Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the stable distribution (bookworm), these problems have been fixed in

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version

https://security-tracker.debian.org/tracker/DSA-5966-1

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

Update to 128.13.0 https://www.thunderbird.net/en-US/thunderbird/128.13.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-62/

Several security issues were fixed in OpenJDK 24.

Several security issues were fixed in OpenJDK 21.

* bsc#1225889 * bsc#1245542 Cross-References: * CVE-2024-1298

* bsc#1229122 * bsc#1241865 Cross-References: * CVE-2025-22872

https://security-tracker.debian.org/tracker/DSA-5964-1

* bsc#1234854 * bsc#1234892 * bsc#1235005 * bsc#1235921 * bsc#1238912

Several security issues were fixed in the Linux kernel.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Updated to latest upstream (141.0)

https://security-tracker.debian.org/tracker/DSA-5965-1

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

* bsc#1244403 * bsc#1244404 * bsc#1244407 Cross-References:

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, information disclosure or bypass of sandbox restrictions.

* bsc#1244644 * bsc#1246112 Cross-References: * CVE-2025-27465

* bsc#1243648 Cross-References: * CVE-2024-56558

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in Drupal.

Several security issues were fixed in the Linux kernel.

CHAOS RAT in AUR: When Trust in Open-Source Goes Too Far

* bsc#1194400 * bsc#1212493 * bsc#1219964 * bsc#1222539 * bsc#1229008

* bsc#1241865 Cross-References: * CVE-2025-22872

Update to 7.3.20 Security fixes for CVE-2025-47273, CVE-2024-47081 and CVE-2025-50181 (in pip and setuptools wheels)

Update to 7.3.20 Security fixes for CVE-2025-47273, CVE-2024-47081 and CVE-2025-50181 (in pip and setuptools wheels)

angular.js a popular JavaScript framework was affected by multiple vulnerabilities. CVE-2022-25844

Update to 138.0.7204.157 * CVE-2025-7656: Integer overflow in V8 * CVE-2025-7657: Use after free in WebRTC * CVE-2025-6558: Incorrect validation of untrusted input in ANGLE and GPU

Update to 1.23.1 (rhbz#2380450)

* bsc#1229008 * bsc#1241865 * bsc#1245087 Cross-References:

* bsc#1243450 Cross-References: * CVE-2024-23337

* bsc#1238912 * bsc#1241579 * bsc#1244337 Cross-References:

* bsc#1234854 * bsc#1234885 * bsc#1234892 * bsc#1235005 * bsc#1235769

Cryptomining Meets AI: H2Miners Multi-Platform Assault Unveiled

* bsc#1243767 Cross-References: * CVE-2025-5278

Reduce risk in Kubernetes: How to separate admin roles for safer, compliant operations

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. Google is aware that an exploit for CVE-2025-6558 exists in the wild.

The newest upstream commit Security fixes for CVE-2025-53906, CVE-2025-53905

https://security-tracker.debian.org/tracker/DSA-5963-1

New bind packages are available for Slackware 15.0 and -current to fix a security issue.

Several security issues were fixed in Apache HTTP Server.

Bind could be made to crash if it received specially crafted network traffic.

Multiple security issues were discovered in GNU TLS, which could result in denial of service. For the stable distribution (bookworm), these problems have been fixed in

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The Linux Kernel in 2025: Security Enhancements, Emerging Threats & Best Practices

https://security-tracker.debian.org/tracker/DSA-5962-1

Several security issues were fixed in libjxl.

* bsc#1244663 Cross-References: * CVE-2025-4565

* bsc#1244663 Cross-References: * CVE-2025-4565

* bsc#1244663 Cross-References: * CVE-2025-4565

Ransomwares New Frontier: Linux Systems Face Intensifying Attacks
Active Wing FTP Exploits Demand Immediate Action from Linux Admins

Several security issues were fixed in Nix.

Contains fixes for regressions introduced during CVE bugfix update (3007.4).

Update to 3.5.29, fixes CVE-2025-53367.

Update to 2.32.4. Fixes CVE-2024-47081.

This updates gnutls to the latest upstream release. Notable changes are: PKCS#11 cryptographic provider support Support for kTLS rekeying with kernel 6.14+ Support for the almost standardized ML-DSA private key formats This also fixes 4 CVEs (CVE-2025-32989, CVE-2025-6395, CVE-2025-32988, and

Update to chromium 138.0.7204.92

Update to version 4.34.0

PHP version 8.4.10 (03 Jul 2025) BcMath: Fixed bug GH-18641 (Accessing a BcMathNumber property by ref crashes). (nielsdos) Core:

Fixes CVE-2025-40909 – Clone dirhandles without fchdir

Fixes CVE-2025-40909 – Clone dirhandles without fchdir

Update to 20250708: Drop incorrect nvidia ghost entries xe: Add fan_control v203.0.0.0 for BMG Update AMD cpu microcode amdgpu: Add DCN 3.6/PSP 14.0.5/SDMA 6.1.3/GC 11.5.3