Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 41: FEDORA-2025-8fdb7be3cb moderate: libheif out-of-bounds read

Latest upstream release. It adds support for tiles and fixes reading images generated by iOS 18+. See https://github.com/strukturag/libheif/releases for more details about the changes since 1.17.6. NOTE: heif-convert tool was renamed to heif-dec. How to test:. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-8fdb7be3cb 2025-02-15 02:35:33.711225+00:00 -------------------------------------------------------------------------------- Name : libheif Product : Fedora 41 Version : 1.19.5 Release : 3.fc41 URL : https://github.com/strukturag/libheif Summary : HEIF and AVIF file format decoder and encoder Description : libheif is an ISO/IEC 23008-12:2017 HEIF and AVIF (AV1 Image File Format) file format decoder and encoder. -------------------------------------------------------------------------------- Update Information: Latest upstream release. It adds support for tiles and fixes reading images generated by iOS 18+. See https://github.com/strukturag/libheif/releases for more details about the changes since 1.17.6. NOTE: heif-convert tool was renamed to heif-dec. How to test: Download and unzip sample images from mastodon issue #31570. Try opening them with e.g. loupe or gimp. They fail to open with libheif-1.17.6, but should open successfully with libheif-1.19.5. Fixes CVE-2024-41311 . -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 5 2025 Robert-André Mauchin - 1.19.5-3 - Rebuilt for aom 3.11.0 * Fri Jan 17 2025 Fedora Release Engineering - 1.19.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Sun Nov 24 2024 Packit - 1.19.5-1 - Update to version 1.19.5 - Resolves: rhbz#2327307 * Sun Nov 17 2024 Dominik Mierzejewski - 1.19.3-3 - disable OpenJPH encoder support to work-around crashes * Sat Nov 16 2024 Sérgio Basto - 1.19.3-2 - Add support to multilib in devel sub-package - Resolves: rhbz#2279891 * Tue Nov 12 2024Dominik Mierzejewski - 1.19.3-1 - update to 1.19.3 (resolves rhbz#2295525) - drop obsolete patches - enable OpenH264, OpenJPH (64-bit only) and Brotli decoders - run tests unconditionally, they no longer require special build options - drop conditional hevc subpackage - use fewer wildcards in the file lists - stop building rav1e and svt AV1 encoders as plugins -------------------------------------------------------------------------------- References: [ 1 ] Bug #2319289 - CVE-2024-41311 libheif: OOB read and write via ImageOverlay::parse() [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2319289 [ 2 ] Bug #2332519 - Update libheif https://bugzilla.redhat.com/show_bug.cgi?id=2332519 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-8fdb7be3cb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- . The recent Libheif enhancements for Fedora 41 address issues related to iOS image handling and additional features. Keep your software current to maintain the highest level of security.. Fedora 41, libheif update, security advisory, encoder security fixes. . LinuxSecurity.com Team

Calendar 2 Feb 15, 2025 Fedora
89

Fedora 40: Update for ONNX 1.14.1 Critical Security Issues

Security fix for CVE-2024-27318 and CVE-2024-27319. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-abe1e34fdb 2024-03-29 00:16:07.816413 -------------------------------------------------------------------------------- Name : onnx Product : Fedora 40 Version : 1.14.1 Release : 2.fc40 URL : Summary : Open standard for machine learning interoperability Description : onnx provides an open source format for AI models, both deep learning and traditional ML. It defines an extensible computation graph model, as well as definitions of built-in operators and standard data types. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2024-27318 and CVE-2024-27319 -------------------------------------------------------------------------------- ChangeLog: * Sat Feb 24 2024 Alejandro Alvarez Ayllon - 1.14.1-2 - Backport of fixes for CVE-2024-27318 and CVE-2024-27319 * Wed Feb 21 2024 Diego Herrera C - 1.14.1-1 - Release 1.14.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2265737 - CVE-2024-27318 onnx: directory traversal https://bugzilla.redhat.com/show_bug.cgi?id=2265737 [ 2 ] Bug #2265739 - CVE-2024-27319 onnx: oob read https://bugzilla.redhat.com/show_bug.cgi?id=2265739 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-abe1e34fdb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 40's latest ONNX update tackles critical security issues, including CVE-2024-27318 and CVE-2024-27319. Ensure system security by following the installation guidelines provided below. Fedora 40, ONNX Security, CVE-2024-27318, CVE-2024-27319, Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 29, 2024 Critical Fedora
203

