Debian 11 DLA-4582-1 Thunderbird Important Arbitrary Code Threat

14.05.2026 23:45 Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.10.2esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.

Debian DSA-6271-1 gsasl Critical Denial of Service Vulnerability Fix

14.05.2026 23:45 It was discovered that missing input sanitising in the DIGEST-MD5 parser of the GNU SASL library could result in denial of service. For the oldstable distribution , this problem has been fixed in version 2.2.0-1+deb12u1. For the stable distribution , this problem has been fixed in

Debian Trixie PostgreSQL-17 Key SQL Injection Vulnerability DSA-6270-1

14.05.2026 23:45 Multiple security issues were discovered in PostgreSQL, which may result in authorisation bypass, execution of arbitrary code, information disclosure, privilege escalation, SQL injection or denial of service. For the stable distribution , these problems have been fixed in version 17.10-0+deb13u1.

Debian DSA-6269-1 PostgreSQL 15 Serious SQL Injection Disruption

14.05.2026 23:45 Multiple security issues were discovered in PostgreSQL, which may result in authorisation bypass, execution of arbitrary code, information disclosure, privilege escalation, SQL injection or denial of service. For the oldstable distribution , these problems have been fixed in version 15.18-0+deb12u1.

Debian Trixie FFmpeg Arbitrary Code Execution Fix DSA-6268-1

14.05.2026 23:45 Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. For the stable distribution , this problem has been fixed in version 7:7.1.4-0+deb13u1.

Ubuntu 26.04 LTS nginx Critical Denial of Service 2026-42945

14.05.2026 23:45 nginx could be made to crash or run programs if it received specially crafted network traffic.

Debian DSA-6266-1 nghttp2 Critical DoS Exploit CVE-2026-27135

14.05.2026 17:15 It was discovered that nghttp2, an implementation of the HTTP/2 protocol, could be crashed via an assertion failure. A remote attacker could exploit this to cause a DoS attack by sending a malformed frame immediately after triggering the termination path. For the oldstable distribution , this problem has been fixed

Mageia 9 perl-XML-LibXML High Buffer Overflow Vulnerability MGASA-2026-0137

14.05.2026 17:15 MGASA-2026-0137 - Updated perl-XML-LibXML packages fix security vulnerability

Mageia 9 perl-Net-CIDR-Lite Severe IP ACL Bypass Vulnerability 2026-0136

14.05.2026 17:15 MGASA-2026-0136 - Updated perl-Net-CIDR-Lite packages fix security vulnerabilities

Mageia 9 dnsmasq Moderate Denial of Service and Buffer Overflow Alert

14.05.2026 17:15 MGASA-2026-0135 - Updated dnsmasq packages fix security vulnerabilities

Mageia 9 Redis Medium Remote Code Execution Vulnerabilities MGASA-2026-0134

14.05.2026 17:15 MGASA-2026-0134 - Updated redis packages fix security vulnerabilities

Mageia 9 Flatpak Critical Sandbox Escape Vulnerability File Deletion Risk

14.05.2026 17:15 MGASA-2026-0133 - Updated flatpak packages fix security vulnerabilities

Fedora 42 Kernel Urgent Security Fragnesia CVE-2026-46299 Notice

14.05.2026 10:32 The 6.19.14-102 stable kernel update contains a fix for the Fragnesia CVE-2026-46300.

Ubuntu 24 node-express10 Major RCE Vulnerability Patch 2026-a1234567bc

14.05.2026 10:32 Fixes CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass Fixes CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST Fixes CVE-2026-6907: Potential exposure of private data due to incorrect

Fedora 42 GitPython 3.1.50 Sec Defects Fix CVE-2026-42215 2026-585a8768df

14.05.2026 10:32 Update to 3.1.50; fixes CVE-2026-42215 / GHSA-mv93-w799-cj2w. Fixes security defects GHSA-rpm5-65cw-6hj4, GHSA-x2qx-6953-8485, GHSA-7545-fcxq-7j24, and GHSA-v87r-6q3f-2j67.