Debian 11

Debian 11 — dolphin — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — dolphin — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 July 2026 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2026-41525 Upstream summary: KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's […]

Read more
Debian 11 — node-handlebars — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — node-handlebars — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 1 July 2026 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-19919 CVE-2019-20920 CVE-2021-23369 CVE-2021-23383 CVE-2026-33916 CVE-2026-33937 CVE-2026-33938 CVE-2026-33939  +2 more Upstream summary: Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. […]

Read more
Debian 11 — python-jwcrypto — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — python-jwcrypto — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 July 2026 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-6298 CVE-2023-6681 CVE-2024-28102 CVE-2026-39373 Upstream summary: The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, which […]

Read more
Debian 11 — node-bn.js — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — node-bn.js — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 June 2026 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2026-2739 Upstream summary: This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods […]

Read more
Debian 11 — golang-github-docker-spdystream — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — golang-github-docker-spdystream — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 June 2026 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2026-35469 Upstream summary: spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts […]

Read more
Debian 11 — logback — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — logback — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 June 2026 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-5929 CVE-2021-42550 CVE-2023-6378 CVE-2024-12798 CVE-2024-12801 CVE-2026-1225 Upstream summary: QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components. Table of contents Symptom & Impact […]

Read more
Debian 11 — golang-github-antchfx-xpath — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — golang-github-antchfx-xpath — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 June 2026 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2026-32287 Upstream summary: Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU usage. This can be triggered by top-level […]

Read more
Debian 11 — csync2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — csync2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 June 2026 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-15522 CVE-2019-15523 CVE-2026-41051 Upstream summary: An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neglects to force a failure of a hello command when the […]

Read more
Debian 11 — ruby-addressable — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ruby-addressable — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 June 2026 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-32740 CVE-2026-35611 Upstream summary: Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncontrolled resource consumption vulnerability exists after version […]

Read more
Debian 11 — jq — multiple vulnerabilities (18 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — jq — multiple vulnerabilities (18 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 26 June 2026 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2015-8863 CVE-2016-4074 CVE-2024-23337 CVE-2025-48060 CVE-2025-9403 CVE-2026-32316 CVE-2026-33947 CVE-2026-33948  +10 more Upstream summary: Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a […]

Read more
CHAT