Principal · Últimas noticias de seguridad
USN-8152-1: Linux kernel (OEM) vulnerabilities
It was discovered that some AMD Zen 5 processors supporting RDSEED instruction did not properly handle entropy, potentially resulting in the consumption of insufficiently random values. A local attacker could possibly use this issue to inf…
USN-8148-4: Linux kernel (Real-time) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Netfilter; - Network traffic c…
USN-8145-3: Linux kernel (GCP) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Cryptographic API; - UDF file…
USN-8151-1: lambdaisland/uri vulnerability
It was discovered that lambdaisland/uri did not properly sanitize the backslash character in URI strings. An attacker could possibly use this issue to bypass security checks or redirect users.
USN-8150-1: SPIP vulnerabilities
It was discovered that SPIP did not properly sanitize certain inputs. A remote attacker could possibly use this issue to perform cross site scripting. (CVE-2022-28959) It was discovered that SPIP did not properly sanitize certain inputs. …
DSA-6197-2 dovecot - regression update
https://security-tracker.debian.org/tracker/DSA-6197-2
DSA-6199-1 trafficserver - security update
https://security-tracker.debian.org/tracker/DSA-6199-1
DSA-6200-1 tor - security update
https://security-tracker.debian.org/tracker/DSA-6200-1
DSA-6197-1 dovecot - security update
https://security-tracker.debian.org/tracker/DSA-6197-1
DSA-6198-1 valkey - security update
https://security-tracker.debian.org/tracker/DSA-6198-1
DSA-6196-1 roundcube - security update
https://security-tracker.debian.org/tracker/DSA-6196-1
DSA-6195-1 python-tornado - security update
https://security-tracker.debian.org/tracker/DSA-6195-1
DSA-6193-1 inetutils - security update
https://security-tracker.debian.org/tracker/DSA-6193-1
DSA-6194-1 pyasn1 - security update
https://security-tracker.debian.org/tracker/DSA-6194-1
USN-8148-3: Linux kernel (Real-time) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Netfilter; - Network traffic c…
USN-8148-2: Linux kernel (FIPS) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Netfilter; - Network traffic c…
USN-8145-2: Linux kernel (FIPS) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Cryptographic API; - UDF file…
USN-8143-2: Linux kernel (FIPS) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - GPU drivers; - BTRFS file syst…
USN-8146-1: libjxl vulnerability
Daniel Novomeský discovered that libjxl did not properly manage memory when decoding certain files. An attacker could use this issue to cause libjxl to crash, resulting in denial of service, or possibly execute arbitrary code.
USN-8149-1: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Netfilter; - Network traffic c…
USN-8147-1: libarchive vulnerabilities
It was discovered that libarchive incorrectly handled certain archive files. An attacker could possibly use this issue to access sensitive information. This issue only affected Ubuntu 14.04 LTS. (CVE-2019-19221) It was discovered that lib…
USN-8148-1: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Netfilter; - Network traffic c…
From AI to Open Source at WordCamp Asia 2026
April 9-11, 2026 | Jio World Convention Centre, Mumbai, India WordCamp Asia 2026 brings the WordPress community to Mumbai, India, from April 9 to 11, with a schedule shaped around artificial intelligence, enterprise WordPress, develop…
USN-8145-1: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Cryptographic API; - UDF fil…
USN-8144-1: Undertow vulnerability
It was discovered that Undertow incorrectly validated the Host header in incoming HTTP requests. A remote attacker could possibly use this issue to gain unintended access to user sessions.
USN-8140-1: Cairo vulnerabilities
Alberto Garcia, Francisco Oca and Suleman Ali discovered that Cairo did not properly manage memory. An attacker could possibly use this issue to cause Cairo to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 …
DSA-6192-1 chromium - security update
https://security-tracker.debian.org/tracker/DSA-6192-1
EasyApache 4 25.52
Security and maintenance updates We released updated packages for EasyApache 4. This security and maintenance release addresses 6 CVEs in ea-nginx 1.29.7, 7 CVEs in ea-nodejs22 and ea-nodejs20, and 1 CVE in ea-nghttp2 (CVE-2026-27135). It …
USN-8143-1: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - GPU drivers; - BTRFS file syst…
USN-8142-1: Linux kernel vulnerability
A security issue was discovered in the Linux kernel. An attacker could possibly use this to compromise the system. This update corrects flaws in the following subsystems: - Network traffic control;
USN-8095-5: Linux kernel (Raspberry Pi) vulnerabilities
Qualys discovered that several vulnerabilities existed in the AppArmor Linux kernel Security Module (LSM). An unprivileged local attacker could use these issues to load, replace, and remove arbitrary AppArmor profiles causing denial of ser…
USN-8141-1: Linux kernel (Raspberry Pi) vulnerabilities
Qualys discovered that several vulnerabilities existed in the AppArmor Linux kernel Security Module (LSM). An unprivileged local attacker could use these issues to load, replace, and remove arbitrary AppArmor profiles causing denial of se…
USN-8094-5: Linux kernel (Raspberry Pi) vulnerabilities
Qualys discovered that several vulnerabilities existed in the AppArmor Linux kernel Security Module (LSM). An unprivileged local attacker could use these issues to load, replace, and remove arbitrary AppArmor profiles causing denial of ser…
USN-8139-1: cargo-c vulnerability
It was discovered that tar-rs embedded in cargo-c incorrectly handled symlinks when unpacking a tar archive. If a user or automated system were tricked into processing a specially crafted tar archive, a remote attacker could use this issue…
USN-8138-1: tar-rs vulnerability
It was discovered that tar-rs incorrectly handled symlinks when unpacking a tar archive. If a user or automated system were tricked into processing a specially crafted tar archive, a remote attacker could use this issue to modify permissio…
DSA-6190-1 gst-plugins-bad1.0 - security update
https://security-tracker.debian.org/tracker/DSA-6190-1
DSA-6191-1 gst-plugins-ugly1.0 - security update
https://security-tracker.debian.org/tracker/DSA-6191-1
USN-8089-2: Go Networking vulnerabilities
USN-8089-1 fixed vulnerabilities in Go Networking. This update provides the corresponding update to code vendored in golang-golang-x-net-dev. Original advisory details: Bahruz Jabiyev, Tommaso Innocenti, Anthony Gavazzi, Steven Sprecher…
USN-8136-1: Dovecot vulnerabilities
It was discovered that Dovecot incorrectly handled invalid base64 SASL data. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 25.10. (CVE-2025-59028) It was discovered that Dovecot sc…
USN-8137-1: Ruby vulnerability
It was discovered that the Ruby URI gem did not properly handle sensitive information when combining URIs. A remote attacker could possibly use this issue to leak authentication credentials.