An update that solves three vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
Security update
Security update
Security update
Security update
Security update
A vulnerability was discovered in yelp, the GNOME help browser, that allows a crafted help document to read files accessible to the user and exfiltrate them to a remote server through resources loaded by the embedded web view. When yelp is launched from a sandboxed application (for example via the Flatpak OpenURI portal), this also […]
updated to 1.6.58 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the
keep GTK4 in rawhide for now switch to GTK4 for GVim Fix CVE-2026-46483
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks since these versions use Perl’s built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. Version 0.10026 of the module fixes this issue.
Update to 1.25.1 (rhbz#2480119) Fix CVE-2026-33278, Possible remote code execution during DNSSEC validation. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-42944, Heap overflow and crash with multiple nsid, cookie, padding EDNS options. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
This is an update fixing CVE-2026-43964.
CVE-2026-27851: lib-var-expand: Safe filter marks all following pipelines safe. CVE-2026-33603: auth: CRAM-SHA-*-PLUS channel binding could be faked. MITM attacker with a certificate trusted by the client could have bypassed the requirement for channel binding. CVE-2026-40020: IMAP folders can be shared-spammed to everyone.
Update to Samba 4.24.3 – Security fix for CVE-2026-4480, CVE-2026-2340, CVE-2026-3012, CVE-2026-1933, CVE-2026-4408, and CVE-2026-3238
Update to Samba 4.24.3 – Security fix for CVE-2026-4480, CVE-2026-2340, CVE-2026-3012, CVE-2026-1933, CVE-2026-4408, and CVE-2026-3238
Update to 3.26.4, fixes CVE-2026-8631, CVE-2026-8632
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks since these versions use Perl’s built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. Version 0.10026 of the module fixes this issue.
This is an update fixing CVE-2026-43964.
CVE-2026-27851: lib-var-expand: Safe filter marks all following pipelines safe. CVE-2026-33603: auth: CRAM-SHA-*-PLUS channel binding could be faked. MITM attacker with a certificate trusted by the client could have bypassed the requirement for channel binding. CVE-2026-40020: IMAP folders can be shared-spammed to everyone.
https://security-tracker.debian.org/tracker/DSA-6320-1
https://security-tracker.debian.org/tracker/DSA-6319-1
https://security-tracker.debian.org/tracker/DSA-6316-1
An update that solves 60 vulnerabilities and has three security fixes can now be installed.
An update that solves 60 vulnerabilities and has three security fixes can now be installed.
An update that solves 29 vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves six vulnerabilities can now be installed.
An update that solves six vulnerabilities can now be installed.
Qt Declarative could be made to use excessive resources if it received specially crafted input.
Evolution Data Server could be made to remove files.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves 68 vulnerabilities, contains one feature and has 10 security fixes can now be installed.
An update that solves 68 vulnerabilities, contains one feature and has 10 security fixes can now be installed.
An update that solves six vulnerabilities can now be installed.
An update that solves six vulnerabilities can now be installed.
An update that solves six vulnerabilities can now be installed.
An update that solves five vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
Several security issues were fixed in rsync.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the kernel.
An update that solves six vulnerabilities can now be installed.
An update that solves five vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
An update that solves five vulnerabilities can now be installed.
An update that solves five vulnerabilities can now be installed.
An update that solves six vulnerabilities can now be installed.
An update that solves six vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
An update that solves five vulnerabilities can now be installed.
An update that solves five vulnerabilities can now be installed.
An update that solves six vulnerabilities can now be installed.
An update that solves six vulnerabilities can now be installed.
An update that solves six vulnerabilities can now be installed.
An update that solves six vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
An update that solves six vulnerabilities can now be installed.
An update that solves six vulnerabilities can now be installed.
Several vulnerabilities have been found in aiohttp, an asynchronous HTTP client/server framework for asyncio and Python. CVE-2025-53643 Request smuggling vulnerability due to not parsing trailer sections of an HTTP request.
Update to 1.5.4. Fixes a buffer overflow caused by integer promotion rules in OFBMPImageFormatHandler and OFQOIImageFormatHandler. Update to 1.5.3
Update to 1.5.4. Fixes a buffer overflow caused by integer promotion rules in OFBMPImageFormatHandler and OFQOIImageFormatHandler. Update to 1.5.3
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 148.0.7778.215-1~deb12u1.
https://security-tracker.debian.org/tracker/DSA-6318-1
https://security-tracker.debian.org/tracker/DSA-6317-1
https://security-tracker.debian.org/tracker/DSA-6315-1
https://security-tracker.debian.org/tracker/DSA-6314-1
https://security-tracker.debian.org/tracker/DSA-6313-1
https://security-tracker.debian.org/tracker/DSA-6312-1
In this roundup, Tony looks at attacks against Polish water treatment facilities, how AI-directed attacks failed in Mexico, and what Google believes is the first AI-generated zero-day exploit
