SLFS Advisories

Introduction

This page covers advisories, notably in relation with security and changes that may have broke or changed how things are done in earlier versions of the book.

In some cases, not every security vulnerability for an advisory will be available. Either upstream does not issue an ID with security authority, like a CVE, or they don't wish to talk about the vulnerability in detail. What's listed is all that can be gathered from upstream and GitHub/Mitre/NVD.

This page was generated from an XML file with XSLT processing. You can easily track updates and view the XML by viewing the advisories GitHub repository.

This page is ordered like the Changelog of the book, with newest items first.

13.1

Security Advisories

slfs-sec-13.1-001: OpenJDK-17.0.20.1-ga - Rating: High (Date: September 2nd, 2026)

Seventeen security vulnerabilities were fixed that could allow for exploitation in the JAXP, networking, JSSE, JGSS, 2D (FreeType, Little-CMS 2, and general), libraries, security, and ImageIO component APIs. A large number of the vulnerabilities are remotely exploitable, without any authentication required.

Assigned vulnerabilities: CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-23865, CVE-2026-34282, CVE-2026-34628, CVE-2026-41254, CVE-2026-46917, CVE-2026-46968, CVE-2026-47010, CVE-2026-47021, CVE-2026-47027, CVE-2026-47059, CVE-2026-47063, and CVE-2026-60147.

Update by following the OpenJDK installation page.


13.0

Breaking Changes

slfs-brk-13.0-001: Wayfire, wlroots, and dependencies (Date: August 24th, 2026)

LXQt-Wayland-Session can utilize multiple Wayland compositors. The most simple one to use is Wayfire. Since LXQT-Wayland-Session is in BLFS, Wayfire was moved to BLFS. As a result, its dependencies like wlroots were also moved to BLFS as a consequence. The following have been moved: nlohmann-json, yyjson, xcb-util-errors (XCB Utilities), libliftoff, seatd, wlroots, xdg-desktop-portal-wlr, Wayfire, and wayfire-plugins-extra.

Read BLFS to follow updates for the moved packages.

Security Advisories

slfs-sec-13.0-025: htop-3.5.3 - Rating: High (Date: August 25th, 2026)

Three security vulnerabilities were fixed that could allow for segmentation faults, improper Clang MSan sanitization, and out-of-bounds access.

Assigned vulnerabilities: CVE-2024-37676.

Update by following the htop installation page.

slfs-sec-13.0-024: tornado-6.5.8 - Rating: High (Date: August 25th, 2026)

Three security vulnerabilities were fixed that could allow for denial of service (DOS), excessive memory consumption, and invalid characters not being restricted.

Assigned vulnerabilities: GHSA-wwv5-g3v4-889x, GHSA-mpf4-983q-p7j4, and GHSA-8423-8fgw-73vq.

Update by following the tornado installation page.

slfs-sec-13.0-023: OSTree-2026.3 - Rating: Medium (Date: August 25th, 2026)

Two security vulnerabilities were fixed that could allow for denial of service (DOS) and heap buffer overflows. These require the attacker to control the content served by the repository.

Assigned vulnerabilities: GHSA-7cgc-gp99-6jmm and GHSA-xppc-j946-vcj7.

Update by following the OSTree installation page.

slfs-sec-13.0-022: Flatpak-1.18.1 - Rating: Critcal (Date: August 25th, 2026)

Ten security vulnerabilities were fixed that could allow for full sandbox escapes, local root privilege escalations, arbitrary root writing, arbitrary host file reading, path traversal, buffer overflows, fixed-filename writing to arbitrary locations, extension metadata path traversal, host filesystem probing, unintended mount locations, anti-downgrade bypassing, and downgrading system apps by unprivileged users.

Assigned vulnerabilities: GHSA-8688-9x26-hhxj, GHSA-qrwq-7qwx-q9rp, GHSA-fqx6-vh4p-42cg, GHSA-8qxj-x646-phcm, GHSA-9rww-v4mm-x4jg, GHSA-v2gw-v9h5-9q4x, GHSA-jr92-2v97-wgvc, GHSA-99wv-m8rp-g58x, GHSA-w69g-9x8j-7p8f, and GHSA-q4gr-vc25-57m5.

Update immediately by following the Flatpak installation page.

slfs-sec-13.0-021: NGINX-1.31.3 - Rating: Critcal (Date: August 25th, 2026)

Three security vulnerabilities were fixed that could allow for buffer overflows, memory disclosure, and use-after-free operations. The ngx_http_slice_module and ngx_http_ssi_module modules are affected. Without ALSR enabled, these vulnerabilities allow denial of service (DOS) attacks and remote + arbitrary code execution (RCE and ACE) on systems hosting NGINX instances.

Assigned vulnerabilities: CVE-2026-42533, CVE-2026-56434, and CVE-2026-60005.

Update immediately by following the NGINX installation page.

slfs-sec-13.0-020: Go-1.26.6 - Rating: Critical (Date: August 25th, 2026)

Nine security vulnerabilities were fixed that could allow for privilege escalation when using the idna package, buffer overflow, denial of service (DOS), unlimited allocation of resources, arbitrary content injection, cross-site scripting (XSS), stack exhaustion, increased memory allocations, infinite operations, undetectable malicious module content, and GOSUMDB check bypassing.

Assigned vulnerabilities: CVE-2026-39821, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862, CVE-2026-56864, and CVE-2026-56865.

Update immediately by following the Go installation page, and reinstall everything that was built with or against the package.

slfs-sec-13.0-019: yt-dlp-2026.07.04 - Rating: High (Date: August 25th, 2026)

A security vulnerability was fixed that could allow for command injection via improper sanitization of output when using the --write-link option.

Assigned vulnerabilities: CVE-2026-55404.

If you use the --write-link option, or use scripts that do use the --write-link option, it is recommended to update by following the yt-dlp installation page.

slfs-sec-13.0-018: socat-1.8.1.3 - Rating: Critical (Date: August 25th, 2026)

A security vulnerability was fixed that could allow for a heap-based buffer overflow in a SOCKS5 proxy server, leading to heap memory overwriting. This is controlled by the attacker, with the size and content being able to be fine-tuned for an attack. No authentication is required. Arbitrary code execution (ACE) can be a result of this attack.

Assigned vulnerabilities: CVE-2026-56123.

VulnCheck gave the vulnerability with an 8.1/10, while NVD gave a 9.8/10. Regardless, update immediately by following the socat installation page.

slfs-sec-13.0-017: NGINX-1.31.2 - Rating: Critical (Date: August 25th, 2026)

Three security vulnerabilities were fixed that could allow for use-after-free operations, buffer overflows, and buffer overreads. The ngx_http_v3_module, ngx_http_proxy_v2_module, ngx_http_grpc_module, and ngx_http_charset_module modules are affected. Without ALSR enabled, these vulnerabilities allow remote and arbitrary code execution (RCE and ACE) on systems hosting NGINX instances.

Assigned vulnerabilities: CVE-2026-42055, CVE-2026-42530, and CVE-2026-48142.

Update immediately by following the NGINX installation page.

slfs-sec-13.0-016: Go-1.26.4 - Rating: High (Date: August 25th, 2026)

Three security vulnerabilities were fixed that could allow for excessive CPU consumption and injection of misleading content to errors.

Assigned vulnerabilities: CVE-2026-42504 and CVE-2026-42507.

Update by following the Go installation page, and reinstall everything that was built with or against the package.

slfs-sec-13.0-015: tornado-6.5.7 - Rating: High (Date: July 14th, 2026)

Six security vulnerabilities were fixed that could allow for auth and cookie headers being part of the request when following redirects to different origins, denial of service (DOS) attacks, out-of-bounds read operations, improper reponse parsing, credential reuse, and unlimited memory consumption.

Assigned vulnerabilities: GHSA-3x9g-8vmp-wqvf, GHSA-mgf9-4vpg-hj56, GHSA-cx3h-4qpv-8hc9, and GHSA-pw6j-qg29-8w7f.

Update by following the tornado installation page.

slfs-sec-13.0-014: Capstone-5.0.9 - Rating: Medium (Date: July 14th, 2026)

Three security vulnerabilities were fixed that could allow for out-of-bounds read operations, denial of service (DOS) attacks, no-progression disassembly, parser desynchronization, and NULL pointer dereferences.

Assigned vulnerabilities: GHSA-289w-cm54-fgrm, GHSA-5m9f-vqcm-g5pr, and GHSA-jrw4-wj52-2vw8.

Update by following the Capstone installation page.

slfs-sec-13.0-013: Go-1.26.3 - Rating: High (Date: June 1st, 2026)

Eleven security vulnerabilities were fixed that could allow for checksum bypassing, query forwarding to unexpected locations, denial of service (DOS) conditions, symlink overwriting, extraction of files to arbitrary locations, and cross-site scripting. These affect multiple components.

Assigned vulnerabilities: CVE-2026-33811, CVE-2026-33814, CVE-2026-39817, CVE-2026-39819, CVE-2026-39820, CVE-2026-39823, CVE-2026-39825, CVE-2026-39826, CVE-2026-39836, CVE-2026-42499, and CVE-2026-42501.

Update by following the Go installation page, and reinstall everything that was built with or against the package.

slfs-sec-13.0-012: NGINX-1.31.1 - Rating: Critical (Date: May 29th, 2026)

Seven security vulnerabilities were fixed that could allow for buffer overflows, overreads, HTTP/3 address spoofing, use-after-free operations, and HTTP/2 request injections. The ngx_http_charset_module, ngx_http_rewrite_module, ngx_http_scgi_module, and ngx_http_uwsgi_module modules are affected. The OCSP (Online Certificate Status Protocol) resolver is also affected.

Remote code execution alongside arbitrary code execution (RCE and ACE) are possible via these vulnerabilities, but requires ALSR must be disabled on systems hosting the NGINX instance(s). The attacker must be in a circumstance to be able to bypass ALSR in order to achieve ACE/RCE. Enabling ALSR can fix this, alongside updating the package.

Assigned vulnerabilities: CVE-2026-9256, CVE-2026-40460, CVE-2026-40701, CVE-2026-42926, CVE-2026-42934, CVE-2026-42945, and CVE-2026-42946.

Update immediately by following the NGINX installation page.

slfs-sec-13.0-011: pycurl-7.46.0 - Rating: High (Date: May 9th, 2026)

Five security vulnerabilities were fixed that could allow for memory and lock leakage, use-after-free operations, and long overflows.

There are no IDs with security authority.

Update by following the pycurl installation page.

slfs-sec-13.0-010: asio-1-38-0 - Rating: High (Date: April 19th, 2026)

Two security vulnerabilities were fixed that could allow for denial of service (DOS) attacks via memory and resource leakage.

There are no IDs with security authority.

Update by following the asio installation page. Every package that uses the package must be reinstalled since the package is header-only.

Updated on April 30th, 2026. Reason: (corrected the link to the asio page).

slfs-sec-13.0-009: Mbed-TLS-3.6.6 - Rating: Critical (Date: April 8th, 2026)

Eleven security vulnerabilities were fixed that could allow for client impersonation, entropy fallback to /dev/urandom, PSA random generator cloning, compiler-induced constant-time violations, arbitrary code execution (ACE), memory corruption, signature algorithm injection, out-of-bounds read operations, information disclosure, insufficient protection of serialized session/context data, and a buffer underread operation.

Assigned vulnerabilities: CVE-2026-25833, CVE-2026-25834, CVE-2026-25835, CVE-2026-34871, CVE-2026-34872, CVE-2026-34873, CVE-2026-34874, CVE-2026-34875, CVE-2026-34876, CVE-2026-34877, and CVE-2025-66442.

Update immediately by following the Mbed-TLS installation page.

slfs-sec-13.0-008: libdatachannel-0.24.2 - Rating: Medium (Date: April 8th, 2026)

A security vulnerability was fixed that could allow for denial of service (DOS) and potential arbitrary code execution (ACE) when processing RTP and RTCP packets. These issues were caused by a lack of size checks on untrusted input.

There are no IDs with security authority.

Update by following the libdatachannel installation page. Only OBS-Studio uses this package in SLFS and BLFS.

slfs-sec-13.0-007: Go-1.26.2 - Rating: Critical (Date: April 8th, 2026)

Ten security vulnerabilities were fixed that could allow for the unconditional symlink following, incorrect tracking of JavaScript template literal contexts, improper applying of excluded DNS constraints in certificates to wildcard domains, bypassing of overlap checking for no-op interface conversions, possible memory corription, unbounded allocation, connection deadlocks, trust layer bypassing, and denial of service (DOS). Multiple Go components are affected.

Assigned vulnerabilities: CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-2026-32281, CVE-2026-32282, CVE-2026-32283, CVE-2026-32288, CVE-2026-32289, and CVE-2026-33810.

Update immediately by following the Go installation page, and reinstall everything that was built with or against the package.

Updated on April 18th, 2026. Reason: (Rating: High -> Critical).

slfs-sec-13.0-006: Flatpak-1.16.5 - Rating: Critical (Date: April 8th, 2026)

Four security vulnerabilities were fixed that could allow for a complete and total sandbox escape, arbitrary file deletion on the host filesystem, arbitrary read access to files in the system-helper context, and orphaning cross-user pull operations. The arbitrary file deletion vulnerability has no restrictions and any app can exploit it or be exploited to do it.

There are no IDs with security authority.

To protect your data, it is highly recommended to update immediately by following the Flatpak installation page.

After updating the package, update to xdg-dbus-proxy-0.1.7 and xdg-desktop-portal-1.20.4 from BLFS to fix security vulnerabilities that allow for arbitrary file deletion and application eavesdropping upon D-Bus activity.

Updated on April 15th, 2026. Reason: (included information regarding updating xdg-desktop-portal and xdg-dbus-proxy).

slfs-sec-13.0-005: NGINX-1.29.8 - Rating: Medium (Date: April 8th, 2026)

A security vulnerability was fixed that could allow for an integer underflow while processing character sets when using the ngx_http_upstream_copy_content_type() function. This is considered as an out-of-bounds memory access vulnerability and can lead to a denial of service (DOS) or information disclosure.

There are no IDs with security authority.

Update by following the NGINX installation page.

slfs-sec-13.0-004: NGINX-1.29.7 - Rating: High (Date: April 7th, 2026)

Six security vulnerabilities were fixed that could allow for buffer overflows, NULL pointer dereferences, arbitrary header injection, and OCSP (Online Certificate Status Protocol) result bypassing in the ngx_http_dav_module and ngx_http_mp4_module modules, while using CRAM-MD5 or APOP, and within auth_http, stream, and XCLIENT.

Assigned vulnerabilities: CVE-2026-27651, CVE-2026-27654, CVE-2026-27784, CVE-2026-28753, CVE-2026-28755, and CVE-2026-32647.

Update by following the NGINX installation page.

slfs-sec-13.0-003: Capstone-5.0.7 - Rating: Critical (Date: April 7th, 2026)

Two security vulnerabilities were fixed that could allow for a heap buffer overflow and stack buffer overflow and underflow.

Assigned vulnerabilities: CVE-2025-67873 and CVE-2025-68114.

Update immediately by following the Capstone installation page.

slfs-sec-13.0-002: OBS-Studio-32.1.0 - Rating: High (Date: April 7th, 2026)

General security was improved for configurations using browser sources which use local files.

There are no IDs with security authority.

If you use browser sources using local files, update by following the OBS-Studio installation page.

slfs-sec-13.0-001: tornado-6.5.5 - Rating: High (Date: March 21st, 2026)

Two security vulnerabilities were fixed that could allow for a denial of service (DOS) attack and incomplete validation of cookie attributes.

Assigned vulnerabilities: GHSA-qjxf-f2mg-c6mc and GHSA-78cv-mqj4-43f7.

