Several security issues were fixed in Freeglut.. ========================================================================== Ubuntu Security Notice USN-7870-1 November 17, 2025 freeglut vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Freeglut. Software Description: - freeglut: Free implementation of the OpenGL Utility Toolkit (GLUT) Details: It was discovered that Freeglut incorrectly managed memory, resulting in a memory leak. An attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 libglut-dev 3.4.0-5ubuntu0.1 libglut3.12 3.4.0-5ubuntu0.1 Ubuntu 25.04 libglut-dev 3.4.0-4ubuntu0.1 libglut3.12 3.4.0-4ubuntu0.1 Ubuntu 24.04 LTS libglut-dev 3.4.0-1ubuntu0.1~esm1 Available with Ubuntu Pro libglut3.12 3.4.0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS freeglut3 2.8.1-6ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS freeglut3 2.8.1-3ubuntu0.20.04.1~esm1 Available with Ubuntu Pro freeglut3-dev 2.8.1-3ubuntu0.20.04.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS freeglut3 2.8.1-3ubuntu0.18.04.1~esm1 Available with Ubuntu Pro freeglut3-dev 2.8.1-3ubuntu0.18.04.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS freeglut3 2.8.1-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 14.04 LTS freeglut3 2.8.1-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7870-1 CVE-2024-24258, CVE-2024-24259 Package Information: https://launchpad.net/ubuntu/+source/freeglut/3.4.0-5ubuntu0.1 https://launchpad.net/ubuntu/+source/freeglut/3.4.0-4ubuntu0.1 . Important security issues in Freeglut resolved. Update Ubuntu for better stability and performance.. Ubuntu Freeglut Update, Important Security Fix, Denial of Service, Memory Leak Issue. . Severity: Important. LinuxSecurity.com Team
freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function. (CVE-2024-24258) freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function. (CVE-2024-24259) . MGASA-2024-0165 - Updated freeglut packages fix security vulnerabilities Publication date: 09 May 2024 URL: https://advisories.mageia.org/MGASA-2024-0165.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-24258, CVE-2024-24259 freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function. (CVE-2024-24258) freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function. (CVE-2024-24259) References: - https://bugs.mageia.org/show_bug.cgi?id=33167 - https://lwn.net/Articles/971670/ - https://www.cve.org/CVERecord?id=CVE-2024-24258 - https://www.cve.org/CVERecord?id=CVE-2024-24259 SRPMS: - 9/core/freeglut-3.4.0-1.1.mga9 . Mageia 9 has issued important security advisories on Freeglut, revealing critical memory leak vulnerabilities. Users are urged to update ASAP to safeguard their systems. Mageia Security Update, Freeglut Memory Leak Fix, Open Source Vulnerability. . Severity: Critical. LinuxSecurity.com Team
Patch for CVE-2024-24258 and CVE-2024-24259. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-0356803680 2024-02-21 01:38:35.302024 -------------------------------------------------------------------------------- Name : freeglut Product : Fedora 38 Version : 3.4.0 Release : 7.fc38 URL : https://freeglut.sourceforge.net/ Summary : A freely licensed alternative to the GLUT library Description : freeglut is a completely open source alternative to the OpenGL Utility Toolkit (GLUT) library with an OSI approved free software license. GLUT was originally written by Mark Kilgard to support the sample programs in the second edition OpenGL 'RedBook'. Since then, GLUT has been used in a wide variety of practical applications because it is simple, universally available and highly portable. freeglut allows the user to create and manage windows containing OpenGL contexts on a wide range of platforms and also read the mouse, keyboard and joystick functions. -------------------------------------------------------------------------------- Update Information: Patch for CVE-2024-24258 and CVE-2024-24259 -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 12 2024 Gwyn Ciesla - 3.4.0-7 - Patch for CVE-2024-24258 and CVE-2024-24259 * Wed Jan 24 2024 Fedora Release Engineering - 3.4.0-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 Fedora Release Engineering - 3.4.0-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Wed Jul 19 2023 Fedora Release Engineering - 3.4.0-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Fri Mar 3 2023 Gwyn Ciesla - 3.4.0-3 - migrated to SPDX license -------------------------------------------------------------------------------- References: [ 1 ] Bug #2263941 - CVE-2024-24258 freeglut: memory leak viaglutAddSubMenu() function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2263941 [ 2 ] Bug #2263946 - CVE-2024-24259 freeglut: memory leak via glutAddMenuEntry() function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2263946 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-0356803680' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Patch for CVE-2024-24258 and CVE-2024-24259. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-b69a4d75a1 2024-02-20 01:38:39.542129 -------------------------------------------------------------------------------- Name : freeglut Product : Fedora 39 Version : 3.4.0 Release : 7.fc39 URL : https://freeglut.sourceforge.net/ Summary : A freely licensed alternative to the GLUT library Description : freeglut is a completely open source alternative to the OpenGL Utility Toolkit (GLUT) library with an OSI approved free software license. GLUT was originally written by Mark Kilgard to support the sample programs in the second edition OpenGL 'RedBook'. Since then, GLUT has been used in a wide variety of practical applications because it is simple, universally available and highly portable. freeglut allows the user to create and manage windows containing OpenGL contexts on a wide range of platforms and also read the mouse, keyboard and joystick functions. -------------------------------------------------------------------------------- Update Information: Patch for CVE-2024-24258 and CVE-2024-24259 -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 12 2024 Gwyn Ciesla - 3.4.0-7 - Patch for CVE-2024-24258 and CVE-2024-24259 * Wed Jan 24 2024 Fedora Release Engineering - 3.4.0-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 Fedora Release Engineering - 3.4.0-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2263941 - CVE-2024-24258 freeglut: memory leak via glutAddSubMenu() function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2263941 [ 2 ] Bug #2263946 - CVE-2024-24259 freeglut: memory leak via glutAddMenuEntry() function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2263946 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-b69a4d75a1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.