proftpd (SSA:2026-227-01)
The Slackware Linux Security Team released updated proftpd 1.3.9d packages for both Slackware 15.0 and -current to patch critical vulnerabilities. The update resolves a use-after-free flaw triggered by the FTP STAT command and corrects how the server handles default AllowForeignAddress settings during passive data transfers.
proftpd (SSA:2026-227-01)
proftpd (SSA:2026-227-01)
The Slackware Linux Security Team released package SSA:2026-225-01 to patch known vulnerabilities and resolve bugs in rsync 3.5.0. This update applies directly to both Slackware 15.0 and the ongoing -current branch. Users can download the official i586 and x86_64 builds from the standard Slackware FTP mirrors before installing them with the root upgradepkg command
rsync (SSA:2026-225-01)
rsync (SSA:2026-225-01)
The Slackware Linux Security Team released updated packages for Slackware 15.0 and -current to patch known vulnerabilities in the expat XML parser and OpenSSH. The expat refresh resolves CVE-2026-72522 by correcting an out-of-bounds read that causes an infinite loop when the parser processes low Unicode surrogates. The OpenSSH upgrade pushes the software to version 10.5p1, which ships with several security hardening patches and routine bug fixes. Users can download the new builds from the official Slackware FTP mirrors and apply them with the upgradepkg command before restarting the sshd daemon.
expat (SSA:2026-223-01)
openssh (SSA:2026-223-02)
expat (SSA:2026-223-01)
openssh (SSA:2026-223-02)
Slackware Linux released updated wpa_supplicant packages to resolve multiple security vulnerabilities affecting Wi-Fi authentication. The new version 2.12 builds ship for both Slackware 15.0 and the rolling -current branch across i586, i686, and x86_64 architectures.
wpa_supplicant (SSA:2026-220-01)
wpa_supplicant (SSA:2026-220-01)
The Slackware Linux Security Team issued new p11-kit and libXfont2 packages for Slackware 15.0 and -current under security advisory SSA:2026-218 to resolve critical vulnerabilities. The p11-kit upgrade to version 0.26.5 patches CVE-2026-18938 by preventing an overflow when the RPC layer decodes nested attributes. The libXfont2 release, version 2.0.9, addresses CVE-2026-59679 and CVE-2026-44950, which involve out-of-bounds read/write errors and a heap buffer overflow in Font Server Client glyph processing. Users should download the updated binaries for their architecture from the Slackware FTP servers and apply the changes using upgradepkg as root.
p11-kit (SSA:2026-218-02)
libXfont2 (SSA:2026-218-01)
p11-kit (SSA:2026-218-02)
libXfont2 (SSA:2026-218-01)
The Slackware Linux Security Team released stunnel version 5.80 for both Slackware 15.0 and the development branch to address two critical vulnerabilities. The first patch resolves an out-of-bounds memory access flaw that activates when logging attacker-controlled protocol messages exceeding 1,024 bytes. The second update closes a SOCKS server mode bypass that allowed attackers to route traffic through alternate local-address encodings and interface-scoped IPv6 destinations.
stunnel (SSA:2026-216-01)
stunnel (SSA:2026-216-01)
The Slackware Linux Security Team issued advisory SSA:2026-209 to patch security vulnerabilities in libarchive, Samba, and SeaMonkey for Slackware 15.0 and -current releases. Libarchive updates to version 3.8.9 to resolve security flaws and bug reports, while Samba advances to 4.22.11 on the stable branch and 4.24.5 on -current to fix defects like DNS crashes, LDAP domain takeovers, and CTDB bounds checking errors linked to CVE-2026-6949 through CVE-2026-58224. SeaMonkey gets version 2.53.24 with security fixes that address unspecified browser exploits.
libarchive (SSA:2026-209-01)
samba (SSA:2026-209-03)
seamonkey (SSA:2026-209-02)
libarchive (SSA:2026-209-01)
samba (SSA:2026-209-03)
seamonkey (SSA:2026-209-02)
Slackware released updated Mozilla Thunderbird packages for versions 15.0 and -current to address critical security vulnerabilities tracked under advisory SSA:2026-204-01. The upgrade bumps the email client to version 140.13 ESR, resolving issues documented in Mozilla Advisory MFSA2026-72 and spanning numerous CVE identifiers including CVE-2026-14899 through CVE-2026-16412. Users can install the fixed packages via upgradepkg as root, with downloads available for both i686 and x86_64 architectures on the official Slackware FTP mirrors hosted by the OSU Open Source Lab.
mozilla-thunderbird (SSA:2026-204-01)
mozilla-thunderbird (SSA:2026-204-01)
Slackware Linux released security updates for libssh and mozilla-firefox affecting versions 15.0 and -current to patch critical vulnerabilities identified in CVE-2026-15370 through CVE-2026-59849 alongside dozens of additional Firefox advisories. The libssh upgrade resolves a stack buffer overflow in SFTP server longname construction, denial of service flaws triggered by oversized read lengths and unchecked fork failures, an information disclosure via ProxyCommand username expansion, and an integrity downgrade linked to OpenSSL AES-GCM tag verification. Mozilla-Firefox receives version 140.13.0esr with security fixes and improvements based on upstream release notes, covering patches for numerous CVEs that address memory safety errors and privilege escalation risks across the browser engine.
libssh (SSA:2026-202-01)
mozilla-firefox (SSA:2026-202-02)
libssh (SSA:2026-202-01)
mozilla-firefox (SSA:2026-202-02)
The Slackware Linux Security Team released SSA:2026-197-01 to update the netatalk package to version 4.5.1 across Slackware 15.0 and the current development branch. This release patches four documented vulnerabilities identified as CVE-2026-62318 through CVE-2026-62321 alongside general code corrections.
netatalk (SSA:2026-197-01)
netatalk (SSA:2026-197-01)
The Slackware Linux Security Team released updated p11-kit packages for versions 15.0 and current to address CVE-2026-13757. This security patch resolves a stack exhaustion flaw caused by unbounded recursion during RPC attribute parsing. Administrators can download the corrected i586 and x86_64 builds directly from the official Slackware FTP server.
p11-kit (SSA:2026-191-01)
p11-kit (SSA:2026-191-01)
Slackware Linux Security Team released updated tigervnc packages for Slackware 15.0 and the -current branch to patch two critical vulnerabilities in the Xorg server components. The fixes address a heap buffer overflow in the glamor Font Atlas and a use-after-free error during CommonMakeCurrent operations.
tigervnc (SSA:2026-190-01)
tigervnc (SSA:2026-190-01)
Slackware Linux Security Team released new packages for Slackware 15.0 and -current to patch security vulnerabilities in proftpd, xorg-server, and libXfont2. The proftpd update resolves numerous flaws including stack buffer overflows in MLSD/MLST handling, SQL injection risks in group name lookups, and bypasses of transfer limits that compromise data integrity. Updates for xorg-server address heap buffer overflows in the glamor Font Atlas and a use-after-free error in GLX context tags, linked to CVE-2026-55999 and CVE-2026-56000. The libXfont2 upgrade mitigates three integer overflow and heap buffer overflow issues within bitmap scaling, PCF font parsing, and property computation functions, associated with CVE-2026-56001 through CVE-2026-56003.
proftpd (SSA:2026-189-02)
xorg-server (SSA:2026-189-03)
libXfont2 (SSA:2026-189-01)
proftpd (SSA:2026-189-02)
xorg-server (SSA:2026-189-03)
libXfont2 (SSA:2026-189-01)
The Slackware Linux Security Team released SSA:2026-188-01 to address multiple vulnerabilities in the tftp-hpa package. Version 5.4 resolves uninitialized buffer reads, broken path tokenizers, and several buffer overflow flaws that allowed crafted requests to bypass directory restrictions or crash the daemon.
tftp-hpa (SSA:2026-188-01)
tftp-hpa (SSA:2026-188-01)
The Slackware Linux Security Team released patched packages for openssh and c-ares to resolve critical flaws across Slackware 15.0 and -current distributions. The openssh update closes path traversal gaps in sftp and scp, fixes a silent argument truncation bug in sshd, and patches a client-side use-after-free error that triggers during host key reexchanges.
openssh (SSA:2026-187-02)
c-ares (SSA:2026-187-01)
openssh (SSA:2026-187-02)
c-ares (SSA:2026-187-01)
The Slackware Linux Security Team distributed updated packages for Slackware 15.0 to patch security flaws in php82 and mutt. The php82 version 8.2.32 update resolves CVE-2026-14355, a memory corruption bug in the zend_mm_heap triggered by openssl_encrypt calls using AES-WRAP-PAD. The mutt version 2.4.1 release eliminates an unsigned integer overflow in imap_cmd_step that allows a malicious IMAP server to shrink a buffer allocation and write data past the end of memory. Administrators need to run upgradepkg as root to apply these fixes, and they must restart the Apache httpd service to complete the php82 installation.
Slackware 15.0 php82 (SSA:2026-186-02)
mutt (SSA:2026-186-01)
Slackware 15.0 php82 (SSA:2026-186-02)
mutt (SSA:2026-186-01)
he Slackware Linux Security Team issued three new package updates to address active vulnerabilities in libevent, Mozilla Thunderbird, and libseccomp. Administrators running Slackware 15.0 or the -current branch can download the patched files for both i586 and x86_64 architectures from the official FTP mirror. The libseccomp update specifically repairs memory corruption and filter weakening bugs, while the other two releases contain broader security patches for affected system modules.
libevent (SSA:2026-182-01)
mozilla-thunderbird (SSA:2026-182-02)
libseccomp (SSA:2026-183-01)
libevent (SSA:2026-182-01)
mozilla-thunderbird (SSA:2026-182-02)
libseccomp (SSA:2026-183-01)
The Slackware Linux Security Team has released libarchive 3.8.8 to fix security issues across 15.0 and -current, so you'll want to grab it. Libarchive has been the silent workhorse behind so many compression tasks for years, and it handles quirky formats way better than most alternatives.
libarchive (SSA:2026-174-01)
libarchive (SSA:2026-174-01)
The Slackware Linux Security Team just rolled out a major security update that patches critical vulnerabilities across five essential packages for both Slackware 15.0 and current development branches. Mozilla Thunderbird and Firefox now ship with updated ESR builds that close dozens of memory safety flaws, while OpenSSL received carefully backported fixes for heap overreads and use-after-free errors. The remaining updates tackle a dangerous out-of-bounds read in libidn alongside a DNS64 response corruption bug that previously allowed corrupted data to reach clients. You can grab the verified packages from official FTP mirrors right now and apply them quickly using standard upgrade commands to keep your systems protected.
mozilla-thunderbird (SSA:2026-168-04)
mozilla-firefox (SSA:2026-168-03)
openssl (SSA:2026-168-05)
libidn (SSA:2026-168-02)
bind (SSA:2026-168-01)
mozilla-thunderbird (SSA:2026-168-04)
mozilla-firefox (SSA:2026-168-03)
openssl (SSA:2026-168-05)
libidn (SSA:2026-168-02)
bind (SSA:2026-168-01)
Slackware 15.0 has released a critical security update for its Samba package to address multiple high severity vulnerabilities. This new version patches dangerous flaws that could allow unauthenticated attackers to execute arbitrary code or bypass authentication mechanisms. Administrators should prioritize installing the upgrade immediately to protect their file sharing and directory services from potential compromise. You can download the updated packages directly from the official Slackware FTP server and apply them using the standard package upgrade command.
samba (SSA:2026-158-01)
samba (SSA:2026-158-01)