Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Update to version 0.16.1 for various bugfixes. This also fixes CVE-2025-22872 in the bundled golang.org/x/net/html.

Resolves CVE-2024-38824 RHBZ#2372731 Resolves CVE-2024-38824 RHBZ#2372733 Resolves CVE-2025-22239 RHBZ#2372732 Resolves CVE-2025-22239 RHBZ#2372734 Resolves CVE-2025-22236 RHBZ#2372774

Update to release v1.32.6

https://security-tracker.debian.org/tracker/DSA-5953-1

Red Hat Advanced Cluster Security 4.8 simplifies management, enhances workflows and offers deeper external IP visibility

Update to 138.0.7204.49 CVE-2025-6555: Use after free in Animation CVE-2025-6556: Insufficient policy enforcement in Loader CVE-2025-6557: Insufficient data validation in DevTools

Automatic update for podman-5.5.2-1.fc41. security fix for CVE-2025-6032 Changelog for podman * Tue Jun 24 2025 Packit – 5:5.5.2-1 – Update to 5.5.2 upstream release

Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517

Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517

xorg-x11-server CVE fix for CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180

Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517

https://security-tracker.debian.org/tracker/DSA-5951-1

* bsc#1232908 * bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062

* bsc#1235231 Cross-References: * CVE-2024-56601

* bsc#1239948 * bsc#1244304 * bsc#1244503 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5952-1

https://security-tracker.debian.org/tracker/DSA-5950-1

Several security issues were fixed in libarchive.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

* bsc#1243565 * bsc#1245054 * bsc#1245055 Cross-References:

* bsc#1236217 * bsc#1244156 * bsc#1244157 * bsc#1244158 * jsc#SLE-18320

Ubuntu Chooses Performance Over Mitigation: Intel GPU Users See 20% Gains

https://security-tracker.debian.org/tracker/DSA-5949-1

https://security-tracker.debian.org/tracker/DSA-5948-1

* bsc#1244148 Cross-References: * CVE-2011-10007

* bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062 * bsc#1235231

Nils Emmerich discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.

commons-beanutils, utility for manipulating Java beans have an improper Access Control vulnerability. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers

* bsc#1239192 Cross-References: * CVE-2025-22868

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

IBM Donates CBOM Toolset to Linux Foundation

Template injection that can lead to XSS has been fixed in node-send, a Node.js module for streaming files over HTTP. For Debian 11 bullseye, this problem has been fixed in version

* bsc#1241067 * bsc#1243273 * bsc#1244032 * bsc#1244056 * bsc#1244059

* bsc#1234421 * bsc#1244405 * bsc#1244406 Cross-References:

* bsc#1243721 Cross-References: * CVE-2025-5222

https://security-tracker.debian.org/tracker/DSA-5947-1

Update to 137.0.7151.119 * CVE-2025-6191: Integer overflow in V8 * CVE-2025-6192: Use after free in Profiler

Harden temporary private mounts (#2373301)

4.9.0

This is the .NET monthly update for June 2025. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release-notes/9.0/9.0.6/9.0.107.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.6/9.0.6.md

Fix improper access control vulnerability Resolves: CVE-2025-48734

https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/OXIGQIHBL26HFKG6TT5SWSH7K7W6RO4H/ https://phabricator.wikimedia.org/T382326

https://security-tracker.debian.org/tracker/DSA-5946-1

https://security-tracker.debian.org/tracker/DSA-5945-1

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

* bsc#1241158 * bsc#1241160 * bsc#1243282 * bsc#1243286 * bsc#1243288

* bsc#1234449 Cross-References: * CVE-2024-47606

* bsc#1239192 Cross-References: * CVE-2025-22868

* bsc#1227690 Cross-References: * CVE-2024-38526

* bsc#1233012 * bsc#1243273 * bsc#1244401 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5944-1

It was discovered that an Out Of Memory error may occur when attempting to initialize a huge byte array, even when maxFrameSize is set. For Debian 11 bullseye, this problem has been fixed in version

* bsc#1234415 * bsc#1234450 * bsc#1234453 * bsc#1234455 * bsc#1234456

Several security issues were fixed in Samba.

Updates to Red Hat Advanced Cluster Security for Kubernetes Cloud Service strengthen your security posture

Several security issues were fixed in Express.

* bsc#1238681 * bsc#1239192 Cross-References: * CVE-2025-22868

https://security-tracker.debian.org/tracker/DSA-5943-1

* bsc#1154353 * bsc#1156395 * bsc#1170891 * bsc#1173139 * bsc#1184350

* bsc#1244039 Cross-References: * CVE-2024-47081

* bsc#1244039 Cross-References: * CVE-2024-47081

* bsc#1244039 Cross-References: * CVE-2024-47081

* bsc#1223096 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757

Secure RHEL Clones Chart Diverging Paths

Django could be made to log injection if received specially crafted input.

Update to 128.11.1 https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/

Fixes CVE-2025-32873: Denial-of-service possibility in strip_tags() Fixes CVE-2025-48432: Potential log injection via unescaped request path

Rebuild for CVE-2024-12224, CVE-2025-4574

Rebuild against idna 1.0+ for CVE-2024-12224

* bsc#1215935 * bsc#1215936 * bsc#1233606 * bsc#1233608 * bsc#1233609

* bsc#1242015 Cross-References: * CVE-2025-3891

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in ModSecurity.

Optimizing Linux Security in 2025: Key Strategies & Best Practices

A stack-based buffer overflow has been fixed in ICU, a C++ and C library for Unicode and Globalization support. For Debian 11 bullseye, this problem has been fixed in version

Two vulnerabilities have been fixed in cJSON, a C library for parsing JSON. CVE-2023-26819

An input sanitization flaw in Konsole might allow remote attackers to execute commands via a malicious URL

An integer overflow vulnerability has been found in sysstat which could result in arbitrary code execution.