Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 77 articles for you...
202

openSUSE Exiv2 Moderate Update Addressing Four Issues 2026-2704-1

An update that solves four vulnerabilities can now be installed.. # Security update for exiv2-0_26 Announcement ID: SUSE-SU-2026:2704-1 Release Date: 2026-06-30T10:28:26Z Rating: moderate References: * bsc#1248962 * bsc#1259083 * bsc#1259084 * bsc#1259085 Cross-References: * CVE-2025-54080 * CVE-2026-25884 * CVE-2026-27596 * CVE-2026-27631 CVSS scores: * CVE-2025-54080 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-54080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-54080 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25884 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25884 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-25884 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25884 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-27596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-27596 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27596 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27631 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27631 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-27631 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27631 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * openSUSE Leap 15.4 An update that solves four vulnerabilities can now be installed. ## Description: This update for exiv2-0_26 fixes the following issues * CVE-2025-54080: out-of-bounds read in `Exiv2::EpsImage::writeMetadata()` when writing metadata into a crafted image file (bsc#1248962). * CVE-2026-25884: out-of-bounds read in `CrwMap::decode0x0805` (bsc#1259083). * CVE-2026-27596: integer overflow in `LoaderNative::getData()` leads to out- of-bounds read (bsc#1259084). * CVE-2026-27631: crash due to uncaught exception when trying to create `std::vector` larger than `max_size()` (bsc#1259085). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2704=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libexiv2-26-debuginfo-0.26-150400.9.34.1 * exiv2-0_26-debugsource-0.26-150400.9.34.1 * libexiv2-26-0.26-150400.9.34.1 * openSUSE Leap 15.4 (x86_64) * libexiv2-26-32bit-debuginfo-0.26-150400.9.34.1 * libexiv2-26-32bit-0.26-150400.9.34.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libexiv2-26-64bit-0.26-150400.9.34.1 * libexiv2-26-64bit-debuginfo-0.26-150400.9.34.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54080.html * https://www.suse.com/security/cve/CVE-2026-25884.html * https://www.suse.com/security/cve/CVE-2026-27596.html * https://www.suse.com/security/cve/CVE-2026-27631.html * https://bugzilla.suse.com/show_bug.cgi?id=1248962 * https://bugzilla.suse.com/show_bug.cgi?id=1259083 *https://bugzilla.suse.com/show_bug.cgi?id=1259084 * https://bugzilla.suse.com/show_bug.cgi?id=1259085 . # Security update for exiv2-0_26 Announcement ID: SUSE-SU-2026:2704-1 Release Date: 2026-06-30T10:28. update, solves, vulnerabilities, installed, security, exiv2-0_26. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 moderate OpenSUSE
100

SUSE exiv2-0_26 Moderate Out-of-Bounds Integer Overflow Update 2026-2704-1

An update that solves four vulnerabilities can now be installed.. # Security update for exiv2-0_26 Announcement ID: SUSE-SU-2026:2704-1 Release Date: 2026-06-30T10:28:26Z Rating: moderate References: * bsc#1248962 * bsc#1259083 * bsc#1259084 * bsc#1259085 Cross-References: * CVE-2025-54080 * CVE-2026-25884 * CVE-2026-27596 * CVE-2026-27631 CVSS scores: * CVE-2025-54080 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-54080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-54080 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25884 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25884 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-25884 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25884 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-27596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-27596 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27596 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27631 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27631 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-27631 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27631 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * openSUSE Leap 15.4 An update that solves four vulnerabilities can now be installed. ## Description: This update for exiv2-0_26 fixes the following issues * CVE-2025-54080: out-of-bounds read in `Exiv2::EpsImage::writeMetadata()` when writing metadata into a crafted image file (bsc#1248962). * CVE-2026-25884: out-of-bounds read in `CrwMap::decode0x0805` (bsc#1259083). * CVE-2026-27596: integer overflow in `LoaderNative::getData()` leads to out- of-bounds read (bsc#1259084). * CVE-2026-27631: crash due to uncaught exception when trying to create `std::vector` larger than `max_size()` (bsc#1259085). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2704=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libexiv2-26-debuginfo-0.26-150400.9.34.1 * exiv2-0_26-debugsource-0.26-150400.9.34.1 * libexiv2-26-0.26-150400.9.34.1 * openSUSE Leap 15.4 (x86_64) * libexiv2-26-32bit-debuginfo-0.26-150400.9.34.1 * libexiv2-26-32bit-0.26-150400.9.34.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libexiv2-26-64bit-0.26-150400.9.34.1 * libexiv2-26-64bit-debuginfo-0.26-150400.9.34.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54080.html * https://www.suse.com/security/cve/CVE-2026-25884.html * https://www.suse.com/security/cve/CVE-2026-27596.html * https://www.suse.com/security/cve/CVE-2026-27631.html * https://bugzilla.suse.com/show_bug.cgi?id=1248962 * https://bugzilla.suse.com/show_bug.cgi?id=1259083 *https://bugzilla.suse.com/show_bug.cgi?id=1259084 * https://bugzilla.suse.com/show_bug.cgi?id=1259085 . Four vulnerabilities in exiv2-0_26 fixed in this SUSE update that enhances system security.. SUSE Linux Security Update exiv2 Security Patching. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 moderate SuSE
100

SUSE Exiv2 Moderate Out-Of-Bounds Integer Overflow Vuln 2026-2663-1

An update that solves four vulnerabilities can now be installed.. # Security update for exiv2 Announcement ID: SUSE-SU-2026:2663-1 Release Date: 2026-06-26T14:04:29Z Rating: moderate References: * bsc#1248962 * bsc#1259083 * bsc#1259084 * bsc#1259085 Cross-References: * CVE-2025-54080 * CVE-2026-25884 * CVE-2026-27596 * CVE-2026-27631 CVSS scores: * CVE-2025-54080 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-54080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-54080 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25884 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25884 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-25884 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25884 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-27596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-27596 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27596 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27631 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27631 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-27631 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27631 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves four vulnerabilities can now be installed. ## Description: This update for exiv2 fixes the following issues * CVE-2025-54080: out-of-bounds read in `Exiv2::EpsImage::writeMetadata()` when writing metadata into a crafted image file (bsc#1248962). * CVE-2026-25884: out-of-bounds read in `CrwMap::decode0x0805` (bsc#1259083). * CVE-2026-27596: integer overflow in `LoaderNative::getData()` leads to out- of-bounds read (bsc#1259084). * CVE-2026-27631: crash due to uncaught exception when trying to create `std::vector` larger than `max_size()` (bsc#1259085). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2663=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * exiv2-debuginfo-0.23-12.26.1 * libexiv2-12-debuginfo-0.23-12.26.1 * libexiv2-12-0.23-12.26.1 * libexiv2-devel-0.23-12.26.1 * exiv2-debugsource-0.23-12.26.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54080.html * https://www.suse.com/security/cve/CVE-2026-25884.html * https://www.suse.com/security/cve/CVE-2026-27596.html * https://www.suse.com/security/cve/CVE-2026-27631.html * https://bugzilla.suse.com/show_bug.cgi?id=1248962 * https://bugzilla.suse.com/show_bug.cgi?id=1259083 *https://bugzilla.suse.com/show_bug.cgi?id=1259084 * https://bugzilla.suse.com/show_bug.cgi?id=1259085 . Install this key SUSE update for exiv2 addressing multiple issues, enhancing your system's security and performance.. SUSE Linux Exiv2 Update Security. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 26, 2026 moderate SuSE
202

