Security fixes Bumped the minimum github.com/go-viper/mapstructure/v2 version to 2.3.0 for GHSA-fv92-fjc5-jj9h or GO-2025-3787 Bumped the minimum github.com/NVIDIA/nvidia-container-toolkit version to 1.17.8 for CVE-2025-23266 and CVE-2025-23267
https://security-tracker.debian.org/tracker/DSA-5984-1
Update to release v1.32.7 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes
Update to release v1.31.12 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fix
Update to release v1.33.4 Resolves: rhbz#2388412 Fixes CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes
Update to 1.67.0 Update to 1.66.0
Update to release v1.31.12 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fix
Update to release v1.32.7 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes
* bsc#1248006 Cross-References: * CVE-2025-55159
Several security issues were fixed in PHP.
* bsc#1248006 Cross-References: * CVE-2025-55159
Several security issues were fixed in Python.
Update to version 0.4.11. This version includes a fix for CVE-2025-55159, but there are zero packages in Fedora or EPEL that use the affected API, so no rebuilds are necessary.
Update to v1.136.0 Update to 1.135.2 Update to 1.135.0
https://security-tracker.debian.org/tracker/DSA-5983-1
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape or bypass of the same-origin policy.
poppler could be made to denial of service if it received a specially crafted PDF file.
* bsc#1245218 * bsc#1247350 * bsc#1247351 Cross-References:
* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351
https://security-tracker.debian.org/tracker/DSA-5981-1
https://security-tracker.debian.org/tracker/DSA-5982-1
* bsc#1244270 * bsc#1244272 * bsc#1244273 * bsc#1244279 * bsc#1244336
* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351
Several security issues were fixed in Apache HTTP Server.
Several security issues were fixed in libxml2.
* bsc#1012628 * bsc#1139073 * bsc#1204142 * bsc#1210025 * bsc#1211226
https://security-tracker.debian.org/tracker/DSA-5980-1
* bsc#1242666 * bsc#1243428 Cross-References: * CVE-2025-3416
* bsc#1244631 * bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351
* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351
https://security-tracker.debian.org/tracker/DSA-5979-1
* bsc#1236217 * bsc#1246118 * bsc#1247719 * bsc#1247720 * jsc#SLE-18320
* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351
* bsc#1244631 * bsc#1245218 * bsc#1245350 * bsc#1245989 * bsc#1247350
* bsc#1244337 * bsc#1247350 * bsc#1247351 Cross-References:
* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351
* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351
https://security-tracker.debian.org/tracker/DSA-5978-1
Update to upstream 1.4.2, fix CVE-2025-22870
* bsc#1245320 Cross-References: * CVE-2025-6032
* bsc#1245320 Cross-References: * CVE-2025-6032
Updated to 139.0.7258.127 * CVE-2025-8879: Heap buffer overflow in libaom * CVE-2025-8880: Race in V8 * CVE-2025-8901: Out of bounds write in ANGLE * CVE-2025-8881: Inappropriate implementation in File Picker
Updated to 139.0.7258.127 * CVE-2025-8879: Heap buffer overflow in libaom * CVE-2025-8880: Race in V8 * CVE-2025-8901: Out of bounds write in ANGLE * CVE-2025-8881: Inappropriate implementation in File Picker
An update that fixes 5 vulnerabilities is now available.
fix CVE-2025-46206 (rhbz#2386395)
fixes CVE-2025-8534: null pointer dereference in tiff2p fixes CVE-2024-13978: null pointer dereference in tiff2pdf
update MANUAL to cover threat related to user HTML iframe
Several security issues were fixed in AIDE.
* bsc#1222040 * bsc#1222041 * bsc#1222042 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5975-1
https://security-tracker.debian.org/tracker/DSA-5974-1
Several security issues were fixed in Request Tracker.
Several security issues were fixed in Sidekiq.
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5976-1
https://security-tracker.debian.org/tracker/DSA-5977-1
* bsc#1243747 Cross-References: * CVE-2025-48057
* bsc#1246397 Cross-References: * CVE-2025-48924
* bsc#1085999 * bsc#1246397 Cross-References: * CVE-2025-48924
* bsc#1247249 Cross-References: * CVE-2025-8194
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
An update that fixes 9 vulnerabilities is now available.
* bsc#1221107 Cross-References: * CVE-2024-2236
* bsc#1246296 Cross-References: * CVE-2025-7425
* bsc#1219386 Cross-References: * CVE-2023-5992
https://security-tracker.debian.org/tracker/DSA-5972-1
https://security-tracker.debian.org/tracker/DSA-5973-1
* bsc#1246318 * bsc#1246388 Cross-References: * CVE-2025-52520
* bsc#1233791 * bsc#1233834 Cross-References: * CVE-2024-22117
* bsc#1247519 * bsc#1247520 * bsc#1247522 Cross-References:
