Aggregator

USN-8699-1: libssh vulnerabilities

6 days 21 hours ago
It was discovered that libssh had a stack buffer overflow in its SFTP server when constructing directory listing entries for long filenames. An attacker could possibly use this issue to cause libssh to crash or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15370) It was discovered that libssh did not correctly handle SSH channel open messages advertising a zero maximum packet size. An authenticated remote attacker could possibly use this issue to cause libssh to consume excessive CPU resources, leading to a denial of service. (CVE-2026-59843) It was discovered that libssh did not correctly limit SFTP read request lengths in its server implementation. An authenticated remote attacker could possibly use this issue to cause libssh to allocate excessive memory, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-59844) It was discovered that libssh did not correctly handle ProxyCommand fork() failures. A local attacker could possibly use this issue to cause a denial of service. (CVE-2026-59845) It was discovered that libssh did not correctly sanitize shell metacharacters when expanding usernames in ProxyCommand strings. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-59846) It was discovered that libssh had incorrect AES-GCM tag verification when built with the OpenSSL backend. A machine-in-the-middle attacker could possibly use this issue to modify encrypted traffic without detection. (CVE-2026-59847) It was discovered that libssh did not correctly handle SFTP server responses for unknown request IDs. An attacker could possibly use this issue to cause libssh to use excessive memory, leading to a denial of service. (CVE-2026-59848) It was discovered that libssh had logic errors in certificate-based authentication that could cause clients to loop indefinitely when certificates were rejected. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-59849) It was discovered that libssh could invoke data callbacks on channels after they had been closed. An attacker could possibly use this issue to cause libssh to crash or execute arbitrary code. (CVE-2026-59850)

USN-8698-1: FreeRDP vulnerabilities

6 days 21 hours ago
It was discovered that FreeRDP contained multiple security issues. An attacker could possibly use these issues to obtain sensitive information, cause FreeRDP to crash, resulting in a denial of service, or execute arbitrary code.

USN-8697-1: GNU Core Utilities vulnerabilities

6 days 21 hours ago
It was discovered that GNU Core Utilities sort had a heap buffer under-read in its begfield() function. A local attacker could possibly use this issue to cause GNU Core Utilities to crash, resulting in a denial of service, or obtain sensitive information. (CVE-2025-5278) It was discovered that GNU Core Utilities uniq had an out-of-bounds read when the -w option was used with crafted multibyte input. A local attacker could possibly use this issue to cause GNU Core Utilities to crash, resulting in a denial of service, or obtain sensitive information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-56391)

USN-8696-1: Bind vulnerability

6 days 21 hours ago
It was discovered that Bind incorrectly handled DNSSEC validation when a domain was covered by both NSEC and NSEC3 records with only one type having an RRSIG. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service.

USN-8689-1: OpenJDK 26 vulnerabilities

1 week ago
It was discovered that the JSSE component of OpenJDK 26 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of OpenJDK 26 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-46917) It was discovered that the ImageIO component of OpenJDK 26 did not correctly authorize users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-47010) It was discovered that the 2D component of OpenJDK 26 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-47021, CVE-2026-47059) It was discovered that the Libraries component of OpenJDK 26 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-47027) It was discovered that the Security component of OpenJDK 26 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-60147) It was discovered that the Libraries component of OpenJDK 26 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-47063) Lian Owen discovered that the 2D (Little CMS) component of OpenJDK 26 did not correctly handle certain integer arithmetic. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-41254)

baresip-4.11.0-1.el8 libre-4.11.0-1.el8

1 week ago
FEDORA-EPEL-2026-baa01fe3db Packages in this update:
  • baresip-4.11.0-1.el8
  • libre-4.11.0-1.el8
Update description: Baresip v4.11.0 (2026-08-25)
  • core: cleanup stream_rtp_h ignore handling
  • audio: increase RTP timestamp also for underruns
  • aubuf: remove adaptive mode
  • webrtc_aec: fix system cmake include
  • call: avoid call progress if media is inactive
  • conf: remove unused conf_aubuf_adaptive()
  • audio: reuse mbuf for telephony events
  • call: add callback for incoming SIP INFO
  • test: check fixture error and fix call progress
  • aureceiver: fix return on error case in aurecv_start_player()
  • audio: fix warning() %d format in encode_rtp_send()
  • opus,aureceiver: fix PLC/FEC handling
  • l16: refactor NR_CODECS by RE_ARRAY_SIZE
  • config: remove unused config option audio_silence
  • echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)

