Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

https://security-tracker.debian.org/tracker/DSA-6065-1

https://security-tracker.debian.org/tracker/DSA-6064-1

Optimizing Linux Security 2026: Key Strategies for Modern Threats

Several vulnerabilities have been found in libssh, a tiny C SSH library. CVE-2025-4877

An update that solves one vulnerability and has one bug fix can now be installed.

An update that solves 83 vulnerabilities and has 101 bug fixes can now be installed.

FFmpeg could be made to crash if it opened a specially crafted file.

An update that solves two vulnerabilities can now be installed.

* bsc#1248672 * bsc#1249537 Cross-References: * CVE-2025-38500

https://security-tracker.debian.org/tracker/DSA-6062-1

https://security-tracker.debian.org/tracker/DSA-6061-1

An update that solves 573 vulnerabilities and has 669 bug fixes can now be installed.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

An update that solves one vulnerability can now be installed.

* bsc#1251983 Cross-References: * CVE-2023-53673

https://security-tracker.debian.org/tracker/DSA-6063-1

An update that contains one feature can now be installed.

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

An update that solves two vulnerabilities can now be installed.

* bsc#1251305 * bsc#1252974 Cross-References: * CVE-2025-6075

* bsc#1252379 * bsc#1252380 Cross-References: * CVE-2025-40778

* bsc#1252931 * bsc#1252932 * bsc#1252933 * bsc#1252934 * bsc#1252935

Key Linux Features Boosting Security Measures for the Year 2026

Several security issues were fixed in cups-filters.

An update that solves nine vulnerabilities can now be installed.

* bsc#1231032 * bsc#1231033 * bsc#1232855 * bsc#1236496 * bsc#1236497

An update that solves four vulnerabilities can now be installed.

* bsc#1237236 * bsc#1237240 * bsc#1237241 * bsc#1237242

* bsc#1065729 * bsc#1199304 * bsc#1205128 * bsc#1206893 * bsc#1210124

An update that solves 3 vulnerabilities can now be installed.

An update that solves 6 vulnerabilities can now be installed.

Update to release v1.32.10 Resolves: rhbz#2414539 Resolves: rhbz#2398587, rhbz#2398848, rhbz#2399249, rhbz#2399522 Resolves: rhbz#2399703, rhbz#2399721, rhbz#2407788, rhbz#2408058 Resolves: rhbz#2408315, rhbz#2408609, rhbz#2408672, rhbz#2408730

Update to the 3.8.11 release with a fix for CVE-2025-9820 and several enhancements.

MGASA-2025-0310 – Updated kernel-linus packages fix security vulnerabilities

MGASA-2025-0309 – Updated kernel, kmod-xtables-addons & kmod-virtualbox packages fix security vulnerabilities

Upstream linux-firmware 20251111 release: rtl_bt: Update RTL8922A BT USB firmware to 0x41C0_C905 add firmware for mt7987 internal 2.5G ethernet phy rtw88: 8822b: Update firmware to v30.20.0 rtl_nic: add firmware rtl8125k-1

Update to release v1.32.10 Resolves: rhbz#2414539 Resolves: rhbz#2398587, rhbz#2398848, rhbz#2399249, rhbz#2399522 Resolves: rhbz#2399703, rhbz#2399721, rhbz#2407788, rhbz#2408058 Resolves: rhbz#2408315, rhbz#2408609, rhbz#2408672, rhbz#2408730

This is the .NET 10 GA update Update .NET 10 to RC 2

Update to 1.16.0

Update to 1.6.0

Update to release v1.31.14 Resolves: rhbz#2398586, rhbz#2398847, rhbz#2399248, rhbz#2399521 Resolves: rhbz#2399702, rhbz#2399720, rhbz#2407787, rhbz#2408057 Resolves: rhbz#2408314, rhbz#2408608, rhbz#2408671, rhbz#2408729 Resolves: rhbz#2409236, rhbz#2409526, rhbz#2409787, rhbz#2410201

Several security issues were fixed in cups-filters.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Several security issues were fixed in libcupsfilters.

