This page covers advisories, notably in relation with security and changes that may have broke or changed how things are done in earlier versions of the book.
In some cases, not every security vulnerability for an advisory will be available. Either upstream does not issue an ID with security authority, like a CVE, or they don't wish to talk about the vulnerability in detail. What's listed is all that can be gathered from upstream and GitHub/Mitre/NVD.
This page was generated from an XML file with XSLT processing. You can easily track updates and view the XML by viewing the advisories GitHub repository.
This page is ordered like the Changelog of the book, with newest items first.
Seventeen security vulnerabilities were fixed that could allow for exploitation in the JAXP, networking, JSSE, JGSS, 2D (FreeType, Little-CMS 2, and general), libraries, security, and ImageIO component APIs. A large number of the vulnerabilities are remotely exploitable, without any authentication required.
Assigned vulnerabilities: CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-23865, CVE-2026-34282, CVE-2026-34628, CVE-2026-41254, CVE-2026-46917, CVE-2026-46968, CVE-2026-47010, CVE-2026-47021, CVE-2026-47027, CVE-2026-47059, CVE-2026-47063, and CVE-2026-60147.
Update by following the OpenJDK installation page.
LXQt-Wayland-Session can utilize multiple Wayland compositors. The most simple one to use is Wayfire. Since LXQT-Wayland-Session is in BLFS, Wayfire was moved to BLFS. As a result, its dependencies like wlroots were also moved to BLFS as a consequence. The following have been moved: nlohmann-json, yyjson, xcb-util-errors (XCB Utilities), libliftoff, seatd, wlroots, xdg-desktop-portal-wlr, Wayfire, and wayfire-plugins-extra.
Read BLFS to follow updates for the moved packages.
Three security vulnerabilities were fixed that could allow for segmentation faults, improper Clang MSan sanitization, and out-of-bounds access.
Assigned vulnerabilities: CVE-2024-37676.
Update by following the htop installation page.
Three security vulnerabilities were fixed that could allow for denial of service (DOS), excessive memory consumption, and invalid characters not being restricted.
Assigned vulnerabilities: GHSA-wwv5-g3v4-889x, GHSA-mpf4-983q-p7j4, and GHSA-8423-8fgw-73vq.
Update by following the tornado installation page.
Two security vulnerabilities were fixed that could allow for denial of service (DOS) and heap buffer overflows. These require the attacker to control the content served by the repository.
Assigned vulnerabilities: GHSA-7cgc-gp99-6jmm and GHSA-xppc-j946-vcj7.
Update by following the OSTree installation page.
Ten security vulnerabilities were fixed that could allow for full sandbox escapes, local root privilege escalations, arbitrary root writing, arbitrary host file reading, path traversal, buffer overflows, fixed-filename writing to arbitrary locations, extension metadata path traversal, host filesystem probing, unintended mount locations, anti-downgrade bypassing, and downgrading system apps by unprivileged users.
Assigned vulnerabilities: GHSA-8688-9x26-hhxj, GHSA-qrwq-7qwx-q9rp, GHSA-fqx6-vh4p-42cg, GHSA-8qxj-x646-phcm, GHSA-9rww-v4mm-x4jg, GHSA-v2gw-v9h5-9q4x, GHSA-jr92-2v97-wgvc, GHSA-99wv-m8rp-g58x, GHSA-w69g-9x8j-7p8f, and GHSA-q4gr-vc25-57m5.
Update immediately by following the Flatpak installation page.
Three security vulnerabilities were fixed that could allow for buffer overflows, memory disclosure, and use-after-free operations. The ngx_http_slice_module and ngx_http_ssi_module modules are affected. Without ALSR enabled, these vulnerabilities allow denial of service (DOS) attacks and remote + arbitrary code execution (RCE and ACE) on systems hosting NGINX instances.
Assigned vulnerabilities: CVE-2026-42533, CVE-2026-56434, and CVE-2026-60005.
Update immediately by following the NGINX installation page.
Nine security vulnerabilities were fixed that could allow for privilege escalation when using the idna package, buffer overflow, denial of service (DOS), unlimited allocation of resources, arbitrary content injection, cross-site scripting (XSS), stack exhaustion, increased memory allocations, infinite operations, undetectable malicious module content, and GOSUMDB check bypassing.
Assigned vulnerabilities: CVE-2026-39821, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862, CVE-2026-56864, and CVE-2026-56865.
Update immediately by following the Go installation page, and reinstall everything that was built with or against the package.
A security vulnerability was fixed that could allow for command injection via improper sanitization of output when using the --write-link option.
Assigned vulnerabilities: CVE-2026-55404.
If you use the --write-link option, or use scripts that do use the --write-link option, it is recommended to update by following the yt-dlp installation page.
A security vulnerability was fixed that could allow for a heap-based buffer overflow in a SOCKS5 proxy server, leading to heap memory overwriting. This is controlled by the attacker, with the size and content being able to be fine-tuned for an attack. No authentication is required. Arbitrary code execution (ACE) can be a result of this attack.
Assigned vulnerabilities: CVE-2026-56123.
VulnCheck gave the vulnerability with an 8.1/10, while NVD gave a 9.8/10. Regardless, update immediately by following the socat installation page.
Three security vulnerabilities were fixed that could allow for use-after-free operations, buffer overflows, and buffer overreads. The ngx_http_v3_module, ngx_http_proxy_v2_module, ngx_http_grpc_module, and ngx_http_charset_module modules are affected. Without ALSR enabled, these vulnerabilities allow remote and arbitrary code execution (RCE and ACE) on systems hosting NGINX instances.
Assigned vulnerabilities: CVE-2026-42055, CVE-2026-42530, and CVE-2026-48142.
Update immediately by following the NGINX installation page.
Three security vulnerabilities were fixed that could allow for excessive CPU consumption and injection of misleading content to errors.
Assigned vulnerabilities: CVE-2026-42504 and CVE-2026-42507.
Update by following the Go installation page, and reinstall everything that was built with or against the package.
Six security vulnerabilities were fixed that could allow for auth and cookie headers being part of the request when following redirects to different origins, denial of service (DOS) attacks, out-of-bounds read operations, improper reponse parsing, credential reuse, and unlimited memory consumption.
Assigned vulnerabilities: GHSA-3x9g-8vmp-wqvf, GHSA-mgf9-4vpg-hj56, GHSA-cx3h-4qpv-8hc9, and GHSA-pw6j-qg29-8w7f.
Update by following the tornado installation page.
Three security vulnerabilities were fixed that could allow for out-of-bounds read operations, denial of service (DOS) attacks, no-progression disassembly, parser desynchronization, and NULL pointer dereferences.
Assigned vulnerabilities: GHSA-289w-cm54-fgrm, GHSA-5m9f-vqcm-g5pr, and GHSA-jrw4-wj52-2vw8.
Update by following the Capstone installation page.
Eleven security vulnerabilities were fixed that could allow for checksum bypassing, query forwarding to unexpected locations, denial of service (DOS) conditions, symlink overwriting, extraction of files to arbitrary locations, and cross-site scripting. These affect multiple components.
Assigned vulnerabilities: CVE-2026-33811, CVE-2026-33814, CVE-2026-39817, CVE-2026-39819, CVE-2026-39820, CVE-2026-39823, CVE-2026-39825, CVE-2026-39826, CVE-2026-39836, CVE-2026-42499, and CVE-2026-42501.
Update by following the Go installation page, and reinstall everything that was built with or against the package.
Seven security vulnerabilities were fixed that could allow for buffer overflows, overreads, HTTP/3 address spoofing, use-after-free operations, and HTTP/2 request injections. The ngx_http_charset_module, ngx_http_rewrite_module, ngx_http_scgi_module, and ngx_http_uwsgi_module modules are affected. The OCSP (Online Certificate Status Protocol) resolver is also affected.
Remote code execution alongside arbitrary code execution (RCE and ACE) are possible via these vulnerabilities, but requires ALSR must be disabled on systems hosting the NGINX instance(s). The attacker must be in a circumstance to be able to bypass ALSR in order to achieve ACE/RCE. Enabling ALSR can fix this, alongside updating the package.
Assigned vulnerabilities: CVE-2026-9256, CVE-2026-40460, CVE-2026-40701, CVE-2026-42926, CVE-2026-42934, CVE-2026-42945, and CVE-2026-42946.
Update immediately by following the NGINX installation page.
Five security vulnerabilities were fixed that could allow for memory and lock leakage, use-after-free operations, and long overflows.
There are no IDs with security authority.
Update by following the pycurl installation page.
Two security vulnerabilities were fixed that could allow for denial of service (DOS) attacks via memory and resource leakage.
There are no IDs with security authority.
Update by following the asio installation page. Every package that uses the package must be reinstalled since the package is header-only.
Updated on April 30th, 2026. Reason: (corrected the link to the asio page).
Eleven security vulnerabilities were fixed that could allow for client impersonation, entropy fallback to /dev/urandom, PSA random generator cloning, compiler-induced constant-time violations, arbitrary code execution (ACE), memory corruption, signature algorithm injection, out-of-bounds read operations, information disclosure, insufficient protection of serialized session/context data, and a buffer underread operation.
Assigned vulnerabilities: CVE-2026-25833, CVE-2026-25834, CVE-2026-25835, CVE-2026-34871, CVE-2026-34872, CVE-2026-34873, CVE-2026-34874, CVE-2026-34875, CVE-2026-34876, CVE-2026-34877, and CVE-2025-66442.
Update immediately by following the Mbed-TLS installation page.
A security vulnerability was fixed that could allow for denial of service (DOS) and potential arbitrary code execution (ACE) when processing RTP and RTCP packets. These issues were caused by a lack of size checks on untrusted input.
There are no IDs with security authority.
Update by following the libdatachannel installation page. Only OBS-Studio uses this package in SLFS and BLFS.
Ten security vulnerabilities were fixed that could allow for the unconditional symlink following, incorrect tracking of JavaScript template literal contexts, improper applying of excluded DNS constraints in certificates to wildcard domains, bypassing of overlap checking for no-op interface conversions, possible memory corription, unbounded allocation, connection deadlocks, trust layer bypassing, and denial of service (DOS). Multiple Go components are affected.
Assigned vulnerabilities: CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-2026-32281, CVE-2026-32282, CVE-2026-32283, CVE-2026-32288, CVE-2026-32289, and CVE-2026-33810.
Update immediately by following the Go installation page, and reinstall everything that was built with or against the package.
Updated on April 18th, 2026. Reason: (Rating: High -> Critical).
Four security vulnerabilities were fixed that could allow for a complete and total sandbox escape, arbitrary file deletion on the host filesystem, arbitrary read access to files in the system-helper context, and orphaning cross-user pull operations. The arbitrary file deletion vulnerability has no restrictions and any app can exploit it or be exploited to do it.
There are no IDs with security authority.
To protect your data, it is highly recommended to update immediately by following the Flatpak installation page.
After updating the package, update to xdg-dbus-proxy-0.1.7 and xdg-desktop-portal-1.20.4 from BLFS to fix security vulnerabilities that allow for arbitrary file deletion and application eavesdropping upon D-Bus activity.
Updated on April 15th, 2026. Reason: (included information regarding updating xdg-desktop-portal and xdg-dbus-proxy).
A security vulnerability was fixed that could allow for an integer underflow while processing character sets when using the ngx_http_upstream_copy_content_type() function. This is considered as an out-of-bounds memory access vulnerability and can lead to a denial of service (DOS) or information disclosure.
There are no IDs with security authority.
Update by following the NGINX installation page.
