Two vulnerabilities have been discovered in the Linux kernel that may lead to local privilege escalation. For the oldstable distribution (bookworm), these problems have been fixed in version 6.1.170-3. We recommend that you upgrade your linux packages.
https://security-tracker.debian.org/tracker/DSA-6259-1
https://security-tracker.debian.org/tracker/DSA-6258-1
Two vulnerabilities have been discovered in the Linux kernel that may lead to local privilege escalation. For Debian 11 bullseye, these problems have been fixed in version 5.10.251-4. We recommend that you upgrade your linux packages.
An update that solves two vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history “for any number” and had been downloaded more than seven million times before being taken down
How come it’s still possible to ‘secure’ an online account with a six-digit string?
Important: git-lfs security update
Multiple vulnerabilities have been discovered in the Apache HTTP server, which may result in remote code execution, privilege escalation, denial of service or information disclosure. For Debian 11 bullseye, these problems have been fixed in version 2.4.67-1~deb11u1.
Lua could be made to crash or run programs as your login if it opened a specially crafted file.
Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes “Content-Length” over “Transfer-Encoding: chunked” when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse
Validate RSA_public_encrypt() result in RSASVE
Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes “Content-Length” over “Transfer-Encoding: chunked” when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse
https://security-tracker.debian.org/tracker/DSA-6257-1
https://security-tracker.debian.org/tracker/DSA-6256-1
https://security-tracker.debian.org/tracker/DSA-6255-1
https://security-tracker.debian.org/tracker/DSA-6254-1
https://security-tracker.debian.org/tracker/DSA-6253-1
https://security-tracker.debian.org/tracker/DSA-6249-1
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
https://security-tracker.debian.org/tracker/DSA-6252-1
https://security-tracker.debian.org/tracker/DSA-6251-1
https://security-tracker.debian.org/tracker/DSA-6250-1
ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games
Important: golang security update
Important: grafana-pcp security update
Moderate: freeipmi security update
Important: grafana security update
Important: dovecot security update
Important: kernel security update
https://security-tracker.debian.org/tracker/DSA-6248-1
An update that solves six vulnerabilities can now be installed.
An update that solves five vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
Multiple vulnerabilities have been discovered in libarchive, a multi-format archive and compression C library, which also provides the following command-line tools: bsdcat, bsdcpio, bsdtar and bsdunzip. CVE-2026-4111 A flaw was identified in the RAR5 archive decompression logic of the
https://security-tracker.debian.org/tracker/DSA-6247-1
