Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Evolution Data Server could be made to remove files.

Linux IDS vs IPS: Operational Differences and Deployment Tradeoffs

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 68 vulnerabilities, contains one feature and has 10 security fixes can now be installed.

An update that solves 68 vulnerabilities, contains one feature and has 10 security fixes can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

Several security issues were fixed in rsync.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the kernel.

An update that solves six vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

SUSE Linux 15 SP7 Kernel RT Important Live Patch 13 Local Root Exploit
An update that solves three vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

Several vulnerabilities have been found in aiohttp, an asynchronous HTTP client/server framework for asyncio and Python. CVE-2025-53643 Request smuggling vulnerability due to not parsing trailer sections of an HTTP request.

Update to 1.5.4. Fixes a buffer overflow caused by integer promotion rules in OFBMPImageFormatHandler and OFQOIImageFormatHandler. Update to 1.5.3

Update to 1.5.4. Fixes a buffer overflow caused by integer promotion rules in OFBMPImageFormatHandler and OFQOIImageFormatHandler. Update to 1.5.3

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 148.0.7778.215-1~deb12u1.

https://security-tracker.debian.org/tracker/DSA-6317-1

https://security-tracker.debian.org/tracker/DSA-6318-1

10 essential reads to optimize performance, security, and ROI in the AI era
7 features of Red Hat Identity Management you need to know for the modern enterprise
Advancing post-quantum capabilities of SSH in Red Hat Enterprise Linux

https://security-tracker.debian.org/tracker/DSA-6312-1

https://security-tracker.debian.org/tracker/DSA-6313-1

https://security-tracker.debian.org/tracker/DSA-6314-1

https://security-tracker.debian.org/tracker/DSA-6315-1

https://security-tracker.debian.org/tracker/DSA-6308-1

https://security-tracker.debian.org/tracker/DSA-6307-1

An update that solves 6 vulnerabilities can now be installed.

How To Understand Failed Authentication Patterns in Linux Logs
How to Respond After Detecting a Compromised Linux Server

https://security-tracker.debian.org/tracker/DSA-6309-1

https://security-tracker.debian.org/tracker/DSA-6310-1

https://security-tracker.debian.org/tracker/DSA-6311-1

https://security-tracker.debian.org/tracker/DSA-6304-1

https://security-tracker.debian.org/tracker/DSA-6303-1

https://security-tracker.debian.org/tracker/DSA-6302-1

https://security-tracker.debian.org/tracker/DSA-6301-1

SSH Key Sprawl on Linux Unmanaged Access Threats and Cleanup Guide
How to Diagnose Suspicious Outbound Connections on Linux Servers 

https://security-tracker.debian.org/tracker/DSA-6305-1

https://security-tracker.debian.org/tracker/DSA-6306-1

https://security-tracker.debian.org/tracker/DSA-6300-1

https://security-tracker.debian.org/tracker/DSA-6299-1

https://security-tracker.debian.org/tracker/DSA-6298-1

Several security issues were fixed in Samba.

Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix, which might result in bypass of access checks, overwrite of files in unintended situations using the WORM vfs module, installing CA certificates over http without verification when auto-enrollment GPO is enabled, denial of service or remote code

Context-aware advisor recommendations in Red Hat Lightspeed
Building the levee: Why Red Hat’s post-quantum strategy is already in production
LinuxSecurity.com Major Update for Improved Threat Discovery and Research

Dnsmasq could be made to crash or run programs if it received specially crafted network traffic.

libssh2 could be made to crash if it received specially crafted network traffic.

Multiple vulnerabilities were discovered in SPIP, a website engine for publishing, which may result in remote code execution or an open redirect. For the stable distribution (trixie), these problems have been fixed in version 4.4.15+dfsg-0+deb13u1.

GitHub Actions Compromise CI/CD Supply Chain Risks Explored
VPN Strategies for Linux Developers Managing Mobile Security Risks

Several security issues were fixed in the Linux kernel.

SimpleEval could be made to run programs if it received specially crafted input.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in Rclone.

ngtcp2 could be made to run programs as your login if it received specially crafted network traffic when qlog was enabled.

An update that solves one vulnerability can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 23 vulnerabilities can now be installed.

An update that solves 6 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 13 vulnerabilities and has 13 bug fixes can now be installed.

An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed.

An update that solves one vulnerability and has 4 bug fixes can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

An update that solves 5 vulnerabilities and has 5 bug fixes can now be installed.

An update that solves 6 vulnerabilities and has 6 bug fixes can now be installed.

An update that solves 20 vulnerabilities and has one bug fix can now be installed.