Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

pam-u2f 1.3.1 includes a fix to resolve CVE-2025-23013 (Partial Authentication Bypass). CVSS score 7.3. 1.3.2 is a fix for a regression that could impact existing use cases.

Update to latest version Fix CVE-2024-53263

PCL could be made to crash if it received specially crafted input.

https://security-tracker.debian.org/tracker/DSA-5849-1

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

https://security-tracker.debian.org/tracker/DSA-5847-1

OpenJPEG could be made to crash or run programs if it opened a specially crafted file.

Django could be made to cause a denial of service if it received a specially crafted IPv6 string.

In FRR, the internet routing protocol suite software, all routes are re-validated if the total size of an update received via RTR exceeds the internal socket’s buffer size, default 4K on most OSes.

Multiple vulnerabilities have been discovered in PHP, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in QtWebEngine, the worst of which could lead to arbitrary code execution.

https://security-tracker.debian.org/tracker/DSA-5848-1

A Sysadmin’s Guide to Securing the Linux Kernel
EMEA blog [DUTCH] | Red Hat closes Master Agreement with SLM Rijk to strengthen digital autonomy within Dutch government
Introducing confidential containers on bare metal

Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5

* bsc#1232762 * jsc#PED-10545 Affected Products: * Containers Module 15-SP6

Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5

https://security-tracker.debian.org/tracker/DSA-5846-1

A Linux Admin’s Guide to Ensuring Data Privacy in 2025
Passwords: a thin line between love and hate

Important: thunderbird security update

Important: raptor2 security update

Important: rsync security update

https://security-tracker.debian.org/tracker/DSA-5843-2

Migrating from .NET Framework to .NET Core: Security and Open Source Benefits

https://security-tracker.debian.org/tracker/DSA-5845-1

The update for rsync announced in DSA 5843-1 introduced a regression when using the -H option to preserve hard links. Updated packages are now available to correct this issue.

* bsc#1235856 Cross-References: * CVE-2024-56374

* bsc#1220145 * bsc#1221302 * bsc#1222882 * bsc#1223059 * bsc#1223363

USN-7206-1 caused some regression in rsync.

* bsc#1228693 Cross-References: * CVE-2024-40779

* bsc#1232637 * bsc#1233712 Cross-References: * CVE-2022-48956

* bsc#1210619 * bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225202

* bsc#1235600 * bsc#1235601 Cross-References: * CVE-2024-50349

* bsc#1214954 * bsc#1216813 * bsc#1220773 * bsc#1224095 * bsc#1224726

* bsc#1234100 * bsc#1234101 * bsc#1234102 * bsc#1234103 * bsc#1234104

https://security-tracker.debian.org/tracker/DSA-5844-1

* bsc#1233712 Cross-References: * CVE-2024-50264

* bsc#1225819 * bsc#1228349 * bsc#1228786 * bsc#1229273 * bsc#1229553

* bsc#1225819 * bsc#1233712 Cross-References: * CVE-2023-52752

* bsc#1228573 * bsc#1229273 * bsc#1229553 * bsc#1232637 * bsc#1233712

* bsc#1229553 * bsc#1232637 * bsc#1233712 Cross-References:

* bsc#1210619 * bsc#1220537 * bsc#1223363 * bsc#1223683 * bsc#1225011

https://security-tracker.debian.org/tracker/DSA-5843-1

An introduction to using tcpdump at the Linux command line

Several security issues were fixed in snapd.

Several security issues were fixed in libxmltok.

https://security-tracker.debian.org/tracker/DSA-5842-1

An issue has been found in gnuchess, a tool to play a game of chess, either against the user or against itself. The issue is related to arbitrary code execution via crafted PGN (Portable

Out of Bounds Memory Read/Write in libjxl. (CVE-2024-11403) Resource exhaustion via Stack overflow in libjxl. (CVE-2024-11498) References: – https://bugs.mageia.org/show_bug.cgi?id=33818

Avahi wide-area dns uses constant source port. (CVE-2024-52615) Avahi wide-area dns predictable transaction ids. (CVE-2024-52616) References: – https://bugs.mageia.org/show_bug.cgi?id=33829

Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die function. (CVE-2024-29645) References:

Command injection via RzBinInfo bclass due legacy code. (CVE-2022-1207) References: – https://bugs.mageia.org/show_bug.cgi?id=33895 – https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/YNDCM5TGWRLSMIJ74ZI6LMNSCCH5DBPL/

Various security, performance, accuracy, and stability issues have been fixed.

work around debugedit bug to fix aarch64 builds xen-hypervisor %post doesn’t load all needed grub2 modules update to xen-4.19.1 which includes Deadlock in x86 HVM standard VGA handling [XSA-463, CVE-2024-45818] libxl leaks data to PVH guests via ACPI tables [XSA-464, CVE-2024-45819]

https://security-tracker.debian.org/tracker/DSA-5841-1

The fix for CVE-2024-6923 in the python3.9 source package which was released as part of a suite of updates in DLA 3980-1 [0] introduced safer processing of input in the email module to order to increase the security around email header injection attacks.

Several vulnerabilities were discovered in OpenAFS, an implementation of the AFS distributed filesystem, which may result in theft of credentials in Unix client PAGs (CVE-2024-10394), fileserver crashes and information leak on StoreACL/FetchACL (CVE-2024-10396) or buffer overflows in XDR

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or privilege escalation.

Important: kernel-rt security update

Important: webkit2gtk3 security update

* jsc#PED-11136 Cross-References: * CVE-2024-12678 * CVE-2024-25131

* bsc#1233435 * bsc#1234663 * bsc#1234664 Cross-References:

* bsc#1234991 Cross-References: * CVE-2025-0237 * CVE-2025-0238

https://security-tracker.debian.org/tracker/DSA-5839-1

* bsc#1235029 Cross-References: * CVE-2024-56826

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

xfpt could be made to crash or run programs if it opened a specially crafted file.

Thunderbird could be made to bypass security restrictions.

Several security issues were fixed in Firefox.

Updated to latest upstream (134.0)

https://security-tracker.debian.org/tracker/DSA-5840-1

* bsc#1082555 * bsc#1176081 * bsc#1206344 * bsc#1213034 * bsc#1218562

* bsc#1082555 * bsc#1157160 * bsc#1218644 * bsc#1221977 * bsc#1222364

Tinyproxy could be made to crash or run programs if it received specially crafted input.

* bsc#1233435 * bsc#1234663 * bsc#1234664 Cross-References:

Several security issues were fixed in HTMLDOC.

* bsc#1234809 Cross-References: * CVE-2024-56326

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: