MGASA-2026-0156 – Updated nginx packages fix security vulnerabilities
MGASA-2026-0155 – Updated x11-server, x11-server-xwayland & tigervnc packages fix security vulnerabilities
MGASA-2026-0154 – Updated perl-Imager packages fix security vulnerabilities
MGASA-2026-0153 – Updated ffmpeg packages fix security vulnerabilities
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Update to 9.18.49 (rhbz#2480121) Security Fixes: Limit resolver server list size. (CVE-2026-3592) Fix GSS-API resource leak. (CVE-2026-3039) Disable recursion, UPDATE, and NOTIFY for non-IN views. (CVE-2026-5946)
Update to 9.18.49 (rhbz#2480121) Security Fixes: Limit resolver server list size. (CVE-2026-3592) Fix GSS-API resource leak. (CVE-2026-3039) Disable recursion, UPDATE, and NOTIFY for non-IN views. (CVE-2026-5946)
Update to 20260519: ASoC: tas2783: Add Firmware files for tas2783A projects add firmware for MT7927 WiFi device Add HP ISH firmware for Intel Panther Lake systems ti: Add PCM6240 firmware with multiple audio profiles support
Update to latest upstream release https://forum.torproject.org/t/security- release-0-4-8-25-and-0-4-9-8/21559
Update to 1.25.1 (rhbz#2480119) Fix CVE-2026-33278, Possible remote code execution during DNSSEC validation. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-42944, Heap overflow and crash with multiple nsid, cookie, padding EDNS options. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Update to latest upstream release https://forum.torproject.org/t/security- release-0-4-8-25-and-0-4-9-8/21559
https://security-tracker.debian.org/tracker/DSA-6297-1
Several security issues were fixed in NLTK.
Several security issues were fixed in Vim.
An update that solves 13 vulnerabilities can now be installed.
An update that solves two vulnerabilities and contains one feature can now be installed.
An update that solves six vulnerabilities can now be installed.
An update that solves six vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves four vulnerabilities can now be installed.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
New kernel packages are available for Slackware 15.0 and -current to fix a security issue.
An update that solves 5 vulnerabilities can now be installed.
An update that solves 6 vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves 4 vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
https://security-tracker.debian.org/tracker/DSA-6296-1
https://security-tracker.debian.org/tracker/DSA-6295-1
The 6.19.14-108 stable kernel update contains a couple if important security fixes.
Update to .NET SDK 8.0.127 and Runtime 8.0.27 Fixes: CVE-2026-32175,CVE-2026-32177,CVE-2026-35433,CVE-2026-42899 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.27/8.0.127.md
Update to .NET SDK 9.0.117 and Runtime 9.0.16 Fixes: CVE-2026-32175,CVE-2026-32177,CVE-2026-35433,CVE-2026-42899 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.16/9.0.117.md
Update to .NET SDK 10.0.108 and Runtime 10.0.8 Fixes: CVE-2026-32175,CVE-2026-32177,CVE-2026-35433,CVE-2026-42899 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.8/10.0.108.md
Update to release v0.30.0 Resolves CVE-2026-39984: rhbz#2458929 Upstream new features and fixes
Update to release v0.34.0 Resolves: rhbz#2467576 Resolves CVE-2026-39984: rhbz#2458930 Upstream new features and fixes
A new prerelease of Python 3.15 with fixes to several CVEs.
Update NSS to 3.123.1 Update to Firefox 151.0
Update NSS to 3.123.1 Update to Firefox 151.0
An update that solves 95 vulnerabilities and has one bug fix can now be installed.
Update to .NET SDK 8.0.127 and Runtime 8.0.27 Fixes: CVE-2026-32175,CVE-2026-32177,CVE-2026-35433,CVE-2026-42899 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.27/8.0.127.md
This update has improvements to generate more secure session IDs (CVE-2026-8503).
Update to .NET SDK 10.0.108 and Runtime 10.0.8 Fixes: CVE-2026-32175,CVE-2026-32177,CVE-2026-35433,CVE-2026-42899 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.8/10.0.108.md
Update to .NET SDK 9.0.117 and Runtime 9.0.16 Fixes: CVE-2026-32175,CVE-2026-32177,CVE-2026-35433,CVE-2026-42899 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.16/9.0.117.md
Update to release v0.30.0 Resolves CVE-2026-39984: rhbz#2458929 Upstream new features and fixes
Update to release v0.34.0 Resolves: rhbz#2467576 Resolves CVE-2026-39984: rhbz#2458930 Upstream new features and fixes
New prerelease of Python 3.15, containing fixes to a few CVEs.
