Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

* bsc#1245309 * bsc#1245310 * bsc#1245311 * bsc#1245314

* bsc#1238063 * bsc#1244136 Cross-References: * CVE-2025-0620

* bsc#1244704 Cross-References: * CVE-2025-6196

Multiple vulnerabilities are discovered in jpeg-xl, the JPEG XL (“JXL”) image coding library, including out of bounds read/write and stack based buffer overflow, which may cause excessive memory usage and denial of service attacks.

Backport fix for CVE-2025-6199.

5.2.0 release

https://security-tracker.debian.org/tracker/DSA-5958-1

SSH Under Siege: Hardening Your Linux Server Against Proxy Abuse
Model Context Protocol (MCP): Understanding security risks and controls

The embedded copy of pjproject is affected by a buffer overflow vulnerability, which affects applications that use PJSIP DNS resolver. For the stable distribution (bookworm), this problem has been fixed in

Several security issues were fixed in pcs.

Several security issues were fixed in Flask-CORS.

Several security issues were fixed in mongo-c-driver.

Several security issues were fixed in logback.

https://security-tracker.debian.org/tracker/DSA-5956-1

https://security-tracker.debian.org/tracker/DSA-5957-1

CVE-2025-6424: A use-after-free in FontFaceSet resulted in a potentially exploitable crash. CVE-2025-6425: An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing

CISA Warns of CVSS 9.3 MICROSENS NMP Web+ Flaws

* bsc#1230092 Cross-References: * CVE-2024-45310

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. Google is aware that an exploit for CVE-2025-6554 exists in the wild.

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-5955-1

The Rise of Rust-Based Malware: Memory Safetys Double-Edged Sword

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

* bsc#1232908 * bsc#1232927 * bsc#1232929 * bsc#1233680 * bsc#1233708

Multiple vulnerabilities have been fixed in catdoc, a text extractor for MS-Office files. CVE-2024-48877

USN-7582-1 introduced a regression in Samba.

* bsc#1243711 * bsc#1243712 Cross-References: * CVE-2025-48797

https://security-tracker.debian.org/tracker/DSA-5954-1

Resolves CVE-2024-38824 RHBZ#2372731 Resolves CVE-2024-38824 RHBZ#2372733 Resolves CVE-2025-22239 RHBZ#2372732 Resolves CVE-2025-22239 RHBZ#2372734 Resolves CVE-2025-22236 RHBZ#2372774

Update to release v1.32.6

4.4.9

Update to version 0.16.1 for various bugfixes. This also fixes CVE-2025-22872 in the bundled golang.org/x/net/html.

Resolves CVE-2024-38824 RHBZ#2372731 Resolves CVE-2024-38824 RHBZ#2372733 Resolves CVE-2025-22239 RHBZ#2372732 Resolves CVE-2025-22239 RHBZ#2372734 Resolves CVE-2025-22236 RHBZ#2372774

Update to release v1.32.6

https://security-tracker.debian.org/tracker/DSA-5953-1

Red Hat Advanced Cluster Security 4.8 simplifies management, enhances workflows and offers deeper external IP visibility

Update to 138.0.7204.49 CVE-2025-6555: Use after free in Animation CVE-2025-6556: Insufficient policy enforcement in Loader CVE-2025-6557: Insufficient data validation in DevTools

Automatic update for podman-5.5.2-1.fc41. security fix for CVE-2025-6032 Changelog for podman * Tue Jun 24 2025 Packit – 5:5.5.2-1 – Update to 5.5.2 upstream release

Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517

Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517

xorg-x11-server CVE fix for CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180

Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517

https://security-tracker.debian.org/tracker/DSA-5951-1

* bsc#1232908 * bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062

* bsc#1235231 Cross-References: * CVE-2024-56601

* bsc#1239948 * bsc#1244304 * bsc#1244503 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5952-1

https://security-tracker.debian.org/tracker/DSA-5950-1

Several security issues were fixed in libarchive.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

* bsc#1243565 * bsc#1245054 * bsc#1245055 Cross-References:

* bsc#1236217 * bsc#1244156 * bsc#1244157 * bsc#1244158 * jsc#SLE-18320

Ubuntu Chooses Performance Over Mitigation: Intel GPU Users See 20% Gains

https://security-tracker.debian.org/tracker/DSA-5949-1

https://security-tracker.debian.org/tracker/DSA-5948-1

* bsc#1244148 Cross-References: * CVE-2011-10007

* bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062 * bsc#1235231

Nils Emmerich discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.

commons-beanutils, utility for manipulating Java beans have an improper Access Control vulnerability. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers

* bsc#1239192 Cross-References: * CVE-2025-22868

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

IBM Donates CBOM Toolset to Linux Foundation

Template injection that can lead to XSS has been fixed in node-send, a Node.js module for streaming files over HTTP. For Debian 11 bullseye, this problem has been fixed in version

* bsc#1241067 * bsc#1243273 * bsc#1244032 * bsc#1244056 * bsc#1244059

* bsc#1234421 * bsc#1244405 * bsc#1244406 Cross-References:

* bsc#1243721 Cross-References: * CVE-2025-5222

https://security-tracker.debian.org/tracker/DSA-5947-1

Update to 137.0.7151.119 * CVE-2025-6191: Integer overflow in V8 * CVE-2025-6192: Use after free in Profiler

Harden temporary private mounts (#2373301)

4.9.0

This is the .NET monthly update for June 2025. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release-notes/9.0/9.0.6/9.0.107.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.6/9.0.6.md

Fix improper access control vulnerability Resolves: CVE-2025-48734

https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/OXIGQIHBL26HFKG6TT5SWSH7K7W6RO4H/ https://phabricator.wikimedia.org/T382326