Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
89

Fedora 44 ThorVG Advisory Denial Of Service Vulnerability 2026-3d1fcd4ffc

Update to 1.0.6. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3d1fcd4ffc 2026-06-23 01:06:46.785055+00:00 -------------------------------------------------------------------------------- Name : thorvg Product : Fedora 44 Version : 1.0.6 Release : 1.fc44 URL : https://www.thorvg.org/ Summary : Lightweight vector-based scenes and animation drawing library Description : ThorVG is an open-source graphics library designed for creating vector-based scenes and animations. It combines immense power with remarkable lightweight efficiency, as Thor embodies a dual meaning—symbolizing both thunderous strength and lightning-fast agility. Embracing the philosophy of simpler is better, the ThorVG project provides intuitive, user-friendly interfaces while maintaining a compact footprint and minimal overhead. The following list shows primitives that are supported by ThorVG: - Lines & Shapes: rectangles, circles, and paths with coordinate control - Filling: solid colors, linear & radial gradients, and path clipping - Stroking: stroke width, joins, caps, dash patterns, and trimming - Scene Management: retainable scene graph and object transformations - Composition: various blending and masking - Text: unicode characters with horizontal text layout using scalable fonts (TTF) - Images: SVG, JPG, PNG, WebP, and raw bitmaps - Effects: blur, drop shadow, fill, tint, tritone and color replacement - Animations: Lottie -------------------------------------------------------------------------------- Update Information: Update to 1.0.6 -------------------------------------------------------------------------------- ChangeLog: * Sun Jun 14 2026 Benson Muite - 1.0.6-1 - Update to 1.0.6 * Sat Feb 14 2026 Benson Muite - 1.0.1-1 - Update to 1.0.1 rhbz#2433764 * Sat Jan 17 2026 Fedora Release Engineering - 0.15.16-2 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2483802 - CVE-2026-45729 thorvg: ThorVG: Denial of Service via untrusted SVG data processing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2483802 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3d1fcd4ffc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . ThorVG 1.0.6 update in Fedora 44 fixes security concerns, enhancing stability and efficiency in vector graphics processing.. Fedora thorvg Denial Of Service Vector Graphics Security. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Jun 22, 2026 Informational Fedora
89

Fedora 44 perl-ExtUtils-Builder-Compiler Notice CVE-2026-8463

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-dafdad8fd3 2026-06-05 04:25:00.358941+00:00 -------------------------------------------------------------------------------- Name : perl-ExtUtils-Builder-Compiler Product : Fedora 44 Version : 0.036 Release : 1.fc44 URL : https://metacpan.org/dist/ExtUtils-Builder-Compiler Summary : Interface around different compilers Description : This is an interface wrapping around different compilers. It's usually not used directly but by a portability layer like ExtUtils::Builder::Autodetect::C. -------------------------------------------------------------------------------- Update Information: Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463 -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 22 2026 Charles R. Anderson 0.036-1 - Update to 0.036 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-dafdad8fd3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives:https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update to perl-ExtUtils-Builder-Compiler addresses CVE-2026-8463, improving security for Fedora 44 users.. perl ExtUtils Builder Compiler Fedora update CVE-2026-8463. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Jun 05, 2026 Informational Fedora
172

Ubuntu 26.04 LTS GNU SASL Informational Denial of Service CVE-2026-48829

GNU SASL could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8356-1 June 01, 2026 gsasl vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS Summary: GNU SASL could be made to crash if it received specially crafted input. Software Description: - gsasl: Simple Authentication and Security Layer framework Details: It was discovered that GNU SASL did not properly handle certain DIGEST-MD5 tokens. An attacker could possibly use this issue to cause GNU SASL to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS gsasl 2.2.2-4ubuntu1.1 libgsasl18 2.2.2-4ubuntu1.1 Ubuntu 25.10 gsasl 2.2.2-2ubuntu1.1 libgsasl18 2.2.2-2ubuntu1.1 Ubuntu 24.04 LTS gsasl 2.2.1-1willsync1ubuntu0.1 libgsasl18 2.2.1-1willsync1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8356-1 CVE-2026-48829 Package Information: https://launchpad.net/ubuntu/+source/gsasl/2.2.2-4ubuntu1.1 https://launchpad.net/ubuntu/+source/gsasl/2.2.2-2ubuntu1.1 https://launchpad.net/ubuntu/+source/gsasl/2.2.1-1willsync1ubuntu0.1 . Update for GNU SASL addresses a denial of service risk from specially crafted input in Ubuntu releases. Critical patch. . GNU SASL update, Ubuntu security patch, denial of service fix, gsasl vulnerability, information security advisory. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Jun 01, 2026 Informational Ubuntu
87

Debian DSA-6145-1 Nova Image Resize Issue CVE-2026-24708

Dan Smith discovered that nova, a cloud computing fabric controller, calls qemu-img without format restrictions for resize, which may result in unsafe image resize operations that could destroy data on the host system. Only compute nodes using the Flat image backend are affected. For the oldstable distribution (bookworm), this problem has been fixed. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6145-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso February 19, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : nova CVE ID : CVE-2026-24708 Debian Bug : 1128294 Dan Smith discovered that nova, a cloud computing fabric controller, calls qemu-img without format restrictions for resize, which may result in unsafe image resize operations that could destroy data on the host system. Only compute nodes using the Flat image backend are affected. For the oldstable distribution (bookworm), this problem has been fixed in version 2:26.2.2-1~deb12u4. For the stable distribution (trixie), this problem has been fixed in version 2:31.0.0-6+deb13u2. We recommend that you upgrade your nova packages. For the detailed security status of nova please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/nova Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Unsanctioned image resize in nova could lead to host data destruction. Upgrade recommended for Debian users to improve security.. cloud computing,nova security,debian advisory,data destruction. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Feb 19, 2026 Informational Debian
89

Fedora 42: linux-firmware Update 20260110 for Various Devices Available

Update to 20260110: update firmware for MT7925 WiFi device mediatek MT7925: update bluetooth firmware to 20260106153314 mediatek MT7920: update bluetooth firmware to 20260105151350 mediatek MT7922: update bluetooth firmware to 20260106153735. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-1d240112ff 2026-01-15 00:51:57.354759+00:00 -------------------------------------------------------------------------------- Name : linux-firmware Product : Fedora 42 Version : 20260110 Release : 1.fc42 URL : http://www.kernel.org/ Summary : Firmware files used by the Linux kernel Description : This package includes firmware files required for some devices to operate. -------------------------------------------------------------------------------- Update Information: Update to 20260110: update firmware for MT7925 WiFi device mediatek MT7925: update bluetooth firmware to 20260106153314 mediatek MT7920: update bluetooth firmware to 20260105151350 mediatek MT7922: update bluetooth firmware to 20260106153735 update firmware for MT7922 WiFi device Mellanox: Add new mlxsw_spectrum firmware xx.2016.3900 amdgpu: Update dcn314, dcn315 firmware to 0.1.42.0 qcom: Update DSP firmware for sa8775 platform QCA: Add Bluetooth firmware for QCC2072 uart interface i915: Xe3p_LPD DMC v2.33 qcom: Update DSP firmware for qcs8300 platform update firmware for MT7920 WiFi device qcom: Update aic100 firmware files qca: Update Bluetooth WCN6750 1.1.3-00100 firmware to 1.1.3-00105 firmware: Revert kernel_boot.elf due to license compliance issue add firmware for an8811hb 2.5G ethernet phy i915: Xe3LPD_3002 DMC v2.28 i915: Xe3LPD DMC v2.33 intel_vpu: Add firmware