https://security-tracker.debian.org/tracker/DSA-6271-1
https://security-tracker.debian.org/tracker/DSA-6270-1
https://security-tracker.debian.org/tracker/DSA-6269-1
https://security-tracker.debian.org/tracker/DSA-6268-1
https://security-tracker.debian.org/tracker/DSA-6267-1
https://security-tracker.debian.org/tracker/DSA-6266-1
Moderate: freerdp security update
Important: openexr security update
Moderate: glib2 security update
Moderate: libsoup3 security update
An update that fixes one vulnerability is now available.
An update that fixes 6 vulnerabilities is now available.
Smart glasses allow anyone to track and record the world around them. That could put your data and the privacy of those nearby at risk.
Several security issues were fixed in ImageMagick.
Update NSS to 3.122.2 Updated to Firefox 150.0.1
Update to 148.0.7778.96 CVE-2026-7896: Integer overflow in Blink CVE-2026-7897: Use after free in Mobile CVE-2026-7898: Use after free in Chromoting CVE-2026-7899: Out of bounds read and write in V8
Update NSS to 3.122.2 Updated to Firefox 150.0.1
Update NSS to 3.122.2 Update to Firefox 150.0.1
Update NSS to 3.122.2 Update to Firefox 150.0.1
https://security-tracker.debian.org/tracker/DSA-6265-1
Moderate: libpng security update
Moderate: freeipmi security update
Moderate: libpng security update
An update that solves two vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
https://security-tracker.debian.org/tracker/DSA-6264-1
https://security-tracker.debian.org/tracker/DSA-6263-1
https://security-tracker.debian.org/tracker/DSA-6262-1
https://security-tracker.debian.org/tracker/DSA-6261-1
https://security-tracker.debian.org/tracker/DSA-6260-1
Two security vulnerabilities were discovered in the Corosync cluster engine, which could result in denial of service or memory disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 3.1.7-1+deb12u2. For the stable distribution (trixie), these problems have been fixed in
Multiple security vulnerabilities were discovered in Tor, a connection- based low-latency anonymous communication system, which could result in denial of service. For the oldstable distribution (bookworm), these problems have been fixed in version 0.4.9.8-0+deb12u1.
MGASA-2026-0126 – Updated openvpn packages fix security vulnerabilities
33.0.3 Release
Update to .NET SDK 10.0.107 and Runtime 10.0.7 Fixes: CVE-2026-40372 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.7/10.0.107.md
This is new version of exim fixing some security bugs.
It was discovered that PyJWT, a Python implementation of JSON web tokens insufficiently validated the “crit” header parameter, which could result in incomplete enforcement of authentication settings. For the oldstable distribution (bookworm), this problem has been fixed in version 2.6.0-1+deb12u1.
A security vulnerability has been discovered in libpng, a library implementing an interface for reading and writing PNG (Portable Network Graphics) files, which could leading to corrupted chunk data and potential heap information disclosure. For Debian 11 bullseye, this problem has been fixed in version
Two vulnerabilities have been discovered in the Linux kernel that may lead to local privilege escalation. For the oldstable distribution (bookworm), these problems have been fixed in version 6.1.170-3. We recommend that you upgrade your linux packages.
https://security-tracker.debian.org/tracker/DSA-6259-1
https://security-tracker.debian.org/tracker/DSA-6258-1
Two vulnerabilities have been discovered in the Linux kernel that may lead to local privilege escalation. For Debian 11 bullseye, these problems have been fixed in version 5.10.251-4. We recommend that you upgrade your linux packages.
An update that solves two vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history “for any number” and had been downloaded more than seven million times before being taken down
How come it’s still possible to ‘secure’ an online account with a six-digit string?
