Debian 11040 Published by Philipp Esselbach 0

Debian published six security and bugfix advisories, delivering updated packages for python-httplib2, unzip, zip, util-linux, postgresql-15, and ca-certificates-java across the stable trixie and bookworm distributions. The python-httplib2 patch resolves an unbounded decompression flaw that could cause a denial of service, while refreshed unzip and zip utilities block arbitrary code execution and command injection attacks triggered by malformed archive inputs. Operators need to upgrade util-linux to neutralize multiple privilege escalation risks, and postgresql-15 administrators must apply a configuration tweak to lock down logical decoding output plugins after patching over two dozen CVEs that previously allowed unauthorized access or data leaks. Applying these package updates immediately will close the newly disclosed vulnerabilities and keep affected systems aligned with current security baselines.

[DSA 6441-1] python-httplib2 security update
[DSA 6440-1] unzip security update
[DSA 6439-1] zip security update
ELA-1809-1 ca-certificates-java bugfix update (by )
[DSA 6442-1] util-linux security update
[DLA 4740-1] postgresql-15 security update

Debian 11040 Ubuntu 7183 Arch Linux 990 Published by Philipp Esselbach 0

Steven Barrett has released Liquorix Kernel 7.1-12, continuing a rapid four-day iteration cycle with eleven targeted patches to Project-C, the project's custom sched/alt scheduler. The update prioritizes reduced task-switching overhead through improved fork handling, hybrid CPU idle-mask tracking, and atomic operation reductions designed specifically for gaming and audio production workloads. While AMD64 users can upgrade immediately via the official repositories, the project currently hosts several open AMDGPU stability reports that may warrant monitoring before switching from stock kernels. Users looking to install the latest build can pull it directly from the Debian, Ubuntu, or Arch Linux repositories today.

Debian 11040 Published by Philipp Esselbach 0

Debian has released latest security patches to address flaws across xorg-server, Chromium, PostgreSQL 17, apr-util, xdg-dbus-proxy, and python-django. The advisories target race conditions, stack buffer overflows, use-after-free errors, and malformed request handling that could allow privilege escalation, arbitrary code execution, or data exposure. Each affected package now includes fixed versions for Debian 11, Debian 12, and the Debian 13 stable distribution.

[DLA 4738-1] xorg-server security update
[DLA 4737-1] xorg-server security update
[DSA 6433-1] xdg-dbus-proxy security update
ELA-1808-1 python-django security update (by )
[DSA 6437-1] apr-util security update
[DSA 6436-1] chromium security update
[DLA 4739-1] chromium security update
[DSA 6438-1] postgresql-17 security update

Debian 11040 Published by Philipp Esselbach 0

Debian and Freexian LTS distributions released security patches addressing more than forty CVEs across BIND DNS, PHP, Django, Flatpak, and several other widely used packages. The BIND9 update backports the software from Debian 10 to stretch, which fixes thirteen CVEs but breaks binary compatibility and requires third-party applications to rebuild against the new libraries. PHP 7.0 and 7.3 patches eliminate stack exhaustion crashes in phar archives and close a SQL injection route in the psql extension, while Django updates block a denial-of-service trigger and cross-site scripting flaws in the admin interface. Additional fixes target Flatpak local privilege escalation, SPIP remote code execution, Neutron network state mutation, jq arbitrary code execution, and libgd2 malformed GIF processing.

ELA-1802-1 bind9 security update (by )
ELA-1801-1 jq security update (by )
ELA-1803-1 ca-certificates CA certificates update (by )
ELA-1802-1 bind9 security update (by )
ELA-1807-1 php7.0 security update (by )
ELA-1806-1 php7.3 security update (by )
ELA-1805-1 libgd2 security update (by )
ELA-1804-1 libconfig-inifiles-perl security update (by )
[DLA 4735-1] neutron security update
[DSA 6434-1] lemonldap-ng security update
[DSA 6432-1] flatpak security update
[DLA 4736-1] python-django security update
[DSA 6435-1] spip security update

Debian 11040 Ubuntu 7183 Arch Linux 990 Published by Philipp Esselbach 0

Liquorix Kernel 7.1-11 drops a focused stability fix that hardens memory protection in the cgroup/dmem and drm/ttm subsystems to prevent race conditions during high-contention scenarios. The update builds on upstream Linux 7.1.8 and applies a single defensive patch to the scheduler and GPU buffer management paths, which helps gamers and video editors avoid sudden freezes or kernel panics while streaming or rendering. Debian and Ubuntu users can grab the package through the official PPA via a one-line install script, while Arch Linux builders pull the linux-lqx package straight from the AUR without relying on third-party wrapper tools.

Debian 11040 Published by Philipp Esselbach 0

Debian has released six security patches released to address critical flaws across NSS, Postfix, PHP 7.4, PHP 8.2, OpenJDK 25, and libgd2. These updates resolve CVEs that enable arbitrary code execution through malformed certificates, SQL injection via backslash escaping errors, denial of service from unbounded recursion, and invalid certificate validation in Java archives. The advisory provides exact version numbers for Debian Stretch through Trixie, ensuring each affected package receives a targeted version bump. Users should deploy these patches through their standard package managers to eliminate the identified vulnerabilities across their respective operating systems.

ELA-1800-1 nss security update (by )
[DSA 6430-1] postfix security update
[DLA 4733-1] php7.4 security update
[DLA 4732-1] php8.2 security update
[DSA 6431-1] openjdk-25 security update
[DLA 4731-1] libgd2 security update

Debian 11040 Ubuntu 7183 Arch Linux 990 Published by Philipp Esselbach 0

Steven Barrett has released linux-liquorix 7.1-10, a performance-focused kernel package built on top of upstream Linux v7.1.8 for Debian and Ubuntu users. The release re-applies a scheduler patch that disables the TTWU wakelist code path, prioritizing lower latency for gaming and real-time audio workloads over theoretical throughput gains. While the upstream merge brings standard security updates and hardware enablement, the maintainer continues to fine-tune the kernel for deterministic responsiveness.

Debian 11040 Published by Philipp Esselbach 0

Debian issued security patches for a wide range of packages including Chromium, Thunderbird, Icinga 2, OpenJDK 21, NSS, WordPress, Caddy, libyaml-syck-perl, and libinput to address dozens of new CVEs. The updates mitigate risks ranging from arbitrary code execution and denial of service to privilege escalation and information disclosure, with Chromium resolving 57 vulnerabilities and Thunderbird fixing over 30 flaws across multiple Debian versions. Users should upgrade to the recommended versions immediately, keeping in mind that Icinga 2 and Caddy require manual intervention for specific configuration changes related to logrotate files and header handling. Legacy systems remain protected as well, with extended support advisories releasing fixes for libinput on Debian 9, 10, and 11 to patch local privilege escalation and code execution flaws.

[DLA 4728-1] chromium security update
[DLA 4727-1] thunderbird security update
[DSA 6426-1] icinga2 security update
[DSA 6425-1] openjdk-21 security update
[DLA 4729-1] nss security update
[DSA 6427-1] wordpress security update
[DSA 6429-1] caddy security update
[DLA 4730-1] libyaml-syck-perl security update
[DSA 6428-1] libyaml-syck-perl security update
ELA-1799-1 libinput security update (by )
ELA-1798-1 libinput security update (by )

Debian 11040 Ubuntu 7183 Published by Philipp Esselbach 0

XanMod released updated kernel builds today, introducing Linux 7.1.8-xanmod1 for the rolling mainline branch and Linux 6.18.44-xanmod1 for the long-term support line. The updates also include a real-time variant at 6.18.44-rt-xanmod1, featuring XanMod's custom optimizations such as LLVM ThinLTO compilation, AMD 3D V-Cache tuning, Cloudflare TCP Collapse, and native Steam Deck EC sensor support. Both branches incorporate extensive upstream fixes spanning graphics, networking, and security, with the LTS branch maintaining stability and support through December 2028. Users can install these builds via the XanMod APT repository across major Debian and Ubuntu derivatives, selecting from x86_64 ABI packages ranging from x64v1 to x64v3 to match their specific CPU generation.

Debian 11040 Published by Philipp Esselbach 0

Debian released three security updates to address critical vulnerabilities in kitty, xen, and ca-certificates. The kitty patch fixes four terminal emulator flaws that could let attackers run arbitrary code or overwrite files through malicious display content. System administrators must upgrade xen to close twenty-seven hypervisor vulnerabilities that risk privilege escalation, data exposure, or service outages. The ca-certificates advisory for Debian 11 and 12 refreshes Mozilla's trusted certificate bundle by adding twenty-four new authorities and removing fifteen expired ones.

[DSA 6423-1] kitty security update
[DSA 6424-1] xen security update
[DLA 4726-1] ca-certificates CA certificate update

Debian 11040 Published by Philipp Esselbach 0

Debian published multiple security advisories to patch critical flaws across PowerDNS, Nginx, Chromium, and Bind9. The updates resolve CVE-2026-52682 in pdns-recursor, pdns, and dnsdist, which could trigger denial of service attacks through malformed DNS packets. The advisory also covers Nginx, which requires updates to patch proxy and charset module flaws, alongside Chromium, which addresses forty-one distinct vulnerabilities that could enable arbitrary code execution or memory disclosure. Bind9 receives the most extensive corrections, sealing flaws that previously enabled cache poisoning, DNSSEC validation bypass, and unbounded memory consumption.

[DSA 6421-1] pdns-recursor security update
[DSA 6420-1] pdns security update
[DSA 6419-1] dnsdist security update
ELA-1797-1 nginx security update (by )
[DSA 6422-1] chromium security update
[DLA 4725-1] bind9 security update

Debian 11040 Published by Philipp Esselbach 0

Debian and Freexian issued a series of security advisories to patch critical flaws across Linux kernels, Thunderbird, Nginx, Redis, and libheif on multiple Debian releases. The kernel updates for versions 6.1 and 6.12 address dozens of common vulnerabilities that could allow attackers to escalate privileges, leak memory, or crash systems. Separate advisories cover remote code execution risks in Thunderbird and Nginx, a heap overflow in the Redis RESTORE command, and memory safety issues in the libheif image decoder. System administrators should manually install the updated packages through their package managers to apply these fixes immediately.

[DLA 4724-1] linux-6.12 new package
[DLA 4723-1] linux-6.1 security update
ELA-1796-1 linux-6.1 security update (by )
ELA-1795-1 redis security update (by )
[DSA 6417-1] libheif security update
[DSA 6418-1] thunderbird security update
ELA-1797-1 nginx security update (by )

Debian 11040 Published by Philipp Esselbach 0

Debian security teams released a batch of advisories to address multiple flaws across seven widely used packages. The updates patch remote code execution risks in the p7zip archiver, potential memory corruption in the libde265 video codec, a local privilege escalation in udisks2, cookie injection flaws in the async-http-client Java library, denial of service and arbitrary code execution threats in the jq JSON processor, a double-free memory bug in Redis, and dozens of kernel-level privilege escalation and information leak issues. Patched builds are now available for the trixie stable release alongside older LTS branches, with the Linux kernel jumping to 6.12.101 and Redis reaching 5.0.14 on Debian 10.

ELA-1794-1 p7zip security update (by )
[DSA 6413-1] libde265 security update
[DSA 6414-1] udisks2 security update
[DLA 4721-1] async-http-client security update
[DSA 6415-1] linux security update
[DSA 6416-1] jq security update
[DLA 4722-1] redis security update

Debian 11040 Ubuntu 7183 Arch Linux 990 Published by Philipp Esselbach 0

Steven Barrett has released Liquorix Linux kernel 7.1-9, shifting focus from feature additions to stabilizing "Project-C,". The release bundles roughly eleven patches, including eight direct upstream syncs that align Project-C with current mainline scheduler development alongside Liquorix-specific hardening tweaks like default latency warning suppression. AMD64 users can install the kernel via the official script or distribution PPAs, though those with AMDGPU hardware should exercise caution as several open issues report hard freezes on integrated graphics. This point release marks a deliberate move toward upstream parity and maintenance consolidation after a rapid development sprint throughout the 7.1 series.

Debian 11040 Published by Philipp Esselbach 0

Debian LTS issued advisory DLA-4717-1 to update the Linux 5.10 kernel to version 5.10.262-1, addressing dozens of CVEs that could enable privilege escalation, denial of service, or information leaks on Debian 9, 10, and 11 systems. Advisory DLA-4720-1 brings kernel version 6.1.180-1 to Debian 12, resolving comparable security issues and adding fixes for earlier vulnerabilities like CVE-2024-36013. The p7zip package undergoes a significant replacement with 7-Zip version 26.02 under advisory DLA-4719-1, eliminating CVE-2026-14266 which permits remote code execution via XZ heap buffer overflow and CVE-2026-58052 that risks file content spoofing on RAR5 archives. Direct 7zip packages also advance to version 26.02 for Debian 12, while FreeXian extends these p7zip and kernel fixes to Debian 9 and 10 through ELA-1793-1 and ELA-1794-1 for extended lifecycle support.

[DLA 4717-1] linux security update
ELA-1793-1 linux-5.10 security update (by )
[DLA 4720-1] linux security update
[DLA 4719-1] p7zip security update
[DLA 4718-1] 7zip security update
ELA-1794-1 p7zip security update (by )

Debian 11040 Ubuntu 7183 Arch Linux 990 Published by Philipp Esselbach 0

Liquorix kernel 7.1-8 just landed, tracking upstream Linux 7.1.6 and bringing enhanced ACS override support for GPU passthrough enthusiasts. Maintainer Steven Barrett shipped the build on August 4, continuing an aggressive four-day turnaround that mirrors upstream stable point releases. The update pulls in modern hardware support including NTFSPLUS, Apple Silicon power reporting for Asahi users, and Intel FRED enabled by default for Arrow Lake processors. You're getting the usual PDS-scheduling and 2ms timeslice tweaks that make Liquorix a favorite for gaming and low-latency workloads, though you should retest your drivers before rebooting.

Debian 11040 Published by Philipp Esselbach 0

Debian released DLA-4716-1 to patch four vulnerabilities in ruby2.7, including a DNS decompression flaw that triggers denial of service and an ERB deserialization bug that allows arbitrary code execution on untrusted data. The botan3 advisory addresses CVE-2026-44378 by upgrading the C++ cryptography library to version 3.12.0, which resolves certificate validation and authentication bypass flaws while renaming the shared library package from libbotan-3-7 to libbotan-3-12.

[DLA 4716-1] ruby2.7 security update
[DSA 6412-1] botan3 security update
[DSA 6411-1] aom security update

Debian 11040 Published by Philipp Esselbach 0

Debian released ELA-1791-1 and ELA-1792-1 to patch critical security flaws in OpenJDK 8 version 8u502-ga-1~deb9u1 and Poppler across stretch and buster distributions. The Java runtime update addresses ten vulnerabilities that could enable denial of service attacks, unauthorized data access, or sandbox restriction bypasses. Poppler patches six PDF processing flaws, including signature forgery risks, infinite recursion crashes, use-after-free memory corruption, and integer overflow errors that enable arbitrary code execution.

ELA-1791-1 openjdk-8 security update (by )
ELA-1792-1 poppler security update (by )

Debian 11040 Ubuntu 7183 Published by Philipp Esselbach 0

XanMod just published two new performance kernels today: the flagship 7.1.6-xanmod1 and the long-term support track at 6.18.42-xanmod1. The 7.1 series finally makes multigenerational LRU and sched_ext defaults production-ready, while XanMod's out-of-tree patches bake in Google's BBRv3 congestion algorithm, Cloudflare TCP collapse processing, and a dedicated AMD 3D V-Cache optimizer. You can grab precompiled packages across four CPU architecture tiers from the official APT repository, alongside DKMS modules for NVIDIA, OpenZFS, VirtualBox, and VMware.

Debian 11040 Ubuntu 7183 Published by Philipp Esselbach 0

Debian and Ubuntu users pulling from DEB.SURY.ORG received a coordinated batch of PHP updates across all active branches, led by PHP 8.4.24 and the development release 8.5.9. The July 30 patch cycle addresses high-severity vulnerabilities including a BCMath out-of-bounds write and a PostgreSQL SQL injection via pg_query(), alongside significant opcache stability fixes for the JIT. This three-week gap from the previous release indicates an emergency response to newly disclosed critical CVEs, prompting SURY to push security-only updates to both current stable and end-of-life approaching branches. Operators should upgrade immediately via apt-get update and verify GPG signatures, though 8.5 users are advised to test carefully due to the heavy changes to the tracing JIT and default OpCache behavior.