Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
100

Ubuntu OS 20.04 xkbcompile Memory Cap Warning DEBIAN-NOTICE-2028-40405-3

An update that solves four vulnerabilities can now be installed.. # Security update for xkbcomp Announcement ID: SUSE-SU-2026:20186-1 Release Date: 2026-01-28T15:47:30Z Rating: low References: * bsc#1105832 Cross-References: * CVE-2018-15853 * CVE-2018-15859 * CVE-2018-15861 * CVE-2018-15863 CVSS scores: * CVE-2018-15853 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15853 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15853 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2018-15859 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15859 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15859 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2018-15861 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15861 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15861 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2018-15863 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15863 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15863 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for xkbcomp fixes the following issues: * CVE-2018-15863, CVE-2018-15861, CVE-2018-15859, CVE-2018-15853: Fixed multiple memory handling and correctness issues (bsc#1105832) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-208=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-208=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * xkbcomp-debuginfo-1.4.7-160000.3.1 * xkbcomp-1.4.7-160000.3.1 * xkbcomp-devel-1.4.7-160000.3.1 * xkbcomp-debugsource-1.4.7-160000.3.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * xkbcomp-debuginfo-1.4.7-160000.3.1 * xkbcomp-1.4.7-160000.3.1 * xkbcomp-devel-1.4.7-160000.3.1 * xkbcomp-debugsource-1.4.7-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2018-15853.html * https://www.suse.com/security/cve/CVE-2018-15859.html * https://www.suse.com/security/cve/CVE-2018-15861.html * https://www.suse.com/security/cve/CVE-2018-15863.html * https://bugzilla.suse.com/show_bug.cgi?id=1105832 . This security advisory highlights a low-severity update for xkbcomp addressing multiple memory handling issues.. SUSE security update,xkbcomp update,low severity security,xkbcomp vulnerabilities,SUSE advisory. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Feb 03, 2026 Low SuSE
202

openSUSE: xkbcomp Moderate Security Issues Advisory 2025:4426-1

An update that solves four vulnerabilities can now be installed.. # Security update for xkbcomp Announcement ID: SUSE-SU-2025:4426-1 Release Date: 2025-12-17T11:22:48Z Rating: moderate References: * bsc#1105832 Cross-References: * CVE-2018-15853 * CVE-2018-15859 * CVE-2018-15861 * CVE-2018-15863 CVSS scores: * CVE-2018-15853 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15853 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15853 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2018-15859 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15859 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15859 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2018-15861 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15861 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15861 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2018-15863 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15863 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15863 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for xkbcomp fixes the following issues: * CVE-2018-15863: NULL pointer dereference triggered by a a crafted keymap file with a no-op modmask expression can lead to a crash(bsc#1105832). * CVE-2018-15861: NULL pointer dereference triggered by a crafted keymap file that induces an `xkb_intern_atom` failure can lead to a crash (bsc#1105832). * CVE-2018-15859: NULL pointer dereference triggered by a specially a crafted keymap file can lead to a crash (bsc#1105832). * CVE-2018-15853: endless recursion triggered by a crafted keymap file that induces boolean negation can lead to a crash (bsc#1105832). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-4426=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-4426=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-4426=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * xkbcomp-devel-1.4.1-150000.3.6.1 * xkbcomp-1.4.1-150000.3.6.1 * xkbcomp-debugsource-1.4.1-150000.3.6.1 * xkbcomp-debuginfo-1.4.1-150000.3.6.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * xkbcomp-devel-1.4.1-150000.3.6.1 * xkbcomp-1.4.1-150000.3.6.1 * xkbcomp-debugsource-1.4.1-150000.3.6.1 * xkbcomp-debuginfo-1.4.1-150000.3.6.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * xkbcomp-devel-1.4.1-150000.3.6.1 * xkbcomp-1.4.1-150000.3.6.1 * xkbcomp-debugsource-1.4.1-150000.3.6.1 * xkbcomp-debuginfo-1.4.1-150000.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2018-15853.html * https://www.suse.com/security/cve/CVE-2018-15859.html * https://www.suse.com/security/cve/CVE-2018-15861.html * https://www.suse.com/security/cve/CVE-2018-15863.html * https://bugzilla.suse.com/show_bug.cgi?id=1105832 . An openSUSE update resolves four security issues in xkbcomp, rated moderate. Install patches promptly to secure your system..openSUSE update,xkbcomp security,xkbcomp vulnerabilities,xkbcomp patches,moderate severity. . LinuxSecurity.com Team

