* bsc#1197331 * bsc#1203769 * bsc#1235441 * bsc#1237768 * bsc#1238271
* bsc#1239750 Cross-References: * CVE-2022-49737
https://security-tracker.debian.org/tracker/DSA-5882-1
go-gh could be made to expose sensitive information over the network.
* bsc#1239547 Cross-References: * CVE-2025-24201
* bsc#1239547 Cross-References: * CVE-2025-24201
* bsc#1237363 * bsc#1237370 * bsc#1237418 Cross-References:
Several security issues were fixed in Valkey.
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in HTTP request smuggling, validation bypass or denial of service.
Multiple vulnerabilities were discovered in modules shipped with cpython 3.9, the primary interpreter for the Python programming language.
fix CVE-2024-56737, CVE-2025-56737, CVE-2025-1864 Fix CVE-2025-1744 and CVE-2025-1864
fix CVE-2024-56737, CVE-2025-56737, CVE-2025-1864 Fix CVE-2025-1744 and CVE-2025-1864
Several security issues were fixed in Alpine.
* bsc#1229640 * bsc#1231196 * bsc#1231204 * bsc#1233679 * bsc#1235452
* bsc#1228755 * bsc#1231196 * bsc#1231204 * bsc#1233679 * bsc#1235452
* bsc#1231204 * bsc#1233679 Cross-References: * CVE-2024-46818
* bsc#1229640 * bsc#1231204 * bsc#1233679 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5881-1
* bsc#1237467 Cross-References: * CVE-2025-26618
* bsc#1228017 * bsc#1229640 * bsc#1231204 * bsc#1233679
* bsc#1233679 Cross-References: * CVE-2024-50302
* bsc#1229640 * bsc#1231204 * bsc#1233679 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5879-1
FreeType could be made to crash or run programs if it opened a specially crafted font file.
* bsc#1239197 Cross-References: * CVE-2025-22868
* bsc#1239197 Cross-References: * CVE-2025-22868
Several security issues were fixed in X.Org X Server.
* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6
https://security-tracker.debian.org/tracker/DSA-5880-1
An update that fixes one vulnerability is now available.
An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related to TrueType GX and variable font files which may result in arbitrary code execution. References:
