Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Fix CVE-2025-49112 Fix CVE-2025-49112

Security update

New version 4.4.7 Ignoring potential error when using udevadm in %post scriptlet

Update to 137.0.7151.103 CVE-2025-5958: Use after free in Media CVE-2025-5959: Type Confusion in V8

This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574

This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574

This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574

This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574

Update to 3.12.11. gh-135034: [CVE 2024-12718] [CVE 2025-4138] [CVE 2025-4330] [CVE 2025-4435] [CVE 2025-4517] Fixes multiple issues that allowed tarfile extraction filters (filter=”data” and filter=”tar”) to be bypassed using crafted symlinks and hard links.

Fix CVE-2025-49466 (fedora#2370375)

Reevaluating Security in Open-Source: Is a Baseline Truly Sufficient?

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Linux ELF Malware: The New Front in the Battle for Cloud Security
A Closer Look at Apples Native macOS Container Tool
Fingwit: Biometric Authentication & Dynamic Security on Linux
Talos Linux: Redefining Security for Kubernetes Environments

https://security-tracker.debian.org/tracker/DSA-5942-1

* bsc#1240750 * bsc#1240752 * bsc#1240754 * bsc#1240756 * bsc#1240757

* bsc#1244035 Cross-References: * CVE-2025-22868 * CVE-2025-22869

* bsc#1237147 * bsc#1241938 * bsc#1243106 Cross-References:

* bsc#1242300 Cross-References: * CVE-2025-47268

* bsc#1232900 * bsc#1236701 * bsc#1239077 * bsc#1239096

* bsc#1236701 * bsc#1239077 * bsc#1239096 Cross-References:

The open source paradox: Unpacking risk, equity and acceptance
Red Hat’s global impact on Linux security

* bsc#1238324 * bsc#1239077 Cross-References: * CVE-2022-49080

* bsc#1243273 Cross-References: * CVE-2025-4516

* bsc#1239949 * bsc#1241050 * bsc#1243217 * bsc#1243218

* bsc#1239949 * bsc#1241050 * bsc#1243217 * bsc#1243218

https://security-tracker.debian.org/tracker/DSA-5941-1

Not-So-Secure Boot: 2 Secure Boot Exploits Discovered

* bsc#1234282 * bsc#1238043 * bsc#1243117 Cross-References:

* bsc#1238324 * bsc#1239077 Cross-References: * CVE-2022-49080

* bsc#1236701 * bsc#1239077 * bsc#1239096 Cross-References:

* bsc#1232900 * bsc#1236701 * bsc#1239077 * bsc#1239096

Several security issues were fixed in tomcat8, tomcat9, tomcat10.

https://security-tracker.debian.org/tracker/DSA-5940-1

DoS with sanitiseArg/sanitizeArg has been fixed in modsecurity-apache, a module for the Apache webserver to tighten Web application security. For Debian 11 bullseye, this problem has been fixed in version

The 2024 Red Hat Product Security Risk Report: CVEs, XZ Backdoor, SSCAs, AI…oh my!

Disallowing use of the arcfour-hmac(-md5) encryption type for session keys Add support for the PKINIT paChecksum2 sequence, required for Active Directory interoperability on Windows Server 2025 Fix generation of RADIUS Message-Authenticator in FIPS mode

Kirill Firsov discovered that Roundcube, a skinnable AJAX based webmail solution for IMAP servers, was performing PHP Object deserialization on unvalidated input, which could lead to remote code execution by an authenticated attacker.

Several vulnerabilities were discovered in modsecurity-apache, an Apache module to tighten the Web application security, which may result in denial of service (high memory consumption).

New libvpx packages are available for Slackware 15.0 and -current to fix security issues.

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and calls pg_insert_id() with user-supplied data.

Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump. (CVE-2025-4598) References:

Security constraint bypass for CGI scripts. (CVE-2025-46701) References: – https://bugs.mageia.org/show_bug.cgi?id=34332 – https://openwall.com/lists/oss-security/2025/05/29/4

Update to version 4.21.6

Add patch for double free

Fix CVE-2025-23016

Update to Samba 4.22.2 – Security fix for CVE-2025-0620

Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink

This update includes mod_security version 2.9.9 which addresses CVE-2025-47947 and includes various bug fixes. See https://github.com/owasp- modsecurity/ModSecurity/releases/tag/v2.9.9 for more information on the changes in this release.

Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink

This update includes mod_security version 2.9.9 which addresses CVE-2025-47947 and includes various bug fixes. See https://github.com/owasp- modsecurity/ModSecurity/releases/tag/v2.9.9 for more information on the changes in this release.

* bsc#1243268 Cross-References: * CVE-2025-47287

* bsc#1236826 * bsc#1239671 * bsc#1241012 Cross-References:

* bsc#1240392 Cross-References: * CVE-2025-2704

* bsc#1236974 Cross-References: * CVE-2024-12243

Several security issues were fixed in the Linux kernel.

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-24223

https://security-tracker.debian.org/tracker/DSA-5937-1

https://security-tracker.debian.org/tracker/DSA-5938-1

https://security-tracker.debian.org/tracker/DSA-5939-1

Several security issues were fixed in Bootstrap.

Several security issues were fixed in the Linux kernel.

* bsc#1243332 * bsc#1243422 * bsc#1243423 Cross-References:

* bsc#1243313 Cross-References: * CVE-2025-47273

* bsc#1241274 * bsc#1241275 * bsc#1241276 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5936-1

https://security-tracker.debian.org/tracker/DSA-5935-1

https://security-tracker.debian.org/tracker/DSA-5934-1

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to “*.example.com”, a request to “[::1%25.example.com]:80` will incorrectly match and not be proxied – CVE-2025-22870.

Several security issues were fixed in the Linux kernel.

The Hidden Security Risks of Open-Source AI

Open VM Tools could be made to overwrite files as the administrator.

Several security issues were fixed in MariaDB.

Fix for local information disclosure in systemd-coredump (CVE-2025-4598) Various other fixes

Two security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. CVE-2025-47779

* bsc#1214960 * bsc#1230092 Cross-References: * CVE-2024-45310

* bsc#1215199 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757

* bsc#1215199 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757

* bsc#1231284 Cross-References: * CVE-2024-8508

* bsc#1237367 * bsc#1239185 * bsc#1239322 * bsc#1239765 * jsc#PED-12534

* bsc#1234128 * bsc#1234665 * bsc#1239883 * bsc#1243317

Unlock sensitive data for AI with Cloudera on Red Hat OpenShift

twitter-bootstrap3 a popular front end framework was affected by a vulnerability. A cross-site scripting (XSS) vulnerability

A vulnerability has been found in kitty, a fast, featureful, GPU based terminal emulator, which possible allows arbitrary code execution. CVE-2022-41322

Update to 128.11.0 https://www.thunderbird.net/en-US/thunderbird/128.11.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-46/

Fix for local information disclosure in systemd-coredump (CVE-2025-4598) Fixes for systemd itself, run0, systemd-networkd, “secure” pager, man pages, shell completions, sd-boot, sd-varlink Hardware database update

https://security-tracker.debian.org/tracker/DSA-5933-1