Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 7 articles for you...
197

Debian 11: Batik Critical Server-Side Request Forgery Fix DLA-4243-1

Multiple cases of Server-Side Request Forgery have been fixed in the Batik SVG toolkit for Java. For Debian 11 bullseye, these problems have been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4243-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk July 20, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : batik Version : 1.12-4+deb11u3 CVE ID : CVE-2020-11987 CVE-2022-38398 CVE-2022-38648 CVE-2022-40146 Debian Bug : 984829 1020589 Multiple cases of Server-Side Request Forgery have been fixed in the Batik SVG toolkit for Java. For Debian 11 bullseye, these problems have been fixed in version 1.12-4+deb11u3. We recommend that you upgrade your batik packages. For the detailed security status of batik please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/batik Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Several vulnerabilities regarding Server-Side Request Forgery have been addressed in the Batik SVG library for Debian 11. It is advisable to upgrade to ensure enhanced stability.. Debian, Batik, Server-Side Request Forgery, security update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 20, 2025 Critical Debian LTS
89

Fedora 40: FEDORA-2024-129d8ca6fc High: Batik Type Confusion Issues

Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-129d8ca6fc 2024-03-07 22:24:39.963937 -------------------------------------------------------------------------------- Name : batik Product : Fedora 40 Version : 1.14 Release : 13.fc40 URL : https://xmlgraphics.apache.org/batik/ Summary : Scalable Vector Graphics for Java Description : Batik is a Java(tm) technology based toolkit for applications that want to use images in the Scalable Vector Graphics (SVG) format for various purposes, such as viewing, generation or manipulation. -------------------------------------------------------------------------------- Update Information: Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires Automatic update for lucene-9.9.2-1.fc40. bump java source/target to 1.8, fixes 2266639 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 2 2024 Jiri Vanek - 1.14-13 - Rebuilt for java-21-openjdk as system jdk * Tue Feb 27 2024 Jiri Vanek - 1.14-12 - Rebuilt for java-21-openjdk as system jdk -------------------------------------------------------------------------------- References: [ 1 ] Bug #2123726 - consoleImageViewer crashes at start https://bugzilla.redhat.com/show_bug.cgi?id=2123726 [ 2 ] Bug #2261062 - directory-maven-plugin: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261062 [ 3 ] Bug #2266639 - directory-maven-plugin fails to build with java-21-openjdk https://bugzilla.redhat.com/show_bug.cgi?id=2266639 [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: typeconfusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266934 [ 5 ] Bug #2266937 - CVE-2024-1939 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266937 [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta https://bugzilla.redhat.com/show_bug.cgi?id=2267486 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest Fedora 40 release for Batik resolves crucial type mismatch problems and fixes several glitches found in Java 21.. Fedora Security, Batik Type Confusion, Java 21 Fix. . LinuxSecurity.com Team

Calendar%202 Mar 07, 2024 Fedora
197

Debian 10 Buster DLA-3619-1 Moderate: SSRF Issues in Batik Fixed

Batik is a toolkit for applications or applets that want to use images in the Scalable Vector Graphics (SVG) format for various purposes, such as viewing, generation or manipulation. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3619-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès October 14, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : batik Version : 1.10-2+deb10u3 CVE ID : CVE-2020-11987 CVE-2022-38398 CVE-2022-38648 CVE-2022-40146 CVE-2022-44729 CVE-2022-44730 Debian Bug : 984829 1020589 Batik is a toolkit for applications or applets that want to use images in the Scalable Vector Graphics (SVG) format for various purposes, such as viewing, generation or manipulation. CVE-2020-11987 A server-side request forgery was found, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. CVE-2022-38398 A Server-Side Request Forgery (SSRF) vulnerability was found that allows an attacker to load a url thru the jar protocol. CVE-2022-38648 A Server-Side Request Forgery (SSRF) vulnerability was found that allows an attacker to fetch external resources. CVE-2022-40146 A Server-Side Request Forgery (SSRF) vulnerability was found that allows an attacker to access files using a Jar url. CVE-2022-44729 A Server-Side Request Forgery (SSRF) vulnerability was found. A malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. CVE-2022-44730 A Server-Side Request Forgery (SSRF) vulnerability was found. A malicious SVG can probe user profile /data and send it directly as parameter to a URL. For Debian 10 buster, these problems have been fixed in version 1.10-2+deb10u3. We recommend that you upgrade your batik packages. For the detailed security status of batik please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/batik Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-5072-1 tackles various remote code execution vulnerabilities in the libxml2 library. Upgrade advised for enhanced protection.. Batik Security, SSRF Exploits, Debian Advisory, Debian Security Updates. . LinuxSecurity.com Team

