MGASA-2025-0269 – Updated libxml2 & libxslt packages fix security vulnerabilities
MGAA-2025-0092 – Updated qarte packages fix bug
This is the October 2025 release of .NET 9, updating the SDK to version 9.0.111 and runtime to version to 9.0.10. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.10/9.0.111.md
Add CVE and bug fixes to bundled mbedtls in dolphin-emu
Rebuild with the latest golang in repos
New upstream stable version 1.22.5
Rebuild with the latest golang in repos
Upgrade to 4.3.4 upstream version. Build with Go 1.24.9 fixes multiple Go CVEs BZ#2408093 BZ#2408688 BZ#2409563 BZ#2410514 BZ#2411412
New version 3.0.2 (rhbz#2407048) Fixes CVE-2025-11232 (rhbz#2407228)
New upstream stable version 1.22.5
Several security issues were fixed in the Linux kernel.
An update that solves one vulnerability can now be installed.
* bsc#1252749 Cross-References: * CVE-2025-62594
An update that solves one vulnerability can now be installed.
* bsc#1239119 Cross-References: * CVE-2025-30258
The system could be made to expose sensitive information.
https://security-tracker.debian.org/tracker/DSA-6050-1
* bsc#1248004 Cross-References: * CVE-2025-55159
* bsc#1250413 Cross-References: * CVE-2025-9900
* bsc#1252414 * bsc#1252417 * bsc#1252418 * bsc#1252758
* bsc#1252414 * bsc#1252417 * bsc#1252418 * bsc#1252758
An update that solves three vulnerabilities and has one security fix can now be installed.
* bsc#1251194 Cross-References: * CVE-2025-61962
https://security-tracker.debian.org/tracker/DSA-6049-1
* bsc#1250413 Cross-References: * CVE-2025-9900
Update to 142.0.7444.59 * High CVE-2025-12428: Type Confusion in V8 * High CVE-2025-12429: Inappropriate implementation in V8 * High CVE-2025-12430: Object lifecycle issue in Media * High CVE-2025-12431: Inappropriate implementation in Extensions
New upstream development version 1.23.10 New upstream development version 1.23.9
add patch to remove dependency upper bound versions remove obsolete patches that updated upper bound versions clean up spec file formatting
uv / python-uv-build 0.9.5 https://github.com/astral-sh/uv/blob/0.9.5/CHANGELOG.md ruff 0.14.2 https://github.com/astral-sh/ruff/blob/0.14.2/CHANGELOG.md Pydantic 2.12.3
uv / python-uv-build 0.9.5 https://github.com/astral-sh/uv/blob/0.9.5/CHANGELOG.md ruff 0.14.2 https://github.com/astral-sh/ruff/blob/0.14.2/CHANGELOG.md Pydantic 2.12.3
https://security-tracker.debian.org/tracker/DSA-6048-1
An update that solves three vulnerabilities can now be installed.
* bsc#1248631 * bsc#1249207 * bsc#1249208 Cross-References:
* bsc#1206051 * bsc#1221829 * bsc#1233551 * bsc#1234480 * bsc#1234863
An update that solves four vulnerabilities can now be installed.
* bsc#1246019 * bsc#1248631 * bsc#1249207 * bsc#1249208
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
* bsc#1250410 Cross-References: * CVE-2025-9230
* bsc#1252282 Cross-References: * CVE-2025-62171
* bsc#1246818 Cross-References: * CVE-2025-7783
Xu Biang discovered a buffer overflow bug in the eap-mschapv2 plugin of strongSwan, an IKE/IPsec suite. The eap-mschapv2 plugin does not correctly check the length of an
Several security vulnerabilities have been discovered in WordPress, a popular content management framework. CVE-2024-6307
* bsc#1251941 Cross-References: * CVE-2025-62291
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
Upgrade to Ruby 3.3.10. CVE-2025-58767 ruby: REXML denial of service (rhbz#2396203)
New seamonkey packages are available for Slackware 15.0 and -current to fix security issues.
An update that solves 2 vulnerabilities can now be installed.
An update that solves 2 vulnerabilities can now be installed.
Update to xwayland 24.1.9, CVE fix for: CVE-2025-62229, CVE-2025-62230, CVE-2025-62231
Update to upstream 2.4.3, including fixes for CVE-2025-62513 and CVE-2025-62705.
Rebuild for CVE-2025-47906. https://pkg.go.dev/vuln/GO-2025-3956
Fix CVE-2025-5455 – QtCore Assertion Failure Denial of Service
Fixes CVE-2025-11561 Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=2402728 After startup SSSD already creates a Kerberos configuration snippet in /var/lib/sss/pubconf/krb5.include.d/localauth_plugin if the AD or IPA providers are used. This enables SSSD’s localauth plugin. Starting with this update the
New version 3.0.2 (rhbz#2407048) Fixes CVE-2025-11232 (rhbz#2407229)
https://security-tracker.debian.org/tracker/DSA-6047-1
https://security-tracker.debian.org/tracker/DSA-6046-1
* bsc#1242300 * bsc#1243284 Cross-References: * CVE-2025-47268
* bsc#1246019 * bsc#1248631 * bsc#1249207 * bsc#1249208
This upload fixes a few of security issues in the Python standard library included with PyPy, an alternative implementation of the Python 3 language. CVE-2024-6232
* bsc#1248631 * bsc#1249207 * bsc#1249208 Cross-References:
* bsc#1246019 * bsc#1248631 * bsc#1249207 * bsc#1249208
* bsc#1247737 * bsc#1248176 * bsc#1248631 * bsc#1249207 * bsc#1249208
https://security-tracker.debian.org/tracker/DSA-6045-1
The system could be made to expose sensitive information.
Netty could be made to send emails as your login if it received specially crafted input.
Several security issues were fixed in AMD Microcode.
Several security issues were fixed in GNU binutils.
Update to 9.18.41 (rhbz#2405786) Security fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780)
Update to 9.18.41 (rhbz#2405786) Security fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780)
https://security-tracker.debian.org/tracker/DSA-6043-1
Jan-Niklas Sohn discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.
Jan-Niklas Sohn discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.
MGASA-2025-0251 – Updated poppler packages fix security vulnerability
MGASA-2025-0250 – Updated tomcat packages fix security vulnerabilities
Multiple vulnerabilities have been found in python-authlib, a Python library for OAuth and OpenID Connect servers.
Update to latest version (#2404637) Fix CVE-2025-47910, CVE-2025-47906, CVE-2025-26625
https://security-tracker.debian.org/tracker/DSA-6044-1
* bsc#1251941 Cross-References: * CVE-2025-62291
* bsc#1246806 * bsc#1252414 * bsc#1252417 Cross-References:
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43272 Big Bear discovered that processing maliciously crafted web content may lead to an unexpected process crash.
* bsc#1019074 * bsc#1227577 * bsc#1229825 * bsc#1243331 * bsc#1243611
* bsc#1019074 * bsc#1227577 * bsc#1229825 * bsc#1237495 * bsc#1243331
* bsc#1227577 * bsc#1231150 * bsc#1231157 * bsc#1246277 * bsc#1246421
https://security-tracker.debian.org/tracker/DSA-6042-1
Moderate: kernel security update
Important: thunderbird security update
Moderate: kernel-rt security update
Moderate: kernel security update
https://security-tracker.debian.org/tracker/DSA-6041-1
https://security-tracker.debian.org/tracker/DSA-6039-1
https://security-tracker.debian.org/tracker/DSA-6040-1
https://security-tracker.debian.org/tracker/DSA-6037-1
https://security-tracker.debian.org/tracker/DSA-6038-1
https://security-tracker.debian.org/tracker/DSA-6036-1
Initial build for PHP81_BCstrftime Update DokuWiki to version 2025-05-14b “Librarian”
