Gnoppix Security Announcement - 2026-09-01T20:00:31.206-04:00

## GSA-6480-1: keystone Security Update Released

Gnoppix Security announces a security update for keystone, addressing multiple vulnerabilities. The update is available for Gnoppix 24/25 (oldstable) and Gnoppix 26 (stable). This release fixes several issues that could allow denial of service or information disclosure.

### Affected Versions and Mitigation

The security update covers keystone packages in both Gnoppix 24/25 and Gnoppix 26. Users should upgrade keystone to version 21.0.1-2+deb12u1 for Gnoppix 24/25 and version 21.0.1-2+deb13u1 for Gnoppix 26.

### Security Implications

These vulnerabilities could allow remote attackers to cause a denial of service via crafted requests. Other issues involve cross-site scripting (XSS) and server-side request forgery (SSRF) risks. System administrators are strongly advised to apply the update immediately.

> **Key Action Required:** Update keystone to the patched versions listed above to protect against active exploitation.

No workarounds are currently available. For more details, refer to the official advisory and the package changelogs.
``` - Please update your systems.