* bsc#1202828 * bsc#1217770 * bsc#1224413 * jsc#PED-11066 * jsc#PED-1174
* bsc#1202828 * bsc#1217770 * bsc#1224413 * jsc#PED-11066 * jsc#PED-1174
ansible 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1 introduced a regression in the win_template module. This caused win_template tasks to fail with an error. For Debian 11 bullseye, this problem has been fixed in version
Update to 136.0.7103.59 CVE-2025-4096: Heap buffer overflow in HTML CVE-2025-4050: Out of bounds memory access in DevTools CVE-2025-4051: Insufficient data validation in DevTools CVE-2025-4052: Inappropriate implementation in DevTools
April 2025 CPU
A heap-based buffer overflow vulnerability was discovered in vips, an fast image processing library designed with efficiency in mind, which may result in denial of service (application crash) if a specially crafted TIFF image file is processed.
Update to 136.0.7103.59 * CVE-2025-4096: Heap buffer overflow in HTML * CVE-2025-4050: Out of bounds memory access in DevTools * CVE-2025-4051: Insufficient data validation in DevTools * CVE-2025-4052: Inappropriate implementation in DevTools
Update to 128.10.0 https://www.thunderbird.net/en-US/thunderbird/128.10.0esr/releasenotes/
Update to version 0.24.4. Also contains fixes for RUSTSEC-2025-0006.
Update to version 1.5.0 (for now, without PPS feature enabled due to potential correctness issues in the code). Release notes: https://github.com/pendulum-project/ntpd-rs/releases/tag/v1.5.0 Also contains the fix for GHSA-v83q-83hj-rw38.
Update pnpm to version 10.9.0 to fix CVE-2024-47829 and nodejs-bash-language- server to version 5.6.0
https://security-tracker.debian.org/tracker/DSA-5915-1
https://security-tracker.debian.org/tracker/DSA-5914-1
https://security-tracker.debian.org/tracker/DSA-5913-1
Update to 1.17.4 Fixes CVE-2025-23359 or GHSA-4hmh-pm5p-9j7j
Update to 128.10.0 https://www.thunderbird.net/en-US/thunderbird/128.10.0esr/releasenotes/
Update to latest upstream (138.0)
Update to 1.17.4 Fixes CVE-2025-23359 or GHSA-4hmh-pm5p-9j7j
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
Update to 1.17.4 Fixes CVE-2025-23359 or GHSA-4hmh-pm5p-9j7j
https://security-tracker.debian.org/tracker/DSA-5911-1
https://security-tracker.debian.org/tracker/DSA-5910-1
https://security-tracker.debian.org/tracker/DSA-5909-1
Several security issues were fixed in micropython.
The following vulnerability has been discovered in the gorilla/csrf package for Go: Prior to 1.7.3, gorilla/csrf did not validate the Origin header against an allowlist. It executed its validation of the Referer header for
In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used. (CVE-2025-43965) In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order). (CVE-2025-46393)
Multiple vulnerabilties were discovered in u-boot, a boot loader for embedded systems.
Multiple vulnerabilities were discovered in nagvis, a visualization addon for Nagios or Icinga. CVE-2021-33178
Backport proposed fix for CVE-2025-31344 from OpenMandriva.
https://security-tracker.debian.org/tracker/DSA-5912-1
H2O could be made to crash if it received specially crafted network traffic.
PostgreSQL could be made to execute arbitrary code if it received specially crafted input.
* bsc#1233294 * bsc#1235431 Cross-References: * CVE-2024-50205
* bsc#1239909 Cross-References: * CVE-2025-2588
https://security-tracker.debian.org/tracker/DSA-5908-1
Several security issues were fixed in Mistral.
Several security issues were fixed in Mistral.
Apache Tomcat could be made to crash if it received specially crafted network traffic.
Apache Tomcat could be made to crash if it received specially crafted network traffic.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Update to version 2.10.0. Aside from the new upstream features, this update also refreshes many bundled dependencies, fixing a few CVEs. https://github.com/caddyserver/caddy/releases/tag/v2.10.0
Update to version 2.10.0. Aside from the new upstream features, this update also refreshes many bundled dependencies, fixing a few CVEs. https://github.com/caddyserver/caddy/releases/tag/v2.10.0
Heap buffer overflow in Codecs. (CVE-2025-3619) Use after free in USB. (CVE-2025-3620) References: – https://bugs.mageia.org/show_bug.cgi?id=34208
Heap buffer overflow in Codecs. (CVE-2025-3619) Use after free in USB. (CVE-2025-3620) References: – https://bugs.mageia.org/show_bug.cgi?id=34208
Juray Sarinay discovered that PDF documents signed with the adbe.pkcs7.sha1 standard were incompletely validated by LibreOffice, which could cause invalid signatures to be accepted as legitimate.
Juray Sarinay discovered that PDF documents signed with the adbe.pkcs7.sha1 standard were incompletely validated by LibreOffice, which could cause invalid signatures to be accepted as legitimate.
Several security vulnerabilities have been discovered in libsoup2.4, a http client/server library popularly used in GNOME, et.al. CVE-2025-2784
Multiple vulnerabilities have been fixed in the PDF rendering library poppler. CVE-2020-36023
* bsc#1241584 * bsc#1241585 Cross-References: * CVE-2015-3885
* bsc#1239680 Cross-References: * CVE-2025-2312
Jupyter Notebook could be made to crash if it received specially crafted input.
Update to 135.0.7049.114
Update to pgadmin-9.2.
April 2025 CPU
April 2025 CPU
April 2025 CPU
April 2025 CPU
https://security-tracker.debian.org/tracker/DSA-5907-1
[CVE-2025-32414] Buffer overflow when parsing text streams with Python API [CVE-2025-32415] Heap-based Buffer Overflow in xmlSchemaIDCFillNodeTables
BUG/MEDIUM: sample: fix risk of overflow when replacing multiple regex back-refsAleandro Prudenzano of Doyensec and Edoardo Geraci of Codean Labs reported a bug in sample_conv_regsub(), which can cause replacements of multiple back-references to overflow the temporary trash buffer. The problem happens when doing “regsub(match,replacement,g)”:
* bsc#1230092 Cross-References: * CVE-2024-45310
Update to 135.0.7049.114
Update to 135.0.7049.114
New upstream version 5.8.1 (with a rebuild to try and fix a gating problem). New upstream version 5.8.1
* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6
Several security issues were fixed in the Linux kernel.
Update to 1.24.1, fixes CVE-2025-2291.
Backport fixes for CVE-2025-32910, CVE-2025-32911, CVE-2025-32913 Backport fixes for CVE-2025-32050 CVE-2025-32052 CVE-2025-32053 CVE-2025-32906 CVE-2025-32907 CVE-2025-32909
Update to 1.24.1, fixes CVE-2025-2291.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Multiple vulnerabilities have been fixed in the OpenRazer drivers for devices from Razer, a company selling hardware mainly targeted at gamers. CVE-2022-23467
Backport fixes for CVE-2025-32364 and CVE-2025-32365.
Several security issues were fixed in the Linux kernel.
Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after free in USB
Latest updates.
Resolves CVE-2024-53868
Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after free in USB
Latest updates.
Update to 128.9.2 https://www.thunderbird.net/en-US/thunderbird/128.9.1esr/releasenotes/ https://www.thunderbird.net/en-US/thunderbird/128.9.2esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-27/
Backport proposed fix for CVE-2025-31344 from OpenMandriva. Install gif_getarg.h header.
Fix CVE-2024-56406
Fix CVE-2024-56406
Fix CVE-2024-56406
Several security issues were fixed in Eclipse Mosquitto.
Multiple vulnerabilities have been fixed in the fig2dev utilities for converting XFig figure files. CVE-2025-31162
Mishandling of semicolons in the userinfo subcomponent of a URI has been fixed in GNU Wget, a utility for retrieving files over HTTP, HTTPS, FTP and FTPS.
