Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact. The functions addr2cidr and cidrlookup may return leading zeros in a CIDR string, which may in turn be parsed as octal numbers by subsequent users. Current versions of the module strip leading zeros from octets.

Update to 1.3.2.

Update to 145.0.7632.159 CVE-2026-3536: Integer overflow in ANGLE CVE-2026-3537: Object lifecycle issue in PowerVR CVE-2026-3538: Integer overflow in Skia CVE-2026-3539: Object lifecycle issue in DevTools

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

Update to 2.87.3

Update to 145.0.7632.116 * CVE-2026-3061: Out of bounds read in Media * CVE-2026-3062: Out of bounds read and write in Tint * CVE-2026-3063: Inappropriate implementation in DevTools

Update to 2.69.4

Rename from golang-github-prometheus and upgrade to 3.10.0

hex_core ver. 0.12.2

Rename from golang-honnef-tools and update to 2026.1

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 145.0.7632.159-1~deb12u1.

Important: postgresql16 security update

Important: postgresql16 security update

https://security-tracker.debian.org/tracker/DSA-6157-1

MCP security: Implementing robust authentication and authorization
Linux Security Strategies for Cloud and IoT Environments

https://security-tracker.debian.org/tracker/DSA-6155-1

https://security-tracker.debian.org/tracker/DSA-6156-1

https://security-tracker.debian.org/tracker/DSA-6154-1

AI trust through open collaboration: A new chapter for responsible innovation

https://security-tracker.debian.org/tracker/DSA-6153-1

What Is ClamAV? A Linux Admins Guide to Risk, Monitoring, and Real-World Use

https://security-tracker.debian.org/tracker/DSA-6152-1

Understanding the Snort NIDS: What It Changes in Your Monitoring and Risk Model

https://security-tracker.debian.org/tracker/DSA-6151-1

The nervous system gets a soul: why sovereign cloud is telco’s real second act

https://security-tracker.debian.org/tracker/DSA-6149-1

https://security-tracker.debian.org/tracker/DSA-6150-1

What Is Fail2ban?
MCP security: The current situation

https://security-tracker.debian.org/tracker/DSA-6148-1

Chasing the holy grail: Why Red Hat’s Hummingbird project aims for “near zero” CVEs
Extend trust across the software supply chain with Red Hat trusted libraries
Zero CVEs: The symptom of a larger problem
From challenge to champion: Elevate your vulnerability management strategy

https://security-tracker.debian.org/tracker/DSA-6124-1

Several security issues were fixed in pip.

An update that solves 76 vulnerabilities and contains one feature can now be installed.

An update that solves 76 vulnerabilities and contains one feature can now be installed.

An update that solves one vulnerability can now be installed.

Update to 1.10.2 Update was blocked by a ppc64 issue, but a workaround has been found.

Update to version 1.2026.1

https://security-tracker.debian.org/tracker/DSA-6127-1

https://security-tracker.debian.org/tracker/DSA-6125-1

https://security-tracker.debian.org/tracker/DSA-6126-1

AI insights with actionable automation accelerate the journey to autonomous networks

Update to 144.0.7559.132 * CVE-2026-1861: Heap buffer overflow in libvpx * CVE-2026-1862: Type Confusion in V8

Update to version 0.50.18

Backport fixes for CVE-2026-1484, CVE-2026-1485, CVE-2026-1489.

Update to version 1.9.2. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.9.2

Release notes for xrdp v0.10.5 (2026/01/27) Security fixes CVE-2025-68670: Improper bounds checking of domain string length leads to Stack- based Buffer Overflow New features

Release notes for xrdp v0.10.5 (2026/01/27) Security fixes CVE-2025-68670: Improper bounds checking of domain string length leads to Stack- based Buffer Overflow New features

Denis Skvortsov discovered that xrdp, a Remote Desktop Protocol (RDP) server, was susceptible to an unauthenticated stack-based buffer overflow vulnerability, which may result in remote execution of arbitrary code. For the oldstable distribution (bookworm), this problem has been fixed

What Is TLS (Transport Layer Security) in Linux Security?

Update to 9.18.44 (rhbz#2431609) Security Fixes: Fix incorrect length checks for BRID and HHIT records. (CVE-2025-13878) Bug Fixes: Allow glue in delegations with QTYPE=ANY.

Update to 9.18.44 (rhbz#2431609) Security Fixes: Fix incorrect length checks for BRID and HHIT records. (CVE-2025-13878) Bug Fixes: Allow glue in delegations with QTYPE=ANY.

Update to 13.0.10.

An update that fixes one vulnerability, contains one feature is now available.

https://security-tracker.debian.org/tracker/DSA-6123-1

Sudo, a program designed to allow a sysadmin to give limited root privileges to users and log root activity, was affected by multiple vulnerabilities. CVE-2023-28486 Sudo did not escape control characters in log messages.

https://security-tracker.debian.org/tracker/DSA-6122-1

https://security-tracker.debian.org/tracker/DSA-6121-1

https://security-tracker.debian.org/tracker/DSA-6120-1

https://security-tracker.debian.org/tracker/DSA-6119-1

MGASA-2026-0032 – Updated python-django packages fix security vulnerabilities

MGAA-2026-0011 – Updated yt-dlp packages fix bugs

This update bumps the bundled lodash to 4.17.23 to ensure openQA is protected against CVE-2025-13465. It likely was not vulnerable in any case, though, as I don’t believe the vulnerable codepaths were exposed by openQA’s use of lodash.

Regenerate vendor tarball. Fixes CVE-2025-13465.

Regenerate vendor tarball. Fixes CVE-2025-13465.

Version 12.5.8 – 2026-01-27 Changed To prevent Poisoned Pipeline Execution (PPE) attacks using prepared .coverage files in pull requests, a PHPT test will no longer be run if the temporary file for writing code coverage information already exists before the test runs

Multiple vulnerabilities were discovered in containerd, an open-source container runtime, used by e.g. Docker or Kubernetes. CVE-2024-25621 Overly broad default permission vulnerability. Directory paths `/var/lib/containerd`, `/run/containerd/io.containerd.grpc.v1.cri`

What’s new in post-quantum cryptography in RHEL 10.1
IT automation with agentic AI: Introducing the MCP server for Red Hat Ansible Automation Platform

MGAA-2026-0010 – Updated libformula & ant-contrib packages fix bug

What Is AppArmor? A Practical Look for Linux Admins

Fix CVE-2026-24882: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution

Regenerate vendor tarball. Fixes CVE-2025-13465.

Regenerate vendor tarball. Fixes CVE-2025-13465.

Version 12.5.8 – 2026-01-27 Changed To prevent Poisoned Pipeline Execution (PPE) attacks using prepared .coverage files in pull requests, a PHPT test will no longer be run if the temporary file for writing code coverage information already exists before the test runs

https://security-tracker.debian.org/tracker/DSA-6118-1

A security issue was discovered in Thunderbird, which could result in information disclosure. For Debian 11 bullseye, this problem has been fixed in version 1:140.7.1esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.

An update that solves three vulnerabilities and has one security fix can now be installed.

An update that solves three vulnerabilities and has one security fix can now be installed.

Several security issues were fixed in ImageMagick.

Several security issues were fixed in MySQL.

MGAA-2026-0009 – Updated subversion packages fix bug