Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Security fix for CVE-2026-4519.

Rebuilt with rust-tar 0.4.45 for CVE-2026-33056

Rebuilt with rust-tar 0.4.45 for CVE-2026-33056

https://security-tracker.debian.org/tracker/DSA-6181-1

AI security: Identity and access control

MGASA-2026-0071 – Updated nodejs packages fix security vulnerabilities

MGASA-2026-0070 – Updated libpng packages fix security vulnerabilities

Update to 146.0.7680.164 * High CVE-2026-4673: Heap buffer overflow in WebAudio * High CVE-2026-4674: Out of bounds read in CSS * High CVE-2026-4675: Heap buffer overflow in WebGL * High CVE-2026-4676: Use after free in Dawn

Update to v2.0.52

Update to 1.23.1

Update to 1.23.1

https://security-tracker.debian.org/tracker/DSA-6182-1

https://security-tracker.debian.org/tracker/DSA-6180-1

https://security-tracker.debian.org/tracker/DSA-6179-1

An update that solves seven vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves nine vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

https://security-tracker.debian.org/tracker/DSA-6178-1

What does “AI security” mean and why does it matter to your business?

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves nine vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that solves 10 vulnerabilities can now be installed.

Update to 146.0.7680.164 * High CVE-2026-4673: Heap buffer overflow in WebAudio * High CVE-2026-4674: Out of bounds read in CSS * High CVE-2026-4675: Heap buffer overflow in WebGL * High CVE-2026-4676: Use after free in Dawn

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 146.0.7680.164-1~deb12u1.

Update to release v1.9.1

Update to 146.0.7680.153 * CVE-2026-4439: Out of bounds memory access in WebGL * CVE-2026-4440: Out of bounds read and write in WebGL * CVE-2026-4441: Use after free in Base * CVE-2026-4442: Heap buffer overflow in CSS

Update to version 1.3.1 to fix CVE-2026-28356.

Update to release v1.9.1 Resolves: rhbz#2448053, rhbz#2423997, rhbz#2424031 Upstream fixes

Update to 146.0.7680.153 * CVE-2026-4439: Out of bounds memory access in WebGL * CVE-2026-4440: Out of bounds read and write in WebGL * CVE-2026-4441: Use after free in Base * CVE-2026-4442: Heap buffer overflow in CSS

https://security-tracker.debian.org/tracker/DSA-6177-1

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

An update that solves 11 vulnerabilities and has two security fixes can now be installed.

An update that solves 11 vulnerabilities and has two security fixes can now be installed.

An update that solves one vulnerability and has two security fixes can now be installed.

An update that solves one vulnerability and has two security fixes can now be installed.

https://security-tracker.debian.org/tracker/DSA-6175-1

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Net-CIDR could allow unintended access to network services.

Debian Goodies could be made to crash or run programs as your login if it opened a specially crafted file.

# Security update for helm Announcement ID: SUSE-SU-2026:0948-1 Release Date: 2026-03-20T18:07:28Z Rating: important References:

https://security-tracker.debian.org/tracker/DSA-6176-1

https://security-tracker.debian.org/tracker/DSA-6173-1

Jul Blobul discovered that SPIP, a website engine for publishing, is prone to a privilege escalation vulnerability. For the stable distribution (trixie), this problem has been fixed in version 4.4.13+dfsg-0+deb13u1. We recommend that you upgrade your spip packages.

Update to 146.0.7680.80 * CVE-2026-3909: Out of bounds write in Ski

Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

https://security-tracker.debian.org/tracker/DSA-6174-1

https://security-tracker.debian.org/tracker/DSA-6171-1

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43214 shandikri discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex

Upstream announcements: WordPress 6.9.2 Release WordPress 6.9.3 and 7.0 beta 4 WordPress 6.9.4 Release

Update to 1.73.3; Fixes: RHBZ#2426392, RHBZ#2415186

Update to 0.37.1 (rbhz#2445943) Fixes Denial of Service via malformed Content-Length header (CVE-2026-31870 Reenables 32-bit build Update to 0.37.0 (rhbz#2441656)

Add patch for CVE-2026-1539 (Also remove Proxy-Authorization header on cross origin redirect)

https://security-tracker.debian.org/tracker/DSA-6172-1

https://security-tracker.debian.org/tracker/DSA-6170-1

https://security-tracker.debian.org/tracker/DSA-6169-1

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Introducing OpenShift Service Mesh 3.3 with post-quantum cryptography

CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex

This is the March 2026 release of .NET 10. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.4/10.0.104.md Runtime: https://github.com/dotnet/core/blob/main/release-

Fix CVE-2026-31812: Bump quinn-proto to 0.11.14 – Closes rhbz#2446359

Update to 146.0.7680.80 * CVE-2026-3909: Out of bounds write in Ski

https://security-tracker.debian.org/tracker/DSA-6168-1

An update that solves one vulnerability can now be installed.

Several security issues were fixed in python2.7

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-6167-1

https://security-tracker.debian.org/tracker/DSA-6166-1

n8n 1.122.0 Critical RCE Auth Bypass Exploit CVE-2025-68613

Important: libpng security update

Flask could be made to expose sensitive information over the network.

USN-8102-1 introduced a regression in snapd

# Security update for container-suseconnect Announcement ID: SUSE-SU-2026:0909-1 Release Date: 2026-03-17T17:34:35Z Rating: important References:

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

Important: libvpx security update

Several security issues were fixed in the Linux kernel.

Important: container-tools:rhel8 security update

Important: container-tools:rhel8 security update

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Update to openexr-3.4.6 resp 3.3.8.

Linux Kernel eBPF Monitoring Rootkit Threats and Evasion Techniques

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. Google is aware that exploits for both CVEs exist in the wild. For the oldstable distribution (bookworm), these problems have been fixed