Debian 11002 Published by Philipp Esselbach 0

Multiple Debian security advisories released to address severe vulnerabilities across several major software packages. The official updates resolve critical flaws in Chromium, the Linux kernel, MediaWiki, OpenVPN, Rsync, and Bird3 that could allow attackers to execute arbitrary code, bypass access controls, or trigger service disruptions. Debian LTS and stable distributions now ship patched versions to stop privilege escalation and prevent sensitive data leaks across both legacy and current operating system releases.

[DSA 6378-1] chromium security update
[DSA 6379-1] bird3 security update
ELA-1767-1 rsync security update (by )
[DLA 4671-1] linux-6.1 security update
[DLA 4653-2] openvpn regression update
[DSA 6381-1] linux security update
[DSA 6380-1] mediawiki security update
ELA-1762-2 openvpn regression update

Debian 11002 Ubuntu 7156 Published by Philipp Esselbach 0

XanMod maintainer Alexandre Frade has released Linux 7.1.3-xanmod1 and Linux 6.18.38-xanmod1, tracking the upstream point releases dropped on July 4, 2026. Both builds inherit all upstream stability and security patches while adding XanMod's performance enhancements, including LLVM ThinLTO compilation, sched_ext support, and Google's multigenerational LRU framework. The update offers users the choice between the mainline 7.1.x series or the 6.18 LTS branch, the latter of which features a dedicated real-time build for latency-sensitive workloads and is available via the official APT repository for Debian-based distributions. Third-party optimizations such as AMD's 3D V-Cache driver, Cloudflare's TCP collapse, and BBRv3 congestion control round out the release, alongside targeted fixes for ksmbd, apparmor, and various WiFi drivers.

Debian 11002 Published by Philipp Esselbach 0

Debian released security updates for php8.2 on Debian 12 and php8.4 on Debian 13 trixie to fix a buffer overflow in the openssl extension's AES Key Wrap with Padding implementation that causes memory corruption. A vulnerability in Sympa allows attackers to bypass authentication using arbitrary email addresses when the generic SSO login feature is enabled, while php-phpseclib on Debian 11 received patches for five issues including hostname validation bypasses, timing side-channels, denial of service, and server-side request forgery. Package versions 8.2.32-1deb12u1, 8.4.23-1deb13u1, 6.2.70~dfsg-2+deb12u1, and 2.0.30-2+deb11u3 resolve the flaws in their respective distributions. System administrators should upgrade php8.2, php8.4, sympa, and php-phpseclib packages immediately to secure their environments against these disclosed risks.

[DLA 4669-1] php8.2 security update
[DLA 4668-1] sympa security update
[DSA 6377-1] php8.4 security update
[DLA 4670-1] php-phpseclib security update

Debian 11002 Published by Philipp Esselbach 0

Debian LTS issued advisories on July 3 and 4, 2026, delivering emergency security patches for the Linux kernel, Nginx, and OpenVPN across multiple Debian releases. Version 5.10.259-1 now ships for Debian 11 bullseye, while version 6.1.176-1 replaces the previous build for Debian 12 bookworm, both neutralizing more than 200 kernel flaws that previously allowed privilege escalation, service disruptions, and data exposure. System administrators running Debian 12 should upgrade Nginx to 1.22.1-9+deb12u9 to close two remote code execution and memory disclosure flaws tied to HTTP/2 proxying and character set handling. OpenVPN received parallel fixes for Debian 12 bookworm and the current stable trixie distribution, patching six vulnerabilities that exposed virtual private network services to denial of service attacks.

[DLA 4664-1] linux security update
[DLA 4665-1] linux security update
[DLA 4667-1] nginx security update
[DLA 4666-1] openvpn security update
[DSA 6376-1] openvpn security update

Debian 11002 Published by Philipp Esselbach 0

Ondřej Surý has released fresh PHP packages spanning from 5.6 up to 8.5, with the newest builds landing at 8.4.22 and 8.5.8 for Debian 11, 12, 13 and Ubuntu 24.04 and 26.04 LTS. The debsury.org repository continues to support coinstalling multiple PHP versions simultaneously, allowing administrators to run specific builds alongside legacy branches without library conflicts. 

Debian 11002 Ubuntu 7156 Arch Linux 981 Published by Philipp Esselbach 0

Liquorix Linux Kernel 7.0-18 has been released, featuring a targeted fix for a use-after-free bug in the Project-C scheduler's active balance task. Built on top of Linux 7.0.14, the update continues to prioritize low-latency performance for gaming and A/V workloads. Debian and Ubuntu users can install the latest build via the official install script or PPA, while Arch Linux users can grab the linux-lqx package from the AUR. Maintainer Steven Barrett continues to deliver regular patches to keep the custom scheduler stable for high-interactivity desktop environments.

Debian 11002 Published by Philipp Esselbach 0

Debian has issued security patches for ImageMagick and FastNetMon to address twelve vulnerabilities each across multiple CVE identifiers. The ImageMagick update for Buster resolves flaws that allow denial of service, sensitive data exposure, or arbitrary code execution when the system processes corrupted image files. Administrators running FastNetMon on Debian Trixie should upgrade to version 1.2.9-0+deb13u1 to fix insecure TLS validation and prevent network traffic parsing errors from crashing the DDoS analyzer.

ELA-1766-1 imagemagick security update (by )
[DSA 6375-1] fastnetmon security update

Debian 11002 Ubuntu 7156 Arch Linux 981 Published by Philipp Esselbach 0

Liquorix Linux Kernel 7.0.17 has arrived, bringing a fresh upstream sync, hardware hardening updates like KFENCE, and new default configurations for memory hotplug and USB gadgets to the popular low-latency enthusiast kernel. Maintained by Steven Barrett, the project continues to push 1,000Hz scheduling, hard kernel preemption, and its custom PDS scheduler to optimize system responsiveness for gaming and audio/video production workloads. The update includes aggressive block layer tunables and a shift to the med_power_with_dipm SATA power policy, though users should be aware of occasional video playback freezes and NVIDIA driver build issues on specific hardware.

Debian 11002 Published by Philipp Esselbach 0

Debian LTS and Freexian Extended teams released four security advisories on July 1 and 2, 2026 to patch critical flaws across jq, librabbitmq, node-lodash, and apache2. The jq updates resolve memory corruption bugs that let attackers crash programs or execute arbitrary code via heap exploitation. Administrators also need to fix prototype pollution and code injection risks in node-lodash, AMQP communication errors in librabbitmq, and several remote code execution and privilege escalation issues in apache2.

[DLA 4661-1] jq security update
ELA-1764-1 librabbitmq security update
[DLA 4662-1] jq security update
[DLA 4663-1] node-lodash security update
ELA-1765-1 apache2 security update

Debian 11002 Published by Philipp Esselbach 0

Debian released four security advisories on June 30, 2026, to patch critical vulnerabilities in nginx and librabbitmq across multiple operating system versions. The nginx patches address two distinct flaws that could allow unauthenticated attackers to trigger heap buffer overflows or memory leaks, affecting both Debian 11 and Debian 13. Administrators must also update librabbitmq to resolve an underflow issue and a handshake overflow that compromise AMQP connections on Debian 11 and Debian 12. The advisory tracker update simultaneously marks the end of long-term security support for pagure, suricata, webkit2gtk, spip, and zulucrypt, while placing epiphany-browser and libsoup2.4 under limited protection.

[DLA 4660-1] nginx security update
[DLA 4659-1] debian-security-support update
[DLA 4658-1] librabbitmq security update
[DSA 6374-1] nginx security update

Debian 11002 Published by Philipp Esselbach 0

Debian LTS released advisory DLA-4657-1 addressing six vulnerabilities in the Sogo webmail server, including SQL injection flaws affecting PostgreSQL and MariaDB backends, XSS issues in calendar and contact views, and TOTP implementation problems. The update also resolves an arbitrary JavaScript execution risk caused by malicious .ICS files, SQL injection in ACL management allowing data extraction by authenticated users, and an XSS flaw in message subject rendering, pushing the package to version 5.8.0-2+deb12u3. Separate guidance via ELA-1760-1 targets Yelp, the GNOME help browser, by correcting CVE-2026-13601 which enables crafted documents to read local user files and exfiltrate them to remote servers through the embedded web view. This vulnerability also permits a sandbox escape when launching the application via Flatpak, affecting versions 3.22.0-1+deb9u2 for Debian stretch and 3.31.90-1+deb10u2 for Debian buster.

[DLA 4657-1] sogo security update
ELA-1760-1 yelp security update

Debian 11002 Published by Philipp Esselbach 0

Debian has released security patches for libhtml-parser-perl, LXD, and Tor across multiple distribution branches. The libhtml-parser-perl update resolves CVE-2026-8829, which allows an attacker to read freed heap memory through the _decode_entities() function. LXD receives fixes for twelve separate vulnerabilities that could otherwise let attackers bypass container restrictions or run unauthorized commands. Tor updates address undisclosed denial of service flaws for Debian stretch, buster, bookworm, and trixie.

[DLA 4655-1] libhtml-parser-perl security update
[DSA 6373-1] lxd security update
[DSA 6372-1] tor security update
ELA-1763-1 libhtml-parser-perl security update
[DLA 4656-1] tor security update

Debian 11002 Ubuntu 7156 Published by Philipp Esselbach 0

XanMod has released three fresh kernel builds, rounding out its maintenance cycle with 7.1.2-xanmod1, 7.0.14-xanmod1, and 6.18.37-xanmod1 LTS. The packages bundle essential upstream maintenance including virtiofs use-after-free patches, Rose networking cleanup, and bnxt_re memory safety fixes. Alongside the upstream work, XanMod continues shipping its custom performance stack featuring LLVM ThinLTO compilation, default BBRv3 congestion control, Cloudflare TCP patches, and dedicated Steam Deck and AMD 3D V-Cache modules. Debian and Ubuntu users can upgrade across four x86_64 ABI tiers, with the LTS branch offering a dedicated PREEMPT_RT variant for ultra-low latency workloads.

