The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-6093-1
An update that solves 70 vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
Moderate: postgresql:15 security update
A vulnerability was found in Curl, an easy-to-use client-side URL transfer library and command line tool. It can cause a crash or potentially a memory out of bounds read. For Debian 11 bullseye, this problem has been fixed in version 7.74.0-1.3+deb11u16.
Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service or potentially the execution of arbitrary code if malformed XCF, JPEG 2000 or PNM files are opened. For the oldstable distribution (bookworm), these problems have been fixed
Update to 1.148.0
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
https://github.com/wb2osz/direwolf/releases/tag/1.8.1
Correctly handle the program name passed to the sleep disabler. Ensure GStreamer is initialized before using the Quirks. Fix several crashes and rendering issues. Fix CVE-2025-14174, CVE-2025-43501, CVE-2025-43529, CVE-2025-43531, CVE-2025-43535, CVE-2025-43536, CVE-2025-43541
Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442
Update to 2.83.2
https://github.com/wb2osz/direwolf/releases/tag/1.8.1
Two vulnerabilities were discovered in smb4k, a KDE desktop utility which allows unprivileged mounting of Samba/CIFS network shares, which may result in local denial of service or local privilege escalation. For the stable distribution (trixie), these problems have been fixed in version 4.0.0-1+deb13u1.
Rebuilt for CVEs
Rebuilt for CVE-2025-47906
Support for Go 1.26 and security fixes. Upstream release notes.
Rebuilt for CVEs
Support for Go 1.26 and security fixes. Upstream release notes.
https://security-tracker.debian.org/tracker/DSA-6092-1
An update that solves three vulnerabilities can now be installed.
An update that fixes 8 vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes one vulnerability is now available.
Update to 1.1.97
Update to 5.8.0
A Buffer Overflow vulnerability has been found in osslsigncode, a OpenSSL based Authenticode signing tool for PE/MSI/Java CAB files, which possibly allows an malicious attacker to execute arbitrary code when signing a crafted file. For Debian 11 bullseye, this problem has been fixed in version
An update that solves four vulnerabilities can now be installed.
An update that solves one vulnerability and has one security fix can now be installed.
An update that solves one vulnerability and has one security fix can now be installed.
Rebuilt for CVE-2025-61723
Rebuild for CVEs
Multiple vulnerabilities have been discovered in Kodi, a media-player and entertainment hub. CVE-2023-23082 A heap buffer overflow vulnerability in Kodi allows attackers to cause a denial of service due to an improper length of the value
Update to 2.5.2 Fix for CVE-2025-68617
Update to 1.4.6: fixes CVE-2025-13654
Update to 2.1.0. Update bundled libpng, libtiff, to latest versions. Built against TCL/TK 9. Fix FTBFS.
Update to 5.32.0
Update to 2.1.0. Update bundled libpng, libtiff, to latest versions. Built against TCL/TK 9. Fix FTBFS.
Update to 5.32.0
Upgrade to 4.3.6 upstream version.
Upgrade to 4.3.6 upstream version.
An update that fixes one vulnerability is now available.
MGAA-2025-0106 – Updated nvidia-current & ldetect-lst packages fix bug
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
Vulnerabilities were found in python-urllib3, an HTTP library with thread-safe connection pooling for Python, which could lead to denial of service or request forgery. CVE-2025-50181 Redirects were not disabled when retries are disabled on PoolManager
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
A couple of vulnerabilities were discovered in postgresql-13, the widely-popular database management system: CVE-2025-12817 Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other
Update to 0.50.2
Update to release v0.26.3 Resolves CVE-2024-25621: rhbz#2419004, rhbz#2419033, rhbz#2419427 Upstream fix
Update to 2.68.1
Update to 1.22.0
Release 1.6.12 Support IPv6 in database DSN (#9937) Don’t force specific error_reporting setting Fix compatibility with PHP 8.5 regarding array_first() Remove X-XSS-Protection example from .htaccess file (#9875)
version update security update
Update to 1.22.0
Release 1.6.12 Support IPv6 in database DSN (#9937) Don’t force specific error_reporting setting Fix compatibility with PHP 8.5 regarding array_first() Remove X-XSS-Protection example from .htaccess file (#9875)
An update that solves 65 vulnerabilities and has nine security fixes can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves four vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves 65 vulnerabilities and has 11 security fixes can now be installed.
An update that solves 65 vulnerabilities and has 11 security fixes can now be installed.
An update that solves eight vulnerabilities and has two security fixes can now be installed.
An update that solves eight vulnerabilities and has two security fixes can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
It was discovered that usbmuxd, USB multiplexor daemon for iPhone and iPod Touch devices, incorrectly handled certain paths received with the SavePairRecord command. A local attacker could possibly use this issue to delete and write files named *.plist in arbitrary locations. For Debian 11 bullseye, this problem has been fixed in version
Erik Krogh Kristensen and Rasmus Petersen from the GitHub Security Lab discovered a ReDoS (Regular Expression Denial of Service) vulnerability in python-mechanize, a library to automate interaction with websites modeled after the Perl module WWW::Mechanize, which could lead to Denial of Service when parsing a malformed authentication header.
Fixes CVE-2025-58188, unretire package and update to 3.8.2.
Update to pgadmin-9.11, fixes CVE_2025-13780.
MGASA-2025-0331 – Updated webkit2 packages fix security vulnerabilities
MGASA-2025-0330 – Updated php packages fix security vulnerabilities
32.0.3 release, fixes RHBZ# 2420196 RHBZ# 2420197 RHBZ# 2420198 RHBZ# 2421368
Update to cef-143.0.10+g8aed01b + chromium-143.0.7499.146 (rhbz#2423482) High CVE-2025-14765: Use after free in WebGPU High CVE-2025-14766: Out of bounds read and write in V8 High CVE-2025-13630: Type Confusion in V8 High CVE-2025-13631: Inappropriate implementation in Google Updater
Update to uriparser-1.0.0, fixes CVE-2025-67899.
