Aggregator

USN-8160-1: MongoDB vulnerability

1 week ago
It was discovered that MongoDB incorrectly handled length parameters in zlib-compressed network messages prior to authentication. An unauthenticated remote attacker could possibly use this issue to cause MongoDB to allocate an oversized memory buffer, resulting in the exposure of sensitive information.

usd-25.08-20.fc43

1 week ago
FEDORA-2026-cde75a1416 Packages in this update:
  • usd-25.08-20.fc43
Update description:

Backport several OpenEXRCore security fixes

  • Fixes CVE-2026-34378 / GHSA-v76p-4qvv-vh4g; closes RHBZ#2455493
  • Fixes CVE-2026-34380 / GHSA-q3v8-hw4m-59w5; closes RHBZ#2455534
  • Fixes CVE-2026-34588 / GHSA-588r-cr5c-w6hf; closes RHBZ#2455505
  • Fixes CVE-2026-34589 / GHSA-p8xc-w3q4-h64x; closes RHBZ#2455501
  • Fixes CVE-2026-34379 / GHSA-w88v-vqhq-5p24; closes RHBZ#2455497

USN-8149-2: Linux kernel vulnerabilities

1 week ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Netfilter; - Network traffic control; (CVE-2026-23060, CVE-2026-23074, CVE-2026-23111)

USN-8148-5: Linux kernel vulnerabilities

1 week ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Netfilter; - Network traffic control; (CVE-2026-23060, CVE-2026-23074, CVE-2026-23111)

USN-8159-3: Linux kernel (Real-time) vulnerabilities

1 week ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Cryptographic API; - Netfilter; - Network traffic control; (CVE-2025-37849, CVE-2026-23060, CVE-2026-23074, CVE-2026-23111)

USN-8159-2: Linux kernel (FIPS) vulnerabilities

1 week ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Cryptographic API; - Netfilter; - Network traffic control; (CVE-2025-37849, CVE-2026-23060, CVE-2026-23074, CVE-2026-23111)

USN-8159-1: Linux kernel vulnerabilities

1 week ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Cryptographic API; - Netfilter; - Network traffic control; (CVE-2025-37849, CVE-2026-23060, CVE-2026-23074, CVE-2026-23111)

ImageMagick-7.1.2.13-2.fc44 LibRaw-0.22.1-1.fc44 OpenImageIO-3.1.12.0-2.fc44 OpenImageIO2.5-2.5.19.1-10.fc44 deepin-image-viewer-5.8.2-21.fc44 dtk6gui-6.7.32-5.fc44 dtkgui-5.7.30-4.fc44 efl-1.28.1-6.fc44 elementary-photos-8.0.1-6.fc44 entangle-3.0-17…

1 week ago
FEDORA-2026-bef0050737 Packages in this update:
  • deepin-image-viewer-5.8.2-21.fc44
  • dtk6gui-6.7.32-5.fc44
  • dtkgui-5.7.30-4.fc44
  • efl-1.28.1-6.fc44
  • elementary-photos-8.0.1-6.fc44
  • entangle-3.0-17.fc44
  • freeimage-3.19.0-0.31.svn1909.fc44
  • geeqie-2.7-2.fc44
  • gegl04-0.4.70-2.fc44
  • gthumb-3.12.10-7.fc44
  • ImageMagick-7.1.2.13-2.fc44
  • kf5-kimageformats-5.116.0-8.fc44
  • kf5-libkdcraw-23.08.5-7.fc44
  • kf6-kimageformats-6.24.0-3.fc44
  • kstars-3.8.0-6.fc44
  • libkdcraw-26.03.80-2.fc44
  • libpasraw-1.3.0-22.fc44
  • LibRaw-0.22.1-1.fc44
  • luminance-hdr-2.6.1.1-89.fc44
  • nomacs-3.22.0-5.fc44
  • OpenImageIO2.5-2.5.19.1-10.fc44
  • OpenImageIO-3.1.12.0-2.fc44
  • photoqt-5.2-3.fc44
  • rawtherapee-5.12-8.fc44
  • shotwell-33~alpha-9.fc44
  • siril-1.4.2-3.fc44
  • swayimg-5.1-2.fc44
  • vips-8.18.0-6.fc44
Update description:

LibRaw 0.22.1 and rebuilds

Release 3.1.12.0 (Apr 1, 2026) -- compared to 3.1.11.0

oiiotool: Better type understanding with -i:ch= and other cleanup #5056 texture: Fix texture overblur with st-blur parameters #5071 #5080 (by Pascal Lecocq) (3.1.12.0, 3.0.17.0) IBA: Handle offset data windows in fillholes_pushpull #5105 (3.1.12.0, 3.0.17.0) ImageInput: check_open fixes and new validity checks #5087 (3.1.12.0, 3.0.17.0) bmp: Use check_open to guard against corrupt resolutions #5086 (3.1.12.0, 3.0.17.0) heif: Fix invalid read writing 8-bit images with dimensions not a multiple of 64 #5095 (by Brecht Van Lommel) ico: Various validity checks and error handling for corruptions #5088 (3.1.12.0, 3.0.17.0) jpeg: Improved safety and error reporting for jpeg and iptc #5081 jpeg2000: Suppress leak when reading with OpenJPH #5098 psd: Fixes against corrupt files with better validation #5089 (3.1.12.0, 3.0.17.0) rla: Lots of additional validity checking and safety #5094 (3.1.12.0, 3.0.17.0) tiff: Support GPS fields, and other metadata enhancements #5050 tiff: Fix buffer overrun and improve error reporting #5082, fix wrong number of values passed to invert_photometric #5083, check for invalid bit depth in palette images #5091 ImageSpec: metadata_val improved safety #5096 (3.1.12.0, 3.0.17.0) fix: Fix UB-sanitizer warning about alignment #5097 fix: Catch exceptions in print-uncaught-messages destructor #5103 fix: Enhanced exception safety for our use of OpenColorIO #5114 fix: Fix possible fmt exceptions where we might have passed null string #5115 build: Test building with clang 22.1, fix warnings uncovered #5067 build: Improve security by pinning auto-build dependencies by hash #5076 build: Include idiff in the python wheels we build #5104 (3.1.12.0, 3.0.17.0) build(pybind11): Address new pybind11 float/int auto-conversion behavior #5058 build(win): Embed manifest in OIIO executables to enable long path handling #5066 (by Nathan Rusch) ci: Add CI test for MSVS 2026 #5060 (3.1.12.0, 3.0.17.0) ci: For security, replace workflow substitutions with safer env substitutions #5070 ci: Speed up slow benchmarks for debug and sanitizer CI tests #5077 ci: On Mac Intel CI variant, don't install openvdb, for speed #5065 (3.1.12.0, 3.0.17.0) ci: Bump GitHub Actions to latest versions #5078 #5110 #5119 ci: Fix broken Mac CI and wheel building by specifying full compiler paths #5100 #5101 (3.1.12.0, 3.0.17.0) ci: Update certificates to be able to install icc #5122 (3.1.12.0, 3.0.17.0) ci: Turn off nightly workflows for user forks #5042 tests: New ref outputs for tiff-misc, heif no-avif, and ffmpeg 8.1 cases #5075 #5079 #5099 #5112 docs: Update description for dwaCompressionLevel #5074 (by Aamir Raza) docs: Fix formatting examples for version macros #5073 docs: Keep TextureSystem docs in sync with ImageCache #5085 (3.1.12.0, 3.0.17.0) docs: Fix typos and incorrect attribute name in a comment #5093 (3.1.12.0, 3.0.17.0) docs: Fix misstatement about oiiotool --if #5102 (3.1.12.0, 3.0.17.0) admin: Draft policy on use of AI coding assistants #5072 (3.1.12.0, 3.0.17.0) ci: Freetype adjustments #4999

tinyproxy-1.11.3-2.fc45

1 week 1 day ago
FEDORA-2026-1c7a717dbc Packages in this update:
  • tinyproxy-1.11.3-2.fc45
Update description:

Automatic update for tinyproxy-1.11.3-2.fc45.

Changelog * Wed Apr 8 2026 Carl George <carlwgeorge@fedoraproject.org> - 1.11.3-2 - Backport upstream CVE fixes - Fixes rhbz#2452969 CVE-2026-3945 - Fixes rhbz#2455913 CVE-2026-31842 - Run upstream test suite