openSUSE Exiv2 Moderate DoS Buffer Overflow Update 2026-2584-1

An update that solves four vulnerabilities can now be installed.. # Security update for exiv2 Announcement ID: SUSE-SU-2026:2584-1 Release Date: 2026-06-23T13:27:50Z Rating: moderate References: * bsc#1189338 * bsc#1259083 * bsc#1259084 * bsc#1259085 Cross-References: * CVE-2021-34334 * CVE-2026-25884 * CVE-2026-27596 * CVE-2026-27631 CVSS scores: * CVE-2021-34334 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2021-34334 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25884 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25884 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-25884 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25884 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-27596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-27596 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27596 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27631 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27631 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-27631 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27631 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.4 *SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for exiv2 fixes the following issues * CVE-2021-34334: DoS due to integer overflow in loop counter (bsc#1189338). * CVE-2026-25884: out-of-bounds read in `CrwMap: decode0x0805` (bsc#1259083). * CVE-2026-27596: integer overflow in `LoaderNative: getData()` leads to out- of-bounds read (bsc#1259084). * CVE-2026-27631: crash due to uncaught exception when trying to create `std: vector` larger than `max_size()` (bsc#1259085). Changes for exiv2: * Minor bugs and fixes * Other improvements * exivsimple has array index errors when stripping quotes form TIFF parser,Binary array elements should be decoded using the Add option -K Key (--key Key) to specify one or more keys to "exiv2 -eX" followed by "exiv2 -iX" produces invalid XMP * This release introduces support for Postscript (EPS) images. XMP metadata can be read and written from/to EPS images and previews are accessible. Further it includes a new build environment for MSVC 64 bit * fix build with gcc 4.3 (upstream backport) * Fix "Since v0.14 the version check macro doesn't work in a precompiler ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2584=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2584=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libexiv2-xmp-static-0.27.5-150400.15.7.1 * exiv2-debugsource-0.27.5-150400.15.7.1 * exiv2-debuginfo-0.27.5-150400.15.7.1 *libexiv2-27-debuginfo-0.27.5-150400.15.7.1 * libexiv2-27-0.27.5-150400.15.7.1 * exiv2-0.27.5-150400.15.7.1 * libexiv2-devel-0.27.5-150400.15.7.1 * openSUSE Leap 15.4 (noarch) * exiv2-lang-0.27.5-150400.15.7.1 * openSUSE Leap 15.4 (x86_64) * libexiv2-27-32bit-0.27.5-150400.15.7.1 * libexiv2-27-32bit-debuginfo-0.27.5-150400.15.7.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libexiv2-27-64bit-debuginfo-0.27.5-150400.15.7.1 * libexiv2-27-64bit-0.27.5-150400.15.7.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libexiv2-xmp-static-0.27.5-150400.15.7.1 * exiv2-debugsource-0.27.5-150400.15.7.1 * exiv2-debuginfo-0.27.5-150400.15.7.1 * libexiv2-27-debuginfo-0.27.5-150400.15.7.1 * libexiv2-27-0.27.5-150400.15.7.1 * libexiv2-devel-0.27.5-150400.15.7.1 ## References: * https://www.suse.com/security/cve/CVE-2021-34334.html * https://www.suse.com/security/cve/CVE-2026-25884.html * https://www.suse.com/security/cve/CVE-2026-27596.html * https://www.suse.com/security/cve/CVE-2026-27631.html * https://bugzilla.suse.com/show_bug.cgi?id=1189338 * https://bugzilla.suse.com/show_bug.cgi?id=1259083 * https://bugzilla.suse.com/show_bug.cgi?id=1259084 * https://bugzilla.suse.com/show_bug.cgi?id=1259085 . # Security update for exiv2 Announcement ID: SUSE-SU-2026:2584-1 Release Date: 2026-06-23T13:27:50Z . update, solves, vulnerabilities, installed, security, exiv2, announc. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 23, 2026 moderate OpenSUSE
100

