A vulnerability has been discovered in FreeType, which can lead to remote code execution.
Abseil could be made to crash if it received specially crafted input.
Update to 136.0.7103.92 CVE-2025-4372: Use after free in WebAudio
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
* bsc#1242008 * bsc#1242009 Cross-References: * CVE-2025-31650
Several security issues were fixed in the Linux kernel.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5918-1
Unlimited output buffer for unauthenticated clients has been fixed in the key¢”value database Redis. For Debian 11 bullseye, this problem has been fixed in version
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
A vulnerability has been discovered in Orc, which can lead to arbitrary code execution
Multiple vulnerabilities have been discovered in NVIDIA Drivers, the worst of which could result in arbitrary code execution.
PDF signature forgery with adbe.pkcs7.sha1 SubFilter. (CVE-2025-2866) References: – https://bugs.mageia.org/show_bug.cgi?id=34234 – https://lists.debian.org/debian-security-announce/2025/msg00070.html
An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on
Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function. (CVE-2025-31162) Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patternarc function.
5.22.9
https://deluge.readthedocs.io/en/deluge-2.2.0/changelog.html 2.2.0 (2025-04-28) Breaking changes Removed Python 3.6 support (Python >= 3.7) Core
Update to version 22.15.0
Here’s a brief dive into the murky waters of shape-shifting attacks that leverage dedicated phishing kits to auto-generate customized login pages on the fly
Update to 47.7 notably fixing CVE-2025-3839
xz 5.8.1
xz 5.8.1
xz 5.8.1
xz 5.8.1
Fixes CVE-2025-47256 .
https://security-tracker.debian.org/tracker/DSA-5917-1
When we get the call, it’s our legal responsibility to attend jury service. But sometimes that call won’t come from the courts – it will be a scammer.
It all starts so innocently. You get a text saying “Your package couldn’t be delivered. Click here to reschedule.” Little do you know, clicking that link could open the door for scammers to steal your identity, empty your bank account, or even plant malicious software (malware) on your device. Unless you know what to look out […]
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
* bsc#1224259 Cross-References: * CVE-2024-4853
* bsc#1242210 Cross-References: * CVE-2025-32873
* bsc#1241274 * bsc#1241275 * bsc#1241276 Cross-References:
A vulnerability has been fixed in mod_auth_openidc, an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality.
Django could be made to crash if it received specially crafted network traffic.
New mariadb packages are available for Slackware 15.0 and -current to fix security issues.
Moderate: libXpm security update
