An update that solves one vulnerability can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
https://security-tracker.debian.org/tracker/DSA-6229-1
Several security issues were fixed in league/commonmark.
Slurm could be made to send data to an arbitrary unix socket on the host.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves six vulnerabilities and has one security fix can now be installed.
An update that solves six vulnerabilities and has one security fix can now be installed.
ESET researchers discover another iteration of NGate malware, this time possibly developed with the assistance of AI
PackageKit could be made to install packages as the administrator.
Several security issues were fixed in strongSwan.
Multiple security issues were discovered in cpp-httplib, a C++ cross platform HTTP/HTTPS library, which could result in denial of service. For the stable distribution (trixie), these problems have been fixed in version 0.18.7-1+deb13u1. We recommend that you upgrade your cpp-httplib packages.
Maik Schaefer discovered that a TOCTOU race condition in PackageKit (a package management service over a DBus interface) could result in local privilege escalation. For Debian 11 bullseye, this problem has been fixed in version 1.2.2-2+deb11u1.
Multiple vulnerabilities were fixed in strongSwan, an IKE/IPsec suite. CVE-2026-35328 A vulnerability in libtls related to the processing of the supported_versions extension in TLS that can result in an infinite loop.
An update that solves one vulnerability can now be installed.
https://security-tracker.debian.org/tracker/DSA-6228-1
https://security-tracker.debian.org/tracker/DSA-6227-1
https://security-tracker.debian.org/tracker/DSA-6226-1
https://security-tracker.debian.org/tracker/DSA-6225-1
https://security-tracker.debian.org/tracker/DSA-6224-1
https://security-tracker.debian.org/tracker/DSA-6223-1
An attack is what you see, but a business operation is what you’re up against
Andrew Nesbitt discovered that .install file directives were insufficiently restricted in OPAM, a package manager for OCaml. This could result in directory traversal out of the package area. For Debian 11 bullseye, this problem has been fixed in version 2.0.8-1+deb11u1.
Yarden Porat found a heap-based buffer overwrite in MuPDF, a lightweight PDF viewer, which may result in denial of service or the execution of arbitrary code if malformed documents are opened. For Debian 11 bullseye, this problem has been fixed in version 1.17.0+ds1-2+deb11u2.
# Security update for rootlesskit Announcement ID: SUSE-SU-2026:1493-1 Release Date: 2026-04-20T15:58:01Z Rating: important References:
# Security update for rootlesskit Announcement ID: SUSE-SU-2026:1494-1 Release Date: 2026-04-20T15:58:21Z Rating: important References:
An update that can now be installed.
# Security update for containerd Announcement ID: SUSE-SU-2026:1495-1 Release Date: 2026-04-20T16:00:19Z Rating: important References:
https://security-tracker.debian.org/tracker/DSA-6222-1
https://security-tracker.debian.org/tracker/DSA-6221-1
An update that solves one vulnerability can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
