Cyberus Linux Security Tracker
This is the security tracker for Cyberus Linux. It allows monitoring the status of vulnerabilities that affect Cyberus Linux releases. Vulnerabilities are ingested from official sources, such as NVD and others.
For general information about installing or upgrading Cyberus Linux, refer to the documentation. We are eager to hear your feedback and suggestions for this security tracker. Channels to reach us are documented here.
Releases
These are the currently supported releases.
Latest Events
CVE-2026-6846
Cyberus Linux 26.05
binutils
Binutils: binutils: arbitrary code execution via malformed xcoff object file processing
2026-10-09 19:52 CEST
Plausible → Invalid
CVE-2026-85091
Cyberus Linux 26.05
zlib
zlib 1.3.1.2 through 1.3.2 Heap Buffer Overflow via gz_vacate
2026-10-09 16:35 CEST
New → Plausible
CVE-2026-85091
Cyberus Linux 26.05
zlib
zlib 1.3.1.2 through 1.3.2 Heap Buffer Overflow via gz_vacate
2026-10-09 16:31 CEST
New
GLIBC-SA-2026-0023
Cyberus Linux 26.05
glibc
AT_SECURE program buffer overflow via $ORIGIN processing
2026-10-09 16:28 CEST
Plausible → In Progress
GHSA-hhw5-qqmc-p6rg
Cyberus Linux 26.05
cups
Incomplete Send-Document request globally suppresses job submission timeouts, allowing unauthenticated DoS
2026-10-09 15:59 CEST
Plausible → Blocked: No known fix
GHSA-58wv-9ffm-5w78
Cyberus Linux 26.05
cups
Embedded job ticket comments can lead to a crash
2026-10-09 15:58 CEST
New → Plausible
GHSA-58wv-9ffm-5w78
Cyberus Linux 26.05
cups
Embedded job ticket comments can lead to a crash
2026-10-09 15:57 CEST
New
CVE-2026-96512
Cyberus Linux 26.05
sudo
Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization
2026-10-09 02:52 CEST
Plausible → Resolved
GHSA-r9hj-j2rw-4q3m
Cyberus Linux 26.05
pcre2
PCRE2: out-of-bounds write in JIT matching with large stack allocations
2026-10-09 02:50 CEST
In Progress → Resolved
CVE-2026-93990
Cyberus Linux 26.05
expat
Expat before 2.8.5 Malformed UTF-16 Acceptance via Unchecked Surrogate
2026-10-09 02:49 CEST
In Progress → Resolved
CVE-2025-59777
Cyberus Linux 26.05
libmicrohttpd
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier
2026-10-09 02:49 CEST
In Progress → Resolved
CVE-2025-62689
Cyberus Linux 26.05
libmicrohttpd
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier
2026-10-09 02:49 CEST
In Progress → Resolved
GLIBC-SA-2026-0020
Cyberus Linux 26.05
glibc
EUC_JISX0213 decoding may hang on crafted input
2026-10-09 02:48 CEST
In Progress → Resolved
GLIBC-SA-2026-0019
Cyberus Linux 26.05
glibc
SHIFT_JISX0213 decoding may hang on crafted input
2026-10-09 02:48 CEST
In Progress → Resolved
GLIBC-SA-2026-0018
Cyberus Linux 26.05
glibc
Stack-based out-of-bounds write in tdelete during tree rebalancing
2026-10-09 02:48 CEST
In Progress → Resolved
GLIBC-SA-2026-0017
Cyberus Linux 26.05
glibc
Buffer overflow in strfmon and strfmon_l right-justification padding
2026-10-09 02:48 CEST
In Progress → Resolved
GLIBC-SA-2026-0021
Cyberus Linux 26.05
glibc
Assertion failure in the DNS stub resolver with a long search domain
2026-10-09 02:48 CEST
In Progress → Resolved
GLIBC-SA-2026-0015
Cyberus Linux 26.05
glibc
Buffer overflow in fopen mode argument processing
2026-10-09 02:48 CEST
In Progress → Resolved
CVE-2026-35189
Cyberus Linux 26.05
openssl_3_6
Excessive Memory Allocation in Relative CRLDP Processing
2026-10-09 02:48 CEST
In Progress → Resolved
CVE-2026-35191
Cyberus Linux 26.05
openssl_3_6
QUIC Unvalidated Amplification Credit may be Over Accounted
2026-10-09 02:48 CEST
In Progress → Resolved
CVE-2026-42772
Cyberus Linux 26.05
openssl_3_6
Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
2026-10-09 02:48 CEST
In Progress → Resolved
CVE-2026-54872
Cyberus Linux 26.05
openssl_3_6
Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves
2026-10-09 02:48 CEST
In Progress → Resolved
CVE-2026-54873
Cyberus Linux 26.05
openssl_3_6
QUIC STREAM Fragment Metadata DoS
2026-10-09 02:48 CEST
In Progress → Resolved
CVE-2026-54875
Cyberus Linux 26.05
openssl_3_6
Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V
2026-10-09 02:48 CEST
In Progress → Resolved
CVE-2026-72897
Cyberus Linux 26.05
openssl_3_6
Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake
2026-10-09 02:48 CEST
In Progress → Resolved
CVE-2026-75804
Cyberus Linux 26.05
openssl_3_6
QUIC Connection-Level Flow Control is Not Enforced for Streams
2026-10-09 02:48 CEST
In Progress → Resolved
CVE-2026-75805
Cyberus Linux 26.05
openssl_3_6
NULL Pointer Dereference in CMP Client Revocation Response Handling
2026-10-09 02:48 CEST
In Progress → Resolved
CVE-2026-75806
Cyberus Linux 26.05
openssl_3_6
Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS
2026-10-09 02:48 CEST
In Progress → Resolved
CVE-2026-77696
Cyberus Linux 26.05
openssl_3_6
Timing Side-Channel in SM2 Signature Generation
2026-10-09 02:48 CEST
In Progress → Resolved
CVE-2026-84782
Cyberus Linux 26.05
openssl_3_6
DTLS Retransmits Handshake Messages From a Stale Buffer Offset
2026-10-09 02:48 CEST
In Progress → Resolved