6 days 21 hours ago
It was discovered that libssh had a stack buffer overflow in its SFTP
server when constructing directory listing entries for long filenames. An
attacker could possibly use this issue to cause libssh to crash or execute
arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15370)
It was discovered that libssh did not correctly handle SSH channel open
messages advertising a zero maximum packet size. An authenticated remote
attacker could possibly use this issue to cause libssh to consume excessive
CPU resources, leading to a denial of service. (CVE-2026-59843)
It was discovered that libssh did not correctly limit SFTP read request
lengths in its server implementation. An authenticated remote attacker
could possibly use this issue to cause libssh to allocate excessive memory,
leading to a denial of service. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-59844)
It was discovered that libssh did not correctly handle ProxyCommand fork()
failures. A local attacker could possibly use this issue to cause a denial
of service. (CVE-2026-59845)
It was discovered that libssh did not correctly sanitize shell
metacharacters when expanding usernames in ProxyCommand strings. An
attacker could possibly use this issue to obtain sensitive information.
(CVE-2026-59846)
It was discovered that libssh had incorrect AES-GCM tag verification when
built with the OpenSSL backend. A machine-in-the-middle attacker could
possibly use this issue to modify encrypted traffic without detection.
(CVE-2026-59847)
It was discovered that libssh did not correctly handle SFTP server
responses for unknown request IDs. An attacker could possibly use this
issue to cause libssh to use excessive memory, leading to a denial of
service. (CVE-2026-59848)
It was discovered that libssh had logic errors in certificate-based
authentication that could cause clients to loop indefinitely when
certificates were rejected. An attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-59849)
It was discovered that libssh could invoke data callbacks on channels after
they had been closed. An attacker could possibly use this issue to cause
libssh to crash or execute arbitrary code. (CVE-2026-59850)
6 days 21 hours ago
It was discovered that FreeRDP contained multiple security issues. An
attacker could possibly use these issues to obtain sensitive information,
cause FreeRDP to crash, resulting in a denial of service, or execute
arbitrary code.
6 days 21 hours ago
It was discovered that GNU Core Utilities sort had a heap buffer under-read
in its begfield() function. A local attacker could possibly use this issue
to cause GNU Core Utilities to crash, resulting in a denial of service, or
obtain sensitive information. (CVE-2025-5278)
It was discovered that GNU Core Utilities uniq had an out-of-bounds read
when the -w option was used with crafted multibyte input. A local attacker
could possibly use this issue to cause GNU Core Utilities to crash,
resulting in a denial of service, or obtain sensitive information. This
issue only affected Ubuntu 26.04 LTS. (CVE-2026-56391)
6 days 21 hours ago
It was discovered that Bind incorrectly handled DNSSEC validation when a
domain was covered by both NSEC and NSEC3 records with only one type having
an RRSIG. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service.
1 week ago
FEDORA-2026-a0cb1e1e61
Packages in this update:
Update description:
Exiv2 0.28.9 bugfix release.
1 week ago
FEDORA-2026-2854e48ee4
Packages in this update:
Update description:
Exiv2 0.28.9 bugfix release.
1 week ago
It was discovered that the JSSE component of OpenJDK 26 did not correctly
authenticate users. A remote attacker could possibly use this issue to read
or modify sensitive data. (CVE-2026-46968)
It was discovered that the JSSE component of OpenJDK 26 did not correctly
authorize users. A remote attacker could possibly use this issue to cause a
denial of service. (CVE-2026-46917)
It was discovered that the ImageIO component of OpenJDK 26 did not
correctly authorize users. A remote attacker could possibly use this issue
to read or modify sensitive data. (CVE-2026-47010)
It was discovered that the 2D component of OpenJDK 26 did not correctly
authorize users. A remote attacker could possibly use this issue to cause a
denial of service. (CVE-2026-47021, CVE-2026-47059)
It was discovered that the Libraries component of OpenJDK 26 did not
correctly authorize users. A remote attacker could possibly use this issue
