* bsc#1229640 * bsc#1231204 * bsc#1233679 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5879-1
FreeType could be made to crash or run programs if it opened a specially crafted font file.
* bsc#1239197 Cross-References: * CVE-2025-22868
* bsc#1239197 Cross-References: * CVE-2025-22868
Several security issues were fixed in X.Org X Server.
* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6
https://security-tracker.debian.org/tracker/DSA-5880-1
An update that fixes one vulnerability is now available.
An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related to TrueType GX and variable font files which may result in arbitrary code execution. References:
patchlevel 1202 Security fix for CVE-2025-29768
Latest maintenance release from 7.1 branch. Changelog: https://github.com/FFmpeg/FFmpeg/blob/n7.1.1/Changelog . Contains backported fix for CVE-2025-22921.
Update to upstream 20250311: amdgpu: many firmware updates qcom: Update gpu firmwares for qcs8300 chipset add firmware for qat_420xx devices amdgpu: DMCUB updates for various ASICs
New freetype packages are available for Slackware 15.0 to fix a security issue.
Update to 134.0.6998.88 High CVE-2025-1920: Type Confusion in V8 High CVE-2025-2135: Type Confusion in V8 Medium CVE-2025-2136: Use after free in Inspector Medium CVE-2025-2137: Out of bounds read in V8
deadlock potential with VT-d and legacy PCI device pass-through [XSA-467, CVE-2025-1713]
Update to 134.0.6998.88 High CVE-2025-1920: Type Confusion in V8 High CVE-2025-2135: Type Confusion in V8 Medium CVE-2025-2136: Use after free in Inspector Medium CVE-2025-2137: Out of bounds read in V8
Update to upstream 20250311: amdgpu: many firmware updates qcom: Update gpu firmwares for qcs8300 chipset add firmware for qat_420xx devices amdgpu: DMCUB updates for various ASICs
This release addresses CVEs: CVE-2025-27835, CVE-2025-27832, CVE-2025-27831, CVE-2025-27836, CVE-2025-27830, CVE-2025-27833, CVE-2025-27837, CVE-2025-27834 The 10.05.0 release deprecates the non-standard operator “selectdevice”, all code should now be using the standard “setpagedevice” operator.
In man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the heap. This at least causes the program to segmentation abort if the heap size parameter isn’t aligned correctly. In versions before GLIBC version 2.29 and if aligned correctly, it allows arbitrary writes […]
* bsc#1233307 Cross-References: * CVE-2024-11168
* bsc#1202848 * bsc#1215945 * bsc#1223070 * bsc#1223235 * bsc#1223256
* bsc#1238702 Cross-References: * CVE-2025-22870
* bsc#1215420 * bsc#1224700 * bsc#1224763 * bsc#1225742 * bsc#1231847
https://security-tracker.debian.org/tracker/DSA-5878-1
* bsc#1239197 Cross-References: * CVE-2025-22868
* bsc#1208995 * bsc#1220946 * bsc#1225742 * bsc#1232472 * bsc#1232919
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
* bsc#1237377 Cross-References: * CVE-2025-0633
Several security issues were fixed in Jinja2.
Several security issues were fixed in opensc.
.NET could be made to elevate privileges.
An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings. (CVE-2025-26699)
Jinja sandbox breakout through attr filter selecting format method. (CVE-2025-27516) References: – https://bugs.mageia.org/show_bug.cgi?id=34081
https://security-tracker.debian.org/tracker/DSA-5877-1
* bsc#1208995 * bsc#1220946 * bsc#1225742 * bsc#1232472 * bsc#1232919
* bsc#1208995 * bsc#1220946 * bsc#1224700 * bsc#1225742 * bsc#1232905
* bsc#1050081 * bsc#1051510 * bsc#1065729 * bsc#1100823 * bsc#1101669
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
* bsc#1237681 Cross-References: * CVE-2025-27144
* bsc#1237681 Cross-References: * CVE-2025-27144
* bsc#1236531 * bsc#1237681 Cross-References: * CVE-2023-45288
Update to 134.0.6998.35 * CVE-2025-1914: Out of bounds read in V8 * CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools * CVE-2025-1916: Use after free in Profiles
Unbundle libxml2.
Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For the stable distribution (bookworm), these problems have been fixed in
Two vulnerabilities were discovered in openvpn, a virtual private network application which could result in authentication bypass or data injection.
High CVE-2025-1914: Out of bounds read in V8. Medium CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools. Medium CVE-2025-1916: Use after free in Profiles. Medium CVE-2025-1917: Inappropriate Implementation in Browser UI.
Update to 134.0.6998.35 * CVE-2025-1914: Out of bounds read in V8 * CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools * CVE-2025-1916: Use after free in Profiles
The newest upstream commit Security fix for CVE-2025-27423
update to version 2.25.1, CVE-2025-27154
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2. (CVE-2023-5520) Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV. (CVE-2024-0321) Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
https://security-tracker.debian.org/tracker/DSA-5876-1
https://security-tracker.debian.org/tracker/DSA-5875-1
Several security issues were fixed in the Linux kernel.
Updated to latest upstream (136.0)
Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian
Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
Several security issues were fixed in Ansible.
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.
Updated to latest upstream (136.0)
The newest upstream commit Security fix for CVE-2025-27423
New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.
https://security-tracker.debian.org/tracker/DSA-5873-1
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.
Several security issues were fixed in the Linux kernel.
* bsc#1237683 Cross-References: * CVE-2024-43097 * CVE-2025-1930
Several security issues were fixed in the Linux kernel.
A security issue was fixed in Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
https://security-tracker.debian.org/tracker/DSA-5874-1
Several security issues were fixed in cmark-gfm.
Several security issues were fixed in spip.
wpa_supplicant and hostapd could be made to expose sensitive information over the network.
Use-after-free of the root cursor. (CVE-2025-26594) Buffer overflow in XkbVModMaskText(). (CVE-2025-26595) Heap overflow in XkbWriteKeySyms(). (CVE-2025-26596) Buffer overflow in XkbChangeTypesOfKey(). (CVE-2025-26597) Out-of-bounds write in CreatePointerBarrierClient(). (CVE-2025-26598)
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
* bsc#1237284 * bsc#1237287 Cross-References: * CVE-2024-57256
* bsc#1236974 Cross-References: * CVE-2024-12243
