Linux Security Roundup: Unbound Criticals and a Chromium Flood Across Six Distros
Six Linux distributions shipped security updates today, with the biggest priorities being a DNS resolver called unbound and major browser patches. Unbound earned Critical ratings across three distros due to remote code execution and DNSSEC flaws that can expose entire networks. The browser bomb came from SUSE (63 vulnerabilities in Firefox ESR), Thunderbird (44 CVEs on AlmaLinux), and Debian's Chromium (108 CVEs), all driven by use-after-free and privilege-escalation bugs. Patch your resolver and browser first, then work through the smaller, more surgical advisories in the coming maintenance window.
Linux Security Roundup: Unbound Criticals and a Chromium Flood Across Six Distros @ Linux Compatible
Linux Security Roundup: Unbound Criticals and a Chromium Flood Across Six Distros
Six Linux distributions have released important security updates, primarily addressing critical vulnerabilities in the DNS resolver Unbound and various web browsers. Unbound has received critical ratings due to remote code execution and DNSSEC flaws, while browsers including Firefox, Thunderbird, and Chromium have been updated to fix numerous vulnerabilities related to use-after-free and privilege escalation bugs. The security updates across AlmaLinux, Debian, Fedora, RHEL, Rocky Linux, and SUSE include a significant focus on patching these critical issues, with recommendations to prioritize updating DNS resolvers and browsers first. Additional advisories cover various packages, including fixes for other software vulnerabilities and maintenance issues, emphasizing the need for administrators to apply these updates promptly to secure their systems
