Slackware 1268 Published by Philipp Esselbach 0

Slackware users on version 15.0 or the current branch should install new libxml2 packages to address several critical security vulnerabilities immediately. These updates specifically fix type confusion in c14n processing along with dangerous memory errors found within the Python bindings. Administrators can retrieve the updated packages from the OSU Open Source Lab or check other mirrors near you. Just run the upgrade command as root to apply the changes correctly.

libxml2 (SSA:2026-106-01)

Slackware 1268 Published by Philipp Esselbach 0

Slackware Linux has released urgent security updates for both xorg-server and libexif packages across their 15.0 and current branches. The xorg-server rebuild targets several critical flaws including integer underflows, buffer overflows, and use-after-free vulnerabilities within various subsystems. Meanwhile users of the libexif library need to install a new version that resolves unsigned integer issues specifically found in camera makernote handling code. Administrators must run standard upgrade commands with root privileges to install the corrected files from the official FTP mirrors immediately.

xorg-server (SSA:2026-104-02)
libexif (SSA:2026-104-01)

Slackware 1268 Published by Philipp Esselbach 0

Slackware users need to update libarchive to version 3.8.7 because new security packages have just arrived for the 15.0 release and current branch. The release addresses critical vulnerabilities like heap buffer overflows on 32-bit systems found within the CAB and iso9660 modules. You can grab the updated files from the OSU Open Source Lab or find additional mirrors near you via the main website. Simply run upgradepkg as root after downloading to ensure your system remains secure against potential exploits.

libarchive (SSA:2026-103-01)

Slackware 1268 Published by Philipp Esselbach 0

New OpenSSL packages for Slackware 15.0 and -current fix critical security issues. Security flaws include potential use-after-free errors in DANE client code plus NULL pointer dereferences during CMS processing. Ken Zalewski prepared the patch by backporting from the OpenSSL-3.0 repo because the fixes were originally part of a premium release only available to subscribers.

openssl (SSA:2026-101-01)

Slackware 1268 Published by Philipp Esselbach 0

Slackware users running version 15.0 or the current branch should upgrade libpng to fix a medium severity security vulnerability. This update addresses use-after-free errors within specific functions that could potentially lead to corrupted chunk data and heap information disclosure. Additional hardening was applied to append-style setters to protect against theoretical variants of this same aliasing pattern during the patch process. You can download the corrected packages from the official FTP site or find additional mirrors near you on the main website before installing them as root.

libpng (SSA:2026-099-01)

Slackware 1268 Published by Philipp Esselbach 0

The Slackware Linux Security Team released new packages to patch security issues in Mozilla Thunderbird and Firefox. Users on Slackware 15.0 or the current development branch should upgrade to version 140.9.1esr to resolve these problems. Specific CVEs are listed in the advisory text for anyone needing more granular details about the flaws. Installation requires root access so you must run upgradepkg with the correct package file names from the FTP server.

mozilla-thunderbird (SSA:2026-098-02)
mozilla-firefox (SSA:2026-098-01)

Slackware 1268 Published by Philipp Esselbach 0

The Slackware Linux Security Team recently issued advisories regarding critical security updates for Krita and Infozip applications. Users running version 15.0 should install the new Krita package which resolves a heap-based buffer overflow vulnerability when parsing TGA files. A separate update for Infozip fixes Unicode string handling flaws that could lead to null pointer dereferences or out-of-bounds writes on current and stable branches.

krita (SSA:2026-093-02)
infozip (SSA:2026-093-01)

Slackware 1268 Published by Philipp Esselbach 0

Slackware Linux has released urgent security updates for the xz package to address critical flaws in versions 15.0 and -current. The developers fixed a buffer overflow inside lzma_index_append() alongside some memory access issues found when handling files. You can get the new packages from the FTP site or find mirrors on their web page if you prefer a closer server location. Just upgrade as root using upgradepkg when ready.

