SLFS Advisories

Introduction

This page covers advisories, notably in relation with security and changes that may have broken earlier versions of the book.

Sometimes, not every security vulnerability for an advisory will be available. Sometimes, upstream does not issue an ID with security authority, like a CVE. Sometimes, they don't wish to talk about the vulnerability in detail. What's listed is all that can be gathered from upstream and GitHub/Mitre/NVD.

This page was generated from an XML file with XSLT processing. You can easily track updates and view the XML by viewing the advisories GitHub repository.

This page is ordered like the Changelog of the book, with newest items first.

13.0

Security Advisories

slfs-sec-13.0-015: tornado-6.5.7 - Rating: High (Date: July 14th, 2026)

Six security vulnerabilities were fixed that could allow for auth and cookie headers being part of the request when following redirects to different origins, denial of service (DOS) attacks, out-of-bounds read operations, improper reponse parsing, credential reuse, and unlimited memory consumption.

Assigned vulnerabilities: GHSA-3x9g-8vmp-wqvf, GHSA-mgf9-4vpg-hj56, GHSA-cx3h-4qpv-8hc9, and GHSA-pw6j-qg29-8w7f.

Update by following the tornado installation page.

slfs-sec-13.0-014: Capstone-5.0.9 - Rating: Medium (Date: July 14th, 2026)

Three security vulnerabilities were fixed that could allow for out-of-bounds read operations, denial of service (DOS) attacks, no-progression disassembly, parser desynchronization, and NULL pointer dereferences.

Assigned vulnerabilities: GHSA-289w-cm54-fgrm, GHSA-5m9f-vqcm-g5pr, and GHSA-jrw4-wj52-2vw8.

Update by following the Capstone installation page.

slfs-sec-13.0-013: Go-1.26.3 - Rating: High (Date: June 1st, 2026)

Eleven security vulnerabilities were fixed that could allow for checksum bypassing, query forwarding to unexpected locations, denial of service (DOS) conditions, symlink overwriting, extraction of files to arbitrary locations, and cross-site scripting. These affect multiple components.

Assigned vulnerabilities: CVE-2026-33811, CVE-2026-33814, CVE-2026-39817, CVE-2026-39819, CVE-2026-39820, CVE-2026-39823, CVE-2026-39825, CVE-2026-39826, CVE-2026-39836, CVE-2026-42499, and CVE-2026-42501.

Update by following the Go installation page, and reinstall everything that was built with or against the package.

slfs-sec-13.0-012: NGINX-1.31.1 - Rating: Critical (Date: May 29th, 2026)

Seven security vulnerabilities were fixed that could allow for buffer overflows, overreads, HTTP/3 address spoofing, use-after-free operations, and HTTP/2 request injections. The ngx_http_charset_module, ngx_http_rewrite_module, ngx_http_scgi_module, and ngx_http_uwsgi_module modules are affected. The OCSP (Online Certificate Status Protocol) resolver is also affected.

Remote code execution alongside arbitrary code execution (RCE and ACE) are possible via these vulnerabilities, but requires ALSR must be disabled on systems hosting the NGINX instance(s). The attacker must be in a circumstance to be able to bypass ALSR in order to achieve ACE/RCE. Enabling ALSR can fix this, alongside updating the package.

Assigned vulnerabilities: CVE-2026-9256, CVE-2026-40460, CVE-2026-40701, CVE-2026-42926, CVE-2026-42934, CVE-2026-42945, and CVE-2026-42946.

Update immediately by following the NGINX installation page.

slfs-sec-13.0-011: pycurl-7.46.0 - Rating: High (Date: May 9th, 2026)

Five security vulnerabilities were fixed that could allow for memory and lock leakage, use-after-free operations, and long overflows.

There are no IDs with security authority.

Update by following the pycurl installation page.

slfs-sec-13.0-010: asio-1-38-0 - Rating: High (Date: April 19th, 2026)

Two security vulnerabilities were fixed that could allow for denial of service (DOS) attacks via memory and resource leakage.

There are no IDs with security authority.

Update by following the asio installation page. Every package that uses the package must be reinstalled since the package is header-only.

Updated on April 30th, 2026. Reason: (corrected the link to the asio page).

slfs-sec-13.0-009: Mbed-TLS-3.6.6 - Rating: Critical (Date: April 8th, 2026)

Eleven security vulnerabilities were fixed that could allow for client impersonation, entropy fallback to /dev/urandom, PSA random generator cloning, compiler-induced constant-time violations, arbitrary code execution (ACE), memory corruption, signature algorithm injection, out-of-bounds read operations, information disclosure, insufficient protection of serialized session/context data, and a buffer underread operation.

Assigned vulnerabilities: CVE-2026-25833, CVE-2026-25834, CVE-2026-25835, CVE-2026-34871, CVE-2026-34872, CVE-2026-34873, CVE-2026-34874, CVE-2026-34875, CVE-2026-34876, CVE-2026-34877, and CVE-2025-66442.

Update immediately by following the Mbed-TLS installation page.

slfs-sec-13.0-008: libdatachannel-0.24.2 - Rating: Medium (Date: April 8th, 2026)

A security vulnerability was fixed that could allow for denial of service (DOS) and potential arbitrary code execution (ACE) when processing RTP and RTCP packets. These issues were caused by a lack of size checks on untrusted input.

There are no IDs with security authority.

Update by following the libdatachannel installation page. Only OBS-Studio uses this package in SLFS and BLFS.

slfs-sec-13.0-007: Go-1.26.2 - Rating: Critical (Date: April 8th, 2026)

Ten security vulnerabilities were fixed that could allow for the unconditional symlink following, incorrect tracking of JavaScript template literal contexts, improper applying of excluded DNS constraints in certificates to wildcard domains, bypassal of overlap checking for no-op interface conversions, possible memory corription, unbounded allocation, connection deadlocks, trust layer bypassal, and denial of service (DOS). Multiple Go components are affected.

Assigned vulnerabilities: CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-2026-32281, CVE-2026-32282, CVE-2026-32283, CVE-2026-32288, CVE-2026-32289, and CVE-2026-33810.

Update immediately by following the Go installation page, and reinstall everything that was built with or against the package.

Updated on April 18th, 2026. Reason: (Rating: High -> Critical).

slfs-sec-13.0-006: Flatpak-1.16.5 - Rating: Critical (Date: April 8th, 2026)

Four security vulnerabilities were fixed that could allow for a complete and total sandbox escape, arbitrary file deletion on the host filesystem, arbitrary read access to files in the system-helper context, and orphaning cross-user pull operations. The arbitrary file deletion vulnerability has no restrictions and any app can exploit it or be exploited to do it.

There are no IDs with security authority.

To protect your data, it is highly recommended to update immediately by following the Flatpak installation page.

After updating the package, update to xdg-dbus-proxy-0.1.7 and xdg-desktop-portal-1.20.4 from BLFS to fix security vulnerabilities that allow for arbitrary file deletion and application eavesdropping upon D-Bus activity.

Updated on April 15th, 2026. Reason: (included information regarding updating xdg-desktop-portal and xdg-dbus-proxy).

slfs-sec-13.0-005: NGINX-1.29.8 - Rating: Medium (Date: April 8th, 2026)

A security vulnerability was fixed that could allow for an integer underflow while processing character sets when using the ngx_http_upstream_copy_content_type() function. This is considered as an out-of-bounds memory access vulnerability and can lead to a denial of service (DOS) or information disclosure.

There are no IDs with security authority.

Update by following the NGINX installation page.

slfs-sec-13.0-004: NGINX-1.29.7 - Rating: High (Date: April 7th, 2026)

Six security vulnerabilities were fixed that could allow for buffer overflows, NULL pointer dereferences, arbitrary header injection, and OCSP (Online Certificate Status Protocol) result bypassing in the ngx_http_dav_module and ngx_http_mp4_module modules, while using CRAM-MD5 or APOP, and within auth_http, stream, and XCLIENT.

Assigned vulnerabilities: CVE-2026-27651, CVE-2026-27654, CVE-2026-27784, CVE-2026-28753, CVE-2026-28755, and CVE-2026-32647.

Update by following the NGINX installation page.

slfs-sec-13.0-003: Capstone-5.0.7 - Rating: Critical (Date: April 7th, 2026)

Two security vulnerabilities were fixed that could allow for a heap buffer overflow and stack buffer overflow and underflow.

Assigned vulnerabilities: CVE-2025-67873 and CVE-2025-68114.

Update immediately by following the Capstone installation page.

slfs-sec-13.0-002: OBS-Studio-32.1.0 - Rating: High (Date: April 7th, 2026)

General security was improved for configurations using browser sources which use local files.

There are no IDs with security authority.

If you use browser sources using local files, update by following the OBS-Studio installation page.

slfs-sec-13.0-001: tornado-6.5.5 - Rating: High (Date: March 21st, 2026)

Two security vulnerabilities were fixed that could allow for a denial of service (DOS) attack and incomplete validation of cookie attributes.

Assigned vulnerabilities: GHSA-qjxf-f2mg-c6mc and GHSA-78cv-mqj4-43f7.

Update by following the tornado installation page.


12.4

Broken Changes

slfs-brk-12.4-003: GNAT/GCC-Ada (Date: January 17th, 2026)

This package, which contains all Ada support in the book, has been removed. BLFS nor GLFS provide a replacement. None of the books need or really benefit from Ada, and its installation, with conflicts with BLFS, was unsafe to install as it could break the toolchain.

slfs-brk-12.4-002: nv-codec-headers (ffnvcodec) and CUDA (Date: November 24th, 2025)

These packages have been moved to GLFS to coincide with the NVIDIA driver installation.

You can track updates via the GLFS Graphics Drivers - NVIDIA page.

slfs-brk-12.4-001: SDL3 (Date: November 18th, 2025)

The book no longer provides SDL3 nor sdl2-compat as BLFS has now took them in. It started off as a showcase of what the instructions could look like, to becoming necessary in the dependency chain for the book. BLFS decided that it's time to bring the two packages in, so the book links to the pages from BLFS. GLFS has done the same as BLFS.

Security Advisories

slfs-sec-12.4-007: yt-dlp-2026.02.21 - Rating: High (Date: February 24th, 2026)

A security vulnerability was fixed that could allow for code injection via a crafted link using the --netrc-cmd option. This works by pushing special characters to the shell outside of Python, like Bash or Zsh, which in turn allows for ACI.

There are no IDs with security authority.

If you use the --netrc-cmd option, or use scripts that do use the --netrc-cmd option, it is highly recommended to update immediately by following the yt-dlp installation page.

slfs-sec-12.4-006: OpenJDK-17.0.18 - Rating: High (Date: January 28th, 2026)

Four security vulnerabilities were fixed that could allow for denial of service (DOS) attacks and modification of data, both critical and Java data. These attacks require network access and for the attacker to go through mutliple protocols, but don't require human interaction. Some of the vulnerabilities are easy to exploit, while the others are more difficult. These vulnerabilities are actively exploited in the wild, like with Minecraft servers.

There are no IDs with security authority.

It is highly recommended to update immediately by following the OpenJDK installation page.

slfs-sec-12.4-005: CDE-2.5.3 - Rating: High (Date: January 7th, 2026)

There were numerous other improvements, but there were also multiple memory safety issues that were fixed.

There are no IDs with security authority.

The sensitive nature of these bugs results in heavy recommendation to update by following the CDE installation page.

slfs-sec-12.4-004: i3-4.25 - Rating: High (Date: December 30th, 2025)

There were general code improvements, along with a memory leak and use-after-free fix.

There are no IDs with security authority.

Update by following the i3 installation page.

slfs-sec-12.4-003: tornado-6.5.3 - Rating: High (Date: December 15th, 2025)

Three security vulnerabilities were fixed that could allow for header injection, cross-site scription, and denial of service (DOS) attacks.

Assigned vulnerabilities: CVE-2025-67724, CVE-2025-67725, and CVE-2025-67726.

Update by following the tornado installation page.

slfs-sec-12.4-002: Mbed-TLS-3.6.5 - Rating: Medium (Date: December 15th, 2025)

Two security vulnerabilities were fixed that could allow for partial recovery of CBC-PKCS7-encrypted plaintext and private key material disclosure.

Assigned vulnerabilities: CVE-2025-54764 and CVE-2025-59438.

Update by following the Mbed-TLS installation page.

slfs-sec-12.4-001: OpenJDK-17.0.17-ga - Rating: High (Date: October 23rd, 2025)

Two security vulnerabilities were fixed that could allow for exploitation of APIs via multiple network protocols, leading to creation, modification, and deletion of data. This is especially an issue with Minecraft servers, as an affected JDK version will have elevated privileges because of calls to mods/modpacks. These vulnerabilities affect other major JDK versions. If you have multiple OpenJDK versions built, update all of them if there is an update present.

Assigned vulnerabilities: CVE-2025-53057 and CVE-2025-53066.

Update by following the OpenJDK installation page.