Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Rebuild for CVE-2025-47906. https://pkg.go.dev/vuln/GO-2025-3956

Fix CVE-2025-5455 – QtCore Assertion Failure Denial of Service

Fixes CVE-2025-11561 Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=2402728 After startup SSSD already creates a Kerberos configuration snippet in /var/lib/sss/pubconf/krb5.include.d/localauth_plugin if the AD or IPA providers are used. This enables SSSD’s localauth plugin. Starting with this update the

New version 3.0.2 (rhbz#2407048) Fixes CVE-2025-11232 (rhbz#2407229)

https://security-tracker.debian.org/tracker/DSA-6047-1

https://security-tracker.debian.org/tracker/DSA-6046-1

* bsc#1242300 * bsc#1243284 Cross-References: * CVE-2025-47268

* bsc#1246019 * bsc#1248631 * bsc#1249207 * bsc#1249208

This upload fixes a few of security issues in the Python standard library included with PyPy, an alternative implementation of the Python 3 language. CVE-2024-6232

* bsc#1248631 * bsc#1249207 * bsc#1249208 Cross-References:

* bsc#1246019 * bsc#1248631 * bsc#1249207 * bsc#1249208

* bsc#1247737 * bsc#1248176 * bsc#1248631 * bsc#1249207 * bsc#1249208

https://security-tracker.debian.org/tracker/DSA-6045-1

The system could be made to expose sensitive information.

Netty could be made to send emails as your login if it received specially crafted input.

Several security issues were fixed in AMD Microcode.

Several security issues were fixed in GNU binutils.

Update to 9.18.41 (rhbz#2405786) Security fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780)

Update to 9.18.41 (rhbz#2405786) Security fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780)

https://security-tracker.debian.org/tracker/DSA-6043-1

Linux: Tee.Fail Moderate TEE Side-Channel Attack for 2024-001

Jan-Niklas Sohn discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.

Introducing Red Hat’s STIG-hardened UBI for NVIDIA GPUs on Red Hat OpenShift

Jan-Niklas Sohn discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.

MGASA-2025-0251 – Updated poppler packages fix security vulnerability

MGASA-2025-0250 – Updated tomcat packages fix security vulnerabilities

Multiple vulnerabilities have been found in python-authlib, a Python library for OAuth and OpenID Connect servers.

Update to latest version (#2404637) Fix CVE-2025-47910, CVE-2025-47906, CVE-2025-26625

https://security-tracker.debian.org/tracker/DSA-6044-1

The Linux Command Line: Bridging Security Awareness for Sysadmins

* bsc#1251941 Cross-References: * CVE-2025-62291

* bsc#1246806 * bsc#1252414 * bsc#1252417 Cross-References:

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43272 Big Bear discovered that processing maliciously crafted web content may lead to an unexpected process crash.

* bsc#1019074 * bsc#1227577 * bsc#1229825 * bsc#1243331 * bsc#1243611

* bsc#1019074 * bsc#1227577 * bsc#1229825 * bsc#1237495 * bsc#1243331

* bsc#1227577 * bsc#1231150 * bsc#1231157 * bsc#1246277 * bsc#1246421

https://security-tracker.debian.org/tracker/DSA-6042-1

Moderate: kernel security update

Important: thunderbird security update

Moderate: kernel-rt security update

Moderate: kernel security update

PAM: Important Risks in Linux Authentication Trust Chain

https://security-tracker.debian.org/tracker/DSA-6041-1

https://security-tracker.debian.org/tracker/DSA-6039-1

https://security-tracker.debian.org/tracker/DSA-6040-1

https://security-tracker.debian.org/tracker/DSA-6037-1

https://security-tracker.debian.org/tracker/DSA-6038-1

https://security-tracker.debian.org/tracker/DSA-6036-1

Initial build for PHP81_BCstrftime Update DokuWiki to version 2025-05-14b “Librarian”

Initial build for PHP81_BCstrftime Update DokuWiki to version 2025-05-14b “Librarian”

New openssl packages are available for Slackware 15.0 to fix a security issue.

MGASA-2025-0247 – Updated thunderbird packgaes fix security vulnerabilities

MGASA-2025-0246 – Updated firefox, nss & rootcerts fix security vulnerabilities

An update that fixes one vulnerability is now available.

https://security-tracker.debian.org/tracker/DSA-6032-1

https://security-tracker.debian.org/tracker/DSA-6031-1

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

An update that solves one vulnerability can now be installed.

* bsc#1250562 Cross-References: * CVE-2025-11021

https://security-tracker.debian.org/tracker/DSA-6033-1

https://security-tracker.debian.org/tracker/DSA-6034-1

https://security-tracker.debian.org/tracker/DSA-6035-1

* bsc#1244663 Cross-References: * CVE-2025-4565

An update that solves two vulnerabilities can now be installed.

* bsc#1239896 * bsc#1243958 Cross-References: * CVE-2025-30348

An update that solves five vulnerabilities can now be installed.

* bsc#1245794 * bsc#1246075 * bsc#1248673 * bsc#1248749 * bsc#1249534

An update that solves three vulnerabilities can now be installed.

https://security-tracker.debian.org/tracker/DSA-6030-1

* bsc#1241219 Cross-References: * CVE-2025-3576

An update that solves one vulnerability can now be installed.

* bsc#1241219 Cross-References: * CVE-2025-3576

An update that solves five vulnerabilities can now be installed.

* bsc#1250439 * bsc#1250440 * bsc#1250441 * bsc#1250442 * bsc#1251975

An update that solves five vulnerabilities can now be installed.

* bsc#1251279 * bsc#1251280 Cross-References: * CVE-2025-10230

An update that solves two vulnerabilities can now be installed.

* bsc#1251279 * bsc#1251280 Cross-References: * CVE-2025-10230

An update that solves six vulnerabilities can now be installed.

* bsc#1232384 * bsc#1245794 * bsc#1246075 * bsc#1248673 * bsc#1248749

An update that solves five vulnerabilities can now be installed.

https://security-tracker.debian.org/tracker/DSA-6029-1

Simplified patching with Red Hat Enterprise Linux and Red Hat Insights

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Update to Python 3.9.24

Update to 3.11.14

Update to Python 3.10.19

Backport fixes for CVE-2025-11082, CVE-2025-11083, CVE-2025-11494, CVE-2025-11495.

What is an Out-of-Bounds Write Linux Security Vulnerability?

When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, an insufficiently seeded random number generator is used when generating the directory name, leading to the possibility for a local attacker to pre-create

Added fix for mzbz#1990430 (crashes) Updated to latest upstream (144.0)

Backport fix for CVE-2025-10729.

Backport fix for CVE-2025-10729.

Update to python-3.11.14, fixes CVE-2025-8291.

Update to release v1.3.2

An update that solves 326 vulnerabilities and has 45 security fixes can now be installed.