Aggregator

USN-8737-1: GNU C Library vulnerabilities

1 week 1 day ago
It was discovered that GNU C Library had a buffer overflow in the strfmon function when handling right-justification padding. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-19499) It was discovered that GNU C Library had an out-of-bounds stack array access in the tdelete function. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-19542) It was discovered that GNU C Library incorrectly handled memory when calling wordexp with the WRDE_APPEND flag. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-6368) It was discovered that GNU C Library had a stack overflow in the wordexp function when expanding paths beginning with a tilde followed by a long username. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-6791) It was discovered that GNU C Library had a hang in the SHIFT_JISX0213 character set converter. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-77117) It was discovered that GNU C Library had a hang in the EUC_JISX0213 character set converter. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-80489)

USN-8736-1: Perl vulnerabilities

1 week 1 day ago
It was discovered that Perl incorrectly handled certain large inputs during regular expression matching. An attacker could possibly use this issue to trigger out-of-bounds heap reads or writes, resulting in a denial of service or arbitrary code execution. (CVE-2026-15534) It was discovered that Perl incorrectly handled certain regular expression containing alternative matching branches. An attacker could possibly use this issue to cause incorrect regular expression matches, resulting in security restrictions being bypassed. (CVE-2026-19487)

php-pecl-mongodb-1.20.1-3.el9

1 week 1 day ago
FEDORA-EPEL-2026-d6aefc999f Packages in this update:
  • php-pecl-mongodb-1.20.1-3.el9
Update description: Backported from 1.21.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
Backported from 1.21.7
  • PHPC-2745: Reject null bytes in namespaces and periods in database names [v1.21] by @GromNaN in #2059

php-pecl-mongodb-1.21.9-1.el10_2

1 week 1 day ago
FEDORA-EPEL-2026-99ac8d2816 Packages in this update:
  • php-pecl-mongodb-1.21.9-1.el10_2
Update description: Version 1.21.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
Version 1.21.7
  • PHPC-2745: Reject null bytes in namespaces and periods in database names [v1.21] by @GromNaN in #2059

php-pecl-mongodb2-2.1.9-1.fc44

1 week 1 day ago
FEDORA-2026-358d3ccdfe Packages in this update:
  • php-pecl-mongodb2-2.1.9-1.fc44
Update description: Version 2.1.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968

php-pecl-mongodb2-2.1.9-2.el10_2

1 week 1 day ago
FEDORA-EPEL-2026-7d7ac5f0f9 Packages in this update:
  • php-pecl-mongodb2-2.1.9-2.el10_2
Update description: Version 2.1.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968

php-pecl-mongodb2-2.1.9-1.fc43

1 week 1 day ago
FEDORA-2026-caf49a7828 Packages in this update:
  • php-pecl-mongodb2-2.1.9-1.fc43
Update description: Version 2.1.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968

roundcubemail-1.7.4-1.fc44

1 week 1 day ago
FEDORA-2026-38c637be37 Packages in this update:
  • roundcubemail-1.7.4-1.fc44
Update description: Release 1.7.4
  • Use X-Content-Type-Options:nosniff for attachment previews and downloads (#10308)
  • zipdownload: Fix attachment filename sanitisation of backslash and control characters (#10325)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

roundcubemail-1.7.4-1.fc45

1 week 1 day ago
FEDORA-2026-6ab831c1c5 Packages in this update:
  • roundcubemail-1.7.4-1.fc45
Update description: Release 1.7.4
  • Use X-Content-Type-Options:nosniff for attachment previews and downloads (#10308)
  • zipdownload: Fix attachment filename sanitisation of backslash and control characters (#10325)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

roundcubemail-1.6.19-1.el10_2

1 week 1 day ago
FEDORA-EPEL-2026-78f8bcff8a Packages in this update:
  • roundcubemail-1.6.19-1.el10_2
Update description: Release 1.6.19
  • Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

roundcubemail-1.6.19-1.fc43

1 week 1 day ago
FEDORA-2026-821349f438 Packages in this update:
  • roundcubemail-1.6.19-1.fc43
Update description: Release 1.6.19
  • Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

roundcubemail-1.6.19-1.el10_4

1 week 1 day ago
FEDORA-EPEL-2026-37f493ad5e Packages in this update:
  • roundcubemail-1.6.19-1.el10_4
Update description: Release 1.6.19
  • Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

roundcubemail-1.6.19-1.el10_3

1 week 1 day ago
FEDORA-EPEL-2026-d623f0849b Packages in this update:
  • roundcubemail-1.6.19-1.el10_3
Update description: Release 1.6.19
  • Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses