Menu

Quote

Update to xserver 21.1.24, fixes for: CVE-2026-55999, CVE-2025-56000

This update, to the current upstream release, addresses a cryptographic flaw (modulo bias) in key generation that could lead to private key compromise (CVE-2026-14570) .

Update to 6.5.7 – CVE-2026-35536 (rhbz#2457335), CVE-2026-31958 (rhbz#2451660)

Update to log4cxx 1.7.0. New features: fallback-ref appender attribute, Qt CMake find_package component, TelnetAppender NonBlocking option. Bug fixes: non-ASCII JSON encoding, invalid XML 1.0 characters in XML output, crash on recursive XML config references, possible UB during

Update to 150.0.7871.114 * CVE-2026-15112: Use after free in Ozone * CVE-2026-15129: Use after free in Views * CVE-2026-15132: Uninitialized Use in V8 * CVE-2026-15133: Use after free in InterestGroups

fdf6afc update to 3.7b fixes rhbz#2498485 CHANGES FROM 3.7a TO 3.7b Fix so that the end of a synchronized update again triggers a redraw. CHANGES FROM 3.7 TO 3.7a Fix crash in break-pane when no name is provided.

libXfont2 2.0.8 (CVE-2026-56001, CVE-2026-56002, CVE-2026-56003)

upower 1.91.3: Feature: up-device-battery: Prefer “Standard” over “Fast” charging (!316 (merged), #344 (closed)) Fix: Resolve potential leaks (!327 (merged)) Fix: Potential out-of-bound access (!328 (merged))

Update to xwayland 24.1.13, fixes for: CVE-2026-55999, CVE-2026-56000

This update, to the current upstream release, addresses a cryptographic flaw (modulo bias) in key generation that could lead to private key compromise (CVE-2026-14570) .

Update to 6.5.7 – CVE-2026-35536 (rhbz#2457335), CVE-2026-31958 (rhbz#2451660)

This update addresses a few security issues, one of which could plausibly result in remote code execution.

Security update

https://security-tracker.debian.org/tracker/DSA-6386-1

An update that solves 10 vulnerabilities and has one security fix can now be installed.

An update that solves 28 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

Kate Deplaix reported that .install file directives were insufficiently restricted in OPAM, a package manager for OCaml. Installing files through .install files did not check symlinks resolution on the target path, which could result in directory traversal out of the package area. For the stable distribution (trixie), this problem has been fixed in

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves nine vulnerabilities, contains one feature and has 12 fixes can now be installed.

An update that solves one vulnerability, contains one feature and has 16 fixes can now be installed.

An update that solves 13 vulnerabilities, contains one feature and has 11 fixes can now be installed.

An update that contains one feature and has 19 fixes can now be installed.

An update that solves two vulnerabilities and has 26 fixes can now be installed.

An update that solves five vulnerabilities and has nine fixes can now be installed.

An update that solves three vulnerabilities and has 12 fixes can now be installed.

An update that solves three vulnerabilities, contains one feature and has 25 fixes can now be installed.

An update that solves one vulnerability and has 16 fixes can now be installed.

An update that solves 8 vulnerabilities and has 9 bug fixes can now be installed.

Security update

An update that solves 7 vulnerabilities can now be installed.

An update that solves 7 vulnerabilities can now be installed.

An update that solves 5 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 3 vulnerabilities can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that fixes two vulnerabilities is now available.

An update that fixes 27 vulnerabilities is now available.

An update that solves five vulnerabilities, contains one feature and has three security fixes can now be installed.

An update that solves two vulnerabilities, contains one feature and has three security fixes can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

# Security update for python-sqlparse Announcement ID: SUSE-SU-2026:2821-1 Release Date: 2026-07-09T18:05:57Z Rating: moderate References:

An update that solves 12 vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves 27 vulnerabilities can now be installed.

An update that solves eight vulnerabilities and has one security fix can now be installed.

An update that solves eight vulnerabilities and has one security fix can now be installed.

An update that solves 19 vulnerabilities can now be installed.

An update that solves 19 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities and has two security fixes can now be installed.

An update that solves 11 vulnerabilities and has two security fixes can now be installed.

An update that solves 10 vulnerabilities and has two security fixes can now be installed.

An update that solves eight vulnerabilities can now be installed.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-6385-1

An update that solves one vulnerability can now be installed.

An update that solves three vulnerabilities can now be installed.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For Debian 12 bookworm, this problem has been fixed in version 150.0.7871.100-1~deb12u1.

Update to opkssh 0.15.0. This release fixes several CVEs in bundled/vendored dependencies: CVE-2026-39829: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39835: golang.org/x/crypto/ssh: Denial of Service via crafted SSH

This package contains the Perl module CSS::Minifier::XS. Versions of the module before 0.14 have a memory leak when the entire document is minified away (CVE-2026-13593). This update brings version 0.15 which fixes this issue.

Update rust-jiter to 0.16.0, adding a serde Deserializer implementation; update python-jiter to match. Both packages now use PyO3 0.29, with fixes for RUSTSEC-2026-0176 and RUSTSEC-2026-0177.

Update rust-jiter to 0.16.0, adding a serde Deserializer implementation; update python-jiter to match. Both packages now use PyO3 0.29, with fixes for RUSTSEC-2026-0176 and RUSTSEC-2026-0177.

Improve GSS KEX algorithms documentation CVE-2026-55653: Fix double free in openssh DH-GEX client path during FIPS known- group validation that leads to client-side denial of service CVE-2026-55654: Fix heap out-of-bounds read during GSSAPI indicator cleanup due to missing NULL terminator

upower 1.91.3: Feature: up-device-battery: Prefer “Standard” over “Fast” charging (!316 (merged), #344 (closed)) Fix: Resolve potential leaks (!327 (merged)) Fix: Potential out-of-bound access (!328 (merged))

Update to opkssh 0.15.0. This release fixes several CVEs in bundled/vendored dependencies: CVE-2026-39829: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39835: golang.org/x/crypto/ssh: Denial of Service via crafted SSH

This package contains the Perl module CSS::Minifier::XS. Versions of the module before 0.14 have a memory leak when the entire document is minified away (CVE-2026-13593). This update brings version 0.15 which fixes this issue.

Update to 3.2.0 (final). Update PyO3 to 0.29, fixing RUSTSEC-2026-0176 and RUSTSEC-2026-0177.

Update to 0.3.6; this includes an update to PyO3 0.29, which fixes RUSTSEC-2026-0176 and RUSTSEC-2026-0177.

Update rust-jiter to 0.16.0, adding a serde Deserializer implementation; update python-jiter to match. Both packages now use PyO3 0.29, with fixes for RUSTSEC-2026-0176 and RUSTSEC-2026-0177.

Update rust-jiter to 0.16.0, adding a serde Deserializer implementation; update python-jiter to match. Both packages now use PyO3 0.29, with fixes for RUSTSEC-2026-0176 and RUSTSEC-2026-0177.

An update that solves 168 vulnerabilities, contains three features and has 14 security fixes can now be installed.

An update that solves 105 vulnerabilities, contains three features and has 12 security fixes can now be installed.

https://security-tracker.debian.org/tracker/DSA-6383-1