ALT-BU-2025-5734-2
Branch sisyphus update bulletin.
Package containerd updated to version 2.0.5-alt1 for branch sisyphus in task 381966.
Closed vulnerabilities
Modified: 2025-09-19
CVE-2025-47291
containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under the Kubernetes' cgroup hierarchy, therefore some Kubernetes limits are not honored. This may cause a denial of service of the Kubernetes node. This bug has been fixed in containerd 2.0.5+ and 2.1.0+. Users should update to these versions to resolve the issue. As a workaround, disable usernamespaced pods in Kubernetes temporarily.
Modified: 2025-05-28
GHSA-cxfp-7pvr-95ff
containerd CRI plugin: Incorrect cgroup hierarchy assignment for containers running in usernamespaced Kubernetes pods.
Package thunderbird updated to version 137.0.2-alt1 for branch sisyphus in task 381767.
Closed vulnerabilities
Modified: 2025-10-02
BDU:2025-06555
Уязвимость почтового клиента Thunderbird, связанная с переадресацией URL на ненадежный сайт, позволяющая нарушителю перенаправить пользователя на произвольный URL-адрес
Modified: 2025-10-02
BDU:2025-06569
Уязвимость почтового клиента Thunderbird, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю раскрыть защищаемую информацию
Modified: 2025-10-02
BDU:2025-07589
Уязвимость почтового клиента Thunderbird, связанная с ошибками представления информации пользовательским интерфейсом, позволяющая нарушителю проводить спуфинг атаки
Modified: 2026-04-13
CVE-2025-2830
By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.
Modified: 2026-04-13
CVE-2025-3522
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.
Modified: 2026-04-13
CVE-2025-3523
When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.
Closed bugs
Некорректный desktop файл
Package python3-module-django updated to version 5.1.8-alt1 for branch sisyphus in task 381812.
Closed vulnerabilities
BDU:2025-05049
Уязвимость функций LoginView, LogoutView и set_language() программной платформы для веб-приложений Django, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2025-10-03
CVE-2025-27556
An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, and django.views.i18n.set_language are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.
Modified: 2025-04-09
GHSA-wqfg-m96j-85vm
Django Potential Denial of Service (DoS) on Windows
- https://nvd.nist.gov/vuln/detail/CVE-2025-27556
- https://github.com/django/django/commit/2cb311f7b069723027fb5def4044d1816d7d2afd
- https://github.com/django/django/commit/39e2297210d9d2938c75fc911d45f0e863dc4821
- https://github.com/django/django/commit/8c6871b097b6c49d2a782c0d80d908bcbe2116f1
- https://github.com/django/django/commit/edc2716d01a6fdd84b173c02031695231bcee1f8
- https://docs.djangoproject.com/en/dev/releases/security
- https://github.com/django/django
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2025-14.yaml
- https://groups.google.com/g/django-announce
- https://www.djangoproject.com/weblog/2025/apr/02/security-releases
- http://www.openwall.com/lists/oss-security/2025/04/02/2
Closed bugs
Словарь QStardict не озвучивает слова
Неполные зависимости
sh: mbrola: команда не найдена
Closed bugs
phosh: Добавить зависимость на xdg-desktop-portal-phosh
Closed bugs
SysTray-X несовместимо с Thunderbird 137.0.
Closed bugs
Добавить xonsh в /etc/shells
Package baikal-openuds updated to version 0.0.3-alt2.2 for branch sisyphus in task 381983.
Closed bugs
Файловые конфликты с пакетом baikal-openuds и xfreerdp3
