An update that solves two vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
An update that solves three vulnerabilities and has two security fixes can now be installed.
An update that solves three vulnerabilities and has two security fixes can now be installed.
An update that solves four vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
MGAA-2026-0003 – Updated isodumper packages fix bugs
MGAA-2026-0002 – Updated sddm-theme-coffee-ng packages fix bug
https://security-tracker.debian.org/tracker/DSA-6095-1
https://security-tracker.debian.org/tracker/DSA-6094-1
An update that solves eight vulnerabilities and has one security fix can now be installed.
An update that solves eight vulnerabilities and has one security fix can now be installed.
An update that solves eight vulnerabilities and has one security fix can now be installed.
An update that solves eight vulnerabilities and has one security fix can now be installed.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-6093-1
An update that solves 70 vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
Moderate: postgresql:15 security update
A vulnerability was found in Curl, an easy-to-use client-side URL transfer library and command line tool. It can cause a crash or potentially a memory out of bounds read. For Debian 11 bullseye, this problem has been fixed in version 7.74.0-1.3+deb11u16.
Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service or potentially the execution of arbitrary code if malformed XCF, JPEG 2000 or PNM files are opened. For the oldstable distribution (bookworm), these problems have been fixed
Update to 1.148.0
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
https://github.com/wb2osz/direwolf/releases/tag/1.8.1
Correctly handle the program name passed to the sleep disabler. Ensure GStreamer is initialized before using the Quirks. Fix several crashes and rendering issues. Fix CVE-2025-14174, CVE-2025-43501, CVE-2025-43529, CVE-2025-43531, CVE-2025-43535, CVE-2025-43536, CVE-2025-43541
Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442
Update to 2.83.2
https://github.com/wb2osz/direwolf/releases/tag/1.8.1
Two vulnerabilities were discovered in smb4k, a KDE desktop utility which allows unprivileged mounting of Samba/CIFS network shares, which may result in local denial of service or local privilege escalation. For the stable distribution (trixie), these problems have been fixed in version 4.0.0-1+deb13u1.
Rebuilt for CVEs
Rebuilt for CVE-2025-47906
Support for Go 1.26 and security fixes. Upstream release notes.
Rebuilt for CVEs
Support for Go 1.26 and security fixes. Upstream release notes.
https://security-tracker.debian.org/tracker/DSA-6092-1
An update that solves three vulnerabilities can now be installed.
An update that fixes 8 vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes one vulnerability is now available.
Update to 1.1.97
Update to 5.8.0
A Buffer Overflow vulnerability has been found in osslsigncode, a OpenSSL based Authenticode signing tool for PE/MSI/Java CAB files, which possibly allows an malicious attacker to execute arbitrary code when signing a crafted file. For Debian 11 bullseye, this problem has been fixed in version
An update that solves four vulnerabilities can now be installed.
An update that solves one vulnerability and has one security fix can now be installed.
An update that solves one vulnerability and has one security fix can now be installed.
Rebuilt for CVE-2025-61723
Rebuild for CVEs
Multiple vulnerabilities have been discovered in Kodi, a media-player and entertainment hub. CVE-2023-23082 A heap buffer overflow vulnerability in Kodi allows attackers to cause a denial of service due to an improper length of the value
Update to 2.5.2 Fix for CVE-2025-68617
Update to 1.4.6: fixes CVE-2025-13654
Update to 2.1.0. Update bundled libpng, libtiff, to latest versions. Built against TCL/TK 9. Fix FTBFS.
Update to 5.32.0
Update to 2.1.0. Update bundled libpng, libtiff, to latest versions. Built against TCL/TK 9. Fix FTBFS.
Update to 5.32.0
Upgrade to 4.3.6 upstream version.
Upgrade to 4.3.6 upstream version.
An update that fixes one vulnerability is now available.
MGAA-2025-0106 – Updated nvidia-current & ldetect-lst packages fix bug
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
Vulnerabilities were found in python-urllib3, an HTTP library with thread-safe connection pooling for Python, which could lead to denial of service or request forgery. CVE-2025-50181 Redirects were not disabled when retries are disabled on PoolManager
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
A couple of vulnerabilities were discovered in postgresql-13, the widely-popular database management system: CVE-2025-12817 Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other
Update to 0.50.2
Update to release v0.26.3 Resolves CVE-2024-25621: rhbz#2419004, rhbz#2419033, rhbz#2419427 Upstream fix
Update to 2.68.1
Update to 1.22.0
Release 1.6.12 Support IPv6 in database DSN (#9937) Don’t force specific error_reporting setting Fix compatibility with PHP 8.5 regarding array_first() Remove X-XSS-Protection example from .htaccess file (#9875)
version update security update
Update to 1.22.0
Release 1.6.12 Support IPv6 in database DSN (#9937) Don’t force specific error_reporting setting Fix compatibility with PHP 8.5 regarding array_first() Remove X-XSS-Protection example from .htaccess file (#9875)
An update that solves 65 vulnerabilities and has nine security fixes can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves four vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
