Re: [lfs-support] Critical information about security vulnerabilities in LFS and BLFS (Dated 2025-05-21)

"Rainer Fiebig" ([email protected] via blfs-support Mailing List) <[email protected]> Wed, 21 May 2025 17:27:34 +0200
Newsgroups gmane.linux.lfs.beyond.support,gmane.linux.lfs.support
Message-ID <[email protected]>
Am 21.05.25 um 09:12 schrieb "Douglas R. Reno"
([email protected] via lfs-support Mailing List):
> Good morning folks (it counts as morning here, just hit 12:15am as I am
> writing this :) )!
> 
> There have been many important security vulnerability fixes since the
> last email. The security updates this particular cycle have been very
> challenging to work with so far, not only because of personal stuff with
> me (hardware failures causing backlogs combined with my university
> classes the last two weeks) but also dealing with regressions/problems
> from a variety of security updates (including WebKit, Qt6, expat,
> libarchive, and QtWebEngine). These issues will be mentioned throughout
> the descriptions of the updates. The security updates in this email
> require special care, and many of them need to be applied to all of your
> systems immediately to protect them due to their severity and impacts.
> Please treat the issues described in this email as **urgent**.
> 
> Before we go over the updates though, I would like to personally thank
> Joe Locash, Rainer Fiebig, Marty Jack, and Zeckma for their help in
> collecting security information, fixing bugs in updates, and
> disseminating security information. Joe has personally reached out to me
> a few times to let me know about issues such as libsoup and giflib, and
> has filed tickets for other ones that I was able to get into the book in
> time for this round of security advisories. Rainer has inquired about
> the advisories a couple of times which has helped me describe some of
> the issues that have come up, and Zeckma assisted me with getting a few
> updates in (Firefox/Thunderbird) to make things easier for this set of
> advisories. Joe also provided me with a helpful fix for LibreOffice due
> to OpenJDK, which saved me potentially several rebuilds of LibreOffice
> trying to fix the issue. Marty also provided me with an extremely
> helpful patch to fix issues with LibreOffice and poppler. Thank you all
> so much for your help, without it this would've been much tougher to
> take care of.
> 
> Another important thing to mention is that **all** users who have
> make-ca installed need to make sure that they are on make-ca-1.16 to
> prevent issues with obtaining updated security certificates from
> Mozilla. Mozilla recently changed the domain that we get the
> certificates from hg.mozilla.org to hg-edge.mozilla.org, and in addition
> to the domain, also changed the organization that signs the certificate
> for the new domain. Because of that, previous versions of make-ca will
> no longer be able to contact Mozilla's servers to download the security
> certificates. In make-ca-1.16 we fixed this by shipping the correct root
> certificate to contact hg-edge.mozilla.org, and corrected the domain name.
> 
> Users who are building stable LFS will have noticed that expat-2.6.4 is
> no longer available. Please download 2.7.1 instead, as 2.6.4 was pulled
> upstream due to security vulnerabilities. It has been tested on BLFS
> 12.3 systems and is confirmed to work well.
> 
> This email will cover the following packages:
> 
> - libxslt
> 
> - PHP
> 
> - Expat (LFS)
> 
> - WebKitGTK
> 
> - libarchive
> 
> - Exim
> 
> - Mercurial
> 
> - Qt6
> 
> - QtWebEngine
> 
> - lxml (Python Module)
> 
> - libxml2
> 
> - Exempi
> 
> - c-ares
> 
> - Perl (LFS)
> 
> - Python (LFS and BLFS)
> 
> - xz (LFS)
> 
> - Yelp
> 
> - libsoup3
> 
> - libsoup2
> 
> - giflib
> 
> - Epiphany
> 
> - ghostscript
> 
> - gstreamer
> 
> - LibreOffice
> 
> - PostgreSQL
> 
> - intel-microcode
> 
> - Screen
> 
> - OpenJDK
> 
> - Gimp
> 
> - Spidermonkey
> 
> - Firefox
> 
> - Thunderbird
> 
> **libxslt**: We'll begin with libxslt. This security update has been
> rated as High. Two security vulnerabilities were fixed here which could
> allow for arbitrary code execution, as well as crashes when processing
> XSL documents. Both vulnerabilities are due to use-after-free bugs. One
> of them happens when processing XPath context nodes, because an XPath
> context node can be modified but never restored when using nested XPath
> evaluations. Applications which use the xsltNumberFormatGetValue,
> xsltEvalXPathPredicate, xsltEvalXPathStringNs, and
> xsltComputeSortResultInternal functions may be impacted. The other
> vulnerability happens in the xsltGetInheritedNsList function, and is
> related to the exclusion of result prefixes. Users who have libxslt
> installed should update to libxslt-1.1.43, especially since these
> vulnerabilities can theoretically be triggered through XHTML pages if
> you are using QtWebEngine as configured in the book.
> 
> **PHP**: This security update has been rated as Medium. A total of seven
> vulnerabilities were fixed that could cause crashes, arbitrary code
> execution, unauthorized HTTP redirects, authentication bypasses, remote
> system crashes, and for invalid HTTP headers to be processed. The
> vulnerabilities exist in the Streams, libxml, and Core components within
> PHP. **ALL** users who have PHP installed and use it in the context of a
> web application are encouraged to update to at least PHP 8.4.5 to fix
> these vulnerabilities.
> 
> **Expat (LFS)**: This security update has been rated as High. A security
> vulnerability was fixed that could result in a crash from chaining a
> large number of entities. The vulnerability is caused by a stack
> overflow, and upstream resolved it by fixing the usage of recursion for
> general entities in character data and attribute data, as well as for
> parameter entities. The crash is unfortunately very easy to trigger.
> This update was a little complex to put in though, as the initial
> version that it was fixed in (2.7.0) introduced a major regression where
> any application that called the XML_GetCurrentByteCount,
> XML_GetCurrentByteIndex, XML_GetCurrentColumnNumber,
> XML_GetCurrentLineNumber, and the XML_GetInputContext functions to
> immediately crash. It was originally discovered in the XML::Parser perl
> module's test suite, and we immediately brought it to upstream at
> https://github.com/cpan-authors/XML-Parser/issues/104 as soon as it was
> discovered. We recommend that all users who have Expat installed update
> to Expat 2.7.1 as soon as possible because of how easy the crash is to
> trigger, and how many applications use Expat for XML parsing behind the
> scenes.
> 
> **WebKitGTK**: This security update has been rated as Critical. Sixteen
> security vulnerabilities were fixed that could result in unexpected
> process crashes, cross-origin data exfiltration, memory corruption,
> cross-site scripting attacks, type confusion (note that this only
> affects ARM architectures), and sandbox escapes. The sandbox escape
> vulnerability is known to be exploited in the wild. This update took a
> long time because of issues that cropped up with 32-bit systems, and
> 64-bit systems with less than 16GB of RAM. CMake defaults to using -O3
> for the optimization level when you do a Release build, and one of the
> automatically generated files that WebKit creates is extremely large. It
> was discovered that systems with less than 16GB of RAM could not build
> WebKitGTK-2.48.0 or later without manually decreasing the optimization
> level, which we now cover in the Important note in the WebKitGTK page
> prior to build instructions. This unfortunately caused a significant
> delay as it took over a dozen attempts before I was able to come up with
> a workable solution. Rahul, Thomas, and Xi also took a stab at the issue
> at points, as well as Ken - thank you all! Because of the variety of
> impacts here as well as the fact that the sandbox escape is known to be
> exploited in the wild, all users who have WebKitGTK installed should
> update to 2.48.2 immediately.
> 
> **libarchive**: This security update has been rated as Medium. Three
> security vulnerabilities were fixed here that could allow for denial of
> service (application crashes) or memory corruption when processing ZIP
> or TAR archives. The ZIP vulnerability exists in the 'bsdunzip' utility,
> and there is a public proof of concept exploit available - however, note
> that the worst impact is a crash. The TAR issues are both due to
> heap-based buffer overreads, and can occur when handling truncation in
> the middle of GNU long linknames, and when checking strftime return
> values. The vulnerabilities were fixed in 3.7.8, but a major regression
> was discovered in 3.7.8 and we thus recommend updating to
> libarchive-3.7.9 instead.
> 
> **Exim**: This security update has been rated as High. A security
> vulnerability was fixed that could allow users with command line access
> to the server to obtain privilege escalation to root. The issue is
> caused by a use-after-free issue, and in BLFS systems, can occur before
> exim fully drops privileges to the 'exim' user depending on timing. If
> you have Exim installed on your system, you should update to Exim 4.98.2.
> 
> **Mercurial**: This security vulnerability has been rated as Medium,
> because the default BLFS configuration is not impacted. If you are not
> using the 'hgweb' program (which is not part of the standard BLFS
> configuration), you may safely skip this update. If you do use the
> 'hgweb' program, it is vulnerable to cross-site scripting attacks. The
> vulnerability allows attackers to forge a link that will execute
> JavaScript code in the victim's browser, but note that most WSGI
> implementations will throw a HTTP 500 error instead of allowing the
> exploit to succeed. Still though, if you use the 'hgweb' functionality
> from Mercurial, you should update to Mercurial 7.0.1.
> 
> **Qt6**: This security update has been rated as Low. A security
> vulnerability has been fixed that could allow for a heap buffer overflow
> when passing an incorrectly formatted Markdown file to an application
> that utilizes QTextMarkdownImporter. The only known impacts at this time
> are application crashes. There are two approaches to fixing this
> vulnerability. One way is to apply the official Qt patch to your system
> if you have Qt 6.8.x installed. That patch can be found at
> https://download.qt.io/official_releases/qt/6.8/CVE-2025-3512-qtbase-6.8.diff,
> but note that the BLFS team has not tested this approach (though there
> is a very very low chance that it doesn't work). The other option would
> be to upgrade your system to Qt 6.9.0. This involves a lot of risk, and
> can be complex. The risk being that a lot of private API that
> applications were depending on was changed in Qt 6.9.0. These issues
> start to crop up in Plasma, libportal, and LXQt (due to a dependency on
> a Plasma component). If you decide to update to Qt 6.9.0, you will need
> to rebuild libportal with the patch in the development book to fix usage
> of private API, as well as rebuild Plasma with the instructions in the
> development book again because of private API usage. If you use LXQt and
> have only installed the minimal set of KDE components necessary to use
> it, you will need to rebuild layer-shell-qt also because of private API
> usage. After updating Qt you will also need to rebuild anything that
> installs files in /opt/qt6 - in BLFS that includes qca and qcoro. Most
> users will very likely not be impacted by this vulnerability, so the
> risk in skipping this update is Low. However, if you do decide to update
> to Qt 6.9.0, please keep the above information in mind.
> 
> **QtWebEngine**: This security update has been rated as Critical. In
> QtWebEngine-6.9.0, fifteen security vulnerabilities were fixed that
> could allow for sensitive system data exfiltration, user interface
> spoofing, remote code execution, arbitrary code execution, and sandbox
> escapes. The vulnerabilities are in a variety of components in the
> bundled copy of Chromium, including GPU, 7-zip, Network, V8, Browser,
> UI, DevTools, Media, Media Stream, PDFium, WebRTC, and Inspector. The
> WebRTC vulnerability is known to be exploited in the wild, and is a
> sandbox escape. It is the exact same vulnerability fixed in WebKitGTK,
> and we thus recommend that all users update this package immediately.
> However, there was a regression discovered after the release of
> QtWebEngine-6.9.0, where GPU acceleration was broken. This was another
> one of those challenging bugs to fully resolve in BLFS, since there were
> many moving parts involved. We've developed a patch with commits from
> upstream that fixes the issue, however in addition to applying the patch
> users must update Falkon to the latest version as well. That has been
> tested to work on a BLFS 12.3 system though without modifications. All
> users with QtWebEngine should update to QtWebEngine 6.9.0 with the patch
> immediately, and then rebuild Falkon to ensure that GPU acceleration
> continues to function correctly.
