Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Update to 138.0.7204.49 CVE-2025-6555: Use after free in Animation CVE-2025-6556: Insufficient policy enforcement in Loader CVE-2025-6557: Insufficient data validation in DevTools

Automatic update for podman-5.5.2-1.fc41. security fix for CVE-2025-6032 Changelog for podman * Tue Jun 24 2025 Packit – 5:5.5.2-1 – Update to 5.5.2 upstream release

Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517

Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517

xorg-x11-server CVE fix for CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180

Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517

https://security-tracker.debian.org/tracker/DSA-5951-1

* bsc#1232908 * bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062

* bsc#1235231 Cross-References: * CVE-2024-56601

* bsc#1239948 * bsc#1244304 * bsc#1244503 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5952-1

https://security-tracker.debian.org/tracker/DSA-5950-1

Several security issues were fixed in libarchive.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

* bsc#1243565 * bsc#1245054 * bsc#1245055 Cross-References:

* bsc#1236217 * bsc#1244156 * bsc#1244157 * bsc#1244158 * jsc#SLE-18320

Ubuntu Chooses Performance Over Mitigation: Intel GPU Users See 20% Gains

https://security-tracker.debian.org/tracker/DSA-5949-1

https://security-tracker.debian.org/tracker/DSA-5948-1

* bsc#1244148 Cross-References: * CVE-2011-10007

* bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062 * bsc#1235231

Nils Emmerich discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.

commons-beanutils, utility for manipulating Java beans have an improper Access Control vulnerability. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers

* bsc#1239192 Cross-References: * CVE-2025-22868

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

IBM Donates CBOM Toolset to Linux Foundation

Template injection that can lead to XSS has been fixed in node-send, a Node.js module for streaming files over HTTP. For Debian 11 bullseye, this problem has been fixed in version

* bsc#1241067 * bsc#1243273 * bsc#1244032 * bsc#1244056 * bsc#1244059

* bsc#1234421 * bsc#1244405 * bsc#1244406 Cross-References:

* bsc#1243721 Cross-References: * CVE-2025-5222

https://security-tracker.debian.org/tracker/DSA-5947-1

Update to 137.0.7151.119 * CVE-2025-6191: Integer overflow in V8 * CVE-2025-6192: Use after free in Profiler

Harden temporary private mounts (#2373301)

4.9.0

This is the .NET monthly update for June 2025. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release-notes/9.0/9.0.6/9.0.107.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.6/9.0.6.md

Fix improper access control vulnerability Resolves: CVE-2025-48734

https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/OXIGQIHBL26HFKG6TT5SWSH7K7W6RO4H/ https://phabricator.wikimedia.org/T382326

https://security-tracker.debian.org/tracker/DSA-5946-1

https://security-tracker.debian.org/tracker/DSA-5945-1

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

* bsc#1241158 * bsc#1241160 * bsc#1243282 * bsc#1243286 * bsc#1243288

* bsc#1234449 Cross-References: * CVE-2024-47606

* bsc#1239192 Cross-References: * CVE-2025-22868

* bsc#1227690 Cross-References: * CVE-2024-38526

* bsc#1233012 * bsc#1243273 * bsc#1244401 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5944-1

It was discovered that an Out Of Memory error may occur when attempting to initialize a huge byte array, even when maxFrameSize is set. For Debian 11 bullseye, this problem has been fixed in version

* bsc#1234415 * bsc#1234450 * bsc#1234453 * bsc#1234455 * bsc#1234456

Several security issues were fixed in Samba.

Updates to Red Hat Advanced Cluster Security for Kubernetes Cloud Service strengthen your security posture

Several security issues were fixed in Express.

* bsc#1238681 * bsc#1239192 Cross-References: * CVE-2025-22868

https://security-tracker.debian.org/tracker/DSA-5943-1

* bsc#1154353 * bsc#1156395 * bsc#1170891 * bsc#1173139 * bsc#1184350

* bsc#1244039 Cross-References: * CVE-2024-47081

* bsc#1244039 Cross-References: * CVE-2024-47081

* bsc#1244039 Cross-References: * CVE-2024-47081

* bsc#1223096 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757

Secure RHEL Clones Chart Diverging Paths

Django could be made to log injection if received specially crafted input.

Update to 128.11.1 https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/

Fixes CVE-2025-32873: Denial-of-service possibility in strip_tags() Fixes CVE-2025-48432: Potential log injection via unescaped request path

Rebuild for CVE-2024-12224, CVE-2025-4574

Rebuild against idna 1.0+ for CVE-2024-12224

* bsc#1215935 * bsc#1215936 * bsc#1233606 * bsc#1233608 * bsc#1233609

* bsc#1242015 Cross-References: * CVE-2025-3891

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in ModSecurity.

Optimizing Linux Security in 2025: Key Strategies & Best Practices

A stack-based buffer overflow has been fixed in ICU, a C++ and C library for Unicode and Globalization support. For Debian 11 bullseye, this problem has been fixed in version

Two vulnerabilities have been fixed in cJSON, a C library for parsing JSON. CVE-2023-26819

An input sanitization flaw in Konsole might allow remote attackers to execute commands via a malicious URL

An integer overflow vulnerability has been found in sysstat which could result in arbitrary code execution.

Fix CVE-2025-49112 Fix CVE-2025-49112

Security update

New version 4.4.7 Ignoring potential error when using udevadm in %post scriptlet

Update to 137.0.7151.103 CVE-2025-5958: Use after free in Media CVE-2025-5959: Type Confusion in V8

This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574