Linux Security Roundup: Thunderbird, Firefox-ESR, and Python Fixes

Published by

A significant wave of Linux security patches has been released across multiple distributions, including Debian, Fedora, Ubuntu, Red Hat, Rocky, Slackware, and SUSE, with a focus on Mozilla's Thunderbird and Firefox-ESR, which account for a large number of the reported vulnerabilities. Debian alone has issued updates for 62 CVEs in Firefox-ESR and 44 in Thunderbird, while security fixes for Python's query string parser could potentially break systems relying on semicolons for separation. Other notable updates include critical patches for OpenSSL and various kernel vulnerabilities, particularly affecting server-side applications that utilize PHP or handle email through Thunderbird. Administrators are advised to prioritize these updates, especially those related to OpenSSL and the major Mozilla updates, while also ensuring proper management of any potential application breakage due to the changes in the Python parser



Linux Security Roundup: Thunderbird, Firefox-ESR, and Python Fixes

A broad wave of Linux security patches rolled out today across Debian, Fedora, Ubuntu, Red Hat, Rocky, Slackware, and SUSE, delivering a heavy multi-distro load rather than one standout critical. Mozilla's Thunderbird and Firefox-ESR dominate the CVE counts, with Debian shipping 62 flaws in Firefox-ESR and 44 in Thunderbird across most of the affected releases. The two fixes that could surprise admins are Debian's Python 3.7 parser, which now treats only ampersands as query separators, and Fedora's ruff and ty, which gained an arbitrary code execution risk when checking untrusted code. Big numbers like SUSE's 108 Chromium CVEs and Ubuntu's 101-CVE Oracle kernel are mostly about staying current, so prioritize the OpenSSL key-recovery and PHP TLS updates and fold the rest into normal maintenance.

Linux Security Roundup: Thunderbird, Firefox-ESR, and Python Fixes @ Linux Compatible