Gentoo 2533 Published by

Gentoo Linux released seven high-severity security advisories in mid-August 2026 targeting widely used system utilities and network services. The vulnerabilities span critical attack vectors, including root privilege escalation in Bubblewrap and rsync, remote code execution in Dnsmasq and Exim, sandbox escape in Flatpak, and input device handling flaws in libinput. Apache HTTPD received the largest single patch addressing 41 tracked issues ranging from denial of service to remote code execution.

[ GLSA 202608-09 ] Bubblewrap: Root privilege escalation
[ GLSA 202608-08 ] libinput: Multiple Vulnerabilities
[ GLSA 202608-06 ] Flatpak: Multiple Vulnerabilities
[ GLSA 202608-07 ] Exim: Multiple Vulnerabilities
[ GLSA 202608-05 ] Apache HTTPD: Multiple Vulnerabilities
[ GLSA 202608-04 ] Dnsmasq: Multiple Vulnerabilities
[ GLSA 202608-03 ] rsync: Multiple Vulnerabilities




[ GLSA 202608-09 ] Bubblewrap: Root privilege escalation


- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202608-09
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: High
Title: Bubblewrap: Root privilege escalation
Date: August 14, 2026
Bugs: #973131
ID: 202608-09

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A vulnerability has been discovered in Bubblewrap that would allow root
privilege escalation.

Background
==========

Bubblewrap is an unprivileged sandboxing tool namespaces-powered chroot-
like solution.

Affected packages
=================

Package Vulnerable Unaffected
------------------- ------------ ------------
sys-apps/bubblewrap < 0.11.2 >= 0.11.2

Description
===========

A vulnerability has been discovered in Bubblewrap. Please review the CVE
identifier referenced below for details.

Impact
======

An attacker could achieve root privilege escalation if Bubblewrap is
used in its suid mode.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Bubblewrap users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=sys-apps/bubblewrap-0.11.2"

References
==========

[ 1 ] CVE-2026-41163
https://nvd.nist.gov/vuln/detail/CVE-2026-41163

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

https://security.gentoo.org/glsa/202608-09

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.



[ GLSA 202608-08 ] libinput: Multiple Vulnerabilities


- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202608-08
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: High
Title: libinput: Multiple Vulnerabilities
Date: August 14, 2026
Bugs: #971879, #976730
ID: 202608-08

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
=======
Multiple vulnerabilities have been found in libinput, the worst of which
could result in privilege escalation.

Background
=========
A library to handle input devices in Wayland and, via xf86-input-
libinput, in X.org.

Affected packages
================
Package Vulnerable Unaffected
----------------- ------------ ------------
dev-libs/libinput < 1.31.3 >= 1.31.3

Description
==========
Multiple vulnerabilities have been discovered in libinput. Please review
the CVE identifiers referenced below for details.

Impact
=====
Please review the referenced CVE identifiers for details.

Workaround
=========
There is no known workaround at this time.

Resolution
=========
All libinput users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">゙v-libs/libinput-1.31.3"

References
=========
[ 1 ] CVE-2026-35093
https://nvd.nist.gov/vuln/detail/CVE-2026-35093
[ 2 ] CVE-2026-35094
https://nvd.nist.gov/vuln/detail/CVE-2026-35094

Availability
===========
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

https://security.gentoo.org/glsa/202608-08

Concerns?
========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
======
Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.



[ GLSA 202608-06 ] Flatpak: Multiple Vulnerabilities


- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202608-06
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: High
Title: Flatpak: Multiple Vulnerabilities
Date: August 14, 2026
Bugs: #972414
ID: 202608-06

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in Flatpak, the worst of which
allows sandbox escape.

Background
==========

Flatpak is a Linux application sandboxing and distribution framework.

Affected packages
=================

Package Vulnerable Unaffected
---------------- ------------ ------------
sys-apps/flatpak < 1.16.4 >= 1.16.4

Description
===========

Multiple vulnerabilities have been discovered in Flatpak. Please review
the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Flatpak users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=sys-apps/flatpak-1.16.4"

References
==========

[ 1 ] CVE-2026-34078
https://nvd.nist.gov/vuln/detail/CVE-2026-34078
[ 2 ] CVE-2026-34079
https://nvd.nist.gov/vuln/detail/CVE-2026-34079

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

https://security.gentoo.org/glsa/202608-06

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.



[ GLSA 202608-07 ] Exim: Multiple Vulnerabilities


- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202608-07
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: High
Title: Exim: Multiple Vulnerabilities
Date: August 14, 2026
Bugs: #938214, #952139, #974785
ID: 202608-07

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in Exim, the worst of which
allows arbitrary code execution.

Background
==========

Exim is a message transfer agent (MTA) designed to be a a highly
configurable, drop-in replacement for sendmail.

