Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 24 articles for you...
89

Fedora 44 ThorVG Advisory Denial Of Service Vulnerability 2026-3d1fcd4ffc

Update to 1.0.6. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3d1fcd4ffc 2026-06-23 01:06:46.785055+00:00 -------------------------------------------------------------------------------- Name : thorvg Product : Fedora 44 Version : 1.0.6 Release : 1.fc44 URL : https://www.thorvg.org/ Summary : Lightweight vector-based scenes and animation drawing library Description : ThorVG is an open-source graphics library designed for creating vector-based scenes and animations. It combines immense power with remarkable lightweight efficiency, as Thor embodies a dual meaning—symbolizing both thunderous strength and lightning-fast agility. Embracing the philosophy of simpler is better, the ThorVG project provides intuitive, user-friendly interfaces while maintaining a compact footprint and minimal overhead. The following list shows primitives that are supported by ThorVG: - Lines & Shapes: rectangles, circles, and paths with coordinate control - Filling: solid colors, linear & radial gradients, and path clipping - Stroking: stroke width, joins, caps, dash patterns, and trimming - Scene Management: retainable scene graph and object transformations - Composition: various blending and masking - Text: unicode characters with horizontal text layout using scalable fonts (TTF) - Images: SVG, JPG, PNG, WebP, and raw bitmaps - Effects: blur, drop shadow, fill, tint, tritone and color replacement - Animations: Lottie -------------------------------------------------------------------------------- Update Information: Update to 1.0.6 -------------------------------------------------------------------------------- ChangeLog: * Sun Jun 14 2026 Benson Muite - 1.0.6-1 - Update to 1.0.6 * Sat Feb 14 2026 Benson Muite - 1.0.1-1 - Update to 1.0.1 rhbz#2433764 * Sat Jan 17 2026 Fedora Release Engineering - 0.15.16-2 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2483802 - CVE-2026-45729 thorvg: ThorVG: Denial of Service via untrusted SVG data processing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2483802 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3d1fcd4ffc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . ThorVG 1.0.6 update in Fedora 44 fixes security concerns, enhancing stability and efficiency in vector graphics processing.. Fedora thorvg Denial Of Service Vector Graphics Security. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Jun 22, 2026 Informational Fedora
89

Fedora 42 libgit2 1.8.5 Update Advisory FEDORA-2026-bb6bb5d1e4

Update to version 1.8.5. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.8.5. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-bb6bb5d1e4 2026-05-17 01:05:24.299228+00:00 -------------------------------------------------------------------------------- Name : libgit2_1.8 Product : Fedora 42 Version : 1.8.5 Release : 1.fc42 URL : https://libgit2.org/ Summary : C implementation of the Git core methods as a library with a solid API Description : libgit2 is a portable, pure C implementation of the Git core methods provided as a re-entrant linkable library with a solid API, allowing you to write native speed custom Git applications in any language with bindings. -------------------------------------------------------------------------------- Update Information: Update to version 1.8.5. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.8.5 -------------------------------------------------------------------------------- ChangeLog: * Wed May 6 2026 Fabio Valentini - 1.8.5-1 - Update to version 1.8.5 * Fri Jan 16 2026 Fedora Release Engineering - 1.8.4-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Thu Jul 24 2025 Fedora Release Engineering - 1.8.4-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Sun May 18 2025 Benjamin A. Beasley - 1.8.4-3 - Rebuilt for llhttp 9.3.0 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bb6bb5d1e4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fedora 42 updates libgit2 to version 1.8.5, enhancing Git core methods with a solid API.. libgit2 Fedora update API Git methods. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 May 17, 2026 Informational Fedora
87

Debian Trixie FFmpeg Arbitrary Code Execution Fix DSA-6268-1

Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. For the stable distribution (trixie), this problem has been fixed in version 7:7.1.4-0+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6268-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff May 14, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ffmpeg CVE ID : not yet available Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. For the stable distribution (trixie), this problem has been fixed in version 7:7.1.4-0+deb13u1. We recommend that you upgrade your ffmpeg packages. For the detailed security status of ffmpeg please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ffmpeg Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . FFmpeg vulnerabilities fixed in Debian DSA-6268-1 advisory to prevent denial of service and arbitrary code execution risks.. FFmpeg vulnerabilities, Debian security advisory, denial of service risk, multimedia framework update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 14, 2026 Important Debian
89

Fedora 43 rust-openssl-sys FFI Binding Update Poses High Security Risk

Update the openssl crate to version 0.10.78 and the openssl-sys crate to version 0.9.114. Release notes: openssl 0.10.77 / openssl-sys 0.9.113: https://github.com/rust-openssl/rust- openssl/releases/tag/openssl-v0.10.77. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-16a3cea414 2026-05-02 01:51:01.714148+00:00 -------------------------------------------------------------------------------- Name : rust-openssl-sys Product : Fedora 43 Version : 0.9.114 Release : 1.fc43 URL : https://crates.io/crates/openssl-sys Summary : FFI bindings to OpenSSL Description : FFI bindings to OpenSSL. -------------------------------------------------------------------------------- Update Information: Update the openssl crate to version 0.10.78 and the openssl-sys crate to version 0.9.114. Release notes: openssl 0.10.77 / openssl-sys 0.9.113: https://github.com/rust-openssl/rust- openssl/releases/tag/openssl-v0.10.77 openssl 0.10.78 / openssl-sys 0.9.114: https://github.com/rust-openssl/rust- openssl/releases/tag/openssl-v0.10.78 This addresses the following security advisories: GHSA-pqf5-4pqq-29f5 / CVE-2026-41676: https://github.com/rust-openssl/rust- openssl/security/advisories/GHSA-pqf5-4pqq-29f5 GHSA-xmgf-hq76-4vx2 / CVE-2026-41677: https://github.com/rust-openssl/rust- openssl/security/advisories/GHSA-xmgf-hq76-4vx2 GHSA-8c75-8mhr-p7r9 / CVE-2026-41678: https://github.com/rust-openssl/rust- openssl/security/advisories/GHSA-8c75-8mhr-p7r9 GHSA-ghm9-cr32-g9qj / CVE-2026-41681: https://github.com/rust-openssl/rust- openssl/security/advisories/GHSA-ghm9-cr32-g9qj GHSA-hppc-g8h3-xhp3 (no CVE entry): https://github.com/rust-openssl/rust- openssl/security/advisories/GHSA-hppc-g8h3-xhp3 Affected applications still need to be rebuilt to pick up these fixes. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 23 2026 Fabio Valentini -0.9.114-1 - Update to version 0.9.114; Fixes RHBZ#2457692 * Mon Apr 13 2026 Fabio Valentini - 0.9.112-2 - Add upper bound to OpenSSL dependency since 4.0 is not supported yet -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-16a3cea414' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update for Fedora addressing security issues in rust-openssl-sys and openssl crate with specific patch details.. Fedora 43 update, openssl-sys, security advisory, rust-openssl, crate update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 02, 2026 Important Fedora
197

Debian 11 GIMP DLA-4547-1 Addressing DoS Arbitrary Code Risks

Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service or potentially the execution of arbitrary code if malformed PSP, JPEG 2000 or PSD files are opened. For Debian 11 bullseye, these problems have been fixed in version. Debian LTS Advisory DLA-4547-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz April 23, 2026 https://wiki.debian.org/LTS Package : gimp Version : 2.10.22-4+deb11u8 CVE ID : CVE-2026-4150 CVE-2026-4152 CVE-2026-4153 Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service or potentially the execution of arbitrary code if malformed PSP, JPEG 2000 or PSD files are opened. For Debian 11 bullseye, these problems have been fixed in version 2.10.22-4+deb11u8. We recommend that you upgrade your gimp packages. For the detailed security status of gimp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/gimp Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Multiple issues fixed in GIMP for Debian 11, addressing potential DoS and arbitrary code execution threats effectively.. GIMP security update, Debian 11 vulnerabilities, code execution threat. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 23, 2026 Important Debian LTS
89

Fedora 44 kf6-kcmutils Advisory 2026-fe3d8d4767 Security Issue

Frameworks 6.25.0 + KDE Plasma 6.6.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fe3d8d4767 2026-04-16 23:40:54.273526+00:00 -------------------------------------------------------------------------------- Name : kf6-kcmutils Product : Fedora 44 Version : 6.25.0 Release : 1.fc44 URL : https://invent.kde.org/frameworks/kcmutils Summary : KDE Frameworks 6 Tier 3 addon with extra API to write KConfigModules Description : KCMUtils provides various classes to work with KCModules. KCModules can be created with the KConfigWidgets framework. -------------------------------------------------------------------------------- Update Information: Frameworks 6.25.0 + KDE Plasma 6.6.4 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 9 2026 Steve Cossette - 6.25.0-1 - 6.25.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455469 - Configuring WifI network via Network pane appears to not work https://bugzilla.redhat.com/show_bug.cgi?id=2455469 [ 2 ] Bug #2457573 - FE: KDE Frameworks 6.25.0 + Plasma 6.6.4 https://bugzilla.redhat.com/show_bug.cgi?id=2457573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fe3d8d4767' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . KDE Frameworks 6.25.0 update resolves network configuration problems on Fedora 44 for improved connectivity and performance. KDE Frameworks 6.25.0. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Apr 16, 2026 Informational Fedora
89

Upgrade to GStreamer1 Library in Ubuntu 24 with version 2021-d82be8f931

1.26.11. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-e77ad9d792 2026-04-01 00:56:24.864678+00:00 -------------------------------------------------------------------------------- Name : gstreamer1 Product : Fedora 43 Version : 1.26.11 Release : 1.fc43 URL : http://gstreamer.freedesktop.org/ Summary : GStreamer streaming media framework runtime Description : GStreamer is a streaming media framework, based on graphs of filters which operate on media data. Applications using this library can do anything from real-time sound processing to playing videos, and just about anything else media-related. Its plugin-based architecture means that new data types or processing capabilities can be added simply by installing new plugins. -------------------------------------------------------------------------------- Update Information: 1.26.11 -------------------------------------------------------------------------------- ChangeLog: * Mon Mar 30 2026 Gwyn Ciesla - 1.26.11-1 - 1.26.11 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e77ad9d792' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ ListGuidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Gstreamer1 for Fedora 43 updated to 1.26.11 for enhanced media processing capabilities and stability improvements.. GStreamer, Fedora 43, media framework. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Apr 01, 2026 Informational Fedora
89

Fedora 42: Rust-LRU 0.16.3 Update Includes RUSTSEC-2026-0002 Fix

Update to version 0.16.3. Includes the fix for RUSTSEC-2026-0002.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-e153bc6b6a 2026-01-20 01:37:20.161994+00:00 -------------------------------------------------------------------------------- Name : rust-lru Product : Fedora 42 Version : 0.16.3 Release : 1.fc42 URL : https://crates.io/crates/lru Summary : LRU cache implementation Description : A LRU cache implementation. -------------------------------------------------------------------------------- Update Information: Update to version 0.16.3. Includes the fix for RUSTSEC-2026-0002. -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 11 2026 Fabio Valentini - 0.16.3-1 - Update to version 0.16.3; Fixes RHBZ#2427568 * Mon Oct 20 2025 Fabio Valentini - 0.16.2-1 - Update to version 0.16.2; Fixes RHBZ#2403982 * Fri Sep 12 2025 Fabio Valentini - 0.16.1-1 - Update to version 0.16.1; Fixes RHBZ#2394055 * Wed Aug 13 2025 Fabio Valentini - 0.16.0-1 - Update to version 0.16.0; Fixes RHBZ#2359224 * Fri Jul 25 2025 Fedora Release Engineering - 0.14.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e153bc6b6a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 42 rust-lru updated to version 0.16.3 with RUSTSEC-2026-0002 fix addressing cache implementation issues.. Fedora rust-lru update cache security. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Jan 20, 2026 Informational Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200