Aggregator

USN-8630-2: Linux kernel vulnerabilities

1 week ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - Mellanox network drivers; - File systems infrastructure; - IPv4 networking; - Network traffic control; - TCP network protocol; - B.A.T.M.A.N. meshing protocol; - IPv6 networking; - Multipath TCP; - Netfilter; - RxRPC session sockets; - SCTP protocol; - SMC sockets; (CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465, CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176, CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)

chromium-151.0.7922.137-1.el10_2

1 week ago
FEDORA-EPEL-2026-164ecb432d Packages in this update:
  • chromium-151.0.7922.137-1.el10_2
Update description:

chromium security release 151.0.7922.137 inludes fixes for:

* CVE-2026-19556: Use after free in V8 * CVE-2026-19557: Use after free in TabStrip * CVE-2026-19558: Use after free in Extensions * CVE-2026-19559: Use after free in HTML * CVE-2026-19560: Use after free in Blink

chromium-151.0.7922.137-1.fc43

1 week ago
FEDORA-2026-51e9d3c767 Packages in this update:
  • chromium-151.0.7922.137-1.fc43
Update description:

chromium security release 151.0.7922.137 inludes fixes for:

* CVE-2026-19556: Use after free in V8 * CVE-2026-19557: Use after free in TabStrip * CVE-2026-19558: Use after free in Extensions * CVE-2026-19559: Use after free in HTML * CVE-2026-19560: Use after free in Blink

chromium-151.0.7922.137-1.fc44

1 week ago
FEDORA-2026-c374680c6a Packages in this update:
  • chromium-151.0.7922.137-1.fc44
Update description:

chromium security release 151.0.7922.137 inludes fixes for:

* CVE-2026-19556: Use after free in V8 * CVE-2026-19557: Use after free in TabStrip * CVE-2026-19558: Use after free in Extensions * CVE-2026-19559: Use after free in HTML * CVE-2026-19560: Use after free in Blink

chromium-151.0.7922.137-1.el9

1 week ago
FEDORA-EPEL-2026-c2dac28c8c Packages in this update:
  • chromium-151.0.7922.137-1.el9
Update description:

chromium security release 151.0.7922.137 inludes fixes for:

* CVE-2026-19556: Use after free in V8 * CVE-2026-19557: Use after free in TabStrip * CVE-2026-19558: Use after free in Extensions * CVE-2026-19559: Use after free in HTML * CVE-2026-19560: Use after free in Blink

chromium-151.0.7922.137-1.el10_3

1 week ago
FEDORA-EPEL-2026-40713968f8 Packages in this update:
  • chromium-151.0.7922.137-1.el10_3
Update description:

chromium security release 151.0.7922.137 inludes fixes for:

* CVE-2026-19556: Use after free in V8 * CVE-2026-19557: Use after free in TabStrip * CVE-2026-19558: Use after free in Extensions * CVE-2026-19559: Use after free in HTML * CVE-2026-19560: Use after free in Blink

dotnet8.0-8.0.130-1.fc44

1 week ago
FEDORA-2026-1397d83d94 Packages in this update:
  • dotnet8.0-8.0.130-1.fc44
Update description:

Update to .NET SDK 8.0.130 and Runtime 8.0.30

Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354

Release Notes:

dotnet8.0-8.0.130-1.fc43

1 week ago
FEDORA-2026-0db5bf0aae Packages in this update:
  • dotnet8.0-8.0.130-1.fc43
Update description:

Update to .NET SDK 8.0.130 and Runtime 8.0.30

Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354

Release Notes:

dotnet10.0-10.0.111-1.fc44

1 week ago
FEDORA-2026-8b4cb2340a Packages in this update:
  • dotnet10.0-10.0.111-1.fc44
Update description:

Update to .NET SDK 10.0.111 and Runtime 10.0.11

Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354

Release Notes:

dotnet10.0-10.0.111-1.fc43

1 week ago
FEDORA-2026-91c099294a Packages in this update:
  • dotnet10.0-10.0.111-1.fc43
Update description:

Update to .NET SDK 10.0.111 and Runtime 10.0.11

Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354

Release Notes:

wordpress-6.9.7-1.fc43

1 week 1 day ago
FEDORA-2026-61704c09ea Packages in this update:
  • wordpress-6.9.7-1.fc43
Update description: WordPress 6.9.7 Release

Security update included in this release

  • Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
WordPress 6.9.6 Release

Security update included in this release

  • Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
  • Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
  • Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
  • Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
  • Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
  • Enumeration of post slugs reported by HDWSec
  • Disclosure of notes in comment feeds reported by Elio Gubser
  • Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
  • Bypass of the email address confirmation flow reported by 0ways
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters

wordpress-6.9.7-1.el9

1 week 1 day ago
FEDORA-EPEL-2026-96feebe88a Packages in this update:
  • wordpress-6.9.7-1.el9
Update description: WordPress 6.9.7 Release

Security update included in this release

  • Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
WordPress 6.9.6 Release

Security update included in this release

  • Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
  • Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
  • Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
  • Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
  • Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
  • Enumeration of post slugs reported by HDWSec
  • Disclosure of notes in comment feeds reported by Elio Gubser
  • Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
  • Bypass of the email address confirmation flow reported by 0ways
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters

wordpress-6.9.7-1.fc44

1 week 1 day ago
FEDORA-2026-dc0ff85b8b Packages in this update:
  • wordpress-6.9.7-1.fc44
Update description: WordPress 6.9.7 Release

Security update included in this release

  • Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
WordPress 6.9.6 Release

Security update included in this release

  • Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
  • Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
  • Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
  • Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
  • Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
  • Enumeration of post slugs reported by HDWSec
  • Disclosure of notes in comment feeds reported by Elio Gubser
  • Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
  • Bypass of the email address confirmation flow reported by 0ways
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters

wordpress-7.0.4-1.el10_3

1 week 1 day ago
FEDORA-EPEL-2026-c91a425a57 Packages in this update:
  • wordpress-7.0.4-1.el10_3
Update description: WordPress 7.0.4 Release

Security update included in this release

  • Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
WordPress 7.0.3 Release

Security update included in this release

  • Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
  • Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
  • Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
  • Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
  • Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
  • Enumeration of post slugs reported by HDWSec
  • Disclosure of notes in comment feeds reported by Elio Gubser
  • Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
  • Bypass of the email address confirmation flow reported by 0ways
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters

wordpress-6.9.7-1.el10_2

1 week 1 day ago
FEDORA-EPEL-2026-4f38e2a6eb Packages in this update:
  • wordpress-6.9.7-1.el10_2
Update description: WordPress 6.9.7 Release

Security update included in this release

  • Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
WordPress 6.9.6 Release

Security update included in this release

  • Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
  • Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
  • Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
  • Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
  • Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
  • Enumeration of post slugs reported by HDWSec
  • Disclosure of notes in comment feeds reported by Elio Gubser
  • Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
  • Bypass of the email address confirmation flow reported by 0ways
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters