The release of the Deepin 25.1 distribution, which develops its own graphical environment.

Several dangerous vulnerabilities have been identified in recent days, most of which can be exploited remotely:

  • The corrective release of the multimedia framework GStreamer 1.28.2 has revealed 11 vulnerabilities, three of which are caused by buffer overflows and could potentially lead to code execution when processing specially crafted multimedia container files MKV (CVE not assigned) and MOV/MP4 (CVE-2026-5056), as well as streams in H.266/VVC format (CVE not assigned). The remaining eight vulnerabilities are caused by integer overflows or null pointer dereferences, which may lead to denial of service or information leakage when processing data in formats such as WAV, JPEG2000, AV1, H.264, MOV, MP4, FLV, mDVDsub, and SRT/WebVTT. The danger of vulnerabilities in GStreamer is exacerbated by its use in GNOME for parsing metadata during the automatic indexing of new files, meaning an attacker only needs to get a file loaded into the indexable directory ~/Downloads.
  • In server CUPS printing has revealed eight vulnerabilities, two of which (CVE-2026-34980, CVE-2026-34990) can be exploited for remote code execution with root privileges by sending a specially crafted request to the print server. The first vulnerability allows an unauthenticated attacker to execute their code with lp user privileges by sending a specifically crafted print job (the issue arises from improper handling of escaped newline characters). The second vulnerability allows privilege escalation from lp user to root by altering files with root privileges via a dummy printer substitution. An update for CUPS addressing these vulnerabilities is not yet available.
  • A corrective release of the cryptographic library wolfSSL 5.9.1 has been published, addressing 21 vulnerabilities. One issue has been assigned a critical severity level, while nine are rated high (leading to memory corruption). The critical vulnerability (CVE-2026-5194) is caused by the lack of validation for hash size and OID identifier, allowing specification of hashes smaller than permissible, which reduces the resilience of digital signature generation algorithms such as ECDSA/ECC, DSA, ML-DSA, ED25519, and ED448, and bypasses certificate-based authentication. This vulnerability was discovered by engineers at Anthropic during AI model code review.
  • Correction releases for the cryptographic library OpenSSL 3.6.2, 3.5.6, 3.4.5, and 3.3.7 have been published, addressing 7 vulnerabilities. The most critical vulnerability (CVE-2026-31790) could lead to the leakage of sensitive data remaining in the buffer after the previous operation. This issue is caused by the use of uninitialized memory when encapsulating RSA KEM RSASVE keys.

    Another vulnerability (CVE-2026-31789) is caused by a buffer overflow and could potentially lead to code execution when converting strings to hexadecimal format while processing specially crafted X.509 certificates. This issue has been rated as non-critical since it only occurs on 32-bit platforms. Other vulnerabilities are caused by reading data from areas outside the buffer, accessing already freed memory, and dereferencing a null pointer.

  • In the AI agent OpenClaw 2026.3.11, which allows AI models to interact with system environments (e.g., running utilities and working with files), a critical vulnerability (CVE-2026-32922) with a severity level of 10 out of 10 has been fixed. The vulnerability arose because the '/pair approve' command did not properly verify permissions, allowing any user with pairing privileges to the host (the lowest privilege level necessary for accessing OpenClaw) to grant admin rights to themselves and gain full control of the environment. To exploit this vulnerability, one simply needs to connect to OpenClaw, request the registration of a fake device with operator.admin access, then approve their own request using the command '/pair approve' and gain complete control over the targeted OpenClaw instance and all associated services.

    Just a few days earlier, a similar vulnerability (CVE-2026-33579) was discovered in OpenClaw that allowed bypassing access rights verification and obtaining admin rights. Researchers who identified the issue provided statistics indicating that 135,000 publicly accessible OpenClaw instances were found on the internet, of which 63% allowed connection without authentication.

  • A vulnerability (CVE-2026-39860) has been discovered in the Nix package manager used in the NixOS distribution, rated as critical (9 out of 10). This vulnerability allows for the overwriting of any file in the system, limited by the access rights of the Nix background process, which in NixOS and multi-user installations runs with root privileges. The issue stems from the improper mitigation of vulnerability CVE-2024-27297 in 2024. Exploitation occurs via the replacement of a symbolic link to a directory within an isolated build environment where the build results were written. The vulnerability has been fixed in updates nix 2.34.5, 2.33.4, 2.32.7, 2.31.4, 2.30.4, 2.29.3, and 2.28.6.
  • Five vulnerabilities have been patched in the Linux kernel, identified during experiments with the Claude Code toolchain, affecting subsystems nfsd, io_uring, futex, and ksmbd (1, 2). A vulnerability in the NFS driver allows for the exposure of kernel memory regions through requests sent to the NFS server. The problem originates from an error present since kernel 2.6.0 (2003).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster