Security 10907 Published by

Here is a roundup of last week's security updates for Linux distributions that address various vulnerabilities across their systems, including AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux. These updates cover multiple components such as kernel fixes, container tools, and packages like Python-cryptography, GnuTLS, OpenTelemetry-collector, MySQL, and Firefox to improve the overall security of the systems. The vulnerabilities addressed range from potential denial-of-service attacks to arbitrary code execution, with some identified in critical components like the Linux kernel. 





AlmaLinux

AlmaLinux has released several security updates to address vulnerabilities in various components. The updates include kernel fixes for AlmaLinux 10 and 9, which resolve issues with drm/vkms, udmabuf, net/sched, and drm/gem. Additionally, container-tools, podman, and kernel updates have been released for AlmaLinux 8, 10, and 9 to address security vulnerabilities. Other components such as GnuTLS, python-cryptography, OpenTelemetry-collector, and MySQL have also received security updates on AlmaLinux systems.

Debian GNU/Linux

Several security advisories have been released by Debian, including updates for Shibboleth Service Provider (shibboleth-sp), Jetty 9 (jetty9), ImageMagick (imagemagick), and others to fix various vulnerabilities. Additionally, updates were issued for Python-Django and Node-SHA.js to address potential security threats in the Django framework and SHA hash functions, respectively. Debian also released updates for Nextcloud-desktop, cJSON, Firefox-ESR, Chromium, Python-Eventlet, Jetty, and OpenVPN to fix multiple vulnerabilities and prevent various types of attacks. These updates are available for different versions of Debian GNU/Linux, including 11 LTS (Bullseye), 12 (Bookworm), and 13 (Trixie).

Fedora Linux

Fedora has released security updates to address various vulnerabilities across multiple versions, including CVE-2025-9810 in Linenoise. Additional updates have been released for packages such as CUPS, Chromium, QEMU, Exiv2, Perl, Firefox, Kea, and Kernel, affecting Fedora versions 41, 42, and 43 Beta. Updates also include fixes for XML parser library expat, virtual machine monitor Xen, and other packages. Additionally, security updates have been released for curl and libssh in Fedora Linux 42 and 43 beta, respectively.

Oracle Linux

Oracle has released security updates for various versions of Oracle Linux, focusing on issues with linux-firmware and cups. The company has also released updates for libarchive on Oracle Linux 7 and podman on Oracle Linux 9, as well as kernel updates for Oracle Linux 8 and 10. Additionally, important security updates have been released for grub2 on Oracle Linux 10 and Firefox on Oracle Linux 9. These updates aim to address various issues and improve the overall security of Oracle Linux.

Red Hat Enterprise Linux

Red Hat Enterprise Linux (RHEL) users have access to multiple security updates from Red Hat. These updates include fixes for various packages such as AIDE, WebkitGTK4, mod_http2, Python-Requests, kernel, Python, and MySQL, among others. The updates have been rated as having a moderate or important security impact by Red Hat, with some addressing critical vulnerabilities. Users of RHEL versions 7 to 10 can benefit from these security updates to ensure the security and stability of their systems.

Slackware Linux

The Slackware Linux Security Team has released updated packages to address security issues in three applications. The affected applications are expat, Mozilla Firefox, and Mozilla Thunderbird. These new packages are available for Slackware 15 users. The updates aim to resolve any existing security vulnerabilities in these applications.

SUSE Linux

Multiple security updates have been released for SUSE Linux, addressing vulnerabilities across various packages and components such as the Linux Kernel, Java applications, CUPS, Cargo, and others. The updates include patches for different versions of Java, live patches for the Linux Kernel, and fixes for specific vulnerabilities in other packages like krb5, PCP, RabbitMQ Server, and more. SUSE has also released security updates for various packages including nginx, raptor, Nvidia-Open-Driver, Firefox, and tkimg, among others.

Ubuntu Linux

Ubuntu has released several security notices (USN) to address vulnerabilities in various packages, including SQLite, JSON-XS, Vim, and RubyGems. Multiple kernel-related security notices have been issued by Ubuntu, affecting different releases such as Ubuntu 20.04 LTS, 18, and 22.04 LTS. Additionally, vulnerabilities were found in OpenJPEG, ImageMagick, and the Linux kernel, which could be exploited to cause a denial of service or execute arbitrary code. Various Linux kernel versions have been discovered with security vulnerabilities affecting systems from providers like Oracle Cloud, AWS, GCP, and Raspberry Pi.

Tuxrepair