Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
202

openSUSE 15.6 glib2 Important Buffer Overflow and Heap Access Patch

An update that solves three vulnerabilities can now be installed.. # Security update for glib2 Announcement ID: SUSE-SU-2026:0373-1 Release Date: 2026-02-04T02:50:53Z Rating: important References: * bsc#1257353 * bsc#1257354 * bsc#1257355 Cross-References: * CVE-2026-1484 * CVE-2026-1485 * CVE-2026-1489 CVSS scores: * CVE-2026-1484 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-1484 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-1484 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-1485 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-1485 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-1485 ( NVD ): 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L * CVE-2026-1489 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-1489 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-1489 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2026-1485: Fixed buffer underflow and out-of-bounds access due to integer wraparound in content type parsing (bsc#1257354). * CVE-2026-1484: Fixed buffer underflow and out-of-bounds access due to miscalculated buffer boundaries in the Base64 encoding routine (bsc#1257355). * CVE-2026-1489: Fixed undersized heap allocation followed by out-of-bounds access due to integer overflow in Unicode case conversion (bsc#1257353). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-373=1 openSUSE-SLE-15.6-2026-373=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-373=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-373=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-373=1 ## Package List: * openSUSE Leap 15.6 (noarch) * gio-branding-upstream-2.78.6-150600.4.35.1 * glib2-lang-2.78.6-150600.4.35.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * glib2-tools-2.78.6-150600.4.35.1 * glib2-tests-devel-2.78.6-150600.4.35.1 * libgio-2_0-0-debuginfo-2.78.6-150600.4.35.1 * libgmodule-2_0-0-debuginfo-2.78.6-150600.4.35.1 * libgthread-2_0-0-debuginfo-2.78.6-150600.4.35.1 * libgobject-2_0-0-debuginfo-2.78.6-150600.4.35.1 * libgio-2_0-0-2.78.6-150600.4.35.1 * libgmodule-2_0-0-2.78.6-150600.4.35.1 * libgobject-2_0-0-2.78.6-150600.4.35.1 * libgthread-2_0-0-2.78.6-150600.4.35.1 * glib2-doc-2.78.6-150600.4.35.1 * libglib-2_0-0-2.78.6-150600.4.35.1 * glib2-devel-static-2.78.6-150600.4.35.1 * glib2-devel-2.78.6-150600.4.35.1 * libglib-2_0-0-debuginfo-2.78.6-150600.4.35.1 * glib2-tools-debuginfo-2.78.6-150600.4.35.1 * glib2-tests-devel-debuginfo-2.78.6-150600.4.35.1 * glib2-devel-debuginfo-2.78.6-150600.4.35.1 * glib2-debugsource-2.78.6-150600.4.35.1 * openSUSE Leap 15.6 (x86_64) * libglib-2_0-0-32bit-2.78.6-150600.4.35.1 * libgmodule-2_0-0-32bit-debuginfo-2.78.6-150600.4.35.1 * libgthread-2_0-0-32bit-2.78.6-150600.4.35.1 * libglib-2_0-0-32bit-debuginfo-2.78.6-150600.4.35.1 * libgmodule-2_0-0-32bit-2.78.6-150600.4.35.1 * glib2-devel-32bit-2.78.6-150600.4.35.1 * libgio-2_0-0-32bit-2.78.6-150600.4.35.1 * glib2-tools-32bit-debuginfo-2.78.6-150600.4.35.1 * libgobject-2_0-0-32bit-2.78.6-150600.4.35.1 * libgobject-2_0-0-32bit-debuginfo-2.78.6-150600.4.35.1 * glib2-tools-32bit-2.78.6-150600.4.35.1 * glib2-devel-32bit-debuginfo-2.78.6-150600.4.35.1 * libgio-2_0-0-32bit-debuginfo-2.78.6-150600.4.35.1 * libgthread-2_0-0-32bit-debuginfo-2.78.6-150600.4.35.1 * openSUSE Leap 15.6 (aarch64_ilp32) * glib2-tools-64bit-2.78.6-150600.4.35.1 * libgmodule-2_0-0-64bit-debuginfo-2.78.6-150600.4.35.1 * libgobject-2_0-0-64bit-2.78.6-150600.4.35.1 * libgio-2_0-0-64bit-2.78.6-150600.4.35.1 * glib2-tools-64bit-debuginfo-2.78.6-150600.4.35.1 * libgthread-2_0-0-64bit-2.78.6-150600.4.35.1 * glib2-devel-64bit-debuginfo-2.78.6-150600.4.35.1 * glib2-devel-64bit-2.78.6-150600.4.35.1 * libgio-2_0-0-64bit-debuginfo-2.78.6-150600.4.35.1 * libglib-2_0-0-64bit-2.78.6-150600.4.35.1 * libgobject-2_0-0-64bit-debuginfo-2.78.6-150600.4.35.1 * libgthread-2_0-0-64bit-debuginfo-2.78.6-150600.4.35.1 * libglib-2_0-0-64bit-debuginfo-2.78.6-150600.4.35.1 * libgmodule-2_0-0-64bit-2.78.6-150600.4.35.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * glib2-tools-2.78.6-150600.4.35.1 * libgio-2_0-0-debuginfo-2.78.6-150600.4.35.1 * libgmodule-2_0-0-debuginfo-2.78.6-150600.4.35.1 * libgthread-2_0-0-debuginfo-2.78.6-150600.4.35.1 * libgobject-2_0-0-debuginfo-2.78.6-150600.4.35.1 * libgio-2_0-0-2.78.6-150600.4.35.1 * libgmodule-2_0-0-2.78.6-150600.4.35.1 * libgobject-2_0-0-2.78.6-150600.4.35.1 * libgthread-2_0-0-2.78.6-150600.4.35.1 * libglib-2_0-0-2.78.6-150600.4.35.1 * glib2-devel-2.78.6-150600.4.35.1 * glib2-tools-debuginfo-2.78.6-150600.4.35.1 * libglib-2_0-0-debuginfo-2.78.6-150600.4.35.1 * glib2-devel-debuginfo-2.78.6-150600.4.35.1 *glib2-debugsource-2.78.6-150600.4.35.1 * Basesystem Module 15-SP7 (noarch) * glib2-lang-2.78.6-150600.4.35.1 * Basesystem Module 15-SP7 (x86_64) * libglib-2_0-0-32bit-2.78.6-150600.4.35.1 * libgmodule-2_0-0-32bit-debuginfo-2.78.6-150600.4.35.1 * libglib-2_0-0-32bit-debuginfo-2.78.6-150600.4.35.1 * libgmodule-2_0-0-32bit-2.78.6-150600.4.35.1 * libgio-2_0-0-32bit-2.78.6-150600.4.35.1 * libgobject-2_0-0-32bit-2.78.6-150600.4.35.1 * libgobject-2_0-0-32bit-debuginfo-2.78.6-150600.4.35.1 * libgio-2_0-0-32bit-debuginfo-2.78.6-150600.4.35.