Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 18 articles for you...
172

Ubuntu 25.10 FFmpeg Critical Memory Issues Denial of Service USN-7982-1

Several security issues were fixed in FFmpeg.. ========================================================================== Ubuntu Security Notice USN-7982-1 January 27, 2026 ffmpeg vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in FFmpeg. Software Description: - ffmpeg: Tools for transcoding, streaming and playing of multimedia files Details: It was discovered that FFmpeg did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.10. (CVE-2025-59728) It was discovered that FFmpeg did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.10. (CVE-2025-59731, CVE-2025-59732) It was discovered that FFmpeg did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.10. (CVE-2025-59733) It was discovered that FFmpeg did not correctly handle certain integer arithmetic operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2025-63757) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 ffmpeg 7:7.1.1-1ubuntu4.2 libavcodec61 7:7.1.1-1ubuntu4.2 libavformat61 7:7.1.1-1ubuntu4.2 Ubuntu 24.04 LTS ffmpeg 7:6.1.1-3ubuntu5+esm7 Available with Ubuntu Pro libavcodec60 7:6.1.1-3ubuntu5+esm7 Available with Ubuntu Pro libavformat60 7:6.1.1-3ubuntu5+esm7 Available with Ubuntu Pro Ubuntu 22.04 LTS ffmpeg 7:4.4.2-0ubuntu0.22.04.1+esm11 Available with Ubuntu Pro libavcodec58 7:4.4.2-0ubuntu0.22.04.1+esm11 Available with Ubuntu Pro libavformat58 7:4.4.2-0ubuntu0.22.04.1+esm11 Available with Ubuntu Pro Ubuntu 20.04 LTS ffmpeg 7:4.2.7-0ubuntu0.1+esm12 Available with Ubuntu Pro libavcodec58 7:4.2.7-0ubuntu0.1+esm12 Available with Ubuntu Pro libavformat58 7:4.2.7-0ubuntu0.1+esm12 Available with Ubuntu Pro Ubuntu 18.04 LTS ffmpeg 7:3.4.11-0ubuntu0.1+esm12 Available with Ubuntu Pro libavcodec57 7:3.4.11-0ubuntu0.1+esm12 Available with Ubuntu Pro libavformat57 7:3.4.11-0ubuntu0.1+esm12 Available with Ubuntu Pro Ubuntu 16.04 LTS ffmpeg 7:2.8.17-0ubuntu0.1+esm14 Available with Ubuntu Pro libavcodec-extra 7:2.8.17-0ubuntu0.1+esm14 Available with Ubuntu Pro libavcodec-ffmpeg56 7:2.8.17-0ubuntu0.1+esm14 Available with Ubuntu Pro libavformat-ffmpeg56 7:2.8.17-0ubuntu0.1+esm14 Available with Ubuntu Pro In general, a standard system update will make all the necessarychanges. References: https://ubuntu.com/security/notices/USN-7982-1 CVE-2025-59728, CVE-2025-59731, CVE-2025-59732, CVE-2025-59733, CVE-2025-63757 Package Information: https://launchpad.net/ubuntu/+source/ffmpeg/7:7.1.1-1ubuntu4.2 . Learn about recent security fixes for FFmpeg on Ubuntu that address potential memory operation flaws and denial of service threats.. FFmpeg security, Ubuntu security advisory, memory operations fix, denial of service threat. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 28, 2026 Critical Ubuntu
172

Ubuntu 25.10: libheif Critical Denial of Service Issues USN-7952-1

Several security issues were fixed in libheif.. ========================================================================== Ubuntu Security Notice USN-7952-1 January 12, 2026 libheif vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in libheif. Software Description: - libheif: An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder Details: It was discovered that libheif did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-25269) Aldo Ristori discovered that libheif did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2025-68431) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 libheif1 1.20.2-1ubuntu0.1 Ubuntu 25.04 libheif1 1.19.7-1ubuntu0.1 Ubuntu 24.04 LTS libheif1 1.17.6-1ubuntu4.2 Ubuntu 22.04 LTS libheif1 1.12.0-2ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 20.04 LTS libheif1 1.6.1-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS libheif1 1.1.0-2ubuntu0.1~esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7952-1 CVE-2024-25269, CVE-2025-68431 Package Information: https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libheif/1.19.7-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.2 . Several security fixes are issued for libheif in Ubuntu affecting multiple LTS versions. Update instructions included.. Ubuntu security, libheif update, memory operations, critical threats. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 12, 2026 Critical Ubuntu
172

