Skip to content

CTRL-OS Security Tracker

This is the security tracker for CTRL-OS. It allows monitoring the status of vulnerabilities that affect CTRL-OS releases. Vulnerabilities are ingested from official sources, such as NVD and others.

For general information about installing or upgrading CTRL-OS, refer to the documentation. We are eager to hear your feedback and suggestions for this security tracker. Channels to reach us are documented here.

Releases

These are the currently supported releases.

Latest Events

CVE-2025-8732
CTRL-OS 26.05
libxml2
libxml2 xmlcatalog xmlParseSGMLCatalog recursion
2026-08-01 01:07 CEST
New → Resolved

CVE-2025-8732
CTRL-OS 26.05
libxml2
libxml2 xmlcatalog xmlParseSGMLCatalog recursion
2026-08-01 01:07 CEST
New

CVE-2026-58055
CTRL-OS 26.05
nghttp2
nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length
2026-08-01 01:06 CEST
New → Plausible

CVE-2026-58055
CTRL-OS 26.05
nghttp2
nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length
2026-08-01 01:04 CEST
New

CVE-2025-61147
CTRL-OS 26.05
libde265
strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().
2026-08-01 01:02 CEST
New → Resolved

CVE-2025-61147
CTRL-OS 26.05
libde265
strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().
2026-08-01 01:02 CEST
New

CVE-2025-70873
CTRL-OS 26.05
sqlite
An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.
2026-08-01 01:01 CEST
New → Resolved

CVE-2026-34085
CTRL-OS 26.05
fontconfig
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution
2026-08-01 01:01 CEST
New → Resolved

CVE-2026-34085
CTRL-OS 26.05
fontconfig
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution
2026-08-01 01:00 CEST
New

CVE-2026-4176
CTRL-OS 26.05
perl
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib
2026-08-01 01:00 CEST
New → Resolved

CVE-2026-35093
CTRL-OS 26.05
libinput
Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins
2026-08-01 00:59 CEST
New → Resolved

CVE-2026-4176
CTRL-OS 26.05
perl
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib
2026-08-01 00:58 CEST
New

CVE-2026-23865
CTRL-OS 26.05
freetype
An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable
2026-08-01 00:56 CEST
New → Resolved

CVE-2025-47268
CTRL-OS 26.05
iputils
ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply packet, because of a signed 64-bit integer overflow in timestamp
2026-08-01 00:56 CEST
New → Resolved

CVE-2025-68972
CTRL-OS 26.05
gnupg
In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material,
2026-08-01 00:53 CEST
New → Resolved

CVE-2025-68973
CTRL-OS 26.05
gnupg
In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input
2026-08-01 00:53 CEST
New → Resolved

CVE-2026-27171
CTRL-OS 26.05
zlib
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
2026-08-01 00:52 CEST
New → Resolved

CVE-2026-22184
CTRL-OS 26.05
zlib
zlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()
2026-08-01 00:52 CEST
New → Resolved

CVE-2025-25468
CTRL-OS 26.05
ffmpeg_4, ffmpeg_6, ffmpeg_7, ffmpeg_8
FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c.
2026-08-01 00:49 CEST
New → Unaffected
Code not present. The issue was only briefly found in the development branch that led to `8.0`.

CVE-2025-10256
CTRL-OS 26.05
ffmpeg_8
Ffmpeg: null pointer dereference in firequalizer filter (libavfilter/af_firequalizer.c)
2026-08-01 00:22 CEST
Resolved

CVE-2025-10256
CTRL-OS 26.05
ffmpeg_7
Ffmpeg: null pointer dereference in firequalizer filter (libavfilter/af_firequalizer.c)
2026-08-01 00:22 CEST
Resolved

CVE-2025-10256
CTRL-OS 26.05
ffmpeg_6
Ffmpeg: null pointer dereference in firequalizer filter (libavfilter/af_firequalizer.c)
2026-08-01 00:22 CEST
Plausible → Resolved

CVE-2025-10256
CTRL-OS 26.05
ffmpeg_4
Ffmpeg: null pointer dereference in firequalizer filter (libavfilter/af_firequalizer.c)
2026-08-01 00:22 CEST
New → Plausible

CVE-2025-10256
CTRL-OS 26.05
ffmpeg_4, ffmpeg_6, ffmpeg_7, ffmpeg_8
Ffmpeg: null pointer dereference in firequalizer filter (libavfilter/af_firequalizer.c)
2026-08-01 00:22 CEST
New

CVE-2025-12343
CTRL-OS 26.05
ffmpeg_8
Ffmpeg: double-free vulnerability in ffmpeg tensorflow dnn backend
2026-08-01 00:22 CEST
Resolved

CVE-2025-12343
CTRL-OS 26.05
ffmpeg_7
Ffmpeg: double-free vulnerability in ffmpeg tensorflow dnn backend
2026-08-01 00:22 CEST
Resolved

CVE-2025-12343
CTRL-OS 26.05
ffmpeg_6
Ffmpeg: double-free vulnerability in ffmpeg tensorflow dnn backend
2026-08-01 00:22 CEST
Unaffected → Resolved

CVE-2025-12343
CTRL-OS 26.05
ffmpeg_4
Ffmpeg: double-free vulnerability in ffmpeg tensorflow dnn backend
2026-08-01 00:22 CEST
New → Unaffected
Code not present.

CVE-2025-12343
CTRL-OS 26.05
ffmpeg_4, ffmpeg_6, ffmpeg_7, ffmpeg_8
Ffmpeg: double-free vulnerability in ffmpeg tensorflow dnn backend
2026-08-01 00:22 CEST
New

CVE-2025-25468
CTRL-OS 26.05
ffmpeg_4, ffmpeg_6, ffmpeg_7, ffmpeg_8
FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c.
2026-08-01 00:22 CEST
New