Aggregator
DSA-6464-1 erlang - security update
gum-2.0.0-1.el10_4
- gum-2.0.0-1.el10_4
Update to version 2.0.0 and override bundled golang.org/x/net to v0.55.0. The latter fixes CVE-2026-25680, CVE-2026-25681, and CVE-2026-42506.
python-linkify-it-py-2.1.1-1.fc44
- python-linkify-it-py-2.1.1-1.fc44
Security release: LinkifyIt.match() was quadratic on untrusted input when linkify is enabled (GHSA-8m2q-wq3r-6hq8).
- Fix quadratic complexity in LinkifyIt.match(), port of linkify-it 5.0.1 and 5.0.2 (upstream CVE-2026-48801, CVE-2026-59887) (#82)
- Match validators at a position instead of slicing the tail, needed because Python 3.10 does not optimize the ^ anchor (#82)
- Allow ; in the email name, matching linkify-it. Behavior change: a;b@example.com is now linkified (#82)
- Update port.yml (linkify-it v5.0.2) (#82)
USN-8671-1: FFmpeg vulnerabilities
python-llm-0.33-2.fc44
- python-llm-0.33-2.fc44
Update to latest upstream release python llm 0.33
USN-8670-1: curl vulnerability
perl-DBD-Pg-3.21.1-2.fc44
- perl-DBD-Pg-3.21.1-2.fc44
Fix missing closing double-quote in su -c commands in dbdpg_test_setup.pl
3.21.0m 3.21.1: - New features: non-blocking async COPY FROM support (pg_putcopydata_async, pg_putcopyend_async, pg_flush); new string-buffer system replacing linked lists with arrays (faster) - Bug fixes: memory leaks fixed (PQclosePrepared cleanup path, bind_param, statement handles); float quoting fixes (NaN); $sth->rows() returns 0 for no-row updates/deletes; safer NUL checking in _dequote_bytea_hex(); allocation fixes in quote_float() / pg_destringify_array() - Fix CVE-2026-78183
chromium-151.0.7922.173-1.el10_2
- chromium-151.0.7922.173-1.el10_2
Update to 151.0.7922.173
* CVE-2026-76017: Use after free in Chromoting * CVE-2026-76018: Privilege elevation in Import * CVE-2026-76019: Incorrect authorization in Workers * CVE-2026-76020: Race condition in V8 * CVE-2026-76021: Use after free in DOM * CVE-2026-76022: Buffer overflow in Network * CVE-2026-76023: Improper resource control in Linux Toolkit Themingchromium-151.0.7922.173-1.fc43
- chromium-151.0.7922.173-1.fc43
Update to 151.0.7922.173
* CVE-2026-76017: Use after free in Chromoting * CVE-2026-76018: Privilege elevation in Import * CVE-2026-76019: Incorrect authorization in Workers * CVE-2026-76020: Race condition in V8 * CVE-2026-76021: Use after free in DOM * CVE-2026-76022: Buffer overflow in Network * CVE-2026-76023: Improper resource control in Linux Toolkit Themingchromium-151.0.7922.173-1.el9
- chromium-151.0.7922.173-1.el9
Update to 151.0.7922.173
* CVE-2026-76017: Use after free in Chromoting * CVE-2026-76018: Privilege elevation in Import * CVE-2026-76019: Incorrect authorization in Workers * CVE-2026-76020: Race condition in V8 * CVE-2026-76021: Use after free in DOM * CVE-2026-76022: Buffer overflow in Network * CVE-2026-76023: Improper resource control in Linux Toolkit Themingchromium-151.0.7922.173-1.fc44
- chromium-151.0.7922.173-1.fc44
Update to 151.0.7922.173
* CVE-2026-76017: Use after free in Chromoting * CVE-2026-76018: Privilege elevation in Import * CVE-2026-76019: Incorrect authorization in Workers * CVE-2026-76020: Race condition in V8 * CVE-2026-76021: Use after free in DOM * CVE-2026-76022: Buffer overflow in Network * CVE-2026-76023: Improper resource control in Linux Toolkit Themingchromium-151.0.7922.173-1.el10_3
- chromium-151.0.7922.173-1.el10_3
Update to 151.0.7922.173
* CVE-2026-76017: Use after free in Chromoting * CVE-2026-76018: Privilege elevation in Import * CVE-2026-76019: Incorrect authorization in Workers * CVE-2026-76020: Race condition in V8 * CVE-2026-76021: Use after free in DOM * CVE-2026-76022: Buffer overflow in Network * CVE-2026-76023: Improper resource control in Linux Toolkit Themingnext-20260824: linux-next
openvkl-2.0.2-1.fc44 rkcommon-1.15.3-1.fc44
- openvkl-2.0.2-1.fc44
- rkcommon-1.15.3-1.fc44
Update to the latest version to fix CVE-2026-21399
perl-DBD-Pg-3.21.1-1.fc44
- perl-DBD-Pg-3.21.1-1.fc44
3.21.0m 3.21.1: - New features: non-blocking async COPY FROM support (pg_putcopydata_async, pg_putcopyend_async, pg_flush); new string-buffer system replacing linked lists with arrays (faster) - Bug fixes: memory leaks fixed (PQclosePrepared cleanup path, bind_param, statement handles); float quoting fixes (NaN); $sth->rows() returns 0 for no-row updates/deletes; safer NUL checking in _dequote_bytea_hex(); allocation fixes in quote_float() / pg_destringify_array() - Fix CVE-2026-78183
openvkl-2.0.2-1.fc45 rkcommon-1.15.3-1.fc45
- openvkl-2.0.2-1.fc45
- rkcommon-1.15.3-1.fc45
Update to the latest version to fix CVE-2026-21399
python-aiohttp-3.14.3-3.fc45
- python-aiohttp-3.14.3-3.fc45
Automatic update for python-aiohttp-3.14.3-3.fc45.
Changelog * Mon Aug 24 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-3 - Preemptively patch for Cython 3.3 compatibility * Mon Aug 24 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-2 - Remove a test skip that’s no longer needed * Thu Aug 20 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-1 - Update to 3.14.3 - Security fix for CVE-2026-34993; fixes RHBZ#2511060 - Security fix for CVE-2026-59881; fixes RHBZ#2509739 - Security fix for CVE-2026-69243; fixes RHBZ#2519530 - Security fix for CVE-2026-69244; fixes RHBZ#2519529 * Thu Aug 20 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.13.5-13 - Use the provisional pyproject declarative buildsystempython-aiohttp-3.14.3-3.fc46
- python-aiohttp-3.14.3-3.fc46
Automatic update for python-aiohttp-3.14.3-3.fc46.
Changelog * Mon Aug 24 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-3 - Preemptively patch for Cython 3.3 compatibility * Mon Aug 24 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-2 - Remove a test skip that’s no longer needed * Thu Aug 20 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-1 - Update to 3.14.3 - Security fix for CVE-2026-34993; fixes RHBZ#2511060 - Security fix for CVE-2026-59881; fixes RHBZ#2509739 - Security fix for CVE-2026-69243; fixes RHBZ#2519530 - Security fix for CVE-2026-69244; fixes RHBZ#2519529 * Thu Aug 20 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.13.5-13 - Use the provisional pyproject declarative buildsystem