Ubuntu 25.04: USN-7631-1 critical: DjVuLibre denial of service

DjVuLibre could be made to crash or run programs if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-7631-1 July 09, 2025 djvulibre vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: DjVuLibre could be made to crash or run programs if it opened a specially crafted file. Software Description: - djvulibre: DjVu image format library and tools Details: It was discovered that DjVuLibre incorrectly handled certain memory operations. If a user or automated system were tricked into processing a specially crafted DjVu file, a remote attacker could cause applications to stop responding or crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 libdjvulibre21 3.5.28-2ubuntu0.25.04.1 Ubuntu 24.04 LTS libdjvulibre21 3.5.28-2ubuntu0.24.04.1 Ubuntu 22.04 LTS libdjvulibre21 3.5.28-2ubuntu0.22.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7631-1 CVE-2025-53367 Package Information: https://launchpad.net/ubuntu/+source/djvulibre/3.5.28-2ubuntu0.25.04.1 https://launchpad.net/ubuntu/+source/djvulibre/3.5.28-2ubuntu0.24.04.1 https://launchpad.net/ubuntu/+source/djvulibre/3.5.28-2ubuntu0.22.04.1 . A vulnerability in DjVuLibre could cause system crashes and allow remote code execution; ensure your Ubuntu installations are updated immediately to avoid potential threats.. DjVuLibre vulnerability, Ubuntu security update, remote code execution, crash prevention, denial of service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 09, 2025 Critical Ubuntu
172

Ubuntu 25.04: 7538-1 critical: FFmpeg remote code execution risk

Several security issues were fixed in FFmpeg.. ========================================================================== Ubuntu Security Notice USN-7538-1 May 28, 2025 ffmpeg vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in FFmpeg. Software Description: - ffmpeg: Tools for transcoding, streaming and playing of multimedia files Details: Simcha Kosman discovered that FFmpeg did not correctly handle certain return values. An attacker could possibly use this issue to leak sensitive information. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2025-0518) It was discovered that FFmpeg did not correctly handle certain memory operations. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 24.10. (CVE-2025-1816) It was discovered that FFmpeg contained a reachable assertion, which could lead to a failure when processing certain AAC files. If a user or automated system were tricked into opening a specially crafted AAC file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2025-22919) It was discovered that FFmpeg did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 24.10 and Ubuntu 25.04. (CVE-2025-22921) It was discovered that FFmpeg did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service or executearbitrary code. This issue only affected Ubuntu 24.04 LTS, Ubuntu 24.10 and Ubuntu 25.04. (CVE-2025-25473) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 ffmpeg 7:7.1.1-1ubuntu1.1 libavcodec-extra61 7:7.1.1-1ubuntu1.1 libavcodec61 7:7.1.1-1ubuntu1.1 libavdevice61 7:7.1.1-1ubuntu1.1 libavfilter-extra10 7:7.1.1-1ubuntu1.1 libavfilter10 7:7.1.1-1ubuntu1.1 libavformat-extra61 7:7.1.1-1ubuntu1.1 libavformat61 7:7.1.1-1ubuntu1.1 libavutil59 7:7.1.1-1ubuntu1.1 libpostproc58 7:7.1.1-1ubuntu1.1 libswresample5 7:7.1.1-1ubuntu1.1 libswscale8 7:7.1.1-1ubuntu1.1 Ubuntu 24.10 ffmpeg 7:7.0.2-3ubuntu1.1 libavcodec-extra61 7:7.0.2-3ubuntu1.1 libavcodec61 7:7.0.2-3ubuntu1.1 libavdevice61 7:7.0.2-3ubuntu1.1 libavfilter-extra10 7:7.0.2-3ubuntu1.1 libavfilter10 7:7.0.2-3ubuntu1.1 libavformat-extra61 7:7.0.2-3ubuntu1.1 libavformat61 7:7.0.2-3ubuntu1.1 libavutil59 7:7.0.2-3ubuntu1.1 libpostproc58 7:7.0.2-3ubuntu1.1 libswresample5 7:7.0.2-3ubuntu1.1 libswscale8 7:7.0.2-3ubuntu1.1 Ubuntu 24.04 LTS ffmpeg 7:6.1.1-3ubuntu5+esm3 Available with Ubuntu Pro libavcodec-extra60 7:6.1.1-3ubuntu5+esm3 Available with Ubuntu Pro libavcodec60 7:6.1.1-3ubuntu5+esm3 Available with Ubuntu Pro libavdevice60 7:6.1.1-3ubuntu5+esm3 Available with Ubuntu Pro libavfilter-extra9 7:6.1.1-3ubuntu5+esm3 Available with Ubuntu Pro libavfilter9 7:6.1.1-3ubuntu5+esm3 Available with Ubuntu Pro libavformat-extra60 7:6.1.1-3ubuntu5+esm3 Available with Ubuntu Pro libavformat60 7:6.1.1-3ubuntu5+esm3 Available with Ubuntu Pro libavutil58 7:6.1.1-3ubuntu5+esm3 Available with Ubuntu Pro libpostproc57 7:6.1.1-3ubuntu5+esm3 Available with Ubuntu Pro libswresample4 7:6.1.1-3ubuntu5+esm3 Available with Ubuntu Pro libswscale7 7:6.1.1-3ubuntu5+esm3 Available with Ubuntu Pro Ubuntu 22.04 LTS ffmpeg 7:4.4.2-0ubuntu0.22.04.1+esm7 Available with Ubuntu Pro libavcodec-extra58 7:4.4.2-0ubuntu0.22.04.1+esm7 Available with Ubuntu Pro libavcodec58 7:4.4.2-0ubuntu0.22.04.1+esm7 Available with Ubuntu Pro libavdevice58 7:4.4.2-0ubuntu0.22.04.1+esm7 Available with Ubuntu Pro libavfilter-extra7 7:4.4.2-0ubuntu0.22.04.1+esm7 Available with Ubuntu Pro libavfilter7 7:4.4.2-0ubuntu0.22.04.1+esm7 Available with Ubuntu Pro libavformat-extra58 7:4.4.2-0ubuntu0.22.04.1+esm7 Available with Ubuntu Pro libavformat58 7:4.4.2-0ubuntu0.22.04.1+esm7 Available with Ubuntu Pro libavutil56 7:4.4.2-0ubuntu0.22.04.1+esm7 Available with Ubuntu Pro libpostproc55 7:4.4.2-0ubuntu0.22.04.1+esm7 Available with Ubuntu Pro libswresample3 7:4.4.2-0ubuntu0.22.04.1+esm7 Available with Ubuntu Pro libswscale5 7:4.4.2-0ubuntu0.22.04.1+esm7 Available with Ubuntu Pro Ubuntu 20.04 LTS ffmpeg 7:4.2.7-0ubuntu0.1+esm8 Available with Ubuntu Pro libavcodec-extra58 7:4.2.7-0ubuntu0.1+esm8 Available with Ubuntu Pro libavcodec58 7:4.2.7-0ubuntu0.1+esm8 Available with Ubuntu Pro libavdevice58 7:4.2.7-0ubuntu0.1+esm8 Available with Ubuntu Pro libavfilter-extra7 7:4.2.7-0ubuntu0.1+esm8 Available with Ubuntu Pro libavfilter7 7:4.2.7-0ubuntu0.1+esm8 Available with Ubuntu Pro libavformat58 7:4.2.7-0ubuntu0.1+esm8 Available with Ubuntu Pro libavresample4 7:4.2.7-0ubuntu0.1+esm8 Available with Ubuntu Pro libavutil56 7:4.2.7-0ubuntu0.1+esm8 Available with Ubuntu Pro libpostproc55 7:4.2.7-0ubuntu0.1+esm8 Available with Ubuntu Pro libswresample3 7:4.2.7-0ubuntu0.1+esm8 Available with Ubuntu Pro libswscale5 7:4.2.7-0ubuntu0.1+esm8 Available with Ubuntu Pro Ubuntu 18.04 LTS ffmpeg 7:3.4.11-0ubuntu0.1+esm8 Available with Ubuntu Pro libavcodec-extra57 7:3.4.11-0ubuntu0.1+esm8 Available with Ubuntu Pro libavcodec57 7:3.4.11-0ubuntu0.1+esm8 Available with Ubuntu Pro libavdevice57 7:3.4.11-0ubuntu0.1+esm8 Available with Ubuntu Pro libavfilter-extra6 7:3.4.11-0ubuntu0.1+esm8 Available with Ubuntu Pro libavfilter6 7:3.4.11-0ubuntu0.1+esm8 Available with Ubuntu Pro libavformat57 7:3.4.11-0ubuntu0.1+esm8 Available with Ubuntu Pro libavresample3 7:3.4.11-0ubuntu0.1+esm8 Available with Ubuntu Pro libavutil55 7:3.4.11-0ubuntu0.1+esm8 Available with Ubuntu Pro libpostproc54 7:3.4.11-0ubuntu0.1+esm8 Available with Ubuntu Pro libswresample2 7:3.4.11-0ubuntu0.1+esm8 Available with Ubuntu Pro libswscale4 7:3.4.11-0ubuntu0.1+esm8 Available with Ubuntu Pro Ubuntu 16.04 LTS ffmpeg 7:2.8.17-0ubuntu0.1+esm10 Available with Ubuntu Pro libav-tools 7:2.8.17-0ubuntu0.1+esm10 Available with Ubuntu Pro libavcodec-ffmpeg-extra56 7:2.8.17-0ubuntu0.1+esm10 Available with Ubuntu Pro libavcodec-ffmpeg56 7:2.8.17-0ubuntu0.1+esm10 Available with Ubuntu Pro libavdevice-ffmpeg56 7:2.8.17-0ubuntu0.1+esm10 Available with Ubuntu Pro libavfilter-ffmpeg5 7:2.8.17-0ubuntu0.1+esm10 Available with Ubuntu Pro libavformat-ffmpeg56 7:2.8.17-0ubuntu0.1+esm10 Available with Ubuntu Pro libavresample-ffmpeg2 7:2.8.17-0ubuntu0.1+esm10 Available with Ubuntu Pro libavutil-ffmpeg54 7:2.8.17-0ubuntu0.1+esm10 Available with Ubuntu Pro libpostproc-ffmpeg53 7:2.8.17-0ubuntu0.1+esm10 Available with Ubuntu Pro libswresample-ffmpeg1 7:2.8.17-0ubuntu0.1+esm10 Available with Ubuntu Pro libswscale-ffmpeg3 7:2.8.17-0ubuntu0.1+esm10 Available with Ubuntu Pro After a standard system update you need to restart FFmpeg to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7538-1 CVE-2025-0518, CVE-2025-1816, CVE-2025-22919, CVE-2025-22921, CVE-2025-25473 Package Information: https://launchpad.net/ubuntu/+source/ffmpeg/7:7.1.1-1ubuntu1.1 https://launchpad.net/ubuntu/+source/ffmpeg/7:7.0.2-3ubuntu1.1 . A security patch from FFmpeg addresses vulnerabilities in multiple Ubuntu versions. Keep your system secure by applying the latest updates promptly. FFmpeg Security, Ubuntu Updates, Memory Operations Fixes, DoS Prevention. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 29, 2025 Critical Ubuntu
172

