Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
89

Fedora 43: rust-jiter Critical JSON Memory Leak Patch 2025-5164ea93d1

uv / python-uv-build 0.9.5 https://github.com/astral-sh/uv/blob/0.9.5/CHANGELOG.md ruff 0.14.2 https://github.com/astral-sh/ruff/blob/0.14.2/CHANGELOG.md Pydantic 2.12.3. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-4154ea83d0 2025-11-05 02:09:57.817569+00:00 -------------------------------------------------------------------------------- Name : rust-jiter Product : Fedora 43 Version : 0.11.1 Release : 1.fc43 URL : https://crates.io/crates/jiter Summary : Fast Iterable JSON parser Description : Fast Iterable JSON parser. -------------------------------------------------------------------------------- Update Information: uv / python-uv-build 0.9.5 https://github.com/astral-sh/uv/blob/0.9.5/CHANGELOG.md ruff 0.14.2 https://github.com/astral-sh/ruff/blob/0.14.2/CHANGELOG.md Pydantic 2.12.3 Blog post maturin 1.9.6 https://github.com/PyO3/maturin/blob/v1.9.6/Changelog.md python-typing-inspection 0.4.2 (2025-10-01) Add typing_objects.is_noextraitems() python-jiter 0.11.0 https://github.com/pydantic/jiter/releases/tag/v0.11.0 python-pydantic-extra-types 2.10.6 https://github.com/pydantic/pydantic-extra-types/releases/tag/v2.10.6 Typer 0.20.0 Features \u2728 Enable command suggestions on typo by default. Upgrades \u2b06\ufe0f Add (official) support for Python 3.14. Internal Assorted small enhancements. FastAPI 0.120.1 Upgrades \u2b06\ufe0f Bump Starlette to

Calendar 2 Nov 05, 2025 Important Fedora
89

Critical Integer Overflow Vulnerability in perl-Cpanel-JSON-XS on Fedora 42

This update fixes an issue where a specially-crafted JSON input could cause an integer overflow leading to a crash in the program parsing the JSON (CVE-2025-40929).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-f4f4dae8f2 2025-09-18 00:55:58.913935+00:00 -------------------------------------------------------------------------------- Name : perl-Cpanel-JSON-XS Product : Fedora 42 Version : 4.40 Release : 1.fc42 URL : https://metacpan.org/release/Cpanel-JSON-XS Summary : JSON::XS for Cpanel, fast and correct serializing Description : This module converts Perl data structures to JSON and vice versa. Its primary goal is to be correct and its secondary goal is to be fast. To reach the latter goal it was written in C. -------------------------------------------------------------------------------- Update Information: This update fixes an issue where a specially-crafted JSON input could cause an integer overflow leading to a crash in the program parsing the JSON (CVE-2025-40929). -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 9 2025 Paul Howarth - 4.40-1 - Update to 4.40 - Fix overflow with overlong numbers, fuzzing only (CVE-2025-40929) - Detect more malformed numbers, with two decimal points - Pin Github actions to latest @v via pinact run -u * Fri Jul 25 2025 Fedora Release Engineering - 4.39-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Tue Jul 8 2025 Jitka Plesnikova - 4.39-4 - Perl 5.42 re-rebuild of bootstrapped packages * Mon Jul 7 2025 Jitka Plesnikova - 4.39-3 - Perl 5.42 rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2393917 - CVE-2025-40929 perl-Cpanel-JSON-XS: integer buffer overflow causing a segfault when parsing crafted JSON [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2393917 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f4f4dae8f2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 42 has upgraded the Cpanel-JSON-XS package to fix an integer overflow vulnerability that could affect JSON data handling. Update now for improved security and validation. Fedora 42, perl-Cpanel-JSON-XS, integer overflow, security update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 18, 2025 Critical Fedora
87

Debian: cJSON Important Input Sanitization Issue DSA-6001-1 CVE-2025-57052

It was discovered that cJSON, an ultralightweight JSON parser, performed insufficient input sanitising, which could result in out-of-bounds memory access. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6001-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff September 14, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : cjson CVE ID : CVE-2025-57052 It was discovered that cJSON, an ultralightweight JSON parser, performed insufficient input sanitising, which could result in out-of-bounds memory access. For the oldstable distribution (bookworm), this problem has been fixed in version 1.7.15-1+deb12u4. For the stable distribution (trixie), this problem has been fixed in version 1.7.18-3.1+deb13u1. We recommend that you upgrade your cjson packages. For the detailed security status of cjson please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/cjson Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . cJSON identified to possess inadequate input validation, resulting in potential buffer overflow vulnerabilities. Update advised.. cJSON security,debian advisory,json parser attack,memory access vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 14, 2025 Important Debian
89

