Aggregator

chromium-153.0.8010.52-1.fc44

6 days 11 hours ago
FEDORA-2026-f910229c11 Packages in this update:
  • chromium-153.0.8010.52-1.fc44
Update description:

Update to 153.0.8010.52

  • CVE-2026-91708: Race condition in Network
  • CVE-2026-91709: Type confusion in ServiceWorker
  • CVE-2026-91710: Use after free in WebAppInstalls
  • CVE-2026-91711: Out of bounds write in ServiceWorker
  • CVE-2026-91712: Race condition in Extensions
  • CVE-2026-91713: Missing authorization in Browser
  • CVE-2026-91714: Observable discrepancy in Fonts
  • CVE-2026-91715: Type confusion in ServiceWorker
  • CVE-2026-91716: Use after free in Auth
  • CVE-2026-91717: Missing authorization in Android
  • CVE-2026-91718: Use after free in Core
  • CVE-2026-91719: Code injection in XML
  • CVE-2026-91720: Uninitialized resource in ANGLE
  • CVE-2026-91721: Use after free in Internals
  • CVE-2026-91722: Use after free in Input
  • CVE-2026-91723: Race condition in WebAppInstalls
  • CVE-2026-91724: Use after free in Input
  • CVE-2026-91725: Observable discrepancy in CSS
  • CVE-2026-91726: Out of bounds read in WebGL
  • CVE-2026-91727: Incorrect reference resolution in Extensions
  • CVE-2026-91728: Integer overflow in V8
  • CVE-2026-91729: Use after free in DigitalCredentials
  • CVE-2026-91730: Incomplete cleanup in GetUserMedia
  • CVE-2026-91731: Type confusion in Compositing
  • CVE-2026-91732: Missing authorization in AppManifest
  • CVE-2026-91733: Improper state validation in Skia
  • CVE-2026-91734: Incorrect authorization in Core
  • CVE-2026-91735: Incorrect authorization in WebUI
  • CVE-2026-91736: Use after free in DOM
  • CVE-2026-91737: Use after free in PDF
  • CVE-2026-91738: Improper input validation in ANGLE
  • CVE-2026-91739: Missing authorization in Transactions Platform
  • CVE-2026-91740: Uninitialized resource in Skia
  • CVE-2026-91741: Type confusion in CacheStorage
  • CVE-2026-91742: Confused deputy in PriceTracking
  • CVE-2026-91743: Race condition in Core
  • CVE-2026-91744: Race condition in PlatformIntegration
  • CVE-2026-91745: Use after free in V8
  • CVE-2026-91746: Integer overflow in Compositing
  • CVE-2026-91747: Use after free in Skia
  • CVE-2026-91748: Race condition in Extensions
  • CVE-2026-91749: Use after free in Workers
  • CVE-2026-93372: Buffer overflow in WebGL
  • CVE-2026-93373: Use after free in Extensions
  • CVE-2026-93374: Use after free in Dawn
  • CVE-2026-93375: Incorrect reference resolution in Tracing
  • CVE-2026-93376: Out of bounds read in DataTransfer
  • CVE-2026-93377: Type confusion in V8
  • CVE-2026-93378: Missing authorization in Storage
  • CVE-2026-93379: Incorrect authorization in ORB
  • CVE-2026-93380: Race condition in FileSystem
  • CVE-2026-93381: Buffer overflow in PDFium
  • CVE-2026-93382: Use after free in PDFium
  • CVE-2026-93383: Information leak in Permissions
  • CVE-2026-93384: Server-side request forgery in Omnibox
  • CVE-2026-93385: Information leak in Paint
  • CVE-2026-93386: UI misrepresentation in WebAppInstalls
  • CVE-2026-93387: Improper state validation in Skia

chromium-153.0.8010.52-1.el10_4

6 days 11 hours ago
FEDORA-EPEL-2026-ef33948ace Packages in this update:
  • chromium-153.0.8010.52-1.el10_4
Update description:

Update to 153.0.8010.52

  • CVE-2026-91708: Race condition in Network
  • CVE-2026-91709: Type confusion in ServiceWorker
  • CVE-2026-91710: Use after free in WebAppInstalls
  • CVE-2026-91711: Out of bounds write in ServiceWorker
  • CVE-2026-91712: Race condition in Extensions
  • CVE-2026-91713: Missing authorization in Browser
  • CVE-2026-91714: Observable discrepancy in Fonts
  • CVE-2026-91715: Type confusion in ServiceWorker
  • CVE-2026-91716: Use after free in Auth
  • CVE-2026-91717: Missing authorization in Android
  • CVE-2026-91718: Use after free in Core
  • CVE-2026-91719: Code injection in XML
  • CVE-2026-91720: Uninitialized resource in ANGLE
  • CVE-2026-91721: Use after free in Internals
  • CVE-2026-91722: Use after free in Input
  • CVE-2026-91723: Race condition in WebAppInstalls
  • CVE-2026-91724: Use after free in Input
  • CVE-2026-91725: Observable discrepancy in CSS
  • CVE-2026-91726: Out of bounds read in WebGL
  • CVE-2026-91727: Incorrect reference resolution in Extensions
  • CVE-2026-91728: Integer overflow in V8
  • CVE-2026-91729: Use after free in DigitalCredentials
  • CVE-2026-91730: Incomplete cleanup in GetUserMedia
  • CVE-2026-91731: Type confusion in Compositing
  • CVE-2026-91732: Missing authorization in AppManifest
  • CVE-2026-91733: Improper state validation in Skia
  • CVE-2026-91734: Incorrect authorization in Core
  • CVE-2026-91735: Incorrect authorization in WebUI
  • CVE-2026-91736: Use after free in DOM
  • CVE-2026-91737: Use after free in PDF
  • CVE-2026-91738: Improper input validation in ANGLE
  • CVE-2026-91739: Missing authorization in Transactions Platform
  • CVE-2026-91740: Uninitialized resource in Skia
  • CVE-2026-91741: Type confusion in CacheStorage
  • CVE-2026-91742: Confused deputy in PriceTracking
  • CVE-2026-91743: Race condition in Core
  • CVE-2026-91744: Race condition in PlatformIntegration
  • CVE-2026-91745: Use after free in V8
  • CVE-2026-91746: Integer overflow in Compositing
  • CVE-2026-91747: Use after free in Skia
  • CVE-2026-91748: Race condition in Extensions
  • CVE-2026-91749: Use after free in Workers
  • CVE-2026-93372: Buffer overflow in WebGL
  • CVE-2026-93373: Use after free in Extensions
  • CVE-2026-93374: Use after free in Dawn
  • CVE-2026-93375: Incorrect reference resolution in Tracing
  • CVE-2026-93376: Out of bounds read in DataTransfer
  • CVE-2026-93377: Type confusion in V8
  • CVE-2026-93378: Missing authorization in Storage
  • CVE-2026-93379: Incorrect authorization in ORB
  • CVE-2026-93380: Race condition in FileSystem
  • CVE-2026-93381: Buffer overflow in PDFium
  • CVE-2026-93382: Use after free in PDFium
  • CVE-2026-93383: Information leak in Permissions
  • CVE-2026-93384: Server-side request forgery in Omnibox
  • CVE-2026-93385: Information leak in Paint
  • CVE-2026-93386: UI misrepresentation in WebAppInstalls
  • CVE-2026-93387: Improper state validation in Skia

chromium-153.0.8010.52-1.fc43

6 days 11 hours ago
FEDORA-2026-dd12c89e57 Packages in this update:
  • chromium-153.0.8010.52-1.fc43
Update description:

Update to 153.0.8010.52

  • CVE-2026-91708: Race condition in Network
  • CVE-2026-91709: Type confusion in ServiceWorker
  • CVE-2026-91710: Use after free in WebAppInstalls
  • CVE-2026-91711: Out of bounds write in ServiceWorker
  • CVE-2026-91712: Race condition in Extensions
  • CVE-2026-91713: Missing authorization in Browser
  • CVE-2026-91714: Observable discrepancy in Fonts
  • CVE-2026-91715: Type confusion in ServiceWorker
  • CVE-2026-91716: Use after free in Auth
  • CVE-2026-91717: Missing authorization in Android
  • CVE-2026-91718: Use after free in Core
  • CVE-2026-91719: Code injection in XML
  • CVE-2026-91720: Uninitialized resource in ANGLE
  • CVE-2026-91721: Use after free in Internals
  • CVE-2026-91722: Use after free in Input
  • CVE-2026-91723: Race condition in WebAppInstalls
  • CVE-2026-91724: Use after free in Input
  • CVE-2026-91725: Observable discrepancy in CSS
  • CVE-2026-91726: Out of bounds read in WebGL
  • CVE-2026-91727: Incorrect reference resolution in Extensions
  • CVE-2026-91728: Integer overflow in V8
  • CVE-2026-91729: Use after free in DigitalCredentials
  • CVE-2026-91730: Incomplete cleanup in GetUserMedia
  • CVE-2026-91731: Type confusion in Compositing
  • CVE-2026-91732: Missing authorization in AppManifest
  • CVE-2026-91733: Improper state validation in Skia
  • CVE-2026-91734: Incorrect authorization in Core
  • CVE-2026-91735: Incorrect authorization in WebUI
  • CVE-2026-91736: Use after free in DOM
  • CVE-2026-91737: Use after free in PDF
  • CVE-2026-91738: Improper input validation in ANGLE
  • CVE-2026-91739: Missing authorization in Transactions Platform
  • CVE-2026-91740: Uninitialized resource in Skia
  • CVE-2026-91741: Type confusion in CacheStorage
  • CVE-2026-91742: Confused deputy in PriceTracking
  • CVE-2026-91743: Race condition in Core
  • CVE-2026-91744: Race condition in PlatformIntegration
  • CVE-2026-91745: Use after free in V8
  • CVE-2026-91746: Integer overflow in Compositing
  • CVE-2026-91747: Use after free in Skia
  • CVE-2026-91748: Race condition in Extensions
  • CVE-2026-91749: Use after free in Workers
  • CVE-2026-93372: Buffer overflow in WebGL
  • CVE-2026-93373: Use after free in Extensions
  • CVE-2026-93374: Use after free in Dawn
  • CVE-2026-93375: Incorrect reference resolution in Tracing
  • CVE-2026-93376: Out of bounds read in DataTransfer
  • CVE-2026-93377: Type confusion in V8
  • CVE-2026-93378: Missing authorization in Storage
  • CVE-2026-93379: Incorrect authorization in ORB
  • CVE-2026-93380: Race condition in FileSystem
  • CVE-2026-93381: Buffer overflow in PDFium
  • CVE-2026-93382: Use after free in PDFium
  • CVE-2026-93383: Information leak in Permissions
  • CVE-2026-93384: Server-side request forgery in Omnibox
  • CVE-2026-93385: Information leak in Paint
  • CVE-2026-93386: UI misrepresentation in WebAppInstalls
  • CVE-2026-93387: Improper state validation in Skia

chromium-153.0.8010.52-1.el10_2

6 days 11 hours ago
FEDORA-EPEL-2026-db43927aa0 Packages in this update:
  • chromium-153.0.8010.52-1.el10_2
Update description:

Update to 153.0.8010.52

  • CVE-2026-91708: Race condition in Network
  • CVE-2026-91709: Type confusion in ServiceWorker
  • CVE-2026-91710: Use after free in WebAppInstalls
  • CVE-2026-91711: Out of bounds write in ServiceWorker
  • CVE-2026-91712: Race condition in Extensions
  • CVE-2026-91713: Missing authorization in Browser
  • CVE-2026-91714: Observable discrepancy in Fonts
  • CVE-2026-91715: Type confusion in ServiceWorker
  • CVE-2026-91716: Use after free in Auth
  • CVE-2026-91717: Missing authorization in Android
  • CVE-2026-91718: Use after free in Core
  • CVE-2026-91719: Code injection in XML
  • CVE-2026-91720: Uninitialized resource in ANGLE
  • CVE-2026-91721: Use after free in Internals
  • CVE-2026-91722: Use after free in Input
  • CVE-2026-91723: Race condition in WebAppInstalls
  • CVE-2026-91724: Use after free in Input
  • CVE-2026-91725: Observable discrepancy in CSS
  • CVE-2026-91726: Out of bounds read in WebGL
  • CVE-2026-91727: Incorrect reference resolution in Extensions
  • CVE-2026-91728: Integer overflow in V8
  • CVE-2026-91729: Use after free in DigitalCredentials
  • CVE-2026-91730: Incomplete cleanup in GetUserMedia
  • CVE-2026-91731: Type confusion in Compositing
  • CVE-2026-91732: Missing authorization in AppManifest
  • CVE-2026-91733: Improper state validation in Skia
  • CVE-2026-91734: Incorrect authorization in Core
  • CVE-2026-91735: Incorrect authorization in WebUI
  • CVE-2026-91736: Use after free in DOM
  • CVE-2026-91737: Use after free in PDF
  • CVE-2026-91738: Improper input validation in ANGLE
  • CVE-2026-91739: Missing authorization in Transactions Platform
  • CVE-2026-91740: Uninitialized resource in Skia
  • CVE-2026-91741: Type confusion in CacheStorage
  • CVE-2026-91742: Confused deputy in PriceTracking
  • CVE-2026-91743: Race condition in Core
  • CVE-2026-91744: Race condition in PlatformIntegration
  • CVE-2026-91745: Use after free in V8
  • CVE-2026-91746: Integer overflow in Compositing
  • CVE-2026-91747: Use after free in Skia
  • CVE-2026-91748: Race condition in Extensions
  • CVE-2026-91749: Use after free in Workers
  • CVE-2026-93372: Buffer overflow in WebGL
  • CVE-2026-93373: Use after free in Extensions
  • CVE-2026-93374: Use after free in Dawn
  • CVE-2026-93375: Incorrect reference resolution in Tracing
  • CVE-2026-93376: Out of bounds read in DataTransfer
  • CVE-2026-93377: Type confusion in V8
  • CVE-2026-93378: Missing authorization in Storage
  • CVE-2026-93379: Incorrect authorization in ORB
  • CVE-2026-93380: Race condition in FileSystem
  • CVE-2026-93381: Buffer overflow in PDFium
  • CVE-2026-93382: Use after free in PDFium
  • CVE-2026-93383: Information leak in Permissions
  • CVE-2026-93384: Server-side request forgery in Omnibox
  • CVE-2026-93385: Information leak in Paint
  • CVE-2026-93386: UI misrepresentation in WebAppInstalls
  • CVE-2026-93387: Improper state validation in Skia

USN-8799-1: libssh2 vulnerabilities

6 days 14 hours ago
It was discovered that libssh2 incorrectly handled certain publickey subsystem attributes. A remote attacker controlling a malicious SSH server could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2026-58050) It was discovered that libssh2 did not properly initialize publickey list entries before parsing. A remote attacker controlling a malicious SSH server could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2026-58051) It was discovered that libssh2 incorrectly handled certain SFTP server responses. A remote attacker controlling an SSH server could use this issue to cause libssh2 to crash or possibly execute arbitrary code. (CVE-2026-66032) It was discovered that libssh2 did not properly check bounds in certain publickey subsystem responses. A remote attacker controlling a malicious SSH server could use this issue to cause a denial of service or possibly execute arbitrary code.. (CVE-2026-66034)

kernel-7.2.7-300.fc45

6 days 19 hours ago
FEDORA-2026-4c098c462e Packages in this update:
  • kernel-7.2.7-300.fc45
Update description:

The 7.2.7 stable kernel update contains a number of important fixes across the tree.

kernel-7.2.7-200.fc44

6 days 19 hours ago
FEDORA-2026-ca91e91bf0 Packages in this update:
  • kernel-7.2.7-200.fc44
Update description:

The 7.2.7 stable kernel update contains a number of important fixes across the tree.

kernel-7.2.7-100.fc43

6 days 19 hours ago
FEDORA-2026-8202400aa0 Packages in this update:
  • kernel-7.2.7-100.fc43
Update description:

The 7.2.7 stable kernel update contains a number of important fixes across the tree.

strongswan-6.1.0-1.fc45

6 days 23 hours ago
FEDORA-2026-5db1745c4f Packages in this update:
  • strongswan-6.1.0-1.fc45
Update description:
  • Update to 6.1.0 for CVE-2026-78123, CVE-2026-78124, CVE-2026-78126, CVE-2026-78127, CVE-2026-78129, CVE-2026-78130, CVE-2026-78131, CVE-2026-78132, CVE-2026-78133, CVE-2026-78134 and CVE-2026-78135

USN-8798-1: GStreamer Good Plugins vulnerabilities

1 week ago
It was discovered that GStreamer Good Plugins incorrectly parsed certain MRF files. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-18295, CVE-2026-18296) It was discovered that GStreamer Good Plugins incorrectly parsed certain PNG files. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-18298) DongHyeon Hwang discovered that GStreamer Good Plugins incorrectly handled certain RTP packets. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-18299)