Showing 41 of 41 items
No results in Linux.
USN-8864-1: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network file system (NFS) server daemon; - IPv6 networking; - Netfilter; (CVE-2025-38724, CVE-2026-53131…
USN-8816-4: Linux kernel (GKE) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - S390 architecture; - x86 architecture; - DRBD Distributed Replicated Block Device drivers…
USN-8818-6: Linux kernel (FIPS) vulnerabilities
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been…
USN-8851-2: Linux kernel (Raspberry Pi) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network file system (NFS) server daemon; - IPv6 networking; - Netfilter; (CVE-2025-38724, CVE-2026-53131…
DSA-6540-1 radsecproxy - security update
It was discovered that incomplete validation of MS-PPPE packets in radsecproxy, a Radius protocol proxy, could result in denial of service or potentially the execution of arbitrary code. https://security-tracker.debian.org/tracker/DSA-6540-1
DSA-6539-1 php-mongodb - security update
Multiple security vulnerabilities have been discovered in the MongoDB driver for PHP, which could result in information disclosure, PHP objection injection or denial of service. https://security-tracker.debian.org/tracker/DSA-6539-1
DSA-6534-2 webkit2gtk - regression update
The webkit2gtk update released as DSA-6534-1 introduced two regressions that cause programs such as evolution or the Eclipse IDE to crash on startup in some cases. https://security-tracker.debian.org/tracker/DSA-6534-2
DSA-6538-1 redis - security update
Multiple vulnerabilities were discovered in Redis, a persistent key-value database, which could result in denial of service or the execution of arbitrary code. This update also includes fixes for several related issues that have not been assigned CVE identifiers: ACL key permission checks for SORT…
USN-8863-1: GStreamer Good Plugins vulnerabilities
Yazan Balawneh discovered that GStreamer Good Plugins incorrectly handled certain FLAC audio streams. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-17072) Seonwook Kim discovered that GStreamer Good Plugins incorrectly parsed certain AVI files. An attacker…
USN-8862-1: libXpm vulnerability
It was discovered that libXpm did not correctly handle XPM images with zero-dimension values. A local attacker could possibly use this issue to cause libXpm to use excessive resources, leading to a denial of service.
USN-8861-1: OpenSSL vulnerabilities
It was discovered that OpenSSL had an inefficient algorithm in its QUIC stream reassembly implementation. A remote attacker could possibly use this issue to cause OpenSSL to use excessive CPU resources, leading to a denial of service. (CVE-2026-42772) It was discovered that OpenSSL did not properly…
USN-8860-1: OpenStack Designate vulnerability
It was discovered that OpenStack Designate did not properly validate overlapping zones under certain circumstances. An authenticated user could possibly use this issue to redirect DNS traffic to attacker-controlled systems or cause a denial of service.
USN-8857-1: KCoreAddons vulnerability
It was discovered that KCoreAddons incorrectly handled shell argument quoting in KShell::quoteArgs. The parsing did not adequately handle shell metacharacters, which could lead to a shell escape. An attacker could possibly use this issue to execute arbitrary commands in applications that relied on…
DSA-6534-1 webkit2gtk - security update
Several vulnerabilities have been discovered in the WebKitGTK web engine, that may lead to heap corruption, local privilege escalation, remote code execution, out-of-bounds memory access, cross-origin data leak and sandbox escape, among other problems. See the WebKitGTK security advisory for…
DSA-6536-1 thunderbird - security update
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. https://security-tracker.debian.org/tracker/DSA-6536-1
DSA-6537-1 libpng1.6 - security update
A use-after-free was discovered in libpng, a library implementing an interface for reading and writing PNG (Portable Network Graphics), which could result in denial of service. https://security-tracker.debian.org/tracker/DSA-6537-1
DSA-6535-1 chromium - security update
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6535-1
USN-8858-1: Authen::SASL vulnerability
It was discovered that Authen::SASL, a Perl authentication library, did not properly validate login attempts. An attacker could possibly use this issue to gain unauthorized access.
DSA-6533-1 firefox-esr - security update
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape, information disclosure or privilege escalation. Debian follows the extended support releases (ESR) of Firefox. Starting with this update…
DSA-6531-1 openssl - security update
Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit, which could result in denial of service, information disclosure or potentially recovery of private keys. Additional details can be found in the upstream advisories…
DSA-6532-1 tor - security update
Multiple security vulnerabilities were discovered in Tor, a connection- based low-latency anonymous communication system, would could result in denial of service. https://security-tracker.debian.org/tracker/DSA-6532-1
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre v2…
DSA-6529-1 libwebsockets - security update
It was discovered that missing input validation in the hpack path header parser of libwebsockets could result in denial of service or potentially the execution of arbitrary code. https://security-tracker.debian.org/tracker/DSA-6529-1
DSA-6530-1 pcre2 - security update
Michael Allen discovered an out-of-bounds write vulnerability in PCRE2, a library of functions to support Perl compatible regular expressions, which could result in denial of service or potentially the execution of arbitrary code. https://security-tracker.debian.org/tracker/DSA-6530-1
DSA-6528-1 linux - security update
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. https://security-tracker.debian.org/tracker/DSA-6528-1
DSA-6527-1 rsync - security update
Several vulnerabilities were discovered in rsync, a fast, versatile, remote (and local) file-copying tool, which could result in local privilege escalation, bypass of intended access restrictions, information disclosure, denial of service or the execution of arbitrary code. Details can be found at…
DSA-6525-1 wordpress - security update
Several vulnerabilities were discovered in wordpress, a web blogging tool, which could result in cross-site scripting, privilege escalation or remote code execution. https://security-tracker.debian.org/tracker/DSA-6525-1
DSA-6526-1 dovecot - security update
Multiple vulnerabilities have been discovered in the Dovecot IMAP server which could result in denial of service, SMTP smuggling, information disclosure, code injection via malformed Sieve scripts or bypass of ACL restrictions. https://security-tracker.debian.org/tracker/DSA-6526-1
DSA-6524-1 flatpak - security update
Multiple security vulnerabilities were discovered in Flatpak, an application deployment framework for desktop apps, which could result in denial service via malicious applications or information disclosure. https://security-tracker.debian.org/tracker/DSA-6524-1
DSA-6523-1 libheif - security update
Multiple security issues were discovered in libheif, an ISO/IEC 23008-12 HEIF and AVIF image file format decoder and encoder, which may result in denial of service, the disclosure of sensitive memory contents or, potentially, the execution of arbitrary code if a malformed image file is processed…
DSA-6521-1 ruby-oj - security update
Multiple security vulnerabilities were discovered in Oj, a fast JSON parser and serializer for Ruby, which could result in denial of service or memory disclosure. https://security-tracker.debian.org/tracker/DSA-6521-1
DSA-6522-1 exim4 - security update
Several vulnerabilities were discovered in the Exim mail transport agent, which could result in SMTP smuggling, information disclosure, denial of service or the execution of arbitrary code. https://security-tracker.debian.org/tracker/DSA-6522-1
DSA-6520-1 lemonldap-ng - security update
Multiple security vulnerabilities were discovered in the Lemonldap::NG web SSO system, which could result in a bypass of access controls, authorisation bypass in setups using PKCE or information disclosure. https://security-tracker.debian.org/tracker/DSA-6520-1
DSA-6517-1 nodejs - security update
Multiple vulnerabilities were discovered in Node.js, which could result in denial of service, permission model bypass, incorrect certificate validation or information disclosure. https://security-tracker.debian.org/tracker/DSA-6517-1
DSA-6519-1 swift - security update
A vulnerability was discovered in the Swift tempurl middleware, which could result in information disclosure. https://security-tracker.debian.org/tracker/DSA-6519-1
DSA-6518-1 incus - security update
Multiple security issues were discovered in Incus, a system container and virtual machine manager, which could result in a bypass of security/authorisation restrictions, guest to host privilege escalation or information disclosure. https://security-tracker.debian.org/tracker/DSA-6518-1
DSA-6513-1 chromium - security update
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6513-1
DSA-6515-1 vlc - security update
Multiple vulnerabilities were discovered in the VLC media player, which could result in the execution of arbitrary code or denial of service if a malformed media file is opened. https://security-tracker.debian.org/tracker/DSA-6515-1
DSA-6516-1 ghostscript - security update
Multiple security issues were discovered in Ghostscript, the GPL PostScript/PDF interpreter, which could result in denial of service and potentially the execution of arbitrary code if malformed document files are processed. https://security-tracker.debian.org/tracker/DSA-6516-1
DSA-6416-2 jq - regression update
The update for jq released as DSA-6416-1 introduced a regression in the loading of modules. The fix for CVE-2026-44777 registered each library before its own dependencies, so a module reached only through another module (a transitive import or include) was discarded as unreferenced and jq aborted…
DSA-6514-1 php8.4 - security update
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in denial of service, information disclosure, incorrect validation of TLS certificates or bypass of access control restrictions…