SUSE exiv2 Moderate DoS Integer Overflow Security Update 2026-2584-1

An update that solves four vulnerabilities can now be installed.. # Security update for exiv2 Announcement ID: SUSE-SU-2026:2584-1 Release Date: 2026-06-23T13:27:50Z Rating: moderate References: * bsc#1189338 * bsc#1259083 * bsc#1259084 * bsc#1259085 Cross-References: * CVE-2021-34334 * CVE-2026-25884 * CVE-2026-27596 * CVE-2026-27631 CVSS scores: * CVE-2021-34334 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2021-34334 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25884 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25884 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-25884 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25884 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-27596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-27596 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27596 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27631 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27631 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-27631 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27631 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.4 *SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for exiv2 fixes the following issues * CVE-2021-34334: DoS due to integer overflow in loop counter (bsc#1189338). * CVE-2026-25884: out-of-bounds read in `CrwMap: decode0x0805` (bsc#1259083). * CVE-2026-27596: integer overflow in `LoaderNative: getData()` leads to out- of-bounds read (bsc#1259084). * CVE-2026-27631: crash due to uncaught exception when trying to create `std: vector` larger than `max_size()` (bsc#1259085). Changes for exiv2: * Minor bugs and fixes * Other improvements * exivsimple has array index errors when stripping quotes form TIFF parser,Binary array elements should be decoded using the Add option -K Key (--key Key) to specify one or more keys to "exiv2 -eX" followed by "exiv2 -iX" produces invalid XMP * This release introduces support for Postscript (EPS) images. XMP metadata can be read and written from/to EPS images and previews are accessible. Further it includes a new build environment for MSVC 64 bit * fix build with gcc 4.3 (upstream backport) * Fix "Since v0.14 the version check macro doesn't work in a precompiler ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2584=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2584=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libexiv2-xmp-static-0.27.5-150400.15.7.1 * exiv2-debugsource-0.27.5-150400.15.7.1 * exiv2-debuginfo-0.27.5-150400.15.7.1 *libexiv2-27-debuginfo-0.27.5-150400.15.7.1 * libexiv2-27-0.27.5-150400.15.7.1 * exiv2-0.27.5-150400.15.7.1 * libexiv2-devel-0.27.5-150400.15.7.1 * openSUSE Leap 15.4 (noarch) * exiv2-lang-0.27.5-150400.15.7.1 * openSUSE Leap 15.4 (x86_64) * libexiv2-27-32bit-0.27.5-150400.15.7.1 * libexiv2-27-32bit-debuginfo-0.27.5-150400.15.7.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libexiv2-27-64bit-debuginfo-0.27.5-150400.15.7.1 * libexiv2-27-64bit-0.27.5-150400.15.7.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libexiv2-xmp-static-0.27.5-150400.15.7.1 * exiv2-debugsource-0.27.5-150400.15.7.1 * exiv2-debuginfo-0.27.5-150400.15.7.1 * libexiv2-27-debuginfo-0.27.5-150400.15.7.1 * libexiv2-27-0.27.5-150400.15.7.1 * libexiv2-devel-0.27.5-150400.15.7.1 ## References: * https://www.suse.com/security/cve/CVE-2021-34334.html * https://www.suse.com/security/cve/CVE-2026-25884.html * https://www.suse.com/security/cve/CVE-2026-27596.html * https://www.suse.com/security/cve/CVE-2026-27631.html * https://bugzilla.suse.com/show_bug.cgi?id=1189338 * https://bugzilla.suse.com/show_bug.cgi?id=1259083 * https://bugzilla.suse.com/show_bug.cgi?id=1259084 * https://bugzilla.suse.com/show_bug.cgi?id=1259085 . Four key vulnerabilities fixed in exiv2 security update for SUSE Linux, addressing critical issues. Install updates immediately.. exiv2 update SUSE vulnerabilities moderation severity security. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 23, 2026 moderate SuSE
89

Fedora 42 mingw-exiv2 Important Denial of Service Fix 2026-592e4238fa

Update to exiv2-0.28.8.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-592e4238fa 2026-04-12 15:52:51.750287+00:00 -------------------------------------------------------------------------------- Name : mingw-exiv2 Product : Fedora 42 Version : 0.28.8 Release : 1.fc42 URL : https://exiv2.org/ Summary : MinGW Windows exiv2 library Description : MinGW Windows exiv2 library. -------------------------------------------------------------------------------- Update Information: Update to exiv2-0.28.8. -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 7 2026 Sandro Mani - 0.28.8-1 - Update to 0.28.8 * Fri Jan 16 2026 Fedora Release Engineering - 0.28.7-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2453392 - CVE-2026-25884 mingw-exiv2: Exiv2: Denial of service via out-of-bounds read in CRW image parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453392 [ 2 ] Bug #2453394 - CVE-2026-27596 mingw-exiv2: Exiv2: Denial of Service via out-of-bounds read in preview component [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453394 [ 3 ] Bug #2453396 - CVE-2026-27631 mingw-exiv2: Exiv2: Denial of Service via integer overflow in preview component [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453396 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-592e4238fa' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPGkeys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Critical updates for mingw-exiv2 in Fedora 42 address important denial of service risks with new security advisories.. mingw-exiv2, Fedora 42 security, denial of service fixes, package updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 12, 2026 Important Fedora
100

