Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517
Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517
xorg-x11-server CVE fix for CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180
Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517
https://security-tracker.debian.org/tracker/DSA-5951-1
* bsc#1232908 * bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062
* bsc#1235231 Cross-References: * CVE-2024-56601
* bsc#1239948 * bsc#1244304 * bsc#1244503 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5952-1
https://security-tracker.debian.org/tracker/DSA-5950-1
Several security issues were fixed in libarchive.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
* bsc#1243565 * bsc#1245054 * bsc#1245055 Cross-References:
* bsc#1236217 * bsc#1244156 * bsc#1244157 * bsc#1244158 * jsc#SLE-18320
https://security-tracker.debian.org/tracker/DSA-5949-1
https://security-tracker.debian.org/tracker/DSA-5948-1
* bsc#1244148 Cross-References: * CVE-2011-10007
* bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062 * bsc#1235231
Nils Emmerich discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.
commons-beanutils, utility for manipulating Java beans have an improper Access Control vulnerability. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers
* bsc#1239192 Cross-References: * CVE-2025-22868
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Template injection that can lead to XSS has been fixed in node-send, a Node.js module for streaming files over HTTP. For Debian 11 bullseye, this problem has been fixed in version
* bsc#1241067 * bsc#1243273 * bsc#1244032 * bsc#1244056 * bsc#1244059
* bsc#1234421 * bsc#1244405 * bsc#1244406 Cross-References:
* bsc#1243721 Cross-References: * CVE-2025-5222
