Backport fixes for CVE-2026-1484, CVE-2026-1485, CVE-2026-1489.
Update to version 1.9.2. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.9.2
Release notes for xrdp v0.10.5 (2026/01/27) Security fixes CVE-2025-68670: Improper bounds checking of domain string length leads to Stack- based Buffer Overflow New features
Release notes for xrdp v0.10.5 (2026/01/27) Security fixes CVE-2025-68670: Improper bounds checking of domain string length leads to Stack- based Buffer Overflow New features
Denis Skvortsov discovered that xrdp, a Remote Desktop Protocol (RDP) server, was susceptible to an unauthenticated stack-based buffer overflow vulnerability, which may result in remote execution of arbitrary code. For the oldstable distribution (bookworm), this problem has been fixed
Update to 9.18.44 (rhbz#2431609) Security Fixes: Fix incorrect length checks for BRID and HHIT records. (CVE-2025-13878) Bug Fixes: Allow glue in delegations with QTYPE=ANY.
Update to 9.18.44 (rhbz#2431609) Security Fixes: Fix incorrect length checks for BRID and HHIT records. (CVE-2025-13878) Bug Fixes: Allow glue in delegations with QTYPE=ANY.
Update to 13.0.10.
An update that fixes one vulnerability, contains one feature is now available.
https://security-tracker.debian.org/tracker/DSA-6123-1
Sudo, a program designed to allow a sysadmin to give limited root privileges to users and log root activity, was affected by multiple vulnerabilities. CVE-2023-28486 Sudo did not escape control characters in log messages.
https://security-tracker.debian.org/tracker/DSA-6122-1
https://security-tracker.debian.org/tracker/DSA-6121-1
https://security-tracker.debian.org/tracker/DSA-6120-1
https://security-tracker.debian.org/tracker/DSA-6119-1
MGASA-2026-0032 – Updated python-django packages fix security vulnerabilities
MGAA-2026-0011 – Updated yt-dlp packages fix bugs
This update bumps the bundled lodash to 4.17.23 to ensure openQA is protected against CVE-2025-13465. It likely was not vulnerable in any case, though, as I don’t believe the vulnerable codepaths were exposed by openQA’s use of lodash.
Regenerate vendor tarball. Fixes CVE-2025-13465.
Regenerate vendor tarball. Fixes CVE-2025-13465.
Version 12.5.8 – 2026-01-27 Changed To prevent Poisoned Pipeline Execution (PPE) attacks using prepared .coverage files in pull requests, a PHPT test will no longer be run if the temporary file for writing code coverage information already exists before the test runs
The mobile marketplace app has a growing number of users, but not all of them are genuine. Watch out for these common scams.
Multiple vulnerabilities were discovered in containerd, an open-source container runtime, used by e.g. Docker or Kubernetes. CVE-2024-25621 Overly broad default permission vulnerability. Directory paths `/var/lib/containerd`, `/run/containerd/io.containerd.grpc.v1.cri`
MGAA-2026-0010 – Updated libformula & ant-contrib packages fix bug
Fix CVE-2026-24882: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution
Regenerate vendor tarball. Fixes CVE-2025-13465.
Regenerate vendor tarball. Fixes CVE-2025-13465.
Version 12.5.8 – 2026-01-27 Changed To prevent Poisoned Pipeline Execution (PPE) attacks using prepared .coverage files in pull requests, a PHPT test will no longer be run if the temporary file for writing code coverage information already exists before the test runs
https://security-tracker.debian.org/tracker/DSA-6118-1
A security issue was discovered in Thunderbird, which could result in information disclosure. For Debian 11 bullseye, this problem has been fixed in version 1:140.7.1esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.
An update that solves three vulnerabilities and has one security fix can now be installed.
An update that solves three vulnerabilities and has one security fix can now be installed.
Several security issues were fixed in ImageMagick.
Several security issues were fixed in MySQL.
MGAA-2026-0009 – Updated subversion packages fix bug
It’s snow joke – sporting events are a big draw for cybercriminals. Make sure you’re not on the losing side by following these best practices.
xrdp is an open source RDP server. It was found that xrdp contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code
Several security issues were fixed in CRaC JDK 21.
Several security issues were fixed in OpenJDK 21.
Several security issues were fixed in OpenJDK 8.
Several security issues were fixed in OpenJDK 11.
15.x 15.1 (2026-01-24) Fix #15088: When building a new train, the refit button state may be incorrect (#15162) Fix #15160: Incorrect company names displayed in load game window (#15161)
