Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
Moderate: pixman security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:7754", "synopsis": "Moderate: pixman security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for pixman.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Pixman is a pixel manipulation library for the X Window System and Cairo.\n\nSecurity Fix(es):\n\n* pixman: Integer overflow in pixman_sample_floor_y leading to heap out-of-bounds write (CVE-2022-44638)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2139988", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2139988", "description": ""}], "cves": [{"name": "CVE-2022-44638", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-44638", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.0", "cwe": "CWE-787"}], "references": [], "publishedAt": "2026-03-18T06:04:00.732333Z", "rpms": {"Rocky Linux 9": {"nvras": ["pixman-0:0.40.0-6.el9_3.aarch64.rpm", "pixman-0:0.40.0-6.el9_3.i686.rpm", "pixman-0:0.40.0-6.el9_3.ppc64le.rpm", "pixman-0:0.40.0-6.el9_3.s390x.rpm", "pixman-0:0.40.0-6.el9_3.src.rpm", "pixman-0:0.40.0-6.el9_3.x86_64.rpm", "pixman-debuginfo-0:0.40.0-6.el9_3.aarch64.rpm", "pixman-debuginfo-0:0.40.0-6.el9_3.i686.rpm", "pixman-debuginfo-0:0.40.0-6.el9_3.ppc64le.rpm", "pixman-debuginfo-0:0.40.0-6.el9_3.s390x.rpm", "pixman-debuginfo-0:0.40.0-6.el9_3.x86_64.rpm", "pixman-debugsource-0:0.40.0-6.el9_3.aarch64.rpm", "pixman-debugsource-0:0.40.0-6.el9_3.i686.rpm", "pixman-debugsource-0:0.40.0-6.el9_3.ppc64le.rpm", "pixman-debugsource-0:0.40.0-6.el9_3.s390x.rpm","pixman-debugsource-0:0.40.0-6.el9_3.x86_64.rpm", "pixman-devel-0:0.40.0-6.el9_3.aarch64.rpm", "pixman-devel-0:0.40.0-6.el9_3.i686.rpm", "pixman-devel-0:0.40.0-6.el9_3.ppc64le.rpm", "pixman-devel-0:0.40.0-6.el9_3.s390x.rpm", "pixman-devel-0:0.40.0-6.el9_3.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Pixman security update for Rocky Linux addresses integer overflow, offering critical fixes for system integrity and performance.. Rocky Linux security update, pixman integer overflow, heap out-of-bounds write, security advisory, moderate severity. . LinuxSecurity.com Team
A vulnerability has been discovered in Pixman, which can lead to a heap buffer overflow.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202407-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Pixman: Heap Buffer Overflow Date: July 01, 2024 Bugs: #879207 ID: 202407-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in Pixman, which can lead to a heap buffer overflow. Background ========== Pixman is a pixel manipulation library. Affected packages ================= Package Vulnerable Unaffected --------------- ------------ ------------ x11-libs/pixman < 0.42.2 > = 0.42.2 Description =========== A vulnerability has been discovered in Pixman. Please review the CVE identifiers referenced below for details. Impact ====== An out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 can occur due to an integer overflow in pixman_sample_floor_y. Workaround ========== There is no known workaround at this time. Resolution ========== All Pixman users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =x11-libs/pixman-0.42.2" References ========== [ 1 ] CVE-2022-44638 https://nvd.nist.gov/vuln/detail/CVE-2022-44638 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202407-04 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-0131 https://linux.oracle.com/errata/ELSA-2024-0131.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: pixman-0.38.4-3.el8_9.i686.rpm pixman-0.38.4-3.el8_9.x86_64.rpm pixman-devel-0.38.4-3.el8_9.i686.rpm pixman-devel-0.38.4-3.el8_9.x86_64.rpm aarch64: pixman-0.38.4-3.el8_9.aarch64.rpm pixman-devel-0.38.4-3.el8_9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//pixman-0.38.4-3.el8_9.src.rpm Related CVEs: CVE-2022-44638 Description of changes: [0.38.4-3] - Security fix for CVE-2022-44638 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-7754 https://linux.oracle.com/errata/ELSA-2023-7754.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: pixman-0.40.0-6.el9_3.i686.rpm pixman-0.40.0-6.el9_3.x86_64.rpm pixman-devel-0.40.0-6.el9_3.i686.rpm pixman-devel-0.40.0-6.el9_3.x86_64.rpm aarch64: pixman-0.40.0-6.el9_3.aarch64.rpm pixman-devel-0.40.0-6.el9_3.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//pixman-0.40.0-6.el9_3.src.rpm Related CVEs: CVE-2022-44638 Description of changes: [0.40.0-6] - Backport fix for CVE-2022-44638 _______________________________________________ El-errata mailing list
pixman could be made to crash or run programs if it processed specially crafted input.. =========================================================================Ubuntu Security Notice USN-5718-2 November 30, 2022 pixman vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: pixman could be made to crash or run programs if it processed specially crafted input. Software Description: - pixman: pixel-manipulation library for X and cairo Details: USN-5718-1 fixed a vulnerability in pixman. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. Original advisory details: Maddie Stone discovered that pixman incorrectly handled certain memory operations. A remote attacker could use this issue to cause pixman to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: libpixman-1-0 0.33.6-1ubuntu0.1~esm1 libpixman-1-dev 0.33.6-1ubuntu0.1~esm1 Ubuntu 14.04 ESM: libpixman-1-0 0.30.2-2ubuntu1.2+esm1 libpixman-1-dev 0.30.2-2ubuntu1.2+esm1 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5718-2 https://ubuntu.com/security/notices/USN-5718-1 CVE-2022-44638 . Linux Security Bulletin LSB-2023-012 highlights a severe vulnerability in libpng that may result in system failures or unauthorized code execution.. pixman update, Ubuntu 16.04, security advisory. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for pixman ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:4249-1 Rating: important References: #1205033 Cross-References: CVE-2022-44638 CVSS scores: CVE-2022-44638 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-44638 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud Crowbar 9 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for pixman fixes the following issues: - CVE-2022-44638: Fixed an integer overflow in pixman_sample_floor_y leading to heap out-of-bounds write (bsc#1205033). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2022-4249=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2022-4249=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-4249=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patchSUSE-SLE-SAP-12-SP4-2022-4249=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-4249=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2022-4249=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2022-4249=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2022-4249=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): libpixman-1-0-0.34.0-8.3.1 libpixman-1-0-32bit-0.34.0-8.3.1 libpixman-1-0-debuginfo-0.34.0-8.3.1 libpixman-1-0-debuginfo-32bit-0.34.0-8.3.1 pixman-debugsource-0.34.0-8.3.1 - SUSE OpenStack Cloud 9 (x86_64): libpixman-1-0-0.34.0-8.3.1 libpixman-1-0-32bit-0.34.0-8.3.1 libpixman-1-0-debuginfo-0.34.0-8.3.1 libpixman-1-0-debuginfo-32bit-0.34.0-8.3.1 pixman-debugsource-0.34.0-8.3.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libpixman-1-0-devel-0.34.0-8.3.1 pixman-debugsource-0.34.0-8.3.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): libpixman-1-0-0.34.0-8.3.1 libpixman-1-0-debuginfo-0.34.0-8.3.1 pixman-debugsource-0.34.0-8.3.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (x86_64): libpixman-1-0-32bit-0.34.0-8.3.1 libpixman-1-0-debuginfo-32bit-0.34.0-8.3.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libpixman-1-0-0.34.0-8.3.1 libpixman-1-0-debuginfo-0.34.0-8.3.1 pixman-debugsource-0.34.0-8.3.1 - SUSE Linux Enterprise Server 12-SP5 (s390x x86_64): libpixman-1-0-32bit-0.34.0-8.3.1 libpixman-1-0-debuginfo-32bit-0.34.0-8.3.