[DLA 4694-1] nss security update
ELA-1781-1 nss security update
ELA-1780-1 nss security update
[DSA 6394-1] firefox-esr security update
[DSA 6396-1] chromium security update
[DSA 6395-1] bind9 security update
[DLA 4695-1] firefox-esr security update
[SECURITY] [DLA 4694-1] nss security update
-------------------------------------------------------------------------
Debian LTS Advisory DLA-4694-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Jochen Sprickerhof
July 22, 2026 https://wiki.debian.org/LTS
-------------------------------------------------------------------------
Package : nss
Version : 2:3.61-1+deb11u6 2:3.87.1-1+deb12u3
CVE ID : CVE-2026-6766 CVE-2026-6767 CVE-2026-6772 CVE-2026-12318
Debian Bug :
Several vulnerabilities were discovered in NSS, a set of cryptographic
libraries, which may result in or denial of service or potentially the
execution of arbitrary code.
For Debian 11 bullseye, these problems have been fixed in version
2:3.61-1+deb11u6.
For Debian 12 bookworm, these problems have been fixed in version
2:3.87.1-1+deb12u3.
We recommend that you upgrade your nss packages.
For the detailed security status of nss please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/nss
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
ELA-1781-1 nss security update (by )
Package : nss
Version : 2:3.26.2-1.1+deb9u10 (stretch)
Related CVEs :
CVE-2026-6772
An Incorrect boundary conditions check was discovered in NSS, a set of
cryptographic libraries, which may result in or denial of service or
potentially the execution of arbitrary code.ELA-1781-1 nss security update (by )
ELA-1780-1 nss security update (by )
Package : nss
Version : 2:3.42.1-1+deb10u11 (buster)
Related CVEs :
CVE-2026-6767
CVE-2026-6772
CVE-2026-12318
Several vulnerabilities were discovered in NSS, a set of cryptographic
libraries, which may result in or denial of service or potentially the
execution of arbitrary code.ELA-1780-1 nss security update (by )
[SECURITY] [DSA 6394-1] firefox-esr security update
- -------------------------------------------------------------------------
Debian Security Advisory DSA-6394-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
July 22, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : firefox-esr
CVE ID : CVE-2026-15718 CVE-2026-15719 CVE-2026-16349 CVE-2026-16350
CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354
CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358
CVE-2026-16359 CVE-2026-16360 CVE-2026-16361 CVE-2026-16362
CVE-2026-16363 CVE-2026-16368 CVE-2026-16369 CVE-2026-16371
CVE-2026-16374 CVE-2026-16375 CVE-2026-16377 CVE-2026-16379
CVE-2026-16381 CVE-2026-16383 CVE-2026-16387 CVE-2026-16390
CVE-2026-16391 CVE-2026-16396 CVE-2026-16405 CVE-2026-16412
Multiple security issues have been found in the Mozilla Firefox web
browser, which could potentially result in the execution of arbitrary
code, bypass of the same-origin policy, privilege escalation,
information disclosure, spoofing or sandbox escape.
For the stable distribution (trixie), these problems have been fixed in
version 140.13.0esr-1~deb13u1.
We recommend that you upgrade your firefox-esr packages.
For the detailed security status of firefox-esr please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/firefox-esr
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
[SECURITY] [DSA 6396-1] chromium security update
- -------------------------------------------------------------------------
Debian Security Advisory DSA-6396-1 security@debian.org
https://www.debian.org/security/ Andres Salomon
July 22, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : chromium
CVE ID : CVE-2026-15899 CVE-2026-15900 CVE-2026-15901 CVE-2026-15902
CVE-2026-15903 CVE-2026-15904 CVE-2026-15905 CVE-2026-16413
CVE-2026-16414 CVE-2026-16415 CVE-2026-16416 CVE-2026-16417
CVE-2026-16418 CVE-2026-16419 CVE-2026-16420 CVE-2026-16421
CVE-2026-16422 CVE-2026-16423 CVE-2026-16424
Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.
For the stable distribution (trixie), these problems have been fixed in
version 150.0.7871.181-1~deb13u1.
We recommend that you upgrade your chromium packages.
For the detailed security status of chromium please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/chromium
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
[SECURITY] [DSA 6395-1] bind9 security update
- -------------------------------------------------------------------------
Debian Security Advisory DSA-6395-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
July 22, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : bind9
CVE ID : CVE-2026-10723 CVE-2026-10822 CVE-2026-11331 CVE-2026-11605
CVE-2026-11622 CVE-2026-11721 CVE-2026-12617 CVE-2026-13204
CVE-2026-13321
Several vulnerabilities were discovered in BIND, a DNS server
implementation, which may result in bypass of DNSSEC validation, RPZ
policy bypass, cache poisoning or denial of service.
For the stable distribution (trixie), these problems have been fixed in
version 1:9.20.26-1~deb13u1.
We recommend that you upgrade your bind9 packages.
For the detailed security status of bind9 please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/bind9
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
[SECURITY] [DLA 4695-1] firefox-esr security update
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4695-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Emilio Pozuelo Monfort
July 22, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : firefox-esr
Version : 140.13.0esr-1~deb11u1 140.13.0esr-1~deb12u1
CVE ID : CVE-2026-15718 CVE-2026-15719 CVE-2026-16349 CVE-2026-16350
CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354
CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358
CVE-2026-16359 CVE-2026-16360 CVE-2026-16361 CVE-2026-16362
CVE-2026-16363 CVE-2026-16368 CVE-2026-16369 CVE-2026-16371
CVE-2026-16374 CVE-2026-16375 CVE-2026-16377 CVE-2026-16379
CVE-2026-16381 CVE-2026-16383 CVE-2026-16387 CVE-2026-16390
CVE-2026-16391 CVE-2026-16396 CVE-2026-16405 CVE-2026-16412
Multiple security issues have been found in the Mozilla Firefox web
browser, which could potentially result in the execution of arbitrary
code, bypass of the same-origin policy, privilege escalation,
information disclosure, spoofing or sandbox escape.
For Debian 11 bullseye, these problems have been fixed in version
140.13.0esr-1~deb11u1.
For Debian 12 bookworm, these problems have been fixed in version
140.13.0esr-1~deb12u1.
We recommend that you upgrade your firefox-esr packages.
For the detailed security status of firefox-esr please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/firefox-esr
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS