Debian 11018 Published by

Debian administrators received a coordinated batch of security advisories, covering python-authlib, the Linux kernel, Chromium, Poppler, Incus, and PHP 8.4. The released patches resolve dozens of CVEs that could let remote attackers execute arbitrary code, bypass authentication checks, forge digital signatures, trigger denial-of-service crashes, or extract sensitive data through crafted file inputs. Operators need to upgrade their systems immediately to the specific Debian bullseye, bookworm, and trixie package versions listed in each advisory to close these vulnerabilities. Full vulnerability details and ongoing status tracking remain available on the official Debian security tracker for every affected component.

[DLA 4708-1] python-authlib security update
[DSA 6405-1] linux security update
[DSA 6408-1] chromium security update
[DLA 4709-1] poppler security update
[DSA 6407-1] incus security update
[DSA 6406-1] php8.4 security update



[SECURITY] [DLA 4708-1] python-authlib security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4708-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Andrej Shadura
July 31, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : python-authlib
Version : 0.15.4-1+deb11u4 1.2.0-1+deb12u2
CVE ID : CVE-2026-27962 CVE-2026-28490 CVE-2026-28498 CVE-2026-41425
CVE-2026-44681

The following security issue has been identified (and fixed) in python-authlib
as shipped in Debian bullseye and Debian bookworm.

CVE-2026-44681

An unauthenticated open redirect in Authlib's OpenIDImplicitGrant
and OpenIDHybridGrant authorisation endpoint allowed a remote
attacker to cause the authorisation server to issue an HTTP 302 to
an attacker-chosen URL by submitting an authorisation request that
omits the openid scope.

For Debian 11 bullseye, this problem has been fixed in version
0.15.4-1+deb11u4.

In addition, the following issues have been fixed in the python-authlib version
as shipped in Debian bookworm:

CVE-2026-27962

Fix authentication and authorization bypass vulnerability by embedding a
crafted public key in the jwk header field when key=None is passed to JWS
deserialisation functions.

CVE-2026-28490

Authlib exposed distinguishable error responses between invalid PKCS#1 v1.5
padding and invalid AES-GCM tag, enabling Bleichenbacher-style attacks.

CVE-2026-28498

Fix OIDC ID Token validation bypass in at_hash and c_hash verification.
_verify_hash() silently returned True when create_half_hash() received an
unknown algorithm, allowing forged ID Tokens to pass validation.

CVE-2026-41425

CSRF protection now covers the cache feature in
authlib.integrations.starlette_client.OAuth as well.

For Debian 12 bookworm, these problems have been fixed in version
1.2.0-1+deb12u2.

We recommend that you upgrade your python-authlib packages.

For the detailed security status of python-authlib please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/python-authlib

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

[SECURITY] [DSA 6405-1] linux security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6405-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
July 31, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : linux
CVE ID : CVE-2026-45944 CVE-2026-53005 CVE-2026-53260 CVE-2026-53365
CVE-2026-63970 CVE-2026-64192 CVE-2026-64206 CVE-2026-64227
CVE-2026-64286 CVE-2026-64287 CVE-2026-64307 CVE-2026-64341
CVE-2026-64352 CVE-2026-64361 CVE-2026-64363 CVE-2026-64364
CVE-2026-64369 CVE-2026-64371 CVE-2026-64375 CVE-2026-64390
CVE-2026-64401 CVE-2026-64405 CVE-2026-64413 CVE-2026-64416
CVE-2026-64421 CVE-2026-64428 CVE-2026-64434 CVE-2026-64438
CVE-2026-64441 CVE-2026-64461 CVE-2026-64462 CVE-2026-64472
CVE-2026-64481 CVE-2026-64488 CVE-2026-64493 CVE-2026-64507
CVE-2026-64508 CVE-2026-64509 CVE-2026-64510 CVE-2026-64530
CVE-2026-64531 CVE-2026-64532 CVE-2026-64533 CVE-2026-64534
CVE-2026-64535 CVE-2026-64537 CVE-2026-64538 CVE-2026-64539
CVE-2026-64540 CVE-2026-64541 CVE-2026-64542 CVE-2026-64543
CVE-2026-64544 CVE-2026-64545 CVE-2026-64546 CVE-2026-64547
CVE-2026-64548 CVE-2026-64549 CVE-2026-64550 CVE-2026-64551
CVE-2026-64552 CVE-2026-64553 CVE-2026-64554 CVE-2026-64555
CVE-2026-64557 CVE-2026-64558 CVE-2026-64559 CVE-2026-64560
Debian Bug : 1130336

Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.

For the stable distribution (trixie), these problems have been fixed in
version 6.12.100-1.

We recommend that you upgrade your linux packages.

For the detailed security status of linux please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/linux

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DSA 6408-1] chromium security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6408-1 security@debian.org
https://www.debian.org/security/ Andres Salomon
July 31, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : chromium
CVE ID : CVE-2026-16804 CVE-2026-16805 CVE-2026-16806 CVE-2026-16807
CVE-2026-17650 CVE-2026-17651 CVE-2026-17652 CVE-2026-17653
CVE-2026-17654 CVE-2026-17655 CVE-2026-17656 CVE-2026-17657
CVE-2026-17658 CVE-2026-17659 CVE-2026-17660 CVE-2026-17661
CVE-2026-17662 CVE-2026-17663 CVE-2026-17664 CVE-2026-17665
CVE-2026-17666 CVE-2026-17667 CVE-2026-17668 CVE-2026-17669
CVE-2026-17670 CVE-2026-17671 CVE-2026-17672 CVE-2026-17673
CVE-2026-17674 CVE-2026-17675 CVE-2026-17676 CVE-2026-17677
CVE-2026-17678 CVE-2026-17679 CVE-2026-17680 CVE-2026-17681
CVE-2026-17682 CVE-2026-17683 CVE-2026-17684 CVE-2026-17685
CVE-2026-17686 CVE-2026-17687 CVE-2026-17688 CVE-2026-17689
CVE-2026-17690 CVE-2026-17691 CVE-2026-17692 CVE-2026-17693
CVE-2026-17694 CVE-2026-17695 CVE-2026-17696 CVE-2026-17697
CVE-2026-17698 CVE-2026-17699 CVE-2026-17700 CVE-2026-17701
CVE-2026-17702 CVE-2026-17703 CVE-2026-17704 CVE-2026-17705
CVE-2026-17706 CVE-2026-17707 CVE-2026-17708 CVE-2026-17709
CVE-2026-17710 CVE-2026-17711 CVE-2026-17712 CVE-2026-17713
CVE-2026-17714 CVE-2026-17715 CVE-2026-17716 CVE-2026-17717
CVE-2026-17718 CVE-2026-17719 CVE-2026-17720 CVE-2026-17721
CVE-2026-17722 CVE-2026-17723 CVE-2026-17724 CVE-2026-17725
CVE-2026-17726 CVE-2026-17727 CVE-2026-17728 CVE-2026-17729
CVE-2026-17730 CVE-2026-17731 CVE-2026-17732 CVE-2026-17733
CVE-2026-17734 CVE-2026-17735 CVE-2026-17736 CVE-2026-17737
CVE-2026-17738 CVE-2026-17739 CVE-2026-17740 CVE-2026-17741
CVE-2026-17742 CVE-2026-17743 CVE-2026-17744 CVE-2026-17745
CVE-2026-17746 CVE-2026-17747 CVE-2026-17748 CVE-2026-17749
CVE-2026-17750 CVE-2026-17751 CVE-2026-17752 CVE-2026-17753
CVE-2026-17754 CVE-2026-17755 CVE-2026-17756 CVE-2026-17757
CVE-2026-17758 CVE-2026-17759 CVE-2026-17760 CVE-2026-17761
CVE-2026-17762 CVE-2026-17763 CVE-2026-17764 CVE-2026-17765
CVE-2026-17766 CVE-2026-17767 CVE-2026-17768 CVE-2026-17769
CVE-2026-17770 CVE-2026-17771 CVE-2026-17772 CVE-2026-17773
CVE-2026-17774 CVE-2026-17775 CVE-2026-17776 CVE-2026-17777
CVE-2026-17778 CVE-2026-17779 CVE-2026-17780 CVE-2026-17781
CVE-2026-17782 CVE-2026-17783 CVE-2026-17784 CVE-2026-17785
CVE-2026-17786 CVE-2026-17787 CVE-2026-17788 CVE-2026-17789
CVE-2026-17790 CVE-2026-17791 CVE-2026-17792 CVE-2026-17793
CVE-2026-17794 CVE-2026-17795 CVE-2026-17796 CVE-2026-17797
CVE-2026-17798 CVE-2026-17799 CVE-2026-17800 CVE-2026-17801
CVE-2026-17802 CVE-2026-17803 CVE-2026-17804 CVE-2026-17805
CVE-2026-17806 CVE-2026-17807 CVE-2026-17808 CVE-2026-17809
CVE-2026-17810 CVE-2026-17811 CVE-2026-17812 CVE-2026-17813
