Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

fix setpwnam() buffer use [CVE-2025-14104] libblkid: use snprintf() instead of sprintf()

https://security-tracker.debian.org/tracker/DSA-6088-1

https://security-tracker.debian.org/tracker/DSA-6089-1

https://security-tracker.debian.org/tracker/DSA-6090-1

https://security-tracker.debian.org/tracker/DSA-6091-1

https://security-tracker.debian.org/tracker/DSA-6087-1

https://security-tracker.debian.org/tracker/DSA-6086-1

https://security-tracker.debian.org/tracker/DSA-6085-1

SNMP: CACTI Command Execution Risk Advisory for Linux Administrators

Update to 0.2.8

Update to 143.0.7499.146 * High CVE-2025-14765: Use after free in WebGPU * High CVE-2025-14766: Out of bounds read and write in V8 * Force dark mode when auto dark mode web content is on

Update to 2.22.11

Update to 17.0.0 version (#2412270) Update fonttools 4.61.0

Update to 17.0.0 version (#2412270) Update fonttools 4.61.0

Update to 143.0.7499.146 * High CVE-2025-14765: Use after free in WebGPU * High CVE-2025-14766: Out of bounds read and write in V8 * Force dark mode when auto dark mode web content is on

Enterprise automation resilience with EDB and Red Hat Ansible Automation Platform
Red Hat to acquire Chatterbox Labs: Frequently Asked Questions
Accelerating NetOps transformation with Ansible Automation Platform

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

An update that solves four vulnerabilities can now be installed.

PHP version 8.4.16 (18 Dec 2025) Core: Sync all boost.context files with release 1.86.0. (mvorisek) Fixed bug GH-20435 (SensitiveParameter doesn’t work for named argument passing to variadic parameter). (ndossche)

It was discovered that c-ares, a library that performs DNS requests and name resolution asynchronously, does not properly handle termination of queries which may result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 1.34.5-1+deb13u1.

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-6083-1

https://security-tracker.debian.org/tracker/DSA-6084-1

An update that solves one vulnerability, contains one feature and has one security fix can now be installed.

This update includes the latest upstream release of mod_md, with various bug fixes and enhancements. See https://github.com/icing/mod_md/releases for more information. A fix for the security vulnerability CVE-2025-55753 is also included.

Update to 25.4.0

Fix seeking and looping of media elements that set the loop property. Fix several crashes and rendering issues. Fix CVE-2025-13947, CVE-2025-43458, CVE-2025-66287

upstream stable upgrade from 2.41.1 to 2.41.3 (CVE-2025-14104 and other issues)

Backport fix for CVE-2025-11277

Harden your AI systems: Applying industry standards in the real world

https://security-tracker.debian.org/tracker/DSA-6082-1

Fixed aarch64 crashes Updated to latest upstream (146.0)

Update to 143.0.7499.109 * High: Under coordination * Medium CVE-2025-14372: Use after free in Password Manager * Medium CVE-2025-14373: Inappropriate implementation in Toolbar

Fixed aarch64 crashes Updated to latest upstream (146.0)

ruby-sidekiq, a simple, efficient background processing for Ruby, had a couple of vulnerabilities as follows: CVE-2021-30151 Sidekiq allows XSS via the queue name of the live-poll feature when Internet Explorer is used.

A couple of vulnerabilities were reported against ruby-git, a Ruby interface to the Git revision control system, that could lead to a command injection and execution of an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product.

Multiple vulnerabilities were discovered in the VLC media player, which could result in denial of service or potentially the execution of arbitrary code if a malformed video file is opened. For the oldstable distribution (bookworm), this problem has been fixed in version 3.0.22-0+deb12u1.

An update that solves 5 vulnerabilities can now be installed.

Moderate: grafana security update

Introducing the Red Hat Ansible Lightspeed intelligent assistant
From incident responder to security steward: My journey to understanding Red Hat’s open approach to vulnerability management

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the oldstable distribution (bookworm), these problems have been fixed in version 1:140.6.0esr-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in

xkbcomp 1.5.0 (CVE-2018-15853, CVE-2018-15859, CVE-2018-15861, CVE-2018-15863)

Fixed CVE-2025-66293 (high severity): Out-of-bounds read in png_image_read_composite. Fixed the Paeth filter handling in the RISC-V RVV implementation. Improved the performance of the RISC-V RVV implementation.

Latest version This build with the latest golang should also fix all the Go CVEs, although I did verify how/if this package is affected by these CVEs.

https://security-tracker.debian.org/tracker/DSA-6081-1

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.6.0esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.

MGASA-2025-0326 – Updated golang packages fix security vulnerabilities

MGAA-2025-0104 – Updated codeblocks packages fix bug

Apply fuse2fs patches that were accidentally empty Update to upstream 1.4.5, including a fix for CVE-2025-65105

Apply fuse2fs patches that were accidentally empty Update to upstream 1.4.5, including a fix for CVE-2025-65105

Apply fuse2fs patches that were accidentally empty Update to upstream 1.4.5, including a fix for CVE-2025-65105

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. An additional CVE (that has yet to be assigned) is fixed in this release; Google is aware of an expoit in the wild for that issue. For the oldstable distribution (bookworm), these problems have […]

This update includes the latest changes to the leap second list, including an update to its expiry date, which was set for the end of December.

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-6080-1

Slash VM provisioning time on Red Hat Openshift Virtualization using Red Hat Ansible Automation Platform
Don’t just automate, validate: How to measure and grow your return on investment

An out-of-bounds read flaw was found in libsndfile’s FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with

version update security update

1.282 – Sanitize all user-supplied values before inserting into HTTP headers; Fixed CVE-2025-40927.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape, same-origin policy bypass or privilege escalation.

Several security issues were fixed in libpng.

Qt could be made to crash or run programs as your login if it opened a specially crafted file.

* bsc#1251198 * bsc#1251199 Cross-References: * CVE-2025-61984

* bsc#1238879 Cross-References: * CVE-2025-27516

* bsc#1254132 Cross-References: * CVE-2025-9820

Insufficient validation of incoming notifies over TCP in PDNS Recursor, a resolving name server, could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 5.2.7-0+deb13u1. We recommend that you upgrade your pdns-recursor packages.

Several vulnerabilities were reported in the libpng PNG library, which could lead to information leaks, denial of service or potentially the execution of arbitrary code if a specially crafted image is processed. For the oldstable distribution (bookworm), these problems have been fixed in version 1.6.39-2+deb12u1.

* bsc#1244485 * bsc#1245878 * bsc#1254227 * bsc#1254430 * bsc#1254431

https://security-tracker.debian.org/tracker/DSA-6075-1

https://security-tracker.debian.org/tracker/DSA-6076-1

https://security-tracker.debian.org/tracker/DSA-6077-1

https://security-tracker.debian.org/tracker/DSA-6078-1

https://security-tracker.debian.org/tracker/DSA-6079-1

Several security issues were fixed in radare2.

* bsc#1241772 * bsc#1250683 * bsc#1253181 * bsc#1253185 * bsc#1253186

python-apt could be made to crash if it opened a specially crafted file.

An update that solves one vulnerability can now be installed.

* bsc#1254132 Cross-References: * CVE-2025-9820

* bsc#1250497 Cross-References: * CVE-2025-10922

https://security-tracker.debian.org/tracker/DSA-6074-1

Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. For the stable distribution (trixie), this problem has been fixed in version 7:7.1.3-0+deb13u1.

Multiple vulnerabilties have been found in libpng, the official PNG reference library, allowing information disclosure via out-of-bounds read, denial of service via application crash, or heap corruption with potential for arbitrary code execution.

Update to 2.9.7

Fix seeking and looping of media elements that set the loop property. Fix several crashes and rendering issues. Fix CVE-2025-13947, CVE-2025-43458, CVE-2025-66287

Update to 2.9.7

https://security-tracker.debian.org/tracker/DSA-6073-1