An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
It was discovered that usbmuxd, USB multiplexor daemon for iPhone and iPod Touch devices, incorrectly handled certain paths received with the SavePairRecord command. A local attacker could possibly use this issue to delete and write files named *.plist in arbitrary locations. For Debian 11 bullseye, this problem has been fixed in version
Erik Krogh Kristensen and Rasmus Petersen from the GitHub Security Lab discovered a ReDoS (Regular Expression Denial of Service) vulnerability in python-mechanize, a library to automate interaction with websites modeled after the Perl module WWW::Mechanize, which could lead to Denial of Service when parsing a malformed authentication header.
Fixes CVE-2025-58188, unretire package and update to 3.8.2.
Update to pgadmin-9.11, fixes CVE_2025-13780.
MGASA-2025-0331 – Updated webkit2 packages fix security vulnerabilities
MGASA-2025-0330 – Updated php packages fix security vulnerabilities
32.0.3 release, fixes RHBZ# 2420196 RHBZ# 2420197 RHBZ# 2420198 RHBZ# 2421368
Update to cef-143.0.10+g8aed01b + chromium-143.0.7499.146 (rhbz#2423482) High CVE-2025-14765: Use after free in WebGPU High CVE-2025-14766: Out of bounds read and write in V8 High CVE-2025-13630: Type Confusion in V8 High CVE-2025-13631: Inappropriate implementation in Google Updater
Update to uriparser-1.0.0, fixes CVE-2025-67899.
fix setpwnam() buffer use [CVE-2025-14104] libblkid: use snprintf() instead of sprintf()
https://security-tracker.debian.org/tracker/DSA-6091-1
https://security-tracker.debian.org/tracker/DSA-6090-1
https://security-tracker.debian.org/tracker/DSA-6089-1
https://security-tracker.debian.org/tracker/DSA-6088-1
https://security-tracker.debian.org/tracker/DSA-6087-1
https://security-tracker.debian.org/tracker/DSA-6086-1
https://security-tracker.debian.org/tracker/DSA-6085-1
Update to 143.0.7499.146 * High CVE-2025-14765: Use after free in WebGPU * High CVE-2025-14766: Out of bounds read and write in V8 * Force dark mode when auto dark mode web content is on
Update to 0.2.8
Update to 2.22.11
Update to 17.0.0 version (#2412270) Update fonttools 4.61.0
Update to 17.0.0 version (#2412270) Update fonttools 4.61.0
Update to 143.0.7499.146 * High CVE-2025-14765: Use after free in WebGPU * High CVE-2025-14766: Out of bounds read and write in V8 * Force dark mode when auto dark mode web content is on
ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
An update that solves four vulnerabilities can now be installed.
PHP version 8.4.16 (18 Dec 2025) Core: Sync all boost.context files with release 1.86.0. (mvorisek) Fixed bug GH-20435 (SensitiveParameter doesn’t work for named argument passing to variadic parameter). (ndossche)
It was discovered that c-ares, a library that performs DNS requests and name resolution asynchronously, does not properly handle termination of queries which may result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 1.34.5-1+deb13u1.
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-6084-1
https://security-tracker.debian.org/tracker/DSA-6083-1
A view of the H2 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts
An update that solves one vulnerability, contains one feature and has one security fix can now be installed.
This update includes the latest upstream release of mod_md, with various bug fixes and enhancements. See https://github.com/icing/mod_md/releases for more information. A fix for the security vulnerability CVE-2025-55753 is also included.
Update to 25.4.0