xz (SSA:2026-090-01)

Slackware 1268 Published by Philipp Esselbach 0

Slackware Linux has issued security advisories for bind and tigervnc packages targeting version 15.0 and -current systems. The bind package resolves an issue regarding unbounded NSEC3 iterations, whereas the TigerVNC upgrade specifically targets a flaw allowing other users to manipulate screen contents via x0vncserver. Administrators must download the new packages from the listed FTP sites and verify their signatures before executing the upgradepkg utility as root.

bind (SSA:2026-084-01)
tigervnc (SSA:2026-084-02)

Slackware 1268 Published by Philipp Esselbach 0

Slackware Linux has issued updated expat packages for version 15.0 and current branches specifically to address multiple significant security issues. These patches address critical vulnerabilities involving NULL pointers and potential infinite loops within the processing functions.

expat (SSA:2026-077-01)

Slackware 1268 Published by Philipp Esselbach 0

New packages are available for libxml2 and libarchive to fix security issues on Slackware 15.0 and -current. The updates for libxml2 address several vulnerabilities, including memory leaks and infinite recursion, while the update for libarchive fixes bugs and security issues such as NULL pointer dereferences and potential memory leaks.

libxml2 (SSA:2026-070-02)
libarchive (SSA:2026-070-01)

Slackware 1268 Published by Philipp Esselbach 0

New packages for nvi have been released to fix a security issue affecting Slackware 15.0 and -current. The update includes fixes for wide-character support, heap-based buffer overflows in regex handling, and other improvements. The patches were contributed by r1w1s1 and merged from Debian, and can be downloaded from various mirror sites or the OSU Open Source Lab's FTP server. To install the updates, users should run "upgradepkg" as root with the relevant package name.

nvi (SSA:2026-063-01)

Slackware 1268 Published by Philipp Esselbach 0

New packages for python3 are available to fix security issues on Slackware 15.0 and -current. The updates include a new version of python3, with the 3.9.25-i586-1_slack15.0 package being upgraded to address bugs and security issues.

python3 (SSA:2026-062-01)

Slackware 1268 Published by Philipp Esselbach 0

Two security updates have been released for Slackware Linux. The first update fixes a vulnerability in the telnet package (SSA:2026-059-02), which can be exploited by an unauthenticated remote attacker to execute arbitrary code on the server running telnetd. This should only be used on isolated networks where security is not a concern. The second update addresses two security issues in the gvfs package (SSA:2026-059-01). These vulnerabilities have been patched, and users are advised to upgrade their packages as soon as possible.

telnet (SSA:2026-059-02)
gvfs (SSA:2026-059-01)

Slackware 1268 Published by Philipp Esselbach 0

Mozilla Firefox and Thunderbird packages have been updated for Slackware 15.0 and -current to fix security issues, including a heap buffer overflow in libvpx. The new packages can be found on the official Slackware FTP servers or mirror sites near you, and the MD5 signatures are provided for verification. Additionally, a new lrzip package is available to address multiple potential security issues with crafted or corrupt archives. Users should upgrade the packages as root by running the "upgradepkg" command with the corresponding package name.

mozilla-firefox (SSA:2026-047-03)
mozilla-thunderbird (SSA:2026-047-04)
lrzip (SSA:2026-047-02)
libssh (SSA:2026-047-01)

Slackware 1268 Published by Philipp Esselbach 0

New security updates are available for OpenSSL and p11-kit on Slackware 15.0. The OpenSSL update fixes several vulnerabilities, including heap out-of-bounds write, unauthenticated/unencrypted trailing bytes, and null pointer dereference issues. The p11-kit update addresses a single security issue: a NULL dereference via C_DeriveKey with specific NULL parameters. This vulnerability has been fixed in the latest version of p11-kit, which is now available for Slackware 15.0 and -current.

openssl (SSA:2026-037-02)
p11-kit (SSA:2026-037-01)