Skip to main content

Clea OS Security Advisories

This page provides a human-readable summary of publicly disclosed security vulnerabilities addressed in Clea OS releases.

Security fixes are organized by release year and quarter and identify the Clea OS release in which the corresponding remediation is included.

The fixes listed on this page may originate from upstream projects, Yocto Project updates, component maintainers, or fixes integrated directly into Clea OS. A vulnerability listed under a release therefore indicates that the corresponding remediation is included in that Clea OS release; it does not imply that the original fix was developed by SECO.

Only vulnerabilities reported as fixed are listed here. Vulnerabilities determined to be not applicable or otherwise not requiring remediation are not included in this summary.

For machine-readable software composition and vulnerability information, see Software Bill of Materials (SBOM) and VEX.

2026​

Q2​

Security fixes

Clea OS 2.04.00​

Clea OS 2.04.00 updates the Yocto Scarthgap baseline from 5.0.9 to 5.0.16 and incorporates the following security fixes.

  • alsa-lib: CVE-2026-25068
  • avahi: CVE-2024-52615
  • bind: CVE-2025-8677, CVE-2025-40778, CVE-2025-40780
  • binutils: CVE-2025-1153, CVE-2025-1179, CVE-2025-1180, CVE-2025-1182, CVE-2025-5244, CVE-2025-5245, CVE-2025-7545, CVE-2025-7546, CVE-2025-8225, CVE-2025-11081, CVE-2025-11082, CVE-2025-11083, CVE-2025-11412, CVE-2025-11413, CVE-2025-11414, CVE-2025-11494, CVE-2025-11839, CVE-2025-11840
  • busybox: CVE-2022-48174, CVE-2023-39810, CVE-2025-46394
  • cmake: CVE-2025-9301
  • cmake-native: CVE-2025-9301
  • connman: CVE-2025-32366, CVE-2025-32743
  • coreutils: CVE-2025-5278
  • cups: CVE-2025-58060, CVE-2025-58364, CVE-2025-58436, CVE-2025-61915
  • curl: CVE-2024-11053, CVE-2025-0167, CVE-2025-9086
  • dpkg: CVE-2025-6297
  • dropbear: CVE-2025-47203
  • elfutils: CVE-2025-1371, CVE-2025-1376, CVE-2025-1377
  • expat: CVE-2024-8176, CVE-2025-59375
  • ffmpeg: CVE-2024-7055, CVE-2024-32230, CVE-2024-35366, CVE-2024-36613, CVE-2024-36616, CVE-2024-36617, CVE-2024-36619, CVE-2025-1373, CVE-2025-1594
  • gdk-pixbuf: CVE-2025-7345
  • ghostscript: CVE-2025-59798, CVE-2025-59799, CVE-2025-59800
  • git: CVE-2024-50349, CVE-2024-52006, CVE-2025-27613, CVE-2025-27614, CVE-2025-46334, CVE-2025-46835, CVE-2025-48384, CVE-2025-48385, CVE-2025-48386
  • glib-2.0: CVE-2025-3360, CVE-2025-4373, CVE-2025-6052, CVE-2025-7039, CVE-2026-1484, CVE-2026-1485, CVE-2026-1489
  • glib-networking: CVE-2025-60018, CVE-2025-60019
  • glibc: CVE-2025-4802, CVE-2025-5702, CVE-2025-8058
  • gnupg: CVE-2025-30258, CVE-2025-68973
  • gnutls: CVE-2025-6395, CVE-2025-9820, CVE-2025-32988, CVE-2025-32989, CVE-2025-32990
  • go: CVE-2025-4673, CVE-2025-4674, CVE-2025-47906, CVE-2025-47907, CVE-2025-47912, CVE-2025-58185, CVE-2025-58187, CVE-2025-58188, CVE-2025-58189, CVE-2025-61723, CVE-2025-61724, CVE-2025-61726, CVE-2025-61727, CVE-2025-61728, CVE-2025-61729, CVE-2025-61730, CVE-2025-61731, CVE-2025-61732, CVE-2025-68119, CVE-2025-68121
  • grub: CVE-2025-54770, CVE-2025-61661, CVE-2025-61662, CVE-2025-61663, CVE-2025-61664
  • grub2: CVE-2024-56738
  • gstreamer1.0-plugins-bad: CVE-2025-3887
  • gstreamer1.0-plugins-base: CVE-2025-47806, CVE-2025-47807, CVE-2025-47808
  • gstreamer1.0-plugins-good: CVE-2025-47183, CVE-2025-47219
  • icu: CVE-2025-5222
  • iputils: CVE-2025-47268, CVE-2025-48964
  • kea: CVE-2025-32801, CVE-2025-32802, CVE-2025-32803
  • libarchive: CVE-2025-5914, CVE-2025-5915, CVE-2025-5916, CVE-2025-5917, CVE-2025-5918, CVE-2025-60753
  • libpam: CVE-2024-10041, CVE-2024-10963, CVE-2025-6020
  • libpng: CVE-2025-64505, CVE-2025-64506, CVE-2025-64720, CVE-2025-65018, CVE-2025-66293
  • libsoup: CVE-2025-4476, CVE-2025-12105, CVE-2025-32906, CVE-2025-32909, CVE-2025-32910, CVE-2025-32911, CVE-2025-32912, CVE-2025-32913, CVE-2025-32914, CVE-2025-46420
  • libsoup-2.4: CVE-2024-52530, CVE-2024-52531, CVE-2024-52532, CVE-2025-2784, CVE-2025-4476, CVE-2025-4945, CVE-2025-4948, CVE-2025-4969, CVE-2025-32050, CVE-2025-32052, CVE-2025-32053, CVE-2025-32906, CVE-2025-32907, CVE-2025-32909, CVE-2025-32910, CVE-2025-32911, CVE-2025-32912, CVE-2025-32913, CVE-2025-32914, CVE-2025-46420, CVE-2025-46421
  • libsoup-3.4: CVE-2025-2784, CVE-2025-4945, CVE-2025-4948, CVE-2025-4969, CVE-2025-32050, CVE-2025-32051, CVE-2025-32052, CVE-2025-32053, CVE-2025-32907, CVE-2025-32908, CVE-2025-46421
  • libssh2: CVE-2023-48795
  • libxml2: CVE-2025-6021, CVE-2025-6170, CVE-2025-7425, CVE-2025-32414, CVE-2025-32415, CVE-2025-49794, CVE-2025-49795, CVE-2025-49796
  • libxslt: CVE-2025-7424, CVE-2025-11731
  • linux-yocto-6.6: CVE-2025-21995, CVE-2025-21996, CVE-2025-21997, CVE-2025-21999, CVE-2025-22001, CVE-2025-22003, CVE-2025-22004, CVE-2025-22005, CVE-2025-22007, CVE-2025-22009, CVE-2025-22010, CVE-2025-22014, CVE-2025-22018, CVE-2025-22020, CVE-2025-22027, CVE-2025-22033, CVE-2025-22035, CVE-2025-22038, CVE-2025-22040, CVE-2025-22041, CVE-2025-22054, CVE-2025-22056, CVE-2025-22063, CVE-2025-22066, CVE-2025-22080, CVE-2025-22081, CVE-2025-22088, CVE-2025-22097, CVE-2025-23136, CVE-2025-37785, CVE-2025-37800, CVE-2025-37801, CVE-2025-37803, CVE-2025-37805, CVE-2025-37838, CVE-2025-37893, CVE-2025-38152, CVE-2025-39728, CVE-2025-39735
  • lz4: CVE-2025-62813
  • musl: CVE-2025-26519
  • ncurses: CVE-2025-6141
  • net-tools: CVE-2025-46836
  • openssh: CVE-2025-32728, CVE-2025-61984, CVE-2025-61985
  • openssl: CVE-2024-41996, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-15468, CVE-2025-27587, CVE-2025-69419
  • perl: CVE-2024-56406
  • ppp: CVE-2024-58250
  • python3: CVE-2024-12718, CVE-2025-4138, CVE-2025-4330, CVE-2025-4435, CVE-2025-4516, CVE-2025-4517, CVE-2025-6075, CVE-2025-8194, CVE-2025-59375
  • python3-jinja2: CVE-2024-56201, CVE-2024-56326, CVE-2025-27516
  • python3-requests: CVE-2024-47081
  • python3-setuptools: CVE-2025-47273
  • python3-urllib3: CVE-2025-50181, CVE-2025-66418, CVE-2025-66471
  • python3-xmltodict: CVE-2025-9375
  • qemu: CVE-2024-8354, CVE-2025-12464
  • rsync: CVE-2025-10158
  • ruby: CVE-2025-24294, CVE-2025-25186, CVE-2025-27221, CVE-2025-61594
  • screen: CVE-2025-46802, CVE-2025-46804, CVE-2025-46805
  • sqlite3: CVE-2025-3277, CVE-2025-6965, CVE-2025-7709, CVE-2025-29087, CVE-2025-29088
  • sudo: CVE-2025-32462, CVE-2025-32463
  • tiff: CVE-2025-9900
  • u-boot: CVE-2024-42040
  • vim: CVE-2025-9389
  • wpa-supplicant: CVE-2022-37660, CVE-2025-24912
  • xserver-xorg: CVE-2022-49737, CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180, CVE-2025-62229, CVE-2025-62230, CVE-2025-62231
  • xwayland: CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180, CVE-2025-62229, CVE-2025-62230, CVE-2025-62231

Q1​

Security fixes

No security fixes are currently listed for this quarter.