Here is a roundup of Linux distributions' security updates from last week, including AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux (RHEL), Slackware Linux, and SUSE Linux, with Ubuntu also releasing multiple security notices. The updates address various vulnerabilities, including denial-of-service attacks, privilege escalation, SQL injection, and heap buffer overflows in packages such as kernel, Firefox, Thunderbird, Chromium, and more. Many of the updates aim to improve the overall security and stability of the respective distributions by fixing issues like memory leaks, out-of-bounds reads, and side-channel information leakage. The severity ratings for these vulnerabilities range from moderate to critical, indicating potential risks if not patched, and users are advised to update their systems as soon as possible to ensure protection against potential attacks.
AlmaLinux
Three security updates have been released for AlmaLinux 8: two kernel security updates with a moderate severity rating and one additional kernel security update with an Important severity rating. Additionally, an AlmaLinux 9 kernel update addresses a moderate-severity vulnerability related to IPv6 multicast. Further updates include a kernel update for AlmaLinux 9 that fixes seven vulnerabilities with a Moderate severity level, as well as Firefox and Thunderbird updates. These security updates aim to address various vulnerabilities in the respective software components.
- ALSA-2025:16372: kernel security update (Moderate)
- ALSA-2025:16373: kernel-rt security update (Moderate)
- ALSA-2025:15785: kernel security update (Important)
- ALSA-2025:15740: kernel security update (Moderate)
- ALSA-2025:16154: grub2 security update (Moderate)
- ALSA-2025:15782: kernel security update (Moderate)
- ALSA-2025:16109: firefox security update (Important)
- ALSA-2025:16157: thunderbird security update (Important)
- ALSA-2025:16156: thunderbird security update (Important)
- ALSA-2025:16589: thunderbird security update (Important)
- ALSA-2025:16260: firefox security update (Important)
Debian GNU/Linux
Multiple security advisories have been issued for various Debian GNU/Linux packages to address vulnerabilities that could lead to denial-of-service attacks, privilege escalation, SQL injection, and heap buffer overflows. The affected packages include pam, ffmpeg, jq, shibboleth-sp, syslog-ng, corosync, linux, libxslt, Chromium, Thunderbird, Ceph, Squid, and MPlayer. Updates have been released to fix security problems such as mishandling of wildcard certificates during TLS authentication, buffer overflows in corosync, and arbitrary code execution vulnerabilities in Chromium. These updates are intended to improve the security of Debian systems and protect against potential attacks.
- ELA-1520-1 jq security update
- ELA-1521-1 shibboleth-sp security update
- [DLA 4306-1] pam security update
- [DLA 4307-1] jq security update
- [DSA 6007-1] ffmpeg security update
- ELA-1523-1 syslog-ng security update
- ELA-1522-1 pam security update
- ELA-1524-1 corosync security update
- [DLA 4308-1] corosync security update
- [DSA 6009-1] linux security update
- [DSA 6008-1] linux security update
- [DSA 5979-2] libxslt regression update
- ELA-1525-1 libxslt security update
- ELA-1522-1 pam security update
- [DLA 4309-1] libxslt security update
- [DLA 4310-1] ceph security update
- [DSA 6010-1] chromium security update
- [DSA 6011-1] thunderbird security update
- [DLA 4311-1] thunderbird security update
- [DSA 6012-1] nncp security update
- [DLA 4312-1] squid security update
- ELA-1527-1 mplayer security update
- ELA-1526-1 ceph security update
Fedora Linux
Fedora has released security updates to address vulnerabilities in several packages, including prometheus-podman-exporter, podman-tui, curl, Chromium, expat, LibSSH, WebkitGTK, mingw-expat, Rust, Trustee, Python, and Firebird. The updates fix issues such as memory leaks, out-of-bounds reads, and side-channel information leakage, with CVEs including CVE-2025-58058, CVE-2025-9086, and CVE-2025-10890 to CVE-2025-10892. Fedora versions 41, 42, and 43 Beta have received updates for various packages to ensure security and stability. The latest versions of some packages include prometheus-podman-exporter and podman-tui version unspecified, curl version 8.9.1-4.fc41, Chromium version 140.0.7339.207, and expat version 2.7.
