Fix seeking and looping of media elements that set the loop property. Fix several crashes and rendering issues. Fix CVE-2025-13947, CVE-2025-43458, CVE-2025-66287
upstream stable upgrade from 2.41.1 to 2.41.3 (CVE-2025-14104 and other issues)
Backport fix for CVE-2025-11277
https://security-tracker.debian.org/tracker/DSA-6082-1
Fixed aarch64 crashes Updated to latest upstream (146.0)
Fixed aarch64 crashes Updated to latest upstream (146.0)
Update to 143.0.7499.109 * High: Under coordination * Medium CVE-2025-14372: Use after free in Password Manager * Medium CVE-2025-14373: Inappropriate implementation in Toolbar
ruby-sidekiq, a simple, efficient background processing for Ruby, had a couple of vulnerabilities as follows: CVE-2021-30151 Sidekiq allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
A couple of vulnerabilities were reported against ruby-git, a Ruby interface to the Git revision control system, that could lead to a command injection and execution of an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product.
Multiple vulnerabilities were discovered in the VLC media player, which could result in denial of service or potentially the execution of arbitrary code if a malformed video file is opened. For the oldstable distribution (bookworm), this problem has been fixed in version 3.0.22-0+deb12u1.
An update that solves 5 vulnerabilities can now be installed.
Moderate: grafana security update
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the oldstable distribution (bookworm), these problems have been fixed in version 1:140.6.0esr-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in
xkbcomp 1.5.0 (CVE-2018-15853, CVE-2018-15859, CVE-2018-15861, CVE-2018-15863)
Fixed CVE-2025-66293 (high severity): Out-of-bounds read in png_image_read_composite. Fixed the Paeth filter handling in the RISC-V RVV implementation. Improved the performance of the RISC-V RVV implementation.
Latest version This build with the latest golang should also fix all the Go CVEs, although I did verify how/if this package is affected by these CVEs.
https://security-tracker.debian.org/tracker/DSA-6081-1
Behind the polished exterior of many modern buildings sit outdated systems with vulnerabilities waiting to be found
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.6.0esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.
MGASA-2025-0326 – Updated golang packages fix security vulnerabilities
MGAA-2025-0104 – Updated codeblocks packages fix bug
Apply fuse2fs patches that were accidentally empty Update to upstream 1.4.5, including a fix for CVE-2025-65105
Apply fuse2fs patches that were accidentally empty Update to upstream 1.4.5, including a fix for CVE-2025-65105
Apply fuse2fs patches that were accidentally empty Update to upstream 1.4.5, including a fix for CVE-2025-65105
Being seen as reliable is good for ‘business’ and ransomware groups care about ‘brand reputation’ just as much as their victims
If you don’t look inside your environment, you can’t know its true state – and attackers count on that
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. An additional CVE (that has yet to be assigned) is fixed in this release; Google is aware of an expoit in the wild for that issue. For the oldstable distribution (bookworm), these problems have […]
This update includes the latest changes to the leap second list, including an update to its expiry date, which was set for the end of December.
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-6080-1
Interpreting the vast cybersecurity vendor landscape through the lens of industry analysts and testing authorities can immensely enhance your cyber-resilience.
An out-of-bounds read flaw was found in libsndfile’s FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with
version update security update
1.282 – Sanitize all user-supplied values before inserting into HTTP headers; Fixed CVE-2025-40927.
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape, same-origin policy bypass or privilege escalation.
Several security issues were fixed in libpng.
Qt could be made to crash or run programs as your login if it opened a specially crafted file.
Is your organization’s senior leadership vulnerable to a cyber-harpooning? Learn how to keep them safe.
