https://security-tracker.debian.org/tracker/DSA-5931-1
https://security-tracker.debian.org/tracker/DSA-5930-1
Apport could be made to leak sensitive information.
* bsc#1243353 Cross-References: * CVE-2025-5263 * CVE-2025-5264
* bsc#1241274 * bsc#1241275 * bsc#1241276 * bsc#1242208 * bsc#1243429
* bsc#1242300 * bsc#1243284 Cross-References: * CVE-2025-47268
* bsc#1242931 Cross-References: * CVE-2025-4207
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code or information disclosure. For Debian 11 bullseye, these problems have been fixed in version
https://security-tracker.debian.org/tracker/DSA-5932-1
https://security-tracker.debian.org/tracker/DSA-5923-2
https://security-tracker.debian.org/tracker/DSA-5928-1
* bsc#1242008 * bsc#1242009 Cross-References: * CVE-2025-31650
* bsc#1236217 * bsc#1242715 Cross-References: * CVE-2025-22873
* bsc#1241658 * bsc#1241659 Cross-References: * CVE-2025-43965
* bsc#1243216 Cross-References: * CVE-2025-3875 * CVE-2025-3877
* bsc#1242809 Cross-References: * CVE-2025-3887
https://security-tracker.debian.org/tracker/DSA-5929-1
Cybercriminals impersonate the trusted e-signature brand and send fake Docusign notifications to trick people into giving away their personal or corporate data
A path traversal vulnerability in `PackageIndex` was found in setuptools. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context.
GNU C Library could be made to crash or run programs if it processed specially crafted dynamically shared library.
* bsc#1243313 Cross-References: * CVE-2025-47273
* bsc#1243356 Cross-References: * CVE-2025-21490
* bsc#1242809 Cross-References: * CVE-2025-3887
https://security-tracker.debian.org/tracker/DSA-5927-1
https://security-tracker.debian.org/tracker/DSA-5926-1
A flaw was discovered in the dynamic linking support in the GNU C Library, the C standard library implementation used by Debian. Privilege escalation may be possible in statically compiled setuid
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in Intel Microcode.
* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6
PgBouncer is a lightweight connection pooler for PostgreSQL. CVE-2021-3539
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
* bsc#1243313 Cross-References: * CVE-2025-47273
* bsc#1242931 Cross-References: * CVE-2025-4207
ESET Research has been tracking Danabot’s activity since 2018 as part of a global effort that resulted in a major disruption of the malware’s infrastructure
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
