Menu

Quote

https://security-tracker.debian.org/tracker/DSA-6119-1

MGASA-2026-0032 – Updated python-django packages fix security vulnerabilities

MGAA-2026-0011 – Updated yt-dlp packages fix bugs

This update bumps the bundled lodash to 4.17.23 to ensure openQA is protected against CVE-2025-13465. It likely was not vulnerable in any case, though, as I don’t believe the vulnerable codepaths were exposed by openQA’s use of lodash.

Regenerate vendor tarball. Fixes CVE-2025-13465.

Regenerate vendor tarball. Fixes CVE-2025-13465.

Version 12.5.8 – 2026-01-27 Changed To prevent Poisoned Pipeline Execution (PPE) attacks using prepared .coverage files in pull requests, a PHPT test will no longer be run if the temporary file for writing code coverage information already exists before the test runs

Multiple vulnerabilities were discovered in containerd, an open-source container runtime, used by e.g. Docker or Kubernetes. CVE-2024-25621 Overly broad default permission vulnerability. Directory paths `/var/lib/containerd`, `/run/containerd/io.containerd.grpc.v1.cri`

MGAA-2026-0010 – Updated libformula & ant-contrib packages fix bug

Fix CVE-2026-24882: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution

Regenerate vendor tarball. Fixes CVE-2025-13465.

Regenerate vendor tarball. Fixes CVE-2025-13465.

Version 12.5.8 – 2026-01-27 Changed To prevent Poisoned Pipeline Execution (PPE) attacks using prepared .coverage files in pull requests, a PHPT test will no longer be run if the temporary file for writing code coverage information already exists before the test runs

https://security-tracker.debian.org/tracker/DSA-6118-1

A security issue was discovered in Thunderbird, which could result in information disclosure. For Debian 11 bullseye, this problem has been fixed in version 1:140.7.1esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.

An update that solves three vulnerabilities and has one security fix can now be installed.

An update that solves three vulnerabilities and has one security fix can now be installed.

Several security issues were fixed in ImageMagick.

Several security issues were fixed in MySQL.

MGAA-2026-0009 – Updated subversion packages fix bug

xrdp is an open source RDP server. It was found that xrdp contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code

Several security issues were fixed in CRaC JDK 21.

Several security issues were fixed in OpenJDK 21.

Several security issues were fixed in OpenJDK 8.

Several security issues were fixed in OpenJDK 11.

15.x 15.1 (2026-01-24) Fix #15088: When building a new train, the refit button state may be incorrect (#15162) Fix #15160: Incorrect company names displayed in load game window (#15161)

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves five vulnerabilities and contains one feature can now be installed.

An update that solves five vulnerabilities and contains one feature can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that fixes one vulnerability is now available.

Multiple vulnerabilities have been found in Pillow, an image processing library for Python. CVE-2021-23437 The getrgb function is susceptible to a ReDoS. CVE-2022-24303

Ceph is a distributed object, block, and file storage platform. CVE-2022-0670 A flaw was found in Openstack manilla owning a Ceph File system “share”, which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the

Tornado is a scalable, non-blocking Python web framework and asynchronous networking library. CVE-2025-67724 Custom reason phrases can cause multiple vulnerabilities (like XSS, header injection, …) due to being used unescaped in HTTP headers.

Update to 0.46.3, fixes CVE-2026-24049.

Security fix for CVE-2026-24049

Fix CVE-2025-15536

MGAA-2026-0008 – Updated remove-old-kernels packages fix bugs

https://security-tracker.debian.org/tracker/DSA-6117-1

Moderate: glibc security update

Important: openssl security update

Moderate: curl security update

Important: openssl security update

Moderate: gcc-toolset-15-binutils security update

A security issue was discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), this problem has been fixed in version 144.0.7559.109-1~deb12u1.

An update that solves seven vulnerabilities can now be installed.

MGASA-2026-0029 – Updated openssl packages fix security vulnerabilities

MGASA-2026-0028 – Updated gpsd packages fix security vulnerabilities

MGASA-2026-0027 – Updated libxml2 packages fix security vulnerabilities

MGASA-2026-0026 – Updated xen packages fix security vulnerabilities

https://security-tracker.debian.org/tracker/DSA-6116-1

https://security-tracker.debian.org/tracker/DSA-6114-1

Several security issues were fixed in containerd.

Several security issues were fixed in wlc.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves seven vulnerabilities can now be installed.

Upgrade to upstream. Eliminates distributing harfbuzz sources. Upgrade to upstream 0.032.

https://security-tracker.debian.org/tracker/DSA-6115-1

https://security-tracker.debian.org/tracker/DSA-6113-1

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

# Recommended update for kernel-firmware Announcement ID: SUSE-SU-2026:0305-1 Release Date: 2026-01-27T16:15:14Z Rating: important References:

An update that solves two vulnerabilities can now be installed.

https://security-tracker.debian.org/tracker/DSA-6111-1

An update that solves 22 vulnerabilities, contains one feature and has six security fixes can now be installed.

An update that solves 22 vulnerabilities, contains one feature and has six security fixes can now be installed.

An update that solves 22 vulnerabilities, contains one feature and has six security fixes can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect certificate validation, CRLF injection or man-in-the-middle attacks. For the stable distribution (trixie), these problems have been fixed in version 21.0.10+7-1~deb13u1.

https://security-tracker.debian.org/tracker/DSA-6112-1

An update that solves 395 vulnerabilities, contains 29 features and has 43 security fixes can now be installed.

An update that solves seven vulnerabilities and has one security fix can now be installed.

An update that solves seven vulnerabilities and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect certificate validation, CRLF injection or man-in-the-middle attacks. For the oldstable distribution (bookworm), these problems have been fixed in version 17.0.18+8-1~deb12u1.

An update that solves one vulnerability and has 2 bug fixes can now be installed.

An update that solves 4 vulnerabilities and has 5 bug fixes can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

https://security-tracker.debian.org/tracker/DSA-6110-1

https://security-tracker.debian.org/tracker/DSA-6109-1

Security fix for CVE-2025-12084

Security fix for CVE-2025-12084

https://security-tracker.debian.org/tracker/DSA-6102-2

https://security-tracker.debian.org/tracker/DSA-6108-1

https://security-tracker.debian.org/tracker/DSA-6107-1

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves two vulnerabilities can now be installed.

An update that solves seven vulnerabilities can now be installed.

An update that solves 392 vulnerabilities, contains 16 features and has 47 security fixes can now be installed.