Security 10907 Published by

Here is a roundup of last week's security updates for multiple Linux distributions to address vulnerabilities in various packages. These updates include fixes for potential crashes, use-after-free bugs, integer buffer overflows, denial-of-service issues, and privilege escalation in distributions such as AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux. The updates aim to improve system security and stability by addressing vulnerabilities in browsers, databases, file systems, HTTP servers, kernel modules, libraries, and other components. Users are advised to upgrade their packages to the latest versions to ensure the security and stability of their systems.





AlmaLinux

AlmaLinux has released several security updates to address vulnerabilities in various packages, including Python 3.12, Kernel, UDisks2, HTTPD, Firefox, MySQL, Podman, and GnuTLS. The team also released updates for kernel and MySQL, which fix crashes, use-after-free bugs, and integer buffer overflows. Additionally, there were two separate updates: one for AlmaLinux 8 to fix a vulnerability in FreeIPA that allows privilege escalation from host to domain admin (CVE-2025-7493), and another update with details not specified.

Debian GNU/Linux

Multiple security updates have been released for Debian systems, addressing vulnerabilities in various packages such as Node-Tar-FS, Firefox ESR, GIMP, TIFF, U-Boot, and OpenSSL. These updates aim to fix connection errors with some sites in Firefox ESR, buffer overflow vulnerabilities in gegl, and denial of service or arbitrary code execution issues. Additionally, security advisories have been issued for Debian GNU/Linux 9, 10, 11, and 12, affecting packages including libjson-xs-perl, chromium, open-vm-tools, and log4cxx. The updates recommend upgrading to the latest versions of these packages to ensure system security and stability.

Fedora Linux

Fedora Linux has received several security updates to address potential vulnerabilities in various packages. Updates have been made to browsers like Chromium (version 140.0.7339.207), Firefox (143.0.3), and Thunderbird, as well as other packages including SQLite, Firebird, and MuPDF. The updates affect multiple versions of Fedora, including Fedora 41, Fedora 42, and Fedora 43 Beta. The patches address issues such as side-channel information leakage, integer overflow in V8, denial-of-service vulnerabilities, access bypass vulnerabilities, and null pointer dereference issues.

Oracle Linux

Oracle has released several updates to its Linux operating system, including bug fixes, security patches, and enhancements for various packages such as Samba, OpenCryptoki, rdma-core, and Squid. The updates also include security updates for Oracle Linux 8, 9, and 10 versions, addressing vulnerabilities in the kernel, nodejs22, linuxptp, and other packages. Oracle has released several bug fix updates to address issues with the Unbreakable Enterprise Kernel (UEK) and include fixes for various kernel versions. The updates aim to improve security, stability, and performance of Oracle Linux 7, 8, 9, and 10 distributions.

Red Hat Enterprise Linux

Red Hat has released several security updates to address potential vulnerabilities in Red Hat Enterprise Linux (RHEL). These updates include kernel updates for various versions of RHEL, such as 8, 9, and 10, which have been rated as having a moderate security impact. Additionally, updates are available for other components like CUPS, Ncurses, OpenShift, IDM, and Perl-JSON-XS. The updates aim to resolve vulnerabilities that could potentially compromise the security of RHEL systems.

Rocky Linux

Several security updates are available for Rocky Linux 9. The updates address vulnerabilities in packages such as pcs, perl-Module-ScanDeps, and microcode_ctl. These patches also provide fixes and enhancements to ensure system stability and security.

Slackware Linux

New fetchmail packages have been released to address a security issue in Slackware 15.0 and -current. The updated packages fix a vulnerability where the SMTP client can crash when authenticating. This update includes version 6 of fetchmail. Users are advised to install the new packages for improved security.

SUSE Linux

Multiple security updates have been released for SUSE Linux, addressing vulnerabilities across various components such as ModSecurity, NVIDIA drivers, and multiple Linux kernel live patches. Additionally, updates were released for packages like GIMP, Ruby, OpenSSL, Docker-Stable, Afterburn, SnpGuest, Nginx, Python-Django, Warewulf4, Cairo, Libsuricate, CURL, Jypyter-Jupyterlab, Frr, LibVMTools, and Mozilla Firefox.

Ubuntu Linux

Ubuntu has released security updates to address vulnerabilities in various packages, including Qt and inetutils, Python 2.7, Ghostscript, curl, Open VM Tools, Rack, and LibTIFF. Additionally, updates have been released for OpenSSL to fix three discovered issues that affect multiple Ubuntu versions. Security updates are also available for the Linux kernel, addressing various kernel vulnerabilities across different versions and architectures. These updates aim to improve security and stability in Ubuntu systems, affecting multiple LTS releases, including 22.04, 20.04, 18.04, and 16.04.

Tuxrepair