Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Add patch for double free

Fix CVE-2025-23016

Update to Samba 4.22.2 – Security fix for CVE-2025-0620

Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink

This update includes mod_security version 2.9.9 which addresses CVE-2025-47947 and includes various bug fixes. See https://github.com/owasp- modsecurity/ModSecurity/releases/tag/v2.9.9 for more information on the changes in this release.

Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink

This update includes mod_security version 2.9.9 which addresses CVE-2025-47947 and includes various bug fixes. See https://github.com/owasp- modsecurity/ModSecurity/releases/tag/v2.9.9 for more information on the changes in this release.

* bsc#1243268 Cross-References: * CVE-2025-47287

* bsc#1236826 * bsc#1239671 * bsc#1241012 Cross-References:

* bsc#1240392 Cross-References: * CVE-2025-2704

* bsc#1236974 Cross-References: * CVE-2024-12243

Several security issues were fixed in the Linux kernel.

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-24223

https://security-tracker.debian.org/tracker/DSA-5937-1

https://security-tracker.debian.org/tracker/DSA-5938-1

https://security-tracker.debian.org/tracker/DSA-5939-1

Several security issues were fixed in Bootstrap.

Several security issues were fixed in the Linux kernel.

* bsc#1243332 * bsc#1243422 * bsc#1243423 Cross-References:

* bsc#1243313 Cross-References: * CVE-2025-47273

* bsc#1241274 * bsc#1241275 * bsc#1241276 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5936-1

https://security-tracker.debian.org/tracker/DSA-5935-1

https://security-tracker.debian.org/tracker/DSA-5934-1

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to “*.example.com”, a request to “[::1%25.example.com]:80` will incorrectly match and not be proxied – CVE-2025-22870.

Several security issues were fixed in the Linux kernel.

The Hidden Security Risks of Open-Source AI

Open VM Tools could be made to overwrite files as the administrator.

Several security issues were fixed in MariaDB.

Fix for local information disclosure in systemd-coredump (CVE-2025-4598) Various other fixes

Two security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. CVE-2025-47779

* bsc#1214960 * bsc#1230092 Cross-References: * CVE-2024-45310

* bsc#1215199 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757

* bsc#1215199 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757

* bsc#1231284 Cross-References: * CVE-2024-8508

* bsc#1237367 * bsc#1239185 * bsc#1239322 * bsc#1239765 * jsc#PED-12534

* bsc#1234128 * bsc#1234665 * bsc#1239883 * bsc#1243317

Unlock sensitive data for AI with Cloudera on Red Hat OpenShift

twitter-bootstrap3 a popular front end framework was affected by a vulnerability. A cross-site scripting (XSS) vulnerability

A vulnerability has been found in kitty, a fast, featureful, GPU based terminal emulator, which possible allows arbitrary code execution. CVE-2022-41322

Update to 128.11.0 https://www.thunderbird.net/en-US/thunderbird/128.11.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-46/

Fix for local information disclosure in systemd-coredump (CVE-2025-4598) Fixes for systemd itself, run0, systemd-networkd, “secure” pager, man pages, shell completions, sd-boot, sd-varlink Hardware database update

https://security-tracker.debian.org/tracker/DSA-5933-1

Multiple stack-based buffer overflows have been fixed in the net-tools network utilities. For Debian 11 bullseye, this problem has been fixed in version

Double free on init failure has been fixed in libvpx, a library for decoding and encoding VP8 and VP9 videos. For Debian 11 bullseye, this problem has been fixed in version

Several issues have been found in espeak-ng, a Multi-lingual software speech synthesizer. The issues are related to buffer overflow or underflow in several

Buffer underflow on glib through glib/gstring.c via function g_string_insert_unichar. (CVE-2025-4373) References: – https://bugs.mageia.org/show_bug.cgi?id=34310

Heap buffer under-read in gnu coreutils sort via key specification. (CVE-2025-5278) References: – https://bugs.mageia.org/show_bug.cgi?id=34313

Multiple security issues were discovered in Flask-CORS, a Flask extension for handling Cross Origin Resource Sharing (CORS). CVE-2024-1681

New upstream version (139.0)

This update contains the backported fix for CVE-2024-52804 (cookie parsing DoS vuln).

https://security-tracker.debian.org/tracker/DSA-5931-1

https://security-tracker.debian.org/tracker/DSA-5930-1

Apport could be made to leak sensitive information.

* bsc#1243353 Cross-References: * CVE-2025-5263 * CVE-2025-5264

* bsc#1241274 * bsc#1241275 * bsc#1241276 * bsc#1242208 * bsc#1243429

* bsc#1242300 * bsc#1243284 Cross-References: * CVE-2025-47268

* bsc#1242931 Cross-References: * CVE-2025-4207

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code or information disclosure. For Debian 11 bullseye, these problems have been fixed in version

https://security-tracker.debian.org/tracker/DSA-5932-1

https://security-tracker.debian.org/tracker/DSA-5923-2

https://security-tracker.debian.org/tracker/DSA-5928-1

* bsc#1242008 * bsc#1242009 Cross-References: * CVE-2025-31650

* bsc#1236217 * bsc#1242715 Cross-References: * CVE-2025-22873

* bsc#1241658 * bsc#1241659 Cross-References: * CVE-2025-43965

* bsc#1243216 Cross-References: * CVE-2025-3875 * CVE-2025-3877

* bsc#1242809 Cross-References: * CVE-2025-3887

Tails and Tor: A New Alliance for Digital Security

https://security-tracker.debian.org/tracker/DSA-5929-1

A path traversal vulnerability in `PackageIndex` was found in setuptools. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context.

GNU C Library could be made to crash or run programs if it processed specially crafted dynamically shared library.

* bsc#1243313 Cross-References: * CVE-2025-47273

* bsc#1243356 Cross-References: * CVE-2025-21490

* bsc#1242809 Cross-References: * CVE-2025-3887

Revive Your Old PC & Fortify Your System with FunOS

https://security-tracker.debian.org/tracker/DSA-5926-1

https://security-tracker.debian.org/tracker/DSA-5927-1

A flaw was discovered in the dynamic linking support in the GNU C Library, the C standard library implementation used by Debian. Privilege escalation may be possible in statically compiled setuid

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in Intel Microcode.

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

PgBouncer is a lightweight connection pooler for PostgreSQL. CVE-2021-3539

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

* bsc#1243313 Cross-References: * CVE-2025-47273

* bsc#1242931 Cross-References: * CVE-2025-4207

New updates for Red Hat Enterprise Linux on confidential virtual machines

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Data Security Best Practices for Strengthening Linux Networks

A few fixes

This is the May 2025 update for .NET 8 for Fedora. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.16/8.0.116.md Runtime: https://github.com/dotnet/core/blob/main/release-

Update to version 12.5.2. Fixes CVE-2025-22247

Update to 128.10.2 https://www.thunderbird.net/en-US/thunderbird/128.10.2esr/releasenotes/