Aggregator

libevent-2.1.13-1.fc44

1 week ago
FEDORA-2026-72d10c874d Packages in this update:
  • libevent-2.1.13-1.fc44
Update description: Update to 2.1.13.

The following security vulnerabilites are fixed in this update:

libevent-2.1.13-1.fc45

1 week ago
FEDORA-2026-0a83f1b852 Packages in this update:
  • libevent-2.1.13-1.fc45
Update description: Update to 2.1.13.

The following security vulnerabilites are fixed in this update:

USN-8734-1: PHP vulnerabilities

1 week ago
It was discovered that PHP incorrectly handled Apache map decoding in SOAP servers with a typemap configured. A remote attacker could use this issue to cause a NULL pointer dereference, resulting in a denial of service. (CVE-2026-7262) It was discovered that PHP incorrectly handled signed integer overflow in the metaphone() function. An attacker could use this issue to cause an out-of-bounds read, resulting in a denial of service. (CVE-2026-7568) It was discovered that PHP incorrectly handled circular symbolic links in phar archives. An attacker could use this issue to cause unbounded recursion, resulting in a denial of service. (CVE-2026-7260) It was discovered that PHP incorrectly escaped backslashes in the pgsql extension when standard_conforming_strings is enabled. An attacker could use this issue to perform SQL injection via a backslash breakout. (CVE-2026-17543)

gegl04-0.4.72-1.fc43

1 week ago
FEDORA-2026-39b07f6dbb Packages in this update:
  • gegl04-0.4.72-1.fc43
Update description:

This update contains a new upstream release with bugfixes and improvements, notably it fixes an overflow in parsing RGBE/HDR image files.

For more information, please consult the upstream changelog.

libcupsfilters-2.2.1-3.fc46

1 week ago
FEDORA-2026-5cce49502a Packages in this update:
  • libcupsfilters-2.2.1-3.fc46
Update description:

Automatic update for libcupsfilters-2.2.1-3.fc46.

Changelog * Fri Sep 4 2026 Zdenek Dohnal <zdohnal@redhat.com> - 1:2.2.1-3 - fix multiple copies not working for raster drivers (rhbz#2312145)

USN-8733-1: Gzip vulnerabilities

1 week ago
Michał Majchrowicz and Marcin Wyczechowski discovered that Gzip's gzexe utility created temporary files in an insecure manner when mktemp was unavailable. A local attacker could possibly use this issue to overwrite arbitrary files. (CVE-2026-41991) Elias Hasas, Michał Majchrowicz and Marcin Wyczechowski discovered that Gzip incorrectly handled certain compressed files. An attacker could possibly use this issue to obtain sensitive information or cause Gzip to crash, resulting in a denial of service. (CVE-2026-41992)

USN-8732-1: Minetest vulnerability

1 week ago
It was discovered that Minetest did not properly sanitize the Lua sandbox environment when using LuaJIT. A malicious mod could escape the sandbox to execute arbitrary code and gain full file system access on the server. An attacker could use this issue to compromise the server.

perl-Authen-SASL-2.2100-1.fc45

1 week ago
FEDORA-2026-81cd7d0f41 Packages in this update:
  • perl-Authen-SASL-2.2100-1.fc45
Update description:

2.2100 - CVE-2026-86219: Replay attack in Authen::SASL::Perl::DIGEST_MD5 Thanks to TIMLEGGE (@timlegge) and the CPANSec team for the AI-assisted detection and fix!

perl-Authen-SASL-2.2100-1.fc44

1 week ago
FEDORA-2026-53e2875c88 Packages in this update:
  • perl-Authen-SASL-2.2100-1.fc44
Update description:

2.2100 - CVE-2026-86219: Replay attack in Authen::SASL::Perl::DIGEST_MD5 Thanks to TIMLEGGE (@timlegge) and the CPANSec team for the AI-assisted detection and fix!

USN-8731-1: MiniUPnPd vulnerability

1 week ago
It was discovered that MiniUPnPd contained an integer underflow vulnerability in SOAPAction header parsing. A remote attacker could use this issue to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote.