Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 40 articles for you...
100

SUSE python-Django Moderate Info Disclosure Vulnern 2026-2819-1

An update that solves two vulnerabilities can now be installed.. # Security update for python-Django Announcement ID: SUSE-SU-2026:2819-1 Release Date: 2026-07-09T17:12:22Z Rating: moderate References: * bsc#1271029 * bsc#1271030 Cross-References: * CVE-2026-48588 * CVE-2026-53877 CVSS scores: * CVE-2026-48588 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48588 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-48588 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-48588 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-53877 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53877 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-53877 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-Django fixes the following issues: * CVE-2026-48588: potential exposure of private data via cached `Set-Cookie` response (bsc#1271029). * CVE-2026-53877: information disclosure via 32-byte heap buffer overread in `GDALRaster` (bsc#1271030). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patchSUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2819=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2819=1 ## Package List: * SUSE Package Hub 15 15-SP7 (noarch) * python311-Django-4.2.11-150600.3.62.1 * openSUSE Leap 15.6 (noarch) * python311-Django-4.2.11-150600.3.62.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48588.html * https://www.suse.com/security/cve/CVE-2026-53877.html * https://bugzilla.suse.com/show_bug.cgi?id=1271029 * https://bugzilla.suse.com/show_bug.cgi?id=1271030 . SUSE releases a moderate security update for python-Django addressing issues and providing patch instructions.. python-Django security issues, SUSE update, security patch instructions, information disclosure, heap buffer overread. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 10, 2026 moderate SuSE
99

Slackware 15.0 libXfont2 Critical Heap Overflow Fix 2026-189-01

New libXfont2 packages are available for Slackware 15.0 and -current to fix security issues.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] libXfont2 (SSA:2026-189-01) New libXfont2 packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/libXfont2-2.0.8-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow. PCF Font Parsing Heap Buffer Overflow. computeProps Property Buffer Heap Buffer Overflow. For more information, see: https://lists.x.org/archives/xorg/2026-July/062253.html https://www.cve.org/CVERecord?id=CVE-2026-56001 https://www.cve.org/CVERecord?id=CVE-2026-56002 https://www.cve.org/CVERecord?id=CVE-2026-56003 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://slackware.com for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libXfont2-2.0.8-i586-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/libXfont2-2.0.8-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/x/libXfont2-2.0.8-i686-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/x/libXfont2-2.0.8-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: 15a36c81b360d94bc803b65560d94934 libXfont2-2.0.8-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 11450cfb5cfb79181d49bcd02cc81554 libXfont2-2.0.8-x86_64-1_slack15.0.txz Slackware -current package: a4aa589efa9b9571fcbe729d0c97c524 x/libXfont2-2.0.8-i686-1.txz Slackware x86_64 -current package: 719ba3cd0d28b303f6b78d16195ad879 x/libXfont2-2.0.8-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg libXfont2-2.0.8-i586-1_slack15.0.txz +-----+ . New libXfont2 packages for Slackware address critical heap buffer overflows related to font parsing and more.. Slackware libXfont2 heap overflow upgrade buffer. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 08, 2026 Critical Slackware
219

Rocky Linux 9 Coreutils Moderate Heap Buffer Issue RLSA-2026-28911

Moderate: coreutils security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:28911", "synopsis": "Moderate: coreutils security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for coreutils.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The coreutils packages contain the GNU Core Utilities and represent a combination of the previously used GNU fileutils, sh-utils, and textutils packages.\n\nSecurity Fix(es):\n\n* coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification (CVE-2025-5278)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2368764", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2368764", "description": ""}], "cves": [{"name": "CVE-2025-5278", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5278", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L", "cvss3BaseScore": "4.4", "cwe": "CWE-121"}], "references": [], "publishedAt": "2026-06-25T12:03:43.452279Z", "rpms": {"Rocky Linux 9": {"nvras": ["coreutils-0:8.32-41.el9_8.aarch64.rpm", "coreutils-0:8.32-41.el9_8.ppc64le.rpm", "coreutils-0:8.32-41.el9_8.s390x.rpm", "coreutils-0:8.32-41.el9_8.src.rpm", "coreutils-0:8.32-41.el9_8.x86_64.rpm", "coreutils-common-0:8.32-41.el9_8.aarch64.rpm", "coreutils-common-0:8.32-41.el9_8.ppc64le.rpm", "coreutils-common-0:8.32-41.el9_8.s390x.rpm", "coreutils-common-0:8.32-41.el9_8.x86_64.rpm", "coreutils-debuginfo-0:8.32-41.el9_8.aarch64.rpm", "coreutils-debuginfo-0:8.32-41.el9_8.ppc64le.rpm", "coreutils-debuginfo-0:8.32-41.el9_8.s390x.rpm","coreutils-debuginfo-0:8.32-41.el9_8.x86_64.rpm", "coreutils-debugsource-0:8.32-41.el9_8.aarch64.rpm", "coreutils-debugsource-0:8.32-41.el9_8.ppc64le.rpm", "coreutils-debugsource-0:8.32-41.el9_8.s390x.rpm", "coreutils-debugsource-0:8.32-41.el9_8.x86_64.rpm", "coreutils-single-0:8.32-41.el9_8.aarch64.rpm", "coreutils-single-0:8.32-41.el9_8.ppc64le.rpm", "coreutils-single-0:8.32-41.el9_8.s390x.rpm", "coreutils-single-0:8.32-41.el9_8.x86_64.rpm", "coreutils-single-debuginfo-0:8.32-41.el9_8.aarch64.rpm", "coreutils-single-debuginfo-0:8.32-41.el9_8.ppc64le.rpm", "coreutils-single-debuginfo-0:8.32-41.el9_8.s390x.rpm", "coreutils-single-debuginfo-0:8.32-41.el9_8.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A moderate coreutils security fix is available for Rocky Linux 9, addressing heap buffer issues in GNU Core Utilities.. Rocky Linux Core Utilities Security Fix Heap Buffer. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 25, 2026 moderate Rocky Linux
89

Fedora 44 Chromium Critical Use After Free Heap Issues 2026-c758d44a9a

Update to 148.0.7778.178 CVE-2026-9111: Use after free in WebRTC CVE-2026-9110: Inappropriate implementation in UI CVE-2026-9112: Use after free in GPU CVE-2026-9113: Out of bounds read in GPU. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-c758d44a9a 2026-05-23 00:56:16.173372+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 44 Version : 148.0.7778.178 Release : 1.fc44 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 148.0.7778.178 CVE-2026-9111: Use after free in WebRTC CVE-2026-9110: Inappropriate implementation in UI CVE-2026-9112: Use after free in GPU CVE-2026-9113: Out of bounds read in GPU CVE-2026-9114: Use after free in QUIC CVE-2026-9115: Insufficient policy enforcement in Service Worker CVE-2026-9116: Insufficient policy enforcement in ServiceWorker CVE-2026-9117: Type Confusion in GFX CVE-2026-9118: Use after free in XR CVE-2026-9119: Heap buffer overflow in WebRTC CVE-2026-9120: Use after free in WebRTC CVE-2026-9126: Use after free in DOM CVE-2026-9121: Out of bounds read in GPU CVE-2026-9122: Out of bounds read in GPU CVE-2026-9123: Heap buffer overflow in Chromecast CVE-2026-9124: Insufficient validation of untrusted input in Input -------------------------------------------------------------------------------- ChangeLog: * Wed May 20 2026 Than Ngo - 148.0.7778.178-1 - Update to 148.0.7778.178 - Backport upstream patches to improve auto dark image inversion logic - Update default chromium browser config * Fri May 15 2026 Than Ngo - 148.0.7778.167-1 - Update to 148.0.7778.167 * CVE-2026-8509: Heap buffer overflowin WebML * CVE-2026-8510: Integer overflow in Skia * CVE-2026-8511: Use after free in UI * CVE-2026-8512: Use after free in FileSystem * CVE-2026-8513: Use after free in Input * CVE-2026-8514: Use after free in Aura * CVE-2026-8515: Use after free in HID * CVE-2026-8516: Insufficient validation of untrusted input in DataTransfer * CVE-2026-8517: Object lifecycle issue in WebShare * CVE-2026-8518: Use after free in Blink * CVE-2026-8519: Integer overflow in ANGLE * CVE-2026-8520: Race in Payments * CVE-2026-8521: Use after free in Tab Groups * CVE-2026-8522: Use after free in Downloads * CVE-2026-8523: Use after free in Mojo * CVE-2026-8558: Out of bounds write in Fonts * CVE-2026-8524: Out of bounds write in WebAudio * CVE-2026-8525: Heap buffer overflow in ANGLE * CVE-2026-8526: Out of bounds write in WebRTC * CVE-2026-8527: Insufficient validation of untrusted input in Downloads * CVE-2026-8528: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8529: Heap buffer overflow in Codecs * CVE-2026-8530: Use after free in Network * CVE-2026-8531: Heap buffer overflow in WebML * CVE-2026-8532: Integer overflow in XML * CVE-2026-8533: Use after free in Accessibility * CVE-2026-8534: Integer overflow in GPU * CVE-2026-8535: Out of bounds read in Media * CVE-2026-8536: Insufficient validation of untrusted input in ReadingMode * CVE-2026-8537: Insufficient policy enforcement in ViewTransitions * CVE-2026-8538: Insufficient validation of untrusted input in GPU * CVE-2026-8539: Script injection in SanitizerAPI * CVE-2026-8540: Type Confusion in V8 * CVE-2026-8541: Out of bounds read in UI * CVE-2026-8542: Use after free in Core * CVE-2026-8543: Out of bounds read in FileSystem * CVE-2026-8544: Use after free in Media * CVE-2026-8545: Object corruption in Compositing * CVE-2026-8546: Out of bounds read in GPU * CVE-2026-8547: Insufficient policyenforcement in Passwords * CVE-2026-8548: Out of bounds write in Media * CVE-2026-8549: Use after free in Media * CVE-2026-8550: Use after free in Google Lens * CVE-2026-8551: Use after free in Downloads * CVE-2026-8552: Heap buffer overflow in GPU * CVE-2026-8553: Use after free in GPU * CVE-2026-8554: Type Confusion in ANGLE * CVE-2026-8555: Use after free in GTK * CVE-2026-8556: Inappropriate implementation in ANGLE * CVE-2026-8557: Use after free in Accessibility * CVE-2026-8559: Integer overflow in Internationalization * CVE-2026-8560: Heap buffer overflow in SwiftShader * CVE-2026-8561: Incorrect security UI in Fullscreen * CVE-2026-8562: Side-channel information leakage in Navigation * CVE-2026-8563: Insufficient policy enforcement in IFrame Sandbox * CVE-2026-8564: Incorrect security UI in Downloads * CVE-2026-8565: Inappropriate implementation in Downloads * CVE-2026-8566: Insufficient policy enforcement in Payments * CVE-2026-8567: Integer overflow in ANGLE * CVE-2026-8568: Insufficient policy enforcement in AI * CVE-2026-8569: Out of bounds write in Codecs * CVE-2026-8570: Type Confusion in V8 * CVE-2026-8571: Insufficient policy enforcement in GPU * CVE-2026-8572: Insufficient policy enforcement in Network * CVE-2026-8573: Integer overflow in Codecs * CVE-2026-8574: Use after free in Core * CVE-2026-8575: Use after free in UI * CVE-2026-8576: Inappropriate implementation in CORS * CVE-2026-8577: Integer overflow in Fonts * CVE-2026-8578: Out of bounds read in GPU * CVE-2026-8579: Insufficient validation of untrusted input in Skia * CVE-2026-8580: Use after free in Mojo * CVE-2026-8581: Use after free in GPU * CVE-2026-8582: Object lifecycle issue in Dawn * CVE-2026-8583: Insufficient policy enforcement in WebXR * CVE-2026-8584: Inappropriate implementation in Views * CVE-2026-8585: Inappropriate implementation in Media * CVE-2026-8586: Inappropriateimplementation in Chromoting * CVE-2026-8587: Use after free in Extensions -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-c758d44a9a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update for Fedora 44 Chromium addresses multiple critical issues including use after free and heap buffer overflows.. Fedora Update, Chromium Security, Use After Free, Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 23, 2026 Critical Fedora
172

Ubuntu 24.04 LTS NASM Security Advisory USN-8248-2 CVE-2023-31722

USN-8248-1 introduced a regression in NASM. ========================================================================== Ubuntu Security Notice USN-8248-2 May 08, 2026 nasm regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: USN-8248-1 introduced a regression in NASM Software Description: - nasm: Netwide Assembler Details: USN-8248-1 fixed vulnerabilities in NASM. Unfortunately the update introduced a regression which could cause NASM to crash. This update fixes the problem by reverting the fix for CVE-2021-33450 and CVE-2021-33452 in Ubuntu 24.04 LTS. We apologize for the inconvenience. Original advisory details: Daisy Chen discovered that NASM was vulnerable to a heap buffer overflow when handling certain input. An attacker could possibly use this issue to cause NASM to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-31722) It was discovered that NASM incorrectly handled memory allocation. An attacker could possibly use this issue to cause NASM to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 24.04 LTS. (CVE-2021-33452, CVE-2021-33450) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS nasm 2.16.01-1ubuntu0.1~esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8248-2 https://ubuntu.com/security/notices/USN-8248-1 CVE-2021-33450, CVE-2021-33452, https://launchpad.net/bugs/2151861 . Update addresses regression in NASM due to previous patches, ensuring stability on Ubuntu 24.04 LTS.. nasm Ubuntu 24.04 LTS security fix denial of service regression. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 08, 2026 Important Ubuntu
202

openSUSE Leap 16.0 util-linux Moderate Access Control Heap Buffer Issue

An update that solves 2 vulnerabilities and has 3 bug fixes can now be installed.. openSUSE security update: security update for util-linux ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20495-1 Rating: moderate References: * bsc#1222465 * bsc#1254666 * bsc#1258859 Cross-References: * CVE-2025-14104 * CVE-2026-3184 CVSS scores: * CVE-2025-14104 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2025-14104 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3184 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-3184 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 3 bug fixes can now be installed. Description: This update for util-linux fixes the following issues: Security issues: - CVE-2025-14104: heap buffer overread in setpwnam() when processing 256-byte usernames (bsc#1254666). - CVE-2026-3184: access control bypass due to improper hostname canonicalization in `login` (bsc#1258859). Non security issues: - fdisk: Fix possible partition overlay and data corruption if EBR gap is missing (bsc#1222465). - lscpu: Add support for NVIDIA Olympus arm64 core (jsc#PED-13682). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-510=1 Package List: - openSUSE Leap 16.0: lastlog2-2.41.1-160000.3.1 libblkid-devel-2.41.1-160000.3.1 libblkid-devel-static-2.41.1-160000.3.1 libblkid1-2.41.1-160000.3.1 libfdisk-devel-2.41.1-160000.3.1 libfdisk-devel-static-2.41.1-160000.3.1 libfdisk1-2.41.1-160000.3.1 liblastlog2-2-2.41.1-160000.3.1 liblastlog2-devel-2.41.1-160000.3.1 libmount-devel-2.41.1-160000.3.1 libmount-devel-static-2.41.1-160000.3.1 libmount1-2.41.1-160000.3.1 libsmartcols-devel-2.41.1-160000.3.1 libsmartcols-devel-static-2.41.1-160000.3.1 libsmartcols1-2.41.1-160000.3.1 libuuid-devel-2.41.1-160000.3.1 libuuid-devel-static-2.41.1-160000.3.1 libuuid1-2.41.1-160000.3.1 python313-libmount-2.41.1-160000.3.1 util-linux-2.41.1-160000.3.1 util-linux-extra-2.41.1-160000.3.1 util-linux-lang-2.41.1-160000.3.1 util-linux-systemd-2.41.1-160000.3.1 util-linux-tty-tools-2.41.1-160000.3.1 uuidd-2.41.1-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2025-14104.html * https://www.suse.com/security/cve/CVE-2026-3184.html . This update resolves 2 vulnerabilities in util-linux for openSUSE, addressing security and bug issues. Immediate installation recommended.. util-linux update, openSUSE vulnerabilities, access control exploit, moderate severity patch. . LinuxSecurity.com Team

Calendar%202 Apr 21, 2026 OpenSUSE
89

Fedora 43 vtk Critical Integer Overflow Fix KissFFT 2026-55f82da186

Add patch to fix integer overflow on 32-bit in KissFFT (CVE-2025-34297). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-55f82da186 2026-03-27 01:16:52.247545+00:00 -------------------------------------------------------------------------------- Name : vtk Product : Fedora 43 Version : 9.2.6 Release : 44.fc43 URL : https://vtk.org/ Summary : The Visualization Toolkit - A high level 3D visualization library Description : VTK is an open-source software system for image processing, 3D graphics, volume rendering and visualization. VTK includes many advanced algorithms (e.g., surface reconstruction, implicit modeling, decimation) and rendering techniques (e.g., hardware-accelerated volume rendering, LOD control). NOTE: The version in this package has NOT been compiled with MPI support. Install the vtk-mpich package to get a version compiled with mpich. -------------------------------------------------------------------------------- Update Information: Add patch to fix integer overflow on 32-bit in KissFFT (CVE-2025-34297) -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 17 2026 Orion Poplawski - 9.2.6-44 - Add patch to fix integer overflow on 32-bit in KissFFT (CVE-2025-34297) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2418144 - CVE-2025-34297 vtk: KissFFT Integer Overflow Heap Buffer Overflow via kiss_fft_alloc [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2418144 [ 2 ] Bug #2418147 - CVE-2025-34297 vtk: KissFFT Integer Overflow Heap Buffer Overflow via kiss_fft_alloc [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2418147 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2026-55f82da186' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . A patch is available for serious integer overflow in KissFFT on Fedora 43. Immediate action is recommended for users.. integer overflow,Fedora 43,KissFFT patch,critical security fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 27, 2026 Critical Fedora
89

Fedora 44 KISS FFT Security Fix 2025-34297 Important Integer Overflow

Update to 131.2.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-ecc754cb95 2026-03-19 00:15:36.606251+00:00 -------------------------------------------------------------------------------- Name : kiss-fft Product : Fedora 44 Version : 131.2.0 Release : 1.fc44 URL : https://github.com/mborgerding/kissfft Summary : A Fast Fourier Transform (FFT) library that tries to Keep it Simple, Stupid Description : KISS FFT - A mixed-radix Fast Fourier Transform based on the principle, "Keep It Simple, Stupid." There are many great fft libraries already around. Kiss FFT is not trying to be better than any of them. It only attempts to be a reasonably efficient, moderately useful FFT that can use fixed or floating data types and can be incorporated into someone's C program in a few minutes with trivial licensing. -------------------------------------------------------------------------------- Update Information: Update to 131.2.0 -------------------------------------------------------------------------------- ChangeLog: * Mon Mar 9 2026 Guido Aulisi - 131.2.0-1 - Update to 131.2.0 - Fix for CVE-2025-34297 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2405958 - kiss-fft-131.2.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2405958 [ 2 ] Bug #2418142 - CVE-2025-34297 kiss-fft: KissFFT Integer Overflow Heap Buffer Overflow via kiss_fft_alloc [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2418142 [ 3 ] Bug #2418145 - CVE-2025-34297 kiss-fft: KissFFT Integer Overflow Heap Buffer Overflow via kiss_fft_alloc [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2418145 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ecc754cb95' atthe command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . KISS FFT library updated in Fedora 44 with fix for integer overflow issue. Upgrade to 131.2.0 to mitigate risk.. Fedora Upgrade, KISS FFT, Buffer Overflow, Integer Overflow Risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 19, 2026 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200