Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

https://security-tracker.debian.org/tracker/DSA-6212-1

https://security-tracker.debian.org/tracker/DSA-6213-1

https://security-tracker.debian.org/tracker/DSA-6209-1

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Important: fontforge security update

Important: perl-XML-Parser security update

It was discovered that gdk-pixbuf, the GDK Pixbuf library, does not properly validate color component counts in the JPEG image loader, which may result in the execution of arbitrary code or denial of service if specially crafted JPEG images are processed. For Debian 11 bullseye, this problem has been fixed in version

Several security issues were fixed in polkit.

Why Your “Shadow IT” Developer Tools Are the Biggest Risk to Your Linux Systems

BIND a popular name server (DNS) was affected by a vulnerability. If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure or incomplete permission checks. For the oldstable distribution (bookworm), these problems have been fixed in version 1:1.39.17-1+deb12u2.

Multiple security vulnerabilities were discovered in Flatpak, an application deployment framework for desktop apps, which could allow a Flatpak app to delete arbitrary hosts on the host or break out of the sandbox resulting in code execution in the host context. For the stable distribution (trixie), these problems have been fixed in

MGASA-2026-0096 – Updated libpng12 packages fix security vulnerability

MGASA-2026-0095 – Updated tomcat packages fix security vulnerabilities

MGASA-2026-0094 – Updated squid packages fix security vulnerabilities

Moderate: kernel security update

https://security-tracker.debian.org/tracker/DSA-6207-1

https://security-tracker.debian.org/tracker/DSA-6208-1

Navigating the Mythos-haunted world of platform security
MCP security: Logging and runtime security measures

Important: kea security update

Several vulnerabilities were discovered in the inetutils implementation of telnetd and telnet, which may result in privilege escalation or information disclosure. CVE-2026-28372 Ron Ben Yizhak from SafeBreach found that the fix for CVE-2026-24061 was

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 140.9.1esr-1~deb11u1.

https://security-tracker.debian.org/tracker/DSA-6206-1

https://security-tracker.debian.org/tracker/DSA-6204-1

An update that solves one vulnerability can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

New upstream release (#2442363) fixing various security issues

Update to latest upstream

https://security-tracker.debian.org/tracker/DSA-6205-1

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

Important: fontforge security update

Moderate: ncurses security update

https://security-tracker.debian.org/tracker/DSA-6201-1

Important: fontforge security update

Important: fontforge security update

Moderate: crun security update

Moderate: kernel security update

Moderate: crun security update

Moderate: kernel security update

https://security-tracker.debian.org/tracker/DSA-6202-1

https://security-tracker.debian.org/tracker/DSA-6197-2

33.0.1 release

Update to 9.6.0. Fixes rhbz#2452087

Moderate: kernel-rt security update

Moderate: kernel-rt security update

Moderate: 389-ds:1.4 security update

Important: python3.12 security update

An update that solves six vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves three vulnerabilities and has two security fixes can now be installed.

An update that solves eight vulnerabilities can now be installed.

Several security issues were fixed in SPIP.

https://security-tracker.debian.org/tracker/DSA-6196-1

Update to 1.94.1

Backport fixes for multiple CVEs.

Update to gstreamer-1.26.11.

Update to gstreamer-1.26.11.

Update to gstreamer-1.26.11.

Update to gstreamer-1.26.11.

https://security-tracker.debian.org/tracker/DSA-6197-1

https://security-tracker.debian.org/tracker/DSA-6198-1

https://security-tracker.debian.org/tracker/DSA-6199-1

https://security-tracker.debian.org/tracker/DSA-6200-1

https://security-tracker.debian.org/tracker/DSA-6195-1

It was discovered that libxml-parser-perl, a Perl module for parsing XML files, was prone to an off-by-one heap buffer overflow in `st_serial_stack()`. This update also includes a follow-up improvement change for CVE-2006-10002 (buffer overwrite in `parse_stream()`.) For Debian 11 bullseye, these problems have been fixed in version

Security fix for CVE-2026-4519

The update fixes CVS-2026-25061

GSSAPI server: Boundary check gss_wrap token (read OOB)

Security fix for CVE-2026-4519.

Security fix for CVE-2026-4519.

https://security-tracker.debian.org/tracker/DSA-6192-1

The npm Supply Chain Problem: Why Installing Packages Executes Untrusted Code

It was discovered that pyasn1, a generic ASN.1 library for Python, is prone to a denial of service vulnerability when decoding ASN.1 data with deeply nested structures. For the oldstable distribution (bookworm), this problem has been fixed in version 0.4.8-3+deb12u2.

Several vulnerabilities were discovered in the inetutils implementation of telnetd and telnet, which may result in privilege escalation or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 2:2.4-2+deb12u3.

Update to upstream 2.5.2, including fixes for CVE-2026-33757 and CVE-2026-33758

Update to 9.21.20 (rhbz#2440560) Security Fixes: Fix unbounded NSEC3 iterations when validating referrals to unsigned delegations. (CVE-2026-1519) Fix memory leaks in code preparing DNSSEC proofs of non-existence.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 146.0.7680.177-1~deb12u1.

https://security-tracker.debian.org/tracker/DSA-6193-1

https://security-tracker.debian.org/tracker/DSA-6194-1