Update the openssl crate to version 0.10.70 and the openssl-sys crate to version 0.9.105. This includes a fix for RUSTSEC-2025-0004 / CVE-2025-0977 and rebuilds of all packages that statically link the openssl crate.
https://security-tracker.debian.org/tracker/DSA-5860-1
* bsc#1236270 Cross-References: * CVE-2024-11218
A vulnerability has been discovered in the OpenJDK Java runtime, which may result in authorisation bypass or information disclosure. For Debian 11 bullseye, this problem has been fixed in version
Updated to latest upstream (135.0)
Fix CVE-2025-0781
Fix CVE-2025-0781
https://security-tracker.debian.org/tracker/DSA-5859-1
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Several security issues were fixed in Ruby.
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
Several security issues were fixed in CKEditor.
Fix for CVE-2025-0781
OpenJDK 23 could be made to expose sensitive information over the network.
OpenJDK 21 could be made to expose sensitive information over the network.
OpenJDK 17 could be made to expose sensitive information over the network.
OpenJDK 11 could be made to expose sensitive information over the network.
USN-7096-1 caused some minor regressions in OpenJDK 8.
Rebuilt against golang-x-net 0.33.0 for CVE-2024-45338
https://security-tracker.debian.org/tracker/DSA-5858-1
* bsc#1236136 Cross-References: * CVE-2024-13176
* bsc#1236518 Cross-References: * CVE-2023-45288
* bsc#1236460 Cross-References: * CVE-2022-49043
Updated to 132.0.6834.159 * Medium CVE-2025-0762: Use after free in DevTools
* bsc#1236518 Cross-References: * CVE-2023-45288
* bsc#1236272 Cross-References: * CVE-2024-11218 * CVE-2024-9407
* bsc#1236272 Cross-References: * CVE-2024-11218 * CVE-2024-9407
Matthias Gerstner reported that pam-u2f, a PAM module which allows to use U2F (Universal 2nd Factor) devices in the PAM authentication stack, does not properly handle PAM_IGNORE return values, allowing to bypass the second factor or password-less login without inserting the proper
https://security-tracker.debian.org/tracker/DSA-5857-1
Several issues have been found in ffmpeg, a package that contains tools for transcoding, streaming and playing of multimedia files Those issues are related to possible integer overflows, double-free on
update to 0.10.4
Updated to 132.0.6834.159 * Medium CVE-2025-0762: Use after free in DevTools
Rebase to 20.18.2 Resolves: CVE-2025-22150 CVE-2025-23085 CVE-2025-23083
Update to version 18.20.6 (rhbz#2341760) (rhbz#2340936) (rhbz#2300997) Resolves CVE-2025-23084
Rebase to 20.18.2 Resolves: CVE-2025-22150 CVE-2025-23085 CVE-2025-23083
Update to version 18.20.6 (rhbz#2341760) (rhbz#2340936) (rhbz#2300997) Resolves CVE-2025-23084
New ASPA support is now always compiled in and available if enable-aspa is set. The aspa Cargo feature has been removed. (#990) If merging mutliple ASPA objects for a single customer ASN results in more than 16,380 provider ASNs, the ASPA is dropped. (Note that ASPA objects with more
An update that fixes one vulnerability is now available.
Multiple vulnerabilities have been fixed in DCMTK, a collection of libraries and applications implementing large parts the DICOM standard for medical images.
Vanilla upstream kernel version 6.6.74 fixes bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=33968
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5854-1
https://security-tracker.debian.org/tracker/DSA-5853-1
* bsc#1236518 Cross-References: * CVE-2023-45288
* bsc#1228770 Cross-References: * CVE-2013-4235
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
Tomcat could be made to run programs if it received specially crafted network traffic.
Several security issues were fixed in jinja2.
VLC could be made to crash or run programs if it received specially crafted network traffic.
https://security-tracker.debian.org/tracker/DSA-5855-1
https://security-tracker.debian.org/tracker/DSA-5856-1
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-5851-1
* bsc#1214612 * bsc#1215807 * bsc#1215926 * bsc#1217828 * bsc#1221677
Multiple vulnerabilities were discovered in git, a fast, scalable and distributed revision control system. CVE-2024-50349
FRR could be made to crash or exhibit degraded performance if it received specially crafted network traffic.
Quagga could be made to crash if it received specially crafted network traffic.
* bsc#1225819 * bsc#1227369 * bsc#1227781 * bsc#1227784 * bsc#1228349
* bsc#1226324 Cross-References: * CVE-2024-36971
* bsc#1226324 * bsc#1227471 * bsc#1227651 * bsc#1228573 * bsc#1229553
An update that fixes two vulnerabilities is now available.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size. (CVE-2025-0395)
Timing side-channel in ECDSA signature computation. (CVE-2024-13176) References: – https://bugs.mageia.org/show_bug.cgi?id=33942 – https://openssl-library.org/news/secadv/20250120.txt
Update to 132.0.6834.110 High CVE-2025-0611: Object corruption in V8 High CVE-2025-0612: Out of bounds memory access in V8
https://lists.wikimedia.org/hyperkitty/list/wikitech- l@lists.wikimedia.org/thread/PFTE5RHUERS6KTUGGRZO7XXV5THNJ77E/ https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/5NYC4UZLY3MWQZ6DYJAUQRJG2ZHZFBJ6/
Update to 132.0.6834.110 High CVE-2025-0611: Object corruption in V8 High CVE-2025-0612: Out of bounds memory access in V8
https://lists.wikimedia.org/hyperkitty/list/wikitech- l@lists.wikimedia.org/thread/PFTE5RHUERS6KTUGGRZO7XXV5THNJ77E/ https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/5NYC4UZLY3MWQZ6DYJAUQRJG2ZHZFBJ6/
https://security-tracker.debian.org/tracker/DSA-5850-1
pam-u2f 1.3.1 includes a fix to resolve CVE-2025-23013 (Partial Authentication Bypass). CVSS score 7.3. 1.3.2 is a fix for a regression that could impact existing use cases.
New version 3.4.1, a couple of fixes for the 3.4.0 release.
Security fix for CVE-2024-11218 – fixed in buildah 1.38.1, podman 5.3.2 Automatic update for buildah-1.38.1-1.fc41, containers-common-0.61.1-1.fc41, podman-5.3.2-1.fc41. Changelog for buildah * Tue Jan 21 2025 Packit – 2:1.38.1-1
Security fix for CVE-2024-11218 – fixed in buildah 1.38.1, podman 5.3.2 Automatic update for buildah-1.38.1-1.fc41, containers-common-0.61.1-1.fc41, podman-5.3.2-1.fc41. Changelog for buildah * Tue Jan 21 2025 Packit – 2:1.38.1-1
Security fix for CVE-2024-11218 – fixed in buildah 1.38.1, podman 5.3.2 Automatic update for buildah-1.38.1-1.fc41, containers-common-0.61.1-1.fc41, podman-5.3.2-1.fc41. Changelog for buildah * Tue Jan 21 2025 Packit – 2:1.38.1-1
Includes security fixes to the crypto/x509 and net/http packages
Update to latest version Fix CVE-2024-53263
