LinuxSecurity.com

Syndikovat obsah
The central voice for Linux and Open Source security news.
Aktualizace: 43 min 1 sek zpět

OpenOffice Vulnerability Can Run Code From Malicious Documents

6 Říjen, 2026 - 04:45
Apache is asking OpenOffice users to turn off its Java integration after warning that a malicious document could run code on their computer.
Kategorie: Hacking & Security

OpenOffice Vulnerability Can Run Code From Malicious Documents

6 Říjen, 2026 - 04:45
Apache is asking OpenOffice users to turn off its Java integration after warning that a malicious document could run code on their computer.
Kategorie: Hacking & Security

Apache Thrift 0.25.0 Adds Memory Limits for Network Messages

6 Říjen, 2026 - 04:40
Apache released Thrift 0.25.0 on Sep 30, 2026 with memory checks for several C++, Java, and Python components.
Kategorie: Hacking & Security

Apache Directory LDAP API 2.1.9 Security Update for CVE-2026-103877

6 Říjen, 2026 - 04:30
Apache’s release notice on Oct 3, 2026 lists six Apache Directory LDAP API vulnerabilities.
Kategorie: Hacking & Security

OpenSSL Vulnerability Can Leak Server Memory Through DTLS

6 Říjen, 2026 - 04:20
OpenSSL issued fixes on Sep 29, 2026 for an OpenSSL vulnerability that can send unrelated program memory to another party during secure connection setup.
Kategorie: Hacking & Security

LiteLLM Key Reuse Lets Internal Users Forge Admin Tokens

3 Říjen, 2026 - 01:45
LiteLLM has patched a privilege-escalation flaw that can let an authenticated internal user forge an administrative session and reach command-execution features in some AI gateway deployments.
Kategorie: Hacking & Security

Apache HTTP Server Vulnerability Update Fixes Code Execution and Memory Flaws

3 Říjen, 2026 - 01:30
Apache released HTTP Server 2.4.69 on October 1, 2026, to fix security faults ranging from unwanted code execution to mishandled web responses.
Kategorie: Hacking & Security

Apache APISIX Vulnerabilities Let Attackers Impersonate Users and Bypass Protected Routes

3 Říjen, 2026 - 01:15
Apache detailed two Apache APISIX vulnerabilities in notices issued on October 1, 2026.
Kategorie: Hacking & Security

Apache APISIX Denial of Service Flaw Can Disrupt Web Traffic

3 Říjen, 2026 - 01:00
Apache disclosed CVE-2026-94250 on October 1, 2026, warning that public access to a batch-request endpoint can let an attacker exhaust a gateway worker's memory.
Kategorie: Hacking & Security

Apache Camel Vulnerability Can Expose Files and Internal Services

3 Říjen, 2026 - 00:45
Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal services.
Kategorie: Hacking & Security

Proposed Linux IPsec Fix Addresses IP-TFS Packet Cleanup Race

2 Říjen, 2026 - 02:00
Linux developers have proposed an IPsec fix after reproducing a memory error in IP-TFS, a mode that groups and pads encrypted traffic to make traffic patterns harder to infer.
Kategorie: Hacking & Security

Proposed Linux FastRPC Fix Addresses Shared-Buffer Cleanup Race

2 Říjen, 2026 - 01:45
Linux developers have proposed a FastRPC fix for a race that can leave the kernel using memory after it has been released.
Kategorie: Hacking & Security

Proposed Linux QNX6 Fixes Address Filesystem Memory Errors

2 Říjen, 2026 - 01:35
Linux developers have proposed six fixes for the driver that reads QNX6 filesystems, a disk format associated with the QNX operating system.
Kategorie: Hacking & Security

LightLLM Profiling Flaw Allows Code Execution Without a Login

2 Říjen, 2026 - 01:20
LightLLM, software used to serve AI models, can expose Linux AI servers to remote code execution when operators enable its profiling mode, a tool for measuring performance.
Kategorie: Hacking & Security

ModSecurity Updates Fix WAF Bypasses on Linux Web Servers

2 Říjen, 2026 - 00:35
ModSecurity has released fixes for a group of web application firewall (WAF) weaknesses that can let dangerous input reach Linux-hosted applications without being inspected as intended.
Kategorie: Hacking & Security

Linux Device Driver Fix Prevents Clock Lookups From Reading Freed Memory

1 Říjen, 2026 - 03:15
A Linux device driver fix closes a use-after-free risk in the AC100 real-time clock (RTC) driver.
Kategorie: Hacking & Security

Flatpak Vulnerability Fixes Protect Linux Host Files and Processes

1 Říjen, 2026 - 03:15
Flatpak 1.18.4 fixes three vulnerabilities that could let a malicious sandboxed app affect files or processes on its Linux host.
Kategorie: Hacking & Security

Linux Storage Fix Stops Cleanup From Freeing the Same Object Twice

1 Říjen, 2026 - 03:00
A Linux flash-storage fix prevents a double free, in which the kernel releases the same object twice during device setup.
Kategorie: Hacking & Security

Apache Karaf Flaws Can Let Limited Users Run Commands or Rewrite Files

1 Říjen, 2026 - 02:45
Apache released Karaf 4.4.12 on September 27, 2026, to fix three authorization flaws in its Java server runtime.
Kategorie: Hacking & Security

Command Injection Flaw in shell-quote Can Execute Linux Commands

1 Říjen, 2026 - 01:00
The maintainers of shell-quote, a JavaScript library for building shell commands, released version 1.11.0 on September 29, 2026, to fix CVE-2026-102422.
Kategorie: Hacking & Security