Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 29 vulnerabilities and has one bug fix can now be installed.. openSUSE security update: security update for mozillafirefox ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21043-1 Rating: important References: * bsc#1268071 Cross-References: * CVE-2026-12289 * CVE-2026-12290 * CVE-2026-12291 * CVE-2026-12292 * CVE-2026-12294 * CVE-2026-12295 * CVE-2026-12296 * CVE-2026-12297 * CVE-2026-12298 * CVE-2026-12299 * CVE-2026-12302 * CVE-2026-12304 * CVE-2026-12305 * CVE-2026-12306 * CVE-2026-12307 * CVE-2026-12308 * CVE-2026-12309 * CVE-2026-12310 * CVE-2026-12311 * CVE-2026-12312 * CVE-2026-12313 * CVE-2026-12314 * CVE-2026-12315 * CVE-2026-12324 * CVE-2026-12325 * CVE-2026-12327 * CVE-2026-12328 * CVE-2026-12329 * CVE-2026-12330 CVSS scores: * CVE-2026-12290 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12291 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12292 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-12294 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12296 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12297 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12298 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12302 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12304 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12305 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12306 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12307 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12308 ( SUSE ): 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12309 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12310 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12311 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12312 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12313 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12314 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12315 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12324 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-12325 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12327 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12329 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-12330 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 29 vulnerabilities and has one bug fix can now be installed. Description: This update for MozillaFirefox fixes the following issue Update to Firefox 140.12.0 ESR (MFSA 2026-58, bsc#1268071): - CVE-2026-12289: Privilege escalation in the Graphics: WebRender component. - CVE-2026-12290: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12291: Use-after-free in the Networking: HTTP component. - CVE-2026-12292: Incorrect boundary conditions in the Web Audio component. - CVE-2026-12294: Sandbox escape in the DOM: Workers component. - CVE-2026-12295: Sandbox escape in the DOM: Navigation component. - CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component. - CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component. - CVE-2026-12298: Memory safety bug fixed in Firefox ESR140.12. - CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component. - CVE-2026-12302: Mitigation bypass in the DOM: Security component. - CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component. - CVE-2026-12305: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12306: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12307: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12308: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12309: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12310: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12311: Information disclosure, sandbox escape in the Security: Process Sandboxing component. - CVE-2026-12312: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12313: Information disclosure, sandbox escape in the Security: Process Sandboxing component. - CVE-2026-12314: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12315: Mitigation bypass in the DOM: Security component. - CVE-2026-12324: Incorrect boundary conditions in the Graphics: CanvasWebGL component. - CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component. - CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. - CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. - CVE-2026-12329: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12330: Incorrect boundary conditions in the Internationalization component. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1056=1 Package List: - openSUSE Leap 16.0: MozillaFirefox-140.12.0-160000.1.1 MozillaFirefox-branding-upstream-140.12.0-160000.1.1 MozillaFirefox-devel-140.12.0-160000.1.1 MozillaFirefox-translations-common-140.12.0-160000.1.1 MozillaFirefox-translations-other-140.12.0-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-12289.html * https://www.suse.com/security/cve/CVE-2026-12290.html * https://www.suse.com/security/cve/CVE-2026-12291.html * https://www.suse.com/security/cve/CVE-2026-12292.html * https://www.suse.com/security/cve/CVE-2026-12294.html * https://www.suse.com/security/cve/CVE-2026-12295.html * https://www.suse.com/security/cve/CVE-2026-12296.html * https://www.suse.com/security/cve/CVE-2026-12297.html * https://www.suse.com/security/cve/CVE-2026-12298.html * https://www.suse.com/security/cve/CVE-2026-12299.html * https://www.suse.com/security/cve/CVE-2026-12302.html * https://www.suse.com/security/cve/CVE-2026-12304.html * https://www.suse.com/security/cve/CVE-2026-12305.html * https://www.suse.com/security/cve/CVE-2026-12306.html * https://www.suse.com/security/cve/CVE-2026-12307.html * https://www.suse.com/security/cve/CVE-2026-12308.html * https://www.suse.com/security/cve/CVE-2026-12309.html * https://www.suse.com/security/cve/CVE-2026-12310.html * https://www.suse.com/security/cve/CVE-2026-12311.html * https://www.suse.com/security/cve/CVE-2026-12312.html * https://www.suse.com/security/cve/CVE-2026-12313.html * https://www.suse.com/security/cve/CVE-2026-12314.html * https://www.suse.com/security/cve/CVE-2026-12315.html * https://www.suse.com/security/cve/CVE-2026-12324.html * https://www.suse.com/security/cve/CVE-2026-12325.html * https://www.suse.com/security/cve/CVE-2026-12327.html * https://www.suse.com/security/cve/CVE-2026-12328.html * https://www.suse.com/security/cve/CVE-2026-12329.html * https://www.suse.com/security/cve/CVE-2026-12330.html . Update for MozillaFirefox on openSUSE addresses 29 issues including essential security fixes and enhancements.. MozillaFirefox security update, openSUSE advisory, important security fixes,software vulnerabilities, risk management. . Severity: Important. LinuxSecurity.com Team
Two security issues were discovered in Luanti, a multiplayer infinite-world block sandbox game, which could result in incomplete restrictions for installed mods or sandbox escape. For the stable distribution (trixie), these problems have been fixed in version 5.10.0+dfsg-5+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6217-1
An update that solves 13 vulnerabilities can now be installed.. # Security update for MozillaThunderbird Announcement ID: SUSE-SU-2026:0153-1 Release Date: 2026-01-19T11:14:05Z Rating: critical References: * bsc#1256340 Cross-References: * CVE-2025-14327 * CVE-2026-0877 * CVE-2026-0878 * CVE-2026-0879 * CVE-2026-0880 * CVE-2026-0882 * CVE-2026-0883 * CVE-2026-0884 * CVE-2026-0885 * CVE-2026-0886 * CVE-2026-0887 * CVE-2026-0890 * CVE-2026-0891 CVSS scores: * CVE-2025-14327 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-14327 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-14327 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-14327 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0877 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-0878 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N * CVE-2026-0879 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-0880 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-0882 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-0883 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-0884 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-0885 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-0886 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-0887 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-0890 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-0891 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise WorkstationExtension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 13 vulnerabilities can now be installed. ## Description: This update for MozillaThunderbird fixes the following issues: MFSA 2026-05 (bsc#1256340): * CVE-2026-0877: Mitigation bypass in the DOM in Security component * CVE-2026-0878: Sandbox escape due to incorrect boundary conditions in the Graphics in CanvasWebGL component * CVE-2026-0879: Sandbox escape due to incorrect boundary conditions in the Graphics component * CVE-2026-0880: Sandbox escape due to integer overflow in the Graphics component * CVE-2026-0882: Use-after-free in the IPC component * CVE-2025-14327: Spoofing issue in the Downloads Panel component * CVE-2026-0883: Information disclosure in the Networking component * CVE-2026-0884: Use-after-free in the JavaScript Engine component * CVE-2026-0885: Use-after-free in the JavaScript: GC component * CVE-2026-0886: Incorrect boundary conditions in the Graphics component * CVE-2026-0887: Clickjacking issue, information disclosure in the PDF Viewer component * CVE-2026-0890: Spoofing issue in the DOM in Copy & Paste and Drag & Drop component * CVE-2026-0891: Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-153=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-153=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-153=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * MozillaThunderbird-translations-common-140.7.0-150200.8.251.1 * MozillaThunderbird-debuginfo-140.7.0-150200.8.251.1 *MozillaThunderbird-translations-other-140.7.0-150200.8.251.1 * MozillaThunderbird-140.7.0-150200.8.251.1 * MozillaThunderbird-debugsource-140.7.0-150200.8.251.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x) * MozillaThunderbird-translations-common-140.7.0-150200.8.251.1 * MozillaThunderbird-debuginfo-140.7.0-150200.8.251.1 * MozillaThunderbird-translations-other-140.7.0-150200.8.251.1 * MozillaThunderbird-140.7.0-150200.8.251.1 * MozillaThunderbird-debugsource-140.7.0-150200.8.251.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * MozillaThunderbird-translations-common-140.7.0-150200.8.251.1 * MozillaThunderbird-debuginfo-140.7.0-150200.8.251.1 * MozillaThunderbird-translations-other-140.7.0-150200.8.251.1 * MozillaThunderbird-140.7.0-150200.8.251.1 * MozillaThunderbird-debugsource-140.7.0-150200.8.251.1 ## References: * https://www.suse.com/security/cve/CVE-2025-14327.html * https://www.suse.com/security/cve/CVE-2026-0877.html * https://www.suse.com/security/cve/CVE-2026-0878.html * https://www.suse.com/security/cve/CVE-2026-0879.html * https://www.suse.com/security/cve/CVE-2026-0880.html * https://www.suse.com/security/cve/CVE-2026-0882.html * https://www.suse.com/security/cve/CVE-2026-0883.html * https://www.suse.com/security/cve/CVE-2026-0884.html * https://www.suse.com/security/cve/CVE-2026-0885.html * https://www.suse.com/security/cve/CVE-2026-0886.html * https://www.suse.com/security/cve/CVE-2026-0887.html * https://www.suse.com/security/cve/CVE-2026-0890.html * https://www.suse.com/security/cve/CVE-2026-0891.html * https://bugzilla.suse.com/show_bug.cgi?id=1256340 . Critical update for MozillaThunderbird resolving 13 important issues. Immediate installation recommended to secure your system.. MozillaThunderbird Security Update, SUSE Updates, Critical Vulnerability Fixes. . Severity: Critical. LinuxSecurity.com Team
MGASA-2025-0303 - Updated flatpak & bubblewrap packages fix security vulnerability. MGASA-2025-0303 - Updated flatpak & bubblewrap packages fix security vulnerability Publication date: 19 Nov 2025 URL: https://advisories.mageia.org/MGASA-2025-0303.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-42472 Description: Flatpak may allow access to files outside sandbox for certain apps. (CVE-2024-42472). References: - https://bugs.mageia.org/show_bug.cgi?id=33510 - https://openwall.com/lists/oss-security/2024/08/14/6 - https://www.cve.org/CVERecord?id=CVE-2024-42472 SRPMS: - 9/core/flatpak-1.14.10-1.mga9 - 9/core/bubblewrap-0.7.0-1.1.mga9 . Discover how updated flatpak & bubblewrap packages resolve critical security issues in Mageia systems.. Mageia Flatpak Security Access Sandbox Updates. . Severity: Critical. LinuxSecurity.com Team
MGASA-2025-0228 - Updated thunderbird packages fix vulnerabilities. MGASA-2025-0228 - Updated thunderbird packages fix vulnerabilities Publication date: 05 Sep 2025 URL: https://advisories.mageia.org/MGASA-2025-0228.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-6424, CVE-2025-6425, CVE-2025-6429, CVE-2025-6430, CVE-2025-8027, CVE-2025-8028, CVE-2025-8029, CVE-2025-8030, CVE-2025-8031, CVE-2025-8032, CVE-2025-8033, CVE-2025-8034, CVE-2025-8035, CVE-2025-9179, CVE-2025-9180, CVE-2025-9181, CVE-2025--9185 Description: Use-after-free in FontFaceSet. (CVE-2025-6424) The WebCompat WebExtension shipped exposed a persistent UUID. (CVE-2025-6425) Incorrect parsing of URLs could have allowed embedding of youtube.com. (CVE-2025-6429) Content-Disposition header ignored when a file is included in an embed or object tag. (CVE-2025-6430) JavaScript engine only wrote partial return value to stack. (CVE-2025-8027) Large branch table could lead to truncated instruction. (CVE-2025-8028) Javascript: URLs executed on object and embed tags. (CVE-2025-8029) Potential user-assisted code execution in “Copy as cURL” command. (CVE-2025-8030) Incorrect URL stripping in CSP reports. (CVE-2025-8031) XSLT documents could bypass CSP. (CVE-2025-8032) Incorrect JavaScript state machine for generators. (CVE-2025-8033) Memory safety bugs fixed in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. (CVE-2025-8034) Memory safety bugs fixed in Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. (CVE-2025-8035) Sandbox escape due to invalid pointer in the Audio/Video: GMP component. (CVE-2025-9179) Same-origin policy bypass in the Graphics: Canvas2D component. (CVE-2025-9180) Uninitialized memory in the JavaScript Engine component. (CVE-2025-9181) Memory safety bugs fixed in Firefox ESR 115.27,Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. (CVE-2025-9185). For the armv7hl architecture this package fixes additional vulnerabilities; see the links below: https://advisories.mageia.org/MGASA-2025-0197.html https://advisories.mageia.org/MGASA-2025-0168.html https://advisories.mageia.org/MGASA-2025-0151.html https://advisories.mageia.org/MGASA-2025-0126.html https://advisories.mageia.org/MGASA-2025-0093.html https://advisories.mageia.org/MGASA-2025-0048.html https://advisories.mageia.org/MGASA-2025-0010.html https://advisories.mageia.org/MGASA-2024-0395.html https://advisories.mageia.org/MGASA-2024-0384.html https://advisories.mageia.org/MGASA-2024-0365.html https://advisories.mageia.org/MGASA-2024-0350.html https://advisories.mageia.org/MGASA-2024-0336.html https://advisories.mageia.org/MGASA-2024-0332.html References: - https://bugs.mageia.org/show_bug.cgi?id=34415 - https://www.thunderbird.net/en-US/thunderbird/128.12.0esr/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa2025-55/ - https://www.thunderbird.net/en-US/thunderbird/128.13.0esr/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa2025-62/ - https://www.thunderbird.net/en-US/thunderbird/128.14.0esr/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa2025-71/ - https://www.cve.org/CVERecord?id=CVE-2025-6424 - https://www.cve.org/CVERecord?id=CVE-2025-6425 - https://www.cve.org/CVERecord?id=CVE-2025-6429 - https://www.cve.org/CVERecord?id=CVE-2025-6430 - https://www.cve.org/CVERecord?id=CVE-2025-8027 - https://www.cve.org/CVERecord?id=CVE-2025-8028 - https://www.cve.org/CVERecord?id=CVE-2025-8029 - https://www.cve.org/CVERecord?id=CVE-2025-8030 - https://www.cve.org/CVERecord?id=CVE-2025-8031 - https://www.cve.org/CVERecord?id=CVE-2025-8032 - https://www.cve.org/CVERecord?id=CVE-2025-8033 - https://www.cve.org/CVERecord?id=CVE-2025-8034 - https://www.cve.org/CVERecord?id=CVE-2025-8035 -https://www.cve.org/CVERecord?id=CVE-2025-9179 - https://www.cve.org/CVERecord?id=CVE-2025-9180 - https://www.cve.org/CVERecord?id=CVE-2025-9181 - https://www.cve.org/CVERecord?id=CVE-2025--9185 SRPMS: - 9/core/thunderbird-128.14.0-1.mga9 - 9/core/thunderbird-l10n-128.14.0-1.mga9 . The latest Firefox updates for Linux address several critical vulnerabilities, significantly improving the browser's security and performance.. Mageia security patch, Thunderbird update, Mageia vulnerabilities, security advisory, application security. . Severity: Important. LinuxSecurity.com Team
