Aggregator

perl-YAML-Syck-1.37-1.el9

6 days 18 hours ago
FEDORA-EPEL-2026-52be5354a0 Packages in this update:
  • perl-YAML-Syck-1.37-1.el9
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

perl-YAML-Syck-1.37-1.el10_2

6 days 18 hours ago
FEDORA-EPEL-2026-de60bba45b Packages in this update:
  • perl-YAML-Syck-1.37-1.el10_2
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

perl-YAML-Syck-1.37-1.el10_3

6 days 18 hours ago
FEDORA-EPEL-2026-e7f8f46758 Packages in this update:
  • perl-YAML-Syck-1.37-1.el10_3
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

perl-YAML-Syck-1.37-1.fc43

6 days 18 hours ago
FEDORA-2026-3572f7e01c Packages in this update:
  • perl-YAML-Syck-1.37-1.fc43
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

perl-YAML-Syck-1.37-1.fc44

6 days 18 hours ago
FEDORA-2026-a8d89d8ae2 Packages in this update:
  • perl-YAML-Syck-1.37-1.fc44
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

perl-YAML-Syck-1.37-1.fc42

6 days 18 hours ago
FEDORA-2026-d226775800 Packages in this update:
  • perl-YAML-Syck-1.37-1.fc42
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

USN-8105-2: FreeRDP regression

6 days 19 hours ago
USN-8105-1 fixed vulnerabilities in FreeRDP. The update introduced a regression which could cause FreeRDP to crash. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that FreeRDP incorrectly handled certain RDP packets. A remote attacker could use this issue to cause FreeRDP to crash, resulting in a denial of service, or possibly execute arbitrary code.

USN-8111-1: OpenStack Glance vulnerability

6 days 21 hours ago
It was discovered that OpenStack Glance was incorrectly validating the IP addresses and the redirect destination URL when downloading or importing images from a remote source. An attacker could possibly use this issue to perform server-side request forgery and obtain sensitive information.

libsoup3-3.6.6-2.fc43

6 days 21 hours ago
FEDORA-2026-f029d04054 Packages in this update:
  • libsoup3-3.6.6-2.fc43
Update description:

Add patch for CVE-2026-1539 (Also remove Proxy-Authorization header on cross origin redirect)

libsoup3-3.6.6-6.fc44

6 days 21 hours ago
FEDORA-2026-55dabf3975 Packages in this update:
  • libsoup3-3.6.6-6.fc44
Update description:

Add patch for CVE-2026-1539 (Also remove Proxy-Authorization header on cross origin redirect)

libsoup3-3.6.6-6.fc45

6 days 21 hours ago
FEDORA-2026-6fb683df94 Packages in this update:
  • libsoup3-3.6.6-6.fc45
Update description:

Automatic update for libsoup3-3.6.6-6.fc45.

Changelog * Thu Mar 19 2026 Milan Crha <mcrha@redhat.com> - 3.6.6-6 - Add patch for CVE-2026-1539 (Also remove Proxy-Authorization header on cross origin redirect) - Resolves: rhbz#2433867

rubygem-json-2.19.2-1.fc44

6 days 22 hours ago
FEDORA-2026-3a7663d43d Packages in this update:
  • rubygem-json-2.19.2-1.fc44
Update description:

New version 2.19.2 is released. This fixes a format string injection vulnerability in JSON.parse, which is now assigned as CVE-2026-33210