Security 10907 Published by

Here is a roundup of this week's security updates, including Open-VM-Tools, Kernel, GnuTLS, Dovecot, FreeIPA, Git, and others. These updates aim to patch vulnerabilities and prevent potential security risks such as arbitrary code execution or denial of service across different versions of various Linux distributions, including AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux. The severity of the kernel updates is classified as moderate in some cases, while others have been rated as having an important or critical security impact by the respective distribution's product security teams.





AlmaLinux

AlmaLinux 10 has received a security update to address an important vulnerability in Open-VM-Tools, identified as CVE-2025-41244, which allows local privilege escalation. Additionally, other security updates have been released for various packages, including Open-VM-Tools (affecting AlmaLinux 8), Kernel (for versions 9 and 10), and GnuTLS. These updates aim to patch vulnerabilities and issues in the respective packages. The severity of the kernel updates is classified as moderate.

Debian GNU/Linux

The Debian project has released several security updates to address vulnerabilities in various packages. These updates include fixes for Dovecot, FreeIPA, Git, Mosquitto, Redis, Python-Django, and Asterisk, among others, which are designed to prevent potential security risks such as arbitrary code execution or denial of service. Additionally, updates were released for Chromium, Valkey, Tiff, and Ghostscript to address multiple issues that could lead to security breaches. The affected Debian versions include Buster (10), Bullseye (11), Bookworm (12), and Trixie (13).

Fedora Linux

Multiple security updates have been released for various Fedora Linux versions, including updates for JupyterLab, Chromium, Apptainer, Civetweb, OpenSSL, Docker, WordPress, and more. These updates address vulnerabilities such as heap buffer overflows, side-channel information leaks, and CVEs related to LaTeX typesetter and web browsers. Specific package updates include version 4.4.9 of JupyterLab, version 141.0.7390.54 of Chromium, and fixes for high-severity issues in Docker BuildKit, pgAdmin4, and ibus-bamboo. Additionally, security updates have been released for Fedora Linux distributions targeting Fedora 41 and Fedora 42 to address vulnerabilities in various packages including Chromium, Rust-based libraries, and yarnpkg.

Oracle Linux

Oracle has released several updates for its Linux distributions, including bug fixes and enhancements for various packages such as gnome-shell, protobuf, autofs, lshw, net-snmp, curl, file, and sos. These updates affect multiple versions of Oracle Linux, including 8, 9, and 10. Additionally, Oracle has also released security patches and bug fixes for other versions, including 7, 8, 9, and 10. The updated packages are part of Oracle's ongoing efforts to improve the stability and security of its Linux operating system.

Red Hat Enterprise Linux

Red Hat has released several updates to address security vulnerabilities and provide bug fixes for various software packages, including Firefox, GnuTLS, Thunderbird, and more. The updates have been rated as having an Important or Moderate security impact by Red Hat Product Security and are available for different versions of Red Hat Enterprise Linux (RHEL). Multiple products have received updates, including kernel, iputils, Satellite, AMQ Broker, IDM, IPA, and VIM, among others. Additionally, a kernel update has been released specifically for RHEL 6 Extended Lifecycle Support with an Important security impact rating.

Rocky Linux

Rocky Linux 8 has received kernel updates (RLSA-2025:16919 and RLSA-2025:16920) classified as moderate in terms of security risk. Additionally, multiple updates are available for Rocky Linux 10, including one that fixes a moderate vulnerability in perl-JSON-XS. Important security updates have been released for the Open-VM-Tools package affecting both Rocky Linux 8 and 10. Various other packages on different versions of Rocky Linux also require updates to mitigate vulnerabilities identified through the CVE list.

Slackware Linux

New packages of Python 3 have been released to address security issues. The updates are available for Slackware 15.0 and -current. For Slackware 15.0, the updated package is python3-3.9.24. This update aims to enhance the security of these Slackware versions.

SUSE Linux

Several security updates have been released to address vulnerabilities in various packages on openSUSE and SUSE Linux systems. The updates include patches for popular software such as Chromium, Firefox, Redis, ImageMagick, and Python libraries, among others. Vulnerabilities in these packages have been rated as critical or moderate by experts and are recommended to be resolved to ensure system security. Users of SUSE Linux can install the available updates using their respective package managers to fix these issues.

Ubuntu Linux

Multiple security updates have been released for various Ubuntu versions to address vulnerabilities in software packages such as MySQL, Squid, poppler, Linux kernels, PAM/U2F, HAProxy, and GStreamer Base Plugins. These updates aim to prevent potential attacks that could cause denial-of-service conditions or allow attackers to execute arbitrary code. Additionally, security issues have been discovered in the Linux kernel for various platforms and in packages like ImageMagick, Vim, LibHTP, and WebKitGTK, which also require updates to ensure system security. Users are advised to install these updates to maintain the security of their Ubuntu systems.

Tuxrepair