Aggregator

golang-x-mod-0.41.0-1.fc46

1 week ago
FEDORA-2026-f84c399b38 Packages in this update:
  • golang-x-mod-0.41.0-1.fc46
Update description:

Automatic update for golang-x-mod-0.41.0-1.fc46.

Changelog * Fri Sep 25 2026 Packit <hello@packit.dev> - 0.41.0-1 - Update to 0.41.0 upstream release - Resolves: rhbz#2486558 - Resolves: rhbz#2521732

ntfs-3g-2022.10.3-12.el9

1 week ago
FEDORA-EPEL-2026-1843885c69 Packages in this update:
  • ntfs-3g-2022.10.3-12.el9
Update description:

apply upstream patches to resolve NTFS-3G-SA_2026-06-1_20 NTFS-3G-SA_2026-06-1_19 NTFS-3G-SA_2026-06-1_12 NTFS-3G-SA_2026-06-1_11 NTFS-3G-SA_2026-06-1_10 NTFS-3G-SA_2026-06-1_08 NTFS-3G-SA_2026-06-1_07 NTFS-3G-SA_2026-06-1_05

Apply backported fixes for CVE-2026-42616 CVE-2026-42617 CVE-2026-42618 CVE-2026-46569 CVE-2026-46571 CVE-2026-46570 CVE-2026-46572 CVE-2026-56135 CVE-2026-56136

ntfs-3g-2026.9.18-1.el10_4

1 week ago
FEDORA-EPEL-2026-6769292d4a Packages in this update:
  • ntfs-3g-2026.9.18-1.el10_4
Update description:

Update to 2026.9.18. ntfs-3g changes:

  • Guard against multiple creator-owner and creator-group ACEs during ACL inheritance.
  • (ntfscat) Fix missing cleanup of opened attribute on error (issue #212).
  • Fix heap out of bounds read/write in ntfs_ie_add_vcn(). (GHSA-r6xj-6488-p8mv, CVE pending)
  • Fix heap data corruption in ntfs_mapping_pairs_decompress_i(). (GHSA-mc3c-983p-wqm8, CVE pending)
  • Fix heap buffer overflow in ntfs_external_attr_find(). (GHSA-wf3w-fjjg-x4w3, CVE pending)
  • Fix heap buffer overflow in ntfs_ea_check_wsldev(). (GHSA-2c97-47cr-9xr8, CVE pending)
  • Fix heap buffer overflow in ntfs_check_restart_area(). (GHSA-xrvx-6jrp-4q3x, CVE pending)
  • Fix denial-of-service in ntfs_inode_attach_all_extents(). (GHSA-jcjj-9262-6j6p, CVE pending)
  • Fix heap buffer overflow in ntfs_same_sid(). (GHSA-x98j-3g35-f59x, CVE pending)
  • Fix heap buffer overflow in ntfs_acl_owner(). (GHSA-pc48-m7cx-qf72, CVE pending) (ntfsresize)
  • Fix stale $MFTMirr data when the first extent of $MFT is relocated (issue #209).

Update to 2026.7.7 to fix: CVE-2026-42616 CVE-2026-42617 CVE-2026-42618 CVE-2026-46569 CVE-2026-46571 CVE-2026-46570 CVE-2026-46572 CVE-2026-56135 CVE-2026-56136

ntfs-3g-2026.9.18-1.fc46 ntfs-3g-system-compression-1.1-5.fc46 partclone-0.3.50-2.fc46 testdisk-7.2-9.fc46 wimlib-1.14.5-4.fc46

1 week ago
FEDORA-2026-a2beb6a664 Packages in this update:
  • ntfs-3g-2026.9.18-1.fc46
  • ntfs-3g-system-compression-1.1-5.fc46
  • partclone-0.3.50-2.fc46
  • testdisk-7.2-9.fc46
  • wimlib-1.14.5-4.fc46
Update description:

ntfs-3g changes:

Guard against multiple creator-owner and creator-group ACEs during ACL inheritance. (ntfscat) Fix missing cleanup of opened attribute on error (issue #212). Fix heap out of bounds read/write in ntfs_ie_add_vcn(). (GHSA-r6xj-6488-p8mv, CVE pending) Fix heap data corruption in ntfs_mapping_pairs_decompress_i(). (GHSA-mc3c-983p-wqm8, CVE pending) Fix heap buffer overflow in ntfs_external_attr_find(). (GHSA-wf3w-fjjg-x4w3, CVE pending) Fix heap buffer overflow in ntfs_ea_check_wsldev(). (GHSA-2c97-47cr-9xr8, CVE pending) Fix heap buffer overflow in ntfs_check_restart_area(). (GHSA-xrvx-6jrp-4q3x, CVE pending) Fix denial-of-service in ntfs_inode_attach_all_extents(). (GHSA-jcjj-9262-6j6p, CVE pending) Fix heap buffer overflow in ntfs_same_sid(). (GHSA-x98j-3g35-f59x, CVE pending) Fix heap buffer overflow in ntfs_acl_owner(). (GHSA-pc48-m7cx-qf72, CVE pending) (ntfsresize) Fix stale $MFTMirr data when the first extent of $MFT is relocated (issue #209).

USN-8729-5: Linux kernel (AWS FIPS) vulnerabilities

1 week ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - PowerPC architecture; - Compute Acceleration Framework; - Drivers core; - Bluetooth drivers; - Arm Firmware Framework for ARMv8-A(FFA); - EFI core; - GPU drivers; - Hardware monitoring drivers; - InfiniBand drivers; - Network drivers; - Microsoft Azure Network Adapter (MANA) driver; - SCSI subsystem; - SPI subsystem; - Network file systems library; - NTFS3 file system; - SMB network file system; - File systems infrastructure; - Software nodes and device properties; - Bluetooth subsystem; - Netfilter; - Tracing infrastructure; - io_uring subsystem; - IRQ subsystem; - KProbes tracing; - Memory management; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Networking core; - IPv4 networking; - IPv6 networking; - Multipath TCP; - Phonet protocol; - SMC sockets; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - Wireless networking; - Key management; - Linux Security Modules (LSM) Framework; - ALSA framework; - AudioScience HPI driver; (CVE-2025-71289, CVE-2026-23469, CVE-2026-31420, CVE-2026-31486, CVE-2026-31560, CVE-2026-46158, CVE-2026-46170, CVE-2026-46275, CVE-2026-46315, CVE-2026-52912, CVE-2026-52915, CVE-2026-52916, CVE-2026-52918, CVE-2026-52919, CVE-2026-52921, CVE-2026-52922, CVE-2026-52926, CVE-2026-52941, CVE-2026-53357, CVE-2026-64015, CVE-2026-64018, CVE-2026-64025, CVE-2026-64029, CVE-2026-64032, CVE-2026-64033, CVE-2026-64034, CVE-2026-64039, CVE-2026-64046, CVE-2026-64047, CVE-2026-64048, CVE-2026-64051, CVE-2026-64055, CVE-2026-64056, CVE-2026-64064, CVE-2026-64073, CVE-2026-64083, CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087, CVE-2026-64088, CVE-2026-64089, CVE-2026-64092, CVE-2026-64096, CVE-2026-64097, CVE-2026-64098, CVE-2026-64102, CVE-2026-64103, CVE-2026-64106, CVE-2026-64108, CVE-2026-64109, CVE-2026-64111, CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64116, CVE-2026-64118, CVE-2026-64121, CVE-2026-64125, CVE-2026-64126, CVE-2026-64127, CVE-2026-64128, CVE-2026-64133, CVE-2026-64134, CVE-2026-64135, CVE-2026-64136, CVE-2026-64137, CVE-2026-64138, CVE-2026-64144, CVE-2026-64147, CVE-2026-64148, CVE-2026-64153, CVE-2026-64155, CVE-2026-64163, CVE-2026-64165, CVE-2026-64166, CVE-2026-64168, CVE-2026-64170, CVE-2026-64173, CVE-2026-64174, CVE-2026-64177, CVE-2026-64178, CVE-2026-64179, CVE-2026-64180, CVE-2026-64182, CVE-2026-64183, CVE-2026-64184, CVE-2026-64185, CVE-2026-64214, CVE-2026-64217, CVE-2026-64218, CVE-2026-64219, CVE-2026-64220, CVE-2026-64221, CVE-2026-64225, CVE-2026-64231, CVE-2026-64518)