Ubuntu 25.04 Security Notice: libxml2 Denial of Service Risk

Several security issues were fixed in libxml2.. ========================================================================== Ubuntu Security Notice USN-7467-1 April 28, 2025 libxml2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in libxml2. Software Description: - libxml2: GNOME XML library Details: It was discovered that the libxml2 Python bindings incorrectly handled certain return values. An attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service. (CVE-2025-32414) It was discovered that libxml2 incorrectly handled certain memory operations. A remote attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service. (CVE-2025-32415) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 libxml2 2.12.7+dfsg+really2.9.14-0.4ubuntu0.1 python3-libxml2 2.12.7+dfsg+really2.9.14-0.4ubuntu0.1 Ubuntu 24.10 libxml2 2.12.7+dfsg-3ubuntu0.3 python3-libxml2 2.12.7+dfsg-3ubuntu0.3 Ubuntu 24.04 LTS libxml2 2.9.14+dfsg-1.3ubuntu3.3 python3-libxml2 2.9.14+dfsg-1.3ubuntu3.3 Ubuntu 22.04 LTS libxml2 2.9.13+dfsg-1ubuntu0.7 python3-libxml2 2.9.13+dfsg-1ubuntu0.7 Ubuntu 20.04 LTS libxml2 2.9.10+dfsg-5ubuntu0.20.04.10 python3-libxml2 2.9.10+dfsg-5ubuntu0.20.04.10 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7467-1 CVE-2025-32414, CVE-2025-32415 PackageInformation: https://launchpad.net/ubuntu/+source/libxml2/2.12.7+dfsg+really2.9.14-0.4ubuntu0.1 https://launchpad.net/ubuntu/+source/libxml2/2.12.7+dfsg-3ubuntu0.3 https://launchpad.net/ubuntu/+source/libxml2/2.9.14+dfsg-1.3ubuntu3.3 https://launchpad.net/ubuntu/+source/libxml2/2.9.13+dfsg-1ubuntu0.7 https://launchpad.net/ubuntu/+source/libxml2/2.9.10+dfsg-5ubuntu0.20.04.10 . Critical vulnerabilities in libxml2 addressed. Users urged to update to minimize crash threats and denial-of-service scenarios on Ubuntu.. libxml2 update, security advisory Ubuntu, libxml2 vulnerabilities, DoS prevention, software security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 28, 2025 Important Ubuntu
172

