Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

* bsc#1239680 Cross-References: * CVE-2025-2312

Jupyter Notebook could be made to crash if it received specially crafted input.

Update to 135.0.7049.114

Update to pgadmin-9.2.

April 2025 CPU

April 2025 CPU

April 2025 CPU

April 2025 CPU

https://security-tracker.debian.org/tracker/DSA-5907-1

[CVE-2025-32414] Buffer overflow when parsing text streams with Python API [CVE-2025-32415] Heap-based Buffer Overflow in xmlSchemaIDCFillNodeTables

BUG/MEDIUM: sample: fix risk of overflow when replacing multiple regex back-refsAleandro Prudenzano of Doyensec and Edoardo Geraci of Codean Labs reported a bug in sample_conv_regsub(), which can cause replacements of multiple back-references to overflow the temporary trash buffer. The problem happens when doing “regsub(match,replacement,g)”:

* bsc#1230092 Cross-References: * CVE-2024-45310

Update to 135.0.7049.114

Update to 135.0.7049.114

New upstream version 5.8.1 (with a rebuild to try and fix a gating problem). New upstream version 5.8.1

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

Several security issues were fixed in the Linux kernel.

Update to 1.24.1, fixes CVE-2025-2291.

Backport fixes for CVE-2025-32910, CVE-2025-32911, CVE-2025-32913 Backport fixes for CVE-2025-32050 CVE-2025-32052 CVE-2025-32053 CVE-2025-32906 CVE-2025-32907 CVE-2025-32909

Update to 1.24.1, fixes CVE-2025-2291.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Multiple vulnerabilities have been fixed in the OpenRazer drivers for devices from Razer, a company selling hardware mainly targeted at gamers. CVE-2022-23467

Backport fixes for CVE-2025-32364 and CVE-2025-32365.

Several security issues were fixed in the Linux kernel.

Overcoming SaaS Security Risks with Open-Source Tools

Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after free in USB

Latest updates.

Resolves CVE-2024-53868

Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after free in USB

Latest updates.

Update to 128.9.2 https://www.thunderbird.net/en-US/thunderbird/128.9.1esr/releasenotes/ https://www.thunderbird.net/en-US/thunderbird/128.9.2esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-27/

Linux 6.15-rc3: Security Advisory for UBLK Driver Enhancements

Backport proposed fix for CVE-2025-31344 from OpenMandriva. Install gif_getarg.h header.

Fix CVE-2024-56406

Fix CVE-2024-56406

Fix CVE-2024-56406

Several security issues were fixed in Eclipse Mosquitto.

New Supply Chain Attack Targets Telegram Bots

Multiple vulnerabilities have been fixed in the fig2dev utilities for converting XFig figure files. CVE-2025-31162

Mishandling of semicolons in the userinfo subcomponent of a URI has been fixed in GNU Wget, a utility for retrieving files over HTTP, HTTPS, FTP and FTPS.

USN-6200-2 introduced a regression in ImageMagick.

Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after free in USB

rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered. See https://www.arin.net/announcements/20250116-tal/ rpki-client reports Certification Authorities that do not meaningfully participate in the RPKI as non-functional CAs. By definition, a CA is non-

release v1.16.0

By the numbers: Security insights from Red Hat and IBM

Several vulnerabilities were discovered in the Erlang/OTP implementation of the SSH protocol, which may result in denial of service or the execution of arbitrary code.

Fix bz2358011

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.

https://security-tracker.debian.org/tracker/DSA-5906-1

https://security-tracker.debian.org/tracker/DSA-5905-1

https://security-tracker.debian.org/tracker/DSA-5904-1

Several vulnerabilities were discovered in the shadow suite of login tools. An attacker may extract a password from memory in limited situations, and confuse an administrator inspecting /etc/passwd from within a terminal.

New libxml2 packages are available for Slackware 15.0 and -current to fix security issues.

* bsc#1241150 Cross-References: * CVE-2025-32460

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

* bsc#1240958 * bsc#1240961 * bsc#1240962 * bsc#1240963 * bsc#1240964

* bsc#1240893 Cross-References: * CVE-2025-31492

* bsc#1240971 Cross-References: * CVE-2025-32464

* bsc#1240880 * bsc#1240881 Cross-References: * CVE-2025-32364

Expired US Funding Threatened to Disrupt Security Flaw Tracking

https://security-tracker.debian.org/tracker/DSA-5903-1

* bsc#1239826 * jsc#MSQA-936 Cross-References: * CVE-2025-23392

* bsc#1240893 Cross-References: * CVE-2025-31492

* bsc#1239863 * bsc#1239864 * bsc#1240958 * bsc#1240961 * bsc#1240962

* bsc#1224295 * bsc#1234840 * bsc#1239308 Cross-References:

* bsc#1239649 Cross-References: * CVE-2024-12088

* bsc#1065729 * bsc#1179878 * bsc#1180814 * bsc#1185762 * bsc#1195823

* bsc#1240971 Cross-References: * CVE-2025-32464

* bsc#1240958 * bsc#1240961 * bsc#1240962 * bsc#1240963 * bsc#1240964

* bsc#1228714 * bsc#1232818 * bsc#1235218 * bsc#1238788 * bsc#1238790

Perl could be made to crash or run programs if it processed specially crafted data.

* bsc#1065729 * bsc#1180814 * bsc#1183682 * bsc#1190336 * bsc#1190768

* bsc#1228714 * bsc#1232818 * bsc#1235218 * bsc#1238788 * bsc#1238790

* bsc#1228714 * bsc#1235218 Cross-References: * CVE-2024-41090

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure, cross-site scripting or restriction bypass.

Update to 135.0.7049.84 * CVE-2025-3066: Use after free in Site Isolation

Update to 6.0.39 (CVE-2024-45700, CVE-2024-36469, CVE-2024-42325, CVE-2024-45699)

Update to 135.0.7049.84 * CVE-2025-3066: Use after free in Site Isolation