New version 4.6.4
Update to 1.89.0 Update to 1.88.0
0.9.31
Latest upstream snapshot from stable-2.0 branch. Fixes CVE-2025-14369 in bundled dr_flac.
Update to 3.23.0 to fix CVE-2026-26965, CVE-2026-26955, CVE-2026-26271, CVE-2026-25997, CVE-2026-25959, CVE-2026-25955, CVE-2026-25954, CVE-2026-25953, CVE-2026-25952, CVE-2026-25942, CVE-2026-25941
Update to 146.0.7680.71 * CVE-2026-3913: Heap buffer overflow in WebML * CVE-2026-3914: Integer overflow in WebML * CVE-2026-3915: Heap buffer overflow in WebML * CVE-2026-3916: Out of bounds read in Web Speech
Latest upstream snapshot from stable-2.0 branch. Fixes CVE-2025-14369 in bundled dr_flac.
Latest snapshot from 3.0 branch. Fixes CVE-2025-14369.
MGASA-2026-0057 – Updated python-nltk packages fix security vulnerability
https://security-tracker.debian.org/tracker/DSA-6164-1
https://security-tracker.debian.org/tracker/DSA-6163-1
https://security-tracker.debian.org/tracker/DSA-6162-1
https://security-tracker.debian.org/tracker/DSA-6161-1
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. The Qualys Threat Research Unit (TRU) discovered several vulnerabilities in Apparmor. Details can be found in the Qualys advisory at
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. The Qualys Threat Research Unit (TRU) discovered several vulnerabilities in Apparmor. Details can be found in the Qualys advisory at
An update that solves two vulnerabilities and has one security fix can now be installed.
FreeType could be made to leak sensitive information.
Rebuilt with updated dr_wav to fix CVE-2026-29022
Update to new release, includes updated dependencies that fix for a number of CVEs
https://security-tracker.debian.org/tracker/DSA-6160-1
An update that solves three vulnerabilities and has one security fix can now be installed.
An update that solves three vulnerabilities and has one security fix can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves 37 vulnerabilities can now be installed.
An update that solves 37 vulnerabilities can now be installed.
https://security-tracker.debian.org/tracker/DSA-6159-1
GeoPandas could be vulnerable to SQL injection attacks.
An update that solves seven vulnerabilities and has one security fix can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
0.011 – Update data pointer on resize for rdrand; Clean up string length handling 0.010 – Disallow requesting strings with negative lengths CVE-2026-2597; Try arc4random in stdlib.h first; Correct value of PROTOTYPES keyword in XS
0.011 – Update data pointer on resize for rdrand; Clean up string length handling 0.010 – Disallow requesting strings with negative lengths CVE-2026-2597; Try arc4random in stdlib.h first; Correct value of PROTOTYPES keyword in XS
https://security-tracker.debian.org/tracker/DSA-6158-1
An update that solves two vulnerabilities and has one security fix can now be installed.
An update that solves two vulnerabilities and has one security fix can now be installed.
Update to 145.0.7632.159 CVE-2026-3536: Integer overflow in ANGLE CVE-2026-3537: Object lifecycle issue in PowerVR CVE-2026-3538: Integer overflow in Skia CVE-2026-3539: Object lifecycle issue in DevTools
Update to 1.3.2.
Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact. The functions addr2cidr and cidrlookup may return leading zeros in a CIDR string, which may in turn be parsed as octal numbers by subsequent users. Current versions of the module strip leading zeros from octets.
Update to 145.0.7632.159 CVE-2026-3536: Integer overflow in ANGLE CVE-2026-3537: Object lifecycle issue in PowerVR CVE-2026-3538: Integer overflow in Skia CVE-2026-3539: Object lifecycle issue in DevTools
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves eight vulnerabilities can now be installed.
An update that solves two vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves six vulnerabilities can now be installed.
An update that solves 2 vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves 10 vulnerabilities can now be installed.
An update that solves 2 vulnerabilities can now be installed.
An update that solves one vulnerability can now be installed.
Update to 2.87.3
Update to 145.0.7632.116 * CVE-2026-3061: Out of bounds read in Media * CVE-2026-3062: Out of bounds read and write in Tint * CVE-2026-3063: Inappropriate implementation in DevTools
Update to 2.69.4
Rename from golang-github-prometheus and upgrade to 3.10.0
hex_core ver. 0.12.2
Rename from golang-honnef-tools and update to 2026.1
An update that solves one vulnerability and contains one feature can now be installed.
An update that solves three vulnerabilities can now be installed.
An update that solves three vulnerabilities can now be installed.
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 145.0.7632.159-1~deb12u1.
Important: postgresql16 security update
Important: postgresql16 security update
https://security-tracker.debian.org/tracker/DSA-6157-1
https://security-tracker.debian.org/tracker/DSA-6155-1
https://security-tracker.debian.org/tracker/DSA-6156-1
https://security-tracker.debian.org/tracker/DSA-6154-1
https://security-tracker.debian.org/tracker/DSA-6153-1
https://security-tracker.debian.org/tracker/DSA-6152-1
https://security-tracker.debian.org/tracker/DSA-6149-1
https://security-tracker.debian.org/tracker/DSA-6150-1
https://security-tracker.debian.org/tracker/DSA-6151-1
https://security-tracker.debian.org/tracker/DSA-6148-1
https://security-tracker.debian.org/tracker/DSA-6124-1
Several security issues were fixed in pip.
An update that solves 76 vulnerabilities and contains one feature can now be installed.
An update that solves 76 vulnerabilities and contains one feature can now be installed.
An update that solves one vulnerability can now be installed.
Update to 1.10.2 Update was blocked by a ppc64 issue, but a workaround has been found.
Update to version 1.2026.1
https://security-tracker.debian.org/tracker/DSA-6125-1
https://security-tracker.debian.org/tracker/DSA-6126-1
https://security-tracker.debian.org/tracker/DSA-6127-1
Update to 144.0.7559.132 * CVE-2026-1861: Heap buffer overflow in libvpx * CVE-2026-1862: Type Confusion in V8
Update to version 0.50.18
Backport fixes for CVE-2026-1484, CVE-2026-1485, CVE-2026-1489.
Update to version 1.9.2. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.9.2
Release notes for xrdp v0.10.5 (2026/01/27) Security fixes CVE-2025-68670: Improper bounds checking of domain string length leads to Stack- based Buffer Overflow New features
Release notes for xrdp v0.10.5 (2026/01/27) Security fixes CVE-2025-68670: Improper bounds checking of domain string length leads to Stack- based Buffer Overflow New features
Denis Skvortsov discovered that xrdp, a Remote Desktop Protocol (RDP) server, was susceptible to an unauthenticated stack-based buffer overflow vulnerability, which may result in remote execution of arbitrary code. For the oldstable distribution (bookworm), this problem has been fixed
Update to 9.18.44 (rhbz#2431609) Security Fixes: Fix incorrect length checks for BRID and HHIT records. (CVE-2025-13878) Bug Fixes: Allow glue in delegations with QTYPE=ANY.
Update to 9.18.44 (rhbz#2431609) Security Fixes: Fix incorrect length checks for BRID and HHIT records. (CVE-2025-13878) Bug Fixes: Allow glue in delegations with QTYPE=ANY.
Update to 13.0.10.
An update that fixes one vulnerability, contains one feature is now available.
https://security-tracker.debian.org/tracker/DSA-6123-1
Sudo, a program designed to allow a sysadmin to give limited root privileges to users and log root activity, was affected by multiple vulnerabilities. CVE-2023-28486 Sudo did not escape control characters in log messages.
https://security-tracker.debian.org/tracker/DSA-6122-1
https://security-tracker.debian.org/tracker/DSA-6121-1
https://security-tracker.debian.org/tracker/DSA-6120-1
