Aggregator

USN-8390-1: Linux kernel vulnerability

1 week 1 day ago
It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could use this to escalate privileges, or possibly escape a container.

USN-8389-1: Linux kernel vulnerabilities

1 week 1 day ago
It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43284, CVE-2026-43500) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - RDS protocol; (CVE-2026-43494)

USN-8388-1: Linux kernel vulnerabilities

1 week 1 day ago
It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43284, CVE-2026-43500) It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503, CVE-2026-46300) Qualys discovered that a race condition existed in the ptrace subsystem of the Linux kernel when privileged processes are exiting. An unprivileged local attacker could use this issue to expose sensitive information. (CVE-2026-46333) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - RDS protocol; (CVE-2026-43494)

USN-8386-1: Nano vulnerabilities

1 week 1 day ago
Michał Majchrowicz and Marcin Wyczechowski discovered that Nano created the ~/.local directory with incorrect permissions. In environments with permissive umask settings, a local attacker could possibly use this issue to inject a malicious launcher file, resulting in information disclosure or other unintended actions. (CVE-2026-6842) Michał Majchrowicz and Marcin Wyczechowski discovered that Nano incorrectly handled directory names when updating the status line. A local attacker could possibly use this issue to cause Nano to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-6843)

systemd-261~rc3-1.fc45

1 week 1 day ago
FEDORA-2026-4280f7beb8 Packages in this update:
  • systemd-261~rc3-1.fc45
Update description:

Automatic update for systemd-261~rc3-1.fc45.

Changelog * Thu Jun 4 2026 Zbigniew Jędrzejewski-Szmek <zbyszek@amutable.com> - 261~rc3-1 - Version 261~rc3 - Various smaller and larger fixes - A hint is emitted if init is called with the legacy telinit args (rhbz#2479961) - Various messages for missing dlopened libraries have been downgraded (rhbz#2463540)

USN-8385-1: Robocode vulnerabilities

1 week 1 day ago
It was discovered that Robocode could be tricked into making network requests to attacker-controlled systems. An attacker could possibly use this issue to cause external service interaction, resulting in information disclosure. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-10648) Lim Sim Yee discovered that Robocode did not properly validate file paths in the CacheCleaner component. An attacker could possibly use this issue to delete arbitrary files. (CVE-2025-14306) Lim Sim Yee discovered that Robocode did not securely create temporary files in the AutoExtract component. An attacker could possibly use this issue to manipulate temporary files, resulting in arbitrary code execution. (CVE-2025-14307) Lim Sim Yee discovered that Robocode did not properly validate data lengths in the Buffer class. An attacker could possibly use this issue to trigger an integer overflow, resulting in arbitrary code execution. (CVE-2025-14308)

python-python-multipart-0.0.31-1.el10_2

1 week 1 day ago
FEDORA-EPEL-2026-4dc7d2c6bb Packages in this update:
  • python-python-multipart-0.0.31-1.el10_2
Update description: 0.0.31 (2026-06-04)
  • Speed up multipart header parsing and callback dispatch.
  • Bound header field name size before validating.
  • Validate Content-Length is non-negative in parse_form.

Fixes security issues GHSA-v9pg-7xvm-68hf, GHSA-5rvq-cxj2-64vf, GHSA-6jv3-5f52-599m, and GHSA-vffw-93wf-4j4q.

0.0.30 (2026-05-31)
  • Parse application/x-www-form-urlencoded bodies per the WHATWG URL standard, treating only & as a field separator.
  • Ignore RFC 2231/5987 extended parameters (name*, filename*) in parse_options_header, keeping the plain parameter authoritative per RFC 7578 §4.2.

python-python-multipart-0.0.31-1.el10_3

1 week 1 day ago
FEDORA-EPEL-2026-63f4d4a3b2 Packages in this update:
  • python-python-multipart-0.0.31-1.el10_3
Update description: 0.0.31 (2026-06-04) 0.0.30 (2026-05-31)
  • Parse application/x-www-form-urlencoded bodies per the WHATWG URL standard, treating only & as a field separator.
  • Ignore RFC 2231/5987 extended parameters (name*, filename*) in parse_options_header, keeping the plain parameter authoritative per RFC 7578 §4.2.

python-python-multipart-0.0.31-1.fc43

1 week 1 day ago
FEDORA-2026-4d81c2ff49 Packages in this update:
  • python-python-multipart-0.0.31-1.fc43
Update description: 0.0.31 (2026-06-04)
  • Speed up multipart header parsing and callback dispatch.
  • Bound header field name size before validating.
  • Validate Content-Length is non-negative in parse_form.

