Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape, information disclosure or bypass of the same-origin policy.

The system could be made to crash or run programs as an administrator.

The system could be made to crash or run programs as an administrator.

The system could be made to crash or run programs as an administrator.

The system could be made to crash or run programs as an administrator.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. Google is aware that an exploit for CVE-2025-10585 exists in the wild.

https://security-tracker.debian.org/tracker/DSA-6004-1

https://security-tracker.debian.org/tracker/DSA-6005-1

https://security-tracker.debian.org/tracker/DSA-6006-1

* bsc#1233421 Cross-References: * CVE-2024-52615

* bsc#1246197 * bsc#1249191 * bsc#1249348 * bsc#1249367 * jsc#PED-13055

* bsc#1246197 * bsc#1249191 * bsc#1249348 * bsc#1249367 * jsc#PED-13055

https://security-tracker.debian.org/tracker/DSA-6003-1

* bsc#1236851 * bsc#1248070 Cross-References: * CVE-2025-23419

* bsc#1235673 * bsc#1235674 Cross-References: * CVE-2024-57822

* bsc#1243581 * bsc#1248410 * bsc#1248687 Cross-References:

* bsc#1237208 * bsc#1247528 * bsc#1247529 * bsc#1247530 * bsc#1247531

What Is a Checksum? Meaning, Examples & Why You Should Use Them
Preparing your organization for the quantum future

This update upgrade the package to version 0.44. This version fixes CVE-2025-40924 by using Crypt::SysRandom to generate properly random session IDs.

This update upgrade the package to version 0.36. This version fixes CVE-2025-40923 by using Crypt::SysRandom to generate secure session IDs.

This update upgrade the package to version 1.019. This version fixes CVE-2025-40920 by using Crypt::SysRandom to generate nonces instead of Data::UUID.

Update to 140.0.7339.127 CVE-2025-10200: Use after free in Serviceworker CVE-2025-10201: Inappropriate implementation in Mojo

2.4.14 (fixes CVE-2025-58060 and CVE-2025-58364)

Fix crash with spice GL (bz 2391334) Update to 10.1.0 GA release Automatic update for qemu-10.1.0-0.4.rc4.fc43.

https://security-tracker.debian.org/tracker/DSA-6002-1

The EU Cyber Resilience Act’s impact on open source security

https://security-tracker.debian.org/tracker/DSA-6001-1

https://security-tracker.debian.org/tracker/DSA-6000-1

https://security-tracker.debian.org/tracker/DSA-5999-1

Navigating AI risk: Building a trusted foundation with Red Hat

https://security-tracker.debian.org/tracker/DSA-5997-1

https://security-tracker.debian.org/tracker/DSA-5996-1

https://security-tracker.debian.org/tracker/DSA-5998-1

https://security-tracker.debian.org/tracker/DSA-5995-1

Important: postgresql:15 security update

Important: postgresql:16 security update

Important: mingw-sqlite security update

Important: kernel-rt security update

Moderate: kernel-rt security update

Moderate: kernel-rt security update

What Are Container Escape Vulnerabilities?

https://security-tracker.debian.org/tracker/DSA-5994-1

https://security-tracker.debian.org/tracker/DSA-5993-1

* bsc#1243314 Cross-References: * CVE-2025-4945

* bsc#1230028 * bsc#1247207 Cross-References: * CVE-2024-58266

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

* bsc#1249011 Cross-References: * CVE-2025-58160

* bsc#1246623 * jsc#PED-13306 Cross-References: * CVE-2025-40918

FFmpeg could be made to crash if it received specially crafted input.

A couple of vulnerabilities have been fixed in ClamAV, an anti-virus utility for Unix. CVE-2025-20128

* bsc#1246058 * bsc#1246059 Cross-References: * CVE-2025-32023

* bsc#1225905 Cross-References: * CVE-2024-35221

* bsc#1248810 Cross-References: * CVE-2025-57833

Security beyond the model: Introducing AI system cards
Learn about confidential clusters

* bsc#1246088 Affected Products: * HPC Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Two vulnerabilities have been fixed in the audio data read/write library libsndfile.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

Exploring Open Source Intelligence (OSINT) Techniques And Tools For Cybersecurity Applications

Several security issues were fixed in ImageMagick.

DoS with large SAML responses has been fixed in ruby-saml, a library implementing the client side of SAML authorization for the Ruby interpreter.

* bsc#1244270 * bsc#1244272 Cross-References: * CVE-2025-5914

Update to release v0.27.0 Resolves: rhvz#2388453, rhbz#2384137, rhbz#2384154 Upstream new features and fixes

Exiv2 0.28.6 + patch to fix silent abi breakage Exiv2 v0.28.6 (Fixes two low severity CVEs)

Update to 139.0.7258.154 CVE-2025-9478: Use after free in ANGLE

Several security issues were fixed in Open VM Tools.

Update to 139.0.7258.154 CVE-2025-9478: Use after free in ANGLE

CVE-2025-8067 Out-Of-Bounds Read in UDisks Daemon

CVE-2025-8010: Type Confusion in V8 CVE-2025-8011: Type Confusion in V8 CVE-2025-8576: Use after free in Extensions CVE-2025-8578: Use after free in Cast CVE-2025-8579: Inappropriate implementation in Gemini Live in Chrome

Update to release v0.27.0 Resolves: rhvz#2388453, rhbz#2384137, rhbz#2384154 Upstream new features and fixes

Remove prebuild libffts.a library

New udisks2 packages are available for Slackware 15.0 and -current to fix a security issue.

Red Hat Trusted Artifact Signer can now be hosted on RHEL