SUSE exiv2 Important Buffer Overflow Denial of Service Vuln 2026-20923-1

An update that solves nine vulnerabilities can now be installed.. # Security update for exiv2 Announcement ID: SUSE-SU-2026:20923-1 Release Date: 2026-03-23T09:44:37Z Rating: important References: * bsc#1219870 * bsc#1219871 * bsc#1227528 * bsc#1237347 * bsc#1248962 * bsc#1248963 * bsc#1259083 * bsc#1259084 * bsc#1259085 Cross-References: * CVE-2024-24826 * CVE-2024-25112 * CVE-2024-39695 * CVE-2025-26623 * CVE-2025-54080 * CVE-2025-55304 * CVE-2026-25884 * CVE-2026-27596 * CVE-2026-27631 CVSS scores: * CVE-2024-24826 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2024-24826 ( NVD ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2024-24826 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-25112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-25112 ( NVD ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2024-25112 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-39695 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2024-39695 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2025-26623 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-26623 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-26623 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54080 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-54080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-54080 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-55304 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-55304 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-55304 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25884 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25884 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-25884 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25884 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-27596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-27596 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27596 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27631 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27631 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-27631 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27631 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server - BCI 16.0 An update that solves nine vulnerabilities can now be installed. ## Description: This update for exiv2 fixes the following issues: Update to exiv2 0.28.8: * CVE-2024-24826: out-of-bounds read inQuickTimeVideo: NikonTagsDecoder (bsc#1219870). * CVE-2024-25112: denial of service due to unbounded recursion in QuickTimeVideo: multipleEntriesDecoder (bsc#1219871). * CVE-2024-39695: out-of-bounds read in AsfVideo: streamProperties (bsc#1227528). * CVE-2025-26623: heap buffer overflow via writing metadata into a crafted image file (bsc#1237347). * CVE-2025-54080: out-of-bounds read in `Exiv2: EpsImage: writeMetadata()` when writing metadata into a crafted image file (bsc#1248962). * CVE-2025-55304: quadratic performance algorithm in the ICC profile parsing code of `JpegBase: readMetadata` (bsc#1248963). * CVE-2026-25884: out-of-bounds read in `CrwMap: decode0x0805` (bsc#1259083). * CVE-2026-27596: integer overflow in `LoaderNative: getData()` leads to out- of-bounds read (bsc#1259084). * CVE-2026-27631: crash due to uncaught exception when trying to create `std: vector` larger than `max_size()` (bsc#1259085). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server - BCI 16.0 zypper in -t patch SUSE-SLES-16.0-424=1 ## Package List: * SUSE Linux Enterprise Server - BCI 16.0 (aarch64 ppc64le s390x x86_64) * exiv2-debugsource-0.28.8-160000.1.1 * libexiv2-28-0.28.8-160000.1.1 * libexiv2-28-debuginfo-0.28.8-160000.1.1 * exiv2-debuginfo-0.28.8-160000.1.1 * SUSE Linux Enterprise Server - BCI 16.0 (x86_64) * libexiv2-28-x86-64-v3-0.28.8-160000.1.1 * libexiv2-28-x86-64-v3-debuginfo-0.28.8-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-24826.html * https://www.suse.com/security/cve/CVE-2024-25112.html * https://www.suse.com/security/cve/CVE-2024-39695.html * https://www.suse.com/security/cve/CVE-2025-26623.html * https://www.suse.com/security/cve/CVE-2025-54080.html *https://www.suse.com/security/cve/CVE-2025-55304.html * https://www.suse.com/security/cve/CVE-2026-25884.html * https://www.suse.com/security/cve/CVE-2026-27596.html * https://www.suse.com/security/cve/CVE-2026-27631.html * https://bugzilla.suse.com/show_bug.cgi?id=1219870 * https://bugzilla.suse.com/show_bug.cgi?id=1219871 * https://bugzilla.suse.com/show_bug.cgi?id=1227528 * https://bugzilla.suse.com/show_bug.cgi?id=1237347 * https://bugzilla.suse.com/show_bug.cgi?id=1248962 * https://bugzilla.suse.com/show_bug.cgi?id=1248963 * https://bugzilla.suse.com/show_bug.cgi?id=1259083 * https://bugzilla.suse.com/show_bug.cgi?id=1259084 * https://bugzilla.suse.com/show_bug.cgi?id=1259085 . SUSE exiv2 important update addresses nine vulnerabilities with critical fixes to ensure system security.. SUSE exiv2 security update important CVE references vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 01, 2026 Important SuSE
202