Version 1.4.4 Dependencies Update Composer to 2.9.8 Version 1.4.3 add output check for dnf permission denied thanks to @asgrim and @hackel
Version 2.9.8 – 2026-05-13 Security: Fixed GitHub token validation and disclosure (GHSA-f9f8-rm49-7jv2)
An update that solves one vulnerability can now be installed.
Multiple vulnerabilities were discovered in Node.js, which could result in denial of service or information disclosure. For Debian 11 bullseye, these problems have been fixed in version 12.22.12~dfsg-1~deb11u8. We recommend that you upgrade your nodejs packages.
Fix command injection CVE-2026-46529
2.33.1 (2026-03-30) Bugfixes – Fixed test cleanup for CVE-2026-25645 to avoid leaving unnecessary files in the tmp directory. – Fixed Content-Type header parsing for malformed values.
2.33.1 (2026-03-30) Bugfixes – Fixed test cleanup for CVE-2026-25645 to avoid leaving unnecessary files in the tmp directory. – Fixed Content-Type header parsing for malformed values.
new version 2.4.67
https://security-tracker.debian.org/tracker/DSA-6294-1
https://security-tracker.debian.org/tracker/DSA-6293-1
https://security-tracker.debian.org/tracker/DSA-6292-1
https://security-tracker.debian.org/tracker/DSA-6291-1
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For the stable distribution (trixie), these problems have been fixed in version 6.12.90-1. Additionally this update includes a fix for a
It was discovered that an incorrect implementation of ECDH encryption (with NIST, Brainpool, X448, or X25519 curves) within Libgcrypt could result in denial of service. For the oldstable distribution (bookworm), this problem has been fixed in version 1.10.1-3+deb12u1.
It was discovered that atril, a simple multi-page document viewer, is prone to a command injection vulnerability if a specially crafted PDF file is opened. For Debian 11 bullseye, this problem has been fixed in version 1.24.0-1+deb11u2.
Cem Onat Karagun discovered two vulnerabilities in the NegoEx parsing in krb5, the MIT implementation of Kerberos. An unauthenticated remote attacker can take advantage of these flaws to cause a denial of service. For the oldstable distribution (bookworm), this problem has been fixed in version 1.20.1-2+deb12u5.
Watch out for bogus World Cup websites that mimic official ticket and merchandise flows to steal money and personal data
An update that fixes one vulnerability is now available.
Update to 148.0.7778.178 CVE-2026-9111: Use after free in WebRTC CVE-2026-9110: Inappropriate implementation in UI CVE-2026-9112: Use after free in GPU CVE-2026-9113: Out of bounds read in GPU
Update to .NET SDK 8.0.127 and Runtime 8.0.27 Fixes: CVE-2026-32175,CVE-2026-32177,CVE-2026-35433,CVE-2026-42899 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.27/8.0.127.md
This update has improvements to generate more secure session IDs (CVE-2026-8503).
Update to .NET SDK 10.0.108 and Runtime 10.0.8 Fixes: CVE-2026-32175,CVE-2026-32177,CVE-2026-35433,CVE-2026-42899 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.8/10.0.108.md
Update to .NET SDK 9.0.117 and Runtime 9.0.16 Fixes: CVE-2026-32175,CVE-2026-32177,CVE-2026-35433,CVE-2026-42899 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.16/9.0.117.md
Update to release v0.34.0 Resolves: rhbz#2467576 Resolves CVE-2026-39984: rhbz#2458930 Upstream new features and fixes
Update to release v0.30.0 Resolves CVE-2026-39984: rhbz#2458929 Upstream new features and fixes
New prerelease of Python 3.15 with several CVE fixes
Version 1.4.4 Dependencies Update Composer to 2.9.8 Version 1.4.3 add output check for dnf permission denied thanks to @asgrim and @hackel
Version 2.9.8 – 2026-05-13 Security: Fixed GitHub token validation and disclosure (GHSA-f9f8-rm49-7jv2)
An update that solves 14 vulnerabilities can now be installed.
An update that solves 20 vulnerabilities can now be installed.
