Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for atril ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21152-1 Rating: important References: * bsc#1265880 Cross-References: * CVE-2026-46519 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for atril fixes the following issues: Changes in atril: - Update to version 1.28.4 (bsc#1265880 CVE-2026-46519): * Build fixes * Fix tests imported from XReader * Fix tests with AT-SPI2 > = 2.53 * Improve search system * pdf: Always use poppler_document_save to avoid data loss * Use properties for can-zoom-in and -out * libview: Allow zooming to the limits of the scale * shell: Fix Max zoom in UI - Update to version 1.28.2: * epub: Disable thumbnailing sidebar * Fix .cbr mimetype * Wayland: stop segfaults on some systems * replace deprecated gtk_menu_tool_button_new_from_stock * libview/ev-document-model.c remove one more deprecation warning * replace ev_document_model_get_dual_page with - Update to version 1.28.1: * Update CBR library to libarchive in README.md * ci: fix travis build failures caused by recent travis changes * Cleanup icons Makefile * icons: Include higher resolution icons * Updated translations. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-347=1 Package List: - openSUSE Leap 16.0: atril-1.28.4-bp160.1.1 atril-backends-1.28.4-bp160.1.1 atril-devel-1.28.4-bp160.1.1 atril-doc-1.28.4-bp160.1.1 atril-lang-1.28.4-bp160.1.1 atril-thumbnailer-1.28.4-bp160.1.1 caja-extension-atril-1.28.4-bp160.1.1 libatrildocument3-1.28.4-bp160.1.1 libatrilview3-1.28.4-bp160.1.1 typelib-1_0-AtrilDocument-1_5_0-1.28.4-bp160.1.1 typelib-1_0-AtrilView-1_5_0-1.28.4-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2026-46519.html . atril security update for openSUSE fixes a significant vulnerability and includes additional bug fixes to enhance stability.. openSUSE atril update security important patch. . Severity: Important. LinuxSecurity.com Team
It was discovered that atril, the MATE document viewer, is prone to a command injection vulnerability if a specially crafted PDF file is opened. For the stable distribution (trixie), this problem has been fixed in version 1.26.2-4+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6349-1
It was discovered that atril, a simple multi-page document viewer, is prone to a command injection vulnerability if a specially crafted PDF file is opened. For Debian 12 bookworm, this problem has been fixed in version 1.26.0-2+deb12u4.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4632-1
An update that solves one vulnerability can now be installed.. # atril-1.28.4-1.1 on GA media Announcement ID: openSUSE-SU-2026:10914-1 Rating: moderate Cross-References: * CVE-2026-46519 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the atril-1.28.4-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * atril 1.28.4-1.1 * atril-backends 1.28.4-1.1 * atril-devel 1.28.4-1.1 * atril-doc 1.28.4-1.1 * atril-lang 1.28.4-1.1 * atril-thumbnailer 1.28.4-1.1 * caja-extension-atril 1.28.4-1.1 * libatrildocument3 1.28.4-1.1 * libatrilview3 1.28.4-1.1 * typelib-1_0-AtrilDocument-1_5_0 1.28.4-1.1 * typelib-1_0-AtrilView-1_5_0 1.28.4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46519.html . # atril-1.28.4-1.1 on GA media Announcement ID: openSUSE-SU-2026:10914-1 Rating: moderate Cross-Refe. update, solves, vulnerability, installed, atril-1, media, announc. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # atril-1.28.4-1.1 on GA media Announcement ID: openSUSE-SU-2026:10914-1 Rating: moderate Cross-References: * CVE-2026-46519 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the atril-1.28.4-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * atril 1.28.4-1.1 * atril-backends 1.28.4-1.1 * atril-devel 1.28.4-1.1 * atril-doc 1.28.4-1.1 * atril-lang 1.28.4-1.1 * atril-thumbnailer 1.28.4-1.1 * caja-extension-atril 1.28.4-1.1 * libatrildocument3 1.28.4-1.1 * libatrilview3 1.28.4-1.1 * typelib-1_0-AtrilDocument-1_5_0 1.28.4-1.1 * typelib-1_0-AtrilView-1_5_0 1.28.4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46519.html . Update for atril-1.28.4-1.1 on openSUSE addresses a moderate severity security issue identified by CVE-2026-46519.. atril update, openSUSE security, CVE-2026-46519, security fix, moderate severity. . Severity: moderate. LinuxSecurity.com Team
It was discovered that atril, a simple multi-page document viewer, is prone to a command injection vulnerability if a specially crafted PDF file is opened. For Debian 11 bullseye, this problem has been fixed in version 1.24.0-1+deb11u2.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4597-1
Atril could be made to crash or run programs as your login if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-7274-1 February 18, 2025 atril vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Atril could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - atril: Official Document Viewer of the MATE Desktop Environment Details: It was discovered that Atril incorrectly handled certain PDF files. An attacker could possibly use this issue to cause a denial of service or to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2019-1010006) Andy Nguyen discovered that Atril incorrectly handled certain images. An attacker could possibly use this issue to expose sensitive information. This issue only affected Ubuntu 16.04 LTS. (CVE-2019-11459) Febin Mon Saji discovered that Atril incorrectly handled certain compressed files. A remote attacker could possibly use this issue to cause a denial of service or to execute arbitrary code. (CVE-2023-51698) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS atril 1.26.0-1ubuntu1.2 atril-common 1.26.0-1ubuntu1.2 libatrildocument3 1.26.0-1ubuntu1.2 Ubuntu 20.04 LTS atril 1.24.0-1ubuntu0.2 atril-common 1.24.0-1ubuntu0.2 libatrildocument3 1.24.0-1ubuntu0.2 Ubuntu 18.04 LTS atril 1.20.1-2ubuntu2+esm2 Available with Ubuntu Pro atril-common 1.20.1-2ubuntu2+esm2 Available with Ubuntu Pro libatrildocument3 1.20.1-2ubuntu2+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7274-1 CVE-2019-1010006, CVE-2019-11459, CVE-2023-51698 Package Information: https://launchpad.net/ubuntu/+source/atril/1.26.0-1ubuntu1.2 https://launchpad.net/ubuntu/+source/atril/1.24.0-1ubuntu0.2 . Keep up-to-date on Atril's security matters impacting Ubuntu through this advisory that outlines vulnerabilities and necessary updates.. Atril Security, Ubuntu Advisory, Software Update. . LinuxSecurity.com Team
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the filesystem to which the user opening a crafted document has access. The . MGASA-2024-0224 - Updated atril packages fix security vulnerability Publication date: 15 Jun 2024 URL: https://advisories.mageia.org/MGASA-2024-0224.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-52076 Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the filesystem to which the user opening a crafted document has access. The only limitation is that this vulnerability cannot be exploited to overwrite existing files, but that doesn't stop an attacker from achieving Remote Command Execution on the target system. (CVE-2023-52076) References: - https://bugs.mageia.org/show_bug.cgi?id=33282 - https://ubuntu.com/security/notices/USN-6808-1 - https://www.cve.org/CVERecord?id=CVE-2023-52076 SRPMS: - 9/core/atril-1.26.1-1.1.mga9 . Atril Document Viewer on Mageia receives crucial updates addressing a file write vulnerability that could potentially allow for Remote Code Execution.. Atril Document Viewer,Mageia Security,Path Traversal Fix,Remote Command Execution,Document Vulnerability. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.