Update to 1.23.1 (rhbz#2380450)
* bsc#1229008 * bsc#1241865 * bsc#1245087 Cross-References:
* bsc#1243450 Cross-References: * CVE-2024-23337
* bsc#1238912 * bsc#1241579 * bsc#1244337 Cross-References:
* bsc#1234854 * bsc#1234885 * bsc#1234892 * bsc#1235005 * bsc#1235769
* bsc#1243767 Cross-References: * CVE-2025-5278
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. Google is aware that an exploit for CVE-2025-6558 exists in the wild.
The newest upstream commit Security fixes for CVE-2025-53906, CVE-2025-53905
https://security-tracker.debian.org/tracker/DSA-5963-1
New bind packages are available for Slackware 15.0 and -current to fix a security issue.
Several security issues were fixed in Apache HTTP Server.
Bind could be made to crash if it received specially crafted network traffic.
Multiple security issues were discovered in GNU TLS, which could result in denial of service. For the stable distribution (bookworm), these problems have been fixed in
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5962-1
Several security issues were fixed in libjxl.
* bsc#1244663 Cross-References: * CVE-2025-4565
* bsc#1244663 Cross-References: * CVE-2025-4565
* bsc#1244663 Cross-References: * CVE-2025-4565
Several security issues were fixed in Nix.
Contains fixes for regressions introduced during CVE bugfix update (3007.4).
Update to 3.5.29, fixes CVE-2025-53367.
Update to 2.32.4. Fixes CVE-2024-47081.
This updates gnutls to the latest upstream release. Notable changes are: PKCS#11 cryptographic provider support Support for kTLS rekeying with kernel 6.14+ Support for the almost standardized ML-DSA private key formats This also fixes 4 CVEs (CVE-2025-32989, CVE-2025-6395, CVE-2025-32988, and
Update to chromium 138.0.7204.92
Update to version 4.34.0
PHP version 8.4.10 (03 Jul 2025) BcMath: Fixed bug GH-18641 (Accessing a BcMathNumber property by ref crashes). (nielsdos) Core:
Fixes CVE-2025-40909 – Clone dirhandles without fchdir
Fixes CVE-2025-40909 – Clone dirhandles without fchdir
Update to 20250708: Drop incorrect nvidia ghost entries xe: Add fan_control v203.0.0.0 for BMG Update AMD cpu microcode amdgpu: Add DCN 3.6/PSP 14.0.5/SDMA 6.1.3/GC 11.5.3
Fix CVE-2024-25176
Multiple vulnerabilities have been fixed in the email, calendar and contacts client Thunderbird. CVE-2025-5986
* bsc#1233012 * bsc#1243273 * bsc#1244032 * bsc#1244056 * bsc#1244059
Several security issues were fixed in resteasy, resteasy3.0.
Update to 128.12.0 https://www.thunderbird.net/en-US/thunderbird/128.12.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-55/
USN-7626-1 introduced a regression in Git
* bsc#1245309 * bsc#1245310 * bsc#1245311 * bsc#1245314
* bsc#1065729 * bsc#1156395 * bsc#1193629 * bsc#1194869 * bsc#1198410
* bsc#1244081 Cross-References: * CVE-2025-5601
* bsc#1244081 Cross-References: * CVE-2025-5601
* bsc#1243902 Cross-References: * CVE-2025-40908
The following updated rpms for have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5960-1
Several security issues were fixed in libssh.
USN-7010-1 introduced a regression in DCMTK
Sekou Diakite from HPE discovered a mistake with permission handling for Coordinators within the accounting system of Slurm Workload Manager, a cluster resource management and job scheduling system, that it could allow a Coordinator to promote a user to Administrator.
* bsc#1227270 * bsc#1227271 * bsc#1227353 * bsc#1228097 * bsc#1233165
Several security issues were fixed in jQuery.
https://security-tracker.debian.org/tracker/DSA-5961-1
Antonio Morales discovered an out-of-bounds write in the MMRDecoder::scanruns method in djvulibre, a library and set of tools to handle documents in the DjVu format, which may result in the execution of arbitrary code if a specially crafted document is processed.
* bsc#1243061 * bsc#1243804 * bsc#1243913 Cross-References:
5.2.0 release
Integer overflow on 32-bit systems has been fixed in the XMedCon toolkit for medical image conversion. For Debian 11 bullseye, this problem has been fixed in version
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the stable distribution (bookworm), these problems have been fixed in
Update to 3.6.4 Release notes: https://github.com/Mbed-TLS/mbedtls/releases/tag/mbedtls-3.6.4
https://security-tracker.debian.org/tracker/DSA-5959-1
PGSQL: Fixed GHSA-hrwm-9436-5mv3 (pgsql extension does not check for errors during escaping). (CVE-2025-1735) SOAP: Fixed GHSA-453j-q27h-5p8x (NULL Pointer Dereference in PHP SOAP
A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in the xls2csv utility version 0.95. (CVE-2024-48877) An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. (CVE-2024-52035)
* bsc#1243314 * bsc#1243332 * bsc#1243422 * bsc#1243423
* bsc#1236931 * bsc#1239119 Cross-References: * CVE-2025-30258
Update bundled pbkdf2 library.
