https://security-tracker.debian.org/tracker/DSA-5985-1
Security fixes Bumped the minimum github.com/go-viper/mapstructure/v2 version to 2.3.0 for GHSA-fv92-fjc5-jj9h or GO-2025-3787 Bumped the minimum github.com/NVIDIA/nvidia-container-toolkit version to 1.17.8 for CVE-2025-23266 and CVE-2025-23267
https://security-tracker.debian.org/tracker/DSA-5984-1
Separating truth from fiction is the first step towards making better parenting decisions. Let’s puncture some of the most common misconceptions about online harassment.
How top-tier managed detection and response (MDR) can help organizations stay ahead of increasingly agile and determined adversaries
Update to release v1.32.7 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes
Update to release v1.31.12 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fix
Update to release v1.33.4 Resolves: rhbz#2388412 Fixes CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes
Update to 1.67.0 Update to 1.66.0
Update to release v1.31.12 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fix
Update to release v1.32.7 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes
* bsc#1248006 Cross-References: * CVE-2025-55159
Several security issues were fixed in PHP.
* bsc#1248006 Cross-References: * CVE-2025-55159
Several security issues were fixed in Python.
Update to version 0.4.11. This version includes a fix for CVE-2025-55159, but there are zero packages in Fedora or EPEL that use the affected API, so no rebuilds are necessary.
Update to v1.136.0 Update to 1.135.2 Update to 1.135.0
https://security-tracker.debian.org/tracker/DSA-5983-1
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape or bypass of the same-origin policy.
poppler could be made to denial of service if it received a specially crafted PDF file.
* bsc#1245218 * bsc#1247350 * bsc#1247351 Cross-References:
* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351
https://security-tracker.debian.org/tracker/DSA-5981-1
https://security-tracker.debian.org/tracker/DSA-5982-1
* bsc#1244270 * bsc#1244272 * bsc#1244273 * bsc#1244279 * bsc#1244336
* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351
Several security issues were fixed in Apache HTTP Server.
Several security issues were fixed in libxml2.
* bsc#1012628 * bsc#1139073 * bsc#1204142 * bsc#1210025 * bsc#1211226
https://security-tracker.debian.org/tracker/DSA-5980-1
Can you tell the difference between legitimate marketing and deepfake scam ads? It’s not always as easy as you may think.
* bsc#1242666 * bsc#1243428 Cross-References: * CVE-2025-3416
* bsc#1244631 * bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351
* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351
https://security-tracker.debian.org/tracker/DSA-5979-1
