Menu

Quote

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Security update

Security update

Security update

Security update

Security update

A vulnerability was discovered in yelp, the GNOME help browser, that allows a crafted help document to read files accessible to the user and exfiltrate them to a remote server through resources loaded by the embedded web view. When yelp is launched from a sandboxed application (for example via the Flatpak OpenURI portal), this also […]

updated to 1.6.58 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the

keep GTK4 in rawhide for now switch to GTK4 for GVim Fix CVE-2026-46483

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks since these versions use Perl’s built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. Version 0.10026 of the module fixes this issue.

Update to 1.25.1 (rhbz#2480119) Fix CVE-2026-33278, Possible remote code execution during DNSSEC validation. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-42944, Heap overflow and crash with multiple nsid, cookie, padding EDNS options. Thanks to Qifan Zhang, Palo Alto Networks, for the report.

CVE-2026-27851: lib-var-expand: Safe filter marks all following pipelines safe. CVE-2026-33603: auth: CRAM-SHA-*-PLUS channel binding could be faked. MITM attacker with a certificate trusted by the client could have bypassed the requirement for channel binding. CVE-2026-40020: IMAP folders can be shared-spammed to everyone.

This is an update fixing CVE-2026-43964.

Update to Samba 4.24.3 – Security fix for CVE-2026-4480, CVE-2026-2340, CVE-2026-3012, CVE-2026-1933, CVE-2026-4408, and CVE-2026-3238

Update to Samba 4.24.3 – Security fix for CVE-2026-4480, CVE-2026-2340, CVE-2026-3012, CVE-2026-1933, CVE-2026-4408, and CVE-2026-3238

Update to 3.26.4, fixes CVE-2026-8631, CVE-2026-8632

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks since these versions use Perl’s built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. Version 0.10026 of the module fixes this issue.

CVE-2026-27851: lib-var-expand: Safe filter marks all following pipelines safe. CVE-2026-33603: auth: CRAM-SHA-*-PLUS channel binding could be faked. MITM attacker with a certificate trusted by the client could have bypassed the requirement for channel binding. CVE-2026-40020: IMAP folders can be shared-spammed to everyone.

This is an update fixing CVE-2026-43964.

https://security-tracker.debian.org/tracker/DSA-6319-1

https://security-tracker.debian.org/tracker/DSA-6320-1

https://security-tracker.debian.org/tracker/DSA-6316-1

An update that solves 60 vulnerabilities and has three security fixes can now be installed.

An update that solves 60 vulnerabilities and has three security fixes can now be installed.

An update that solves 29 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

Qt Declarative could be made to use excessive resources if it received specially crafted input.

Evolution Data Server could be made to remove files.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 68 vulnerabilities, contains one feature and has 10 security fixes can now be installed.

An update that solves 68 vulnerabilities, contains one feature and has 10 security fixes can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

Several security issues were fixed in rsync.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the kernel.

An update that solves six vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

Several vulnerabilities have been found in aiohttp, an asynchronous HTTP client/server framework for asyncio and Python. CVE-2025-53643 Request smuggling vulnerability due to not parsing trailer sections of an HTTP request.

Update to 1.5.4. Fixes a buffer overflow caused by integer promotion rules in OFBMPImageFormatHandler and OFQOIImageFormatHandler. Update to 1.5.3

Update to 1.5.4. Fixes a buffer overflow caused by integer promotion rules in OFBMPImageFormatHandler and OFQOIImageFormatHandler. Update to 1.5.3

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 148.0.7778.215-1~deb12u1.

https://security-tracker.debian.org/tracker/DSA-6317-1

https://security-tracker.debian.org/tracker/DSA-6318-1

https://security-tracker.debian.org/tracker/DSA-6312-1

https://security-tracker.debian.org/tracker/DSA-6313-1

https://security-tracker.debian.org/tracker/DSA-6314-1

https://security-tracker.debian.org/tracker/DSA-6315-1

https://security-tracker.debian.org/tracker/DSA-6308-1

https://security-tracker.debian.org/tracker/DSA-6307-1

An update that solves 6 vulnerabilities can now be installed.

https://security-tracker.debian.org/tracker/DSA-6309-1

https://security-tracker.debian.org/tracker/DSA-6310-1

https://security-tracker.debian.org/tracker/DSA-6311-1

https://security-tracker.debian.org/tracker/DSA-6304-1

https://security-tracker.debian.org/tracker/DSA-6303-1

https://security-tracker.debian.org/tracker/DSA-6302-1

https://security-tracker.debian.org/tracker/DSA-6301-1

https://security-tracker.debian.org/tracker/DSA-6305-1

https://security-tracker.debian.org/tracker/DSA-6306-1

https://security-tracker.debian.org/tracker/DSA-6300-1

https://security-tracker.debian.org/tracker/DSA-6299-1

https://security-tracker.debian.org/tracker/DSA-6298-1

Several security issues were fixed in Samba.

Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix, which might result in bypass of access checks, overwrite of files in unintended situations using the WORM vfs module, installing CA certificates over http without verification when auto-enrollment GPO is enabled, denial of service or remote code

Dnsmasq could be made to crash or run programs if it received specially crafted network traffic.