The central voice for Linux and Open Source security news.
Përditësimi: 1 ditë 43 min më parë
Mar, 06/10/2026 - 5:10pd
Linux developers have merged a fix for a Linux kernel vulnerability that can leave Binder device creation writing to memory the kernel has already released.
Mar, 06/10/2026 - 5:00pd
Citrix has confirmed targeted attacks involving a Citrix NetScaler vulnerability and urged affected customers to update.
Mar, 06/10/2026 - 4:45pd
Apache is asking OpenOffice users to turn off its Java integration after warning that a malicious document could run code on their computer.
Mar, 06/10/2026 - 4:40pd
Apache released Thrift 0.25.0 on Sep 30, 2026 with memory checks for several C++, Java, and Python components.
Mar, 06/10/2026 - 4:30pd
Apache’s release notice on Oct 3, 2026 lists six Apache Directory LDAP API vulnerabilities.
Mar, 06/10/2026 - 4:20pd
OpenSSL issued fixes on Sep 29, 2026 for an OpenSSL vulnerability that can send unrelated program memory to another party during secure connection setup.
Sht, 03/10/2026 - 1:45pd
LiteLLM has patched a privilege-escalation flaw that can let an authenticated internal user forge an administrative session and reach command-execution features in some AI gateway deployments.
Sht, 03/10/2026 - 1:30pd
Apache released HTTP Server 2.4.69 on October 1, 2026, to fix security faults ranging from unwanted code execution to mishandled web responses.
Sht, 03/10/2026 - 1:15pd
Apache detailed two Apache APISIX vulnerabilities in notices issued on October 1, 2026.
Sht, 03/10/2026 - 1:00pd
Apache disclosed CVE-2026-94250 on October 1, 2026, warning that public access to a batch-request endpoint can let an attacker exhaust a gateway worker's memory.
Sht, 03/10/2026 - 12:45pd
Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal services.
Pre, 02/10/2026 - 2:00pd
Linux developers have proposed an IPsec fix after reproducing a memory error in IP-TFS, a mode that groups and pads encrypted traffic to make traffic patterns harder to infer.
Pre, 02/10/2026 - 1:45pd
Linux developers have proposed a FastRPC fix for a race that can leave the kernel using memory after it has been released.
Pre, 02/10/2026 - 1:35pd
Linux developers have proposed six fixes for the driver that reads QNX6 filesystems, a disk format associated with the QNX operating system.
Pre, 02/10/2026 - 1:20pd
LightLLM, software used to serve AI models, can expose Linux AI servers to remote code execution when operators enable its profiling mode, a tool for measuring performance.
Pre, 02/10/2026 - 12:35pd
ModSecurity has released fixes for a group of web application firewall (WAF) weaknesses that can let dangerous input reach Linux-hosted applications without being inspected as intended.
Enj, 01/10/2026 - 3:15pd
A Linux device driver fix closes a use-after-free risk in the AC100 real-time clock (RTC) driver.
Enj, 01/10/2026 - 3:15pd
Flatpak 1.18.4 fixes three vulnerabilities that could let a malicious sandboxed app affect files or processes on its Linux host.
Enj, 01/10/2026 - 3:00pd
A Linux flash-storage fix prevents a double free, in which the kernel releases the same object twice during device setup.
Enj, 01/10/2026 - 2:45pd
Apache released Karaf 4.4.12 on September 27, 2026, to fix three authorization flaws in its Java server runtime.
Faqet