https://security-tracker.debian.org/tracker/DSA-6006-1
https://security-tracker.debian.org/tracker/DSA-6005-1
https://security-tracker.debian.org/tracker/DSA-6004-1
* bsc#1233421 Cross-References: * CVE-2024-52615
* bsc#1246197 * bsc#1249191 * bsc#1249348 * bsc#1249367 * jsc#PED-13055
* bsc#1246197 * bsc#1249191 * bsc#1249348 * bsc#1249367 * jsc#PED-13055
https://security-tracker.debian.org/tracker/DSA-6003-1
HybridPetya is the fourth publicly known real or proof-of-concept bootkit with UEFI Secure Boot bypass functionality
* bsc#1236851 * bsc#1248070 Cross-References: * CVE-2025-23419
* bsc#1235673 * bsc#1235674 Cross-References: * CVE-2024-57822
* bsc#1243581 * bsc#1248410 * bsc#1248687 Cross-References:
* bsc#1237208 * bsc#1247528 * bsc#1247529 * bsc#1247530 * bsc#1247531
This update upgrade the package to version 0.36. This version fixes CVE-2025-40923 by using Crypt::SysRandom to generate secure session IDs.
This update upgrade the package to version 0.44. This version fixes CVE-2025-40924 by using Crypt::SysRandom to generate properly random session IDs.
This update upgrade the package to version 1.019. This version fixes CVE-2025-40920 by using Crypt::SysRandom to generate nonces instead of Data::UUID.
Update to 140.0.7339.127 CVE-2025-10200: Use after free in Serviceworker CVE-2025-10201: Inappropriate implementation in Mojo
2.4.14 (fixes CVE-2025-58060 and CVE-2025-58364)
Fix crash with spice GL (bz 2391334) Update to 10.1.0 GA release Automatic update for qemu-10.1.0-0.4.rc4.fc43.
https://security-tracker.debian.org/tracker/DSA-6002-1
https://security-tracker.debian.org/tracker/DSA-6001-1
UEFI copycat of Petya/NotPetya exploiting CVE-2024-7344 discovered on VirusTotal
https://security-tracker.debian.org/tracker/DSA-6000-1
https://security-tracker.debian.org/tracker/DSA-5999-1
As bad actors often simply waltz through companies’ digital front doors with a key, here’s how to keep your own door firmly locked tight