- Fedora 41 Update: prometheus-podman-exporter-1.18.1-1.fc41
- Fedora 41 Update: podman-tui-1.8.0-1.fc41
- Fedora 42 Update: prometheus-podman-exporter-1.18.1-1.fc42
- Fedora 42 Update: podman-tui-1.8.0-1.fc42
- Fedora 43 Update: prometheus-podman-exporter-1.18.1-1.fc43
- Fedora 43 Update: podman-tui-1.8.0-1.fc43
- Fedora 41 Update: curl-8.9.1-4.fc41
- Fedora 41 Update: checkpointctl-1.4.0-3.fc41
- Fedora 42 Update: chromium-140.0.7339.185-1.fc42
- Fedora 42 Update: checkpointctl-1.4.0-3.fc42
- Fedora 43 Update: checkpointctl-1.4.0-3.fc43
- Fedora 43 Update: perl-Catalyst-Authentication-Credential-HTTP-1.019-1.fc43
- Fedora 41 Update: expat-2.7.2-1.fc41
- Fedora 41 Update: libssh-0.11.3-1.fc41
- Fedora 42 Update: webkitgtk-2.50.0-1.fc42
- Fedora 43 Update: chromium-140.0.7339.185-1.fc43
- Fedora 42 Update: mingw-expat-2.7.2-1.fc42
- Fedora 42 Update: rust-az-tdx-vtpm-0.7.4-1.fc42
- Fedora 42 Update: rust-az-cvm-vtpm-0.7.4-3.fc42
- Fedora 42 Update: trustee-guest-components-0.13.0-3.fc42
- Fedora 42 Update: rust-az-snp-vtpm-0.7.4-1.fc42
- Fedora 42 Update: python-orderly-set-5.5.0-2.fc42
- Fedora 42 Update: python-deepdiff-8.6.1-1.fc42
- Fedora 43 Update: mingw-expat-2.7.2-1.fc43
- Fedora 42 Update: chromium-140.0.7339.207-1.fc42
- Fedora 42 Update: firebird-4.0.6.3221-1.fc42
- Fedora 43 Update: chromium-140.0.7339.207-1.fc43
Oracle Linux
Oracle Linux has received several updates to address security vulnerabilities and provide bug fixes across various versions. For version 10 of Oracle Linux, important security updates were made for packages such as thunderbird, firefox, kernel, and gnutls. Additionally, other versions like Oracle Linux 7, 8, and 9 have also received updates covering packages including ImageMagick, Firefox, kernel, mysql, and Unbreakable Enterprise kernel. These updates aim to enhance security, stability, and overall performance of the Oracle Linux distributions.
- ELSA-2025-16157 Important: Oracle Linux 10 thunderbird security update
- ELSA-2025-16115 Moderate: Oracle Linux 10 gnutls security, bug fix, and enhancement update
- ELSA-2025-16109 Important: Oracle Linux 10 firefox security update
- ELSA-2025-15782 Moderate: Oracle Linux 10 kernel security update
- ELSA-2025-16156 Important: Oracle Linux 9 thunderbird security update
- ELSA-2025-16116 Moderate: Oracle Linux 9 gnutls security, bug fix, and enhancement update
- ELBA-2025-12877 Oracle Linux 9 linux-firmware bug fix and enhancement update
- ELBA-2025-20599 Oracle Linux 8 selinux-policy bug fix update
- ELSA-2025-14987 Moderate: Oracle Linux 7 kernel security update
- ELSA-2025-14748 Important: Oracle Linux 7 kernel security update
- ELSA-2025-15666 Important: Oracle Linux 7 ImageMagick security update
- ELSA-2025-15430 Important: Oracle Linux 7 firefox security update
- ELSA-2025-16372 Moderate: Oracle Linux 8 kernel security update
- ELSA-2025-16260 Important: Oracle Linux 8 firefox security update
- ELBA-2025-16372-1 Oracle Linux 8 kernel bug fix update
- ELSA-2025-20609 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
- ELSA-2025-16398 Moderate: Oracle Linux 9 kernel security update
- ELSA-2025-16086 Moderate: Oracle Linux 9 mysql security update
- ELBA-2025-16329 Oracle Linux 9 crun bug fix and enhancement update
- ELBA-2025-16261 Oracle Linux 9 container-selinux bug fix and enhancement update
- ELSA-2025-20609 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
- ELSA-2025-20609 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
- ELBA-2025-20545 Oracle Linux 8 oVirt 4.5 ovirt-ansible-collection bug fix update
- ELBA-2025-20544 Oracle Linux 8 oVirt 4.5 ovirt-engine bug fix update
- ELSA-2025-20608 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
- ELSA-2025-16441 Moderate: Oracle Linux 10 avahi security update
- ELSA-2025-16428 Moderate: Oracle Linux 10 libtpms security update
- ELBA-2025-16442 Oracle Linux 10 firewalld bug fix and enhancement update
- ELBA-2025-16439 Oracle Linux 10 iptables bug fix update
- ELBA-2025-16437 Oracle Linux 10 libuv bug fix and enhancement update
- ELBA-2025-16435 Oracle Linux 10 libinput bug fix and enhancement update
- ELBA-2025-16429 Oracle Linux 10 virtiofsd bug fix and enhancement update
- ELSA-2025-20608 Important: Unbreakable Enterprise kernel security update
- ELSA-2025-15648 Important: Oracle Linux 7 kernel security update
- ELSA-2025-15728 Important: Oracle Linux 7 aide security update
- ELSA-2025-20632 Important: Oracle Linux 7 Unbreakable Enterprise kernel security update
- ELSA-2025-16589 Important: Oracle Linux 8 thunderbird security update
- ELSA-2025-20632 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
- ELBA-2025-20629 Oracle Linux 8 leapp-repository bug fix update
- ELSA-2025-20632 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
- ELBA-2025-16489 Oracle Linux 10 libinput bug fix and enhancement update
- ELBA-2025-16450 Oracle Linux 10 man-pages bug fix and enhancement update
- ELSA-2025-16354 Moderate: Oracle Linux 10 kernel security update
- ELBA-2025-16680 Oracle Linux 9 irqbalance bug fix and enhancement update
- ELBA-2025-16449 Oracle Linux 10 dnf bug fix and enhancement update
- ELBA-2025-16445 Oracle Linux 10 gnome-shell and gsettings-desktop-schemas bug fix and enhancement update
- ELBA-2025-16448 Oracle Linux 10 NetworkManager bug fix and enhancement update
- ELBA-2025-16447 Oracle Linux 10 linux-firmware bug fix and enhancement update
- ELBA-2025-16433 Oracle Linux 10 libwacom bug fix and enhancement update
- ELBA-2025-16431 Oracle Linux 10 redhat-rpm-config bug fix and enhancement update
- ELBA-2025-16434 Oracle Linux 10 libvirt bug fix and enhancement update
Red Hat Enterprise Linux
Red Hat Enterprise Linux (RHEL) users can update their systems with various security patches. The updates include fixes for Firefox and Python 3 on RHEL 8, as well as other patches for kernel, ImageMagick, Ncurses, OpenShift, Podman, Kpatch-Patch, CUPS, Thunderbird, JBoss, and OpenSSH across different RHEL versions. Red Hat Product Security has rated these updates as Important or Moderate, with some also providing Common Vulnerability Scoring System (CVSS) base scores to indicate their severity. These security patches aim to address vulnerabilities in various packages to improve the overall security of RHEL systems.
- RHSA-2025:16260: Important: firefox security update
- RHSA-2025:16262: Moderate: python3 security update
- RHSA-2025:16354: Moderate: kernel security update
- RHSA-2025:16346: Moderate: command-line-assistant security update
- RHSA-2025:16345: Moderate: command-line-assistant security update
- RHSA-2025:16313: Important: ImageMagick security update
- RHSA-2025:16400: Moderate: Red Hat build of Keycloak 26.2.9 Images Security Update
- RHSA-2025:16399: Moderate: Red Hat build of Keycloak 26.2.9 Security Update
- RHSA-2025:16372: Moderate: kernel security update
- RHSA-2025:16373: Moderate: kernel-rt security update
- RHSA-2025:16411: Moderate: NetworkManager security update
- RHSA-2025:16414: Low: ncurses security update
- RHSA-2025:16418: Low: ncurses security update
- RHSA-2025:16398: Moderate: kernel security update
- RHSA-2025:16409: Important: Red Hat AMQ Broker 7.12.5 release and security update
- RHSA-2025:16407: Important: Streams for Apache Kafka 3.0.1 release and security update
- RHSA-2025:16404: Important: Red Hat Ansible Automation Platform 2.4 Container Release Update
- RHSA-2025:16403: Important: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
- RHSA-2025:16462: Important: Red Hat Product OCP Tools 4.15 OpenShift Jenkins security update
- RHSA-2025:16459: Important: Red Hat Product OCP Tools 4.12 OpenShift Jenkins security update
- RHSA-2025:16457: Important: Red Hat Product OCP Tools 4.16 OpenShift Jenkins security update
- RHSA-2025:16456: Important: Red Hat Product OCP Tools 4.17 OpenShift Jenkins security update
- RHSA-2025:16454: Important: Red Hat Product OCP Tools 4.19 OpenShift Jenkins security update
- RHSA-2025:16455: Important: Red Hat Product OCP Tools 4.18 Openshift Jenkins security update
- RHSA-2025:16441: Moderate: avahi security update
- RHSA-2025:16428: Moderate: libtpms security update
- RHSA-2025:16432: Moderate: opentelemetry-collector security update
- RHSA-2025:16482: Important: container-tools:rhel8 security update
- RHSA-2025:16480: Important: podman security update
- RHSA-2025:16483: Important: OpenShift Virtualization 4.12.20 Images
- RHSA-2025:16538: Important: kpatch-patch-5_14_0-570_17_1 security update
- RHSA-2025:16540: Important: kpatch-patch-5_14_0-427_31_1, kpatch-patch-5_14_0-427_44_1, kpatch-patch-5_14_0-427_55_1, kpatch-patch-5_14_0-427_68_2, and kpatch-patch-5_14_0-427_84_1 secur ...
- RHSA-2025:16541: Important: kpatch-patch-5_14_0-70_112_1, kpatch-patch-5_14_0-70_121_1, kpatch-patch-5_14_0-70_124_1, and kpatch-patch-5_14_0-70_132_1 security update
- RHSA-2025:16539: Important: kpatch-patch-5_14_0-284_104_1, kpatch-patch-5_14_0-284_117_1, kpatch-patch-5_14_0-284_79_1, and kpatch-patch-5_14_0-284_92_1 security update
- RHSA-2025:16514: Important: Red Hat Ansible Automation Platform 2.5 Container Release Update
- RHSA-2025:16515: Important: container-tools:rhel8 security update
- RHSA-2025:16487: Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
- RHSA-2025:16488: Important: podman security update
- RHSA-2025:16481: Important: podman security update
- RHSA-2025:16461: Important: Red Hat Product OCP Tools 4.14 OpenShift Jenkins security update
- RHSA-2025:16460: Important: Red Hat Product OCP Tools 4.13 OpenShift Jenkins security update
- RHSA-2025:16591: Important: cups security update
- RHSA-2025:16590: Important: cups security update
- RHSA-2025:16589: Important: thunderbird security update
- RHSA-2025:16583: Important: kpatch-patch-4_18_0-477_67_1, kpatch-patch-4_18_0-477_81_1, kpatch-patch-4_18_0-477_89_1, and kpatch-patch-4_18_0-477_97_1 security update
- RHSA-2025:16582: Important: kpatch-patch-4_18_0-553_16_1, kpatch-patch-4_18_0-553_30_1, kpatch-patch-4_18_0-553_40_1, kpatch-patch-4_18_0-553_53_1, and kpatch-patch-4_18_0-553_72_1 secur ...
