expat (SSA:2026-077-01)
Slackware Linux has issued updated expat packages for version 15.0 and current branches specifically to address multiple significant security issues. These patches address critical vulnerabilities involving NULL pointers and potential infinite loops within the processing functions.
expat (SSA:2026-077-01)
expat (SSA:2026-077-01)
New packages are available for libxml2 and libarchive to fix security issues on Slackware 15.0 and -current. The updates for libxml2 address several vulnerabilities, including memory leaks and infinite recursion, while the update for libarchive fixes bugs and security issues such as NULL pointer dereferences and potential memory leaks.
libxml2 (SSA:2026-070-02)
libarchive (SSA:2026-070-01)
libxml2 (SSA:2026-070-02)
libarchive (SSA:2026-070-01)
New packages for nvi have been released to fix a security issue affecting Slackware 15.0 and -current. The update includes fixes for wide-character support, heap-based buffer overflows in regex handling, and other improvements. The patches were contributed by r1w1s1 and merged from Debian, and can be downloaded from various mirror sites or the OSU Open Source Lab's FTP server. To install the updates, users should run "upgradepkg" as root with the relevant package name.
nvi (SSA:2026-063-01)
nvi (SSA:2026-063-01)
New packages for python3 are available to fix security issues on Slackware 15.0 and -current. The updates include a new version of python3, with the 3.9.25-i586-1_slack15.0 package being upgraded to address bugs and security issues.
python3 (SSA:2026-062-01)
python3 (SSA:2026-062-01)
Two security updates have been released for Slackware Linux. The first update fixes a vulnerability in the telnet package (SSA:2026-059-02), which can be exploited by an unauthenticated remote attacker to execute arbitrary code on the server running telnetd. This should only be used on isolated networks where security is not a concern. The second update addresses two security issues in the gvfs package (SSA:2026-059-01). These vulnerabilities have been patched, and users are advised to upgrade their packages as soon as possible.
telnet (SSA:2026-059-02)
gvfs (SSA:2026-059-01)
telnet (SSA:2026-059-02)
gvfs (SSA:2026-059-01)
Mozilla Thunderbird has been updated to fix security issues. The new packages are available for Slackware 15.0 and -current, and can be found at various mirror sites including ftp.slackware.com.
mozilla-thunderbird (SSA:2026-058-01)
mozilla-thunderbird (SSA:2026-058-01)
New mozilla-firefox packages are available to fix security issues for Slackware 15.0 and -current. The updated packages can be found on the Slackware FTP server or through additional mirror sites listed on the project's website.
mozilla-firefox (SSA:2026-055-01)
mozilla-firefox (SSA:2026-055-01)
Mozilla Firefox and Thunderbird packages have been updated for Slackware 15.0 and -current to fix security issues, including a heap buffer overflow in libvpx. The new packages can be found on the official Slackware FTP servers or mirror sites near you, and the MD5 signatures are provided for verification. Additionally, a new lrzip package is available to address multiple potential security issues with crafted or corrupt archives. Users should upgrade the packages as root by running the "upgradepkg" command with the corresponding package name.
mozilla-firefox (SSA:2026-047-03)
mozilla-thunderbird (SSA:2026-047-04)
lrzip (SSA:2026-047-02)
libssh (SSA:2026-047-01)
mozilla-firefox (SSA:2026-047-03)
mozilla-thunderbird (SSA:2026-047-04)
lrzip (SSA:2026-047-02)
libssh (SSA:2026-047-01)
New updates are available for libpng and gnutls to fix security issues in Slackware 15.0 and -current. The libpng update fixes a high-severity issue with a heap buffer overflow, while the gnutls update addresses two security vulnerabilities, including a NULL pointer dereference.
libpng (SSA:2026-042-02)
gnutls (SSA:2026-042-01)
libpng (SSA:2026-042-02)
gnutls (SSA:2026-042-01)
New security updates are available for OpenSSL and p11-kit on Slackware 15.0. The OpenSSL update fixes several vulnerabilities, including heap out-of-bounds write, unauthenticated/unencrypted trailing bytes, and null pointer dereference issues. The p11-kit update addresses a single security issue: a NULL dereference via C_DeriveKey with specific NULL parameters. This vulnerability has been fixed in the latest version of p11-kit, which is now available for Slackware 15.0 and -current.
openssl (SSA:2026-037-02)
p11-kit (SSA:2026-037-01)
openssl (SSA:2026-037-02)
p11-kit (SSA:2026-037-01)
Expats packages have been updated for Slackware 15.0 and -current to fix security issues, including vulnerabilities that can cause denial of service or integer overflow. The update addresses two specific CVEs: CVE-2026-24515 and CVE-2026-25210. Users can find the new packages on various mirror sites, including the official Slackware website and the OSU Open Source Lab's FTP servers.
expat (SSA:2026-031-01)
expat (SSA:2026-031-01)
New packages for Mozilla Thunderbird have been released to address security issues in Slackware 15.0 and -current. The updated packages, including version 140.7.1esr, can be found on the official Slackware FTP site or through additional mirror sites listed on the "Get Slack" section of the Slackware website.
mozilla-thunderbird (SSA:2026-027-01)
mozilla-thunderbird (SSA:2026-027-01)
New bind packages are available for Slackware 15.0 and -current to fix security issues. The update fixes a security issue where malformed BRID and HHIT records could trigger an assertion failure, with more information available on the ISC Knowledge Base.
bind (SSA:2026-021-01)
bind (SSA:2026-021-01)
Mozilla Firefox, libpng, and Mozilla Thunderbird security updates are available for Slackware 15.0 and -current to fix security issues. The updates contain patches for security vulnerabilities, including heap buffer over-reads and integer truncation errors. Users can find the new packages on the OSU Open Source Lab's FTP site or by visiting additional mirror sites listed on the Slackware website.
mozilla-firefox (SSA:2026-014-02)
libpng (SSA:2026-014-01)
mozilla-thunderbird (SSA:2026-014-03)
mozilla-firefox (SSA:2026-014-02)
libpng (SSA:2026-014-01)
mozilla-thunderbird (SSA:2026-014-03)
New lcms2 packages are available for Slackware 15.0 and -current to address a security issue. The updated package, lcms2-2.18-i586-1_slack15.0.txz, fixes a heap buffer overflow on convert_utf16_to_utf32() (* Security fix *) and is available from the official FTP site or through additional mirror sites listed on the Slackware website.
lcms2 (SSA:2026-009-01)
lcms2 (SSA:2026-009-01)
New libtasn1 packages have been released for Slackware 15.0 and -current to fix a security issue caused by a stack-based buffer overflow. This update fixes CVE-2025-13151, and more information about the vulnerability can be found on the CERT website.
libtasn1 (SSA:2026-008-01)
libtasn1 (SSA:2026-008-01)
New packages for curl have been released to fix security issues on Slackware 15.0 and -current. The updates address three vulnerabilities: an OpenSSL partial chain store policy bypass, a bearer token leak on cross-protocol redirect, and No QUIC certificate pinning with GnuTLS.
curl (SSA:2026-007-01)
curl (SSA:2026-007-01)
New packages for libsodium are available to fix a security issue in Slackware 15.0 and -current. The update fixes an insufficient validation vulnerability in crypto_core_ed25519_is_valid_point() and can be found at the official Slackware FTP site. To upgrade, users should run the "upgradepkg libsodium-1.0.18-i586-4_slack15.0.txz" command as root. The security issue is documented on the CVE website with ID CVE-2025-69277.
libsodium (SSA:2026-006-01)
libsodium (SSA:2026-006-01)
New packages are available for Slackware 15.0 and -current to fix security issues with libpcap and seamonkey. The updates include fixes for bugs and security vulnerabilities, including a bug that affected character encoding mapping from UTF-16 to UTF-8 and other issues with OOBR and OOBW in pcap_ether_aton().
libpcap (SSA:2026-001-02)
seamonkey (SSA:2026-001-01)
libpcap (SSA:2026-001-02)
seamonkey (SSA:2026-001-01)
New gnupg2 packages are available for Slackware 15.0 and -current to address security issues, including CVE-2025-68973 and CVE-2025-68972. These updates also include improvements and require the installation of the new libgpg-error package. Additionally, new wget2 packages are available for Slackware 15.0 and -current to address bugs and security issues, including a file overwrite issue with metalink and buffer overflows in get_local_filename_real() and wget_iri_clone(). Users can upgrade these packages by running the command "upgradepkg" as root.
gnupg2 (SSA:2025-364-01)
wget2 (SSA:2025-364-02)
gnupg2 (SSA:2025-364-01)
wget2 (SSA:2025-364-02)