Fedora 32: FEDORA-2020-39852a8ef8 Critical Update for JSON Parser

Multiple bug fixes, including a fix for CVE-2020-10675 .. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-39852a8ef8 2020-04-25 02:14:03.393588 --------------------------------------------------------------------------------Name : golang-github-buger-jsonparser Product : Fedora 32 Version : 0 Release : 0.9.20200406gitf7e751e.fc32 URL : https://github.com/buger/jsonparser Summary : Alternative JSON parser for Go that does not require schema Description : Alternative JSON parser for Go. It does not require you to know the structure of the payload (eg. create structs), and allows accessing fields by providing the path to them. It is up to 10 times faster than standard encoding/json package (depending on payload size and usage), allocates no memory. --------------------------------------------------------------------------------Update Information: Multiple bug fixes, including a fix for CVE-2020-10675 . --------------------------------------------------------------------------------ChangeLog: * Mon Apr 6 2020 Dominik Mierzejewski - 0-0.9.20200406gitf7e751e - Bump to commit f7e751efca132eb5c767c4b0b20f68524ba89742 (fixes CVE-2020-10675) --------------------------------------------------------------------------------References: [ 1 ] Bug #1817733 - CVE-2020-10675 golang-github-buger-jsonparser: infinite loop via a Delete call https://bugzilla.redhat.com/show_bug.cgi?id=1817733 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-39852a8ef8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora 32 update for golang-github-buger-jsonparser addresses critical bugs including infinite loop vulnerability.. Fedora Updates, Go JSON Parser, Security Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 24, 2020 Critical Fedora
89

Fedora 31: FEDORA-2020-97e8a67945 Critical: JSON Parser Infinite Loop

Multiple bug fixes, including a fix for CVE-2020-10675 . . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-97e8a67945 2020-04-15 20:32:17.101637 --------------------------------------------------------------------------------Name : golang-github-buger-jsonparser Product : Fedora 31 Version : 0 Release : 0.8.20200406gitf7e751e.fc31 URL : https://github.com/buger/jsonparser Summary : Alternative JSON parser for Go that does not require schema Description : Alternative JSON parser for Go. It does not require you to know the structure of the payload (eg. create structs), and allows accessing fields by providing the path to them. It is up to 10 times faster than standard encoding/json package (depending on payload size and usage), allocates no memory. --------------------------------------------------------------------------------Update Information: Multiple bug fixes, including a fix for CVE-2020-10675 . --------------------------------------------------------------------------------ChangeLog: * Mon Apr 6 2020 Dominik Mierzejewski - 0-0.8.20200406gitf7e751e - Bump to commit f7e751efca132eb5c767c4b0b20f68524ba89742 (fixes CVE-2020-10675) --------------------------------------------------------------------------------References: [ 1 ] Bug #1817733 - CVE-2020-10675 golang-github-buger-jsonparser: infinite loop via a Delete call https://bugzilla.redhat.com/show_bug.cgi?id=1817733 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-97e8a67945' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Numerous patch updates released for golang-github-buger-jsonparser, tackling CVE-2020-10675 in Fedora 31.. CVE-2020-10675,Fedora,JSON Parser,Bug Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 15, 2020 Critical Fedora
197

Debian Wheezy: DLA-1167-1 Urgent: Ruby-Yajl Denial Of Service Vulnerability

A vulnerability was found in ruby-yajl, an interface to Yajl, a JSON stream-based parser library. When a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This may result . Hash: SHA512 Package : ruby-yajl Version : 1.1.0-2+deb7u1 CVE ID : CVE-2017-16516 Debian Bug : 880691 A vulnerability was found in ruby-yajl, an interface to Yajl, a JSON stream-based parser library. When a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This may result in a denial of service. For Debian 7 "Wheezy", these problems have been fixed in version 1.1.0-2+deb7u1. We recommend that you upgrade your ruby-yajl packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Explore the newly released security patch for ruby-yajl on Debian LTS that resolves a significant issue related to JSON parsing vulnerabilities.. Debian LTS, Ruby-Yajl, Security Update, JSON Parser, Denial of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 08, 2017 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here