Several security issues were fixed in OpenSSH.
An update that solves two vulnerabilities and has one security fix can now be installed.
Multiple vulnerabilities where identified in polkit, a toolkit for defining and handling the policy that allows unprivileged processes to speak to privileged processes. CVE-2021-4115 Kevin Backhouse of GitHub Security Lab (GHSL) found that there is a
PackageKit could be made to install packages as the administrator.
An update that solves 14 vulnerabilities and has five security fixes can now be installed.
An update that solves 14 vulnerabilities and has five security fixes can now be installed.
https://security-tracker.debian.org/tracker/DSA-6237-1
https://security-tracker.debian.org/tracker/DSA-6236-1
https://security-tracker.debian.org/tracker/DSA-6231-1
Important: grafana security update
Important: sudo security update
Important: kernel security update
Important: firefox security update
Important: gdk-pixbuf2 security update
Important: firefox security update
https://security-tracker.debian.org/tracker/DSA-6235-1
https://security-tracker.debian.org/tracker/DSA-6234-1
https://security-tracker.debian.org/tracker/DSA-6233-1
https://security-tracker.debian.org/tracker/DSA-6232-1
Several security issues were fixed in nginx.
Pillow could be made to crash if it opened a specially crafted file.
HAProxy could be made to expose sensitive information over the network.
Little CMS could be made to crash or run programs if it opened a specially crafted ICC profile.
ClamAV could be made to crash if it opened a specially crafted HTML file.
Several security issues were fixed in strongSwan.
An update that solves 25 vulnerabilities can now be installed.
Important: kernel-rt security update
Important: kernel-rt security update
Important: kernel-rt security update
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.10.0esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.
https://security-tracker.debian.org/tracker/DSA-6230-1
A breach claims the systems as well as the confidence that was, in retrospect, a major vulnerability
Backport security patches from OpenSSL 3.5.6
CVE-2026-35385: Fix privilege escalation via scp legacy protocol when not in preserving file mode CVE-2026-35388: Add connection multiplexing confirmation for proxy-mode multiplexing sessions CVE-2026-35387: Fix incomplete application of PubkeyAcceptedAlgorithms and
Fix CVE-2026-35535
Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-5713, CVE-2026-6100
Fix CVE-2026-40192.
Update to 147.0.7727.101 Critical CVE-2026-6296: Heap buffer overflow in ANGLE Critical CVE-2026-6297: Use after free in Proxy Critical CVE-2026-6298: Heap buffer overflow in Skia Critical CVE-2026-6299: Use after free in Prerender
ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions
Several security issues were fixed in GStreamer Bad Plugins.
An update that solves 10 vulnerabilities, contains one feature and has one security fix can now be installed.
An update that solves nine vulnerabilities, contains one feature and has one security fix can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
