6 days 10 hours ago
It was discovered that Atril did not properly sanitize command-line
arguments in PDF /GoToR actions. If a user opened a specially crafted PDF
file, an attacker could possibly use this issue to execute arbitrary code.
(CVE-2026-46529)
It was discovered that Atril incorrectly handled certain PDF files. An
attacker could possibly use this issue to cause a denial of service or
to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2019-1010006)
Andy Nguyen discovered that Atril incorrectly handled certain images. An
attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 16.04 LTS. (CVE-2019-11459)
6 days 10 hours ago
It was discovered that catdoc had an integer overflow when processing
shared string tables in malformed spreadsheet files. An attacker could
possibly use this issue to cause catdoc to crash or execute arbitrary code.
(CVE-2024-48877)
It was discovered that catdoc had an integer overflow when processing file
allocation tables in malformed document files. An attacker could possibly
use this issue to cause catdoc to crash or execute arbitrary code.
(CVE-2024-52035)
It was discovered that catdoc incorrectly validated sector sizes when
processing malformed document files, leading to an integer underflow. An
attacker could possibly use this issue to cause catdoc to crash or execute
arbitrary code. (CVE-2024-54028)
6 days 11 hours ago
It was discovered that pdfminer did not safely parse specially crafted
PDF files. An attacker could possibly use these issues to execute
arbitrary code. (CVE-2025-64512, CVE-2025-70559)
6 days 11 hours ago
It was discovered that Emacs improperly handled specially crafted SVG
images, resulting in memory corruption. An attacker could possibly use
this issue to cause Emacs to crash, resulting in a denial of service, or
obtain sensitive information.
6 days 11 hours ago
It was discovered that Booth did not properly validate message
authentication codes under certain circumstances. A remote attacker
could possibly use this issue to bypass authentication.
6 days 11 hours ago
Version:next-20260928 (linux-next)
Released:2026-09-28
6 days 11 hours ago
It was discovered that phpseclib did not perform constant-time padding
validation when using AES in CBC mode. A remote attacker could possibly
use this issue to obtain sensitive information. (CVE-2026-32935)
It was discovered that phpseclib did not use a constant-time comparison
when validating SSH packet authentication codes. A remote attacker could
possibly use this issue to obtain sensitive information. (CVE-2026-40194)
It was discovered that phpseclib did not properly limit object identifier
lengths when parsing ASN.1 data. An attacker could possibly use this issue
to cause phpseclib to use excessive resources, leading to a denial of
service. (CVE-2026-44167)
6 days 12 hours ago
Fabian Vogt discovered that Plasma Workspace did not properly authenticate
local clients connecting to the session manager. A local attacker could
possibly use this issue to execute arbitrary code as another user.
6 days 12 hours ago
It was discovered that dracut created initramfs images with overly
permissive permissions under certain circumstances. A local attacker could
possibly use this issue to obtain sensitive information. This issue only
affected Ubuntu 16.04 LTS. (CVE-2016-8637)
It was discovered that dracut did not properly sanitize DHCP options
before writing them to shell scripts under certain circumstances. A remote
attacker controlling a DHCP server on the local network could possibly use
this issue to execute arbitrary code as root during system boot. This issue
only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-6893)
It was discovered that dracut did not properly quote error messages written
to shell scripts under certain circumstances. A remote attacker controlling
a DHCP server on the local network could possibly use this issue to execute
arbitrary code as root during system boot. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2026-15816)
It was discovered that dracut did not properly sanitize network
configuration data before writing it to a temporary shell script under
certain circumstances. A remote attacker controlling DHCP on the local
network could possibly use this issue to execute arbitrary code as root
during system boot. This issue only affected Ubuntu 22.04 LTS.
(CVE-2026-16445)
6 days 12 hours ago
It was discovered that the Erlang Port Mapper Daemon did not properly
handle slow connections. A remote attacker could possibly use this issue
to cause a denial of service. (CVE-2026-42792)
It was discovered that Erlang incorrectly handled certain external term
format data, leading to heap corruption. An attacker could possibly use
this issue to cause Erlang to crash, resulting in a denial of service.
This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-55737)
It was discovered that Erlang incorrectly handled invalid external term
format data. An attacker could possibly use this issue to cause Erlang to
crash, resulting in a denial of service. This issue only affected Ubuntu
26.04 LTS. (CVE-2026-54890)
It was discovered that Erlang incorrectly handled certain packet lengths,
leading to a buffer overflow. A remote attacker could possibly use this
issue to cause Erlang to crash or execute arbitrary code. (CVE-2026-75538)
It was discovered that the Erlang Megaco flex scanner incorrectly handled
certain input, leading to a buffer overflow. A remote attacker could
possibly use this issue to cause Erlang to crash or execute arbitrary code.
