This page covers advisories, notably in relation with security and changes that may have broken earlier versions of the book.
Sometimes, not every security vulnerability for an advisory will be available. Sometimes, upstream does not issue an ID with security authority, like a CVE. Sometimes, they don't wish to talk about the vulnerability in detail. What's listed is all that can be gathered from upstream and GitHub/Mitre/NVD.
This page was generated from an XML file with XSLT processing. You can easily track updates and view the XML by viewing the advisories GitHub repository.
This page is ordered like the Changelog of the book, with newest items first.
Six security vulnerabilities were fixed that could allow for auth and cookie headers being part of the request when following redirects to different origins, denial of service (DOS) attacks, out-of-bounds read operations, improper reponse parsing, credential reuse, and unlimited memory consumption.
Assigned vulnerabilities: GHSA-3x9g-8vmp-wqvf, GHSA-mgf9-4vpg-hj56, GHSA-cx3h-4qpv-8hc9, and GHSA-pw6j-qg29-8w7f.
Update by following the tornado installation page.
Three security vulnerabilities were fixed that could allow for out-of-bounds read operations, denial of service (DOS) attacks, no-progression disassembly, parser desynchronization, and NULL pointer dereferences.
Assigned vulnerabilities: GHSA-289w-cm54-fgrm, GHSA-5m9f-vqcm-g5pr, and GHSA-jrw4-wj52-2vw8.
Update by following the Capstone installation page.
Eleven security vulnerabilities were fixed that could allow for checksum bypassing, query forwarding to unexpected locations, denial of service (DOS) conditions, symlink overwriting, extraction of files to arbitrary locations, and cross-site scripting. These affect multiple components.
Assigned vulnerabilities: CVE-2026-33811, CVE-2026-33814, CVE-2026-39817, CVE-2026-39819, CVE-2026-39820, CVE-2026-39823, CVE-2026-39825, CVE-2026-39826, CVE-2026-39836, CVE-2026-42499, and CVE-2026-42501.
Update by following the Go installation page, and reinstall everything that was built with or against the package.
Seven security vulnerabilities were fixed that could allow for buffer overflows, overreads, HTTP/3 address spoofing, use-after-free operations, and HTTP/2 request injections. The ngx_http_charset_module, ngx_http_rewrite_module, ngx_http_scgi_module, and ngx_http_uwsgi_module modules are affected. The OCSP (Online Certificate Status Protocol) resolver is also affected.
Remote code execution alongside arbitrary code execution (RCE and ACE) are possible via these vulnerabilities, but requires ALSR must be disabled on systems hosting the NGINX instance(s). The attacker must be in a circumstance to be able to bypass ALSR in order to achieve ACE/RCE. Enabling ALSR can fix this, alongside updating the package.
Assigned vulnerabilities: CVE-2026-9256, CVE-2026-40460, CVE-2026-40701, CVE-2026-42926, CVE-2026-42934, CVE-2026-42945, and CVE-2026-42946.
Update immediately by following the NGINX installation page.
Five security vulnerabilities were fixed that could allow for memory and lock leakage, use-after-free operations, and long overflows.
There are no IDs with security authority.
Update by following the pycurl installation page.
Two security vulnerabilities were fixed that could allow for denial of service (DOS) attacks via memory and resource leakage.
There are no IDs with security authority.
Update by following the asio installation page. Every package that uses the package must be reinstalled since the package is header-only.
Updated on April 30th, 2026. Reason: (corrected the link to the asio page).
Eleven security vulnerabilities were fixed that could allow for client impersonation, entropy fallback to /dev/urandom, PSA random generator cloning, compiler-induced constant-time violations, arbitrary code execution (ACE), memory corruption, signature algorithm injection, out-of-bounds read operations, information disclosure, insufficient protection of serialized session/context data, and a buffer underread operation.
Assigned vulnerabilities: CVE-2026-25833, CVE-2026-25834, CVE-2026-25835, CVE-2026-34871, CVE-2026-34872, CVE-2026-34873, CVE-2026-34874, CVE-2026-34875, CVE-2026-34876, CVE-2026-34877, and CVE-2025-66442.
Update immediately by following the Mbed-TLS installation page.
A security vulnerability was fixed that could allow for denial of service (DOS) and potential arbitrary code execution (ACE) when processing RTP and RTCP packets. These issues were caused by a lack of size checks on untrusted input.
There are no IDs with security authority.
Update by following the libdatachannel installation page. Only OBS-Studio uses this package in SLFS and BLFS.
Ten security vulnerabilities were fixed that could allow for the unconditional symlink following, incorrect tracking of JavaScript template literal contexts, improper applying of excluded DNS constraints in certificates to wildcard domains, bypassal of overlap checking for no-op interface conversions, possible memory corription, unbounded allocation, connection deadlocks, trust layer bypassal, and denial of service (DOS). Multiple Go components are affected.
Assigned vulnerabilities: CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-2026-32281, CVE-2026-32282, CVE-2026-32283, CVE-2026-32288, CVE-2026-32289, and CVE-2026-33810.
Update immediately by following the Go installation page, and reinstall everything that was built with or against the package.
Updated on April 18th, 2026. Reason: (Rating: High -> Critical).
Four security vulnerabilities were fixed that could allow for a complete and total sandbox escape, arbitrary file deletion on the host filesystem, arbitrary read access to files in the system-helper context, and orphaning cross-user pull operations. The arbitrary file deletion vulnerability has no restrictions and any app can exploit it or be exploited to do it.
There are no IDs with security authority.
To protect your data, it is highly recommended to update immediately by following the Flatpak installation page.
After updating the package, update to xdg-dbus-proxy-0.1.7 and xdg-desktop-portal-1.20.4 from BLFS to fix security vulnerabilities that allow for arbitrary file deletion and application eavesdropping upon D-Bus activity.
Updated on April 15th, 2026. Reason: (included information regarding updating xdg-desktop-portal and xdg-dbus-proxy).
A security vulnerability was fixed that could allow for an integer underflow while processing character sets when using the ngx_http_upstream_copy_content_type() function. This is considered as an out-of-bounds memory access vulnerability and can lead to a denial of service (DOS) or information disclosure.
There are no IDs with security authority.
Update by following the NGINX installation page.
Six security vulnerabilities were fixed that could allow for buffer overflows, NULL pointer dereferences, arbitrary header injection, and OCSP (Online Certificate Status Protocol) result bypassing in the ngx_http_dav_module and ngx_http_mp4_module modules, while using CRAM-MD5 or APOP, and within auth_http, stream, and XCLIENT.
Assigned vulnerabilities: CVE-2026-27651, CVE-2026-27654, CVE-2026-27784, CVE-2026-28753, CVE-2026-28755, and CVE-2026-32647.
Update by following the NGINX installation page.
Two security vulnerabilities were fixed that could allow for a heap buffer overflow and stack buffer overflow and underflow.
Assigned vulnerabilities: CVE-2025-67873 and CVE-2025-68114.
Update immediately by following the Capstone installation page.
General security was improved for configurations using browser sources which use local files.
There are no IDs with security authority.
If you use browser sources using local files, update by following the OBS-Studio installation page.
Two security vulnerabilities were fixed that could allow for a denial of service (DOS) attack and incomplete validation of cookie attributes.
Assigned vulnerabilities: GHSA-qjxf-f2mg-c6mc and GHSA-78cv-mqj4-43f7.
Update by following the tornado installation page.
This package, which contains all Ada support in the book, has been removed. BLFS nor GLFS provide a replacement. None of the books need or really benefit from Ada, and its installation, with conflicts with BLFS, was unsafe to install as it could break the toolchain.
These packages have been moved to GLFS to coincide with the NVIDIA driver installation.
You can track updates via the GLFS Graphics Drivers - NVIDIA page.
The book no longer provides SDL3 nor sdl2-compat as BLFS has now took them in. It started off as a showcase of what the instructions could look like, to becoming necessary in the dependency chain for the book. BLFS decided that it's time to bring the two packages in, so the book links to the pages from BLFS. GLFS has done the same as BLFS.
A security vulnerability was fixed that could allow for code injection via a crafted link using the --netrc-cmd option. This works by pushing special characters to the shell outside of Python, like Bash or Zsh, which in turn allows for ACI.
There are no IDs with security authority.
If you use the --netrc-cmd option, or use scripts that do use the --netrc-cmd option, it is highly recommended to update immediately by following the yt-dlp installation page.
Four security vulnerabilities were fixed that could allow for denial of service (DOS) attacks and modification of data, both critical and Java data. These attacks require network access and for the attacker to go through mutliple protocols, but don't require human interaction. Some of the vulnerabilities are easy to exploit, while the others are more difficult. These vulnerabilities are actively exploited in the wild, like with Minecraft servers.
There are no IDs with security authority.
It is highly recommended to update immediately by following the OpenJDK installation page.
There were numerous other improvements, but there were also multiple memory safety issues that were fixed.
There are no IDs with security authority.
The sensitive nature of these bugs results in heavy recommendation to update by following the CDE installation page.
There were general code improvements, along with a memory leak and use-after-free fix.
There are no IDs with security authority.
Update by following the i3 installation page.
Three security vulnerabilities were fixed that could allow for header injection, cross-site scription, and denial of service (DOS) attacks.
Assigned vulnerabilities: CVE-2025-67724, CVE-2025-67725, and CVE-2025-67726.
Update by following the tornado installation page.
Two security vulnerabilities were fixed that could allow for partial recovery of CBC-PKCS7-encrypted plaintext and private key material disclosure.
Assigned vulnerabilities: CVE-2025-54764 and CVE-2025-59438.
Update by following the Mbed-TLS installation page.
Two security vulnerabilities were fixed that could allow for exploitation of APIs via multiple network protocols, leading to creation, modification, and deletion of data. This is especially an issue with Minecraft servers, as an affected JDK version will have elevated privileges because of calls to mods/modpacks. These vulnerabilities affect other major JDK versions. If you have multiple OpenJDK versions built, update all of them if there is an update present.
Assigned vulnerabilities: CVE-2025-53057 and CVE-2025-53066.
Update by following the OpenJDK installation page.