Calendar%202 Oct 14, 2023 Debian LTS
89

Fedora 33 Update: Batik SSRF Threat - Moderate Severity Alert

Enforce minimal build as jython is orphaned. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-33a1b73e48 2021-04-16 14:33:16.807687 --------------------------------------------------------------------------------Name : batik Product : Fedora 33 Version : 1.14 Release : 2.fc33 URL : https://xmlgraphics.apache.org/batik/ Summary : Scalable Vector Graphics for Java Description : Batik is a Java(tm) technology based toolkit for applications that want to use images in the Scalable Vector Graphics (SVG) format for various purposes, such as viewing, generation or manipulation. --------------------------------------------------------------------------------Update Information: Enforce minimal build as jython is orphaned --------------------------------------------------------------------------------ChangeLog: * Tue Mar 9 2021 Aleksandar Kurtakov - 1.14-2 - Enforce minimal build as jython is orphaned * Mon Mar 1 2021 Jie Kang - 1.14-1 - Update to latest upstream release * Tue Jan 26 2021 Fedora Release Engineering - 1.13-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1933808 - CVE-2020-11987 batik: SSRF due to improper input validation by the NodePickerPanel https://bugzilla.redhat.com/show_bug.cgi?id=1933808 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-33a1b73e48' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Notification on Fedora 33 concerning Batik updates, implementing strict build criteria and resolving unmaintained jython instances.. Batik Update, Fedora 33 Security, Java Toolkits, SVG Manipulation, Software Upgrade. . LinuxSecurity.com Team

Calendar%202 Apr 16, 2021 Fedora
89

Ubuntu 21.04: 2021-ab12cd34ef Critical: Gnome System DDoS Vulnerability

Updates to latest upstream release and fixes CVE-2020-11987. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-65ff5f10e2 2021-03-19 19:51:22.366547 --------------------------------------------------------------------------------Name : batik Product : Fedora 34 Version : 1.14 Release : 1.fc34 URL : https://xmlgraphics.apache.org/batik/ Summary : Scalable Vector Graphics for Java Description : Batik is a Java(tm) technology based toolkit for applications that want to use images in the Scalable Vector Graphics (SVG) format for various purposes, such as viewing, generation or manipulation. --------------------------------------------------------------------------------Update Information: Updates to latest upstream release and fixes CVE-2020-11987 --------------------------------------------------------------------------------ChangeLog: * Mon Mar 1 2021 Jie Kang - 1.14-1 - Update to latest upstream release --------------------------------------------------------------------------------References: [ 1 ] Bug #1918540 - batik-1.14 is available https://bugzilla.redhat.com/show_bug.cgi?id=1918540 [ 2 ] Bug #1933809 - CVE-2020-11987 batik: SSRF due to improper input validation by the NodePickerPanel [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1933809 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-65ff5f10e2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: . Fedora 34 system alert concerning batik patching CVE-2020-11987 input validation vulnerability to improve overall safety.. Fedora 34 Security Fix,Batik 1.14 Update,Input Validation Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 19, 2021 Critical Fedora
89

