Jul Blobul discovered that SPIP, a website engine for publishing, is prone to a privilege escalation vulnerability. For the stable distribution (trixie), this problem has been fixed in version 4.4.13+dfsg-0+deb13u1. We recommend that you upgrade your spip packages.
Update to 146.0.7680.80 * CVE-2026-3909: Out of bounds write in Ski
Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens
Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.
Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens
Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.
https://security-tracker.debian.org/tracker/DSA-6174-1
https://security-tracker.debian.org/tracker/DSA-6171-1
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43214 shandikri discovered that processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex
Upstream announcements: WordPress 6.9.2 Release WordPress 6.9.3 and 7.0 beta 4 WordPress 6.9.4 Release
Update to 1.73.3; Fixes: RHBZ#2426392, RHBZ#2415186
Update to 0.37.1 (rbhz#2445943) Fixes Denial of Service via malformed Content-Length header (CVE-2026-31870 Reenables 32-bit build Update to 0.37.0 (rhbz#2441656)
Add patch for CVE-2026-1539 (Also remove Proxy-Authorization header on cross origin redirect)
https://security-tracker.debian.org/tracker/DSA-6172-1
https://security-tracker.debian.org/tracker/DSA-6170-1
https://security-tracker.debian.org/tracker/DSA-6169-1
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex
This is the March 2026 release of .NET 10. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.4/10.0.104.md Runtime: https://github.com/dotnet/core/blob/main/release-
Fix CVE-2026-31812: Bump quinn-proto to 0.11.14 – Closes rhbz#2446359
Update to 146.0.7680.80 * CVE-2026-3909: Out of bounds write in Ski
https://security-tracker.debian.org/tracker/DSA-6168-1
An update that solves one vulnerability can now be installed.
Several security issues were fixed in python2.7
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-6167-1
https://security-tracker.debian.org/tracker/DSA-6166-1
Important: libpng security update
Flask could be made to expose sensitive information over the network.
USN-8102-1 introduced a regression in snapd
# Security update for container-suseconnect Announcement ID: SUSE-SU-2026:0909-1 Release Date: 2026-03-17T17:34:35Z Rating: important References:
An update that solves three vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
Important: libvpx security update
Several security issues were fixed in the Linux kernel.
Important: container-tools:rhel8 security update
Important: container-tools:rhel8 security update
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
Update to openexr-3.4.6 resp 3.3.8.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. Google is aware that exploits for both CVEs exist in the wild. For the oldstable distribution (bookworm), these problems have been fixed
Update to 146.0.7680.71 CVE-2026-3913: Heap buffer overflow in WebML CVE-2026-3914: Integer overflow in WebML CVE-2026-3915: Heap buffer overflow in WebML CVE-2026-3916: Out of bounds read in Web Speech
Update to pgadmin4-9.13.
Update to qgis-3.44.8.
https://security-tracker.debian.org/tracker/DSA-6165-1
New upstream snapshot. Fixes CVEs 2025-11494, 2025-11495, 2026-2341, 2026-3441, 2026-3442. Fixes CVEs 2025-69644, 2025-69645, 2025-69646. Fixes FTBFS. Relax BR of itcl/itk/iwidgets.
Rebased pcs to the newest major version (see CHANGELOG.md) Updated standalone web UI and HA Cluster Management Cockpit application to pcs- web-ui 0.1.24.2 (see CHANGELOG_WUI.md) Fixed FTBFS with Python 3.15 Fixed issues with installing pcs on Fedora 43+, upgrade and uninstall
Initial build after rename and update to 0.31.1
New version 4.6.4
Update to 1.89.0 Update to 1.88.0
0.9.31
Latest upstream snapshot from stable-2.0 branch. Fixes CVE-2025-14369 in bundled dr_flac.
Update to 3.23.0 to fix CVE-2026-26965, CVE-2026-26955, CVE-2026-26271, CVE-2026-25997, CVE-2026-25959, CVE-2026-25955, CVE-2026-25954, CVE-2026-25953, CVE-2026-25952, CVE-2026-25942, CVE-2026-25941
Update to 146.0.7680.71 * CVE-2026-3913: Heap buffer overflow in WebML * CVE-2026-3914: Integer overflow in WebML * CVE-2026-3915: Heap buffer overflow in WebML * CVE-2026-3916: Out of bounds read in Web Speech
Latest upstream snapshot from stable-2.0 branch. Fixes CVE-2025-14369 in bundled dr_flac.
Latest snapshot from 3.0 branch. Fixes CVE-2025-14369.
MGASA-2026-0057 – Updated python-nltk packages fix security vulnerability
https://security-tracker.debian.org/tracker/DSA-6164-1
https://security-tracker.debian.org/tracker/DSA-6163-1
https://security-tracker.debian.org/tracker/DSA-6162-1
https://security-tracker.debian.org/tracker/DSA-6161-1
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. The Qualys Threat Research Unit (TRU) discovered several vulnerabilities in Apparmor. Details can be found in the Qualys advisory at
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. The Qualys Threat Research Unit (TRU) discovered several vulnerabilities in Apparmor. Details can be found in the Qualys advisory at
An update that solves two vulnerabilities and has one security fix can now be installed.
FreeType could be made to leak sensitive information.
Rebuilt with updated dr_wav to fix CVE-2026-29022
Update to new release, includes updated dependencies that fix for a number of CVEs
https://security-tracker.debian.org/tracker/DSA-6160-1
An update that solves three vulnerabilities and has one security fix can now be installed.
An update that solves three vulnerabilities and has one security fix can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves 37 vulnerabilities can now be installed.
An update that solves 37 vulnerabilities can now be installed.
https://security-tracker.debian.org/tracker/DSA-6159-1
GeoPandas could be vulnerable to SQL injection attacks.
An update that solves seven vulnerabilities and has one security fix can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
0.011 – Update data pointer on resize for rdrand; Clean up string length handling 0.010 – Disallow requesting strings with negative lengths CVE-2026-2597; Try arc4random in stdlib.h first; Correct value of PROTOTYPES keyword in XS
0.011 – Update data pointer on resize for rdrand; Clean up string length handling 0.010 – Disallow requesting strings with negative lengths CVE-2026-2597; Try arc4random in stdlib.h first; Correct value of PROTOTYPES keyword in XS
https://security-tracker.debian.org/tracker/DSA-6158-1
An update that solves two vulnerabilities and has one security fix can now be installed.
An update that solves two vulnerabilities and has one security fix can now be installed.
Update to 145.0.7632.159 CVE-2026-3536: Integer overflow in ANGLE CVE-2026-3537: Object lifecycle issue in PowerVR CVE-2026-3538: Integer overflow in Skia CVE-2026-3539: Object lifecycle issue in DevTools
Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact. The functions addr2cidr and cidrlookup may return leading zeros in a CIDR string, which may in turn be parsed as octal numbers by subsequent users. Current versions of the module strip leading zeros from octets.
Update to 1.3.2.
Update to 145.0.7632.159 CVE-2026-3536: Integer overflow in ANGLE CVE-2026-3537: Object lifecycle issue in PowerVR CVE-2026-3538: Integer overflow in Skia CVE-2026-3539: Object lifecycle issue in DevTools
An update that solves one vulnerability can now be installed.
