https://security-tracker.debian.org/tracker/DSA-5901-1
https://security-tracker.debian.org/tracker/DSA-5902-1
Multiple vulnerabilities were found in wpa, a set of tools including the widely-used wpasupplicant client for authenticating with WPA and WPA2 wireless networks.
A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN. (CVE-2025-32364) Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits. (CVE-2025-27795) References: – https://bugs.mageia.org/show_bug.cgi?id=34163
https://security-tracker.debian.org/tracker/DSA-5900-1
https://security-tracker.debian.org/tracker/DSA-5899-1
Update to 1.34.5. Fixes CVE-2025-31498.
Limit the data stored in session state. Remove the empty area below the title bar in Web Inspector when not docked. Fix various crashes and rendering issues
Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate implementation in Intents Medium CVE-2025-3069: Inappropriate implementation in Extensions
Update to 7.2.5 (CVE-2024-36469, CVE-2024-42325, CVE-2024-45700)
* bsc#1073014 Cross-References: * CVE-2017-17521
* bsc#1239618 * jsc#PED-12500 * jsc#SLE-21253 Cross-References:
Update to 2025.04 GA Update to 2025.04 RC5
Update to 128.9.0 https://www.thunderbird.net/en-US/thunderbird/128.9.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-24/
https://security-tracker.debian.org/tracker/DSA-5898-1
HAProxy could be made to crash or run programs if it received specially crafted network traffic.
* bsc#1234452 Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4
CVE-2025-27835 ghostscript: Buffer overflow when converting glyphs to unicode (fedora#2355025) CVE-2025-27834 ghostscript: Buffer overflow caused by an oversized Type 4 function in a PDF (fedora#2355023) CVE-2025-27832 ghostscript: NPDL device: Compression buffer overflow
Dino could be made to expose sensitive information over the network.
* bsc#1239460 Cross-References: * CVE-2025-24049
An update that fixes one vulnerability is now available.
This update includes an upstream patch to accept “0” as a valid epoch in Debian packages processed by BSSolv. This fixes a bug that prevents the Open Build Service backend from working
* bsc#1207948 * bsc#1215199 * bsc#1215211 * bsc#1218470 * bsc#1221651
Update to 128.9.0 https://www.thunderbird.net/en-US/thunderbird/128.9.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-24/
Expat could be made to crash if it received specially crafted input.
* bsc#1240416 Cross-References: * CVE-2025-31344
* bsc#1240416 Cross-References: * CVE-2025-31344
Net::EasyTCP Perl module includes encryption functionality that requires a secure random number generator. Until and including the version 0.26, this module used a random number generator without any such guarantees. The reason for this was that it relied on Crypt::Random, a Perl module
Prior to version 0.008, the Perl module Data::Entropy relied on Perl’s builtin rand function to choose an entropy source. Version 0.008 does away with this need.
https://security-tracker.debian.org/tracker/DSA-5897-1
* bsc#1236217 * bsc#1239182 * bsc#1240550 Cross-References:
* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6
* bsc#1240083 Cross-References: * CVE-2025-3028 * CVE-2025-3029
5.0.0
Update to 0.4.8; Fixes: RHBZ#2237964, RHBZ#2282129
Fix CVE-2024-12905.
Address CVE-2025-30093 – rhbz#2355671
5.0.0
Fix CVE-2024-12905.
Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate implementation in Intents Medium CVE-2025-3069: Inappropriate implementation in Extensions
Backport fixes from v1.127.1
This is an update fixing CVE 2025-30232.
Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate implementation in Intents Medium CVE-2025-3069: Inappropriate implementation in Extensions
CVE-2025-27835 ghostscript: Buffer overflow when converting glyphs to unicode (fedora#2355026) CVE-2025-27834 ghostscript: Buffer overflow caused by an oversized Type 4 function in a PDF (fedora#2355024) CVE-2025-27832 ghostscript: NPDL device: Compression buffer overflow
This is an update fixing CVE 2025-30232.
https://security-tracker.debian.org/tracker/DSA-5893-1
https://security-tracker.debian.org/tracker/DSA-5894-1
https://security-tracker.debian.org/tracker/DSA-5895-1
https://security-tracker.debian.org/tracker/DSA-5896-1
https://security-tracker.debian.org/tracker/DSA-5892-1
* bsc#1229122 * bsc#1240550 Cross-References: * CVE-2025-22871
Upgrade to 2.48.0: Move tile rendering to worker threads when rendering with the GPU. Fix preserve-3D intersection rendering. Added new function for creating Promise objects to the JavaScriptCore GLib API. The MediaRecorder backend gained WebM support (requires at least GStreamer
Several security issues were fixed in the Linux kernel.
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP. (CVE-2024-56161)
* bsc#1228012 * bsc#1228578 * bsc#1233023 Cross-References:
* bsc#1238591 * bsc#1239625 * bsc#1239637 Cross-References:
* bsc#1239302 * bsc#1239676 Cross-References: * CVE-2024-56337
* bsc#1240075 * bsc#1240077 * bsc#1240080 * bsc#1240081
https://security-tracker.debian.org/tracker/DSA-5890-1
https://security-tracker.debian.org/tracker/DSA-5891-1
* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6
* bsc#1234452 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5
* bsc#1219437 * bsc#1234089 * bsc#1237367 * bsc#1239185 * bsc#1239322
* bsc#1240083 Cross-References: * CVE-2025-3028 * CVE-2025-3029
https://security-tracker.debian.org/tracker/DSA-5889-1
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
A security issue was fixed in MariaDB.
* bsc#1237367 * bsc#1239185 * bsc#1239322 Cross-References:
* bsc#1234452 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5
The perl module Data::Entropy was using the cryptographically insecure rand() function as default entropy source. For Debian 11 bullseye, this problem has been fixed in version
Microcode updates has been released for Intel(R) processors, addressing multiple potential vulnerabilties that may allow local privilege escalation, denial of service or information disclosure.
