Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

USN-6200-2 introduced a regression in ImageMagick.

Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after free in USB

rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered. See https://www.arin.net/announcements/20250116-tal/ rpki-client reports Certification Authorities that do not meaningfully participate in the RPKI as non-functional CAs. By definition, a CA is non-

release v1.16.0

By the numbers: Security insights from Red Hat and IBM

Several vulnerabilities were discovered in the Erlang/OTP implementation of the SSH protocol, which may result in denial of service or the execution of arbitrary code.

Fix bz2358011

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.

https://security-tracker.debian.org/tracker/DSA-5906-1

https://security-tracker.debian.org/tracker/DSA-5905-1

https://security-tracker.debian.org/tracker/DSA-5904-1

Several vulnerabilities were discovered in the shadow suite of login tools. An attacker may extract a password from memory in limited situations, and confuse an administrator inspecting /etc/passwd from within a terminal.

New libxml2 packages are available for Slackware 15.0 and -current to fix security issues.

* bsc#1241150 Cross-References: * CVE-2025-32460

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

* bsc#1240958 * bsc#1240961 * bsc#1240962 * bsc#1240963 * bsc#1240964

* bsc#1240893 Cross-References: * CVE-2025-31492

* bsc#1240971 Cross-References: * CVE-2025-32464

* bsc#1240880 * bsc#1240881 Cross-References: * CVE-2025-32364

Expired US Funding Threatened to Disrupt Security Flaw Tracking

https://security-tracker.debian.org/tracker/DSA-5903-1

* bsc#1239826 * jsc#MSQA-936 Cross-References: * CVE-2025-23392

* bsc#1240893 Cross-References: * CVE-2025-31492

* bsc#1239863 * bsc#1239864 * bsc#1240958 * bsc#1240961 * bsc#1240962

* bsc#1224295 * bsc#1234840 * bsc#1239308 Cross-References:

* bsc#1239649 Cross-References: * CVE-2024-12088

* bsc#1065729 * bsc#1179878 * bsc#1180814 * bsc#1185762 * bsc#1195823

* bsc#1240971 Cross-References: * CVE-2025-32464

* bsc#1240958 * bsc#1240961 * bsc#1240962 * bsc#1240963 * bsc#1240964

* bsc#1228714 * bsc#1232818 * bsc#1235218 * bsc#1238788 * bsc#1238790

Perl could be made to crash or run programs if it processed specially crafted data.

* bsc#1065729 * bsc#1180814 * bsc#1183682 * bsc#1190336 * bsc#1190768

* bsc#1228714 * bsc#1232818 * bsc#1235218 * bsc#1238788 * bsc#1238790

* bsc#1228714 * bsc#1235218 Cross-References: * CVE-2024-41090

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure, cross-site scripting or restriction bypass.

Update to 135.0.7049.84 * CVE-2025-3066: Use after free in Site Isolation

Update to 6.0.39 (CVE-2024-45700, CVE-2024-36469, CVE-2024-42325, CVE-2024-45699)

Update to 135.0.7049.84 * CVE-2025-3066: Use after free in Site Isolation

https://security-tracker.debian.org/tracker/DSA-5901-1

https://security-tracker.debian.org/tracker/DSA-5902-1

Multiple vulnerabilities were found in wpa, a set of tools including the widely-used wpasupplicant client for authenticating with WPA and WPA2 wireless networks.

A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN. (CVE-2025-32364) Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in

ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits. (CVE-2025-27795) References: – https://bugs.mageia.org/show_bug.cgi?id=34163

https://security-tracker.debian.org/tracker/DSA-5900-1

https://security-tracker.debian.org/tracker/DSA-5899-1

Update to 1.34.5. Fixes CVE-2025-31498.

Limit the data stored in session state. Remove the empty area below the title bar in Web Inspector when not docked. Fix various crashes and rendering issues

Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate implementation in Intents Medium CVE-2025-3069: Inappropriate implementation in Extensions

Update to 7.2.5 (CVE-2024-36469, CVE-2024-42325, CVE-2024-45700)

* bsc#1073014 Cross-References: * CVE-2017-17521

* bsc#1239618 * jsc#PED-12500 * jsc#SLE-21253 Cross-References:

Update to 2025.04 GA Update to 2025.04 RC5

Update to 128.9.0 https://www.thunderbird.net/en-US/thunderbird/128.9.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-24/

https://security-tracker.debian.org/tracker/DSA-5898-1

HAProxy could be made to crash or run programs if it received specially crafted network traffic.

Repair the bridge before it cracks: Understanding vulnerabilities and weaknesses in modern IT

* bsc#1234452 Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4

CVE-2025-27835 ghostscript: Buffer overflow when converting glyphs to unicode (fedora#2355025) CVE-2025-27834 ghostscript: Buffer overflow caused by an oversized Type 4 function in a PDF (fedora#2355023) CVE-2025-27832 ghostscript: NPDL device: Compression buffer overflow

Dino could be made to expose sensitive information over the network.

* bsc#1239460 Cross-References: * CVE-2025-24049

Securing Kubernetes and Cloud-Native Environments through DevSecOps

An update that fixes one vulnerability is now available.

This update includes an upstream patch to accept “0” as a valid epoch in Debian packages processed by BSSolv. This fixes a bug that prevents the Open Build Service backend from working

* bsc#1207948 * bsc#1215199 * bsc#1215211 * bsc#1218470 * bsc#1221651

Update to 128.9.0 https://www.thunderbird.net/en-US/thunderbird/128.9.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-24/

Expat could be made to crash if it received specially crafted input.

Mastering SSH for Secure Linux Remote Server Management

* bsc#1240416 Cross-References: * CVE-2025-31344

* bsc#1240416 Cross-References: * CVE-2025-31344

Net::EasyTCP Perl module includes encryption functionality that requires a secure random number generator. Until and including the version 0.26, this module used a random number generator without any such guarantees. The reason for this was that it relied on Crypt::Random, a Perl module

Prior to version 0.008, the Perl module Data::Entropy relied on Perl’s builtin rand function to choose an entropy source. Version 0.008 does away with this need.

https://security-tracker.debian.org/tracker/DSA-5897-1

* bsc#1236217 * bsc#1239182 * bsc#1240550 Cross-References:

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

* bsc#1240083 Cross-References: * CVE-2025-3028 * CVE-2025-3029