Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Jul Blobul discovered that SPIP, a website engine for publishing, is prone to a privilege escalation vulnerability. For the stable distribution (trixie), this problem has been fixed in version 4.4.13+dfsg-0+deb13u1. We recommend that you upgrade your spip packages.

Update to 146.0.7680.80 * CVE-2026-3909: Out of bounds write in Ski

Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

https://security-tracker.debian.org/tracker/DSA-6174-1

https://security-tracker.debian.org/tracker/DSA-6171-1

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43214 shandikri discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex

Upstream announcements: WordPress 6.9.2 Release WordPress 6.9.3 and 7.0 beta 4 WordPress 6.9.4 Release

Update to 1.73.3; Fixes: RHBZ#2426392, RHBZ#2415186

Update to 0.37.1 (rbhz#2445943) Fixes Denial of Service via malformed Content-Length header (CVE-2026-31870 Reenables 32-bit build Update to 0.37.0 (rhbz#2441656)

Add patch for CVE-2026-1539 (Also remove Proxy-Authorization header on cross origin redirect)

https://security-tracker.debian.org/tracker/DSA-6172-1

https://security-tracker.debian.org/tracker/DSA-6170-1

https://security-tracker.debian.org/tracker/DSA-6169-1

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Introducing OpenShift Service Mesh 3.3 with post-quantum cryptography

CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex

This is the March 2026 release of .NET 10. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.4/10.0.104.md Runtime: https://github.com/dotnet/core/blob/main/release-

Fix CVE-2026-31812: Bump quinn-proto to 0.11.14 – Closes rhbz#2446359

Update to 146.0.7680.80 * CVE-2026-3909: Out of bounds write in Ski

https://security-tracker.debian.org/tracker/DSA-6168-1

An update that solves one vulnerability can now be installed.

Several security issues were fixed in python2.7

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-6167-1

https://security-tracker.debian.org/tracker/DSA-6166-1

n8n 1.122.0 Critical RCE Auth Bypass Exploit CVE-2025-68613

Important: libpng security update

Flask could be made to expose sensitive information over the network.

USN-8102-1 introduced a regression in snapd

# Security update for container-suseconnect Announcement ID: SUSE-SU-2026:0909-1 Release Date: 2026-03-17T17:34:35Z Rating: important References:

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

Important: libvpx security update

Several security issues were fixed in the Linux kernel.

Important: container-tools:rhel8 security update

Important: container-tools:rhel8 security update

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Update to openexr-3.4.6 resp 3.3.8.

Linux Kernel eBPF Monitoring Rootkit Threats and Evasion Techniques

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. Google is aware that exploits for both CVEs exist in the wild. For the oldstable distribution (bookworm), these problems have been fixed

Update to 146.0.7680.71 CVE-2026-3913: Heap buffer overflow in WebML CVE-2026-3914: Integer overflow in WebML CVE-2026-3915: Heap buffer overflow in WebML CVE-2026-3916: Out of bounds read in Web Speech

Update to pgadmin4-9.13.

Update to qgis-3.44.8.

https://security-tracker.debian.org/tracker/DSA-6165-1

New upstream snapshot. Fixes CVEs 2025-11494, 2025-11495, 2026-2341, 2026-3441, 2026-3442. Fixes CVEs 2025-69644, 2025-69645, 2025-69646. Fixes FTBFS. Relax BR of itcl/itk/iwidgets.

Rebased pcs to the newest major version (see CHANGELOG.md) Updated standalone web UI and HA Cluster Management Cockpit application to pcs- web-ui 0.1.24.2 (see CHANGELOG_WUI.md) Fixed FTBFS with Python 3.15 Fixed issues with installing pcs on Fedora 43+, upgrade and uninstall

Initial build after rename and update to 0.31.1

New version 4.6.4

Update to 1.89.0 Update to 1.88.0

0.9.31

Latest upstream snapshot from stable-2.0 branch. Fixes CVE-2025-14369 in bundled dr_flac.

Update to 3.23.0 to fix CVE-2026-26965, CVE-2026-26955, CVE-2026-26271, CVE-2026-25997, CVE-2026-25959, CVE-2026-25955, CVE-2026-25954, CVE-2026-25953, CVE-2026-25952, CVE-2026-25942, CVE-2026-25941

Update to 146.0.7680.71 * CVE-2026-3913: Heap buffer overflow in WebML * CVE-2026-3914: Integer overflow in WebML * CVE-2026-3915: Heap buffer overflow in WebML * CVE-2026-3916: Out of bounds read in Web Speech

Latest upstream snapshot from stable-2.0 branch. Fixes CVE-2025-14369 in bundled dr_flac.

Latest snapshot from 3.0 branch. Fixes CVE-2025-14369.

MGASA-2026-0057 – Updated python-nltk packages fix security vulnerability

https://security-tracker.debian.org/tracker/DSA-6164-1

https://security-tracker.debian.org/tracker/DSA-6163-1

https://security-tracker.debian.org/tracker/DSA-6162-1

https://security-tracker.debian.org/tracker/DSA-6161-1

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. The Qualys Threat Research Unit (TRU) discovered several vulnerabilities in Apparmor. Details can be found in the Qualys advisory at

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. The Qualys Threat Research Unit (TRU) discovered several vulnerabilities in Apparmor. Details can be found in the Qualys advisory at

An update that solves two vulnerabilities and has one security fix can now be installed.

Intrusion Detection Systems vs Prevention Systems Snort Overview

FreeType could be made to leak sensitive information.

Rebuilt with updated dr_wav to fix CVE-2026-29022

Update to new release, includes updated dependencies that fix for a number of CVEs

https://security-tracker.debian.org/tracker/DSA-6160-1

An update that solves three vulnerabilities and has one security fix can now be installed.

An update that solves three vulnerabilities and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 37 vulnerabilities can now be installed.

An update that solves 37 vulnerabilities can now be installed.

https://security-tracker.debian.org/tracker/DSA-6159-1

GeoPandas could be vulnerable to SQL injection attacks.

An update that solves seven vulnerabilities and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

0.011 – Update data pointer on resize for rdrand; Clean up string length handling 0.010 – Disallow requesting strings with negative lengths CVE-2026-2597; Try arc4random in stdlib.h first; Correct value of PROTOTYPES keyword in XS

0.011 – Update data pointer on resize for rdrand; Clean up string length handling 0.010 – Disallow requesting strings with negative lengths CVE-2026-2597; Try arc4random in stdlib.h first; Correct value of PROTOTYPES keyword in XS

https://security-tracker.debian.org/tracker/DSA-6158-1

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

Port Scanning Explained: Tools, Techniques, and Best Open-Source Port Scanners for Linux

Update to 145.0.7632.159 CVE-2026-3536: Integer overflow in ANGLE CVE-2026-3537: Object lifecycle issue in PowerVR CVE-2026-3538: Integer overflow in Skia CVE-2026-3539: Object lifecycle issue in DevTools

Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact. The functions addr2cidr and cidrlookup may return leading zeros in a CIDR string, which may in turn be parsed as octal numbers by subsequent users. Current versions of the module strip leading zeros from octets.

Update to 1.3.2.

Update to 145.0.7632.159 CVE-2026-3536: Integer overflow in ANGLE CVE-2026-3537: Object lifecycle issue in PowerVR CVE-2026-3538: Integer overflow in Skia CVE-2026-3539: Object lifecycle issue in DevTools

An update that solves one vulnerability can now be installed.