curl could be made to expose sensitive information over the network.
Several security issues were fixed in Exim.
sed could be made to overwrite files.
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.10.1esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Important: libcap security update
Important: libcap security update
Important: sudo security update
Update to version 0.6.0. Addresses RUSTSEC-2026-0109.
Fix CVE-2026-6846.
This update provides various security fixes. Buffer overflow in scanf %mc (CVE-2026-5450) ns_sprintrrf buffer overreads (CVE-2026-6238) ns_sprintrrf buffer overflow in TSIG record processing (CVE-2026-5435) Memory corruption in ungetwc (CVE-2026-5928)
https://security-tracker.debian.org/tracker/DSA-6246-1
https://security-tracker.debian.org/tracker/DSA-6245-1
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For Debian 11 bullseye, these problems have been fixed in version 6.1.170-1~deb11u1.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For Debian 11 bullseye, these problems have been fixed in version 5.10.251-3.
This update provides various security fixes. Buffer overflow in scanf %mc (CVE-2026-5450) ns_sprintrrf buffer overreads (CVE-2026-6238) ns_sprintrrf buffer overflow in TSIG record processing (CVE-2026-5435) Memory corruption in ungetwc (CVE-2026-5928)
Fix NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356) Add upstream patches to build against openssl 4.0 Make configure.ac work with autoconf 2.73
Fixes security defects GHSA-rpm5-65cw-6hj4, GHSA-x2qx-6953-8485, GHSA-7545-fcxq-7j24, and GHSA-v87r-6q3f-2j67.
oxenstored keeps quota related use counts across domain destruction [XSA-483, CVE-2026-23556] Xenstored DoS via XS_RESET_WATCHES command [XSA-484, CVE-2026-23557] grant table v2 race in status page mapping [XSA-486, CVE-2026-23558] x86: Floating Point Divider State Sampling [XSA-488, CVE-2025-54505]
https://security-tracker.debian.org/tracker/DSA-6244-1
https://security-tracker.debian.org/tracker/DSA-6238-1
Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 – here’s some of what made the headlines this month
Three security vulnerabilities were discovered in libexif, a library to reads and writes EXIF metainformation from and to images files, that can causes crashes or information leaks. CVE-2026-32775 If the exif_mnote_data_get_value function in MakerNotes gets passed
Important: vim security update
Important: yggdrasil security update
Important: yggdrasil-worker-package-manager security update
Important: xorg-x11-server-Xwayland security update
Important: libtiff security update
https://security-tracker.debian.org/tracker/DSA-6243-1
https://security-tracker.debian.org/tracker/DSA-6242-1
https://security-tracker.debian.org/tracker/DSA-6240-1
https://security-tracker.debian.org/tracker/DSA-6197-3
https://security-tracker.debian.org/tracker/DSA-6239-1