Ubuntu 7371-1: FreeRDP Security Advisory Updates

Several security issues were fixed in FreeRDP.. ========================================================================== Ubuntu Security Notice USN-7371-1 March 25, 2025 freerdp2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in FreeRDP. Software Description: - freerdp2: RDP client for Windows Terminal Services Details: Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory operations. If a user were tricked into connecting to a malicious server, a remote attacker could possibly use this issue to cause FreeRDP to crash, resulting in a denial of service. (CVE-2024-32458) Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory operations. A remote attacker could possibly use this issue to cause FreeRDP clients and servers to crash, resulting in a denial of service. (CVE-2024-32459) It was discovered that FreeRDP incorrectly handled certain memory operations. If a user were tricked into connecting to a malicious server, a remote attacker could possibly use this issue to cause FreeRDP to crash, resulting in a denial of service. (CVE-2024-32659, CVE-2024-32660) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libfreerdp-client2-2t64 2.11.5+dfsg1-1ubuntu0.1~esm2 Available with Ubuntu Pro libfreerdp-server2-2t64 2.11.5+dfsg1-1ubuntu0.1~esm2 Available with Ubuntu Pro libfreerdp2-2t64 2.11.5+dfsg1-1ubuntu0.1~esm2 Available with Ubuntu Pro In general, a standard system update will make all thenecessary changes. References: https://ubuntu.com/security/notices/USN-7371-1 CVE-2024-32458, CVE-2024-32459, CVE-2024-32659, CVE-2024-32660 . Critical security updates for FreeRDP in Ubuntu 24.04 LTS address multiple memory issues leading to denial of service.. security, freerdp, =====================================================. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 25, 2025 Critical Ubuntu
172

Ubuntu 7357-1: Libxslt Security Advisory Updates

Libxslt could be made to crash or run programs if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-7357-1 March 19, 2025 libxslt vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Libxslt could be made to crash or run programs if it opened a specially crafted file. Software Description: - libxslt: XSLT processing library Details: Ivan Fratric discovered that Libxslt incorrectly handled certain memory operations when handling documents. A remote attacker could use this issue to cause Libxslt to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 libxslt1.1 1.1.39-0exp1ubuntu1.1 Ubuntu 24.04 LTS libxslt1.1 1.1.39-0exp1ubuntu0.24.04.1 Ubuntu 22.04 LTS libxslt1.1 1.1.34-4ubuntu0.22.04.2 Ubuntu 20.04 LTS libxslt1.1 1.1.34-4ubuntu0.20.04.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7357-1 CVE-2024-55549 Package Information: https://launchpad.net/ubuntu/+source/libxslt/1.1.39-0exp1ubuntu1.1 https://launchpad.net/ubuntu/+source/libxslt/1.1.39-0exp1ubuntu0.24.04.1 https://launchpad.net/ubuntu/+source/libxslt/1.1.34-4ubuntu0.22.04.2 https://launchpad.net/ubuntu/+source/libxslt/1.1.34-4ubuntu0.20.04.2 . Critical update for libxslt on Ubuntu addresses a denial of service risk from improper memory handling.. libxslt, crash, programs, opened, specially, crafted, ==============. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 19, 2025 Important Ubuntu
172

Ubuntu 7352-2: FreeType Security Advisory Updates

Several security issues were fixed in FreeType.. ========================================================================== Ubuntu Security Notice USN-7352-2 March 17, 2025 freetype vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in FreeType. Software Description: - freetype: FreeType 2 is a font engine library Details: USN-7352-1 fixed a vulnerability in FreeType. This update provides the corresponding updates for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. This update also fixes an additional vulnerability in Ubuntu 14.04 LTS. Original advisory details: It was discovered that FreeType incorrectly handled certain memory operations when parsing font subglyph structures. A remote attacker could use this issue to cause FreeType to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2025-27363) Additional advisory details: It was discovered that FreeType incorrectly handled certain memory operations during typical execution. An attacker could possibly use this issue to cause FreeType to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2022-27406) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS libfreetype6 2.8.1-2ubuntu2.2+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libfreetype6 2.6.1-0.1ubuntu2.5+esm2 Available with Ubuntu Pro Ubuntu 14.04 LTS libfreetype6 2.5.2-1ubuntu2.8+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7352-2 https://ubuntu.com/security/notices/USN-7352-1 CVE-2022-27406, CVE-2025-27363 . Several important security issues fixed in FreeType versions for Ubuntu 14.04, 16.04, and 18.04 LTS. Immediate action is advised.. security, freetype, ====================================================. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 18, 2025 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200