Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 8 articles for you...
203

Mageia 10 9 libidn Critical Out-Of-Bounds Read CVE-2026-57053

Security update. Publication date: 18 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0262.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-57053 Description: GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2. (CVE-2026-57053) References: - https://bugs.mageia.org/show_bug.cgi?id=35726 - http://www.slackware.com/security/viewer.php?l=slackware-security&y=2026&m=slackware-security.355846 - https://lists.gnu.org/archive/html/help-libidn/2026-05/msg00000.html - https://lists.gnu.org/archive/html/help-libidn/2025-06/msg00000.html - https://ubuntu.com/security/notices/USN-8521-1 - https://www.cve.org/CVERecord?id=CVE-2026-57053 SRPMS: - 10/core/libidn-1.43-2.1.mga10 - 9/core/libidn-1.41-2.1.mga9 . Security update for Mageia addressing out-of-bounds reads in libidn. Prompt action recommended to mitigate risks.. Mageia update, libidn security, out-of-bounds, security risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 18, 2026 Important Mageia
172

Ubuntu 26.04 LTS Libidn Critical DoS Information Exposure USN-8521-1

Libidn could be made to crash or expose sensitive information if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8521-1 July 09, 2026 libidn vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Libidn could be made to crash or expose sensitive information if it received specially crafted input. Software Description: - libidn: implementation of IETF IDN specifications Details: It was discovered that Libidn incorrectly handled certain internationalized domain name strings. An attacker could possibly use this issue to obtain sensitive information or cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libidn12 1.43-2ubuntu0.26.04.1 Ubuntu 24.04 LTS libidn12 1.42-1ubuntu0.1 Ubuntu 22.04 LTS libidn12 1.38-4ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8521-1 CVE-2026-57053 Package Information: https://launchpad.net/ubuntu/+source/libidn/1.43-2ubuntu0.26.04.1 https://launchpad.net/ubuntu/+source/libidn/1.42-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libidn/1.38-4ubuntu1.1 . Libidn issues in Ubuntu could lead to system crash or information exposure if vulnerable inputs are received. Update recommended.. Ubuntu security update, libidn security vulnerability, Ubuntu critical advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 09, 2026 Critical Ubuntu
99

Slackware libidn Critical Buffer Overflow Fix 2026-168-02

New libidn packages are available for Slackware 15.0 and -current to fix security issues.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] libidn (SSA:2026-168-02) New libidn packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/libidn-1.44-i586-1-slack15.0.txz: Rebuilt. This update fixes security issues: libidn: Fix read-out-of-bounds error in ToUnicode APIs. examples: Fix strcpy buffer overflow. For more information, see: https://lists.gnu.org/archive/html/help-libidn/2026-05/msg00000.html https://lists.gnu.org/archive/html/help-libidn/2025-06/msg00000.html (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://slackware.com for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libidn-1.44-i586-1-slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/libidn-1.44-x86_64-1-slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/libidn-1.44-i686-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/libidn-1.44-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: cebf86a9c5bd63bcc97933b6a81c975b libidn-1.44-i586-1-slack15.0.txz Slackware x86_64 15.0 package: b9438bfe435f323eb2752fc0a42bd39c libidn-1.44-x86_64-1-slack15.0.txz Slackware -current package: d0ffe04c5036d4592440cb1d17a30b9b l/libidn-1.44-i686-1.txz Slackware x86_64 -current package: 7a0f4faa705823200e445097bcf8dd5f l/libidn-1.44-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg libidn-1.44-i586-1-slack15.0.txz +-----+ . New libidn packages for Slackware 15.0 to fix security issues including a buffer overflow and read-out-of-bounds error.. libidn packages Slackware security updates critical. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 17, 2026 Critical Slackware
197

Debian 8: DLA-1447-1 Moderate: Integer Overflow in Libidn Leads to DoS

An integer overflow vulnerability was discovered in libidn, the GNU library for Internationalized Domain Names (IDNs), in its Punycode handling (a Unicode characters to ASCII encoding) allowing a remote attacker to cause a denial of . Package : libidn Version : 1.29-1+deb8u3 CVE ID : CVE-2017-14062 Debian Bug : 873903 An integer overflow vulnerability was discovered in libidn, the GNU library for Internationalized Domain Names (IDNs), in its Punycode handling (a Unicode characters to ASCII encoding) allowing a remote attacker to cause a denial of service against applications using the library. For Debian 8 "Jessie", this problem has been fixed in version 1.29-1+deb8u3. We recommend that you upgrade your libidn packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A critical integer vulnerability has been identified in libidn impacting Debian 8 systems. Immediate upgrade is recommended to mitigate potential denial of service threats.. libidn update, integer overflow vulnerability, debian security advisory. . LinuxSecurity.com Team

Calendar%202 Jul 27, 2018 Debian LTS
89

Fedora 27: FEDORA-2018-02e23192f5 Critical: libidn Integer Overflow

Update to the latest upstream release, which fixes CVE-2017-14062.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-02e23192f5 2018-04-06 15:00:04.588443 --------------------------------------------------------------------------------Name : libidn Product : Fedora 27 Version : 1.34 Release : 1.fc27 URL : http://www.gnu.org/software/libidn/ Summary : Internationalized Domain Name support library Description : GNU Libidn is an implementation of the Stringprep, Punycode and IDNA specifications defined by the IETF Internationalized Domain Names (IDN) working group, used for internationalized domain names. --------------------------------------------------------------------------------Update Information: Update to the latest upstream release, which fixes CVE-2017-14062. --------------------------------------------------------------------------------References: [ 1 ] Bug #1486882 - CVE-2017-14062 libidn2: Integer overflow in puny_decode.c/decode_digit https://bugzilla.redhat.com/show_bug.cgi?id=1486882 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libidn' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent libidn patch on Fedora 27 resolves critical integer overflow vulnerabilities, enhancing system security with the latest version's implementation..libidn Update,Fedora 27 Security,Integer Overflow Fix,IDN Support,Latest Upstream Release. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 06, 2018 Critical Fedora
89

Fedora 27 libidn Security Update: Integer Overflow Fix for CVE-2017-14062

Update to the latest upstream release, which fixes CVE-2017-14062.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-02e23192f5 2018-04-06 15:00:04.588443 --------------------------------------------------------------------------------Name : libidn Product : Fedora 27 Version : 1.34 Release : 1.fc27 URL : Summary : Internationalized Domain Name support library Description : GNU Libidn is an implementation of the Stringprep, Punycode and IDNA specifications defined by the IETF Internationalized Domain Names (IDN) working group, used for internationalized domain names. --------------------------------------------------------------------------------Update Information: Update to the latest upstream release, which fixes CVE-2017-14062. --------------------------------------------------------------------------------References: [ 1 ] Bug #1486882 - CVE-2017-14062 libidn2: Integer overflow in puny_decode.c/decode_digit https://bugzilla.redhat.com/show_bug.cgi?id=1486882 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libidn' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent Fedora upgrade for libidn has resolved an integer overflow vulnerability identified as CVE-2017-14062.. Fedora 27 libidn update,integer overflowpatch,security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 06, 2018 Critical Fedora
89

Fedora 28 FEDORA-2018-f749c70191 Moderate: libidn Integer Overflow Fix

Update to the latest upstream release, which fixes CVE-2017-14062.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-f749c70191 2018-04-06 11:07:50.699727 --------------------------------------------------------------------------------Name : libidn Product : Fedora 28 Version : 1.34 Release : 1.fc28 URL : http://www.gnu.org/software/libidn/ Summary : Internationalized Domain Name support library Description : GNU Libidn is an implementation of the Stringprep, Punycode and IDNA specifications defined by the IETF Internationalized Domain Names (IDN) working group, used for internationalized domain names. --------------------------------------------------------------------------------Update Information: Update to the latest upstream release, which fixes CVE-2017-14062. --------------------------------------------------------------------------------References: [ 1 ] Bug #1486882 - CVE-2017-14062 libidn2: Integer overflow in puny_decode.c/decode_digit https://bugzilla.redhat.com/show_bug.cgi?id=1486882 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libidn' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 28 introduces significant updates to libidn, addressing a critical integer overflow vulnerability and enhancing its domain name handling capabilities..Fedora Security Update, libidn Patch, Integer Overflow Fix. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Apr 06, 2018 Medium Fedora
89

Fedora 28: FEDORA-2018-f749c70191 critical: libidn Integer Overflow

Update to the latest upstream release, which fixes CVE-2017-14062.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-f749c70191 2018-04-06 11:07:50.699727 --------------------------------------------------------------------------------Name : libidn Product : Fedora 28 Version : 1.34 Release : 1.fc28 URL : http://www.gnu.org/software/libidn/ Summary : Internationalized Domain Name support library Description : GNU Libidn is an implementation of the Stringprep, Punycode and IDNA specifications defined by the IETF Internationalized Domain Names (IDN) working group, used for internationalized domain names. --------------------------------------------------------------------------------Update Information: Update to the latest upstream release, which fixes CVE-2017-14062. --------------------------------------------------------------------------------References: [ 1 ] Bug #1486882 - CVE-2017-14062 libidn2: Integer overflow in puny_decode.c/decode_digit https://bugzilla.redhat.com/show_bug.cgi?id=1486882 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libidn' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Recent Fedora security patch for libidn tackles integer underflow vulnerability and improves IDN functionality.. libidnsecurity, integer overflow fix, Fedora security update, libidn update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 06, 2018 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200