* bsc#1238324 * bsc#1239077 Cross-References: * CVE-2022-49080
* bsc#1243273 Cross-References: * CVE-2025-4516
* bsc#1239949 * bsc#1241050 * bsc#1243217 * bsc#1243218
* bsc#1239949 * bsc#1241050 * bsc#1243217 * bsc#1243218
https://security-tracker.debian.org/tracker/DSA-5941-1
* bsc#1234282 * bsc#1238043 * bsc#1243117 Cross-References:
* bsc#1238324 * bsc#1239077 Cross-References: * CVE-2022-49080
* bsc#1236701 * bsc#1239077 * bsc#1239096 Cross-References:
* bsc#1232900 * bsc#1236701 * bsc#1239077 * bsc#1239096
Several security issues were fixed in tomcat8, tomcat9, tomcat10.
https://security-tracker.debian.org/tracker/DSA-5940-1
DoS with sanitiseArg/sanitizeArg has been fixed in modsecurity-apache, a module for the Apache webserver to tighten Web application security. For Debian 11 bullseye, this problem has been fixed in version
Disallowing use of the arcfour-hmac(-md5) encryption type for session keys Add support for the PKINIT paChecksum2 sequence, required for Active Directory interoperability on Windows Server 2025 Fix generation of RADIUS Message-Authenticator in FIPS mode
Kirill Firsov discovered that Roundcube, a skinnable AJAX based webmail solution for IMAP servers, was performing PHP Object deserialization on unvalidated input, which could lead to remote code execution by an authenticated attacker.
Several vulnerabilities were discovered in modsecurity-apache, an Apache module to tighten the Web application security, which may result in denial of service (high memory consumption).
New libvpx packages are available for Slackware 15.0 and -current to fix security issues.
ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and calls pg_insert_id() with user-supplied data.
Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump. (CVE-2025-4598) References:
Security constraint bypass for CGI scripts. (CVE-2025-46701) References: – https://bugs.mageia.org/show_bug.cgi?id=34332 – https://openwall.com/lists/oss-security/2025/05/29/4
Add patch for double free
Update to version 4.21.6
Fix CVE-2025-23016
Update to Samba 4.22.2 – Security fix for CVE-2025-0620
Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink
This update includes mod_security version 2.9.9 which addresses CVE-2025-47947 and includes various bug fixes. See https://github.com/owasp- modsecurity/ModSecurity/releases/tag/v2.9.9 for more information on the changes in this release.
Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink
This update includes mod_security version 2.9.9 which addresses CVE-2025-47947 and includes various bug fixes. See https://github.com/owasp- modsecurity/ModSecurity/releases/tag/v2.9.9 for more information on the changes in this release.
ESET researchers analyzed a cyberespionage campaign conducted by BladedFeline, an Iran-aligned APT group with likely ties to OilRig
* bsc#1243268 Cross-References: * CVE-2025-47287
* bsc#1236826 * bsc#1239671 * bsc#1241012 Cross-References:
* bsc#1240392 Cross-References: * CVE-2025-2704
* bsc#1236974 Cross-References: * CVE-2024-12243
Several security issues were fixed in the Linux kernel.
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-24223
https://security-tracker.debian.org/tracker/DSA-5939-1
https://security-tracker.debian.org/tracker/DSA-5938-1
https://security-tracker.debian.org/tracker/DSA-5937-1