CVE-2026-17814 CVE-2026-17815 CVE-2026-17816 CVE-2026-17817
CVE-2026-17818 CVE-2026-17819 CVE-2026-17820 CVE-2026-17821
CVE-2026-17822 CVE-2026-17823 CVE-2026-17824 CVE-2026-17825
CVE-2026-17826 CVE-2026-17827 CVE-2026-17828 CVE-2026-17829
CVE-2026-17830 CVE-2026-17831 CVE-2026-17832 CVE-2026-17833
CVE-2026-17834 CVE-2026-17835 CVE-2026-17836 CVE-2026-17837
CVE-2026-17838 CVE-2026-17839 CVE-2026-17840 CVE-2026-17841
CVE-2026-17842 CVE-2026-17843 CVE-2026-17844 CVE-2026-17845
CVE-2026-17846 CVE-2026-17847 CVE-2026-17848 CVE-2026-17849
CVE-2026-17850 CVE-2026-17851 CVE-2026-17852 CVE-2026-17853
CVE-2026-17854 CVE-2026-17855 CVE-2026-17856 CVE-2026-17857
CVE-2026-17858 CVE-2026-17859 CVE-2026-17860 CVE-2026-17861
CVE-2026-17862 CVE-2026-17863 CVE-2026-17864 CVE-2026-17865
CVE-2026-17866 CVE-2026-17867 CVE-2026-17868 CVE-2026-17869
CVE-2026-17870 CVE-2026-17871 CVE-2026-17872 CVE-2026-17873
CVE-2026-17874 CVE-2026-17875 CVE-2026-17876 CVE-2026-17877
CVE-2026-17878 CVE-2026-17879 CVE-2026-17880 CVE-2026-17881
CVE-2026-17882 CVE-2026-17883 CVE-2026-17884 CVE-2026-17885
CVE-2026-17886 CVE-2026-17887 CVE-2026-17888 CVE-2026-17889
CVE-2026-17890 CVE-2026-17891 CVE-2026-17892 CVE-2026-17893
CVE-2026-17894 CVE-2026-17895 CVE-2026-17896 CVE-2026-17897
CVE-2026-17898 CVE-2026-17899 CVE-2026-17900 CVE-2026-17901
CVE-2026-17902 CVE-2026-17903 CVE-2026-17904 CVE-2026-17905
CVE-2026-17906 CVE-2026-17907 CVE-2026-17908 CVE-2026-17909
CVE-2026-17910 CVE-2026-17911 CVE-2026-17912 CVE-2026-17913
CVE-2026-17914 CVE-2026-17915 CVE-2026-17916 CVE-2026-17917
CVE-2026-17918 CVE-2026-17919 CVE-2026-17920 CVE-2026-17921
CVE-2026-17922 CVE-2026-17923 CVE-2026-17924 CVE-2026-17925
CVE-2026-17926 CVE-2026-17927 CVE-2026-17928 CVE-2026-17929
CVE-2026-17930 CVE-2026-17931 CVE-2026-17932 CVE-2026-17933
CVE-2026-17934 CVE-2026-17935 CVE-2026-17936 CVE-2026-17937
CVE-2026-17938 CVE-2026-17939 CVE-2026-17940 CVE-2026-17941
CVE-2026-17942 CVE-2026-17943 CVE-2026-17944 CVE-2026-17945
CVE-2026-17946 CVE-2026-17947 CVE-2026-17948 CVE-2026-17949
CVE-2026-17950 CVE-2026-17951 CVE-2026-17952 CVE-2026-17953
CVE-2026-17954 CVE-2026-17955 CVE-2026-17956 CVE-2026-17957
CVE-2026-17958 CVE-2026-17959 CVE-2026-17960 CVE-2026-17961
CVE-2026-17962 CVE-2026-17963 CVE-2026-17964 CVE-2026-17965
CVE-2026-17966 CVE-2026-17967 CVE-2026-17968 CVE-2026-17969
CVE-2026-17970 CVE-2026-17971 CVE-2026-17972 CVE-2026-17973
CVE-2026-17974 CVE-2026-17975 CVE-2026-17976 CVE-2026-17977
CVE-2026-17978 CVE-2026-17979 CVE-2026-17980 CVE-2026-17981
CVE-2026-17982 CVE-2026-17983 CVE-2026-17984 CVE-2026-17985
CVE-2026-17986 CVE-2026-17987 CVE-2026-17988 CVE-2026-17989
CVE-2026-17990 CVE-2026-17991 CVE-2026-17992 CVE-2026-17993
CVE-2026-17994 CVE-2026-17995 CVE-2026-17996 CVE-2026-17997
CVE-2026-17998 CVE-2026-17999 CVE-2026-18000 CVE-2026-18001
CVE-2026-18002 CVE-2026-18003 CVE-2026-18004 CVE-2026-18005
CVE-2026-18006 CVE-2026-18007 CVE-2026-18008 CVE-2026-18009
CVE-2026-18010 CVE-2026-18011 CVE-2026-18012 CVE-2026-18013
CVE-2026-18014 CVE-2026-18015 CVE-2026-18016 CVE-2026-18017
CVE-2026-18018 CVE-2026-18019

Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.

For the stable distribution (trixie), these problems have been fixed in
version 151.0.7922.71-1~deb13u1.

We recommend that you upgrade your chromium packages.

For the detailed security status of chromium please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/chromium

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DLA 4709-1] poppler security update


-------------------------------------------------------------------------
Debian LTS Advisory DLA-4709-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Guilhem Moulin
July 31, 2026 https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package : poppler
Version : 20.09.0-3.1+deb11u3 22.12.0-2+deb12u3
CVE ID : CVE-2025-43718 CVE-2025-43903 CVE-2025-50420 CVE-2025-52885
CVE-2025-52886 CVE-2026-10118
Debian Bug : 1103545 1108784 1110463 1117046 1117853 1138708

Multiple vulnerabilities were discovered in poppler, a PDF rendering
library, which could result in signature forgery, information
disclosure, denial of service, or potentially the execution of arbitrary
code.

The following security issues have been identified (and fixed) in poppler
as shipped in Debian bullseye and Debian bookworm.

CVE-2025-43903

It was discovered signatures with non-empty encapsulated content
(typically adbe.pkcs7.sha1) were not correctly verified, thereby
allowing trivial signature forgery.

CVE-2025-50420

An infinite recursion issue was discovered in the pdfseparate(1)
utility, which may cause denial of service via crafted PDF input
file.

CVE-2025-52886

Kevin Backhouse discovered an integer overflow issue, which may lead
to use-after-free via crafted PDF input file.

For Debian 12 bookworm, these problems have been fixed in version
22.12.0-2+deb12u3.

In addition, the following issues have been fixed in the poppler version
as shipped in Debian bullseye (for bookworm, these issues were already
fixed in 22.12.0-2+deb12u2 from DSA-6334-1):

CVE-2025-43718

It was discovered that crafted PDF files containing deeply nested
structures within the metadata could lead to Denial of Service.

CVE-2025-52885

Antonio Morales discovered a use-after-free issue, which may lead to
arbitrary code execution via crafted PDF input files.

CVE-2026-10118

An integer overflow issue was discovered in tilingPatternFill, which
may lead to arbitrary code execution via crafted PDF input files.

For Debian 11 bullseye, these problems have been fixed in version
20.09.0-3.1+deb11u3.

We recommend that you upgrade your poppler packages.

For the detailed security status of poppler please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/poppler

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



[SECURITY] [DSA 6407-1] incus security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6407-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
July 31, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : incus
CVE ID : CVE-2026-62313 CVE-2026-62867 CVE-2026-62940 CVE-2026-62941
CVE-2026-63125 CVE-2026-63343

Multiple security issues were discovered in Incus, a system container
and virtual machine manager, which may result in bypass of security
restrictions or privilege escalation.

For the stable distribution (trixie), these problems have been fixed in
version 6.0.4-2+deb13u9.

We recommend that you upgrade your incus packages.

For the detailed security status of incus please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/incus

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DSA 6406-1] php8.4 security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6406-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
July 31, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : php8.4
CVE ID : CVE-2026-7260 CVE-2026-17543 CVE-2026-17544
Debian Bug : 1143153

Multiple security issues were found in PHP, a widely-used open source
general purpose scripting language, which could result in denial of
service, SQL injection, information disclosure or the execution of
arbitrary code.

For the stable distribution (trixie), these problems have been fixed in
version 8.4.24-1~deb13u1.

We recommend that you upgrade your php8.4 packages.

For the detailed security status of php8.4 please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/php8.4

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/