Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 3 articles for you...
197

Debian 11 calibre DLA-4554-1 Path Traversal and File Write Risks

Multiple vulnerabilities have been discovered in calibre, an e-book manager CVE-2025-64486 calibre does not validate filenames when handling binary assets in FB2 files, allowing an attacker to write arbitrary files on the. Debian LTS Advisory DLA-4554-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Abhijith PA April 29, 2026 https://wiki.debian.org/LTS Package : calibre Version : 5.12.0+dfsg-1+deb11u4 CVE ID : CVE-2025-64486 CVE-2026-25635 CVE-2026-25636 CVE-2026-26064 CVE-2026-26065 Multiple vulnerabilities have been discovered in calibre, an e-book manager CVE-2025-64486 calibre does not validate filenames when handling binary assets in FB2 files, allowing an attacker to write arbitrary files on the filesystem when viewing or converting a malicious FictionBook file. This can be leveraged to achieve arbitrary code execution. CVE-2026-25635 Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. CVE-2026-25636 a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process CVE-2026-26064 a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. CVE-2026-26065 Path Traversal through PDB readers that allow arbitrary file writes with arbitrary extension and arbitrary content anywhere the user has write permissions. Files are written in 'wb' mode, silently overwriting existing files. This can lead to potential code execution and Denial of Service through file corruption. For Debian 11 bullseye, these problems have been fixed in version 5.12.0+dfsg-1+deb11u4. We recommend that you upgrade your calibre packages. For the detailed security status of calibre please refer to its securitytracker page at: https://security-tracker.debian.org/tracker/calibre Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Multiple vulnerabilities in calibre e-book manager could allow file writes and code execution in Debian systems.. calibre security, Debian LTS, file write flaws, path traversal issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 30, 2026 Critical Debian LTS
89

Fedora 44 Calibre 9.6.0 Important Server-Side Request Forgery Patch

Update to 9.6.0. Fixes rhbz#2452087. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-7de23151cd 2026-04-25 01:21:36.171214+00:00 -------------------------------------------------------------------------------- Name : calibre Product : Fedora 44 Version : 9.6.0 Release : 1.fc44 URL : https://calibre-ebook.com/ Summary : E-book converter and library manager Description : Calibre is meant to be a complete e-library solution. It includes library management, format conversion, news feeds to ebook conversion as well as e-book reader sync features. Calibre is primarily a ebook cataloging program. It manages your ebook collection for you. It is designed around the concept of the logical book, i.e. a single entry in the database that may correspond to ebooks in several formats. It also supports conversion to and from a dozen different ebook formats. Supported input formats are: MOBI, LIT, PRC, EPUB, CHM, ODT, HTML, CBR, CBZ, RTF, TXT, PDF and LRS. -------------------------------------------------------------------------------- Update Information: Update to 9.6.0. Fixes rhbz#2452087 -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 29 2026 Kevin Fenzi - 9.6.0-1 - Update to 9.6.0. Fixes rhbz#2452087 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452087 - calibre-9.6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2452087 [ 2 ] Bug #2452379 - CVE-2026-33205 calibre: server-side request forgery in ebook viewer backend [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452379 [ 3 ] Bug #2452380 - CVE-2026-33206 calibre: path traversal allows reading arbitrary files when converting a text-based file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452380 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-7de23151cd' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update calibre 9.6.0 in Fedora 44 fixes critical security issues affecting e-book management system.. Fedora calibre update security 9.6.0. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 25, 2026 Critical Fedora
89

Arch Linux 2024 Kindle Significant Client-Side Vulnerability 2026-5bac4d9f3

Update to 9.6.0. Fixes rhbz#2452087. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9cc418c23e 2026-04-07 00:49:46.037802+00:00 -------------------------------------------------------------------------------- Name : calibre Product : Fedora 43 Version : 9.6.0 Release : 1.fc43 URL : https://calibre-ebook.com/ Summary : E-book converter and library manager Description : Calibre is meant to be a complete e-library solution. It includes library management, format conversion, news feeds to ebook conversion as well as e-book reader sync features. Calibre is primarily a ebook cataloging program. It manages your ebook collection for you. It is designed around the concept of the logical book, i.e. a single entry in the database that may correspond to ebooks in several formats. It also supports conversion to and from a dozen different ebook formats. Supported input formats are: MOBI, LIT, PRC, EPUB, CHM, ODT, HTML, CBR, CBZ, RTF, TXT, PDF and LRS. -------------------------------------------------------------------------------- Update Information: Update to 9.6.0. Fixes rhbz#2452087 -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 29 2026 Kevin Fenzi - 9.6.0-1 - Update to 9.6.0. Fixes rhbz#2452087 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452087 - calibre-9.6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2452087 [ 2 ] Bug #2452379 - CVE-2026-33205 calibre: server-side request forgery in ebook viewer backend [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452379 [ 3 ] Bug #2452380 - CVE-2026-33206 calibre: path traversal allows reading arbitrary files when converting a text-based file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452380 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9cc418c23e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Calibre 9.6.0 update addresses critical server-side request forgery and path traversal issues in Fedora 43.. Fedora 43, Calibre, Security Advisory, Critical Update, E-book Manager. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 07, 2026 Critical Fedora
89

Fedora 43: calibre 8.14.0 Critical Update to Prevent Code Execution Risks

Update to 8.14.0. Fixes rhbz#2413304. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-355be35bb1 2025-11-24 01:24:44.272905+00:00 -------------------------------------------------------------------------------- Name : calibre Product : Fedora 43 Version : 8.14.0 Release : 1.fc43 URL : https://calibre-ebook.com/ Summary : E-book converter and library manager Description : Calibre is meant to be a complete e-library solution. It includes library management, format conversion, news feeds to ebook conversion as well as e-book reader sync features. Calibre is primarily a ebook cataloging program. It manages your ebook collection for you. It is designed around the concept of the logical book, i.e. a single entry in the database that may correspond to ebooks in several formats. It also supports conversion to and from a dozen different ebook formats. Supported input formats are: MOBI, LIT, PRC, EPUB, CHM, ODT, HTML, CBR, CBZ, RTF, TXT, PDF and LRS. -------------------------------------------------------------------------------- Update Information: Update to 8.14.0. Fixes rhbz#2413304 -------------------------------------------------------------------------------- ChangeLog: * Sat Nov 15 2025 Kevin Fenzi - 8.14.0-1 - Update to 8.14.0. Fixes rhbz#2413304 * Wed Nov 5 2025 Dominik 'Rathann' Mierzejewski - 8.13.0-2 - Rebuilt for FFmpeg 8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2413304 - calibre-8.14.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2413304 [ 2 ] Bug #2414459 - CVE-2025-64486 calibre: calibre is vulnerable to arbitrary code execution when opening FB2 files [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2414459 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program.Use su -c 'dnf upgrade --advisory FEDORA-2025-355be35bb1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Upgrade to calibre 8.14.0 for Fedora 43. Fixes important security issue with FB2 file handling.. calibre upgrade, Fedora e-library management, FB2 file security, software patching. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 24, 2025 Important Fedora
203

Mageia 9 MGASA-2025-0049 critical: calibre multiple exploits

link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root. (CVE-2023-46303) Path traversal in Calibre

Calendar 2 Feb 12, 2025 Critical Mageia
91

Gentoo: GLSA-202409-04 High: calibre remote execution threats

Multiple vulnerabilities have been discovered in calibre, the worst of which could lead to remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202409-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: calibre: Multiple Vulnerabilities Date: September 22, 2024 Bugs: #918429, #936961 ID: 202409-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in calibre, the worst of which could lead to remote code execution. Background ========== calibre is a powerful and easy to use e-book manager. Affected packages ================= Package Vulnerable Unaffected ---------------- ------------ ------------ app-text/calibre < 7.16.0 > = 7.16.0 Description =========== Multiple vulnerabilities have been discovered in calibre. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All calibre users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-text/calibre-7.16.0" References ========== [ 1 ] CVE-2023-46303 https://nvd.nist.gov/vuln/detail/CVE-2023-46303 [ 2 ] CVE-2024-6781 https://nvd.nist.gov/vuln/detail/CVE-2024-6781 [ 3 ] CVE-2024-6782 https://nvd.nist.gov/vuln/detail/CVE-2024-6782 [ 4 ] CVE-2024-7008 https://nvd.nist.gov/vuln/detail/CVE-2024-7008 [ 5 ] CVE-2024-7009 https://nvd.nist.gov/vuln/detail/CVE-2024-7009 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202409-04 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5 . Numerous security flaws identified in calibre may permit remote code execution. It is crucial for users to upgrade to maintain protection against potential threats.. Gentoo Linux, calibre, security updates, remote access, security issues. . LinuxSecurity.com Team

