Several security issues were fixed in the Linux kernel.
https://security-tracker.debian.org/tracker/DSA-6250-1
https://security-tracker.debian.org/tracker/DSA-6251-1
https://security-tracker.debian.org/tracker/DSA-6252-1
Important: kernel security update
Important: dovecot security update
Important: grafana security update
Moderate: freeipmi security update
Important: grafana-pcp security update
Important: golang security update
https://security-tracker.debian.org/tracker/DSA-6248-1
An update that solves six vulnerabilities can now be installed.
An update that solves five vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
Multiple vulnerabilities have been discovered in libarchive, a multi-format archive and compression C library, which also provides the following command-line tools: bsdcat, bsdcpio, bsdtar and bsdunzip. CVE-2026-4111 A flaw was identified in the RAR5 archive decompression logic of the
https://security-tracker.debian.org/tracker/DSA-6247-1
curl could be made to expose sensitive information over the network.
Several security issues were fixed in Exim.
sed could be made to overwrite files.
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.10.1esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Important: libcap security update
Important: sudo security update
Important: libcap security update
Update to version 0.6.0. Addresses RUSTSEC-2026-0109.
Fix CVE-2026-6846.
This update provides various security fixes. Buffer overflow in scanf %mc (CVE-2026-5450) ns_sprintrrf buffer overreads (CVE-2026-6238) ns_sprintrrf buffer overflow in TSIG record processing (CVE-2026-5435) Memory corruption in ungetwc (CVE-2026-5928)
https://security-tracker.debian.org/tracker/DSA-6245-1
https://security-tracker.debian.org/tracker/DSA-6246-1
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For Debian 11 bullseye, these problems have been fixed in version 6.1.170-1~deb11u1.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For Debian 11 bullseye, these problems have been fixed in version 5.10.251-3.
This update provides various security fixes. Buffer overflow in scanf %mc (CVE-2026-5450) ns_sprintrrf buffer overreads (CVE-2026-6238) ns_sprintrrf buffer overflow in TSIG record processing (CVE-2026-5435) Memory corruption in ungetwc (CVE-2026-5928)
Fix NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356) Add upstream patches to build against openssl 4.0 Make configure.ac work with autoconf 2.73
Fixes security defects GHSA-rpm5-65cw-6hj4, GHSA-x2qx-6953-8485, GHSA-7545-fcxq-7j24, and GHSA-v87r-6q3f-2j67.
oxenstored keeps quota related use counts across domain destruction [XSA-483, CVE-2026-23556] Xenstored DoS via XS_RESET_WATCHES command [XSA-484, CVE-2026-23557] grant table v2 race in status page mapping [XSA-486, CVE-2026-23558] x86: Floating Point Divider State Sampling [XSA-488, CVE-2025-54505]
https://security-tracker.debian.org/tracker/DSA-6244-1
https://security-tracker.debian.org/tracker/DSA-6238-1
Three security vulnerabilities were discovered in libexif, a library to reads and writes EXIF metainformation from and to images files, that can causes crashes or information leaks. CVE-2026-32775 If the exif_mnote_data_get_value function in MakerNotes gets passed
Important: vim security update
Important: libtiff security update
Important: xorg-x11-server-Xwayland security update
Important: yggdrasil-worker-package-manager security update
Important: yggdrasil security update
https://security-tracker.debian.org/tracker/DSA-6239-1
https://security-tracker.debian.org/tracker/DSA-6197-3
https://security-tracker.debian.org/tracker/DSA-6240-1
https://security-tracker.debian.org/tracker/DSA-6242-1
https://security-tracker.debian.org/tracker/DSA-6243-1
Important: vim security update
Important: PackageKit security update
Important: xorg-x11-server security update
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or sandbox escape. For Debian 11 bullseye, these problems have been fixed in version 140.10.1esr-1~deb11u1.
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Several security issues were fixed in OpenSSH.
An update that solves two vulnerabilities and has one security fix can now be installed.
Multiple vulnerabilities where identified in polkit, a toolkit for defining and handling the policy that allows unprivileged processes to speak to privileged processes. CVE-2021-4115 Kevin Backhouse of GitHub Security Lab (GHSL) found that there is a
PackageKit could be made to install packages as the administrator.
An update that solves 14 vulnerabilities and has five security fixes can now be installed.
An update that solves 14 vulnerabilities and has five security fixes can now be installed.
https://security-tracker.debian.org/tracker/DSA-6236-1
https://security-tracker.debian.org/tracker/DSA-6237-1
https://security-tracker.debian.org/tracker/DSA-6231-1
Important: gdk-pixbuf2 security update
Important: firefox security update
Important: kernel security update
Important: sudo security update
Important: grafana security update
Important: firefox security update
https://security-tracker.debian.org/tracker/DSA-6232-1
https://security-tracker.debian.org/tracker/DSA-6233-1
https://security-tracker.debian.org/tracker/DSA-6234-1
https://security-tracker.debian.org/tracker/DSA-6235-1
Several security issues were fixed in nginx.
Pillow could be made to crash if it opened a specially crafted file.
HAProxy could be made to expose sensitive information over the network.
Little CMS could be made to crash or run programs if it opened a specially crafted ICC profile.
ClamAV could be made to crash if it opened a specially crafted HTML file.
Several security issues were fixed in strongSwan.
An update that solves 25 vulnerabilities can now be installed.
Important: kernel-rt security update
Important: kernel-rt security update
Important: kernel-rt security update
