Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Security update. Publication date: 18 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0262.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-57053 Description: GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2. (CVE-2026-57053) References: - https://bugs.mageia.org/show_bug.cgi?id=35726 - http://www.slackware.com/security/viewer.php?l=slackware-security&y=2026&m=slackware-security.355846 - https://lists.gnu.org/archive/html/help-libidn/2026-05/msg00000.html - https://lists.gnu.org/archive/html/help-libidn/2025-06/msg00000.html - https://ubuntu.com/security/notices/USN-8521-1 - https://www.cve.org/CVERecord?id=CVE-2026-57053 SRPMS: - 10/core/libidn-1.43-2.1.mga10 - 9/core/libidn-1.41-2.1.mga9 . Security update for Mageia addressing out-of-bounds reads in libidn. Prompt action recommended to mitigate risks.. Mageia update, libidn security, out-of-bounds, security risk. . Severity: Important. LinuxSecurity.com Team
Libidn could be made to crash or expose sensitive information if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8521-1 July 09, 2026 libidn vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Libidn could be made to crash or expose sensitive information if it received specially crafted input. Software Description: - libidn: implementation of IETF IDN specifications Details: It was discovered that Libidn incorrectly handled certain internationalized domain name strings. An attacker could possibly use this issue to obtain sensitive information or cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libidn12 1.43-2ubuntu0.26.04.1 Ubuntu 24.04 LTS libidn12 1.42-1ubuntu0.1 Ubuntu 22.04 LTS libidn12 1.38-4ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8521-1 CVE-2026-57053 Package Information: https://launchpad.net/ubuntu/+source/libidn/1.43-2ubuntu0.26.04.1 https://launchpad.net/ubuntu/+source/libidn/1.42-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libidn/1.38-4ubuntu1.1 . Libidn issues in Ubuntu could lead to system crash or information exposure if vulnerable inputs are received. Update recommended.. Ubuntu security update, libidn security vulnerability, Ubuntu critical advisory. . Severity: Critical. LinuxSecurity.com Team
New libidn packages are available for Slackware 15.0 and -current to fix security issues.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] libidn (SSA:2026-168-02) New libidn packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/libidn-1.44-i586-1-slack15.0.txz: Rebuilt. This update fixes security issues: libidn: Fix read-out-of-bounds error in ToUnicode APIs. examples: Fix strcpy buffer overflow. For more information, see: https://lists.gnu.org/archive/html/help-libidn/2026-05/msg00000.html https://lists.gnu.org/archive/html/help-libidn/2025-06/msg00000.html (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://slackware.com for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libidn-1.44-i586-1-slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/libidn-1.44-x86_64-1-slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/libidn-1.44-i686-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/libidn-1.44-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: cebf86a9c5bd63bcc97933b6a81c975b libidn-1.44-i586-1-slack15.0.txz Slackware x86_64 15.0 package: b9438bfe435f323eb2752fc0a42bd39c libidn-1.44-x86_64-1-slack15.0.txz Slackware -current package: d0ffe04c5036d4592440cb1d17a30b9b l/libidn-1.44-i686-1.txz Slackware x86_64 -current package: 7a0f4faa705823200e445097bcf8dd5f l/libidn-1.44-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg libidn-1.44-i586-1-slack15.0.txz +-----+ . New libidn packages for Slackware 15.0 to fix security issues including a buffer overflow and read-out-of-bounds error.. libidn packages Slackware security updates critical. . Severity: Critical. LinuxSecurity.com Team
An integer overflow vulnerability was discovered in libidn, the GNU library for Internationalized Domain Names (IDNs), in its Punycode handling (a Unicode characters to ASCII encoding) allowing a remote attacker to cause a denial of . Package : libidn Version : 1.29-1+deb8u3 CVE ID : CVE-2017-14062 Debian Bug : 873903 An integer overflow vulnerability was discovered in libidn, the GNU library for Internationalized Domain Names (IDNs), in its Punycode handling (a Unicode characters to ASCII encoding) allowing a remote attacker to cause a denial of service against applications using the library. For Debian 8 "Jessie", this problem has been fixed in version 1.29-1+deb8u3. We recommend that you upgrade your libidn packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A critical integer vulnerability has been identified in libidn impacting Debian 8 systems. Immediate upgrade is recommended to mitigate potential denial of service threats.. libidn update, integer overflow vulnerability, debian security advisory. . LinuxSecurity.com Team
Update to the latest upstream release, which fixes CVE-2017-14062.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-02e23192f5 2018-04-06 15:00:04.588443 --------------------------------------------------------------------------------Name : libidn Product : Fedora 27 Version : 1.34 Release : 1.fc27 URL : http://www.gnu.org/software/libidn/ Summary : Internationalized Domain Name support library Description : GNU Libidn is an implementation of the Stringprep, Punycode and IDNA specifications defined by the IETF Internationalized Domain Names (IDN) working group, used for internationalized domain names. --------------------------------------------------------------------------------Update Information: Update to the latest upstream release, which fixes CVE-2017-14062. --------------------------------------------------------------------------------References: [ 1 ] Bug #1486882 - CVE-2017-14062 libidn2: Integer overflow in puny_decode.c/decode_digit https://bugzilla.redhat.com/show_bug.cgi?id=1486882 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libidn' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to the latest upstream release, which fixes CVE-2017-14062.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-02e23192f5 2018-04-06 15:00:04.588443 --------------------------------------------------------------------------------Name : libidn Product : Fedora 27 Version : 1.34 Release : 1.fc27 URL : Summary : Internationalized Domain Name support library Description : GNU Libidn is an implementation of the Stringprep, Punycode and IDNA specifications defined by the IETF Internationalized Domain Names (IDN) working group, used for internationalized domain names. --------------------------------------------------------------------------------Update Information: Update to the latest upstream release, which fixes CVE-2017-14062. --------------------------------------------------------------------------------References: [ 1 ] Bug #1486882 - CVE-2017-14062 libidn2: Integer overflow in puny_decode.c/decode_digit https://bugzilla.redhat.com/show_bug.cgi?id=1486882 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libidn' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to the latest upstream release, which fixes CVE-2017-14062.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-f749c70191 2018-04-06 11:07:50.699727 --------------------------------------------------------------------------------Name : libidn Product : Fedora 28 Version : 1.34 Release : 1.fc28 URL : http://www.gnu.org/software/libidn/ Summary : Internationalized Domain Name support library Description : GNU Libidn is an implementation of the Stringprep, Punycode and IDNA specifications defined by the IETF Internationalized Domain Names (IDN) working group, used for internationalized domain names. --------------------------------------------------------------------------------Update Information: Update to the latest upstream release, which fixes CVE-2017-14062. --------------------------------------------------------------------------------References: [ 1 ] Bug #1486882 - CVE-2017-14062 libidn2: Integer overflow in puny_decode.c/decode_digit https://bugzilla.redhat.com/show_bug.cgi?id=1486882 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libidn' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to the latest upstream release, which fixes CVE-2017-14062.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-f749c70191 2018-04-06 11:07:50.699727 --------------------------------------------------------------------------------Name : libidn Product : Fedora 28 Version : 1.34 Release : 1.fc28 URL : http://www.gnu.org/software/libidn/ Summary : Internationalized Domain Name support library Description : GNU Libidn is an implementation of the Stringprep, Punycode and IDNA specifications defined by the IETF Internationalized Domain Names (IDN) working group, used for internationalized domain names. --------------------------------------------------------------------------------Update Information: Update to the latest upstream release, which fixes CVE-2017-14062. --------------------------------------------------------------------------------References: [ 1 ] Bug #1486882 - CVE-2017-14062 libidn2: Integer overflow in puny_decode.c/decode_digit https://bugzilla.redhat.com/show_bug.cgi?id=1486882 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libidn' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.