[DSA 6198-1] valkey security update
[DSA 6197-1] dovecot security update
[DSA 6200-1] tor security update
[DSA 6199-1] trafficserver security update
[SECURITY] [DSA 6198-1] valkey security update
- -------------------------------------------------------------------------
Debian Security Advisory DSA-6198-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
April 05, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : valkey
CVE ID : CVE-2025-67733 CVE-2026-21863
Two security vulnerabilities were discovered in Valkey, a persistent
key-value database with network interface, which could result in denial
of service or data manipulation.
For the stable distribution (trixie), these problems have been fixed in
version 8.1.1+dfsg1-3+deb13u2.
We recommend that you upgrade your valkey packages.
For the detailed security status of valkey please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/valkey
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
[SECURITY] [DSA 6197-1] dovecot security update
- -------------------------------------------------------------------------
Debian Security Advisory DSA-6197-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
April 05, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : dovecot
CVE ID : CVE-2025-59031 CVE-2025-59032 CVE-2026-27855
CVE-2026-27856 CVE-2026-27857 CVE-2026-27858
CVE-2026-27859 CVE-2026-59028 CVE-2026-24031
CVE-2026-27860 CVE-2026-0394
Multiple vulnerabilities have been discovered in the Dovecot IMAP server
which way result in denial of service, SQL injection, path traversal,
replay attacks or timing side channel attacks.
For the oldstable distribution (bookworm), these problems have been fixed
in version 1:2.3.19.1+dfsg1-2.1+deb12u2.
For the stable distribution (trixie), these problems have been fixed in
version 1:2.4.1+dfsg1-6+deb13u4.
We recommend that you upgrade your dovecot packages.
For the detailed security status of dovecot please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/dovecot
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
[SECURITY] [DSA 6200-1] tor security update
- -------------------------------------------------------------------------
Debian Security Advisory DSA-6200-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
April 05, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : tor
CVE ID : not yet available
Two security vulnerabilities (TROVE-2026-004 and TROVE-2025-015) were
discovered in Tor, a connection-based low-latency anonymous
communication system, which could result in denial of service.
For the oldstable distribution (bookworm), this problem has been fixed
in version 0.4.9.6-0+deb12u1.
For the stable distribution (trixie), this problem has been fixed in
version 0.4.9.6-0+deb13u1.
We recommend that you upgrade your tor packages.
For the detailed security status of tor please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/tor
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
[SECURITY] [DSA 6199-1] trafficserver security update
- -------------------------------------------------------------------------
Debian Security Advisory DSA-6199-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
April 05, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : trafficserver
CVE ID : CVE-2025-58136 CVE-2025-65114
Two vulnerabilities were discovered in Apache Traffic Server, a reverse
and forward proxy server, which could result in denial of service or
HTTP request smuggling.
For the oldstable distribution (bookworm), these problems have been fixed
in version 9.2.5+ds-0+deb12u4.
We recommend that you upgrade your trafficserver packages.
For the detailed security status of trafficserver please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/trafficserver
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/