* bsc#1239197 Cross-References: * CVE-2025-22868
* bsc#1208995 * bsc#1220946 * bsc#1225742 * bsc#1232472 * bsc#1232919
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Our digital lives are filled with essential personal information, and it’s easy to forget how vulnerable all that data can be. But if your hard drive crashes, your laptop gets stolen, or you fall victim to cybercrime, the loss can be devastating. Your financial records, your work files, and even years of family photos can […]
* bsc#1237377 Cross-References: * CVE-2025-0633
Several security issues were fixed in Jinja2.
Several security issues were fixed in opensc.
.NET could be made to elevate privileges.
An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings. (CVE-2025-26699)
Jinja sandbox breakout through attr filter selecting format method. (CVE-2025-27516) References: – https://bugs.mageia.org/show_bug.cgi?id=34081
https://security-tracker.debian.org/tracker/DSA-5877-1
* bsc#1208995 * bsc#1220946 * bsc#1225742 * bsc#1232472 * bsc#1232919
* bsc#1208995 * bsc#1220946 * bsc#1224700 * bsc#1225742 * bsc#1232905
* bsc#1050081 * bsc#1051510 * bsc#1065729 * bsc#1100823 * bsc#1101669
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
* bsc#1237681 Cross-References: * CVE-2025-27144
* bsc#1237681 Cross-References: * CVE-2025-27144
* bsc#1236531 * bsc#1237681 Cross-References: * CVE-2023-45288
Update to 134.0.6998.35 * CVE-2025-1914: Out of bounds read in V8 * CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools * CVE-2025-1916: Use after free in Profiles
Unbundle libxml2.
Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For the stable distribution (bookworm), these problems have been fixed in
Two vulnerabilities were discovered in openvpn, a virtual private network application which could result in authentication bypass or data injection.
High CVE-2025-1914: Out of bounds read in V8. Medium CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools. Medium CVE-2025-1916: Use after free in Profiles. Medium CVE-2025-1917: Inappropriate Implementation in Browser UI.
Update to 134.0.6998.35 * CVE-2025-1914: Out of bounds read in V8 * CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools * CVE-2025-1916: Use after free in Profiles
The newest upstream commit Security fix for CVE-2025-27423
update to version 2.25.1, CVE-2025-27154
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2. (CVE-2023-5520) Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV. (CVE-2024-0321) Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
https://security-tracker.debian.org/tracker/DSA-5876-1
https://security-tracker.debian.org/tracker/DSA-5875-1
Several security issues were fixed in the Linux kernel.
Updated to latest upstream (136.0)
