Skip to content

Cyberus Linux Security Tracker

This is the security tracker for Cyberus Linux. It allows monitoring the status of vulnerabilities that affect Cyberus Linux releases. Vulnerabilities are ingested from official sources, such as NVD and others.

For general information about installing or upgrading Cyberus Linux, refer to the documentation. We are eager to hear your feedback and suggestions for this security tracker. Channels to reach us are documented here.

Releases

These are the currently supported releases.

Latest Events

GHSA-m25x-3hj9-m26f
Cyberus Linux 26.05
util-linux
Failed external mount helper still triggers privileged X-mount post-hooks, enabling deterministic local privilege escalation
2026-09-04 15:32 CEST
Plausible

GHSA-rh77-686x-2f2m
Cyberus Linux 26.05
util-linux
Restricted bind mounts do not pin the source, allowing `X-mount.owner/group/mode` redirection
2026-09-04 15:32 CEST
Plausible

GHSA-8f2p-47x3-43mv
Cyberus Linux 26.05
util-linux
`X-mount.subdir` detached-tree resolution can escape via intermediate symlinks and procfs paths
2026-09-04 15:32 CEST
Plausible

GHSA-55fx-f4gg-cfhj
Cyberus Linux 26.05
util-linux
nsenter --join-cgroup leaks root cgroup migration authority
2026-09-04 15:32 CEST
Plausible

GHSA-4558-p62c-vv5v
Cyberus Linux 26.05
util-linux
BannerEscape: escape sequence injection in wall(1)/write(1) message headers via hostname
2026-09-04 15:32 CEST
Plausible

GHSA-7hjx-392p-f8cm
Cyberus Linux 26.05
imagemagick
Policy Bypass in UHDR encoder
2026-09-04 15:17 CEST
New → Plausible

GHSA-4gg2-hfgh-6f5c
Cyberus Linux 26.05
imagemagick
Division by Zero in FLIF encoder
2026-09-04 15:17 CEST
New → Plausible

GHSA-92rw-c5mw-27v4
Cyberus Linux 26.05
imagemagick
Null Pointer Dereference in PNM coder when hitting a memory limit
2026-09-04 15:17 CEST
New → Plausible

GHSA-89wq-f8f6-2j2v
Cyberus Linux 26.05
imagemagick
Policy Bypass in PCD, CUBE and HALD decoder when using a specific command line option.
2026-09-04 15:17 CEST
New → Plausible

GHSA-3rjr-534c-8v67
Cyberus Linux 26.05
imagemagick
Use after free in ImagesToBlob method
2026-09-04 15:17 CEST
New → Plausible

GHSA-7hjx-392p-f8cm
Cyberus Linux 26.05
imagemagick
Policy Bypass in UHDR encoder
2026-09-04 15:16 CEST
New

GHSA-4gg2-hfgh-6f5c
Cyberus Linux 26.05
imagemagick
Division by Zero in FLIF encoder
2026-09-04 15:16 CEST
New

GHSA-92rw-c5mw-27v4
Cyberus Linux 26.05
imagemagick
Null Pointer Dereference in PNM coder when hitting a memory limit
2026-09-04 15:16 CEST
New

GHSA-89wq-f8f6-2j2v
Cyberus Linux 26.05
imagemagick
Policy Bypass in PCD, CUBE and HALD decoder when using a specific command line option.
2026-09-04 15:16 CEST
New

GHSA-3rjr-534c-8v67
Cyberus Linux 26.05
imagemagick
Use after free in ImagesToBlob method
2026-09-04 15:16 CEST
New

CVE-2026-59843
Cyberus Linux 26.05
libssh
Libssh: libssh: denial of service via zero advertised channel packet size
2026-09-03 23:09 CEST
In Progress → Resolved

CVE-2026-15588
Cyberus Linux 26.05
glib
Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering
2026-09-03 23:09 CEST
In Progress → Resolved

CVE-2026-50593
Cyberus Linux 26.05
graphite2
Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.
2026-09-03 23:09 CEST
In Progress → Resolved

CVE-2026-12912
Cyberus Linux 26.05
libtiff
Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image
2026-09-03 23:08 CEST
In Progress → Resolved

CVE-2026-4775
Cyberus Linux 26.05
libtiff
Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing
2026-09-03 23:08 CEST
In Progress → Resolved

CVE-2026-59679
Cyberus Linux 26.05
libxfont_2
Font Server Client encoding Out-Of-Bounds Read/Write
2026-09-03 23:08 CEST
In Progress → Resolved

CVE-2026-44950
Cyberus Linux 26.05
libxfont_2
Font Server Client Cumulative Glyph Data Heap Buffer Overflow
2026-09-03 23:08 CEST
In Progress → Resolved

GHSA-ghq2-5c67-fprm
Cyberus Linux 26.05
pdm
Project-Local State and Config Writes Follow Symlinks
2026-09-03 23:08 CEST
In Progress → Resolved

GHSA-qq6c-99pv-prvf
Cyberus Linux 26.05
pdm
Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing
2026-09-03 23:07 CEST
In Progress → Resolved

GHSA-78v8-vpjp-cjqh
Cyberus Linux 26.05
pdm
Path traversal in wheel installation via overridden write_to_fs (CWE-22)
2026-09-03 23:07 CEST
In Progress → Resolved

CVE-2026-66035
Cyberus Linux 26.05
libssh2
libssh2 Heap Buffer Overflow via ETM Cipher Negotiation
2026-09-03 23:07 CEST
In Progress → Resolved

CVE-2026-66034
Cyberus Linux 26.05
libssh2
libssh2 Heap Out-of-Bounds Read via publickey subsystem
2026-09-03 23:07 CEST
In Progress → Resolved

CVE-2026-66033
Cyberus Linux 26.05
libssh2
libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation
2026-09-03 23:07 CEST
In Progress → Resolved

CVE-2026-66032
Cyberus Linux 26.05
libssh2
libssh2 Double-Free Heap Corruption via sftp_open()
2026-09-03 23:07 CEST
In Progress → Resolved

CVE-2026-20713
Cyberus Linux 26.05
microcode-intel
Always-incorrect control flow implementation in some firmware for some Intel(R) Xeon(R) processors may allow an escalation of privilege
2026-09-03 23:06 CEST
In Progress → Resolved