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * glib2-tools-2.78.6-150600.4.35.1 * libgio-2_0-0-debuginfo-2.78.6-150600.4.35.1 * libgmodule-2_0-0-debuginfo-2.78.6-150600.4.35.1 * libgthread-2_0-0-debuginfo-2.78.6-150600.4.35.1 * libgobject-2_0-0-debuginfo-2.78.6-150600.4.35.1 * libgio-2_0-0-2.78.6-150600.4.35.1 * libgmodule-2_0-0-2.78.6-150600.4.35.1 * libgobject-2_0-0-2.78.6-150600.4.35.1 * libgthread-2_0-0-2.78.6-150600.4.35.1 * libglib-2_0-0-2.78.6-150600.4.35.1 * glib2-devel-2.78.6-150600.4.35.1 * glib2-tools-debuginfo-2.78.6-150600.4.35.1 * libglib-2_0-0-debuginfo-2.78.6-150600.4.35.1 * glib2-devel-debuginfo-2.78.6-150600.4.35.1 * glib2-debugsource-2.78.6-150600.4.35.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * glib2-lang-2.78.6-150600.4.35.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libglib-2_0-0-32bit-2.78.6-150600.4.35.1 * libgmodule-2_0-0-32bit-debuginfo-2.78.6-150600.4.35.1 * libglib-2_0-0-32bit-debuginfo-2.78.6-150600.4.35.1 * libgmodule-2_0-0-32bit-2.78.6-150600.4.35.1 * libgio-2_0-0-32bit-2.78.6-150600.4.35.1 * libgobject-2_0-0-32bit-2.78.6-150600.4.35.1 * libgobject-2_0-0-32bit-debuginfo-2.78.6-150600.4.35.1 * libgio-2_0-0-32bit-debuginfo-2.78.6-150600.4.35.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * glib2-tools-2.78.6-150600.4.35.1 *libgio-2_0-0-debuginfo-2.78.6-150600.4.35.1 * libgmodule-2_0-0-debuginfo-2.78.6-150600.4.35.1 * libgthread-2_0-0-debuginfo-2.78.6-150600.4.35.1 * libgobject-2_0-0-debuginfo-2.78.6-150600.4.35.1 * libgio-2_0-0-2.78.6-150600.4.35.1 * libgmodule-2_0-0-2.78.6-150600.4.35.1 * libgobject-2_0-0-2.78.6-150600.4.35.1 * libgthread-2_0-0-2.78.6-150600.4.35.1 * libglib-2_0-0-2.78.6-150600.4.35.1 * glib2-devel-2.78.6-150600.4.35.1 * glib2-tools-debuginfo-2.78.6-150600.4.35.1 * libglib-2_0-0-debuginfo-2.78.6-150600.4.35.1 * glib2-devel-debuginfo-2.78.6-150600.4.35.1 * glib2-debugsource-2.78.6-150600.4.35.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * glib2-lang-2.78.6-150600.4.35.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libglib-2_0-0-32bit-2.78.6-150600.4.35.1 * libgmodule-2_0-0-32bit-debuginfo-2.78.6-150600.4.35.1 * libglib-2_0-0-32bit-debuginfo-2.78.6-150600.4.35.1 * libgmodule-2_0-0-32bit-2.78.6-150600.4.35.1 * libgio-2_0-0-32bit-2.78.6-150600.4.35.1 * libgobject-2_0-0-32bit-2.78.6-150600.4.35.1 * libgobject-2_0-0-32bit-debuginfo-2.78.6-150600.4.35.1 * libgio-2_0-0-32bit-debuginfo-2.78.6-150600.4.35.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1484.html * https://www.suse.com/security/cve/CVE-2026-1485.html * https://www.suse.com/security/cve/CVE-2026-1489.html * https://bugzilla.suse.com/show_bug.cgi?id=1257353 * https://bugzilla.suse.com/show_bug.cgi?id=1257354 * https://bugzilla.suse.com/show_bug.cgi?id=1257355 . An important update for openSUSE addressing three vulnerabilities in glib2, includes crucial fixes and recommendations.. SUSE Update, glib2 Patch, OpenSUSE Vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 04, 2026 Important OpenSUSE
89

Fedora 38: FEDORA-2024-07597a0fb3 Critical: Glibc Buffer Overflow

Security fix for CVE-2023-6246, CVE-2023-6779, and CVE-2023-6780. CVE-2023-6246: __vsyslog_internal did not handle a case where printing a SYSLOG_HEADER containing a long program name failed to update the required buffer size, leading to the allocation and overflow of a too-small buffer on the heap. CVE-2023-6779: __vsyslog_internal used the return value of. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-07597a0fb3 2024-02-01 01:23:37.270537 -------------------------------------------------------------------------------- Name : glibc Product : Fedora 38 Version : 2.37 Release : 18.fc38 URL : Summary : The GNU libc libraries Description : The glibc package contains standard libraries which are used by multiple programs on the system. In order to save disk space and memory, as well as to make upgrading easier, common system code is kept in one place and shared between programs. This particular package contains the most important sets of shared libraries: the standard C library and the standard math library. Without these two libraries, a Linux system will not function. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-6246, CVE-2023-6779, and CVE-2023-6780. CVE-2023-6246: __vsyslog_internal did not handle a case where printing a SYSLOG_HEADER containing a long program name failed to update the required buffer size, leading to the allocation and overflow of a too-small buffer on the heap. CVE-2023-6779: __vsyslog_internal used the return value of snprintf/vsnprintf to calculate buffer sizes for memory allocation. If these functions (for any reason) failed and returned -1, the resulting buffer would be too small to hold output. CVE-2023-6780: __vsyslog_internal calculated a buffer size by adding two integers, but did not first check if the additionwould overflow. -------------------------------------------------------------------------------- ChangeLog: * Tue Jan 30 2024 Patsy Griffin - 2.37-18 - Auto-sync with upstream branch release/2.37/master, commit 2b58cba076e912961ceaa5fa58588e4b10f791c0: - syslog: Fix integer overflow in __vsyslog_internal (CVE-2023-6780) - syslog: Fix heap buffer overflow in __vsyslog_internal (CVE-2023-6779) - syslog: Fix heap buffer overflow in __vsyslog_internal (CVE-2023-6246) - sunrpc: Fix netname build with older gcc * Mon Jan 29 2024 Arjun Shankar - 2.37-17 - Auto-sync with upstream branch release/2.37/master, commit bd9f194c34333c0148fc0a793b8e68e2399f27cb: - libio: Check remaining buffer size in _IO_wdo_write (bug 31183) - getaddrinfo: translate ENOMEM to EAI_MEMORY (bug 31163) - NEWS: Mention bug fixes for 29039/30745/30843 - x86-64: Fix the tcb field load for x32 [BZ #31185] - x86-64: Fix the dtv field load for x32 [BZ #31184] - elf: Fix TLS modid reuse generation assignment (BZ 29039) - elf: Fix wrong break removal from 8ee878592c -------------------------------------------------------------------------------- References: [ 1 ] Bug #2249053 - CVE-2023-6246 glibc: heap-based buffer overflow in __vsyslog_internal() https://bugzilla.redhat.com/show_bug.cgi?id=2249053 [ 2 ] Bug #2254395 - CVE-2023-6779 glibc: off-by-one heap-based buffer overflow in __vsyslog_internal() https://bugzilla.redhat.com/show_bug.cgi?id=2254395 [ 3 ] Bug #2254396 - CVE-2023-6780 glibc: integer overflow in __vsyslog_internal() https://bugzilla.redhat.com/show_bug.cgi?id=2254396 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-07597a0fb3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key.More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . A significant security patch for glibc resolves several critical buffer overflow vulnerabilities affecting Fedora 38 installations.. glibc Security Update, Buffer Overflow Fix, Fedora Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 01, 2024 Critical Fedora
203

Mageia 7: 2020-0196 Moderate: Exiv2 DoS via WEBP Image Exploit

The updated packages fix a security vulnerability: A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file. . MGASA-2020-0196 - Updated exiv2 packages fix security vulnerability Publication date: 05 May 2020 URL: https://advisories.mageia.org/MGASA-2020-0196.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-13111 The updated packages fix a security vulnerability: A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file. (CVE-2019-13111) References: - https://bugs.mageia.org/show_bug.cgi?id=26561 - https://access.redhat.com/errata/RHSA-2020:1577 - https://www.cve.org/CVERecord?id=CVE-2019-13111 SRPMS: - 7/core/exiv2-0.27.1-3.4.mga7 . Newly released updates fix a critical vulnerability in Exiv2, which can cause Denial of Service when processing specially crafted WEBP images, impacting Mageia 7.. Exiv2 Security Fix, WEBP Image Vulnerability, Mageia Update. . LinuxSecurity.com Team

Calendar 2 May 05, 2020 Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here