Security 10912 Published by

This week's roundup includes security updates from various Linux distributions to address vulnerabilities and ensure system security and stability. The updates cover multiple packages across different distributions, including AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux. Specific issues addressed in the updates include identity takeover via duplicate UUID registration, denial of service, memory corruption, and arbitrary code execution in affected packages. The security patches aim to protect users from potential threats and ensure the smooth functioning of various applications on their respective operating systems.





AlmaLinux

AlmaLinux has released security updates to address vulnerabilities in Grafana and kernel packages. The first update fixes a moderate-level vulnerability in Grafana related to parsing GNU sparse maps (CVE-2025-58183). Another update addresses several security issues, such as identity takeover via duplicate UUID registration in Keylime and various kernel vulnerabilities. AlmaLinux users can use these patches to enhance system security and stability.

Debian GNU/Linux

Debian has released multiple security advisories to address vulnerabilities in various packages. Updates were issued for Thunderbird, VLC media player, and Ruby, as well as other packages, including Python-APT and Paramiko. Additionally, Debian 11 LTS received updates for Glib2.0, Binwalk, Libgd2, and Node-URL-Pause, while Debian saw security advisories for Webkit2GTK, Roundcube, C-Ares, Dropbear, and MediaWiki. These updates aim to fix issues such as denial of service, memory corruption, or arbitrary code execution in the affected packages.

Fedora Linux

Fedora has released various security patches and updates across multiple versions, including 42 and 43. These updates address vulnerabilities in packages such as Firefox, Chromium, Python, Qtdeclarative, and others to improve system security. Additionally, Fedora has updated several other packages like Nextcloud, CEF, and Util-Linux to enhance overall system stability and security. The updates aim to protect users from potential threats and ensure the smooth functioning of various applications on the Fedora operating system.

Oracle Linux

Oracle has released various security updates and bug fixes for its Linux operating systems. For Oracle Linux 7, these updates include kernel security patches (ELSA-2025-28049 and ELSA-2025-22040), a Linux-firmware bug fix update (ELBA-2025-28050), and Firefox security updates. Additionally, Oracle has released updates for other packages such as oVirt, FreeRADIUS, Rust-Sequoia-SQ, Bind, Keylime, LibSSH, curl, binutils, Dracut, httpd, libvirt, openssh, and podman. These updates affect multiple versions of Oracle Linux, including 7, 8, 9, and 10.

Red Hat Enterprise Linux

Red Hat Enterprise Linux 8.6 has been updated to fix a moderate security vulnerability in libpq. A similar update was also released for Ghostscript on Red Hat Enterprise Linux 9 with the same security rating. Various other package updates, including rsync, keylime, binutils, kernel, and webkit2gtk3 across multiple versions of RHEL, have addressed unspecified vulnerabilities. These vulnerabilities had been rated as Important or Moderate by Red Hat Product Security.

Slackware Linux

New packages of PHP have been released to address security issues in both Slackware 15.0 and the current version. These updates specifically fix vulnerabilities found in PDO quoting, array_merge(), and getimagesize(). Users are advised to install these updates as soon as possible.

SUSE Linux

Multiple security updates have been released for SUSE Linux, including updates for Chromium, Hauler, Keylime, and Go. These updates address critical vulnerabilities in various packages, such as Keylime, which received a critical security update to fix a serious vulnerability. Additionally, other essential tools like govulncheck-vulndb and Thunderbird have also been updated with security patches. The updates are available for installation using SUSE-recommended methods or specific commands for each affected product.

Ubuntu Linux

Ubuntu has released several security updates to address vulnerabilities in the Linux kernel, including fixes for usbmuxd and libsoup. The updates specifically target different systems such as Azure, FIPS, real-time, Raspberry Pi, and OEM configurations. Additionally, critical kernel updates are available for Ubuntu Linux, covering standard and Azure variants. Multiple security vulnerabilities have been fixed in the Linux kernel for various Ubuntu versions, including 24.04 LTS.

Tuxrepair