Menu

Quote

Moderate: yggdrasil-worker-package-manager security update

Important: hplip security update

Important: dracut security update

Important: tomcat security update

Important: valkey security update

Important: fence-agents security update

Important: podman security update

Important: rsync security update

Important: 389-ds-base security, bug fix, and enhancement update

Important: dracut security update

An update that solves one vulnerability can now be installed.

An update that solves 5 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

https://security-tracker.debian.org/tracker/DSA-6351-1

Important: tomcat security update

Important: valkey security update

Important: fence-agents security update

Important: podman security update

Important: rsync security update

Important: 389-ds-base security, bug fix, and enhancement update

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 3 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 14 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 9 vulnerabilities can now be installed.

An update that solves 40 vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

Important: dracut security update

Important: hplip security update

Moderate: yggdrasil-worker-package-manager security update

Important: dracut security update

Important: hplip security update

Important: dracut security update

Moderate: yggdrasil-worker-package-manager security update

Important: hplip security update

Important: 389-ds-base security, bug fix, and enhancement update

Moderate: yggdrasil-worker-package-manager security update

Important: rsync security, bug fix, and enhancement update

Important: 389-ds-base security, bug fix, and enhancement update

Important: postfix security update

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.12.0esr-1~deb11u1. For Debian 12 bookworm, these problems have been fixed in version

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, bypass of the same-origin policy, privilege escalation, information disclosure, spoofing or sandbox escape. For Debian 11 bullseye, these problems have been fixed in version

Important: dracut security update

Important: xorg-x11-server-Xwayland security, bug fix, and enhancement update

Important: xorg-x11-server security, bug fix, and enhancement update

Important: xorg-x11-server security, bug fix, and enhancement update

Important: 389-ds:1.4 security update

Important: xorg-x11-server-Xwayland security, bug fix, and enhancement update

Important: kernel security update

Important: dracut security update

Update NSS to 3.124.0 Update to Firefox 152.0

Update NSS to 3.124.0 Update to Firefox 152.0

Update to 149.0.7827.114 CVE-2026-12007: Use after free Core CVE-2026-12008: Use after free DigitalCredentials CVE-2026-12009: Insufficient validation of untrusted input Accessibility CVE-2026-12010: Heap buffer overflow GPU

Ongres Scram update and security fix.

This update fixes a command injection issue resulting from the use of the 2-argument form of open (CVE-2026-11526).

Upgrade to 4.4.2 upstream version.

Changes: 6.17 2026-05-19 23:11:06Z Fix CVE-2026-8450 (affects 6.15 and earlier): 2-arg open() in send_file() enabled RCE / arbitrary file write / response-body exfiltration when a string argument was derived from attacker-

https://security-tracker.debian.org/tracker/DSA-6353-1

https://security-tracker.debian.org/tracker/DSA-6354-1

Security update

Security update

Security update

Security update

Several security issues were fixed in LXD.

An update that solves 11 vulnerabilities can now be installed.

An update that solves 11 vulnerabilities can now be installed.

An update that solves 11 vulnerabilities can now be installed.

An update that solves 11 vulnerabilities can now be installed.

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in version 1:140.12.0esr-1~deb13u1. We recommend that you upgrade your thunderbird packages.

Several security issues were fixed in libheif.

Several security issues were fixed in Net::CIDR::Lite.

Several security issues were fixed in Vim.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, bypass of the same-origin policy, privilege escalation, information disclosure, spoofing or sandbox escape. For the stable distribution (trixie), these problems have been fixed in

Dolibarr could be made to run programs if it received specially crafted network traffic.

Several security issues were fixed in kitty.

It was discovered that atril, the MATE document viewer, is prone to a command injection vulnerability if a specially crafted PDF file is opened. For the stable distribution (trixie), this problem has been fixed in version 1.26.2-4+deb13u1.

Several security issues were fixed in Go Cryptography.

Security update

Several security issues were fixed in Tomcat.

An update that solves three vulnerabilities can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 4 vulnerabilities can now be installed.

An update that solves 3 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 3 vulnerabilities can now be installed.

ldns could be made to accept spoofed DNS responses.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: