Collected every two hours from specialised publications — each link leads to the original article.
An update that solves two vulnerabilities can now be installed.
Fixes CVE-2025-32728
Fixes CVE-2025-32728
Machine-in-the-middle attack vulnerability if verifyhostkeydns is enabled. (CVE-2025-26465) References: - https://bugs.mageia.org/show_bug.cgi?id=34036
* bsc#1237040 * bsc#1237041 Cross-References: * CVE-2025-26465
* bsc#1226642 Cross-References: * CVE-2024-6387
Backport fix for CVE-2024-6387 (rhbz#2294879)
* bsc#1226642 Cross-References: * CVE-2024-6387
* bsc#1218215 Cross-References: * CVE-2023-51385
* bsc#1218215 * bsc#1220110 Cross-References: * CVE-2023-51385
* bsc#1218215 Cross-References: * CVE-2023-51385
Apply fix for CVE-2023-28531
Security fix for CVE-2023-38408
Avoid possible self-DoS attack Resolves: CVE-2023-25136
Avoid possible self-DoS attack Resolves: CVE-2023-25136
Security fix for CVE-2021-41617
Add fix to CVE-2021-28041
We often view OpenSSH security updates through the lens of standard patch management. When a new CVE hits, we scramble to update, check our versions, and retur…
Important: openssh security update
Debian 12.9 has just been released, offering numerous security enhancements and bug fixes vital for Linux security admins managing Debian systems. This point r…
It was discovered that phpseclib, a PHP library for arbitrary-precision integer arithmetic, was vulnerable to the so-called Terrapin Attack. The SSH transport …