Security 10917 Published by

Various Linux distributions released security updates last week to address vulnerabilities in their packages. The roundup covers multiple versions of AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux. These updates resolve issues such as memory out-of-bounds reads, arbitrary code execution, cross-site scripting (XSS) attacks, remote code execution, denial-of-service, and other security vulnerabilities in packages like GNU tar, Ruby, Kernel, Mozilla Thunderbird, GIMP, Adminer, curl, ImageMagick, Chromium, and more. Users are advised to install these updates to ensure their systems remain secure and stable, with some distributions offering multiple versions of them to cover different release numbers.





AlmaLinux

AlmaLinux has released a series of security updates to address potential vulnerabilities in various packages. These updates include fixes for GNU tar and Ruby, as well as kernel and Mozilla Thunderbird packages, which are considered moderate or important. Additionally, the team has released updates for httpd, xorg-x11-server, and other packages like poppler and libpng to address vulnerabilities. The security updates are available for different versions of AlmaLinux, with some specific to version 10 and others specific to version 9.

Debian GNU/Linux

Debian has released several security updates to address various vulnerabilities in its packages. These updates include fixes for popular software like GIMP, Adminer, curl, ImageMagick, and Chromium. The security patches aim to prevent issues such as memory out-of-bounds reads, arbitrary code execution, and cross-site scripting (XSS) attacks. Some notable vulnerabilities have been addressed in these updates, including a crash-causing issue in curl, malicious PDF file processing by pdfminer, and XSS vulnerabilities in SOGo groupware server. These fixes also cover other packages like U-Boot, ImageMagick, Adminer, Ruby-Rmagick, Libsodium, Foomuuri, VLC, and Chromium.

Fedora Linux

Fedora 43 has received several security updates to various packages, including gnupg2, proxychains-ng, and libpcap, which address vulnerabilities such as remote code execution and denial-of-service. Additionally, Fedora users can upgrade to version 2.2.1 of GNU Wget2, a downloader with improved performance features. Other packages that have been updated include Python 3, SeaMonkey, MariaDB, and more. Fedora 42 has also received updates for various packages, including python-pdfminer, libsodium, wasmedge, and Nginx, to address security vulnerabilities.

Oracle Linux

Oracle Linux has released several security updates to address vulnerabilities in various packages. The updates include bug fixes and enhancements for nodejs versions 20, 22, and 24 on Oracle Linux 8, as well as a security update for Thunderbird on the same platform. Additionally, updates have been made available for BIND, MariaDB, libpng, Poppler, and other packages across multiple versions of Oracle Linux (7, 8, 9, and 10). These updates aim to improve the overall security of the Oracle Linux distributions.

Red Hat Enterprise Linux

Red Hat has released a series of security updates to address vulnerabilities in various packages on Red Hat Enterprise Linux (RHEL) systems. These updates include fixes for critical components such as the Xorg-X11-Server-Xwayland, Firefox, and MariaDB. Additionally, other packages like GCC-toolset, PostgreSQL, and libpng have received important and moderate security patches. The updates are available for different RHEL versions and can be accessed through links provided with each announcement.

Rocky Linux

Rocky Linux users should be aware that several security updates are available for various packages. These updates include PostgreSQL 15 for Rocky Linux 8, Tar and Thunderbird updates affecting multiple versions of the operating system, and PHP updates for Rocky Linux 8. Additionally, other packages such as Poppler, MariaDB, MinGW, and Python have also received security updates with varying levels of severity. Multiple security updates are available across different versions of Rocky Linux (8, 9, and 10), including important updates for MariaDB on version 9.

Slackware Linux

Slackware users are advised to update their systems due to several security issues affecting the operating system. Libsodium, CURL, libtasn1, and lcms2 have all released new packages to address vulnerabilities such as insufficient validation, OpenSSL bypass, stack-based buffer overflow, and heap buffer overflow.

SUSE Linux

Several security updates have been released for SUSE Linux to address various vulnerabilities and security issues. The updates include patches for multiple packages such as Python312-Django6, Xen, pgAdmin4, Buildah, kernel, dcmtk, rsync, and others. These updates aim to fix a total of over 100 identified vulnerabilities in the affected software packages. Users are advised to install these updates to ensure their systems remain secure and stable.

Ubuntu Linux

Several security notices have been issued by Ubuntu to address vulnerabilities in various libraries and software, including WebKitGTK, GLib, Linux kernel, libcaca, Libxslt, Net-SNMP, libvirt, Tornado, GnuPG, Sodium, and GPSd. These vulnerabilities could allow remote attackers to exploit cross-site scripting attacks or cause denial of service on affected systems. The updates aim to improve the security of Ubuntu systems by patching these issues in various releases, including 22.04 LTS, 24.04 LTS, 25.10, 25.04, and others.

Tuxrepair