Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For Debian 11 bullseye, these problems have been fixed in version 5.10.251-3.
This update provides various security fixes. Buffer overflow in scanf %mc (CVE-2026-5450) ns_sprintrrf buffer overreads (CVE-2026-6238) ns_sprintrrf buffer overflow in TSIG record processing (CVE-2026-5435) Memory corruption in ungetwc (CVE-2026-5928)
Fix NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356) Add upstream patches to build against openssl 4.0 Make configure.ac work with autoconf 2.73
Fixes security defects GHSA-rpm5-65cw-6hj4, GHSA-x2qx-6953-8485, GHSA-7545-fcxq-7j24, and GHSA-v87r-6q3f-2j67.
oxenstored keeps quota related use counts across domain destruction [XSA-483, CVE-2026-23556] Xenstored DoS via XS_RESET_WATCHES command [XSA-484, CVE-2026-23557] grant table v2 race in status page mapping [XSA-486, CVE-2026-23558] x86: Floating Point Divider State Sampling [XSA-488, CVE-2025-54505]
https://security-tracker.debian.org/tracker/DSA-6244-1
https://security-tracker.debian.org/tracker/DSA-6238-1
Three security vulnerabilities were discovered in libexif, a library to reads and writes EXIF metainformation from and to images files, that can causes crashes or information leaks. CVE-2026-32775 If the exif_mnote_data_get_value function in MakerNotes gets passed
Important: vim security update
Important: libtiff security update
Important: xorg-x11-server-Xwayland security update
Important: yggdrasil-worker-package-manager security update
Important: yggdrasil security update
https://security-tracker.debian.org/tracker/DSA-6239-1
https://security-tracker.debian.org/tracker/DSA-6197-3
https://security-tracker.debian.org/tracker/DSA-6240-1
https://security-tracker.debian.org/tracker/DSA-6242-1
https://security-tracker.debian.org/tracker/DSA-6243-1
Important: vim security update
Important: PackageKit security update
Important: xorg-x11-server security update
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or sandbox escape. For Debian 11 bullseye, these problems have been fixed in version 140.10.1esr-1~deb11u1.
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Several security issues were fixed in OpenSSH.
An update that solves two vulnerabilities and has one security fix can now be installed.
Multiple vulnerabilities where identified in polkit, a toolkit for defining and handling the policy that allows unprivileged processes to speak to privileged processes. CVE-2021-4115 Kevin Backhouse of GitHub Security Lab (GHSL) found that there is a
PackageKit could be made to install packages as the administrator.
An update that solves 14 vulnerabilities and has five security fixes can now be installed.
An update that solves 14 vulnerabilities and has five security fixes can now be installed.
https://security-tracker.debian.org/tracker/DSA-6236-1
https://security-tracker.debian.org/tracker/DSA-6237-1
https://security-tracker.debian.org/tracker/DSA-6231-1
Important: gdk-pixbuf2 security update
Important: firefox security update
Important: kernel security update
Important: sudo security update
Important: grafana security update
Important: firefox security update
https://security-tracker.debian.org/tracker/DSA-6232-1
https://security-tracker.debian.org/tracker/DSA-6233-1
https://security-tracker.debian.org/tracker/DSA-6234-1
https://security-tracker.debian.org/tracker/DSA-6235-1
Several security issues were fixed in nginx.
Pillow could be made to crash if it opened a specially crafted file.
HAProxy could be made to expose sensitive information over the network.
Little CMS could be made to crash or run programs if it opened a specially crafted ICC profile.
ClamAV could be made to crash if it opened a specially crafted HTML file.
Several security issues were fixed in strongSwan.
An update that solves 25 vulnerabilities can now be installed.
Important: kernel-rt security update
Important: kernel-rt security update
Important: kernel-rt security update
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.10.0esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.
https://security-tracker.debian.org/tracker/DSA-6230-1
Backport security patches from OpenSSL 3.5.6
CVE-2026-35385: Fix privilege escalation via scp legacy protocol when not in preserving file mode CVE-2026-35388: Add connection multiplexing confirmation for proxy-mode multiplexing sessions CVE-2026-35387: Fix incomplete application of PubkeyAcceptedAlgorithms and
Fix CVE-2026-35535
Fix CVE-2026-40192.
Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-5713, CVE-2026-6100
Update to 147.0.7727.101 Critical CVE-2026-6296: Heap buffer overflow in ANGLE Critical CVE-2026-6297: Use after free in Proxy Critical CVE-2026-6298: Heap buffer overflow in Skia Critical CVE-2026-6299: Use after free in Prerender
Several security issues were fixed in GStreamer Bad Plugins.
An update that solves 10 vulnerabilities, contains one feature and has one security fix can now be installed.
An update that solves nine vulnerabilities, contains one feature and has one security fix can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
https://security-tracker.debian.org/tracker/DSA-6229-1
Several security issues were fixed in league/commonmark.
Slurm could be made to send data to an arbitrary unix socket on the host.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves six vulnerabilities and has one security fix can now be installed.
An update that solves six vulnerabilities and has one security fix can now be installed.
PackageKit could be made to install packages as the administrator.
Several security issues were fixed in strongSwan.
Multiple security issues were discovered in cpp-httplib, a C++ cross platform HTTP/HTTPS library, which could result in denial of service. For the stable distribution (trixie), these problems have been fixed in version 0.18.7-1+deb13u1. We recommend that you upgrade your cpp-httplib packages.
Maik Schaefer discovered that a TOCTOU race condition in PackageKit (a package management service over a DBus interface) could result in local privilege escalation. For Debian 11 bullseye, this problem has been fixed in version 1.2.2-2+deb11u1.
Multiple vulnerabilities were fixed in strongSwan, an IKE/IPsec suite. CVE-2026-35328 A vulnerability in libtls related to the processing of the supported_versions extension in TLS that can result in an infinite loop.
An update that solves one vulnerability can now be installed.
https://security-tracker.debian.org/tracker/DSA-6224-1
https://security-tracker.debian.org/tracker/DSA-6225-1
