Two security vulnberabilities were discovered in librabbitmq, an AMQP client library, which could result in denial of service or potentially the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in version 0.15.0-1+deb13u1.
It was discovered that missing input sanitising in the PNM/PBM parser of the reference code implementation of the JPEG XL format could result in denial of service or potentially the execution of arbitrary code if malformed images are processed. For the stable distribution (trixie), this problem has been fixed in
Multiple security vulnerabilities were discovered in Ironic, the OpenStack component to manage and provision baremetal servers, which could result in information disclosure or denial of service. For the oldstable distribution (bookworm), these problems have been fixed in version 1:21.4.4-0+deb12u1. In addition python-oslo.messaging needed
Tim Shepard discovered a vulnerability in Neutron, the OpenStack virtual network service, which allowed the bypass of port RBAC rules. The oldstable distribution (bookworm) is not affected. For the stable distribution (trixie), this problem has been fixed in version 2:26.0.3-0+deb13u2.
It was discovered that a udev helper provided by libinput, a input device management and event handling library, performed insufficient sanitising of device properties, which can result in local privilege escalation in some setups. For the oldstable distribution (bookworm), this problem has been fixed