https://security-tracker.debian.org/tracker/DSA-6175-1
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Net-CIDR could allow unintended access to network services.
Debian Goodies could be made to crash or run programs as your login if it opened a specially crafted file.
# Security update for helm Announcement ID: SUSE-SU-2026:0948-1 Release Date: 2026-03-20T18:07:28Z Rating: important References:
https://security-tracker.debian.org/tracker/DSA-6176-1
https://security-tracker.debian.org/tracker/DSA-6173-1
Jul Blobul discovered that SPIP, a website engine for publishing, is prone to a privilege escalation vulnerability. For the stable distribution (trixie), this problem has been fixed in version 4.4.13+dfsg-0+deb13u1. We recommend that you upgrade your spip packages.
Update to 146.0.7680.80 * CVE-2026-3909: Out of bounds write in Ski
Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens
Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.
Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens
Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.
https://security-tracker.debian.org/tracker/DSA-6174-1
https://security-tracker.debian.org/tracker/DSA-6171-1
What you do – and how fast – after an account is compromised often matters more than it may seem
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43214 shandikri discovered that processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex
Upstream announcements: WordPress 6.9.2 Release WordPress 6.9.3 and 7.0 beta 4 WordPress 6.9.4 Release
Update to 1.73.3; Fixes: RHBZ#2426392, RHBZ#2415186
Update to 0.37.1 (rbhz#2445943) Fixes Denial of Service via malformed Content-Length header (CVE-2026-31870 Reenables 32-bit build Update to 0.37.0 (rhbz#2441656)
Add patch for CVE-2026-1539 (Also remove Proxy-Authorization header on cross origin redirect)
https://security-tracker.debian.org/tracker/DSA-6172-1
https://security-tracker.debian.org/tracker/DSA-6170-1
https://security-tracker.debian.org/tracker/DSA-6169-1
ESET researchers dive deeper into the EDR killer ecosystem, disclosing how attackers abuse vulnerable drivers
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
This is the March 2026 release of .NET 10. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.4/10.0.104.md Runtime: https://github.com/dotnet/core/blob/main/release-
CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex
Fix CVE-2026-31812: Bump quinn-proto to 0.11.14 – Closes rhbz#2446359
Update to 146.0.7680.80 * CVE-2026-3909: Out of bounds write in Ski
https://security-tracker.debian.org/tracker/DSA-6168-1
An update that solves one vulnerability can now be installed.
Several security issues were fixed in python2.7
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-6167-1
https://security-tracker.debian.org/tracker/DSA-6166-1
Important: libpng security update
Flask could be made to expose sensitive information over the network.
USN-8102-1 introduced a regression in snapd
# Security update for container-suseconnect Announcement ID: SUSE-SU-2026:0909-1 Release Date: 2026-03-17T17:34:35Z Rating: important References:
An update that solves three vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
