Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
197

Debian: FFmpeg Critical Denial of Service Threat DLA-4440-1 CVE-2023-6603

Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. CVE-2023-6603 A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4440-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Carlos Henrique Lima Melara January 16, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : ffmpeg Version : 7:4.3.9-0+deb11u2 CVE ID : CVE-2023-6603 CVE-2024-36615 CVE-2025-1594 CVE-2025-7700 CVE-2025-9951 CVE-2025-10256 CVE-2025-63757 Debian Bug : Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. CVE-2023-6603 A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a denial of service via a maliciously crafted HLS playlist that triggers a null pointer dereference during initialization. CVE-2024-36615 FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread. CVE-2025-1594 A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. CVE-2025-7700 A flaw was found in FFmpeg’sALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrupt services and cause a denial of service. CVE-2025-9951 A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000. CVE-2025-10256 A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service. CVE-2025-63757 Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0. For Debian 11 bullseye, these problems have been fixed in version 7:4.3.9-0+deb11u2. We recommend that you upgrade your ffmpeg packages. For the detailed security status of ffmpeg please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ffmpeg Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Explore critical FFmpeg security updates with details on multiple vulnerabilities affecting multimedia processing.. FFmpeg update, Debian LTS, security patch, media framework, denial of service. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 16, 2026 Critical Debian LTS
203

Mageia 9: 2025-0085 critical: FFmpeg DoS and Memory Corruption Issues

A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file. (CVE-2025-22919) A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted . MGASA-2025-0085 - Updated ffmpeg packages fix security vulnerabilities Publication date: 02 Mar 2025 URL: https://advisories.mageia.org/MGASA-2025-0085.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-0518, CVE-2025-22919, CVE-2025-22920, CVE-2025-22921, CVE-2025-25473 A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file. (CVE-2025-22919) A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS). (CVE-2025-22920) FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c. (CVE-2025-22921) FFmpeg git master before commit c08d30 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c. (CVE-2025-25473) References: - https://bugs.mageia.org/show_bug.cgi?id=34054 - - https://www.cve.org/CVERecord?id=CVE-2025-0518 - https://www.cve.org/CVERecord?id=CVE-2025-22919 - https://www.cve.org/CVERecord?id=CVE-2025-22920 - https://www.cve.org/CVERecord?id=CVE-2025-22921 - https://www.cve.org/CVERecord?id=CVE-2025-25473 SRPMS: - 9/core/ffmpeg-5.1.6-1.3.mga9 - 9/tainted/ffmpeg-5.1.6-1.3.mga9.tainted . Enhanced ffmpeg versions address various vulnerabilities in Mageia. Critical notice, examine for specifics.. FFmpeg Security,Mageia Updates,Denial of Service Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 02, 2025 Critical Mageia
89

Fedora 41: FEDORA-2024-0a5722a980 critical: mingw-gstreamer1 security fix

Update to gstreamer-1.24.10, fixes multiple CVEs.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-0a5722a980 2024-12-22 02:00:45.594041+00:00 -------------------------------------------------------------------------------- Name : mingw-gstreamer1 Product : Fedora 41 Version : 1.24.10 Release : 1.fc41 URL : http://gstreamer.freedesktop.org/ Summary : MinGW Windows Streaming-Media Framework Runtime Description : GStreamer is a streaming-media framework, based on graphs of filters which operate on media data. Applications using this library can do anything from real-time sound processing to playing videos, and just about anything else media-related. Its plug-in-based architecture means that new data types or processing capabilities can be added by installing new plug-ins. -------------------------------------------------------------------------------- Update Information: Update to gstreamer-1.24.10, fixes multiple CVEs. -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 6 2024 Sandro Mani - 1.24.10-1 - Update to 1.24.10 * Tue Nov 5 2024 Sandro Mani - 1.24.9-1 - Update to 1.24.9 * Mon Sep 23 2024 Sandro Mani - 1.24.8-1 - Update to 1.24.8 * Fri Aug 23 2024 Sandro Mani - 1.24.7-1 - Update to 1.24.7 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2331794 - CVE-2024-47542 mingw-gstreamer1-plugins-base: ID3v2 parser out-of-bounds read and NULL-pointer dereference [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331794 [ 2 ] Bug #2331798 - CVE-2024-47540 mingw-gstreamer1-plugins-good: uninitialized stack memory in Matroska/WebM demuxer [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331798 [ 3 ] Bug #2331815 - CVE-2024-47537 mingw-gstreamer1-plugins-good: OOB-write in isomp4/qtdemux.c [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331815 [ 4 ] Bug #2331819 - CVE-2024-47539 mingw-gstreamer1-plugins-good: OOB-write in convert_to_s334_1a [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331819 [ 5 ] Bug #2331829 - CVE-2024-47538 mingw-gstreamer1-plugins-base: GStreamer has a stack-buffer overflow in vorbis_handle_identification_packet [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331829 [ 6 ] Bug #2331865 - CVE-2024-47615 mingw-gstreamer1-plugins-base: out-of-bounds write in Ogg demuxer [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331865 [ 7 ] Bug #2331875 - CVE-2024-47607 mingw-gstreamer1-plugins-base: stack-buffer overflow in gst_opus_dec_parse_header [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331875 [ 8 ] Bug #2331890 - CVE-2024-47606 mingw-gstreamer1-plugins-good: integer overflows in MP4/MOV demuxer and memory allocator that can lead to out-of-bounds writes [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331890 [ 9 ] Bug #2331894 - CVE-2024-47543 mingw-gstreamer1-plugins-good: OOB-read in qtdemux_parse_container [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331894 [ 10 ] Bug #2331899 - CVE-2024-47541 mingw-gstreamer1-plugins-base: GStreamer has an out-of-bounds write in SSA subtitle parser [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331899 [ 11 ] Bug #2331903 - CVE-2024-47600 mingw-gstreamer1-plugins-base: GStreamer has an OOB-read in format_channel_mask [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331903 [ 12 ] Bug #2331907 - CVE-2024-47774 mingw-gstreamer1-plugins-good: GStreamer has an OOB-read in gst_avi_subtitle_parse_gab2_chunk [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331907 [ 13 ] Bug #2332091 - CVE-2024-47777 mingw-gstreamer1-plugins-good: OOB-read in gst_wavparse_smpl_chunk [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332091 [ 14 ] Bug #2332093 -CVE-2024-47835 mingw-gstreamer1-plugins-base: NULL-pointer dereference in LRC subtitle parser [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332093 [ 15 ] Bug #2332096 - CVE-2024-47778 mingw-gstreamer1-plugins-good: OOB-read in gst_wavparse_adtl_chunk [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332096 [ 16 ] Bug #2332098 - CVE-2024-47775 mingw-gstreamer1-plugins-good: OOB-read in parse_ds64 [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332098 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-0a5722a980' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . The mingw-gstreamer1 1.24.10 release introduces crucial security enhancements for Fedora users, bolstering protection against significant vulnerabilities.. mingw-gstreamer1, Fedora 41, security fixes, streaming media. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 22, 2024 Critical Fedora
89