Affected packages
=================

Package Vulnerable Unaffected
------------- ------------ ------------
mail-mta/exim < 4.99.4 >= 4.99.4

Description
===========

Multiple vulnerabilities have been discovered in Exim. Please review the
CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Exim users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=mail-mta/exim-4.99.4"

References
==========

[ 1 ] CVE-2024-39929
https://nvd.nist.gov/vuln/detail/CVE-2024-39929
[ 2 ] CVE-2025-30232
https://nvd.nist.gov/vuln/detail/CVE-2025-30232
[ 3 ] CVE-2026-40684
https://nvd.nist.gov/vuln/detail/CVE-2026-40684
[ 4 ] CVE-2026-40685
https://nvd.nist.gov/vuln/detail/CVE-2026-40685
[ 5 ] CVE-2026-40686
https://nvd.nist.gov/vuln/detail/CVE-2026-40686
[ 6 ] CVE-2026-40687
https://nvd.nist.gov/vuln/detail/CVE-2026-40687
[ 7 ] CVE-2026-45185
https://nvd.nist.gov/vuln/detail/CVE-2026-45185

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

https://security.gentoo.org/glsa/202608-07

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.



[ GLSA 202608-05 ] Apache HTTPD: Multiple Vulnerabilities


- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202608-05
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: High
Title: Apache HTTPD: Multiple Vulnerabilities
Date: August 13, 2026
Bugs: #915996, #959821, #967089, #973625, #977098
ID: 202608-05

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in Apache HTTPD, the worst of
which could result in remote code execution.

Background
==========

The Apache HTTP server is one of the most popular web servers on the
Internet.

Affected packages
=================

Package Vulnerable Unaffected
------------------ ------------ ------------
www-servers/apache < 2.4.68 >= 2.4.68

Description
===========

Multiple vulnerabilities have been discovered in Apache HTTPD. Please
review the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Apache HTTPD users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-servers/apache-2.4.68"

References
==========

[ 1 ] CVE-2023-31122
https://nvd.nist.gov/vuln/detail/CVE-2023-31122
[ 2 ] CVE-2023-43622
https://nvd.nist.gov/vuln/detail/CVE-2023-43622
[ 3 ] CVE-2023-44487
https://nvd.nist.gov/vuln/detail/CVE-2023-44487
[ 4 ] CVE-2023-45802
https://nvd.nist.gov/vuln/detail/CVE-2023-45802
[ 5 ] CVE-2024-42516
https://nvd.nist.gov/vuln/detail/CVE-2024-42516
[ 6 ] CVE-2024-43204
https://nvd.nist.gov/vuln/detail/CVE-2024-43204
[ 7 ] CVE-2024-43394
https://nvd.nist.gov/vuln/detail/CVE-2024-43394
[ 8 ] CVE-2024-47252
https://nvd.nist.gov/vuln/detail/CVE-2024-47252
[ 9 ] CVE-2025-23048
https://nvd.nist.gov/vuln/detail/CVE-2025-23048
[ 10 ] CVE-2025-49630
https://nvd.nist.gov/vuln/detail/CVE-2025-49630
[ 11 ] CVE-2025-49812
https://nvd.nist.gov/vuln/detail/CVE-2025-49812
[ 12 ] CVE-2025-53020
https://nvd.nist.gov/vuln/detail/CVE-2025-53020
[ 13 ] CVE-2025-55753
https://nvd.nist.gov/vuln/detail/CVE-2025-55753
[ 14 ] CVE-2025-58098
https://nvd.nist.gov/vuln/detail/CVE-2025-58098
[ 15 ] CVE-2025-59775
https://nvd.nist.gov/vuln/detail/CVE-2025-59775
[ 16 ] CVE-2025-65082
https://nvd.nist.gov/vuln/detail/CVE-2025-65082
[ 17 ] CVE-2025-66200
https://nvd.nist.gov/vuln/detail/CVE-2025-66200
[ 18 ] CVE-2026-23918
https://nvd.nist.gov/vuln/detail/CVE-2026-23918
[ 19 ] CVE-2026-24072
https://nvd.nist.gov/vuln/detail/CVE-2026-24072
[ 20 ] CVE-2026-28780
https://nvd.nist.gov/vuln/detail/CVE-2026-28780
[ 21 ] CVE-2026-29167
https://nvd.nist.gov/vuln/detail/CVE-2026-29167
[ 22 ] CVE-2026-29168
https://nvd.nist.gov/vuln/detail/CVE-2026-29168
[ 23 ] CVE-2026-29169
https://nvd.nist.gov/vuln/detail/CVE-2026-29169
[ 24 ] CVE-2026-29170
https://nvd.nist.gov/vuln/detail/CVE-2026-29170
[ 25 ] CVE-2026-33006
https://nvd.nist.gov/vuln/detail/CVE-2026-33006
[ 26 ] CVE-2026-33007
https://nvd.nist.gov/vuln/detail/CVE-2026-33007
[ 27 ] CVE-2026-33523
https://nvd.nist.gov/vuln/detail/CVE-2026-33523
[ 28 ] CVE-2026-33857
https://nvd.nist.gov/vuln/detail/CVE-2026-33857
[ 29 ] CVE-2026-34032
https://nvd.nist.gov/vuln/detail/CVE-2026-34032
[ 30 ] CVE-2026-34059
https://nvd.nist.gov/vuln/detail/CVE-2026-34059
[ 31 ] CVE-2026-34355
https://nvd.nist.gov/vuln/detail/CVE-2026-34355
[ 32 ] CVE-2026-34356
https://nvd.nist.gov/vuln/detail/CVE-2026-34356
[ 33 ] CVE-2026-42535
https://nvd.nist.gov/vuln/detail/CVE-2026-42535
[ 34 ] CVE-2026-42536
https://nvd.nist.gov/vuln/detail/CVE-2026-42536
[ 35 ] CVE-2026-43951
https://nvd.nist.gov/vuln/detail/CVE-2026-43951
[ 36 ] CVE-2026-44119
https://nvd.nist.gov/vuln/detail/CVE-2026-44119
[ 37 ] CVE-2026-44185
https://nvd.nist.gov/vuln/detail/CVE-2026-44185
[ 38 ] CVE-2026-44186
https://nvd.nist.gov/vuln/detail/CVE-2026-44186
[ 39 ] CVE-2026-44631
https://nvd.nist.gov/vuln/detail/CVE-2026-44631
[ 40 ] CVE-2026-48913
https://nvd.nist.gov/vuln/detail/CVE-2026-48913
[ 41 ] CVE-2026-49975
https://nvd.nist.gov/vuln/detail/CVE-2026-49975