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64 ppc64le s390x x86_64): libpixman-1-0-0.34.0-8.3.1 libpixman-1-0-debuginfo-0.34.0-8.3.1 pixman-debugsource-0.34.0-8.3.1 - SUSE Linux EnterpriseServer 12-SP4-LTSS (s390x x86_64): libpixman-1-0-32bit-0.34.0-8.3.1 libpixman-1-0-debuginfo-32bit-0.34.0-8.3.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): libpixman-1-0-0.34.0-8.3.1 libpixman-1-0-32bit-0.34.0-8.3.1 libpixman-1-0-debuginfo-0.34.0-8.3.1 libpixman-1-0-debuginfo-32bit-0.34.0-8.3.1 pixman-debugsource-0.34.0-8.3.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): libpixman-1-0-0.34.0-8.3.1 libpixman-1-0-32bit-0.34.0-8.3.1 libpixman-1-0-debuginfo-0.34.0-8.3.1 libpixman-1-0-debuginfo-32bit-0.34.0-8.3.1 pixman-debugsource-0.34.0-8.3.1 References: https://www.suse.com/security/cve/CVE-2022-44638.html https://bugzilla.suse.com/1205033 . Essential SUSE Security Patch addresses a buffer overflow vulnerability in pixman, improving overall system security.. SUSE Pixman Update, Security Fix, Heap Overflow Prevention, Software Update. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for pixman ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:4206-1 Rating: important References: #1205033 Cross-References: CVE-2022-44638 CVSS scores: CVE-2022-44638 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-44638 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Micro 5.3 SUSE Linux Enterprise Module for Basesystem 15-SP4 SUSE Linux Enterprise Module for Desktop Applications 15-SP4 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.3 openSUSE Leap 15.4 openSUSE Leap Micro 5.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for pixman fixes the following issues: - CVE-2022-44638: Fixed an integer overflow in pixman_sample_floor_y leading to heap out-of-bounds write (bsc#1205033). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap Micro 5.3: zypper in -t patch openSUSE-Leap-Micro-5.3-2022-4206=1 - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-4206=1 - SUSE Linux Enterprise Module for Desktop Applications15-SP4: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP4-2022-4206=1 - SUSE Linux Enterprise Module for Basesystem 15-SP4: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2022-4206=1 - SUSE Linux Enterprise Micro 5.3: zypper in -t patch SUSE-SLE-Micro-5.3-2022-4206=1 Package List: - openSUSE Leap Micro 5.3 (aarch64 x86_64): libpixman-1-0-0.40.0-150400.3.3.1 libpixman-1-0-debuginfo-0.40.0-150400.3.3.1 pixman-debugsource-0.40.0-150400.3.3.1 - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): libpixman-1-0-0.40.0-150400.3.3.1 libpixman-1-0-debuginfo-0.40.0-150400.3.3.1 libpixman-1-0-devel-0.40.0-150400.3.3.1 pixman-debugsource-0.40.0-150400.3.3.1 - openSUSE Leap 15.4 (x86_64): libpixman-1-0-32bit-0.40.0-150400.3.3.1 libpixman-1-0-32bit-debuginfo-0.40.0-150400.3.3.1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP4 (x86_64): libpixman-1-0-32bit-0.40.0-150400.3.3.1 libpixman-1-0-32bit-debuginfo-0.40.0-150400.3.3.1 pixman-debugsource-0.40.0-150400.3.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (aarch64 ppc64le s390x x86_64): libpixman-1-0-0.40.0-150400.3.3.1 libpixman-1-0-debuginfo-0.40.0-150400.3.3.1 libpixman-1-0-devel-0.40.0-150400.3.3.1 pixman-debugsource-0.40.0-150400.3.3.1 - SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64): libpixman-1-0-0.40.0-150400.3.3.1 libpixman-1-0-debuginfo-0.40.0-150400.3.3.1 pixman-debugsource-0.40.0-150400.3.3.1 References: https://www.suse.com/security/cve/CVE-2022-44638.html https://bugzilla.suse.com/1205033 . SUSE Security Patch for libjpeg addresses critical memory corruption vulnerability leading to potential denial of service. Update immediately.. SUSE Security Update,pixman patch,heap overflow fix. . Severity: Important. LinuxSecurity.com Team
Maddie Stone reported a heap-based buffer overflow flaw in pixman, a pixel-manipulation library for X and cairo, which could result in denial of service or potentially the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5276-1
Get the latest Linux and open source security news straight to your inbox.