Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

* bsc#1012628 * bsc#1139073 * bsc#1204142 * bsc#1210025 * bsc#1211226

https://security-tracker.debian.org/tracker/DSA-5980-1

* bsc#1242666 * bsc#1243428 Cross-References: * CVE-2025-3416

* bsc#1244631 * bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

https://security-tracker.debian.org/tracker/DSA-5979-1

What Is A Virtual Private Network (VPN)?

* bsc#1236217 * bsc#1246118 * bsc#1247719 * bsc#1247720 * jsc#SLE-18320

Introducing Red Hat Technical Account Management Service for Product Security

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

* bsc#1244631 * bsc#1245218 * bsc#1245350 * bsc#1245989 * bsc#1247350

* bsc#1244337 * bsc#1247350 * bsc#1247351 Cross-References:

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

https://security-tracker.debian.org/tracker/DSA-5978-1

Update to upstream 1.4.2, fix CVE-2025-22870

* bsc#1245320 Cross-References: * CVE-2025-6032

* bsc#1245320 Cross-References: * CVE-2025-6032

Updated to 139.0.7258.127 * CVE-2025-8879: Heap buffer overflow in libaom * CVE-2025-8880: Race in V8 * CVE-2025-8901: Out of bounds write in ANGLE * CVE-2025-8881: Inappropriate implementation in File Picker

Updated to 139.0.7258.127 * CVE-2025-8879: Heap buffer overflow in libaom * CVE-2025-8880: Race in V8 * CVE-2025-8901: Out of bounds write in ANGLE * CVE-2025-8881: Inappropriate implementation in File Picker

An update that fixes 5 vulnerabilities is now available.

fix CVE-2025-46206 (rhbz#2386395)

fixes CVE-2025-8534: null pointer dereference in tiff2p fixes CVE-2024-13978: null pointer dereference in tiff2pdf

update MANUAL to cover threat related to user HTML iframe

Several security issues were fixed in AIDE.

* bsc#1222040 * bsc#1222041 * bsc#1222042 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5975-1

https://security-tracker.debian.org/tracker/DSA-5974-1

What Is a Use-After-Free (UAF) Vulnerability?

Several security issues were fixed in Request Tracker.

Several security issues were fixed in Sidekiq.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5976-1

https://security-tracker.debian.org/tracker/DSA-5977-1

* bsc#1243747 Cross-References: * CVE-2025-48057

* bsc#1246397 Cross-References: * CVE-2025-48924

* bsc#1085999 * bsc#1246397 Cross-References: * CVE-2025-48924

* bsc#1247249 Cross-References: * CVE-2025-8194

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

National Security & AI at DEFCON 2025: Where Code Meets Crisis

An update that fixes 9 vulnerabilities is now available.

* bsc#1221107 Cross-References: * CVE-2024-2236

* bsc#1246296 Cross-References: * CVE-2025-7425

* bsc#1219386 Cross-References: * CVE-2023-5992

https://security-tracker.debian.org/tracker/DSA-5972-1

https://security-tracker.debian.org/tracker/DSA-5973-1

* bsc#1246318 * bsc#1246388 Cross-References: * CVE-2025-52520

* bsc#1233791 * bsc#1233834 Cross-References: * CVE-2024-22117

* bsc#1247519 * bsc#1247520 * bsc#1247522 Cross-References:

update to xen-4.19.3 includes patches for x86: Incorrect stubs exception handling for flags recovery [XSA-470, CVE-2025-27465] x86: Transitive Scheduler Attacks [XSA-471, CVE-2024-36350,

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

New release of Incus. Release information: https://github.com/lxc/incus/releases/tag/v6.15.0

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

What is a CSRF Vulnerability?

* bsc#1246090 Affected Products: * openSUSE Leap 15.4

* bsc#1245573 Cross-References: * CVE-2025-6297

* bsc#1244925 Cross-References: * CVE-2025-50181

Hashcat 7.0.0: Redefining Password Recovery & Security on Linux
Critical NestJS Vulnerability Exposes Developers to RCE Risk
How to Build a Ransomware Kill Chain Strategy for Linux Security
What Is a SQLi Vulnerability?

https://security-tracker.debian.org/tracker/DSA-5971-1

* bsc#1234959 Cross-References: * CVE-2024-56738

* bsc#1234959 Cross-References: * CVE-2024-56738

* bsc#1234959 Cross-References: * CVE-2024-56738

Introducing OpenShift Service Mesh 3.1

Several security issues were fixed in cifs-utils.

* bsc#1221107 * bsc#1246934 Cross-References: * CVE-2024-2236

Multiple vulnerabilities have been discovered in Composer, the worst of which can lead to arbitrary code execution.