AlmaLinux 2607 Published by Philipp Esselbach 0

Multiple security updates have been released by AlmaLinux, including patches for FontForge, Node.js, Mozilla Thunderbird, and Firefox to address remote code execution vulnerabilities and other issues. The updates also include fixes for a heap-based buffer overflow in BMP file parsing, a use-after-free bug in SFD file parsing, and denial of service vulnerabilities in Node.js. Additionally, the kernel packages have been updated to resolve several security issues, including a Linux kernel ALSA USB audio driver buffer overflow that could lead to information disclosure and denial of service. Users can find more details about these updates on the AlmaLinux errata website, which includes full package listings and other related information.

ALSA-2026:2039: fontforge security update (Important)
ALSA-2026:1843: nodejs22 security update (Important)
ALSA-2026:2286: thunderbird security update (Important)
ALSA-2026:2271: firefox security update (Important)
ALSA-2026:1831: qemu-kvm security update (Moderate)
ALSA-2026:1837: osbuild-composer security update (Moderate)
ALSA-2026:2182: libsoup3 security update (Important)
ALSA-2026:1842: nodejs24 security update (Important)
ALSA-2026:2215: libsoup security update (Important)
ALSA-2026:2264: kernel security update (Moderate)
ALSA-2026:2124: osbuild-composer security update (Important)

AlmaLinux 2607 Published by Philipp Esselbach 0

Multiple security updates are available for various packages on AlmaLinux systems, including Python 3 and FreeRDP. The affected versions include AlmaLinux 8 and 9, with vulnerabilities addressed in the updates including a privilege escalation or code execution flaw in Python 3.12-wheel and several heap buffer overflow issues in FreeRDP. Additionally, a kernel security update is available for AlmaLinux 9, addressing flaws such as a stack out-of-bounds write vulnerability.

ALSA-2026:2090: python3.12-wheel security update (Important)
ALSA-2026:2128: python3 security update (Moderate)
ALSA-2026:2081: freerdp security update (Important)
ALSA-2026:1617: kernel security update (Moderate)

AlmaLinux 2607 Published by Philipp Esselbach 0

The AlmaLinux Security team has released several important and moderate security updates to address vulnerabilities in various packages, including kernel, python-wheel, curl, python3.12, and brotli. These updates aim to fix issues such as use-after-free vulnerabilities, out-of-bounds reads, and denial of service attacks that could compromise system security. The CVEs listed for each update include Linux kernel vulnerabilities (CVE-2025-37819, CVE-2025-38349), python-wheel privilege escalation (CVE-2026-24049), curl out-of-bounds read (CVE-2025-9086), and brotli decompression bomb DoS (CVE-2025-6176).

ALSA-2026:1690: kernel security update (Important)
ALSA-2026:1902: python-wheel security update (Important)
ALSA-2026:1825: curl security update (Moderate)
ALSA-2026:1828: python3.12 security update (Moderate)
ALSA-2026:2042: brotli security update (Important)

AlmaLinux 2607 Published by Philipp Esselbach 0

AlmaLinux has issued three security updates to address vulnerabilities in its system. The first update, ALSA-2026:1714, fixes a NULL Pointer Dereference in Wireshark (CVE-2025-9817) and is rated as Moderate severity. The second update, ALSA-2026:1696, addresses a Heap buffer overread in util-linux (CVE-2025-14104), also classified as Moderate severity. The third update, ALSA-2026:1715, fixes a Denial of Service vulnerability due to excessive resource consumption in golang-github-openprinting-ipp-usb and is rated as Important severity.

ALSA-2026:1714: wireshark security update (Moderate)
ALSA-2026:1696: util-linux security update (Moderate)
ALSA-2026:1715: golang-github-openprinting-ipp-usb security update (Important)

AlmaLinux 2607 Published by Philipp Esselbach 0

AlmaLinux 2607 Published by Philipp Esselbach 0

Several security updates have been released for AlmaLinux 9, addressing vulnerabilities in various packages, including Python, PHP, kernel, Java, and curl. The updates are categorized by severity, with one update marked as important due to its potential impact on system stability. Specific security fixes include excessive read buffering DoS in http.client, heap-based buffer overflow in array_merge(), and use-after-free in device mapper.

ALSA-2026:1410: python3.11 security update (Moderate)
ALSA-2026:1429: php:8.3 security update (Important)
ALSA-2026:1143: kernel security update (Important)
ALSA-2026:0932: java-1.8.0-openjdk security update (Important)
ALSA-2026:1350: curl security update (Moderate)
ALSA-2026:1408: python3.12 security update (Moderate)

AlmaLinux 2607 Published by Philipp Esselbach 0

Security updates have been released for AlmaLinux. These updates include patches for various security issues, such as remote code execution vulnerabilities (CVE-2025-14422 and CVE-2026-21441), denial of service due to excessive resource consumption via crafted certificates (CVE-2025-61729), and integer overflows leading to heap corruption (CVE-2026-0861). The updates cover several packages, including GIMP, Grafana, python-urllib3, osbuild-composer, and glibc.

ALSA-2026:1574: gimp:2.8 security update (Important)
ALSA-2026:1518: grafana-pcp security update (Important)
ALSA-2026:1254: python-urllib3 security update (Important)
ALSA-2026:1374: python3.11 security update (Moderate)
ALSA-2026:1380: osbuild-composer security update (Moderate)
ALSA-2026:1344: grafana security update (Important)
ALSA-2026:1334: glibc security update (Moderate)

AlmaLinux 2607 Published by Philipp Esselbach 0

The AlmaLinux Security team has released several security updates for various packages, including java-1.8.0-openjdk and openssl. The updates address important vulnerabilities such as arbitrary code execution, denial of service, and information disclosure. For example, the java-1.8.0-openjdk update fixes three security issues (CVE-2026-21925 to CVE-2026-21945), while the openssl update addresses 12 vulnerabilities (CVE-2025-11187 to CVE-2026-22796). Users can find more information and updated packages on the AlmaLinux Errata website, including links to CVE pages for each vulnerability.

ALSA-2026:0932: java-1.8.0-openjdk security update (Important)
ALSA-2026:0933: java-25-openjdk security update (Important)
ALSA-2026:0933: java-25-openjdk security update (Important)
ALSA-2026:1478: python3.9 security update (Moderate)
ALSA-2026:1472: openssl security update (Important)

AlmaLinux 2607 Published by Philipp Esselbach 0

The AlmaLinux Security team has issued several security updates for the python3-urllib3 package, which includes fixes for three vulnerabilities: unbounded decompression chain leading to resource exhaustion (CVE-2025-66418), improper handling of highly compressed data (CVE-2025-66471), and bypassing of decompression-bomb safeguard when following HTTP redirects (CVE-2026-21441). These updates are important and affect multiple versions of the python3-urllib3 package, including those for AlmaLinux 8 and 9.

ALSA-2026:1226: python3.12-urllib3 security update (Important)
ALSA-2026:1224: python3.11-urllib3 security update (Important)
ALSA-2026:1087: python-urllib3 security update (Important)
ALSA-2026:1089: python3.11-urllib3 security update (Important)
ALSA-2026:1088: python3.12-urllib3 security update (Important)

AlmaLinux 2607 Published by Philipp Esselbach 0

Several important security updates have been released for AlmaLinux, including updates for Java 21 OpenJDK, Go Toolset, GIMP, net-snmp, kernel, and Python urllib3. These updates address various vulnerabilities, such as remote code execution, denial of service, and memory corruption, and are rated as important due to their potential impact on system security.

ALSA-2026:0928: java-21-openjdk security update (Important)
ALSA-2026:0921: go-toolset:rhel8 security update (Important)
ALSA-2026:0914: gimp security update (Important)
ALSA-2026:0696: net-snmp security update (Important)
ALSA-2026:1142: kernel security update (Important)
ALSA-2026:1148: kernel-rt security update (Important)
ALSA-2026:1086: python-urllib3 security update (Important)

AlmaLinux 2607 Published by Philipp Esselbach 0

The AlmaLinux Security team has released several security updates to address various vulnerabilities across different packages and versions of the operating system. The updates include fixes for kernel, Java, Go, and glib2 packages, with some being rated as important or moderate severity. Each update provides a brief description of the affected package, the type and severity of the vulnerability, and instructions on how to access full details about the issue and updated packages.

