Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
172

Ubuntu libheif Critical Denial of Service Issues USN-8454-1

Several security issues were fixed in libheif.. ========================================================================== Ubuntu Security Notice USN-8454-1 June 18, 2026 libheif vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in libheif. Software Description: - libheif: An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder Details: Elhanan Haenel discovered that libheif incorrectly handled certain malformed HEIF sequence files. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-32738) Elhanan Haenel discovered that libheif incorrectly handled certain malformed HEIF sequence files, leading to an infinite loop. An attacker could possibly use this issue to cause libheif to use excessive resources, resulting in a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-32739) Elhanan Haenel discovered that libheif incorrectly handled certain crafted HEIF/AVIF image files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-32740) It was discovered that libheif incorrectly handled certain crafted HEIF files containing mask images. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-32741) It was discovered that libheif incorrectly handled certain crafted grid-based HEIF/AVIF files. An attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, andUbuntu 26.04 LTS. (CVE-2026-32814) It was discovered that libheif incorrectly handled certain crafted HEIF files when compositing overlay images. An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2026-32882) It was discovered that libheif incorrectly handled certain crafted files. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-3950) It was discovered that libheif incorrectly handled certain malformed HEIF sequence files. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-41069) It was discovered that libheif incorrectly handled certain crafted HEIF sequence files. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-41071) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS heif-gdk-pixbuf 1.21.2-3ubuntu0.1 heif-thumbnailer 1.21.2-3ubuntu0.1 heif-view 1.21.2-3ubuntu0.1 libheif-dev 1.21.2-3ubuntu0.1 libheif-plugin-aomdec 1.21.2-3ubuntu0.1 libheif-plugin-aomenc 1.21.2-3ubuntu0.1 libheif-plugin-dav1d 1.21.2-3ubuntu0.1 libheif-plugin-ffmpegdec 1.21.2-3ubuntu0.1 libheif-plugin-j2kdec 1.21.2-3ubuntu0.1 libheif-plugin-j2kenc 1.21.2-3ubuntu0.1 libheif-plugin-jpegdec 1.21.2-3ubuntu0.1 libheif-plugin-jpegenc 1.21.2-3ubuntu0.1 libheif-plugin-kvazaar 1.21.2-3ubuntu0.1 libheif-plugin-libde265 1.21.2-3ubuntu0.1 libheif-plugin-rav1e 1.21.2-3ubuntu0.1 libheif-plugin-svtenc 1.21.2-3ubuntu0.1 libheif-plugin-x265 1.21.2-3ubuntu0.1 libheif-plugins-all 1.21.2-3ubuntu0.1 libheif1 1.21.2-3ubuntu0.1 Ubuntu 25.10 heif-gdk-pixbuf 1.20.2-1ubuntu0.4 heif-thumbnailer 1.20.2-1ubuntu0.4 heif-view 1.20.2-1ubuntu0.4 libheif-dev 1.20.2-1ubuntu0.4 libheif-plugin-aomdec 1.20.2-1ubuntu0.4 libheif-plugin-aomenc 1.20.2-1ubuntu0.4 libheif-plugin-dav1d 1.20.2-1ubuntu0.4 libheif-plugin-ffmpegdec 1.20.2-1ubuntu0.4 libheif-plugin-j2kdec 1.20.2-1ubuntu0.4 libheif-plugin-j2kenc 1.20.2-1ubuntu0.4 libheif-plugin-jpegdec 1.20.2-1ubuntu0.4 libheif-plugin-jpegenc 1.20.2-1ubuntu0.4 libheif-plugin-kvazaar 1.20.2-1ubuntu0.4 libheif-plugin-libde265 1.20.2-1ubuntu0.4 libheif-plugin-rav1e 1.20.2-1ubuntu0.4 libheif-plugin-svtenc 1.20.2-1ubuntu0.4 libheif-plugin-x265 1.20.2-1ubuntu0.4 libheif-plugins-all 1.20.2-1ubuntu0.4 libheif1 1.20.2-1ubuntu0.4 Ubuntu 24.04 LTS heif-gdk-pixbuf 1.17.6-1ubuntu4.4 heif-thumbnailer 1.17.6-1ubuntu4.4 libheif-dev 1.17.6-1ubuntu4.4 libheif-plugin-aomdec 1.17.6-1ubuntu4.4 libheif-plugin-aomenc 1.17.6-1ubuntu4.4 libheif-plugin-dav1d 1.17.6-1ubuntu4.4 libheif-plugin-ffmpegdec 1.17.6-1ubuntu4.4 libheif-plugin-j2kdec 1.17.6-1ubuntu4.4 libheif-plugin-j2kenc 1.17.6-1ubuntu4.4 libheif-plugin-jpegdec 1.17.6-1ubuntu4.4 libheif-plugin-jpegenc 1.17.6-1ubuntu4.4 libheif-plugin-libde265 1.17.6-1ubuntu4.4 libheif-plugin-rav1e 1.17.6-1ubuntu4.4 libheif-plugin-svtenc 1.17.6-1ubuntu4.4 libheif-plugin-x265 1.17.6-1ubuntu4.4 libheif1 1.17.6-1ubuntu4.4 Ubuntu 22.04 LTS heif-gdk-pixbuf 1.12.0-2ubuntu0.1~esm3 Available with Ubuntu Pro heif-thumbnailer 1.12.0-2ubuntu0.1~esm3 Available with Ubuntu Pro libheif-dev 1.12.0-2ubuntu0.1~esm3 Available with Ubuntu Pro libheif1 1.12.0-2ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 20.04 LTS heif-gdk-pixbuf 1.6.1-1ubuntu0.1~esm3 Available with Ubuntu Pro heif-thumbnailer 1.6.1-1ubuntu0.1~esm3 Available with Ubuntu Pro libheif-dev 1.6.1-1ubuntu0.1~esm3 Available with Ubuntu Pro libheif1 1.6.1-1ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS libheif-dev 1.1.0-2ubuntu0.1~esm3 Available with Ubuntu Pro libheif1 1.1.0-2ubuntu0.1~esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8454-1 CVE-2026-32738, CVE-2026-32739, CVE-2026-32740, CVE-2026-32741, CVE-2026-32814, CVE-2026-32882, CVE-2026-3950, CVE-2026-41069, CVE-2026-41071 Package Information: https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1 https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4 https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4 . Multiple security issues in libheif require immediate updates for affected Ubuntu releases to prevent potential attacks.. libheif security fix, Ubuntu update advisory, denial of service vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 18, 2026 Critical Ubuntu
203

