6 days 9 hours ago
FEDORA-EPEL-2026-a72ac31b48
Packages in this update:
- chromium-150.0.7871.128-1.el9
Update description:
Update to 150.0.7871.128
* CVE-2026-15899: Use after free in CameraCapture
* CVE-2026-15900: Use after free in GPU
* CVE-2026-15901: Use after free in Network
* CVE-2026-15902: Use after free in Cast
* CVE-2026-15903: Out of bounds read and write in V8
* CVE-2026-15904: Use after free in Ozone
* CVE-2026-15905: Use after free in Aura
6 days 9 hours ago
FEDORA-EPEL-2026-81064cea8f
Packages in this update:
- chromium-150.0.7871.128-1.el10_2
Update description:
Update to 150.0.7871.128
* CVE-2026-15899: Use after free in CameraCapture
* CVE-2026-15900: Use after free in GPU
* CVE-2026-15901: Use after free in Network
* CVE-2026-15902: Use after free in Cast
* CVE-2026-15903: Out of bounds read and write in V8
* CVE-2026-15904: Use after free in Ozone
* CVE-2026-15905: Use after free in Aura
6 days 9 hours ago
FEDORA-2026-ac712bf651
Packages in this update:
- chromium-150.0.7871.128-1.fc43
Update description:
Update to 150.0.7871.128
* CVE-2026-15899: Use after free in CameraCapture
* CVE-2026-15900: Use after free in GPU
* CVE-2026-15901: Use after free in Network
* CVE-2026-15902: Use after free in Cast
* CVE-2026-15903: Out of bounds read and write in V8
* CVE-2026-15904: Use after free in Ozone
* CVE-2026-15905: Use after free in Aura
6 days 11 hours ago
FEDORA-EPEL-2026-b847a0b309
Packages in this update:
Update description:
Version 6.9.5
Security updates
- A facilitated SQL injection issue
- A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
6 days 11 hours ago
FEDORA-EPEL-2026-224c06e2c7
Packages in this update:
Update description:
Version 6.9.5
Security updates
- A facilitated SQL injection issue
- A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
6 days 11 hours ago
FEDORA-2026-46346e9637
Packages in this update:
Update description:
Version 6.9.5
Security updates
- A facilitated SQL injection issue
- A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
6 days 11 hours ago
FEDORA-2026-2b8250197a
Packages in this update:
Update description:
Version 6.9.5
Security updates
- A facilitated SQL injection issue
- A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
6 days 12 hours ago
FEDORA-EPEL-2026-604236f7b8
Packages in this update:
Update description:
Version 7.0.2
Security updates
- A facilitated SQL injection issue
- A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
6 days 12 hours ago
FEDORA-EPEL-2026-6fe04abf84
Packages in this update:
Update description:
Backport upstream fixes for CVE-2023-52890 and CVE-2026-40706.
6 days 12 hours ago
FEDORA-EPEL-2026-ede554e3f3
Packages in this update:
- ntfs-3g-2022.10.3-10.el10_2
Update description:
Backport upstream fix for CVE-2026-40706.
6 days 13 hours ago
6 days 16 hours ago
FEDORA-2026-336f10ee31
Packages in this update:
Update description:
The 7.1.4-101/201 stable kernel update contains a fix for a rather important security issue with net/can.
6 days 16 hours ago
FEDORA-2026-eb0b86b6f9
Packages in this update:
Update description:
The 7.1.4-101/201 stable kernel update contains a fix for a rather important security issue with net/can.
