Security 10907 Published by

Here is a roundup of last week's security updates for AlmaLinux, Debian, Fedora, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux. These updates cover multiple components such as kernels, OpenSSL, MySQL, PHP, Python, and more, with some addressing critical vulnerabilities that could lead to denial-of-service attacks, privilege escalation, or arbitrary code execution. The severity of the updates varies, with some classified as important, moderate, or critical, depending on the potential impact and risk posed by the vulnerabilities. Overall, these security updates aim to enhance the overall security and stability of the Linux distributions across different versions, mitigating potential threats and protecting users from exploitation.





AlmaLinux

AlmaLinux has released several security updates to address various vulnerabilities. Two important kernel updates (ALSA-2025:15472, ALSA-2025:15471) fix issues with bpf array range checking and posix-cpu-timers, while a moderate update addresses a severe vulnerability. Additionally, a security update was released for AlmaLinux 9 to patch a NULL pointer dereference issue in the python3.12-cryptography package (CVE-2024-26130). The AlmaLinux Security team also released an update to fix multiple security issues in MySQL and OpenSSL for AlmaLinux 10 with a moderate severity rating (ALSA-2025:15699).

Debian GNU/Linux

Debian has released several security updates to address vulnerabilities in various packages, including Shibboleth-SP, modsecurity-apache, libhtp, openafs, QEMU, and more. These updates affect multiple versions of Debian, including Bullseye LTS, Bookworm, and Buster Extended LTS, and aim to fix issues such as denial-of-service attacks, privilege escalation, and authentication bypass. The security advisories also include fixes for vulnerabilities in packages like ImageMagick, MariaDB, Chromium, OpenCV, and CUPS.

Fedora Linux

Multiple security updates have been released for various Fedora Linux versions, including fixes for vulnerabilities such as CVE-2025-9566 and CVE-2025-58160. Other packages that received updates include tuigreet, rust-monitord, chromium, glycin, snapshot, among others. Fedora versions 41 and 42 have received a significant number of updates, with the most up-to-date versions having received the largest number. Additionally, kernel updates were released to mitigate vulnerabilities such as VMSCAPE on x86 CPUs for Fedora 41.

Oracle Linux

Oracle Linux has received several security updates, including important kernel security updates for versions 7, 8, and 9 to address various vulnerabilities. These updates cover multiple components such as the Unbreakable Enterprise kernel, NSS, .NET, CUPS, MySQL, PHP, and more. The latest security patches aim to enhance the overall security and stability of Oracle Linux across different versions, including Oracle Linux 10, 9, 8, and 7. The updates are considered important and moderate in severity, with some addressing critical vulnerabilities in key components such as the kernel.

Red Hat Enterprise Linux

Red Hat has released several security updates for Red Hat Enterprise Linux (RHEL), including updates for Firefox, Python 3.9, QT5-QT3D, Opentelemetry, and AIDE. Other updates have been released for Thunderbird, the kernel, HTTPD, and qt5-qt3d, among other packages. Additionally, an update has been released for OpenShift Container Platform 4.19.11, which includes bug fixes, enhancements, and a security update. Red Hat has also released numerous security updates for various RHEL packages, including kernel, PHP, CUPS, and more.

Rocky Linux

Several security updates are available for Rocky Linux to address potential vulnerabilities. These updates affect various versions of Rocky Linux, including 8 and 9, and include updates for PostgreSQL 16 and 15. Additionally, other packages such as MinGW-SqLite and Firefox have also received updates.

Slackware Linux

Several security updates are available for Slackware Linux, including new packages for libxml2 and libssh to address vulnerabilities such as integer overflow and use-after-free issues. Additionally, kernel packages have been released for Slackware 15.0 to fix various bugs and mitigate the VMScape flaw. A patch update is also available for Slackware 15.0, which upgrades the existing patch version and fixes several security issues listed under CVE numbers.

SUSE Linux

Multiple security updates have been released for openSUSE and SUSE Linux to address vulnerabilities in various packages. These updates include fixes for libQt5Pdf5, 7zip, Firebird, Netty, Kernel, OpenJDK, RegionServiceClientConfig, Python-Deepdiff, Warewulf, perl-JSON-XL, Opera, FFmpeg, PostgreSQL, ImageMagick, and more. Some of the most critical updates include Live Patch 32 for SLE 15 SP4 and multiple patches for SLE 15 SP5, as well as updates for third-party packages such as curl and go1. Additionally, openSUSE has released two security updates for Chromium to address vulnerabilities affecting openSUSE Backports SLE-15-SP6 and SLE-15-SP7.

Ubuntu Linux

Ubuntu has released several security notices to address vulnerabilities in various packages. The first notice (USN-7740-1) addresses a vulnerability in LibEtPan that could allow a remote attacker to crash the application. Additionally, USN-7742-1 fixes vulnerabilities in GnuTLS that could lead to denial-of-service or arbitrary code execution. Other security updates have been released for PostgreSQL, BIND, Cipher-Base, CUPS, and QEMU to address various potential threats.

Tuxrepair