https://security-tracker.debian.org/tracker/DSA-6047-1
https://security-tracker.debian.org/tracker/DSA-6046-1
* bsc#1242300 * bsc#1243284 Cross-References: * CVE-2025-47268
* bsc#1246019 * bsc#1248631 * bsc#1249207 * bsc#1249208
This upload fixes a few of security issues in the Python standard library included with PyPy, an alternative implementation of the Python 3 language. CVE-2024-6232
* bsc#1248631 * bsc#1249207 * bsc#1249208 Cross-References:
* bsc#1246019 * bsc#1248631 * bsc#1249207 * bsc#1249208
* bsc#1247737 * bsc#1248176 * bsc#1248631 * bsc#1249207 * bsc#1249208
https://security-tracker.debian.org/tracker/DSA-6045-1
The system could be made to expose sensitive information.
Netty could be made to send emails as your login if it received specially crafted input.
Several security issues were fixed in AMD Microcode.
Several security issues were fixed in GNU binutils.
Update to 9.18.41 (rhbz#2405786) Security fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780)
Update to 9.18.41 (rhbz#2405786) Security fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780)
https://security-tracker.debian.org/tracker/DSA-6043-1
Jan-Niklas Sohn discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.
Jan-Niklas Sohn discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.
MGASA-2025-0251 – Updated poppler packages fix security vulnerability
MGASA-2025-0250 – Updated tomcat packages fix security vulnerabilities
Multiple vulnerabilities have been found in python-authlib, a Python library for OAuth and OpenID Connect servers.
Update to latest version (#2404637) Fix CVE-2025-47910, CVE-2025-47906, CVE-2025-26625
https://security-tracker.debian.org/tracker/DSA-6044-1
* bsc#1251941 Cross-References: * CVE-2025-62291
* bsc#1246806 * bsc#1252414 * bsc#1252417 Cross-References:
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43272 Big Bear discovered that processing maliciously crafted web content may lead to an unexpected process crash.
* bsc#1019074 * bsc#1227577 * bsc#1229825 * bsc#1243331 * bsc#1243611
* bsc#1019074 * bsc#1227577 * bsc#1229825 * bsc#1237495 * bsc#1243331
* bsc#1227577 * bsc#1231150 * bsc#1231157 * bsc#1246277 * bsc#1246421
https://security-tracker.debian.org/tracker/DSA-6042-1
Moderate: kernel security update
Important: thunderbird security update
Moderate: kernel-rt security update
Moderate: kernel security update
