Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 6 articles for you...
89

Fedora 43 Calibre Critical Arbitrary Code Execution CVE-2026-53511

Fixes CVE-2026-53511. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6776f4e492 2026-07-14 01:23:26.838757+00:00 -------------------------------------------------------------------------------- Name : calibre Product : Fedora 43 Version : 9.11.0 Release : 1.fc43 URL : https://calibre-ebook.com/ Summary : E-book converter and library manager Description : Calibre is meant to be a complete e-library solution. It includes library management, format conversion, news feeds to ebook conversion as well as e-book reader sync features. Calibre is primarily a ebook cataloging program. It manages your ebook collection for you. It is designed around the concept of the logical book, i.e. a single entry in the database that may correspond to ebooks in several formats. It also supports conversion to and from a dozen different ebook formats. Supported input formats are: MOBI, LIT, PRC, EPUB, CHM, ODT, HTML, CBR, CBZ, RTF, TXT, PDF and LRS. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2026-53511 -------------------------------------------------------------------------------- ChangeLog: * Sun Jul 5 2026 Kevin Fenzi - 9.11.0-1 - Update to 9.11.0. Fixes rhbz#2493338 * Fri Jun 12 2026 Yaakov Selkowitz - 9.9.0-4 - Rebuilt for openssl 4.0 * Mon Jun 8 2026 František Zatloukal - 9.9.0-3 - Rebuilt for icu 78.3 * Sun Jun 7 2026 Kevin Fenzi - 9.9.0-2 - Disable test_mem_leaks for now, it is failing on x86_64 only for some reason * Sat May 30 2026 Kevin Fenzi - 9.9.0-1 - Update to 9.9.0. Fixes rhbz#2482466 * Tue May 19 2026 Michael J Gruber - 9.8.0-2 - add missing tzlocal requires * Mon May 4 2026 Kevin Fenzi - 9.8.0-1 - Update to 9.8.0. Fixes rhbz#2464288 * Thu Apr 16 2026 Jan Grulich - 9.7.0-2 - Rebuild (qt6) * Wed Apr 15 2026 Kevin Fenzi - 9.7.0-1 - Update to 9.7.0. fixesrhbz#2457244 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2498951 - CVE-2026-53511 calibre: Calibre: Arbitrary code execution via malicious e-book file processing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2498951 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6776f4e492' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fixes arbitrary code execution issue in calibre for Fedora 43 with update for CVE-2026-53511 following best practices.. Fedora update, calibre security fix, arbitrary code execution, software vulnerability, Linux application management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 13, 2026 Important Fedora
89

Fedora 44 Calibre Significant Remedy for Code Execution 2026-79a5573be3

Update to 9.11.0. Fixes rhbz#2493338 and CVE-2026-53511. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-79a5573be3 2026-07-14 01:00:15.022433+00:00 -------------------------------------------------------------------------------- Name : calibre Product : Fedora 44 Version : 9.11.0 Release : 1.fc44 URL : https://calibre-ebook.com/ Summary : E-book converter and library manager Description : Calibre is meant to be a complete e-library solution. It includes library management, format conversion, news feeds to ebook conversion as well as e-book reader sync features. Calibre is primarily a ebook cataloging program. It manages your ebook collection for you. It is designed around the concept of the logical book, i.e. a single entry in the database that may correspond to ebooks in several formats. It also supports conversion to and from a dozen different ebook formats. Supported input formats are: MOBI, LIT, PRC, EPUB, CHM, ODT, HTML, CBR, CBZ, RTF, TXT, PDF and LRS. -------------------------------------------------------------------------------- Update Information: Update to 9.11.0. Fixes rhbz#2493338 and CVE-2026-53511 -------------------------------------------------------------------------------- ChangeLog: * Sun Jul 5 2026 Kevin Fenzi - 9.11.0-1 - Update to 9.11.0. Fixes rhbz#2493338 * Fri Jun 12 2026 Yaakov Selkowitz - 9.9.0-4 - Rebuilt for openssl 4.0 * Mon Jun 8 2026 František Zatloukal - 9.9.0-3 - Rebuilt for icu 78.3 * Sun Jun 7 2026 Kevin Fenzi - 9.9.0-2 - Disable test_mem_leaks for now, it is failing on x86_64 only for some reason * Sat May 30 2026 Kevin Fenzi - 9.9.0-1 - Update to 9.9.0. Fixes rhbz#2482466 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2498951 - CVE-2026-53511 calibre: Calibre: Arbitrary code execution via malicious e-book file processing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2498951 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-79a5573be3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . An important update for Fedora 44 calibre addresses a critical code execution risk through malicious e-book files. Stay secure!. Fedora 44, Calibre, Code Execution, Software Update, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 13, 2026 Important Fedora
202

