: 10, 9 Description: The updated package fixes a security vulnerability: XML external entity vulnerability. References: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. oraproject.org/message/KDR5XRMVBCDZ4HWDCGLKDVKGSCWACG33/ References: - https://bugs.mageia.org/show_bug.cgi?id=35671 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/KDR5XRMVBCDZ4HWDCGLKDVKGSCWACG33/ SRPMS: - 10/core/xmlstarlet-1.6.1-12.1.mga10 - 9/core/xmlstarlet-1.6.1-9.1.mga9 . The Mageia XMLStarlet update addresses a critical XML external entity vulnerability for versions 10 and 9.. Mageia XML external entity security update, xmlstarlet vulnerability, mageia advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 20, 2026 Important Mageia
203

Mageia Golang Critical Security Advisory CVE-2026-42504 CVE-2026-42507

Security update. Publication date: 20 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0276.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-42504, CVE-2026-42507, CVE-2026-27145, CVE-2026-39822, CVE-2026-42505 Description: The updated packages fix security vulnerabilities: mime: quadratic complexity in WordDecoder.DecodeHeader. (CVE-2026-42504) net/textproto: arbitrary input are included in errors without any escaping. (CVE-2026-42507) crypto/x509: split candidate hostname only once. (CVE-2026-27145) os: Root escape via symlink plus trailing slash. (CVE-2026-39822) crypto/tls: Encrypted Client Hello privacy leak. (CVE-2026-42505) References: - https://bugs.mageia.org/show_bug.cgi?id=35624 - https://www.openwall.com/lists/oss-security/2026/06/03/2 - https://www.openwall.com/lists/oss-security/2026/07/08/10 - https://lists.opensuse.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/PHOAHESABWDZPEWFOMKYQVZYR2MQH3RA/ - https://www.cve.org/CVERecord?id=CVE-2026-42504 - https://www.cve.org/CVERecord?id=CVE-2026-42507 - https://www.cve.org/CVERecord?id=CVE-2026-27145 - https://www.cve.org/CVERecord?id=CVE-2026-39822 - https://www.cve.org/CVERecord?id=CVE-2026-42505 SRPMS: - 10/core/golang-1.25.12-1.mga10 - 9/core/golang-1.25.12-1.mga9 . Critical security update for Mageia to address multiple vulnerabilities in golang with recommended patching steps.. Mageia security update, golang vulnerabilities, software patching recommendations. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 20, 2026 Critical Mageia
203

Mageia 10 Haveged Important Privilege Escalation CVE-2026-41054

Security update. Publication date: 20 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0275.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-41054 Description: The updated package fixes a security vulnerability: Privilege escalation via command socket. (CVE-2026-41054) References: - https://bugs.mageia.org/show_bug.cgi?id=35550 - https://www.openwall.com/lists/oss-security/2026/05/19/3 - https://www.cve.org/CVERecord?id=CVE-2026-41054 SRPMS: - 10/core/haveged-1.9.21-2.mga10 - 9/core/haveged-1.9.21-2.mga9 . Mageia security update addresses privilege escalation in haveged package, identified as CVE-2026-41054, for Mageia 9 and 10.. Mageia security update, privilege escalation, haveged patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 20, 2026 Important Mageia
203

Mageia PHP Critical Memory Corruption Vulnerability CVE-2026-14355

Security update. Publication date: 20 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0274.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-14355 Description: The updated php packages fix a security issue: Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD. (CVE-2026-14355) References: - https://bugs.mageia.org/show_bug.cgi?id=35807 - https://www.php.net/ChangeLog-8.php#8.2.32 - https://www.cve.org/CVERecord?id=CVE-2026-14355 SRPMS: - 9/core/php-8.2.32-1.mga9 . Critical php security update addresses memory corruption issue in Mageia 9, protecting against potential exploits.. Mageia security update, php memory corruption, OpenSSL AES-WRAP-PAD, CVE-2026-14355. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 20, 2026 Critical Mageia
203

