Menu

Quote

alsa-lib could be made to crash or run programs as your login if it opened a specially crafted file.

An update that fixes 13 vulnerabilities is now available.

An update that solves 10 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 21 vulnerabilities can now be installed.

An update that solves 20 vulnerabilities can now be installed.

An update that solves 23 vulnerabilities can now be installed.

Important: xorg-x11-server security update

Important: freerdp security update

Important: xorg-x11-server-Xwayland security update

Important: gegl security update

Moderate: openssl security update

Security update

Security update

Fixes CVE-2026-53511

0.9.34 – security fixes for CVE-2026-27145

Update to 9.11.0. Fixes rhbz#2493338 and CVE-2026-53511

Allow PyO3 0.29, which fixes RUSTSEC-2026-0194 and RUSTSEC-2026-0195. Update to 3.3.21, including upstream fixes for compatibility with dulwich 0.25 and later.

It was discovered that there were two issues in Redis, the in-memory key/value database: CVE-2026-23631 An authenticated attacker could have exploited the master-replica synchronization mechanism to trigger a use-after-free on replicas

Multiple security vulnerabilities were discovered in imagemagick, a software suite used for editing and manipulating digital images, which could lead to denial of service, information disclosure or potentially arbitrary code execution if malformed images are processed. For Debian 11 bullseye, these problems have been fixed in version

Security update

Security update

Security update

Security update

An update that solves 29 vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

An update that solves 22 vulnerabilities can now be installed.

An update that solves 24 vulnerabilities can now be installed.

An update that solves 25 vulnerabilities can now be installed.

An update that solves nine vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves 21 vulnerabilities can now be installed.

An update that solves 21 vulnerabilities can now be installed.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

A vulnerability has been found in the mesa 3D graphics library, possibly allowing out of bound memory access by craftet input. CVE-2026-40393 An out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then

rebase to v2.6.0 to fix CVE-2026-54371

rebase to v2.4.0 to fix CVE-2026-54369 and CVE-2026-54370 Resolves: CVE-2026-54369 Resolves: CVE-2026-54370

https://security-tracker.debian.org/tracker/DSA-6387-1

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

A series of heap overflows in bitmap/PCF parser code could be used by authenticated attackers to execute code in the X server context. CVE-2026-56001 A heap buffer overflow in BitmapScaleBitmaps in due to an overflowing 32-bit size.

An update that solves one vulnerability can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 15 vulnerabilities can now be installed.

Update to 3.13.0

rebase to v2.4.0 to fix CVE-2026-54369 and CVE-2026-54370 Resolves: CVE-2026-54369 Resolves: CVE-2026-54370

rebase to v2.6.0 to fix CVE-2026-54371

Update to version 1.7.19. https://github.com/DaveGamble/cJSON/blob/v1.7.19/CHANGELOG.md

This package provides the Perl module HTML::Gumbo. Versions before 0.19 disclose heap memory via type confusion. Support for the element was added to libgumbo 0.10.0 in 2015, but the walk_tree function in lib/HTML/Gumbo.xs was not updated to support it. The element was treated as a text-node, where strlen() over-reads the heap block that the

fdf6afc update to 3.7b fixes rhbz#2498485 CHANGES FROM 3.7a TO 3.7b Fix so that the end of a synchronized update again triggers a redraw. CHANGES FROM 3.7 TO 3.7a Fix crash in break-pane when no name is provided.

CVE fixes: CVE-2026-12610 CVE-2026-14474 CVE-2026-14476 – rhbz#2494777: CVE-2026-12610 sssd: Use-after-free crash in SSSD’ ‘sssd_pam’ process – rhbz#2497650: CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized

Fix CVE-2026-55380, CVE-2026-54060, CVE-2026-54059, CVE-2026-55379, CVE-2026-55798

Update to 2.112.0.

Version 0.17.0 – 2026-07-01 Security Fix size_t overflow in amqp_decode_bytes bounds check leading to out-of-bounds read (GHSA-jgjf-7fwf-f3c7, #888) Fix heap buffer overflow in amqp_frame_to_bytes for oversized body frames (GHSA-

Version 2.10.2 – 2026-07-01 Security: Validate package names (GHSA-499r-g7pc-vmp9) Security: Validate package bin paths against path traversal (GHSA-gjfg-22fp- rrxx) Security: Sanitize URL-embedded usernames/token in verbose output

https://github.com/AcademySoftwareFoundation/OpenImageIO/releases/tag/v3.1.15.0

This package provides the Perl module HTML::Gumbo. Versions before 0.19 disclose heap memory via type confusion. Support for the element was added to libgumbo 0.10.0 in 2015, but the walk_tree function in lib/HTML/Gumbo.xs was not updated to support it. The element was treated as a text-node, where strlen() over-reads the heap block that the

Update to 3.13.0

CVE-2026-55653: Fix double free in openssh DH-GEX client path during FIPS known- group validation that leads to client-side denial of service CVE-2026-55654: Fix heap out-of-bounds read during GSSAPI indicator cleanup due to missing NULL terminator CVE-2026-55655: Fix MITM of X11 forwarding via abstract UNIX socket pre-binding

An update that solves 28 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 59 vulnerabilities can now be installed.

An update that solves 3 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 3 vulnerabilities can now be installed.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For Debian 12 bookworm, these problems have been fixed in version 150.0.7871.114-1~deb12u1.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 150.0.7871.114-1~deb13u1.

Security update

Security update

Security update

Security update

1.2.9, CVE fixes

Fire scrollend event for instant programmatic scrolls. Increase network idle connection timeout to 115 seconds. Fix several crashes and rendering issues. Fix CVE-2024-4367, CVE-2026-39872, CVE-2026-43663, CVE-2026-43676, CVE-2026-43699, CVE-2026-43701, CVE-2026-43705, CVE-2026-43707, CVE-2026-43712,

server: fixed stack exhaustion via unbounded recursion in RPC attribute parsing by enforcing a recursion depth limit (CVE-2026-13757) fixed confusing error message when trying to store an existing cert with trust anchor fixed assert when parsing p11-kit files with value (“)

Update to the latest version to bring fixes for CVE-2026-45409 and CVE-2024-3651 into the stable releases.

Update to 150.0.7871.114 * CVE-2026-15112: Use after free in Ozone * CVE-2026-15129: Use after free in Views * CVE-2026-15132: Uninitialized Use in V8 * CVE-2026-15133: Use after free in InterestGroups