You are here
Debian Security
DSA-5996-1 chromium - security update
DSA-5995-1 hsqldb1.8.0 - security update
DSA-5994-1 shibboleth-sp - security update
For additional information please refer to the upstream advisory at https://shibboleth.net/community/advisories/secadv_20250903.txt
DSA-5993-1 chromium - security update
DSA-5992-1 firebird4.0 - security update
DSA-5991-1 nodejs - security update
DSA-5990-1 libxml2 - security update
DSA-5989-1 udisks2 - security update
DSA-5988-1 chromium - security update
DSA-5987-1 unbound - security update
DSA-5986-1 node-cipher-base - security update
DSA-5985-1 ffmpeg - security update
DSA-5984-1 thunderbird - security update
DSA-5983-1 qemu - security update
In Bookworm the affected packages are qemu-user-static (and qemu-user-binfmt) instead of qemu-user.
Additionally, two security issues were fixed the in SR-IOV support of QEMU system emulation.
DSA-5982-1 squid - security update
DSA-5981-1 chromium - security update
DSA-5980-1 firefox-esr - security update
DSA-5979-1 libxslt - security update
CVE-2023-40403
Information disclosure with weak memory handling of generated-id()
CVE-2025-7424
Type confusion in xmlNode.psvi between stylesheet and source nodes, which may allow an attacker to crash the application or corrupt memory.
DSA-5978-1 webkit2gtk - security update
CVE-2025-6558
Clement Lecigne and Vlad Stolyarov discovered that processing maliciously crafted web content may lead to an unexpected crash.
CVE-2025-31273
Yuhao Hu, Yan Kang, Chenggang Wu, and Xiaojie Wei discovered that processing maliciously crafted web content may lead to memory corruption.
CVE-2025-31278
Yuhao Hu, Yan Kang, Chenggang Wu, and Xiaojie Wei discovered that processing maliciously crafted web content may lead to memory corruption.
CVE-2025-43211
Yuhao Hu, Yan Kang, Chenggang Wu, and Xiaojie Wei discovered that processing web content may lead to a denial-of-service.
CVE-2025-43212
Nan Wang and Ziling Chen discovered that processing maliciously crafted web content may lead to an unexpected crash.
CVE-2025-43216
Ignacio Sanmillan discovered that processing maliciously crafted web content may lead to an unexpected crash.
CVE-2025-43227
Gilad Moav discovered that processing maliciously crafted web content may disclose sensitive user information.
CVE-2025-43228
Jaydev Ahire discovered that visiting a malicious website may lead to address bar spoofing.
CVE-2025-43240
Syarif Muhammad Sajjad discovered that a download's origin may be incorrectly associated.
CVE-2025-43265
HexRabbit discovered that processing maliciously crafted web content may disclose internal states of the app.