Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Two vulnerabilities have been fixed in the audio data read/write library libsndfile.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

Exploring Open Source Intelligence (OSINT) Techniques And Tools For Cybersecurity Applications

Several security issues were fixed in ImageMagick.

DoS with large SAML responses has been fixed in ruby-saml, a library implementing the client side of SAML authorization for the Ruby interpreter.

* bsc#1244270 * bsc#1244272 Cross-References: * CVE-2025-5914

Update to release v0.27.0 Resolves: rhvz#2388453, rhbz#2384137, rhbz#2384154 Upstream new features and fixes

Exiv2 0.28.6 + patch to fix silent abi breakage Exiv2 v0.28.6 (Fixes two low severity CVEs)

Update to 139.0.7258.154 CVE-2025-9478: Use after free in ANGLE

Several security issues were fixed in Open VM Tools.

Update to 139.0.7258.154 CVE-2025-9478: Use after free in ANGLE

CVE-2025-8067 Out-Of-Bounds Read in UDisks Daemon

CVE-2025-8010: Type Confusion in V8 CVE-2025-8011: Type Confusion in V8 CVE-2025-8576: Use after free in Extensions CVE-2025-8578: Use after free in Cast CVE-2025-8579: Inappropriate implementation in Gemini Live in Chrome

Update to release v0.27.0 Resolves: rhvz#2388453, rhbz#2384137, rhbz#2384154 Upstream new features and fixes

Remove prebuild libffts.a library

New udisks2 packages are available for Slackware 15.0 and -current to fix a security issue.

Red Hat Trusted Artifact Signer can now be hosted on RHEL

Update to latest upstream (142.0.1) Updated to new upstream release (142.0)

https://security-tracker.debian.org/tracker/DSA-5992-1

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

* bsc#1240414 Cross-References: * CVE-2025-31115

* bsc#1238078 * bsc#1243450 * bsc#1244116 Cross-References:

* bsc#1220262 Cross-References: * CVE-2023-50782

* bsc#1244270 * bsc#1244272 * bsc#1244273 * bsc#1244279 * bsc#1244336

* bsc#1248502 Cross-References: * CVE-2025-8067

* bsc#1248502 Cross-References: * CVE-2025-8067

* bsc#1248502 Cross-References: * CVE-2025-8067

* bsc#1248119 * bsc#1248120 * bsc#1248122 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5990-1

https://security-tracker.debian.org/tracker/DSA-5991-1

https://security-tracker.debian.org/tracker/DSA-5988-1

https://security-tracker.debian.org/tracker/DSA-5987-1

* bsc#1246472 Cross-References: * CVE-2025-7519

* bsc#1244270 * bsc#1244272 * bsc#1244273 * bsc#1244279 * bsc#1244336

* bsc#1246597 Cross-References: * CVE-2025-6965

* bsc#1245573 Cross-References: * CVE-2025-6297

* bsc#1246232 * bsc#1246233 * bsc#1246267 * bsc#1246299

* bsc#1244554 * bsc#1244555 * bsc#1244557 * bsc#1244580 * bsc#1244700

What Is a Privilege Escalation Vulnerability?

https://security-tracker.debian.org/tracker/DSA-5989-1

Linux Rootkits: Detecting, Preventing, and Surviving an Attack

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

fix CVE-2025-9165: memory leak in tiffcmp (rhbz#2389608)

Update to upstream version 0.2.8 Update idna dependency to a version not affected by CVE-2024-12224

fix CVE-2025-8534: null pointer dereference in tiff2ps (rhbz#2386494) fix CVE-2024-13978: null pointer dereference in tiff2pdf (rhbz#2386201)

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

* bsc#1248119 * bsc#1248120 * bsc#1248122 Cross-References:

* bsc#1248119 * bsc#1248120 * bsc#1248122 Cross-References:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5986-1

* bsc#1232234 * bsc#1246221 Cross-References: * CVE-2024-10041

* bsc#1232234 * bsc#1246221 Cross-References: * CVE-2024-10041

* bsc#1234018 * bsc#1234019 * bsc#1234020 * bsc#1245313 * bsc#1246790

* bsc#1239547 * bsc#1239863 * bsc#1239864 * bsc#1247562 * bsc#1247563

https://security-tracker.debian.org/tracker/DSA-5985-1

Security fixes Bumped the minimum github.com/go-viper/mapstructure/v2 version to 2.3.0 for GHSA-fv92-fjc5-jj9h or GO-2025-3787 Bumped the minimum github.com/NVIDIA/nvidia-container-toolkit version to 1.17.8 for CVE-2025-23266 and CVE-2025-23267

How RingReaper Linux Malware Exploits io_uring to Evade EDR Systems

https://security-tracker.debian.org/tracker/DSA-5984-1

Update to release v1.32.7 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes

Update to release v1.31.12 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fix

Update to release v1.33.4 Resolves: rhbz#2388412 Fixes CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes

Update to 1.67.0 Update to 1.66.0

Update to release v1.31.12 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fix

Update to release v1.32.7 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes

* bsc#1248006 Cross-References: * CVE-2025-55159

Several security issues were fixed in PHP.

* bsc#1248006 Cross-References: * CVE-2025-55159

Several security issues were fixed in Python.

Update to version 0.4.11. This version includes a fix for CVE-2025-55159, but there are zero packages in Fedora or EPEL that use the affected API, so no rebuilds are necessary.

Update to v1.136.0 Update to 1.135.2 Update to 1.135.0

https://security-tracker.debian.org/tracker/DSA-5983-1

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape or bypass of the same-origin policy.

poppler could be made to denial of service if it received a specially crafted PDF file.

* bsc#1245218 * bsc#1247350 * bsc#1247351 Cross-References:

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

https://security-tracker.debian.org/tracker/DSA-5981-1

https://security-tracker.debian.org/tracker/DSA-5982-1

* bsc#1244270 * bsc#1244272 * bsc#1244273 * bsc#1244279 * bsc#1244336

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

Several security issues were fixed in Apache HTTP Server.

Several security issues were fixed in libxml2.