Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
An update that solves two vulnerabilities can now be installed.. # Security update for libjxl Announcement ID: SUSE-SU-2026:20903-1 Release Date: 2026-03-18T10:13:37Z Rating: important References: * bsc#1258090 * bsc#1258091 Cross-References: * CVE-2025-12474 * CVE-2026-1837 CVSS scores: * CVE-2025-12474 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-12474 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-12474 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-1837 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-1837 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-1837 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server - BCI 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for libjxl fixes the following issues: Update to libjxl 0.11.2: * CVE-2025-12474: a specially crafted file can cause the decoder to read pixel data from uninitialized allocated memory (bsc#1258090). * CVE-2026-1837: a specially crafted file can cause the decoder to write pixel data to uninitialized unallocated memory (bsc#1258091). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server - BCI 16.0 zypper in -t patch SUSE-SLES-16.0-403=1 ## Package List: * SUSE Linux Enterprise Server - BCI 16.0 (aarch64 ppc64le s390x x86_64) *libjxl-debugsource-0.11.2-160000.1.1 * libjxl-devel-0.11.2-160000.1.1 * libjxl0_11-debuginfo-0.11.2-160000.1.1 * libjxl0_11-0.11.2-160000.1.1 * SUSE Linux Enterprise Server - BCI 16.0 (x86_64) * libjxl0_11-x86-64-v3-debuginfo-0.11.2-160000.1.1 * libjxl0_11-x86-64-v3-0.11.2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-12474.html * https://www.suse.com/security/cve/CVE-2026-1837.html * https://bugzilla.suse.com/show_bug.cgi?id=1258090 * https://bugzilla.suse.com/show_bug.cgi?id=1258091 . An important update for libjxl resolves two significant issues and enhances security for SUSE Linux Enterprise Server.. libjxl update. . Severity: Important. LinuxSecurity.com Team
An issue has been found in libpgf, a library to handle Progressive Graphics File (PGF). . Package : libpgf Version : 6.14.12-3+deb8u1 CVE ID : CVE-2015-6673 An issue has been found in libpgf, a library to handle Progressive Graphics File (PGF). Due to lack of validation of ColorTableSize, a use-after-free issue might appear in Decoder.cpp For Debian 8 "Jessie", this problem has been fixed in version 6.14.12-3+deb8u1. We recommend that you upgrade your libpgf packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade libpgf to address security risks concerning flaws in color table validation mechanisms.. libpgf Security Update, Debian 8, Use-After-Free Issue. . LinuxSecurity.com Team
Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library. A full list of the changes is available at ;a=blob;f=Changelog;hb=refs/tags/v0.8.15 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3003-1
Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library. A full list of the changes is available at ;a=blob;f=Changelog;hb=refs/tags/v0.8.12 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2947-1
Get the latest Linux and open source security news straight to your inbox.