* bsc#1244485 * bsc#1245878 * bsc#1254227 * bsc#1254430 * bsc#1254431
https://security-tracker.debian.org/tracker/DSA-6075-1
https://security-tracker.debian.org/tracker/DSA-6076-1
https://security-tracker.debian.org/tracker/DSA-6077-1
https://security-tracker.debian.org/tracker/DSA-6078-1
https://security-tracker.debian.org/tracker/DSA-6079-1
Several security issues were fixed in radare2.
* bsc#1241772 * bsc#1250683 * bsc#1253181 * bsc#1253185 * bsc#1253186
python-apt could be made to crash if it opened a specially crafted file.
An update that solves one vulnerability can now be installed.
* bsc#1254132 Cross-References: * CVE-2025-9820
* bsc#1250497 Cross-References: * CVE-2025-10922
https://security-tracker.debian.org/tracker/DSA-6074-1
Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. For the stable distribution (trixie), this problem has been fixed in version 7:7.1.3-0+deb13u1.
Multiple vulnerabilties have been found in libpng, the official PNG reference library, allowing information disclosure via out-of-bounds read, denial of service via application crash, or heap corruption with potential for arbitrary code execution.
Update to 2.9.7
Fix seeking and looping of media elements that set the loop property. Fix several crashes and rendering issues. Fix CVE-2025-13947, CVE-2025-43458, CVE-2025-66287
Update to 2.9.7
https://security-tracker.debian.org/tracker/DSA-6073-1
Loading a manipulated TGA file in krita, an image manipulation program, could result in a heap-based buffer overflow in KisTgaImport.
Update to 143.0.7499.40 * High CVE-2025-13630: Type Confusion in V8 * High CVE-2025-13631: Inappropriate implementation in Google Updater * High CVE-2025-13632: Inappropriate implementation in DevTools * High CVE-2025-13633: Use after free in Digital Credentials
Fix CVE-2025-12744
Update to cef-142.0.17+g60aac24 & chromium 142.0.7444.175 (rhbz#2413981) High CVE-2025-13223: Type Confusion in V8 High CVE-2025-13224: Type Confusion in V8
Update to 143.0.7499.40 * High CVE-2025-13630: Type Confusion in V8 * High CVE-2025-13631: Inappropriate implementation in Google Updater * High CVE-2025-13632: Inappropriate implementation in DevTools * High CVE-2025-13633: Use after free in Digital Credentials
Fix CVE-2025-12744
https://security-tracker.debian.org/tracker/DSA-6072-1
https://security-tracker.debian.org/tracker/DSA-6071-1
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Update to security release 4.3.5a
Rebuilt with latest patched stb_image: memory-safety fixes
https://security-tracker.debian.org/tracker/DSA-6069-1
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43392
Rebuilt with stb_image patched for two new security bugs.
Patch two newly-reported memory-safety bugs in stb_image: https://github.com/nothings/stb/issues/1860 https://github.com/nothings/stb/issues/1861
https://security-tracker.debian.org/tracker/DSA-6070-1
https://security-tracker.debian.org/tracker/DSA-6068-1
https://security-tracker.debian.org/tracker/DSA-6067-1
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
KDE Connect could allow authentication of impersonated devices.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Several security issues were fixed in CRaC JDK 17.
Several security issues were fixed in CRaC JDK 25.
Several security issues were fixed in CRaC JDK 21.
update to version 2.25.2
Update to 1.24.2 (rhbz#2417261) Additional fix for CVE-2025-11411 https://nlnetlabs.nl/projects/unbound/download/#unbound-1-24-2
Prevent unsafe URI schemes from participating in media playback. Make jsc_value_array_buffer_get_data() function introspectable. Fix logging in to Google accounts that have a WebAuthn second factor configured. Fix loading webkit://gpu when there are no threads configured for GPU rendering. Fix rendering gradients that use the CSS hue interpolation method.
A local file inclusion vulnerability has been discovered in mistral- dashboard, the OpenStack Workflow as a Service dashboard plugin, that may result in disclosure of arbitrary local files content through the
A local file inclusion vulnerability has been discovered in python- mistralclient, the OpenStack Workflow as a Service client, that may result in disclosure of arbitrary local files content through the
Multiple vulnerabilities have been discovered in Pagure, a Git-centered code hosting system (forge).
A possible remote code execution (RCE) vulnerability has been discovered in pytorch, an open source machine learning framework.
Update to pgadmin-9.10
Update to 2.86.2 Fix CVE-2025-13601 or #YWH-PGM9867-134
Version 0.18.1 Security Fixed critical issue where PKESK (public-key encrypted) session keys were generated as all-zero, allowing trivial decryption of messages encrypted with public keys only (CVE-2025-13402)
An update that solves 2 vulnerabilities can now be installed.
An update that solves 2 vulnerabilities can now be installed.
An update that solves 9 vulnerabilities can now be installed.
Update to 20251125: Revert “amdgpu: update GC 11.0.1 firmware” QCA: Add Bluetooth firmware for WCN685x uart interface qcom: Add ADSP firmware for qcs6490-thundercomm-rubikpi3 qcom: venus-5.4: update firmware binary for v5.4
Update to 4.19.0 Address CVEs by rebuilding with Go 1.24.10
https://security-tracker.debian.org/tracker/DSA-6066-1
* bsc#1253757 Cross-References: * CVE-2025-11563
* bsc#1245953 * bsc#1252930 * bsc#1252931 * bsc#1252932 * bsc#1252933
A race condition was discovered in Qt, a cross-platform C++ application framework. Code to make security-relevant decisions about an established HTTP2 connection may execute too early, because the encrypted() signal has not yet been emitted and processed.
* bsc#1249537 Cross-References: * CVE-2025-38616
New libxslt packages are available for Slackware 15.0 and -current to fix security issues.
Several security vulnerabilities were discovered in the server of the Tryton application platform, which could lead to information disclosure. For Debian 11 bullseye, these problems have been fixed in version
* bsc#1252110 * bsc#1252232 Cross-References: * CVE-2025-31133
* bsc#1215199 * bsc#1218644 * bsc#1230062 * bsc#1234634 * bsc#1234693
* bsc#1249191 * bsc#1249348 * bsc#1249367 * bsc#1253757
* bsc#1218644 * bsc#1238472 * bsc#1239206 * bsc#1241166 * bsc#1241637
* bsc#1253278 * bsc#1253642 * bsc#1253703 * jsc#PED-9265
* bsc#1252414 * bsc#1252417 * bsc#1252418 * jsc#PED-14233
