Security 10911 Published by

Several Linux distributions have released security updates in the last week to address various vulnerabilities in their packages. The affected distributions include AlmaLinux, Debian GNU/Linux, Fedora Linux, Gentoo Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux. These updates patch vulnerabilities in key applications such as Podman, Firefox, Bind, Kernel, Erlang, Rails, and other essential components to improve the overall security and stability of each distribution.





AlmaLinux

Several security updates have been released for AlmaLinux. The critical updates include patches for podman, python-kdcproxy, firefox, and bind, all classified as important. These updates aim to address potential vulnerabilities in these key applications.

Debian GNU/Linux

Debian has released multiple security updates to address vulnerabilities in various packages, including Erlang, the Linux kernel, Rails, and more. These updates also cover other applications such as KDE Connect, Samba, xrdp, ImageMagic, LibSSH, Krita, Tryton-server, tryton-server, and Sogo.

Fedora Linux

Fedora 43 has received security updates to address vulnerabilities in various packages. The first update affects Chromium, an open-source web browser, fixing two high-level CVEs related to type confusion in V8. Additionally, other versions of Fedora have also received security updates, including those for Docker, 7zip, Unbound, and Linux firmware. These updates aim to improve the overall security and stability of Fedora Linux by patching vulnerabilities in different packages.

Gentoo Linux

Gentoo Linux has released security updates to address multiple vulnerabilities in various packages, including UDisks, WebKitGTK+, qtsvg, Chromium, and Redis. These affected packages were found to have security issues that needed to be patched. Additionally, a separate security advisory was issued for the librnp package due to its vulnerability with weak random number generation. Users of Gentoo Linux are advised to update their systems as soon as possible to prevent potential security risks.

Oracle Linux

Oracle Linux has released several updates to address security vulnerabilities and bugs in various packages. These updates include patches for libssh, kernel, expat, podman, haproxy, Firefox, redis, ipa, sssd, vim, and other essential components. Additionally, critical security patches have been made available for Oracle Linux 9, including updates for bind, .NET, and nmstate.

Red Hat Enterprise Linux

Red Hat has released several security updates for Red Hat Enterprise Linux (RHEL), addressing vulnerabilities in various packages. Updates have been released for multiple versions of RHEL, including 8, 9, and 10, and affect packages such as kernel, Valkey, Ghostscript, BIND, TigerVNC, CUPS, expat, libxml2, Golang, and more. The updates have varying levels of severity, ranging from moderate to important, and are available for different versions of RHEL. Additionally, Red Hat has also released updates for its OpenShift Container Platform, addressing bugs and adding enhancements to packages and images.

Rocky Linux

Several security updates are available for Rocky Linux. The affected packages include openssl, valkey, java-25-openjdk, haproxy, gimp, mingw-expat, and libssh, with updates also available for other versions of the operating system, including 8, 9, and 10. These updates address various security vulnerabilities across different Rocky Linux versions, targeting packages like buildah, kernel, expat, go-rpm-macros, and module.crun. Additionally, separate updates are available for Redis, Container-Tools, CUPS, and other components on Rocky Linux.

Slackware Linux

Slackware users should be aware that the libpng package has been updated to address several security issues, including CVE-2025-64505 and others. This update is part of a broader effort to secure various packages in Slackware 15.0 and -current. In addition to libpng, CUPS has also received an update for Slackware to fix local denial-of-service issues and other vulnerabilities. LibXSLT packages have been updated as well to address CVE-2025-9714 and other security concerns.

SUSE Linux

SUSE Linux has received multiple security updates addressing various vulnerabilities in its packages. The updated components include the Linux Kernel, Mozilla Firefox, Podman, Python 3.9, GRUB2, and other third-party applications to ensure system security and stability. Additionally, several critical and important fixes have been issued for components like Redis, Tomcat 11, XWayland, PostgreSQL, and libcoap-devel to address specific vulnerabilities. These updates are designed to patch multiple weaknesses across various packages and maintain the overall security of SUSE Linux systems.

Ubuntu Linux

Ubuntu has released several security updates to address vulnerabilities in various packages, including runC, CUPS-Filters, Python, and the kernel. Other affected components include OpenJDK, MuPDF, H2O, Valkey, and EDK II, with multiple security notices issued for these packages. The updates aim to resolve issues such as incorrect handling of masked paths, malformed TIFF image files, and inefficiently handled expanding system environments. Ubuntu users should ensure their systems are up-to-date to prevent potential security risks associated with these vulnerabilities.

Tuxrepair