baresip-4.11.0-1.el9 libre-4.11.0-1.el9

1 week ago
FEDORA-EPEL-2026-fe7f0afd86 Packages in this update:
  • baresip-4.11.0-1.el9
  • libre-4.11.0-1.el9
Update description: Baresip v4.11.0 (2026-08-25)
  • core: cleanup stream_rtp_h ignore handling
  • audio: increase RTP timestamp also for underruns
  • aubuf: remove adaptive mode
  • webrtc_aec: fix system cmake include
  • call: avoid call progress if media is inactive
  • conf: remove unused conf_aubuf_adaptive()
  • audio: reuse mbuf for telephony events
  • call: add callback for incoming SIP INFO
  • test: check fixture error and fix call progress
  • aureceiver: fix return on error case in aurecv_start_player()
  • audio: fix warning() %d format in encode_rtp_send()
  • opus,aureceiver: fix PLC/FEC handling
  • l16: refactor NR_CODECS by RE_ARRAY_SIZE
  • config: remove unused config option audio_silence
  • echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)

baresip-4.11.0-1.el10_2 libre-4.11.0-1.el10_2

1 week ago
FEDORA-EPEL-2026-cd90eb246c Packages in this update:
  • baresip-4.11.0-1.el10_2
  • libre-4.11.0-1.el10_2
Update description: Baresip v4.11.0 (2026-08-25)
  • core: cleanup stream_rtp_h ignore handling
  • audio: increase RTP timestamp also for underruns
  • aubuf: remove adaptive mode
  • webrtc_aec: fix system cmake include
  • call: avoid call progress if media is inactive
  • conf: remove unused conf_aubuf_adaptive()
  • audio: reuse mbuf for telephony events
  • call: add callback for incoming SIP INFO
  • test: check fixture error and fix call progress
  • aureceiver: fix return on error case in aurecv_start_player()
  • audio: fix warning() %d format in encode_rtp_send()
  • opus,aureceiver: fix PLC/FEC handling
  • l16: refactor NR_CODECS by RE_ARRAY_SIZE
  • config: remove unused config option audio_silence
  • echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)

baresip-4.11.0-1.el10_3 libre-4.11.0-1.el10_3

1 week ago
FEDORA-EPEL-2026-b83833c59a Packages in this update:
  • baresip-4.11.0-1.el10_3
  • libre-4.11.0-1.el10_3
Update description: Baresip v4.11.0 (2026-08-25)
  • core: cleanup stream_rtp_h ignore handling
  • audio: increase RTP timestamp also for underruns
  • aubuf: remove adaptive mode
  • webrtc_aec: fix system cmake include
  • call: avoid call progress if media is inactive
  • conf: remove unused conf_aubuf_adaptive()
  • audio: reuse mbuf for telephony events
  • call: add callback for incoming SIP INFO
  • test: check fixture error and fix call progress
  • aureceiver: fix return on error case in aurecv_start_player()
  • audio: fix warning() %d format in encode_rtp_send()
  • opus,aureceiver: fix PLC/FEC handling
  • l16: refactor NR_CODECS by RE_ARRAY_SIZE
  • config: remove unused config option audio_silence
  • echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)

baresip-4.11.0-1.el10_4 libre-4.11.0-1.el10_4

1 week ago
FEDORA-EPEL-2026-8250797b7b Packages in this update:
  • baresip-4.11.0-1.el10_4
  • libre-4.11.0-1.el10_4
Update description: Baresip v4.11.0 (2026-08-25)
  • core: cleanup stream_rtp_h ignore handling
  • audio: increase RTP timestamp also for underruns
  • aubuf: remove adaptive mode
  • webrtc_aec: fix system cmake include
  • call: avoid call progress if media is inactive
  • conf: remove unused conf_aubuf_adaptive()
  • audio: reuse mbuf for telephony events
  • call: add callback for incoming SIP INFO
  • test: check fixture error and fix call progress
  • aureceiver: fix return on error case in aurecv_start_player()
  • audio: fix warning() %d format in encode_rtp_send()
  • opus,aureceiver: fix PLC/FEC handling
  • l16: refactor NR_CODECS by RE_ARRAY_SIZE
  • config: remove unused config option audio_silence
  • echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)

baresip-4.11.0-1.fc43 libre-4.11.0-1.fc43

1 week ago
FEDORA-2026-3edf59885d Packages in this update:
  • baresip-4.11.0-1.fc43
  • libre-4.11.0-1.fc43
Update description: Baresip v4.11.0 (2026-08-25)
  • core: cleanup stream_rtp_h ignore handling
  • audio: increase RTP timestamp also for underruns
  • aubuf: remove adaptive mode
  • webrtc_aec: fix system cmake include
  • call: avoid call progress if media is inactive
  • conf: remove unused conf_aubuf_adaptive()
  • audio: reuse mbuf for telephony events
  • call: add callback for incoming SIP INFO
  • test: check fixture error and fix call progress
  • aureceiver: fix return on error case in aurecv_start_player()
  • audio: fix warning() %d format in encode_rtp_send()
  • opus,aureceiver: fix PLC/FEC handling
  • l16: refactor NR_CODECS by RE_ARRAY_SIZE
  • config: remove unused config option audio_silence
  • echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)

baresip-4.11.0-1.fc44 libre-4.11.0-1.fc44

1 week ago
FEDORA-2026-27c291e67c Packages in this update:
  • baresip-4.11.0-1.fc44
  • libre-4.11.0-1.fc44
Update description: Baresip v4.11.0 (2026-08-25)
  • core: cleanup stream_rtp_h ignore handling
  • audio: increase RTP timestamp also for underruns
  • aubuf: remove adaptive mode
  • webrtc_aec: fix system cmake include
  • call: avoid call progress if media is inactive
  • conf: remove unused conf_aubuf_adaptive()
  • audio: reuse mbuf for telephony events
  • call: add callback for incoming SIP INFO
  • test: check fixture error and fix call progress
  • aureceiver: fix return on error case in aurecv_start_player()
  • audio: fix warning() %d format in encode_rtp_send()
  • opus,aureceiver: fix PLC/FEC handling
  • l16: refactor NR_CODECS by RE_ARRAY_SIZE
  • config: remove unused config option audio_silence
  • echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)

baresip-4.11.0-1.fc45 libre-4.11.0-1.fc45

1 week ago
FEDORA-2026-c70f6e6ebc Packages in this update:
  • baresip-4.11.0-1.fc45
  • libre-4.11.0-1.fc45
Update description: Baresip v4.11.0 (2026-08-25)
  • core: cleanup stream_rtp_h ignore handling
  • audio: increase RTP timestamp also for underruns
  • aubuf: remove adaptive mode
  • webrtc_aec: fix system cmake include
  • call: avoid call progress if media is inactive
  • conf: remove unused conf_aubuf_adaptive()
  • audio: reuse mbuf for telephony events
  • call: add callback for incoming SIP INFO
  • test: check fixture error and fix call progress
  • aureceiver: fix return on error case in aurecv_start_player()
  • audio: fix warning() %d format in encode_rtp_send()
  • opus,aureceiver: fix PLC/FEC handling
  • l16: refactor NR_CODECS by RE_ARRAY_SIZE
  • config: remove unused config option audio_silence
  • echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)

baresip-4.11.0-1.fc46 libre-4.11.0-1.fc46

1 week ago
FEDORA-2026-3a803930eb Packages in this update:
  • baresip-4.11.0-1.fc46
  • libre-4.11.0-1.fc46
Update description: Baresip v4.11.0 (2026-08-25)
  • core: cleanup stream_rtp_h ignore handling
  • audio: increase RTP timestamp also for underruns
  • aubuf: remove adaptive mode
  • webrtc_aec: fix system cmake include
  • call: avoid call progress if media is inactive
  • conf: remove unused conf_aubuf_adaptive()
  • audio: reuse mbuf for telephony events
  • call: add callback for incoming SIP INFO
  • test: check fixture error and fix call progress
  • aureceiver: fix return on error case in aurecv_start_player()
  • audio: fix warning() %d format in encode_rtp_send()
  • opus,aureceiver: fix PLC/FEC handling
  • l16: refactor NR_CODECS by RE_ARRAY_SIZE
  • config: remove unused config option audio_silence
  • echo: refactor call_event_handler closed with bevent
libre v4.11.0 (2026-08-25)