This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574
This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574
This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574
This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574
Update to 3.12.11. gh-135034: [CVE 2024-12718] [CVE 2025-4138] [CVE 2025-4330] [CVE 2025-4435] [CVE 2025-4517] Fixes multiple issues that allowed tarfile extraction filters (filter=”data” and filter=”tar”) to be bypassed using crafted symlinks and hard links.
Fix CVE-2025-49466 (fedora#2370375)
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5942-1
* bsc#1240750 * bsc#1240752 * bsc#1240754 * bsc#1240756 * bsc#1240757
* bsc#1244035 Cross-References: * CVE-2025-22868 * CVE-2025-22869
* bsc#1237147 * bsc#1241938 * bsc#1243106 Cross-References:
* bsc#1242300 Cross-References: * CVE-2025-47268
* bsc#1232900 * bsc#1236701 * bsc#1239077 * bsc#1239096
* bsc#1236701 * bsc#1239077 * bsc#1239096 Cross-References:
* bsc#1238324 * bsc#1239077 Cross-References: * CVE-2022-49080
* bsc#1243273 Cross-References: * CVE-2025-4516
* bsc#1239949 * bsc#1241050 * bsc#1243217 * bsc#1243218
* bsc#1239949 * bsc#1241050 * bsc#1243217 * bsc#1243218
https://security-tracker.debian.org/tracker/DSA-5941-1
* bsc#1234282 * bsc#1238043 * bsc#1243117 Cross-References:
* bsc#1238324 * bsc#1239077 Cross-References: * CVE-2022-49080
* bsc#1236701 * bsc#1239077 * bsc#1239096 Cross-References:
* bsc#1232900 * bsc#1236701 * bsc#1239077 * bsc#1239096
Several security issues were fixed in tomcat8, tomcat9, tomcat10.
https://security-tracker.debian.org/tracker/DSA-5940-1
DoS with sanitiseArg/sanitizeArg has been fixed in modsecurity-apache, a module for the Apache webserver to tighten Web application security. For Debian 11 bullseye, this problem has been fixed in version