Debian 11002 Published by Philipp Esselbach 0

Debian released security advisories addressing vulnerabilities in xorg-server, OpenVPN, and Chromium that could result in privilege escalation, server crashes, and arbitrary code execution. The xorg-server patch resolves nine CVEs that allow attackers to gain elevated access when the X server runs with privileges, while the OpenVPN fix targets a race condition caused by use-after-free errors during TLS session promotion that risks memory leaks and denial of service. Chromium receives the most extensive update with eighteen CVEs resolved in the LTS distribution, preventing potential remote code execution, denial of service, and information disclosure.

[DSA 6370-1] xorg-server security update
ELA-1762-1 openvpn security update
[DLA 4654-1] chromium security update

Debian 11002 Published by Philipp Esselbach 0

Debian released multiple security advisories, addressing critical vulnerabilities across giflib, libdbi-perl, python-urllib3, incus, ansible, openvpn, and gdcm. These updates resolve buffer overflow exploits, information disclosure flaws, denial-of-service risks, and authorization bypass issues that could compromise system stability and sensitive data.

[DLA 4650-1] giflib security update
[DLA 4649-1] libdbi-perl security update
[DLA 4651-1] python-urllib3 security update
ELA-1758-1 libdbi-perl security update
ELA-1757-1 giflib security update
[DSA 6370-1] incus security update
ELA-1759-1 ansible security update
[DLA 4653-1] openvpn security update
[DLA 4652-1] gdcm security update
ELA-1761-1 python-urllib3 security update
ELA-1760-1 yelp security update

Debian 11002 Published by Philipp Esselbach 0

Debian and Freexian security teams released updated advisories for packages including pdns, dnsdist, libtext-csv-xs-perl, SOGo, libssh2, and Chromium. The updates resolve flaws that enable attackers to trigger denial of service attacks, poison DNS caches, execute cross-site scripting code, and run arbitrary commands.

[DSA 6368-1] pdns security update
[DSA 6367-1] dnsdist security update
[DLA 4648-1] libtext-csv-xs-perl security update
[DSA 6366-1] sogo security update
[DSA 6365-1] libssh2 security update
[DSA 6364-1] chromium security update
[DSA 6369-1] pdns-recursor security update
ELA-1756-1 libtext-csv-xs-perl security update

Debian 11002 Ubuntu 7156 Arch Linux 981 Published by Philipp Esselbach 0

Liquorix Kernel 7.0.15 is live, built on the Linux 7.0.13 base to deliver targeted latency improvements and a critical hard freeze fix. The release abandons the mq-deadline block scheduler in favor of kyber and bfq, while cutting CPU timeslices down to 2ms for tighter interactivity. Liquorix also disables split-lock detection and adjusts virtual memory watermarks to smooth out latency spikes during demanding workloads. You can grab the updated kernel immediately using their automated curl installer, which pushes fresh binaries to Debian, Ubuntu, and Archl Linux within hours of the release.

Debian 11002 Published by Philipp Esselbach 0

As of right now, Debian maintains a steady stream of emergency patches, and this latest batch tackles roughly six distinct vulnerabilities across major Linux packages. Longtime system watchers notice a familiar pattern of technical debt piling up across database tools, yet administrators must return to prioritizing this specific upgrade before the next wave of exploits surfaces. Roughly equivalent trouble waits in cloud-init, where broken repository links stop machines from grabbing security updates, while yelp, libhttp-daemon-perl, and libmatio open doors for sandbox escapes, arbitrary command execution, and remote code execution.

[DLA 4644-1] libmatio security update
ELA-1755-1 libhttp-daemon-perl security update (by )
[DLA 4645-1] cloud-init - correct sources.list generation
[DLA 4646-1] postgresql-13 security update
[DLA 4647-1] yelp security update

Debian 11002 Published by Philipp Esselbach 0

Debian shipped critical updates for gst-plugins-bad1.0, python-urllib3, ImageMagick, u-boot, and beets across trixie, bullseye, and bookworm. The gst-plugins patch squashes three CVEs including CVE-2026-52718 and CVE-2026-53701 that let corrupted media trigger crashes, while the urllib3 update plugs that cross-origin redirect leak that’s arguably slipped past developers for months.

[DSA 6362-1] gst-plugins-bad1.0 security update
[DSA 6363-1] python-urllib3 security update
[DLA 4643-1] imagemagick security update
[DLA 4642-1] u-boot security update
[DLA 4641-1] beets security update

Debian 11002 Published by Philipp Esselbach 0

Debian has published an urgent security advisory for the ffmpeg multimedia toolkit to address several dangerous vulnerabilities linked to CVE-2025-22921, CVE-2026-8461, and CVE-2026-30997. Malformed media inputs could trigger system crashes or allow remote attackers to run arbitrary code on vulnerable machines. The trixie stable release now ships the corrected version 7:7.1.5-0+deb13u1 to completely mitigate these risks.

[SECURITY] [DSA 6361-1] ffmpeg security update