Debian 11049 Published by Philipp Esselbach 0

Debian and Freexian issued a series of security advisories to patch critical flaws across Linux kernels, Thunderbird, Nginx, Redis, and libheif on multiple Debian releases. The kernel updates for versions 6.1 and 6.12 address dozens of common vulnerabilities that could allow attackers to escalate privileges, leak memory, or crash systems. Separate advisories cover remote code execution risks in Thunderbird and Nginx, a heap overflow in the Redis RESTORE command, and memory safety issues in the libheif image decoder. System administrators should manually install the updated packages through their package managers to apply these fixes immediately.

[DLA 4724-1] linux-6.12 new package
[DLA 4723-1] linux-6.1 security update
ELA-1796-1 linux-6.1 security update (by )
ELA-1795-1 redis security update (by )
[DSA 6417-1] libheif security update
[DSA 6418-1] thunderbird security update
ELA-1797-1 nginx security update (by )

Debian 11049 Published by Philipp Esselbach 0

Debian security teams released a batch of advisories to address multiple flaws across seven widely used packages. The updates patch remote code execution risks in the p7zip archiver, potential memory corruption in the libde265 video codec, a local privilege escalation in udisks2, cookie injection flaws in the async-http-client Java library, denial of service and arbitrary code execution threats in the jq JSON processor, a double-free memory bug in Redis, and dozens of kernel-level privilege escalation and information leak issues. Patched builds are now available for the trixie stable release alongside older LTS branches, with the Linux kernel jumping to 6.12.101 and Redis reaching 5.0.14 on Debian 10.

ELA-1794-1 p7zip security update (by )
[DSA 6413-1] libde265 security update
[DSA 6414-1] udisks2 security update
[DLA 4721-1] async-http-client security update
[DSA 6415-1] linux security update
[DSA 6416-1] jq security update
[DLA 4722-1] redis security update

Debian 11049 Ubuntu 7192 Arch Linux 996 Published by Philipp Esselbach 0

Steven Barrett has released Liquorix Linux kernel 7.1-9, shifting focus from feature additions to stabilizing "Project-C,". The release bundles roughly eleven patches, including eight direct upstream syncs that align Project-C with current mainline scheduler development alongside Liquorix-specific hardening tweaks like default latency warning suppression. AMD64 users can install the kernel via the official script or distribution PPAs, though those with AMDGPU hardware should exercise caution as several open issues report hard freezes on integrated graphics. This point release marks a deliberate move toward upstream parity and maintenance consolidation after a rapid development sprint throughout the 7.1 series.

Debian 11049 Published by Philipp Esselbach 0

Debian LTS issued advisory DLA-4717-1 to update the Linux 5.10 kernel to version 5.10.262-1, addressing dozens of CVEs that could enable privilege escalation, denial of service, or information leaks on Debian 9, 10, and 11 systems. Advisory DLA-4720-1 brings kernel version 6.1.180-1 to Debian 12, resolving comparable security issues and adding fixes for earlier vulnerabilities like CVE-2024-36013. The p7zip package undergoes a significant replacement with 7-Zip version 26.02 under advisory DLA-4719-1, eliminating CVE-2026-14266 which permits remote code execution via XZ heap buffer overflow and CVE-2026-58052 that risks file content spoofing on RAR5 archives. Direct 7zip packages also advance to version 26.02 for Debian 12, while FreeXian extends these p7zip and kernel fixes to Debian 9 and 10 through ELA-1793-1 and ELA-1794-1 for extended lifecycle support.

[DLA 4717-1] linux security update
ELA-1793-1 linux-5.10 security update (by )
[DLA 4720-1] linux security update
[DLA 4719-1] p7zip security update
[DLA 4718-1] 7zip security update
ELA-1794-1 p7zip security update (by )

Debian 11049 Ubuntu 7192 Arch Linux 996 Published by Philipp Esselbach 0

Liquorix kernel 7.1-8 just landed, tracking upstream Linux 7.1.6 and bringing enhanced ACS override support for GPU passthrough enthusiasts. Maintainer Steven Barrett shipped the build on August 4, continuing an aggressive four-day turnaround that mirrors upstream stable point releases. The update pulls in modern hardware support including NTFSPLUS, Apple Silicon power reporting for Asahi users, and Intel FRED enabled by default for Arrow Lake processors. You're getting the usual PDS-scheduling and 2ms timeslice tweaks that make Liquorix a favorite for gaming and low-latency workloads, though you should retest your drivers before rebooting.

Debian 11049 Published by Philipp Esselbach 0

Debian released DLA-4716-1 to patch four vulnerabilities in ruby2.7, including a DNS decompression flaw that triggers denial of service and an ERB deserialization bug that allows arbitrary code execution on untrusted data. The botan3 advisory addresses CVE-2026-44378 by upgrading the C++ cryptography library to version 3.12.0, which resolves certificate validation and authentication bypass flaws while renaming the shared library package from libbotan-3-7 to libbotan-3-12.

[DLA 4716-1] ruby2.7 security update
[DSA 6412-1] botan3 security update
[DSA 6411-1] aom security update

Debian 11049 Published by Philipp Esselbach 0

Debian released ELA-1791-1 and ELA-1792-1 to patch critical security flaws in OpenJDK 8 version 8u502-ga-1~deb9u1 and Poppler across stretch and buster distributions. The Java runtime update addresses ten vulnerabilities that could enable denial of service attacks, unauthorized data access, or sandbox restriction bypasses. Poppler patches six PDF processing flaws, including signature forgery risks, infinite recursion crashes, use-after-free memory corruption, and integer overflow errors that enable arbitrary code execution.

ELA-1791-1 openjdk-8 security update (by )
ELA-1792-1 poppler security update (by )

Debian 11049 Ubuntu 7192 Published by Philipp Esselbach 0

XanMod just published two new performance kernels today: the flagship 7.1.6-xanmod1 and the long-term support track at 6.18.42-xanmod1. The 7.1 series finally makes multigenerational LRU and sched_ext defaults production-ready, while XanMod's out-of-tree patches bake in Google's BBRv3 congestion algorithm, Cloudflare TCP collapse processing, and a dedicated AMD 3D V-Cache optimizer. You can grab precompiled packages across four CPU architecture tiers from the official APT repository, alongside DKMS modules for NVIDIA, OpenZFS, VirtualBox, and VMware.

Debian 11049 Ubuntu 7192 Published by Philipp Esselbach 0

Debian and Ubuntu users pulling from DEB.SURY.ORG received a coordinated batch of PHP updates across all active branches, led by PHP 8.4.24 and the development release 8.5.9. The July 30 patch cycle addresses high-severity vulnerabilities including a BCMath out-of-bounds write and a PostgreSQL SQL injection via pg_query(), alongside significant opcache stability fixes for the JIT. This three-week gap from the previous release indicates an emergency response to newly disclosed critical CVEs, prompting SURY to push security-only updates to both current stable and end-of-life approaching branches. Operators should upgrade immediately via apt-get update and verify GPG signatures, though 8.5 users are advised to test carefully due to the heavy changes to the tracing JIT and default OpCache behavior.

Debian 11049 Published by Philipp Esselbach 0

Debian administrators received two security advisories addressing critical flaws in the kissfft and libssh packages. The kissfft library contains two integer overflow bugs tracked under CVE-2025-34297 and CVE-2026-41445 that now require version 131.1.0-1+deb11u1 on Debian 11 bullseye. The libssh C library faces fourteen separate vulnerabilities across multiple CVEs, including risks for denial of service and arbitrary code execution, with a patch available at version 0.11.5-0+deb13u1 for the trixie distribution.

[SECURITY] [DLA 4715-1] kissfft security update
[SECURITY] [DSA 6410-1] libssh security update

Debian 11049 Published by Philipp Esselbach 0

Debian has released security patches for six packages that contain multiple exploitable vulnerabilities. The Chromium browser update resolves over one hundred flaws that could allow attackers to run malicious code or steal sensitive data, while fixes for node-tar and Starlette block dangerous archive extraction bypasses and HTTP request poisoning attacks. Additional advisories address a stack buffer overflow in libmodbus, a link following flaw in sslh, and a denial of service risk in the libgd2 graphics library that triggers when processing corrupted GIF files.

[DLA 4712-1] node-tar security update
[DLA 4711-1] starlette security update
[DSA 6409-1] libgd2 security update
[DLA 4710-1] chromium security update
[DLA 4713-1] sslh security update
[DLA 4714-1] libmodbus security update

Debian 11049 Published by Philipp Esselbach 0

Debian administrators received a coordinated batch of security advisories, covering python-authlib, the Linux kernel, Chromium, Poppler, Incus, and PHP 8.4. The released patches resolve dozens of CVEs that could let remote attackers execute arbitrary code, bypass authentication checks, forge digital signatures, trigger denial-of-service crashes, or extract sensitive data through crafted file inputs. Operators need to upgrade their systems immediately to the specific Debian bullseye, bookworm, and trixie package versions listed in each advisory to close these vulnerabilities. Full vulnerability details and ongoing status tracking remain available on the official Debian security tracker for every affected component.

[DLA 4708-1] python-authlib security update
[DSA 6405-1] linux security update
[DSA 6408-1] chromium security update
[DLA 4709-1] poppler security update
[DSA 6407-1] incus security update
[DSA 6406-1] php8.4 security update

Debian 11049 Ubuntu 7192 Arch Linux 996 Published by Philipp Esselbach 0

Liquorix linux-liquorix 7.1-7 released on July 31, 2026, bringing a single focused packaging change: stripping out the irqbalance recommendation and disabling the service during installation. The kernel remains based on Linux 7.1.5, continuing a rapid 18-day sprint that has produced seven releases as the project aggressively converges scheduler logic with upstream mainline. Available now for Debian and Ubuntu on amd64, the update is the latest step in an enthusiast kernel built specifically for interactive responsiveness and gaming workloads over background automation.

Debian 11049 Published by Philipp Esselbach 0

Debian issued security advisories addressing critical vulnerabilities in the expat, libraw, imagemagick, gsasl, and ruby-rack packages. The patches resolve integer overflows, heap buffer overflows, memory disclosure flaws, and arbitrary code execution risks that could allow attackers to crash systems or run unauthorized commands via malformed inputs. Detailed findings include multipart smuggling and denial-of-service vectors in ruby-rack, regex injection flaws in imagemagick and libraw, and missing input sanitization in the gsasl NTLM client.

[DSA 6404-1] expat security update
ELA-1790-1 libraw security update (by )
ELA-1789-1 imagemagick security update (by )
[DLA 4707-1] gsasl security update
[DLA 4706-1] ruby-rack security update

Debian 11049 Ubuntu 7192 Published by Philipp Esselbach 0

XanMod Linux Kernel 6.18.41-xanmod1 arrived today and built on top of upstream Linux 6.18.41 LTS. The kernel compiles with LLVM ThinLTO across three x86-64 ABI tiers and applies a curated collection of performance patches, including Google BBRv3, AMD 3D V-Cache optimization, and Cloudflare TCP Collapse. This point release prioritizes stability by backporting Thomas Gleixner's fixes for posix-cpu-timers use-after-free vulnerabilities and timer arm callback validation. The 6.18 branch provides long-term support through December 2028 and bundles NVIDIA graphics drivers for both open and proprietary stacks.

Debian 11049 Published by Philipp Esselbach 0

Debian issued two security advisories, addressing critical flaws in the calibre e-book manager and the nss cryptography library. The calibre update (DLA-4705-1) resolves five vulnerabilities across CVE-2026-27810, CVE-2026-27824, CVE-2026-30853, CVE-2026-33205, and CVE-2026-33206, which include path traversal risks in the RocketBook plugin, HTTP response header injection, brute-force protection bypasses via spoofed headers, and server-side request forgery that could expose data from the ebook sandbox. The nss advisory (DSA-6403-1) fixes CVE-2026-16389 in the Mozilla Network Security Service library, where processing a maliciously crafted certificate could trigger arbitrary code execution. Users running Debian 11 bullseye should upgrade calibre to version 5.12.0+dfsg-1+deb11u5 immediately, while trixie users must apply nss update 2:3.110-1+deb13u4 to close these security gaps.

[DLA 4705-1] calibre security update
[DSA 6403-1] nss security update

Debian 11049 Published by Philipp Esselbach 0

Debian developers are casting preferential votes on how the project handles LLM-assisted contributions, with five competing resolutions currently in discussion. The proposals range from a hard ban on AI-generated code to a permissive framework that mandates disclosure and contributor accountability. The core tension pits volunteer reviewer burnout and copyright clarity against the practical reality that many maintainers already rely on AI for day-to-day work. Results will land in the coming weeks and likely define Debian's official stance on generative AI for the next several years.

Debian 11049 Published by Philipp Esselbach 0

Debian released security advisories covering critical updates for Samba, OpenJDK Java runtimes, HPLIP printing software, libxfont1, and libraw image library across stable and LTS distributions. The advisories remediate vulnerabilities that could allow attackers to achieve privilege escalation, arbitrary code execution, domain takeover, sandbox bypasses, or data corruption through specially crafted inputs targeting buffer handling and decoder routines in these applications.

[DSA 6401-1] samba security update
[DLA 4703-1] openjdk-17 security update
[DLA 4702-1] openjdk-11 security update
ELA-1787-1 openjdk-11 security update (by )
[DSA 6402-1] hplip security update
ELA-1788-1 libxfont1 security update (by )
[DLA 4704-1] libraw security update

Debian 11049 Published by Philipp Esselbach 0

Debian Long Term Support released advisory DLA-4701-1 to update Chromium version 150.0.7871.181-1~deb12u1 on Debian 12 Bookworm. The patch resolves eighteen vulnerabilities identified under CVE identifiers from CVE-2026-15899 through CVE-2026-16424 that could enable arbitrary code execution, denial of service attacks, or unauthorized data access.

[SECURITY] [DLA 4701-1] chromium security update

Debian 11049 Ubuntu 7192 Arch Linux 996 Published by Philipp Esselbach 0

Liquorix Linux Kernel 7.1-6 has arrived, merging upstream Linux Kernel 7.1.5 and rolling out targeted fixes to Steven Barrett’s custom Project-C scheduler. The update introduces auto-detection for heterogeneous CPU topologies, improving task placement on modern hybrid processors like Intel Meteor Lake and AMD Zen 4/5. Designed for gamers and multimedia creators, the AMD64-only build trades power efficiency and raw throughput for aggressive 1000Hz scheduling and lower input latency.