(CVE-2026-59250)
It was discovered that Erlang TLS clients incorrectly accepted cipher
suites that they had not offered. A remote attacker could possibly use
this issue to intercept and modify TLS communications. (CVE-2026-55953)
It was discovered that Erlang incorrectly handled certain certificate
chains. A remote attacker could possibly use this issue to cause Erlang to
use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-58227)
It was discovered that Erlang incorrectly handled certain certificate
policies. A remote attacker could possibly use this issue to cause Erlang
to use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-59251)
It was discovered that the Erlang HTTP server incorrectly handled certain
conflicting HTTP framing headers. A remote attacker could possibly use this
issue to smuggle HTTP requests. (CVE-2026-23941, CVE-2026-73812)
It was discovered that the Erlang HTTP server incorrectly handled certain
malformed chunk sizes. A remote attacker could possibly use this issue to
cause Erlang to crash, resulting in a denial of service. (CVE-2026-69664)
It was discovered that the Erlang HTTP server did not properly limit the
size of chunked request bodies. A remote attacker could possibly use this
issue to cause Erlang to use excessive resources, leading to a denial of
service. (CVE-2026-74835)
It was discovered that the Erlang HTTP server incorrectly handled certain
equivalent request paths and differences in character case. A remote
attacker could possibly use this issue to bypass authentication and gain
unauthorized access. (CVE-2026-66835, CVE-2026-73270)
It was discovered that the Erlang HTTP server did not properly limit
simultaneous connections. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-70399)
It was discovered that the Erlang HTTP server incorrectly handled header
continuation lines. A remote attacker could possibly use this issue to
smuggle HTTP requests. (CVE-2026-66357)
It was discovered that the Erlang HTTP server incorrectly handled certain
malformed header names. A remote attacker could possibly use this issue to
smuggle HTTP requests. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-73276)
It was discovered that the Erlang HTTP server incorrectly handled
incomplete request bodies. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
(CVE-2026-71380)
It was discovered that the Erlang HTTP client did not properly limit the
size of HTTP response headers. A malicious HTTP server could possibly use
this issue to cause Erlang to use excessive resources, leading to a denial
of service. (CVE-2026-55951)
It was discovered that Erlang did not properly limit the length of port
numbers when parsing URIs. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-59696)
It was discovered that the Erlang SNMP application did not properly limit
the size of certain integer values. A remote attacker could possibly use
this issue to cause Erlang to use excessive resources, leading to a denial
of service. (CVE-2026-70405)
It was discovered that the Erlang LDAP client did not properly limit the
length of port numbers in referral URLs. A malicious LDAP server could
possibly use this issue to cause Erlang to use excessive resources, leading
to a denial of service. (CVE-2026-70409)
6 days 12 hours ago
FEDORA-2026-203e30f5d8
Packages in this update:
- golang-x-mod-0.27.0-4.fc43
Update description:
Rebuild for security fixes
6 days 12 hours ago
FEDORA-2026-9626645a48
Packages in this update:
- golang-x-mod-0.28.0-5.fc44
Update description:
Rebuild for security fixes
6 days 13 hours ago
It was discovered that FreeRDP contained multiple security issues. An
attacker could possibly use these issues to obtain sensitive information,
cause FreeRDP to crash, resulting in a denial of service, or execute
arbitrary code.
6 days 13 hours ago
It was discovered that Exim had an out-of-bounds write when
Proxy-Protocol was used with an attacker-controlled proxy. A remote
attacker could possibly use this issue to execute arbitrary code.
(CVE-2026-94054)
It was discovered that Exim had a use-after-free when certain
non-default TLS settings were used with GnuTLS. A remote attacker
could possibly use this issue to cause Exim to crash, resulting in
a denial of service. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-94055)
It was discovered that Exim allowed attackers to read uninitialized
data from stack memory when Proxy-Protocol was used with an
attacker-controlled proxy. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2026-94056)
It was discovered that Exim allowed SMTP smuggling via crafted data
sent after a rejection during DATA processing. A remote attacker
could possibly use this issue to inject arbitrary email messages.
(CVE-2026-94057)
6 days 13 hours ago
It was discovered that libvirt did not properly validate newline characters
in DNS TXT record values and SRV record attributes in its virtual network
driver. A local attacker with permission to define virtual networks could
possibly use this issue to inject arbitrary dnsmasq configuration
directives, leading to arbitrary command execution as root.
(CVE-2026-61477)
It was discovered that libvirt did not properly handle errors during XML
context parsing. An attacker could possibly use this issue to cause libvirt
to crash, resulting in a denial of service. (CVE-2026-61478)
He Wei discovered that libvirt had a symlink-following vulnerability in the
file ownership change function used for virtual TPM state directories. A
local attacker running as the swtpm user could possibly use this issue to
cause libvirt to change the ownership of an arbitrary file, leading to
privilege escalation. (CVE-2026-63622)
It was discovered that libvirt created storage volume images with overly
permissive permissions during clone or convert operations. A local attacker
could possibly use this issue to read guest disk contents, resulting in
information disclosure. (CVE-2026-63623)
It was discovered that libvirt had an integer overflow in the
NodeGetFreePages RPC handler. A local attacker could possibly use this
issue to cause libvirt to crash or execute arbitrary code.
(CVE-2026-18917)
It was discovered that libvirt had a symlink-following flaw in the virtual
TPM emulator setup function. A local attacker with access to the swtpm
account could possibly use this issue to cause libvirt to change the
ownership of an arbitrary file, leading to privilege escalation.
(CVE-2026-77159)
6 days 14 hours ago
It was discovered that libvirt had an integer overflow vulnerability in
the NodeGetFreePages RPC handler. A local attacker could possibly use
this issue to cause a denial of service or execute arbitrary code.
(CVE-2026-18917)
It was discovered that libvirt did not correctly handle symbolic links
when changing ownership of the TPM emulator log file. A local attacker
with access to the swtpm account could possibly use this issue to cause libvirt
to change the ownership of an arbitrary file. (CVE-2026-77159)
6 days 14 hours ago
FEDORA-2026-e1cac11588
Packages in this update:
- xdg-dbus-proxy-0.1.9-1.fc43
Update description:
Update to 0.1.9
6 days 14 hours ago
FEDORA-2026-93f562a43f
Packages in this update:
- xdg-dbus-proxy-0.1.9-1.fc44
Update description:
Update to 0.1.9
6 days 14 hours ago
FEDORA-2026-f10257ca80
Packages in this update:
- xdg-dbus-proxy-0.1.9-1.fc45
Update description:
Update to 0.1.9
6 days 15 hours ago