Six security vulnerabilities were fixed that could allow for buffer overflows, NULL pointer dereferences, arbitrary header injection, and OCSP (Online Certificate Status Protocol) result bypassing in the ngx_http_dav_module and ngx_http_mp4_module modules, while using CRAM-MD5 or APOP, and within auth_http, stream, and XCLIENT.
Assigned vulnerabilities: CVE-2026-27651, CVE-2026-27654, CVE-2026-27784, CVE-2026-28753, CVE-2026-28755, and CVE-2026-32647.
Update by following the NGINX installation page.
Two security vulnerabilities were fixed that could allow for a heap buffer overflow and stack buffer overflow and underflow.
Assigned vulnerabilities: CVE-2025-67873 and CVE-2025-68114.
Update immediately by following the Capstone installation page.
General security was improved for configurations using browser sources which use local files.
There are no IDs with security authority.
If you use browser sources using local files, update by following the OBS-Studio installation page.
Two security vulnerabilities were fixed that could allow for a denial of service (DOS) attack and incomplete validation of cookie attributes.
Assigned vulnerabilities: GHSA-qjxf-f2mg-c6mc and GHSA-78cv-mqj4-43f7.
Update by following the tornado installation page.
This package, which contains all Ada support in the book, has been removed. BLFS nor GLFS provide a replacement. None of the books need or really benefit from Ada, and its installation, with conflicts with BLFS, was unsafe to install as it could break the toolchain.
These packages have been moved to GLFS to coincide with the NVIDIA driver installation.
You can track updates via the GLFS Graphics Drivers - NVIDIA page.
The book no longer provides SDL3 nor sdl2-compat as BLFS has now took them in. It started off as a showcase of what the instructions could look like, to becoming necessary in the dependency chain for the book. BLFS decided that it's time to bring the two packages in, so the book links to the pages from BLFS. GLFS has done the same as BLFS.
A security vulnerability was fixed that could allow for code injection via a crafted link using the --netrc-cmd option. This works by pushing special characters to the shell outside of Python, like Bash or Zsh, which in turn allows for ACI.
There are no IDs with security authority.
If you use the --netrc-cmd option, or use scripts that do use the --netrc-cmd option, it is highly recommended to update immediately by following the yt-dlp installation page.
Four security vulnerabilities were fixed that could allow for denial of service (DOS) attacks and modification of data, both critical and Java data. These attacks require network access and for the attacker to go through mutliple protocols, but don't require human interaction. Some of the vulnerabilities are easy to exploit, while the others are more difficult. These vulnerabilities are actively exploited in the wild, like with Minecraft servers.
There are no IDs with security authority.
It is highly recommended to update immediately by following the OpenJDK installation page.
There were numerous other improvements, but there were also multiple memory safety issues that were fixed.
There are no IDs with security authority.
The sensitive nature of these bugs results in heavy recommendation to update by following the CDE installation page.
There were general code improvements, along with a memory leak and use-after-free fix.
There are no IDs with security authority.
Update by following the i3 installation page.
Three security vulnerabilities were fixed that could allow for header injection, cross-site scription, and denial of service (DOS) attacks.
Assigned vulnerabilities: CVE-2025-67724, CVE-2025-67725, and CVE-2025-67726.
Update by following the tornado installation page.
Two security vulnerabilities were fixed that could allow for partial recovery of CBC-PKCS7-encrypted plaintext and private key material disclosure.
Assigned vulnerabilities: CVE-2025-54764 and CVE-2025-59438.
Update by following the Mbed-TLS installation page.
Two security vulnerabilities were fixed that could allow for exploitation of APIs via multiple network protocols, leading to creation, modification, and deletion of data. This is especially an issue with Minecraft servers, as an affected JDK version will have elevated privileges because of calls to mods/modpacks. These vulnerabilities affect other major JDK versions. If you have multiple OpenJDK versions built, update all of them if there is an update present.
Assigned vulnerabilities: CVE-2025-53057 and CVE-2025-53066.
Update by following the OpenJDK installation page.