1 week ago
FEDORA-2026-9c8770dffb
Packages in this update:
Update description:
Update to .NET SDK 9.0.120 and Runtime 9.0.19
Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354
Release Notes:
1 week ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- Thunderbolt and USB4 drivers;
- Network traffic control;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RxRPC session sockets;
- SCTP protocol;
(CVE-2026-46331, CVE-2026-52924, CVE-2026-53131, CVE-2026-53146,
CVE-2026-53147, CVE-2026-53148, CVE-2026-53149, CVE-2026-53150,
CVE-2026-53151, CVE-2026-53175, CVE-2026-53176, CVE-2026-53186,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53216, CVE-2026-53221,
CVE-2026-53224, CVE-2026-53225, CVE-2026-53228, CVE-2026-53246,
CVE-2026-53247, CVE-2026-53260, CVE-2026-53359)
1 week ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- NVME drivers;
- Ext4 file system;
- SMB network file system;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- Locking primitives;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- SCTP protocol;
- SMC sockets;
(CVE-2026-31414, CVE-2026-31448, CVE-2026-31705, CVE-2026-43198,
CVE-2026-43378, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331,
CVE-2026-52924, CVE-2026-52989, CVE-2026-53086, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359)
1 week ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- Mellanox network drivers;
- File systems infrastructure;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- B.A.T.M.A.N. meshing protocol;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- RxRPC session sockets;
- SCTP protocol;
- SMC sockets;
(CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465,
CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914,
CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359)
1 week ago
Version:next-20260813 (linux-next)
Released:2026-08-13
1 week ago
FEDORA-EPEL-2026-164ecb432d
Packages in this update:
- chromium-151.0.7922.137-1.el10_2
Update description:
chromium security release 151.0.7922.137 inludes fixes for:
* CVE-2026-19556: Use after free in V8
* CVE-2026-19557: Use after free in TabStrip
* CVE-2026-19558: Use after free in Extensions
* CVE-2026-19559: Use after free in HTML
* CVE-2026-19560: Use after free in Blink
1 week ago
FEDORA-2026-51e9d3c767
Packages in this update:
- chromium-151.0.7922.137-1.fc43
Update description:
chromium security release 151.0.7922.137 inludes fixes for:
* CVE-2026-19556: Use after free in V8
* CVE-2026-19557: Use after free in TabStrip
* CVE-2026-19558: Use after free in Extensions
* CVE-2026-19559: Use after free in HTML
* CVE-2026-19560: Use after free in Blink
1 week ago
FEDORA-2026-c374680c6a
Packages in this update:
- chromium-151.0.7922.137-1.fc44
Update description:
chromium security release 151.0.7922.137 inludes fixes for:
* CVE-2026-19556: Use after free in V8
* CVE-2026-19557: Use after free in TabStrip
* CVE-2026-19558: Use after free in Extensions
* CVE-2026-19559: Use after free in HTML
* CVE-2026-19560: Use after free in Blink
1 week ago
FEDORA-EPEL-2026-c2dac28c8c
Packages in this update:
- chromium-151.0.7922.137-1.el9
Update description:
chromium security release 151.0.7922.137 inludes fixes for:
* CVE-2026-19556: Use after free in V8
* CVE-2026-19557: Use after free in TabStrip
* CVE-2026-19558: Use after free in Extensions
* CVE-2026-19559: Use after free in HTML
* CVE-2026-19560: Use after free in Blink
1 week ago
FEDORA-EPEL-2026-40713968f8
Packages in this update:
- chromium-151.0.7922.137-1.el10_3
Update description:
chromium security release 151.0.7922.137 inludes fixes for:
* CVE-2026-19556: Use after free in V8
* CVE-2026-19557: Use after free in TabStrip
* CVE-2026-19558: Use after free in Extensions
* CVE-2026-19559: Use after free in HTML
* CVE-2026-19560: Use after free in Blink
1 week ago
FEDORA-2026-1397d83d94
Packages in this update:
Update description:
Update to .NET SDK 8.0.130 and Runtime 8.0.30
Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354
Release Notes:
1 week ago
FEDORA-2026-0db5bf0aae
Packages in this update:
Update description:
Update to .NET SDK 8.0.130 and Runtime 8.0.30
Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354
Release Notes:
1 week ago
FEDORA-2026-8b4cb2340a
Packages in this update:
- dotnet10.0-10.0.111-1.fc44
Update description:
Update to .NET SDK 10.0.111 and Runtime 10.0.11
Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354
Release Notes:
1 week ago
FEDORA-2026-91c099294a
Packages in this update:
- dotnet10.0-10.0.111-1.fc43
Update description:
Update to .NET SDK 10.0.111 and Runtime 10.0.11
Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354
Release Notes:
1 week 1 day ago
FEDORA-2026-61704c09ea
Packages in this update:
Update description:
WordPress 6.9.7 Release
Security update included in this release
- Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
WordPress 6.9.6 Release
Security update included in this release
- Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
- Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
- Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
- Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
- Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
- A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
- An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
- Enumeration of post slugs reported by HDWSec
- Disclosure of notes in comment feeds reported by Elio Gubser
- Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
- Bypass of the email address confirmation flow reported by 0ways
- A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters
1 week 1 day ago
FEDORA-EPEL-2026-96feebe88a
Packages in this update:
Update description:
WordPress 6.9.7 Release
Security update included in this release
- Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
WordPress 6.9.6 Release
Security update included in this release
- Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
- Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
- Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
- Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
- Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
- A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
- An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
- Enumeration of post slugs reported by HDWSec
- Disclosure of notes in comment feeds reported by Elio Gubser
- Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
- Bypass of the email address confirmation flow reported by 0ways
- A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters
1 week 1 day ago
FEDORA-2026-dc0ff85b8b
Packages in this update:
Update description:
WordPress 6.9.7 Release
Security update included in this release
- Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
WordPress 6.9.6 Release
Security update included in this release
- Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
- Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
- Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
- Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
- Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
- A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
- An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
- Enumeration of post slugs reported by HDWSec
- Disclosure of notes in comment feeds reported by Elio Gubser
- Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
- Bypass of the email address confirmation flow reported by 0ways
- A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters
1 week 1 day ago
FEDORA-EPEL-2026-c91a425a57
Packages in this update:
Update description:
WordPress 7.0.4 Release
Security update included in this release
- Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
WordPress 7.0.3 Release
Security update included in this release
- Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
- Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
- Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
- Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
- Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
- A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
- An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
- Enumeration of post slugs reported by HDWSec
- Disclosure of notes in comment feeds reported by Elio Gubser
- Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
- Bypass of the email address confirmation flow reported by 0ways
- A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters
1 week 1 day ago
FEDORA-EPEL-2026-4f38e2a6eb
Packages in this update:
Update description:
WordPress 6.9.7 Release
Security update included in this release
- Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
WordPress 6.9.6 Release
Security update included in this release
- Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
- Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
- Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
- Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
- Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
- A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
- An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
- Enumeration of post slugs reported by HDWSec
- Disclosure of notes in comment feeds reported by Elio Gubser
- Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
- Bypass of the email address confirmation flow reported by 0ways
- A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters
1 week 1 day ago