You are here

LinuxSecurity.com

Subscribe to Feed LinuxSecurity.com
The central voice for Linux and Open Source security news.
Përditësimi: 20 orë 22 min më parë

Linux Kernel Vulnerability Fixed in Binder Device Creation

Mar, 06/10/2026 - 5:10pd
Linux developers have merged a fix for a Linux kernel vulnerability that can leave Binder device creation writing to memory the kernel has already released.

Citrix NetScaler Vulnerability Is Being Exploited: Check SAML Systems

Mar, 06/10/2026 - 5:00pd
Citrix has confirmed targeted attacks involving a Citrix NetScaler vulnerability and urged affected customers to update.

OpenOffice Vulnerability Can Run Code From Malicious Documents

Mar, 06/10/2026 - 4:45pd
Apache is asking OpenOffice users to turn off its Java integration after warning that a malicious document could run code on their computer.

Apache Thrift 0.25.0 Adds Memory Limits for Network Messages

Mar, 06/10/2026 - 4:40pd
Apache released Thrift 0.25.0 on Sep 30, 2026 with memory checks for several C++, Java, and Python components.

Apache Directory LDAP API 2.1.9 Security Update for CVE-2026-103877

Mar, 06/10/2026 - 4:30pd
Apache’s release notice on Oct 3, 2026 lists six Apache Directory LDAP API vulnerabilities.

OpenSSL Vulnerability Can Leak Server Memory Through DTLS

Mar, 06/10/2026 - 4:20pd
OpenSSL issued fixes on Sep 29, 2026 for an OpenSSL vulnerability that can send unrelated program memory to another party during secure connection setup.

LiteLLM Key Reuse Lets Internal Users Forge Admin Tokens

Sht, 03/10/2026 - 1:45pd
LiteLLM has patched a privilege-escalation flaw that can let an authenticated internal user forge an administrative session and reach command-execution features in some AI gateway deployments.

Apache HTTP Server Vulnerability Update Fixes Code Execution and Memory Flaws

Sht, 03/10/2026 - 1:30pd
Apache released HTTP Server 2.4.69 on October 1, 2026, to fix security faults ranging from unwanted code execution to mishandled web responses.

Apache APISIX Vulnerabilities Let Attackers Impersonate Users and Bypass Protected Routes

Sht, 03/10/2026 - 1:15pd
Apache detailed two Apache APISIX vulnerabilities in notices issued on October 1, 2026.

Apache APISIX Denial of Service Flaw Can Disrupt Web Traffic

Sht, 03/10/2026 - 1:00pd
Apache disclosed CVE-2026-94250 on October 1, 2026, warning that public access to a batch-request endpoint can let an attacker exhaust a gateway worker's memory.

Apache Camel Vulnerability Can Expose Files and Internal Services

Sht, 03/10/2026 - 12:45pd
Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal services.

Proposed Linux IPsec Fix Addresses IP-TFS Packet Cleanup Race

Pre, 02/10/2026 - 2:00pd
Linux developers have proposed an IPsec fix after reproducing a memory error in IP-TFS, a mode that groups and pads encrypted traffic to make traffic patterns harder to infer.

Proposed Linux FastRPC Fix Addresses Shared-Buffer Cleanup Race

Pre, 02/10/2026 - 1:45pd
Linux developers have proposed a FastRPC fix for a race that can leave the kernel using memory after it has been released.

Proposed Linux QNX6 Fixes Address Filesystem Memory Errors

Pre, 02/10/2026 - 1:35pd
Linux developers have proposed six fixes for the driver that reads QNX6 filesystems, a disk format associated with the QNX operating system.

LightLLM Profiling Flaw Allows Code Execution Without a Login

Pre, 02/10/2026 - 1:20pd
LightLLM, software used to serve AI models, can expose Linux AI servers to remote code execution when operators enable its profiling mode, a tool for measuring performance.

ModSecurity Updates Fix WAF Bypasses on Linux Web Servers

Pre, 02/10/2026 - 12:35pd
ModSecurity has released fixes for a group of web application firewall (WAF) weaknesses that can let dangerous input reach Linux-hosted applications without being inspected as intended.

Linux Device Driver Fix Prevents Clock Lookups From Reading Freed Memory

Enj, 01/10/2026 - 3:15pd
A Linux device driver fix closes a use-after-free risk in the AC100 real-time clock (RTC) driver.

Flatpak Vulnerability Fixes Protect Linux Host Files and Processes

Enj, 01/10/2026 - 3:15pd
Flatpak 1.18.4 fixes three vulnerabilities that could let a malicious sandboxed app affect files or processes on its Linux host.

Linux Storage Fix Stops Cleanup From Freeing the Same Object Twice

Enj, 01/10/2026 - 3:00pd
A Linux flash-storage fix prevents a double free, in which the kernel releases the same object twice during device setup.

Apache Karaf Flaws Can Let Limited Users Run Commands or Rewrite Files

Enj, 01/10/2026 - 2:45pd
Apache released Karaf 4.4.12 on September 27, 2026, to fix three authorization flaws in its Java server runtime.

Faqet