Aggregator

firefox-153.0-3.fc43

1 week 1 day ago
FEDORA-2026-6dab7a3eff Packages in this update:
  • firefox-153.0-3.fc43
Update description:
  • Update to latest upstream (153.0)
  • New upstream release (153.0)
  • Updated to latest upstream (153.0)

USN-8369-2: mod_jk regression

1 week 1 day ago
USN-8369-1 fixed a vulnerability in mod_jk. It was discovered that for Ubuntu 18.04 LTS, during the update preparation phase, a previous fix for CVE-2023-41081 was incorrectly dropped. This update reintroduces the fix for CVE-2023-41081. We apologize for the inconvenience. Original advisory details: It was discovered that Apache Tomcat Connectors used incorrect default permissions for shared memory on Unix-like systems. A local attacker could possibly use this issue to view or modify mod_jk configuration data in shared memory, resulting in sensitive information exposure or a denial of service.

pack-0.40.8-1.el9

1 week 1 day ago
FEDORA-EPEL-2026-75bd5ec746 Packages in this update:
  • pack-0.40.8-1.el9
Update description:

Security update to pack 0.40.8

Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution via discarded SSH permissions Fixes GO-2026-4970: Root escape via symlink plus trailing slash in os package Fixes GO-2026-5856: Encrypted Client Hello privacy leak in crypto/tls

pack-0.40.8-1.el10_2

1 week 1 day ago
FEDORA-EPEL-2026-394b18b263 Packages in this update:
  • pack-0.40.8-1.el10_2
Update description:

Security update to pack 0.40.8

Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution via discarded SSH permissions Fixes GO-2026-4970: Root escape via symlink plus trailing slash in os package Fixes GO-2026-5856: Encrypted Client Hello privacy leak in crypto/tls

pack-0.40.8-1.fc43

1 week 1 day ago
FEDORA-2026-e6e0368149 Packages in this update:
  • pack-0.40.8-1.fc43
Update description:

Security update to pack 0.40.8

Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution via discarded SSH permissions Fixes GO-2026-4970: Root escape via symlink plus trailing slash in os package Fixes GO-2026-5856: Encrypted Client Hello privacy leak in crypto/tls

pack-0.40.8-1.fc44

1 week 1 day ago
FEDORA-2026-8729dce4b8 Packages in this update:
  • pack-0.40.8-1.fc44
Update description:

Security update to pack 0.40.8

Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution via discarded SSH permissions Fixes GO-2026-4970: Root escape via symlink plus trailing slash in os package Fixes GO-2026-5856: Encrypted Client Hello privacy leak in crypto/tls

skopeo-1.22.2-2.fc44

1 week 1 day ago
FEDORA-2026-9b2e56edf5 Packages in this update:
  • skopeo-1.22.2-2.fc44
Update description:

Security fix for CVE-2026-27145 (Go stdlib crypto/x509 DoS vulnerability). Rebuild with golang-1.26.5 which includes the fix.

skopeo-1.22.2-2.fc43

1 week 1 day ago
FEDORA-2026-4d9a2870e5 Packages in this update:
  • skopeo-1.22.2-2.fc43
Update description:

Security fix for CVE-2026-27145 (Go stdlib crypto/x509 DoS vulnerability). Rebuild with golang-1.25.12 which includes the fix.

kernel-7.1.4-204.fc44

1 week 1 day ago
FEDORA-2026-2b94d8d05c Packages in this update:
  • kernel-7.1.4-204.fc44
Update description:

The 7.1.4-104/204 stable kennel updates contain a couple of security fixes for issues with exploits in the wild.

kernel-7.1.4-104.fc43

1 week 1 day ago
FEDORA-2026-6503a6a639 Packages in this update:
  • kernel-7.1.4-104.fc43
Update description:

The 7.1.4-104/204 stable kennel updates contain a couple of security fixes for issues with exploits in the wild.

USN-8591-1: AIOHTTP vulnerabilities

1 week 1 day ago
Sean Gilligan discovered that AIOHTTP did not properly limit memory usage when processing HTTP headers and trailers. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-22815) It was discovered that AIOHTTP did not properly limit the size of its DNS cache. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-34513) Mingi Jung discovered that AIOHTTP did not properly sanitize the content_type parameter. An attacker could possibly use this issue to inject malicious HTTP headers, resulting in HTTP response splitting. (CVE-2026-34514) It was discovered that AIOHTTP did not properly limit memory usage when processing multipart headers. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-34516)

USN-8590-1: Exim vulnerabilities

1 week 1 day ago
It was discovered that Exim incorrectly handled certain command line options. A local attacker could possibly use this issue to access files outside of the spool area. It was discovered that Exim incorrectly handled string expansion in .local files. A local attacker could possibly use this issue to escalate privileges.