Fedora 39: FEDORA-2023-7b5dcd5e22 Severe Stack Overflow

1.22.7. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-6a4aea6d13 2023-11-19 01:23:27.465357 -------------------------------------------------------------------------------- Name : gstreamer1-plugins-good Product : Fedora 39 Version : 1.22.7 Release : 1.fc39 URL : https://gstreamer.freedesktop.org/ Summary : GStreamer plugins with good code and licensing Description : GStreamer is a streaming media framework, based on graphs of filters which operate on media data. Applications using this library can do anything from real-time sound processing to playing videos, and just about anything else media-related. Its plugin-based architecture means that new data types or processing capabilities can be added simply by installing new plugins. GStreamer Good Plugins is a collection of well-supported plugins of good quality and under the LGPL license. -------------------------------------------------------------------------------- Update Information: 1.22.7 -------------------------------------------------------------------------------- ChangeLog: * Tue Nov 14 2023 Gwyn Ciesla - 1.22.7-1 - 1.22.7 * Fri Oct 13 2023 Jan Grulich - 1.22.5-3 - Rebuild (qt6) * Thu Oct 5 2023 Jan Grulich - 1.22.5-2 - Rebuild (qt6) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2250248 - CVE-2023-44429 gstreamer1-plugins-bad-free: gstreamer: AV1 codec parser buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2250248 [ 2 ] Bug #2250250 - CVE-2023-44446 gstreamer1-plugins-bad-free: gstreamer: MXF demuxer use-after-free vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2250250 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2023-6a4aea6d13' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Important Fedora patch for gstreamer1-plugins-good version 1.22.7 addresses existing problems linked to multimedia handling.. Fedora Update,Gstreamer Plugins,Software Patch,Media Processing,Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 19, 2023 Critical Fedora
89

Fedora 39: Advisory 2023-6a4aea6d13 Critical: GStreamer Buffer Overflow

1.22.7. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-6a4aea6d13 2023-11-19 01:23:27.465357 -------------------------------------------------------------------------------- Name : gstreamer1-plugin-libav Product : Fedora 39 Version : 1.22.7 Release : 1.fc39 URL : https://gstreamer.freedesktop.org/ Summary : GStreamer FFmpeg/LibAV plugin Description : GStreamer is a streaming media framework, based on graphs of filters which operate on media data. Applications using this library can do anything from real-time sound processing to playing videos, and just about anything else media-related. Its plugin-based architecture means that new data types or processing capabilities can be added simply by installing new plugins. This package provides FFmpeg/LibAV GStreamer plugin. -------------------------------------------------------------------------------- Update Information: 1.22.7 -------------------------------------------------------------------------------- ChangeLog: * Tue Nov 14 2023 Gwyn Ciesla - 1.22.7-1 - 1.22.7 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2250248 - CVE-2023-44429 gstreamer1-plugins-bad-free: gstreamer: AV1 codec parser buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2250248 [ 2 ] Bug #2250250 - CVE-2023-44446 gstreamer1-plugins-bad-free: gstreamer: MXF demuxer use-after-free vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2250250 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-6a4aea6d13' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora ProjectGPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The release of Gstreamer1-plugin-libav version 1.22.7 addresses several significant vulnerabilities in Fedora 39, bolstering its security mechanisms.. GStreamer FFmpeg, Media Processing Plugin, Fedora 39 Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 19, 2023 Critical Fedora
87

Debian: DSA-5183-1 Critical: Wpewebkit Code Execution Issue

The following vulnerabilities have been discovered in the WPE WebKit web engine: CVE-2022-22677 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5183-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Alberto Garcia July 15, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : wpewebkit CVE ID : CVE-2022-22677 CVE-2022-26710 The following vulnerabilities have been discovered in the WPE WebKit web engine: CVE-2022-22677 An anonymous researcher discovered that the video in a webRTC call may be interrupted if the audio capture gets interrupted. CVE-2022-26710 Chijin Zhou discovered that processing maliciously crafted web content may lead to arbitrary code execution. For the stable distribution (bullseye), these problems have been fixed in version 2.36.4-1~deb11u1. We recommend that you upgrade your wpewebkit packages. For the detailed security status of wpewebkit please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/wpewebkit Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Update the wpewebkit framework to address vulnerabilities noted in DSA-5183-1, particularly those relating to potential remote code execution threats.. wpewebkit Update, Debian Security, WebRTC Risks, Media Processing Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 14, 2022 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here