Aggregator

aegisub-3.5.0-2.fc44

5 days 8 hours ago
FEDORA-2026-0c6d4471fc Packages in this update:
  • aegisub-3.5.0-2.fc44
Update description:

Update to Aegisub 3.5.0, fixing CVE-2026-92705: arbitrary code execution when opening crafted ASS subtitle files containing associated Automation script references. The fix requires confirmation before loading associated scripts, makes extension validation consistent with filesystem path interpretation, and sanitizes embedded NUL characters in project metadata. Upstream advisory: https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23

aegisub-3.5.0-1.fc45

5 days 8 hours ago
FEDORA-2026-d296db490c Packages in this update:
  • aegisub-3.5.0-1.fc45
Update description:

Update to Aegisub 3.5.0, fixing CVE-2026-92705: arbitrary code execution when opening crafted ASS subtitle files containing associated Automation script references. The fix requires confirmation before loading associated scripts, makes extension validation consistent with filesystem path interpretation, and sanitizes embedded NUL characters in project metadata. Upstream advisory: https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23

zabbix7.0-7.0.31-1.el10_3

5 days 8 hours ago
FEDORA-EPEL-2026-042a8bf4e4 Packages in this update:
  • zabbix7.0-7.0.31-1.el10_3
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

zabbix7.0-7.0.31-1.el10_4

5 days 8 hours ago
FEDORA-EPEL-2026-3e248bfcbd Packages in this update:
  • zabbix7.0-7.0.31-1.el10_4
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

zabbix7.0-7.0.31-1.el9

5 days 8 hours ago
FEDORA-EPEL-2026-0879abafaa Packages in this update:
  • zabbix7.0-7.0.31-1.el9
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

zabbix7.0-7.0.31-1.el8

5 days 8 hours ago
FEDORA-EPEL-2026-367fe24aeb Packages in this update:
  • zabbix7.0-7.0.31-1.el8
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

Update to 7.0.28

zabbix7.0-7.0.31-1.el10_2

5 days 8 hours ago
FEDORA-EPEL-2026-6aaa054bb4 Packages in this update:
  • zabbix7.0-7.0.31-1.el10_2
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

zabbix-6.0.48-1.el9

5 days 8 hours ago
FEDORA-EPEL-2026-d82469a549 Packages in this update:
  • zabbix-6.0.48-1.el9
Update description:

Update to 6.0.48 (CVE-2026-59782, CVE-2026-59785, CVE-2026-59787)

USN-8868-1: LibreOffice vulnerabilities

5 days 9 hours ago
It was discovered that LibreOffice incorrectly handled WMF image imports. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63272) It was discovered that LibreOffice incorrectly handled PDF document imports. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63273, CVE-2026-63274) It was discovered that LibreOffice incorrectly handled CFF fonts embedded in documents. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63275, CVE-2026-63276) It was discovered that LibreOffice incorrectly validated package URLs. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-63278) It was discovered that LibreOffice incorrectly handled PICT image imports. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or obtain sensitive information. (CVE-2026-63279) It was discovered that LibreOffice incorrectly mitigated out-of-bounds writes via Graphite font actions. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-50593)

avr-binutils-2.45-8.fc45

5 days 10 hours ago
FEDORA-2026-220bbf27df Packages in this update:
  • avr-binutils-2.45-8.fc45
Update description:
  • fix CVE-2026-19582: a potential buffer overflow in rsrc_resource_name (rhbz#2519351)

avr-binutils-2.45-8.fc44

5 days 10 hours ago
FEDORA-2026-bd6b3ee737 Packages in this update:
  • avr-binutils-2.45-8.fc44
Update description:
  • fix CVE-2026-19582: a potential buffer overflow in rsrc_resource_name (rhbz#2519351)

avr-binutils-2.45-8.fc43

5 days 10 hours ago
FEDORA-2026-5a5f49bc55 Packages in this update:
  • avr-binutils-2.45-8.fc43
Update description:
  • fix CVE-2026-19582: a potential buffer overflow in rsrc_resource_name (rhbz#2519351)

USN-8867-1: Ceph vulnerability

5 days 11 hours ago
It was discovered that the Ceph Object Gateway (RGW) SigV4 handler did not reject requests carrying x-amz-* headers that were absent from the signed header set. An attacker holding a presigned URL could possibly use this issue to attach arbitrary unsigned x-amz-* headers that RGW would honor, allowing them to escalate their privileges beyond what the URL's signer intended.

USN-8865-1: EDK II vulnerabilities

5 days 11 hours ago
It was discovered that EDK II incorrectly handled CMS key unwrapping in the embedded OpenSSL library. An attacker could possibly use this issue to cause a heap buffer overflow, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-63072) It was discovered that EDK II incorrectly handled CMP protection verification in the embedded OpenSSL library. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-63076) It was discovered that EDK II incorrectly buffered DTLS records in the embedded OpenSSL library. A remote attacker could possibly use this issue to cause EDK II to consume excessive memory, resulting in a denial of service. (CVE-2026-54874) It was discovered that EDK II incorrectly verified AEAD tags in the embedded OpenSSL library. An attacker could possibly use this issue to cause EDK II to accept forged messages. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-75803)