Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update for Mageia 10 addresses a connectivity issue with the plugin and upgrades it to version 1.52.1, improving functionality for downloading models.. Publication date: 23 Jul 2026 URL: https://advisories.mageia.org/MGAA-2026-0062.html Type: bugfix Affected Mageia releases: 10 Description: The plugin can't connect to server to download models. This update fixes the reported issue and updates the plugin to version 1.52.1. References: - https://bugs.mageia.org/show_bug.cgi?id=35955 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.52.1 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.52.0 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.51.1 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.51.0 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.50.0 - https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.49.1 SRPMS: - 10/core/krita-ai-diffusion-1.52.1-1.mga10 . Krita-AI-Diffusion update for Mageia fixes plugin issue and enhances functionality with new release version.. Krita-AI-Diffusion, Mageia security advisory, plugin update. . Severity: Critical. LinuxSecurity.com Team
GStreamer Base Plugins could be made to crash or run programs if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-8130-2 June 02, 2026 gst-plugins-base1.0 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: GStreamer Base Plugins could be made to crash or run programs if it opened a specially crafted file. Software Description: - gst-plugins-base1.0: GStreamer plugins Details: USN-8130-1 fixed a vulnerability in GStreamer Base Plugins. This update provides the corresponding update for Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. Original advisory details: It was discovered that GStreamer Base Plugins incorrectly handled certain AVI media files. A remote attacker could use this issue to cause GStreamer Base Plugins to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS gstreamer1.0-plugins-base 1.16.3-0ubuntu1.4+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS gstreamer1.0-plugins-base 1.14.5-0ubuntu1~18.04.3+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8130-2 https://ubuntu.com/security/notices/USN-8130-1 CVE-2026-2921 . GStreamer Base Plugins in Ubuntu could crash or execute arbitrary code with specially crafted files. Update recommended.. GStreamer Security Ubuntu, Plugin Denial of Service, Ubuntu Update Recommendations. . Severity: Important. LinuxSecurity.com Team
Two vulnerabilities were fixed in Apache Traffic Server, a reverse and forward proxy server. CVE-2023-41752 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3645-1
Multiple vulnerabilities were discovered in plugins for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3069-1
Multiple vulnerabilities were discovered in plugins for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2643-1
Update to new upstream release 2.0.50. * fix a security issue in .apkg imports * fix a problem with plugin download * use python send2trash module from system * use correct shebang for python2 * upstream changelog: . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-50039f6b61 2018-04-17 00:11:16.755305 --------------------------------------------------------------------------------Name : anki Product : Fedora 28 Version : 2.0.50 Release : 1.fc28 URL : https://apps.ankiweb.net/ Summary : Flashcard program for using space repetition learning Description : Anki is a program designed to help you remember facts (such as words and phrases in a foreign language) as easily, quickly and efficiently as possible. Anki is based on a theory called spaced repetition. --------------------------------------------------------------------------------Update Information: Update to new upstream release 2.0.50. * fix a security issue in .apkg imports * fix a problem with plugin download * use python send2trash module from system * use correct shebang for python2 * upstream changelog: --------------------------------------------------------------------------------References: [ 1 ] Bug #1529540 - anki: Security issue in .apkg imports fixed in 2.0.47 https://bugzilla.redhat.com/show_bug.cgi?id=1529540 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade anki' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Rod Widdowson of Steading System Software LLP discovered a coding error in the "Dynamic" metadata plugin of the Shibboleth Service Provider, causing the plugin to fail configuring itself with the filters provided and omitting whatever checks they are intended to perform. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4038-1
vmncdec: Sanity-check width/height before using it ---- Remove insecure nsf plugin (#1395126). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-a3bc78de2b 2016-12-15 23:54:24.668228 -------------------------------------------------------------------------------- Name : gstreamer-plugins-bad-free Product : Fedora 24 Version : 0.10.23 Release : 34.fc24 URL : https://gstreamer.freedesktop.org/ Summary : GStreamer streaming media framework "bad" plug-ins Description : GStreamer is a streaming media framework, based on graphs of elements which operate on media data. This package contains plug-ins that aren't tested well enough, or the code is not of good enough quality. -------------------------------------------------------------------------------- Update Information: vmncdec: Sanity-check width/height before using it ---- Remove insecure nsf plugin (#1395126) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1395126 - CVE-2016-9447 gstreamer-plugins-bad-free: Memory corruption flaw in NSF decoder https://bugzilla.redhat.com/show_bug.cgi?id=1395126 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade gstreamer-plugins-bad-free' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.