Debian 11002 Published by Philipp Esselbach 0

Debian published a series of security advisories that patches dozens of critical flaws across core system components and popular software packages. The Linux kernel update resolves a massive list of common vulnerability identifiers that could allow attackers to escalate privileges or crash services. Popular media and web frameworks like ImageMagick, Pillow, and Squid now ship corrected versions that block malicious input from triggering arbitrary code execution.

[DSA 6355-1] linux security update
[DLA 4638-1] libgd-perl security update
[DSA 6356-1] imagemagick security update
[DSA 6359-1] gst-plugins-good1.0 security update
[DSA 6358-1] libhttp-daemon-perl security update
[DSA 6357-1] pillow security update
[DSA 6360-1] squid security update
[DLA 4639-1] libhttp-daemon-perl security update
[DLA 4640-1] mediawiki security update

Debian 11002 Ubuntu 7156 Arch Linux 981 Published by Philipp Esselbach 0

The Liquorix kernel 7.0-14 update tightens the scheduler and wakelist logic to deliver more consistent frame times for gaming and audio workloads. By reintroducing PSI support for Project-C and refining CPU masking routines, the release targets the exact paths that cause context switch stutter on interactive desktops. Users can deploy the changes quickly through the official one-line installer script, which safely handles repository setup and leaves the previous kernel as a fallback. Testing the new build on live audio sessions or benchmark runs will quickly reveal whether the scheduler tweaks match specific hardware quirks.

Debian 11002 Published by Philipp Esselbach 0

Debian administrators should immediately apply critical security patches for Thunderbird, Firefox ESR, libconfig-inifiles-perl, and gst-libav1.0 to address numerous high-risk vulnerabilities. These updates resolve dozens of common vulnerability identifiers that could allow attackers to execute arbitrary code or bypass browser security restrictions. The fixes also target a Perl module flaw capable of triggering shell command execution alongside heap memory corruption issues within the GStreamer multimedia framework.

[DLA 4636-1] thunderbird security update
[DLA 4635-1] firefox-esr security update
[DLA 4637-1] libconfig-inifiles-perl security update
[DSA 6354-1] libconfig-inifiles-perl security update
[DSA 6353-1] gst-libav1.0 security update

Debian 11002 Ubuntu 7156 Published by Philipp Esselbach 0

XanMod just pushed out kernels 6.18.36 LTS, 7.0.13, and 7.1.1 for Debian and Ubuntu, packing in LLVM ThinLTO optimizations and default BBRv3 network handling. The update also adds targeted hardware patches like AMD 3D V-Cache support and Steam Deck sensor drivers to improve real-world responsiveness. Anyone running NVIDIA graphics, OpenZFS, or VMware should verify dkms compatibility first, since proprietary modules frequently break during rapid kernel shifts. Official repositories make the upgrade straightforward, and the GPLv2 license keeps the entire build process fully transparent for tinkerers.

Debian 11002 Published by Philipp Esselbach 0

Debian has rolled out urgent security patches for Thunderbird and Chromium to address dozens of critical flaws that could let attackers run malicious code or leak private data. These updates tackle a long list of common vulnerability identifiers by hardening the email client and browser engine across both current and legacy stable distributions. System administrators will also notice quiet maintenance releases for Linux kernels 5.10 and 6.1 that simply correct broken package metadata caused by recent server hiccups. You should install these fixes right away to keep your Debian machines protected against active threats and repository errors.

[DSA 6351-1] thunderbird security update
ELA-1738-2 linux-5.10 regression update
ELA-1739-2 linux-6.1 regression update
[DSA 6351-1] chromium security update

Debian 11002 Published by Philipp Esselbach 0

Debian administrators should immediately apply a fresh batch of security patches released to protect their systems from multiple critical flaws across popular open source applications. LibreOffice and Nginx received urgent fixes for memory corruption and remote execution vulnerabilities that could allow attackers to crash software or take full control of affected machines through malicious files or network requests. Firefox ESR faces numerous sandbox escape and privilege escalation risks while Atril contains a dangerous command injection bug triggered by specially crafted PDF documents.

[DLA 4633-1] libreoffice security update
[DLA 4634-1] nginx security update
[DSA 6350-1] firefox-esr security update
[DSA 6349-1] atril security update

Debian 11002 Published by Philipp Esselbach 0

Debian administrators received three urgent security advisories that target serious vulnerabilities in gsasl, Asterisk, and Atril. The GNU SASL library needs a quick patch since its NTLM client lacks proper input sanitizing, which could expose sensitive memory contents to malicious users. Asterisk also demands immediate attention because developers fixed twelve separate issues involving heap overflows, stack underflows, and flawed certificate validation processes. Users running Debian GNU/Linux 11 (Bullseye) LTS or 12 (Bookworm) must upgrade their packages immediately to close these dangerous gaps before attackers can exploit them.

[DSA 6348-1] gsasl security update
[DLA 4631-1] asterisk security update
[DLA 4632-1] atril security update

Debian 11002 Published by Philipp Esselbach 0

Debian administrators need to apply a fresh security patch that tackles multiple critical flaws across the bird2 routing daemon, LibreOffice suite, and libgd-perl module right now. Attackers could exploit these weaknesses to crash systems through denial of service attacks or run arbitrary code by opening malicious documents. The stable Debian GNU/Linux 13 (Trixie) distribution already receives updated package versions designed to completely remove these dangerous vulnerabilities from your network. You should upgrade every affected system immediately before threat actors can take advantage of the unpatched software.

[DSA 6347-1] bird2 security update
[DSA 6346-1] libreoffice security update
[DSA 6345-1] libgd-perl security update

Debian 11002 Published by Philipp Esselbach 0

Debian Long Term Support recently issued urgent security patches for Apache2 version 2.4.59 and OpenSSL version 1.1.1w to resolve a wave of critical flaws. The Apache update addresses twelve separate CVEs that could enable remote code execution or information leaks through privilege escalation attacks. System administrators will also want to review the OpenSSL advisory which details five distinct issues including heap buffer overflows and dangerous memory handling errors.

ELA-1754-1 apache2 security update (by )
[DLA 4630-1] openssl security update

Debian 11002 Published by Philipp Esselbach 0

Debian has issued a critical security advisory for Chromium that patches 29 distinct vulnerabilities ranging from CVE-2026-12007 through CVE-2026-12035. These flaws could potentially let attackers execute arbitrary code on your machine or trigger denial of service attacks while exposing private information. Upgrade immediately to version 149.0.7827.114 on Debian GNU/Linux 12 (Bookworm) or Debian GNU/Linux 13 (Trixie) systems.

[DSA 6344-1] chromium security update

Debian 11002 Published by Philipp Esselbach 0

A fresh wave of Debian security advisories dropped and demands immediate attention from system operators who want to keep their networks safe. Critical vulnerabilities in apache2 librabbitmq and jpeg xl could allow malicious users to execute arbitrary code or trigger severe service crashes if left unpatched. The release also includes necessary updates for linux base and kernel wedge so they can properly support the upcoming Linux 6.12 backport on Debian 12 systems. Administrators should verify their current package versions right away since delayed upgrades leave infrastructure wide open to exploitation.

[DLA 4628-1] linux-base update
[DLA 4627-1] kernel-wedge update
[DLA 4629-1] apache2 security update
[DSA 6343-1] librabbitmq security update
{DSA 6342-1] jpeg-xl security update

Debian 11002 Published by Philipp Esselbach 0

Debian system administrators need to apply urgent security patches that address serious flaws across several widely used libraries and cloud infrastructure tools. The libinput driver requires an immediate upgrade because flawed device property handling could allow attackers to gain unauthorized root access on affected machines. Meanwhile, OpenStack deployments face multiple risks including data exposure and network rule bypasses until ironic and neutron receive their respective version updates. Developers relying on XML processing frameworks must also install fresh releases to stop recursive parsing errors from crashing applications or leaking sensitive memory information.

[DSA 6339-1] libinput security update
[DSA 6338-1] libdbi-perl security update
[DLA 4626-1] libinput security update
[DSA 6341-1] ironic security update
[DSA 6340-1] neutron security update
ELA-1753-1 libxml2 security update (by )

Debian 11002 Published by Philipp Esselbach 0

Debian released a batch of security advisories to patch critical flaws across four widely used packages. The dnsmasq update addresses multiple heap overflow and DNSSEC validation bugs that could allow attackers to inject false cache entries or trigger denial of service attacks. strongSwan patches a double free flaw that could crash the daemon. Chromium and Jackson-core also need urgent updates to stop arbitrary code execution and crash attacks, so system owners must deploy these patches immediately.

[DLA 4625-1] dnsmasq security update
[DSA 6330-1] strongswan security update
[DSA 6337-1] chromium security update
[DSA 6336-1] jackson-core security update

Debian 11002 Ubuntu 7156 Arch Linux 981 Published by Philipp Esselbach 0

Steven Barrett pushes Liquorix Linux Kernel 7.0-13 based on Kernel 7.0.12 to squash memory leaks, fix Thunderbolt property parsing race conditions, and clean up AMD and Intel graphics drivers. The update routes out of memory failures through proper cleanup paths and adds a hard recursion limit to prevent crafted peer devices from collapsing the kernel stack. Desktop users running external monitors or heavy GPU workloads will notice fewer random freezes and cleaner frame timing across interactive applications.

Debian 11002 Published by Philipp Esselbach 0

Debian issued a series of security advisories to address serious flaws in several key software packages. The OpenSSL updates tackle numerous vulnerabilities that could lead to denial of service or remote code execution, while Poppler receives patches to prevent data leaks and application crashes. Meanwhile, the Mistral workflow engine gets fixed for broken access controls, and Okular addresses a critical issue that could allow arbitrary code execution when opening damaged fax files.

[DLA 4624-1] openssl security update
[DSA 6335-1] openssl security update
[DSA 6334-1] poppler security update
[DSA 6333-1] mistral security update
[DSA 6332-1] okular security update

Debian 11002 Ubuntu 7156 Published by Philipp Esselbach 0

The XanMod Kernel 6.18.35 LTS and 7.0.12 drop into Debian-based systems with a heavy focus on fixing memory leaks in USB and Bluetooth drivers while tightening networking stack bounds checking. Official repositories make the five-minute installation straightforward, though users must register the GPG key and add the correct distribution codename before running the package manager. Systems relying on external kernel modules need the dkms and build dependency packages installed first to prevent driver compilation failures after the reboot. Verifying hardware detection and proprietary graphics modules on the first boot prevents silent failures, and the automated repository updates keep the optimized scheduler and memory tweaks current without manual intervention.

Debian 11002 Published by Philipp Esselbach 0

Debian system administrators should immediately apply security patches for Tomcat 10, Tomcat 11, Jackson Core, libxml2, and Keystone to address numerous critical vulnerabilities. Attackers could exploit these flaws to bypass authorization controls, expose sensitive data, or trigger denial of service conditions through malicious XML and JSON inputs. Fixed package versions are now available across both stable and extended maintenance releases, though upgrading related libraries might be necessary to prevent build failures. System operators must verify their current software versions and follow the official Debian tracking pages to ensure all identified CVEs are properly resolved on their servers.

[DSA 6329-1] tomcat11 security update
[DSA 6328-1] tomcat10 security update
[DLA 4623-1] jackson-core security update
[DLA 4622-1] libxml2 security update
[DSA 6331-1] keystone security update

Debian 11002 Published by Philipp Esselbach 0

Debian administrators received a batch of urgent security advisories targeting several widely used software packages. The patches address severe vulnerabilities across Apache2, the GNU C Library, Request Tracker, Nginx, and Chromium that could allow attackers to crash systems, execute malicious code, or steal sensitive information. System operators should prioritize upgrading to the recommended versions right away to close these dangerous attack vectors. These fixes span both extended support and current stable releases to maintain security across different Debian environments.

[DLA 4620-1] apache2 security update
ELA-1752-1 apache2 security update
[DLA 4621-1] glibc security update
[DSA 6327-1] request-tracker4 security update
[DSA 6326-1] nginx security update
[DSA 6325-1] chromium security update

Debian 11002 Published by Philipp Esselbach 0

Debian administrators must upgrade Dovecot, Request Tracker5, Apache2, and Tomcat9 to address a wave of critical vulnerabilities. These security advisories patch dangerous flaws ranging from denial of service crashes and path traversal errors to authentication bypasses and cross site scripting risks. Each package requires specific version updates tailored to either the oldstable or stable Debian releases, with some upgrades also demanding compatible native library revisions. System operators should verify their current configurations before applying these patches to ensure uninterrupted service across all affected components.

ELA-1751-1 dovecot security update
[DSA 6324-1] request-tracker5 security update
[DSA 6323-1] apache2 security update
[DLA 4619-1] tomcat9 security update

Debian 11002 Published by Philipp Esselbach 0

Ondřej Surý just pushed PHP 8.4.22/8.5.7 packages for Debian Bullseye, Bookworm, and Trixie, bringing much needed stability fixes to the tracing JIT and OpenSSL 4.0 compatibility layers. The update also patches several URI parsing vulnerabilities and cleans up error reporting in the intl and date extensions so your scripts stop throwing cryptic constant names at you. Getting it onto a Debian machine means adding the debsury.org source, refreshing the package index, and running a standard apt install without breaking older PHP versions that might still be in use. Once installed, verifying the active version and checking opcache behavior will keep background jobs from crashing when they hit unexpected interrupts.