USN-8818-2: Linux kernel (IBM) vulnerabilities

1 week ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - exFAT file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - B.A.T.M.A.N. meshing protocol; - IPv4 networking; - IPv6 networking; - Netfilter; - RDS protocol; (CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)

USN-8819-2: Linux kernel vulnerabilities

1 week ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network file system (NFS) server daemon; - IPv6 networking; - Netfilter; (CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)

chromium-154.0.8037.57-1.el10_4

1 week ago
FEDORA-EPEL-2026-0004b04067 Packages in this update:
  • chromium-154.0.8037.57-1.el10_4
Update description:

Update to 154.0.8037.57

  • CVE-2026-95274: Improper output encoding in DevTools
  • CVE-2026-95275: Incorrect reference resolution in MediaStream
  • CVE-2026-95276: Improper input validation in Themes
  • CVE-2026-95277: Use after free in Views
  • CVE-2026-95278: Missing authorization in WakeLock
  • CVE-2026-95279: UI misrepresentation in Omnibox
  • CVE-2026-95280: Race condition in V8
  • CVE-2026-95281: Buffer overflow in ANGLE
  • CVE-2026-95282: Use after free in Platform
  • CVE-2026-95283: Buffer overflow in Tint
  • CVE-2026-95284: Buffer overflow in ANGLE
  • CVE-2026-95285: Missing authorization in WebView
  • CVE-2026-95286: Type confusion in Bindings
  • CVE-2026-95287: Missing authorization in Navigation
  • CVE-2026-95288: UI misrepresentation in Mobile
  • CVE-2026-95289: Incorrect authorization in Scroll
  • CVE-2026-95290: Missing authorization in NFC
  • CVE-2026-95291: UI misrepresentation in SecurityIndicators
  • CVE-2026-95292: Incorrect authorization in Safebrowsing
  • CVE-2026-95293: Uninitialized resource in GPU
  • CVE-2026-95294: UI misrepresentation in Browser
  • CVE-2026-95295: Information leak in Mobile
  • CVE-2026-95296: Missing authorization in Core
  • CVE-2026-95297: Missing authorization in Contextual Tasks
  • CVE-2026-95298: Use after free in Browser
  • CVE-2026-95299: Use after free in GPU
  • CVE-2026-95300: Missing authorization in DevTools
  • CVE-2026-95301: Missing authorization in Extensions
  • CVE-2026-95302: Incorrect authorization in WebAPKs
  • CVE-2026-95303: Incomplete cleanup in SmartCard
  • CVE-2026-95304: Out of bounds write in V8
  • CVE-2026-95305: UI misrepresentation in Chromoting
  • CVE-2026-95306: Type confusion in V8
  • CVE-2026-95307: UI misrepresentation in ExtensionsMenu
  • CVE-2026-95308: Integer overflow in Metrics
  • CVE-2026-95309: UI misrepresentation in Mobile
  • CVE-2026-95310: Use after free in AdFilter
  • CVE-2026-95311: Free of non-heap memory in Fonts
  • CVE-2026-95312: Information leak in Passwords
  • CVE-2026-95313: Use after free in Fullscreen
  • CVE-2026-95314: Incorrect authorization in HID
  • CVE-2026-95315: Use after free in Aura
  • CVE-2026-95316: Unchecked return value in Performance
  • CVE-2026-95317: Incorrect authorization in MediaCapture
  • CVE-2026-95318: Buffer overflow in Video
  • CVE-2026-95319: Use after free in Printing
  • CVE-2026-95320: Missing authorization in Navigation
