Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

How Linux Pentesting Improves Network Security
AI-Driven Cybersecurity Upgrades: 3 Strategic Uses
Tails 7.7 Surfaces Secure Boot Risk as 2026 Certificate Expiry Approaches
Boost Linux Security Through Clear and Readable Coding Practices

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.10.0esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.

https://security-tracker.debian.org/tracker/DSA-6230-1

Understanding Log Management and Analysis Tools for Linux Systems

Backport security patches from OpenSSL 3.5.6

CVE-2026-35385: Fix privilege escalation via scp legacy protocol when not in preserving file mode CVE-2026-35388: Add connection multiplexing confirmation for proxy-mode multiplexing sessions CVE-2026-35387: Fix incomplete application of PubkeyAcceptedAlgorithms and

Fix CVE-2026-35535

Fix CVE-2026-40192.

Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-5713, CVE-2026-6100

Update to 147.0.7727.101 Critical CVE-2026-6296: Heap buffer overflow in ANGLE Critical CVE-2026-6297: Use after free in Proxy Critical CVE-2026-6298: Heap buffer overflow in Skia Critical CVE-2026-6299: Use after free in Prerender

Integrating Red Hat Lightspeed with CrowdStrike for enhanced malware detection coverage

Several security issues were fixed in GStreamer Bad Plugins.

An update that solves 10 vulnerabilities, contains one feature and has one security fix can now be installed.

An update that solves nine vulnerabilities, contains one feature and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

https://security-tracker.debian.org/tracker/DSA-6229-1

Why Linux Logging Fails: Detection Gaps in Real-World Systems

Several security issues were fixed in league/commonmark.

Slurm could be made to send data to an arbitrary unix socket on the host.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves six vulnerabilities and has one security fix can now be installed.

An update that solves six vulnerabilities and has one security fix can now be installed.

Beyond the Sandbox: Container Escape Techniques Observed in Recent Research

PackageKit could be made to install packages as the administrator.

Several security issues were fixed in strongSwan.

Multiple security issues were discovered in cpp-httplib, a C++ cross platform HTTP/HTTPS library, which could result in denial of service. For the stable distribution (trixie), these problems have been fixed in version 0.18.7-1+deb13u1. We recommend that you upgrade your cpp-httplib packages.

Maik Schaefer discovered that a TOCTOU race condition in PackageKit (a package management service over a DBus interface) could result in local privilege escalation. For Debian 11 bullseye, this problem has been fixed in version 1.2.2-2+deb11u1.

Multiple vulnerabilities were fixed in strongSwan, an IKE/IPsec suite. CVE-2026-35328 A vulnerability in libtls related to the processing of the supported_versions extension in TLS that can result in an infinite loop.

An update that solves one vulnerability can now be installed.

Lateral Movement Detection Strategies for Linux Systems

https://security-tracker.debian.org/tracker/DSA-6224-1

https://security-tracker.debian.org/tracker/DSA-6225-1

https://security-tracker.debian.org/tracker/DSA-6226-1

https://security-tracker.debian.org/tracker/DSA-6227-1

https://security-tracker.debian.org/tracker/DSA-6228-1

https://security-tracker.debian.org/tracker/DSA-6223-1

Andrew Nesbitt discovered that .install file directives were insufficiently restricted in OPAM, a package manager for OCaml. This could result in directory traversal out of the package area. For Debian 11 bullseye, this problem has been fixed in version 2.0.8-1+deb11u1.

Yarden Porat found a heap-based buffer overwrite in MuPDF, a lightweight PDF viewer, which may result in denial of service or the execution of arbitrary code if malformed documents are opened. For Debian 11 bullseye, this problem has been fixed in version 1.17.0+ds1-2+deb11u2.

# Security update for rootlesskit Announcement ID: SUSE-SU-2026:1493-1 Release Date: 2026-04-20T15:58:01Z Rating: important References:

An update that can now be installed.

# Security update for rootlesskit Announcement ID: SUSE-SU-2026:1494-1 Release Date: 2026-04-20T15:58:21Z Rating: important References:

# Security update for containerd Announcement ID: SUSE-SU-2026:1495-1 Release Date: 2026-04-20T16:00:19Z Rating: important References:

https://security-tracker.debian.org/tracker/DSA-6221-1

https://security-tracker.debian.org/tracker/DSA-6222-1

Auditd vs eBPF: Modern Approaches to Linux System Monitoring

An update that solves one vulnerability can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

https://security-tracker.debian.org/tracker/DSA-6220-1

MCP security: Containerization and Red Hat OpenShift integration

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-6219-1

https://security-tracker.debian.org/tracker/DSA-6217-1

https://security-tracker.debian.org/tracker/DSA-6216-1

https://security-tracker.debian.org/tracker/DSA-6215-1

What is Nmap? How To Use It Effectively for Network Security
Zero Trust for Email: Implementing Advanced Protections on Linux
2027 Budget Proposal: Why CISA Funding Cuts Matter to Linux Security Teams

MGASA-2026-0101 – Updated rsync packages fix security vulnerability

Backport patch for CVE-2026-20884. Backport fixes for CVE-2026-20889 CVE-2026-21413 CVE-2026-24450 CVE-2026-24660 Update to libraw-0.21.5.

Update to version 4.0.6

Fix access/use of uninitialized memory in stb_image

Latest Monkey’s Audio Codec release. Changes: https://monkeysaudio.com/versionhistory.html .

Latest Monkey’s Audio Codec release. Changes: https://monkeysaudio.com/versionhistory.html .

https://security-tracker.debian.org/tracker/DSA-6218-1

eBPF for Runtime Threat Detection: What Linux Admins Are Actually Deploying

Several security issues were fixed in the Linux kernel.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that has one security fix can now be installed.

# Security update for smc-tools Announcement ID: SUSE-SU-2026:1422-1 Release Date: 2026-04-17T07:21:34Z Rating: moderate References:

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-6214-1

When LKML Patches Signal Exploitation Risk Before CVE Assignment

Important: vim security update

Moderate: pcs security update

Important: firefox security update

Important: nghttp2 security update

Several security issues were fixed in .NET.

An update that solves six vulnerabilities and contains one feature can now be installed.

https://security-tracker.debian.org/tracker/DSA-6211-1

https://security-tracker.debian.org/tracker/DSA-6210-1

Kubernetes Container Security Misconfigurations Leading to Threats
Top Linux Vulnerability Scanners in 2026: A Guide to Open-Source Security Tools

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.