https://security-tracker.debian.org/tracker/DSA-6191-1
https://security-tracker.debian.org/tracker/DSA-6190-1
An update that solves two vulnerabilities can now be installed.
Moderate: mariadb:10.11 security update
Undertow would allow unintended access to user sessions over the network.
CVE-2026-4897 aisle.com fix of unsanitized getline
Security fix for CVE-2026-4519
Automatic update for crun-1.27-1.fc43. Changelog for crun * Wed Mar 25 2026 Packit – 1.27-1 – Update to 1.27 upstream release * Mon Dec 22 2025 Packit – 1.26-1
Fix CVE-2026-31812: Bump tar-rs to .5.45 – Closes rhbz#2449672
https://security-tracker.debian.org/tracker/DSA-6189-1
https://security-tracker.debian.org/tracker/DSA-6188-1
Tornado is a scalable, non-blocking Python web framework and asynchronous networking library. CVE-2026-31958 Introduce new limits on the size and complexity of multipart bodies, including a default limit of 100 parts per request to mitigate a
An update that solves three vulnerabilities and has one security fix can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves nine vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves nine vulnerabilities can now be installed.
Several security issues were fixed in Pillow.
An update that solves 25 vulnerabilities can now be installed.
An update that solves 25 vulnerabilities can now be installed.
Several security issues were fixed in pyasn1.
Several security issues were fixed in ImageMagick.
MGAA-2026-0024 – Updated zynaddsubfx packages fix bug
Multiple vulnerabilities were discovered in asterisk, an Open Source Private Branch Exchange (PBX) and telephony toolkit. CVE-2026-23738 XSS vulnerability in the /httpstatus page. Cookie names/values and GET parameter names/values are rendered without HTML-escaping, allowing
An update that solves 655 vulnerabilities, contains four features and has 57 fixes can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves eight vulnerabilities can now be installed.
An update that solves seven vulnerabilities can now be installed.
https://security-tracker.debian.org/tracker/DSA-6187-1
https://security-tracker.debian.org/tracker/DSA-6186-1
https://security-tracker.debian.org/tracker/DSA-6185-1
https://security-tracker.debian.org/tracker/DSA-6184-1
https://security-tracker.debian.org/tracker/DSA-6183-1
MGASA-2026-0073 – Updated python-ujson packages fix security vulnerabilities
MGASA-2026-0072 – Updated strongswan packages fix security vulnerability
Security fix for CVE-2026-4519.
Security fix for CVE-2026-4519.
Rebuilt with rust-tar 0.4.45 for CVE-2026-33056
Rebuilt with rust-tar 0.4.45 for CVE-2026-33056
https://security-tracker.debian.org/tracker/DSA-6181-1
MGASA-2026-0071 – Updated nodejs packages fix security vulnerabilities
MGASA-2026-0070 – Updated libpng packages fix security vulnerabilities
Update to 146.0.7680.164 * High CVE-2026-4673: Heap buffer overflow in WebAudio * High CVE-2026-4674: Out of bounds read in CSS * High CVE-2026-4675: Heap buffer overflow in WebGL * High CVE-2026-4676: Use after free in Dawn
Update to v2.0.52
Update to 1.23.1
Update to 1.23.1
https://security-tracker.debian.org/tracker/DSA-6182-1
https://security-tracker.debian.org/tracker/DSA-6180-1
https://security-tracker.debian.org/tracker/DSA-6179-1
An update that solves seven vulnerabilities can now be installed.
An update that solves eight vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves nine vulnerabilities can now be installed.
An update that solves eight vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
https://security-tracker.debian.org/tracker/DSA-6178-1
An update that solves two vulnerabilities and has one security fix can now be installed.
An update that solves nine vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves 10 vulnerabilities can now be installed.
An update that solves 10 vulnerabilities can now be installed.
Update to 146.0.7680.164 * High CVE-2026-4673: Heap buffer overflow in WebAudio * High CVE-2026-4674: Out of bounds read in CSS * High CVE-2026-4675: Heap buffer overflow in WebGL * High CVE-2026-4676: Use after free in Dawn
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 146.0.7680.164-1~deb12u1.
Update to release v1.9.1
Update to 146.0.7680.153 * CVE-2026-4439: Out of bounds memory access in WebGL * CVE-2026-4440: Out of bounds read and write in WebGL * CVE-2026-4441: Use after free in Base * CVE-2026-4442: Heap buffer overflow in CSS
Update to version 1.3.1 to fix CVE-2026-28356.
Update to release v1.9.1 Resolves: rhbz#2448053, rhbz#2423997, rhbz#2424031 Upstream fixes
Update to 146.0.7680.153 * CVE-2026-4439: Out of bounds memory access in WebGL * CVE-2026-4440: Out of bounds read and write in WebGL * CVE-2026-4441: Use after free in Base * CVE-2026-4442: Heap buffer overflow in CSS
https://security-tracker.debian.org/tracker/DSA-6177-1
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
An update that solves 11 vulnerabilities and has two security fixes can now be installed.
An update that solves 11 vulnerabilities and has two security fixes can now be installed.
An update that solves one vulnerability and has two security fixes can now be installed.
An update that solves one vulnerability and has two security fixes can now be installed.
https://security-tracker.debian.org/tracker/DSA-6175-1
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Net-CIDR could allow unintended access to network services.
Debian Goodies could be made to crash or run programs as your login if it opened a specially crafted file.
# Security update for helm Announcement ID: SUSE-SU-2026:0948-1 Release Date: 2026-03-20T18:07:28Z Rating: important References:
https://security-tracker.debian.org/tracker/DSA-6176-1
https://security-tracker.debian.org/tracker/DSA-6173-1
Jul Blobul discovered that SPIP, a website engine for publishing, is prone to a privilege escalation vulnerability. For the stable distribution (trixie), this problem has been fixed in version 4.4.13+dfsg-0+deb13u1. We recommend that you upgrade your spip packages.
Update to 146.0.7680.80 * CVE-2026-3909: Out of bounds write in Ski
Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens
Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.
Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens
Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.
https://security-tracker.debian.org/tracker/DSA-6174-1
https://security-tracker.debian.org/tracker/DSA-6171-1
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43214 shandikri discovered that processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex
Upstream announcements: WordPress 6.9.2 Release WordPress 6.9.3 and 7.0 beta 4 WordPress 6.9.4 Release
