AlmaLinux 2538 Published by Philipp Esselbach 0

Several important security updates have been released for AlmaLinux, including updates for Java 21 OpenJDK, Go Toolset, GIMP, net-snmp, kernel, and Python urllib3. These updates address various vulnerabilities, such as remote code execution, denial of service, and memory corruption, and are rated as important due to their potential impact on system security.

ALSA-2026:0928: java-21-openjdk security update (Important)
ALSA-2026:0921: go-toolset:rhel8 security update (Important)
ALSA-2026:0914: gimp security update (Important)
ALSA-2026:0696: net-snmp security update (Important)
ALSA-2026:1142: kernel security update (Important)
ALSA-2026:1148: kernel-rt security update (Important)
ALSA-2026:1086: python-urllib3 security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

The AlmaLinux Security team has released several security updates to address various vulnerabilities across different packages and versions of the operating system. The updates include fixes for kernel, Java, Go, and glib2 packages, with some being rated as important or moderate severity. Each update provides a brief description of the affected package, the type and severity of the vulnerability, and instructions on how to access full details about the issue and updated packages.

ALSA-2026:0786: kernel security update (Important)
ALSA-2026:0927: java-17-openjdk security update (Important)
ALSA-2026:0930: pcs security update (Moderate)
ALSA-2026:0991: glib2 security update (Moderate)
ALSA-2026:0923: golang security update (Important)
ALSA-2026:0927: java-17-openjdk security update (Important)
ALSA-2026:0924: thunderbird security update (Important)
ALSA-2026:0936: glib2 security update (Moderate)
ALSA-2026:0928: java-21-openjdk security update (Important)
ALSA-2026:0793: kernel security update (Important)
ALSA-2026:0922: golang security update (Important)
ALSA-2026:0928: java-21-openjdk security update (Important)
ALSA-2026:0975: glib2 security update (Moderate)

AlmaLinux 2538 Published by Philipp Esselbach 0

The AlmaLinux team is sending out security updates for three different packages: brotli, gpsd, and container-tools. Brotli has been updated to fix a potential DoS attack (CVE-2025-6176) via decompression bomb, while gpsd has two vulnerabilities fixed (CVE-2025-67269 and CVE-2025-67268) that could lead to denial of service or arbitrary code execution. The container-tools module for AlmaLinux 8 has also been updated to fix a vulnerability in the golang.org/x/crypto package that could cause an SSH client panic (CVE-2025-47913).

ALSA-2026:0845: brotli security update (Important)
ALSA-2026:0770: gpsd security update (Important)
ALSA-2026:0753: container-tools:rhel8 security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

The AlmaLinux Security team has sent out important security updates for several packages, including jmc, gpsd-minimal, kernel-rt, kernel, and net-snmp. These updates address various security issues such as information disclosure, denial-of-service vulnerabilities, and arbitrary code execution. The CVE numbers for the identified security issues are listed in each update, along with references to more detailed information on the affected packages and their corresponding fixes.

ALSA-2026:0752: jmc security update (Important)
ALSA-2026:0771: gpsd-minimal security update (Important)
ALSA-2026:0760: kernel-rt security update (Important)
ALSA-2026:0759: kernel security update (Important)
ALSA-2026:0750: net-snmp security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

AlmaLinux has released several security updates, including patches for PostgreSQL 15 and 16, which address moderate-level vulnerabilities. Additionally, libsoup, buildah, podman, and kernel components have received significant security updates to address critical issues. Moderate-level updates are also available for cups, libpq, vsftpd, and transfig to enhance system security. Other notable updates include a Firefox update to fix an important vulnerability.

