Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Security fixes Bumped the minimum github.com/go-viper/mapstructure/v2 version to 2.3.0 for GHSA-fv92-fjc5-jj9h or GO-2025-3787 Bumped the minimum github.com/NVIDIA/nvidia-container-toolkit version to 1.17.8 for CVE-2025-23266 and CVE-2025-23267

How RingReaper Linux Malware Exploits io_uring to Evade EDR Systems

https://security-tracker.debian.org/tracker/DSA-5984-1

Update to release v1.32.7 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes

Update to release v1.31.12 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fix

Update to release v1.33.4 Resolves: rhbz#2388412 Fixes CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes

Update to 1.67.0 Update to 1.66.0

Update to release v1.31.12 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fix

Update to release v1.32.7 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes

* bsc#1248006 Cross-References: * CVE-2025-55159

Several security issues were fixed in PHP.

* bsc#1248006 Cross-References: * CVE-2025-55159

Several security issues were fixed in Python.

Update to version 0.4.11. This version includes a fix for CVE-2025-55159, but there are zero packages in Fedora or EPEL that use the affected API, so no rebuilds are necessary.

Update to v1.136.0 Update to 1.135.2 Update to 1.135.0

https://security-tracker.debian.org/tracker/DSA-5983-1

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape or bypass of the same-origin policy.

poppler could be made to denial of service if it received a specially crafted PDF file.

* bsc#1245218 * bsc#1247350 * bsc#1247351 Cross-References:

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

https://security-tracker.debian.org/tracker/DSA-5981-1

https://security-tracker.debian.org/tracker/DSA-5982-1

* bsc#1244270 * bsc#1244272 * bsc#1244273 * bsc#1244279 * bsc#1244336

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

Several security issues were fixed in Apache HTTP Server.

Several security issues were fixed in libxml2.

* bsc#1012628 * bsc#1139073 * bsc#1204142 * bsc#1210025 * bsc#1211226

https://security-tracker.debian.org/tracker/DSA-5980-1

* bsc#1242666 * bsc#1243428 Cross-References: * CVE-2025-3416

* bsc#1244631 * bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

https://security-tracker.debian.org/tracker/DSA-5979-1

What Is A Virtual Private Network (VPN)?

* bsc#1236217 * bsc#1246118 * bsc#1247719 * bsc#1247720 * jsc#SLE-18320

Introducing Red Hat Technical Account Management Service for Product Security

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

* bsc#1244631 * bsc#1245218 * bsc#1245350 * bsc#1245989 * bsc#1247350

* bsc#1244337 * bsc#1247350 * bsc#1247351 Cross-References:

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

https://security-tracker.debian.org/tracker/DSA-5978-1

Update to upstream 1.4.2, fix CVE-2025-22870

* bsc#1245320 Cross-References: * CVE-2025-6032

* bsc#1245320 Cross-References: * CVE-2025-6032

Updated to 139.0.7258.127 * CVE-2025-8879: Heap buffer overflow in libaom * CVE-2025-8880: Race in V8 * CVE-2025-8901: Out of bounds write in ANGLE * CVE-2025-8881: Inappropriate implementation in File Picker

Updated to 139.0.7258.127 * CVE-2025-8879: Heap buffer overflow in libaom * CVE-2025-8880: Race in V8 * CVE-2025-8901: Out of bounds write in ANGLE * CVE-2025-8881: Inappropriate implementation in File Picker

An update that fixes 5 vulnerabilities is now available.

fix CVE-2025-46206 (rhbz#2386395)

fixes CVE-2025-8534: null pointer dereference in tiff2p fixes CVE-2024-13978: null pointer dereference in tiff2pdf

update MANUAL to cover threat related to user HTML iframe

Several security issues were fixed in AIDE.

* bsc#1222040 * bsc#1222041 * bsc#1222042 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5975-1

https://security-tracker.debian.org/tracker/DSA-5974-1

What Is a Use-After-Free (UAF) Vulnerability?

Several security issues were fixed in Request Tracker.

Several security issues were fixed in Sidekiq.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5976-1

https://security-tracker.debian.org/tracker/DSA-5977-1

* bsc#1243747 Cross-References: * CVE-2025-48057

* bsc#1246397 Cross-References: * CVE-2025-48924

* bsc#1085999 * bsc#1246397 Cross-References: * CVE-2025-48924

* bsc#1247249 Cross-References: * CVE-2025-8194

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

National Security & AI at DEFCON 2025: Where Code Meets Crisis

An update that fixes 9 vulnerabilities is now available.

* bsc#1221107 Cross-References: * CVE-2024-2236

* bsc#1246296 Cross-References: * CVE-2025-7425

* bsc#1219386 Cross-References: * CVE-2023-5992

https://security-tracker.debian.org/tracker/DSA-5972-1

https://security-tracker.debian.org/tracker/DSA-5973-1

* bsc#1246318 * bsc#1246388 Cross-References: * CVE-2025-52520

* bsc#1233791 * bsc#1233834 Cross-References: * CVE-2024-22117

* bsc#1247519 * bsc#1247520 * bsc#1247522 Cross-References: