Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Security update

Security update

Ubuntu Kylin Software Center could be made to run programs as an administrator if it received specially crafted input via its D-Bus service.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that fixes 5 vulnerabilities is now available.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 5 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Mistral could be made to expose sensitive information or run code.

Langflow 1.9.0 Advisory CVE-2026-5027 High File Write Threat
After Years of Supply Chain Attacks, npm Is Finally Closing the Door on Auto-Scripts
How to Find and Secure Exposed Services on Linux
Actively Exploited Chromium V8 Zero-Day: What Linux Admins Need to Know

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Crypt-SaltedHash incorrectly generated random numbers.

It was discovered that a udev helper provided by libinput, a input device management and event handling library, performed insufficient sanitising of device properties, which can result in local privilege escalation in some setups. For the oldstable distribution (bookworm), this problem has been fixed

Two vulnerabilities were discovered in libdbi-perl, a Perl framework that provides a common interface to access various backend databases in a uniform manner, which may result in denial of service, or potentially the execution of arbitrary code. For the oldstable distribution (bookworm), these problems have been fixed

Security update

Fixes XML external entity vulnerability. For more information, refer to https://src.fedoraproject.org/rpms/xmlstarlet/pull-request/4.

Update to Rust 1.96.0: New Range* types Assert matching patterns Changes to WebAssembly targets Stabilized APIs

new version 2.4.68 fixes various security issues

Fixes XML external entity vulnerability. For more information, refer to https://src.fedoraproject.org/rpms/xmlstarlet/pull-request/4.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves one vulnerability and contains one feature can now be installed.

https://security-tracker.debian.org/tracker/DSA-6341-1

https://security-tracker.debian.org/tracker/DSA-6338-1

https://security-tracker.debian.org/tracker/DSA-6339-1

https://security-tracker.debian.org/tracker/DSA-6340-1

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 149.0.7827.102-1~deb12u1.

A flaw was discovered in jackson-core, a fast and powerful JSON library for Java, which may allow an attacker to cause a denial of service by using deeply nested JSON data. Please note that related and complementary jackson-* packages like jackson- databind or jackson-dataformat-smile had to be upgraded as well in

https://security-tracker.debian.org/tracker/DSA-6335-1

https://security-tracker.debian.org/tracker/DSA-6334-1

https://security-tracker.debian.org/tracker/DSA-6333-1

https://security-tracker.debian.org/tracker/DSA-6332-1

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Security update

Security update

HTTP-Daemon could be made to run programs if it received specially crafted network traffic.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves 12 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 4 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

USN-6455-1 introduced a regression in Exim

An update that solves one vulnerability can now be installed.

An update that solves six vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves three vulnerabilities and has one security fix can now be installed.

An update that solves three vulnerabilities and has one security fix can now be installed.

Several vulnerabilities have been discovered in dnsmasq, a caching DNS proxy and DHCP/TFTP server. CVE-2026-2291 dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries,

Several security issues were fixed in Tomcat.

Security update

Security update

Security update

Security update

Security update

Security update