ldns could be made to accept spoofed DNS responses.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
An update that fixes one vulnerability is now available.
Security update
Security update
Security update
A vulnerability was discoverd in Nginx, a high-performance web and reverse proxy server, which could result in remote code execution and denial of service. For Debian 11 bullseye, this problem has been fixed in version 1.18.0-6.1+deb11u7.
An update that solves two vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves six vulnerabilities and contains one feature can now be installed.
# Security update for helm Announcement ID: SUSE-SU-2026:2439-1 Release Date: 2026-06-17T14:48:27Z Rating: important References:
New openssl packages are available for Slackware 15.0 and -current to fix security issues.
New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.
New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.
New libidn packages are available for Slackware 15.0 and -current to fix security issues.
New bind packages are available for Slackware 15.0 and -current to fix a security issue.
# Security update for xwayland Announcement ID: SUSE-SU-2026:2426-1 Release Date: 2026-06-17T09:50:05Z Rating: important References:
An update that solves one vulnerability can now be installed.
njs could be made to crash or run programs if it received a specially crafted input.
ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
Several security issues were fixed in GStreamer Bad Plugins.
graphite2 could be made to crash or run programs if it opened a specially crafted file.
Multiple security vulnerabilities were discovered in LibreOffice, which could result in denial of service or potentially the execution of arbitrary code if malformed files are opened. For Debian 12 bookworm, these problems have been fixed in version 4:7.4.7-1+deb12u13.
The system could be made to run programs as an administrator.
Several security issues were fixed in the Linux kernel.
The system could be compromised under certain conditions.
Update NSS to 3.124.0 Update Firefox to 152.0
Update NSS to 3.124.0 Update Firefox to 152.0
Fix editor command injection vulnerability (only affectsversion 2.6.0). (#1432) https://github.com/jonas/tig/issues/1432
Update to 149.0.7827.114 CVE-2026-12007: Use after free Core CVE-2026-12008: Use after free DigitalCredentials CVE-2026-12009: Insufficient validation of untrusted input Accessibility CVE-2026-12010: Heap buffer overflow GPU
x86 HVM I/O port list traversal [XSA-491, CVE-2026-42487] domctl lock open to abuse [XSA-492, CVE-2026-42489, CVE-2026-42490] Arm: Completion of memory accesses not guaranteed by completion of a TLBI [XSA-493, CVE-2025-10263] x86: mismatched mapcache metadata [XSA-494, CVE-2026-42488]
Update to 1.9.2 for CVE-2026-10846
Version 0.16.0 – 2026-06-08 Security Fix out-of-bounds read via undersized frames in amqp_handle_input (GHSA-9mmv-r8g3-qp46, #878) Fix client crash when server negotiates frame_max below the AMQP protocol
BIRD 3.3.1 (2026-06-09) BGP: Fix crash when incoming connection for disabled protocol arrives BGP: Fix parsing labelled NLRIs with no next hop BGP: Fix cork behavior in collision with graceful restart BGP: Fix crash on dumping pending export statistics
CVE-2026-34253 – fix arbitrary code execution via buffer underflow
33.0.5 Release
This release fixes CVE-2026-10725 (exhausting memory when decompressing request headers). It also improves examples.
Fix arbitrary memory write with crafted Ventana BIF file (CVE-2026-48977).
Fix editor command injection vulnerability (only affectsversion 2.6.0). (#1432) https://github.com/jonas/tig/issues/1432
BIRD 3.3.1 (2026-06-09) BGP: Fix crash when incoming connection for disabled protocol arrives BGP: Fix parsing labelled NLRIs with no next hop BGP: Fix cork behavior in collision with graceful restart BGP: Fix crash on dumping pending export statistics
33.0.5 Release
This release fixes CVE-2026-10725 (exhausting memory when decompressing request headers). It also improves examples.
Fix arbitrary memory write with crafted Ventana BIF file (CVE-2026-48977).
Update to version 3.10.0
Security update
Security update
Security update
# Security update for distribution Announcement ID: SUSE-SU-2026:2413-1 Release Date: 2026-06-16T12:20:29Z Rating: important References:
# Security update for runc Announcement ID: SUSE-SU-2026:2414-1 Release Date: 2026-06-16T12:22:39Z Rating: important References:
# Security update for buildah Announcement ID: SUSE-SU-2026:2415-1 Release Date: 2026-06-16T12:23:37Z Rating: important References:
# Security update for buildah Announcement ID: SUSE-SU-2026:2416-1 Release Date: 2026-06-16T12:24:12Z Rating: important References:
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