OpenSUSE Tumbleweed Calibre Moderate CVE-2026-53511 Advisory 2026-11130-1

An update that solves one vulnerability can now be installed.. # calibre-9.10.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:11130-1 Rating: moderate Cross-References: * CVE-2026-53511 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the calibre-9.10.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * calibre 9.10.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53511.html . OpenSUSE Tumbleweed has released a security advisory for calibre 9.10.0-1.1 addressing a moderate severity issue.. OpenSUSE,Tumbleweed,calibre,security advisory,moderate severity. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 28, 2026 moderate OpenSUSE
197

Debian 11 calibre DLA-4554-1 Path Traversal and File Write Risks

Multiple vulnerabilities have been discovered in calibre, an e-book manager CVE-2025-64486 calibre does not validate filenames when handling binary assets in FB2 files, allowing an attacker to write arbitrary files on the. Debian LTS Advisory DLA-4554-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Abhijith PA April 29, 2026 https://wiki.debian.org/LTS Package : calibre Version : 5.12.0+dfsg-1+deb11u4 CVE ID : CVE-2025-64486 CVE-2026-25635 CVE-2026-25636 CVE-2026-26064 CVE-2026-26065 Multiple vulnerabilities have been discovered in calibre, an e-book manager CVE-2025-64486 calibre does not validate filenames when handling binary assets in FB2 files, allowing an attacker to write arbitrary files on the filesystem when viewing or converting a malicious FictionBook file. This can be leveraged to achieve arbitrary code execution. CVE-2026-25635 Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. CVE-2026-25636 a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process CVE-2026-26064 a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. CVE-2026-26065 Path Traversal through PDB readers that allow arbitrary file writes with arbitrary extension and arbitrary content anywhere the user has write permissions. Files are written in 'wb' mode, silently overwriting existing files. This can lead to potential code execution and Denial of Service through file corruption. For Debian 11 bullseye, these problems have been fixed in version 5.12.0+dfsg-1+deb11u4. We recommend that you upgrade your calibre packages. For the detailed security status of calibre please refer to its securitytracker page at: https://security-tracker.debian.org/tracker/calibre Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Multiple vulnerabilities in calibre e-book manager could allow file writes and code execution in Debian systems.. calibre security, Debian LTS, file write flaws, path traversal issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 30, 2026 Critical Debian LTS
89

Fedora 44 Calibre 9.6.0 Important Server-Side Request Forgery Patch

Update to 9.6.0. Fixes rhbz#2452087. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-7de23151cd 2026-04-25 01:21:36.171214+00:00 -------------------------------------------------------------------------------- Name : calibre Product : Fedora 44 Version : 9.6.0 Release : 1.fc44 URL : https://calibre-ebook.com/ Summary : E-book converter and library manager Description : Calibre is meant to be a complete e-library solution. It includes library management, format conversion, news feeds to ebook conversion as well as e-book reader sync features. Calibre is primarily a ebook cataloging program. It manages your ebook collection for you. It is designed around the concept of the logical book, i.e. a single entry in the database that may correspond to ebooks in several formats. It also supports conversion to and from a dozen different ebook formats. Supported input formats are: MOBI, LIT, PRC, EPUB, CHM, ODT, HTML, CBR, CBZ, RTF, TXT, PDF and LRS. -------------------------------------------------------------------------------- Update Information: Update to 9.6.0. Fixes rhbz#2452087 -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 29 2026 Kevin Fenzi - 9.6.0-1 - Update to 9.6.0. Fixes rhbz#2452087 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452087 - calibre-9.6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2452087 [ 2 ] Bug #2452379 - CVE-2026-33205 calibre: server-side request forgery in ebook viewer backend [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452379 [ 3 ] Bug #2452380 - CVE-2026-33206 calibre: path traversal allows reading arbitrary files when converting a text-based file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452380 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-7de23151cd' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update calibre 9.6.0 in Fedora 44 fixes critical security issues affecting e-book management system.. Fedora calibre update security 9.6.0. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 25, 2026 Critical Fedora
89

Arch Linux 2024 Kindle Significant Client-Side Vulnerability 2026-5bac4d9f3

Update to 9.6.0. Fixes rhbz#2452087. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9cc418c23e 2026-04-07 00:49:46.037802+00:00 -------------------------------------------------------------------------------- Name : calibre Product : Fedora 43 Version : 9.6.0 Release : 1.fc43 URL : https://calibre-ebook.com/ Summary : E-book converter and library manager Description : Calibre is meant to be a complete e-library solution. It includes library management, format conversion, news feeds to ebook conversion as well as e-book reader sync features. Calibre is primarily a ebook cataloging program. It manages your ebook collection for you. It is designed around the concept of the logical book, i.e. a single entry in the database that may correspond to ebooks in several formats. It also supports conversion to and from a dozen different ebook formats. Supported input formats are: MOBI, LIT, PRC, EPUB, CHM, ODT, HTML, CBR, CBZ, RTF, TXT, PDF and LRS. -------------------------------------------------------------------------------- Update Information: Update to 9.6.0. Fixes rhbz#2452087 -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 29 2026 Kevin Fenzi - 9.6.0-1 - Update to 9.6.0. Fixes rhbz#2452087 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452087 - calibre-9.6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2452087 [ 2 ] Bug #2452379 - CVE-2026-33205 calibre: server-side request forgery in ebook viewer backend [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452379 [ 3 ] Bug #2452380 - CVE-2026-33206 calibre: path traversal allows reading arbitrary files when converting a text-based file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452380 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9cc418c23e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Calibre 9.6.0 update addresses critical server-side request forgery and path traversal issues in Fedora 43.. Fedora 43, Calibre, Security Advisory, Critical Update, E-book Manager. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 07, 2026 Critical Fedora
89

Fedora 43: calibre 8.14.0 Critical Update to Prevent Code Execution Risks

Update to 8.14.0. Fixes rhbz#2413304. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-355be35bb1 2025-11-24 01:24:44.272905+00:00 -------------------------------------------------------------------------------- Name : calibre Product : Fedora 43 Version : 8.14.0 Release : 1.fc43 URL : https://calibre-ebook.com/ Summary : E-book converter and library manager Description : Calibre is meant to be a complete e-library solution. It includes library management, format conversion, news feeds to ebook conversion as well as e-book reader sync features. Calibre is primarily a ebook cataloging program. It manages your ebook collection for you. It is designed around the concept of the logical book, i.e. a single entry in the database that may correspond to ebooks in several formats. It also supports conversion to and from a dozen different ebook formats. Supported input formats are: MOBI, LIT, PRC, EPUB, CHM, ODT, HTML, CBR, CBZ, RTF, TXT, PDF and LRS. -------------------------------------------------------------------------------- Update Information: Update to 8.14.0. Fixes rhbz#2413304 -------------------------------------------------------------------------------- ChangeLog: * Sat Nov 15 2025 Kevin Fenzi - 8.14.0-1 - Update to 8.14.0. Fixes rhbz#2413304 * Wed Nov 5 2025 Dominik 'Rathann' Mierzejewski - 8.13.0-2 - Rebuilt for FFmpeg 8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2413304 - calibre-8.14.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2413304 [ 2 ] Bug #2414459 - CVE-2025-64486 calibre: calibre is vulnerable to arbitrary code execution when opening FB2 files [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2414459 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program.Use su -c 'dnf upgrade --advisory FEDORA-2025-355be35bb1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Upgrade to calibre 8.14.0 for Fedora 43. Fixes important security issue with FB2 file handling.. calibre upgrade, Fedora e-library management, FB2 file security, software patching. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 24, 2025 Important Fedora
203

Mageia 9 MGASA-2025-0049 critical: calibre multiple exploits

link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root. (CVE-2023-46303) Path traversal in Calibre

Calendar%202 Feb 12, 2025 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200