ALSA-2026:0492: postgresql:15 security update (Moderate)
ALSA-2026:0493: postgresql:16 security update (Moderate)
ALSA-2026:0422: libsoup security update (Important)
ALSA-2026:0437: buildah security update (Important)
ALSA-2026:0312: cups security update (Moderate)
ALSA-2026:0458: libpq security update (Moderate)
ALSA-2026:0445: kernel security update (Moderate)
ALSA-2026:0470: podman security update (Important)
ALSA-2026:0605: vsftpd security update (Moderate)
ALSA-2026:0491: postgresql security update (Moderate)
ALSA-2026:0694: firefox security update (Important)
ALSA-2026:0700: transfig security update (Moderate)
ALSA-2026:0464: cups security update (Moderate)
ALSA-2026:0423: libsoup3 security update (Important)
ALSA-2026:0545: podman security update (Important)
ALSA-2026:0525: postgresql16 security update (Moderate)
ALSA-2026:0594: libpq security update (Moderate)
ALSA-2026:0668: net-snmp security update (Important)
ALSA-2026:0436: buildah security update (Important)
ALSA-2026:0606: vsftpd security update (Moderate)
ALSA-2026:0453: kernel security update (Important)
ALSA-2026:0421: libsoup security update (Important)
ALSA-2026:0756: transfig security update (Moderate)
ALSA-2026:0337: openssl security update (Moderate)
ALSA-2026:0443: kernel-rt security update (Important)
ALSA-2026:0519: postgresql:16 security update (Moderate)
ALSA-2026:0523: postgresql:13 security update (Moderate)
ALSA-2026:0444: kernel security update (Important)
ALSA-2026:0524: postgresql:15 security update (Moderate)
ALSA-2026:0596: cups security update (Moderate)
ALSA-2026:0695: libpq security update (Moderate)
ALSA-2026:0608: vsftpd security update (Moderate)

AlmaLinux 2538 Published by Philipp Esselbach 0

The AlmaLinux team sent out security update emails for multiple versions of their operating system, including AlmaLinux 8, 9, and 10. The updates address a critical vulnerability in GnuPG (CVE-2025-68973), which could lead to information disclosure and potential arbitrary code execution via an out-of-bounds write. For more details on the security issue and its impact, users can refer to the CVE page(s) listed in the References section of each update email.

ALSA-2026:0697: gnupg2 security update (Important)
ALSA-2026:0728: gnupg2 security update (Important)
ALSA-2026:0719: gnupg2 security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

You have received AlmaLinux Security update emails due to subscribing to receive errata notifications from AlmaLinux. The updates are for MariaDB, a multi-user SQL database server that is binary compatible with MySQL, and address various security issues, including remote code execution vulnerabilities. Five different versions (AlmaLinux 8, 9, 10) of the MariaDB update are listed, each addressing multiple security fixes, such as Denial of Service Vulnerabilities in MySQL Server and MariaDB Server crashes

ALSA-2026:0225: mariadb:10.3 security update (Important)
ALSA-2026:0232: mariadb:10.11 security update (Important)
ALSA-2026:0233: mariadb:10.5 security update (Important)
ALSA-2026:0136: mariadb10.11 security update (Important)
ALSA-2026:0247: mariadb:10.11 security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

The AlmaLinux team has released several security updates to address vulnerabilities in various packages, including poppler, libpng, binutils, and mariadb. These updates are available for different versions of AlmaLinux, with some being specific to version 10 and others specific to version 9. The updates resolve issues such as out-of-bounds reads, buffer overflows, and remote code execution vulnerabilities, which have been assigned CVE IDs for tracking purposes. Users can find more information about the security issues and updated packages on the AlmaLinux errata website.

ALSA-2026:0128: poppler security update (Moderate)
ALSA-2026:0237: libpng security update (Important)
ALSA-2026:0108: gcc-toolset-15-binutils security update (Moderate)
ALSA-2026:0238: libpng security update (Important)
ALSA-2026:0126: poppler security update (Moderate)
ALSA-2026:0137: mariadb security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

Security updates have been released for AlmaLinux, affecting various packages, such as httpd and kernel. The updates include fixes for ruby, xorg-x11-server, resource-agents, thunderbird, mingw-libpng, poppler, python3.12, libpng, and others. These updates range from moderate to important in severity, with several rated as high priority. AlmaLinux users should review the available security updates to ensure their system is up-to-date and secure.

ALSA-2025:23063: ruby:3.3 security update (Moderate)
ALSA-2025:23919: httpd security update (Important)
ALSA-2026:0052: gcc-toolset-14-binutils security update (Moderate)
ALSA-2025:23241: kernel security update (Important)
ALSA-2025:19434: xorg-x11-server security update (Moderate)
ALSA-2025:14999: resource-agents security update (Moderate)
ALSA-2025:23062: ruby:3.3 security update (Moderate)
ALSA-2026:0026: thunderbird security update (Important)
ALSA-2026:0125: mingw-libpng security update (Important)
ALSA-2026:0130: poppler security update (Moderate)
ALSA-2026:0123: python3.12 security update (Moderate)
ALSA-2026:0241: libpng security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

Three AlmaLinux security updates have been released to address potential security vulnerabilities: an update for Ruby (ALSA-2025:23141), which is considered moderate, and two updates for Mozilla Thunderbird and kernel packages, both rated important. The Ruby update fixes Denial of Service issues in the resolv and rexml gems, while the other updates fix various memory safety bugs, use-after-free vulnerabilities, sandbox escapes, and JIT miscompilations in Firefox and the kernel. Users can find more details about these security issues, including their impact, CVSS scores, and acknowledgments, on the corresponding CVE pages listed in the References section of each update.

ALSA-2025:23141: ruby security update (Moderate)
ALSA-2026:0025: thunderbird security update (Important)
ALSA-2025:23279: kernel security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

AlmaLinux has released several security updates, including one for container-tools (ALSA-2025:23543), which addresses a vulnerability that could lead to a container escape or denial of service. Additionally, AlmaLinux has released updates for Grafana (ALSA-2025:23948) and opentelemetry-collector (ALSA-2025:23729), both of which are considered important security fixes. Mozilla Thunderbird is also receiving an update (ALSA-2025:23856) to address multiple security vulnerabilities, including memory safety bugs and privilege escalation issues.

ALSA-2025:23543: container-tools:rhel8 security update (Important)
ALSA-2025:23948: grafana security update (Moderate)
ALSA-2025:23856: thunderbird security update (Important)
ALSA-2025:23729: opentelemetry-collector security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

Several security updates have been released for AlmaLinux, addressing potential vulnerabilities in various packages. These updates include patches for ALSA-2025:23738, which involves the mod_md package, rated as Important, and ALSA-2025:23479, a moderate-rated update for openssh. Additionally, several other moderate-rated updates are available for packages such as binutils, python3.12, and skopeo.

ALSA-2025:23294: skopeo security update (Moderate)
ALSA-2025:23306: binutils security update (Moderate)
ALSA-2025:23295: podman security update (Moderate)
ALSA-2025:23738: mod_md security update (Important)
ALSA-2025:23932: httpd security update (Important)
ALSA-2025:23940: python3.12 security update (Moderate)
ALSA-2025:23201: keylime security update (Important)
ALSA-2025:23667: git-lfs security update (Important)
ALSA-2025:23479: openssh security update (Moderate)
ALSA-2025:23484: libssh security update (Moderate)
ALSA-2025:23050: tomcat security update (Important)
ALSA-2025:23052: tomcat9 security update (Important)
ALSA-2025:23309: php:8.3 security update (Moderate)
ALSA-2025:23325: podman security update (Moderate)
ALSA-2025:23326: skopeo security update (Moderate)
ALSA-2025:23343: binutils security update (Moderate)
ALSA-2025:23336: gcc-toolset-13-binutils security update (Moderate)
ALSA-2025:23342: python3.9 security update (Moderate)
ALSA-2025:23700: webkit2gtk3 security update (Important)
ALSA-2025:23323: python3.12 security update (Moderate)
ALSA-2025:23739: mod_md security update (Important)
ALSA-2025:23744: git-lfs security update (Important)
ALSA-2025:23483: libssh security update (Moderate)
ALSA-2025:23480: openssh security update (Moderate)
ALSA-2025:23664: opentelemetry-collector security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

