Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

This update fixes these CVEs: CVE-2025-32364 CVE-2025-32365 CVE-2024-56378

reposurgeon: update to 5.3 version

In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL. References: – https://bugs.mageia.org/show_bug.cgi?id=34447

Stefan Buehler discovered a flaw in sope, the set of Objective-C frameworks powering SOGo, which may result in denial of service via a specially crafted POST request.

A flaw was found in how GLib¢”s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn¢”t. As a result, data may be written […]

Backports patch to fix non-CVE 2025-8224

This update fixes these CVEs: CVE-2025-4948 CVE-2025-32908 CVE-2025-32907 CVE-2025-4969

What Is An XSS Vulnerability?

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5970-1

* bsc#1243855 Cross-References: * CVE-2024-12224

* bsc#1243868 Cross-References: * CVE-2024-12224

* bsc#1221107 Cross-References: * CVE-2024-2236

Deploy sensitive workloads with OpenShift confidential containers
Confidential containers on Microsoft Azure with Red Hat OpenShift Sandboxed Containers 1.10 and Red Hat Build of Trustee

An update that fixes one vulnerability is now available.

* bsc#1234675 * bsc#1235461 * bsc#1235871 Cross-References:

* bsc#1236621 * bsc#1243009 * bsc#1243105 * bsc#1243268 * bsc#1243274

* bsc#1236621 * bsc#1243009 * bsc#1243105 * bsc#1243268 * bsc#1243274

* bsc#1236621 * bsc#1243009 * bsc#1243105 * bsc#1243268 * bsc#1243274

* bsc#1244795 * bsc#1246058 * bsc#1246059 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5969-1

Several security issues were fixed in SQLite.

Several security issues were fixed in cloud-init.

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5968-1

https://security-tracker.debian.org/tracker/DSA-5967-1

Several security issues were fixed in the Linux kernel.

* bsc#1246090 Affected Products: * openSUSE Leap 15.3

Hidden in Plain Sight: Koske Linux Malwares Stealthy Panda Image Delivery

Several security issues were fixed in OpenJDK 11.

Several security issues were fixed in OpenJDK 8.

This update fixes CVE-2025-8058, a low-impact security vulnerability in the regcomp function.

Soco404: Linux Cryptomining Campaign Masquerades as 404 Error Pages

Two issues have been found in libcaca, a colour ASCII art library. Both are related to heap buffer overflow, which might lead to memory corruption.

It was discovered that there was a potential null pointer dereference vulnerability in libetpan, an low-level library for handling email.

The audiofile library allows the processing of audio data to and from audio files of many common formats (currently AIFF, AIFF-C, WAVE, NeXT/Sun, BICS, and raw data).

* bsc#1229007 Cross-References: * CVE-2024-7409

* bsc#1246664 Cross-References: * CVE-2025-8027 * CVE-2025-8028

Several security issues were fixed in CRaC JDK 21.

An update that fixes three vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the stable distribution (bookworm), these problems have been fixed in

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version

https://security-tracker.debian.org/tracker/DSA-5966-1

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

Update to 128.13.0 https://www.thunderbird.net/en-US/thunderbird/128.13.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-62/

Several security issues were fixed in OpenJDK 24.

Several security issues were fixed in OpenJDK 21.

* bsc#1225889 * bsc#1245542 Cross-References: * CVE-2024-1298

* bsc#1229122 * bsc#1241865 Cross-References: * CVE-2025-22872

https://security-tracker.debian.org/tracker/DSA-5964-1

* bsc#1234854 * bsc#1234892 * bsc#1235005 * bsc#1235921 * bsc#1238912

Several security issues were fixed in the Linux kernel.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Updated to latest upstream (141.0)

https://security-tracker.debian.org/tracker/DSA-5965-1

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

* bsc#1244403 * bsc#1244404 * bsc#1244407 Cross-References:

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, information disclosure or bypass of sandbox restrictions.

* bsc#1244644 * bsc#1246112 Cross-References: * CVE-2025-27465

* bsc#1243648 Cross-References: * CVE-2024-56558

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in Drupal.

Several security issues were fixed in the Linux kernel.

CHAOS RAT in AUR: When Trust in Open-Source Goes Too Far

* bsc#1194400 * bsc#1212493 * bsc#1219964 * bsc#1222539 * bsc#1229008

* bsc#1241865 Cross-References: * CVE-2025-22872

Update to 7.3.20 Security fixes for CVE-2025-47273, CVE-2024-47081 and CVE-2025-50181 (in pip and setuptools wheels)

Update to 7.3.20 Security fixes for CVE-2025-47273, CVE-2024-47081 and CVE-2025-50181 (in pip and setuptools wheels)

angular.js a popular JavaScript framework was affected by multiple vulnerabilities. CVE-2022-25844

Update to 138.0.7204.157 * CVE-2025-7656: Integer overflow in V8 * CVE-2025-7657: Use after free in WebRTC * CVE-2025-6558: Incorrect validation of untrusted input in ANGLE and GPU