1 week 1 day ago
It was discovered that GNU C Library had a buffer overflow in the strfmon
function when handling right-justification padding. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-19499)
It was discovered that GNU C Library had an out-of-bounds stack array
access in the tdelete function. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. (CVE-2026-19542)
It was discovered that GNU C Library incorrectly handled memory when
calling wordexp with the WRDE_APPEND flag. An attacker could possibly use
this issue to cause a denial of service. (CVE-2026-6368)
It was discovered that GNU C Library had a stack overflow in the wordexp
function when expanding paths beginning with a tilde followed by a long
username. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-6791)
It was discovered that GNU C Library had a hang in the SHIFT_JISX0213
character set converter. An attacker could possibly use this issue to cause
a denial of service. (CVE-2026-77117)
It was discovered that GNU C Library had a hang in the EUC_JISX0213
character set converter. An attacker could possibly use this issue to cause
a denial of service. (CVE-2026-80489)
1 week 1 day ago
It was discovered that Perl incorrectly handled certain large inputs during
regular expression matching. An attacker could possibly use this issue to
trigger out-of-bounds heap reads or writes, resulting in a denial of
service or arbitrary code execution. (CVE-2026-15534)
It was discovered that Perl incorrectly handled certain regular expression
containing alternative matching branches. An attacker could possibly use
this issue to cause incorrect regular expression matches, resulting in
security restrictions being bypassed. (CVE-2026-19487)
1 week 1 day ago
It was discovered that HSQLDB incorrectly handled specially crafted
database files. An attacker could possibly use this issue to overwrite
arbitrary files.
1 week 1 day ago
FEDORA-EPEL-2026-80df4fb4ea
Packages in this update:
- perl-Net-OAuth-0.33-2.el10_2
Update description:
Fixes CVE-2025-22376 and CVE-2026-75589
1 week 1 day ago
FEDORA-EPEL-2026-a0e219c2a3
Packages in this update:
- perl-Net-OAuth-0.33-2.el10_3
Update description:
Fixes CVE-2025-22376 and CVE-2026-75589
1 week 1 day ago
FEDORA-EPEL-2026-e6faf4f038
Packages in this update:
- perl-Net-OAuth-0.33-2.el10_4
Update description:
Fixes CVE-2025-22376 and CVE-2026-75589
1 week 1 day ago
FEDORA-2026-3fd073ad5b
Packages in this update:
Update description:
Update to 1.5.8
1 week 1 day ago
FEDORA-2026-6d919ea521
Packages in this update:
Update description:
Update to 1.5.8
1 week 1 day ago
FEDORA-2026-8cbd9e2c8b
Packages in this update:
Update description:
Update to 1.5.8
1 week 1 day ago
FEDORA-EPEL-2026-d6aefc999f
Packages in this update:
- php-pecl-mongodb-1.20.1-3.el9
Update description:
Backported from 1.21.9
- PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
Backported from 1.21.7
- PHPC-2745: Reject null bytes in namespaces and periods in database names [v1.21] by @GromNaN in #2059
1 week 1 day ago
FEDORA-EPEL-2026-99ac8d2816
Packages in this update:
- php-pecl-mongodb-1.21.9-1.el10_2
Update description:
Version 1.21.9
- PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
Version 1.21.7
- PHPC-2745: Reject null bytes in namespaces and periods in database names [v1.21] by @GromNaN in #2059
1 week 1 day ago
FEDORA-2026-358d3ccdfe
Packages in this update:
- php-pecl-mongodb2-2.1.9-1.fc44
Update description:
Version 2.1.9
- PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
1 week 1 day ago
FEDORA-EPEL-2026-7d7ac5f0f9
Packages in this update:
- php-pecl-mongodb2-2.1.9-2.el10_2
Update description:
Version 2.1.9
- PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
1 week 1 day ago
FEDORA-2026-caf49a7828
Packages in this update:
- php-pecl-mongodb2-2.1.9-1.fc43
Update description:
Version 2.1.9
- PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
1 week 1 day ago
FEDORA-2026-38c637be37
Packages in this update:
- roundcubemail-1.7.4-1.fc44
Update description:
Release 1.7.4
- Use X-Content-Type-Options:nosniff for attachment previews and downloads (#10308)
- zipdownload: Fix attachment filename sanitisation of backslash and control characters (#10325)
- Security: Fix CSS declaration smuggling via un-encoded ampersand emission
- Security: Fix CSS property injection via body background attribute
- Security: Fix email header injection via bare CR in the subject field
- Security: Fix email header injection via C-escape \r in the recipient display name
- Security: Fix email header injection via identity's organization field
- Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
- Security: Fix XSS in the HTML editor using text/enriched part content
- Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
- Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
- Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
- Security: Fix remote-content blocker bypass via SVG SMIL src animation
- Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses
1 week 1 day ago
FEDORA-2026-6ab831c1c5
Packages in this update:
- roundcubemail-1.7.4-1.fc45
Update description:
Release 1.7.4
- Use X-Content-Type-Options:nosniff for attachment previews and downloads (#10308)
- zipdownload: Fix attachment filename sanitisation of backslash and control characters (#10325)
- Security: Fix CSS declaration smuggling via un-encoded ampersand emission
- Security: Fix CSS property injection via body background attribute
- Security: Fix email header injection via bare CR in the subject field
- Security: Fix email header injection via C-escape \r in the recipient display name
- Security: Fix email header injection via identity's organization field
- Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
- Security: Fix XSS in the HTML editor using text/enriched part content
- Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
- Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
- Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
- Security: Fix remote-content blocker bypass via SVG SMIL src animation
- Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses
1 week 1 day ago
FEDORA-EPEL-2026-78f8bcff8a
Packages in this update:
- roundcubemail-1.6.19-1.el10_2
Update description:
Release 1.6.19
- Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294)
- Security: Fix CSS declaration smuggling via un-encoded ampersand emission
- Security: Fix CSS property injection via body background attribute
- Security: Fix email header injection via bare CR in the subject field
- Security: Fix email header injection via C-escape \r in the recipient display name
- Security: Fix email header injection via identity's organization field
- Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
- Security: Fix XSS in the HTML editor using text/enriched part content
- Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
- Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
- Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
- Security: Fix remote-content blocker bypass via SVG SMIL src animation
- Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses
1 week 1 day ago
FEDORA-2026-821349f438
Packages in this update:
- roundcubemail-1.6.19-1.fc43
Update description:
Release 1.6.19
- Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294)
- Security: Fix CSS declaration smuggling via un-encoded ampersand emission
- Security: Fix CSS property injection via body background attribute
- Security: Fix email header injection via bare CR in the subject field
- Security: Fix email header injection via C-escape \r in the recipient display name
- Security: Fix email header injection via identity's organization field
- Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
- Security: Fix XSS in the HTML editor using text/enriched part content
- Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
- Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
- Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
- Security: Fix remote-content blocker bypass via SVG SMIL src animation
- Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses
1 week 1 day ago
FEDORA-EPEL-2026-37f493ad5e
Packages in this update:
- roundcubemail-1.6.19-1.el10_4
Update description:
Release 1.6.19
- Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294)
- Security: Fix CSS declaration smuggling via un-encoded ampersand emission
- Security: Fix CSS property injection via body background attribute
- Security: Fix email header injection via bare CR in the subject field
- Security: Fix email header injection via C-escape \r in the recipient display name
- Security: Fix email header injection via identity's organization field
- Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
- Security: Fix XSS in the HTML editor using text/enriched part content
- Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
- Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
- Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
- Security: Fix remote-content blocker bypass via SVG SMIL src animation
- Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses
1 week 1 day ago
FEDORA-EPEL-2026-d623f0849b
Packages in this update:
- roundcubemail-1.6.19-1.el10_3
Update description:
Release 1.6.19
- Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294)
- Security: Fix CSS declaration smuggling via un-encoded ampersand emission
- Security: Fix CSS property injection via body background attribute
- Security: Fix email header injection via bare CR in the subject field
- Security: Fix email header injection via C-escape \r in the recipient display name
- Security: Fix email header injection via identity's organization field
- Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
- Security: Fix XSS in the HTML editor using text/enriched part content
- Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
- Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
- Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
- Security: Fix remote-content blocker bypass via SVG SMIL src animation
- Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses