Aggregator

gnatcoll-25.0.0-6.fc43

1 week ago
FEDORA-2026-d5c7f91202 Packages in this update:
  • gnatcoll-25.0.0-6.fc43
Update description:

Patched the vulnerabilities GNATCOLL-CORE-0162 and GNATCOLL-CORE-0164 in a way that avoids interface changes.

curl-8.15.0-10.fc43

1 week ago
FEDORA-2026-6841033933 Packages in this update:
  • curl-8.15.0-10.fc43
Update description:
  • fix HTTP/2 stream-dependency tree UAF (CVE-2026-10536)
  • fix stale proxy password leak (CVE-2026-9079)
  • fix wrong reuse for different services (CVE-2026-8458)

curl-8.18.0-10.fc44

1 week 1 day ago
FEDORA-2026-f26b509a1a Packages in this update:
  • curl-8.18.0-10.fc44
Update description:
  • Fix HTTP/2 stream-dependency tree UAF (CVE-2026-10536)
  • Fix Native CA trust persist (CVE-2026-11564)
  • Fix stale proxy password leak (CVE-2026-9079)
  • Fix wrong reuse for different services (CVE-2026-8458)

USN-8739-1: ImageMagick vulnerabilities

1 week 1 day ago
It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56366, CVE-2026-56368, CVE-2026-56371, CVE-2026-56373) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-56370) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56378) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56379) It was discovered that ImageMagick incorrectly handled memory allocation in certain operations. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-61465) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 22.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-61857) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61870) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-61866) It was discovered that ImageMagick incorrectly handled certain images on 32-bit systems. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-62946)

USN-8670-3: curl vulnerability

1 week 1 day ago
USN-8670-1 fixed a vulnerability in curl. This update provides the corresponding update for Ubuntu 26.04 LTS. Original advisory details: Joshua Rogers discovered that curl incorrectly handled reusing connections when client certificate settings changed. This could result in the wrong client certificates being used, contrary to expectations.

USN-8679-2: Vim vulnerability

1 week 1 day ago
USN-8679-1 fixed a vulnerability in Vim. This update provides the corresponding update for Ubuntu 26.04 LTS. Original advisory details: It was discovered that Vim incorrectly handled certain tags files. An attacker could possibly use this issue to execute arbitrary code.