Security 10911 Published by

Multiple Linux distributions have released security updates over the past week to address vulnerabilities in various packages. Distributions such as AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux have all issued updates to patch issues in packages like kernels, web browsers, and libraries. These security updates aim to improve the overall security and stability of each distribution by addressing vulnerabilities that could lead to local privilege escalation, information disclosure, or code execution if left unpatched. Each distribution has released specific updates for its versions, with some also releasing critical updates to address significant security issues.





AlmaLinux

AlmaLinux has released several security updates to address vulnerabilities in various packages, including the kernel and xorg-x11-server-Xwayland. These updates also cover other packages, such as expat, osbuild-composer, valkey, qt6-qtsvg, bind, and runc. Additionally, AlmaLinux has released two more updates: a kernel-rt package update that addresses three vulnerabilities, including one related to conditional IBPB mitigation (CVE-2025-40300), and a libtiff update. A separate kernel security update has been released for AlmaLinux 9 to address multiple vulnerabilities affecting AMD processors and x86/vmscape.

Debian GNU/Linux

Multiple security updates have been released for various Debian packages, including gdk-pixbuf, Incus, strongSwan, libarchive, and Firefox-ESR. These updates address vulnerabilities that could lead to heap buffer overflows, local privilege escalation, information disclosure, or code execution if left unpatched. Other affected packages include gst-plugins-good1.0, LXD, Chromium, Keystone, Squid, and Lasso, each with its own specific vulnerability fixes.

Fedora Linux

Several security updates have been released for Fedora Linux, addressing vulnerabilities in various packages such as Xwayland, Chromium, .NET Runtime, and Rust libraries. Updates were made to multiple versions of Fedora, including Fedora 41, 42, and 43, and resolved issues like out-of-bounds writes, denial-of-service attacks, and memory exhaustion. Additionally, updates were released for packages like Ruby, Forgejo, WebkitGTK, SeaMonkey, Docker BuildKit, runc, gh, Lasso, Firefox, Gitleaks, and more. These updates aim to improve the security of Fedora Linux by addressing various vulnerabilities and bugs in different components.

Oracle Linux

Oracle has released several security updates and bug fixes for its Linux distribution, including an important update to the Unbreakable Enterprise kernel. These updates also include enhancements for various packages, such as ca-certificates and Oracle Common Release. Additionally, multiple versions of Oracle Linux have received security updates, including versions 7, 8, 9, and 10. Oracle Linux 7 has also been updated with a new release addressing several OpenJDK security vulnerabilities.

Red Hat Enterprise Linux

Multiple security updates are now available for various Red Hat Enterprise Linux versions. These updates aim to address vulnerabilities and improve system security by patching issues in several packages, including kernel, Bind, Thunderbird, Squid, LibTIFF, JBoss, zziplib, shadow-utils, OpenSSH, Firefox, and others. The affected systems include various versions of Red Hat Enterprise Linux, such as 8, 9, and 10, as well as OpenShift Container Platform. Red Hat Product Security has rated the updates with a security impact ranging from moderate to important.

Rocky Linux

Rocky Linux users, a security update is available for LibTIFF in version 8 to address a critical issue affecting the system's stability and security. In addition, updates are also available for several packages, including xorg-x11-server-Xwayland and libssh, which affect Rocky Linux 9 and address potential security vulnerabilities. Meanwhile, kernel updates have been released for Rocky Linux 8, one addressing security issues with the standard kernel and another with kernel-rt, both of which have CVSS base scores to gauge severity. Users should check available updates for their specific version of Rocky Linux to ensure system stability and security.

Slackware Linux

Mozilla has released updates for several popular applications on the Linux distribution Slackware. The updates include a new version of Firefox, version 140.5.0esr, which fixes security issues and improves performance. Mozilla also updated Thunderbird to fix various security vulnerabilities. Meanwhile, xpdf packages have been released with bug and security fixes for Slackware 15.0.

SUSE Linux

Multiple security updates have been released for SUSE Linux, addressing vulnerabilities in various packages. Updates include fixes for popular software such as Java, Mozilla Thunderbird, Python-Django, Chromium, and Firefox, among others. In addition to these individual package updates, several kernel live patches have also been updated to improve system security. A total of eight separate security update announcements have been made, covering a range of affected components and vulnerabilities.

Ubuntu Linux

Ubuntu has issued several security updates to address vulnerabilities in various components. The first update fixes Intel Microcode issues that specifically affect Intel Xeon processors with SGX enabled and stream cache mechanisms. Additionally, the company has released updates for Rust-sudo-rs, Raptor, the Linux kernel, and BIND to address multiple security issues affecting different versions of Ubuntu. These updates aim to mitigate potential risks and ensure system security for Ubuntu users.

Tuxrepair