An update that fixes 6 vulnerabilities is now available.
Several security issues were fixed in ImageMagick.
Update to 148.0.7778.96 CVE-2026-7896: Integer overflow in Blink CVE-2026-7897: Use after free in Mobile CVE-2026-7898: Use after free in Chromoting CVE-2026-7899: Out of bounds read and write in V8
Update NSS to 3.122.2 Updated to Firefox 150.0.1
Update NSS to 3.122.2 Updated to Firefox 150.0.1
Update NSS to 3.122.2 Update to Firefox 150.0.1
Update NSS to 3.122.2 Update to Firefox 150.0.1
https://security-tracker.debian.org/tracker/DSA-6265-1
Moderate: libpng security update
Moderate: libpng security update
Moderate: freeipmi security update
An update that solves two vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
https://security-tracker.debian.org/tracker/DSA-6264-1
https://security-tracker.debian.org/tracker/DSA-6263-1
https://security-tracker.debian.org/tracker/DSA-6262-1
https://security-tracker.debian.org/tracker/DSA-6261-1
https://security-tracker.debian.org/tracker/DSA-6260-1
Two security vulnerabilities were discovered in the Corosync cluster engine, which could result in denial of service or memory disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 3.1.7-1+deb12u2. For the stable distribution (trixie), these problems have been fixed in
Multiple security vulnerabilities were discovered in Tor, a connection- based low-latency anonymous communication system, which could result in denial of service. For the oldstable distribution (bookworm), these problems have been fixed in version 0.4.9.8-0+deb12u1.
MGASA-2026-0126 – Updated openvpn packages fix security vulnerabilities
33.0.3 Release
This is new version of exim fixing some security bugs.
Update to .NET SDK 10.0.107 and Runtime 10.0.7 Fixes: CVE-2026-40372 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.7/10.0.107.md
It was discovered that PyJWT, a Python implementation of JSON web tokens insufficiently validated the “crit” header parameter, which could result in incomplete enforcement of authentication settings. For the oldstable distribution (bookworm), this problem has been fixed in version 2.6.0-1+deb12u1.
A security vulnerability has been discovered in libpng, a library implementing an interface for reading and writing PNG (Portable Network Graphics) files, which could leading to corrupted chunk data and potential heap information disclosure. For Debian 11 bullseye, this problem has been fixed in version
Two vulnerabilities have been discovered in the Linux kernel that may lead to local privilege escalation. For the oldstable distribution (bookworm), these problems have been fixed in version 6.1.170-3. We recommend that you upgrade your linux packages.
https://security-tracker.debian.org/tracker/DSA-6258-1
https://security-tracker.debian.org/tracker/DSA-6259-1
Two vulnerabilities have been discovered in the Linux kernel that may lead to local privilege escalation. For Debian 11 bullseye, these problems have been fixed in version 5.10.251-4. We recommend that you upgrade your linux packages.
An update that solves two vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
Important: git-lfs security update
Multiple vulnerabilities have been discovered in the Apache HTTP server, which may result in remote code execution, privilege escalation, denial of service or information disclosure. For Debian 11 bullseye, these problems have been fixed in version 2.4.67-1~deb11u1.
Lua could be made to crash or run programs as your login if it opened a specially crafted file.
Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes “Content-Length” over “Transfer-Encoding: chunked” when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse
Validate RSA_public_encrypt() result in RSASVE
Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes “Content-Length” over “Transfer-Encoding: chunked” when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse
https://security-tracker.debian.org/tracker/DSA-6254-1
https://security-tracker.debian.org/tracker/DSA-6255-1
https://security-tracker.debian.org/tracker/DSA-6256-1
https://security-tracker.debian.org/tracker/DSA-6257-1
https://security-tracker.debian.org/tracker/DSA-6253-1
https://security-tracker.debian.org/tracker/DSA-6249-1
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
https://security-tracker.debian.org/tracker/DSA-6250-1
https://security-tracker.debian.org/tracker/DSA-6251-1
https://security-tracker.debian.org/tracker/DSA-6252-1
Important: kernel security update
Important: dovecot security update
Important: grafana security update
Moderate: freeipmi security update
Important: grafana-pcp security update
Important: golang security update
https://security-tracker.debian.org/tracker/DSA-6248-1
An update that solves six vulnerabilities can now be installed.
An update that solves five vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
Multiple vulnerabilities have been discovered in libarchive, a multi-format archive and compression C library, which also provides the following command-line tools: bsdcat, bsdcpio, bsdtar and bsdunzip. CVE-2026-4111 A flaw was identified in the RAR5 archive decompression logic of the
https://security-tracker.debian.org/tracker/DSA-6247-1
curl could be made to expose sensitive information over the network.
Several security issues were fixed in Exim.
sed could be made to overwrite files.
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.10.1esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Important: libcap security update
Important: sudo security update
Important: libcap security update
Update to version 0.6.0. Addresses RUSTSEC-2026-0109.
Fix CVE-2026-6846.
This update provides various security fixes. Buffer overflow in scanf %mc (CVE-2026-5450) ns_sprintrrf buffer overreads (CVE-2026-6238) ns_sprintrrf buffer overflow in TSIG record processing (CVE-2026-5435) Memory corruption in ungetwc (CVE-2026-5928)
https://security-tracker.debian.org/tracker/DSA-6245-1
https://security-tracker.debian.org/tracker/DSA-6246-1
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For Debian 11 bullseye, these problems have been fixed in version 6.1.170-1~deb11u1.
