5 days 22 hours ago
USN-8514-1 fixed a vulnerability in OpenSSH. This update provides
the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and
Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that OpenSSH incorrectly handled file permissions when
downloading files as root using the legacy scp protocol without the
preserve-mode option. An attacker could use this to install setuid or setgid
files on a system, possibly leading to privilege escalation.
6 days ago
FEDORA-2026-16f1152378
Packages in this update:
- mingw-gdk-pixbuf-2.44.8-2.fc44
Update description:
Backport fixes for CVE-2026-16768 and CVE-2026-81893.
6 days ago
FEDORA-2026-4e6575b35f
Packages in this update:
- mingw-gdk-pixbuf-2.44.8-2.fc43
Update description:
Backport fixes for CVE-2026-16768 and CVE-2026-81893.
6 days ago
FEDORA-2026-26573b6029
Packages in this update:
- mingw-gdk-pixbuf-2.44.8-2.fc45
Update description:
Backport fixes for CVE-2026-16768 and CVE-2026-81893.
6 days 3 hours ago
Madelyn Olson discovered that Valkey incorrectly handled TLS connections
under certain conditions. A remote attacker could possibly use this issue to
cause Valkey to crash, resulting in a denial of service, or execute arbitrary
code. (CVE-2026-56684)
It was discovered that Valkey incorrectly handled certain stream RDB payloads
when executing the RESTORE command. An authenticated remote attacker could
possibly use this issue to cause Valkey to crash, resulting in a denial
of service, or execute arbitrary code. (CVE-2026-63639)
It was discovered that Valkey incorrectly handled cluster slot migration
operations. A remote attacker could possibly use this issue to cause Valkey
to crash, resulting in a denial of service. This issue was only addressed in
Ubuntu 26.04 LTS. (CVE-2026-85522)
6 days 3 hours ago
6 days 3 hours ago
6 days 3 hours ago
6 days 3 hours ago
6 days 3 hours ago
6 days 10 hours ago
FEDORA-2026-68e2c40a81
Packages in this update:
Update description:
Update to pcre-10.48
6 days 10 hours ago
FEDORA-2026-98f3f016c4
Packages in this update:
Update description:
Update to pcre-10.48
6 days 10 hours ago
FEDORA-2026-e9c6062c07
Packages in this update:
Update description:
Update to pcre-10.48
6 days 14 hours ago
Version:next-20260915 (linux-next)
Released:2026-09-15
6 days 15 hours ago
It was discovered that SimpleSAMLphp incorrectly validated cryptographic
signatures in XML messages. An authenticated attacker could possibly use
this issue to impersonate users or gain elevated privileges. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-3465)
It was discovered that SimpleSAMLphp incorrectly handled external entities
when parsing untrusted XML documents. A remote attacker could possibly use
this issue to obtain sensitive information. This issue did not affect
Ubuntu 24.04 LTS. (CVE-2024-52596)
It was discovered that SimpleSAMLphp incorrectly verified signatures in
SAML messages using the HTTP-Redirect binding. A remote attacker could
possibly use this issue to bypass authentication and impersonate users.
(CVE-2025-27773)
6 days 15 hours ago
It was discovered that phpseclib did not perform padding validation in
constant time when using AES in CBC mode. A remote attacker could possibly
use this issue to conduct a padding oracle timing attack and obtain
sensitive information.
6 days 15 hours ago
Florian Stuhlmann discovered that Shibboleth incorrectly escaped input
when using the ODBC storage plugin. A remote attacker could possibly use
this issue to perform SQL injection attacks and obtain sensitive
information.
6 days 16 hours ago
It was discovered that Snapcast incorrectly handled crafted JSON-RPC
requests. A remote attacker could possibly use this issue to execute
arbitrary code or obtain sensitive information.
6 days 16 hours ago
Guillem Lefait discovered that Suricata-Update did not properly validate
destination paths when extracting files referenced by downloaded rule
archives. An attacker could possibly use this issue to write arbitrary
files outside the configured rules directory.
6 days 16 hours ago
Cédric Krier discovered that python-sql incorrectly escaped values passed
to unary operators. An attacker could possibly use this issue to perform
SQL injection attacks.