Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

update to xen-4.19.3 includes patches for x86: Incorrect stubs exception handling for flags recovery [XSA-470, CVE-2025-27465] x86: Transitive Scheduler Attacks [XSA-471, CVE-2024-36350,

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

New release of Incus. Release information: https://github.com/lxc/incus/releases/tag/v6.15.0

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

What is a CSRF Vulnerability?

* bsc#1246090 Affected Products: * openSUSE Leap 15.4

* bsc#1245573 Cross-References: * CVE-2025-6297

* bsc#1244925 Cross-References: * CVE-2025-50181

Hashcat 7.0.0: Redefining Password Recovery & Security on Linux
Critical NestJS Vulnerability Exposes Developers to RCE Risk
How to Build a Ransomware Kill Chain Strategy for Linux Security
What Is a SQLi Vulnerability?

https://security-tracker.debian.org/tracker/DSA-5971-1

* bsc#1234959 Cross-References: * CVE-2024-56738

* bsc#1234959 Cross-References: * CVE-2024-56738

* bsc#1234959 Cross-References: * CVE-2024-56738

Introducing OpenShift Service Mesh 3.1

Several security issues were fixed in cifs-utils.

* bsc#1221107 * bsc#1246934 Cross-References: * CVE-2024-2236

Multiple vulnerabilities have been discovered in Composer, the worst of which can lead to arbitrary code execution.

A vulnerability has been discovered in Spreadsheet-ParseExcel, which can lead to arbitrary code execution.

A vulnerability has been discovered in NSS, which can lead to the recovery of private data.

A vulnerability has been discovered in FontForge, which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in GPL Ghostscript, the worst of which can lead to execution of arbitrary code.

Multiple vulnerabilities have been discovered in PAM, the worst of which could lead to privilege escalation.

What Is a RCE Vulnerability?

* bsc#1245773 Cross-References: * CVE-2025-53367

* bsc#1247249 Cross-References: * CVE-2025-8194

* bsc#1247249 Cross-References: * CVE-2025-8194

* bsc#1234675 * bsc#1235461 * bsc#1235871 Cross-References:

* bsc#1228645 * bsc#1235250 * bsc#1245771 * bsc#1245776 * bsc#1245793

* bsc#1245776 * bsc#1245793 * bsc#1245797 Cross-References:

* bsc#1235250 * bsc#1245776 * bsc#1245793 * bsc#1245797

* bsc#1245776 * bsc#1245793 * bsc#1245797 Cross-References:

Update to 138.0.7204.183 * CVE-2025-8292: Use after free in Media Stream

This update fixes CVE-2025-7345 and CVE-2025-6199.

This update fixes these CVEs: CVE-2025-32364 CVE-2025-32365 CVE-2024-56378

reposurgeon: update to 5.3 version

In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL. References: – https://bugs.mageia.org/show_bug.cgi?id=34447

Stefan Buehler discovered a flaw in sope, the set of Objective-C frameworks powering SOGo, which may result in denial of service via a specially crafted POST request.

A flaw was found in how GLib¢”s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn¢”t. As a result, data may be written […]

Backports patch to fix non-CVE 2025-8224

This update fixes these CVEs: CVE-2025-4948 CVE-2025-32908 CVE-2025-32907 CVE-2025-4969

What Is An XSS Vulnerability?

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5970-1

* bsc#1243855 Cross-References: * CVE-2024-12224

* bsc#1243868 Cross-References: * CVE-2024-12224

* bsc#1221107 Cross-References: * CVE-2024-2236

Deploy sensitive workloads with OpenShift confidential containers
Confidential containers on Microsoft Azure with Red Hat OpenShift Sandboxed Containers 1.10 and Red Hat Build of Trustee

An update that fixes one vulnerability is now available.

* bsc#1234675 * bsc#1235461 * bsc#1235871 Cross-References:

* bsc#1236621 * bsc#1243009 * bsc#1243105 * bsc#1243268 * bsc#1243274

* bsc#1236621 * bsc#1243009 * bsc#1243105 * bsc#1243268 * bsc#1243274

* bsc#1236621 * bsc#1243009 * bsc#1243105 * bsc#1243268 * bsc#1243274

* bsc#1244795 * bsc#1246058 * bsc#1246059 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5969-1

Several security issues were fixed in SQLite.

Several security issues were fixed in cloud-init.

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5968-1

https://security-tracker.debian.org/tracker/DSA-5967-1

Several security issues were fixed in the Linux kernel.

* bsc#1246090 Affected Products: * openSUSE Leap 15.3

Hidden in Plain Sight: Koske Linux Malwares Stealthy Panda Image Delivery

Several security issues were fixed in OpenJDK 11.

Several security issues were fixed in OpenJDK 8.

This update fixes CVE-2025-8058, a low-impact security vulnerability in the regcomp function.

Soco404: Linux Cryptomining Campaign Masquerades as 404 Error Pages

Two issues have been found in libcaca, a colour ASCII art library. Both are related to heap buffer overflow, which might lead to memory corruption.

It was discovered that there was a potential null pointer dereference vulnerability in libetpan, an low-level library for handling email.

The audiofile library allows the processing of audio data to and from audio files of many common formats (currently AIFF, AIFF-C, WAVE, NeXT/Sun, BICS, and raw data).

* bsc#1229007 Cross-References: * CVE-2024-7409

* bsc#1246664 Cross-References: * CVE-2025-8027 * CVE-2025-8028

Several security issues were fixed in CRaC JDK 21.

An update that fixes three vulnerabilities is now available.