Debian administrators received two security advisories addressing critical flaws in the kissfft and libssh packages. The kissfft library contains two integer overflow bugs tracked under CVE-2025-34297 and CVE-2026-41445 that now require version 131.1.0-1+deb11u1 on Debian 11 bullseye. The libssh C library faces fourteen separate vulnerabilities across multiple CVEs, including risks for denial of service and arbitrary code execution, with a patch available at version 0.11.5-0+deb13u1 for the trixie distribution.
[SECURITY] [DLA 4715-1] kissfft security update
[SECURITY] [DSA 6410-1] libssh security update
Debian has released security patches for six packages that contain multiple exploitable vulnerabilities. The Chromium browser update resolves over one hundred flaws that could allow attackers to run malicious code or steal sensitive data, while fixes for node-tar and Starlette block dangerous archive extraction bypasses and HTTP request poisoning attacks. Additional advisories address a stack buffer overflow in libmodbus, a link following flaw in sslh, and a denial of service risk in the libgd2 graphics library that triggers when processing corrupted GIF files.
[DLA 4712-1] node-tar security update
[DLA 4711-1] starlette security update
[DSA 6409-1] libgd2 security update
[DLA 4710-1] chromium security update
[DLA 4713-1] sslh security update
[DLA 4714-1] libmodbus security update
Debian administrators received a coordinated batch of security advisories, covering python-authlib, the Linux kernel, Chromium, Poppler, Incus, and PHP 8.4. The released patches resolve dozens of CVEs that could let remote attackers execute arbitrary code, bypass authentication checks, forge digital signatures, trigger denial-of-service crashes, or extract sensitive data through crafted file inputs. Operators need to upgrade their systems immediately to the specific Debian bullseye, bookworm, and trixie package versions listed in each advisory to close these vulnerabilities. Full vulnerability details and ongoing status tracking remain available on the official Debian security tracker for every affected component.
[DLA 4708-1] python-authlib security update
[DSA 6405-1] linux security update
[DSA 6408-1] chromium security update
[DLA 4709-1] poppler security update
[DSA 6407-1] incus security update
[DSA 6406-1] php8.4 security update
Liquorix linux-liquorix 7.1-7 released on July 31, 2026, bringing a single focused packaging change: stripping out the irqbalance recommendation and disabling the service during installation. The kernel remains based on Linux 7.1.5, continuing a rapid 18-day sprint that has produced seven releases as the project aggressively converges scheduler logic with upstream mainline. Available now for Debian and Ubuntu on amd64, the update is the latest step in an enthusiast kernel built specifically for interactive responsiveness and gaming workloads over background automation.
Debian issued security advisories addressing critical vulnerabilities in the expat, libraw, imagemagick, gsasl, and ruby-rack packages. The patches resolve integer overflows, heap buffer overflows, memory disclosure flaws, and arbitrary code execution risks that could allow attackers to crash systems or run unauthorized commands via malformed inputs. Detailed findings include multipart smuggling and denial-of-service vectors in ruby-rack, regex injection flaws in imagemagick and libraw, and missing input sanitization in the gsasl NTLM client.
[DSA 6404-1] expat security update
ELA-1790-1 libraw security update (by )
ELA-1789-1 imagemagick security update (by )
[DLA 4707-1] gsasl security update
[DLA 4706-1] ruby-rack security update
XanMod Linux Kernel 6.18.41-xanmod1 arrived today and built on top of upstream Linux 6.18.41 LTS. The kernel compiles with LLVM ThinLTO across three x86-64 ABI tiers and applies a curated collection of performance patches, including Google BBRv3, AMD 3D V-Cache optimization, and Cloudflare TCP Collapse. This point release prioritizes stability by backporting Thomas Gleixner's fixes for posix-cpu-timers use-after-free vulnerabilities and timer arm callback validation. The 6.18 branch provides long-term support through December 2028 and bundles NVIDIA graphics drivers for both open and proprietary stacks.
Debian issued two security advisories, addressing critical flaws in the calibre e-book manager and the nss cryptography library. The calibre update (DLA-4705-1) resolves five vulnerabilities across CVE-2026-27810, CVE-2026-27824, CVE-2026-30853, CVE-2026-33205, and CVE-2026-33206, which include path traversal risks in the RocketBook plugin, HTTP response header injection, brute-force protection bypasses via spoofed headers, and server-side request forgery that could expose data from the ebook sandbox. The nss advisory (DSA-6403-1) fixes CVE-2026-16389 in the Mozilla Network Security Service library, where processing a maliciously crafted certificate could trigger arbitrary code execution. Users running Debian 11 bullseye should upgrade calibre to version 5.12.0+dfsg-1+deb11u5 immediately, while trixie users must apply nss update 2:3.110-1+deb13u4 to close these security gaps.
[DLA 4705-1] calibre security update
[DSA 6403-1] nss security update
Debian developers are casting preferential votes on how the project handles LLM-assisted contributions, with five competing resolutions currently in discussion. The proposals range from a hard ban on AI-generated code to a permissive framework that mandates disclosure and contributor accountability. The core tension pits volunteer reviewer burnout and copyright clarity against the practical reality that many maintainers already rely on AI for day-to-day work. Results will land in the coming weeks and likely define Debian's official stance on generative AI for the next several years.
Debian released security advisories covering critical updates for Samba, OpenJDK Java runtimes, HPLIP printing software, libxfont1, and libraw image library across stable and LTS distributions. The advisories remediate vulnerabilities that could allow attackers to achieve privilege escalation, arbitrary code execution, domain takeover, sandbox bypasses, or data corruption through specially crafted inputs targeting buffer handling and decoder routines in these applications.
[DSA 6401-1] samba security update
[DLA 4703-1] openjdk-17 security update
[DLA 4702-1] openjdk-11 security update
ELA-1787-1 openjdk-11 security update (by )
[DSA 6402-1] hplip security update
ELA-1788-1 libxfont1 security update (by )
[DLA 4704-1] libraw security update
Debian Long Term Support released advisory DLA-4701-1 to update Chromium version 150.0.7871.181-1~deb12u1 on Debian 12 Bookworm. The patch resolves eighteen vulnerabilities identified under CVE identifiers from CVE-2026-15899 through CVE-2026-16424 that could enable arbitrary code execution, denial of service attacks, or unauthorized data access.
[SECURITY] [DLA 4701-1] chromium security update
Liquorix Linux Kernel 7.1-6 has arrived, merging upstream Linux Kernel 7.1.5 and rolling out targeted fixes to Steven Barrett’s custom Project-C scheduler. The update introduces auto-detection for heterogeneous CPU topologies, improving task placement on modern hybrid processors like Intel Meteor Lake and AMD Zen 4/5. Designed for gamers and multimedia creators, the AMD64-only build trades power efficiency and raw throughput for aggressive 1000Hz scheduling and lower input latency.
Debian Long Term Support and Freexian Extended advisories released security patches addressing serious flaws in the linux-6.1 kernel, hplip printing software, BIND9 DNS server, and php-phpseclib cryptography library. The update for linux-6.1 closes more than fifty vulnerabilities that could enable privilege escalation or information disclosure on Debian 11 systems while also incorporating changes to the Azure Network Adapter driver. Additional fixes resolve arbitrary code execution risks in HP's printing tools across multiple distributions and repair DNSSEC bypass, cache poisoning, and denial of service weaknesses in BIND9 for older releases.
[DLA 4700-1] linux-6.1 security update
[DLA 4699-1] hplip security update
ELA-1784-1 hplip security update
ELA-1786-1 bind9 security update
ELA-1785-1 php-phpseclib security update (by )
XanMod has released updated builds for its Mainline and LTS kernel branches, bringing the 7.1.5 and 6.18.40 upstream releases to Debian-based systems. The builds layer in LLVM ThinLTO compilation, Google BBRv3 congestion control, Cloudflare TCP collapse processing, and the AMD 3D V-Cache optimizer. Upstream security work takes center stage, closing critical ksmbd SMB server vulnerabilities, NTFS bounds-checking gaps, and a long-standing POSIX CPU timer use-after-free. Users can install via APT using psABI-matched packages, though NVIDIA DKMS driver compatibility should be verified before switching branches.
Debian administrators must apply four new security patches targeting critical flaws in spice-vdagent, ImageMagick, GRUB2, and Exim4 this month. The spice-vdagent release closes an integer overflow that crashes virtual machines alongside a path traversal bug permitting unauthorized file writes, while ImageMagick addresses more than twelve issues where malformed images risk denial of service or arbitrary code execution. GRUB2 clears twenty weaknesses tied to UEFI Secure Boot bypasses and system instability, and Exim4 patches two mail server bugs that enabled local privilege escalation. System operators running Debian 10 through 13 should upgrade to the specified package versions right away to block active exploitation.
[DLA 4698-1] spice-vdagent security update
[DLA 4696-1] imagemagick security update
ELA-1783-1 grub2 security update (by )
[DSA 6400-1] exim4 security update
Debian released four security advisories on July 23 and 24, 2026, targeting serious vulnerabilities in pdns-recursor, webkit2gtk, squid, and wordpress. The pdns-recursor update closes two specific flaws that could enable cache poisoning or bypass DNSSEC validation checks. WebKitGTK received over thirty fixes for bugs that allowed arbitrary JavaScript execution, sandbox escapes, clipboard hijacking, memory corruption, and silent data leaks when browsers processed malicious web pages.
[DSA 6397-1] pdns-recursor security update
[DSA 6398-1] webkit2gtk security update
[DLA 4697-1] squid security update
[DSA 6399-1] wordpress security update
ELA-1782-1 squid security update
Debian released a batch of security advisories addressing critical flaws in the NSS cryptographic libraries, Firefox ESR web browser, Chromium browser, and BIND9 DNS server across both current stable and legacy Long Term Support distributions. The NSS update patches four CVEs that could allow denial of service or arbitrary code execution for Debian 11, Debian 12, and older Stretch/Buster releases managed by Freexian, while Firefox ESR and Chromium fixes address over 40 vulnerabilities linked to privilege escalation, sandbox escapes, and data leaks. BIND9 administrators must install the new package version immediately to prevent DNSSEC validation bypasses, cache poisoning attacks, and service disruptions identified in nine separate security issues.
[DLA 4694-1] nss security update
ELA-1781-1 nss security update
ELA-1780-1 nss security update
[DSA 6394-1] firefox-esr security update
[DSA 6396-1] chromium security update
[DSA 6395-1] bind9 security update
[DLA 4695-1] firefox-esr security update
Debian released multiple security advisories addressing vulnerabilities in rtpengine, the Linux kernel, Samba, Tomcat8, Roundcube, xz-utils, and ImageMagick. The Linux kernel update for Debian stable (trixie) resolves twelve CVEs linked to privilege escalation and denial of service, while Samba fixes five issues including remote code execution and certificate verification flaws across Debian 10 and 11. Roundcube patches six vulnerabilities involving cross-site scripting and account takeover risks on Debian 11 and 12, whereas xz-utils addresses a buffer overflow in the LZMA decoder and ImageMagick corrects nine flaws that could allow arbitrary code execution via malformed image files.
[DLA 4691-1] rtpengine security update
[DSA 6393-1] linux security update
[DLA 4692-1] samba security update
ELA-1777-1 tomcat8 security update (by )
[DLA 4693-1] roundcube security update
[DLA 4690-1] xz-utils security update
ELA-1779-1 samba security update (by )
ELA-1778-1 imagemagick security update (by )
Debian has issued a security patch for ImageMagick version 8:6.9.10.23+dfsg-2.1+deb10u20 on the Buster operating system. The ELA-1776-1 release resolves nine flaws tracked under multiple CVE identifiers issued in 2026. Attackers can exploit these weaknesses by feeding crafted image files to the application, which may trigger service outages or leak private data. The update also blocks potential remote code execution for users relying on the Debian extended support track.
ELA-1776-1 imagemagick security update
Liquorix Kernel 7.1-5 dropped on July 19, 2026, merging upstream Linux v7.1.4 with over 40 patches that realign its custom Project-C scheduler with mainline locking models. The update slashes the default scheduling timeslice to 2ms, disables split lock detection, and zeroes out watermark boost to aggressively prioritize low-latency task switching for gaming and multimedia workloads. While it locks support strictly to AMD64 and x86_64 hardware, the kernel trades sustained throughput and power efficiency for tighter system responsiveness that creative professionals and desktop tinkerers will actually notice.
Debian released updates for libnfs that patch CVE-2026-53689, which stems from unchecked string lengths causing integer overflows. The tiff library update addresses CVE-2026-12912, allowing attackers to crash systems or run arbitrary code when processing malformed images. Users must upgrade roundcube to version 1.6.17+dfsg-0+deb13u1 to patch six vulnerabilities that enable cross-site scripting, SSRF bypasses, and complete account takeovers.
ELA-1775-1 libnfs security update (by )
[DSA 6392-1] tiff security update
[DSA 6391-1] roundcube security update