Mageia Libssh2 Critical DoS and Buffer Overflow Vuln 2026-0273

Security update. Publication date: 20 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0273.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2025-15661, CVE-2026-7598, CVE-2026-55199, CVE-2026-55200, CVE-2026-58050, CVE-2026-58051 Description: The updated packages fix security vulnerabilities: Heap Buffer Over-read via sftp_symlink() in sftp.c. (CVE-2025-15661) libssh2 userauth.c userauth_password integer overflow. (CVE-2026-7598) Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler. (CVE-2026-55199) Out-of-Bounds Write via Unchecked packet_length in transport.c. (CVE-2026-55200) Integer Overflow in publickey Subsystem Attribute Allocation. (CVE-2026-58050) Free of Uninitialized Pointer in publickey List Cleanup. (CVE-2026-58051) References: - https://bugs.mageia.org/show_bug.cgi?id=35616 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/NRU63FODXZBBO73NFWUI32A2A36ETDQZ/ - https://www.openwall.com/lists/oss-security/2026/06/23/10 - https://www.openwall.com/lists/oss-security/2026/06/23/11 - https://lists.debian.org/debian-security-announce/2026/msg00276.html - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/ZREI4LITT4U2ZXPEEVVNALFKPLXGLAFM/ - https://lists.opensuse.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/SRBHQ76PA4ZHTWY5F4ESYPYF3G2NLGWI/ - https://ubuntu.com/security/notices/USN-8486-1 - https://ubuntu.com/security/notices/USN-8532-1 - https://www.cve.org/CVERecord?id=CVE-2025-15661 - https://www.cve.org/CVERecord?id=CVE-2026-7598 - https://www.cve.org/CVERecord?id=CVE-2026-55199 - https://www.cve.org/CVERecord?id=CVE-2026-55200 - https://www.cve.org/CVERecord?id=CVE-2026-58050 - https://www.cve.org/CVERecord?id=CVE-2026-58051 SRPMS: - 10/core/libssh2-1.11.1-2.1.mga10 - 9/core/libssh2-1.11.0-1.1.mga9 . Critical security advisory for Mageia addressing multiple vulnerabilities in libssh2 including DoS and buffer issues.. Mageia security advisory,libssh2 vulnerabilities, buffer overflow, integer overflow, DoS attack. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 20, 2026 Critical Mageia
217

Oracle 8 hplip Important Buffer Overflow Fix ELSA-2026-40894

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-40894 http://linux.oracle.com/errata/ELSA-2026-40894.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: hplip-3.18.4-14.el8_10.x86_64.rpm hplip-common-3.18.4-14.el8_10.i686.rpm hplip-common-3.18.4-14.el8_10.x86_64.rpm hplip-gui-3.18.4-14.el8_10.x86_64.rpm hplip-libs-3.18.4-14.el8_10.i686.rpm hplip-libs-3.18.4-14.el8_10.x86_64.rpm libsane-hpaio-3.18.4-14.el8_10.i686.rpm libsane-hpaio-3.18.4-14.el8_10.x86_64.rpm aarch64: hplip-3.18.4-14.el8_10.aarch64.rpm hplip-common-3.18.4-14.el8_10.aarch64.rpm hplip-gui-3.18.4-14.el8_10.aarch64.rpm hplip-libs-3.18.4-14.el8_10.aarch64.rpm libsane-hpaio-3.18.4-14.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/hplip-3.18.4-14.el8_10.src.rpm Related CVEs: CVE-2026-14544 Description of changes: [3.18.4-14] - RHEL-192009 CVE-2026-14544 hplip: Incomplete Fix for CVE-2026-8631 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 8 has updated hplip packages addressing an important security issue that could lead to data exposure.. Oracle Linux,hplip,security advisory,important fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 20, 2026 Important Oracle
217

Oracle Linux 8 Kernel Important Security Advisory ELSA-2026-39179

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-39179 http://linux.oracle.com/errata/ELSA-2026-39179.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: bpftool-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-abi-stablelists-4.18.0-553.144.1.el8_10.noarch.rpm kernel-core-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-cross-headers-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-debug-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-debug-core-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-debug-devel-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-debug-modules-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-debug-modules-extra-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-devel-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-doc-4.18.0-553.144.1.el8_10.noarch.rpm kernel-headers-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-modules-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-modules-extra-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-tools-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-tools-libs-4.18.0-553.144.1.el8_10.x86_64.rpm kernel-tools-libs-devel-4.18.0-553.144.1.el8_10.x86_64.rpm perf-4.18.0-553.144.1.el8_10.x86_64.rpm python3-perf-4.18.0-553.144.1.el8_10.x86_64.rpm aarch64: bpftool-4.18.0-553.144.1.el8_10.aarch64.rpm kernel-cross-headers-4.18.0-553.144.1.el8_10.aarch64.rpm kernel-headers-4.18.0-553.144.1.el8_10.aarch64.rpm kernel-tools-4.18.0-553.144.1.el8_10.aarch64.rpm kernel-tools-libs-4.18.0-553.144.1.el8_10.aarch64.rpm kernel-tools-libs-devel-4.18.0-553.144.1.el8_10.aarch64.rpm perf-4.18.0-553.144.1.el8_10.aarch64.rpm python3-perf-4.18.0-553.144.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/kernel-4.18.0-553.144.1.el8_10.src.rpm Related CVEs: CVE-2026-46086 CVE-2026-46116 Description of changes: [4.18.0-553.144.1] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK ModuleSigning Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64

Calendar%202 Jul 20, 2026 Important Oracle
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200