> 
> **lxml (Python Module)**: This security update has been rated as High.
> In lxml-5.4.0, the bundled copies of libxml2 and libxslt were updated to
> fix five security vulnerabilities. The vulnerabilities allow for
> arbitrary code execution and crashes when processing crafted XML and
> XSLT documents. The issues occur due to heap-based buffer underreads,
> stack buffer overflows, out of bounds memory accesses, and
> use-after-free issues. Users who have the lxml python module installed
> should update to lxml-5.4.0.
> 
> **libxml2**: This security update has been rated as High. In
> libxml2-2.14.2 (and 2.13.8), two security vulnerabilities were fixed
> that could result in a denial of service or arbitrary code execution
> when processing XML documents. One of the issues occurs in the
> xmlSchemalDCFillNodeTables function, and is due to a heap-based buffer
> under read. To exploit that vulnerability, an attacker must validate the
> XML document against an XML schema with certain identity constraints
> (although a crafted XML schema can be used as well). The other
> vulnerability is in the Python API, and it causes an out of bounds
> memory access due to an incorrect return value when using the
> xmlPythonFileRead and xmlPythonFileReadRaw functions. The issue occurs
> because of a difference in bytes and characters. This update brings
> something that requires special care. libxml2-2.14 is ABI incompatible
> with libxml2-2.13, and many packages on the system must be recompiled in
> order to fix the vulnerability. If you update to libxml2-2.14, you must
> also update libxkbcommon and localsearch to fix critical runtime issues
> that libxml2-2.14 causes in those packages. As a result, we recommend
> that users stay on the libxml2-2.13 series and update to 2.13.8 instead
> of upgrading to 2.14 on an existing system.
> 
> **Exempi**: This security update has been rated as Medium. Before we go
> any further on this one, I want to note that even though the
> vulnerabilities look severe here, they are rated as Medium by upstream
> because they are challenging to exploit and require the usage of
> advanced XMP features. In Exempi-2.6.6, five security vulnerabilities
> were fixed in the bundled Adobe XML Toolkit SDK that could allow for
> out-of-bounds reads. The impacts include denial of service (application
> crashes), and information disclosure of sensitive memory when processing
> crafted XMP metadata. Updating to Exempi-2.6.6 is recommended if you
> manipulate files with XMP metadata.
> 
> **c-ares**: This security update has been rated as High. A security
> vulnerability was fixed that could allow for a crash when processing DNS
> queries where a DNS Cookie Failure occurs, when an upstream server does
> not properly support EDNS, or potentially on TCP queries if the remote
> server closed the connection immediately after a response. The crash
> occurs due to a use-after-free issue in the read_answers() function, and
> is theoretically exploitable by remote attackers if the attacker can
> flood your system with ICMP UNREACHABLE packets - but in order for this
> to happen, the attackers must have control over the upstream nameserver.
> The vulnerability has been rated as High upstream due to the fact that
> it's attack vector is Network, and the impact is a remotely exploitable
> crash, but note that the attack complexity is High. Users who have
> c-ares installed should update to c-ares-1.34.5.
> 
> **Perl (LFS)**: This security update has been rated as High. A security
> vulnerability was fixed that could allow for a denial of service or
> arbitrary code execution when transliterating non-ASCII bytes. The issue
> is caused by a heap buffer overflow, and a subsequent out of bounds
> write. A simple one-line reproducer is available that demonstrates a
> crash caused by the vulnerability. Users should update to Perl 5.40.2.
> If you are on an older version of LFS which has one of Perl 5.38, 5.36,
> or 5.34 - the Perl developers have put out new releases for those lines!
> You'll want to update to 5.38.4, 5.36.3, or 5.34.3.
> 
> **Python (LFS and BLFS): This security update has been rated as Medium.
> In Python-3.13.3, two security vulnerabilities were fixed that could
> allow for unbounded memory usage (causing a denial of service by
> consuming all of the RAM on your system), and for email header spoofing.
> However, after the release of 3.13.3, an additional security
> vulnerability was discovered that can allow for a crash when using the
> unicode_escape encoding or an error handler when decoding bytes with the
> bytes.decode() function. The unbounded memory usage issue occurs while
> writing temporary files with the
> tempfile.SpooledTemporaryFile.writelines() function, as the function
> only checks whether it should roll over after the entire line's iterator
> is exhausted. The email header spoofing vulnerability occurs when using
> RFC2047 encoding and using the as_bytes function with the policy=default
> behavior. Users should update to Python 3.13.3 with the security fixes
> patch that we implemented earlier for the unicode_escape vulnerability
> (thank you to Joe Locash for filing a ticket in BLFS for it).
> 
> **xz (LFS)**: This security update has been rated as High. A security
> vulnerability was resolved that could allow for invalid input when
> decompressing a XZ file to cause a denial of service (crash) or
> arbitrary code execution. The issue is caused by a heap use after free,
> but it can also write to an address based on the null pointer plus an
> offset. This can be used to inject bytes into memory. Applications and
> libraries which use the lzma_stream_decoder_mt function are impacted,
> but note that the vulnerability only gets triggered when decompressing
> crafted files. That being said though, all users are recommended to
> update to xz-5.8.1 as soon as possible especially if you decompress
> unknown/untrusted xz files.
> 
> **yelp**: This security update has been rated as High. This one is a bit
> special, as it really should be rated as Critical. A security
> vulnerability was found in Yelp-42.2 that allows for help documents to
> execute arbitrary JavaScript and also read arbitrary files on the disk.
> Upstream has **not** released a patched version of yelp/yelp-xsl to
> resolve the problem, but the BLFS team has adopted some patches from
> upstream to resolve it ourselves. The patches resolve the issue by
> implementing a Content Security Policy through some calls to WebKit,
> which prevent JavaScript code from being executed. There is a public
> writeup and exploit available, and it shows just how dangerous this
> vulnerability is. The exploit demonstrates reading a user's SSH private
> key via a crafted help document, and exfiltrating it to another system.
> Because of that, **ALL** BLFS USERS WHO HAVE YELP INSTALLED SHOULD APPLY
> THE PATCHES AS SOON AS POSSIBLE. Note that patches will need to be
> applied to both yelp-xsl and yelp for the mitigation of the
> vulnerability to be successful.
> 
> **libsoup3*: This security update has been rated as Critical. In
> libsoup3, ten security vulnerabilities were fixed that could allow for
> remotely exploitable crashes, remote code execution, and memory
> corruption. The vulnerabilities happen in a variety of different
> functions inside of libsoup3, including append_param_quoted(),
> sniff_unknown(), sniff_feed_or_html(), soup_headers_parse_request(),
> sniff_mp4(), soup_auth_digest_authenticate(), and
> soup_message_headers_get_content_disposition(). These functions are used
> in many programs that use libsoup3, and the issues occur due to a
> variety of problems including integer overflows, segmentation faults,
> heap buffer over reads, out of bounds reads, NULL pointer dereferences,
> and double frees. Unfortunately there are many more vulnerabilities in
> libsoup3 which have been reported upstream but have not been properly
> fixed at this time, but please keep an eye on the security advisories to
> be informed on when more are fixed. All users who have libsoup3 should
> update to 3.6.5 as soon as possible. Special thanks goes to Joe Locash
> for reporting the initial list and to both Joe and Xi for helping keep
> track of the new issues.
> 
> **libsoup2**: This security update has been rated as Critical. In
> libsoup2, fourteen security vulnerabilities were fixed that could allow
> for remotely exploitable crashes, remote code execution, HTTP Request
> Smuggling, and memory corruption. These are extremely similar to the
> vulnerabilities fixed in libsoup3, but with some that are also specific
> to libsoup2. Because libsoup2 is no longer maintained upstream, and the
> packages which use it are abandoned, it has been removed from the
> development books and will not be available in BLFS 12.4. That has
> included archiving AbiWord and libgdata as they are both abandoned.
> However, we have created a final patch to fix the fourteen security
> vulnerabilities, and the patch can be found at
> https://linuxfromscratch.org/patches/downloads/libsoup/libsoup-2.74.3-security_fixes-1.patch.
> Users who have libsoup2 installed should discontinue use and migrate to
> libsoup3 where possible, but the patch that we have created and tested
> passes the test suite cleanly and does not break libgdata or AbiWord.
> 
> **giflib**: This security update has been rated as High. Several
> security vulnerabilities were discovered in giflib-5.2.2, but only one
> of them has a functional patch. That vulnerability has been assigned
> four different individual CVEs, and it causes a buffer overflow in the
> gif2rgb utility. Upon the issue being reported to us, we adopted a patch
> from OpenMandriva which fixes this particular vulnerability, but please
> stay tuned to the security advisories for future updates which fix other
> issues in giflib that are currently known (and reported to upstream),
> but have not been fixed at this time. Rebuilding giflib with the patch
> now implemented in the development books is recommended.
> 
> **Epiphany**: This security update has been rated as High. In
> Epiphany-48.1, a security vulnerability was fixed that allows websites
> to trigger URL handlers with no user interaction or warning. If the
> handler application that is called is vulnerable to other issues, remote
> code execution would be possible under the user's current context.
> Before 48.1, the browser did not prevent external URL handler
> applications from launching without a user's permission, and also did
> not warn users about the applications opening. As an example, this could
> be chained with the Yelp vulnerability to trigger Yelp into launching a
> malicious Help document from a server. However, two regressions were
> introduced with this update which cause crashes when downloading opened
> files and opening Incognito windows, so we recommend that all users
> update to Epiphany 48.3 instead if they have Epiphany installed.
> 
> **ghostscript**: This security update has been rated as Critical. In
> ghostscript-10.05.0, nine security vulnerabilities were fixed that could
> result in remote code execution or arbitrary file accesses. The
> arbitrary file execution vulnerability occurs due to truncated paths
> with invalid UTF-8 characters, but the remote code execution
> vulnerabilities occur due to buffer overflows in various contexts,
> including processing PDF files, serializing fonts (common when
> printing!), utilizing BJ10V, DOCXWRITE TXTWRITE, and NPDL devices, and
> when converting glyphs to Unicode. All users who have ghostscript
> installed are encouraged to update to ghostscript-10.05.0 or later as
> soon as possible, especially if they use a printer or use ghostscript
> for PDF manipulation.
> 
> **gstreamer**: This security update has been rated as High. In
> gst-plugins-bad-1.26.1, a security vulnerability was fixed that can
> allow for crashes or remote code execution (in the context of a web
> browser) when processing malformed streams in a video file using the
> H.265 codec. The issue is caused by a stack buffer overflow that occurs
> when processing slice headers. The CVE number is still reserved, but
> some basic information can be found upstream at
> https://gstreamer.freedesktop.org/security/sa-2025-0001.html. All users
> who have the gstreamer stack installed should update to update the stack
> to 1.26.1 as soon as possible.
> 
> **LibreOffice**: This security update has been rated as Critical. Note
> that this vulnerability only impacts users who use LibreOffice to open
> or modify PDF documents. In LibreOffice-25.2.2.2, a security
> vulnerability was fixed that allows for PDF signature forgery when using
> the adbe.pkcs7.sha1 SubFilter. The bug causes invalid signatures to be
> accepted as valid, and NVD has rated it as Critical because it meets
> criteria including "Improper Verification of Cryptographic Signature"
> and "PDF Signature Spoofing by Improper Validation". Users who use
> LibreOffice for reading or modifying PDFs should update to
> LibreOffice-25.2.2.2 as soon as possible, especially as this could allow
> for phishing attacks.
> 
> **PostgreSQL**: This security update has been rated as Medium. In
> PostgreSQL-17.5, a security vulnerability was fixed that could allow for
> a database input provider to achieve a temporary denial of service on
> any platform where a 1-byte over-read can trigger process termination.
> The issue occurs when performing GB18030 encoding validation, and it's
> classified as a buffer over-read. Unfortunately it affects libpq as well
> as the database server, so client applications can also crash as well as
> the database server itself. Note that text must fail validation for this
> vulnerability to get exploited. Users who have PostgreSQL installed
> should consider upgrading to PostgreSQL 17.5 depending on the context in
> which they use the database server (or client applications), such as
> when processing untrusted input. If you are just using PostgreSQL as a
> build dependency for something else, there is no need to update. If you
> are on older versions of BLFS that use older versions of PostgreSQL,
> versions 16.9, 15.13, 14.18, and 13.21 have also been made available!
> 
> **intel-microcode**: This security update has been rated as Medium. In
> intel-microcode-20250512, eight processor level security issues were
> addressed. Six of the vulnerabilities allow for information disclosure,
> and two allow for denial of service. These vulnerabilities apply to a
> variety of different processors, including the 8th, 9th, 10th, 11th,
> 12th, 13th, and 14th generation of Intel Core CPUs, the Atom P6000
> family, various Celeron and Pentium CPUs, the Core Ultra family, the
> Intel Xeon Scalable CPU family, the Xeon E processor family, the Xeon 6
> processor family, and the Xeon W processor family. Users with Intel CPUs
> are encouraged to review the security advisory to determine if their CPU
> is affected, and update the microcode if they are. In the future, we may
> add fwupd which may allow users to install BIOS updates to fix these
> issues instead, depending on if their hardware is supported by LVFS.
> 
> **Screen**: This security update has been rated as High. In
> Screen-5.0.1, five security vulnerabilities were fixed that could allow
> for users to reliably escalate privileges to root, for allowing
> attackers to determine if files exist, for TTY hijacking while attaching
> to a multi-user session, for race conditions when sending signals, and
> for PTYs to be created world-writable. A serious buffer overflow bug
> caused by a bad strncpy() was also fixed in this release. The default
> configuration in BLFS is to install Screen as setuid-root, and thus all
> systems with Screen installed are impacted by these vulnerabilities.
> Some of the vulnerabilities date back to around 2005. If you have Screen
> installed please update to Screen-5.0.1 immediately. More details about
> this set of vulnerabilities can be found at
> https://seclists.org/oss-sec/2025/q2/117
> 
> **OpenJDK**: This security update has been rated as High. In
> OpenJDK-24.0.1, three security vulnerabilities were fixed that could
> allow for remote code execution, arbitrary code execution, and
> unauthorized data modification. No user interaction, nor privileges, are
> required to exploit these vulnerabilities. The vulnerabilities are in
> the JSSE, 2D, and Compiler components. The JSSE and 2D vulnerabilities
> impact all versions of Java after JDK 8, while the Compiler
> vulnerability only impacts JDK 21 and higher. All users who have Java
> installed should update to OpenJDK-24.0.1, especially if you are running
> a networked application. If you update to OpenJDK-24.0.1, please update
> to fop-2.11 at the same time and update to Libreoffice-25.2.3.2 to work
> around issues with the removal of the Java Security Manager API.
> 
> **Gimp**: This security update has been rated as High. In Gimp-3.0.4, a
> security vulnerability was fixed that could allow for remote code
> execution when processing a crafted .ICO file. The vulnerability is
> caused by an integer overflow. No CVE has been assigned yet, but there
> is a Zero Day Initiative identifier assigned to the vulnerability. There
> is a proof of concept exploit available that corrupts Gimp's internal
> state. Given that it's a remote code execution vulnerability, we've
> decided to go ahead with filing an advisory for it even though the only
> information available is the bug report and the fix (which has been
> officially released). All users who have Gimp installed that may
> read/modify .ICO files should update to Gimp-3.0.4, but note that you
> must update to babl-0.1.114 and gegl-0.4.62 at the same time. Users who
> are not reading/modifying .ICO files can ignore this security update.
> 
> **Spidermonkey**: This security update has been rated as Critical. If
> there were a higher rating than Critical, I would assign it to this and
> the two updates following this one. At the Vancouver Pwn2Own conference,
> two critical security vulnerabilities were demonstrated where attackers
> were able to read and write out of bounds memory through executing
> malicious JavaScript. This allows for JavaScript manipulation as well as
> remote code execution. All users who have SpiderMonkey installed
> **urgently** need to install Spidermonkey-128.10.1. Do NOT delay with
> this update, please update immediately!
> 
> **Firefox**: This security update has been rated as Critical. In
> Firefox-128.10.1 (and previous versions dating back to 128.9.0 which was
> the last time an advisory was filed), a total of nine security
> vulnerabilities were fixed. These vulnerabilities allow for remote code
> execution, URL bar spoofing, sandbox escapes, and unsafe attribute
> access (leading to out of bounds memory access and memory corruption).
> Most of these vulnerabilities are exploitable via standard web browsing.
> Two of the remote code execution vulnerabilities are known to be
> exploited in the wild. At the Vancouver Pwn2Own conference, two critical
> security vulnerabilities were demonstrated where attackers were able to
> read and write out of bounds memory through executing malicious
> JavaScript. This allows for JavaScript manipulation as well as remote
> code execution. **ALL USERS WHO HAVE FIREFOX INSTALLED MUST UPDATE
> IMMEDIATELY TO PROTECT THEIR SYSTEMS!!**
> 
> **Thunderbird**: This security update has been rated as Critical. Note
> the several additional critical impacts in addition to the remote code
> execution issues shared by Spidermonkey and Firefox. In
> Thunderbird-128.10.2esr (as well as versions dating back to 128.9.1),
> eighteen security vulnerabilities were fixed. These vulnerabilities
> allow for remote code execution, URL bar spoofing, arbitrary code
> execution, exfiltration of credentials to remote attackers via
> compromised emails and attachments, information disclosure of a
> directory listing of the contents of /tmp, UI misrepresentation of
> attachment URLs (leading to possible phishing attacks), remotely
> exploitable crashes, sandbox escapes, unauthorized and unsolicited file
> downloads to arbitrary locations on a user's hard disk, JavaScript
> execution via malicious PDF attachments, and tracking links in
> attachments bypassing remote content blocking. This may be one of the
> most serious and dangerous set of vulnerabilities I have seen in my
> entire 11+ years working on LFS/BLFS. Note that Thunderbird is also
> impacted by the same remote code execution issues fixed in Spidermonkey
> and Firefox. **ALL USERS WHO HAVE THUNDERBIRD INSTALLED MUST UPDATE
> IMMEDIATELY TO PROTECT THEIR SYSTEMS!!**
> 
> 
> This was quite the long set of security updates, and there's a lot to
> unpack here. I know I've said so several times, but I must urge everyone
> to take these updates seriously and update as soon as humanly possible
> to protect your systems (as well as your data and credentials,
> especially in the case of Thunderbird/Firefox/Spidermonkey). In all of
> my years working on the books, this is probably the largest set of
> significant vulnerabilities I have ever seen, in a very large sprawl of
> packages. Please take these issues seriously, and do not delay with
> updating your systems.
> 
> - Douglas Reno
> 
Thanks a lot, Doug, for this tremendous and important piece of work and
the huge amount of spare time this must have cost you!

I'm still reeling a bit from this avalanche of updates and given all the
text one had to digest, one thing came to my mind: that it might be
better to put the most important stuff, the instruction of what to do,
rather at the beginning of a section instead of at the end.  Examples:

**libxslt**: Update to libxslt-1.1.43.  This security update has been
rated as High. ...

**libsoup3*: Update to 3.6.5. This security update has been rated as
Critical. ...

I think this would make it easier to see what needs to be done,
especially when confronted with a mountain of updates like this time.

Having updated _one_ system, I'm wondering whether I will ever recover
from this.  At least I need a break now... ;)

Thank you very much again!  Fine work and great service!

Rainer

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-support
Unsubscribe: See the above information page