ALSA-2026:0786: kernel security update (Important)
ALSA-2026:0927: java-17-openjdk security update (Important)
ALSA-2026:0930: pcs security update (Moderate)
ALSA-2026:0991: glib2 security update (Moderate)
ALSA-2026:0923: golang security update (Important)
ALSA-2026:0927: java-17-openjdk security update (Important)
ALSA-2026:0924: thunderbird security update (Important)
ALSA-2026:0936: glib2 security update (Moderate)
ALSA-2026:0928: java-21-openjdk security update (Important)
ALSA-2026:0793: kernel security update (Important)
ALSA-2026:0922: golang security update (Important)
ALSA-2026:0928: java-21-openjdk security update (Important)
ALSA-2026:0975: glib2 security update (Moderate)

AlmaLinux 2607 Published by Philipp Esselbach 0

The AlmaLinux team is sending out security updates for three different packages: brotli, gpsd, and container-tools. Brotli has been updated to fix a potential DoS attack (CVE-2025-6176) via decompression bomb, while gpsd has two vulnerabilities fixed (CVE-2025-67269 and CVE-2025-67268) that could lead to denial of service or arbitrary code execution. The container-tools module for AlmaLinux 8 has also been updated to fix a vulnerability in the golang.org/x/crypto package that could cause an SSH client panic (CVE-2025-47913).

ALSA-2026:0845: brotli security update (Important)
ALSA-2026:0770: gpsd security update (Important)
ALSA-2026:0753: container-tools:rhel8 security update (Important)

AlmaLinux 2607 Published by Philipp Esselbach 0

The AlmaLinux Security team has sent out important security updates for several packages, including jmc, gpsd-minimal, kernel-rt, kernel, and net-snmp. These updates address various security issues such as information disclosure, denial-of-service vulnerabilities, and arbitrary code execution. The CVE numbers for the identified security issues are listed in each update, along with references to more detailed information on the affected packages and their corresponding fixes.

ALSA-2026:0752: jmc security update (Important)
ALSA-2026:0771: gpsd-minimal security update (Important)
ALSA-2026:0760: kernel-rt security update (Important)
ALSA-2026:0759: kernel security update (Important)
ALSA-2026:0750: net-snmp security update (Important)

AlmaLinux 2607 Published by Philipp Esselbach 0

AlmaLinux has released several security updates, including patches for PostgreSQL 15 and 16, which address moderate-level vulnerabilities. Additionally, libsoup, buildah, podman, and kernel components have received significant security updates to address critical issues. Moderate-level updates are also available for cups, libpq, vsftpd, and transfig to enhance system security. Other notable updates include a Firefox update to fix an important vulnerability.

ALSA-2026:0492: postgresql:15 security update (Moderate)
ALSA-2026:0493: postgresql:16 security update (Moderate)
ALSA-2026:0422: libsoup security update (Important)
ALSA-2026:0437: buildah security update (Important)
ALSA-2026:0312: cups security update (Moderate)
ALSA-2026:0458: libpq security update (Moderate)
ALSA-2026:0445: kernel security update (Moderate)
ALSA-2026:0470: podman security update (Important)
ALSA-2026:0605: vsftpd security update (Moderate)
ALSA-2026:0491: postgresql security update (Moderate)
ALSA-2026:0694: firefox security update (Important)
ALSA-2026:0700: transfig security update (Moderate)
ALSA-2026:0464: cups security update (Moderate)
ALSA-2026:0423: libsoup3 security update (Important)
ALSA-2026:0545: podman security update (Important)
ALSA-2026:0525: postgresql16 security update (Moderate)
ALSA-2026:0594: libpq security update (Moderate)
ALSA-2026:0668: net-snmp security update (Important)
ALSA-2026:0436: buildah security update (Important)
ALSA-2026:0606: vsftpd security update (Moderate)
ALSA-2026:0453: kernel security update (Important)
ALSA-2026:0421: libsoup security update (Important)
ALSA-2026:0756: transfig security update (Moderate)
ALSA-2026:0337: openssl security update (Moderate)
ALSA-2026:0443: kernel-rt security update (Important)
ALSA-2026:0519: postgresql:16 security update (Moderate)
ALSA-2026:0523: postgresql:13 security update (Moderate)
ALSA-2026:0444: kernel security update (Important)
ALSA-2026:0524: postgresql:15 security update (Moderate)
ALSA-2026:0596: cups security update (Moderate)
ALSA-2026:0695: libpq security update (Moderate)
ALSA-2026:0608: vsftpd security update (Moderate)

AlmaLinux 2607 Published by Philipp Esselbach 0

The AlmaLinux team sent out security update emails for multiple versions of their operating system, including AlmaLinux 8, 9, and 10. The updates address a critical vulnerability in GnuPG (CVE-2025-68973), which could lead to information disclosure and potential arbitrary code execution via an out-of-bounds write. For more details on the security issue and its impact, users can refer to the CVE page(s) listed in the References section of each update email.

