Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

An update that solves two vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Red Hat Hybrid Cloud Console: Your questions answered

An update that solves three vulnerabilities and has two security fixes can now be installed.

An update that solves three vulnerabilities and has two security fixes can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

MGAA-2026-0003 – Updated isodumper packages fix bugs

MGAA-2026-0002 – Updated sddm-theme-coffee-ng packages fix bug

Red Team Blue Team Insights for Linux Admins: Key Security Roles Explained

https://security-tracker.debian.org/tracker/DSA-6095-1

https://security-tracker.debian.org/tracker/DSA-6094-1

An update that solves eight vulnerabilities and has one security fix can now be installed.

An update that solves eight vulnerabilities and has one security fix can now be installed.

An update that solves eight vulnerabilities and has one security fix can now be installed.

An update that solves eight vulnerabilities and has one security fix can now be installed.

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-6093-1

An update that solves 70 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

Moderate: postgresql:15 security update

A vulnerability was found in Curl, an easy-to-use client-side URL transfer library and command line tool. It can cause a crash or potentially a memory out of bounds read. For Debian 11 bullseye, this problem has been fixed in version 7.74.0-1.3+deb11u16.

Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service or potentially the execution of arbitrary code if malformed XCF, JPEG 2000 or PNM files are opened. For the oldstable distribution (bookworm), these problems have been fixed

Update to 1.148.0

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

https://github.com/wb2osz/direwolf/releases/tag/1.8.1

Correctly handle the program name passed to the sleep disabler. Ensure GStreamer is initialized before using the Quirks. Fix several crashes and rendering issues. Fix CVE-2025-14174, CVE-2025-43501, CVE-2025-43529, CVE-2025-43531, CVE-2025-43535, CVE-2025-43536, CVE-2025-43541

Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442

Update to 2.83.2

https://github.com/wb2osz/direwolf/releases/tag/1.8.1

Two vulnerabilities were discovered in smb4k, a KDE desktop utility which allows unprivileged mounting of Samba/CIFS network shares, which may result in local denial of service or local privilege escalation. For the stable distribution (trixie), these problems have been fixed in version 4.0.0-1+deb13u1.

Rebuilt for CVEs

Rebuilt for CVE-2025-47906

Support for Go 1.26 and security fixes. Upstream release notes.

Rebuilt for CVEs

Support for Go 1.26 and security fixes. Upstream release notes.

https://security-tracker.debian.org/tracker/DSA-6092-1

An update that solves three vulnerabilities can now be installed.

An update that fixes 8 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

NSA: Managing Secure Boot for Linux Against Bootchain Attacks

An update that fixes one vulnerability is now available.

Update to 1.1.97

Update to 5.8.0

A Buffer Overflow vulnerability has been found in osslsigncode, a OpenSSL based Authenticode signing tool for PE/MSI/Java CAB files, which possibly allows an malicious attacker to execute arbitrary code when signing a crafted file. For Debian 11 bullseye, this problem has been fixed in version

An update that solves four vulnerabilities can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

Rebuilt for CVE-2025-61723

Rebuild for CVEs

Exploring AI Agents’ Influence on Linux Security Threats and Administration

Multiple vulnerabilities have been discovered in Kodi, a media-player and entertainment hub. CVE-2023-23082 A heap buffer overflow vulnerability in Kodi allows attackers to cause a denial of service due to an improper length of the value

Update to 2.5.2 Fix for CVE-2025-68617

Update to 1.4.6: fixes CVE-2025-13654

Update to 2.1.0. Update bundled libpng, libtiff, to latest versions. Built against TCL/TK 9. Fix FTBFS.

Update to 5.32.0

Update to 2.1.0. Update bundled libpng, libtiff, to latest versions. Built against TCL/TK 9. Fix FTBFS.

Update to 5.32.0

Upgrade to 4.3.6 upstream version.

Upgrade to 4.3.6 upstream version.

An update that fixes one vulnerability is now available.

MGAA-2025-0106 – Updated nvidia-current & ldetect-lst packages fix bug

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Vulnerabilities were found in python-urllib3, an HTTP library with thread-safe connection pooling for Python, which could lead to denial of service or request forgery. CVE-2025-50181 Redirects were not disabled when retries are disabled on PoolManager

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

A couple of vulnerabilities were discovered in postgresql-13, the widely-popular database management system: CVE-2025-12817 Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other

Update to 0.50.2

Update to release v0.26.3 Resolves CVE-2024-25621: rhbz#2419004, rhbz#2419033, rhbz#2419427 Upstream fix

Update to 2.68.1

Update to 1.22.0

Release 1.6.12 Support IPv6 in database DSN (#9937) Don’t force specific error_reporting setting Fix compatibility with PHP 8.5 regarding array_first() Remove X-XSS-Protection example from .htaccess file (#9875)

version update security update

Update to 1.22.0

Release 1.6.12 Support IPv6 in database DSN (#9937) Don’t force specific error_reporting setting Fix compatibility with PHP 8.5 regarding array_first() Remove X-XSS-Protection example from .htaccess file (#9875)

An update that solves 65 vulnerabilities and has nine security fixes can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

Linux Kernel Encryption Changes Prevent Physical Hardware Attacks
Why IPv6 Influences Linux Firewall Behavior and Exposure Risks
React2Shell: How a Framework Bug Drives Full Linux Compromise

An update that solves three vulnerabilities can now be installed.