Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 24 articles for you...
87

Debian Pillow Important DoS Code Exec Vulnern DSA-6357-1

Multiple security vulnerabilities have been discovered in Pillow, a Python imaging library, which could result in denial of service or the execution of arbitrary code if malformed files are processed. For the stable distribution (trixie), these problems have been fixed in version 11.1.0-5+deb13u3.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6357-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff June 21, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : pillow CVE ID : CVE-2026-42308 CVE-2026-42310 CVE-2026-42311 Multiple security vulnerabilities have been discovered in Pillow, a Python imaging library, which could result in denial of service or the execution of arbitrary code if malformed files are processed. For the stable distribution (trixie), these problems have been fixed in version 11.1.0-5+deb13u3. We recommend that you upgrade your pillow packages. For the detailed security status of pillow please refer to its security tracker page at: https://security-tracker.debian.org/tracker/pillow Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Upgrade Pillow on Debian to mitigate denial of service and code execution risks from multiple vulnerabilities.. Pillow Security Fix,debian DSA 6357-1,Pillow Denial of Service,Pillow Code Execution. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 21, 2026 Important Debian
172

Ubuntu 26.04 LTS 8399-1 Pillow Denial of Service Risk CVE-2026-42308

Several security issues were fixed in Pillow.. ========================================================================== Ubuntu Security Notice USN-8399-1 June 08, 2026 pillow vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Pillow. Software Description: - pillow: Python Imaging Library Details: It was discovered that Pillow incorrectly handled large glyph advance values in fonts. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service. (CVE-2026-42308) It was discovered that Pillow incorrectly handled nested coordinate lists in certain APIs. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42309) It was discovered that Pillow incorrectly handled certain malformed PDF files. An attacker could possibly use this issue to cause Pillow to use excessive resources, leading to a denial of service. (CVE-2026-42310) It was discovered that Pillow incorrectly handled certain malformed PSD files. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service, or to execute arbitrary code. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42311) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS python3-pil 12.1.1-2ubuntu1.2 Ubuntu 25.10 python3-pil 11.3.0-1ubuntu1.3 Ubuntu 24.04 LTS python3-pil 10.2.0-1ubuntu1.2 Ubuntu 22.04 LTS python3-pil 9.0.1-1ubuntu0.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8399-1 CVE-2026-42308, CVE-2026-42309, CVE-2026-42310, CVE-2026-42311 Package Information: https://launchpad.net/ubuntu/+source/pillow/12.1.1-2ubuntu1.2 https://launchpad.net/ubuntu/+source/pillow/11.3.0-1ubuntu1.3 https://launchpad.net/ubuntu/+source/pillow/10.2.0-1ubuntu1.2 https://launchpad.net/ubuntu/+source/pillow/9.0.1-1ubuntu0.4 . Several security issues fixed in Pillow for various Ubuntu releases prevent potential crashes and resource misuse.. Ubuntu security patches, Pillow library issues, Python Imaging denial of service, Ubuntu vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 08, 2026 Important Ubuntu
172

Ubuntu 26.04 Pillow Critical Denial of Service Vulnerabilities USN-8399-1

Several security issues were fixed in Pillow.. ========================================================================== Ubuntu Security Notice USN-8399-1 June 08, 2026 pillow vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Pillow. Software Description: - pillow: Python Imaging Library Details: It was discovered that Pillow incorrectly handled large glyph advance values in fonts. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service. (CVE-2026-42308) It was discovered that Pillow incorrectly handled nested coordinate lists in certain APIs. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42309) It was discovered that Pillow incorrectly handled certain malformed PDF files. An attacker could possibly use this issue to cause Pillow to use excessive resources, leading to a denial of service. (CVE-2026-42310) It was discovered that Pillow incorrectly handled certain malformed PSD files. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service, or to execute arbitrary code. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42311) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS python3-pil 12.1.1-2ubuntu1.2 Ubuntu 25.10 python3-pil 11.3.0-1ubuntu1.3 Ubuntu 24.04 LTS python3-pil 10.2.0-1ubuntu1.2 Ubuntu 22.04 LTS python3-pil 9.0.1-1ubuntu0.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8399-1 CVE-2026-42308, CVE-2026-42309, CVE-2026-42310, CVE-2026-42311 Package Information: https://launchpad.net/ubuntu/+source/pillow/12.1.1-2ubuntu1.2 https://launchpad.net/ubuntu/+source/pillow/11.3.0-1ubuntu1.3 https://launchpad.net/ubuntu/+source/pillow/10.2.0-1ubuntu1.2 https://launchpad.net/ubuntu/+source/pillow/9.0.1-1ubuntu0.4 . Explore critical updates to Pillow in Ubuntu, fixing multiple denial-of-service risks and enhancing system security.. Pillow update, Ubuntu security, denial of service, Pillow vulnerabilities, Ubuntu advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 08, 2026 Critical Ubuntu
172

Ubuntu 25.10 Pillow Severely Affected by DoS Resource Crash Flaw USN-8211-1

Pillow could be made to crash if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-8211-1 April 27, 2026 pillow vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 Summary: Pillow could be made to crash if it opened a specially crafted file. Software Description: - pillow: Python Imaging Library Details: It was discovered that Pillow incorrectly handled certain FITS images. An attacker could possibly use this issue to cause Pillow to consume resources, leading to a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 python3-pil 11.3.0-1ubuntu1.2 python3-pil.imagetk 11.3.0-1ubuntu1.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8211-1 CVE-2026-40192 Package Information: https://launchpad.net/ubuntu/+source/pillow/11.3.0-1ubuntu1.2 . Pillow crash risk on Ubuntu 25.10 addresses crucial update for denial of service vulnerability.. Ubuntu security,Pillow update,denial of service,security patch,resource crash. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 27, 2026 Important Ubuntu
87

Debian Trixie pillow Important DoS Risk DSA-6219-1 CVE-2026-40192

It was discovered that missing input sanitising in the FITS support of Pillow, a Python imaging library, could result in denial of service. The oldstable distribution (bookworm) is not affected. For the stable distribution (trixie), this problem has been fixed in version 11.1.0-5+deb13u2.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6219-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 19, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : pillow CVE ID : CVE-2026-40192 It was discovered that missing input sanitising in the FITS support of Pillow, a Python imaging library, could result in denial of service. The oldstable distribution (bookworm) is not affected. For the stable distribution (trixie), this problem has been fixed in version 11.1.0-5+deb13u2. We recommend that you upgrade your pillow packages. For the detailed security status of pillow please refer to its security tracker page at: https://security-tracker.debian.org/tracker/pillow Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Pillow library faces Denial of Service risk due to input sanitizing issue. Update recommended for stable distribution.. pillow library, debian security, input sanitizing, denial of service, security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 19, 2026 Important Debian
172

Ubuntu 25.10 Pillow Important Denial of Service USN-8047-1 CVE-2026-25990

Pillow could be made to crash or run programs if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-8047-1 February 17, 2026 pillow vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 Summary: Pillow could be made to crash or run programs if it opened a specially crafted file. Software Description: - pillow: Python Imaging Library Details: Yarden Porat discovered that Pillow incorrectly handled certain malformed PSD images. An attacker could use this issue to cause Pillow to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 python3-pil 11.3.0-1ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8047-1 CVE-2026-25990 Package Information: https://launchpad.net/ubuntu/+source/pillow/11.3.0-1ubuntu1.1 . Pillow on Ubuntu could crash or run code due to malformed files, leading to significant threats. Update recommended.. Pillow update Ubuntu crash security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 17, 2026 Important Ubuntu
197

Debian 11 Pillow Important Path Traversal DoS Vulnerability DLA-4462-1

Multiple vulnerabilities have been found in Pillow, an image processing library for Python. CVE-2021-23437 The getrgb function is susceptible to a ReDoS. CVE-2022-24303. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4462-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Daniel Leidert February 01, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : pillow Version : 8.1.2+dfsg-0.3+deb11u3 CVE ID : CVE-2021-23437 CVE-2022-24303 CVE-2022-45198 Multiple vulnerabilities have been found in Pillow, an image processing library for Python. CVE-2021-23437 The getrgb function is susceptible to a ReDoS. CVE-2022-24303 A possible path traversal vulnerability allows attackers to delete files. CVE-2022-45198 An improper handling of highly compressed GIF data can lead to a decompression bomb. For Debian 11 bullseye, these problems have been fixed in version 8.1.2+dfsg-0.3+deb11u3. We recommend that you upgrade your pillow packages. For the detailed security status of pillow please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/pillow Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Multiple vulnerabilities in Pillow lead to critical security threats requiring immediate updates. Get details on how to protect your system.. Debian Pillow Security Update, Image Processing Vulnerability, Python Security Issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 01, 2026 Important Debian LTS
91

Gentoo: GLSA-202411-07 High Severity: Pillow Arbitrary Code Execution

A vulnerability has been discovered in Pillow, which may lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202411-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Pillow: Arbitrary code execution Date: November 17, 2024 Bugs: #928391 ID: 202411-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in Pillow, which may lead to arbitrary code execution. Background ========== The friendly PIL fork. Affected packages ================= Package Vulnerable Unaffected ----------------- ------------ ------------ dev-python/pillow < 10.3.0 > = 10.3.0 Description =========== A vulnerability has been discovered in Pillow. Please review the CVE identifier referenced below for details. Impact ====== Please review the referenced CVE identifier for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Pillow users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-python/pillow-10.3.0" References ========== [ 1 ] CVE-2024-28219 https://nvd.nist.gov/vuln/detail/CVE-2024-28219 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202411-07 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc;referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo Linux Security Advisory: GLSA 202411-08 tackles critical vulnerability in Requests library. Immediate patching advised.. Gentoo Linux, Pillow update, security advisory, code execution. . LinuxSecurity.com Team

Calendar%202 Nov 17, 2024 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200