Aggregator

mongo-c-driver-2.5.2-1.el10_4

1 week ago
FEDORA-EPEL-2026-9df5c5ffc2 Packages in this update:
  • mongo-c-driver-2.5.2-1.el10_4
Update description: libmongoc 2.5.2

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963
libmongoc 2.5.1

Fixes

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81524)
libmongoc 2.5.0

New Features

  • Honor the server-supplied baseBackoffMS on responses labeled SystemOverloadedError, using it in place of the driver's default base delay when calculating how long to wait before retrying.
  • Add collection bulk write getters.

mongo-c-driver-2.5.2-1.fc45

1 week ago
FEDORA-2026-83792d666c Packages in this update:
  • mongo-c-driver-2.5.2-1.fc45
Update description: libmongoc 2.5.2

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963
libmongoc 2.5.1

Fixes

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81524)

libmongocrypt-1.20.4-1.el10_3

1 week ago
FEDORA-EPEL-2026-52df07119c Packages in this update:
  • libmongocrypt-1.20.4-1.el10_3
Update description: Version 1.20.4

Fixed

  • Reject undersized decryption payloads. CVE-2026-84971
Version 1.20.3

Fixed

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81523).

libmongocrypt-1.20.4-1.el10_4

1 week ago
FEDORA-EPEL-2026-20b328f827 Packages in this update:
  • libmongocrypt-1.20.4-1.el10_4
Update description: Version 1.20.4

Fixed

  • Reject undersized decryption payloads. CVE-2026-84971
Version 1.20.3

Fixed

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81523).

libmongocrypt-1.20.4-1.fc45

1 week ago
FEDORA-2026-0664f1b41b Packages in this update:
  • libmongocrypt-1.20.4-1.fc45
Update description: Version 1.20.4

Fixed

  • Reject undersized decryption payloads. CVE-2026-84971
Version 1.20.3

Fixed

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81523).

chromium-152.0.7977.75-1.el10_3

1 week ago
FEDORA-EPEL-2026-75f4754ad0 Packages in this update:
  • chromium-152.0.7977.75-1.el10_3
Update description:
  • Update to 152.0.7977.75

  • CVE-2026-84353: Use after free in Shared Tab Groups

  • CVE-2026-84352: Use after free in WebGL
  • CVE-2026-84354: Incorrect authorization in FileSystem
  • CVE-2026-84359: Information leak in Skia
  • CVE-2026-84357: Improper input validation in Omnibox
  • CVE-2026-84324: Use after free in Proxy
  • CVE-2026-84349: Use after free in Browser
  • CVE-2026-84326: Uninitialized resource in V8
  • CVE-2026-84333: Use after free in Dawn
  • CVE-2026-84351: Buffer overflow in GPU
  • CVE-2026-84325: Improper input validation in DataTransfer
  • CVE-2026-84328: Missing authorization in FileSystem
  • CVE-2026-84347: Use after free in WebRTC
  • CVE-2026-84323: Missing authorization in FileSystem
  • CVE-2026-84355: Incorrect authorization in Navigation
  • CVE-2026-84358: Improper privilege management in Downloads
  • CVE-2026-84332: Incorrect authorization in SiteSettings
  • CVE-2026-84330: UI misrepresentation in FullScreen
  • CVE-2026-84334: Incorrect authorization in Chromoting
  • CVE-2026-84348: Information leak in MediaCapture
  • CVE-2026-84335: Incorrect authorization in TabStrip
  • CVE-2026-84327: Incorrect authorization in Autofill
  • CVE-2026-84329: Confused deputy in CredentialProvider
  • CVE-2026-84356: UI misrepresentation in FullScreen
  • CVE-2026-84350: Use after free in TabStrip
  • CVE-2026-84331: Incorrect authorization in Actor

chromium-152.0.7977.75-1.el10_2

1 week ago
FEDORA-EPEL-2026-8b6c578bd3 Packages in this update:
  • chromium-152.0.7977.75-1.el10_2
Update description:
  • Update to 152.0.7977.75

  • CVE-2026-84353: Use after free in Shared Tab Groups

  • CVE-2026-84352: Use after free in WebGL
  • CVE-2026-84354: Incorrect authorization in FileSystem
  • CVE-2026-84359: Information leak in Skia
  • CVE-2026-84357: Improper input validation in Omnibox
  • CVE-2026-84324: Use after free in Proxy
  • CVE-2026-84349: Use after free in Browser
  • CVE-2026-84326: Uninitialized resource in V8
  • CVE-2026-84333: Use after free in Dawn
  • CVE-2026-84351: Buffer overflow in GPU
  • CVE-2026-84325: Improper input validation in DataTransfer
  • CVE-2026-84328: Missing authorization in FileSystem
  • CVE-2026-84347: Use after free in WebRTC
  • CVE-2026-84323: Missing authorization in FileSystem
  • CVE-2026-84355: Incorrect authorization in Navigation
  • CVE-2026-84358: Improper privilege management in Downloads
  • CVE-2026-84332: Incorrect authorization in SiteSettings
  • CVE-2026-84330: UI misrepresentation in FullScreen
  • CVE-2026-84334: Incorrect authorization in Chromoting
  • CVE-2026-84348: Information leak in MediaCapture
  • CVE-2026-84335: Incorrect authorization in TabStrip
  • CVE-2026-84327: Incorrect authorization in Autofill
  • CVE-2026-84329: Confused deputy in CredentialProvider
  • CVE-2026-84356: UI misrepresentation in FullScreen
  • CVE-2026-84350: Use after free in TabStrip
  • CVE-2026-84331: Incorrect authorization in Actor

chromium-152.0.7977.75-1.fc44

1 week ago
FEDORA-2026-d805461e31 Packages in this update:
  • chromium-152.0.7977.75-1.fc44
Update description:
  • Update to 152.0.7977.75

  • CVE-2026-84353: Use after free in Shared Tab Groups

  • CVE-2026-84352: Use after free in WebGL
  • CVE-2026-84354: Incorrect authorization in FileSystem
  • CVE-2026-84359: Information leak in Skia
  • CVE-2026-84357: Improper input validation in Omnibox
  • CVE-2026-84324: Use after free in Proxy
  • CVE-2026-84349: Use after free in Browser
  • CVE-2026-84326: Uninitialized resource in V8
  • CVE-2026-84333: Use after free in Dawn
  • CVE-2026-84351: Buffer overflow in GPU
  • CVE-2026-84325: Improper input validation in DataTransfer
  • CVE-2026-84328: Missing authorization in FileSystem
  • CVE-2026-84347: Use after free in WebRTC
  • CVE-2026-84323: Missing authorization in FileSystem
  • CVE-2026-84355: Incorrect authorization in Navigation
  • CVE-2026-84358: Improper privilege management in Downloads
  • CVE-2026-84332: Incorrect authorization in SiteSettings
  • CVE-2026-84330: UI misrepresentation in FullScreen
  • CVE-2026-84334: Incorrect authorization in Chromoting
  • CVE-2026-84348: Information leak in MediaCapture
  • CVE-2026-84335: Incorrect authorization in TabStrip
  • CVE-2026-84327: Incorrect authorization in Autofill
  • CVE-2026-84329: Confused deputy in CredentialProvider
  • CVE-2026-84356: UI misrepresentation in FullScreen
  • CVE-2026-84350: Use after free in TabStrip
  • CVE-2026-84331: Incorrect authorization in Actor

chromium-152.0.7977.75-1.fc43

1 week ago
FEDORA-2026-ee60d45695 Packages in this update:
  • chromium-152.0.7977.75-1.fc43
Update description:
  • Update to 152.0.7977.75

  • CVE-2026-84353: Use after free in Shared Tab Groups

  • CVE-2026-84352: Use after free in WebGL
  • CVE-2026-84354: Incorrect authorization in FileSystem
  • CVE-2026-84359: Information leak in Skia
  • CVE-2026-84357: Improper input validation in Omnibox
  • CVE-2026-84324: Use after free in Proxy
  • CVE-2026-84349: Use after free in Browser
  • CVE-2026-84326: Uninitialized resource in V8
  • CVE-2026-84333: Use after free in Dawn
  • CVE-2026-84351: Buffer overflow in GPU
  • CVE-2026-84325: Improper input validation in DataTransfer
  • CVE-2026-84328: Missing authorization in FileSystem
  • CVE-2026-84347: Use after free in WebRTC
  • CVE-2026-84323: Missing authorization in FileSystem
  • CVE-2026-84355: Incorrect authorization in Navigation
  • CVE-2026-84358: Improper privilege management in Downloads
  • CVE-2026-84332: Incorrect authorization in SiteSettings
  • CVE-2026-84330: UI misrepresentation in FullScreen
  • CVE-2026-84334: Incorrect authorization in Chromoting
  • CVE-2026-84348: Information leak in MediaCapture
  • CVE-2026-84335: Incorrect authorization in TabStrip
  • CVE-2026-84327: Incorrect authorization in Autofill
  • CVE-2026-84329: Confused deputy in CredentialProvider
  • CVE-2026-84356: UI misrepresentation in FullScreen
  • CVE-2026-84350: Use after free in TabStrip
  • CVE-2026-84331: Incorrect authorization in Actor

chromium-152.0.7977.75-1.el9

1 week ago
FEDORA-EPEL-2026-8b1140c82b Packages in this update:
  • chromium-152.0.7977.75-1.el9
Update description:
  • Update to 152.0.7977.75

  • CVE-2026-84353: Use after free in Shared Tab Groups

  • CVE-2026-84352: Use after free in WebGL
  • CVE-2026-84354: Incorrect authorization in FileSystem
  • CVE-2026-84359: Information leak in Skia
  • CVE-2026-84357: Improper input validation in Omnibox
  • CVE-2026-84324: Use after free in Proxy
  • CVE-2026-84349: Use after free in Browser
  • CVE-2026-84326: Uninitialized resource in V8
  • CVE-2026-84333: Use after free in Dawn
  • CVE-2026-84351: Buffer overflow in GPU
  • CVE-2026-84325: Improper input validation in DataTransfer
  • CVE-2026-84328: Missing authorization in FileSystem
  • CVE-2026-84347: Use after free in WebRTC
  • CVE-2026-84323: Missing authorization in FileSystem
  • CVE-2026-84355: Incorrect authorization in Navigation
  • CVE-2026-84358: Improper privilege management in Downloads
  • CVE-2026-84332: Incorrect authorization in SiteSettings
  • CVE-2026-84330: UI misrepresentation in FullScreen
  • CVE-2026-84334: Incorrect authorization in Chromoting
  • CVE-2026-84348: Information leak in MediaCapture
  • CVE-2026-84335: Incorrect authorization in TabStrip
  • CVE-2026-84327: Incorrect authorization in Autofill
  • CVE-2026-84329: Confused deputy in CredentialProvider
  • CVE-2026-84356: UI misrepresentation in FullScreen
  • CVE-2026-84350: Use after free in TabStrip
  • CVE-2026-84331: Incorrect authorization in Actor

chromium-152.0.7977.75-1.el10_4

1 week ago
FEDORA-EPEL-2026-d2ab47ea82 Packages in this update:
  • chromium-152.0.7977.75-1.el10_4
Update description:
  • Update to 152.0.7977.75

  • CVE-2026-84353: Use after free in Shared Tab Groups

  • CVE-2026-84352: Use after free in WebGL
  • CVE-2026-84354: Incorrect authorization in FileSystem
  • CVE-2026-84359: Information leak in Skia
  • CVE-2026-84357: Improper input validation in Omnibox
  • CVE-2026-84324: Use after free in Proxy
  • CVE-2026-84349: Use after free in Browser
  • CVE-2026-84326: Uninitialized resource in V8
  • CVE-2026-84333: Use after free in Dawn
  • CVE-2026-84351: Buffer overflow in GPU
  • CVE-2026-84325: Improper input validation in DataTransfer
  • CVE-2026-84328: Missing authorization in FileSystem
  • CVE-2026-84347: Use after free in WebRTC
  • CVE-2026-84323: Missing authorization in FileSystem
  • CVE-2026-84355: Incorrect authorization in Navigation
  • CVE-2026-84358: Improper privilege management in Downloads
  • CVE-2026-84332: Incorrect authorization in SiteSettings
  • CVE-2026-84330: UI misrepresentation in FullScreen
  • CVE-2026-84334: Incorrect authorization in Chromoting
  • CVE-2026-84348: Information leak in MediaCapture
  • CVE-2026-84335: Incorrect authorization in TabStrip
  • CVE-2026-84327: Incorrect authorization in Autofill
  • CVE-2026-84329: Confused deputy in CredentialProvider
  • CVE-2026-84356: UI misrepresentation in FullScreen
  • CVE-2026-84350: Use after free in TabStrip
  • CVE-2026-84331: Incorrect authorization in Actor