Calendar 2 Dec 17, 2025 OpenSUSE
100

SUSE: xkbcomp Moderate NULL Pointer Crashes Vuln 2025:4426-1

An update that solves four vulnerabilities can now be installed.. # Security update for xkbcomp Announcement ID: SUSE-SU-2025:4426-1 Release Date: 2025-12-17T11:22:48Z Rating: moderate References: * bsc#1105832 Cross-References: * CVE-2018-15853 * CVE-2018-15859 * CVE-2018-15861 * CVE-2018-15863 CVSS scores: * CVE-2018-15853 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15853 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15853 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2018-15859 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15859 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15859 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2018-15861 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15861 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15861 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2018-15863 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15863 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15863 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for xkbcomp fixes the following issues: * CVE-2018-15863: NULL pointer dereference triggered by a a crafted keymap file with a no-op modmask expression can lead to a crash(bsc#1105832). * CVE-2018-15861: NULL pointer dereference triggered by a crafted keymap file that induces an `xkb_intern_atom` failure can lead to a crash (bsc#1105832). * CVE-2018-15859: NULL pointer dereference triggered by a specially a crafted keymap file can lead to a crash (bsc#1105832). * CVE-2018-15853: endless recursion triggered by a crafted keymap file that induces boolean negation can lead to a crash (bsc#1105832). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-4426=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-4426=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-4426=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * xkbcomp-devel-1.4.1-150000.3.6.1 * xkbcomp-1.4.1-150000.3.6.1 * xkbcomp-debugsource-1.4.1-150000.3.6.1 * xkbcomp-debuginfo-1.4.1-150000.3.6.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * xkbcomp-devel-1.4.1-150000.3.6.1 * xkbcomp-1.4.1-150000.3.6.1 * xkbcomp-debugsource-1.4.1-150000.3.6.1 * xkbcomp-debuginfo-1.4.1-150000.3.6.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * xkbcomp-devel-1.4.1-150000.3.6.1 * xkbcomp-1.4.1-150000.3.6.1 * xkbcomp-debugsource-1.4.1-150000.3.6.1 * xkbcomp-debuginfo-1.4.1-150000.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2018-15853.html * https://www.suse.com/security/cve/CVE-2018-15859.html * https://www.suse.com/security/cve/CVE-2018-15861.html * https://www.suse.com/security/cve/CVE-2018-15863.html * https://bugzilla.suse.com/show_bug.cgi?id=1105832 . Critical update for xkbcomp addressing four vulnerabilities and their risks in SUSE systems effective December 2025.. SUSEsecurity update, xkbcomp issues, Linux security patch. . LinuxSecurity.com Team

Calendar 2 Dec 17, 2025 SuSE
100

SUSE: xkbcomp Moderate Update CVE-2018-15853 Crash Risk 2025:4407-1

An update that solves four vulnerabilities can now be installed.. # Security update for xkbcomp Announcement ID: SUSE-SU-2025:4407-1 Release Date: 2025-12-15T16:54:15Z Rating: moderate References: * bsc#1105832 Cross-References: * CVE-2018-15853 * CVE-2018-15859 * CVE-2018-15861 * CVE-2018-15863 CVSS scores: * CVE-2018-15853 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15853 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15853 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2018-15859 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15859 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15859 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2018-15861 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15861 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15861 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2018-15863 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15863 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15863 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves four vulnerabilities can now be installed. ## Description: This update for xkbcomp fixes the following issues: * CVE-2018-15863: NULL pointer dereference triggered by a a crafted keymap file with a no-op modmask expression can lead to a crash (bsc#1105832). * CVE-2018-15861: NULL pointer dereference triggered by a crafted keymap file that induces an `xkb_intern_atom` failure can lead to a crash (bsc#1105832). * CVE-2018-15859: NULL pointer dereference triggered by a specially a crafted keymap file can lead to a crash(bsc#1105832). * CVE-2018-15853: endless recursion triggered by a crafted keymap file that induces boolean negation can lead to a crash (bsc#1105832). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-4407=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * xkbcomp-1.2.4-11.3.1 * xkbcomp-devel-1.2.4-11.3.1 * xkbcomp-debugsource-1.2.4-11.3.1 * xkbcomp-debuginfo-1.2.4-11.3.1 ## References: * https://www.suse.com/security/cve/CVE-2018-15853.html * https://www.suse.com/security/cve/CVE-2018-15859.html * https://www.suse.com/security/cve/CVE-2018-15861.html * https://www.suse.com/security/cve/CVE-2018-15863.html * https://bugzilla.suse.com/show_bug.cgi?id=1105832 . Four vulnerabilities addressed in SUSE's xkbcomp update—critical for maintaining system security and stability.. xkbcomp update, SUSE Linux security, moderate security issue, system stability fix. . LinuxSecurity.com Team

Calendar 2 Dec 16, 2025 SuSE
89

Fedora 42: xkbcomp Critical Advisory for CVE-2018-15853 DoS Risk

xkbcomp 1.5.0 (CVE-2018-15853, CVE-2018-15859, CVE-2018-15861, CVE-2018-15863). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e110b32ac7 2025-12-14 01:31:22.817224+00:00 -------------------------------------------------------------------------------- Name : xkbcomp Product : Fedora 42 Version : 1.5.0 Release : 1.fc42 URL : https://https:// Summary : XKB keymap compiler Description : X.Org XKB keymap compiler -------------------------------------------------------------------------------- Update Information: xkbcomp 1.5.0 (CVE-2018-15853, CVE-2018-15859, CVE-2018-15861, CVE-2018-15863) -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 3 2025 Peter Hutterer - 1.5.0-1 - xkbcomp 1.5.0 (CVE-2018-15853, CVE-2018-15859, CVE-2018-15861, CVE-2018-15863) * Fri Jul 25 2025 Fedora Release Engineering - 1.4.7-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e110b32ac7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines:https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Critical security advisory for Fedora 42 xkbcomp addressing DoS threats following multiple CVE reports.. Fedora xkbcomp update critical security DoS. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 14, 2025 Critical Fedora
202

openSUSE Tumbleweed: xkbcomp Moderate Security Update 2025:15815-1

An update that solves 4 vulnerabilities can now be installed.. # xkbcomp-1.5.0-1.1 on GA media Announcement ID: openSUSE-SU-2025:15815-1 Rating: moderate Cross-References: * CVE-2018-15853 * CVE-2018-15859 * CVE-2018-15861 * CVE-2018-15863 CVSS scores: * CVE-2018-15853 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15859 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15861 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-15863 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * openSUSE Tumbleweed An update that solves 4 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the xkbcomp-1.5.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * xkbcomp 1.5.0-1.1 * xkbcomp-devel 1.5.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2018-15853.html * https://www.suse.com/security/cve/CVE-2018-15859.html * https://www.suse.com/security/cve/CVE-2018-15861.html * https://www.suse.com/security/cve/CVE-2018-15863.html . An update for xkbcomp on openSUSE addresses moderate severity security flaws enhancing system protection.. openSUSE Security, xkbcomp Update, System Vulnerability Fixes, Security Advisory 2025, Moderate Threat Management. . LinuxSecurity.com Team

Calendar 2 Dec 12, 2025 OpenSUSE
89

Fedora 43: Critical NULL Pointer Dereference Vulnerability in xkbcomp

xkbcomp 1.5.0 (CVE-2018-15853, CVE-2018-15859, CVE-2018-15861, CVE-2018-15863). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-3a9b79ca0e 2025-12-06 00:48:01.839815+00:00 -------------------------------------------------------------------------------- Name : xkbcomp Product : Fedora 43 Version : 1.5.0 Release : 1.fc43 URL : https://https:// Summary : XKB keymap compiler Description : X.Org XKB keymap compiler -------------------------------------------------------------------------------- Update Information: xkbcomp 1.5.0 (CVE-2018-15853, CVE-2018-15859, CVE-2018-15861, CVE-2018-15863) -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 3 2025 Peter Hutterer - 1.5.0-1 - xkbcomp 1.5.0 (CVE-2018-15853, CVE-2018-15859, CVE-2018-15861, CVE-2018-15863) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2418046 - CVE-2018-15853 xkbcomp: Endless recursion in xkbcomp/expr.c resulting in a crash [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2418046 [ 2 ] Bug #2418048 - CVE-2018-15863 xkbcomp: NULL pointer dereference in ResolveStateAndPredicate resulting in a crash [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2418048 [ 3 ] Bug #2418050 - CVE-2018-15861 xkbcomp: NULL pointer dereference in ExprResolveLhs resulting in a crash [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2418050 [ 4 ] Bug #2418053 - CVE-2018-15859 xkbcomp: NULL pointer dereference when parsing invalid atoms in ExprResolveLhs resulting in a crash [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2418053 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-3a9b79ca0e' at the command line. For moreinformation, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Critical update for Fedora 43 addressing multiple xkbcomp crashes from NULL pointer dereferences and other keymap issues.. Fedora 43,xkbcomp,security advisory,null pointer crash. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 06, 2025 Important Fedora
203

Mageia 9: Resolving xkbcomp Crash Issues with MGASA-2025-0321 and CVEs

MGASA-2025-0321 - Updated xkbcomp packages fix security vulnerabilities. MGASA-2025-0321 - Updated xkbcomp packages fix security vulnerabilities Publication date: 04 Dec 2025 URL: https://advisories.mageia.org/MGASA-2025-0321.html Type: security Affected Mageia releases: 9 CVE: CVE-2018-15853, CVE-2018-15859, CVE-2018-15861, CVE-2018-15863 Description: Endless recursion in xkbcomp/expr.c resulting in a crash. (CVE-2018-15853) NULL pointer dereference when parsing invalid atoms in ExprResolveLhs resulting in a crash. (CVE-2018-15859) NULL pointer dereference in ExprResolveLhs resulting in a crash. (CVE-2018-15861) NULL pointer dereference in ResolveStateAndPredicate resulting in a crash. (CVE-2018-15863) References: - https://bugs.mageia.org/show_bug.cgi?id=34796 - https://www.openwall.com/lists/oss-security/2025/12/03/1 - https://www.cve.org/CVERecord?id=CVE-2018-15853 - https://www.cve.org/CVERecord?id=CVE-2018-15859 - https://www.cve.org/CVERecord?id=CVE-2018-15861 - https://www.cve.org/CVERecord?id=CVE-2018-15863 SRPMS: - 9/core/xkbcomp-1.4.6-1.1.mga9 . Mageia's xkbcomp package has been updated to address critical crashes from multiple security issues. Patch now!. Mageia xkbcomp security patch crash updates. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 05, 2025 Important Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here