Update to uriparser-1.0.0, fixes CVE-2025-67899.
fix setpwnam() buffer use [CVE-2025-14104] libblkid: use snprintf() instead of sprintf()
https://security-tracker.debian.org/tracker/DSA-6088-1
https://security-tracker.debian.org/tracker/DSA-6089-1
https://security-tracker.debian.org/tracker/DSA-6090-1
https://security-tracker.debian.org/tracker/DSA-6091-1
https://security-tracker.debian.org/tracker/DSA-6087-1
https://security-tracker.debian.org/tracker/DSA-6086-1
https://security-tracker.debian.org/tracker/DSA-6085-1
Update to 0.2.8
Update to 143.0.7499.146 * High CVE-2025-14765: Use after free in WebGPU * High CVE-2025-14766: Out of bounds read and write in V8 * Force dark mode when auto dark mode web content is on
Update to 2.22.11
Update to 17.0.0 version (#2412270) Update fonttools 4.61.0
Update to 17.0.0 version (#2412270) Update fonttools 4.61.0
Update to 143.0.7499.146 * High CVE-2025-14765: Use after free in WebGPU * High CVE-2025-14766: Out of bounds read and write in V8 * Force dark mode when auto dark mode web content is on
ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
An update that solves four vulnerabilities can now be installed.
PHP version 8.4.16 (18 Dec 2025) Core: Sync all boost.context files with release 1.86.0. (mvorisek) Fixed bug GH-20435 (SensitiveParameter doesn’t work for named argument passing to variadic parameter). (ndossche)
It was discovered that c-ares, a library that performs DNS requests and name resolution asynchronously, does not properly handle termination of queries which may result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 1.34.5-1+deb13u1.
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-6083-1
https://security-tracker.debian.org/tracker/DSA-6084-1
A view of the H2 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts
An update that solves one vulnerability, contains one feature and has one security fix can now be installed.
This update includes the latest upstream release of mod_md, with various bug fixes and enhancements. See https://github.com/icing/mod_md/releases for more information. A fix for the security vulnerability CVE-2025-55753 is also included.
Update to 25.4.0
Fix seeking and looping of media elements that set the loop property. Fix several crashes and rendering issues. Fix CVE-2025-13947, CVE-2025-43458, CVE-2025-66287
upstream stable upgrade from 2.41.1 to 2.41.3 (CVE-2025-14104 and other issues)
Backport fix for CVE-2025-11277
https://security-tracker.debian.org/tracker/DSA-6082-1