for 50xx NPUs and update older ones Update AMD SEV firmware amdgpu: DMCUB updates for various ASICs qcom: venus-5.4: fix ELF segment alignment to 4 bytes mediatek MT7925: update bluetooth firmware to 20251210093205 update firmware for MT7925 WiFidevice rcar_gen4_pcie: add firmware for Renesas R-Car Gen4 PCIe controller qcom: Update CDSP firmware for qcm6490 platform rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x488C_DB55 iwlwifi: Add firmware file for Intel Scorpius core rtw89: 8852b: update fw to v0.29.29.15 cirrus: cs35l41: Update firmware and tuning for various HP laptops cirrus: cs35l41: Add support for new HP Clipper laptop qcom: drop compatibility a640_zap.mdt symlink qcom: add version for a530v3_gpmu.fw2 xe: Update GUC to v70.55.3 for BMG, PTL iwlwifi: add Bz/Sc FW for core101-82 release iwlwifi: Add Sc/Gf firmware for core101-82 release iwlwifi: update ty/So/Ma firmwares for core101-82 release iwlwifi: update cc/Qu/QuZ firmwares for core101-82 release amdgpu: DMCUB updates for various ASICs qcom: Add firmwares for sm8150/sm8450/sm8550/sm8650/sm8750 GPUs ath10k: WCN3990 hw1.0: update board-2.bin ath10k: QCA9888 hw2.0: update board-2.bin ath10k: QCA4019 hw1.0: update board-2.bin cirrus: cs35l41: Add support for new HP laptops Revert "amdgpu: update GC 11.5.0 firmware" Update amd-ucode copyright information Update AMD cpu microcode Update firmware file for Intel Scorpius core Update firmware file for Intel BlazarIGfP core Update firmware file for Intel BlazarI core Update firmware file for Intel BlazarU-HrPGfP core Update firmware file for Intel BlazarU core ath11k: QCA6698AQ hw2.1: update to WLAN.HSP.1.1-04866-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1 ath11k: QCA2066 hw2.1: update board-2.bin qcom: update ADSP firmware for x1e80100 platform, change the license qcom: reorder ADSP, CDSP firmware entries for qcs8300 in WHENCE Reapply "amdgpu: update SMU 14.0.3 firmware" Revert "amdgpu: update SMU 14.0.3 firmware" Revert "amdgpu: update GC 10.3.6 firmware" Revert "amdgpu: update GC 11.5.1 firmware" update firmware for MT7925 WiFi device mediatek MT7925: update bluetooth firmware to 20251124093155 intel_vpu: Update NPU firmware qcom: vpu: update video firmware binary for SM8250 xe: Update GUC to v70.54.0 for BMG,PTL -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 11 2026 Peter Robinson - 20260110-1 - Update to 20260110 - update firmware for MT7925 WiFi device - mediatek MT7925: update bluetooth firmware to 20260106153314 - mediatek MT7920: update bluetooth firmware to 20260105151350 - mediatek MT7922: update bluetooth firmware to 20260106153735 - update firmware for MT7922 WiFi device - Mellanox: Add new mlxsw_spectrum firmware xx.2016.3900 - amdgpu: Update dcn314, dcn315 firmware to 0.1.42.0 - qcom: Update DSP firmware for sa8775 platform - QCA: Add Bluetooth firmware for QCC2072 uart interface - i915: Xe3p_LPD DMC v2.33 - qcom: Update DSP firmware for qcs8300 platform - update firmware for MT7920 WiFi device - qcom: Update aic100 firmware files - qca: Update Bluetooth WCN6750 1.1.3-00100 firmware to 1.1.3-00105 - firmware: Revert kernel_boot.elf due to license compliance issue - add firmware for an8811hb 2.5G ethernet phy - i915: Xe3LPD_3002 DMC v2.28 - i915: Xe3LPD DMC v2.33 - intel_vpu: Add firmware for 50xx NPUs and update older ones - Update AMD SEV firmware - amdgpu: DMCUB updates for various ASICs - qcom: venus-5.4: fix ELF segment alignment to 4 bytes - mediatek MT7925: update bluetooth firmware to 20251210093205 - update firmware for MT7925 WiFi device - rcar_gen4_pcie: add firmware for Renesas R-Car Gen4 PCIe controller - qcom: Update CDSP firmware for qcm6490 platform - rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x488C_DB55 - iwlwifi: Add firmware file for Intel Scorpius core - rtw89: 8852b: update fw to v0.29.29.15 - cirrus: cs35l41: Update firmware and tuning for various HP laptops - cirrus: cs35l41: Add support for new HP Clipper laptop - qcom: drop compatibility a640_zap.mdt symlink - qcom: add version for a530v3_gpmu.fw2 - xe: Update GUC to v70.55.3 for BMG, PTL - iwlwifi: add Bz/Sc FW for core101-82 release - iwlwifi: Add Sc/Gf firmware for core101-82 release - iwlwifi: update ty/So/Ma firmwaresfor core101-82 release - iwlwifi: update cc/Qu/QuZ firmwares for core101-82 release - amdgpu: DMCUB updates for various ASICs - qcom: Add firmwares for sm8150/sm8450/sm8550/sm8650/sm8750 GPUs - ath10k: WCN3990 hw1.0: update board-2.bin - ath10k: QCA9888 hw2.0: update board-2.bin - ath10k: QCA4019 hw1.0: update board-2.bin - cirrus: cs35l41: Add support for new HP laptops - Revert "amdgpu: update GC 11.5.0 firmware" - Update amd-ucode copyright information - Update AMD cpu microcode - Update firmware file for Intel Scorpius core - Update firmware file for Intel BlazarIGfP core - Update firmware file for Intel BlazarI core - Update firmware file for Intel BlazarU-HrPGfP core - Update firmware file for Intel BlazarU core - ath11k: QCA6698AQ hw2.1: update to WLAN.HSP.1.1-04866-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1 - ath11k: QCA2066 hw2.1: update board-2.bin - qcom: update ADSP firmware for x1e80100 platform, change the license - qcom: reorder ADSP, CDSP firmware entries for qcs8300 in WHENCE - Reapply "amdgpu: update SMU 14.0.3 firmware" - Revert "amdgpu: update SMU 14.0.3 firmware" - Revert "amdgpu: update GC 10.3.6 firmware" - Revert "amdgpu: update GC 11.5.1 firmware" - update firmware for MT7925 WiFi device - mediatek MT7925: update bluetooth firmware to 20251124093155 - intel_vpu: Update NPU firmware - qcom: vpu: update video firmware binary for SM8250 - xe: Update GUC to v70.54.0 for BMG, PTL -------------------------------------------------------------------------------- References: [ 1 ] Bug #2341650 - Bluetooth audio stutter or completely lost when wifi is being used https://bugzilla.redhat.com/show_bug.cgi?id=2341650 [ 2 ] Bug #2390638 - amd graphics fail on laptop, due to faulty amd-gpu firmware file. https://bugzilla.redhat.com/show_bug.cgi?id=2390638 [ 3 ] Bug #2419812 - mt7xxx-firmware-20251125 breaks bluetooth https://bugzilla.redhat.com/show_bug.cgi?id=2419812 [ 4 ] Bug #2420062 - requesting updated build to fix issues with AMD APUplatforms https://bugzilla.redhat.com/show_bug.cgi?id=2420062 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1d240112ff' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 42 updates firmware for MT7925 WiFi and Bluetooth devices with several enhancements and fixes.. Fedora Firmware Update, MT7925 Bluetooth Firmware, Linux Firmware Management. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Jan 15, 2026 Informational Fedora
89

Fedora 42: luksmeta Update CVE-2025-11568 Severity Informational

New upstream release v10 Fix: CVE-2025-11568. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-457000540a 2025-11-16 00:54:19.352364+00:00 -------------------------------------------------------------------------------- Name : luksmeta Product : Fedora 42 Version : 10 Release : 1.fc42 URL : https://github.com/latchset/luksmeta Summary : Utility for storing small metadata in the LUKSv1 header Description : LUKSMeta is a command line utility for storing small portions of metadata in the LUKSv1 header for use before unlocking the volume. -------------------------------------------------------------------------------- Update Information: New upstream release v10 Fix: CVE-2025-11568 -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 31 2025 Sergio Correia - 10-1 - New upstream release v10 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2404247 - CVE-2025-11568 luksmeta: Data corruption when handling LUKS1 partitions with luksmeta [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2404247 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-457000540a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 42 update addresses CVE-2025-11568 in luksmeta with a new release to fix data corruption risks.. Fedora,LUKSmata,CVE-2025-11568,security patch,data integrity. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Nov 16, 2025 Informational Fedora
203

Mageia 9: nvidia-current Bugfix Advisory MGAA-2025-0091

MGAA-2025-0091 - Updated nvidia-current packages fix bug. MGAA-2025-0091 - Updated nvidia-current packages fix bug Publication date: 07 Nov 2025 URL: https://advisories.mageia.org/MGAA-2025-0091.html Type: bugfix Affected Mageia releases: 9 Description: Added support for YCbCr 4:2:2 display modes over HDMI Fixed Rate Link (FRL). This capability is only supported on Blackwell or later. Downgraded an error message "Failed to allocate NvKmsKapiDevice" to an informational message "NUMA was not set up yet; ignoring this device" when initializing nvidia-drm in cases where initialization is expected to fail due to NUMA not being online. Fixed a bug that caused interactive object outlines to not be rendered in Indiana Jones and the Great Circle. Fixed a regression introduced in the 575 driver series that caused GPUs to be powered on unnecessarily when processing redundant system power source notifications from the ACPI subsystem. References: - https://bugs.mageia.org/show_bug.cgi?id=34712 - https://www.nvidia.com/en-us/drivers/details/254665/ SRPMS: - 9/nonfree/nvidia-current-580.95.05-1.mga9.nonfree . Updated nvidia-current packages in Mageia resolve critical bugs and improve HDMI display modes for enhanced performance.. Mageia updates,nvidia-current bugfix,device management improvements,HDMI display support. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Nov 07, 2025 Informational Mageia
89

Fedora 41: Chromium High Heap Buffer Overflows Advisories 2025-2d4d91b00a

Update to 141.0.7390.54 * High CVE-2025-11205: Heap buffer overflow in WebGPU * High CVE-2025-11206: Heap buffer overflow in Video * Medium CVE-2025-11207: Side-channel information leakage in Storage * Medium CVE-2025-11208: Inappropriate implementation in Media. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-2d4d91b00a 2025-10-09 01:14:09.802863+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 41 Version : 141.0.7390.54 Release : 1.fc41 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 141.0.7390.54 * High CVE-2025-11205: Heap buffer overflow in WebGPU * High CVE-2025-11206: Heap buffer overflow in Video * Medium CVE-2025-11207: Side-channel information leakage in Storage * Medium CVE-2025-11208: Inappropriate implementation in Media * Medium CVE-2025-11209: Inappropriate implementation in Omnibox * Medium CVE-2025-11210: Side-channel information leakage in Tab * Medium CVE-2025-11211: Out of bounds read in Media * Medium CVE-2025-11212: Inappropriate implementation in Media * Medium CVE-2025-11213: Inappropriate implementation in Omnibox * Medium CVE-2025-11215: Off by one error in V8 * Low CVE-2025-11216: Inappropriate implementation in Storage * Low CVE-2025-11219: Use after free in V8 -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 2 2025 Than Ngo - 141.0.7390.54-1 - Update to 141.0.7390.54 * High CVE-2025-11205: Heap buffer overflow in WebGPU * High CVE-2025-11206: Heap buffer overflow in Video * Medium CVE-2025-11207: Side-channel informationleakage in Storage * Medium CVE-2025-11208: Inappropriate implementation in Media * Medium CVE-2025-11209: Inappropriate implementation in Omnibox * Medium CVE-2025-11210: Side-channel information leakage in Tab * Medium CVE-2025-11211: Out of bounds read in Media * Medium CVE-2025-11212: Inappropriate implementation in Media * Medium CVE-2025-11213: Inappropriate implementation in Omnibox * Medium CVE-2025-11215: Off by one error in V8 * Low CVE-2025-11216: Inappropriate implementation in Storage * Low CVE-2025-11219: Use after free in V8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2381730 - DebugInfo packages aren't being produced. https://bugzilla.redhat.com/show_bug.cgi?id=2381730 [ 2 ] Bug #2400095 - Update chromium-141.0.7390.54 major release [fedora-all, epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2400095 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-2d4d91b00a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply tospam, report it: https://pagure.io/fedora-infrastructure/new_issue . Critical updates for Fedora 41 Chromium address significant heap overflow risks. Details on updates and installation instructions.. Fedora Chromium Update, CVE-2025-11205, CVE-2025-11206, Heap Overflow, Security Advisory. . LinuxSecurity.com Team

Calendar%202 Oct 09, 2025 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200