* bsc#1234847 Cross-References: * CVE-2024-53156
* bsc#1205495 * bsc#1230764 * bsc#1231103 * bsc#1231450 * bsc#1231910
Several security issues were fixed in the Linux kernel.
* bsc#1242631 * bsc#1243177 Cross-References: * CVE-2025-3416
Microcode updates has been released for Intel(R) processors, addressing multiple potential vulnerabilties that may allow denial of service or information disclosure.
.NET could be used to perform spoofing over a network.
* bsc#1228634 * bsc#1232533 * bsc#1241012 * bsc#1241045
New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.
Enable CSS Overscroll Behavior by default. Change threaded rendering implementation to use Skia API instead of WebCore display list that is not thread safe. Fix rendering when device scale factor change comes before the web view geometry update.
Mohamed Maatallah discovered a stack-based buffer overflow in the get_name() function in net-tools, a collection of programs for controlling the network subsystem of the Linux kernel, which may result in denial of service (application crash) or potentially the execution of
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.
Update to 136.0.7103.113 CVE-2025-4664: Insufficient policy enforcement in Loader CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo
Update to 1.25.0
Update to 136.0.7103.113 CVE-2025-4664: Insufficient policy enforcement in Loader CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo
Update to 1.25.0
https://security-tracker.debian.org/tracker/DSA-5923-1
https://security-tracker.debian.org/tracker/DSA-5922-1
https://security-tracker.debian.org/tracker/DSA-5921-1
Enable CSS Overscroll Behavior by default. Change threaded rendering implementation to use Skia API instead of WebCore display list that is not thread safe. Fix rendering when device scale factor change comes before the web view geometry update.
x86: Indirect Target Selection [XSA-469, CVE-2024-28956]
update to 4.8.2 fixing CVE-2024-47619
update to 4.8.2 to fix CVE-2024-47619
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
* bsc#1242617 Cross-References: * CVE-2025-3416
* bsc#1236136 * bsc#1236771 Cross-References: * CVE-2024-13176
Operation RoundPress targets webmail software to steal secrets from email accounts belonging mainly to governmental organizations in Ukraine and defense contractors in the EU
ESET researchers uncover a Russia-aligned espionage operation targeting webmail servers via XSS vulnerabilities
https://security-tracker.debian.org/tracker/DSA-5919-1
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
* bsc#1218424 * bsc#1236045 * bsc#1236046 * bsc#1236801 * jsc#SLE-18320
Update to 1.9.9 to fix CVE-2025-30194
Update to 1.9.9 to fix CVE-2025-30194
https://security-tracker.debian.org/tracker/DSA-5920-1
It was discovered that insecure file handling in open-vm-tools, an open source implementation of VMware Tools, may allow an unprivileged local guest user to tamper local files to trigger insecure file operations within that VM.
* bsc#1230959 * bsc#1231748 * bsc#1232326 * bsc#1240366 * bsc#1240607
Ever wondered why a lie can spread faster than the truth? Tune in for an insightful look at disinformation and how we can fight one of the most pressing challenges facing our digital world.
