Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

A security issue was fixed in MariaDB.

* bsc#1237367 * bsc#1239185 * bsc#1239322 Cross-References:

* bsc#1234452 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5

The perl module Data::Entropy was using the cryptographically insecure rand() function as default entropy source. For Debian 11 bullseye, this problem has been fixed in version

Microcode updates has been released for Intel(R) processors, addressing multiple potential vulnerabilties that may allow local privilege escalation, denial of service or information disclosure.

Multiple vulnerabilities were discovered in vim, an enhanced vi editor. CVE-2021-3872

Update to 0.4.8; Fixes: RHBZ#2237964, RHBZ#2282129

An issue has been found in librabbitmq, a AMQP client library and tools written in C. The issue is related to credential visibility when

Update to 2.12.10

CVE-2025-2588

* bsc#1235147 Cross-References: * CVE-2024-5594

* bsc#1239685 Cross-References: * CVE-2025-2361

* bsc#1238685 Cross-References: * CVE-2025-22870

How Cloud Security is Transforming Cybersecurity Services

CVE-2025-2588

Update to 1.1.43, fixes CVE-2024-55549 and CVE-2025-24855.

Added patch for CVE-2024-4068 (rhbz#2280624)

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-5888-1

Several security issues were fixed in the Linux kernel.

Alexander Tan discovered that the OpenSAML C++ library was susceptible to forging of signed SAML messages. For additional details please refer to the upstream advisory at https://shibboleth.net/community/advisories/secadv_20250313.txt

* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869

* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869

* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869

https://security-tracker.debian.org/tracker/DSA-5886-1

* bsc#1239339 Cross-References: * CVE-2025-22869 * CVE-2025-27144

* bsc#1239339 Cross-References: * CVE-2025-22869 * CVE-2025-27144

* bsc#1239460 Cross-References: * CVE-2025-24049

https://security-tracker.debian.org/tracker/DSA-5887-1

This upload fixes two security issues in the version of nginx shipped in bullseye. CVE-2024-7347

* bsc#1239465 Cross-References: * CVE-2025-27363

Several security issues were fixed in SmartDNS.

Update to 134.0.6998.117 * Critical CVE-2025-2476: Use after free in Lens

0.9.30, rebuild due golang CVE-2025-22870

https://security-tracker.debian.org/tracker/DSA-5885-1

Ivan Fratric discovered two use-after-free vulnerabilities in libxslt, an XSLT processing runtime library, which may result in the execution of arbitrary code if a specially crafted files are processed.

Anatomy of Linux Ransomware Attacks and Protection Strategies

Two use-after-free vulnerabilities have been fixed in the XSLT processing library libxslt. CVE-2024-55549

Several security issues were fixed in NLTK.

Update to 134.0.6998.117 * Critical CVE-2025-2476: Use after free in Lens

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-44192

An update that fixes two vulnerabilities is now available.

Mitigating threats against telco networks in the cloud

Update to 4.3.6 (rhbz#2352545)

This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md

Update to 4.3.6 (rhbz#2352545)

This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md

Backported fix for CVE-2024-12361 .

This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md

https://security-tracker.debian.org/tracker/DSA-5884-1

A cross-site scripting vulnerability was discovered in hgweb, the integrated stand-alone web interface of the Mercurial version control system.

Update to 0.40.0 https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes

https://security-tracker.debian.org/tracker/DSA-5883-1

* bsc#1197331 * bsc#1203769 * bsc#1235441 * bsc#1237768 * bsc#1238271

* bsc#1239750 Cross-References: * CVE-2022-49737

https://security-tracker.debian.org/tracker/DSA-5882-1

go-gh could be made to expose sensitive information over the network.

* bsc#1239547 Cross-References: * CVE-2025-24201

* bsc#1239547 Cross-References: * CVE-2025-24201

* bsc#1237363 * bsc#1237370 * bsc#1237418 Cross-References:

What OpenInfra Joining Linux Foundation Means for Cloud Security Posture Management

Several security issues were fixed in Valkey.

Red Hat Advanced Cluster Security 4.7 simplifies management, enhances workflows, and generates SBOMs
Secure AI inferencing: POC with NVIDIA NIM on CoCo with OpenShift AI

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in HTTP request smuggling, validation bypass or denial of service.

Multiple vulnerabilities were discovered in modules shipped with cpython 3.9, the primary interpreter for the Python programming language.

fix CVE-2024-56737, CVE-2025-56737, CVE-2025-1864 Fix CVE-2025-1744 and CVE-2025-1864

fix CVE-2024-56737, CVE-2025-56737, CVE-2025-1864 Fix CVE-2025-1744 and CVE-2025-1864

Several security issues were fixed in Alpine.

Effective Strategies to Optimize Linux Security in 2025
Rising Malware Threats to Linux: Understanding Risks and Defenses
Exploring FireDragon: A High-Performing, Secure Linux Browser
Apache Tomcat Vulnerability CVE-2025-24813 Exposes Linux Servers to Remote Attacks

* bsc#1229640 * bsc#1231196 * bsc#1231204 * bsc#1233679 * bsc#1235452

* bsc#1228755 * bsc#1231196 * bsc#1231204 * bsc#1233679 * bsc#1235452

* bsc#1231204 * bsc#1233679 Cross-References: * CVE-2024-46818

* bsc#1229640 * bsc#1231204 * bsc#1233679 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5881-1

* bsc#1237467 Cross-References: * CVE-2025-26618

* bsc#1228017 * bsc#1229640 * bsc#1231204 * bsc#1233679

* bsc#1233679 Cross-References: * CVE-2024-50302