Update to 134.0.6998.35 * CVE-2025-1914: Out of bounds read in V8 * CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools * CVE-2025-1916: Use after free in Profiles
Unbundle libxml2.
Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For the stable distribution (bookworm), these problems have been fixed in
Two vulnerabilities were discovered in openvpn, a virtual private network application which could result in authentication bypass or data injection.
High CVE-2025-1914: Out of bounds read in V8. Medium CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools. Medium CVE-2025-1916: Use after free in Profiles. Medium CVE-2025-1917: Inappropriate Implementation in Browser UI.
Update to 134.0.6998.35 * CVE-2025-1914: Out of bounds read in V8 * CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools * CVE-2025-1916: Use after free in Profiles
The newest upstream commit Security fix for CVE-2025-27423
update to version 2.25.1, CVE-2025-27154
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2. (CVE-2023-5520) Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV. (CVE-2024-0321) Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
https://security-tracker.debian.org/tracker/DSA-5876-1
https://security-tracker.debian.org/tracker/DSA-5875-1
Several security issues were fixed in the Linux kernel.
Updated to latest upstream (136.0)
Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian
Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
Several security issues were fixed in Ansible.
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.
Updated to latest upstream (136.0)
The newest upstream commit Security fix for CVE-2025-27423
New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.
https://security-tracker.debian.org/tracker/DSA-5873-1
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.
Several security issues were fixed in the Linux kernel.
* bsc#1237683 Cross-References: * CVE-2024-43097 * CVE-2025-1930
Several security issues were fixed in the Linux kernel.
A security issue was fixed in Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
https://security-tracker.debian.org/tracker/DSA-5874-1
Several security issues were fixed in cmark-gfm.
Several security issues were fixed in spip.
wpa_supplicant and hostapd could be made to expose sensitive information over the network.
Use-after-free of the root cursor. (CVE-2025-26594) Buffer overflow in XkbVModMaskText(). (CVE-2025-26595) Heap overflow in XkbWriteKeySyms(). (CVE-2025-26596) Buffer overflow in XkbChangeTypesOfKey(). (CVE-2025-26597) Out-of-bounds write in CreatePointerBarrierClient(). (CVE-2025-26598)
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
* bsc#1237284 * bsc#1237287 Cross-References: * CVE-2024-57256
* bsc#1236974 Cross-References: * CVE-2024-12243
* bsc#1236974 Cross-References: * CVE-2024-12243
A vulnerability was discovered in MariaDB, a SQL database server compatible with MySQL. A privileged attacker could cause a Denial-of-Service (DoS) of the MariaDB server.
A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file. (CVE-2025-22919) A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted
nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm –without-symbol-version` function. (CVE-2024-57360) GNU Binutils objdump.c disassemble_bytes stack-based overflow. (CVE-2025-0840)
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
https://security-tracker.debian.org/tracker/DSA-5872-1
Update to chromium-133.0.6943.141
CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function
CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function
New version 4.2.11
Update to WebKitGTK 2.46.6: Fix a crash when enabling Skia CPU rendering. Fix several crashes and rendering issues. Fix CVE-2024-54543, CVE-2025-24143, CVE-2025-24150, CVE-2025-24158, CVE-2025-24162
deadlock potential with VT-d and legacy PCI device pass-through [XSA-467, CVE-2025-1713]
https://security-tracker.debian.org/tracker/DSA-5871-1
* bsc#1237093 Cross-References: * CVE-2025-1094
* bsc#1237431 Cross-References: * CVE-2025-26597
* bsc#1237431 Cross-References: * CVE-2025-26597
https://security-tracker.debian.org/tracker/DSA-5870-1
Several security issues were fixed in PHP.
Multiple vulnerabilities were discovered in GNU Emacs, the extensible, customisable, self-documenting, real-time display editor. CVE-2023-28617
Libxmltok could be made to crash if it opened a specially crafted file.
Merge branch ‘f42’ into f41 Merge branch ‘rawhide’ into f41 Fix merge conflict
A heap-based buffer overflow flaw in the decoding functions of openh264, a codec library which supports H.264 encoding and decoding, may allow a remote attacker to cause a denial of service or the execution of arbitrary code if a specially crafted video is processed.
New emacs packages are available for Slackware 15.0 and -current to fix security issues.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Cross-References: * CVE-2020-13936 CVSS scores:
Upstream kernel version 6.6.79 fixes bugs and vulnerabilities. The kmod-virtualbox and kmod-xtables-addons packages have been updated to work with this new kernel. For information about the vulnerabilities see the links.
Vanilla upstream kernel version 6.6.79 fixes bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=34024
Several security issues were fixed in the Linux kernel.
* bsc#1237058 * bsc#1237062 Cross-References: * CVE-2025-24031
* bsc#1227320 * bsc#1227371 * bsc#1228585 * bsc#1236783
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
* bsc#1233296 * bsc#1236278 * bsc#1236470 Cross-References:
* bsc#1233296 * bsc#1236278 * bsc#1236470 Cross-References:
* bsc#1236783 Cross-References: * CVE-2024-53104
* bsc#1227320 * bsc#1227371 * bsc#1228585 * bsc#1236783
Security fixes for CVE-2024-11168 and CVE-2025-0938
update to 1.33.2 fix CVE-2025-24898
Security fixes for CVE-2024-11168 and CVE-2025-0938
update to 1.33.2 fix CVE-2025-24898
Multiple vulnerabilities have been found in libxml2, a library providing support to read, modify and write XML and HTML files. These vulnerabilities could potentially lead to denial of servie or other unintended behaviors.
Update to 133.0.6943.126 CVE-2025-0999: Heap buffer overflow in V8 CVE-2025-1426: Heap buffer overflow in GPU CVE-2025-1006: Use after free in Network
This update addresses a null pointer dereferencing issue that could cause the session for a client that sent specially-crafted commands to the server to crash (not the sessions of other clients).
This update addresses a null pointer dereferencing issue that could cause the session for a client that sent specially-crafted commands to the server to crash (not the sessions of other clients).
