Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 44 libmicrohttpd Major Update Resolving Null Pointer Complications

Update to 1.0.5-1 Update to 1.0.4-1 Update to 1.0.3-1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-17060a5ba0 2026-04-25 01:21:36.173323+00:00 -------------------------------------------------------------------------------- Name : libmicrohttpd Product : Fedora 44 Version : 1.0.5 Release : 1.fc44 URL : http://www.gnu.org/software/libmicrohttpd/ Summary : Lightweight library for embedding a webserver in applications Description : GNU libmicrohttpd is a small C library that is supposed to make it easy to run an HTTP server as part of another application. Key features that distinguish libmicrohttpd from other projects are: * C library: fast and small * API is simple, expressive and fully reentrant * Implementation is http 1.1 compliant * HTTP server can listen on multiple ports * Support for IPv6 * Support for incremental processing of POST data * Creates binary of only 25k (for now) * Three different threading models -------------------------------------------------------------------------------- Update Information: Update to 1.0.5-1 Update to 1.0.4-1 Update to 1.0.3-1 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 16 2026 Martin Gansser - 1:1.0.5-1 - Update to 1:1.0.5 * Mon Apr 13 2026 Martin Gansser - 1:1.0.4-1 - Update to 1:1.0.4 * Thu Apr 2 2026 Martin Gansser - 1:1.0.3-1 - Update to 1:1.0.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2413882 - CVE-2025-59777 libmicrohttpd: GNU libmicrohttpd null pointer dereference [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2413882 [ 2 ] Bug #2413888 - CVE-2025-59777 libmicrohttpd: GNU libmicrohttpd null pointer dereference [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2413888 [ 3 ] Bug #2413893 - CVE-2025-62689 libmicrohttpd: GNU libmicrohttpd nullpointer dereference [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2413893 [ 4 ] Bug #2413896 - CVE-2025-62689 libmicrohttpd: GNU libmicrohttpd null pointer dereference [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2413896 [ 5 ] Bug #2454160 - libmicrohttpd-1.0.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2454160 [ 6 ] Bug #2457804 - libmicrohttpd-1.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2457804 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-17060a5ba0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Latest Fedora 44 libmicrohttpd updates address multiple critical null pointer issues to enhance application security.. libmicrohttpd updates, Fedora security, C library vulnerabilities, null pointer dereference. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 25, 2026 Critical Fedora
89

Fedora 43 libmicrohttpd Null Pointer Dereference Advisory 2026-65a08d1312

Update to 1.0.3-1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-65a08d1312 2026-04-12 15:36:52.829593+00:00 -------------------------------------------------------------------------------- Name : libmicrohttpd Product : Fedora 43 Version : 1.0.3 Release : 1.fc43 URL : http://www.gnu.org/software/libmicrohttpd/ Summary : Lightweight library for embedding a webserver in applications Description : GNU libmicrohttpd is a small C library that is supposed to make it easy to run an HTTP server as part of another application. Key features that distinguish libmicrohttpd from other projects are: * C library: fast and small * API is simple, expressive and fully reentrant * Implementation is http 1.1 compliant * HTTP server can listen on multiple ports * Support for IPv6 * Support for incremental processing of POST data * Creates binary of only 25k (for now) * Three different threading models -------------------------------------------------------------------------------- Update Information: Update to 1.0.3-1 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 2 2026 Martin Gansser - 1:1.0.3-1 - Update to 1:1.0.3 * Fri Jan 16 2026 Fedora Release Engineering - 1:1.0.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2413882 - CVE-2025-59777 libmicrohttpd: GNU libmicrohttpd null pointer dereference [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2413882 [ 2 ] Bug #2413888 - CVE-2025-59777 libmicrohttpd: GNU libmicrohttpd null pointer dereference [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2413888 [ 3 ] Bug #2413893 - CVE-2025-62689 libmicrohttpd: GNU libmicrohttpd null pointer dereference [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2413893 [ 4 ] Bug #2413896 - CVE-2025-62689 libmicrohttpd: GNU libmicrohttpd null pointer dereference [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2413896 [ 5 ] Bug #2454160 - libmicrohttpd-1.0.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2454160 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-65a08d1312' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Latest update for Fedora 43 addresses null pointer dereference in libmicrohttpd to ensure improved security and stability.. Fedora Security Update, libmicrohttpd, null pointer dereference, Fedora 43. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 12, 2026 Important Fedora
89

Fedora 42 mingw-expat Update 2.7.5 Addresses Denial of Service Issue

Update to 2.7.5.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-1cbd107c34 2026-03-30 18:41:12.319042+00:00 -------------------------------------------------------------------------------- Name : mingw-expat Product : Fedora 42 Version : 2.7.5 Release : 1.fc42 URL : http://www.libexpat.org/ Summary : MinGW Windows port of expat XML parser library Description : This is expat, the C library for parsing XML, written by James Clark. Expat is a stream oriented XML parser. This means that you register handlers with the parser prior to starting the parse. These handlers are called when the parser discovers the associated structures in the document being parsed. A start tag is an example of the kind of structures for which you may register handlers. -------------------------------------------------------------------------------- Update Information: Update to 2.7.5. -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 21 2026 Sandro Mani - 2.7.5-1 - Update to 2.7.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2447973 - CVE-2026-32777 mingw-expat: libexpat: Denial of Service via infinite loop in DTD content parsing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2447973 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1cbd107c34' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . MinGW Expat update to 2.7.5 addresses denial of service issue in Fedora 42, ensuring better XML parsing.. Fedora Update, XML Parser, mingw-expat, security update, Denial of Service. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 30, 2026 Important Fedora
89

Ubuntu 20.04 mingw-libxml Critical Memory Leak Mitigation 2026-82938471f4

Update to expat-2.7.4.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-37324381f3 2026-02-15 01:10:21.966845+00:00 -------------------------------------------------------------------------------- Name : mingw-expat Product : Fedora 43 Version : 2.7.4 Release : 1.fc43 URL : http://www.libexpat.org/ Summary : MinGW Windows port of expat XML parser library Description : This is expat, the C library for parsing XML, written by James Clark. Expat is a stream oriented XML parser. This means that you register handlers with the parser prior to starting the parse. These handlers are called when the parser discovers the associated structures in the document being parsed. A start tag is an example of the kind of structures for which you may register handlers. -------------------------------------------------------------------------------- Update Information: Update to expat-2.7.4. -------------------------------------------------------------------------------- ChangeLog: * Fri Feb 6 2026 Sandro Mani - 2.7.4-1 - Update to 2.7.4 * Fri Jan 16 2026 Fedora Release Engineering - 2.7.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2433616 - CVE-2026-24515 mingw-expat: libexpat null pointer dereference [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2433616 [ 2 ] Bug #2433618 - CVE-2026-24515 mingw-expat: libexpat null pointer dereference [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2433618 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-37324381f3' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Critical security update for Fedora 43 to fix null pointer dereference in mingw-expat library. Immediate action required.. Fedora mingw-expat security update null pointer dereference. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 15, 2026 Critical Fedora
172

Ubuntu 24.04 LTS Libwebsockets High Denial of Service Risks USN-8024-1

Several security issues were fixed in Libwebsockets.. ========================================================================== Ubuntu Security Notice USN-8024-1 February 11, 2026 libwebsockets vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in Libwebsockets. Software Description: - libwebsockets: C library for building WebSocket-based network applications Details: Raffaele Bova discovered that Libwebsockets incorrectly handled memory when the upgrade header is not valid in the WebSocket server. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-11677) Raffaele Bova discovered that Libwebsockets did not properly check the size of the destination buffer in the async-dns component. An attacker could possibly use this issue to cause applications to crash, leading to a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-11678) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libwebsockets19t64 4.3.3-1.1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS libwebsockets16 4.0.20-2ubuntu1.1 Ubuntu 20.04 LTS libwebsockets15 3.2.1-3ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8024-1 CVE-2025-11677, CVE-2025-11678 Package Information: https://launchpad.net/ubuntu/+source/libwebsockets/4.0.20-2ubuntu1.1 . Libwebsockets fixes several issues in Ubuntu affecting denial of service and potential code execution vulnerabilities.. Ubuntu Libwebsockets security patchnetwork applications. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 12, 2026 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here