AlmaLinux 2607 Published by Philipp Esselbach 0

AlmaLinux has released several security updates, including one for container-tools (ALSA-2025:23543), which addresses a vulnerability that could lead to a container escape or denial of service. Additionally, AlmaLinux has released updates for Grafana (ALSA-2025:23948) and opentelemetry-collector (ALSA-2025:23729), both of which are considered important security fixes. Mozilla Thunderbird is also receiving an update (ALSA-2025:23856) to address multiple security vulnerabilities, including memory safety bugs and privilege escalation issues.

ALSA-2025:23543: container-tools:rhel8 security update (Important)
ALSA-2025:23948: grafana security update (Moderate)
ALSA-2025:23856: thunderbird security update (Important)
ALSA-2025:23729: opentelemetry-collector security update (Important)

AlmaLinux 2607 Published by Philipp Esselbach 0

Several security updates have been released for AlmaLinux, addressing potential vulnerabilities in various packages. These updates include patches for ALSA-2025:23738, which involves the mod_md package, rated as Important, and ALSA-2025:23479, a moderate-rated update for openssh. Additionally, several other moderate-rated updates are available for packages such as binutils, python3.12, and skopeo.

ALSA-2025:23294: skopeo security update (Moderate)
ALSA-2025:23306: binutils security update (Moderate)
ALSA-2025:23295: podman security update (Moderate)
ALSA-2025:23738: mod_md security update (Important)
ALSA-2025:23932: httpd security update (Important)
ALSA-2025:23940: python3.12 security update (Moderate)
ALSA-2025:23201: keylime security update (Important)
ALSA-2025:23667: git-lfs security update (Important)
ALSA-2025:23479: openssh security update (Moderate)
ALSA-2025:23484: libssh security update (Moderate)
ALSA-2025:23050: tomcat security update (Important)
ALSA-2025:23052: tomcat9 security update (Important)
ALSA-2025:23309: php:8.3 security update (Moderate)
ALSA-2025:23325: podman security update (Moderate)
ALSA-2025:23326: skopeo security update (Moderate)
ALSA-2025:23343: binutils security update (Moderate)
ALSA-2025:23336: gcc-toolset-13-binutils security update (Moderate)
ALSA-2025:23342: python3.9 security update (Moderate)
ALSA-2025:23700: webkit2gtk3 security update (Important)
ALSA-2025:23323: python3.12 security update (Moderate)
ALSA-2025:23739: mod_md security update (Important)
ALSA-2025:23744: git-lfs security update (Important)
ALSA-2025:23483: libssh security update (Moderate)
ALSA-2025:23480: openssh security update (Moderate)
ALSA-2025:23664: opentelemetry-collector security update (Important)

AlmaLinux 2607 Published by Philipp Esselbach 0

Several security updates have been released for AlmaLinux 8, affecting various packages including binutils, curl, python39, webkit2gtk3, httpd:2.4, git-lfs, and openssh. These updates address multiple vulnerabilities with varying severity levels, ranging from moderate to important. The affected packages include binary utilities for object file manipulation (binutils), a library and utility for downloading files from servers (curl), the Python programming language (python39), a web rendering engine (webkit2gtk3), an HTTP server (httpd:2.4), a Git extension for large file storage (git-lfs), and an SSH protocol implementation (openssh).

ALSA-2025:23382: binutils security update (Moderate)
ALSA-2025:23383: curl security update (Moderate)
ALSA-2025:23530: python39:3.9 security update (Important)
ALSA-2025:23663: webkit2gtk3 security update (Important)
ALSA-2025:23732: httpd:2.4 security update (Important)
ALSA-2025:23745: git-lfs security update (Important)
ALSA-2025:23481: openssh security update (Moderate)

AlmaLinux 2607 Published by Philipp Esselbach 0

AlmaLinux has released several security updates for its users, including patches for Keylime, Kernel, Tomcat, and MySQL vulnerabilities. The updates address issues such as identity takeover via duplicate UUID registration (CVE-2025-13609) in Keylime, can: j1939: implement NETDEV_UNREGISTER notification handler (CVE-2025-39925), and unspecified vulnerabilities in MySQL and its components.

ALSA-2025:23210: keylime security update (Important)
ALSA-2025:22865: kernel security update (Moderate)
ALSA-2025:23049: tomcat security update (Important)
ALSA-2025:23111: mysql:8.4 security update (Moderate)

AlmaLinux 2607 Published by Philipp Esselbach 0

AlmaLinux has released two security updates to address vulnerabilities in Grafana and the kernel packages. The first update, ALSA-2025:23087, fixes a moderate-level vulnerability in Grafana related to unbounded allocation when parsing GNU sparse maps (CVE-2025-58183). The second update, ALSA-2025:22395, addresses multiple moderate-level vulnerabilities in the kernel packages, including issues with ublk, nfsd, memory failure, and network interface drivers.

