Aggregator

USN-8563-5: nginx vulnerability

5 days 21 hours ago
USN-8563-1 fixed vulnerabilities in nginx. The fix for CVE-2026-42533 was backed out in USN-8563-2 because it could cause a regression. This update includes a better fix for CVE-2026-42533. We apologize for the inconvenience. Original advisory details: It was discovered that nginx incorrectly handled certain map directives using regex matching and capture variables. A remote attacker could use this issue to cause nginx to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-42533) It was discovered that nginx had a use-after-free vulnerability in the ngx_http_ssi_module module when configured with Server-Side Includes, proxy_pass, and proxy buffering disabled directives. An attacker able to intercept traffic and control responses from an upstream server could possibly use this issue to cause nginx to crash, resulting in a denial of service. (CVE-2026-56434) It was discovered that nginx incorrectly handled certain requests in the ngx_http_slice_module module. A remote attacker could possibly use this issue to obtain sensitive information or cause nginx to crash, resulting in a denial of service. (CVE-2026-60005)

freeipmi-1.6.19-1.fc45

5 days 21 hours ago
FEDORA-2026-abe39f1809 Packages in this update:
  • freeipmi-1.6.19-1.fc45
Update description:

Updates to 1.6.19, also fixes CVE-2026-33554 CVE-2026-50031 CVE-2026-85504 CVE-2026-85505 CVE-2026-85506 CVE-2026-85507 CVE-2026-85508 CVE-2026-85509, and adds tmpfiles configs for image mode

perl-Net-DNS-1.57-1.el10_4

5 days 22 hours ago
FEDORA-EPEL-2026-0f5b361fa5 Packages in this update:
  • perl-Net-DNS-1.57-1.el10_4
Update description:

Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)

perl-Net-DNS-1.57-1.el10_3

5 days 22 hours ago
FEDORA-EPEL-2026-8a37d4d02f Packages in this update:
  • perl-Net-DNS-1.57-1.el10_3
Update description:

Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)

perl-Net-DNS-1.57-1.fc44

5 days 22 hours ago
FEDORA-2026-57f107ed83 Packages in this update:
  • perl-Net-DNS-1.57-1.fc44
Update description:

Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)

perl-Net-DNS-1.57-1.fc43

5 days 22 hours ago
FEDORA-2026-48a4531e02 Packages in this update:
  • perl-Net-DNS-1.57-1.fc43
Update description:

Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)

evolution-3.62.0-1.fc45 evolution-data-server-3.62.0-1.fc45 evolution-ews-3.62.0-1.fc45

5 days 23 hours ago
FEDORA-2026-5debc0de2b Packages in this update:
  • evolution-3.62.0-1.fc45
  • evolution-data-server-3.62.0-1.fc45
  • evolution-ews-3.62.0-1.fc45
Update description:

Update to 3.62.0

evolution-data-server

Bug Fixes:

  • I#660 - GOA EWS: Do not require OABUrl in autodiscover
  • I#662 - EBackend: Document how OAuth2 sources should ask to be authenticated (Tobias Mueller)
  • I#665 - CalDAV: Ignore Bad Request (400) on overwrite
  • M!243 - ESourceRegistry: Name the credentials source in failed-lookup debug message (Tobias Mueller)

Translations:

  • Alan Mortensen (da)
  • Aurimas Černius (lt)
  • Balázs Úr (hu)
  • Baurzhan Muftakhidinov (kk)
  • Emin Tufan Çetin (tr)
  • Juliano de Souza Camargo (pt_BR)
  • Kjartan Maraas (nb)
evolution

Bug Fixes:

  • I#3381 - Composer: De-duplicate inline images before send
  • I#3383 - junk-filters: Do not leak the child stdin pipe into concurrent spawns (Benjamin Herrenschmidt)
  • I#3386 - Default to not use read-only calendars for reminders and conflict search
  • I#3387 - EUIParser: Notify about accelerators moved by an action rename (Martin Monperrus (AI-assisted))
  • I#3388 - Mail: Validate clickable preview elements are generated by Evolution
  • M!235 - Mail: Remove deprecated SHA1 signature algorithm (Robin Haberkorn)

Miscellaneous:

  • docs: Add API index for newly added symbols in 3.62 for e-util

Translations:

  • Alan Mortensen (da)
  • Aurimas Černius (lt)
  • Balázs Úr (hu)
  • Baurzhan Muftakhidinov (kk)
  • burns (pt_BR)
  • Emin Tufan Çetin (tr)
  • Guillaume Bernard (fr)
  • Jiri Eischmann (cs)
  • Kjartan Maraas (nb)
evolution-ews

Bug Fixes:

  • M!18 - Add a per-folder coalescing gate for sync and refresh (Benjamin Herrenschmidt)
  • M!19 - camel: Do not save the folder summary in the subclass dispose (David Woodhouse)

Translations:

  • Alan Mortensen (da)
  • Balázs Úr (hu)
  • Jiri Eischmann (cs)
  • Kjartan Maraas (nb)