Fedora 38 Plasma 5.24 Significant Memory Leak Issue Fedora-SU-2026-50212-8

An update that solves 9 vulnerabilities and has 9 bug fixes can now be installed.. openSUSE security update: security update for exiv2 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20410-1 Rating: important References: * bsc#1219870 * bsc#1219871 * bsc#1227528 * bsc#1237347 * bsc#1248962 * bsc#1248963 * bsc#1259083 * bsc#1259084 * bsc#1259085 Cross-References: * CVE-2024-24826 * CVE-2024-25112 * CVE-2024-39695 * CVE-2025-26623 * CVE-2025-54080 * CVE-2025-55304 * CVE-2026-25884 * CVE-2026-27596 * CVE-2026-27631 CVSS scores: * CVE-2024-24826 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2024-25112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-39695 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2025-26623 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-26623 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-54080 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-55304 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-55304 ( SUSE ): 2 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-25884 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-25884 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-27596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27631 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-27631 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 9vulnerabilities and has 9 bug fixes can now be installed. Description: This update for exiv2 fixes the following issues: Update to exiv2 0.28.8: - CVE-2024-24826: out-of-bounds read in QuickTimeVideo: NikonTagsDecoder (bsc#1219870). - CVE-2024-25112: denial of service due to unbounded recursion in QuickTimeVideo: multipleEntriesDecoder (bsc#1219871). - CVE-2024-39695: out-of-bounds read in AsfVideo: streamProperties (bsc#1227528). - CVE-2025-26623: heap buffer overflow via writing metadata into a crafted image file (bsc#1237347). - CVE-2025-54080: out-of-bounds read in `Exiv2: EpsImage: writeMetadata()` when writing metadata into a crafted image file (bsc#1248962). - CVE-2025-55304: quadratic performance algorithm in the ICC profile parsing code of `JpegBase: readMetadata` (bsc#1248963). - CVE-2026-25884: out-of-bounds read in `CrwMap: decode0x0805` (bsc#1259083). - CVE-2026-27596: integer overflow in `LoaderNative: getData()` leads to out-of-bounds read (bsc#1259084). - CVE-2026-27631: crash due to uncaught exception when trying to create `std: vector` larger than `max_size()` (bsc#1259085). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-424=1 Package List: - openSUSE Leap 16.0: exiv2-0.28.8-160000.1.1 exiv2-lang-0.28.8-160000.1.1 libexiv2-28-0.28.8-160000.1.1 libexiv2-28-x86-64-v3-0.28.8-160000.1.1 libexiv2-devel-0.28.8-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2024-24826.html * https://www.suse.com/security/cve/CVE-2024-25112.html * https://www.suse.com/security/cve/CVE-2024-39695.html * https://www.suse.com/security/cve/CVE-2025-26623.html * https://www.suse.com/security/cve/CVE-2025-54080.html * https://www.suse.com/security/cve/CVE-2025-55304.html * https://www.suse.com/security/cve/CVE-2026-25884.html *https://www.suse.com/security/cve/CVE-2026-27596.html * https://www.suse.com/security/cve/CVE-2026-27631.html . A critical update for openSUSE exiv2 addresses 9 important issues, ensuring enhanced system security.. openSUSE exiv2 bug fixes vulnerabilities update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 28, 2026 Important OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200