New gnutls packages are available for Slackware 15.0 and -current to fix security issues.

ImageMagick could be made to crash or run programs as your login if it opened a specially crafted file.

https://security-tracker.debian.org/tracker/DSA-6060-1

An update that solves two vulnerabilities can now be installed.

* bsc#1250353 * bsc#1250354 Cross-References: * CVE-2025-59798

An update that solves five vulnerabilities can now be installed.

* bsc#1252931 * bsc#1252932 * bsc#1252933 * bsc#1252934 * bsc#1252935

New openvpn packages are available for Slackware 15.0 and -current to fix security issues.

Several security issues were fixed in the Linux kernel.

Enhance workload security with confidential containers on Azure Red Hat OpenShift
Introducing OpenShift Service Mesh 3.2 with Istio’s ambient mode

MGASA-2025-0305 – Updated thunderbird packages fix security vulnerabilities

MGASA-2025-0304 – Updated cups-filters packages fix security vulnerabilities

MGASA-2025-0303 – Updated flatpak & bubblewrap packages fix security vulnerability

Update to 142.0.7444.162 * High CVE-2025-13042: Inappropriate implementation in V8

Updated to latest upstream (145.0) Added fix for mzbz#1990430 (crashes) Updated to latest upstream (144.0)

New libarchive packages are available for Slackware 15.0 and -current to fix security issues.

* bsc#1103203 * bsc#1149841 * bsc#1230998 * bsc#1231204 * bsc#1231676

MGASA-2025-0302 – Updated postgresql15 & postgresql13 packages fix security vulnerabilities

MGASA-2025-0301 – Updated apache packages fix security vulnerabilities

Several security issues were fixed in Freeglut.

Update to 142.0.7444.162 * High CVE-2025-13042: Inappropriate implementation in V8

FVWM3 ver. 1.1.4

Red Hat Advanced Cluster Security 4.9: Security built with your workflows in mind

An update that solves 173 vulnerabilities, contains two features and has 19 security fixes can now be installed.

* bsc#1065729 * bsc#1205128 * bsc#1206893 * bsc#1207612 * bsc#1207619

An update that solves two vulnerabilities can now be installed.

* bsc#1251198 * bsc#1251199 Cross-References: * CVE-2025-61984

An update that solves two vulnerabilities can now be installed.

* bsc#1247850 * bsc#1249076 Cross-References: * CVE-2025-8732

https://security-tracker.debian.org/tracker/DSA-6058-1

Update to 142.0.7444.162 * High CVE-2025-13042: Inappropriate implementation in V8

Update to 9.21.14 (rhbz#2394406) Security Fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780)

New upstream release v10 Fix: CVE-2025-11568

Update to 9.21.14 (rhbz#2394406) Security Fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780)

New upstream release v10 Fix: CVE-2025-11568

https://security-tracker.debian.org/tracker/DSA-6059-1

New xpdf packages are available for Slackware 15.0 and -current to fix security issues.

Keylogging in Linux (Part 3): Kernel Techniques for the Keyboard Driver Path

MGASA-2025-0298 – Updated stardict packages fix security vulnerability

MGASA-2025-0297 – Updated yelp & yelp-xsl packages fix security vulnerability

MGASA-2025-0296 – Updated apache-commons-fileupload packages fix security vulnerability

MGASA-2025-0295 – Updated botan2 packages fix security vulnerabilitiy

MGASA-2025-0294 – Updated spdlog packages fix security vulnerability

MGASA-2025-0293 – Updated apache-commons-lang3 & apache-commons-lang packages fix security vulnerability

https://security-tracker.debian.org/tracker/DSA-6057-1

https://security-tracker.debian.org/tracker/DSA-6056-1

Improving modern software supply chain security: From AI models to container images
Prepare for a post-quantum future with RHEL 9.7
A deeper look at post-quantum cryptography support in Red Hat OpenShift 4.20 control plane
Keylogging in Linux (Part 2): Advanced Techniques in the Linux GUI and X Server

* bsc#1253092 * bsc#1253093 * bsc#1253094 * bsc#1253095

Update to 2.53.22