Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

* bsc#1241502 * bsc#1249112 Cross-References: * CVE-2023-26819

* bsc#1225417 * bsc#1227086 * bsc#1250627 Cross-References:

https://security-tracker.debian.org/tracker/DSA-6023-1

Your Red Hat OpenShift AI models are waiting at the door. Who’s knocking?
Mitigating AI’s new risk frontier: Unifying enterprise cybersecurity with AI safety

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-6021-1

https://security-tracker.debian.org/tracker/DSA-6022-1

* bsc#1122338 Cross-References: * CVE-2019-6461

* bsc#1250553 Cross-References: * CVE-2025-10911

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-6020-1

* bsc#1250715 Cross-References: * CVE-2025-11226

* bsc#1249036 Cross-References: * CVE-2025-9375

* bsc#1230028 Affected Products: * Desktop Applications Module 15-SP6 * Desktop Applications Module 15-SP7

* bsc#1243701 Cross-References: * CVE-2025-48708

* bsc#1243701 Cross-References: * CVE-2025-48708

* bsc#1250452 Affected Products: * Desktop Applications Module 15-SP6 * Desktop Applications Module 15-SP7

poppler could be made to crash if it opened a specially crafted file.

Squid could be made to crash if it received specially crafted network traffic.

Several security issues were fixed in MySQL.

CVE-2025-27613 With Gitk, the Git history browser, when a user clones an untrusted repository and runs gitk without additional command arguments,

jupyterlab 4.4.9 fixing CVE-2025-59842.

jupyterlab 4.4.9 fixing CVE-2025-59842.

Update to latest upstream version.

Resolve CVE-2025-47910

Updated to latest upstream (143.0.3)

Update to latest upstream version.

https://security-tracker.debian.org/tracker/DSA-6019-1

Multiple vulnerabilities were discovered in log4cxx, a logging library for C++ that is compatible with the JAVA log4j framework. CVE-2025-54812

How Red Hat can support your journey to a standard operating environment
Security update: Incident related to Red Hat Consulting GitLab instance

4.0.6.3221

fix rhbz#2397702

fix rhbz#2397703

4.0.6.3221

Important: pcs security update

Important: perl-File-Find-Rule security update

* bsc#1235237 Cross-References: * CVE-2024-55553

New upstream release (143.0.3)

CVE-2025-7493: host to admin escalation prevention: https://www.freeipa.org/release-notes/4-12-5.html Update FreeIPA to latest fixes from ipa-4-12 branch

Update to 7.1.2.

cve fixes

Security update for path traversal CVE-2025-59825 / GHSA-3wgq-wrwc-vqmv.

https://security-tracker.debian.org/tracker/DSA-6017-1

https://security-tracker.debian.org/tracker/DSA-6018-1

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Why Software Supply Chain Security Matters in Linux Systems

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-6016-1

Several security issues were fixed in the Linux kernel.

An issue was found in open-vm-tools, a set of tools for VMs hosted on VMware. The issue is related to a local privilege escalation in combination with the get-versions.sh script, shipped with the service

BIRD 3.1.4 (2025-09-22) BGP: Fixed crash on Notification with a message, CVE-2025-59688 BGP: Fixed invalid memory access in pending TX flush BGP: Fixed a rare bug with listening socket delay Pipe: Disabled statisticts for stopping pipe

Update to version 1.6.2. Includes fixes for CVE-2025-58066 (potential DoS in the ntpd-rs server) and CVE-2025-58160 (potential tracing log pollution).

Update to 2.0.1 to CVE-2025-30187

Update the ammonia crate to version 4.1.2 and rebuild python-nh3 to apply fixes for RUSTSEC-2025-0071.

https://security-tracker.debian.org/tracker/DSA-6015-1

Supply Chain Attacks Are Spreading: NPM, PyPI, and Docker Hub All Hit in 2025

Multiple vulnerabilities were fixed in tiff, a library and tools providing support for the Tag Image File Format (TIFF). CVE-2024-13978

31.0.9 release RHBZ#2388493 RHBZ#2389830 RHBZ#2389831 RHBZ#2389842 RHBZ#2389843 RHBZ#2389814 RHBZ#2389815

31.0.9 release RHBZ#2388493 RHBZ#2389830 RHBZ#2389831 RHBZ#2389842 RHBZ#2389843 RHBZ#2389814 RHBZ#2389815

31.0.9 release RHBZ#2388493 RHBZ#2389830 RHBZ#2389831 RHBZ#2389842 RHBZ#2389843 RHBZ#2389814 RHBZ#2389815

A vulnerability has been discovered in python-internetarchive, a Python library and command-line interface for searching, downloading and uploading content to the Internet Archive.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

USN-7280-2 introduced a regression in Python 2.7

USN-7015-4 introduced a regression in Python 2.7

An update that solves one vulnerability can now be installed.

* bsc#1247674 Cross-References: * CVE-2025-54571

* bsc#1247674 Cross-References: * CVE-2025-54571

* bsc#1236658 * bsc#1236746 * bsc#1237208 * bsc#1237308 * bsc#1237585

An update that solves 2 vulnerabilities can now be installed.

An update that solves 18 vulnerabilities can now be installed.

An update that solves 7 vulnerabilities can now be installed.

Three security issues were discovered in the Squid proxy caching server, which could result in the execution of arbitrary code, information disclosure or denial of service.

It was discovered that the symlink validation in node-tar-fs, a Node.js module that provides filesystem-like access to tar files, could be bypassed.

Firefox 140.3.1 has been released, which fixes connection errors with some sites; if HTTP/3 connections failed, the fallback is now handled more gracefully.

https://security-tracker.debian.org/tracker/DSA-6003-2

https://security-tracker.debian.org/tracker/DSA-6013-1

https://security-tracker.debian.org/tracker/DSA-6014-1

https://security-tracker.debian.org/tracker/DSA-6012-1

Update to 140.0.7339.207 * CVE-2025-10890: Side-channel information leakage in V8 * CVE-2025-10891: Integer overflow in V8 * CVE-2025-10892: Integer overflow in V8

4.0.6.3221

Update to 140.0.7339.207 * CVE-2025-10890: Side-channel information leakage in V8 * CVE-2025-10891: Integer overflow in V8 * CVE-2025-10892: Integer overflow in V8

Eugene Medvedev discovered that nncp, a package facilitating secure store-and-forward file and mail exchange, was susceptible to path traversal with the freq and file commands.

An update that fixes one vulnerability is now available.

* bsc#1234896 * bsc#1244824 * bsc#1245970 * bsc#1246473 * bsc#1246911

* bsc#1247901 * bsc#1247902 * bsc#1247904 Cross-References:

* bsc#1246974 * bsc#1249375 Cross-References: * CVE-2025-8114