Jaroslav Lobačevski from GitHub Security Lab discovered a memory corruption vulnerability in the RAR module of p7zip, a now unmaintained fork of 7-Zip, a file archiver handling multiple formats. It is unlikely it could lead to arbitrary code execution, but it may lead to denial of service.
Multiple vulnerabilities were discovered in p7zip, a now unmaintained fork of 7-Zip, a file archiver handling multiple formats. To address these security vulnerabilities, whose fixes are unfortunately not isolated, this update replaces p7zip with 7-Zip v25 (which now supports GNU/Linux natively), slightly modified to make it
Three security vulnerabilities were discovered in python-authlib, a python library which builds OAuth and OpenID Connect servers, that can cause authentication bypass or information leaks. CVE-2026-27962 Fix authentication and authorization bypass vulnerability by embedding a
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 140.10.2esr-1~deb11u1.
Two vulnerabilities have been discovered in the Linux kernel that may lead to local privilege escalation. For Debian 11 bullseye, these problems have been fixed in version 6.1.170-3~deb11u1. This version also fixes some regressions found in the previous update.