ALSA-2025:23087: grafana security update (Moderate)
ALSA-2025:22395: kernel security update (Moderate)

AlmaLinux 2607 Published by Philipp Esselbach 0

AlmaLinux 2607 Published by Philipp Esselbach 0

There are two separate security updates for AlmaLinux: one for AlmaLinux 10 (ALSA-2025:22854) and another for AlmaLinux 8 (ALSA-2025:22760). The kernel package in AlmaLinux 10 has been updated to fix several vulnerabilities, including oops due to an uninitialized variable and possible UAFs. Meanwhile, the abrt security update for AlmaLinux 8 fixes a command-injection vulnerability that could lead to local privilege escalation.

ALSA-2025:22854: kernel security update (Moderate)
ALSA-2025:22760: abrt security update (Important)

AlmaLinux 2607 Published by Philipp Esselbach 0

Three security updates have been released for AlmaLinux 8 and 9, addressing vulnerabilities in WebKitGTK3 and the Linux kernel. The first update (ALSA-2025:22790) fixes 15 issues in WebKitGTK3, including potential DoS attacks, memory corruption, and information disclosure. The second and third updates (ALSA-2025:22405 and ALSA-2025:22800) address vulnerabilities in the Linux kernel, including potential crashes, DoS attacks, and information disclosure

ALSA-2025:22790: webkit2gtk3 security update (Important)
ALSA-2025:22405: kernel security update (Moderate)
ALSA-2025:22789: webkit2gtk3 security update (Important)
ALSA-2025:22800: kernel-rt security update (Moderate)
ALSA-2025:22801: kernel security update (Moderate)

AlmaLinux 2607 Published by Philipp Esselbach 0

AlmaLinux 2607 Published by Philipp Esselbach 0

The AlmaLinux Security team has issued two updates: one for libxml2, rated as Moderate (CVE-2025-9714), and another for expat, rated as Important (CVE-2025-59375). The libxml2 update fixes an infinite recursion issue in the exsltDynMapFunction function of libexslt. The expat update addresses a vulnerability that allows attackers to trigger large dynamic memory allocations through parsing small XML documents.

ALSA-2025:22376: libxml2 security update (Moderate)
ALSA-2025:22175: expat security update (Important)

AlmaLinux 2607 Published by Philipp Esselbach 0

AlmaLinux has released several security updates. These updates include fixes for sssd, tigervnc, pcs, bind9.18, openssl, valkey, kernel, gimp, mingw-expat, cups, and libssh. The severity of the updates varies from moderate to important, indicating a range of potential risks if not addressed promptly. Users should review the available security updates and apply them as necessary to ensure the integrity and security of their AlmaLinux system.

ALSA-2025:20954: sssd security update (Important)
ALSA-2025:20958: tigervnc security update (Important)
ALSA-2025:20962: pcs security update (Important)
ALSA-2025:21111: bind9.18 security update (Important)
ALSA-2025:21255: openssl security update (Moderate)
ALSA-2025:21916: valkey security update (Important)
ALSA-2025:21926: kernel security update (Moderate)
ALSA-2025:21968: gimp security update (Important)
ALSA-2025:21974: mingw-expat security update (Important)
ALSA-2025:22063: cups security update (Moderate)
ALSA-2025:21977: libssh security update (Moderate)

AlmaLinux 2607 Published by Philipp Esselbach 0

Several security updates have been released for AlmaLinux. The most critical updates include patches for podman, python-kdcproxy, firefox, and bind, which all have a severity level of "Important." In addition to these high-priority updates, there are also several moderate-severity updates for various packages such as openssh, openssl, and kernel-rt.

ALSA-2025:20983: podman security update (Important)
ALSA-2025:21220: podman security update (Important)
ALSA-2025:21142: python-kdcproxy security update (Important)
ALSA-2025:21691: haproxy security update (Important)
ALSA-2025:21281: firefox security update (Important)
ALSA-2025:21248: openssl security update (Moderate)
ALSA-2025:20126: openssh security update (Moderate)
ALSA-2025:20478: zziplib security update (Moderate)
ALSA-2025:20095: kernel security update (Moderate)
ALSA-2025:21816: delve and golang security update (Moderate)
ALSA-2025:21843: thunderbird security update (Important)
ALSA-2025:21035: xorg-x11-server-Xwayland security update (Moderate)
ALSA-2025:20145: shadow-utils security update (Low)
ALSA-2025:21034: bind security update (Important)
ALSA-2025:21032: libsoup3 security update (Important)
ALSA-2025:21030: expat security update (Important)
ALSA-2025:20155: binutils security update (Moderate)
ALSA-2025:21015: vim security update (Moderate)
ALSA-2025:21013: libssh security update (Moderate)
ALSA-2025:20181: pam security update (Important)
ALSA-2025:21002: squid security update (Important)
ALSA-2025:20998: libtiff security update (Important)
ALSA-2025:22011: buildah security update (Important)
ALSA-2025:22005: go-rpm-macros security update (Moderate)
ALSA-2025:21280: firefox security update (Important)
ALSA-2025:20909: podman security update (Important)
ALSA-2025:21881: thunderbird security update (Important)
ALSA-2025:21917: kernel security update (Moderate)
ALSA-2025:21920: kernel-rt security update (Moderate)

AlmaLinux 2607 Published by Philipp Esselbach 0

AlmaLinux 10.1, codenamed "Heliotrope Lion," has been released with several key updates. The new release includes full Btrfs support, allowing users to install it directly onto a Btrfs filesystem without additional configuration, as well as expanded hardware compatibility for older x86_64_v2 processors through an EPEL variant. AlmaLinux 10.1 also offers performance gains, improved virtualization capabilities, enhanced security features, and updated tools such as compilers, debuggers, and monitoring utilities. One notable difference between AlmaLinux 10.1 and its upstream source, RHEL, is that it continues to support older x86_64_v2 CPUs, providing an option for users who may still depend on or prefer the specific binaries from RHEL.

AlmaLinux 2607 Published by Philipp Esselbach 0

AlmaLinux has released several security updates, including important fixes for container-tools (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881), pcs (CVE-2025-59830, CVE-2025-61770, CVE-2025-61771, CVE-2025-61772, CVE-2025-61919), idm:DL1 (CVE-2025-59088, CVE-2025-59089), and expat (CVE-2025-59375). Additionally, there are moderate updates for kernel-rt (CVE-2025-39718) and delve and golang (CVE-2025-58183).

ALSA-2025:21232: container-tools:rhel8 security update (Important)
ALSA-2025:19719: pcs security update (Important)
ALSA-2025:21140: idm:DL1 security update (Important)
ALSA-2025:21776: expat security update (Important)
ALSA-2025:21397: kernel-rt security update (Moderate)
ALSA-2025:21398: kernel security update (Moderate)
ALSA-2025:21815: delve and golang security update (Moderate)

AlmaLinux 2607 Published by Philipp Esselbach 0

New AlmaLinux updates are available with critical and important fixes. Moderate-severity updates are also present for various packages such as kernel, libssh, vim, xorg-x11-server, and others.

ALSA-2025:21628: lasso security update (Critical)
ALSA-2025:19931: kernel security update (Moderate)
ALSA-2025:20956: libtiff security update (Important)
ALSA-2025:20943: libssh security update (Moderate)
ALSA-2025:20945: vim security update (Moderate)
ALSA-2025:20961: xorg-x11-server security update (Moderate)
ALSA-2025:20960: xorg-x11-server-Xwayland security update (Moderate)
ALSA-2025:20959: libsoup security update (Important)
ALSA-2025:20935: squid security update (Important)
ALSA-2025:20936: sqlite security update (Important)
ALSA-2025:20922: webkit2gtk3 security update (Important)
ALSA-2025:20838: zziplib security update (Moderate)
ALSA-2025:20559: shadow-utils security update (Low)
ALSA-2025:20532: grub2 security update (Moderate)
ALSA-2025:20518: kernel security update (Moderate)
ALSA-2025:20926: redis security update (Important)
ALSA-2025:19950: bind9.18 security update (Important)
ALBA-2025:20841: open-vm-tools bug fix and enhancement update (Moderate)
ALSA-2025:21110: bind security update (Important)
ALSA-2025:20957: runc security update (Important)
ALSA-2025:21702: podman security update (Important)
ALSA-2025:21462: lasso security update (Critical)
ALSA-2025:20963: qt5-qt3d security update (Moderate)
ALSA-2025:21693: haproxy security update (Important)
ALSA-2025:20955: redis:7 security update (Important)
ALSA-2025:21139: python-kdcproxy security update (Important)

AlmaLinux 2607 Published by Philipp Esselbach 0

AlmaLinux 9.7 has been released, bringing numerous updates focused on performance, developer tools, and security. This release includes improvements to system responsiveness through updated core libraries like Glibc and Annobin, as well as new compiler toolsets such as GCC Toolset 15 and LLVM Toolset 20.1.8. Networking support has also been enhanced with updates for NetworkManager, iproute, and ethtool, while security buffs will appreciate revised SELinux policies and newer versions of SSSD and Keylime. OpenSSL 3.5, which supports post-quantum cryptography, and various other components like Node.js, SWIG, PCP, and Grafana have also received notable updates.

AlmaLinux 2607 Published by Philipp Esselbach 0

AlmaLinux has released two security updates: ALSA-2025:19932 for the kernel-rt package and ALSA-2025:20034 for libtiff. The kernel-rt update addresses three vulnerabilities, including one related to conditional IBPB mitigation (CVE-2025-40300) and another that fixes a zswap writeback race condition (CVE-2023-53178). In contrast, the libtiff update patches a single vulnerability known as LibTIFF Use-After-Free Vulnerability (CVE-2025-8176), which is classified as "Important."

ALSA-2025:19932: kernel-rt security update (Moderate)
ALSA-2025:20034: libtiff security update (Important)