Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

* bsc#1251279 * bsc#1251280 Cross-References: * CVE-2025-10230

An update that solves six vulnerabilities can now be installed.

* bsc#1232384 * bsc#1245794 * bsc#1246075 * bsc#1248673 * bsc#1248749

An update that solves five vulnerabilities can now be installed.

https://security-tracker.debian.org/tracker/DSA-6029-1

Simplified patching with Red Hat Enterprise Linux and Red Hat Insights

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Update to Python 3.9.24

Update to 3.11.14

Update to Python 3.10.19

Backport fixes for CVE-2025-11082, CVE-2025-11083, CVE-2025-11494, CVE-2025-11495.

What is an Out-of-Bounds Write Linux Security Vulnerability?

When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, an insufficiently seeded random number generator is used when generating the directory name, leading to the possibility for a local attacker to pre-create

Added fix for mzbz#1990430 (crashes) Updated to latest upstream (144.0)

Backport fix for CVE-2025-10729.

Backport fix for CVE-2025-10729.

Update to python-3.11.14, fixes CVE-2025-8291.

Update to release v1.3.2

An update that solves 326 vulnerabilities and has 45 security fixes can now be installed.

* bsc#1065729 * bsc#1164051 * bsc#1193629 * bsc#1194869 * bsc#1202700

An update that solves one vulnerability and contains one feature can now be installed.

* bsc#1223219 * jsc#PED-13826 Cross-References: * CVE-2024-32650

* bsc#1250232 Cross-References: * CVE-2025-9230

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, memory disclosure or cross-site scripting.

https://security-tracker.debian.org/tracker/DSA-6027-1

https://security-tracker.debian.org/tracker/DSA-6028-1

https://security-tracker.debian.org/tracker/DSA-6025-1

Redis could be made to crash or run programs if it received specially crafted network traffic from an authenticated user.

Redict could be made to crash or run programs if it received specially crafted network traffic from an authenticated user.

Redis could be made to crash or run programs if it received specially crafted network traffic from an authenticated user.

Apache Subversion could be made to crash if it opened a specially crafted file.

The following updated rpms for have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-6026-1

An update that solves one vulnerability can now be installed.

* bsc#1250553 Cross-References: * CVE-2025-10911

Update to exiv2-0.28.7, fixes CVE-2025-54080 and CVE-2025-55304.

Update to exiv2-0.28.7, fixes CVE-2025-54080 and CVE-2025-55304.

Update mirrorlist-server to version 3.0.8. Update the maxminddb crate to version 0.26.0. Update the prometheus crate to version 0.14.0. Update the protobuf and protobuf-codegen crates to version 3.7.2. Initial packaging of the protobuf-parse and protobuf-support crates.

Update mirrorlist-server to version 3.0.8. Update the maxminddb crate to version 0.26.0. Update the prometheus crate to version 0.14.0. Update the protobuf and protobuf-codegen crates to version 3.7.2. Initial packaging of the protobuf-parse and protobuf-support crates.

* bsc#1246197 * bsc#1249191 * bsc#1249348 * bsc#1249367 * jsc#PED-13055

* bsc#1243581 * bsc#1248410 * bsc#1248687 * bsc#142461 * bsc#544339

* bsc#1237048 * bsc#1240744 * bsc#1243650 * bsc#1245509 * bsc#1247315

* bsc#1237048 * bsc#1240744 * bsc#1245509 * bsc#1247315

* bsc#1245509 * bsc#1247315 Cross-References: * CVE-2025-38089

* bsc#1245509 * bsc#1247315 Cross-References: * CVE-2025-38089

CVE-2025-11371: Linux Security Must Prepare for Cross-Stack Breach

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

An update that solves 53 vulnerabilities, contains one feature and has 137 security fixes can now be installed.

* bsc#1001161 * bsc#1004490 * bsc#1007249 * bsc#1009961 * bsc#1012568

* bsc#1250232 Cross-References: * CVE-2025-9230

An update that solves 10 vulnerabilities and has one security fix can now be installed.

Update to release v0.29.1 Upstream fixes Update to release v0.29.0 Resolves: rhbz#2397747, rhbz#2398425, rhbz#2398679, rhbz#2399082, rhbz#2399355

Update to release v0.29.1 Upstream fixes Update to release v0.29.0 Resolves: rhbz#2397747, rhbz#2398425, rhbz#2398679, rhbz#2399082, rhbz#2399355

Update to 1.5.0, fix CVE-2025-54813, CVE-2025-22838

Urgent: How Hackers Use eBPF to Evade Detection

MGASA-2025-0237 – Updated open-vm-tools package fixes security vulnerability

MGAA-2025-0083 – Updated qarte package fixes bug

Update to 141.0.7390.65 * High CVE-2025-11458: Heap buffer overflow in Sync * High CVE-2025-11460: Use after free in Storage * Medium CVE-2025-11211: Out of bounds read in WebCodecs

Update to release 1.32.9 Resolves: rhbz#2333357, rhbz#2398407, rhbz#2398662, rhbz#2399064, rhbz#2399338 Upstream fix

Update to release v1.33.5 Resolves: rhbz#2333357, rhbz#2375096, rhbz#2398408, rhbz#2398663, rhbz#2399065, rhbz#2399339 Upstream fixes

Update to release v1.31.13 Resolves: rhbz#2333357, rhbz#2398406, rhbz#2398661, rhbz#2399063, rhbz#2399337 Upstream fix

https://security-tracker.debian.org/tracker/DSA-6024-1

* bsc#1244485 * bsc#1249141 * jsc#SLE-18320 Cross-References:

An update that solves one vulnerability, contains one feature and has one security fix can now be installed.

* bsc#1244485 * bsc#1249141 * jsc#SLE-18320 Cross-References:

An update that fixes three vulnerabilities is now available.

* bsc#1241502 * bsc#1249112 Cross-References: * CVE-2023-26819

* bsc#1225417 * bsc#1227086 * bsc#1250627 Cross-References:

https://security-tracker.debian.org/tracker/DSA-6023-1

Your Red Hat OpenShift AI models are waiting at the door. Who’s knocking?
Mitigating AI’s new risk frontier: Unifying enterprise cybersecurity with AI safety

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-6021-1

https://security-tracker.debian.org/tracker/DSA-6022-1

* bsc#1122338 Cross-References: * CVE-2019-6461

* bsc#1250553 Cross-References: * CVE-2025-10911

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-6020-1

* bsc#1250715 Cross-References: * CVE-2025-11226

* bsc#1249036 Cross-References: * CVE-2025-9375

* bsc#1230028 Affected Products: * Desktop Applications Module 15-SP6 * Desktop Applications Module 15-SP7

* bsc#1243701 Cross-References: * CVE-2025-48708

* bsc#1243701 Cross-References: * CVE-2025-48708

* bsc#1250452 Affected Products: * Desktop Applications Module 15-SP6 * Desktop Applications Module 15-SP7

poppler could be made to crash if it opened a specially crafted file.

Squid could be made to crash if it received specially crafted network traffic.

Several security issues were fixed in MySQL.

CVE-2025-27613 With Gitk, the Git history browser, when a user clones an untrusted repository and runs gitk without additional command arguments,

jupyterlab 4.4.9 fixing CVE-2025-59842.