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

https://security.gentoo.org/glsa/202608-05

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.



[ GLSA 202608-04 ] Dnsmasq: Multiple Vulnerabilities


- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202608-04
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: High
Title: Dnsmasq: Multiple Vulnerabilities
Date: August 13, 2026
Bugs: #974690
ID: 202608-04

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in Dnsmasq, one of which
includes remote code execution.

Background
==========

Dnsmasq is a lightweight and easily-configurable DNS forwarder and DHCP
server.

Affected packages
=================

Package Vulnerable Unaffected
--------------- ------------ ------------
net-dns/dnsmasq < 2.92_p2 >= 2.92_p2

Description
===========

Multiple vulnerabilities have been discovered in Dnsmasq. Please review
the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Dnsmasq users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-dns/dnsmasq-2.92_p2"

References
==========

[ 1 ] CVE-2026-2291
https://nvd.nist.gov/vuln/detail/CVE-2026-2291
[ 2 ] CVE-2026-4890
https://nvd.nist.gov/vuln/detail/CVE-2026-4890
[ 3 ] CVE-2026-4891
https://nvd.nist.gov/vuln/detail/CVE-2026-4891
[ 4 ] CVE-2026-4892
https://nvd.nist.gov/vuln/detail/CVE-2026-4892
[ 5 ] CVE-2026-4893
https://nvd.nist.gov/vuln/detail/CVE-2026-4893
[ 6 ] CVE-2026-5172
https://nvd.nist.gov/vuln/detail/CVE-2026-5172

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

https://security.gentoo.org/glsa/202608-04

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.



[ GLSA 202608-03 ] rsync: Multiple Vulnerabilities


- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202608-03
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: High
Title: rsync: Multiple Vulnerabilities
Date: August 13, 2026
Bugs: #972779, #975525
ID: 202608-03

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in rsync, the worst of which
could result in privilege escalation.

Background
==========

rsync is a server and client utility that provides fast incremental file
transfers. It is used to efficiently synchronize files between hosts and
is used by emerge to fetch Gentoo's Portage tree.

Affected packages
=================

Package Vulnerable Unaffected
-------------- ------------ ------------
net-misc/rsync < 3.4.3 >= 3.4.3

Description
===========

Multiple vulnerabilities have been discovered in rsync. Please review
the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All rsync users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/rsync-3.4.3"

References
==========

[ 1 ] CVE-2026-29518
https://nvd.nist.gov/vuln/detail/CVE-2026-29518
[ 2 ] CVE-2026-41035
https://nvd.nist.gov/vuln/detail/CVE-2026-41035
[ 3 ] CVE-2026-43617
https://nvd.nist.gov/vuln/detail/CVE-2026-43617
[ 4 ] CVE-2026-43618
https://nvd.nist.gov/vuln/detail/CVE-2026-43618
[ 5 ] CVE-2026-43619
https://nvd.nist.gov/vuln/detail/CVE-2026-43619
[ 6 ] CVE-2026-43620
https://nvd.nist.gov/vuln/detail/CVE-2026-43620
[ 7 ] CVE-2026-45232
https://nvd.nist.gov/vuln/detail/CVE-2026-45232

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

https://security.gentoo.org/glsa/202608-03

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.