Calendar 2 Sep 22, 2024 Gentoo
197

Debian 11 Bullseye DLA-3862-1: Calibre Moderate Denial Of Service

Two vulnerabilities have been fixed in the e-book manager Calibre. CVE-2021-44686 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3862-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk September 02, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : calibre Version : 5.12.0+dfsg-1+deb11u3 CVE ID : CVE-2021-44686 CVE-2023-46303 Debian Bug : Two vulnerabilities have been fixed in the e-book manager Calibre. CVE-2021-44686 Regular Expression Denial of Service CVE-2023-46303 HTML Input: Don't add resources that exist outside the document root by default For Debian 11 bullseye, these problems have been fixed in version 5.12.0+dfsg-1+deb11u3. We recommend that you upgrade your calibre packages. For the detailed security status of calibre please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/calibre Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Calibre e-book manager has resolved two security issues, one of which could lead to denial of service. Ensure you update to version 5.12.0+dfsg-1+deb11u3 for the patch.. Debian Security, Calibre Update, E-Book Vulnerabilities, HTML Security. . LinuxSecurity.com Team

Calendar 2 Sep 02, 2024 Debian LTS
89

Fedora 40: 2024-a455bea9ca Critical: Calibre Remote Code Execution

Fix fonts for < f41 releases. Upgrade to latest upstream release to fix 4 CVE's and enable new hardware. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-a455bea9ca 2024-08-27 17:07:11.621204 -------------------------------------------------------------------------------- Name : calibre Product : Fedora 40 Version : 7.17.0 Release : 3.fc40 URL : https://calibre-ebook.com/ Summary : E-book converter and library manager Description : Calibre is meant to be a complete e-library solution. It includes library management, format conversion, news feeds to ebook conversion as well as e-book reader sync features. Calibre is primarily a ebook cataloging program. It manages your ebook collection for you. It is designed around the concept of the logical book, i.e. a single entry in the database that may correspond to ebooks in several formats. It also supports conversion to and from a dozen different ebook formats. Supported input formats are: MOBI, LIT, PRC, EPUB, CHM, ODT, HTML, CBR, CBZ, RTF, TXT, PDF and LRS. -------------------------------------------------------------------------------- Update Information: Fix fonts for < f41 releases. Upgrade to latest upstream release to fix 4 CVE's and enable new hardware -------------------------------------------------------------------------------- ChangeLog: * Sun Aug 25 2024 Kevin Fenzi - 7.17.0-2 - Fix font conditionals to handle f40 and older correctly * Sat Aug 24 2024 Kevin Fenzi - 7.17.0-1 - Update to 7.17.0. Fixes rhbz#2307557 * Wed Aug 21 2024 Parag Nemade - 7.16.0-3 - Update to use new Liberation fonts installation path for F41+ releases. * Thu Aug 15 2024 Kevin Fenzi - 7.16.0-2 - Remove pycryptdome as a BuildRequires * Sun Aug 4 2024 Kevin Fenzi - 7.16.0-1 - Update to calibre 7.16.0. Fixes rhbz#2302040 * Sat Jul 20 2024 Kevin Fenzi - 7.15.0-1 - Update to 7.15.0. Fixes rhbz#2298824 * Wed Jul 17 2024Fedora Release Engineering - 7.14.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild * Sat Jul 13 2024 Kevin Fenzi - 7.14.0-1 - Update to 7.14.0. Fixes rhbz#2297462 * Sun Jul 7 2024 Kevin Fenzi - 7.13.0-2 - correct path for liberation fonts -------------------------------------------------------------------------------- References: [ 1 ] Bug #2303060 - CVE-2024-7009 calibre: From NVD collector [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2303060 [ 2 ] Bug #2303063 - CVE-2024-7008 calibre: Unsanitized user-input in Calibre allow attackers to perform reflected cross-site scripting [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2303063 [ 3 ] Bug #2303065 - CVE-2024-6782 calibre: Improper access control in Calibre allow unauthenticated attackers to achieve remote code execution. [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2303065 [ 4 ] Bug #2303067 - CVE-2024-6781 calibre: Path traversal in Calibre allow unauthenticated attackers to achieve arbitrary file read. [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2303067 [ 5 ] Bug #2307794 - Crash at start of "calibre" https://bugzilla.redhat.com/show_bug.cgi?id=2307794 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a455bea9ca' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Elevate Calibre on Fedora 40 by applying the most recent patches that rectify four CVEs, ensuring bolstered security measures and improved performance.. Fedora 40 calibre advisory, latest calibre update, e-library management fix, Fedora security update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 27, 2024 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here