ALSA-2026:0697: gnupg2 security update (Important)
ALSA-2026:0728: gnupg2 security update (Important)
ALSA-2026:0719: gnupg2 security update (Important)

AlmaLinux 2607 Published by Philipp Esselbach 0

You have received AlmaLinux Security update emails due to subscribing to receive errata notifications from AlmaLinux. The updates are for MariaDB, a multi-user SQL database server that is binary compatible with MySQL, and address various security issues, including remote code execution vulnerabilities. Five different versions (AlmaLinux 8, 9, 10) of the MariaDB update are listed, each addressing multiple security fixes, such as Denial of Service Vulnerabilities in MySQL Server and MariaDB Server crashes

ALSA-2026:0225: mariadb:10.3 security update (Important)
ALSA-2026:0232: mariadb:10.11 security update (Important)
ALSA-2026:0233: mariadb:10.5 security update (Important)
ALSA-2026:0136: mariadb10.11 security update (Important)
ALSA-2026:0247: mariadb:10.11 security update (Important)

AlmaLinux 2607 Published by Philipp Esselbach 0

The AlmaLinux team has released several security updates to address vulnerabilities in various packages, including poppler, libpng, binutils, and mariadb. These updates are available for different versions of AlmaLinux, with some being specific to version 10 and others specific to version 9. The updates resolve issues such as out-of-bounds reads, buffer overflows, and remote code execution vulnerabilities, which have been assigned CVE IDs for tracking purposes. Users can find more information about the security issues and updated packages on the AlmaLinux errata website.

ALSA-2026:0128: poppler security update (Moderate)
ALSA-2026:0237: libpng security update (Important)
ALSA-2026:0108: gcc-toolset-15-binutils security update (Moderate)
ALSA-2026:0238: libpng security update (Important)
ALSA-2026:0126: poppler security update (Moderate)
ALSA-2026:0137: mariadb security update (Important)

AlmaLinux 2607 Published by Philipp Esselbach 0

Security updates have been released for AlmaLinux, affecting various packages, such as httpd and kernel. The updates include fixes for ruby, xorg-x11-server, resource-agents, thunderbird, mingw-libpng, poppler, python3.12, libpng, and others. These updates range from moderate to important in severity, with several rated as high priority. AlmaLinux users should review the available security updates to ensure their system is up-to-date and secure.

ALSA-2025:23063: ruby:3.3 security update (Moderate)
ALSA-2025:23919: httpd security update (Important)
ALSA-2026:0052: gcc-toolset-14-binutils security update (Moderate)
ALSA-2025:23241: kernel security update (Important)
ALSA-2025:19434: xorg-x11-server security update (Moderate)
ALSA-2025:14999: resource-agents security update (Moderate)
ALSA-2025:23062: ruby:3.3 security update (Moderate)
ALSA-2026:0026: thunderbird security update (Important)
ALSA-2026:0125: mingw-libpng security update (Important)
ALSA-2026:0130: poppler security update (Moderate)
ALSA-2026:0123: python3.12 security update (Moderate)
ALSA-2026:0241: libpng security update (Important)

AlmaLinux 2607 Published by Philipp Esselbach 0

Three AlmaLinux security updates have been released to address potential security vulnerabilities: an update for Ruby (ALSA-2025:23141), which is considered moderate, and two updates for Mozilla Thunderbird and kernel packages, both rated important. The Ruby update fixes Denial of Service issues in the resolv and rexml gems, while the other updates fix various memory safety bugs, use-after-free vulnerabilities, sandbox escapes, and JIT miscompilations in Firefox and the kernel. Users can find more details about these security issues, including their impact, CVSS scores, and acknowledgments, on the corresponding CVE pages listed in the References section of each update.

ALSA-2025:23141: ruby security update (Moderate)
ALSA-2026:0025: thunderbird security update (Important)
ALSA-2025:23279: kernel security update (Important)