You are here
Security
DSA-5956-1 ring - security update
DSA-5955-1 chromium - security update
DSA-5954-1 sudo - security update
DSA-5953-1 catdoc - security update
DSA-5952-1 chromium - security update
DSA-5951-1 icu - security update
DSA-5949-1 libxml2 - security update
Multiple memory related vulnerabilities, inlcuding use-after-free, out-of-bounds memory access and NULL pointer dereference, were discovered in GNOME XML Parser and Toolkit Library and its Python bindings, which may cause denial of service or other unintended behaviors.
DSA-5950-1 firefox-esr - security update
DSA-5948-1 trafficserver - security update
DSA-5947-1 xorg-server - security update
DSA-5946-1 gdk-pixbuf - security update
DSA-5945-1 konsole - security update
DSA-5944-1 chromium - security update
DSA-5943-1 libblockdev - security update
Details can be found in the Qualys advisory at https://www.qualys.com/2025/06/17/suse15-pam-udisks-lpe.txt
Along with the libblockdev update, updated udisks2 packages are released, to enforce that private mounts are mounted with 'nodev,nosuid'.
DSA-5942-1 chromium - security update
DSA-5941-1 gst-plugins-bad1.0 - security update
DSA-5940-1 modsecurity-apache - security update
DSA-5939-1 gimp - security update
DSA-5938-1 python-tornado - security update
DSA-5937-1 webkit2gtk - security update
CVE-2025-24223
rheza and an anonymous researcher discovered that processing maliciously crafted web content may lead to memory corruption.
CVE-2025-31204
Nan Wang discovered that processing maliciously crafted web content may lead to memory corruption.
CVE-2025-31205
Ivan Fratric discovered that a malicious website may exfiltrate data cross-origin.
CVE-2025-31206
An anonymous researcher discovered that processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2025-31215
Jiming Wang and Jikai Ren discovered that processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2025-31257
Juergen Schmied discovered that processing maliciously crafted web content may lead to an unexpected process crash.
Pages