Fixes security issues GHSA-v9pg-7xvm-68hf, GHSA-5rvq-cxj2-64vf, GHSA-6jv3-5f52-599m, and GHSA-vffw-93wf-4j4q.

0.0.30 (2026-05-31)
  • Parse application/x-www-form-urlencoded bodies per the WHATWG URL standard, treating only & as a field separator.
  • Ignore RFC 2231/5987 extended parameters (name*, filename*) in parse_options_header, keeping the plain parameter authoritative per RFC 7578 §4.2.

python-python-multipart-0.0.31-1.fc44

1 week 1 day ago
FEDORA-2026-c7869a8216 Packages in this update:
  • python-python-multipart-0.0.31-1.fc44
Update description: 0.0.31 (2026-06-04)
  • Speed up multipart header parsing and callback dispatch.
  • Bound header field name size before validating.
  • Validate Content-Length is non-negative in parse_form.

Fixes security issues GHSA-v9pg-7xvm-68hf, GHSA-5rvq-cxj2-64vf, GHSA-6jv3-5f52-599m, and GHSA-vffw-93wf-4j4q.

0.0.30 (2026-05-31)
  • Parse application/x-www-form-urlencoded bodies per the WHATWG URL standard, treating only & as a field separator.
  • Ignore RFC 2231/5987 extended parameters (name*, filename*) in parse_options_header, keeping the plain parameter authoritative per RFC 7578 §4.2.

webkitgtk-2.52.4-1.fc44

1 week 1 day ago
FEDORA-2026-a63aad0224 Packages in this update:
  • webkitgtk-2.52.4-1.fc44
Update description:
  • Add support for half-width fonts.
  • Improve content filter compilation by avoiding file copies.
  • Improve handling of out of disk space conditions when the NetworkProcess tried to write data in caches.
  • Fix painting scrollbars when their width changes.
  • Fix playback of certain YouTube videos with low frame rates.
  • Fix webkit://gpu not working in systems where neither libGL.so.1 nor libOpenGL.so.0 are available.
  • Fix several crashes and rendering issues.
  • Security fixes: CVE-2026-28847, CVE-2026-28883, CVE-2026-28901, CVE-2026-28902, CVE-2026-28903, CVE-2026-28904, CVE-2026-28905, CVE-2026-28907, CVE-2026-28942, CVE-2026-28946, CVE-2026-28947, CVE-2026-28953, CVE-2026-28955, CVE-2026-28958, CVE-2026-43658, CVE-2026-43660

webkitgtk-2.52.4-1.fc43

1 week 1 day ago
FEDORA-2026-1557aaef26 Packages in this update:
  • webkitgtk-2.52.4-1.fc43
Update description:
  • Add support for half-width fonts.
  • Improve content filter compilation by avoiding file copies.
  • Improve handling of out of disk space conditions when the NetworkProcess tried to write data in caches.
  • Fix painting scrollbars when their width changes.
  • Fix playback of certain YouTube videos with low frame rates.
  • Fix webkit://gpu not working in systems where neither libGL.so.1 nor libOpenGL.so.0 are available.
  • Fix several crashes and rendering issues.
  • Security fixes: CVE-2026-28847, CVE-2026-28883, CVE-2026-28901, CVE-2026-28902, CVE-2026-28903, CVE-2026-28904, CVE-2026-28905, CVE-2026-28907, CVE-2026-28942, CVE-2026-28946, CVE-2026-28947, CVE-2026-28953, CVE-2026-28955, CVE-2026-28958, CVE-2026-43658, CVE-2026-43660