- RHSA-2025:16580: Important: kpatch-patch-4_18_0-372_118_1, kpatch-patch-4_18_0-372_131_1, kpatch-patch-4_18_0-372_137_1, and kpatch-patch-4_18_0-372_145_1 security update
- RHSA-2025:16592: Important: cups security update
- RHSA-2025:16669: Moderate: kernel security update
- RHSA-2025:16667: Important: Red Hat JBoss Enterprise Application Platform 7.3.15 security update
- RHSA-2025:16668: Important: Red Hat JBoss Enterprise Application Platform 7.1.12 on RHEL 7 security update
- RHSA-2025:16159: Moderate: OpenShift Container Platform 4.15.58 bug fix and security update
- RHSA-2025:16823: Moderate: openssh security update
Slackware Linux
A security issue has been identified in the Expat package used by Slackware Linux 15.0. To resolve this issue, new packages are available for download that upgrade Expat to version 2. This update aims to improve the security of Slackware Linux 15.0. Users can find more information about the update on the provided website link.
SUSE Linux
Multiple security updates have been released by SUSE Linux to address various vulnerabilities in its distributions. The updates include fixes for the rke2 package, which resolved a moderate-rated vulnerability, and patches for packages such as PostgreSQL, mybatis/ognl, govulncheck-vulndb, and more. Several high-priority and critical security issues have been addressed in these updates, particularly with regards to the Linux kernel, indicating potential security risks if not patched. The updates aim to resolve vulnerabilities and ensure the overall security of SUSE Linux distributions.
- openSUSE-SU-2025:15569-1: moderate: rke2-1.33-1.33.5+rke2r1-1.1 on GA media
- SUSE-SU-2025:03285-1: important: Security update for mybatis, ognl
- SUSE-SU-2025:03289-1: moderate: Security update for govulncheck-vulndb
- SUSE-SU-2025:03294-1: moderate: Security update for wireshark
- SUSE-SU-2025:03291-1: important: Security update for MozillaFirefox
- SUSE-SU-2025:03298-1: moderate: Security update for rustup
- SUSE-SU-2025:03301-1: important: Security update for the Linux Kernel
- SUSE-SU-2025:03300-1: moderate: Security update for vim
- SUSE-SU-2025:03314-1: important: Security update for the Linux Kernel
- SUSE-SU-2025:03307-1: moderate: Security update for sevctl
- SUSE-SU-2025:03271-2: moderate: Security update for busybox, busybox-links
- SUSE-SU-2025:03310-1: important: Security update for the Linux Kernel
- SUSE-SU-2025:03309-1: important: Security update for MozillaThunderbird
- openSUSE-SU-2025:15571-1: moderate: tor-0.4.8.18-1.1 on GA media
- openSUSE-SU-2025:15570-1: moderate: tcpreplay-4.5.1-2.1 on GA media
- SUSE-SU-2025:03333-1: moderate: Security update for avahi
- SUSE-SU-2025:03331-1: moderate: Security update for avahi
- openSUSE-SU-2025:15572-1: moderate: bird3-3.1.4-1.1 on GA media
- openSUSE-SU-2025:15573-1: moderate: expat-2.7.2-1.1 on GA media
- SUSE-SU-2025:03344-1: important: Security update for the Linux Kernel
- SUSE-SU-2025:03348-1: moderate: Security update for tiff
- SUSE-SU-2025:03352-1: low: Security update for openjpeg2
- SUSE-SU-2025:03354-1: moderate: Security update for python-pycares
- SUSE-SU-2025:03359-1: important: Security update for the Linux Kernel (Live Patch 51 for SLE 15 SP3)
- SUSE-SU-2025:03358-1: important: Security update for the Linux Kernel (Live Patch 49 for SLE 15 SP3)
- SUSE-SU-2025:03363-1: important: Security update for the Linux Kernel (Live Patch 59 for SLE 15 SP3)
- SUSE-SU-2025:03362-1: important: Security update for the Linux Kernel (Live Patch 58 for SLE 15 SP3)
- SUSE-SU-2025:03369-1: moderate: Security update for libssh
- SUSE-SU-2025:03370-1: important: Security update for the Linux Kernel (Live Patch 32 for SLE 15 SP4)
- openSUSE-SU-2025:15576-1: moderate: govulncheck-vulndb-0.0.20250924T192141-1.1 on GA media
- openSUSE-SU-2025:15577-1: moderate: krita-5.2.13-1.1 on GA media
- SUSE-SU-2025:03381-1: important: Security update for the Linux Kernel (Live Patch 41 for SLE 15 SP4)
- SUSE-SU-2025:03375-1: important: Security update for the Linux Kernel (Live Patch 37 for SLE 15 SP4)
- openSUSE-SU-2025:0373-1: moderate: Security update for tor
- SUSE-SU-2025:03378-1: low: Security update for luajit
- SUSE-SU-2025:03374-1: important: Security update for the Linux Kernel (Live Patch 31 for SLE 15 SP4)
- openSUSE-SU-2025:15580-1: moderate: postgresql17-17.6-2.1 on GA media
- openSUSE-SU-2025:15582-1: moderate: tree-sitter-ruby-0.23.1-2.1 on GA media
- openSUSE-SU-2025:15578-1: moderate: chromedriver-140.0.7339.207-1.1 on GA media
Ubuntu Linux
Ubuntu has released multiple security notices to address vulnerabilities in various packages, including PAM and GNU C Library. Additionally, there are security updates available for pip, RabbitMQ, Kea DHCP, Linux kernel, DPKG, Gnuplot, Eventlet, PCRE2, Sha.js, and other packages to fix potential security issues. The vulnerabilities could allow attackers to compromise systems, bypass access restrictions, or expose sensitive information. These updates aim to address various Linux kernel vulnerabilities affecting different versions and configurations on Ubuntu Linux.
- [USN-7761-1] PAM vulnerability
- [USN-7760-1] GNU C Library vulnerability
- [USN-7762-1] pip vulnerabilities
- [USN-7763-1] RabbitMQ Server vulnerability
- [USN-7759-1] Kea DHCP vulnerabilities
- [USN-7755-3] Linux kernel (AWS FIPS) vulnerabilities
- [USN-7766-1] Linux kernel vulnerabilities
- [USN-7765-1] Linux kernel (NVIDIA) vulnerabilities
- [USN-7764-1] Linux kernel vulnerabilities
- [USN-7767-1] Linux kernel (Real-time) vulnerabilities
- [USN-7771-1] Linux kernel (OEM) vulnerabilities
- [USN-7770-1] Linux kernel (Azure) vulnerabilities
- [USN-7769-1] Linux kernel vulnerabilities
- [USN-7769-2] Linux kernel (Real-time) vulnerabilities
- [USN-7768-1] dpkg vulnerability
- [USN-7775-1] Linux kernel (Azure FIPS) vulnerabilities
- [USN-7774-3] Linux kernel (Real-time) vulnerabilities
- [USN-7774-1] Linux kernel vulnerabilities
- [USN-7773-1] Gnuplot vulnerabilities
- [USN-7772-1] Eventlet vulnerability
- [USN-7776-1] Linux kernel (Oracle) vulnerabilities
- [USN-7767-2] Linux kernel (Real-time) vulnerabilities
- [USN-7779-1] Linux kernel (IBM) vulnerabilities
- [USN-7777-1] PCRE2 vulnerability
- [USN-7778-1] sha.js vulnerability
- [USN-7775-2] Linux kernel (Azure) vulnerabilities
- [USN-7769-3] Linux kernel vulnerabilities
- [USN-7764-2] Linux kernel (HWE) vulnerabilities