https://security-tracker.debian.org/tracker/DSA-5971-1
* bsc#1234959 Cross-References: * CVE-2024-56738
* bsc#1234959 Cross-References: * CVE-2024-56738
* bsc#1234959 Cross-References: * CVE-2024-56738
Several security issues were fixed in cifs-utils.
* bsc#1221107 * bsc#1246934 Cross-References: * CVE-2024-2236
Threat actors are embracing ClickFix, ransomware gangs are turning on each other – toppling even the leaders – and law enforcement is disrupting one infostealer after another
Multiple vulnerabilities have been discovered in Composer, the worst of which can lead to arbitrary code execution.
A vulnerability has been discovered in Spreadsheet-ParseExcel, which can lead to arbitrary code execution.
A vulnerability has been discovered in NSS, which can lead to the recovery of private data.
A vulnerability has been discovered in FontForge, which can lead to arbitrary code execution.
Multiple vulnerabilities have been discovered in GPL Ghostscript, the worst of which can lead to execution of arbitrary code.
Multiple vulnerabilities have been discovered in PAM, the worst of which could lead to privilege escalation.
* bsc#1245773 Cross-References: * CVE-2025-53367
* bsc#1247249 Cross-References: * CVE-2025-8194
* bsc#1247249 Cross-References: * CVE-2025-8194
* bsc#1234675 * bsc#1235461 * bsc#1235871 Cross-References:
* bsc#1228645 * bsc#1235250 * bsc#1245771 * bsc#1245776 * bsc#1245793
* bsc#1245776 * bsc#1245793 * bsc#1245797 Cross-References:
* bsc#1235250 * bsc#1245776 * bsc#1245793 * bsc#1245797
* bsc#1245776 * bsc#1245793 * bsc#1245797 Cross-References:
Update to 138.0.7204.183 * CVE-2025-8292: Use after free in Media Stream
This update fixes CVE-2025-7345 and CVE-2025-6199.
This update fixes these CVEs: CVE-2025-32364 CVE-2025-32365 CVE-2024-56378
reposurgeon: update to 5.3 version
In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL. References: – https://bugs.mageia.org/show_bug.cgi?id=34447
Stefan Buehler discovered a flaw in sope, the set of Objective-C frameworks powering SOGo, which may result in denial of service via a specially crafted POST request.
Here’s what you need to know about the inner workings of modern spyware and how to stay away from apps that know too much
Restricting end-to-end encryption on a single-country basis would not only be absurdly difficult to enforce, but it would also fail to deter criminal activity
A flaw was found in how GLib¢”s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn¢”t. As a result, data may be written […]
This update fixes these CVEs: CVE-2025-4948 CVE-2025-32908 CVE-2025-32907 CVE-2025-4969
Backports patch to fix non-CVE 2025-8224
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5970-1
Here’s a look at cybersecurity stories that moved the needle, raised the alarm, or offered vital lessons in July 2025
* bsc#1243855 Cross-References: * CVE-2024-12224