Mageia: 2023:0209 Critical: OOB Read And Integer Overflow

The OOB read and integer-overflow made by attacker may lead to crash, high consumption of memory or even other more serious consequences. (CVE-2023-32307) References: . MGASA-2023-0209 - Updated sofia-sip packages fix security vulnerability Publication date: 28 Jun 2023 URL: https://advisories.mageia.org/MGASA-2023-0209.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-32307 The OOB read and integer-overflow made by attacker may lead to crash, high consumption of memory or even other more serious consequences. (CVE-2023-32307) References: - https://bugs.mageia.org/show_bug.cgi?id=32020 - https://lists.debian.org/debian-lts-announce/2023/06/msg00002.html - https://www.cve.org/CVERecord?id=CVE-2023-32307 SRPMS: - 8/core/sofia-sip-1.12.11-10.4.mga8 . Revised sofia-sip modules address out-of-bounds read and integer overflow vulnerabilities, which could result in system crashes and excessive memory consumption.. Mageia Security, Sofia-SIP, Memory Management, Integer Overflow Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 28, 2023 Critical Mageia
203

Mageia 8: 2021-0239 Critical: cgal Out-Of-Bounds Read Security Update

Updated cgal packages fix security vulnerabilities: An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of[] OOB read. An attacker can provide malicious input to trigger this vulnerability (CVE-2020-28601). . MGASA-2021-0239 - Updated cgal packages fix security vulnerabilities Publication date: 08 Jun 2021 URL: https://advisories.mageia.org/MGASA-2021-0239.html Type: security Affected Mageia releases: 8 CVE: CVE-2020-28601, CVE-2020-28636, CVE-2020-35628, CVE-2020-35636 Updated cgal packages fix security vulnerabilities: An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of[] OOB read. An attacker can provide malicious input to trigger this vulnerability (CVE-2020-28601). An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh-> twin() An attacker can provide malicious input to trigger this vulnerability (CVE-2020-28636). An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh-> incident_sface. An attacker can provide malicious input to trigger this vulnerability (CVE-2020-35628). An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sface() sfh-> volume(). An attacker can provide malicious input to trigger this vulnerability (CVE-2020-35636). The cgal package has been updated to version 5.2.1, fixing the issues and other bugs. The openfoam and openscad packages have been rebuilt against the updated cgal library. References: - https://bugs.mageia.org/show_bug.cgi?id=28881 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/E4J344OKKDLPRN422OYRR46HDEN6MM6P/ - https://www.cve.org/CVERecord?id=CVE-2020-28601 - https://www.cve.org/CVERecord?id=CVE-2020-28636 - https://www.cve.org/CVERecord?id=CVE-2020-35628 - https://www.cve.org/CVERecord?id=CVE-2020-35636 SRPMS: - 8/core/cgal-5.2.1-1.mga8 - 8/core/openfoam-7-17.1.mga8 - 8/core/openscad-2021.01-1.1.mga8 . Recent cgal updatesin Mageia address critical out-of-bounds read issues. Essential for maintaining system security on vulnerable editions.. Mageia Security Advisory, cgal Package Update, OOB Read Issue, Mageia 8 Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 08, 2021 Critical Mageia
197

Debian 10: DLA-2650-1 High-Risk: GnuTLS Remote Exploitation Vulnerabilities

Four security issues have been discovered in cgal. A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL. CVE-2020-28601 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2649-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Anton Gladky May 04, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : cgal Version : 4.9-1+deb9u1 CVE ID : CVE-2020-28601 CVE-2020-28636 CVE-2020-35628 CVE-2020-35636 Four security issues have been discovered in cgal. A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL. CVE-2020-28601 An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of[] OOB read. An attacker can provide malicious input to trigger this vulnerability. CVE-2020-28636 An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh-> twin() An attacker can provide malicious input to trigger this vulnerability. CVE-2020-35628 An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh-> incident_sface. An attacker can provide malicious input to trigger this vulnerability. CVE-2020-35636 An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sface() sfh-> volume(). An attacker can provide malicious input to trigger this vulnerability. For Debian 9 stretch, these problems have been fixed in version 4.9-1+deb9u1. We recommend that you upgrade your cgal packages. For the detailed security status of cgal please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/cgal Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at:https://wiki.debian.org/LTS . Uncover patches for cgal weaknesses in Debian LTS DLA-2650-1, tackling arbitrary code execution glitches and beyond.. Debian Security Advisory, CGAL Code Execution, Debian LTS Updates, cgal Security Fixes. . LinuxSecurity.com Team

Calendar 2 May 05, 2021 Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here