Update by following the tornado installation page.


12.4

Breaking Changes

slfs-brk-12.4-003: GNAT/GCC-Ada (Date: January 17th, 2026)

This package, which contains all Ada support in the book, has been removed. BLFS nor GLFS provide a replacement. None of the books need or really benefit from Ada, and its installation, with conflicts with BLFS, was unsafe to install as it could break the toolchain.

slfs-brk-12.4-002: nv-codec-headers (ffnvcodec) and CUDA (Date: November 24th, 2025)

These packages have been moved to GLFS to coincide with the NVIDIA driver installation.

You can track updates via the GLFS Graphics Drivers - NVIDIA page.

slfs-brk-12.4-001: SDL3 (Date: November 18th, 2025)

The book no longer provides SDL3 nor sdl2-compat as BLFS has now took them in. It started off as a showcase of what the instructions could look like, to becoming necessary in the dependency chain for the book. BLFS decided that it's time to bring the two packages in, so the book links to the pages from BLFS. GLFS has done the same as BLFS.

Security Advisories

slfs-sec-12.4-007: yt-dlp-2026.02.21 - Rating: High (Date: February 24th, 2026)

A security vulnerability was fixed that could allow for code injection via a crafted link using the --netrc-cmd option. This works by pushing special characters to the shell outside of Python, like Bash or Zsh, which in turn allows for ACI.

There are no IDs with security authority.

If you use the --netrc-cmd option, or use scripts that do use the --netrc-cmd option, it is highly recommended to update immediately by following the yt-dlp installation page.

slfs-sec-12.4-006: OpenJDK-17.0.18 - Rating: High (Date: January 28th, 2026)

Four security vulnerabilities were fixed that could allow for denial of service (DOS) attacks and modification of data, both critical and Java data. These attacks require network access and for the attacker to go through mutliple protocols, but don't require human interaction. Some of the vulnerabilities are easy to exploit, while the others are more difficult. These vulnerabilities are actively exploited in the wild, like with Minecraft servers.

There are no IDs with security authority.

It is highly recommended to update immediately by following the OpenJDK installation page.

slfs-sec-12.4-005: CDE-2.5.3 - Rating: High (Date: January 7th, 2026)

There were numerous other improvements, but there were also multiple memory safety issues that were fixed.

There are no IDs with security authority.

The sensitive nature of these bugs results in heavy recommendation to update by following the CDE installation page.

slfs-sec-12.4-004: i3-4.25 - Rating: High (Date: December 30th, 2025)

There were general code improvements, along with a memory leak and use-after-free fix.

There are no IDs with security authority.

Update by following the i3 installation page.

slfs-sec-12.4-003: tornado-6.5.3 - Rating: High (Date: December 15th, 2025)

Three security vulnerabilities were fixed that could allow for header injection, cross-site scription, and denial of service (DOS) attacks.

Assigned vulnerabilities: CVE-2025-67724, CVE-2025-67725, and CVE-2025-67726.

Update by following the tornado installation page.

slfs-sec-12.4-002: Mbed-TLS-3.6.5 - Rating: Medium (Date: December 15th, 2025)

Two security vulnerabilities were fixed that could allow for partial recovery of CBC-PKCS7-encrypted plaintext and private key material disclosure.

Assigned vulnerabilities: CVE-2025-54764 and CVE-2025-59438.

Update by following the Mbed-TLS installation page.

slfs-sec-12.4-001: OpenJDK-17.0.17-ga - Rating: High (Date: October 23rd, 2025)

Two security vulnerabilities were fixed that could allow for exploitation of APIs via multiple network protocols, leading to creation, modification, and deletion of data. This is especially an issue with Minecraft servers, as an affected JDK version will have elevated privileges because of calls to mods/modpacks. These vulnerabilities affect other major JDK versions. If you have multiple OpenJDK versions built, update all of them if there is an update present.

Assigned vulnerabilities: CVE-2025-53057 and CVE-2025-53066.

Update by following the OpenJDK installation page.