https://security-tracker.debian.org/tracker/DSA-5948-1
* bsc#1244148 Cross-References: * CVE-2011-10007
* bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062 * bsc#1235231
Nils Emmerich discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.
commons-beanutils, utility for manipulating Java beans have an improper Access Control vulnerability. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers
* bsc#1239192 Cross-References: * CVE-2025-22868
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Template injection that can lead to XSS has been fixed in node-send, a Node.js module for streaming files over HTTP. For Debian 11 bullseye, this problem has been fixed in version
* bsc#1241067 * bsc#1243273 * bsc#1244032 * bsc#1244056 * bsc#1244059
* bsc#1234421 * bsc#1244405 * bsc#1244406 Cross-References:
* bsc#1243721 Cross-References: * CVE-2025-5222
https://security-tracker.debian.org/tracker/DSA-5947-1
Update to 137.0.7151.119 * CVE-2025-6191: Integer overflow in V8 * CVE-2025-6192: Use after free in Profiler
Harden temporary private mounts (#2373301)
4.9.0
This is the .NET monthly update for June 2025. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release-notes/9.0/9.0.6/9.0.107.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.6/9.0.6.md
Fix improper access control vulnerability Resolves: CVE-2025-48734
https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/OXIGQIHBL26HFKG6TT5SWSH7K7W6RO4H/ https://phabricator.wikimedia.org/T382326
https://security-tracker.debian.org/tracker/DSA-5946-1
https://security-tracker.debian.org/tracker/DSA-5945-1
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
* bsc#1241158 * bsc#1241160 * bsc#1243282 * bsc#1243286 * bsc#1243288
* bsc#1234449 Cross-References: * CVE-2024-47606
* bsc#1239192 Cross-References: * CVE-2025-22868
* bsc#1227690 Cross-References: * CVE-2024-38526
* bsc#1233012 * bsc#1243273 * bsc#1244401 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5944-1
It was discovered that an Out Of Memory error may occur when attempting to initialize a huge byte array, even when maxFrameSize is set. For Debian 11 bullseye, this problem has been fixed in version
* bsc#1234415 * bsc#1234450 * bsc#1234453 * bsc#1234455 * bsc#1234456
Several security issues were fixed in Samba.
Several security issues were fixed in Express.
* bsc#1238681 * bsc#1239192 Cross-References: * CVE-2025-22868
