AlmaLinux 2538 Published by Philipp Esselbach 0

AlmaLinux 2538 Published by Philipp Esselbach 0

The AlmaLinux Security team has issued two updates: one for libxml2, rated as Moderate (CVE-2025-9714), and another for expat, rated as Important (CVE-2025-59375). The libxml2 update fixes an infinite recursion issue in the exsltDynMapFunction function of libexslt. The expat update addresses a vulnerability that allows attackers to trigger large dynamic memory allocations through parsing small XML documents.

ALSA-2025:22376: libxml2 security update (Moderate)
ALSA-2025:22175: expat security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

AlmaLinux has released several security updates. These updates include fixes for sssd, tigervnc, pcs, bind9.18, openssl, valkey, kernel, gimp, mingw-expat, cups, and libssh. The severity of the updates varies from moderate to important, indicating a range of potential risks if not addressed promptly. Users should review the available security updates and apply them as necessary to ensure the integrity and security of their AlmaLinux system.

ALSA-2025:20954: sssd security update (Important)
ALSA-2025:20958: tigervnc security update (Important)
ALSA-2025:20962: pcs security update (Important)
ALSA-2025:21111: bind9.18 security update (Important)
ALSA-2025:21255: openssl security update (Moderate)
ALSA-2025:21916: valkey security update (Important)
ALSA-2025:21926: kernel security update (Moderate)
ALSA-2025:21968: gimp security update (Important)
ALSA-2025:21974: mingw-expat security update (Important)
ALSA-2025:22063: cups security update (Moderate)
ALSA-2025:21977: libssh security update (Moderate)

AlmaLinux 2538 Published by Philipp Esselbach 0

Several security updates have been released for AlmaLinux. The most critical updates include patches for podman, python-kdcproxy, firefox, and bind, which all have a severity level of "Important." In addition to these high-priority updates, there are also several moderate-severity updates for various packages such as openssh, openssl, and kernel-rt.

ALSA-2025:20983: podman security update (Important)
ALSA-2025:21220: podman security update (Important)
ALSA-2025:21142: python-kdcproxy security update (Important)
ALSA-2025:21691: haproxy security update (Important)
ALSA-2025:21281: firefox security update (Important)
ALSA-2025:21248: openssl security update (Moderate)
ALSA-2025:20126: openssh security update (Moderate)
ALSA-2025:20478: zziplib security update (Moderate)
ALSA-2025:20095: kernel security update (Moderate)
ALSA-2025:21816: delve and golang security update (Moderate)
ALSA-2025:21843: thunderbird security update (Important)
ALSA-2025:21035: xorg-x11-server-Xwayland security update (Moderate)
ALSA-2025:20145: shadow-utils security update (Low)
ALSA-2025:21034: bind security update (Important)
ALSA-2025:21032: libsoup3 security update (Important)
ALSA-2025:21030: expat security update (Important)
ALSA-2025:20155: binutils security update (Moderate)
ALSA-2025:21015: vim security update (Moderate)
ALSA-2025:21013: libssh security update (Moderate)
ALSA-2025:20181: pam security update (Important)
ALSA-2025:21002: squid security update (Important)
ALSA-2025:20998: libtiff security update (Important)
ALSA-2025:22011: buildah security update (Important)
ALSA-2025:22005: go-rpm-macros security update (Moderate)
ALSA-2025:21280: firefox security update (Important)
ALSA-2025:20909: podman security update (Important)
ALSA-2025:21881: thunderbird security update (Important)
ALSA-2025:21917: kernel security update (Moderate)
ALSA-2025:21920: kernel-rt security update (Moderate)

AlmaLinux 2538 Published by Philipp Esselbach 0

AlmaLinux 10.1, codenamed "Heliotrope Lion," has been released with several key updates. The new release includes full Btrfs support, allowing users to install it directly onto a Btrfs filesystem without additional configuration, as well as expanded hardware compatibility for older x86_64_v2 processors through an EPEL variant. AlmaLinux 10.1 also offers performance gains, improved virtualization capabilities, enhanced security features, and updated tools such as compilers, debuggers, and monitoring utilities. One notable difference between AlmaLinux 10.1 and its upstream source, RHEL, is that it continues to support older x86_64_v2 CPUs, providing an option for users who may still depend on or prefer the specific binaries from RHEL.

AlmaLinux 2538 Published by Philipp Esselbach 0

AlmaLinux has released several security updates, including important fixes for container-tools (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881), pcs (CVE-2025-59830, CVE-2025-61770, CVE-2025-61771, CVE-2025-61772, CVE-2025-61919), idm:DL1 (CVE-2025-59088, CVE-2025-59089), and expat (CVE-2025-59375). Additionally, there are moderate updates for kernel-rt (CVE-2025-39718) and delve and golang (CVE-2025-58183).

ALSA-2025:21232: container-tools:rhel8 security update (Important)
ALSA-2025:19719: pcs security update (Important)
ALSA-2025:21140: idm:DL1 security update (Important)
ALSA-2025:21776: expat security update (Important)
ALSA-2025:21397: kernel-rt security update (Moderate)
ALSA-2025:21398: kernel security update (Moderate)
ALSA-2025:21815: delve and golang security update (Moderate)

AlmaLinux 2538 Published by Philipp Esselbach 0

New AlmaLinux updates are available with critical and important fixes. Moderate-severity updates are also present for various packages such as kernel, libssh, vim, xorg-x11-server, and others.

ALSA-2025:21628: lasso security update (Critical)
ALSA-2025:19931: kernel security update (Moderate)
ALSA-2025:20956: libtiff security update (Important)
ALSA-2025:20943: libssh security update (Moderate)
ALSA-2025:20945: vim security update (Moderate)
ALSA-2025:20961: xorg-x11-server security update (Moderate)
ALSA-2025:20960: xorg-x11-server-Xwayland security update (Moderate)
ALSA-2025:20959: libsoup security update (Important)
ALSA-2025:20935: squid security update (Important)
ALSA-2025:20936: sqlite security update (Important)
ALSA-2025:20922: webkit2gtk3 security update (Important)
ALSA-2025:20838: zziplib security update (Moderate)
ALSA-2025:20559: shadow-utils security update (Low)
ALSA-2025:20532: grub2 security update (Moderate)
ALSA-2025:20518: kernel security update (Moderate)
ALSA-2025:20926: redis security update (Important)
ALSA-2025:19950: bind9.18 security update (Important)
ALBA-2025:20841: open-vm-tools bug fix and enhancement update (Moderate)
ALSA-2025:21110: bind security update (Important)
ALSA-2025:20957: runc security update (Important)
ALSA-2025:21702: podman security update (Important)
ALSA-2025:21462: lasso security update (Critical)
ALSA-2025:20963: qt5-qt3d security update (Moderate)
ALSA-2025:21693: haproxy security update (Important)
ALSA-2025:20955: redis:7 security update (Important)
ALSA-2025:21139: python-kdcproxy security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

AlmaLinux 9.7 has been released, bringing numerous updates focused on performance, developer tools, and security. This release includes improvements to system responsiveness through updated core libraries like Glibc and Annobin, as well as new compiler toolsets such as GCC Toolset 15 and LLVM Toolset 20.1.8. Networking support has also been enhanced with updates for NetworkManager, iproute, and ethtool, while security buffs will appreciate revised SELinux policies and newer versions of SSSD and Keylime. OpenSSL 3.5, which supports post-quantum cryptography, and various other components like Node.js, SWIG, PCP, and Grafana have also received notable updates.

AlmaLinux 2538 Published by Philipp Esselbach 0

AlmaLinux has released two security updates: ALSA-2025:19932 for the kernel-rt package and ALSA-2025:20034 for libtiff. The kernel-rt update addresses three vulnerabilities, including one related to conditional IBPB mitigation (CVE-2025-40300) and another that fixes a zswap writeback race condition (CVE-2023-53178). In contrast, the libtiff update patches a single vulnerability known as LibTIFF Use-After-Free Vulnerability (CVE-2025-8176), which is classified as "Important."

ALSA-2025:19932: kernel-rt security update (Moderate)
ALSA-2025:20034: libtiff security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

AlmaLinux has released several security updates to address vulnerabilities in various packages, including kernel, xorg-x11-server-Xwayland, expat, osbuild-composer, valkey, qt6-qtsvg, bind, and runc. The security fixes include patches for use-after-free vulnerabilities, integer overflow issues, and potential remote code execution (RCE) flaws. These updates are available for AlmaLinux 10 and 9, and users can find more information about the security issues and updated packages on the AlmaLinux errata website.

ALSA-2025:19469: kernel security update (Moderate)
ALSA-2025:19435: xorg-x11-server-Xwayland security update (Moderate)
ALSA-2025:19403: expat security update (Important)
ALSA-2025:19566: osbuild-composer security update (Moderate)
ALSA-2025:19675: valkey security update (Important)
ALSA-2025:19772: qt6-qtsvg security update (Important)
ALSA-2025:19912: bind security update (Important)
ALSA-2025:19927: runc security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

AlmaLinux 2538 Published by Philipp Esselbach 0

Three important security updates are available for Rocky Linux 8. The first update affects the PCS package, addressing vulnerabilities that can be found on a detailed severity rating page. A second update is available for SSSD, with similar information about vulnerability severity ratings. A third update is also available for the libsoup package, which impacts Rocky Linux 8 users and provides access to CVSS base scores for each identified issue.

RLSA-2025:19719: Important: pcs security update
RLSA-2025:19610: Important: sssd security update
RLSA-2025:19714: Important: libsoup security update

AlmaLinux 2538 Published by Philipp Esselbach 0

Several security updates have been announced for AlmaLinux systems, including .NET framework updates and a WebKitGTK update. The .NET security updates address vulnerabilities in versions 8.0 and 9.0, which may lead to information disclosure, security feature bypass, or denial of service (CVE-2025-55248, CVE-2025-55315, CVE-2025-55247). These updates are available for AlmaLinux versions 8, 9, and 10.

ALSA-2025:18151: .NET 9.0 security update (Important)
ALSA-2025:18150: .NET 9.0 security update (Important)
ALSA-2025:18070: webkit2gtk3 security update (Important)
ALSA-2025:18153: .NET 9.0 security update (Important)
ALSA-2025:18152: .NET 8.0 security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

A security update for AlmaLinux 8 has been released to fix an important vulnerability in the libtiff packages. The issue, identified as CVE-2025-9900, is related to Libtiff Write-What-Where and requires immediate attention from users. For more information about the security issue, including impact, CVSS score, and acknowledgments, users can refer to the CVE page listed in the References section. Users can find full details on the update, updated packages, and other related information by visiting the provided link.

ALSA-2025:19276: libtiff security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

AlmaLinux has released several security updates for its systems, including updates for libtiff (important), java-21-openjdk (moderate), and redis (important). The libtiff update fixes a Write-What-Where vulnerability (CVE-2025-9900) in the library. The java-21-openjdk update addresses three vulnerabilities, including Enhance Path Factories (CVE-2025-53066), Enhance Certificate Handling (CVE-2025-53057), and Enhance String Handling (CVE-2025-61748). The Redis updates address four vulnerabilities, including Lua library commands that may lead to integer overflow and potential RCE (CVE-2025-46817) and Redis: Authenticated users can execute LUA scripts as a different user (CVE-2025-46818).

ALSA-2025:19156: libtiff security update (Important)
ALSA-2025:18824: java-21-openjdk security update (Moderate)
ALSA-2025:18821: java-17-openjdk security update (Moderate)
ALSA-2025:18815: java-1.8.0-openjdk security update (Moderate)
ALSA-2025:18824: java-21-openjdk security update (Moderate)
ALSA-2025:19237: redis security update (Important)
ALSA-2025:18815: java-1.8.0-openjdk security update (Moderate)
ALSA-2025:18821: java-17-openjdk security update (Moderate)
ALSA-2025:18824: java-21-openjdk security update (Moderate)
ALSA-2025:19238: redis:6 security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

Four security updates have been released for AlmaLinux, including updates for libtiff, squid, kernel, and thunderbird. The libtiff update addresses two vulnerabilities (CVE-2025-8176 and CVE-2025-9900) classified as Important, while the squid update fixes a vulnerability (CVE-2025-62168) also classified as Important. The kernel updates address six vulnerabilities (CVE-2023-53297, CVE-2025-39817, CVE-2023-53386, CVE-2022-50386, CVE-2025-39849, and CVE-2025-39841), all classified as moderate. Meanwhile, the Thunderbird update addresses seven security vulnerabilities (CVE-2025-11714 to CVE-2025-11712), also classified as important.

ALSA-2025:19113: libtiff security update (Important)
ALSA-2025:19107: squid:4 security update (Important)
ALSA-2025:19102: kernel security update (Moderate)
ALSA-2025:19103: kernel-rt security update (Moderate)
ALSA-2025:18983: thunderbird security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

A security update has been released for AlmaLinux 9 to address several vulnerabilities in WebKitGTK, a web rendering engine. The vulnerabilities include potential crashes and unauthorized access to sensor information without user consent. The update fixes five security issues identified by CVE numbers: CVE-2025-43272, CVE-2025-43342, CVE-2025-43356, CVE-2025-43368, and CVE-2025-43343.

ALSA-2025:18097: webkit2gtk3 security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

The AlmaLinux team has released several security updates, including important updates for Mozilla Thunderbird and the kernel on AlmaLinux 10, as well as an important update for FreeIPA on AlmaLinux 9. The kernel updates address multiple vulnerabilities, including those that could lead to privilege escalation or denial-of-service attacks. Additionally, a new security update for Mozilla Thunderbird has been released for both AlmaLinux 9 and 10, addressing memory safety bugs and other issues.

ALSA-2025:18320: thunderbird security update (Important)
ALSA-2025:18318: kernel security update (Moderate)
ALSA-2025:17084: ipa security update (Important)
ALSA-2025:18321: thunderbird security update (Important)
ALSA-2025:18281: kernel security update (Moderate)