Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
libjxl could be made to crash or run programs if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-8397-1 June 08, 2026 jpeg-xl vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 Summary: libjxl could be made to crash or run programs if it opened a specially crafted file. Software Description: - jpeg-xl: Reference codec implementation for JPEG XL compressed raster image format Details: It was discovered that libjxl did not properly handle certain crafted PBM images. An attacker could possibly use this issue to cause libjxl to crash, resulting in a denial of service, or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libjxl-tools 0.11.1-6ubuntu4.2 libjxl0.11 0.11.1-6ubuntu4.2 Ubuntu 25.10 libjxl-tools 0.11.1-6ubuntu1.2 libjxl0.11 0.11.1-6ubuntu1.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8397-1 CVE-2025-70103 Package Information: https://launchpad.net/ubuntu/+source/jpeg-xl/0.11.1-6ubuntu4.2 https://launchpad.net/ubuntu/+source/jpeg-xl/0.11.1-6ubuntu1.2 . The libjxl in Ubuntu may crash or run unintended programs due to crafted files; updates are urged for safety.. Ubuntu libjxl security update, jpeg-xl vulnerability patch, Ubuntu crash fix. . Severity: moderate. LinuxSecurity.com Team
An update that solves various issues can now be installed.. openSUSE security update: security update for putty ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20851-1 Rating: important Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves various issues can now be installed. Description: This update for putty fixes the following issues: Changes in putty: - Update to release 0.84 * Fixed a remotely triggerable double-free in RSA key exchange. * Fixed a remotely triggerable crash (assertion failure - program termination) in NIST ECDSA signature verification. * Fixed marking of Telnet and Rlogin session data with a trust sigil after you authenticated to a proxy (possibly allowing a server to spoof a repeat proxy password prompt). * New ability to run a specified command before starting the connection, e.g. to perform wake-on-LAN or a port knock. * Display 'pre-edit text', showing the progress of using multiple keystrokes to compose a single Unicode character. * Improved support for to running the GUI tools on Wayland (fixed startup issues and tuned performance). * Configuring a SSH certificate authority used to fail unless you manually made a config directory, now fixed. * Fixed a spurious "Network error: Socket is not connected" when authenticating to some HTTP proxies. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-281=1 Package List: - openSUSE Leap 16.0: putty-0.84-bp160.1.1 . Update for openSUSE Leap 16.0 addressing important security flaws in Putty ensuring stable connections.. openSUSE security, putty patch, important update, software stability. . Severity: Important.LinuxSecurity.com Team
Exim could be made to crash or run programs if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-8270-1 May 12, 2026 exim4 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Exim could be made to crash or run programs if it received specially crafted network traffic. Software Description: - exim4: Exim is a mail transport agent Details: It was discovered that Exim incorrectly handled BDAT body parsing. A remote attacker could use this issue to cause Exim to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS exim4 4.99.1-1ubuntu1.2 exim4-base 4.99.1-1ubuntu1.2 eximon4 4.99.1-1ubuntu1.2 Ubuntu 25.10 exim4 4.98.2-1ubuntu2.2 exim4-base 4.98.2-1ubuntu2.2 eximon4 4.98.2-1ubuntu2.2 Ubuntu 24.04 LTS exim4 4.97-4ubuntu4.5 exim4-base 4.97-4ubuntu4.5 eximon4 4.97-4ubuntu4.5 Ubuntu 22.04 LTS exim4 4.95-4ubuntu2.8 exim4-base 4.95-4ubuntu2.8 eximon4 4.95-4ubuntu2.8 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8270-1 https://launchpad.net/bugs/2152202 Package Information: https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.2 https://launchpad.net/ubuntu/+source/exim4/4.98.2-1ubuntu2.2 https://launchpad.net/ubuntu/+source/exim4/4.97-4ubuntu4.5 https://launchpad.net/ubuntu/+source/exim4/4.95-4ubuntu2.8 . Exim in Ubuntu is vulnerable to DoS attacks from crafted traffic, updates recommended for systems affected.. Exim, Ubuntu, security issue, DoS, system update. . Severity: Important. LinuxSecurity.com Team
Ruby could be made to crash or run programs as your login if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-6838-2 February 10, 2025 ruby2.3, ruby2.5 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Ruby could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - ruby2.5: Object-oriented scripting language - ruby2.3: Object-oriented scripting language Details: USN-6838-1 fixed CVE-2024-27281 in Ruby 2.7, Ruby 3.0, Ruby 3.1, and Ruby 3.2. This update provides the corresponding updates for Ruby 2.3 and Ruby 2.5. Original advisory details: It was discovered that Ruby RDoc incorrectly parsed certain YAML files. If a user or automated system were tricked into parsing a specially crafted .rdoc_options file, a remote attacker could possibly use this issue to execute arbitrary code. (CVE-2024-27281) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS libruby2.5 2.5.1-1ubuntu1.16+esm3 Available with Ubuntu Pro ruby2.5 2.5.1-1ubuntu1.16+esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS libruby2.3 2.3.1-2~ubuntu16.04.16+esm9 Available with Ubuntu Pro ruby2.3 2.3.1-2~ubuntu16.04.16+esm9 Available with Ubuntu Pro In general, a standard system update will make all the necessarychanges. References: https://ubuntu.com/security/notices/USN-6838-2 https://ubuntu.com/security/notices/USN-6838-1 CVE-2024-27281 . Secure your Ubuntu Ruby packages against vulnerabilities that can lead to arbitrary code execution by following these essential steps for updating and verifying installations. ruby2.5 update,ruby2.3 advisory,Ubuntu security notice,execution flaw fix. . Severity: Critical. LinuxSecurity.com Team
New gimp packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] gimp (SSA:2023-320-01) New gimp packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/gimp-2.10.36-i586-1_slack15.0.txz: Upgraded. This release fixes security issues: If a user loads a malicious DDS, PSD, or PSP file, this could result in a program crash or possibly the execution of arbitrary code. Please note that this package also requires the updated gegl package. Thanks to henca for the heads-up. For more information, see: https://www.gimp.org/news/2023/11/07/gimp-2-10-36-released/ https://www.zerodayinitiative.com/advisories/ZDI-23-1591/ https://www.zerodayinitiative.com/advisories/ZDI-23-1592/ https://www.zerodayinitiative.com/advisories/ZDI-23-1593/ https://www.zerodayinitiative.com/advisories/ZDI-23-1594/ https://www.cve.org/CVERecord?id=CVE-2023-44441 https://www.cve.org/CVERecord?id=CVE-2023-44442 https://www.cve.org/CVERecord?id=CVE-2023-44443 https://www.cve.org/CVERecord?id=CVE-2023-44444 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/gimp-2.10.36-i586-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/gimp-2.10.36-x86_64-1_slack15.0.txz Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware15.0 package: 405c519ddcdd8b84299315dd567c014e gimp-2.10.36-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 03365737f0bfbe3bb2307b6b4670610b gimp-2.10.36-x86_64-1_slack15.0.txz Slackware -current package: 2e4fd2a98e7b7f5cb3fa70242accd547 xap/gimp-2.10.36-i586-1.txz Slackware x86_64 -current package: 1935e4ebc9980f687283785870ae3812 xap/gimp-2.10.36-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg gimp-2.10.36-i586-1_slack15.0.txz +-----+ . Gimp upgrade for Slackware 15.0 resolves significant vulnerabilities, enhancing user protection and program reliability.. Gimp Security Fix, Slackware Update, Software Patch. . Severity: Critical. LinuxSecurity.com Team
GStreamer Base Plugins could be made to crash or run programs if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-6268-1 August 02, 2023 gst-plugins-base1.0 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: GStreamer Base Plugins could be made to crash or run programs if it opened a specially crafted file. Software Description: - gst-plugins-base1.0: GStreamer plugins Details: It was discovered that GStreamer Base Plugins incorrectly handled certain FLAC image tags. A remote attacker could use this issue to cause GStreamer Base Plugins to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-37327) It was discovered that GStreamer Base Plugins incorrectly handled certain subtitles. A remote attacker could use this issue to cause GStreamer Base Plugins to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-37328) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: gstreamer1.0-plugins-base 1.22.1-1ubuntu1.1 Ubuntu 22.04 LTS: gstreamer1.0-plugins-base 1.20.1-1ubuntu0.1 Ubuntu 20.04 LTS: gstreamer1.0-plugins-base 1.16.3-0ubuntu1.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6268-1 CVE-2023-37327, CVE-2023-37328 Package Information: https://launchpad.net/ubuntu/+source/gst-plugins-base1.0/1.22.1-1ubuntu1.1 https://launchpad.net/ubuntu/+source/gst-plugins-base1.0/1.20.1-1ubuntu0.1 https://launchpad.net/ubuntu/+source/gst-plugins-base1.0/1.16.3-0ubuntu1.2 . Enhance your Ubuntu security by applying updates for GStreamerBase Plugins to fix vulnerabilities that could lead to denial of service attacks or unauthorized code execution. GStreamer Base, Ubuntu Security, Denial Of Service, Update Instructions. . Severity: Critical. LinuxSecurity.com Team
cups-filters could be made to crash or run programs if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-6083-1 May 17, 2023 cups-filters vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: cups-filters could be made to crash or run programs if it received specially crafted network traffic. Software Description: - cups-filters: OpenPrinting CUPS Filters Details: It was discovered that cups-filters incorrectly handled the beh CUPS backend. A remote attacker could possibly use this issue to cause the backend to stop responding or to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: cups-filters 2.0~rc1-0ubuntu1.2 Ubuntu 22.10: cups-filters 1.28.16-1ubuntu0.2 Ubuntu 22.04 LTS: cups-filters 1.28.15-0ubuntu1.2 Ubuntu 20.04 LTS: cups-filters 1.27.4-1ubuntu0.2 Ubuntu 18.04 LTS: cups-filters 1.20.2-0ubuntu3.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6083-1 CVE-2023-24805 Package Information: https://launchpad.net/ubuntu/+source/cups-filters/2.0~rc1-0ubuntu1.2 https://launchpad.net/ubuntu/+source/cups-filters/1.28.16-1ubuntu0.2 https://launchpad.net/ubuntu/+source/cups-filters/1.28.15-0ubuntu1.2 https://launchpad.net/ubuntu/+source/cups-filters/1.27.4-1ubuntu0.2 https://launchpad.net/ubuntu/+source/cups-filters/1.20.2-0ubuntu3.3 . A vulnerability in the CUPS filters of Ubuntu might allow malicious network traffic to cause system crashesor execute arbitrary programs.. cups-filters, Remote Code Execution, Ubuntu Security. . Severity: Critical. LinuxSecurity.com Team
There is a double free or corruption in rotateImage() at tiffcrop.c:8839 found in libtiff 4.4.0rc1. (CVE-2022-2519) A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can cause program crash when . MGASA-2022-0410 - Updated libtiff packages fix security vulnerability Publication date: 08 Nov 2022 URL: https://advisories.mageia.org/MGASA-2022-0410.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-2519, CVE-2022-2520, CVE-2022-2521, CVE-2022-3570, CVE-2022-3598 There is a double free or corruption in rotateImage() at tiffcrop.c:8839 found in libtiff 4.4.0rc1. (CVE-2022-2519) A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can cause program crash when reading a crafted input. (CVE-2022-2520) It was found in libtiff 4.4.0rc1 that there is an invalid pointer free operation in TIFFClose() at tif_close.c:131 called by tiffcrop.c:2522 that can cause a program crash and denial of service while processing crafted input. (CVE-2022-2521) Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact. (CVE-2022-3570) LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attackers to cause a denial-of-service via a crafted tiff file. (CVE-2022-3598) References: - https://bugs.mageia.org/show_bug.cgi?id=30999 - - https://ubuntu.com/security/notices/USN-5705-1 - https://www.cve.org/CVERecord?id=CVE-2022-2519 - https://www.cve.org/CVERecord?id=CVE-2022-2520 - https://www.cve.org/CVERecord?id=CVE-2022-2521 - https://www.cve.org/CVERecord?id=CVE-2022-3570 - https://www.cve.org/CVERecord?id=CVE-2022-3598 SRPMS: - 8/core/libtiff-4.2.0-1.9.mga8 . Mageia's recent libtiff updatetackles severe remote threats, averting system crashes and data breaches due to malicious inputs.. libtiff security,Mageia update,security vulnerability,memory corruption,program crash. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.