An update that solves three vulnerabilities and has two security fixes can now be installed.
An update that solves three vulnerabilities and has two security fixes can now be installed.
An update that solves four vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
MGAA-2026-0003 – Updated isodumper packages fix bugs
MGAA-2026-0002 – Updated sddm-theme-coffee-ng packages fix bug
https://security-tracker.debian.org/tracker/DSA-6095-1
https://security-tracker.debian.org/tracker/DSA-6094-1
An update that solves eight vulnerabilities and has one security fix can now be installed.
An update that solves eight vulnerabilities and has one security fix can now be installed.
An update that solves eight vulnerabilities and has one security fix can now be installed.
An update that solves eight vulnerabilities and has one security fix can now be installed.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
https://security-tracker.debian.org/tracker/DSA-6093-1
An update that solves 70 vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
Moderate: postgresql:15 security update
A vulnerability was found in Curl, an easy-to-use client-side URL transfer library and command line tool. It can cause a crash or potentially a memory out of bounds read. For Debian 11 bullseye, this problem has been fixed in version 7.74.0-1.3+deb11u16.
Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service or potentially the execution of arbitrary code if malformed XCF, JPEG 2000 or PNM files are opened. For the oldstable distribution (bookworm), these problems have been fixed
Update to 1.148.0
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).
https://github.com/wb2osz/direwolf/releases/tag/1.8.1
Correctly handle the program name passed to the sleep disabler. Ensure GStreamer is initialized before using the Quirks. Fix several crashes and rendering issues. Fix CVE-2025-14174, CVE-2025-43501, CVE-2025-43529, CVE-2025-43531, CVE-2025-43535, CVE-2025-43536, CVE-2025-43541
Update to 2.83.2
Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442
https://github.com/wb2osz/direwolf/releases/tag/1.8.1
Two vulnerabilities were discovered in smb4k, a KDE desktop utility which allows unprivileged mounting of Samba/CIFS network shares, which may result in local denial of service or local privilege escalation. For the stable distribution (trixie), these problems have been fixed in version 4.0.0-1+deb13u1.
Rebuilt for CVE-2025-47906
Rebuilt for CVEs
Support for Go 1.26 and security fixes. Upstream release notes.
Rebuilt for CVEs
Support for Go 1.26 and security fixes. Upstream release notes.
https://security-tracker.debian.org/tracker/DSA-6092-1
An update that solves three vulnerabilities can now be installed.
An update that fixes 8 vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes one vulnerability is now available.
Update to 1.1.97
Update to 5.8.0
As 2025 draws to a close, Tony looks back at the cybersecurity stories that stood out both in December and across the whole of this year
A Buffer Overflow vulnerability has been found in osslsigncode, a OpenSSL based Authenticode signing tool for PE/MSI/Java CAB files, which possibly allows an malicious attacker to execute arbitrary code when signing a crafted file. For Debian 11 bullseye, this problem has been fixed in version
An update that solves four vulnerabilities can now be installed.
