The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-6106-1
https://security-tracker.debian.org/tracker/DSA-6104-1
GLib could be made to crash or run programs if it received specially crafted input.
An update that solves two vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves five vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves nine vulnerabilities can now be installed.
An update that solves nine vulnerabilities can now be installed.
An update that solves 17 vulnerabilities, contains one feature and has one security fix can now be installed.
An update that solves 10 vulnerabilities can now be installed.
An update that solves 10 vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that contains one feature can now be installed.
An update that contains one feature can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves seven vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
An update that solves 10 vulnerabilities and has one bug fix can now be installed.
Update to 144.0.7559.59 * CVE-2026-0899: Out of bounds memory access in V8 * CVE-2026-0900: Inappropriate implementation in V8 * CVE-2026-0901: Inappropriate implementation in Blink * CVE-2026-0902: Inappropriate implementation in V8
This update adds a patch to fix CVE-2025-56225, a flaw in the bundled version of fluidsynth.
Upgrade to libtpms 0.10.2 fixing CVE-2026-21444
Update to 144.0.7559.59 * CVE-2026-0899: Out of bounds memory access in V8 * CVE-2026-0900: Inappropriate implementation in V8 * CVE-2026-0901: Inappropriate implementation in Blink * CVE-2026-0902: Inappropriate implementation in V8
Upgrade to libtpms 0.10.2 fixing CVE-2026-21444
Several vulnerabilities were discovered in python-urllib3, a HTTP library with thread-safe connection pooling for Python3, which could result in denial of service or request forgery. For the oldstable distribution (bookworm), these problems have been fixed in version 1.26.12-1+deb12u2.
MGASA-2026-0012 – Updated gimp packages fix security vulnerabilities
MGASA-2026-0011 – Updated python-urllib3 packages fix security vulnerabilities
MGASA-2026-0010 – Updated libpng packages fix security vulnerabilities
MGASA-2026-0009 – Updated nodejs packages fix security vulnerabilities
MGAA-2026-0006 – Updated v4l2loopback packages fix bug
https://security-tracker.debian.org/tracker/DSA-6102-1
https://security-tracker.debian.org/tracker/DSA-6103-1
https://security-tracker.debian.org/tracker/DSA-6101-1
USN-7916-1 introduced a regression in python-apt
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-6100-1
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves four vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
Viral Vaghela discovered an SQL injection vulnerability in Parsl, a parallel scripting library for Python. For the stable distribution (trixie), this problem has been fixed in version 2025.01.13+ds-1+deb13u1. We recommend that you upgrade your python-parsl packages.
Version 2.9.3 – 2025-12-30 Security: Fixed ANSI sequence injection (GHSA-59pp-r3rg-353g / CVE-2025-67746) Fixed COMPOSER_NO_SECURITY_BLOCKING env var not being respected for updates done via the install command, and added –no-security-blocking flag to install as well (#12677)
New upstream release (147.0)
Update to 2.69.0
Version 2.9.3 – 2025-12-30 Security: Fixed ANSI sequence injection (GHSA-59pp-r3rg-353g / CVE-2025-67746) Fixed COMPOSER_NO_SECURITY_BLOCKING env var not being respected for updates done via the install command, and added –no-security-blocking flag to install as well (#12677)
Update to Upstream version 0.1.2 – https://github.com/complytime/complyctl/releases/tag/v0.1.2
https://security-tracker.debian.org/tracker/DSA-6099-1
https://security-tracker.debian.org/tracker/DSA-6098-1
An update that solves one vulnerability and contains one feature can now be installed.
An update that solves one vulnerability and contains one feature can now be installed.
An update that solves one vulnerability and contains one feature can now be installed.
An update that solves one vulnerability and contains one feature can now be installed.
An update that solves one vulnerability can now be installed.
Google Guest Agent could be made to crash if it received specially crafted network traffic.
Several security issues were fixed in PHP.
Several security issues were fixed in libheif.
Update to 143.0.7499.192 * High CVE-2026-0628: Insufficient policy enforcement in WebView tag * Enable control flow integrity support for x86_64/aarch64 * Enable build for epel10.1
This update adds a patch to fix CVE-2025-56225, a flaw in the bundled version of fluidsynth.
MGASA-2026-0006 – Updated zlib packages fix security vulnerability
MGAA-2026-0004 – Updated nvidia470 packages fix bug
Update to 143.0.7499.192 * High CVE-2026-0628: Insufficient policy enforcement in WebView tag * Enable control flow integrity support for x86_64/aarch64 * Enable build for epel10.1
Backport fix for CVE-2025-22921
Version 1.0.21 This point release includes all the changes from 1.0.20-stable, which include a security fix for the crypto_core_ed25519_is_valid_point() function, as well as two new sets of functions: The new crypto_ipcrypt_* functions implement mechanisms for securely
Backport fix for CVE-2025-64512 / GHSA-wf5f-4jwr-ppcp
https://security-tracker.debian.org/tracker/DSA-6097-1
MGASA-2026-0005 – Updated libpcap packages fix security vulnerability
MGASA-2026-0004 – Updated sodium packages fix security vulnerability
MGASA-2026-0003 – Updated curl packages fix security vulnerabilities
MGASA-2026-0002 – Updated wget2 packages fix security vulnerability
A security issue was discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), this problem has been fixed in version 143.0.7499.192-1~deb12u1.
MariaDB 10.11.15 Release notes: server/10.11/10.11.15
https://security-tracker.debian.org/tracker/DSA-6096-1
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
Several security issues were fixed in Tornado.
GnuPG could be made to crash or run programs if it received specially crafted network traffic.
GnuPG could be made to crash or run programs if it received specially crafted network traffic.
An update that solves one vulnerability can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