Version 3.1.6 Released 2025-03-05 The |attr filter does not bypass the environment's attribute lookup, allowing the sandbox to apply its checks.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-8b6aa24ab4 2025-03-25 00:57:48.852448+00:00 -------------------------------------------------------------------------------- Name : python-jinja2 Product : Fedora 40 Version : 3.1.6 Release : 1.fc40 URL : https://palletsprojects.com/projects/jinja/ Summary : General purpose template engine Description : Jinja2 is a template engine written in pure Python. It provides a Django inspired non-XML syntax but supports inline expressions and an optional sandboxed environment. If you have any exposure to other text-based template languages, such as Smarty or Django, you should feel right at home with Jinja2. It's both designer and developer friendly by sticking to Python's principles and adding functionality useful for templating environments. -------------------------------------------------------------------------------- Update Information: Version 3.1.6 Released 2025-03-05 The |attr filter does not bypass the environment's attribute lookup, allowing the sandbox to apply its checks. -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 9 2025 Thomas Moschny - 3.1.6-1 - Update to 3.1.6. * Sat Jan 18 2025 Fedora Release Engineering - 3.1.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2350190 - CVE-2025-27516 jinja2: Jinja sandbox breakout through attr filter selecting format method https://bugzilla.redhat.com/show_bug.cgi?id=2350190 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnfupgrade --advisory FEDORA-2025-8b6aa24ab4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Version 3.1.6 Released 2025-03-05 The |attr filter does not bypass the environment's attribute lookup, allowing the sandbox to apply its checks.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-cd7f5876b2 2025-03-11 01:33:11.319592+00:00 -------------------------------------------------------------------------------- Name : python-jinja2 Product : Fedora 41 Version : 3.1.6 Release : 1.fc41 URL : https://palletsprojects.com/projects/jinja/ Summary : General purpose template engine Description : Jinja2 is a template engine written in pure Python. It provides a Django inspired non-XML syntax but supports inline expressions and an optional sandboxed environment. If you have any exposure to other text-based template languages, such as Smarty or Django, you should feel right at home with Jinja2. It's both designer and developer friendly by sticking to Python's principles and adding functionality useful for templating environments. -------------------------------------------------------------------------------- Update Information: Version 3.1.6 Released 2025-03-05 The |attr filter does not bypass the environment's attribute lookup, allowing the sandbox to apply its checks. -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 9 2025 Thomas Moschny - 3.1.6-1 - Update to 3.1.6. * Sat Jan 18 2025 Fedora Release Engineering - 3.1.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2350190 - CVE-2025-27516 jinja2: Jinja sandbox breakout through attr filter selecting format method https://bugzilla.redhat.com/show_bug.cgi?id=2350190 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnfupgrade --advisory FEDORA-2025-cd7f5876b2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to jinja2-3.1.5.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-5f04326f4f 2025-01-17 01:35:26.873127+00:00 -------------------------------------------------------------------------------- Name : mingw-python-jinja2 Product : Fedora 40 Version : 3.1.5 Release : 1.fc40 URL : https://palletsprojects.com/projects/jinja/ Summary : MinGW Windows Python jinja2 library Description : MinGW Windows Python jinja2 library. -------------------------------------------------------------------------------- Update Information: Update to jinja2-3.1.5. -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 8 2025 Sandro Mani - 3.1.5-1 - Update to 3.1.5 * Thu Jul 18 2024 Fedora Release Engineering - 3.1.4-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2336370 - CVE-2024-56201 mingw-python-jinja2: Jinja has a sandbox breakout through malicious filenames [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2336370 [ 2 ] Bug #2336376 - CVE-2024-56201 mingw-python-jinja2: Jinja has a sandbox breakout through malicious filenames [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2336376 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-5f04326f4f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.