https://security-tracker.debian.org/tracker/DSA-5946-1
https://security-tracker.debian.org/tracker/DSA-5945-1
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
* bsc#1241158 * bsc#1241160 * bsc#1243282 * bsc#1243286 * bsc#1243288
* bsc#1234449 Cross-References: * CVE-2024-47606
* bsc#1239192 Cross-References: * CVE-2025-22868
* bsc#1227690 Cross-References: * CVE-2024-38526
* bsc#1233012 * bsc#1243273 * bsc#1244401 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5944-1
It was discovered that an Out Of Memory error may occur when attempting to initialize a huge byte array, even when maxFrameSize is set. For Debian 11 bullseye, this problem has been fixed in version
* bsc#1234415 * bsc#1234450 * bsc#1234453 * bsc#1234455 * bsc#1234456
Several security issues were fixed in Samba.
Several security issues were fixed in Express.
* bsc#1238681 * bsc#1239192 Cross-References: * CVE-2025-22868
https://security-tracker.debian.org/tracker/DSA-5943-1
* bsc#1154353 * bsc#1156395 * bsc#1170891 * bsc#1173139 * bsc#1184350
* bsc#1244039 Cross-References: * CVE-2024-47081
* bsc#1244039 Cross-References: * CVE-2024-47081
* bsc#1244039 Cross-References: * CVE-2024-47081
* bsc#1223096 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757
Django could be made to log injection if received specially crafted input.
Update to 128.11.1 https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/
Fixes CVE-2025-32873: Denial-of-service possibility in strip_tags() Fixes CVE-2025-48432: Potential log injection via unescaped request path
Rebuild for CVE-2024-12224, CVE-2025-4574
Rebuild against idna 1.0+ for CVE-2024-12224
* bsc#1215935 * bsc#1215936 * bsc#1233606 * bsc#1233608 * bsc#1233609
* bsc#1242015 Cross-References: * CVE-2025-3891
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Several security issues were fixed in ModSecurity.
A stack-based buffer overflow has been fixed in ICU, a C++ and C library for Unicode and Globalization support. For Debian 11 bullseye, this problem has been fixed in version
Two vulnerabilities have been fixed in cJSON, a C library for parsing JSON. CVE-2023-26819
An input sanitization flaw in Konsole might allow remote attackers to execute commands via a malicious URL
An integer overflow vulnerability has been found in sysstat which could result in arbitrary code execution.
Fix CVE-2025-49112 Fix CVE-2025-49112
Security update
New version 4.4.7 Ignoring potential error when using udevadm in %post scriptlet
Update to 137.0.7151.103 CVE-2025-5958: Use after free in Media CVE-2025-5959: Type Confusion in V8
This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574
This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574
This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574
This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574
Update to 3.12.11. gh-135034: [CVE 2024-12718] [CVE 2025-4138] [CVE 2025-4330] [CVE 2025-4435] [CVE 2025-4517] Fixes multiple issues that allowed tarfile extraction filters (filter=”data” and filter=”tar”) to be bypassed using crafted symlinks and hard links.
Fix CVE-2025-49466 (fedora#2370375)
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5942-1
* bsc#1240750 * bsc#1240752 * bsc#1240754 * bsc#1240756 * bsc#1240757
* bsc#1244035 Cross-References: * CVE-2025-22868 * CVE-2025-22869
* bsc#1237147 * bsc#1241938 * bsc#1243106 Cross-References:
* bsc#1242300 Cross-References: * CVE-2025-47268
* bsc#1232900 * bsc#1236701 * bsc#1239077 * bsc#1239096
* bsc#1236701 * bsc#1239077 * bsc#1239096 Cross-References:
* bsc#1238324 * bsc#1239077 Cross-References: * CVE-2022-49080
* bsc#1243273 Cross-References: * CVE-2025-4516
* bsc#1239949 * bsc#1241050 * bsc#1243217 * bsc#1243218
* bsc#1239949 * bsc#1241050 * bsc#1243217 * bsc#1243218
https://security-tracker.debian.org/tracker/DSA-5941-1
* bsc#1234282 * bsc#1238043 * bsc#1243117 Cross-References:
* bsc#1238324 * bsc#1239077 Cross-References: * CVE-2022-49080
* bsc#1236701 * bsc#1239077 * bsc#1239096 Cross-References:
* bsc#1232900 * bsc#1236701 * bsc#1239077 * bsc#1239096
Several security issues were fixed in tomcat8, tomcat9, tomcat10.
https://security-tracker.debian.org/tracker/DSA-5940-1
DoS with sanitiseArg/sanitizeArg has been fixed in modsecurity-apache, a module for the Apache webserver to tighten Web application security. For Debian 11 bullseye, this problem has been fixed in version
Disallowing use of the arcfour-hmac(-md5) encryption type for session keys Add support for the PKINIT paChecksum2 sequence, required for Active Directory interoperability on Windows Server 2025 Fix generation of RADIUS Message-Authenticator in FIPS mode
Kirill Firsov discovered that Roundcube, a skinnable AJAX based webmail solution for IMAP servers, was performing PHP Object deserialization on unvalidated input, which could lead to remote code execution by an authenticated attacker.
Several vulnerabilities were discovered in modsecurity-apache, an Apache module to tighten the Web application security, which may result in denial of service (high memory consumption).
New libvpx packages are available for Slackware 15.0 and -current to fix security issues.
ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and calls pg_insert_id() with user-supplied data.
Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump. (CVE-2025-4598) References:
Security constraint bypass for CGI scripts. (CVE-2025-46701) References: – https://bugs.mageia.org/show_bug.cgi?id=34332 – https://openwall.com/lists/oss-security/2025/05/29/4
Update to version 4.21.6
