Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

DSA-6514-1 php8.4 – security update
Debian 12 Redis Critical Use-After-Free and Out-of-Bounds Alerts DLA-4794-1
Slackware PHP Important Buffer Overflow and Memory Fixes SSA-2026-267-01
Linux Cgroup Namespace Race Could Expose a Freed Root Object
A cgroup namespace gives a Linux process a limited view of the control-group hierarchy that organizes workloads and accounts for resources.
Kubernetes Security Fix Blocks Cross-Namespace Pod Creation
Kubernetes released fixes on Sep 23, 2026 for a control-plane flaw that could create a pod outside the namespace where a user’s permissions applied. [...]
Linux Device Driver Race Leaves Open Files Using Freed Memory
A Linux device driver can keep an open file alive while freeing the hardware state that file still needs.
Linux Integrity Checks Could Read Freed dm-verity Policy Data
Linux integrity checks depend on more than a correct policy or a trusted hash. The kernel must also keep that security state alive for the entire decision. [...]
Linux Console Font Bug Could Read Past Its Memory Buffer
A Linux console font change could leave the framebuffer console with a buffer sized for 256 characters even after a 512-character font was installed.
Ubuntu curl USN-8820-1 Important Remote Code Exec Denial of Service
Ubuntu libass Security Notice USN-8815-1 Code Execution Denial of Service
Ubuntu GDAL Critical Code Execution Crash Threat Notice USN-8812-1
DSA-6511-1 znc – security update
Turning security complexity into useful intelligence: What’s new in Red Hat Lightspeed
In a post-Mythos world, IT teams face a mounting crisis. Many are doing more with the same staff, and security work hasn’t gotten simpler. Alerts still [...]
2026 update: The road to quantum-safe cryptography in Red Hat OpenShift
A year ago, I wrote about the road to quantum-safe cryptography in Red Hat OpenShift. At the time, much of that road was forward-looking: TLS 1.3 was not [...]
AlmaLinux 8 Python 2.7 Major SQL Injection Info Disclosure Vulnerability
AlmaLinux 8 Container-Tools Important Security Fix CVE-2019-5736
AlmaLinux 8 libyang Bug Fix Advisory ALEA-2021-1906 Moderate
AlmaLinux 8 libarchive Moderate Bug Fix Advisory ALEA-2021-1580
Mageia 10 xdg-dbus-proxy Medium Broadcast Filtering Bypass CVE-2026-93676
Mageia perl-URI Important IDNA Encoding Fix CVE-2026-19953
Mageia KBD Important Local Escalation Vulnerability CVE-2026-72693
Fedora 43 kernel 7.2.7 Important System Fix Advisory FEDORA-2026-8202400aa0
Fedora 43 Chromium Critical Race Condition Buffer Overflow Vulnerability
Fedora 43 mingw-pcre2 Important Information Disclosures – CVE-2026-89162
Fedora 44 Unbound Important Heap Buffer Overflow RCE Vuln 2026-996b326401
Fedora 44 mingw-pcre2 Critical Information Disclosure and Code Exec CVEs
SUSE Apptainer Important DoS Buffer Overflow Fix SUSE-SU-2026-4308-1
SUSE gimp Important Denial of Service and Code Execution Fix 2026-4309-1
openSUSE Kernel Important Security Update CVE-2026-46150 CVE-2026-64423
Fedora 45 libheif Security Advisory 2026-78461b38b3 Denial of Service
Fedora 45 WebKitGTK Update for Eclipse Crash Notice FEDORA-2026-c66009e517
Fedora 45 mingw-pcre2 Out-of-Bounds Disclosure and Code Execution Risk
Fedora 45 evolution-ews Update Addresses Severe JavaScript Execution Bug
Fedora 45 evolution-data-server Update Bug Fixes CVE-2026-88859
Fedora 45 Evolution Important Security Fix Advisory 2026-5debc0de2b
DSA-6512-1 libreoffice – security update
Mageia Pipewire Significant RAOP Buffer Overflow Vulnerability 2026-0443
Mageia Libwebsockets Security Update Resource Consumption CVE-2026-10650
Mageia 10 amavisd Service Vulnerability Fix for Bug 2026-0133
Ubuntu 26.04 XDG Desktop Portal Local Deletion Vulnerability USN-8287-2
Ubuntu 26.04 LTS libgit2 Important Remote Exec Vulnerability CVE-2026-5917
Rocky Linux 10 libarchive Low Heap Overflow Signed Integer Overflow Alert
Rocky Linux 10 rsyslog Important Denial of Service RLSA-2026-69541
Rocky Linux 10 RLSA-2026-69609 OpenEXR Important Heap Overflow
Rocky Linux 10 perl-DBI Important Heap Overflow Risk RLSA-2026-70753
Rocky Linux Podman Important Denial of Service Fixes RLSA-2026-70201
Rocky Linux PostgreSQL16 Important Arbitrary Code Execution RLSA-2026-70186
Rocky Linux 9 RLSA-2026-70191 Runc Important Denial of Service Fix
Rocky Linux 9 RLSA-2026-70391 Key Update for Networking Denial of Service
Rocky Linux OpenEXR Important Heap Overflow Vuln RLSA-2026-69608
Rocky Linux PostgreSQL Important Security Update RLSA-2026-69607
Rocky Linux 9 Podman Important Denial of Service Issues RLSA-2026-69961
Rocky Linux 9 Firefox Gains Key Security Patch for Privilege Escalation
Rocky Linux 8 RLSA-2026-69924 postgresql Important Arbitrary Code Execution
Debian znc Critical DoS Fix DSA-6511-1 CVE-2026-82373 CVE-2026-82374
MCP Toolbox Flaw Could Expose Google Service Tokens
A September 23 advisory describes a flaw in the Python SDK used with MCP Toolbox: a shared cache could send a Google ID token to a service it was not meant for.
