Multiple stack-based buffer overflows have been fixed in the net-tools network utilities. For Debian 11 bullseye, this problem has been fixed in version
Double free on init failure has been fixed in libvpx, a library for decoding and encoding VP8 and VP9 videos. For Debian 11 bullseye, this problem has been fixed in version
Several issues have been found in espeak-ng, a Multi-lingual software speech synthesizer. The issues are related to buffer overflow or underflow in several
Buffer underflow on glib through glib/gstring.c via function g_string_insert_unichar. (CVE-2025-4373) References: – https://bugs.mageia.org/show_bug.cgi?id=34310
Heap buffer under-read in gnu coreutils sort via key specification. (CVE-2025-5278) References: – https://bugs.mageia.org/show_bug.cgi?id=34313
Multiple security issues were discovered in Flask-CORS, a Flask extension for handling Cross Origin Resource Sharing (CORS). CVE-2024-1681
New upstream version (139.0)
This update contains the backported fix for CVE-2024-52804 (cookie parsing DoS vuln).
https://security-tracker.debian.org/tracker/DSA-5931-1
https://security-tracker.debian.org/tracker/DSA-5930-1
Apport could be made to leak sensitive information.
* bsc#1243353 Cross-References: * CVE-2025-5263 * CVE-2025-5264
* bsc#1241274 * bsc#1241275 * bsc#1241276 * bsc#1242208 * bsc#1243429
* bsc#1242300 * bsc#1243284 Cross-References: * CVE-2025-47268
* bsc#1242931 Cross-References: * CVE-2025-4207
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code or information disclosure. For Debian 11 bullseye, these problems have been fixed in version
https://security-tracker.debian.org/tracker/DSA-5932-1
https://security-tracker.debian.org/tracker/DSA-5923-2
https://security-tracker.debian.org/tracker/DSA-5928-1
* bsc#1242008 * bsc#1242009 Cross-References: * CVE-2025-31650
* bsc#1236217 * bsc#1242715 Cross-References: * CVE-2025-22873
* bsc#1241658 * bsc#1241659 Cross-References: * CVE-2025-43965
* bsc#1243216 Cross-References: * CVE-2025-3875 * CVE-2025-3877
* bsc#1242809 Cross-References: * CVE-2025-3887
https://security-tracker.debian.org/tracker/DSA-5929-1
A path traversal vulnerability in `PackageIndex` was found in setuptools. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context.
GNU C Library could be made to crash or run programs if it processed specially crafted dynamically shared library.
* bsc#1243313 Cross-References: * CVE-2025-47273
* bsc#1243356 Cross-References: * CVE-2025-21490
* bsc#1242809 Cross-References: * CVE-2025-3887
https://security-tracker.debian.org/tracker/DSA-5926-1
https://security-tracker.debian.org/tracker/DSA-5927-1
A flaw was discovered in the dynamic linking support in the GNU C Library, the C standard library implementation used by Debian. Privilege escalation may be possible in statically compiled setuid
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in Intel Microcode.
* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6
PgBouncer is a lightweight connection pooler for PostgreSQL. CVE-2021-3539
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
* bsc#1243313 Cross-References: * CVE-2025-47273
* bsc#1242931 Cross-References: * CVE-2025-4207
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
A few fixes
This is the May 2025 update for .NET 8 for Fedora. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.16/8.0.116.md Runtime: https://github.com/dotnet/core/blob/main/release-
Update to version 12.5.2. Fixes CVE-2025-22247
Update to 128.10.2 https://www.thunderbird.net/en-US/thunderbird/128.10.2esr/releasenotes/
A few fixes
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
Update to 128.10.2 https://www.thunderbird.net/en-US/thunderbird/128.10.2esr/releasenotes/ Update to 128.10.1 https://www.mozilla.org/en-US/security/advisories/mfsa2025-34/ https://www.thunderbird.net/en-US/thunderbird/128.10.1esr/releasenotes/
CVE-2025-46646 ghostscript: Mishandling of Overlong UTF-8 Encoding in decode_utf8() (fedora#2362639, fedora#2362446)
Fix for CVE-2025-47268
https://security-tracker.debian.org/tracker/DSA-5925-1
Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel’® Processors may allow an authenticated user to potentially enable information disclosure via local access. (CVE-2024-28956) Insufficient resource pool in the core management mechanism for some
Heap buffer overflow in HTML. (CVE-2025-4096) Out of bounds memory access in DevTools. (CVE-2025-4050) Insufficient data validation in DevTools. (CVE-2025-4051) Inappropriate implementation in DevTools. (CVE-2025-4052) Use after free in WebAudio. (CVE-2025-4372)
* bsc#1229504 * bsc#1233019 * bsc#1234847 Cross-References:
* bsc#1233019 * bsc#1234847 Cross-References: * CVE-2024-50115
* bsc#1233019 * bsc#1233678 * bsc#1234847 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5924-1
libfcgi-perl could be made to crash or execute arbitrary code.
* bsc#1243268 Cross-References: * CVE-2025-47287
Update to version 0.2.6.
Latest upstream release. Changelog: https://github.com/gorhill/uBlock/releases/tag/1.64.0 . Fixes CVE-2025-4215 .
Update to version 0.2.6.
PostgreSQL could be made to crash if it received specially crafted network traffic.
* bsc#1215199 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757
* bsc#1235958 * bsc#1235971 * bsc#1239651 * bsc#1242971 * jsc#PED-12028
* bsc#1242622 * jsc#PED-12028 Cross-References: * CVE-2025-3416
* bsc#1240897 Cross-References: * CVE-2025-3360
* bsc#1234847 Cross-References: * CVE-2024-53156
* bsc#1205495 * bsc#1230764 * bsc#1231103 * bsc#1231450 * bsc#1231910
Several security issues were fixed in the Linux kernel.
* bsc#1242631 * bsc#1243177 Cross-References: * CVE-2025-3416
Microcode updates has been released for Intel(R) processors, addressing multiple potential vulnerabilties that may allow denial of service or information disclosure.