  • CVE-2026-95321: UI misrepresentation in Payments
  • CVE-2026-95322: Out of bounds write in GPU
  • CVE-2026-95323: UI misrepresentation in Chromium
  • CVE-2026-95324: Uninitialized resource in GPU
  • CVE-2026-95325: Use after free in ANGLE
  • CVE-2026-95326: Incomplete cleanup in Bluetooth
  • CVE-2026-95327: Information leak in Networking
  • CVE-2026-95328: Confused deputy in Mobile
  • CVE-2026-95329: Out of bounds write in WebGL
  • CVE-2026-95330: Improper state validation in Downloads
  • CVE-2026-95331: Out of bounds write in ANGLE
  • CVE-2026-95332: Use of uninitialized variable in Tint
  • CVE-2026-95333: Use after free in Metrics
  • CVE-2026-95334: Incorrect reference resolution in WebProtect
  • CVE-2026-95335: Use after free in HID
  • CVE-2026-95336: Information leak in Transactions Platform
  • CVE-2026-95337: UI misrepresentation in Messages
  • CVE-2026-95338: Use after free in PDFium
  • CVE-2026-95339: Use after free in ServiceWorker
  • CVE-2026-95340: Incorrect authorization in PictureInPicture
  • CVE-2026-95341: Improper input validation in Desktop
  • CVE-2026-95342: Missing authorization in V8
  • CVE-2026-95343: Use after free in WebAudio
  • CVE-2026-95344: Race condition in DevTools
  • CVE-2026-95345: Use after free in Actor
  • CVE-2026-95346: UI misrepresentation in Chromoting
  • CVE-2026-95347: Use after free in Updater
  • CVE-2026-95348: Use after free in Bluetooth
  • CVE-2026-95349: Buffer overflow in WebGL
  • CVE-2026-95350: Buffer overflow in ANGLE
  • CVE-2026-95351: Use after free in Views
  • CVE-2026-95352: Incorrect authorization in DevTools
  • CVE-2026-95353: Use after free in Bindings
  • CVE-2026-95354: Use after free in Verifier
  • CVE-2026-95355: Incorrect authorization in Navigation
  • CVE-2026-95356: Use after free in WindowDialog
  • CVE-2026-95357: Out of bounds write in GPU
  • CVE-2026-95358: Incorrect authorization in Mobile
  • CVE-2026-95359: Uninitialized resource in GPU
  • CVE-2026-95360: Race condition in Editing
  • CVE-2026-95361: Confused deputy in DevTools
  • CVE-2026-95362: Cross-site request forgery in DevTools
  • CVE-2026-95363: UI misrepresentation in FileSystem
  • CVE-2026-95364: Improper input validation in Passwords
  • CVE-2026-95365: Type confusion in IndexedDB
  • CVE-2026-95366: Use of released resource in Core
  • CVE-2026-95367: Information leak in DataTransfer
  • CVE-2026-95368: Incorrect authorization in DevTools
  • CVE-2026-95369: Inappropriate implementation in XML
  • CVE-2026-95370: Inappropriate implementation in NFC
  • CVE-2026-95371: Missing authorization in Views
  • CVE-2026-95372: Use after free in Chromecast
  • CVE-2026-95373: Use after free in DevTools
  • CVE-2026-95374: Incorrect authorization in Network
  • CVE-2026-95375: Incorrect authorization in BrowserTag
  • CVE-2026-95376: Externally controlled reference in DevTools
  • CVE-2026-95380: Type confusion in V8
  • CVE-2026-95381: Improper input validation in Printing
  • CVE-2026-95382: Improper input validation in Auth
  • CVE-2026-95384: Race condition in Transactions Platform
  • CVE-2026-95385: Inappropriate implementation in PlatformIntegration