Emacs Security Flaw Could Run Code From an Untrusted File
A September 22 advisory on an Emacs vulnerability says opening a crafted file could run code on the reader’s computer, even with the editor’s [...]
Linux HID Flaw Could Leak Kernel Memory Through Input Events
A newly merged Linux HID fix addresses a Wacom input-device path that could read beyond a short report and pass a value to local software.
Linux DAMON Page-Table Bug Could Corrupt Arm64 System Memory
Linux DAMON, the kernel’s Data Access Monitor, samples memory use to show which pages a workload touches.
Ubuntu 26.04 LTS NetworkManager Important Info Exposure CVE-2026-19685
Ubuntu 26.04 SQL Parsing Denial of Service Vulnerabilities USN-8808-1
Ubuntu Open-iSNS Critical Denial of Service Vulnerability USN-8807-1
GitHub Enterprise Server Flaw Could Let Attackers Run Code
A GitHub Enterprise Server security fix addresses a way to turn the appliance’s notebook viewer into a route to its own internal services.
Oracle Linux 10 Podman Important Updates CVE-2026-17106 ELSA-2026-70201
Oracle Linux 10 PostgreSQL 16 Significant Security Advisory ELSA-2026-70186
Oracle Linux 10 libarchive Low Security Advisory ELSA-2026-69553
Oracle rsyslog Important Buffer Overflow Fix ELSA-2026-69541
Oracle Linux 10 Firefox Important Vulnerability Update ELSA-2026-69461
Oracle Linux 10 Curl Important Security Flaws ELSA-2026-69125
Oracle Linux PostgreSQL 18 PostGIS Security Fix ELSA-2026-67166-0
Oracle Linux 7 389-ds-base Important Security Updates ELSA-2026-55758
Oracle Linux Firefox Important Remote Access Vulnern ELSA-2026-54248
Debian LTS DLA-4791-1 memcached Buffer Overflow and Timing Attacks
Mageia perl-Dancer2 Vulnerable Session IDs Detected CVE-2026-13577
Mageia 10 9 Security Update PKCE Weak Random Number Issue CVE-2026-16615
Mageia 10 9 Important GNU cpio Path Traversal Memory Issues 2026-0435
Mageia diffutils Critical Heap Overflow Vulnern 2026-0434
Mageia Twinkle Bugfix Advisory for the Year 2026 and Update 0130
Why Seccomp Must Be Rechecked After Container Restore
Seccomp limits which Linux system calls a process can make.
How Container Restore Can Reopen Privilege Escalation Paths
Privilege escalation in a container does not always begin with a new exploit.
What CRIU Restores Beyond Application Memory in Linux Containers
Linux containers can be paused, checkpointed, and rebuilt later with CRIU.
Fedora 44 Chromium Buffer Overflow Race Condition Fix 2026-f910229c11
Fedora 44 Kernel Significant Patches Upgrade 2026-ca91e91bf0
Fedora 44 dotnet10.0 Critical Multiple Threat Fixes 2026-a5c27e8727
Fedora 44 dotnet8.0 Severe Batch of CVEs Update 2026-0fa8c76e88
Fedora 44 dotnet9.0 Critical SDK Updates CVE-2026-58649, CVE-2026-69304
Fedora 44 FreeIPMI Important Updates for CVE-2026-33554 2026-febfd10293
Fedora 44 perl-Net-DNS 1.57 Denial of Service Fix Advisory 2026-57f107ed83
Fedora 44 postgresql16-anonymizer Major Arbitrary Execution CVE-2026-19633
Fedora cyrus-imapd Security Advisory CVE-2026-47087 CVE-2026-47088
Why Container Security Needs a Separate Restore Boundary
A container normally starts under the security rules of the system receiving it.
Fedora 43 dotnet 8.0.131 Critical Update CVE-2026-58649 and More
Fedora 43 dotnet10.0 Important SDK Runtime Update for CVEs 2026-04a0116777
Fedora 43 Dotnet 9.0 Update Addresses CVE-2026-58649 and More Issues
Fedora 43 perl-Net-DNS CVE-2026-81928 Denial of Service Advisory
Fedora 43 Cyrus IMAP Update Security Advisory 2026-97a7ec5786
CRI-O Restore Flaw Can Bypass Kubernetes Security Policies
Kubernetes groups one or more containers into a pod, the basic unit it deploys.
SUSE Kernel Update 2026-4284-1 Important Security Issues Addressed
SUSE Bind Important Remote Denial of Service Fix SUSE-SU-2026-4285-1
SUSE Amazon SSM Agent Important Fix Denial of Service Vuln 2026-4286-1