Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Fixes CVE-2026-53511. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6776f4e492 2026-07-14 01:23:26.838757+00:00 -------------------------------------------------------------------------------- Name : calibre Product : Fedora 43 Version : 9.11.0 Release : 1.fc43 URL : https://calibre-ebook.com/ Summary : E-book converter and library manager Description : Calibre is meant to be a complete e-library solution. It includes library management, format conversion, news feeds to ebook conversion as well as e-book reader sync features. Calibre is primarily a ebook cataloging program. It manages your ebook collection for you. It is designed around the concept of the logical book, i.e. a single entry in the database that may correspond to ebooks in several formats. It also supports conversion to and from a dozen different ebook formats. Supported input formats are: MOBI, LIT, PRC, EPUB, CHM, ODT, HTML, CBR, CBZ, RTF, TXT, PDF and LRS. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2026-53511 -------------------------------------------------------------------------------- ChangeLog: * Sun Jul 5 2026 Kevin Fenzi - 9.11.0-1 - Update to 9.11.0. Fixes rhbz#2493338 * Fri Jun 12 2026 Yaakov Selkowitz - 9.9.0-4 - Rebuilt for openssl 4.0 * Mon Jun 8 2026 František Zatloukal - 9.9.0-3 - Rebuilt for icu 78.3 * Sun Jun 7 2026 Kevin Fenzi - 9.9.0-2 - Disable test_mem_leaks for now, it is failing on x86_64 only for some reason * Sat May 30 2026 Kevin Fenzi - 9.9.0-1 - Update to 9.9.0. Fixes rhbz#2482466 * Tue May 19 2026 Michael J Gruber - 9.8.0-2 - add missing tzlocal requires * Mon May 4 2026 Kevin Fenzi - 9.8.0-1 - Update to 9.8.0. Fixes rhbz#2464288 * Thu Apr 16 2026 Jan Grulich - 9.7.0-2 - Rebuild (qt6) * Wed Apr 15 2026 Kevin Fenzi - 9.7.0-1 - Update to 9.7.0. fixesrhbz#2457244 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2498951 - CVE-2026-53511 calibre: Calibre: Arbitrary code execution via malicious e-book file processing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2498951 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6776f4e492' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fixes arbitrary code execution issue in calibre for Fedora 43 with update for CVE-2026-53511 following best practices.. Fedora update, calibre security fix, arbitrary code execution, software vulnerability, Linux application management. . Severity: Important. LinuxSecurity.com Team
Update to 9.11.0. Fixes rhbz#2493338 and CVE-2026-53511. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-79a5573be3 2026-07-14 01:00:15.022433+00:00 -------------------------------------------------------------------------------- Name : calibre Product : Fedora 44 Version : 9.11.0 Release : 1.fc44 URL : https://calibre-ebook.com/ Summary : E-book converter and library manager Description : Calibre is meant to be a complete e-library solution. It includes library management, format conversion, news feeds to ebook conversion as well as e-book reader sync features. Calibre is primarily a ebook cataloging program. It manages your ebook collection for you. It is designed around the concept of the logical book, i.e. a single entry in the database that may correspond to ebooks in several formats. It also supports conversion to and from a dozen different ebook formats. Supported input formats are: MOBI, LIT, PRC, EPUB, CHM, ODT, HTML, CBR, CBZ, RTF, TXT, PDF and LRS. -------------------------------------------------------------------------------- Update Information: Update to 9.11.0. Fixes rhbz#2493338 and CVE-2026-53511 -------------------------------------------------------------------------------- ChangeLog: * Sun Jul 5 2026 Kevin Fenzi - 9.11.0-1 - Update to 9.11.0. Fixes rhbz#2493338 * Fri Jun 12 2026 Yaakov Selkowitz - 9.9.0-4 - Rebuilt for openssl 4.0 * Mon Jun 8 2026 František Zatloukal - 9.9.0-3 - Rebuilt for icu 78.3 * Sun Jun 7 2026 Kevin Fenzi - 9.9.0-2 - Disable test_mem_leaks for now, it is failing on x86_64 only for some reason * Sat May 30 2026 Kevin Fenzi - 9.9.0-1 - Update to 9.9.0. Fixes rhbz#2482466 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2498951 - CVE-2026-53511 calibre: Calibre: Arbitrary code execution via malicious e-book file processing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2498951 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-79a5573be3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . An important update for Fedora 44 calibre addresses a critical code execution risk through malicious e-book files. Stay secure!. Fedora 44, Calibre, Code Execution, Software Update, Security Advisory. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # calibre-9.10.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:11130-1 Rating: moderate Cross-References: * CVE-2026-53511 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the calibre-9.10.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * calibre 9.10.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53511.html . OpenSUSE Tumbleweed has released a security advisory for calibre 9.10.0-1.1 addressing a moderate severity issue.. OpenSUSE,Tumbleweed,calibre,security advisory,moderate severity. . Severity: moderate. LinuxSecurity.com Team
Multiple vulnerabilities have been discovered in calibre, an e-book manager CVE-2025-64486 calibre does not validate filenames when handling binary assets in FB2 files, allowing an attacker to write arbitrary files on the. Debian LTS Advisory DLA-4554-1
Update to 9.6.0. Fixes rhbz#2452087. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-7de23151cd 2026-04-25 01:21:36.171214+00:00 -------------------------------------------------------------------------------- Name : calibre Product : Fedora 44 Version : 9.6.0 Release : 1.fc44 URL : https://calibre-ebook.com/ Summary : E-book converter and library manager Description : Calibre is meant to be a complete e-library solution. It includes library management, format conversion, news feeds to ebook conversion as well as e-book reader sync features. Calibre is primarily a ebook cataloging program. It manages your ebook collection for you. It is designed around the concept of the logical book, i.e. a single entry in the database that may correspond to ebooks in several formats. It also supports conversion to and from a dozen different ebook formats. Supported input formats are: MOBI, LIT, PRC, EPUB, CHM, ODT, HTML, CBR, CBZ, RTF, TXT, PDF and LRS. -------------------------------------------------------------------------------- Update Information: Update to 9.6.0. Fixes rhbz#2452087 -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 29 2026 Kevin Fenzi - 9.6.0-1 - Update to 9.6.0. Fixes rhbz#2452087 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452087 - calibre-9.6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2452087 [ 2 ] Bug #2452379 - CVE-2026-33205 calibre: server-side request forgery in ebook viewer backend [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452379 [ 3 ] Bug #2452380 - CVE-2026-33206 calibre: path traversal allows reading arbitrary files when converting a text-based file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452380 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-7de23151cd' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 9.6.0. Fixes rhbz#2452087. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9cc418c23e 2026-04-07 00:49:46.037802+00:00 -------------------------------------------------------------------------------- Name : calibre Product : Fedora 43 Version : 9.6.0 Release : 1.fc43 URL : https://calibre-ebook.com/ Summary : E-book converter and library manager Description : Calibre is meant to be a complete e-library solution. It includes library management, format conversion, news feeds to ebook conversion as well as e-book reader sync features. Calibre is primarily a ebook cataloging program. It manages your ebook collection for you. It is designed around the concept of the logical book, i.e. a single entry in the database that may correspond to ebooks in several formats. It also supports conversion to and from a dozen different ebook formats. Supported input formats are: MOBI, LIT, PRC, EPUB, CHM, ODT, HTML, CBR, CBZ, RTF, TXT, PDF and LRS. -------------------------------------------------------------------------------- Update Information: Update to 9.6.0. Fixes rhbz#2452087 -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 29 2026 Kevin Fenzi - 9.6.0-1 - Update to 9.6.0. Fixes rhbz#2452087 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452087 - calibre-9.6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2452087 [ 2 ] Bug #2452379 - CVE-2026-33205 calibre: server-side request forgery in ebook viewer backend [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452379 [ 3 ] Bug #2452380 - CVE-2026-33206 calibre: path traversal allows reading arbitrary files when converting a text-based file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452380 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9cc418c23e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 8.14.0. Fixes rhbz#2413304. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-355be35bb1 2025-11-24 01:24:44.272905+00:00 -------------------------------------------------------------------------------- Name : calibre Product : Fedora 43 Version : 8.14.0 Release : 1.fc43 URL : https://calibre-ebook.com/ Summary : E-book converter and library manager Description : Calibre is meant to be a complete e-library solution. It includes library management, format conversion, news feeds to ebook conversion as well as e-book reader sync features. Calibre is primarily a ebook cataloging program. It manages your ebook collection for you. It is designed around the concept of the logical book, i.e. a single entry in the database that may correspond to ebooks in several formats. It also supports conversion to and from a dozen different ebook formats. Supported input formats are: MOBI, LIT, PRC, EPUB, CHM, ODT, HTML, CBR, CBZ, RTF, TXT, PDF and LRS. -------------------------------------------------------------------------------- Update Information: Update to 8.14.0. Fixes rhbz#2413304 -------------------------------------------------------------------------------- ChangeLog: * Sat Nov 15 2025 Kevin Fenzi - 8.14.0-1 - Update to 8.14.0. Fixes rhbz#2413304 * Wed Nov 5 2025 Dominik 'Rathann' Mierzejewski - 8.13.0-2 - Rebuilt for FFmpeg 8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2413304 - calibre-8.14.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2413304 [ 2 ] Bug #2414459 - CVE-2025-64486 calibre: calibre is vulnerable to arbitrary code execution when opening FB2 files [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2414459 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program.Use su -c 'dnf upgrade --advisory FEDORA-2025-355be35bb1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root. (CVE-2023-46303) Path traversal in Calibre
Get the latest Linux and open source security news straight to your inbox.