news
Security Leftovers
-
LWN ☛ Security updates for Friday
Security updates have been issued by Debian (chromium, cjson, and firefox-esr), Fedora (expat, gh, scap-security-guide, and xen), Oracle (container-tools:rhel8, firefox, grub2, and mysql:8.4), SUSE (busybox, busybox-links, element-web, kernel, shadowsocks-v2ray-plugin, and yt-dlp), and Ubuntu (imagemagick, linux, linux-aws, linux-gcp, linux-gke, linux-gkeop, linux-hwe-6.8, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-oracle, linux-azure, linux-azure-5.15, linux-azure-fips, linux-ibm, linux-ibm-6.8, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-raspi, linux-oracle-6.8, linux-realtime, and openjpeg2).
-
OpenSSF (Linux Foundation) ☛ From Ghent to Brussels: OpenSSF’s Week of Policy and Security in Europe
At the end of October, the 'Linux' Foundation, the 'Linux' Foundation Europe and OpenSSF will gather leaders across industry, government, and open source communities for three impactful events in Belgium. Together, these back-to-back gatherings will advance collaboration, shape policy, and highlight the critical role of open source in Europe’s digital future.
-
PureVPN on Linux Leaks IPv6 Traffic and Tampers with Firewalls
Two critical security issues affecting PureVPN’s Linux clients can lead to IPv6 traffic leaking outside the encrypted tunnel and permanent changes to host firewall rules, exposing users to unintended network risks.
The flaws are tracked under CVE-2025-59691 and CVE-2025-59692, and as of this writing, the VPN vendor has not pushed fixes, so they remain unresolved and exploitable.
-
It's FOSS ☛ eBPF Foundation Awards $100K in Research Grants to Universities
Researchers receive funding to advance eBPF tech.