Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

5.0.0

Update to 0.4.8; Fixes: RHBZ#2237964, RHBZ#2282129

Fix CVE-2024-12905.

Address CVE-2025-30093 – rhbz#2355671

5.0.0

Fix CVE-2024-12905.

Red Hat OpenShift and zero trust: Securing workloads with cert-manager and OpenShift Service Mesh

Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate implementation in Intents Medium CVE-2025-3069: Inappropriate implementation in Extensions

Backport fixes from v1.127.1

This is an update fixing CVE 2025-30232.

Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate implementation in Intents Medium CVE-2025-3069: Inappropriate implementation in Extensions

CVE-2025-27835 ghostscript: Buffer overflow when converting glyphs to unicode (fedora#2355026) CVE-2025-27834 ghostscript: Buffer overflow caused by an oversized Type 4 function in a PDF (fedora#2355024) CVE-2025-27832 ghostscript: NPDL device: Compression buffer overflow

This is an update fixing CVE 2025-30232.

https://security-tracker.debian.org/tracker/DSA-5893-1

https://security-tracker.debian.org/tracker/DSA-5894-1

https://security-tracker.debian.org/tracker/DSA-5895-1

https://security-tracker.debian.org/tracker/DSA-5896-1

https://security-tracker.debian.org/tracker/DSA-5892-1

* bsc#1229122 * bsc#1240550 Cross-References: * CVE-2025-22871

Upgrade to 2.48.0: Move tile rendering to worker threads when rendering with the GPU. Fix preserve-3D intersection rendering. Added new function for creating Promise objects to the JavaScriptCore GLib API. The MediaRecorder backend gained WebM support (requires at least GStreamer

Several security issues were fixed in the Linux kernel.

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP. (CVE-2024-56161)

* bsc#1228012 * bsc#1228578 * bsc#1233023 Cross-References:

* bsc#1238591 * bsc#1239625 * bsc#1239637 Cross-References:

* bsc#1239302 * bsc#1239676 Cross-References: * CVE-2024-56337

* bsc#1240075 * bsc#1240077 * bsc#1240080 * bsc#1240081

https://security-tracker.debian.org/tracker/DSA-5890-1

https://security-tracker.debian.org/tracker/DSA-5891-1

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

* bsc#1234452 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5

* bsc#1219437 * bsc#1234089 * bsc#1237367 * bsc#1239185 * bsc#1239322

* bsc#1240083 Cross-References: * CVE-2025-3028 * CVE-2025-3029

When bots commit: AI-generated code in open source projects

https://security-tracker.debian.org/tracker/DSA-5889-1

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Meet Giovanni Bechis: The New Lead of SpamAssassin’s Future

A security issue was fixed in MariaDB.

* bsc#1237367 * bsc#1239185 * bsc#1239322 Cross-References:

* bsc#1234452 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5

The perl module Data::Entropy was using the cryptographically insecure rand() function as default entropy source. For Debian 11 bullseye, this problem has been fixed in version

Microcode updates has been released for Intel(R) processors, addressing multiple potential vulnerabilties that may allow local privilege escalation, denial of service or information disclosure.

Multiple vulnerabilities were discovered in vim, an enhanced vi editor. CVE-2021-3872

Update to 0.4.8; Fixes: RHBZ#2237964, RHBZ#2282129

An issue has been found in librabbitmq, a AMQP client library and tools written in C. The issue is related to credential visibility when

Update to 2.12.10

CVE-2025-2588

* bsc#1235147 Cross-References: * CVE-2024-5594

* bsc#1239685 Cross-References: * CVE-2025-2361

* bsc#1238685 Cross-References: * CVE-2025-22870

How Cloud Security is Transforming Cybersecurity Services

CVE-2025-2588

Update to 1.1.43, fixes CVE-2024-55549 and CVE-2025-24855.

Added patch for CVE-2024-4068 (rhbz#2280624)

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-5888-1

Several security issues were fixed in the Linux kernel.

Alexander Tan discovered that the OpenSAML C++ library was susceptible to forging of signed SAML messages. For additional details please refer to the upstream advisory at https://shibboleth.net/community/advisories/secadv_20250313.txt

* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869

* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869

* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869

https://security-tracker.debian.org/tracker/DSA-5886-1

* bsc#1239339 Cross-References: * CVE-2025-22869 * CVE-2025-27144

* bsc#1239339 Cross-References: * CVE-2025-22869 * CVE-2025-27144

* bsc#1239460 Cross-References: * CVE-2025-24049

https://security-tracker.debian.org/tracker/DSA-5887-1

This upload fixes two security issues in the version of nginx shipped in bullseye. CVE-2024-7347

* bsc#1239465 Cross-References: * CVE-2025-27363

Several security issues were fixed in SmartDNS.

Update to 134.0.6998.117 * Critical CVE-2025-2476: Use after free in Lens

0.9.30, rebuild due golang CVE-2025-22870

https://security-tracker.debian.org/tracker/DSA-5885-1

Ivan Fratric discovered two use-after-free vulnerabilities in libxslt, an XSLT processing runtime library, which may result in the execution of arbitrary code if a specially crafted files are processed.

Anatomy of Linux Ransomware Attacks and Protection Strategies

Two use-after-free vulnerabilities have been fixed in the XSLT processing library libxslt. CVE-2024-55549

Several security issues were fixed in NLTK.

Update to 134.0.6998.117 * Critical CVE-2025-2476: Use after free in Lens