* bsc#1236974 Cross-References: * CVE-2024-12243
A vulnerability was discovered in MariaDB, a SQL database server compatible with MySQL. A privileged attacker could cause a Denial-of-Service (DoS) of the MariaDB server.
A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file. (CVE-2025-22919) A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted
nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm –without-symbol-version` function. (CVE-2024-57360) GNU Binutils objdump.c disassemble_bytes stack-based overflow. (CVE-2025-0840)
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
https://security-tracker.debian.org/tracker/DSA-5872-1
Update to chromium-133.0.6943.141
CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function
CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function
New version 4.2.11
Update to WebKitGTK 2.46.6: Fix a crash when enabling Skia CPU rendering. Fix several crashes and rendering issues. Fix CVE-2024-54543, CVE-2025-24143, CVE-2025-24150, CVE-2025-24158, CVE-2025-24162
deadlock potential with VT-d and legacy PCI device pass-through [XSA-467, CVE-2025-1713]
https://security-tracker.debian.org/tracker/DSA-5871-1
* bsc#1237093 Cross-References: * CVE-2025-1094
* bsc#1237431 Cross-References: * CVE-2025-26597
* bsc#1237431 Cross-References: * CVE-2025-26597
https://security-tracker.debian.org/tracker/DSA-5870-1
Several security issues were fixed in PHP.
Multiple vulnerabilities were discovered in GNU Emacs, the extensible, customisable, self-documenting, real-time display editor. CVE-2023-28617
Libxmltok could be made to crash if it opened a specially crafted file.
Merge branch ‘f42’ into f41 Merge branch ‘rawhide’ into f41 Fix merge conflict
A heap-based buffer overflow flaw in the decoding functions of openh264, a codec library which supports H.264 encoding and decoding, may allow a remote attacker to cause a denial of service or the execution of arbitrary code if a specially crafted video is processed.
New emacs packages are available for Slackware 15.0 and -current to fix security issues.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Cross-References: * CVE-2020-13936 CVSS scores:
Upstream kernel version 6.6.79 fixes bugs and vulnerabilities. The kmod-virtualbox and kmod-xtables-addons packages have been updated to work with this new kernel. For information about the vulnerabilities see the links.
Vanilla upstream kernel version 6.6.79 fixes bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=34024
Several security issues were fixed in the Linux kernel.
* bsc#1237058 * bsc#1237062 Cross-References: * CVE-2025-24031
* bsc#1227320 * bsc#1227371 * bsc#1228585 * bsc#1236783
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
* bsc#1233296 * bsc#1236278 * bsc#1236470 Cross-References:
* bsc#1233296 * bsc#1236278 * bsc#1236470 Cross-References:
* bsc#1236783 Cross-References: * CVE-2024-53104
* bsc#1227320 * bsc#1227371 * bsc#1228585 * bsc#1236783
Security fixes for CVE-2024-11168 and CVE-2025-0938
update to 1.33.2 fix CVE-2025-24898
Security fixes for CVE-2024-11168 and CVE-2025-0938
update to 1.33.2 fix CVE-2025-24898
Multiple vulnerabilities have been found in libxml2, a library providing support to read, modify and write XML and HTML files. These vulnerabilities could potentially lead to denial of servie or other unintended behaviors.
Update to 133.0.6943.126 CVE-2025-0999: Heap buffer overflow in V8 CVE-2025-1426: Heap buffer overflow in GPU CVE-2025-1006: Use after free in Network
This update addresses a null pointer dereferencing issue that could cause the session for a client that sent specially-crafted commands to the server to crash (not the sessions of other clients).
This update addresses a null pointer dereferencing issue that could cause the session for a client that sent specially-crafted commands to the server to crash (not the sessions of other clients).
Bing Shi discovered that GnuTLS, a portable library which implements the Transport Layer Security and Datagram Transport Layer Security protocols, had inefficient handling of certificate data with a large number of names or name constraints, potentially leading to Denial of
* bsc#1236946 Cross-References: * CVE-2024-27856 * CVE-2024-54543
* bsc#1237084 Affected Products: * openSUSE Leap 15.6 * Server Applications Module 15-SP6
* bsc#1237084 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5
* bsc#1236560 Cross-References: * CVE-2024-45339
https://security-tracker.debian.org/tracker/DSA-5869-1
The following vulnerabilities have been discovered in the package mosquitto, MQTT message broker.
