Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

.NET could be used to perform spoofing over a network.

* bsc#1228634 * bsc#1232533 * bsc#1241012 * bsc#1241045

New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.

Enable CSS Overscroll Behavior by default. Change threaded rendering implementation to use Skia API instead of WebCore display list that is not thread safe. Fix rendering when device scale factor change comes before the web view geometry update.

Mohamed Maatallah discovered a stack-based buffer overflow in the get_name() function in net-tools, a collection of programs for controlling the network subsystem of the Linux kernel, which may result in denial of service (application crash) or potentially the execution of

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Update to 136.0.7103.113 CVE-2025-4664: Insufficient policy enforcement in Loader CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo

Update to 1.25.0

Update to 136.0.7103.113 CVE-2025-4664: Insufficient policy enforcement in Loader CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo

Update to 1.25.0

https://security-tracker.debian.org/tracker/DSA-5922-1

https://security-tracker.debian.org/tracker/DSA-5923-1

https://security-tracker.debian.org/tracker/DSA-5921-1

Using RHEL confidential virtual machines to protect AI workloads on Microsoft Azure

Enable CSS Overscroll Behavior by default. Change threaded rendering implementation to use Skia API instead of WebCore display list that is not thread safe. Fix rendering when device scale factor change comes before the web view geometry update.

x86: Indirect Target Selection [XSA-469, CVE-2024-28956]

update to 4.8.2 fixing CVE-2024-47619

update to 4.8.2 to fix CVE-2024-47619

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

* bsc#1242617 Cross-References: * CVE-2025-3416

* bsc#1236136 * bsc#1236771 Cross-References: * CVE-2024-13176

https://security-tracker.debian.org/tracker/DSA-5919-1

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

* bsc#1218424 * bsc#1236045 * bsc#1236046 * bsc#1236801 * jsc#SLE-18320

Update to 1.9.9 to fix CVE-2025-30194

Update to 1.9.9 to fix CVE-2025-30194

https://security-tracker.debian.org/tracker/DSA-5920-1

It was discovered that insecure file handling in open-vm-tools, an open source implementation of VMware Tools, may allow an unprivileged local guest user to tamper local files to trigger insecure file operations within that VM.

* bsc#1230959 * bsc#1231748 * bsc#1232326 * bsc#1240366 * bsc#1240607

A vulnerability has been discovered in FreeType, which can lead to remote code execution.

Abseil could be made to crash if it received specially crafted input.

Update to 136.0.7103.92 CVE-2025-4372: Use after free in WebAudio

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Emerging ClickFix Attacks Are Now Targeting Linux Systems

* bsc#1242008 * bsc#1242009 Cross-References: * CVE-2025-31650

Several security issues were fixed in the Linux kernel.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5918-1

Unlimited output buffer for unauthenticated clients has been fixed in the key¢”value database Redis. For Debian 11 bullseye, this problem has been fixed in version

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

A vulnerability has been discovered in Orc, which can lead to arbitrary code execution

Multiple vulnerabilities have been discovered in NVIDIA Drivers, the worst of which could result in arbitrary code execution.

PDF signature forgery with adbe.pkcs7.sha1 SubFilter. (CVE-2025-2866) References: – https://bugs.mageia.org/show_bug.cgi?id=34234 – https://lists.debian.org/debian-security-announce/2025/msg00070.html

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on

Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function. (CVE-2025-31162) Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patternarc function.

https://deluge.readthedocs.io/en/deluge-2.2.0/changelog.html 2.2.0 (2025-04-28) Breaking changes Removed Python 3.6 support (Python >= 3.7) Core

5.22.9

Update to version 22.15.0

Update to 47.7 notably fixing CVE-2025-3839

xz 5.8.1

xz 5.8.1

xz 5.8.1

xz 5.8.1

Fixes CVE-2025-47256 .

https://security-tracker.debian.org/tracker/DSA-5917-1

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

* bsc#1224259 Cross-References: * CVE-2024-4853

* bsc#1242210 Cross-References: * CVE-2025-32873

* bsc#1241274 * bsc#1241275 * bsc#1241276 Cross-References:

The dual challenge: Security and compliance
Trust and authenticity: In the kitchen and the software supply chain

A vulnerability has been fixed in mod_auth_openidc, an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality.

Django could be made to crash if it received specially crafted network traffic.

New mariadb packages are available for Slackware 15.0 and -current to fix security issues.

nodejs:18 enhancement update

nodejs:20 enhancement update

Moderate: libXpm security update

The Hidden Risks of Russian-Linked Open-Source Tool easyjson

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-5916-1

CNCF and Synadia Resolve NATS Trademark Dispute

An update that fixes four vulnerabilities is now available.

Several security issues were fixed in OpenJDK 24.

Several security issues were fixed in OpenJDK 21.

Several security issues were fixed in OpenJDK 17.

Several security issues were fixed in OpenJDK 11.

Several security issues were fixed in OpenJDK 8.

* bsc#1223272 * bsc#1234028 * bsc#1235091 * bsc#1235092 * bsc#1236007