update to xen-4.19.3 includes patches for x86: Incorrect stubs exception handling for flags recovery [XSA-470, CVE-2025-27465] x86: Transitive Scheduler Attacks [XSA-471, CVE-2024-36350,
Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod
Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod
New release of Incus. Release information: https://github.com/lxc/incus/releases/tag/v6.15.0
Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod
Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod
* bsc#1246090 Affected Products: * openSUSE Leap 15.4
* bsc#1245573 Cross-References: * CVE-2025-6297
* bsc#1244925 Cross-References: * CVE-2025-50181
https://security-tracker.debian.org/tracker/DSA-5971-1
* bsc#1234959 Cross-References: * CVE-2024-56738
* bsc#1234959 Cross-References: * CVE-2024-56738
* bsc#1234959 Cross-References: * CVE-2024-56738
Several security issues were fixed in cifs-utils.
* bsc#1221107 * bsc#1246934 Cross-References: * CVE-2024-2236
Multiple vulnerabilities have been discovered in Composer, the worst of which can lead to arbitrary code execution.
A vulnerability has been discovered in Spreadsheet-ParseExcel, which can lead to arbitrary code execution.
A vulnerability has been discovered in NSS, which can lead to the recovery of private data.
A vulnerability has been discovered in FontForge, which can lead to arbitrary code execution.
Multiple vulnerabilities have been discovered in GPL Ghostscript, the worst of which can lead to execution of arbitrary code.
Multiple vulnerabilities have been discovered in PAM, the worst of which could lead to privilege escalation.
* bsc#1245773 Cross-References: * CVE-2025-53367
* bsc#1247249 Cross-References: * CVE-2025-8194
* bsc#1247249 Cross-References: * CVE-2025-8194
* bsc#1234675 * bsc#1235461 * bsc#1235871 Cross-References:
* bsc#1228645 * bsc#1235250 * bsc#1245771 * bsc#1245776 * bsc#1245793
* bsc#1245776 * bsc#1245793 * bsc#1245797 Cross-References:
* bsc#1235250 * bsc#1245776 * bsc#1245793 * bsc#1245797
* bsc#1245776 * bsc#1245793 * bsc#1245797 Cross-References:
Update to 138.0.7204.183 * CVE-2025-8292: Use after free in Media Stream
This update fixes CVE-2025-7345 and CVE-2025-6199.
This update fixes these CVEs: CVE-2025-32364 CVE-2025-32365 CVE-2024-56378
reposurgeon: update to 5.3 version
In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL. References: – https://bugs.mageia.org/show_bug.cgi?id=34447
Stefan Buehler discovered a flaw in sope, the set of Objective-C frameworks powering SOGo, which may result in denial of service via a specially crafted POST request.
A flaw was found in how GLib¢”s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn¢”t. As a result, data may be written […]
Backports patch to fix non-CVE 2025-8224
This update fixes these CVEs: CVE-2025-4948 CVE-2025-32908 CVE-2025-32907 CVE-2025-4969
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5970-1
* bsc#1243855 Cross-References: * CVE-2024-12224
* bsc#1243868 Cross-References: * CVE-2024-12224
* bsc#1221107 Cross-References: * CVE-2024-2236
An update that fixes one vulnerability is now available.
* bsc#1234675 * bsc#1235461 * bsc#1235871 Cross-References:
* bsc#1236621 * bsc#1243009 * bsc#1243105 * bsc#1243268 * bsc#1243274
* bsc#1236621 * bsc#1243009 * bsc#1243105 * bsc#1243268 * bsc#1243274
* bsc#1236621 * bsc#1243009 * bsc#1243105 * bsc#1243268 * bsc#1243274
* bsc#1244795 * bsc#1246058 * bsc#1246059 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5969-1
Several security issues were fixed in SQLite.
Several security issues were fixed in cloud-init.
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5968-1
https://security-tracker.debian.org/tracker/DSA-5967-1
Several security issues were fixed in the Linux kernel.
* bsc#1246090 Affected Products: * openSUSE Leap 15.3
Several security issues were fixed in OpenJDK 11.
Several security issues were fixed in OpenJDK 8.
This update fixes CVE-2025-8058, a low-impact security vulnerability in the regcomp function.
Two issues have been found in libcaca, a colour ASCII art library. Both are related to heap buffer overflow, which might lead to memory corruption.
It was discovered that there was a potential null pointer dereference vulnerability in libetpan, an low-level library for handling email.
The audiofile library allows the processing of audio data to and from audio files of many common formats (currently AIFF, AIFF-C, WAVE, NeXT/Sun, BICS, and raw data).
* bsc#1229007 Cross-References: * CVE-2024-7409
* bsc#1246664 Cross-References: * CVE-2025-8027 * CVE-2025-8028
Several security issues were fixed in CRaC JDK 21.
An update that fixes three vulnerabilities is now available.
