Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Mitigating threats against telco networks in the cloud

Update to 4.3.6 (rhbz#2352545)

This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md

Update to 4.3.6 (rhbz#2352545)

This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md

Backported fix for CVE-2024-12361 .

This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md

https://security-tracker.debian.org/tracker/DSA-5884-1

A cross-site scripting vulnerability was discovered in hgweb, the integrated stand-alone web interface of the Mercurial version control system.

Update to 0.40.0 https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes

https://security-tracker.debian.org/tracker/DSA-5883-1

* bsc#1197331 * bsc#1203769 * bsc#1235441 * bsc#1237768 * bsc#1238271

* bsc#1239750 Cross-References: * CVE-2022-49737

https://security-tracker.debian.org/tracker/DSA-5882-1

go-gh could be made to expose sensitive information over the network.

* bsc#1239547 Cross-References: * CVE-2025-24201

* bsc#1239547 Cross-References: * CVE-2025-24201

* bsc#1237363 * bsc#1237370 * bsc#1237418 Cross-References:

What OpenInfra Joining Linux Foundation Means for Cloud Security Posture Management

Several security issues were fixed in Valkey.

Red Hat Advanced Cluster Security 4.7 simplifies management, enhances workflows, and generates SBOMs
Secure AI inferencing: POC with NVIDIA NIM on CoCo with OpenShift AI

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in HTTP request smuggling, validation bypass or denial of service.

Multiple vulnerabilities were discovered in modules shipped with cpython 3.9, the primary interpreter for the Python programming language.

fix CVE-2024-56737, CVE-2025-56737, CVE-2025-1864 Fix CVE-2025-1744 and CVE-2025-1864

fix CVE-2024-56737, CVE-2025-56737, CVE-2025-1864 Fix CVE-2025-1744 and CVE-2025-1864

Several security issues were fixed in Alpine.

Effective Strategies to Optimize Linux Security in 2025
Rising Malware Threats to Linux: Understanding Risks and Defenses
Exploring FireDragon: A High-Performing, Secure Linux Browser
Apache Tomcat Vulnerability CVE-2025-24813 Exposes Linux Servers to Remote Attacks

* bsc#1229640 * bsc#1231196 * bsc#1231204 * bsc#1233679 * bsc#1235452

* bsc#1228755 * bsc#1231196 * bsc#1231204 * bsc#1233679 * bsc#1235452

* bsc#1231204 * bsc#1233679 Cross-References: * CVE-2024-46818

* bsc#1229640 * bsc#1231204 * bsc#1233679 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5881-1

* bsc#1237467 Cross-References: * CVE-2025-26618

* bsc#1228017 * bsc#1229640 * bsc#1231204 * bsc#1233679

* bsc#1233679 Cross-References: * CVE-2024-50302

* bsc#1229640 * bsc#1231204 * bsc#1233679 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5879-1

FreeType could be made to crash or run programs if it opened a specially crafted font file.

* bsc#1239197 Cross-References: * CVE-2025-22868

* bsc#1239197 Cross-References: * CVE-2025-22868

Several security issues were fixed in X.Org X Server.

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

https://security-tracker.debian.org/tracker/DSA-5880-1

An update that fixes one vulnerability is now available.

An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related to TrueType GX and variable font files which may result in arbitrary code execution. References:

patchlevel 1202 Security fix for CVE-2025-29768

Latest maintenance release from 7.1 branch. Changelog: https://github.com/FFmpeg/FFmpeg/blob/n7.1.1/Changelog . Contains backported fix for CVE-2025-22921.

Update to upstream 20250311: amdgpu: many firmware updates qcom: Update gpu firmwares for qcs8300 chipset add firmware for qat_420xx devices amdgpu: DMCUB updates for various ASICs

New freetype packages are available for Slackware 15.0 to fix a security issue.

Update to 134.0.6998.88 High CVE-2025-1920: Type Confusion in V8 High CVE-2025-2135: Type Confusion in V8 Medium CVE-2025-2136: Use after free in Inspector Medium CVE-2025-2137: Out of bounds read in V8

deadlock potential with VT-d and legacy PCI device pass-through [XSA-467, CVE-2025-1713]

Update to 134.0.6998.88 High CVE-2025-1920: Type Confusion in V8 High CVE-2025-2135: Type Confusion in V8 Medium CVE-2025-2136: Use after free in Inspector Medium CVE-2025-2137: Out of bounds read in V8

Update to upstream 20250311: amdgpu: many firmware updates qcom: Update gpu firmwares for qcs8300 chipset add firmware for qat_420xx devices amdgpu: DMCUB updates for various ASICs

This release addresses CVEs: CVE-2025-27835, CVE-2025-27832, CVE-2025-27831, CVE-2025-27836, CVE-2025-27830, CVE-2025-27833, CVE-2025-27837, CVE-2025-27834 The 10.05.0 release deprecates the non-standard operator “selectdevice”, all code should now be using the standard “setpagedevice” operator.

In man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the heap. This at least causes the program to segmentation abort if the heap size parameter isn’t aligned correctly. In versions before GLIBC version 2.29 and if aligned correctly, it allows arbitrary writes […]

* bsc#1233307 Cross-References: * CVE-2024-11168

* bsc#1202848 * bsc#1215945 * bsc#1223070 * bsc#1223235 * bsc#1223256

* bsc#1238702 Cross-References: * CVE-2025-22870

* bsc#1215420 * bsc#1224700 * bsc#1224763 * bsc#1225742 * bsc#1231847

Introducing Red Hat OpenShift Service Mesh 3.0

https://security-tracker.debian.org/tracker/DSA-5878-1

* bsc#1239197 Cross-References: * CVE-2025-22868

* bsc#1208995 * bsc#1220946 * bsc#1225742 * bsc#1232472 * bsc#1232919

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

The Security-Conscious Sysadmin’s Guide to Choosing the Right Linux Distro

* bsc#1237377 Cross-References: * CVE-2025-0633

Several security issues were fixed in Jinja2.

Several security issues were fixed in opensc.

.NET could be made to elevate privileges.

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings. (CVE-2025-26699)

Jinja sandbox breakout through attr filter selecting format method. (CVE-2025-27516) References: – https://bugs.mageia.org/show_bug.cgi?id=34081

https://security-tracker.debian.org/tracker/DSA-5877-1

* bsc#1208995 * bsc#1220946 * bsc#1225742 * bsc#1232472 * bsc#1232919

* bsc#1208995 * bsc#1220946 * bsc#1224700 * bsc#1225742 * bsc#1232905

* bsc#1050081 * bsc#1051510 * bsc#1065729 * bsc#1100823 * bsc#1101669

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Enhancing Cybersecurity Quality Assurance with AI & Machine Learning

* bsc#1237681 Cross-References: * CVE-2025-27144