Multiple High-Risk Vulnerabilities Discovered in Gentoo Linux Packages

Multiple High-Risk Vulnerabilities Discovered in Gentoo Linux Packages

First seen 20 Aug 2026, 11:54 UTC Linuxsecurity 77% similarity 74.0

Article Content

Browse articles
ThreatCluster

On August 20, 2026, Gentoo Linux announced multiple high-severity vulnerabilities affecting various packages, including libssh2, acl, attr, quickjs-ng, and Emacs. The vulnerabilities allow for high remote code execution risks, impacting users running these packages. Specific CVEs include CVE-2025-15661, CVE-2026-7598, CVE-2026-54369, CVE-2026-54370, CVE-2026-54371, CVE-2026-55199, CVE-2026-55200, CVE-2026-0821, CVE-2026-1144, and CVE-2026-1145. No known workarounds are available, and users are advised to monitor for updates. The vulnerabilities were disclosed in advisories published on the same day, indicating an urgent need for remediation. The scope of impact includes all systems utilizing the affected packages, emphasizing the critical nature of the vulnerabilities.

Key Points: • Multiple high-severity vulnerabilities identified in Gentoo Linux packages. • Affected packages include libssh2, acl, attr, quickjs-ng, and Emacs. • No known workarounds; users urged to apply updates promptly.

ThreatCluster AI How this analysis works

Timeline

2025-05-01
CVE-2026-7598 published
A high-severity vulnerability in libssh2 was disclosed, allowing remote code execution.
Linuxsecurity
2026-01-10
CVE-2026-0821 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-19
CVE-2026-1145 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-19
CVE-2026-1144 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-17
CVE-2026-55199 and CVE-2026-55200 published
Two vulnerabilities in libssh2 were disclosed, increasing the risk of exploitation.
Linuxsecurity
2026-06-18
CVE-2025-15661 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-29
CVE-2026-54369, CVE-2026-54370, CVE-2026-54371 published
Multiple vulnerabilities in acl and attr were disclosed, posing significant risks.
Linuxsecurity
2026-08-20
Gentoo advisories published
Gentoo released advisories for multiple high-severity vulnerabilities affecting various packages.
Linuxsecurity
2026-08-20
No workarounds available
Gentoo advises users to monitor for updates as no known workarounds exist for the vulnerabilities.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story