* bsc#1236217 * bsc#1242715 Cross-References: * CVE-2025-22873
* bsc#1241658 * bsc#1241659 Cross-References: * CVE-2025-43965
* bsc#1243216 Cross-References: * CVE-2025-3875 * CVE-2025-3877
* bsc#1242809 Cross-References: * CVE-2025-3887
https://security-tracker.debian.org/tracker/DSA-5929-1
Cybercriminals impersonate the trusted e-signature brand and send fake Docusign notifications to trick people into giving away their personal or corporate data
A path traversal vulnerability in `PackageIndex` was found in setuptools. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context.
GNU C Library could be made to crash or run programs if it processed specially crafted dynamically shared library.
* bsc#1243313 Cross-References: * CVE-2025-47273
* bsc#1243356 Cross-References: * CVE-2025-21490
* bsc#1242809 Cross-References: * CVE-2025-3887
https://security-tracker.debian.org/tracker/DSA-5926-1
https://security-tracker.debian.org/tracker/DSA-5927-1
A flaw was discovered in the dynamic linking support in the GNU C Library, the C standard library implementation used by Debian. Privilege escalation may be possible in statically compiled setuid
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in Intel Microcode.
* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6
PgBouncer is a lightweight connection pooler for PostgreSQL. CVE-2021-3539
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
* bsc#1243313 Cross-References: * CVE-2025-47273
* bsc#1242931 Cross-References: * CVE-2025-4207
ESET Research has been tracking Danabot’s activity since 2018 as part of a global effort that resulted in a major disruption of the malware’s infrastructure
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
A few fixes
This is the May 2025 update for .NET 8 for Fedora. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.16/8.0.116.md Runtime: https://github.com/dotnet/core/blob/main/release-
Update to version 12.5.2. Fixes CVE-2025-22247
Update to 128.10.2 https://www.thunderbird.net/en-US/thunderbird/128.10.2esr/releasenotes/
A few fixes
ESET Research shares its findings on the workings of Danabot, an infostealer recently disrupted in a multinational law enforcement operation
The bustling cybercrime enterprise has been dealt a significant blow in a global operation that relied on the expertise of ESET and other technology companies
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
Update to 128.10.2 https://www.thunderbird.net/en-US/thunderbird/128.10.2esr/releasenotes/ Update to 128.10.1 https://www.mozilla.org/en-US/security/advisories/mfsa2025-34/ https://www.thunderbird.net/en-US/thunderbird/128.10.1esr/releasenotes/
CVE-2025-46646 ghostscript: Mishandling of Overlong UTF-8 Encoding in decode_utf8() (fedora#2362639, fedora#2362446)
Fix for CVE-2025-47268
https://security-tracker.debian.org/tracker/DSA-5925-1
Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel’® Processors may allow an authenticated user to potentially enable information disclosure via local access. (CVE-2024-28956) Insufficient resource pool in the core management mechanism for some
Heap buffer overflow in HTML. (CVE-2025-4096) Out of bounds memory access in DevTools. (CVE-2025-4050) Insufficient data validation in DevTools. (CVE-2025-4051) Inappropriate implementation in DevTools. (CVE-2025-4052) Use after free in WebAudio. (CVE-2025-4372)
Our intense monitoring of tens of thousands of malicious samples helped this global disruption operation
* bsc#1229504 * bsc#1233019 * bsc#1234847 Cross-References:
* bsc#1233019 * bsc#1234847 Cross-References: * CVE-2024-50115
* bsc#1233019 * bsc#1233678 * bsc#1234847 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5924-1
