Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Several security issues were fixed in the Linux kernel.

The system could be compromised under certain conditions.

Update NSS to 3.124.0 Update Firefox to 152.0

Update NSS to 3.124.0 Update Firefox to 152.0

Fix editor command injection vulnerability (only affectsversion 2.6.0). (#1432) https://github.com/jonas/tig/issues/1432

Update to 149.0.7827.114 CVE-2026-12007: Use after free Core CVE-2026-12008: Use after free DigitalCredentials CVE-2026-12009: Insufficient validation of untrusted input Accessibility CVE-2026-12010: Heap buffer overflow GPU

x86 HVM I/O port list traversal [XSA-491, CVE-2026-42487] domctl lock open to abuse [XSA-492, CVE-2026-42489, CVE-2026-42490] Arm: Completion of memory accesses not guaranteed by completion of a TLBI [XSA-493, CVE-2025-10263] x86: mismatched mapcache metadata [XSA-494, CVE-2026-42488]

Update to 1.9.2 for CVE-2026-10846

Version 0.16.0 – 2026-06-08 Security Fix out-of-bounds read via undersized frames in amqp_handle_input (GHSA-9mmv-r8g3-qp46, #878) Fix client crash when server negotiates frame_max below the AMQP protocol

BIRD 3.3.1 (2026-06-09) BGP: Fix crash when incoming connection for disabled protocol arrives BGP: Fix parsing labelled NLRIs with no next hop BGP: Fix cork behavior in collision with graceful restart BGP: Fix crash on dumping pending export statistics

CVE-2026-34253 – fix arbitrary code execution via buffer underflow

33.0.5 Release

This release fixes CVE-2026-10725 (exhausting memory when decompressing request headers). It also improves examples.

Fix arbitrary memory write with crafted Ventana BIF file (CVE-2026-48977).

Fix editor command injection vulnerability (only affectsversion 2.6.0). (#1432) https://github.com/jonas/tig/issues/1432

BIRD 3.3.1 (2026-06-09) BGP: Fix crash when incoming connection for disabled protocol arrives BGP: Fix parsing labelled NLRIs with no next hop BGP: Fix cork behavior in collision with graceful restart BGP: Fix crash on dumping pending export statistics

33.0.5 Release

This release fixes CVE-2026-10725 (exhausting memory when decompressing request headers). It also improves examples.

Fix arbitrary memory write with crafted Ventana BIF file (CVE-2026-48977).

Update to version 3.10.0

Security update

Security update

Security update

# Security update for distribution Announcement ID: SUSE-SU-2026:2413-1 Release Date: 2026-06-16T12:20:29Z Rating: important References:

# Security update for runc Announcement ID: SUSE-SU-2026:2414-1 Release Date: 2026-06-16T12:22:39Z Rating: important References:

# Security update for buildah Announcement ID: SUSE-SU-2026:2415-1 Release Date: 2026-06-16T12:23:37Z Rating: important References:

# Security update for buildah Announcement ID: SUSE-SU-2026:2416-1 Release Date: 2026-06-16T12:24:12Z Rating: important References:

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

# Security update for container-suseconnect Announcement ID: SUSE-SU-2026:2420-1 Release Date: 2026-06-16T14:05:08Z Rating: important References:

An update that solves eight vulnerabilities can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 60 vulnerabilities and has four fixes can now be installed.

An update that solves 107 vulnerabilities and has 11 fixes can now be installed.

An update that solves one vulnerability can now be installed.

https://security-tracker.debian.org/tracker/DSA-6349-1

https://security-tracker.debian.org/tracker/DSA-6350-1

Several security issues were fixed in OpenImageIO.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

USN-8412-1 introduced a regression in QEMU

https://security-tracker.debian.org/tracker/DSA-6347-1

https://security-tracker.debian.org/tracker/DSA-6346-1

https://security-tracker.debian.org/tracker/DSA-6345-1

Several issues have been found in asterisk, an Open Source Private Branch Exchange (PBX). They are related to buffer under- or overflows, either on heap or on stack. Some are related to use-after-free or wrong processing of invalid or untrusted certificates. For Debian 11 bullseye, these problems have been fixed in version

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

# Security update for containerized-data-importer Announcement ID: SUSE-SU-2026:2407-1 Release Date: 2026-06-16T07:47:27Z Rating: important References:

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

An update that solves four vulnerabilities and has one security fix can now be installed.

An update that solves four vulnerabilities and has one security fix can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

Several security issues were fixed in rabbitmq-c.

Several security issues were fixed in Squid.

The CA certificates in the ca-certificates package were updated.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 3 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

Cisco SD-WAN Vulnerability: Why Security Starts With the Management Plane

An update that solves one vulnerability can now be installed.

Several security issues were fixed in FreeRDP.

Ruby could allow unintended access to network services.

USN-8349-1 introduced regressions in rsync.

Security update

Security update

Security update

Fixes CVE-2026-48092: Information disclosure in 32-bit builds Fixes CVE-2026-48095: Arbitrary code execution in NTFS handler Fixes CVE-2026-48101: Information disclosure in UEFI capsule parser Fixes CVE-2026-48102: Information disclosure and DOS via crafted UDF image

Update to 0.162.1 (rhbz#2455512)

This release of Mojo::JWT Improves the security of decode to prevent timing side-channel attacks in symmetric signatures

Fixes CVE-2026-48092: Information disclosure in 32-bit builds Fixes CVE-2026-48095: Arbitrary code execution in NTFS handler Fixes CVE-2026-48101: Information disclosure in UEFI capsule parser Fixes CVE-2026-48102: Information disclosure and DOS via crafted UDF image

Update to version 3.10.0

Update to 0.162.1 (rhbz#2455512)

This release of Mojo::JWT Improves the security of decode to prevent timing side-channel attacks in symmetric signatures

An update that solves one vulnerability can now be installed.

An update that solves three vulnerabilities and has one security fix can now be installed.

An update that solves seven vulnerabilities and has one security fix can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves seven vulnerabilities and has one security fix can now be installed.

An update that solves seven vulnerabilities can now be installed.

An update that solves seven vulnerabilities can now be installed.

https://security-tracker.debian.org/tracker/DSA-6348-1

An update that solves five vulnerabilities and has one security fix can now be installed.

An update that solves nine vulnerabilities can now be installed.

An update that solves nine vulnerabilities can now be installed.

Multiple security vulnerabilities were discovered in the BIRD internet routing daemon, which could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 2.17.5-0+deb13u1. We recommend that you upgrade your bird2 packages.

Multiple security vulnerabilities were discovered in LibreOffice, which could result in denial of service or potentially the execution of arbitrary code if malformed files are opened. For the stable distribution (trixie), these problems have been fixed in version 4:25.2.3-2+deb13u5.

A flaw was discovered in libgd-perl, a Perl module wrapper for libgd, which may result in the execution of arbitrary shell commands or file overwrite when processing specially crafted file names. For the stable distribution (trixie), this problem has been fixed in version 2.78-1+deb13u1.