Several security updates have been released for AlmaLinux 8, affecting various packages including binutils, curl, python39, webkit2gtk3, httpd:2.4, git-lfs, and openssh. These updates address multiple vulnerabilities with varying severity levels, ranging from moderate to important. The affected packages include binary utilities for object file manipulation (binutils), a library and utility for downloading files from servers (curl), the Python programming language (python39), a web rendering engine (webkit2gtk3), an HTTP server (httpd:2.4), a Git extension for large file storage (git-lfs), and an SSH protocol implementation (openssh).

ALSA-2025:23382: binutils security update (Moderate)
ALSA-2025:23383: curl security update (Moderate)
ALSA-2025:23530: python39:3.9 security update (Important)
ALSA-2025:23663: webkit2gtk3 security update (Important)
ALSA-2025:23732: httpd:2.4 security update (Important)
ALSA-2025:23745: git-lfs security update (Important)
ALSA-2025:23481: openssh security update (Moderate)

AlmaLinux 2538 Published by Philipp Esselbach 0

AlmaLinux has released several security updates for its users, including patches for Keylime, Kernel, Tomcat, and MySQL vulnerabilities. The updates address issues such as identity takeover via duplicate UUID registration (CVE-2025-13609) in Keylime, can: j1939: implement NETDEV_UNREGISTER notification handler (CVE-2025-39925), and unspecified vulnerabilities in MySQL and its components.

ALSA-2025:23210: keylime security update (Important)
ALSA-2025:22865: kernel security update (Moderate)
ALSA-2025:23049: tomcat security update (Important)
ALSA-2025:23111: mysql:8.4 security update (Moderate)

AlmaLinux 2538 Published by Philipp Esselbach 0

AlmaLinux has released two security updates to address vulnerabilities in Grafana and the kernel packages. The first update, ALSA-2025:23087, fixes a moderate-level vulnerability in Grafana related to unbounded allocation when parsing GNU sparse maps (CVE-2025-58183). The second update, ALSA-2025:22395, addresses multiple moderate-level vulnerabilities in the kernel packages, including issues with ublk, nfsd, memory failure, and network interface drivers.

ALSA-2025:23087: grafana security update (Moderate)
ALSA-2025:22395: kernel security update (Moderate)

AlmaLinux 2538 Published by Philipp Esselbach 0

AlmaLinux 2538 Published by Philipp Esselbach 0

There are two separate security updates for AlmaLinux: one for AlmaLinux 10 (ALSA-2025:22854) and another for AlmaLinux 8 (ALSA-2025:22760). The kernel package in AlmaLinux 10 has been updated to fix several vulnerabilities, including oops due to an uninitialized variable and possible UAFs. Meanwhile, the abrt security update for AlmaLinux 8 fixes a command-injection vulnerability that could lead to local privilege escalation.

ALSA-2025:22854: kernel security update (Moderate)
ALSA-2025:22760: abrt security update (Important)

AlmaLinux 2538 Published by Philipp Esselbach 0

Three security updates have been released for AlmaLinux 8 and 9, addressing vulnerabilities in WebKitGTK3 and the Linux kernel. The first update (ALSA-2025:22790) fixes 15 issues in WebKitGTK3, including potential DoS attacks, memory corruption, and information disclosure. The second and third updates (ALSA-2025:22405 and ALSA-2025:22800) address vulnerabilities in the Linux kernel, including potential crashes, DoS attacks, and information disclosure

ALSA-2025:22790: webkit2gtk3 security update (Important)
ALSA-2025:22405: kernel security update (Moderate)
ALSA-2025:22789: webkit2gtk3 security update (Important)
ALSA-2025:22800: kernel-rt security update (Moderate)
ALSA-2025:22801: kernel security update (Moderate)