Mageia: 2020-0131 Moderate: HTTP-Parser Request Smuggling Issue

http-parser has been updated to fix a security issue. HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed (VE-2019-15605). . MGASA-2020-0131 - Updated http-parser packages fix security vulnerability Publication date: 08 Mar 2020 URL: https://advisories.mageia.org/MGASA-2020-0131.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-15605 http-parser has been updated to fix a security issue. HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed (VE-2019-15605). References: - https://bugs.mageia.org/show_bug.cgi?id=26293 - https://access.redhat.com/errata/RHSA-2020:0703 - https://www.cve.org/CVERecord?id=CVE-2019-15605 SRPMS: - 7/core/http-parser-2.9.3-1.mga7 . Mageia enhances its HTTP-parser to tackle transfer-encoding smuggling vulnerabilities affecting various Node.js releases.. HTTP Request Smuggling, Mageia Security Update, Node.js Vulnerability. . LinuxSecurity.com Team

Calendar%202 Mar 08, 2020 Mageia
91

Gentoo: GLSA 200612-15 High: McAfee VirusScan Remote Code Execution

McAfee VirusScan for Linux is distributed with an insecure DT_RPATH, potentially allowing a remote attacker to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200612-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: McAfee VirusScan: Insecure DT_RPATH Date: December 14, 2006 Bugs: #156989 ID: 200612-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= McAfee VirusScan for Linux is distributed with an insecure DT_RPATH, potentially allowing a remote attacker to execute arbitrary code. Background ========= McAfee VirusScan for Linux is a commercial antivirus solution for Linux. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-antivirus/vlnx

Calendar%202 Dec 14, 2006 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200