Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 42: USD CVE-2025-14439 Moderate Backport Fix for RCE 2025-2e7d5d49f2

Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-2e7d5d49f2 2026-01-03 01:15:48.095284+00:00 -------------------------------------------------------------------------------- Name : usd Product : Fedora 42 Version : 25.02a Release : 5.fc42 URL : https://openusd.org/ Summary : 3D VFX pipeline interchange file format Description : Universal Scene Description (USD) is a time-sampled scene description for interchange between graphics applications. -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442 -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 25 2025 Benjamin A. Beasley - 25.02a-5 - Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442 (fix RHBZ#2422275) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2422275 - CVE-2025-14439 usd: OpenUSD File Parsing Use-After-Free Remote Code Execution Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2422275 [ 2 ] Bug #2424910 - CVE-2025-12839 usd: OpenEXR: Remote Code Execution via Heap-based Buffer Overflow in EXR File Parsing [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2424910 [ 3 ] Bug #2424912 - CVE-2025-12840 usd: OpenEXR: Remote Code Execution via EXR file parsing heap-based buffer overflow [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2424912 [ 4 ] Bug #2424917 - CVE-2025-12495 usd: OpenEXR: Remote Code Execution via malicious EXR file parsing [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2424917 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2025-2e7d5d49f2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 42 update addresses CVE-2025-14439 with a backport fix for exploitation risks in OpenUSD format.. Fedora 42, USD, remote execution, CVE-2025-14439, backport fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 03, 2026 Important Fedora
89

Fedora 43: usd Critical Remote Code Execution Advisory 2025-f882263432

Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-f882263432 2026-01-02 00:38:59.597974+00:00 -------------------------------------------------------------------------------- Name : usd Product : Fedora 43 Version : 25.08 Release : 13.fc43 URL : https://openusd.org/ Summary : 3D VFX pipeline interchange file format Description : Universal Scene Description (USD) is a time-sampled scene description for interchange between graphics applications. -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442 -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 24 2025 Benjamin A. Beasley - 25.08-13 - Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442 (fix RHBZ#2422276) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2422276 - CVE-2025-14439 usd: OpenUSD File Parsing Use-After-Free Remote Code Execution Vulnerability [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2422276 [ 2 ] Bug #2424922 - CVE-2025-12839 usd: OpenEXR: Remote Code Execution via Heap-based Buffer Overflow in EXR File Parsing [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2424922 [ 3 ] Bug #2424924 - CVE-2025-12840 usd: OpenEXR: Remote Code Execution via EXR file parsing heap-based buffer overflow [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2424924 [ 4 ] Bug #2424926 - CVE-2025-12495 usd: OpenEXR: Remote Code Execution via malicious EXR file parsing [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2424926 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2025-f882263432' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Critical patch for Fedora 43 addressing remote code execution in usd due to CVE-2025-14439. Update recommended.. Fedora 43, OpenUSD, Remote Code Execution, Security Advisory, Critical Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 02, 2026 Critical Fedora
89

Fedora 43: usd Security Advisory 2025-0cc929ff17 - PySide6 Update

PySide6 6.10.1 update. Pyside6 6.10.1 release. Rebuilt with stb_image patched for two new security bugs.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-0cc929ff17 2025-12-04 00:51:14.440721+00:00 -------------------------------------------------------------------------------- Name : usd Product : Fedora 43 Version : 25.08 Release : 11.fc43 URL : https://openusd.org/ Summary : 3D VFX pipeline interchange file format Description : Universal Scene Description (USD) is a time-sampled scene description for interchange between graphics applications. -------------------------------------------------------------------------------- Update Information: PySide6 6.10.1 update. Pyside6 6.10.1 release. Rebuilt with stb_image patched for two new security bugs. -------------------------------------------------------------------------------- ChangeLog: * Tue Dec 2 2025 Jan Grulich - 25.08-11 - Rebuild (python-pyside6) * Tue Nov 25 2025 Benjamin A. Beasley - 25.08-10 - Correct minimum NVR for stb_image * Tue Nov 25 2025 Benjamin A. Beasley - 25.08-9 - Rebuilt with stb_image patched for two new security bugs * Tue Nov 25 2025 Benjamin A. Beasley - 25.08-7 - Add direct build dependency on OpenCL as a workaround * Tue Sep 30 2025 Luya Tshimbalanga - 25.08-6 - Rebuild for openvdb 12.1.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2400455 - python-pyside6-6.10.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2400455 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-0cc929ff17' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 43's usd update addresses two security bugs in PySide6 6.10.1 with necessary patches for a safer experience.. Fedora Security Update, PySide6, 3D Graphics, USD Vulnerability Fix. . Severity: Informational. LinuxSecurity.com Team

Calendar 2 Dec 04, 2025 Informational Fedora
89

Fedora 35: FEDORA-2022-61f6ee6353 Security Fix for 3D USD Buffer Overflow

Security fix for CVE-2022-28041. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-61f6ee6353 2022-05-01 19:39:06.906407 --------------------------------------------------------------------------------Name : usd Product : Fedora 35 Version : 21.11 Release : 11.fc35 URL : https://openusd.org/ Summary : 3D VFX pipeline interchange file format Description : Universal Scene Description (USD) is a time-sampled scene description for interchange between graphics applications. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2022-28041 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 20 2022 Benjamin A. Beasley 21.11-11 - Security fix for CVE-2022-28041 --------------------------------------------------------------------------------References: [ 1 ] Bug #2077054 - Rebuild usd with updated stb_image-{devel,static} for CVE-2022-28041 https://bugzilla.redhat.com/show_bug.cgi?id=2077054 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-61f6ee6353' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ ListGuidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora 35's latest update addresses the critical CVE-2022-28041 vulnerability in the usd package, protecting users from potential data breaches and system instability.. Fedora 35, USD Security, Security Update, CVE 2022, Software Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 01, 2022 Critical Fedora
89

Fedora 34 2022-832689aa6b Moderate: Multiple USD Threat Fixes

Security fix for CVE-2021-28021, CVE-2021-42715, CVE-2021-42716, and CVE-2022-28041. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-832689aa6b 2022-04-29 06:56:10.869253 --------------------------------------------------------------------------------Name : usd Product : Fedora 34 Version : 21.08 Release : 19.fc34 URL : https://openusd.org/ Summary : 3D VFX pipeline interchange file format Description : Universal Scene Description (USD) is a time-sampled scene description for interchange between graphics applications. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-28021, CVE-2021-42715, CVE-2021-42716, and CVE-2022-28041 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 20 2022 Benjamin A. Beasley 21.08-19 - Security fix for CVE-2022-28041 * Wed Apr 20 2022 Benjamin A. Beasley 21.08-18 - Move bundled library virtual Provides to -libs * Wed Apr 20 2022 Benjamin A. Beasley 21.08-17 - Patch CVE-2021-28021, CVE-2021-42715, and CVE-2021-42716 * Wed Apr 20 2022 Benjamin A. Beasley 21.08-16 - Add comments explaining where to find versions for bundled deps --------------------------------------------------------------------------------References: [ 1 ] Bug #2077054 - Rebuild usd with updated stb_image-{devel,static} for CVE-2022-28041 https://bugzilla.redhat.com/show_bug.cgi?id=2077054 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-832689aa6b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Projectcan be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Announcement concerning Fedora 34, delivering crucial security patches addressing various weaknesses in the usd software, thereby improving graphics performance and stability.. Fedora Update, USD Software, Security Issues, Threat Fixes. . LinuxSecurity.com Team

Calendar 2 Apr 29, 2022 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here