Update to version 0.16.1 for various bugfixes. This also fixes CVE-2025-22872 in the bundled golang.org/x/net/html.
Resolves CVE-2024-38824 RHBZ#2372731 Resolves CVE-2024-38824 RHBZ#2372733 Resolves CVE-2025-22239 RHBZ#2372732 Resolves CVE-2025-22239 RHBZ#2372734 Resolves CVE-2025-22236 RHBZ#2372774
Update to release v1.32.6
https://security-tracker.debian.org/tracker/DSA-5953-1
Update to 138.0.7204.49 CVE-2025-6555: Use after free in Animation CVE-2025-6556: Insufficient policy enforcement in Loader CVE-2025-6557: Insufficient data validation in DevTools
Automatic update for podman-5.5.2-1.fc41. security fix for CVE-2025-6032 Changelog for podman * Tue Jun 24 2025 Packit – 5:5.5.2-1 – Update to 5.5.2 upstream release
Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517
Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517
xorg-x11-server CVE fix for CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180
Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517
https://security-tracker.debian.org/tracker/DSA-5951-1
* bsc#1232908 * bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062
* bsc#1235231 Cross-References: * CVE-2024-56601
* bsc#1239948 * bsc#1244304 * bsc#1244503 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5952-1
https://security-tracker.debian.org/tracker/DSA-5950-1
Several security issues were fixed in libarchive.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
* bsc#1243565 * bsc#1245054 * bsc#1245055 Cross-References:
* bsc#1236217 * bsc#1244156 * bsc#1244157 * bsc#1244158 * jsc#SLE-18320
https://security-tracker.debian.org/tracker/DSA-5949-1
https://security-tracker.debian.org/tracker/DSA-5948-1
* bsc#1244148 Cross-References: * CVE-2011-10007
* bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062 * bsc#1235231
Nils Emmerich discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.
commons-beanutils, utility for manipulating Java beans have an improper Access Control vulnerability. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers
* bsc#1239192 Cross-References: * CVE-2025-22868
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Template injection that can lead to XSS has been fixed in node-send, a Node.js module for streaming files over HTTP. For Debian 11 bullseye, this problem has been fixed in version
* bsc#1241067 * bsc#1243273 * bsc#1244032 * bsc#1244056 * bsc#1244059
* bsc#1234421 * bsc#1244405 * bsc#1244406 Cross-References:
* bsc#1243721 Cross-References: * CVE-2025-5222
https://security-tracker.debian.org/tracker/DSA-5947-1
Update to 137.0.7151.119 * CVE-2025-6191: Integer overflow in V8 * CVE-2025-6192: Use after free in Profiler
Harden temporary private mounts (#2373301)
4.9.0
This is the .NET monthly update for June 2025. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release-notes/9.0/9.0.6/9.0.107.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.6/9.0.6.md
Fix improper access control vulnerability Resolves: CVE-2025-48734
https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/OXIGQIHBL26HFKG6TT5SWSH7K7W6RO4H/ https://phabricator.wikimedia.org/T382326
https://security-tracker.debian.org/tracker/DSA-5946-1
https://security-tracker.debian.org/tracker/DSA-5945-1
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
* bsc#1241158 * bsc#1241160 * bsc#1243282 * bsc#1243286 * bsc#1243288
* bsc#1234449 Cross-References: * CVE-2024-47606
* bsc#1239192 Cross-References: * CVE-2025-22868
* bsc#1227690 Cross-References: * CVE-2024-38526
* bsc#1233012 * bsc#1243273 * bsc#1244401 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5944-1
It was discovered that an Out Of Memory error may occur when attempting to initialize a huge byte array, even when maxFrameSize is set. For Debian 11 bullseye, this problem has been fixed in version
* bsc#1234415 * bsc#1234450 * bsc#1234453 * bsc#1234455 * bsc#1234456
Several security issues were fixed in Samba.
Several security issues were fixed in Express.
* bsc#1238681 * bsc#1239192 Cross-References: * CVE-2025-22868
https://security-tracker.debian.org/tracker/DSA-5943-1
* bsc#1154353 * bsc#1156395 * bsc#1170891 * bsc#1173139 * bsc#1184350
* bsc#1244039 Cross-References: * CVE-2024-47081
* bsc#1244039 Cross-References: * CVE-2024-47081
* bsc#1244039 Cross-References: * CVE-2024-47081
* bsc#1223096 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757
Django could be made to log injection if received specially crafted input.
Update to 128.11.1 https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/
Fixes CVE-2025-32873: Denial-of-service possibility in strip_tags() Fixes CVE-2025-48432: Potential log injection via unescaped request path
Rebuild for CVE-2024-12224, CVE-2025-4574
Rebuild against idna 1.0+ for CVE-2024-12224
* bsc#1215935 * bsc#1215936 * bsc#1233606 * bsc#1233608 * bsc#1233609
* bsc#1242015 Cross-References: * CVE-2025-3891
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Several security issues were fixed in ModSecurity.
A stack-based buffer overflow has been fixed in ICU, a C++ and C library for Unicode and Globalization support. For Debian 11 bullseye, this problem has been fixed in version
Two vulnerabilities have been fixed in cJSON, a C library for parsing JSON. CVE-2023-26819
An input sanitization flaw in Konsole might allow remote attackers to execute commands via a malicious URL
An integer overflow vulnerability has been found in sysstat which could result in arbitrary code execution.
