Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Tornado is a scalable, non-blocking Python web framework and asynchronous networking library. CVE-2025-67724 Custom reason phrases can cause multiple vulnerabilities (like XSS, header injection, …) due to being used unescaped in HTTP headers.

Update to 0.46.3, fixes CVE-2026-24049.

Security fix for CVE-2026-24049

Fix CVE-2025-15536

MGAA-2026-0008 – Updated remove-old-kernels packages fix bugs

https://security-tracker.debian.org/tracker/DSA-6117-1

Moderate: glibc security update

Important: openssl security update

Moderate: curl security update

Important: openssl security update

Moderate: gcc-toolset-15-binutils security update

How Banco do Brasil uses hyperautomation and platform engineering to drive efficiency
From if to how: A year of post-quantum reality

A security issue was discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), this problem has been fixed in version 144.0.7559.109-1~deb12u1.

An update that solves seven vulnerabilities can now be installed.

Best Open-Source Linux Patch Management Software for Secure Linux Servers

MGASA-2026-0029 – Updated openssl packages fix security vulnerabilities

MGASA-2026-0028 – Updated gpsd packages fix security vulnerabilities

MGASA-2026-0027 – Updated libxml2 packages fix security vulnerabilities

MGASA-2026-0026 – Updated xen packages fix security vulnerabilities

https://security-tracker.debian.org/tracker/DSA-6116-1

https://security-tracker.debian.org/tracker/DSA-6114-1

Several security issues were fixed in containerd.

Several security issues were fixed in wlc.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves seven vulnerabilities can now be installed.

Upgrade to upstream. Eliminates distributing harfbuzz sources. Upgrade to upstream 0.032.

https://security-tracker.debian.org/tracker/DSA-6115-1

https://security-tracker.debian.org/tracker/DSA-6113-1

End-to-end security for AI: Integrating AltaStata Storage with Red Hat OpenShift confidential containers

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

# Recommended update for kernel-firmware Announcement ID: SUSE-SU-2026:0305-1 Release Date: 2026-01-27T16:15:14Z Rating: important References:

An update that solves two vulnerabilities can now be installed.

https://security-tracker.debian.org/tracker/DSA-6111-1

An update that solves 22 vulnerabilities, contains one feature and has six security fixes can now be installed.

An update that solves 22 vulnerabilities, contains one feature and has six security fixes can now be installed.

An update that solves 22 vulnerabilities, contains one feature and has six security fixes can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect certificate validation, CRLF injection or man-in-the-middle attacks. For the stable distribution (trixie), these problems have been fixed in version 21.0.10+7-1~deb13u1.

https://security-tracker.debian.org/tracker/DSA-6112-1

An update that solves 395 vulnerabilities, contains 29 features and has 43 security fixes can now be installed.

An update that solves seven vulnerabilities and has one security fix can now be installed.

An update that solves seven vulnerabilities and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Understanding security embargoes at Red Hat
New observability features in Red Hat OpenShift 4.20 and Red Hat Advanced Cluster Management 2.15

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect certificate validation, CRLF injection or man-in-the-middle attacks. For the oldstable distribution (bookworm), these problems have been fixed in version 17.0.18+8-1~deb12u1.

An update that solves one vulnerability and has 2 bug fixes can now be installed.

An update that solves 4 vulnerabilities and has 5 bug fixes can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

https://security-tracker.debian.org/tracker/DSA-6110-1

https://security-tracker.debian.org/tracker/DSA-6109-1

Security fix for CVE-2025-12084

Security fix for CVE-2025-12084

https://security-tracker.debian.org/tracker/DSA-6102-2

https://security-tracker.debian.org/tracker/DSA-6108-1

https://security-tracker.debian.org/tracker/DSA-6107-1

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves two vulnerabilities can now be installed.

An update that solves seven vulnerabilities can now be installed.

2025 was a year of transformative customer success with Red Hat Ansible Automation Platform
2025 Red Hat Ansible Automation Platform: A year in review
From manual to agentic: streamlining IT processes with Red Hat OpenShift AI
Event-Driven Ansible: Simplified event routing with Event Streams
Automating Microsoft Endpoint Configuration Manager with Red Hat Ansible Automation Platform

An update that solves 392 vulnerabilities, contains 16 features and has 47 security fixes can now be installed.

An update that solves 392 vulnerabilities, contains 16 features and has 47 security fixes can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-6105-1

An update that solves three vulnerabilities can now be installed.

Kyu Neushwaistein discovered that telnetd from inetutils does not sanitize the USER environment variable before passing it on to login. A remote attacker can take advantage of this flaw to login as root, bypassing normal authentication processes. For the oldstable distribution (bookworm), this problem has been fixed

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Evolving Linux Malware Threats: A Guide for Admins in Cloud-Native Contexts

https://security-tracker.debian.org/tracker/DSA-6106-1

https://security-tracker.debian.org/tracker/DSA-6104-1

GLib could be made to crash or run programs if it received specially crafted input.

An update that solves two vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves nine vulnerabilities can now be installed.

An update that solves nine vulnerabilities can now be installed.

An update that solves 17 vulnerabilities, contains one feature and has one security fix can now be installed.