6 days 18 hours ago
It was discovered that ImageMagick did not limit mutual references between
MVG files. An attacker could possibly use this issue to cause a stack
overflow, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu
22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2025-68950)
It was discovered that the ImageMagick MSL coder destroyed a cloned image
twice when an MSL script failed. An attacker could possibly use this issue
to cause a use-after-free, resulting in a denial of service, or arbitrary
code execution. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04
LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04
LTS. (CVE-2026-28688)
It was discovered that the ImageMagick VIFF image encoder did not properly
validate the packet count, leading to an integer overflow on 32-bit
systems. An attacker could possibly use this issue to cause an out-of-
bounds heap write, resulting in a denial of service. (CVE-2026-33900)
It was discovered that ImageMagick did not properly handle the column
offset when sampling an image. An attacker could possibly use this issue to
cause ImageMagick to read out of bounds, resulting in a denial of service.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-33905)
6 days 19 hours ago
USN-8563-1 fixed vulnerabilities in nginx. One of the fixes introduced ABI
changes that could cause issues with external modules. This update reverts
the fix for CVE-2026-42533 pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that nginx incorrectly handled certain map directives
using regex matching and capture variables. A remote attacker could use
this issue to cause nginx to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2026-42533)
It was discovered that nginx had a use-after-free vulnerability in the
ngx_http_ssi_module module when configured with Server-Side Includes,
proxy_pass, and proxy buffering disabled directives. An attacker able to
intercept traffic and control responses from an upstream server could
possibly use this issue to cause nginx to crash, resulting in a denial of
service. (CVE-2026-56434)
It was discovered that nginx incorrectly handled certain requests in the
ngx_http_slice_module module. A remote attacker could possibly use this
issue to obtain sensitive information or cause nginx to crash, resulting
in a denial of service. (CVE-2026-60005)
6 days 20 hours ago
FEDORA-2026-d1cd8e3d25
Packages in this update:
- nginx-1.30.4-1.fc45
- nginx-mod-brotli-1.0.0~rc-13.fc45
- nginx-mod-fancyindex-0.6.0-8.fc45
- nginx-mod-headers-more-0.40-3.fc45
- nginx-mod-js-challenge-0^20230517.gitda6852d-11.fc45
- nginx-mod-modsecurity-1.0.4-16.fc45
- nginx-mod-naxsi-1.6-21.fc45
- nginx-mod-vts-0.2.4-13.fc45
Update description:
nginx-mod-fancyindex:
Rebuild for 1.30.4
nginx-mod-modsecurity:
Rebuild for 1.30.4
nginx-mod-naxsi:
Rebuild for 1.30.4
nginx-mod-headers-more:
Rebuild for 1.30.4
nginx-mod-brotli:
Rebuild for 1.30.4
nginx-mod-js-challenge:
Rebuild for 1.30.4
nginx-mod-vts:
Rebuild for 1.30.4
nginx:
update to 1.30.4
fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
6 days 21 hours ago
It was discovered that libde265 did not properly manage memory under
certain circumstances. An attacker could possibly use this issue to
cause libde265 to crash, resulting in a denial of service. This issue
only affected Ubuntu 22.04 LTS. (CVE-2023-51792)
It was discovered that libde265 did not properly handle certain
malformed media files, leading to a heap buffer overflow. An attacker
could possibly use this issue to cause libde265 to crash, resulting in
a denial of service. (CVE-2024-38949, CVE-2024-38950)
It was discovered that libde265 did not properly handle certain
malformed input, leading to a segmentation fault. An attacker could
possibly use this issue to cause libde265 to crash, resulting in a
denial of service. (CVE-2025-61147)
It was discovered that libde265 did not properly handle a malformed
H.265 PPS NAL unit, leading to a segmentation fault. An attacker could
possibly use this issue to cause libde265 to crash, resulting in a
denial of service. (CVE-2026-33164)
It was discovered that libde265 did not properly handle certain
crafted HEVC bitstreams, leading to an out-of-bounds write. An attacker
could possibly use this issue to cause libde265 to crash, resulting in
a denial of service. (CVE-2026-33165)
Valentin Mercier discovered that libde265 did not properly validate
tile geometry when handling crafted media files, leading to an
out-of-bounds read. An attacker could possibly use this issue to cause
libde265 to crash, resulting in a denial of service, or to obtain
sensitive information. (CVE-2026-45382)
It was discovered that libde265 did not properly validate certain
values when decoding crafted media files, leading to an out-of-bounds
read. An attacker could possibly use this issue to cause libde265 to
crash, resulting in a denial of service, or to obtain sensitive
information. (CVE-2026-45383)
Ying Dong discovered that libde265 did not properly validate reference
picture set entries when handling a crafted H.265 bitstream, leading to
an out-of-bounds write. An attacker could possibly use this issue to
cause libde265 to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2026-49295)
Ying Dong discovered that libde265 did not properly manage memory when
handling a crafted sequence of H.265 NAL units, leading to excessive
memory consumption. An attacker could possibly use this issue to cause
libde265 to use excessive resources, leading to a denial of service.
(CVE-2026-49337)
Ying Dong discovered that libde265 did not properly handle certain
crafted H.265 bitstreams with large dimensions, leading to a heap
buffer overflow. An attacker could possibly use this issue to cause
libde265 to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2026-49346)
It was discovered that libde265 did not properly handle certain crafted
HEVC bitstreams with large dimensions, leading to an out-of-bounds
read and write. An attacker could possibly use this issue to cause
libde265 to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2026-54240)
It was discovered that libde265 did not properly handle certain crafted
HEVC bitstreams with large dimensions, leading to a heap buffer
overflow. An attacker could possibly use this issue to cause libde265
to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2026-54241)
6 days 21 hours ago
It was discovered that Wget did not properly validate the IP address
provided in an FTP PASV response when operating in FTP passive mode. A
remote attacker controlling a malicious FTP server, or an HTTP server
that redirects to an FTP URL, could possibly use this issue to redirect
Wget's data connection to an arbitrary address and perform server-side
request forgery, potentially accessing localhost services or internal
network resources.
6 days 21 hours ago
Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server
incorrectly handled certain memory operations in mod_authn_socache. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2026-33007)
Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache
HTTP Server had an HTTP response splitting vulnerability in multiple
modules when used with untrusted or compromised backend servers. An
attacker could possibly use this issue to inject arbitrary HTTP headers.
(CVE-2026-33523)
Elhanan Haenel discovered that Apache HTTP Server incorrectly handled
certain memory operations in mod_proxy_ajp. A remote attacker could
possibly use this issue to cause a denial of service. (CVE-2026-33857)
Tianshuo Han and Jérôme Djouder discovered that Apache HTTP Server
incorrectly handled certain string operations in mod_proxy_ajp. A remote
attacker could possibly use this issue to obtain sensitive information.
(CVE-2026-34032)
It was discovered that Apache HTTP Server's mod_proxy_html module
incorrectly handled certain content from an untrusted backend. A remote
attacker could possibly use this issue to cause a denial of service.
(CVE-2026-34355)
It was discovered that Apache HTTP Server incorrectly handled
ProxyPassReverseCookie directives with a malicious backend server. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2026-34356)
It was discovered that Apache HTTP Server's mod_dav_fs module incorrectly
handled certain path operations. An authenticated user could possibly use
this issue to manipulate trusted WebDAV property databases or cause a
denial of service. (CVE-2026-42535)
It was discovered that Apache HTTP Server's mod_xml2enc module incorrectly
handled certain content from an untrusted backend. A remote attacker could
possibly use this issue to cause a denial of service. (CVE-2026-42536)
It was discovered that Apache HTTP Server incorrectly handled response
headers when multiple content languages were configured. A remote
attacker could possibly use this issue to obtain sensitive information.
(CVE-2026-43951)
It was discovered that Apache HTTP Server incorrectly restricted certain
file functions in expressions within .htaccess files. A local attacker
with .htaccess write access could possibly use this issue to obtain
sensitive information. (CVE-2026-44119)
It was discovered that Apache HTTP Server's mod_ssl module incorrectly
handled OCSP responses from an attacker-controlled server. A remote
attacker could possibly use this issue to obtain sensitive information or
cause a denial of service. (CVE-2026-44185)
It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled responses from an attacker-controlled backend FTP
server. A remote attacker could possibly use this issue to cause a denial
of service. (CVE-2026-44186)
It was discovered that Apache HTTP Server incorrectly handled crafted
regular expressions in the server configuration. An attacker could
possibly use this issue to execute arbitrary code or cause a denial of
service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and
Ubuntu 20.04 LTS. (CVE-2026-44631)
It was discovered that Apache HTTP Server's mod_http2 module had a
use-after-free vulnerability when file handles were exhausted. A remote
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 20.04 LTS. (CVE-2026-48913)
1 week ago
FEDORA-2026-1c5ffc6018
Packages in this update:
Update description:
1.651 bump - Fix CVE-2026-15043, CVE-2026-15392, CVE-2026-60082 and CVE-2026-60081