Fedora 32: batik Update 2020-cf8ef2f333 Critical SSRF Risk

Updates to the latest upstream release of Eclipse. See the upstream release notes for details: https://eclipseide.org/release/noteworthy/ Also contains security fixes for CVE-2019-17566 and CVE-2019-17638.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-cf8ef2f333 2020-08-31 15:48:37.485399 --------------------------------------------------------------------------------Name : batik Product : Fedora 32 Version : 1.13 Release : 1.fc32 URL : https://xmlgraphics.apache.org/batik/ Summary : Scalable Vector Graphics for Java Description : Batik is a Java(tm) technology based toolkit for applications that want to use images in the Scalable Vector Graphics (SVG) format for various purposes, such as viewing, generation or manipulation. --------------------------------------------------------------------------------Update Information: Updates to the latest upstream release of Eclipse. See the upstream release notes for details: https://eclipseide.org/release/noteworthy/ Also contains security fixes for CVE-2019-17566 and CVE-2019-17638. --------------------------------------------------------------------------------ChangeLog: * Tue Aug 18 2020 Mat Booth - 1.13-1 - Update to latest upstream release - Add requirements on full JRE for subpackages that require AWT * Mon Jul 27 2020 Fedora Release Engineering - 1.11-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Fri Jul 10 2020 Jiri Vanek - 1.11-6 - Rebuilt for JDK-11, see https://fedoraproject.org/wiki/Changes/Java11 * Mon Jun 15 2020 Fedora Release Engineering - 1.11-4 - build with --xmvn-javadoc --------------------------------------------------------------------------------References: [ 1 ] Bug #1848617 - CVE-2019-17566 batik: SSRF via "xlink:href" https://bugzilla.redhat.com/show_bug.cgi?id=1848617 [ 2 ] Bug #1864680 - CVE-2019-17638 jetty: double release of resource can lead toinformation disclosure https://bugzilla.redhat.com/show_bug.cgi?id=1864680 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-cf8ef2f333' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The latest patch for Fedora 32 to batik addresses critical issues regarding SSRF and leaks of sensitive resources.. Fedora Updates, Java Toolkit, Batik Security, Scalable Vector Graphics. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 31, 2020 Critical Fedora
89

Fedora 27: 2018-79792e0c64 Critical: Batik Information Disclosure

Security fix for CVE-2018-8013. Updated to upstream release 1.10.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-79792e0c64 2018-06-09 19:45:50.208252 --------------------------------------------------------------------------------Name : batik Product : Fedora 27 Version : 1.10 Release : 1.fc27 URL : https://xmlgraphics.apache.org/batik/ Summary : Scalable Vector Graphics for Java Description : Batik is a Java(tm) technology based toolkit for applications that want to use images in the Scalable Vector Graphics (SVG) format for various purposes, such as viewing, generation or manipulation. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2018-8013. Updated to upstream release 1.10. --------------------------------------------------------------------------------ChangeLog: * Mon May 28 2018 Michael Simacek - 1.10-1 - Update to upstream version 1.10 - Use Recommends for jai-imageio-core (needed for TIFF support) * Wed Apr 25 2018 Mat Booth - 1.9-7 - Generate correct OSGi metadata * Wed Feb 7 2018 Fedora Release Engineering - 1.9-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1581725 - CVE-2018-8013 batik: information disclosure when deserializing https://bugzilla.redhat.com/show_bug.cgi?id=1581725 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-79792e0c64' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/WW6NISJ6YG4UTRTFNLZCGSBMON3QGQJW/ . Fedora 28 batik security patch resolves CVE-2018-8021 and updates to version 1.12 to counter information leakage vulnerabilities.. Fedora Batik Update, Security Patch, Information Disclosure Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 09, 2018 Critical Fedora
87

Debian DSA-4215-1 Critical: Batik Denial of Service and XSS Risks

Man Yue Mo, Lars Krapf and Pierre Ernst discovered that Batik, a toolkit for processing SVG images, did not properly validate its input. This would allow an attacker to cause a denial-of-service, mount cross-site scripting attacks, or access restricted files on the . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4215-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Sebastien Delafond June 02, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : batik CVE ID : CVE-2017-5662 CVE-2018-8013 Debian Bug : 860566 899374 Man Yue Mo, Lars Krapf and Pierre Ernst discovered that Batik, a toolkit for processing SVG images, did not properly validate its input. This would allow an attacker to cause a denial-of-service, mount cross-site scripting attacks, or access restricted files on the server. For the oldstable distribution (jessie), these problems have been fixed in version 1.7+dfsg-5+deb8u1. For the stable distribution (stretch), these problems have been fixed in version 1.8-4+deb9u1. We recommend that you upgrade your batik packages. For the detailed security status of batik please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/batik Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Ubuntu Security Notice USN-4542-1 reveals critical vulnerabilities in libxml2, prompting users to update for better defense.. Batik Security Update, Debian DSA, Input Validation Flaw. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 02, 2018 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200