Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Multiple stack-based buffer overflows have been fixed in the net-tools network utilities. For Debian 11 bullseye, this problem has been fixed in version

Double free on init failure has been fixed in libvpx, a library for decoding and encoding VP8 and VP9 videos. For Debian 11 bullseye, this problem has been fixed in version

Several issues have been found in espeak-ng, a Multi-lingual software speech synthesizer. The issues are related to buffer overflow or underflow in several

Buffer underflow on glib through glib/gstring.c via function g_string_insert_unichar. (CVE-2025-4373) References: – https://bugs.mageia.org/show_bug.cgi?id=34310

Heap buffer under-read in gnu coreutils sort via key specification. (CVE-2025-5278) References: – https://bugs.mageia.org/show_bug.cgi?id=34313

Multiple security issues were discovered in Flask-CORS, a Flask extension for handling Cross Origin Resource Sharing (CORS). CVE-2024-1681

New upstream version (139.0)

This update contains the backported fix for CVE-2024-52804 (cookie parsing DoS vuln).

https://security-tracker.debian.org/tracker/DSA-5931-1

https://security-tracker.debian.org/tracker/DSA-5930-1

Apport could be made to leak sensitive information.

* bsc#1243353 Cross-References: * CVE-2025-5263 * CVE-2025-5264

* bsc#1241274 * bsc#1241275 * bsc#1241276 * bsc#1242208 * bsc#1243429

* bsc#1242300 * bsc#1243284 Cross-References: * CVE-2025-47268

* bsc#1242931 Cross-References: * CVE-2025-4207

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code or information disclosure. For Debian 11 bullseye, these problems have been fixed in version

https://security-tracker.debian.org/tracker/DSA-5932-1

https://security-tracker.debian.org/tracker/DSA-5923-2

https://security-tracker.debian.org/tracker/DSA-5928-1

* bsc#1242008 * bsc#1242009 Cross-References: * CVE-2025-31650

* bsc#1236217 * bsc#1242715 Cross-References: * CVE-2025-22873

* bsc#1241658 * bsc#1241659 Cross-References: * CVE-2025-43965

* bsc#1243216 Cross-References: * CVE-2025-3875 * CVE-2025-3877

* bsc#1242809 Cross-References: * CVE-2025-3887

Tails and Tor: A New Alliance for Digital Security

https://security-tracker.debian.org/tracker/DSA-5929-1

A path traversal vulnerability in `PackageIndex` was found in setuptools. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context.

GNU C Library could be made to crash or run programs if it processed specially crafted dynamically shared library.

* bsc#1243313 Cross-References: * CVE-2025-47273

* bsc#1243356 Cross-References: * CVE-2025-21490

* bsc#1242809 Cross-References: * CVE-2025-3887

Revive Your Old PC & Fortify Your System with FunOS

https://security-tracker.debian.org/tracker/DSA-5926-1

https://security-tracker.debian.org/tracker/DSA-5927-1

A flaw was discovered in the dynamic linking support in the GNU C Library, the C standard library implementation used by Debian. Privilege escalation may be possible in statically compiled setuid

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in Intel Microcode.

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

PgBouncer is a lightweight connection pooler for PostgreSQL. CVE-2021-3539

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

* bsc#1243313 Cross-References: * CVE-2025-47273

* bsc#1242931 Cross-References: * CVE-2025-4207

New updates for Red Hat Enterprise Linux on confidential virtual machines

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Data Security Best Practices for Strengthening Linux Networks

A few fixes

This is the May 2025 update for .NET 8 for Fedora. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.16/8.0.116.md Runtime: https://github.com/dotnet/core/blob/main/release-

Update to version 12.5.2. Fixes CVE-2025-22247

Update to 128.10.2 https://www.thunderbird.net/en-US/thunderbird/128.10.2esr/releasenotes/

A few fixes

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Update to 128.10.2 https://www.thunderbird.net/en-US/thunderbird/128.10.2esr/releasenotes/ Update to 128.10.1 https://www.mozilla.org/en-US/security/advisories/mfsa2025-34/ https://www.thunderbird.net/en-US/thunderbird/128.10.1esr/releasenotes/

CVE-2025-46646 ghostscript: Mishandling of Overlong UTF-8 Encoding in decode_utf8() (fedora#2362639, fedora#2362446)

Fix for CVE-2025-47268

https://security-tracker.debian.org/tracker/DSA-5925-1

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel’® Processors may allow an authenticated user to potentially enable information disclosure via local access. (CVE-2024-28956) Insufficient resource pool in the core management mechanism for some

Heap buffer overflow in HTML. (CVE-2025-4096) Out of bounds memory access in DevTools. (CVE-2025-4050) Insufficient data validation in DevTools. (CVE-2025-4051) Inappropriate implementation in DevTools. (CVE-2025-4052) Use after free in WebAudio. (CVE-2025-4372)

Understanding Security Threats In Open-Source Software Supply Chains
RHEL 10 Enhances Security Across Hybrid Environments

* bsc#1229504 * bsc#1233019 * bsc#1234847 Cross-References:

* bsc#1233019 * bsc#1234847 Cross-References: * CVE-2024-50115

* bsc#1233019 * bsc#1233678 * bsc#1234847 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5924-1

Understanding Malicious .desktop Files: A Persistent Threat to Linux Systems
Tails 6.15.1 Fixes Critical Tor Browser Flaws
The road to quantum-safe cryptography in Red Hat OpenShift
Unleashing innovation in Red Hat Enterprise Linux with extensions repository
Post-quantum cryptography in Red Hat Enterprise Linux 10
Zero trust workload identity manager now available in tech preview
EMEA blog | Dutch | Red Hat OpenShift Comes Out Exceptionally Strong in Data Security Survey Results
How HashiCorp Vault and Red Hat OpenShift can work together

libfcgi-perl could be made to crash or execute arbitrary code.

* bsc#1243268 Cross-References: * CVE-2025-47287

Update to version 0.2.6.

Latest upstream release. Changelog: https://github.com/gorhill/uBlock/releases/tag/1.64.0 . Fixes CVE-2025-4215 .

Update to version 0.2.6.

PostgreSQL could be made to crash if it received specially crafted network traffic.

* bsc#1215199 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757

* bsc#1235958 * bsc#1235971 * bsc#1239651 * bsc#1242971 * jsc#PED-12028

* bsc#1242622 * jsc#PED-12028 Cross-References: * CVE-2025-3416

Microsoft Open-Sources WSL Years After Its Debut

* bsc#1240897 Cross-References: * CVE-2025-3360

* bsc#1234847 Cross-References: * CVE-2024-53156

* bsc#1205495 * bsc#1230764 * bsc#1231103 * bsc#1231450 * bsc#1231910

Several security issues were fixed in the Linux kernel.

* bsc#1242631 * bsc#1243177 Cross-References: * CVE-2025-3416

Microcode updates has been released for Intel(R) processors, addressing multiple potential vulnerabilties that may allow denial of service or information disclosure.