to cause a denial of service. (CVE-2026-47027)
It was discovered that the Security component of OpenJDK 26 did not
correctly authenticate users. A remote attacker could possibly use this
issue to read or modify sensitive data. (CVE-2026-60147)
It was discovered that the Libraries component of OpenJDK 26 did not
correctly authenticate users. A remote attacker could possibly use this
issue to read or modify sensitive data. (CVE-2026-47063)
Lian Owen discovered that the 2D (Little CMS) component of OpenJDK 26 did
not correctly handle certain integer arithmetic. An attacker could possibly
use this issue to cause a denial of service. (CVE-2026-41254)
1 week ago
FEDORA-EPEL-2026-baa01fe3db
Packages in this update:
- baresip-4.11.0-1.el8
- libre-4.11.0-1.el8
Update description:
Baresip v4.11.0 (2026-08-25)
- core: cleanup stream_rtp_h ignore handling
- audio: increase RTP timestamp also for underruns
- aubuf: remove adaptive mode
- webrtc_aec: fix system cmake include
- call: avoid call progress if media is inactive
- conf: remove unused conf_aubuf_adaptive()
- audio: reuse mbuf for telephony events
- call: add callback for incoming SIP INFO
- test: check fixture error and fix call progress
- aureceiver: fix return on error case in aurecv_start_player()
- audio: fix warning() %d format in encode_rtp_send()
- opus,aureceiver: fix PLC/FEC handling
- l16: refactor NR_CODECS by RE_ARRAY_SIZE
- config: remove unused config option audio_silence
- echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)
1 week ago
FEDORA-EPEL-2026-fe7f0afd86
Packages in this update:
- baresip-4.11.0-1.el9
- libre-4.11.0-1.el9
Update description:
Baresip v4.11.0 (2026-08-25)
- core: cleanup stream_rtp_h ignore handling
- audio: increase RTP timestamp also for underruns
- aubuf: remove adaptive mode
- webrtc_aec: fix system cmake include
- call: avoid call progress if media is inactive
- conf: remove unused conf_aubuf_adaptive()
- audio: reuse mbuf for telephony events
- call: add callback for incoming SIP INFO
- test: check fixture error and fix call progress
- aureceiver: fix return on error case in aurecv_start_player()
- audio: fix warning() %d format in encode_rtp_send()
- opus,aureceiver: fix PLC/FEC handling
- l16: refactor NR_CODECS by RE_ARRAY_SIZE
- config: remove unused config option audio_silence
- echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)
1 week ago
FEDORA-EPEL-2026-cd90eb246c
Packages in this update:
- baresip-4.11.0-1.el10_2
- libre-4.11.0-1.el10_2
Update description:
Baresip v4.11.0 (2026-08-25)
- core: cleanup stream_rtp_h ignore handling
- audio: increase RTP timestamp also for underruns
- aubuf: remove adaptive mode
- webrtc_aec: fix system cmake include
- call: avoid call progress if media is inactive
- conf: remove unused conf_aubuf_adaptive()
- audio: reuse mbuf for telephony events
- call: add callback for incoming SIP INFO
- test: check fixture error and fix call progress
- aureceiver: fix return on error case in aurecv_start_player()
- audio: fix warning() %d format in encode_rtp_send()
- opus,aureceiver: fix PLC/FEC handling
- l16: refactor NR_CODECS by RE_ARRAY_SIZE
- config: remove unused config option audio_silence
- echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)
1 week ago
FEDORA-EPEL-2026-b83833c59a
Packages in this update:
- baresip-4.11.0-1.el10_3
- libre-4.11.0-1.el10_3
Update description:
Baresip v4.11.0 (2026-08-25)
- core: cleanup stream_rtp_h ignore handling
- audio: increase RTP timestamp also for underruns
- aubuf: remove adaptive mode
- webrtc_aec: fix system cmake include
- call: avoid call progress if media is inactive
- conf: remove unused conf_aubuf_adaptive()
- audio: reuse mbuf for telephony events
- call: add callback for incoming SIP INFO
- test: check fixture error and fix call progress
- aureceiver: fix return on error case in aurecv_start_player()
- audio: fix warning() %d format in encode_rtp_send()
- opus,aureceiver: fix PLC/FEC handling
- l16: refactor NR_CODECS by RE_ARRAY_SIZE
- config: remove unused config option audio_silence
- echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)
1 week ago
FEDORA-EPEL-2026-8250797b7b
Packages in this update:
- baresip-4.11.0-1.el10_4
- libre-4.11.0-1.el10_4
Update description:
Baresip v4.11.0 (2026-08-25)
- core: cleanup stream_rtp_h ignore handling
- audio: increase RTP timestamp also for underruns
- aubuf: remove adaptive mode
- webrtc_aec: fix system cmake include
- call: avoid call progress if media is inactive
- conf: remove unused conf_aubuf_adaptive()
- audio: reuse mbuf for telephony events
- call: add callback for incoming SIP INFO
- test: check fixture error and fix call progress
- aureceiver: fix return on error case in aurecv_start_player()
- audio: fix warning() %d format in encode_rtp_send()
- opus,aureceiver: fix PLC/FEC handling
- l16: refactor NR_CODECS by RE_ARRAY_SIZE
- config: remove unused config option audio_silence
- echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)
1 week ago
FEDORA-2026-3edf59885d
Packages in this update:
- baresip-4.11.0-1.fc43
- libre-4.11.0-1.fc43
Update description:
Baresip v4.11.0 (2026-08-25)
- core: cleanup stream_rtp_h ignore handling
- audio: increase RTP timestamp also for underruns
- aubuf: remove adaptive mode
- webrtc_aec: fix system cmake include
- call: avoid call progress if media is inactive
- conf: remove unused conf_aubuf_adaptive()
- audio: reuse mbuf for telephony events
- call: add callback for incoming SIP INFO
- test: check fixture error and fix call progress
- aureceiver: fix return on error case in aurecv_start_player()
- audio: fix warning() %d format in encode_rtp_send()
- opus,aureceiver: fix PLC/FEC handling
- l16: refactor NR_CODECS by RE_ARRAY_SIZE
- config: remove unused config option audio_silence
- echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)
1 week ago
FEDORA-2026-27c291e67c
Packages in this update:
- baresip-4.11.0-1.fc44
- libre-4.11.0-1.fc44
Update description:
Baresip v4.11.0 (2026-08-25)
- core: cleanup stream_rtp_h ignore handling
- audio: increase RTP timestamp also for underruns
- aubuf: remove adaptive mode
- webrtc_aec: fix system cmake include
- call: avoid call progress if media is inactive
- conf: remove unused conf_aubuf_adaptive()
- audio: reuse mbuf for telephony events
- call: add callback for incoming SIP INFO
- test: check fixture error and fix call progress
- aureceiver: fix return on error case in aurecv_start_player()
- audio: fix warning() %d format in encode_rtp_send()
- opus,aureceiver: fix PLC/FEC handling
- l16: refactor NR_CODECS by RE_ARRAY_SIZE
- config: remove unused config option audio_silence
- echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)
1 week ago
FEDORA-2026-c70f6e6ebc
Packages in this update:
- baresip-4.11.0-1.fc45
- libre-4.11.0-1.fc45
Update description:
Baresip v4.11.0 (2026-08-25)
- core: cleanup stream_rtp_h ignore handling
- audio: increase RTP timestamp also for underruns
- aubuf: remove adaptive mode
- webrtc_aec: fix system cmake include
- call: avoid call progress if media is inactive
- conf: remove unused conf_aubuf_adaptive()
- audio: reuse mbuf for telephony events
- call: add callback for incoming SIP INFO
- test: check fixture error and fix call progress
- aureceiver: fix return on error case in aurecv_start_player()
- audio: fix warning() %d format in encode_rtp_send()
- opus,aureceiver: fix PLC/FEC handling
- l16: refactor NR_CODECS by RE_ARRAY_SIZE
- config: remove unused config option audio_silence
- echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)
1 week ago
FEDORA-2026-3a803930eb
Packages in this update:
- baresip-4.11.0-1.fc46
- libre-4.11.0-1.fc46
Update description:
Baresip v4.11.0 (2026-08-25)
- core: cleanup stream_rtp_h ignore handling
- audio: increase RTP timestamp also for underruns
- aubuf: remove adaptive mode
- webrtc_aec: fix system cmake include
- call: avoid call progress if media is inactive
- conf: remove unused conf_aubuf_adaptive()
- audio: reuse mbuf for telephony events
- call: add callback for incoming SIP INFO
- test: check fixture error and fix call progress
- aureceiver: fix return on error case in aurecv_start_player()
- audio: fix warning() %d format in encode_rtp_send()
- opus,aureceiver: fix PLC/FEC handling
- l16: refactor NR_CODECS by RE_ARRAY_SIZE
- config: remove unused config option audio_silence
- echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)
1 week ago
1 week ago
FEDORA-2026-a05d65f5fa
Packages in this update:
Update description:
This update fixes an overflow in parsing RGBE/HDR image files.
1 week ago
FEDORA-2026-03ea7c5707
Packages in this update:
Update description:
This update fixes an overflow in parsing RGBE/HDR image files.
1 week ago
FEDORA-2026-79b351972c
Packages in this update:
Update description:
This update fixes an overflow in parsing RGBE/HDR image files.