BIND a popular name server (DNS) was affected by a vulnerability. If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers
An update that solves two vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves eight vulnerabilities can now be installed.
An update that solves eight vulnerabilities can now be installed.
An update that solves six vulnerabilities can now be installed.
Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure or incomplete permission checks. For the oldstable distribution (bookworm), these problems have been fixed in version 1:1.39.17-1+deb12u2.
Multiple security vulnerabilities were discovered in Flatpak, an application deployment framework for desktop apps, which could allow a Flatpak app to delete arbitrary hosts on the host or break out of the sandbox resulting in code execution in the host context. For the stable distribution (trixie), these problems have been fixed in
MGASA-2026-0096 – Updated libpng12 packages fix security vulnerability
MGASA-2026-0095 – Updated tomcat packages fix security vulnerabilities
MGASA-2026-0094 – Updated squid packages fix security vulnerabilities
Moderate: kernel security update
https://security-tracker.debian.org/tracker/DSA-6208-1
https://security-tracker.debian.org/tracker/DSA-6207-1
If you’ve been the victim of fraud, you’re likely already a lead on a ‘sucker list’ – and if you’re not careful, your ordeal may be about to get worse.
Important: kea security update
Several vulnerabilities were discovered in the inetutils implementation of telnetd and telnet, which may result in privilege escalation or information disclosure. CVE-2026-28372 Ron Ben Yizhak from SafeBreach found that the fix for CVE-2026-24061 was
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 140.9.1esr-1~deb11u1.
https://security-tracker.debian.org/tracker/DSA-6206-1
https://security-tracker.debian.org/tracker/DSA-6204-1
An update that solves one vulnerability can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
An update that solves eight vulnerabilities can now be installed.
An update that solves eight vulnerabilities can now be installed.
New upstream release (#2442363) fixing various security issues
Update to latest upstream
https://security-tracker.debian.org/tracker/DSA-6205-1
An update that solves six vulnerabilities can now be installed.
An update that solves six vulnerabilities can now be installed.
An update that solves eight vulnerabilities can now be installed.
An update that solves eight vulnerabilities can now be installed.
Important: fontforge security update
Moderate: ncurses security update
https://security-tracker.debian.org/tracker/DSA-6201-1
Threat actors are using AI to supercharge tried-and-tested TTPs. When attacks move this fast, cyber-defenders need to rethink their own strategy.
Important: fontforge security update
Important: fontforge security update
Moderate: kernel security update
Moderate: crun security update
Moderate: kernel security update
Moderate: crun security update
https://security-tracker.debian.org/tracker/DSA-6202-1
https://security-tracker.debian.org/tracker/DSA-6197-2
