Menu

Monthly Archives: October 2025

Update to 3.11.14

Backport fixes for CVE-2025-11082, CVE-2025-11083, CVE-2025-11494, CVE-2025-11495.

What is an Out-of-Bounds Write Linux Security Vulnerability?

When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, an insufficiently seeded random number generator is used when generating the directory name, leading to the possibility for a local attacker to pre-create

Added fix for mzbz#1990430 (crashes) Updated to latest upstream (144.0)

Backport fix for CVE-2025-10729.

Backport fix for CVE-2025-10729.

Update to python-3.11.14, fixes CVE-2025-8291.

Update to release v1.3.2

Threat actors are spreading malicious extensions via VS marketplaces
Have I Been Pwned logs 17.6M victims in Prosper breach
Labor unions sue Trump administration over social media surveillance
Carmakers fear chip crunch as Dutch sanctions hit Nexperia

An update that solves 326 vulnerabilities and has 45 security fixes can now be installed.

* bsc#1065729 * bsc#1164051 * bsc#1193629 * bsc#1194869 * bsc#1202700

* bsc#1223219 * jsc#PED-13826 Cross-References: * CVE-2024-32650

An update that solves one vulnerability and contains one feature can now be installed.

* bsc#1250232 Cross-References: * CVE-2025-9230

A mini-CrowdStrike moment? Windows 11 update cripples dev environments

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, memory disclosure or cross-site scripting.

Agents of chaos
An EU breakup with US cloud providers

https://security-tracker.debian.org/tracker/DSA-6028-1

https://security-tracker.debian.org/tracker/DSA-6027-1

https://security-tracker.debian.org/tracker/DSA-6025-1

Vulnerability scores, huh, what are they good for? Almost nothing
Chinese cyberspies snoop on Russian IT biz in rare east-on-east attack
Locked out of your Gmail account? Google says phone a friend

Redis could be made to crash or run programs if it received specially crafted network traffic from an authenticated user.

Redict could be made to crash or run programs if it received specially crafted network traffic from an authenticated user.

Redis could be made to crash or run programs if it received specially crafted network traffic from an authenticated user.

Apache Subversion could be made to crash if it opened a specially crafted file.

Microsoft kills 9.9-rated ASP.NET Core bug – ‘our highest ever’ score
Senator presses Cisco over firewall flaws that burned US agency

The following updated rpms for have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

Auction house Sotheby’s finds its data on the block after cyberattack
Tech industry grad hiring crashes 46% as bots do junior work
Operation Heracles strikes blow against massive network of fraudulent crypto trading sites
Rethinking operations in an agentic AI world
How to run an R data visualization chatbot you can talk to
Using Valkey on Azure and in .NET Aspire
Machine learning meets malware: how AI-powered ransomware could destroy your business

https://security-tracker.debian.org/tracker/DSA-6026-1

Smashing Security podcast #439: A breach, a burnout, and a bit of Fleetwood Mac
Devs are writing VS Code extensions that blab secrets by the bucketload
NCSC warns companies to prepare for a day when your screens go dark
Capita fined £14M after 58-hour delay exposed 6.6M records
Selective retraining helps AI learn new skills without forgetting, study finds
7 newer data science tools you should be using with Python
The best Java microframeworks to learn now
Zoom dooms the developer’s afternoon

* bsc#1250553 Cross-References: * CVE-2025-10911

An update that solves one vulnerability can now be installed.

Update to exiv2-0.28.7, fixes CVE-2025-54080 and CVE-2025-55304.

Update to exiv2-0.28.7, fixes CVE-2025-54080 and CVE-2025-55304.

Update mirrorlist-server to version 3.0.8. Update the maxminddb crate to version 0.26.0. Update the prometheus crate to version 0.14.0. Update the protobuf and protobuf-codegen crates to version 3.7.2. Initial packaging of the protobuf-parse and protobuf-support crates.