chromium-152.0.7977.75-1.fc45

1 week ago
FEDORA-2026-865fdc3e81 Packages in this update:
  • chromium-152.0.7977.75-1.fc45
Update description:
  • Update to 152.0.7977.75

  • CVE-2026-84353: Use after free in Shared Tab Groups

  • CVE-2026-84352: Use after free in WebGL
  • CVE-2026-84354: Incorrect authorization in FileSystem
  • CVE-2026-84359: Information leak in Skia
  • CVE-2026-84357: Improper input validation in Omnibox
  • CVE-2026-84324: Use after free in Proxy
  • CVE-2026-84349: Use after free in Browser
  • CVE-2026-84326: Uninitialized resource in V8
  • CVE-2026-84333: Use after free in Dawn
  • CVE-2026-84351: Buffer overflow in GPU
  • CVE-2026-84325: Improper input validation in DataTransfer
  • CVE-2026-84328: Missing authorization in FileSystem
  • CVE-2026-84347: Use after free in WebRTC
  • CVE-2026-84323: Missing authorization in FileSystem
  • CVE-2026-84355: Incorrect authorization in Navigation
  • CVE-2026-84358: Improper privilege management in Downloads
  • CVE-2026-84332: Incorrect authorization in SiteSettings
  • CVE-2026-84330: UI misrepresentation in FullScreen
  • CVE-2026-84334: Incorrect authorization in Chromoting
  • CVE-2026-84348: Information leak in MediaCapture
  • CVE-2026-84335: Incorrect authorization in TabStrip
  • CVE-2026-84327: Incorrect authorization in Autofill
  • CVE-2026-84329: Confused deputy in CredentialProvider
  • CVE-2026-84356: UI misrepresentation in FullScreen
  • CVE-2026-84350: Use after free in TabStrip
  • CVE-2026-84331: Incorrect authorization in Actor

USN-8724-1: rabbitmq-c vulnerabilities

1 week 1 day ago
It was discovered that the rabbitmq-c command-line tools only accepted credentials on the command line, making them visible to other local users through the process list. An attacker could possibly use this to obtain sensitive credentials. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2023-35789) It was discovered that rabbitmq-c did not correctly compute AMQP frame lengths, leading to a size_t underflow. A remote attacker could possibly use this to cause rabbitmq-c to crash, resulting in a denial of service, or possibly expose sensitive information. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2026-44235) It was discovered that rabbitmq-c did not properly validate the frame size during the AMQP login handshake. A remote attacker could possibly use this to cause a heap buffer overflow, resulting in a denial of service or possibly the execution of arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2026-44236) It was discovered that rabbitmq-c did not correctly validate the length of decoded bytes fields, leading to an integer overflow in a bounds check on 32-bit systems. A remote attacker controlling a broker, or able to intercept an unencrypted connection, could possibly use this to cause an out-of-bounds read, resulting in a denial of service or the exposure of sensitive information. (CVE-2026-59986) It was discovered that rabbitmq-c did not validate the body fragment length when serialising an AMQP body frame with the amqp_send_frame() API. An attacker could possibly use this to cause a heap buffer overflow, resulting in a denial of service (application crash) or possibly the execution of arbitrary code. This issue did not affect Ubuntu 14.04 LTS. (CVE-2026-61547)

nagios-plugins-2.5-2.el9

1 week 1 day ago
FEDORA-EPEL-2026-b3ba209e5d Packages in this update:
  • nagios-plugins-2.5-2.el9
Update description:

Update to upstream (bz#2453492). check_icmp: host-count overflow leads to heap buffer overflow (bz#2513957) Update 0012-fix-perl-ntp-ipv6.patch to allow uppercase hostnames (bz#2500542) Added perl-Math-BigInt as dependency for nagios-plugins-ssl_validity (bz#2439960)