CVE-2025-2588
Update to 1.1.43, fixes CVE-2024-55549 and CVE-2025-24855.
Added patch for CVE-2024-4068 (rhbz#2280624)
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
https://security-tracker.debian.org/tracker/DSA-5888-1
Several security issues were fixed in the Linux kernel.
Alexander Tan discovered that the OpenSAML C++ library was susceptible to forging of signed SAML messages. For additional details please refer to the upstream advisory at https://shibboleth.net/community/advisories/secadv_20250313.txt
* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869
* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869
* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869
https://security-tracker.debian.org/tracker/DSA-5886-1
* bsc#1239339 Cross-References: * CVE-2025-22869 * CVE-2025-27144
* bsc#1239339 Cross-References: * CVE-2025-22869 * CVE-2025-27144
* bsc#1239460 Cross-References: * CVE-2025-24049
https://security-tracker.debian.org/tracker/DSA-5887-1
This upload fixes two security issues in the version of nginx shipped in bullseye. CVE-2024-7347
* bsc#1239465 Cross-References: * CVE-2025-27363
Several security issues were fixed in SmartDNS.
Update to 134.0.6998.117 * Critical CVE-2025-2476: Use after free in Lens
0.9.30, rebuild due golang CVE-2025-22870
https://security-tracker.debian.org/tracker/DSA-5885-1
Ivan Fratric discovered two use-after-free vulnerabilities in libxslt, an XSLT processing runtime library, which may result in the execution of arbitrary code if a specially crafted files are processed.
Two use-after-free vulnerabilities have been fixed in the XSLT processing library libxslt. CVE-2024-55549
Several security issues were fixed in NLTK.
Update to 134.0.6998.117 * Critical CVE-2025-2476: Use after free in Lens
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-44192
An update that fixes two vulnerabilities is now available.
Update to 4.3.6 (rhbz#2352545)
This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md
Update to 4.3.6 (rhbz#2352545)
This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md
Backported fix for CVE-2024-12361 .
This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md
https://security-tracker.debian.org/tracker/DSA-5884-1
A cross-site scripting vulnerability was discovered in hgweb, the integrated stand-alone web interface of the Mercurial version control system.
Update to 0.40.0 https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes
https://security-tracker.debian.org/tracker/DSA-5883-1