The 6.12.15 stable kernel update contains a number of important fixes across the tree. The 6.12.14 stable kernel update contains a number of important fixes across the tree.
Includes CVE fixes.
Fix regression of Match directive processing
Update gnutls to the latest upstream release, including a fix for CVE-2024-12243.
Security fix for CVE-2025-0938
* bsc#1237091 Cross-References: * CVE-2025-1244
* bsc#1237037 * bsc#1237038 Cross-References: * CVE-2025-24970
* bsc#1237096 Cross-References: * CVE-2024-31068 * CVE-2024-36293
Several security issues were fixed in libsndfile.
https://security-tracker.debian.org/tracker/DSA-5867-1
* bsc#1237091 Cross-References: * CVE-2025-1244
A vulnerability was discovered in pam-pkcs11, a PAM module which allows to use PKCS#11 based smart cards in the PAM authentication stack, which may allow to bypass the authentication in some scenarios.
The Qualys Threat Research Unit (TRU) discovered that the OpenSSH client is vulnerable to a machine-in-the-middle attack if the VerifyHostKeyDNS option is enabled (disabled by default).
Several security issues were fixed in Docker.
The Qualys Threat Research Unit (TRU) discovered that the OpenSSH client is vulnerable to a machine-in-the-middle attack if the VerifyHostKeyDNS option is enabled (disabled by default).
* bsc#1237096 Cross-References: * CVE-2024-31068 * CVE-2024-36293
https://security-tracker.debian.org/tracker/DSA-5868-1
The following vulnerability has been discovered in the glog package for Go: When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process’s log file path
Multiple vulnerabilties have been found in freelrdp2, a free implementation of the Remote Desktop Protocol (RDP). The vulnerabilties potentially allows authentication bypasses on configuration errors, buffer overreads, DoS vectors, buffer overflows or accessing files
Update to 133.0.6943.98 CVE-2025-0995: Use after free in V8 CVE-2025-0996: Inappropriate implementation in Browser UI CVE-2025-0997: Use after free in Navigation CVE-2025-0998: Out of bounds memory access in V8
Update to upstream 2.1-48. 20250211 Addition of 06-bf-06/0x07 microcode (in intel-ucode/06-97-02) at revision 0x38; Addition of 06-bf-07/0x07 microcode (in intel-ucode/06-97-02) at revision 0x38; Addition of 06-bf-06/0x07 microcode (in intel-ucode/06-97-05) at revision 0x38; Addition of 06-bf-07/0x07 microcode (in intel-ucode/06-97-05) at revision 0x38;
Update to 133.0.6943.98 CVE-2025-0995: Use after free in V8 CVE-2025-0996: Inappropriate implementation in Browser UI CVE-2025-0997: Use after free in Navigation CVE-2025-0998: Out of bounds memory access in V8
Multiple vulnerabilities were fixed in trafficserver, a caching proxy server. CVE-2024-38479
C’©dric Krier has found that trytond, the Tryton application server, accepts compressed content from unauthenticated requests which makes it vulnerable to zip bomb attacks (see DLA 4022-1).
Update to WebKitGTK 2.46.6: Fix a crash when enabling Skia CPU rendering. Fix several crashes and rendering issues. Fix CVE-2024-54543, CVE-2025-24143, CVE-2025-24150, CVE-2025-24158, CVE-2025-24162
Latest upstream release. It adds support for tiles and fixes reading images generated by iOS 18+. See https://github.com/strukturag/libheif/releases for more details about the changes since 1.17.6. NOTE: heif-convert tool was renamed to heif-dec. How to test:
Changes with nginx 1.26.3 05 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419). *) Bugfix: in the ngx_http_mp4_module.
Changes with nginx 1.26.3 05 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419). *) Bugfix: in the ngx_http_mp4_module.
