Aggregator

USN-8737-2: GNU C Library vulnerabilities

1 week ago
USN-8737-1 fixed vulnerabilities in GNU C Library. This update provides the corresponding fixes for Ubuntu 24.04 LTS. Original advisory details: It was discovered that GNU C Library had a buffer overflow in the strfmon function when handling right-justification padding. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-19499) It was discovered that GNU C Library had an out-of-bounds stack array access in the tdelete function. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-19542) It was discovered that GNU C Library incorrectly handled memory when calling wordexp with the WRDE_APPEND flag. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-6368) It was discovered that GNU C Library had a stack overflow in the wordexp function when expanding paths beginning with a tilde followed by a long username. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-6791) It was discovered that GNU C Library had a hang in the SHIFT_JISX0213 character set converter. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-77117) It was discovered that GNU C Library had a hang in the EUC_JISX0213 character set converter. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-80489)

ruby-3.4.10-32.fc43

1 week ago
FEDORA-2026-b3bccd6a30 Packages in this update:
  • ruby-3.4.10-32.fc43
Update description:

This rpm updates included resolv gem to 0.7.2 to resolve CVE security issues.

ruby-4.0.6-38.fc44

1 week ago
FEDORA-2026-da06bdeb38 Packages in this update:
  • ruby-4.0.6-38.fc44
Update description:

This rpm updates included resolv gem to 0.7.2 to resolve CVE security issues.

ruby-4.0.6-38.fc45

1 week ago
FEDORA-2026-ab0c751524 Packages in this update:
  • ruby-4.0.6-38.fc45
Update description:

This rpm updates included resolv gem to 0.7.2 to resolve CVE security issues.

perl-DBI-1.653-1.fc44

1 week 1 day ago
FEDORA-2026-195d764078 Packages in this update:
  • perl-DBI-1.653-1.fc44
Update description:

1.653 Fix test for 32bit-perl Fix arbitrary module and file loading via dbm_type/dbm_mldbm (CVE-2026-78030) Tighten symlink outside of f_dir (CVE-2026-15392) check

perl-DBI-1.653-1.fc45

1 week 1 day ago
FEDORA-2026-2bf3261da2 Packages in this update:
  • perl-DBI-1.653-1.fc45
Update description:

1.653 Fix test for 32bit-perl Fix arbitrary module and file loading via dbm_type/dbm_mldbm (CVE-2026-78030) Tighten symlink outside of f_dir (CVE-2026-15392) check

perl-DBI-1.653-1.fc43

1 week 1 day ago
FEDORA-2026-a4674c5df6 Packages in this update:
  • perl-DBI-1.653-1.fc43
Update description:

1.653 Fix test for 32bit-perl Fix arbitrary module and file loading via dbm_type/dbm_mldbm (CVE-2026-78030) Tighten symlink outside of f_dir (CVE-2026-15392) check

stb-0^20260802.2c980bb-2.fc46

1 week 1 day ago
FEDORA-2026-ee846faf9d Packages in this update:
  • stb-0^20260802.2c980bb-2.fc46
Update description:

Automatic update for stb-0^20260802.2c980bb-2.fc46.

Changelog * Thu Sep 10 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 0^20260802.2c980bb-2 - Patch stb_sprintf: security fix for CVE-2026-79516 - Fixes RHBZ#2531291; Fixes RHBZ#2531290 * Thu Sep 10 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 0^20260802.2c980bb-1 - Update to 0^20260802.2c980bb

libpcap-1.10.7-1.fc43

1 week 1 day ago
FEDORA-2026-4401b94ad0 Packages in this update:
  • libpcap-1.10.7-1.fc43
Update description:

New version 10.7.1 Fix for CVE-2026-0799, CVE-2026-6244, CVE-2026-6554, CVE-2026-18238, CVE-2026-18313, CVE-2026-31911, CVE-2026-31912

libpcap-1.10.7-1.fc45

1 week 1 day ago
FEDORA-2026-c3fb234b87 Packages in this update:
  • libpcap-1.10.7-1.fc45
Update description:

New version 10.7.1 Fix for CVE-2026-0799, CVE-2026-6244, CVE-2026-6554, CVE-2026-18238, CVE-2026-18313, CVE-2026-31911, CVE-2026-31912

USN-8741-1: Flatpak vulnerabilities

1 week 1 day ago
It was discovered that Flatpak did not properly validate paths in sandbox-expose options. A malicious or compromised Flatpak app could use app-controlled symlinks to access arbitrary host files and gain code execution in the host context. This issue was addressed in Ubuntu Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-34078) It was discovered that Flatpak did not properly validate paths when removing outdated ld.so cache files. A malicious or compromised Flatpak app could use this issue to delete arbitrary files on the host. (CVE-2026-34079)

rubygems-4.0.20-1.fc44

1 week 1 day ago
FEDORA-2026-2857104379 Packages in this update:
  • rubygems-4.0.20-1.fc44
Update description:

Update rubygems to 4.0.20. Additionally, several security issues were found in resolv gem bundled in rubygems. This update resolves these issues by updating resolv to 0.7.2.

rubygems-4.0.20-1.fc45

1 week 1 day ago
FEDORA-2026-9831a751e2 Packages in this update:
  • rubygems-4.0.20-1.fc45
Update description:

Update rubygems to 4.0.20. Additionally, several security issues were found in resolv gem bundled in rubygems. This update resolves these issues by updating resolv to 0.7.2.

rubygems-4.0.20-1.fc46

1 week 1 day ago
FEDORA-2026-c77b963cc9 Packages in this update:
  • rubygems-4.0.20-1.fc46
Update description:

Automatic update for rubygems-4.0.20-1.fc46.

Changelog * Thu Sep 3 2026 Mamoru TASAKA <mtasaka@fedoraproject.org> - 4.0.20-1 - Update to RubyGems 4.0.20 - Backport ruby upstream patch to update resolv to 0.7.2 - Resolves: CVE-2026-80212 (rhbz#2527309) - Resolves: CVE-2026-80213 (rhbz#2527311)