Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 5 articles for you...
172

Ubuntu 16.04 LTS GDAL Important Denial Of Service CVE-2025-9900 USN-8345-1

GDAL could be made to crash or run programs if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8345-1 May 28, 2026 gdal vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: GDAL could be made to crash or run programs if it received specially crafted input. Software Description: - gdal: Geospatial Data Abstraction Library Details: It was discovered that the vendored LibTIFF in GDAL incorrectly handled memory when parsing malformed TIFF image metadata. An attacker could possibly use this issue to cause a denial of service, obtain sensitive information, or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS gdal-bin 1.11.3+dfsg-3ubuntu0.1~esm1 Available with Ubuntu Pro libgdal-dev 1.11.3+dfsg-3ubuntu0.1~esm1 Available with Ubuntu Pro libgdal-java 1.11.3+dfsg-3ubuntu0.1~esm1 Available with Ubuntu Pro libgdal-perl 1.11.3+dfsg-3ubuntu0.1~esm1 Available with Ubuntu Pro libgdal1i 1.11.3+dfsg-3ubuntu0.1~esm1 Available with Ubuntu Pro python-gdal 1.11.3+dfsg-3ubuntu0.1~esm1 Available with Ubuntu Pro python3-gdal 1.11.3+dfsg-3ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 14.04 LTS gdal-bin 1.10.1+dfsg-5ubuntu1+esm2 Available with Ubuntu Pro libgdal-dev 1.10.1+dfsg-5ubuntu1+esm2 Available with Ubuntu Pro libgdal-java 1.10.1+dfsg-5ubuntu1+esm2 Available with Ubuntu Pro libgdal-perl 1.10.1+dfsg-5ubuntu1+esm2 Available with Ubuntu Pro libgdal1h 1.10.1+dfsg-5ubuntu1+esm2 Available with Ubuntu Pro python-gdal 1.10.1+dfsg-5ubuntu1+esm2 Available with Ubuntu Pro python3-gdal 1.10.1+dfsg-5ubuntu1+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8345-1 CVE-2025-9900 . GDAL for Ubuntu may crash or allow arbitrary code execution with crafted input. Update to secure your systems.. GDAL Ubuntu Denial of Service. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 29, 2026 Important Ubuntu
91

Gentoo: GLSA-202210-16 High: OpenSSL Certificate Validation Vulnerability

A heap buffer overflow vulnerability has been found in GDAL which could result in denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202210-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: GDAL: Heap Buffer Overflow Date: October 31, 2022 Bugs: #830370 ID: 202210-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A heap buffer overflow vulnerability has been found in GDAL which could result in denial of service. Background ========= GDAL is a geospatial data abstraction library. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sci-libs/gdal < 3.4.1 > = 3.4.1 Description ========== GDAL does not sufficiently sanitize input when loading PCIDSK binary segments. Impact ===== Loading crafted PCIDSK data via GDAL could result in denial of service. Workaround ========= There is no known workaround at this time. Resolution ========= All GDAL users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sci-libs/gdal-3.4.1" References ========= [ 1 ] CVE-2021-45943 https://nvd.nist.gov/vuln/detail/CVE-2021-45943 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202210-15 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressedto This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2022 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . A buffer overflow vulnerability in GDAL may lead to service disruptions; users advised to update to the most recent version.. GDAL Vulnerability,Gentoo Security Advisory,Heap Overflow,Denial of Service,Low Severity. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Oct 30, 2022 Low Gentoo
197

Debian 10 buster DLA-3129-1 Moderate: gdal Denial Of Service Threat

Two issues were found in GDAL, a geospatial library, that could lead to denial of service via application crash or possibly the execution of arbitrary code if maliciously crafted data was parsed. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-3129-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta October 01, 2022 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : gdal Version : 2.4.0+dfsg-1+deb10u1 CVE ID : CVE-2019-17545 CVE-2021-45943 Two issues were found in GDAL, a geospatial library, that could lead to denial of service via application crash or possibly the execution of arbitrary code if maliciously crafted data was parsed. For Debian 10 buster, these problems have been fixed in version 2.4.0+dfsg-1+deb10u1. We recommend that you upgrade your gdal packages. For the detailed security status of gdal please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/gdal Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A pair of vulnerabilities in GDAL may result in denial of service or arbitrary code execution; an upgrade is strongly advised.. GDAL Security Update, Debian LTS Advisory, Denial of Service, Arbitrary Code Execution. . LinuxSecurity.com Team

Calendar 2 Oct 01, 2022 Debian LTS
87

Debian: DSA-5240-1 Urgent: libxyz Memory Leak and Service Crash

A heap-based buffer overflow vulnerability was discovered in gdal, a Geospatial Data Abstraction Library, which could result in denial of service or potentially the execution of arbitrary code, if a specially crafted file is processed with the PCIDSK driver. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5239-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Aron Xu September 27, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : gdal CVE ID : CVE-2021-45943 A heap-based buffer overflow vulnerability was discovered in gdal, a Geospatial Data Abstraction Library, which could result in denial of service or potentially the execution of arbitrary code, if a specially crafted file is processed with the PCIDSK driver. For the stable distribution (bullseye), this problem has been fixed in version 3.2.2+dfsg-2+deb11u2. We recommend that you upgrade your gdal packages. For the detailed security status of gdal please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/gdal Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . This advisory highlights a critical buffer overflow flaw in the GDAL library affecting Debian users, enabling potential remote code execution risks. GDAL Buffer Overflow, Debian Security Advisory, Critical Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 27, 2022 Critical Debian
89

Fedora 35: FEDORA-2023-dcbe783a83 Urgent: OpenSSL Security Flaw

Backport patch for CVE-2021-45943.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-cffca5dbf4 2022-04-06 18:44:22.683037 --------------------------------------------------------------------------------Name : gdal Product : Fedora 34 Version : 3.2.2 Release : 3.fc34 URL : https://gdal.org/en/latest/ Summary : GIS file format library Description : Geospatial Data Abstraction Library (GDAL/OGR) is a cross platform C++ translator library for raster and vector geospatial data formats. As a library, it presents a single abstract data model to the calling application for all supported formats. It also comes with a variety of useful commandline utilities for data translation and processing. It provides the primary data access engine for many applications. GDAL/OGR is the most widely used geospatial data access library. --------------------------------------------------------------------------------Update Information: Backport patch for CVE-2021-45943. --------------------------------------------------------------------------------ChangeLog: * Fri Feb 4 2022 Sandro Mani - 3.2.2-3 - Backport patch for CVE-2021-45943 --------------------------------------------------------------------------------References: [ 1 ] Bug #2049069 - CVE-2021-45943 gdal: heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2049069 [ 2 ] Bug #2049070 - CVE-2021-45943 mingw-gdal: gdal: heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2049070 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-cffca5dbf4' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Hotfix update addressing a critical buffer overflow vulnerability within the GDAL library for Fedora 34, issued on the 6th of April, 2022.. gdal patch management, Fedora update, security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 06, 2022 Important Fedora
89

Fedora 35 Advisory FEDORA-2022-e85e37206b Critical: mingw-python3 Overflow

Update to gdal-3.3.3 and python-3.10.4.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-e85e37206b 2022-04-05 15:42:46.531282 --------------------------------------------------------------------------------Name : mingw-python3 Product : Fedora 35 Version : 3.10.4 Release : 1.fc35 URL : https://www.python.org/ Summary : MinGW Windows python3 Description : MinGW Windows python3 library. --------------------------------------------------------------------------------Update Information: Update to gdal-3.3.3 and python-3.10.4. --------------------------------------------------------------------------------ChangeLog: * Mon Mar 28 2022 Sandro Mani - 3.10.4-1 - Update to 3.10.4 * Fri Mar 25 2022 Sandro Mani - 3.10.3-2 - Rebuild with mingw-gcc-12 * Sun Mar 20 2022 Sandro Mani - 3.10.3-1 - Update to 3.10.3 * Mon Feb 28 2022 Sandro Mani - 3.10.2-14 - Re-add wrapper scripts under mingw host bin dir * Sun Feb 27 2022 Sandro Mani - 3.10.2-13 - Require python%{py_ver} rather than python(abi) = %{py_ver} * Wed Feb 23 2022 Sandro Mani - 3.10.2-12 - Rework macros * Thu Feb 17 2022 Sandro Mani - 3.10.2-11 - Rebuild (openssl) * Fri Feb 11 2022 Sandro Mani - 3.10.2-10 - Override runtime_library_dir_option in distutils Mingw32Compiler to prevent unsupported -Wl,--enable-new-dtags getting added to ldflags * Thu Feb 10 2022 Sandro Mani - 3.10.2-9 - Rebuild for new python dependency generator (take two) * Thu Feb 10 2022 Sandro Mani - 3.10.2-8 - Bump release * Thu Feb 10 2022 Sandro Mani - 3.10.2-7 - Add missing dependency generator namespace for provides * Thu Feb 10 2022 Sandro Mani - 3.10.2-6 - Rebuild for new python dependency generator * Thu Feb 10 2022 Sandro Mani - 3.10.2-5 - Install dependency generators * Sat Jan 22 2022 Sandro Mani - 3.10.2-4 - Also set CFLAGS/CXX/CXXFLAGS/LDFLAGS in mingw-python wrappers * Fri Jan 21 2022 Tom Stellard -3.10.2-3 - Build fix for https://fedoraproject.org/wiki/Changes/SetBuildFlagsBuildCheck * Thu Jan 20 2022 Fedora Release Engineering - 3.10.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild * Tue Jan 18 2022 Sandro Mani - 3.10.2-1 - Update to 3.10.2 --------------------------------------------------------------------------------References: [ 1 ] Bug #2049069 - CVE-2021-45943 gdal: heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2049069 [ 2 ] Bug #2049070 - CVE-2021-45943 mingw-gdal: gdal: heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2049070 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-e85e37206b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora 35 introduces an updated mingw-python3 with gdal-3.3.3 and python-3.10.4, addressing a buffer overflow issue and improvingsecurity and stability. Users should upgrade. mingw-python3 Fedora 35 gdal buffer overflow. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 05, 2022 Critical Fedora
89

Ubuntu 22.04: 2023-a12b45678c Critical: libxml2 Memory Leak

Update to gdal-3.3.3 and python-3.10.4.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-e85e37206b 2022-04-05 15:42:46.531282 --------------------------------------------------------------------------------Name : gdal Product : Fedora 35 Version : 3.3.3 Release : 1.fc35 URL : https://gdal.org/en/latest/ Summary : GIS file format library Description : Geospatial Data Abstraction Library (GDAL/OGR) is a cross platform C++ translator library for raster and vector geospatial data formats. As a library, it presents a single abstract data model to the calling application for all supported formats. It also comes with a variety of useful commandline utilities for data translation and processing. It provides the primary data access engine for many applications. GDAL/OGR is the most widely used geospatial data access library. --------------------------------------------------------------------------------Update Information: Update to gdal-3.3.3 and python-3.10.4. --------------------------------------------------------------------------------ChangeLog: * Fri Feb 4 2022 Sandro Mani - 3.3.3-1 - Update to 3.3.3 * Fri Feb 4 2022 Sandro Mani - 3.3.2-2 - Backport patch for CVE-2021-45943 --------------------------------------------------------------------------------References: [ 1 ] Bug #2049069 - CVE-2021-45943 gdal: heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2049069 [ 2 ] Bug #2049070 - CVE-2021-45943 mingw-gdal: gdal: heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2049070 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-e85e37206b' at the command line. For moreinformation, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora 36 patches for GDAL and Python unveiled to tackle concerns and boost capabilities with the newest advancements.. gdal update,Fedora security,geospatial data library,software update,python improvements. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 05, 2022 Critical Fedora
197

Debian 9: DLA-2877-1 Important Announce: gdal DoS Vulnerability

Two issues were found in GDAL, a geospatial library, that could lead to denial of service via application crash or possibly the execution of arbitrary code if maliciously crafted data was parsed. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2877-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort January 12, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : gdal Version : 2.1.2+dfsg-5+deb9u1 CVE ID : CVE-2019-17545 CVE-2021-45943 Two issues were found in GDAL, a geospatial library, that could lead to denial of service via application crash or possibly the execution of arbitrary code if maliciously crafted data was parsed. For Debian 9 stretch, these problems have been fixed in version 2.1.2+dfsg-5+deb9u1. We recommend that you upgrade your gdal packages. For the detailed security status of gdal please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/gdal Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A pair of significant vulnerabilities within the GDAL library have been addressed by Debian LTS to avert system crashes and mitigate potential code execution threats.. Debian LTS, GDAL Security Update, Denial of Service Issues. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 12, 2022 Important Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here