* bsc#1245309 * bsc#1245310 * bsc#1245311 * bsc#1245314
* bsc#1238063 * bsc#1244136 Cross-References: * CVE-2025-0620
* bsc#1244704 Cross-References: * CVE-2025-6196
Multiple vulnerabilities are discovered in jpeg-xl, the JPEG XL (“JXL”) image coding library, including out of bounds read/write and stack based buffer overflow, which may cause excessive memory usage and denial of service attacks.
Backport fix for CVE-2025-6199.
5.2.0 release
https://security-tracker.debian.org/tracker/DSA-5958-1
The embedded copy of pjproject is affected by a buffer overflow vulnerability, which affects applications that use PJSIP DNS resolver. For the stable distribution (bookworm), this problem has been fixed in
Several security issues were fixed in pcs.
Several security issues were fixed in Flask-CORS.
Several security issues were fixed in mongo-c-driver.
Several security issues were fixed in logback.
https://security-tracker.debian.org/tracker/DSA-5956-1
https://security-tracker.debian.org/tracker/DSA-5957-1
CVE-2025-6424: A use-after-free in FontFaceSet resulted in a potentially exploitable crash. CVE-2025-6425: An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing
* bsc#1230092 Cross-References: * CVE-2024-45310
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. Google is aware that an exploit for CVE-2025-6554 exists in the wild.
New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
https://security-tracker.debian.org/tracker/DSA-5955-1
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
* bsc#1232908 * bsc#1232927 * bsc#1232929 * bsc#1233680 * bsc#1233708
Multiple vulnerabilities have been fixed in catdoc, a text extractor for MS-Office files. CVE-2024-48877
USN-7582-1 introduced a regression in Samba.
* bsc#1243711 * bsc#1243712 Cross-References: * CVE-2025-48797
https://security-tracker.debian.org/tracker/DSA-5954-1
Resolves CVE-2024-38824 RHBZ#2372731 Resolves CVE-2024-38824 RHBZ#2372733 Resolves CVE-2025-22239 RHBZ#2372732 Resolves CVE-2025-22239 RHBZ#2372734 Resolves CVE-2025-22236 RHBZ#2372774
Update to release v1.32.6
4.4.9
Update to version 0.16.1 for various bugfixes. This also fixes CVE-2025-22872 in the bundled golang.org/x/net/html.
Resolves CVE-2024-38824 RHBZ#2372731 Resolves CVE-2024-38824 RHBZ#2372733 Resolves CVE-2025-22239 RHBZ#2372732 Resolves CVE-2025-22239 RHBZ#2372734 Resolves CVE-2025-22236 RHBZ#2372774
Update to release v1.32.6
https://security-tracker.debian.org/tracker/DSA-5953-1
Update to 138.0.7204.49 CVE-2025-6555: Use after free in Animation CVE-2025-6556: Insufficient policy enforcement in Loader CVE-2025-6557: Insufficient data validation in DevTools
Automatic update for podman-5.5.2-1.fc41. security fix for CVE-2025-6032 Changelog for podman * Tue Jun 24 2025 Packit – 5:5.5.2-1 – Update to 5.5.2 upstream release
Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517
Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517
xorg-x11-server CVE fix for CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180
Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517
https://security-tracker.debian.org/tracker/DSA-5951-1
* bsc#1232908 * bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062
* bsc#1235231 Cross-References: * CVE-2024-56601
* bsc#1239948 * bsc#1244304 * bsc#1244503 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5952-1
https://security-tracker.debian.org/tracker/DSA-5950-1
Several security issues were fixed in libarchive.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
* bsc#1243565 * bsc#1245054 * bsc#1245055 Cross-References:
* bsc#1236217 * bsc#1244156 * bsc#1244157 * bsc#1244158 * jsc#SLE-18320
https://security-tracker.debian.org/tracker/DSA-5949-1
https://security-tracker.debian.org/tracker/DSA-5948-1
* bsc#1244148 Cross-References: * CVE-2011-10007
* bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062 * bsc#1235231
Nils Emmerich discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.
commons-beanutils, utility for manipulating Java beans have an improper Access Control vulnerability. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers
* bsc#1239192 Cross-References: * CVE-2025-22868
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Template injection that can lead to XSS has been fixed in node-send, a Node.js module for streaming files over HTTP. For Debian 11 bullseye, this problem has been fixed in version
* bsc#1241067 * bsc#1243273 * bsc#1244032 * bsc#1244056 * bsc#1244059
* bsc#1234421 * bsc#1244405 * bsc#1244406 Cross-References:
* bsc#1243721 Cross-References: * CVE-2025-5222
https://security-tracker.debian.org/tracker/DSA-5947-1
Update to 137.0.7151.119 * CVE-2025-6191: Integer overflow in V8 * CVE-2025-6192: Use after free in Profiler
Harden temporary private mounts (#2373301)
4.9.0
This is the .NET monthly update for June 2025. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release-notes/9.0/9.0.6/9.0.107.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.6/9.0.6.md
Fix improper access control vulnerability Resolves: CVE-2025-48734
https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/OXIGQIHBL26HFKG6TT5SWSH7K7W6RO4H/ https://phabricator.wikimedia.org/T382326