Update mirrorlist-server to version 3.0.8. Update the maxminddb crate to version 0.26.0. Update the prometheus crate to version 0.14.0. Update the protobuf and protobuf-codegen crates to version 3.7.2. Initial packaging of the protobuf-parse and protobuf-support crates.

The AI Fix #72: The AI hype train, space data centers, and lifelike robot heads
Asahi breach leaves bitter taste as brewer fears personal data slurped
Mozilla is recruiting beta testers for a free, baked-in Firefox VPN
Oracle debuts Iceberg-compatible Autonomous AI Lakehouse to boost enterprise analytics
Oracle targets agentic use cases with AI Database 26ai
Oracle rushes out another emergency E-Business Suite patch as Clop fallout widens

* bsc#1246197 * bsc#1249191 * bsc#1249348 * bsc#1249367 * jsc#PED-13055

* bsc#1243581 * bsc#1248410 * bsc#1248687 * bsc#142461 * bsc#544339

* bsc#1237048 * bsc#1240744 * bsc#1243650 * bsc#1245509 * bsc#1247315

* bsc#1237048 * bsc#1240744 * bsc#1245509 * bsc#1247315

* bsc#1245509 * bsc#1247315 Cross-References: * CVE-2025-38089

* bsc#1245509 * bsc#1247315 Cross-References: * CVE-2025-38089

CVE-2025-11371: Linux Security Must Prepare for Cross-Stack Breach
British govt agents demand action after UK mega-cyberattacks surge 50%
The rise of purpose-built clouds
EU biometric border system launch hits inevitable teething problems
Scattered Lapsus$ Hunters rage-quit the internet (again), promise to return next year
Microsoft ‘illegally’ tracked students via 365 Education, says data watchdog
China probes Qualcomm’s Autotalks deal amid rising US trade tensions
Ofcom fines 4chan £20K and counting for pretending UK’s Online Safety Act doesn’t exist
Dutch government puts Nexperia on a short leash over chip security fears

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

How to run RAG projects for better data analytics results
Know your ops: Why all ops lead back to devops
OpenAI Codex rivals Claude Code
Java or Python for building agents?

An update that solves 53 vulnerabilities, contains one feature and has 137 security fixes can now be installed.

* bsc#1001161 * bsc#1004490 * bsc#1007249 * bsc#1009961 * bsc#1012568

* bsc#1250232 Cross-References: * CVE-2025-9230

An update that solves 10 vulnerabilities and has one security fix can now be installed.

Update to release v0.29.1 Upstream fixes Update to release v0.29.0 Resolves: rhbz#2397747, rhbz#2398425, rhbz#2398679, rhbz#2399082, rhbz#2399355

Update to release v0.29.1 Upstream fixes Update to release v0.29.0 Resolves: rhbz#2397747, rhbz#2398425, rhbz#2398679, rhbz#2399082, rhbz#2399355

Update to 1.5.0, fix CVE-2025-54813, CVE-2025-22838

Urgent: How Hackers Use eBPF to Evade Detection

MGASA-2025-0237 – Updated open-vm-tools package fixes security vulnerability

MGAA-2025-0083 – Updated qarte package fixes bug

Update to 141.0.7390.65 * High CVE-2025-11458: Heap buffer overflow in Sync * High CVE-2025-11460: Use after free in Storage * Medium CVE-2025-11211: Out of bounds read in WebCodecs

Update to release v1.33.5 Resolves: rhbz#2333357, rhbz#2375096, rhbz#2398408, rhbz#2398663, rhbz#2399065, rhbz#2399339 Upstream fixes

Update to release 1.32.9 Resolves: rhbz#2333357, rhbz#2398407, rhbz#2398662, rhbz#2399064, rhbz#2399338 Upstream fix

Update to release v1.31.13 Resolves: rhbz#2333357, rhbz#2398406, rhbz#2398661, rhbz#2399063, rhbz#2399337 Upstream fix

https://security-tracker.debian.org/tracker/DSA-6024-1