https://security-tracker.debian.org/tracker/DSA-6226-1
https://security-tracker.debian.org/tracker/DSA-6227-1
https://security-tracker.debian.org/tracker/DSA-6228-1
https://security-tracker.debian.org/tracker/DSA-6223-1
Andrew Nesbitt discovered that .install file directives were insufficiently restricted in OPAM, a package manager for OCaml. This could result in directory traversal out of the package area. For Debian 11 bullseye, this problem has been fixed in version 2.0.8-1+deb11u1.
Yarden Porat found a heap-based buffer overwrite in MuPDF, a lightweight PDF viewer, which may result in denial of service or the execution of arbitrary code if malformed documents are opened. For Debian 11 bullseye, this problem has been fixed in version 1.17.0+ds1-2+deb11u2.
# Security update for rootlesskit Announcement ID: SUSE-SU-2026:1493-1 Release Date: 2026-04-20T15:58:01Z Rating: important References:
An update that can now be installed.
# Security update for rootlesskit Announcement ID: SUSE-SU-2026:1494-1 Release Date: 2026-04-20T15:58:21Z Rating: important References:
# Security update for containerd Announcement ID: SUSE-SU-2026:1495-1 Release Date: 2026-04-20T16:00:19Z Rating: important References:
https://security-tracker.debian.org/tracker/DSA-6221-1
https://security-tracker.debian.org/tracker/DSA-6222-1
An update that solves one vulnerability can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
https://security-tracker.debian.org/tracker/DSA-6220-1
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-6219-1
https://security-tracker.debian.org/tracker/DSA-6217-1
https://security-tracker.debian.org/tracker/DSA-6216-1
https://security-tracker.debian.org/tracker/DSA-6215-1
MGASA-2026-0101 – Updated rsync packages fix security vulnerability
Backport patch for CVE-2026-20884. Backport fixes for CVE-2026-20889 CVE-2026-21413 CVE-2026-24450 CVE-2026-24660 Update to libraw-0.21.5.
Update to version 4.0.6
Fix access/use of uninitialized memory in stb_image
Latest Monkey’s Audio Codec release. Changes: https://monkeysaudio.com/versionhistory.html .
Latest Monkey’s Audio Codec release. Changes: https://monkeysaudio.com/versionhistory.html .
https://security-tracker.debian.org/tracker/DSA-6218-1
Several security issues were fixed in the Linux kernel.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that has one security fix can now be installed.
# Security update for smc-tools Announcement ID: SUSE-SU-2026:1422-1 Release Date: 2026-04-17T07:21:34Z Rating: moderate References:
Several security issues were fixed in the Linux kernel.
https://security-tracker.debian.org/tracker/DSA-6214-1
Important: vim security update
Moderate: pcs security update
Important: firefox security update
Important: nghttp2 security update
Several security issues were fixed in .NET.
An update that solves six vulnerabilities and contains one feature can now be installed.
https://security-tracker.debian.org/tracker/DSA-6211-1
https://security-tracker.debian.org/tracker/DSA-6210-1
An update that solves five vulnerabilities can now be installed.
An update that solves five vulnerabilities can now be installed.
An update that solves five vulnerabilities can now be installed.
An update that solves five vulnerabilities can now be installed.
An update that solves five vulnerabilities can now be installed.
An update that solves five vulnerabilities can now be installed.
https://security-tracker.debian.org/tracker/DSA-6212-1
https://security-tracker.debian.org/tracker/DSA-6213-1
https://security-tracker.debian.org/tracker/DSA-6209-1
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
Important: fontforge security update
Important: perl-XML-Parser security update
It was discovered that gdk-pixbuf, the GDK Pixbuf library, does not properly validate color component counts in the JPEG image loader, which may result in the execution of arbitrary code or denial of service if specially crafted JPEG images are processed. For Debian 11 bullseye, this problem has been fixed in version
Several security issues were fixed in polkit.
BIND a popular name server (DNS) was affected by a vulnerability. If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers
An update that solves two vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves eight vulnerabilities can now be installed.
An update that solves eight vulnerabilities can now be installed.
An update that solves six vulnerabilities can now be installed.
Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure or incomplete permission checks. For the oldstable distribution (bookworm), these problems have been fixed in version 1:1.39.17-1+deb12u2.
Multiple security vulnerabilities were discovered in Flatpak, an application deployment framework for desktop apps, which could allow a Flatpak app to delete arbitrary hosts on the host or break out of the sandbox resulting in code execution in the host context. For the stable distribution (trixie), these problems have been fixed in
MGASA-2026-0096 – Updated libpng12 packages fix security vulnerability
MGASA-2026-0095 – Updated tomcat packages fix security vulnerabilities
MGASA-2026-0094 – Updated squid packages fix security vulnerabilities
Moderate: kernel security update
https://security-tracker.debian.org/tracker/DSA-6207-1
https://security-tracker.debian.org/tracker/DSA-6208-1
Important: kea security update
Several vulnerabilities were discovered in the inetutils implementation of telnetd and telnet, which may result in privilege escalation or information disclosure. CVE-2026-28372 Ron Ben Yizhak from SafeBreach found that the fix for CVE-2026-24061 was
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 140.9.1esr-1~deb11u1.
https://security-tracker.debian.org/tracker/DSA-6206-1
https://security-tracker.debian.org/tracker/DSA-6204-1
An update that solves one vulnerability can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
