Linuxsecurity Critical Integer Overflow Vulnerability in Krita Affects Fedora 43 and 44
Article Content
- •CVE-2026-42144 is a critical integer overflow vulnerability in Krita.
- •Affected systems include Fedora 43 and Fedora 44, with patches available.
- •Users should upgrade to the latest versions to avoid potential exploitation.
A critical integer overflow vulnerability, CVE-2026-42144, has been identified in Krita, affecting both Fedora 43 and Fedora 44. The flaw allows attackers to bypass memory guards during PNM size checks, potentially leading to arbitrary code execution. Fedora 44 has been updated to version 6.0.2.1 to address this issue, while Fedora 43 has been patched to version 5.2.16-2. The vulnerability was published on May 4, 2026, and has been confirmed in both versions of the software. Users are advised to upgrade their installations using the provided dnf commands. The flaw impacts systems running Krita, a popular open-source digital painting application. Immediate action is recommended to mitigate potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Fedora and CVE-2026-42144 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…