Important: perl-XML-LibXML security update
Important: nodejs:24 security, bug fix, and enhancement update
Important: python3.12 security update
Update PyO3 to 0.29; addresses RUSTSEC-2026-0176 and RUSTSEC-2026-0177
Release 1.7.2 Add HEAD request handler to the static.php Fix so the oauth_password_claim claim is retrieved via token or userinfo request (#9631) Fix bug where static.php would return a 416 error on a specific Range request
Update to upstream release 0.13.0; update PyO3 to 0.29, fixing RUSTSEC-2026-0176 and RUSTSEC-2026-0177.
Security update
Security update
Security update
Security update
Security update
An update that can now be installed.
An update that solves 15 vulnerabilities and has one security fix can now be installed.
An update that solves seven vulnerabilities can now be installed.
An update that can now be installed.
https://security-tracker.debian.org/tracker/DSA-6390-1
Important: perl-XML-LibXML security update
Important: perl-XML-LibXML security update
An update that solves 14 vulnerabilities can now be installed.
An update that solves 41 vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves eight vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves eight vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves 10 vulnerabilities can now be installed.
Several vulnerabilities were discovered in NTFS-3G, a read-write NTFS driver for FUSE. A local user can take advantage of these flaws for local root privilege escalation. For the stable distribution (trixie), these problems have been fixed in version 1:2022.10.3-5+deb13u2.
ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities
Security update
Security update
Security update
Security update
Security update
Sympa could allow unintended access to network services.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
An update that solves five vulnerabilities can now be installed.
Several security issues were fixed in the Linux kernel.
Several issues were found in the GRUB2 bootloader, which could result in crashes and potentially execution of arbitrary code. These could lead to bypass of UEFI Secure Boot on affected systems. For Debian 11 bullseye, these problems have been fixed in version 2.06-3~deb11u7.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
An update that solves 3 vulnerabilities and has 2 bug fixes can now be installed.
————————————————————-
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.
An update that solves 10 vulnerabilities and has 9 bug fixes can now be installed.
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.
An update that solves one vulnerability and has one bug fix can now be installed.
An update that solves 6 vulnerabilities and has 7 bug fixes can now be installed.
An update that solves 6 vulnerabilities and has 6 bug fixes can now be installed.
An update that solves 5 vulnerabilities and has 8 bug fixes can now be installed.
An update that solves 2 vulnerabilities and has 5 bug fixes can now be installed.
An update that solves 30 vulnerabilities and has 34 bug fixes can now be installed.
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.
Several vulnerabilities were discovered in libXfont, the X11 font rasterisation library, which may result in arbitrary code execution in the X server context for authenticated X clients. For the stable distribution (trixie), these problems have been fixed in version 1:2.0.6-1+deb13u1.
Update to 3.28.0 It fixes CVE-2026-57156, CVE-2026-57157 and CVE-2026-57158.
Kate Deplaix reported that .install file directives were insufficiently restricted in OPAM, a package manager for OCaml. Installing files through .install files did not check symlinks resolution on the target path, which could result in directory traversal out of the package area. For Debian 12 bookworm, this problem has been fixed in version
Multiple vulnerabilities were discovered in wolfSSL, a lightweight, portable, C-language-based SSL/TLS library, which could result in signature forgery, authentication bypass, information disclosure, or denial of service. CVE-2026-5194
Update to 3.28.0 It fixes CVE-2026-57156, CVE-2026-57157 and CVE-2026-57158.
https://security-tracker.debian.org/tracker/DSA-6388-1
Several security issues were fixed in Wget.
An update that contains security fixes can now be installed.
